-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat: EKS IAM Roles for Service Accounts for Runner Pods
One of the pod recreation conditions has been modified to use hash of runner spec, so that the controller does not keep restarting pods mutated by admission webhooks. This naturally allows us, for example, to use IRSA for EKS that requires its admission webhook to mutate the runner pod to have additional, IRSA-related volumes, volume mounts and env. Resolves #200
- Loading branch information
Yusuke Kuoka
committed
Dec 7, 2020
1 parent
85c29a9
commit c1deeaf
Showing
3 changed files
with
63 additions
and
3 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,17 @@ | ||
package hash | ||
|
||
import ( | ||
"fmt" | ||
"hash/fnv" | ||
"k8s.io/apimachinery/pkg/util/rand" | ||
) | ||
|
||
func FNVHashStringObjects(objs ...interface{}) string { | ||
hash := fnv.New32a() | ||
|
||
for _, obj := range objs { | ||
DeepHashObject(hash, obj) | ||
} | ||
|
||
return rand.SafeEncodeString(fmt.Sprint(hash.Sum32())) | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,25 @@ | ||
// Copyright 2015 The Kubernetes Authors. | ||
// hash.go is copied from kubernetes's pkg/util/hash.go | ||
// See https://github.com/kubernetes/kubernetes/blob/e1c617a88ec286f5f6cb2589d6ac562d095e1068/pkg/util/hash/hash.go#L25-L37 | ||
|
||
package hash | ||
|
||
import ( | ||
"hash" | ||
|
||
"github.com/davecgh/go-spew/spew" | ||
) | ||
|
||
// DeepHashObject writes specified object to hash using the spew library | ||
// which follows pointers and prints actual values of the nested objects | ||
// ensuring the hash does not change when a pointer changes. | ||
func DeepHashObject(hasher hash.Hash, objectToWrite interface{}) { | ||
hasher.Reset() | ||
printer := spew.ConfigState{ | ||
Indent: " ", | ||
SortKeys: true, | ||
DisableMethods: true, | ||
SpewKeys: true, | ||
} | ||
printer.Fprintf(hasher, "%#v", objectToWrite) | ||
} |