pushsecret_controller_template.go 3.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111
  1. /*
  2. Licensed under the Apache License, Version 2.0 (the "License");
  3. you may not use this file except in compliance with the License.
  4. You may obtain a copy of the License at
  5. http://www.apache.org/licenses/LICENSE-2.0
  6. Unless required by applicable law or agreed to in writing, software
  7. distributed under the License is distributed on an "AS IS" BASIS,
  8. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  9. See the License for the specific language governing permissions and
  10. limitations under the License.
  11. */
  12. package pushsecret
  13. import (
  14. "context"
  15. "fmt"
  16. "maps"
  17. v1 "k8s.io/api/core/v1"
  18. esv1 "github.com/external-secrets/external-secrets/apis/externalsecrets/v1"
  19. "github.com/external-secrets/external-secrets/apis/externalsecrets/v1alpha1"
  20. "github.com/external-secrets/external-secrets/pkg/controllers/templating"
  21. "github.com/external-secrets/external-secrets/pkg/template"
  22. "github.com/external-secrets/external-secrets/pkg/utils"
  23. _ "github.com/external-secrets/external-secrets/pkg/provider/register" // Loading registered providers.
  24. )
  25. const (
  26. errFetchTplFrom = "error fetching templateFrom data: %w"
  27. errExecTpl = "could not execute template: %w"
  28. )
  29. // applyTemplate merges template in the following order:
  30. // * template.Data (highest precedence)
  31. // * template.templateFrom
  32. // * secret via ps.data or ps.dataFrom.
  33. // Apply template modifications for the source secret. These modifications will only live in memory as we will
  34. // never modify it.
  35. func (r *Reconciler) applyTemplate(ctx context.Context, ps *v1alpha1.PushSecret, secret *v1.Secret) error {
  36. // no template: nothing to do
  37. if ps.Spec.Template == nil {
  38. return nil
  39. }
  40. if err := setMetadata(secret, ps); err != nil {
  41. return err
  42. }
  43. execute, err := template.EngineForVersion(esv1.TemplateEngineV2)
  44. if err != nil {
  45. return err
  46. }
  47. // Copies secret.Data to dataMap to avoid modifying the original secret
  48. // This avoids uncertain behavior if kube-apiserver sends the
  49. // template map in a different order on each reconcile loop
  50. // ref: https://github.com/external-secrets/external-secrets/issues/5018
  51. dataMap := make(map[string][]byte)
  52. maps.Copy(dataMap, secret.Data)
  53. p := templating.Parser{
  54. Client: r.Client,
  55. TargetSecret: secret,
  56. DataMap: dataMap,
  57. Exec: execute,
  58. }
  59. // apply templates defined in template.templateFrom
  60. err = p.MergeTemplateFrom(ctx, ps.Namespace, ps.Spec.Template)
  61. if err != nil {
  62. return fmt.Errorf(errFetchTplFrom, err)
  63. }
  64. // explicitly defined template.Data takes precedence over templateFrom
  65. err = p.MergeMap(ps.Spec.Template.Data, esv1.TemplateTargetData)
  66. if err != nil {
  67. return fmt.Errorf(errExecTpl, err)
  68. }
  69. // get template data for labels
  70. err = p.MergeMap(ps.Spec.Template.Metadata.Labels, esv1.TemplateTargetLabels)
  71. if err != nil {
  72. return fmt.Errorf(errExecTpl, err)
  73. }
  74. // get template data for annotations
  75. err = p.MergeMap(ps.Spec.Template.Metadata.Annotations, esv1.TemplateTargetAnnotations)
  76. if err != nil {
  77. return fmt.Errorf(errExecTpl, err)
  78. }
  79. return nil
  80. }
  81. // setMetadata sets Labels and Annotations in the source secret, but we will never write them back.
  82. // It is only set to satisfy templated changes.
  83. func setMetadata(secret *v1.Secret, ps *v1alpha1.PushSecret) error {
  84. if secret.Labels == nil {
  85. secret.Labels = make(map[string]string)
  86. }
  87. if secret.Annotations == nil {
  88. secret.Annotations = make(map[string]string)
  89. }
  90. secret.Type = ps.Spec.Template.Type
  91. utils.MergeStringMap(secret.ObjectMeta.Labels, ps.Spec.Template.Metadata.Labels)
  92. utils.MergeStringMap(secret.ObjectMeta.Annotations, ps.Spec.Template.Metadata.Annotations)
  93. return nil
  94. }