Ory Hydra Maester is developed by the Ory community and is not actively maintained by Ory core maintainers due to lack of resources, time, and knolwedge. As such please be aware that there might be issues with the system. If you have ideas for better testing and development principles please open an issue or PR!
This project contains a Kubernetes controller that uses Custom Resources (CR) to
manage Hydra Oauth2 clients. ORY Hydra Maester watches for instances of
oauth2clients.hydra.ory.sh/v1alpha1
CR and creates, updates, or deletes
corresponding OAuth2 clients by communicating with ORY Hydra's API.
Visit Hydra-maester's
chart documentation
and view sample OAuth2 client resources to learn more about
the oauth2clients.hydra.ory.sh/v1alpha1
CR.
The project is based on Kubebuilder.
- recent version of Go language with support for modules (e.g: 1.12.6)
- make
- kubectl
- kustomize
- kubebuilder for running tests
- ginkgo for local integration testing
- access to K8s environment: minikube or a remote K8s cluster
- mockery to generate mocks for testing purposes
Take a look at Design Readme.
make test
to run testsmake test-integration
to run integration testsmake install
to generate CRD file from go sources and install it on the clusterexport HYDRA_URL={HYDRA_SERVICE_URL} && make run
to run the controller
To deploy the controller, edit the value of the --hydra-url
argument in the
manager.yaml file and run make deploy
.
Name | Required | Description | Default value | Example values |
---|---|---|---|---|
hydra-url | yes | ORY Hydra's service address | - | ory-hydra-admin.ory.svc.cluster.local |
hydra-port | no | ORY Hydra's service port | 4445 |
4445 |
tls-trust-store | no | TLS cert path for hydra client | "" |
/etc/ssl/certs/ca-certificates.crt |
insecure-skip-verify | no | Skip http client insecure verification | false |
true or false |
namespace | no | Namespace in which the controller should operate. Setting this will make the controller ignore other namespaces. | "" |
"my-namespace" |
leader-elector-namespace | no | Leader elector namespace where controller should be set. | "" |
"my-namespace" |
Variable name | Default value | Example value |
---|---|---|
**CLIENT_ID_KEY** |
**CLIENT_ID** |
**MY_SECRET_NAME** |
**CLIENT_SECRET_KEY** |
**CLIENT_SECRET** |
**MY_SECRET_VALUE** |
Use mockery to generate mock types that implement existing interfaces. To generate a mock type for an interface, navigate to the directory containing that interface and run this command:
mockery -name={INTERFACE_NAME}