Skip to content

Commit 3fdf9f9

Browse files
committed
Add support for a chunked release storage driver
This commit adds a custom helm release storage driver that overcomes limitations in the size of a single value that can be stored in etcd. In order to remain backward-compatible and also make this storage driver available, this commit also refactors the ActionConfigGetter options so that a custom function can be provided to the ActionConfigGetter that can create the desired storage driver. This commit also separates the rest config mapping into two separate options. One for interactions with the storage backend, and the other for managing release content. Signed-off-by: Joe Lanford <[email protected]>
1 parent 20a5c31 commit 3fdf9f9

File tree

3 files changed

+597
-37
lines changed

3 files changed

+597
-37
lines changed

pkg/client/actionconfig.go

Lines changed: 137 additions & 37 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,8 @@ import (
3333
v1 "k8s.io/client-go/kubernetes/typed/core/v1"
3434
"k8s.io/client-go/rest"
3535
"sigs.k8s.io/controller-runtime/pkg/client"
36+
37+
customstorage "github.com/operator-framework/helm-operator-plugins/pkg/storage"
3638
)
3739

3840
type ActionConfigGetter interface {
@@ -57,14 +59,25 @@ func NewActionConfigGetter(baseRestConfig *rest.Config, rm meta.RESTMapper, opts
5759
if acg.objectToClientNamespace == nil {
5860
acg.objectToClientNamespace = getObjectNamespace
5961
}
60-
if acg.objectToStorageNamespace == nil {
61-
acg.objectToStorageNamespace = getObjectNamespace
62+
if acg.objectToClientRestConfig == nil {
63+
acg.objectToClientRestConfig = func(_ context.Context, _ client.Object, baseRestConfig *rest.Config) (*rest.Config, error) {
64+
return rest.CopyConfig(baseRestConfig), nil
65+
}
6266
}
63-
if acg.objectToRestConfig == nil {
64-
acg.objectToRestConfig = func(_ context.Context, _ client.Object, baseRestConfig *rest.Config) (*rest.Config, error) {
67+
if acg.objectToStorageRestConfig == nil {
68+
acg.objectToStorageRestConfig = func(_ context.Context, _ client.Object, baseRestConfig *rest.Config) (*rest.Config, error) {
6569
return rest.CopyConfig(baseRestConfig), nil
6670
}
6771
}
72+
if acg.objectToStorageDriver == nil {
73+
if acg.objectToStorageNamespace == nil {
74+
acg.objectToStorageNamespace = getObjectNamespace
75+
}
76+
acg.objectToStorageDriver = DefaultSecretsStorageDriver(SecretsStorageDriverOpts{
77+
DisableOwnerRefInjection: acg.disableStorageOwnerRefInjection,
78+
StorageNamespaceMapper: acg.objectToStorageNamespace,
79+
})
80+
}
6881
return acg, nil
6982
}
7083

@@ -73,28 +86,52 @@ var _ ActionConfigGetter = &actionConfigGetter{}
7386
type ActionConfigGetterOption func(getter *actionConfigGetter)
7487

7588
type ObjectToStringMapper func(client.Object) (string, error)
89+
type ObjectToRestConfigMapper func(context.Context, client.Object, *rest.Config) (*rest.Config, error)
90+
type ObjectToStorageDriverMapper func(context.Context, client.Object, *rest.Config) (driver.Driver, error)
91+
92+
func ClientRestConfigMapper(f ObjectToRestConfigMapper) ActionConfigGetterOption {
93+
return func(getter *actionConfigGetter) {
94+
getter.objectToClientRestConfig = f
95+
}
96+
}
7697

7798
func ClientNamespaceMapper(m ObjectToStringMapper) ActionConfigGetterOption { // nolint:revive
7899
return func(getter *actionConfigGetter) {
79100
getter.objectToClientNamespace = m
80101
}
81102
}
82103

104+
func StorageRestConfigMapper(f ObjectToRestConfigMapper) ActionConfigGetterOption {
105+
return func(getter *actionConfigGetter) {
106+
getter.objectToStorageRestConfig = f
107+
}
108+
}
109+
110+
func StorageDriverMapper(f ObjectToStorageDriverMapper) ActionConfigGetterOption {
111+
return func(getter *actionConfigGetter) {
112+
getter.objectToStorageDriver = f
113+
}
114+
}
115+
116+
// Deprecated: use StorageDriverMapper(DefaultSecretsStorageDriver(SecretsStorageDriverOpts)) instead.
83117
func StorageNamespaceMapper(m ObjectToStringMapper) ActionConfigGetterOption {
84118
return func(getter *actionConfigGetter) {
85119
getter.objectToStorageNamespace = m
86120
}
87121
}
88122

123+
// Deprecated: use StorageDriverMapper(DefaultSecretsStorageDriver(SecretsStorageDriverOpts)) instead.
89124
func DisableStorageOwnerRefInjection(v bool) ActionConfigGetterOption {
90125
return func(getter *actionConfigGetter) {
91126
getter.disableStorageOwnerRefInjection = v
92127
}
93128
}
94129

95-
func RestConfigMapper(f func(context.Context, client.Object, *rest.Config) (*rest.Config, error)) ActionConfigGetterOption {
130+
// Deprecated: use ClientRestConfigMapper and StorageRestConfigMapper instead.
131+
func RestConfigMapper(f ObjectToRestConfigMapper) ActionConfigGetterOption {
96132
return func(getter *actionConfigGetter) {
97-
getter.objectToRestConfig = f
133+
getter.objectToClientRestConfig = f
134+
getter.objectToStorageRestConfig = f
98135
}
99136
}
100137

@@ -107,58 +144,54 @@ type actionConfigGetter struct {
107144
restMapper meta.RESTMapper
108145
discoveryClient discovery.CachedDiscoveryInterface
109146

110-
objectToClientNamespace ObjectToStringMapper
111-
objectToStorageNamespace ObjectToStringMapper
112-
objectToRestConfig func(context.Context, client.Object, *rest.Config) (*rest.Config, error)
147+
objectToClientRestConfig ObjectToRestConfigMapper
148+
objectToClientNamespace ObjectToStringMapper
149+
150+
objectToStorageRestConfig ObjectToRestConfigMapper
151+
objectToStorageDriver ObjectToStorageDriverMapper
152+
153+
// Deprecated: only keep around for backward compatibility with StorageNamespaceMapper option.
154+
objectToStorageNamespace ObjectToStringMapper
155+
// Deprecated: only keep around for backward compatibility with DisableStorageOwnerRefInjection option.
113156
disableStorageOwnerRefInjection bool
114157
}
115158

116159
func (acg *actionConfigGetter) ActionConfigFor(ctx context.Context, obj client.Object) (*action.Configuration, error) {
117-
storageNs, err := acg.objectToStorageNamespace(obj)
160+
clientRestConfig, err := acg.objectToClientRestConfig(ctx, obj, acg.baseRestConfig)
118161
if err != nil {
119-
return nil, fmt.Errorf("get storage namespace for object: %v", err)
120-
}
121-
122-
restConfig, err := acg.objectToRestConfig(ctx, obj, acg.baseRestConfig)
123-
if err != nil {
124-
return nil, fmt.Errorf("get rest config for object: %v", err)
162+
return nil, fmt.Errorf("get client rest config for object: %v", err)
125163
}
126164

127165
clientNamespace, err := acg.objectToClientNamespace(obj)
128166
if err != nil {
129167
return nil, fmt.Errorf("get client namespace for object: %v", err)
130168
}
131169

132-
rcg := newRESTClientGetter(restConfig, acg.restMapper, acg.discoveryClient, clientNamespace)
133-
kc := kube.New(rcg)
134-
kc.Namespace = clientNamespace
170+
clientRCG := newRESTClientGetter(clientRestConfig, acg.restMapper, acg.discoveryClient, clientNamespace)
171+
clientKC := kube.New(clientRCG)
172+
clientKC.Namespace = clientNamespace
173+
174+
// Setup the debug log function that Helm will use
175+
debugLog := getDebugLogger(ctx)
135176

136-
kcs, err := kc.Factory.KubernetesClientSet()
177+
storageRestConfig, err := acg.objectToStorageRestConfig(ctx, obj, acg.baseRestConfig)
137178
if err != nil {
138-
return nil, fmt.Errorf("create kubernetes clientset: %v", err)
179+
return nil, fmt.Errorf("get storage rest config for object: %v", err)
139180
}
140181

141-
// Setup the debug log function that Helm will use
142-
debugLog := getDebugLogger(ctx)
182+
d, err := acg.objectToStorageDriver(ctx, obj, storageRestConfig)
183+
if err != nil {
184+
return nil, fmt.Errorf("get storage driver for object: %v", err)
143185

144-
secretClient := kcs.CoreV1().Secrets(storageNs)
145-
if !acg.disableStorageOwnerRefInjection {
146-
ownerRef := metav1.NewControllerRef(obj, obj.GetObjectKind().GroupVersionKind())
147-
secretClient = &ownerRefSecretClient{
148-
SecretInterface: secretClient,
149-
refs: []metav1.OwnerReference{*ownerRef},
150-
}
151186
}
152-
d := driver.NewSecrets(secretClient)
153-
d.Log = debugLog
154187

155188
// Initialize the storage backend
156189
s := storage.Init(d)
157190

158191
return &action.Configuration{
159-
RESTClientGetter: rcg,
192+
RESTClientGetter: clientRCG,
160193
Releases: s,
161-
KubeClient: kc,
194+
KubeClient: clientKC,
162195
Log: debugLog,
163196
}, nil
164197
}
@@ -177,15 +210,82 @@ var _ v1.SecretInterface = &ownerRefSecretClient{}
177210

178211
type ownerRefSecretClient struct {
179212
v1.SecretInterface
180-
refs []metav1.OwnerReference
213+
match func(secret *corev1.Secret) bool
214+
refs []metav1.OwnerReference
181215
}
182216

183217
func (c *ownerRefSecretClient) Create(ctx context.Context, in *corev1.Secret, opts metav1.CreateOptions) (*corev1.Secret, error) {
184-
in.OwnerReferences = append(in.OwnerReferences, c.refs...)
218+
if c.match == nil || c.match(in) {
219+
in.OwnerReferences = append(in.OwnerReferences, c.refs...)
220+
}
185221
return c.SecretInterface.Create(ctx, in, opts)
186222
}
187223

188224
func (c *ownerRefSecretClient) Update(ctx context.Context, in *corev1.Secret, opts metav1.UpdateOptions) (*corev1.Secret, error) {
189-
in.OwnerReferences = append(in.OwnerReferences, c.refs...)
225+
if c.match == nil || c.match(in) {
226+
in.OwnerReferences = append(in.OwnerReferences, c.refs...)
227+
}
190228
return c.SecretInterface.Update(ctx, in, opts)
191229
}
230+
231+
type SecretsStorageDriverOpts struct {
232+
DisableOwnerRefInjection bool
233+
StorageNamespaceMapper ObjectToStringMapper
234+
}
235+
236+
func DefaultSecretsStorageDriver(opts SecretsStorageDriverOpts) ObjectToStorageDriverMapper {
237+
if opts.StorageNamespaceMapper == nil {
238+
opts.StorageNamespaceMapper = getObjectNamespace
239+
}
240+
return func(ctx context.Context, obj client.Object, restConfig *rest.Config) (driver.Driver, error) {
241+
storageNamespace, err := opts.StorageNamespaceMapper(obj)
242+
if err != nil {
243+
return nil, fmt.Errorf("get storage namespace for object: %v", err)
244+
}
245+
secretsInterface, err := v1.NewForConfig(restConfig)
246+
if err != nil {
247+
return nil, fmt.Errorf("create secrets client for storage: %v", err)
248+
}
249+
250+
secretClient := secretsInterface.Secrets(storageNamespace)
251+
if !opts.DisableOwnerRefInjection {
252+
ownerRef := metav1.NewControllerRef(obj, obj.GetObjectKind().GroupVersionKind())
253+
secretClient = &ownerRefSecretClient{
254+
SecretInterface: secretClient,
255+
refs: []metav1.OwnerReference{*ownerRef},
256+
}
257+
}
258+
d := driver.NewSecrets(secretClient)
259+
d.Log = getDebugLogger(ctx)
260+
return d, nil
261+
}
262+
}
263+
264+
func ChunkedSecretsStorageDriver(owner string, chunkSize int, opts SecretsStorageDriverOpts) ObjectToStorageDriverMapper {
265+
if opts.StorageNamespaceMapper == nil {
266+
opts.StorageNamespaceMapper = getObjectNamespace
267+
}
268+
return func(ctx context.Context, obj client.Object, restConfig *rest.Config) (driver.Driver, error) {
269+
storageNamespace, err := opts.StorageNamespaceMapper(obj)
270+
if err != nil {
271+
return nil, fmt.Errorf("get storage namespace for object: %v", err)
272+
}
273+
secretsInterface, err := v1.NewForConfig(restConfig)
274+
if err != nil {
275+
return nil, fmt.Errorf("create secrets client for storage: %v", err)
276+
}
277+
278+
secretClient := secretsInterface.Secrets(storageNamespace)
279+
if !opts.DisableOwnerRefInjection {
280+
ownerRef := metav1.NewControllerRef(obj, obj.GetObjectKind().GroupVersionKind())
281+
secretClient = &ownerRefSecretClient{
282+
SecretInterface: secretClient,
283+
match: func(secret *corev1.Secret) bool { return secret.Type == customstorage.SecretTypeChunkedIndex },
284+
refs: []metav1.OwnerReference{*ownerRef},
285+
}
286+
}
287+
d := customstorage.NewChunkedSecrets(secretClient, chunkSize, owner)
288+
d.Log = getDebugLogger(ctx)
289+
return d, nil
290+
}
291+
}

0 commit comments

Comments
 (0)