Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support RRSA auth in AliCloud #5340

Merged
merged 13 commits into from
Apr 24, 2023
Merged

Support RRSA auth in AliCloud #5340

merged 13 commits into from
Apr 24, 2023

Conversation

maximrub
Copy link
Contributor

Which component this PR applies to?

cluster-autoscaler

What type of PR is this?

/kind feature

What this PR does / why we need it:

This PR allows use of RRSA to authorize pods to access different cloud services
this way we can assign roles to the autoscaler pod only instead to the whole cluster, and allow to use other roles instead only of the automatically created RAM role by ACK

Which issue(s) this PR fixes:

Fixes #5339

Special notes for your reviewer:

Does this PR introduce a user-facing change?

no

NONE

Additional documentation e.g., KEPs (Kubernetes Enhancement Proposals), usage docs, etc.:

@k8s-ci-robot k8s-ci-robot added the kind/feature Categorizes issue or PR as related to a new feature. label Nov 29, 2022
@k8s-ci-robot
Copy link
Contributor

Welcome @maximrub!

It looks like this is your first PR to kubernetes/autoscaler 🎉. Please refer to our pull request process documentation to help your PR have a smooth ride to approval.

You will be prompted by a bot to use commands during the review process. Do not be afraid to follow the prompts! It is okay to experiment. Here is the bot commands documentation.

You can also check if kubernetes/autoscaler has its own contribution guidelines.

You may want to refer to our testing guide if you run into trouble with your tests not passing.

If you are having difficulty getting your pull request seen, please follow the recommended escalation practices. Also, for tips and tricks in the contribution process you may want to read the Kubernetes contributor cheat sheet. We want to make sure your contribution gets all the attention it needs!

Thank you, and welcome to Kubernetes. 😃

@linux-foundation-easycla
Copy link

linux-foundation-easycla bot commented Nov 29, 2022

CLA Signed

The committers listed above are authorized under a signed CLA.

@k8s-ci-robot k8s-ci-robot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. labels Nov 29, 2022
@k8s-ci-robot k8s-ci-robot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. and removed cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. labels Nov 29, 2022
@x13n
Copy link
Member

x13n commented Dec 19, 2022

/cc @ringtail - can you take a look?

Copy link
Member

@x13n x13n left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you add tests for the newly introduced code?

@x13n
Copy link
Member

x13n commented Dec 19, 2022

/assign

@ringtail
Copy link
Contributor

/cc @ringtail - can you take a look?

I'll check it.

@maximrub
Copy link
Contributor Author

Can you add tests for the newly introduced code?

yes, will add some more tests

@mozillazg
Copy link
Contributor

mozillazg commented Feb 23, 2023

@maximrub Sorry for ping, are you still working on this?

@maximrub
Copy link
Contributor Author

maximrub commented Mar 5, 2023

Hello @mozillazg
yes, I'll push the tests in a few days
thank you

@x13n
Copy link
Member

x13n commented Apr 14, 2023

Unassigning myself for now. Feel free to assign me back for approval after getting lgtm from @ringtail

/unassign

@maximrub maximrub requested a review from x13n April 15, 2023 20:48
@maximrub
Copy link
Contributor Author

@mozillazg @ringtail I added the tests that cover the added functionality of creating ecs and ess clients with RRSA authentication
The signer itself is not covered as it will work on Alibaba env only

Signed-off-by: Maxim Rubchinsky <[email protected]>
@maximrub
Copy link
Contributor Author

maximrub commented Apr 23, 2023

Hi @ringtail
Did you had a chance to go over the changes?

@ringtail
Copy link
Contributor

Hi @ringtail Did you had a chance to go over the changes?

sure, @mozillazg is working on reviewing the code

@mozillazg
Copy link
Contributor

@maximrub I took some time to deploy and test this, it works like a charm 🏅 👍

maximrub and others added 5 commits April 24, 2023 12:36
…/sdk/auth/signers/signer_oidc.go

Co-authored-by: Huang Huang <[email protected]>
…/sdk/auth/signers/signer_oidc.go

Co-authored-by: Huang Huang <[email protected]>
…/sdk/auth/signers/signer_oidc.go

Co-authored-by: Huang Huang <[email protected]>
Signed-off-by: Maxim Rubchinsky <[email protected]>
@maximrub
Copy link
Contributor Author

maximrub commented Apr 24, 2023

@maximrub I took some time to deploy and test this, it works like a charm 🏅 👍

thanks @mozillazg
I fixed your comments

Copy link
Contributor

@mozillazg mozillazg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ringtail
Copy link
Contributor

/LGTM

@k8s-ci-robot
Copy link
Contributor

@ringtail: changing LGTM is restricted to collaborators

In response to this:

/LGTM

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@ringtail
Copy link
Contributor

/assign @x13n

@x13n
Copy link
Member

x13n commented Apr 24, 2023

/lgtm
/approve

@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Apr 24, 2023
@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: maximrub, mozillazg, x13n

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Apr 24, 2023
@k8s-ci-robot k8s-ci-robot merged commit 240ac79 into kubernetes:master Apr 24, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. area/cluster-autoscaler cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. kind/feature Categorizes issue or PR as related to a new feature. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/XL Denotes a PR that changes 500-999 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Support RRSA auth in AliCloud
6 participants