mirror of
https://github.com/vmware-tanzu/velero.git
synced 2026-09-28 10:45:44 +00:00
Run the E2E test on kind / get-go-version (push) Successful in 59s
Run the E2E test on kind / setup-test-matrix (push) Successful in 4s
Main CI / get-go-version (push) Successful in 14s
Run the E2E test on kind / build (push) Failing after 1m48s
Run the E2E test on kind / run-e2e-test (push) Has been skipped
Main CI / Build (push) Failing after 25s
* Replace github.com/robfig/cron/v3 by github.com/netresearch/go-cron Replace k8s.io/utils/pointer with k8s.io/utils/ptr Signed-off-by: Xun Jiang <xun.jiang@broadcom.com> * Replace gopkg.in/yaml.v3 by go.yaml.in/yaml/v3 Signed-off-by: Xun Jiang <xun.jiang@broadcom.com> * Replace github.com/joho/godotenv. Move the needed code into Velero repository. Signed-off-by: Xun Jiang <xun.jiang@broadcom.com> * Replace github.com/pkg/errors by github.com/cockroachdb/errors Change errors.Cause to errors.Is, because github.com/cockroachdb/errors New() function create a error with error stack with depth 1, but github.com/pkg/errors's New() function create error with no depth. Signed-off-by: Xun Jiang <xun.jiang@broadcom.com> --------- Signed-off-by: Xun Jiang <xun.jiang@broadcom.com> Signed-off-by: Xun Jiang/Bruce Jiang <59276555+blackpiglet@users.noreply.github.com>
74 lines
2.6 KiB
Go
74 lines
2.6 KiB
Go
/*
|
|
Copyright the Velero contributors.
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/
|
|
|
|
package actions
|
|
|
|
import (
|
|
"github.com/cockroachdb/errors"
|
|
"github.com/sirupsen/logrus"
|
|
"k8s.io/apimachinery/pkg/api/meta"
|
|
"k8s.io/apimachinery/pkg/runtime"
|
|
|
|
v1 "github.com/vmware-tanzu/velero/pkg/apis/velero/v1"
|
|
velerodiscovery "github.com/vmware-tanzu/velero/pkg/discovery"
|
|
"github.com/vmware-tanzu/velero/pkg/plugin/velero"
|
|
"github.com/vmware-tanzu/velero/pkg/util/actionhelpers"
|
|
)
|
|
|
|
// ServiceAccountAction implements ItemBlockAction.
|
|
type ServiceAccountAction struct {
|
|
log logrus.FieldLogger
|
|
clusterRoleBindings []actionhelpers.ClusterRoleBinding
|
|
}
|
|
|
|
// NewServiceAccountAction creates a new ItemBlockAction for service accounts.
|
|
func NewServiceAccountAction(logger logrus.FieldLogger, clusterRoleBindingListers map[string]actionhelpers.ClusterRoleBindingLister, discoveryHelper velerodiscovery.Helper) (*ServiceAccountAction, error) {
|
|
crbs, err := actionhelpers.ClusterRoleBindingsForAction(clusterRoleBindingListers, discoveryHelper)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
return &ServiceAccountAction{
|
|
log: logger,
|
|
clusterRoleBindings: crbs,
|
|
}, nil
|
|
}
|
|
|
|
// AppliesTo returns a ResourceSelector that applies only to service accounts.
|
|
func (a *ServiceAccountAction) AppliesTo() (velero.ResourceSelector, error) {
|
|
return velero.ResourceSelector{
|
|
IncludedResources: []string{"serviceaccounts"},
|
|
}, nil
|
|
}
|
|
|
|
// GetRelatedItems checks for any ClusterRoleBindings that have this service account as a subject, and
|
|
// returns the ClusterRoleBinding and associated ClusterRole.
|
|
func (a *ServiceAccountAction) GetRelatedItems(item runtime.Unstructured, backup *v1.Backup) ([]velero.ResourceIdentifier, error) {
|
|
a.log.Info("Running ServiceAccount ItemBlockAction")
|
|
defer a.log.Info("Done running ServiceAccount ItemBlockAction")
|
|
|
|
objectMeta, err := meta.Accessor(item)
|
|
if err != nil {
|
|
return nil, errors.WithStack(err)
|
|
}
|
|
|
|
return actionhelpers.RelatedItemsForServiceAccount(objectMeta, a.clusterRoleBindings, a.log), nil
|
|
}
|
|
|
|
func (a *ServiceAccountAction) Name() string {
|
|
return "ServiceAccountItemBlockAction"
|
|
}
|