pushsecret_controller_template.go 3.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113
  1. /*
  2. Copyright © The ESO Authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. https://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package pushsecret
  14. import (
  15. "context"
  16. "fmt"
  17. "maps"
  18. v1 "k8s.io/api/core/v1"
  19. esv1 "github.com/external-secrets/external-secrets/apis/externalsecrets/v1"
  20. "github.com/external-secrets/external-secrets/apis/externalsecrets/v1alpha1"
  21. "github.com/external-secrets/external-secrets/pkg/controllers/templating"
  22. "github.com/external-secrets/external-secrets/runtime/esutils"
  23. "github.com/external-secrets/external-secrets/runtime/template"
  24. _ "github.com/external-secrets/external-secrets/pkg/register" // Loading registered providers.
  25. )
  26. const (
  27. errFetchTplFrom = "error fetching templateFrom data: %w"
  28. errExecTpl = "could not execute template: %w"
  29. )
  30. // applyTemplate merges template in the following order:
  31. // * template.Data (highest precedence)
  32. // * template.templateFrom
  33. // * secret via ps.data or ps.dataFrom.
  34. // Apply template modifications for the source secret. These modifications will only live in memory as we will
  35. // never modify it.
  36. func (r *Reconciler) applyTemplate(ctx context.Context, ps *v1alpha1.PushSecret, secret *v1.Secret) error {
  37. // no template: nothing to do
  38. if ps.Spec.Template == nil {
  39. return nil
  40. }
  41. if err := setMetadata(secret, ps); err != nil {
  42. return err
  43. }
  44. execute, err := template.EngineForVersion(esv1.TemplateEngineV2)
  45. if err != nil {
  46. return err
  47. }
  48. // Copies secret.Data to dataMap to avoid modifying the original secret
  49. // This avoids uncertain behavior if kube-apiserver sends the
  50. // template map in a different order on each reconcile loop
  51. // ref: https://github.com/external-secrets/external-secrets/issues/5018
  52. dataMap := make(map[string][]byte)
  53. maps.Copy(dataMap, secret.Data)
  54. p := templating.Parser{
  55. Client: r.Client,
  56. TargetSecret: secret,
  57. DataMap: dataMap,
  58. Exec: execute,
  59. }
  60. // apply templates defined in template.templateFrom
  61. err = p.MergeTemplateFrom(ctx, ps.Namespace, ps.Spec.Template)
  62. if err != nil {
  63. return fmt.Errorf(errFetchTplFrom, err)
  64. }
  65. // explicitly defined template.Data takes precedence over templateFrom
  66. err = p.MergeMap(ps.Spec.Template.Data, esv1.TemplateTargetData)
  67. if err != nil {
  68. return fmt.Errorf(errExecTpl, err)
  69. }
  70. // get template data for labels
  71. err = p.MergeMap(ps.Spec.Template.Metadata.Labels, esv1.TemplateTargetLabels)
  72. if err != nil {
  73. return fmt.Errorf(errExecTpl, err)
  74. }
  75. // get template data for annotations
  76. err = p.MergeMap(ps.Spec.Template.Metadata.Annotations, esv1.TemplateTargetAnnotations)
  77. if err != nil {
  78. return fmt.Errorf(errExecTpl, err)
  79. }
  80. return nil
  81. }
  82. // setMetadata sets Labels and Annotations in the source secret, but we will never write them back.
  83. // It is only set to satisfy templated changes.
  84. func setMetadata(secret *v1.Secret, ps *v1alpha1.PushSecret) error {
  85. if secret.Labels == nil {
  86. secret.Labels = make(map[string]string)
  87. }
  88. if secret.Annotations == nil {
  89. secret.Annotations = make(map[string]string)
  90. }
  91. secret.Type = ps.Spec.Template.Type
  92. esutils.MergeStringMap(secret.ObjectMeta.Labels, ps.Spec.Template.Metadata.Labels)
  93. esutils.MergeStringMap(secret.ObjectMeta.Annotations, ps.Spec.Template.Metadata.Annotations)
  94. return nil
  95. }