docs: refactoring for v1beta2

This commit is contained in:
Dario Tranchitella
2023-01-28 11:42:34 +01:00
parent 91a979edc4
commit f8e212c291
8 changed files with 249 additions and 247 deletions
+2 -2
View File
@@ -152,7 +152,7 @@ $ kubectl -n capsule-system logs --all-containers -l control-plane=controller-ma
# You may have a try to deploy a Tenant too to make sure it works end to end
$ kubectl apply -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -307,7 +307,7 @@ To verify that, we can open a new console and create a new Tenant:
```shell
$ kubectl apply -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: gas
+42 -42
View File
@@ -3229,7 +3229,7 @@ Specifies options for the Ingress resources, such as allowed hostnames and Ingre
<td>
Toggles the ability for Ingress resources created in a Tenant to have a hostname wildcard.<br/>
</td>
<td>true</td>
<td>false</td>
</tr><tr>
<td><b><a href="#tenantspecingressoptionsallowedclasses-1">allowedClasses</a></b></td>
<td>object</td>
@@ -3518,25 +3518,25 @@ Specifies options for the Namespaces, such as additional metadata or maximum num
</tr>
</thead>
<tbody><tr>
<td><b><a href="#tenantspecnamespaceoptionsadditionalmetadata-1">additionalMetadata</a></b></td>
<td>object</td>
<td>
Specifies additional labels and annotations the Capsule operator places on any Namespace resource in the Tenant. Optional.<br/>
</td>
<td>false</td>
</tr><tr>
<td><b><a href="#tenantspecnamespaceoptionsforbiddenannotations">forbiddenAnnotations</a></b></td>
<td>object</td>
<td>
Define the annotations that a Tenant Owner cannot set for their Namespace resources.<br/>
</td>
<td>true</td>
<td>false</td>
</tr><tr>
<td><b><a href="#tenantspecnamespaceoptionsforbiddenlabels">forbiddenLabels</a></b></td>
<td>object</td>
<td>
Define the labels that a Tenant Owner cannot set for their Namespace resources.<br/>
</td>
<td>true</td>
</tr><tr>
<td><b><a href="#tenantspecnamespaceoptionsadditionalmetadata-1">additionalMetadata</a></b></td>
<td>object</td>
<td>
Specifies additional labels and annotations the Capsule operator places on any Namespace resource in the Tenant. Optional.<br/>
</td>
<td>false</td>
</tr><tr>
<td><b>quota</b></td>
@@ -3552,6 +3552,39 @@ Specifies options for the Namespaces, such as additional metadata or maximum num
</table>
### Tenant.spec.namespaceOptions.additionalMetadata
Specifies additional labels and annotations the Capsule operator places on any Namespace resource in the Tenant. Optional.
<table>
<thead>
<tr>
<th>Name</th>
<th>Type</th>
<th>Description</th>
<th>Required</th>
</tr>
</thead>
<tbody><tr>
<td><b>annotations</b></td>
<td>map[string]string</td>
<td>
<br/>
</td>
<td>false</td>
</tr><tr>
<td><b>labels</b></td>
<td>map[string]string</td>
<td>
<br/>
</td>
<td>false</td>
</tr></tbody>
</table>
### Tenant.spec.namespaceOptions.forbiddenAnnotations
@@ -3618,39 +3651,6 @@ Define the labels that a Tenant Owner cannot set for their Namespace resources.
</table>
### Tenant.spec.namespaceOptions.additionalMetadata
Specifies additional labels and annotations the Capsule operator places on any Namespace resource in the Tenant. Optional.
<table>
<thead>
<tr>
<th>Name</th>
<th>Type</th>
<th>Description</th>
<th>Required</th>
</tr>
</thead>
<tbody><tr>
<td><b>annotations</b></td>
<td>map[string]string</td>
<td>
<br/>
</td>
<td>false</td>
</tr><tr>
<td><b>labels</b></td>
<td>map[string]string</td>
<td>
<br/>
</td>
<td>false</td>
</tr></tbody>
</table>
### Tenant.spec.networkPolicies
+1 -1
View File
@@ -35,7 +35,7 @@ Create the tenant as cluster admin:
```yaml
kubectl create -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
+28 -26
View File
@@ -51,7 +51,7 @@ As cluster admin, create a tenant
```yaml
kubectl create -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -129,7 +129,7 @@ As cluster admin, create a tenant
```yaml
kubectl create -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -188,7 +188,7 @@ As cluster admin, create a tenant
```yaml
kubectl create -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -247,7 +247,7 @@ As cluster admin, create a tenant
```yaml
kubectl create -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -361,7 +361,7 @@ As cluster admin, create a tenant
```yaml
kubectl create -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -517,7 +517,7 @@ As cluster admin, create a couple of tenants
```yaml
kubectl create -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -535,7 +535,7 @@ and
```yaml
kubectl create -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: gas
@@ -659,7 +659,7 @@ And assign it to the tenant
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -737,7 +737,7 @@ As cluster admin, create a tenant
```yaml
kubectl create -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -807,7 +807,7 @@ As cluster admin, create a couple of tenants
```yaml
kubectl create -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -834,7 +834,7 @@ and
```yaml
kubectl create -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: gas
@@ -956,7 +956,7 @@ And assign it to the tenant
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1072,7 +1072,7 @@ And assign it to the tenant
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1148,7 +1148,7 @@ As cluster admin, create a tenant
```yaml
kubectl create -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1231,7 +1231,7 @@ And assign it to the tenant
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1348,7 +1348,7 @@ And assign it to the tenant
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1489,7 +1489,7 @@ And assign it to the tenant
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1613,7 +1613,7 @@ And assign it to the tenant
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1687,12 +1687,14 @@ As cluster admin, create a tenant
```yaml
kubectl create -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
spec:
enableNodePorts: false
serviceOptions:
allowedServices:
nodePort: false
owners:
- kind: User
name: alice
@@ -1763,7 +1765,7 @@ As cluster admin, create a tenant
```yaml
kubectl create -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1830,7 +1832,7 @@ As cluster admin, create a tenant
```yaml
kubectl create -f - <<EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1896,7 +1898,7 @@ As cluster admin, create a tenant
```yaml
kubectl create -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -2011,7 +2013,7 @@ And assign it to the tenant
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -2106,7 +2108,7 @@ As cluster admin, create a tenant and assign the above Storage Class
```yaml
kubectl create -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -2229,7 +2231,7 @@ And assign it to the tenant
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
+6 -6
View File
@@ -104,7 +104,7 @@ For a web-based dashboard, like the [Kubernetes Dashboard](https://github.com/ku
Each Tenant owner can have their capabilities managed pretty similar to a standard Kubernetes RBAC.
```yaml
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: my-tenant
@@ -171,7 +171,7 @@ namespace/solar-development created
The Capsule Proxy gives the owners the ability to access the nodes matching the `.spec.nodeSelector` in the Tenant manifest:
```yaml
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -209,7 +209,7 @@ These are mandatory in order to retrieve the list of the running Pods on the req
A Tenant may be limited to use a set of allowed Storage Class resources, as follows.
```yaml
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -267,7 +267,7 @@ provisioner: cephfs
As for Storage Class, also Ingress Class can be enforced.
```yaml
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -330,7 +330,7 @@ spec:
Allowed PriorityClasses assigned to a Tenant Owner can be enforced as follows:
```yaml
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -403,7 +403,7 @@ These tenant users, groups and services accounts have less privileged access tha
As a Tenant Owner `alice`, you can create a `ProxySetting` resources to allow `bob` to list nodes, storage classes, ingress classes and priority classes
```yaml
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: ProxySetting
metadata:
name: sre-readers
+164 -164
View File
@@ -24,7 +24,7 @@ Bill creates a new tenant `oil` in the CaaS management portal according to the t
```yaml
kubectl create -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -88,7 +88,7 @@ In the example above, Bill assigned the ownership of `oil` tenant to `alice` use
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -107,7 +107,7 @@ The tenant manifest is modified as in the following:
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -133,7 +133,7 @@ The tenant manifest is modified as in the following:
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -154,7 +154,7 @@ yes
The service account has to be part of Capsule group, so Bill has to set in the `CapsuleConfiguration`
```yaml
apiVersion: capsule.clastix.io/v1alpha1
apiVersion: capsule.clastix.io/v1beta2
kind: CapsuleConfiguration
metadata:
name: default
@@ -242,18 +242,18 @@ For example, assign user `Joe` the tenant ownership with only [view](https://kub
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
annotations:
clusterrolenames.capsule.clastix.io/user.joe: view
spec:
owners:
- name: alice
kind: User
- name: joe
kind: User
clusterRoles:
- view
EOF
```
@@ -262,9 +262,9 @@ you'll see the new Role Bindings assigned to Joe:
```
kubectl -n oil-production get rolebindings
NAME ROLE AGE
capsule-oil-0-admin ClusterRole/admin 8d
capsule-oil-1-capsule-namespace-deleter ClusterRole/capsule-namespace-deleter 8d
capsule-oil-2-view ClusterRole/edit 5s
capsule-oil-0-admin ClusterRole/admin 3s
capsule-oil-1-capsule-namespace-deleter ClusterRole/capsule-namespace-deleter 3s
capsule-oil-2-view ClusterRole/view 3s
```
so that Joe can only view resources in the tenant namespaces:
@@ -274,7 +274,8 @@ kubectl --as joe --as-group capsule.clastix.io auth can-i delete pods -n oil-mar
no
```
> Please, note that, despite created with more restricted permissions, a tenant owner can still create namespaces in the tenant because he belongs to the `capsule.clastix.io` group. If you want a user not acting as tenant owner, but still operating in the tenant, you can assign additional `RoleBindings` without assigning him the tenant ownership.
> Please, note that, despite created with more restricted permissions, a tenant owner can still create namespaces in the tenant because he belongs to the `capsule.clastix.io` group.
> If you want a user not acting as tenant owner, but still operating in the tenant, you can assign additional `RoleBindings` without assigning him the tenant ownership.
Custom ClusterRoles are also supported. Assuming the cluster admin creates:
@@ -295,18 +296,19 @@ These permissions can be granted to Joe
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
annotations:
clusterrolenames.capsule.clastix.io/user.joe: view,prometheus-servicemonitors-viewer
spec:
owners:
- name: alice
kind: User
- name: joe
kind: User
clusterRoles:
- view
- prometheus-servicemonitors-viewer
EOF
```
@@ -315,51 +317,12 @@ For the given configuration, the resulting RoleBinding resources are the followi
```
kubectl -n oil-production get rolebindings
NAME ROLE AGE
capsule-oil-0-admin ClusterRole/admin 8d
capsule-oil-1-capsule-namespace-deleter ClusterRole/capsule-namespace-deleter 8d
capsule-oil-2-view ClusterRole/view 11m
capsule-oil-3-prometheus-servicemonitors-viewer ClusterRole/prometheus-servicemonitors-viewer 18s
capsule-oil-0-admin ClusterRole/admin 90s
capsule-oil-1-capsule-namespace-deleter ClusterRole/capsule-namespace-deleter 90s
capsule-oil-2-view ClusterRole/view 90s
capsule-oil-3-prometheus-servicemonitors-viewer ClusterRole/prometheus-servicemonitors-viewer 25s
```
> The pattern for the annotation is `clusterrolenames.capsule.clastix.io/${KIND}.${NAME}`.
> The placeholders `${KIND}` and `${NAME}` are referring to the Tenant Owner specification fields, both lower-cased.
>
> In the case of users that are identified using their email address, the symbol `@` wouldn't be supported by the RFC 1123.
> For such cases, the `@` symbol can be replaced with the placeholder `__AT__`.
>
> ```yaml
> apiVersion: capsule.clastix.io/v1beta1
> kind: Tenant
> metadata:
> annotations:
> clusterrolenames.capsule.clastix.io/alice__AT__clastix.io: editor,manager
> spec:
> owners:
> - kind: User
> name: alice@org.tld
> - kind: User
> name: alice@clastix.io
> ```
>
> Instead, with the resulting annotation key exceeding 63 characters length, the zero-based index of the owner can be specified as follows:
>
> ```yaml
> apiVersion: capsule.clastix.io/v1beta1
> kind: Tenant
> metadata:
> annotations:
> clusterrolenames.capsule.clastix.io/1: editor,manager
> spec:
> owners:
> - kind: User
> name: alice@org.tld
> - kind: User
> name: very-long-user-name-that-breaks-rfc-1123@org.tld
> ```
>
> This latter example will assign the roles `editor` and `manager`, assigned to the user `very-long-user-name-that-breaks-rfc-1123@org.tld`.
### Assign additional Role Bindings
The tenant owner acts as admin of tenant namespaces. Other users can operate inside the tenant namespaces with different levels of permissions and authorizations.
@@ -382,7 +345,7 @@ These permissions can be granted to a user without giving the role of tenant own
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -421,7 +384,7 @@ The cluster admin, can control how many namespaces Alice, creates by setting a q
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -454,7 +417,8 @@ status:
oil-development
oil-production
oil-test
size: 3 # current namespace count
Size: 3 # current namespace count
State: Active
...
```
@@ -476,7 +440,7 @@ Bill, the cluster admin, creates multiple tenants having `alice` as owner:
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -491,7 +455,7 @@ and
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: gas
@@ -506,7 +470,7 @@ Alternatively, the ownership can be assigned to a group called `oil-and-gas`:
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -521,7 +485,7 @@ and
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: gas
@@ -564,7 +528,7 @@ Set resources quota for each namespace in the Alice's tenant by defining them in
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -716,7 +680,7 @@ By setting enforcement at the namespace level, i.e. `spec.resourceQuotas.scope=N
Bill, the cluster admin, can also set Limit Ranges for each namespace in Alice's tenant by defining limits for pods and containers in the tenant spec:
```yaml
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -757,40 +721,54 @@ spec:
Limits will be inherited by all the namespaces created by Alice. In our case, when Alice creates the namespace `oil-production`, Capsule creates the following:
```yaml
kind: LimitRange
apiVersion: v1
kind: LimitRange
metadata:
name: limits
name: capsule-oil-0
namespace: oil-production
labels:
tenant: oil
spec:
limits:
- type: Pod
min:
cpu: "50m"
memory: "5Mi"
max:
cpu: "1"
memory: "1Gi"
- type: Container
defaultRequest:
cpu: "100m"
memory: "10Mi"
default:
cpu: "200m"
memory: "100Mi"
min:
cpu: "50m"
memory: "5Mi"
max:
cpu: "1"
memory: "1Gi"
- type: PersistentVolumeClaim
min:
storage: "1Gi"
max:
storage: "10Gi"
- max:
cpu: "1"
memory: 1Gi
min:
cpu: 50m
memory: 5Mi
type: Pod
---
apiVersion: v1
kind: LimitRange
metadata:
name: capsule-oil-1
namespace: oil-production
spec:
limits:
- default:
cpu: 200m
memory: 100Mi
defaultRequest:
cpu: 100m
memory: 10Mi
max:
cpu: "1"
memory: 1Gi
min:
cpu: 50m
memory: 5Mi
type: Container
---
apiVersion: v1
kind: LimitRange
metadata:
name: capsule-oil-2
namespace: oil-production
spec:
limits:
- max:
storage: 10Gi
min:
storage: 1Gi
type: PersistentVolumeClaim
```
> Note: being the limit range specific of single resources, there is no aggregate to count.
@@ -831,9 +809,8 @@ spec:
allowed:
- custom
allowedRegex: "^tier-.*$"
selector:
matchLabels:
env: "production"
matchLabels:
env: "production"
EOF
```
@@ -845,7 +822,6 @@ With the said Tenant specification, Alice can create a Pod resource if `spec.pri
If a Pod is going to use a non-allowed _Priority Class_, it will be rejected by the Validation Webhook enforcing it.
### Assign Pod Priority Class as tenant default
It's possible to assign each tenant a PriorityClass which will be used, if no PriorityClass is set on pod basis:
@@ -865,9 +841,8 @@ spec:
- custom
default: "tenant-default"
allowedRegex: "^tier-.*$"
selector:
matchLabels:
env: "production"
matchLabels:
env: "production"
EOF
```
@@ -913,9 +888,8 @@ spec:
allowed:
- legacy
allowedRegex: "^hardened-.*$"
selector:
matchLabels:
env: "production"
matchLabels:
env: "production"
EOF
```
@@ -946,7 +920,7 @@ The label `pool=oil` is defined as node selector in the tenant manifest:
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -965,7 +939,7 @@ The Capsule controller makes sure that any namespace created in the tenant has t
Multiple node selector labels can be defined as in the following snippet:
```yaml
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1009,9 +983,8 @@ spec:
allowed:
- legacy
allowedRegex: ^\w+-lb$
selector:
matchLabels:
env: "production"
matchLabels:
env: "production"
EOF
```
@@ -1040,9 +1013,12 @@ spec:
http:
paths:
- backend:
serviceName: nginx
servicePort: 80
service:
name: nginx
port:
number: 80
path: /
pathType: ImplementationSpecific
EOF
```
@@ -1068,9 +1044,8 @@ spec:
- legacy
default: "tenant-default"
allowedRegex: ^\w+-lb$
selector:
matchLabels:
env: "production"
matchLabels:
env: "production"
EOF
```
@@ -1105,7 +1080,7 @@ Bill can control ingress hostnames in the `oil` tenant to force the applications
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1161,7 +1136,7 @@ In a multi-tenant environment, as more and more ingresses are defined, there is
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1248,9 +1223,8 @@ spec:
- ceph-rbd
- ceph-nfs
allowedRegex: "^ceph-.*$"
selector:
matchLabels:
env: "production"
matchLabels:
env: "production"
EOF
```
@@ -1301,9 +1275,8 @@ spec:
- ceph-rbd
- ceph-nfs
allowedRegex: "^ceph-.*$"
selector:
matchLabels:
env: "production"
matchLabels:
env: "production"
EOF
```
@@ -1341,7 +1314,7 @@ Bill can set network policies in the tenant manifest, according to the requireme
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1442,7 +1415,7 @@ To avoid this kind of attack, Bill, the cluster admin, can force Alice, the tena
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1468,7 +1441,7 @@ The spec `containerRegistries` addresses this task and can provide a combination
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1524,7 +1497,7 @@ Bill can assign this role to any namespace in the Alice's tenant by setting it i
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1579,7 +1552,7 @@ Starting from Capsule **v0.1.1**, this can be done using a special annotation in
Imagine the case where a Custom Resource named `MySQL` in the API group `databases.acme.corp/v1` usage must be limited in the Tenant `oil`: this can be done as follows.
```yaml
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1606,7 +1579,7 @@ spec:
When `alice` will create a `MySQL` instance in one of their Tenant Namespace, the Cluster Administrator can easily retrieve the overall usage.
```yaml
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1628,7 +1601,7 @@ Assigns additional labels and annotations to all namespaces created in the `oil`
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1660,7 +1633,7 @@ metadata:
capsule.clastix.io/backup: "true"
name: oil-production
ownerReferences:
- apiVersion: capsule.clastix.io/v1beta1
- apiVersion: capsule.clastix.io/v1beta2
blockOwnerDeletion: true
controller: true
kind: Tenant
@@ -1678,7 +1651,7 @@ Assigns additional labels and annotations to all services created in the `oil` t
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1724,20 +1697,36 @@ Bill needs to cordon a Tenant and its Namespaces for several reasons:
With this said, the Tenant Owner and the related Service Account living into managed Namespaces, cannot proceed to any update, create or delete action.
This is possible just labeling the Tenant as follows:
This is possible by just toggling the specific Tenant specification:
```shell
kubectl label tenant oil capsule.clastix.io/cordon=enabled
tenant oil labeled
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
spec:
cordoned: true
owners:
- kind: User
name: alice
```
Any operation performed by Alice, the Tenant Owner, will be rejected by the Admission controller.
Uncordoning can be done by removing the said label:
Uncordoning can be done by removing the said specification key:
```shell
$ kubectl label tenant oil capsule.clastix.io/cordon-
tenant.capsule.clastix.io/oil labeled
$ cat <<EOF | kubectl apply -f -
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
spec:
cordoned: false
owners:
- kind: User
name: alice
EOF
$ kubectl --as alice --as-group capsule.clastix.io -n oil-dev create deployment nginx --image nginx
deployment.apps/nginx created
@@ -1765,7 +1754,7 @@ Bill, the cluster admin, can block the creation of services with `NodePort` serv
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1786,7 +1775,7 @@ Service with the type of `ExternalName` has been found subject to many security
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1808,7 +1797,7 @@ Same as previously, the Service of type of `LoadBalancer` could be blocked for v
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -1835,16 +1824,16 @@ To avoid this kind of problems, Bill can deny the use of wildcard hostnames in t
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
annotations:
capsule.clastix.io/deny-wildcard: true
spec:
owners:
- name: alice
kind: User
- name: alice
kind: User
ingressOptions:
allowWildcardHostnames: false
EOF
```
@@ -1860,16 +1849,22 @@ Bill, the cluster admin, can deny Alice to add specific labels and annotations o
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
annotations:
capsule.clastix.io/forbidden-namespace-labels: foo.acme.net,bar.acme.net
capsule.clastix.io/forbidden-namespace-labels-regexp: .*.acme.net
capsule.clastix.io/forbidden-namespace-annotations: foo.acme.net,bar.acme.net
capsule.clastix.io/forbidden-namespace-annotations-regexp: .*.acme.net
spec:
namespaceOptions:
forbiddenAnnotations:
denied:
- foo.acme.net
- bar.acme.net
deniedRegex: .*.acme.net
forbiddenLabels:
denied:
- foo.acme.net
- bar.acme.net
deniedRegex: .*.acme.net
owners:
- name: alice
kind: User
@@ -1888,16 +1883,22 @@ Bill, the cluster admin, can deny Tenant Owners to add or modify specific labels
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1alpha1
apiVersion: capsule.clastix.io/v1beta2
kind: CapsuleConfiguration
metadata:
name: default
annotations:
capsule.clastix.io/forbidden-node-labels: foo.acme.net,bar.acme.net
capsule.clastix.io/forbidden-node-labels-regexp: .*.acme.net
capsule.clastix.io/forbidden-node-annotations: foo.acme.net,bar.acme.net
capsule.clastix.io/forbidden-node-annotations-regexp: .*.acme.net
name: default
spec:
nodeMetadata:
forbiddenAnnotations:
denied:
- foo.acme.net
- bar.acme.net
deniedRegex: .*.acme.net
forbiddenLabels:
denied:
- foo.acme.net
- bar.acme.net
deniedRegex: .*.acme.net
userGroups:
- capsule.clastix.io
- system:serviceaccounts:default
@@ -1915,20 +1916,19 @@ EOF
## Protecting tenants from deletion
Sometimes it is important to protect business critical tenants from accidental deletion.
This can be achieved by adding `capsule.clastix.io/protected` annotation on the tenant:
This can be achieved by toggling `preventDeletion` specification key on the tenant:
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
annotations:
capsule.clastix.io/protected: ""
spec:
owners:
- name: alice
kind: User
preventDeletion: true
EOF
```
+3 -3
View File
@@ -77,7 +77,7 @@ metadata:
name: gitops-reconciler
namespace: my-tenant
---
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: my-tenant
@@ -93,7 +93,7 @@ From now on, we'll refer to it as the **Tenant GitOps Reconciler**.
We also need to state that Capsule should enforce tenant access control for requests coming from tenants, and we can do that by specifying one of the `Group`s bound by default by Kubernetes to the Tenant GitOps Reconciler `ServiceAccount` in the `CapsuleConfiguration`:
```yaml
apiVersion: capsule.clastix.io/v1alpha1
apiVersion: capsule.clastix.io/v1beta2
kind: CapsuleConfiguration
metadata:
name: default
@@ -238,7 +238,7 @@ this is the required set of resources to setup a Tenant:
- Additional binding to *cluster-admin* `ClusterRole` for the Tenant's `Namespace`s and `Namespace` of the Tenant GitOps Reconciler' `ServiceAccount`.
By default Capsule binds only `admin` ClusterRole, which has no privileges over Custom Resources, but *cluster-admin* has. This is needed to operate on Flux CRs:
```yaml
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: my-tenant
+3 -3
View File
@@ -47,7 +47,7 @@ He can assign this role to all namespaces in a tenant by setting the tenant mani
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -171,7 +171,7 @@ As cluster admin, create a tenant with additional labels:
```yaml
kubectl apply -f - << EOF
apiVersion: capsule.clastix.io/v1beta1
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
name: oil
@@ -203,7 +203,7 @@ metadata:
pod-security.kubernetes.io/audit: restricted
name: oil-development
ownerReferences:
- apiVersion: capsule.clastix.io/v1beta1
- apiVersion: capsule.clastix.io/v1beta2
blockOwnerDeletion: true
controller: true
kind: Tenant