2022-09-05 03:06:08 -04:00
|
|
|
/*
|
|
|
|
Copyright (c) Edgeless Systems GmbH
|
|
|
|
|
|
|
|
SPDX-License-Identifier: AGPL-3.0-only
|
|
|
|
*/
|
|
|
|
|
2022-03-22 11:03:15 -04:00
|
|
|
package client
|
|
|
|
|
|
|
|
import (
|
|
|
|
"bytes"
|
2022-07-18 06:28:02 -04:00
|
|
|
"context"
|
2022-03-22 11:03:15 -04:00
|
|
|
"fmt"
|
|
|
|
|
2022-09-21 07:47:57 -04:00
|
|
|
kubernetesshared "github.com/edgelesssys/constellation/v2/internal/kubernetes"
|
2022-07-18 06:28:02 -04:00
|
|
|
corev1 "k8s.io/api/core/v1"
|
2022-08-04 10:15:52 -04:00
|
|
|
apiextensionsv1 "k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1"
|
|
|
|
apiextensionsclientv1 "k8s.io/apiextensions-apiserver/pkg/client/clientset/clientset/typed/apiextensions/v1"
|
2022-03-22 11:03:15 -04:00
|
|
|
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
|
|
|
"k8s.io/apimachinery/pkg/apis/meta/v1/unstructured"
|
|
|
|
"k8s.io/apimachinery/pkg/runtime"
|
|
|
|
"k8s.io/apimachinery/pkg/types"
|
2022-08-04 10:15:52 -04:00
|
|
|
"k8s.io/apimachinery/pkg/watch"
|
2022-03-22 11:03:15 -04:00
|
|
|
"k8s.io/cli-runtime/pkg/resource"
|
|
|
|
"k8s.io/client-go/kubernetes"
|
|
|
|
"k8s.io/client-go/tools/clientcmd"
|
2022-07-14 15:15:31 -04:00
|
|
|
"k8s.io/client-go/util/retry"
|
2022-03-22 11:03:15 -04:00
|
|
|
)
|
|
|
|
|
2022-06-29 09:26:29 -04:00
|
|
|
const fieldManager = "constellation-bootstrapper"
|
2022-03-22 11:03:15 -04:00
|
|
|
|
2022-04-26 05:22:21 -04:00
|
|
|
// Client implements k8sapi.Client interface and talks to the Kubernetes API.
|
2022-03-22 11:03:15 -04:00
|
|
|
type Client struct {
|
2022-08-04 10:15:52 -04:00
|
|
|
clientset kubernetes.Interface
|
|
|
|
apiextensionClient apiextensionsclientv1.ApiextensionsV1Interface
|
|
|
|
builder *resource.Builder
|
2022-03-22 11:03:15 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
// New creates a new Client, talking to the real k8s API.
|
|
|
|
func New(config []byte) (*Client, error) {
|
|
|
|
clientConfig, err := clientcmd.RESTConfigFromKubeConfig(config)
|
|
|
|
if err != nil {
|
2022-06-09 10:04:30 -04:00
|
|
|
return nil, fmt.Errorf("creating k8s client config from kubeconfig: %w", err)
|
2022-03-22 11:03:15 -04:00
|
|
|
}
|
|
|
|
clientset, err := kubernetes.NewForConfig(clientConfig)
|
|
|
|
if err != nil {
|
2022-06-09 10:04:30 -04:00
|
|
|
return nil, fmt.Errorf("creating k8s client from kubeconfig: %w", err)
|
2022-03-22 11:03:15 -04:00
|
|
|
}
|
|
|
|
|
2022-08-04 10:15:52 -04:00
|
|
|
apiextensionClient, err := apiextensionsclientv1.NewForConfig(clientConfig)
|
|
|
|
if err != nil {
|
|
|
|
return nil, fmt.Errorf("creating api extension client from kubeconfig: %w", err)
|
|
|
|
}
|
|
|
|
|
2022-03-22 11:03:15 -04:00
|
|
|
restClientGetter, err := newRESTClientGetter(config)
|
|
|
|
if err != nil {
|
2022-06-09 10:04:30 -04:00
|
|
|
return nil, fmt.Errorf("creating k8s RESTClientGetter from kubeconfig: %w", err)
|
2022-03-22 11:03:15 -04:00
|
|
|
}
|
|
|
|
builder := resource.NewBuilder(restClientGetter).Unstructured()
|
|
|
|
|
2022-08-04 10:15:52 -04:00
|
|
|
return &Client{clientset: clientset, apiextensionClient: apiextensionClient, builder: builder}, nil
|
2022-03-22 11:03:15 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
// ApplyOneObject uses server-side apply to send unstructured JSON blobs to the server and let it handle the core logic.
|
|
|
|
func (c *Client) ApplyOneObject(info *resource.Info, forceConflicts bool) error {
|
|
|
|
// helper can be used to patch k8s resources using server-side-apply.
|
|
|
|
helper := resource.NewHelper(info.Client, info.Mapping).
|
|
|
|
WithFieldManager(fieldManager)
|
|
|
|
|
|
|
|
// server-side-apply uses unstructured JSON instead of strict typing on the client side.
|
|
|
|
data, err := runtime.Encode(unstructured.UnstructuredJSONScheme, info.Object)
|
|
|
|
if err != nil {
|
2022-06-09 10:04:30 -04:00
|
|
|
return fmt.Errorf("preparing resource for server-side apply: encoding of resource: %w", err)
|
2022-03-22 11:03:15 -04:00
|
|
|
}
|
|
|
|
options := metav1.PatchOptions{
|
|
|
|
Force: &forceConflicts,
|
|
|
|
}
|
|
|
|
obj, err := helper.Patch(
|
|
|
|
info.Namespace,
|
|
|
|
info.Name,
|
|
|
|
types.ApplyPatchType,
|
|
|
|
data,
|
|
|
|
&options,
|
|
|
|
)
|
|
|
|
if err != nil {
|
2022-06-09 10:04:30 -04:00
|
|
|
return fmt.Errorf("applying object %v using server-side apply: %w", info, err)
|
2022-03-22 11:03:15 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
return info.Refresh(obj, true)
|
|
|
|
}
|
|
|
|
|
|
|
|
// GetObjects tries to marshal the resources into []*resource.Info using a resource.Builder.
|
2022-08-29 08:30:20 -04:00
|
|
|
func (c *Client) GetObjects(resources kubernetesshared.Marshaler) ([]*resource.Info, error) {
|
2022-03-22 11:03:15 -04:00
|
|
|
// convert our resource struct into YAML
|
|
|
|
data, err := resources.Marshal()
|
|
|
|
if err != nil {
|
2022-06-09 10:04:30 -04:00
|
|
|
return nil, fmt.Errorf("converting resources to YAML: %w", err)
|
2022-03-22 11:03:15 -04:00
|
|
|
}
|
|
|
|
// read into resource.Info using builder
|
|
|
|
reader := bytes.NewReader(data)
|
|
|
|
result := c.builder.
|
|
|
|
ContinueOnError().
|
|
|
|
NamespaceParam("default").
|
|
|
|
DefaultNamespace().
|
|
|
|
Stream(reader, "yaml").
|
|
|
|
Flatten().
|
|
|
|
Do()
|
|
|
|
return result.Infos()
|
|
|
|
}
|
2022-07-18 06:28:02 -04:00
|
|
|
|
|
|
|
// CreateConfigMap creates the given ConfigMap.
|
|
|
|
func (c *Client) CreateConfigMap(ctx context.Context, configMap corev1.ConfigMap) error {
|
|
|
|
_, err := c.clientset.CoreV1().ConfigMaps(configMap.ObjectMeta.Namespace).Create(ctx, &configMap, metav1.CreateOptions{})
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2022-07-14 15:15:31 -04:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2022-11-04 07:36:26 -04:00
|
|
|
// ListAllNamespaces returns a list of all namespaces.
|
|
|
|
func (c *Client) ListAllNamespaces(ctx context.Context) (*corev1.NamespaceList, error) {
|
|
|
|
return c.clientset.CoreV1().Namespaces().List(ctx, metav1.ListOptions{})
|
|
|
|
}
|
|
|
|
|
2022-11-09 09:57:54 -05:00
|
|
|
// AddTolerationsToDeployment adds [K8s tolerations] to the deployment, identified
|
|
|
|
// by name and namespace.
|
|
|
|
//
|
|
|
|
// [K8s tolerations]: https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/
|
2022-07-28 10:07:29 -04:00
|
|
|
func (c *Client) AddTolerationsToDeployment(ctx context.Context, tolerations []corev1.Toleration, name string, namespace string) error {
|
|
|
|
deployments := c.clientset.AppsV1().Deployments(namespace)
|
2022-07-14 15:15:31 -04:00
|
|
|
|
|
|
|
// retry resource update if an error occurs
|
|
|
|
err := retry.RetryOnConflict(retry.DefaultRetry, func() error {
|
|
|
|
result, err := deployments.Get(ctx, name, metav1.GetOptions{})
|
|
|
|
if err != nil {
|
2022-07-28 10:07:29 -04:00
|
|
|
return fmt.Errorf("failed to get Deployment to add toleration: %v", err)
|
2022-07-14 15:15:31 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
result.Spec.Template.Spec.Tolerations = append(result.Spec.Template.Spec.Tolerations, tolerations...)
|
|
|
|
if _, err = deployments.Update(ctx, result, metav1.UpdateOptions{}); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
})
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2022-07-26 04:10:34 -04:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2022-11-09 09:57:54 -05:00
|
|
|
// AddNodeSelectorsToDeployment adds [K8s selectors] to the deployment, identified
|
|
|
|
// by name and namespace.
|
|
|
|
//
|
|
|
|
// [K8s selectors]: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
|
2022-07-28 10:07:29 -04:00
|
|
|
func (c *Client) AddNodeSelectorsToDeployment(ctx context.Context, selectors map[string]string, name string, namespace string) error {
|
|
|
|
deployments := c.clientset.AppsV1().Deployments(namespace)
|
2022-07-26 04:10:34 -04:00
|
|
|
|
|
|
|
// retry resource update if an error occurs
|
|
|
|
err := retry.RetryOnConflict(retry.DefaultRetry, func() error {
|
|
|
|
result, err := deployments.Get(ctx, name, metav1.GetOptions{})
|
|
|
|
if err != nil {
|
2022-07-28 10:07:29 -04:00
|
|
|
return fmt.Errorf("failed to get Deployment to add node selector: %v", err)
|
2022-07-26 04:10:34 -04:00
|
|
|
}
|
2022-07-18 06:28:02 -04:00
|
|
|
|
2022-07-26 04:10:34 -04:00
|
|
|
for k, v := range selectors {
|
|
|
|
result.Spec.Template.Spec.NodeSelector[k] = v
|
|
|
|
}
|
|
|
|
|
|
|
|
if _, err = deployments.Update(ctx, result, metav1.UpdateOptions{}); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
})
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2022-07-18 06:28:02 -04:00
|
|
|
return nil
|
|
|
|
}
|
2022-08-04 10:15:52 -04:00
|
|
|
|
|
|
|
// WaitForCRD waits for the given CRD to be established.
|
|
|
|
func (c *Client) WaitForCRD(ctx context.Context, crd string) error {
|
|
|
|
watcher, err := c.apiextensionClient.CustomResourceDefinitions().Watch(ctx, metav1.ListOptions{
|
|
|
|
FieldSelector: fmt.Sprintf("metadata.name=%s", crd),
|
|
|
|
})
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
defer watcher.Stop()
|
|
|
|
for event := range watcher.ResultChan() {
|
|
|
|
switch event.Type {
|
|
|
|
case watch.Added, watch.Modified:
|
|
|
|
crd := event.Object.(*apiextensionsv1.CustomResourceDefinition)
|
|
|
|
if crdHasCondition(crd.Status.Conditions, apiextensionsv1.Established) {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
case watch.Deleted:
|
|
|
|
return fmt.Errorf("crd %q deleted", crd)
|
|
|
|
case watch.Error:
|
|
|
|
return fmt.Errorf("crd %q error: %v", crd, event.Object)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return fmt.Errorf("crd %q not established", crd)
|
|
|
|
}
|
|
|
|
|
|
|
|
func crdHasCondition(conditions []apiextensionsv1.CustomResourceDefinitionCondition, conditionType apiextensionsv1.CustomResourceDefinitionConditionType) bool {
|
|
|
|
for _, condition := range conditions {
|
|
|
|
if condition.Type == conditionType && condition.Status == apiextensionsv1.ConditionTrue {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return false
|
|
|
|
}
|