Skip to content

Commit

Permalink
Add Application, Role, Group, RoleAssignment support
Browse files Browse the repository at this point in the history
Signed-off-by: vaspahomov <[email protected]>
  • Loading branch information
vaspahomov committed Oct 29, 2021
1 parent 3a2c932 commit 0288a64
Show file tree
Hide file tree
Showing 26 changed files with 3,076 additions and 5 deletions.
2 changes: 2 additions & 0 deletions apis/azure.go
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@ import (
databasev1beta1 "github.com/crossplane/provider-azure/apis/database/v1beta1"
keyvaultv1alpha1 "github.com/crossplane/provider-azure/apis/keyvault/v1alpha1"
networkv1alpha3 "github.com/crossplane/provider-azure/apis/network/v1alpha3"
rbacv1alpha1 "github.com/crossplane/provider-azure/apis/rbac/v1alpha1"
storagev1alpha3 "github.com/crossplane/provider-azure/apis/storage/v1alpha3"
azurev1alpha3 "github.com/crossplane/provider-azure/apis/v1alpha3"
azurev1beta1 "github.com/crossplane/provider-azure/apis/v1beta1"
Expand All @@ -42,6 +43,7 @@ func init() {
databasev1beta1.SchemeBuilder.AddToScheme,
keyvaultv1alpha1.SchemeBuilder.AddToScheme,
networkv1alpha3.SchemeBuilder.AddToScheme,
rbacv1alpha1.SchemeBuilder.AddToScheme,
storagev1alpha3.SchemeBuilder.AddToScheme,
)
}
Expand Down
18 changes: 18 additions & 0 deletions apis/rbac/rbac.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
/*
Copyright 2021 The Crossplane Authors.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

// Package rbac contains Azure rbac API versions
package rbac
21 changes: 21 additions & 0 deletions apis/rbac/v1alpha1/doc.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
/*
Copyright 2021 The Crossplane Authors.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

// Package v1alpha1 contains managed resources for Azure rbac.
// +kubebuilder:object:generate=true
// +groupName=rbac.azure.crossplane.io
// +versionName=v1alpha1
package v1alpha1
67 changes: 67 additions & 0 deletions apis/rbac/v1alpha1/referencers.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
/*
Copyright 2021 The Crossplane Authors.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

package v1alpha1

import (
"context"

"github.com/pkg/errors"
"sigs.k8s.io/controller-runtime/pkg/client"

"github.com/crossplane/crossplane-runtime/pkg/reference"
)

// ResolveReferences of this ServicePrincipal
func (mg *ServicePrincipal) ResolveReferences(ctx context.Context, c client.Reader) error {
r := reference.NewAPIResolver(c, mg)

// Resolve spec.applicationID
rsp, err := r.Resolve(ctx, reference.ResolutionRequest{
CurrentValue: mg.Spec.ForProvider.ApplicationID,
Reference: mg.Spec.ForProvider.ApplicationIDRef,
Selector: mg.Spec.ForProvider.ApplicationIDSelector,
To: reference.To{Managed: &Application{}, List: &ApplicationList{}},
Extract: reference.ExternalName(),
})
if err != nil {
return errors.Wrap(err, "spec.applicationID")
}
mg.Spec.ForProvider.ApplicationID = rsp.ResolvedValue
mg.Spec.ForProvider.ApplicationIDRef = rsp.ResolvedReference

return nil
}

// ResolveReferences of this ServicePrincipal
func (mg *RoleAssignment) ResolveReferences(ctx context.Context, c client.Reader) error {
r := reference.NewAPIResolver(c, mg)

rsp, err := r.Resolve(ctx, reference.ResolutionRequest{
CurrentValue: mg.Spec.ForProvider.PrincipalID,
Reference: mg.Spec.ForProvider.PrincipalIDRef,
Selector: mg.Spec.ForProvider.PrincipalIDSelector,
To: reference.To{Managed: &ServicePrincipal{}, List: &ServicePrincipalList{}},
Extract: reference.ExternalName(),
})
if err != nil {
return errors.Wrap(err, "spec.principalID")
}
mg.Spec.ForProvider.PrincipalID = rsp.ResolvedValue
mg.Spec.ForProvider.PrincipalIDRef = rsp.ResolvedReference

return nil
}
62 changes: 62 additions & 0 deletions apis/rbac/v1alpha1/register.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
/*
Copyright 2019 The Crossplane Authors.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

package v1alpha1

import (
"reflect"

"k8s.io/apimachinery/pkg/runtime/schema"
"sigs.k8s.io/controller-runtime/pkg/scheme"
)

// Package type metadata.
const (
Group = "rbac.azure.crossplane.io"
Version = "v1alpha1"
)

var (
// SchemeGroupVersion is group version used to register these objects
SchemeGroupVersion = schema.GroupVersion{Group: Group, Version: Version}

// SchemeBuilder is used to add go types to the GroupVersionKind scheme
SchemeBuilder = &scheme.Builder{GroupVersion: SchemeGroupVersion}
)

// Application type metadata.
var (
ApplicationKind = reflect.TypeOf(Application{}).Name()
ApplicationGroupKind = schema.GroupKind{Group: Group, Kind: ApplicationKind}.String()
ApplicationKindAPIVersion = ApplicationKind + "." + SchemeGroupVersion.String()
ApplicationGroupVersionKind = SchemeGroupVersion.WithKind(ApplicationKind)

ServicePrincipalKind = reflect.TypeOf(ServicePrincipal{}).Name()
ServicePrincipalGroupKind = schema.GroupKind{Group: Group, Kind: ServicePrincipalKind}.String()
ServicePrincipalKindAPIVersion = ServicePrincipalKind + "." + SchemeGroupVersion.String()
ServicePrincipalGroupVersionKind = SchemeGroupVersion.WithKind(ServicePrincipalKind)

RoleAssignmentKind = reflect.TypeOf(RoleAssignment{}).Name()
RoleAssignmentGroupKind = schema.GroupKind{Group: Group, Kind: RoleAssignmentKind}.String()
RoleAssignmentKindAPIVersion = RoleAssignmentKind + "." + SchemeGroupVersion.String()
RoleAssignmentGroupVersionKind = SchemeGroupVersion.WithKind(RoleAssignmentKind)
)

func init() {
SchemeBuilder.Register(&Application{}, &ApplicationList{})
SchemeBuilder.Register(&ServicePrincipal{}, &ServicePrincipalList{})
SchemeBuilder.Register(&RoleAssignment{}, &RoleAssignmentList{})
}
206 changes: 206 additions & 0 deletions apis/rbac/v1alpha1/types.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,206 @@
/*
Copyright 2019 The Crossplane Authors.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

package v1alpha1

import (
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"

xpv1 "github.com/crossplane/crossplane-runtime/apis/common/v1"
)

// ApplicationParameters parameters for an application.
type ApplicationParameters struct {
// AvailableToOtherTenants - Whether the application is available to other tenants.
// +optional
// +immutable
AvailableToOtherTenants *bool `json:"availableToOtherTenants,omitempty"`

// DisplayName - The display name of the application.
// +optional
// +immutable
DisplayName *string `json:"displayName,omitempty"`

// Homepage - The home page of the application.
// +optional
// +immutable
Homepage *string `json:"homepage,omitempty"`

// IdentifierUris - A collection of URIs for the application.
// +optional
// +immutable
IdentifierURIs []string `json:"identifierUris,omitempty"`
}

// An ApplicationSpec defines the desired state of an Application.
type ApplicationSpec struct {
xpv1.ResourceSpec `json:",inline"`
ForProvider ApplicationParameters `json:"forProvider"`
}

// An ApplicationStatus represents the observed state of an Application.
type ApplicationStatus struct {
xpv1.ResourceStatus `json:",inline"`

// ApplicationID - The application ID.
ApplicationID string `json:"applicationID,omitempty"`
}

// +kubebuilder:object:root=true

// A Application is a managed resource that represents an Application.
// +kubebuilder:printcolumn:name="READY",type="string",JSONPath=".status.conditions[?(@.type=='Ready')].status"
// +kubebuilder:printcolumn:name="SYNCED",type="string",JSONPath=".status.conditions[?(@.type=='Synced')].status"
// +kubebuilder:printcolumn:name="AGE",type="date",JSONPath=".metadata.creationTimestamp"
// +kubebuilder:subresource:status
// +kubebuilder:resource:scope=Cluster,categories={crossplane,managed,azure}
type Application struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`

Spec ApplicationSpec `json:"spec"`
Status ApplicationStatus `json:"status,omitempty"`
}

// +kubebuilder:object:root=true

// ApplicationList contains a list of Application items
type ApplicationList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []Application `json:"items"`
}

// An ServicePrincipalParameters defines the desired state of an ServicePrincipal.
type ServicePrincipalParameters struct {
// ApplicationID - The application ID.
// +optional
ApplicationID string `json:"applicationID,omitempty"`

// ApplicationIDRef - A reference to the Application id.
// +optional
// +immutable
ApplicationIDRef *xpv1.Reference `json:"applicationIDRef,omitempty"`

// ApplicationIDSelector - Select a reference to the Application id.
// +immutable
ApplicationIDSelector *xpv1.Selector `json:"applicationIDSelector,omitempty"`

// AccountEnabled - whether or not the service principal account is enabled
// +optional
// +immutable
AccountEnabled *bool `json:"accountEnabled,omitempty"`
}

// An ServicePrincipalSpec defines the desired state of an ServicePrincipal.
type ServicePrincipalSpec struct {
xpv1.ResourceSpec `json:",inline"`
ForProvider ServicePrincipalParameters `json:"forProvider"`
}

// An ServicePrincipalStatus represents the observed state of an ServicePrincipal.
type ServicePrincipalStatus struct {
xpv1.ResourceStatus `json:",inline"`
}

// +kubebuilder:object:root=true

// A ServicePrincipal is a managed resource that represents an ServicePrincipal.
// +kubebuilder:printcolumn:name="READY",type="string",JSONPath=".status.conditions[?(@.type=='Ready')].status"
// +kubebuilder:printcolumn:name="SYNCED",type="string",JSONPath=".status.conditions[?(@.type=='Synced')].status"
// +kubebuilder:printcolumn:name="AGE",type="date",JSONPath=".metadata.creationTimestamp"
// +kubebuilder:subresource:status
// +kubebuilder:resource:scope=Cluster,categories={crossplane,managed,azure}
type ServicePrincipal struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`

Spec ServicePrincipalSpec `json:"spec"`
Status ServicePrincipalStatus `json:"status,omitempty"`
}

// An RoleAssignmentParameters defines the desired state of an RoleAssignment.
type RoleAssignmentParameters struct {
// PrincipalID - The principal ID assigned to the role.
// This maps to the ID inside the Active Directory.
// It can point to a user, service principal, or security group.
// +optional
PrincipalID string `json:"principalID,omitempty"`

// PrincipalIDRef - A reference to the Principal id.
// +optional
// +immutable
PrincipalIDRef *xpv1.Reference `json:"principalIDRef,omitempty"`

// PrincipalIDRef - Select a reference to the Principal id.
// +immutable
PrincipalIDSelector *xpv1.Selector `json:"principalIDSelector,omitempty"`

// RoleID - The role definition ID.
// +immutable
// +kubebuilder:validation:Required
RoleID string `json:"roleID"`

// Scope - The role assignment scope.
// +immutable
// +kubebuilder:validation:Required
Scope string `json:"scope"`
}

// +kubebuilder:object:root=true

// ServicePrincipalList contains a list of ServicePrincipal items
type ServicePrincipalList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []ServicePrincipal `json:"items"`
}

// An RoleAssignmentSpec defines the desired state of an RoleAssignment.
type RoleAssignmentSpec struct {
xpv1.ResourceSpec `json:",inline"`
ForProvider RoleAssignmentParameters `json:"forProvider"`
}

// An RoleAssignmentStatus represents the observed state of an RoleAssignment.
type RoleAssignmentStatus struct {
xpv1.ResourceStatus `json:",inline"`
}

// +kubebuilder:object:root=true

// A RoleAssignment is a managed resource that represents an RoleAssignment.
// +kubebuilder:printcolumn:name="READY",type="string",JSONPath=".status.conditions[?(@.type=='Ready')].status"
// +kubebuilder:printcolumn:name="SYNCED",type="string",JSONPath=".status.conditions[?(@.type=='Synced')].status"
// +kubebuilder:printcolumn:name="AGE",type="date",JSONPath=".metadata.creationTimestamp"
// +kubebuilder:subresource:status
// +kubebuilder:resource:scope=Cluster,categories={crossplane,managed,azure}
type RoleAssignment struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`

Spec RoleAssignmentSpec `json:"spec"`
Status RoleAssignmentStatus `json:"status,omitempty"`
}

// +kubebuilder:object:root=true

// RoleAssignmentList contains a list of RoleAssignment items
type RoleAssignmentList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []RoleAssignment `json:"items"`
}
Loading

0 comments on commit 0288a64

Please sign in to comment.