Schema: Add schema for role+access policies (#68047)
This commit is contained in:
@@ -7,6 +7,17 @@
|
||||
//
|
||||
// Run 'make gen-cue' from repository root to regenerate.
|
||||
|
||||
// Raw generated types from AccessPolicy kind.
|
||||
export type {
|
||||
AccessPolicy,
|
||||
RoleRef,
|
||||
ResourceRef,
|
||||
AccessRule
|
||||
} from './raw/accesspolicy/x/accesspolicy_types.gen';
|
||||
|
||||
// Raw generated enums and default consts from accesspolicy kind.
|
||||
export { defaultAccessPolicy } from './raw/accesspolicy/x/accesspolicy_types.gen';
|
||||
|
||||
// Raw generated types from Dashboard kind.
|
||||
export type {
|
||||
AnnotationTarget,
|
||||
@@ -129,6 +140,17 @@ export type {
|
||||
// Raw generated types from PublicDashboard kind.
|
||||
export type { PublicDashboard } from './raw/publicdashboard/x/publicdashboard_types.gen';
|
||||
|
||||
// Raw generated types from Role kind.
|
||||
export type { Role } from './raw/role/x/role_types.gen';
|
||||
|
||||
// Raw generated types from RoleBinding kind.
|
||||
export type {
|
||||
RoleBinding,
|
||||
CustomRoleRef,
|
||||
BuiltinRoleRef,
|
||||
RoleBindingSubject
|
||||
} from './raw/rolebinding/x/rolebinding_types.gen';
|
||||
|
||||
// Raw generated types from ServiceAccount kind.
|
||||
export type {
|
||||
ServiceAccount,
|
||||
|
||||
@@ -0,0 +1,60 @@
|
||||
// Code generated - EDITING IS FUTILE. DO NOT EDIT.
|
||||
//
|
||||
// Generated by:
|
||||
// kinds/gen.go
|
||||
// Using jennies:
|
||||
// TSResourceJenny
|
||||
// LatestMajorsOrXJenny
|
||||
//
|
||||
// Run 'make gen-cue' from repository root to regenerate.
|
||||
|
||||
export interface RoleRef {
|
||||
/**
|
||||
* Policies can apply to roles, teams, or users
|
||||
* Applying policies to individual users is supported, but discouraged
|
||||
*/
|
||||
kind: ('Role' | 'BuiltinRole' | 'Team' | 'User');
|
||||
name: string;
|
||||
xname: string; // temporary
|
||||
}
|
||||
|
||||
export interface ResourceRef {
|
||||
kind: string; // explicit resource or folder will cascade
|
||||
name: string;
|
||||
}
|
||||
|
||||
export interface AccessRule {
|
||||
/**
|
||||
* The kind this rule applies to (dashboars, alert, etc)
|
||||
*/
|
||||
kind: ('*' | string);
|
||||
/**
|
||||
* Specific sub-elements like "alert.rules" or "dashboard.permissions"????
|
||||
*/
|
||||
target?: string;
|
||||
/**
|
||||
* READ, WRITE, CREATE, DELETE, ...
|
||||
* should move to k8s style verbs like: "get", "list", "watch", "create", "update", "patch", "delete"
|
||||
*/
|
||||
verb: ('*' | 'none' | string);
|
||||
}
|
||||
|
||||
export interface AccessPolicy {
|
||||
/**
|
||||
* The role that must apply this policy
|
||||
*/
|
||||
role: RoleRef;
|
||||
/**
|
||||
* The set of rules to apply. Note that * is required to modify
|
||||
* access policy rules, and that "none" will reject all actions
|
||||
*/
|
||||
rules: Array<AccessRule>;
|
||||
/**
|
||||
* The scope where these policies should apply
|
||||
*/
|
||||
scope: ResourceRef;
|
||||
}
|
||||
|
||||
export const defaultAccessPolicy: Partial<AccessPolicy> = {
|
||||
rules: [],
|
||||
};
|
||||
@@ -0,0 +1,32 @@
|
||||
// Code generated - EDITING IS FUTILE. DO NOT EDIT.
|
||||
//
|
||||
// Generated by:
|
||||
// kinds/gen.go
|
||||
// Using jennies:
|
||||
// TSResourceJenny
|
||||
// LatestMajorsOrXJenny
|
||||
//
|
||||
// Run 'make gen-cue' from repository root to regenerate.
|
||||
|
||||
export interface Role {
|
||||
/**
|
||||
* Role description
|
||||
*/
|
||||
description?: string;
|
||||
/**
|
||||
* Optional display
|
||||
*/
|
||||
displayName?: string;
|
||||
/**
|
||||
* Name of the team.
|
||||
*/
|
||||
groupName?: string;
|
||||
/**
|
||||
* Do not show this role
|
||||
*/
|
||||
hidden: (boolean | false);
|
||||
/**
|
||||
* The role identifier `managed:builtins:editor:permissions`
|
||||
*/
|
||||
name: string;
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
// Code generated - EDITING IS FUTILE. DO NOT EDIT.
|
||||
//
|
||||
// Generated by:
|
||||
// kinds/gen.go
|
||||
// Using jennies:
|
||||
// TSResourceJenny
|
||||
// LatestMajorsOrXJenny
|
||||
//
|
||||
// Run 'make gen-cue' from repository root to regenerate.
|
||||
|
||||
export interface CustomRoleRef {
|
||||
kind: 'Role';
|
||||
name: string;
|
||||
}
|
||||
|
||||
export interface BuiltinRoleRef {
|
||||
kind: 'BuiltinRole';
|
||||
name: ('viewer' | 'editor' | 'admin');
|
||||
}
|
||||
|
||||
export interface RoleBindingSubject {
|
||||
kind: ('Team' | 'User');
|
||||
/**
|
||||
* The team/user identifier name
|
||||
*/
|
||||
name: string;
|
||||
}
|
||||
|
||||
export interface RoleBinding {
|
||||
/**
|
||||
* The role we are discussing
|
||||
*/
|
||||
role: (BuiltinRoleRef | CustomRoleRef);
|
||||
/**
|
||||
* The team or user that has the specified role
|
||||
*/
|
||||
subject: RoleBindingSubject;
|
||||
}
|
||||
Reference in New Issue
Block a user