Documentation
¶
Index ¶
- Constants
- func ApplyRestrictedPodDefaults(spec *corev1.PodSpec)
- func EnsureOperatorSecretAccess(ctx context.Context, client kubernetes.Interface, namespace string) error
- func EnsureOperatorTrustBundleAccess(ctx context.Context, client kubernetes.Interface, namespace string) error
- func EnsureServiceAccount(ctx context.Context, client kubernetes.Interface, namespace string) error
- func OperatorSecretNamespaceProtected(namespace string) bool
- func RestrictedContainerSecurityContext() *corev1.SecurityContext
- func RestrictedPodSecurityContext() *corev1.PodSecurityContext
- func RestrictedReadOnlyContainerSecurityContext() *corev1.SecurityContext
- func ServiceAccount(namespace string) *corev1.ServiceAccount
Constants ¶
const ( // DefaultServiceAccountName is the service account used by managed MCP workloads. DefaultServiceAccountName = "mcp-workload" // RestrictedRunAsUser is the non-root user used by managed workload pods. RestrictedRunAsUser = int64(65532) )
const ( OperatorSecretAccessName = "mcp-runtime-operator-managed-secrets" // #nosec G101 -- ClusterRole name, not a credential // OperatorWorkloadAccessName grants Deployment, ServiceAccount and // Certificate mutation, which are indirect routes to a Secret. OperatorWorkloadAccessName = "mcp-runtime-operator-managed-workloads" OperatorServiceAccountName = "mcp-runtime-operator-controller-manager" OperatorNamespace = "github.com/mcp-runtime/mcp-runtime" OperatorTrustBundleName = "mcp-adapter-client-ca" // #nosec G101 -- object name, not a credential )
Variables ¶
This section is empty.
Functions ¶
func ApplyRestrictedPodDefaults ¶
ApplyRestrictedPodDefaults applies the shared restricted pod defaults.
func EnsureOperatorSecretAccess ¶
func EnsureOperatorSecretAccess(ctx context.Context, client kubernetes.Interface, namespace string) error
EnsureOperatorSecretAccess binds the operator's namespace-local Secret and workload roles. It is invoked only after the installer or platform has established that the namespace hosts managed MCPServers.
func EnsureOperatorTrustBundleAccess ¶
func EnsureOperatorTrustBundleAccess(ctx context.Context, client kubernetes.Interface, namespace string) error
EnsureOperatorTrustBundleAccess pre-creates the public CA bundle Secret and grants only named get/update/patch. Kubernetes cannot restrict create by resourceNames, so the operator never gets Secret create in the TLS namespace. An existing bundle is preserved; the operator refreshes it after issuance.
func EnsureServiceAccount ¶
EnsureServiceAccount creates or updates the restricted workload ServiceAccount.
func OperatorSecretNamespaceProtected ¶
OperatorSecretNamespaceProtected excludes infrastructure and prospective namespace domains from tenant Secret grants, including before migration.
func RestrictedContainerSecurityContext ¶
func RestrictedContainerSecurityContext() *corev1.SecurityContext
RestrictedContainerSecurityContext returns the shared container-level security context.
func RestrictedPodSecurityContext ¶
func RestrictedPodSecurityContext() *corev1.PodSecurityContext
RestrictedPodSecurityContext returns the shared pod-level security context.
func RestrictedReadOnlyContainerSecurityContext ¶
func RestrictedReadOnlyContainerSecurityContext() *corev1.SecurityContext
RestrictedReadOnlyContainerSecurityContext returns the shared read-only security context.
func ServiceAccount ¶
func ServiceAccount(namespace string) *corev1.ServiceAccount
ServiceAccount returns the restricted workload ServiceAccount object.
Types ¶
This section is empty.