Skip to content

Commit d2f31aa

Browse files
authored
rename bootstrap sa name (#466)
Signed-off-by: Zhiwei Yin <[email protected]>
1 parent 4081bde commit d2f31aa

File tree

12 files changed

+27
-27
lines changed

12 files changed

+27
-27
lines changed

go.mod

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ require (
3131
open-cluster-management.io/api v0.15.1-0.20250109024121-1a5e25a78a43
3232
open-cluster-management.io/cluster-proxy v0.4.0
3333
open-cluster-management.io/managed-serviceaccount v0.6.0
34-
open-cluster-management.io/ocm v0.15.1-0.20250110031959-11896ccda197
34+
open-cluster-management.io/ocm v0.15.1-0.20250116085531-34275ef1eac8
3535
open-cluster-management.io/sdk-go v0.15.1-0.20241125015855-1536c3970f8f
3636
sigs.k8s.io/apiserver-network-proxy v0.29.0
3737
sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.30.3

go.sum

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -563,8 +563,8 @@ open-cluster-management.io/cluster-proxy v0.4.0 h1:rm0UDaDWe3/P3xLzwqdHtqNksKwSz
563563
open-cluster-management.io/cluster-proxy v0.4.0/go.mod h1:gTvfDHAhGezhdg4BD3ECBn6jbg2Y5PbHhV2ceW5nrB0=
564564
open-cluster-management.io/managed-serviceaccount v0.6.0 h1:qIi5T9WQJBuoGqnYGIktXbtqfQoiN2H9XU2P/6lAQiw=
565565
open-cluster-management.io/managed-serviceaccount v0.6.0/go.mod h1:G4LUTbZiyrB8c0+rqi/xnDmGlsg7Rdr4T7MPLCWhyQI=
566-
open-cluster-management.io/ocm v0.15.1-0.20250110031959-11896ccda197 h1:ECwQuYbtUxDbKUKHfnmQYwLG2cV3i7OwsU4dJP/XrDg=
567-
open-cluster-management.io/ocm v0.15.1-0.20250110031959-11896ccda197/go.mod h1:daPkqFxkVqKb4O8UTX+7jCyEcJWarGOG7uDie9rFfck=
566+
open-cluster-management.io/ocm v0.15.1-0.20250116085531-34275ef1eac8 h1:IDjk8EeKajwqezVM1eDNYPHyaJx4V0N/sZoSAVhIUJk=
567+
open-cluster-management.io/ocm v0.15.1-0.20250116085531-34275ef1eac8/go.mod h1:daPkqFxkVqKb4O8UTX+7jCyEcJWarGOG7uDie9rFfck=
568568
open-cluster-management.io/sdk-go v0.15.1-0.20241125015855-1536c3970f8f h1:zeC7QrFNarfK2zY6jGtd+mX+yDrQQmnH/J8A7n5Nh38=
569569
open-cluster-management.io/sdk-go v0.15.1-0.20241125015855-1536c3970f8f/go.mod h1:fi5WBsbC5K3txKb8eRLuP0Sim/Oqz/PHX18skAEyjiA=
570570
oras.land/oras-go v1.2.5 h1:XpYuAwAb0DfQsunIyMfeET92emK8km3W4yEzZvUbsTo=

pkg/cmd/accept/exec.go

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ import (
2727
const (
2828
groupNameBootstrap = "system:bootstrappers:managedcluster"
2929
userNameSignatureBootstrapPrefix = "system:bootstrap:"
30-
userNameSignatureSA = "system:serviceaccount:open-cluster-management:cluster-bootstrap"
30+
userNameSignatureSA = "system:serviceaccount:open-cluster-management:agent-registration-bootstrap"
3131
groupNameSA = "system:serviceaccounts:open-cluster-management"
3232
clusterLabel = "open-cluster-management.io/cluster-name"
3333
)
@@ -124,12 +124,12 @@ func (o *Options) approveCSR(kubeClient *kubernetes.Clientset, clusterName strin
124124
passedCSRs = csrs.Items
125125
} else {
126126
for _, item := range csrs.Items {
127-
//Does not have the correct name prefix
127+
// Does not have the correct name prefix
128128
if !strings.HasPrefix(item.Spec.Username, userNameSignatureBootstrapPrefix) &&
129129
!strings.HasPrefix(item.Spec.Username, userNameSignatureSA) {
130130
continue
131131
}
132-
//Check groups
132+
// Check groups
133133
groups := sets.NewString(item.Spec.Groups...)
134134
if !groups.Has(groupNameBootstrap) &&
135135
!groups.Has(groupNameSA) {
@@ -173,14 +173,14 @@ func (o *Options) approveCSR(kubeClient *kubernetes.Clientset, clusterName strin
173173
fmt.Fprintf(o.Streams.Out, "CSR %s with requester %s is not in the approve list\n", passedCSR.Name, cn)
174174
continue
175175
}
176-
//Check if already approved or denied
176+
// Check if already approved or denied
177177
approved, denied := GetCertApprovalCondition(&passedCSR.Status)
178-
//if already denied, then nothing to do
178+
// if already denied, then nothing to do
179179
if denied {
180180
fmt.Fprintf(o.Streams.Out, "CSR %s already denied\n", passedCSR.Name)
181181
continue
182182
}
183-
//if already approved, then nothing to do
183+
// if already approved, then nothing to do
184184
if approved {
185185
fmt.Fprintf(o.Streams.Out, "CSR %s already approved\n", passedCSR.Name)
186186
hasApproved = true
@@ -189,15 +189,15 @@ func (o *Options) approveCSR(kubeClient *kubernetes.Clientset, clusterName strin
189189
csrToApprove = append(csrToApprove, passedCSR)
190190
}
191191

192-
//no csr found
192+
// no csr found
193193
if len(csrToApprove) == 0 {
194194
if waitMode {
195195
fmt.Fprintf(o.Streams.Out, "no CSR to approve for cluster %s\n", clusterName)
196196
}
197197

198198
return hasApproved, nil
199199
}
200-
//if dry-run don't approve
200+
// if dry-run don't approve
201201
if o.ClusteradmFlags.DryRun {
202202
return hasApproved, nil
203203
}

pkg/config/env.go

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,10 @@ package config
44

55
const (
66
OpenClusterManagementNamespace = "open-cluster-management"
7-
BootstrapSAName = "cluster-bootstrap"
8-
BootstrapClusterRoleBindingName = "cluster-bootstrap"
9-
BootstrapClusterRoleBindingSAName = "cluster-bootstrap-sa"
10-
BootstrapClusterRoleName = "system:open-cluster-management:bootstrap"
7+
BootstrapSAName = "agent-registration-bootstrap"
8+
BootstrapClusterRoleBindingName = "open-cluster-management:bootstrap:agent-registration"
9+
BootstrapClusterRoleBindingSAName = "agent-registration-bootstrap"
10+
BootstrapClusterRoleName = "open-cluster-management:bootstrap"
1111
ClusterManagerName = "cluster-manager"
1212
LabelApp = "app"
1313
BootstrapSecretPrefix = "bootstrap-token-"

vendor/modules.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1282,7 +1282,7 @@ open-cluster-management.io/managed-serviceaccount/pkg/generated/clientset/versio
12821282
open-cluster-management.io/managed-serviceaccount/pkg/generated/clientset/versioned/scheme
12831283
open-cluster-management.io/managed-serviceaccount/pkg/generated/clientset/versioned/typed/authentication/v1alpha1
12841284
open-cluster-management.io/managed-serviceaccount/pkg/generated/clientset/versioned/typed/authentication/v1beta1
1285-
# open-cluster-management.io/ocm v0.15.1-0.20250110031959-11896ccda197
1285+
# open-cluster-management.io/ocm v0.15.1-0.20250116085531-34275ef1eac8
12861286
## explicit; go 1.22.5
12871287
open-cluster-management.io/ocm/deploy/cluster-manager/chart
12881288
open-cluster-management.io/ocm/deploy/klusterlet/chart

vendor/open-cluster-management.io/ocm/deploy/cluster-manager/chart/cluster-manager/templates/bootstrap_cluster_role.yaml

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/open-cluster-management.io/ocm/deploy/cluster-manager/chart/cluster-manager/templates/bootstrap_cluster_role_binding.yaml

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/open-cluster-management.io/ocm/deploy/cluster-manager/chart/cluster-manager/templates/bootstrap_sa.yaml

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/open-cluster-management.io/ocm/deploy/cluster-manager/chart/cluster-manager/templates/bootstrap_sa_cluster_role_binding.yaml

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/open-cluster-management.io/ocm/deploy/cluster-manager/chart/cluster-manager/templates/cluster_manager.yaml

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)