9da206dc7c
PVCs and CloudNativePG Clusters need S3 buckets and backup schedules
provisioned consistently. This operator watches the
backups.unkin.net/{schedule,destination} annotations on those objects and
provisions everything needed to back them up, with no new CRDs.
- Add a PVC controller that provisions cephrgw ObjectStoreUser/Bucket/BucketAccess,
auto-generates a restic repo-password Secret and creates a k8up Schedule scoped
to the PVC via spec.backup.volumes[].persistentVolumeClaim.claimName.
- Add a CNPG Cluster controller that provisions the same bucket stack, idempotently
patches spec.backup.barmanObjectStore (leaving a user-set destinationPath alone
with a Warning event) and creates a ScheduledBackup.
- Resolve destinations through a ConfigMap lookup table; requeue until the
BucketAccess is Ready before creating schedule resources; own-reference created
resources and retain bucket data by default.
- Add schedule-mapping helpers (k8up 5-field/shortcut pass-through, CNPG 6-field
seconds-first) and deterministic, length-bounded name derivation.
- Add unit tests (schedule mapping, name derivation, destination resolution) and
envtest controller tests for both paths, wiring the external CRDs into envtest.
- Add kubebuilder-generated RBAC, a Dockerfile (distroless/nonroot), Woodpecker
lint/test/build pipelines and a tag-triggered image push to the artifactapi
docker-internal registry, plus a version-bump Makefile and deploy manifests.
19 lines
727 B
Markdown
19 lines
727 B
Markdown
# Security Policy
|
|
|
|
If you have discovered a security vulnerability in this project, please report it
|
|
privately. **Do not disclose it as a public issue.** This gives us time to work with you
|
|
to fix the issue before public exposure, reducing the chance that the exploit will be
|
|
used before a patch is released.
|
|
|
|
You may submit the report in the following ways:
|
|
|
|
- send an email to go-logr-security@googlegroups.com
|
|
- send us a [private vulnerability report](https://github.com/go-logr/logr/security/advisories/new)
|
|
|
|
Please provide the following information in your report:
|
|
|
|
- A description of the vulnerability and its impact
|
|
- How to reproduce the issue
|
|
|
|
We ask that you give us 90 days to work on a fix before public exposure.
|