Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Draft]: CSPL-2600: Integrate HashiCorp Vault Support in Splunk Operator #1388

Open
wants to merge 21 commits into
base: CSPL-2601
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 22 additions & 0 deletions api/v4/common_types.go
Original file line number Diff line number Diff line change
Expand Up @@ -238,6 +238,8 @@ type CommonSplunkSpec struct {
// Sets imagePullSecrets if image is being pulled from a private registry.
// See https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
ImagePullSecrets []corev1.LocalObjectReference `json:"imagePullSecrets,omitempty"`

VaultIntegration VaultIntegration `json:"vaultIntegration,omitempty"`
}

// StorageClassSpec defines storage class configuration
Expand Down Expand Up @@ -569,6 +571,26 @@ type PhaseInfo struct {
FailCount uint32 `json:"failCount,omitempty"`
}

// Vault represents the Vault configuration for enabling secret injection.
// +kubebuilder:object:generate=true
// +kubebuilder:validation:Optional
type VaultIntegration struct {
// Enable vault support
Enable bool `json:"enable,omitempty"`

// Vault Address
Address string `json:"address"`

// Vault Role
Role string `json:"role"`

// Vault secret path
SecretPath string `json:"secretPath"`

// OperatorRole if different from the role
OperatorRole string `json:"operatorRole,omitempty"`
}

const (
// AppPkgDownloadPending indicates pending
AppPkgDownloadPending AppPhaseStatusType = 101
Expand Down
16 changes: 16 additions & 0 deletions api/v4/zz_generated.deepcopy.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

91 changes: 86 additions & 5 deletions config/crd/bases/enterprise.splunk.com_clustermanagers.yaml

Large diffs are not rendered by default.

91 changes: 86 additions & 5 deletions config/crd/bases/enterprise.splunk.com_clustermasters.yaml

Large diffs are not rendered by default.

180 changes: 171 additions & 9 deletions config/crd/bases/enterprise.splunk.com_indexerclusters.yaml

Large diffs are not rendered by default.

91 changes: 86 additions & 5 deletions config/crd/bases/enterprise.splunk.com_licensemanagers.yaml

Large diffs are not rendered by default.

91 changes: 86 additions & 5 deletions config/crd/bases/enterprise.splunk.com_licensemasters.yaml

Large diffs are not rendered by default.

180 changes: 171 additions & 9 deletions config/crd/bases/enterprise.splunk.com_monitoringconsoles.yaml

Large diffs are not rendered by default.

180 changes: 171 additions & 9 deletions config/crd/bases/enterprise.splunk.com_searchheadclusters.yaml

Large diffs are not rendered by default.

180 changes: 171 additions & 9 deletions config/crd/bases/enterprise.splunk.com_standalones.yaml

Large diffs are not rendered by default.

288 changes: 274 additions & 14 deletions config/rbac/role.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -27,14 +27,113 @@ rules:
- ""
resources:
- configmaps
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
resources:
- endpoints
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
resources:
- events
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
resources:
- persistentvolumeclaims
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
resources:
- pods
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
resources:
- pods/exec
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
resources:
- secrets
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
resources:
- serviceaccounts
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
resources:
- services
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
resources:
- services/finalizers
verbs:
- create
Expand All @@ -48,13 +147,6 @@ rules:
- enterprise.splunk.com
resources:
- clustermanagers
- clustermasters
- indexerclusters
- licensemanagers
- licensemasters
- monitoringconsoles
- searchheadclusters
- standalones
verbs:
- create
- delete
Expand All @@ -67,25 +159,193 @@ rules:
- enterprise.splunk.com
resources:
- clustermanagers/finalizers
- clustermasters/finalizers
- indexerclusters/finalizers
- licensemanagers/finalizers
- licensemasters/finalizers
- monitoringconsoles/finalizers
- searchheadclusters/finalizers
- standalones/finalizers
verbs:
- update
- apiGroups:
- enterprise.splunk.com
resources:
- clustermanagers/status
verbs:
- get
- patch
- update
- apiGroups:
- enterprise.splunk.com
resources:
- clustermasters
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- enterprise.splunk.com
resources:
- clustermasters/finalizers
verbs:
- update
- apiGroups:
- enterprise.splunk.com
resources:
- clustermasters/status
verbs:
- get
- patch
- update
- apiGroups:
- enterprise.splunk.com
resources:
- indexerclusters
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- enterprise.splunk.com
resources:
- indexerclusters/finalizers
verbs:
- update
- apiGroups:
- enterprise.splunk.com
resources:
- indexerclusters/status
verbs:
- get
- patch
- update
- apiGroups:
- enterprise.splunk.com
resources:
- licensemanagers
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- enterprise.splunk.com
resources:
- licensemanagers/finalizers
verbs:
- update
- apiGroups:
- enterprise.splunk.com
resources:
- licensemanagers/status
verbs:
- get
- patch
- update
- apiGroups:
- enterprise.splunk.com
resources:
- licensemasters
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- enterprise.splunk.com
resources:
- licensemasters/finalizers
verbs:
- update
- apiGroups:
- enterprise.splunk.com
resources:
- licensemasters/status
verbs:
- get
- patch
- update
- apiGroups:
- enterprise.splunk.com
resources:
- monitoringconsoles
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- enterprise.splunk.com
resources:
- monitoringconsoles/finalizers
verbs:
- update
- apiGroups:
- enterprise.splunk.com
resources:
- monitoringconsoles/status
verbs:
- get
- patch
- update
- apiGroups:
- enterprise.splunk.com
resources:
- searchheadclusters
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- enterprise.splunk.com
resources:
- searchheadclusters/finalizers
verbs:
- update
- apiGroups:
- enterprise.splunk.com
resources:
- searchheadclusters/status
verbs:
- get
- patch
- update
- apiGroups:
- enterprise.splunk.com
resources:
- standalones
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- enterprise.splunk.com
resources:
- standalones/finalizers
verbs:
- update
- apiGroups:
- enterprise.splunk.com
resources:
- standalones/status
verbs:
- get
Expand Down
Loading
Loading