* feat: Enhance PipeSpec and FromSpec with AuthorizedKeysSecret - Added AuthorizedKeysSecret field to FromSpec for referencing Kubernetes secrets. - Updated deepcopy functions to handle new AuthorizedKeysSecret field. - Modified CRD definition to include the new private_key_secret field. - Refactored fake client and lister implementations to support new fields. - Introduced shared informers and listers for Pipe resources. - Updated code generation scripts to reflect changes in API structure. * refactor: Rename private_key_secret to authorized_keys_secret in CRD schema * feat: Add support for authorized_keys from secret in skel and update k8sworkload.yaml * feat: Enhance authorized keys handling to include secret name check * Update plugin/kubernetes/skel.go Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
110 lines
4.3 KiB
YAML
110 lines
4.3 KiB
YAML
apiVersion: apiextensions.k8s.io/v1
|
|
kind: CustomResourceDefinition
|
|
metadata:
|
|
name: pipes.sshpiper.com
|
|
spec:
|
|
group: sshpiper.com
|
|
names:
|
|
kind: Pipe
|
|
listKind: PipeList
|
|
plural: pipes
|
|
singular: pipe
|
|
scope: Namespaced
|
|
versions:
|
|
- name: v1beta1
|
|
schema:
|
|
openAPIV3Schema:
|
|
properties:
|
|
apiVersion:
|
|
description: 'APIVersion defines the versioned schema of this representation
|
|
of an object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
|
type: string
|
|
kind:
|
|
description: 'Kind is a string value representing the REST resource this
|
|
object represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
|
type: string
|
|
metadata:
|
|
type: object
|
|
spec:
|
|
properties:
|
|
from:
|
|
items:
|
|
properties:
|
|
authorized_keys_data:
|
|
type: string
|
|
authorized_keys_file:
|
|
type: string
|
|
authorized_keys_secret:
|
|
description: LocalObjectReference contains enough information
|
|
to let you locate the referenced object inside the same namespace.
|
|
properties:
|
|
name:
|
|
description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
|
|
TODO: Add other useful fields. apiVersion, kind, uid?'
|
|
type: string
|
|
type: object
|
|
username:
|
|
type: string
|
|
htpasswd_data:
|
|
type: string
|
|
htpasswd_file:
|
|
type: string
|
|
username_regex_match:
|
|
type: boolean
|
|
required:
|
|
- username
|
|
type: object
|
|
type: array
|
|
to:
|
|
properties:
|
|
host:
|
|
type: string
|
|
ignore_hostkey:
|
|
type: boolean
|
|
known_hosts_data:
|
|
type: string
|
|
private_key_secret:
|
|
description: LocalObjectReference contains enough information
|
|
to let you locate the referenced object inside the same namespace.
|
|
properties:
|
|
name:
|
|
description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
|
|
TODO: Add other useful fields. apiVersion, kind, uid?'
|
|
type: string
|
|
type: object
|
|
password_secret:
|
|
description: LocalObjectReference contains enough information
|
|
to let you locate the referenced object inside the same namespace.
|
|
properties:
|
|
name:
|
|
description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
|
|
TODO: Add other useful fields. apiVersion, kind, uid?'
|
|
type: string
|
|
type: object
|
|
username:
|
|
type: string
|
|
required:
|
|
- host
|
|
type: object
|
|
required:
|
|
- from
|
|
- to
|
|
type: object
|
|
required:
|
|
- spec
|
|
type: object
|
|
additionalPrinterColumns:
|
|
- jsonPath: .spec.from[0].username
|
|
name: FromUser
|
|
type: string
|
|
- jsonPath: .spec.to.username
|
|
name: ToUser
|
|
type: string
|
|
- jsonPath: .spec.to.host
|
|
name: ToHost
|
|
type: string
|
|
|
|
served: true
|
|
storage: true
|