From 69efc6e557fdab3d66a8fcbe53dcaadf0acb4902 Mon Sep 17 00:00:00 2001 From: ezgidemirel Date: Thu, 28 Apr 2022 12:03:11 +0300 Subject: [PATCH] Add IAM OpenID Connect Provider Signed-off-by: ezgidemirel --- apis/iam/v1alpha2/zz_generated.deepcopy.go | 190 ++++++++++++++ apis/iam/v1alpha2/zz_generated.managed.go | 66 +++++ apis/iam/v1alpha2/zz_generated.managedlist.go | 9 + apis/iam/v1alpha2/zz_generated_terraformed.go | 74 ++++++ .../zz_openidconnectprovider_types.go | 98 +++++++ config/iam/config.go | 5 + config/provider.go | 1 + examples/iam/openidconnectprovider.yaml | 12 + .../openidconnectprovider/zz_controller.go | 63 +++++ internal/controller/zz_setup.go | 2 + ....crossplane.io_openidconnectproviders.yaml | 243 ++++++++++++++++++ 11 files changed, 763 insertions(+) create mode 100755 apis/iam/v1alpha2/zz_openidconnectprovider_types.go create mode 100644 examples/iam/openidconnectprovider.yaml create mode 100755 internal/controller/iam/openidconnectprovider/zz_controller.go create mode 100644 package/crds/iam.aws.jet.crossplane.io_openidconnectproviders.yaml diff --git a/apis/iam/v1alpha2/zz_generated.deepcopy.go b/apis/iam/v1alpha2/zz_generated.deepcopy.go index 85dcfbc82..e8a07c40d 100644 --- a/apis/iam/v1alpha2/zz_generated.deepcopy.go +++ b/apis/iam/v1alpha2/zz_generated.deepcopy.go @@ -733,6 +733,196 @@ func (in *InstanceProfileStatus) DeepCopy() *InstanceProfileStatus { return out } +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *OpenIDConnectProvider) DeepCopyInto(out *OpenIDConnectProvider) { + *out = *in + out.TypeMeta = in.TypeMeta + in.ObjectMeta.DeepCopyInto(&out.ObjectMeta) + in.Spec.DeepCopyInto(&out.Spec) + in.Status.DeepCopyInto(&out.Status) +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new OpenIDConnectProvider. +func (in *OpenIDConnectProvider) DeepCopy() *OpenIDConnectProvider { + if in == nil { + return nil + } + out := new(OpenIDConnectProvider) + in.DeepCopyInto(out) + return out +} + +// DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object. +func (in *OpenIDConnectProvider) DeepCopyObject() runtime.Object { + if c := in.DeepCopy(); c != nil { + return c + } + return nil +} + +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *OpenIDConnectProviderList) DeepCopyInto(out *OpenIDConnectProviderList) { + *out = *in + out.TypeMeta = in.TypeMeta + in.ListMeta.DeepCopyInto(&out.ListMeta) + if in.Items != nil { + in, out := &in.Items, &out.Items + *out = make([]OpenIDConnectProvider, len(*in)) + for i := range *in { + (*in)[i].DeepCopyInto(&(*out)[i]) + } + } +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new OpenIDConnectProviderList. +func (in *OpenIDConnectProviderList) DeepCopy() *OpenIDConnectProviderList { + if in == nil { + return nil + } + out := new(OpenIDConnectProviderList) + in.DeepCopyInto(out) + return out +} + +// DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object. +func (in *OpenIDConnectProviderList) DeepCopyObject() runtime.Object { + if c := in.DeepCopy(); c != nil { + return c + } + return nil +} + +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *OpenIDConnectProviderObservation) DeepCopyInto(out *OpenIDConnectProviderObservation) { + *out = *in + if in.Arn != nil { + in, out := &in.Arn, &out.Arn + *out = new(string) + **out = **in + } + if in.ID != nil { + in, out := &in.ID, &out.ID + *out = new(string) + **out = **in + } + if in.TagsAll != nil { + in, out := &in.TagsAll, &out.TagsAll + *out = make(map[string]*string, len(*in)) + for key, val := range *in { + var outVal *string + if val == nil { + (*out)[key] = nil + } else { + in, out := &val, &outVal + *out = new(string) + **out = **in + } + (*out)[key] = outVal + } + } +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new OpenIDConnectProviderObservation. +func (in *OpenIDConnectProviderObservation) DeepCopy() *OpenIDConnectProviderObservation { + if in == nil { + return nil + } + out := new(OpenIDConnectProviderObservation) + in.DeepCopyInto(out) + return out +} + +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *OpenIDConnectProviderParameters) DeepCopyInto(out *OpenIDConnectProviderParameters) { + *out = *in + if in.ClientIDList != nil { + in, out := &in.ClientIDList, &out.ClientIDList + *out = make([]*string, len(*in)) + for i := range *in { + if (*in)[i] != nil { + in, out := &(*in)[i], &(*out)[i] + *out = new(string) + **out = **in + } + } + } + if in.Tags != nil { + in, out := &in.Tags, &out.Tags + *out = make(map[string]*string, len(*in)) + for key, val := range *in { + var outVal *string + if val == nil { + (*out)[key] = nil + } else { + in, out := &val, &outVal + *out = new(string) + **out = **in + } + (*out)[key] = outVal + } + } + if in.ThumbprintList != nil { + in, out := &in.ThumbprintList, &out.ThumbprintList + *out = make([]*string, len(*in)) + for i := range *in { + if (*in)[i] != nil { + in, out := &(*in)[i], &(*out)[i] + *out = new(string) + **out = **in + } + } + } + if in.URL != nil { + in, out := &in.URL, &out.URL + *out = new(string) + **out = **in + } +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new OpenIDConnectProviderParameters. +func (in *OpenIDConnectProviderParameters) DeepCopy() *OpenIDConnectProviderParameters { + if in == nil { + return nil + } + out := new(OpenIDConnectProviderParameters) + in.DeepCopyInto(out) + return out +} + +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *OpenIDConnectProviderSpec) DeepCopyInto(out *OpenIDConnectProviderSpec) { + *out = *in + in.ResourceSpec.DeepCopyInto(&out.ResourceSpec) + in.ForProvider.DeepCopyInto(&out.ForProvider) +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new OpenIDConnectProviderSpec. +func (in *OpenIDConnectProviderSpec) DeepCopy() *OpenIDConnectProviderSpec { + if in == nil { + return nil + } + out := new(OpenIDConnectProviderSpec) + in.DeepCopyInto(out) + return out +} + +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *OpenIDConnectProviderStatus) DeepCopyInto(out *OpenIDConnectProviderStatus) { + *out = *in + in.ResourceStatus.DeepCopyInto(&out.ResourceStatus) + in.AtProvider.DeepCopyInto(&out.AtProvider) +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new OpenIDConnectProviderStatus. +func (in *OpenIDConnectProviderStatus) DeepCopy() *OpenIDConnectProviderStatus { + if in == nil { + return nil + } + out := new(OpenIDConnectProviderStatus) + in.DeepCopyInto(out) + return out +} + // DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. func (in *Policy) DeepCopyInto(out *Policy) { *out = *in diff --git a/apis/iam/v1alpha2/zz_generated.managed.go b/apis/iam/v1alpha2/zz_generated.managed.go index 17e95ea4c..d4a3dc51e 100644 --- a/apis/iam/v1alpha2/zz_generated.managed.go +++ b/apis/iam/v1alpha2/zz_generated.managed.go @@ -283,6 +283,72 @@ func (mg *InstanceProfile) SetWriteConnectionSecretToReference(r *xpv1.SecretRef mg.Spec.WriteConnectionSecretToReference = r } +// GetCondition of this OpenIDConnectProvider. +func (mg *OpenIDConnectProvider) GetCondition(ct xpv1.ConditionType) xpv1.Condition { + return mg.Status.GetCondition(ct) +} + +// GetDeletionPolicy of this OpenIDConnectProvider. +func (mg *OpenIDConnectProvider) GetDeletionPolicy() xpv1.DeletionPolicy { + return mg.Spec.DeletionPolicy +} + +// GetProviderConfigReference of this OpenIDConnectProvider. +func (mg *OpenIDConnectProvider) GetProviderConfigReference() *xpv1.Reference { + return mg.Spec.ProviderConfigReference +} + +/* +GetProviderReference of this OpenIDConnectProvider. +Deprecated: Use GetProviderConfigReference. +*/ +func (mg *OpenIDConnectProvider) GetProviderReference() *xpv1.Reference { + return mg.Spec.ProviderReference +} + +// GetPublishConnectionDetailsTo of this OpenIDConnectProvider. +func (mg *OpenIDConnectProvider) GetPublishConnectionDetailsTo() *xpv1.PublishConnectionDetailsTo { + return mg.Spec.PublishConnectionDetailsTo +} + +// GetWriteConnectionSecretToReference of this OpenIDConnectProvider. +func (mg *OpenIDConnectProvider) GetWriteConnectionSecretToReference() *xpv1.SecretReference { + return mg.Spec.WriteConnectionSecretToReference +} + +// SetConditions of this OpenIDConnectProvider. +func (mg *OpenIDConnectProvider) SetConditions(c ...xpv1.Condition) { + mg.Status.SetConditions(c...) +} + +// SetDeletionPolicy of this OpenIDConnectProvider. +func (mg *OpenIDConnectProvider) SetDeletionPolicy(r xpv1.DeletionPolicy) { + mg.Spec.DeletionPolicy = r +} + +// SetProviderConfigReference of this OpenIDConnectProvider. +func (mg *OpenIDConnectProvider) SetProviderConfigReference(r *xpv1.Reference) { + mg.Spec.ProviderConfigReference = r +} + +/* +SetProviderReference of this OpenIDConnectProvider. +Deprecated: Use SetProviderConfigReference. +*/ +func (mg *OpenIDConnectProvider) SetProviderReference(r *xpv1.Reference) { + mg.Spec.ProviderReference = r +} + +// SetPublishConnectionDetailsTo of this OpenIDConnectProvider. +func (mg *OpenIDConnectProvider) SetPublishConnectionDetailsTo(r *xpv1.PublishConnectionDetailsTo) { + mg.Spec.PublishConnectionDetailsTo = r +} + +// SetWriteConnectionSecretToReference of this OpenIDConnectProvider. +func (mg *OpenIDConnectProvider) SetWriteConnectionSecretToReference(r *xpv1.SecretReference) { + mg.Spec.WriteConnectionSecretToReference = r +} + // GetCondition of this Policy. func (mg *Policy) GetCondition(ct xpv1.ConditionType) xpv1.Condition { return mg.Status.GetCondition(ct) diff --git a/apis/iam/v1alpha2/zz_generated.managedlist.go b/apis/iam/v1alpha2/zz_generated.managedlist.go index b127a7fe3..dd33af483 100644 --- a/apis/iam/v1alpha2/zz_generated.managedlist.go +++ b/apis/iam/v1alpha2/zz_generated.managedlist.go @@ -55,6 +55,15 @@ func (l *InstanceProfileList) GetItems() []resource.Managed { return items } +// GetItems of this OpenIDConnectProviderList. +func (l *OpenIDConnectProviderList) GetItems() []resource.Managed { + items := make([]resource.Managed, len(l.Items)) + for i := range l.Items { + items[i] = &l.Items[i] + } + return items +} + // GetItems of this PolicyList. func (l *PolicyList) GetItems() []resource.Managed { items := make([]resource.Managed, len(l.Items)) diff --git a/apis/iam/v1alpha2/zz_generated_terraformed.go b/apis/iam/v1alpha2/zz_generated_terraformed.go index 231e27a8b..b4b2bfda4 100755 --- a/apis/iam/v1alpha2/zz_generated_terraformed.go +++ b/apis/iam/v1alpha2/zz_generated_terraformed.go @@ -321,6 +321,80 @@ func (tr *InstanceProfile) GetTerraformSchemaVersion() int { return 0 } +// GetTerraformResourceType returns Terraform resource type for this OpenIDConnectProvider +func (mg *OpenIDConnectProvider) GetTerraformResourceType() string { + return "aws_iam_openid_connect_provider" +} + +// GetConnectionDetailsMapping for this OpenIDConnectProvider +func (tr *OpenIDConnectProvider) GetConnectionDetailsMapping() map[string]string { + return nil +} + +// GetObservation of this OpenIDConnectProvider +func (tr *OpenIDConnectProvider) GetObservation() (map[string]interface{}, error) { + o, err := json.TFParser.Marshal(tr.Status.AtProvider) + if err != nil { + return nil, err + } + base := map[string]interface{}{} + return base, json.TFParser.Unmarshal(o, &base) +} + +// SetObservation for this OpenIDConnectProvider +func (tr *OpenIDConnectProvider) SetObservation(obs map[string]interface{}) error { + p, err := json.TFParser.Marshal(obs) + if err != nil { + return err + } + return json.TFParser.Unmarshal(p, &tr.Status.AtProvider) +} + +// GetID returns ID of underlying Terraform resource of this OpenIDConnectProvider +func (tr *OpenIDConnectProvider) GetID() string { + if tr.Status.AtProvider.ID == nil { + return "" + } + return *tr.Status.AtProvider.ID +} + +// GetParameters of this OpenIDConnectProvider +func (tr *OpenIDConnectProvider) GetParameters() (map[string]interface{}, error) { + p, err := json.TFParser.Marshal(tr.Spec.ForProvider) + if err != nil { + return nil, err + } + base := map[string]interface{}{} + return base, json.TFParser.Unmarshal(p, &base) +} + +// SetParameters for this OpenIDConnectProvider +func (tr *OpenIDConnectProvider) SetParameters(params map[string]interface{}) error { + p, err := json.TFParser.Marshal(params) + if err != nil { + return err + } + return json.TFParser.Unmarshal(p, &tr.Spec.ForProvider) +} + +// LateInitialize this OpenIDConnectProvider using its observed tfState. +// returns True if there are any spec changes for the resource. +func (tr *OpenIDConnectProvider) LateInitialize(attrs []byte) (bool, error) { + params := &OpenIDConnectProviderParameters{} + if err := json.TFParser.Unmarshal(attrs, params); err != nil { + return false, errors.Wrap(err, "failed to unmarshal Terraform state parameters for late-initialization") + } + opts := []resource.GenericLateInitializerOption{resource.WithZeroValueJSONOmitEmptyFilter(resource.CNameWildcard)} + + li := resource.NewGenericLateInitializer(opts...) + return li.LateInitialize(&tr.Spec.ForProvider, params) +} + +// GetTerraformSchemaVersion returns the associated Terraform schema version +func (tr *OpenIDConnectProvider) GetTerraformSchemaVersion() int { + return 0 +} + // GetTerraformResourceType returns Terraform resource type for this Policy func (mg *Policy) GetTerraformResourceType() string { return "aws_iam_policy" diff --git a/apis/iam/v1alpha2/zz_openidconnectprovider_types.go b/apis/iam/v1alpha2/zz_openidconnectprovider_types.go new file mode 100755 index 000000000..a9a1910b7 --- /dev/null +++ b/apis/iam/v1alpha2/zz_openidconnectprovider_types.go @@ -0,0 +1,98 @@ +/* +Copyright 2021 The Crossplane Authors. + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. +*/ + +// Code generated by terrajet. DO NOT EDIT. + +package v1alpha2 + +import ( + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" + "k8s.io/apimachinery/pkg/runtime/schema" + + v1 "github.com/crossplane/crossplane-runtime/apis/common/v1" +) + +type OpenIDConnectProviderObservation struct { + Arn *string `json:"arn,omitempty" tf:"arn,omitempty"` + + ID *string `json:"id,omitempty" tf:"id,omitempty"` + + TagsAll map[string]*string `json:"tagsAll,omitempty" tf:"tags_all,omitempty"` +} + +type OpenIDConnectProviderParameters struct { + + // +kubebuilder:validation:Required + ClientIDList []*string `json:"clientIdList" tf:"client_id_list,omitempty"` + + // +kubebuilder:validation:Optional + Tags map[string]*string `json:"tags,omitempty" tf:"tags,omitempty"` + + // +kubebuilder:validation:Required + ThumbprintList []*string `json:"thumbprintList" tf:"thumbprint_list,omitempty"` + + // +kubebuilder:validation:Required + URL *string `json:"url" tf:"url,omitempty"` +} + +// OpenIDConnectProviderSpec defines the desired state of OpenIDConnectProvider +type OpenIDConnectProviderSpec struct { + v1.ResourceSpec `json:",inline"` + ForProvider OpenIDConnectProviderParameters `json:"forProvider"` +} + +// OpenIDConnectProviderStatus defines the observed state of OpenIDConnectProvider. +type OpenIDConnectProviderStatus struct { + v1.ResourceStatus `json:",inline"` + AtProvider OpenIDConnectProviderObservation `json:"atProvider,omitempty"` +} + +// +kubebuilder:object:root=true + +// OpenIDConnectProvider is the Schema for the OpenIDConnectProviders API +// +kubebuilder:printcolumn:name="READY",type="string",JSONPath=".status.conditions[?(@.type=='Ready')].status" +// +kubebuilder:printcolumn:name="SYNCED",type="string",JSONPath=".status.conditions[?(@.type=='Synced')].status" +// +kubebuilder:printcolumn:name="EXTERNAL-NAME",type="string",JSONPath=".metadata.annotations.crossplane\\.io/external-name" +// +kubebuilder:printcolumn:name="AGE",type="date",JSONPath=".metadata.creationTimestamp" +// +kubebuilder:subresource:status +// +kubebuilder:resource:scope=Cluster,categories={crossplane,managed,awsjet} +type OpenIDConnectProvider struct { + metav1.TypeMeta `json:",inline"` + metav1.ObjectMeta `json:"metadata,omitempty"` + Spec OpenIDConnectProviderSpec `json:"spec"` + Status OpenIDConnectProviderStatus `json:"status,omitempty"` +} + +// +kubebuilder:object:root=true + +// OpenIDConnectProviderList contains a list of OpenIDConnectProviders +type OpenIDConnectProviderList struct { + metav1.TypeMeta `json:",inline"` + metav1.ListMeta `json:"metadata,omitempty"` + Items []OpenIDConnectProvider `json:"items"` +} + +// Repository type metadata. +var ( + OpenIDConnectProvider_Kind = "OpenIDConnectProvider" + OpenIDConnectProvider_GroupKind = schema.GroupKind{Group: CRDGroup, Kind: OpenIDConnectProvider_Kind}.String() + OpenIDConnectProvider_KindAPIVersion = OpenIDConnectProvider_Kind + "." + CRDGroupVersion.String() + OpenIDConnectProvider_GroupVersionKind = CRDGroupVersion.WithKind(OpenIDConnectProvider_Kind) +) + +func init() { + SchemeBuilder.Register(&OpenIDConnectProvider{}, &OpenIDConnectProviderList{}) +} diff --git a/config/iam/config.go b/config/iam/config.go index 151ca47f1..74c220aa5 100644 --- a/config/iam/config.go +++ b/config/iam/config.go @@ -122,4 +122,9 @@ func Configure(p *config.Provider) { } }) + p.AddResourceConfigurator("aws_iam_openid_connect_provider", func(r *config.Resource) { + r.Version = common.VersionV1Alpha2 + r.ExternalName = config.IdentifierFromProvider + }) + } diff --git a/config/provider.go b/config/provider.go index 5eec73f91..a599ee446 100644 --- a/config/provider.go +++ b/config/provider.go @@ -120,6 +120,7 @@ var IncludedResources = []string{ "aws_iam_user_group_membership$", "aws_iam_user_policy$", "aws_iam_user_policy_attachment$", + "aws_iam_openid_connect_provider$", // EKS "aws_eks_addon$", diff --git a/examples/iam/openidconnectprovider.yaml b/examples/iam/openidconnectprovider.yaml new file mode 100644 index 000000000..a24c6620b --- /dev/null +++ b/examples/iam/openidconnectprovider.yaml @@ -0,0 +1,12 @@ +apiVersion: iam.aws.jet.crossplane.io/v1alpha2 +kind: OpenIDConnectProvider +metadata: + name: example +spec: + forProvider: + clientIdList: + - 266362248691-342342xasdasdasda-apps.googleusercontent.com + thumbprintList: [] + url: https://accounts.google.com + providerConfigRef: + name: example \ No newline at end of file diff --git a/internal/controller/iam/openidconnectprovider/zz_controller.go b/internal/controller/iam/openidconnectprovider/zz_controller.go new file mode 100755 index 000000000..04e5b3a6c --- /dev/null +++ b/internal/controller/iam/openidconnectprovider/zz_controller.go @@ -0,0 +1,63 @@ +/* +Copyright 2021 The Crossplane Authors. + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. +*/ + +// Code generated by terrajet. DO NOT EDIT. + +package openidconnectprovider + +import ( + "time" + + "github.com/crossplane/crossplane-runtime/pkg/connection" + "github.com/crossplane/crossplane-runtime/pkg/event" + "github.com/crossplane/crossplane-runtime/pkg/ratelimiter" + "github.com/crossplane/crossplane-runtime/pkg/reconciler/managed" + xpresource "github.com/crossplane/crossplane-runtime/pkg/resource" + tjcontroller "github.com/crossplane/terrajet/pkg/controller" + "github.com/crossplane/terrajet/pkg/terraform" + ctrl "sigs.k8s.io/controller-runtime" + + v1alpha2 "github.com/crossplane-contrib/provider-jet-aws/apis/iam/v1alpha2" +) + +// Setup adds a controller that reconciles OpenIDConnectProvider managed resources. +func Setup(mgr ctrl.Manager, o tjcontroller.Options) error { + name := managed.ControllerName(v1alpha2.OpenIDConnectProvider_GroupVersionKind.String()) + var initializers managed.InitializerChain + for _, i := range o.Provider.Resources["aws_iam_openid_connect_provider"].InitializerFns { + initializers = append(initializers, i(mgr.GetClient())) + } + cps := []managed.ConnectionPublisher{managed.NewAPISecretPublisher(mgr.GetClient(), mgr.GetScheme())} + if o.SecretStoreConfigGVK != nil { + cps = append(cps, connection.NewDetailsManager(mgr.GetClient(), *o.SecretStoreConfigGVK)) + } + r := managed.NewReconciler(mgr, + xpresource.ManagedKind(v1alpha2.OpenIDConnectProvider_GroupVersionKind), + managed.WithExternalConnecter(tjcontroller.NewConnector(mgr.GetClient(), o.WorkspaceStore, o.SetupFn, o.Provider.Resources["aws_iam_openid_connect_provider"])), + managed.WithLogger(o.Logger.WithValues("controller", name)), + managed.WithRecorder(event.NewAPIRecorder(mgr.GetEventRecorderFor(name))), + managed.WithFinalizer(terraform.NewWorkspaceFinalizer(o.WorkspaceStore, xpresource.NewAPIFinalizer(mgr.GetClient(), managed.FinalizerName))), + managed.WithTimeout(3*time.Minute), + managed.WithInitializers(initializers), + managed.WithConnectionPublishers(cps...), + ) + + return ctrl.NewControllerManagedBy(mgr). + Named(name). + WithOptions(o.ForControllerRuntime()). + For(&v1alpha2.OpenIDConnectProvider{}). + Complete(ratelimiter.NewReconciler(name, r, o.GlobalRateLimiter)) +} diff --git a/internal/controller/zz_setup.go b/internal/controller/zz_setup.go index 25a55e985..62bd9b164 100755 --- a/internal/controller/zz_setup.go +++ b/internal/controller/zz_setup.go @@ -69,6 +69,7 @@ import ( group "github.com/crossplane-contrib/provider-jet-aws/internal/controller/iam/group" grouppolicyattachment "github.com/crossplane-contrib/provider-jet-aws/internal/controller/iam/grouppolicyattachment" instanceprofile "github.com/crossplane-contrib/provider-jet-aws/internal/controller/iam/instanceprofile" + openidconnectprovider "github.com/crossplane-contrib/provider-jet-aws/internal/controller/iam/openidconnectprovider" policy "github.com/crossplane-contrib/provider-jet-aws/internal/controller/iam/policy" role "github.com/crossplane-contrib/provider-jet-aws/internal/controller/iam/role" rolepolicyattachment "github.com/crossplane-contrib/provider-jet-aws/internal/controller/iam/rolepolicyattachment" @@ -163,6 +164,7 @@ func Setup(mgr ctrl.Manager, o controller.Options) error { group.Setup, grouppolicyattachment.Setup, instanceprofile.Setup, + openidconnectprovider.Setup, policy.Setup, role.Setup, rolepolicyattachment.Setup, diff --git a/package/crds/iam.aws.jet.crossplane.io_openidconnectproviders.yaml b/package/crds/iam.aws.jet.crossplane.io_openidconnectproviders.yaml new file mode 100644 index 000000000..7b90a4fb8 --- /dev/null +++ b/package/crds/iam.aws.jet.crossplane.io_openidconnectproviders.yaml @@ -0,0 +1,243 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.8.0 + creationTimestamp: null + name: openidconnectproviders.iam.aws.jet.crossplane.io +spec: + group: iam.aws.jet.crossplane.io + names: + categories: + - crossplane + - managed + - awsjet + kind: OpenIDConnectProvider + listKind: OpenIDConnectProviderList + plural: openidconnectproviders + singular: openidconnectprovider + scope: Cluster + versions: + - additionalPrinterColumns: + - jsonPath: .status.conditions[?(@.type=='Ready')].status + name: READY + type: string + - jsonPath: .status.conditions[?(@.type=='Synced')].status + name: SYNCED + type: string + - jsonPath: .metadata.annotations.crossplane\.io/external-name + name: EXTERNAL-NAME + type: string + - jsonPath: .metadata.creationTimestamp + name: AGE + type: date + name: v1alpha2 + schema: + openAPIV3Schema: + description: OpenIDConnectProvider is the Schema for the OpenIDConnectProviders + API + properties: + apiVersion: + description: 'APIVersion defines the versioned schema of this representation + of an object. Servers should convert recognized schemas to the latest + internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources' + type: string + kind: + description: 'Kind is a string value representing the REST resource this + object represents. Servers may infer this from the endpoint the client + submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds' + type: string + metadata: + type: object + spec: + description: OpenIDConnectProviderSpec defines the desired state of OpenIDConnectProvider + properties: + deletionPolicy: + default: Delete + description: DeletionPolicy specifies what will happen to the underlying + external when this managed resource is deleted - either "Delete" + or "Orphan" the external resource. + enum: + - Orphan + - Delete + type: string + forProvider: + properties: + clientIdList: + items: + type: string + type: array + tags: + additionalProperties: + type: string + type: object + thumbprintList: + items: + type: string + type: array + url: + type: string + required: + - clientIdList + - thumbprintList + - url + type: object + providerConfigRef: + default: + name: default + description: ProviderConfigReference specifies how the provider that + will be used to create, observe, update, and delete this managed + resource should be configured. + properties: + name: + description: Name of the referenced object. + type: string + required: + - name + type: object + providerRef: + description: 'ProviderReference specifies the provider that will be + used to create, observe, update, and delete this managed resource. + Deprecated: Please use ProviderConfigReference, i.e. `providerConfigRef`' + properties: + name: + description: Name of the referenced object. + type: string + required: + - name + type: object + publishConnectionDetailsTo: + description: PublishConnectionDetailsTo specifies the connection secret + config which contains a name, metadata and a reference to secret + store config to which any connection details for this managed resource + should be written. Connection details frequently include the endpoint, + username, and password required to connect to the managed resource. + properties: + configRef: + default: + name: default + description: SecretStoreConfigRef specifies which secret store + config should be used for this ConnectionSecret. + properties: + name: + description: Name of the referenced object. + type: string + required: + - name + type: object + metadata: + description: Metadata is the metadata for connection secret. + properties: + annotations: + additionalProperties: + type: string + description: Annotations are the annotations to be added to + connection secret. - For Kubernetes secrets, this will be + used as "metadata.annotations". - It is up to Secret Store + implementation for others store types. + type: object + labels: + additionalProperties: + type: string + description: Labels are the labels/tags to be added to connection + secret. - For Kubernetes secrets, this will be used as "metadata.labels". + - It is up to Secret Store implementation for others store + types. + type: object + type: + description: Type is the SecretType for the connection secret. + - Only valid for Kubernetes Secret Stores. + type: string + type: object + name: + description: Name is the name of the connection secret. + type: string + required: + - name + type: object + writeConnectionSecretToRef: + description: WriteConnectionSecretToReference specifies the namespace + and name of a Secret to which any connection details for this managed + resource should be written. Connection details frequently include + the endpoint, username, and password required to connect to the + managed resource. This field is planned to be replaced in a future + release in favor of PublishConnectionDetailsTo. Currently, both + could be set independently and connection details would be published + to both without affecting each other. + properties: + name: + description: Name of the secret. + type: string + namespace: + description: Namespace of the secret. + type: string + required: + - name + - namespace + type: object + required: + - forProvider + type: object + status: + description: OpenIDConnectProviderStatus defines the observed state of + OpenIDConnectProvider. + properties: + atProvider: + properties: + arn: + type: string + id: + type: string + tagsAll: + additionalProperties: + type: string + type: object + type: object + conditions: + description: Conditions of the resource. + items: + description: A Condition that may apply to a resource. + properties: + lastTransitionTime: + description: LastTransitionTime is the last time this condition + transitioned from one status to another. + format: date-time + type: string + message: + description: A Message containing details about this condition's + last transition from one status to another, if any. + type: string + reason: + description: A Reason for this condition's last transition from + one status to another. + type: string + status: + description: Status of this condition; is it currently True, + False, or Unknown? + type: string + type: + description: Type of this condition. At most one of each condition + type may apply to a resource at any point in time. + type: string + required: + - lastTransitionTime + - reason + - status + - type + type: object + type: array + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} +status: + acceptedNames: + kind: "" + plural: "" + conditions: [] + storedVersions: []