Skip to content

Commit

Permalink
OCM-10387 | Wif API updates to suppport SRE access
Browse files Browse the repository at this point in the history
Defining wif support

The support group specifies the permissions the user needs to grant the
SRE team in order to perform the SOPs needed to service OSD-GCP
clusters. The granting of these permissions occurs on the client side
after they have created a WifConfig resource.

Added wif access method
  • Loading branch information
renan-campos committed Sep 3, 2024
1 parent f804bb9 commit 23db8ce
Show file tree
Hide file tree
Showing 6 changed files with 46 additions and 0 deletions.
2 changes: 2 additions & 0 deletions model/clusters_mgmt/v1/wif_config_type.model
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,8 @@ struct WifGcp {
// The list of service accounts and their associated roles that will need to be
// configured on the user's GCP project.
ServiceAccounts []WifServiceAccount
// Defines the access configuration for support.
Support WifSupport
// The workload identity configuration data that will be used to create the
// workload identity pool on the user's account.
WorkloadIdentityPool WifPool
Expand Down
1 change: 1 addition & 0 deletions model/clusters_mgmt/v1/wif_service_account_type.model
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ struct WifServiceAccount {

enum WifAccessMethod {
Impersonate
Vm
Wif
}

Expand Down
20 changes: 20 additions & 0 deletions model/clusters_mgmt/v1/wif_support_type.model
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
/*
Copyright (c) 2024 Red Hat, Inc.

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

struct WifSupport {
Principal String
Roles []WifRole
}
2 changes: 2 additions & 0 deletions model/clusters_mgmt/v2alpha1/wif_config_type.model
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,8 @@ struct WifGcp {
// The list of service accounts and their associated roles that will need to be
// configured on the user's GCP project.
ServiceAccounts []WifServiceAccount
// Defines the access configuration for support.
Support WifSupport
// The workload identity configuration data that will be used to create the
// workload identity pool on the user's account.
WorkloadIdentityPool WifPool
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ struct WifServiceAccount {

enum WifAccessMethod {
Impersonate
Vm
Wif
}

Expand Down
20 changes: 20 additions & 0 deletions model/clusters_mgmt/v2alpha1/wif_support_type.model
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
/*
Copyright (c) 2024 Red Hat, Inc.

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

struct WifSupport {
Principal String
Roles []WifRole
}

0 comments on commit 23db8ce

Please sign in to comment.