INNER CODE UNIT · Go

Get

jaegertracing/jaeger-operator · pkg/clusterrolebinding/main.go:16

func Get(jaeger *v1.Jaeger) []rbac.ClusterRoleBinding {
	if jaeger.Spec.Ingress.Security == v1.IngressSecurityOAuthProxy && len(jaeger.Spec.Ingress.Openshift.DelegateUrls) > 0 {
		if autodetect.OperatorConfiguration.IsAuthDelegatorAvailable() {
			return []rbac.ClusterRoleBinding{oauthProxyAuthDelegator(jaeger)}
		}

		jaeger.Logger().V(1).Info("the requested instance specifies the delegate-urls option for the OAuth Proxy, but this operator cannot assign the proper cluster role to it (system:auth-delegator). Create a cluster role binding between the operator's service account and the cluster role 'system:auth-delegator' in order to allow instances to use 'delegate-urls'")

	}
	return []rbac.ClusterRoleBinding{}
}

func oauthProxyAuthDelegator(jaeger *v1.Jaeger) rbac.ClusterRoleBinding {
	name := util.DNSName(fmt.Sprintf("%s-%s-oauth-proxy-auth-delegator", jaeger.Namespace, jaeger.Name))
	trueVar := true

	return rbac.ClusterRoleBinding{
		ObjectMeta: metav1.ObjectMeta{

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…