Files
cephrgw-operator/config/crd/bases/ceph.unkin.net_bucketaccesses.yaml
T
benvin 1ea1713d6e Initial cephrgw-operator: Ceph RGW buckets & keys via dashboard API
Adds a Kubernetes operator that provisions Ceph RGW (S3) buckets and
access keys declaratively through the Ceph manager dashboard REST API.

Three CRDs in group ceph.unkin.net/v1alpha1:
- ObjectStoreUser: creates an RGW user, delivers its key pair to a Secret
- Bucket: creates an S3 bucket owned by an ObjectStoreUser; owns the
  bucket's aggregate S3 policy (union of all BucketAccess grants)
- BucketAccess: grants read-only/read-write/full access, provisioning a
  dedicated user (or reusing a referenced one) and delivering RW/RO keys

The internal/ceph client wraps the dashboard /api/auth, /api/rgw/user and
/api/rgw/bucket endpoints with lazy token auth and re-auth on 401. Bucket
policies are rendered deterministically and applied via the bucket
policy API (Reef 18.2+). Credentials come from the cephrgw-credentials
Secret via env. Includes generated CRDs/RBAC, samples, kind manifests,
Woodpecker CI, and docs/ceph-setup.md covering the required Ceph
dashboard account, RGW wiring and permissions.
2026-07-18 00:07:22 +10:00

179 lines
7.4 KiB
YAML

---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.17.3
name: bucketaccesses.ceph.unkin.net
spec:
group: ceph.unkin.net
names:
kind: BucketAccess
listKind: BucketAccessList
plural: bucketaccesses
shortNames:
- ba
singular: bucketaccess
scope: Namespaced
versions:
- additionalPrinterColumns:
- jsonPath: .spec.bucketRef
name: Bucket
type: string
- jsonPath: .spec.level
name: Level
type: string
- jsonPath: .status.uid
name: UID
type: string
- jsonPath: .status.phase
name: Phase
type: string
name: v1alpha1
schema:
openAPIV3Schema:
description: |-
BucketAccess grants an RGW user read-only, read-write or full access to a
Bucket via the bucket's S3 policy.
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
description: |-
BucketAccessSpec grants an RGW user a level of access to a Bucket by
maintaining a statement in the bucket's S3 policy. If UserRef is empty the
operator provisions a dedicated user for this grant and writes its keys into
a Secret; otherwise it grants an existing ObjectStoreUser.
properties:
bucketRef:
description: BucketRef names the Bucket (in this namespace) to grant
access to.
type: string
level:
description: Level is the access level to grant.
enum:
- read-only
- read-write
- full
type: string
secretName:
description: |-
SecretName is the Secret the operator writes credentials into for the
dedicated user it creates (UserRef empty). Defaults to "<name>-rgw".
type: string
uid:
description: |-
UID overrides the id of the dedicated user created when UserRef is empty.
Defaults to "<bucket>-<name>". Ignored when UserRef is set.
type: string
userRef:
description: |-
UserRef optionally names an existing ObjectStoreUser (in this namespace)
to grant. When set, the operator does not create or delete a user and
SecretName is ignored (that user already owns its own credential Secret).
type: string
required:
- bucketRef
- level
type: object
status:
description: BucketAccessStatus reports observed grant state.
properties:
bound:
description: Bound reports whether the grant is reflected in the bucket
policy.
type: boolean
conditions:
items:
description: Condition contains details for one aspect of the current
state of this API Resource.
properties:
lastTransitionTime:
description: |-
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: |-
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
x-kubernetes-list-map-keys:
- type
x-kubernetes-list-type: map
observedGeneration:
format: int64
type: integer
phase:
description: Phase is a coarse lifecycle summary (Pending/Ready/Error).
type: string
secretName:
description: SecretName is the Secret holding the dedicated user's
credentials, if any.
type: string
uid:
description: UID is the RGW user id that was granted access.
type: string
type: object
type: object
served: true
storage: true
subresources:
status: {}