From 87dc41469ca16c6db5abc5c9159cd68cdfb6378e Mon Sep 17 00:00:00 2001 From: DangPeng Liu Date: Thu, 2 Mar 2023 09:40:43 +0800 Subject: [PATCH] remove old webhook (#330) Signed-off-by: ldpliu --- ...nager-registration-webhook-apiservice.yaml | 13 --- ...-manager-registration-webhook-service.yaml | 3 - ...uster-manager-work-webhook-apiservice.yaml | 13 --- .../cluster-manager-work-webhook-service.yaml | 3 - ...nager-registration-webhook-deployment.yaml | 54 ----------- ...uster-manager-work-webhook-deployment.yaml | 55 ----------- pkg/helpers/helpers.go | 11 --- pkg/helpers/helpers_test.go | 96 +++---------------- .../clustermanager_controller.go | 23 ++--- .../clustermanager_controller_test.go | 20 +--- .../clustermanager_hub_reconcile.go | 22 +---- .../clustermanager_runtime_reconcile.go | 5 +- .../clustermanager_webhook_reconcile.go | 2 +- .../klusterlet_managed_reconcile.go | 1 - .../klusterlet_management_recocile.go | 2 +- 15 files changed, 35 insertions(+), 288 deletions(-) delete mode 100644 manifests/cluster-manager/hub/cluster-manager-registration-webhook-apiservice.yaml delete mode 100644 manifests/cluster-manager/hub/cluster-manager-work-webhook-apiservice.yaml diff --git a/manifests/cluster-manager/hub/cluster-manager-registration-webhook-apiservice.yaml b/manifests/cluster-manager/hub/cluster-manager-registration-webhook-apiservice.yaml deleted file mode 100644 index 72f1391b8..000000000 --- a/manifests/cluster-manager/hub/cluster-manager-registration-webhook-apiservice.yaml +++ /dev/null @@ -1,13 +0,0 @@ -apiVersion: apiregistration.k8s.io/v1 -kind: APIService -metadata: - name: v1.admission.cluster.open-cluster-management.io -spec: - group: admission.cluster.open-cluster-management.io - version: v1 - service: - name: cluster-manager-registration-webhook - namespace: {{ .ClusterManagerNamespace }} - port: {{.RegistrationWebhook.Port}} - groupPriorityMinimum: 10000 - versionPriority: 20 diff --git a/manifests/cluster-manager/hub/cluster-manager-registration-webhook-service.yaml b/manifests/cluster-manager/hub/cluster-manager-registration-webhook-service.yaml index 19bf0b4ee..51dadba04 100644 --- a/manifests/cluster-manager/hub/cluster-manager-registration-webhook-service.yaml +++ b/manifests/cluster-manager/hub/cluster-manager-registration-webhook-service.yaml @@ -7,9 +7,6 @@ spec: selector: app: {{ .ClusterManagerName }}-registration-webhook ports: - - name: webhook-server - port: 443 - targetPort: 6443 - name: webhook port: 9443 targetPort: 9443 diff --git a/manifests/cluster-manager/hub/cluster-manager-work-webhook-apiservice.yaml b/manifests/cluster-manager/hub/cluster-manager-work-webhook-apiservice.yaml deleted file mode 100644 index 9e8f2b4c5..000000000 --- a/manifests/cluster-manager/hub/cluster-manager-work-webhook-apiservice.yaml +++ /dev/null @@ -1,13 +0,0 @@ -apiVersion: apiregistration.k8s.io/v1 -kind: APIService -metadata: - name: v1.admission.work.open-cluster-management.io -spec: - group: admission.work.open-cluster-management.io - version: v1 - service: - name: cluster-manager-work-webhook - namespace: {{ .ClusterManagerNamespace }} - port: {{.WorkWebhook.Port}} - groupPriorityMinimum: 10000 - versionPriority: 20 diff --git a/manifests/cluster-manager/hub/cluster-manager-work-webhook-service.yaml b/manifests/cluster-manager/hub/cluster-manager-work-webhook-service.yaml index f45b06ea8..8df676362 100644 --- a/manifests/cluster-manager/hub/cluster-manager-work-webhook-service.yaml +++ b/manifests/cluster-manager/hub/cluster-manager-work-webhook-service.yaml @@ -7,9 +7,6 @@ spec: selector: app: {{ .ClusterManagerName }}-work-webhook ports: - - name: webhook-server - port: 443 - targetPort: 6443 - name: webhook port: 9443 targetPort: 9443 diff --git a/manifests/cluster-manager/management/cluster-manager-registration-webhook-deployment.yaml b/manifests/cluster-manager/management/cluster-manager-registration-webhook-deployment.yaml index 708a3a419..da74be7cc 100644 --- a/manifests/cluster-manager/management/cluster-manager-registration-webhook-deployment.yaml +++ b/manifests/cluster-manager/management/cluster-manager-registration-webhook-deployment.yaml @@ -40,60 +40,6 @@ spec: serviceAccountName: {{ .ClusterManagerName }}-registration-webhook-sa {{ end }} containers: - - name: {{ .ClusterManagerName }}-registration-webhook-sa - image: {{ .RegistrationImage }} - args: - - "/registration" - - "webhook" - - "--secure-port=6443" - - "--tls-cert-file=/serving-cert/tls.crt" - - "--tls-private-key-file=/serving-cert/tls.key" - {{ if gt (len .RegistrationFeatureGates) 0 }} - {{range .RegistrationFeatureGates}} - - {{ . }} - {{ end }} - {{ else }} - - "--feature-gates=DefaultClusterSet=true" - {{ end }} - - "--feature-gates=APIPriorityAndFairness=false" - {{ if .HostedMode }} - - "--kubeconfig=/var/run/secrets/hub/kubeconfig" - - "--authentication-kubeconfig=/var/run/secrets/hub/kubeconfig" - - "--authorization-kubeconfig=/var/run/secrets/hub/kubeconfig" - {{ end }} - securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - privileged: false - runAsNonRoot: true - livenessProbe: - httpGet: - path: /healthz - scheme: HTTPS - port: 6443 - initialDelaySeconds: 2 - periodSeconds: 10 - readinessProbe: - httpGet: - path: /healthz - scheme: HTTPS - port: 6443 - initialDelaySeconds: 2 - resources: - requests: - cpu: 2m - memory: 16Mi - volumeMounts: - - name: webhook-secret - mountPath: "/serving-cert" - readOnly: true - {{ if .HostedMode }} - - mountPath: /var/run/secrets/hub - name: kubeconfig - readOnly: true - {{ end }} - name: {{ .ClusterManagerName }}-webhook image: {{ .RegistrationImage }} args: diff --git a/manifests/cluster-manager/management/cluster-manager-work-webhook-deployment.yaml b/manifests/cluster-manager/management/cluster-manager-work-webhook-deployment.yaml index dba630767..71ccf1bb3 100644 --- a/manifests/cluster-manager/management/cluster-manager-work-webhook-deployment.yaml +++ b/manifests/cluster-manager/management/cluster-manager-work-webhook-deployment.yaml @@ -90,61 +90,6 @@ spec: name: kubeconfig readOnly: true {{ end }} - - name: {{ .ClusterManagerName }}-work-webhook-sa - image: {{ .WorkImage }} - args: - - /work - - "webhook" - {{ if gt (len .WorkFeatureGates) 0 }} - {{range .WorkFeatureGates}} - - {{ . }} - {{ end }} - {{ end }} - - "--secure-port=6443" - - "--tls-cert-file=/serving-cert/tls.crt" - - "--tls-private-key-file=/serving-cert/tls.key" - - "--feature-gates=APIPriorityAndFairness=false" - {{ if .HostedMode }} - - "--kubeconfig=/var/run/secrets/hub/kubeconfig" - - "--authentication-kubeconfig=/var/run/secrets/hub/kubeconfig" - - "--authorization-kubeconfig=/var/run/secrets/hub/kubeconfig" - {{ end }} - securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - privileged: false - runAsNonRoot: true - livenessProbe: - httpGet: - path: /healthz - scheme: HTTPS - port: 6443 - initialDelaySeconds: 2 - periodSeconds: 10 - readinessProbe: - httpGet: - path: /healthz - scheme: HTTPS - port: 6443 - initialDelaySeconds: 2 - resources: - requests: - cpu: 2m - memory: 16Mi - ports: - - containerPort: 9443 - protocol: TCP - volumeMounts: - - name: webhook-secret - mountPath: "/serving-cert" - readOnly: true - {{ if .HostedMode }} - - mountPath: /var/run/secrets/hub - name: kubeconfig - readOnly: true - {{ end }} volumes: - name: webhook-secret secret: diff --git a/pkg/helpers/helpers.go b/pkg/helpers/helpers.go index b71cae4d2..79e0f37ec 100644 --- a/pkg/helpers/helpers.go +++ b/pkg/helpers/helpers.go @@ -2,7 +2,6 @@ package helpers import ( "context" - "crypto/sha256" "fmt" "reflect" @@ -422,7 +421,6 @@ func ApplyDirectly( ctx context.Context, client kubernetes.Interface, apiExtensionClient apiextensionsclient.Interface, - apiRegistrationClient apiregistrationclient.APIServicesGetter, recorder events.Recorder, cache resourceapply.ResourceCache, manifests resourceapply.AssetFunc, @@ -455,15 +453,6 @@ func ApplyDirectly( case *admissionv1.MutatingWebhookConfiguration: result.Result, result.Changed, result.Error = ApplyMutatingWebhookConfiguration( client.AdmissionregistrationV1(), t) - case *apiregistrationv1.APIService: - if apiRegistrationClient == nil { - result.Error = fmt.Errorf("apiRegistrationClient is nil") - } else { - t.ObjectMeta.Annotations = make(map[string]string) - checksum := fmt.Sprintf("%x", sha256.Sum256(t.Spec.CABundle)) - t.ObjectMeta.Annotations["caBundle-checksum"] = string(checksum[:]) // to trigger the update when caBundle changed - result.Result, result.Changed, result.Error = resourceapply.ApplyAPIService(ctx, apiRegistrationClient, recorder, t) - } case *corev1.Endpoints: result.Result, result.Changed, result.Error = ApplyEndpoints(context.TODO(), client.CoreV1(), t) default: diff --git a/pkg/helpers/helpers_test.go b/pkg/helpers/helpers_test.go index 5848f7a8c..9c96145cb 100644 --- a/pkg/helpers/helpers_test.go +++ b/pkg/helpers/helpers_test.go @@ -405,46 +405,22 @@ func TestApplyMutatingWebhookConfiguration(t *testing.T) { func TestApplyDirectly(t *testing.T) { testcase := []struct { - name string - applyFiles map[string]runtime.Object - applyFileNames []string - nilapiExtensionClient bool - nilapiRegistratonClient bool - expectErr bool + name string + applyFiles map[string]runtime.Object + applyFileNames []string + nilapiExtensionClient bool + expectErr bool }{ { - name: "Apply webhooks & apiservice & secret", + name: "Apply webhooks & secret", applyFiles: map[string]runtime.Object{ "validatingwebhooks": newUnstructured("admissionregistration.k8s.io/v1", "ValidatingWebhookConfiguration", "", "", map[string]interface{}{"webhooks": []interface{}{}}), "mutatingwebhooks": newUnstructured("admissionregistration.k8s.io/v1", "MutatingWebhookConfiguration", "", "", map[string]interface{}{"webhooks": []interface{}{}}), - "apiservice": newUnstructured("apiregistration.k8s.io/v1", "APIService", "", "", map[string]interface{}{"spec": map[string]interface{}{"service": map[string]string{"name": "svc1", "namespace": "svc1"}}}), "secret": newUnstructured("v1", "Secret", "ns1", "n1", map[string]interface{}{"data": map[string]interface{}{"key1": []byte("key1")}}), }, - applyFileNames: []string{"validatingwebhooks", "mutatingwebhooks", "apiservice", "secret"}, + applyFileNames: []string{"validatingwebhooks", "mutatingwebhooks", "secret"}, expectErr: false, }, - { - name: "Apply webhooks & apiservice & secret with nil apiRegistrationClient", - applyFiles: map[string]runtime.Object{ - "validatingwebhooks": newUnstructured("admissionregistration.k8s.io/v1", "ValidatingWebhookConfiguration", "", "", map[string]interface{}{"webhooks": []interface{}{}}), - "mutatingwebhooks": newUnstructured("admissionregistration.k8s.io/v1", "MutatingWebhookConfiguration", "", "", map[string]interface{}{"webhooks": []interface{}{}}), - "apiservice": newUnstructured("apiregistration.k8s.io/v1", "APIService", "", "", map[string]interface{}{"spec": map[string]interface{}{"service": map[string]string{"name": "svc1", "namespace": "svc1"}}}), - "secret": newUnstructured("v1", "Secret", "ns1", "n1", map[string]interface{}{"data": map[string]interface{}{"key1": []byte("key1")}}), - }, - applyFileNames: []string{"validatingwebhooks", "mutatingwebhooks", "apiservice", "secret"}, - nilapiRegistratonClient: true, - expectErr: true, - }, - { - name: "Apply generic resources with nil apiExtensionclient & nil apiRegistrationClient", - applyFiles: map[string]runtime.Object{ - "secret": newUnstructured("v1", "Secret", "ns1", "n1", map[string]interface{}{"data": map[string]interface{}{"key1": []byte("key1")}}), - }, - nilapiExtensionClient: true, - nilapiRegistratonClient: true, - applyFileNames: []string{"secret"}, - expectErr: false, - }, { name: "Apply CRD", applyFiles: map[string]runtime.Object{ @@ -476,7 +452,6 @@ func TestApplyDirectly(t *testing.T) { t.Run(c.name, func(t *testing.T) { fakeKubeClient := fakekube.NewSimpleClientset() fakeExtensionClient := fakeapiextensions.NewSimpleClientset() - fakeResgistrationClient := fakeapiregistration.NewSimpleClientset().ApiregistrationV1() fakeApplyFunc := func(name string) ([]byte, error) { if c.applyFiles[name] == nil { return nil, fmt.Errorf("Failed to find file") @@ -488,28 +463,10 @@ func TestApplyDirectly(t *testing.T) { cache := resourceapply.NewResourceCache() var results []resourceapply.ApplyResult switch { - case c.nilapiExtensionClient && c.nilapiRegistratonClient: - results = ApplyDirectly( - context.TODO(), - fakeKubeClient, nil, nil, - eventstesting.NewTestingEventRecorder(t), - cache, - fakeApplyFunc, - c.applyFileNames..., - ) case c.nilapiExtensionClient: results = ApplyDirectly( context.TODO(), - fakeKubeClient, nil, fakeResgistrationClient, - eventstesting.NewTestingEventRecorder(t), - cache, - fakeApplyFunc, - c.applyFileNames..., - ) - case c.nilapiRegistratonClient: - results = ApplyDirectly( - context.TODO(), - fakeKubeClient, fakeExtensionClient, nil, + fakeKubeClient, nil, eventstesting.NewTestingEventRecorder(t), cache, fakeApplyFunc, @@ -518,7 +475,7 @@ func TestApplyDirectly(t *testing.T) { default: results = ApplyDirectly( context.TODO(), - fakeKubeClient, fakeExtensionClient, fakeResgistrationClient, + fakeKubeClient, fakeExtensionClient, eventstesting.NewTestingEventRecorder(t), cache, fakeApplyFunc, @@ -547,17 +504,15 @@ func TestDeleteStaticObject(t *testing.T) { applyFiles := map[string]runtime.Object{ "validatingwebhooks": newUnstructured("admissionregistration.k8s.io/v1", "ValidatingWebhookConfiguration", "", "", map[string]interface{}{"webhooks": []interface{}{}}), "mutatingwebhooks": newUnstructured("admissionregistration.k8s.io/v1", "MutatingWebhookConfiguration", "", "", map[string]interface{}{"webhooks": []interface{}{}}), - "apiservice": newUnstructured("apiregistration.k8s.io/v1", "APIService", "", "", map[string]interface{}{"spec": map[string]interface{}{"service": map[string]string{"name": "svc1", "namespace": "svc1"}}}), "secret": newUnstructured("v1", "Secret", "ns1", "n1", map[string]interface{}{"data": map[string]interface{}{"key1": []byte("key1")}}), "crd": newUnstructured("apiextensions.k8s.io/v1beta1", "CustomResourceDefinition", "", "", map[string]interface{}{}), "kind1": newUnstructured("v1", "Kind1", "ns1", "n1", map[string]interface{}{"spec": map[string]interface{}{"key1": []byte("key1")}}), } testcase := []struct { - name string - applyFileName string - expectErr bool - nilapiExtensionClient bool - nilapiRegistrationClient bool + name string + applyFileName string + expectErr bool + nilapiExtensionClient bool }{ { name: "Delete validating webhooks", @@ -569,17 +524,6 @@ func TestDeleteStaticObject(t *testing.T) { applyFileName: "mutatingwebhooks", expectErr: false, }, - { - name: "Delete apiservice", - applyFileName: "apiservice", - expectErr: false, - }, - { - name: "Delete apiservice with nil apiRegistrationClient", - applyFileName: "apiservice", - nilapiRegistrationClient: true, - expectErr: true, - }, { name: "Delete secret", applyFileName: "secret", @@ -618,13 +562,6 @@ func TestDeleteStaticObject(t *testing.T) { var err error switch { - case c.nilapiExtensionClient && c.nilapiRegistrationClient: - err = CleanUpStaticObject( - context.TODO(), - fakeKubeClient, nil, nil, - fakeAssetFunc, - c.applyFileName, - ) case c.nilapiExtensionClient: err = CleanUpStaticObject( context.TODO(), @@ -632,13 +569,6 @@ func TestDeleteStaticObject(t *testing.T) { fakeAssetFunc, c.applyFileName, ) - case c.nilapiRegistrationClient: - err = CleanUpStaticObject( - context.TODO(), - fakeKubeClient, fakeExtensionClient, nil, - fakeAssetFunc, - c.applyFileName, - ) default: err = CleanUpStaticObject( context.TODO(), diff --git a/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_controller.go b/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_controller.go index 756fda70c..48ebfeba8 100644 --- a/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_controller.go +++ b/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_controller.go @@ -3,6 +3,7 @@ package clustermanagercontroller import ( "context" "encoding/base64" + utilerrors "k8s.io/apimachinery/pkg/util/errors" errorhelpers "errors" @@ -14,7 +15,6 @@ import ( "k8s.io/client-go/kubernetes" "k8s.io/client-go/rest" "k8s.io/klog/v2" - apiregistrationclient "k8s.io/kube-aggregator/pkg/client/clientset_generated/clientset/typed/apiregistration/v1" "github.com/openshift/library-go/pkg/controller/factory" "github.com/openshift/library-go/pkg/operator/events" @@ -55,7 +55,7 @@ type clusterManagerController struct { cache resourceapply.ResourceCache // For testcases which don't need these functions, we could set fake funcs ensureSAKubeconfigs func(ctx context.Context, clusterManagerName, clusterManagerNamespace string, hubConfig *rest.Config, hubClient, managementClient kubernetes.Interface, recorder events.Recorder) error - generateHubClusterClients func(hubConfig *rest.Config) (kubernetes.Interface, apiextensionsclient.Interface, apiregistrationclient.APIServicesGetter, migrationclient.StorageVersionMigrationsGetter, error) + generateHubClusterClients func(hubConfig *rest.Config) (kubernetes.Interface, apiextensionsclient.Interface, migrationclient.StorageVersionMigrationsGetter, error) skipRemoveCRDs bool } @@ -185,7 +185,7 @@ func (n *clusterManagerController) sync(ctx context.Context, controllerContext f if err != nil { return err } - hubClient, hubApiExtensionClient, hubApiRegistrationClient, hubMigrationClient, err := n.generateHubClusterClients(hubKubeConfig) + hubClient, hubApiExtensionClient, hubMigrationClient, err := n.generateHubClusterClients(hubKubeConfig) if err != nil { return err } @@ -194,7 +194,7 @@ func (n *clusterManagerController) sync(ctx context.Context, controllerContext f var errs []error reconcilers := []clusterManagerReconcile{ &crdReconcile{cache: n.cache, recorder: n.recorder, hubAPIExtensionClient: hubApiExtensionClient, hubMigrationClient: hubMigrationClient, skipRemoveCRDs: n.skipRemoveCRDs}, - &hubReoncile{cache: n.cache, recorder: n.recorder, hubKubeClient: hubClient, hubAPIRegistrationClient: hubApiRegistrationClient}, + &hubReoncile{cache: n.cache, recorder: n.recorder, hubKubeClient: hubClient}, &runtimeReconcile{cache: n.cache, recorder: n.recorder, hubKubeConfig: hubKubeConfig, hubKubeClient: hubClient, kubeClient: managementClient, ensureSAKubeconfigs: n.ensureSAKubeconfigs}, &webhookReconcile{cache: n.cache, recorder: n.recorder, hubKubeClient: hubClient, kubeClient: managementClient}, } @@ -313,24 +313,21 @@ func removeClusterManagerFinalizer(ctx context.Context, clusterManagerClient ope return nil } -func generateHubClients(hubKubeConfig *rest.Config) (kubernetes.Interface, apiextensionsclient.Interface, apiregistrationclient.APIServicesGetter, migrationclient.StorageVersionMigrationsGetter, error) { +func generateHubClients(hubKubeConfig *rest.Config) (kubernetes.Interface, apiextensionsclient.Interface, migrationclient.StorageVersionMigrationsGetter, error) { hubClient, err := kubernetes.NewForConfig(hubKubeConfig) if err != nil { - return nil, nil, nil, nil, err + return nil, nil, nil, err } hubApiExtensionClient, err := apiextensionsclient.NewForConfig(hubKubeConfig) if err != nil { - return nil, nil, nil, nil, err - } - hubApiRegistrationClient, err := apiregistrationclient.NewForConfig(hubKubeConfig) - if err != nil { - return nil, nil, nil, nil, err + return nil, nil, nil, err } + hubMigrationClient, err := migrationclient.NewForConfig(hubKubeConfig) if err != nil { - return nil, nil, nil, nil, err + return nil, nil, nil, err } - return hubClient, hubApiExtensionClient, hubApiRegistrationClient, hubMigrationClient, nil + return hubClient, hubApiExtensionClient, hubMigrationClient, nil } // ensureSAKubeconfigs is used to create a kubeconfig with a token from a ServiceAccount. diff --git a/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_controller_test.go b/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_controller_test.go index 53a1bb625..691aca676 100644 --- a/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_controller_test.go +++ b/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_controller_test.go @@ -23,8 +23,6 @@ import ( fakekube "k8s.io/client-go/kubernetes/fake" "k8s.io/client-go/rest" clienttesting "k8s.io/client-go/testing" - fakeapiregistration "k8s.io/kube-aggregator/pkg/client/clientset_generated/clientset/fake" - apiregistrationclient "k8s.io/kube-aggregator/pkg/client/clientset_generated/clientset/typed/apiregistration/v1" fakeoperatorlient "open-cluster-management.io/api/client/operator/clientset/versioned/fake" operatorinformers "open-cluster-management.io/api/client/operator/informers/externalversions" operatorapiv1 "open-cluster-management.io/api/operator/v1" @@ -44,7 +42,6 @@ type testController struct { managementKubeClient *fakekube.Clientset hubKubeClient *fakekube.Clientset apiExtensionClient *fakeapiextensions.Clientset - apiRegistrationClient *fakeapiregistration.Clientset operatorClient *fakeoperatorlient.Clientset } @@ -190,20 +187,18 @@ func setup(t *testing.T, tc *testController, cd []runtime.Object, crds ...runtim fakeHubKubeClient := fakekube.NewSimpleClientset() fakeManagementKubeClient := fakekube.NewSimpleClientset(cd...) fakeAPIExtensionClient := fakeapiextensions.NewSimpleClientset(crds...) - fakeAPIRegistrationClient := fakeapiregistration.NewSimpleClientset() fakeMigrationClient := fakemigrationclient.NewSimpleClientset() // set clients in test controller tc.apiExtensionClient = fakeAPIExtensionClient - tc.apiRegistrationClient = fakeAPIRegistrationClient tc.hubKubeClient = fakeHubKubeClient tc.managementKubeClient = fakeManagementKubeClient // set clients in clustermanager controller tc.clusterManagerController.recorder = eventstesting.NewTestingEventRecorder(t) tc.clusterManagerController.operatorKubeClient = fakeManagementKubeClient - tc.clusterManagerController.generateHubClusterClients = func(hubKubeConfig *rest.Config) (kubernetes.Interface, apiextensionsclient.Interface, apiregistrationclient.APIServicesGetter, migrationclient.StorageVersionMigrationsGetter, error) { - return fakeHubKubeClient, fakeAPIExtensionClient, fakeAPIRegistrationClient.ApiregistrationV1(), fakeMigrationClient.MigrationV1alpha1(), nil + tc.clusterManagerController.generateHubClusterClients = func(hubKubeConfig *rest.Config) (kubernetes.Interface, apiextensionsclient.Interface, migrationclient.StorageVersionMigrationsGetter, error) { + return fakeHubKubeClient, fakeAPIExtensionClient, fakeMigrationClient.MigrationV1alpha1(), nil } tc.clusterManagerController.ensureSAKubeconfigs = func(ctx context.Context, clusterManagerName, clusterManagerNamespace string, hubConfig *rest.Config, hubClient, managementClient kubernetes.Interface, recorder events.Recorder) error { return nil @@ -350,17 +345,6 @@ func TestSyncDelete(t *testing.T) { // Check if resources are created as expected testinghelper.AssertEqualNumber(t, len(deleteCRDActions), 13) - deleteAPIServiceActions := []clienttesting.DeleteActionImpl{} - apiServiceActions := tc.apiRegistrationClient.Actions() - for _, action := range apiServiceActions { - if action.GetVerb() == "delete" { - deleteAPIServiceAction := action.(clienttesting.DeleteActionImpl) - deleteAPIServiceActions = append(deleteAPIServiceActions, deleteAPIServiceAction) - } - } - // Check if resources are created as expected - testinghelper.AssertEqualNumber(t, len(deleteAPIServiceActions), 2) - for _, action := range deleteKubeActions { switch action.Resource.Resource { case "namespaces": diff --git a/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_hub_reconcile.go b/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_hub_reconcile.go index c265f1373..82e1bfba4 100644 --- a/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_hub_reconcile.go +++ b/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_hub_reconcile.go @@ -7,6 +7,7 @@ package clustermanagercontroller import ( "context" "fmt" + "github.com/openshift/library-go/pkg/assets" "github.com/openshift/library-go/pkg/operator/events" "github.com/openshift/library-go/pkg/operator/resource/resourceapply" @@ -14,7 +15,6 @@ import ( metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" utilerrors "k8s.io/apimachinery/pkg/util/errors" "k8s.io/client-go/kubernetes" - apiregistrationclient "k8s.io/kube-aggregator/pkg/client/clientset_generated/clientset/typed/apiregistration/v1" operatorapiv1 "open-cluster-management.io/api/operator/v1" "open-cluster-management.io/registration-operator/manifests" "open-cluster-management.io/registration-operator/pkg/helpers" @@ -56,20 +56,12 @@ var ( // hubHostedWebhookEndpointFiles only apply when the deploy mode is hosted and address is IPFormat. hubHostedWebhookEndpointRegistration = "cluster-manager/hub/cluster-manager-registration-webhook-endpoint-hosted.yaml" hubHostedWebhookEndpointWork = "cluster-manager/hub/cluster-manager-work-webhook-endpoint-hosted.yaml" - - // The apiservice resources should be deleted - hubApiserviceFiles = []string{ - "cluster-manager/hub/cluster-manager-work-webhook-apiservice.yaml", - "cluster-manager/hub/cluster-manager-registration-webhook-apiservice.yaml", - } ) type hubReoncile struct { - hubKubeClient kubernetes.Interface - hubAPIRegistrationClient apiregistrationclient.APIServicesGetter - - cache resourceapply.ResourceCache - recorder events.Recorder + hubKubeClient kubernetes.Interface + cache resourceapply.ResourceCache + recorder events.Recorder } func (c *hubReoncile) reconcile(ctx context.Context, cm *operatorapiv1.ClusterManager, config manifests.HubConfig) (*operatorapiv1.ClusterManager, reconcileState, error) { @@ -80,7 +72,6 @@ func (c *hubReoncile) reconcile(ctx context.Context, cm *operatorapiv1.ClusterMa ctx, c.hubKubeClient, nil, - nil, c.recorder, c.cache, func(name string) ([]byte, error) { @@ -115,15 +106,12 @@ func (c *hubReoncile) reconcile(ctx context.Context, cm *operatorapiv1.ClusterMa func (c *hubReoncile) clean(ctx context.Context, cm *operatorapiv1.ClusterManager, config manifests.HubConfig) (*operatorapiv1.ClusterManager, reconcileState, error) { hubResources := getHubResources(cm.Spec.DeployOption.Mode, config) - // TODO apiservice is added only to ensure they are removed when cleanup. this code should be removed later - hubResources = append(hubResources, hubApiserviceFiles...) - for _, file := range hubResources { err := helpers.CleanUpStaticObject( ctx, c.hubKubeClient, nil, - c.hubAPIRegistrationClient, + nil, func(name string) ([]byte, error) { template, err := manifests.ClusterManagerManifestFiles.ReadFile(name) if err != nil { diff --git a/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_runtime_reconcile.go b/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_runtime_reconcile.go index 6149b73cc..00513807f 100644 --- a/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_runtime_reconcile.go +++ b/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_runtime_reconcile.go @@ -7,6 +7,8 @@ package clustermanagercontroller import ( "context" "fmt" + "strings" + "github.com/openshift/library-go/pkg/assets" "github.com/openshift/library-go/pkg/operator/events" "github.com/openshift/library-go/pkg/operator/resource/resourceapply" @@ -18,7 +20,6 @@ import ( operatorapiv1 "open-cluster-management.io/api/operator/v1" "open-cluster-management.io/registration-operator/manifests" "open-cluster-management.io/registration-operator/pkg/helpers" - "strings" ) var ( @@ -68,7 +69,7 @@ func (c *runtimeReconcile) reconcile(ctx context.Context, cm *operatorapiv1.Clus var appliedErrs []error resourceResults := helpers.ApplyDirectly( ctx, - c.kubeClient, nil, nil, + c.kubeClient, nil, c.recorder, c.cache, func(name string) ([]byte, error) { diff --git a/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_webhook_reconcile.go b/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_webhook_reconcile.go index 8e4ca6fa4..9be4e4430 100644 --- a/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_webhook_reconcile.go +++ b/pkg/operators/clustermanager/controllers/clustermanagercontroller/clustermanager_webhook_reconcile.go @@ -7,6 +7,7 @@ package clustermanagercontroller import ( "context" "fmt" + "github.com/openshift/library-go/pkg/assets" "github.com/openshift/library-go/pkg/operator/events" "github.com/openshift/library-go/pkg/operator/resource/resourceapply" @@ -55,7 +56,6 @@ func (c *webhookReconcile) reconcile(ctx context.Context, cm *operatorapiv1.Clus ctx, c.hubKubeClient, nil, - nil, c.recorder, c.cache, func(name string) ([]byte, error) { diff --git a/pkg/operators/klusterlet/controllers/klusterletcontroller/klusterlet_managed_reconcile.go b/pkg/operators/klusterlet/controllers/klusterletcontroller/klusterlet_managed_reconcile.go index 7b941765b..974e8e42a 100644 --- a/pkg/operators/klusterlet/controllers/klusterletcontroller/klusterlet_managed_reconcile.go +++ b/pkg/operators/klusterlet/controllers/klusterletcontroller/klusterlet_managed_reconcile.go @@ -93,7 +93,6 @@ func (r *managedReconcile) reconcile(ctx context.Context, klusterlet *operatorap ctx, r.managedClusterClients.kubeClient, r.managedClusterClients.apiExtensionClient, - nil, r.recorder, r.cache, func(name string) ([]byte, error) { diff --git a/pkg/operators/klusterlet/controllers/klusterletcontroller/klusterlet_management_recocile.go b/pkg/operators/klusterlet/controllers/klusterletcontroller/klusterlet_management_recocile.go index 5c4772ab2..14c75f3ee 100644 --- a/pkg/operators/klusterlet/controllers/klusterletcontroller/klusterlet_management_recocile.go +++ b/pkg/operators/klusterlet/controllers/klusterletcontroller/klusterlet_management_recocile.go @@ -7,6 +7,7 @@ package klusterletcontroller import ( "context" "fmt" + "github.com/openshift/library-go/pkg/assets" "github.com/openshift/library-go/pkg/operator/events" "github.com/openshift/library-go/pkg/operator/resource/resourceapply" @@ -59,7 +60,6 @@ func (r *managementReconcile) reconcile(ctx context.Context, klusterlet *operato ctx, r.kubeClient, nil, - nil, r.recorder, r.cache, func(name string) ([]byte, error) {