|
| 1 | +package controllers |
| 2 | + |
| 3 | +import ( |
| 4 | + "context" |
| 5 | + "errors" |
| 6 | + "fmt" |
| 7 | + topology "github.com/rabbitmq/messaging-topology-operator/api/v1beta1" |
| 8 | + "github.com/rabbitmq/messaging-topology-operator/internal" |
| 9 | + "github.com/rabbitmq/messaging-topology-operator/rabbitmqclient" |
| 10 | + "k8s.io/apimachinery/pkg/runtime" |
| 11 | + ctrl "sigs.k8s.io/controller-runtime" |
| 12 | + "sigs.k8s.io/controller-runtime/pkg/client" |
| 13 | + "sigs.k8s.io/controller-runtime/pkg/controller/controllerutil" |
| 14 | +) |
| 15 | + |
| 16 | +//+kubebuilder:rbac:groups=rabbitmq.com,resources=topicpermissions,verbs=get;list;watch;create;update;patch;delete |
| 17 | +//+kubebuilder:rbac:groups=rabbitmq.com,resources=topicpermissions/status,verbs=get;update;patch |
| 18 | +//+kubebuilder:rbac:groups=rabbitmq.com,resources=topicpermissions/finalizers,verbs=update |
| 19 | + |
| 20 | +type TopicPermissionReconciler struct { |
| 21 | + client.Client |
| 22 | + Scheme *runtime.Scheme |
| 23 | +} |
| 24 | + |
| 25 | +func (r *TopicPermissionReconciler) DeclareFunc(ctx context.Context, client rabbitmqclient.Client, obj topology.TopologyResource) error { |
| 26 | + permission := obj.(*topology.TopicPermission) |
| 27 | + user := &topology.User{} |
| 28 | + username := permission.Spec.User |
| 29 | + if permission.Spec.UserReference != nil { |
| 30 | + var err error |
| 31 | + if user, err = getUsernameFromUser(ctx, r.Client, permission.Namespace, permission.Spec.UserReference.Name); err != nil { |
| 32 | + return err |
| 33 | + } else if user != nil { |
| 34 | + // User exist |
| 35 | + username = user.Status.Username |
| 36 | + } |
| 37 | + } |
| 38 | + if username == "" { |
| 39 | + return fmt.Errorf("failed create Permission, missing User") |
| 40 | + } |
| 41 | + |
| 42 | + // user != nil, not working because user has always a name set |
| 43 | + if user.Name != "" { |
| 44 | + if err := controllerutil.SetControllerReference(user, permission, r.Scheme); err != nil { |
| 45 | + return fmt.Errorf("failed set controller reference: %v", err) |
| 46 | + } |
| 47 | + if err := r.Client.Update(ctx, permission); err != nil { |
| 48 | + return fmt.Errorf("failed to Update object with controller reference: %w", err) |
| 49 | + } |
| 50 | + } |
| 51 | + return validateResponse(client.UpdateTopicPermissionsIn(permission.Spec.Vhost, username, internal.GenerateTopicPermissions(permission))) |
| 52 | +} |
| 53 | + |
| 54 | +func (r *TopicPermissionReconciler) DeleteFunc(ctx context.Context, client rabbitmqclient.Client, obj topology.TopologyResource) error { |
| 55 | + logger := ctrl.LoggerFrom(ctx) |
| 56 | + permission := obj.(*topology.TopicPermission) |
| 57 | + |
| 58 | + username := permission.Spec.User |
| 59 | + if permission.Spec.UserReference != nil { |
| 60 | + if user, err := getUsernameFromUser(ctx, r.Client, permission.Namespace, permission.Spec.UserReference.Name); err != nil { |
| 61 | + return err |
| 62 | + } else if user != nil { |
| 63 | + // User exist |
| 64 | + username = user.Status.Username |
| 65 | + } |
| 66 | + } |
| 67 | + |
| 68 | + if username == "" { |
| 69 | + logger.Info("user already removed; no need to delete topic permission") |
| 70 | + } else if err := r.clearTopicPermission(ctx, client, permission, username); err != nil { |
| 71 | + return err |
| 72 | + } |
| 73 | + return removeFinalizer(ctx, r.Client, permission) |
| 74 | +} |
| 75 | + |
| 76 | +func (r *TopicPermissionReconciler) clearTopicPermission(ctx context.Context, client rabbitmqclient.Client, permission *topology.TopicPermission, user string) error { |
| 77 | + logger := ctrl.LoggerFrom(ctx) |
| 78 | + err := validateResponseForDeletion(client.DeleteTopicPermissionsIn(permission.Spec.Vhost, user, permission.Spec.Permissions.Exchange)) |
| 79 | + if errors.Is(err, NotFound) { |
| 80 | + logger.Info("cannot find user or vhost in rabbitmq server; no need to delete permission", "user", user, "vhost", permission.Spec.Vhost) |
| 81 | + return nil |
| 82 | + } |
| 83 | + return err |
| 84 | +} |
0 commit comments