Add sidecar profile (#192)

This change adds a new SidecarProfile resource which allows configuring
client sidecar injection into pods. It replaces the older annotation
based solution. This removes any pod specific configuration from the
setup key and puts it all in this side car configuration.

Fixes #188

Signed-off-by: Philip Laine <philip.laine@gmail.com>
This commit is contained in:
Philip Laine
2026-04-23 19:17:53 +02:00
committed by GitHub
parent 876a0e1eb3
commit 9838f0dccc
14 changed files with 1447 additions and 29 deletions
@@ -0,0 +1,48 @@
// Code generated by controller-gen. DO NOT EDIT.
package v1alpha1
import (
v1 "k8s.io/api/core/v1"
)
// ContainerOverrideApplyConfiguration represents a declarative configuration of the ContainerOverride type for use
// with apply.
type ContainerOverrideApplyConfiguration struct {
// Image overrides the image used by the client.
Image *string `json:"image,omitempty"`
Env []v1.EnvVar `json:"env,omitempty"`
SecurityContext *v1.SecurityContext `json:"securityContext,omitempty"`
}
// ContainerOverrideApplyConfiguration constructs a declarative configuration of the ContainerOverride type for use with
// apply.
func ContainerOverride() *ContainerOverrideApplyConfiguration {
return &ContainerOverrideApplyConfiguration{}
}
// WithImage sets the Image field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the Image field is set to the value of the last call.
func (b *ContainerOverrideApplyConfiguration) WithImage(value string) *ContainerOverrideApplyConfiguration {
b.Image = &value
return b
}
// WithEnv adds the given value to the Env field in the declarative configuration
// and returns the receiver, so that objects can be build by chaining "With" function invocations.
// If called multiple times, values provided by each call will be appended to the Env field.
func (b *ContainerOverrideApplyConfiguration) WithEnv(values ...v1.EnvVar) *ContainerOverrideApplyConfiguration {
for i := range values {
b.Env = append(b.Env, values[i])
}
return b
}
// WithSecurityContext sets the SecurityContext field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the SecurityContext field is set to the value of the last call.
func (b *ContainerOverrideApplyConfiguration) WithSecurityContext(value v1.SecurityContext) *ContainerOverrideApplyConfiguration {
b.SecurityContext = &value
return b
}
@@ -0,0 +1,229 @@
// Code generated by controller-gen. DO NOT EDIT.
package v1alpha1
import (
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
types "k8s.io/apimachinery/pkg/types"
v1 "k8s.io/client-go/applyconfigurations/meta/v1"
)
// SidecarProfileApplyConfiguration represents a declarative configuration of the SidecarProfile type for use
// with apply.
//
// SidecarProfile is the Schema for the sidecarprofiles API.
type SidecarProfileApplyConfiguration struct {
v1.TypeMetaApplyConfiguration `json:",inline"`
*v1.ObjectMetaApplyConfiguration `json:"metadata,omitempty"`
Spec *SidecarProfileSpecApplyConfiguration `json:"spec,omitempty"`
Status *SidecarProfileStatusApplyConfiguration `json:"status,omitempty"`
}
// SidecarProfile constructs a declarative configuration of the SidecarProfile type for use with
// apply.
func SidecarProfile(name, namespace string) *SidecarProfileApplyConfiguration {
b := &SidecarProfileApplyConfiguration{}
b.WithName(name)
b.WithNamespace(namespace)
b.WithKind("SidecarProfile")
b.WithAPIVersion("netbird.io/v1alpha1")
return b
}
func (b SidecarProfileApplyConfiguration) IsApplyConfiguration() {}
// WithKind sets the Kind field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the Kind field is set to the value of the last call.
func (b *SidecarProfileApplyConfiguration) WithKind(value string) *SidecarProfileApplyConfiguration {
b.TypeMetaApplyConfiguration.Kind = &value
return b
}
// WithAPIVersion sets the APIVersion field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the APIVersion field is set to the value of the last call.
func (b *SidecarProfileApplyConfiguration) WithAPIVersion(value string) *SidecarProfileApplyConfiguration {
b.TypeMetaApplyConfiguration.APIVersion = &value
return b
}
// WithName sets the Name field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the Name field is set to the value of the last call.
func (b *SidecarProfileApplyConfiguration) WithName(value string) *SidecarProfileApplyConfiguration {
b.ensureObjectMetaApplyConfigurationExists()
b.ObjectMetaApplyConfiguration.Name = &value
return b
}
// WithGenerateName sets the GenerateName field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the GenerateName field is set to the value of the last call.
func (b *SidecarProfileApplyConfiguration) WithGenerateName(value string) *SidecarProfileApplyConfiguration {
b.ensureObjectMetaApplyConfigurationExists()
b.ObjectMetaApplyConfiguration.GenerateName = &value
return b
}
// WithNamespace sets the Namespace field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the Namespace field is set to the value of the last call.
func (b *SidecarProfileApplyConfiguration) WithNamespace(value string) *SidecarProfileApplyConfiguration {
b.ensureObjectMetaApplyConfigurationExists()
b.ObjectMetaApplyConfiguration.Namespace = &value
return b
}
// WithUID sets the UID field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the UID field is set to the value of the last call.
func (b *SidecarProfileApplyConfiguration) WithUID(value types.UID) *SidecarProfileApplyConfiguration {
b.ensureObjectMetaApplyConfigurationExists()
b.ObjectMetaApplyConfiguration.UID = &value
return b
}
// WithResourceVersion sets the ResourceVersion field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the ResourceVersion field is set to the value of the last call.
func (b *SidecarProfileApplyConfiguration) WithResourceVersion(value string) *SidecarProfileApplyConfiguration {
b.ensureObjectMetaApplyConfigurationExists()
b.ObjectMetaApplyConfiguration.ResourceVersion = &value
return b
}
// WithGeneration sets the Generation field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the Generation field is set to the value of the last call.
func (b *SidecarProfileApplyConfiguration) WithGeneration(value int64) *SidecarProfileApplyConfiguration {
b.ensureObjectMetaApplyConfigurationExists()
b.ObjectMetaApplyConfiguration.Generation = &value
return b
}
// WithCreationTimestamp sets the CreationTimestamp field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the CreationTimestamp field is set to the value of the last call.
func (b *SidecarProfileApplyConfiguration) WithCreationTimestamp(value metav1.Time) *SidecarProfileApplyConfiguration {
b.ensureObjectMetaApplyConfigurationExists()
b.ObjectMetaApplyConfiguration.CreationTimestamp = &value
return b
}
// WithDeletionTimestamp sets the DeletionTimestamp field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the DeletionTimestamp field is set to the value of the last call.
func (b *SidecarProfileApplyConfiguration) WithDeletionTimestamp(value metav1.Time) *SidecarProfileApplyConfiguration {
b.ensureObjectMetaApplyConfigurationExists()
b.ObjectMetaApplyConfiguration.DeletionTimestamp = &value
return b
}
// WithDeletionGracePeriodSeconds sets the DeletionGracePeriodSeconds field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the DeletionGracePeriodSeconds field is set to the value of the last call.
func (b *SidecarProfileApplyConfiguration) WithDeletionGracePeriodSeconds(value int64) *SidecarProfileApplyConfiguration {
b.ensureObjectMetaApplyConfigurationExists()
b.ObjectMetaApplyConfiguration.DeletionGracePeriodSeconds = &value
return b
}
// WithLabels puts the entries into the Labels field in the declarative configuration
// and returns the receiver, so that objects can be build by chaining "With" function invocations.
// If called multiple times, the entries provided by each call will be put on the Labels field,
// overwriting an existing map entries in Labels field with the same key.
func (b *SidecarProfileApplyConfiguration) WithLabels(entries map[string]string) *SidecarProfileApplyConfiguration {
b.ensureObjectMetaApplyConfigurationExists()
if b.ObjectMetaApplyConfiguration.Labels == nil && len(entries) > 0 {
b.ObjectMetaApplyConfiguration.Labels = make(map[string]string, len(entries))
}
for k, v := range entries {
b.ObjectMetaApplyConfiguration.Labels[k] = v
}
return b
}
// WithAnnotations puts the entries into the Annotations field in the declarative configuration
// and returns the receiver, so that objects can be build by chaining "With" function invocations.
// If called multiple times, the entries provided by each call will be put on the Annotations field,
// overwriting an existing map entries in Annotations field with the same key.
func (b *SidecarProfileApplyConfiguration) WithAnnotations(entries map[string]string) *SidecarProfileApplyConfiguration {
b.ensureObjectMetaApplyConfigurationExists()
if b.ObjectMetaApplyConfiguration.Annotations == nil && len(entries) > 0 {
b.ObjectMetaApplyConfiguration.Annotations = make(map[string]string, len(entries))
}
for k, v := range entries {
b.ObjectMetaApplyConfiguration.Annotations[k] = v
}
return b
}
// WithOwnerReferences adds the given value to the OwnerReferences field in the declarative configuration
// and returns the receiver, so that objects can be build by chaining "With" function invocations.
// If called multiple times, values provided by each call will be appended to the OwnerReferences field.
func (b *SidecarProfileApplyConfiguration) WithOwnerReferences(values ...*v1.OwnerReferenceApplyConfiguration) *SidecarProfileApplyConfiguration {
b.ensureObjectMetaApplyConfigurationExists()
for i := range values {
if values[i] == nil {
panic("nil value passed to WithOwnerReferences")
}
b.ObjectMetaApplyConfiguration.OwnerReferences = append(b.ObjectMetaApplyConfiguration.OwnerReferences, *values[i])
}
return b
}
// WithFinalizers adds the given value to the Finalizers field in the declarative configuration
// and returns the receiver, so that objects can be build by chaining "With" function invocations.
// If called multiple times, values provided by each call will be appended to the Finalizers field.
func (b *SidecarProfileApplyConfiguration) WithFinalizers(values ...string) *SidecarProfileApplyConfiguration {
b.ensureObjectMetaApplyConfigurationExists()
for i := range values {
b.ObjectMetaApplyConfiguration.Finalizers = append(b.ObjectMetaApplyConfiguration.Finalizers, values[i])
}
return b
}
func (b *SidecarProfileApplyConfiguration) ensureObjectMetaApplyConfigurationExists() {
if b.ObjectMetaApplyConfiguration == nil {
b.ObjectMetaApplyConfiguration = &v1.ObjectMetaApplyConfiguration{}
}
}
// WithSpec sets the Spec field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the Spec field is set to the value of the last call.
func (b *SidecarProfileApplyConfiguration) WithSpec(value *SidecarProfileSpecApplyConfiguration) *SidecarProfileApplyConfiguration {
b.Spec = value
return b
}
// WithStatus sets the Status field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the Status field is set to the value of the last call.
func (b *SidecarProfileApplyConfiguration) WithStatus(value *SidecarProfileStatusApplyConfiguration) *SidecarProfileApplyConfiguration {
b.Status = value
return b
}
// GetKind retrieves the value of the Kind field in the declarative configuration.
func (b *SidecarProfileApplyConfiguration) GetKind() *string {
return b.TypeMetaApplyConfiguration.Kind
}
// GetAPIVersion retrieves the value of the APIVersion field in the declarative configuration.
func (b *SidecarProfileApplyConfiguration) GetAPIVersion() *string {
return b.TypeMetaApplyConfiguration.APIVersion
}
// GetName retrieves the value of the Name field in the declarative configuration.
func (b *SidecarProfileApplyConfiguration) GetName() *string {
b.ensureObjectMetaApplyConfigurationExists()
return b.ObjectMetaApplyConfiguration.Name
}
// GetNamespace retrieves the value of the Namespace field in the declarative configuration.
func (b *SidecarProfileApplyConfiguration) GetNamespace() *string {
b.ensureObjectMetaApplyConfigurationExists()
return b.ObjectMetaApplyConfiguration.Namespace
}
@@ -0,0 +1,74 @@
// Code generated by controller-gen. DO NOT EDIT.
package v1alpha1
import (
apiv1alpha1 "github.com/netbirdio/kubernetes-operator/api/v1alpha1"
v1 "k8s.io/api/core/v1"
metav1 "k8s.io/client-go/applyconfigurations/meta/v1"
)
// SidecarProfileSpecApplyConfiguration represents a declarative configuration of the SidecarProfileSpec type for use
// with apply.
//
// SidecarProfileSpec defines the desired state of SidecarProfile.
type SidecarProfileSpecApplyConfiguration struct {
// SetupKeyRef is the reference to the setup key used in the client.
SetupKeyRef *v1.LocalObjectReference `json:"setupKeyRef,omitempty"`
// PodSelector determines which pods the profile should apply to.
// An empty slector means the profile will apply to all pods in the namespace.
PodSelector *metav1.LabelSelectorApplyConfiguration `json:"podSelector,omitempty"`
// InjectionMode defines whether the sidecar is injected as a native Kubernetes sidecar container or as a regular container.
InjectionMode *apiv1alpha1.InjectionMode `json:"injectionMode,omitempty"`
// ExtraDNSLabels assigns additional DNS names to peers beyond their default hostname.
ExtraDNSLabels []string `json:"extraDNSLabels,omitempty"`
ContainerOverride *ContainerOverrideApplyConfiguration `json:"containerOverride,omitempty"`
}
// SidecarProfileSpecApplyConfiguration constructs a declarative configuration of the SidecarProfileSpec type for use with
// apply.
func SidecarProfileSpec() *SidecarProfileSpecApplyConfiguration {
return &SidecarProfileSpecApplyConfiguration{}
}
// WithSetupKeyRef sets the SetupKeyRef field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the SetupKeyRef field is set to the value of the last call.
func (b *SidecarProfileSpecApplyConfiguration) WithSetupKeyRef(value v1.LocalObjectReference) *SidecarProfileSpecApplyConfiguration {
b.SetupKeyRef = &value
return b
}
// WithPodSelector sets the PodSelector field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the PodSelector field is set to the value of the last call.
func (b *SidecarProfileSpecApplyConfiguration) WithPodSelector(value *metav1.LabelSelectorApplyConfiguration) *SidecarProfileSpecApplyConfiguration {
b.PodSelector = value
return b
}
// WithInjectionMode sets the InjectionMode field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the InjectionMode field is set to the value of the last call.
func (b *SidecarProfileSpecApplyConfiguration) WithInjectionMode(value apiv1alpha1.InjectionMode) *SidecarProfileSpecApplyConfiguration {
b.InjectionMode = &value
return b
}
// WithExtraDNSLabels adds the given value to the ExtraDNSLabels field in the declarative configuration
// and returns the receiver, so that objects can be build by chaining "With" function invocations.
// If called multiple times, values provided by each call will be appended to the ExtraDNSLabels field.
func (b *SidecarProfileSpecApplyConfiguration) WithExtraDNSLabels(values ...string) *SidecarProfileSpecApplyConfiguration {
for i := range values {
b.ExtraDNSLabels = append(b.ExtraDNSLabels, values[i])
}
return b
}
// WithContainerOverride sets the ContainerOverride field in the declarative configuration to the given value
// and returns the receiver, so that objects can be built by chaining "With" function invocations.
// If called multiple times, the ContainerOverride field is set to the value of the last call.
func (b *SidecarProfileSpecApplyConfiguration) WithContainerOverride(value *ContainerOverrideApplyConfiguration) *SidecarProfileSpecApplyConfiguration {
b.ContainerOverride = value
return b
}
@@ -0,0 +1,35 @@
// Code generated by controller-gen. DO NOT EDIT.
package v1alpha1
import (
v1 "k8s.io/client-go/applyconfigurations/meta/v1"
)
// SidecarProfileStatusApplyConfiguration represents a declarative configuration of the SidecarProfileStatus type for use
// with apply.
//
// SidecarProfileStatus defines the observed state of SidecarProfile.
type SidecarProfileStatusApplyConfiguration struct {
// Conditions holds the conditions for the SidecarProfile.
Conditions []v1.ConditionApplyConfiguration `json:"conditions,omitempty"`
}
// SidecarProfileStatusApplyConfiguration constructs a declarative configuration of the SidecarProfileStatus type for use with
// apply.
func SidecarProfileStatus() *SidecarProfileStatusApplyConfiguration {
return &SidecarProfileStatusApplyConfiguration{}
}
// WithConditions adds the given value to the Conditions field in the declarative configuration
// and returns the receiver, so that objects can be build by chaining "With" function invocations.
// If called multiple times, values provided by each call will be appended to the Conditions field.
func (b *SidecarProfileStatusApplyConfiguration) WithConditions(values ...*v1.ConditionApplyConfiguration) *SidecarProfileStatusApplyConfiguration {
for i := range values {
if values[i] == nil {
panic("nil value passed to WithConditions")
}
b.Conditions = append(b.Conditions, *values[i])
}
return b
}
+8
View File
@@ -16,6 +16,8 @@ import (
func ForKind(kind schema.GroupVersionKind) interface{} {
switch kind {
// Group=netbird.io, Version=v1alpha1
case v1alpha1.SchemeGroupVersion.WithKind("ContainerOverride"):
return &apiv1alpha1.ContainerOverrideApplyConfiguration{}
case v1alpha1.SchemeGroupVersion.WithKind("CrossNamespaceReference"):
return &apiv1alpha1.CrossNamespaceReferenceApplyConfiguration{}
case v1alpha1.SchemeGroupVersion.WithKind("DNSZoneReference"):
@@ -46,6 +48,12 @@ func ForKind(kind schema.GroupVersionKind) interface{} {
return &apiv1alpha1.SetupKeySpecApplyConfiguration{}
case v1alpha1.SchemeGroupVersion.WithKind("SetupKeyStatus"):
return &apiv1alpha1.SetupKeyStatusApplyConfiguration{}
case v1alpha1.SchemeGroupVersion.WithKind("SidecarProfile"):
return &apiv1alpha1.SidecarProfileApplyConfiguration{}
case v1alpha1.SchemeGroupVersion.WithKind("SidecarProfileSpec"):
return &apiv1alpha1.SidecarProfileSpecApplyConfiguration{}
case v1alpha1.SchemeGroupVersion.WithKind("SidecarProfileStatus"):
return &apiv1alpha1.SidecarProfileStatusApplyConfiguration{}
case v1alpha1.SchemeGroupVersion.WithKind("WorkloadOverride"):
return &apiv1alpha1.WorkloadOverrideApplyConfiguration{}