9da206dc7c
PVCs and CloudNativePG Clusters need S3 buckets and backup schedules
provisioned consistently. This operator watches the
backups.unkin.net/{schedule,destination} annotations on those objects and
provisions everything needed to back them up, with no new CRDs.
- Add a PVC controller that provisions cephrgw ObjectStoreUser/Bucket/BucketAccess,
auto-generates a restic repo-password Secret and creates a k8up Schedule scoped
to the PVC via spec.backup.volumes[].persistentVolumeClaim.claimName.
- Add a CNPG Cluster controller that provisions the same bucket stack, idempotently
patches spec.backup.barmanObjectStore (leaving a user-set destinationPath alone
with a Warning event) and creates a ScheduledBackup.
- Resolve destinations through a ConfigMap lookup table; requeue until the
BucketAccess is Ready before creating schedule resources; own-reference created
resources and retain bucket data by default.
- Add schedule-mapping helpers (k8up 5-field/shortcut pass-through, CNPG 6-field
seconds-first) and deterministic, length-bounded name derivation.
- Add unit tests (schedule mapping, name derivation, destination resolution) and
envtest controller tests for both paths, wiring the external CRDs into envtest.
- Add kubebuilder-generated RBAC, a Dockerfile (distroless/nonroot), Woodpecker
lint/test/build pipelines and a tag-triggered image push to the artifactapi
docker-internal registry, plus a version-bump Makefile and deploy manifests.
33 lines
1.1 KiB
Go
33 lines
1.1 KiB
Go
// Copyright 2024 The Go Authors. All rights reserved.
|
|
// Use of this source code is governed by a BSD-style
|
|
// license that can be found in the LICENSE file.
|
|
|
|
package http2
|
|
|
|
import (
|
|
"crypto/tls"
|
|
"errors"
|
|
"net"
|
|
)
|
|
|
|
const nextProtoUnencryptedHTTP2 = "unencrypted_http2"
|
|
|
|
// unencryptedNetConnFromTLSConn retrieves a net.Conn wrapped in a *tls.Conn.
|
|
//
|
|
// TLSNextProto functions accept a *tls.Conn.
|
|
//
|
|
// When passing an unencrypted HTTP/2 connection to a TLSNextProto function,
|
|
// we pass a *tls.Conn with an underlying net.Conn containing the unencrypted connection.
|
|
// To be extra careful about mistakes (accidentally dropping TLS encryption in a place
|
|
// where we want it), the tls.Conn contains a net.Conn with an UnencryptedNetConn method
|
|
// that returns the actual connection we want to use.
|
|
func unencryptedNetConnFromTLSConn(tc *tls.Conn) (net.Conn, error) {
|
|
conner, ok := tc.NetConn().(interface {
|
|
UnencryptedNetConn() net.Conn
|
|
})
|
|
if !ok {
|
|
return nil, errors.New("http2: TLS conn unexpectedly found in unencrypted handoff")
|
|
}
|
|
return conner.UnencryptedNetConn(), nil
|
|
}
|