Skip to content

Commit 2e1eea6

Browse files
committed
03-remove-preflight-permissions
1 parent 25704ad commit 2e1eea6

File tree

20 files changed

+7
-2702
lines changed

20 files changed

+7
-2702
lines changed

Makefile

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -153,10 +153,6 @@ lint-custom: custom-linter-build #EXHELP Call custom linter for the project
153153
lint-api-diff: $(GOLANGCI_LINT) #HELP Validate API changes using kube-api-linter with diff-aware analysis
154154
hack/api-lint-diff/run.sh
155155

156-
.PHONY: k8s-pin
157-
k8s-pin: #EXHELP Pin k8s staging modules based on k8s.io/kubernetes version (in go.mod or from K8S_IO_K8S_VERSION env var) and run go mod tidy.
158-
K8S_IO_K8S_VERSION='$(K8S_IO_K8S_VERSION)' go run hack/tools/k8smaintainer/main.go
159-
160156
.PHONY: tidy #HELP Run go mod tidy.
161157
tidy:
162158
go mod tidy
@@ -202,7 +198,7 @@ generate: $(CONTROLLER_GEN) #EXHELP Generate code containing DeepCopy, DeepCopyI
202198
$(CONTROLLER_GEN) --load-build-tags=$(GO_BUILD_TAGS) object:headerFile="hack/boilerplate.go.txt" paths="./..."
203199

204200
.PHONY: verify
205-
verify: k8s-pin kind-verify-versions fmt generate manifests update-tls-profiles crd-ref-docs update-registryv1-bundle-schema verify-bingo #HELP Verify all generated code is up-to-date. Runs k8s-pin instead of just tidy.
201+
verify: tidy kind-verify-versions fmt generate manifests update-tls-profiles crd-ref-docs update-registryv1-bundle-schema verify-bingo #HELP Verify all generated code is up-to-date.
206202
git diff --exit-code
207203

208204
.PHONY: verify-bingo

cmd/operator-controller/main.go

Lines changed: 0 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,6 @@ import (
6060
"github.com/operator-framework/operator-controller/internal/operator-controller/action"
6161
"github.com/operator-framework/operator-controller/internal/operator-controller/applier"
6262
"github.com/operator-framework/operator-controller/internal/operator-controller/authentication"
63-
"github.com/operator-framework/operator-controller/internal/operator-controller/authorization"
6463
"github.com/operator-framework/operator-controller/internal/operator-controller/catalogmetadata/cache"
6564
catalogclient "github.com/operator-framework/operator-controller/internal/operator-controller/catalogmetadata/client"
6665
"github.com/operator-framework/operator-controller/internal/operator-controller/contentmanager"
@@ -598,12 +597,6 @@ func (c *boxcutterReconcilerConfigurator) Configure(ceReconciler *controllers.Cl
598597
return err
599598
}
600599

601-
// determine if PreAuthorizer should be enabled based on feature gate
602-
var preAuth authorization.PreAuthorizer
603-
if features.OperatorControllerFeatureGate.Enabled(features.PreflightPermissions) {
604-
preAuth = authorization.NewRBACPreAuthorizer(c.mgr.GetClient())
605-
}
606-
607600
// TODO: better scheme handling - which types do we want to support?
608601
_ = apiextensionsv1.AddToScheme(c.mgr.GetScheme())
609602
rg := &applier.SimpleRevisionGenerator{
@@ -615,7 +608,6 @@ func (c *boxcutterReconcilerConfigurator) Configure(ceReconciler *controllers.Cl
615608
Scheme: c.mgr.GetScheme(),
616609
RevisionGenerator: rg,
617610
Preflights: c.preflights,
618-
PreAuthorizer: preAuth,
619611
FieldOwner: fmt.Sprintf("%s/clusterextension-controller", fieldOwnerPrefix),
620612
}
621613
revisionStatesGetter := &controllers.BoxcutterRevisionStatesGetter{Reader: c.mgr.GetClient()}
@@ -718,12 +710,6 @@ func (c *helmReconcilerConfigurator) Configure(ceReconciler *controllers.Cluster
718710
return fmt.Errorf("unable to create helm action client getter: %w", err)
719711
}
720712

721-
// determine if PreAuthorizer should be enabled based on feature gate
722-
var preAuth authorization.PreAuthorizer
723-
if features.OperatorControllerFeatureGate.Enabled(features.PreflightPermissions) {
724-
preAuth = authorization.NewRBACPreAuthorizer(c.mgr.GetClient())
725-
}
726-
727713
cm := contentmanager.NewManager(clientRestConfigMapper, c.mgr.GetConfig(), c.mgr.GetRESTMapper())
728714
err = c.finalizers.Register(controllers.ClusterExtensionCleanupContentManagerCacheFinalizer, finalizers.FinalizerFunc(func(ctx context.Context, obj client.Object) (crfinalizer.Result, error) {
729715
ext := obj.(*ocv1.ClusterExtension)
@@ -735,15 +721,13 @@ func (c *helmReconcilerConfigurator) Configure(ceReconciler *controllers.Cluster
735721
return err
736722
}
737723

738-
// now initialize the helmApplier, assigning the potentially nil preAuth
739724
appl := &applier.Helm{
740725
ActionClientGetter: acg,
741726
Preflights: c.preflights,
742727
HelmChartProvider: &applier.RegistryV1HelmChartProvider{
743728
ManifestProvider: c.regv1ManifestProvider,
744729
},
745730
HelmReleaseToObjectsConverter: &applier.HelmReleaseToObjectsConverter{},
746-
PreAuthorizer: preAuth,
747731
Watcher: c.watcher,
748732
Manager: cm,
749733
}

docs/draft/howto/rbac-permissions-checking.md

Lines changed: 0 additions & 54 deletions
This file was deleted.

go.mod

Lines changed: 2 additions & 67 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ require (
3131
github.com/stretchr/testify v1.11.1
3232
go.podman.io/image/v5 v5.39.1
3333
golang.org/x/exp v0.0.0-20260209203927-2842357ff358
34-
golang.org/x/mod v0.33.0
34+
golang.org/x/mod v0.33.0 // indirect
3535
golang.org/x/sync v0.19.0
3636
golang.org/x/tools v0.42.0
3737
helm.sh/helm/v3 v3.20.0
@@ -43,7 +43,6 @@ require (
4343
k8s.io/client-go v0.35.0
4444
k8s.io/component-base v0.35.0
4545
k8s.io/klog/v2 v2.130.1
46-
k8s.io/kubernetes v1.35.0
4746
k8s.io/utils v0.0.0-20260108192941-914a6e750570
4847
pkg.package-operator.run/boxcutter v0.10.0
4948
sigs.k8s.io/controller-runtime v0.23.1
@@ -52,10 +51,7 @@ require (
5251
sigs.k8s.io/yaml v1.6.0
5352
)
5453

55-
require (
56-
k8s.io/component-helpers v0.35.0 // indirect
57-
k8s.io/kube-openapi v0.0.0-20260127142750-a19766b6e2d4 // indirect
58-
)
54+
require k8s.io/kube-openapi v0.0.0-20260127142750-a19766b6e2d4 // indirect
5955

6056
require (
6157
cel.dev/expr v0.25.1 // indirect
@@ -243,7 +239,6 @@ require (
243239
gopkg.in/warnings.v0 v0.1.2 // indirect
244240
gopkg.in/yaml.v2 v2.4.0 // indirect
245241
gopkg.in/yaml.v3 v3.0.1 // indirect
246-
k8s.io/controller-manager v0.33.2 // indirect
247242
k8s.io/kubectl v0.35.0 // indirect
248243
oras.land/oras-go/v2 v2.6.0 // indirect
249244
sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.34.0 // indirect
@@ -256,63 +251,3 @@ require (
256251
)
257252

258253
retract v1.5.0 // contains filename with ':' which causes failure creating module zip file
259-
260-
replace k8s.io/api => k8s.io/api v0.35.0
261-
262-
replace k8s.io/apiextensions-apiserver => k8s.io/apiextensions-apiserver v0.35.0
263-
264-
replace k8s.io/apimachinery => k8s.io/apimachinery v0.35.0
265-
266-
replace k8s.io/apiserver => k8s.io/apiserver v0.35.0
267-
268-
replace k8s.io/cli-runtime => k8s.io/cli-runtime v0.35.0
269-
270-
replace k8s.io/client-go => k8s.io/client-go v0.35.0
271-
272-
replace k8s.io/cloud-provider => k8s.io/cloud-provider v0.35.0
273-
274-
replace k8s.io/cluster-bootstrap => k8s.io/cluster-bootstrap v0.35.0
275-
276-
replace k8s.io/code-generator => k8s.io/code-generator v0.35.0
277-
278-
replace k8s.io/component-base => k8s.io/component-base v0.35.0
279-
280-
replace k8s.io/component-helpers => k8s.io/component-helpers v0.35.0
281-
282-
replace k8s.io/controller-manager => k8s.io/controller-manager v0.35.0
283-
284-
replace k8s.io/cri-api => k8s.io/cri-api v0.35.0
285-
286-
replace k8s.io/cri-client => k8s.io/cri-client v0.35.0
287-
288-
replace k8s.io/csi-translation-lib => k8s.io/csi-translation-lib v0.35.0
289-
290-
replace k8s.io/dynamic-resource-allocation => k8s.io/dynamic-resource-allocation v0.35.0
291-
292-
replace k8s.io/endpointslice => k8s.io/endpointslice v0.35.0
293-
294-
replace k8s.io/externaljwt => k8s.io/externaljwt v0.35.0
295-
296-
replace k8s.io/kms => k8s.io/kms v0.35.0
297-
298-
replace k8s.io/kube-aggregator => k8s.io/kube-aggregator v0.35.0
299-
300-
replace k8s.io/kube-controller-manager => k8s.io/kube-controller-manager v0.35.0
301-
302-
replace k8s.io/kube-proxy => k8s.io/kube-proxy v0.35.0
303-
304-
replace k8s.io/kube-scheduler => k8s.io/kube-scheduler v0.35.0
305-
306-
replace k8s.io/kubectl => k8s.io/kubectl v0.35.0
307-
308-
replace k8s.io/kubelet => k8s.io/kubelet v0.35.0
309-
310-
replace k8s.io/kubernetes => k8s.io/kubernetes v1.35.0
311-
312-
replace k8s.io/metrics => k8s.io/metrics v0.35.0
313-
314-
replace k8s.io/mount-utils => k8s.io/mount-utils v0.35.0
315-
316-
replace k8s.io/pod-security-admission => k8s.io/pod-security-admission v0.35.0
317-
318-
replace k8s.io/sample-apiserver => k8s.io/sample-apiserver v0.35.0

go.sum

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -780,18 +780,12 @@ k8s.io/client-go v0.35.0 h1:IAW0ifFbfQQwQmga0UdoH0yvdqrbwMdq9vIFEhRpxBE=
780780
k8s.io/client-go v0.35.0/go.mod h1:q2E5AAyqcbeLGPdoRB+Nxe3KYTfPce1Dnu1myQdqz9o=
781781
k8s.io/component-base v0.35.0 h1:+yBrOhzri2S1BVqyVSvcM3PtPyx5GUxCK2tinZz1G94=
782782
k8s.io/component-base v0.35.0/go.mod h1:85SCX4UCa6SCFt6p3IKAPej7jSnF3L8EbfSyMZayJR0=
783-
k8s.io/component-helpers v0.35.0 h1:wcXv7HJRksgVjM4VlXJ1CNFBpyDHruRI99RrBtrJceA=
784-
k8s.io/component-helpers v0.35.0/go.mod h1:ahX0m/LTYmu7fL3W8zYiIwnQ/5gT28Ex4o2pymF63Co=
785-
k8s.io/controller-manager v0.35.0 h1:KteodmfVIRzfZ3RDaxhnHb72rswBxEngvdL9vuZOA9A=
786-
k8s.io/controller-manager v0.35.0/go.mod h1:1bVuPNUG6/dpWpevsJpXioS0E0SJnZ7I/Wqc9Awyzm4=
787783
k8s.io/klog/v2 v2.130.1 h1:n9Xl7H1Xvksem4KFG4PYbdQCQxqc/tTUyrgXaOhHSzk=
788784
k8s.io/klog/v2 v2.130.1/go.mod h1:3Jpz1GvMt720eyJH1ckRHK1EDfpxISzJ7I9OYgaDtPE=
789785
k8s.io/kube-openapi v0.0.0-20260127142750-a19766b6e2d4 h1:HhDfevmPS+OalTjQRKbTHppRIz01AWi8s45TMXStgYY=
790786
k8s.io/kube-openapi v0.0.0-20260127142750-a19766b6e2d4/go.mod h1:kdmbQkyfwUagLfXIad1y2TdrjPFWp2Q89B3qkRwf/pQ=
791787
k8s.io/kubectl v0.35.0 h1:cL/wJKHDe8E8+rP3G7avnymcMg6bH6JEcR5w5uo06wc=
792788
k8s.io/kubectl v0.35.0/go.mod h1:VR5/TSkYyxZwrRwY5I5dDq6l5KXmiCb+9w8IKplk3Qo=
793-
k8s.io/kubernetes v1.35.0 h1:PUOojD8c8E3csMP5NX+nLLne6SGqZjrYCscptyBfWMY=
794-
k8s.io/kubernetes v1.35.0/go.mod h1:Tzk9Y9W/XUFFFgTUVg+BAowoFe+Pc7koGLuaiLHdcFg=
795789
k8s.io/utils v0.0.0-20260108192941-914a6e750570 h1:JT4W8lsdrGENg9W+YwwdLJxklIuKWdRm+BC+xt33FOY=
796790
k8s.io/utils v0.0.0-20260108192941-914a6e750570/go.mod h1:xDxuJ0whA3d0I4mf/C4ppKHxXynQ+fxnkmQH0vTHnuk=
797791
oras.land/oras-go/v2 v2.6.0 h1:X4ELRsiGkrbeox69+9tzTu492FMUu7zJQW6eJU+I2oc=

hack/tools/k8smaintainer/README.md

Lines changed: 0 additions & 43 deletions
This file was deleted.

0 commit comments

Comments
 (0)