BindTSIGKey: add secretTemplate for labels/annotations on the managed Secret
The operator-generated TSIG Secret previously carried only the managed-by
label, so it could not be mirrored to another namespace by emberstack
reflector (which requires reflection-allowed annotations on the source).
Add spec.secretTemplate.{annotations,labels}, applied both when the Secret
is first generated and reconciled onto the existing Secret when the CR
changes (imported secrets are left untouched so we don't fight their
external manager). This lets the external-dns TSIG key be managed in
bind-internal and reflected into the externaldns namespace.
This commit is contained in:
@@ -41,6 +41,24 @@ type BindTSIGKeySpec struct {
|
||||
// `secret` key and the operator will not generate new material.
|
||||
// +optional
|
||||
ImportExisting bool `json:"importExisting,omitempty"`
|
||||
|
||||
// SecretTemplate customizes metadata written onto the managed key Secret.
|
||||
// Useful, for example, to let secret-reflection tooling mirror the key into
|
||||
// another namespace. Operator-managed labels are always preserved.
|
||||
// +optional
|
||||
SecretTemplate *SecretMetadata `json:"secretTemplate,omitempty"`
|
||||
}
|
||||
|
||||
// SecretMetadata carries extra labels and annotations to stamp onto a
|
||||
// Secret managed by the operator.
|
||||
type SecretMetadata struct {
|
||||
// Annotations to set on the Secret.
|
||||
// +optional
|
||||
Annotations map[string]string `json:"annotations,omitempty"`
|
||||
|
||||
// Labels to set on the Secret.
|
||||
// +optional
|
||||
Labels map[string]string `json:"labels,omitempty"`
|
||||
}
|
||||
|
||||
// BindTSIGKeyStatus reports observed TSIG key state.
|
||||
|
||||
@@ -691,7 +691,7 @@ func (in *BindTSIGKey) DeepCopyInto(out *BindTSIGKey) {
|
||||
*out = *in
|
||||
out.TypeMeta = in.TypeMeta
|
||||
in.ObjectMeta.DeepCopyInto(&out.ObjectMeta)
|
||||
out.Spec = in.Spec
|
||||
in.Spec.DeepCopyInto(&out.Spec)
|
||||
in.Status.DeepCopyInto(&out.Status)
|
||||
}
|
||||
|
||||
@@ -748,6 +748,11 @@ func (in *BindTSIGKeyList) DeepCopyObject() runtime.Object {
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *BindTSIGKeySpec) DeepCopyInto(out *BindTSIGKeySpec) {
|
||||
*out = *in
|
||||
if in.SecretTemplate != nil {
|
||||
in, out := &in.SecretTemplate, &out.SecretTemplate
|
||||
*out = new(SecretMetadata)
|
||||
(*in).DeepCopyInto(*out)
|
||||
}
|
||||
}
|
||||
|
||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new BindTSIGKeySpec.
|
||||
@@ -1208,3 +1213,32 @@ func (in *Record) DeepCopy() *Record {
|
||||
in.DeepCopyInto(out)
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *SecretMetadata) DeepCopyInto(out *SecretMetadata) {
|
||||
*out = *in
|
||||
if in.Annotations != nil {
|
||||
in, out := &in.Annotations, &out.Annotations
|
||||
*out = make(map[string]string, len(*in))
|
||||
for key, val := range *in {
|
||||
(*out)[key] = val
|
||||
}
|
||||
}
|
||||
if in.Labels != nil {
|
||||
in, out := &in.Labels, &out.Labels
|
||||
*out = make(map[string]string, len(*in))
|
||||
for key, val := range *in {
|
||||
(*out)[key] = val
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SecretMetadata.
|
||||
func (in *SecretMetadata) DeepCopy() *SecretMetadata {
|
||||
if in == nil {
|
||||
return nil
|
||||
}
|
||||
out := new(SecretMetadata)
|
||||
in.DeepCopyInto(out)
|
||||
return out
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user