kubeworkload

package
v0.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// DefaultServiceAccountName is the service account used by managed MCP workloads.
	DefaultServiceAccountName = "mcp-workload"
	// RestrictedRunAsUser is the non-root user used by managed workload pods.
	RestrictedRunAsUser = int64(65532)
)
View Source
const (
	OperatorSecretAccessName = "mcp-runtime-operator-managed-secrets" // #nosec G101 -- ClusterRole name, not a credential
	// OperatorWorkloadAccessName grants Deployment, ServiceAccount and
	// Certificate mutation, which are indirect routes to a Secret.
	OperatorWorkloadAccessName = "mcp-runtime-operator-managed-workloads"
	OperatorServiceAccountName = "mcp-runtime-operator-controller-manager"
	OperatorNamespace          = "github.com/mcp-runtime/mcp-runtime"
	OperatorTrustBundleName    = "mcp-adapter-client-ca" // #nosec G101 -- object name, not a credential
)

Variables

This section is empty.

Functions

func ApplyRestrictedPodDefaults

func ApplyRestrictedPodDefaults(spec *corev1.PodSpec)

ApplyRestrictedPodDefaults applies the shared restricted pod defaults.

func EnsureOperatorSecretAccess

func EnsureOperatorSecretAccess(ctx context.Context, client kubernetes.Interface, namespace string) error

EnsureOperatorSecretAccess binds the operator's namespace-local Secret and workload roles. It is invoked only after the installer or platform has established that the namespace hosts managed MCPServers.

func EnsureOperatorTrustBundleAccess

func EnsureOperatorTrustBundleAccess(ctx context.Context, client kubernetes.Interface, namespace string) error

EnsureOperatorTrustBundleAccess pre-creates the public CA bundle Secret and grants only named get/update/patch. Kubernetes cannot restrict create by resourceNames, so the operator never gets Secret create in the TLS namespace. An existing bundle is preserved; the operator refreshes it after issuance.

func EnsureServiceAccount

func EnsureServiceAccount(ctx context.Context, client kubernetes.Interface, namespace string) error

EnsureServiceAccount creates or updates the restricted workload ServiceAccount.

func OperatorSecretNamespaceProtected

func OperatorSecretNamespaceProtected(namespace string) bool

OperatorSecretNamespaceProtected excludes infrastructure and prospective namespace domains from tenant Secret grants, including before migration.

func RestrictedContainerSecurityContext

func RestrictedContainerSecurityContext() *corev1.SecurityContext

RestrictedContainerSecurityContext returns the shared container-level security context.

func RestrictedPodSecurityContext

func RestrictedPodSecurityContext() *corev1.PodSecurityContext

RestrictedPodSecurityContext returns the shared pod-level security context.

func RestrictedReadOnlyContainerSecurityContext

func RestrictedReadOnlyContainerSecurityContext() *corev1.SecurityContext

RestrictedReadOnlyContainerSecurityContext returns the shared read-only security context.

func ServiceAccount

func ServiceAccount(namespace string) *corev1.ServiceAccount

ServiceAccount returns the restricted workload ServiceAccount object.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL