feat: profile-gated workspace-maintenance service and connector override generator (P2)
This commit is contained in:
@@ -3,7 +3,10 @@
|
||||
set -euo pipefail
|
||||
|
||||
usage() {
|
||||
echo "usage: $0 --bindings-env <workspace-bindings.env> --operator-env <operator.env> --output <override.yaml>" >&2
|
||||
cat >&2 <<'EOF'
|
||||
usage: $0 --bindings-env <workspace-bindings.env> --operator-env <operator.env> --output <override.yaml> \
|
||||
[--service <core|workspace-maintenance>]... [--role <all|dwh|evidence>]...
|
||||
EOF
|
||||
exit 2
|
||||
}
|
||||
|
||||
@@ -40,20 +43,59 @@ read_env_value() {
|
||||
printf '%s' "$result"
|
||||
}
|
||||
|
||||
binding_matches_roles() {
|
||||
local name="$1" role
|
||||
for role in "${roles[@]}"; do
|
||||
case "$role" in
|
||||
all) return 0 ;;
|
||||
dwh)
|
||||
[[ "$name" == *"_DWH_"* ]] && return 0
|
||||
;;
|
||||
evidence)
|
||||
[[ "$name" == *"_EVIDENCE_"* ]] && return 0
|
||||
;;
|
||||
*)
|
||||
echo "unsupported role filter: $role" >&2
|
||||
exit 2
|
||||
;;
|
||||
esac
|
||||
done
|
||||
return 1
|
||||
}
|
||||
|
||||
bindings_env=""
|
||||
operator_env=""
|
||||
output=""
|
||||
services=()
|
||||
roles=()
|
||||
while (($#)); do
|
||||
case "$1" in
|
||||
--bindings-env) bindings_env="${2:-}"; shift 2 ;;
|
||||
--operator-env) operator_env="${2:-}"; shift 2 ;;
|
||||
--output) output="${2:-}"; shift 2 ;;
|
||||
--service) services+=("${2:-}"); shift 2 ;;
|
||||
--role)
|
||||
roles+=("$(printf '%s' "${2:-}" | tr '[:upper:]' '[:lower:]')")
|
||||
shift 2
|
||||
;;
|
||||
*) usage ;;
|
||||
esac
|
||||
done
|
||||
|
||||
[[ -f "$bindings_env" && -f "$operator_env" && -n "$output" ]] || usage
|
||||
[[ ! -e "$output" ]] || { echo "refusing to overwrite connector override: $output" >&2; exit 2; }
|
||||
((${#services[@]})) || services=(core)
|
||||
((${#roles[@]})) || roles=(all)
|
||||
|
||||
for service in "${services[@]}"; do
|
||||
case "$service" in
|
||||
core|workspace-maintenance) ;;
|
||||
*)
|
||||
echo "unsupported service target: $service" >&2
|
||||
exit 2
|
||||
;;
|
||||
esac
|
||||
done
|
||||
|
||||
names=()
|
||||
targets=()
|
||||
@@ -64,6 +106,7 @@ while IFS=$'\t' read -r name target; do
|
||||
echo "retired semantic secret binding is not supported: ${name%_FILE}_SOURCE" >&2
|
||||
exit 2
|
||||
fi
|
||||
binding_matches_roles "$name" || continue
|
||||
[[ "$target" =~ ^/run/secrets/[A-Za-z0-9][A-Za-z0-9_.-]*$ && "$target" != *..* ]] || {
|
||||
echo "invalid connector secret target for $name: $target" >&2
|
||||
exit 2
|
||||
@@ -101,20 +144,25 @@ done < <(
|
||||
' "$bindings_env"
|
||||
)
|
||||
|
||||
((${#names[@]})) || { echo "no THT_WS_*_FILE connector bindings found in $bindings_env" >&2; exit 2; }
|
||||
((${#names[@]})) || {
|
||||
echo "no THT_WS_*_FILE connector bindings matched the selected roles in $bindings_env" >&2
|
||||
exit 2
|
||||
}
|
||||
|
||||
{
|
||||
printf '%s\n' '# Generated by scripts/generate-connector-secrets-override.sh; keep this file untracked.'
|
||||
printf '%s\n' \
|
||||
'services:' \
|
||||
' core:' \
|
||||
' env_file:' \
|
||||
' - path: ${THT_WORKSPACE_BINDINGS_ENV_FILE:?set THT_WORKSPACE_BINDINGS_ENV_FILE}' \
|
||||
' required: true' \
|
||||
' secrets:'
|
||||
for ((index = 0; index < ${#names[@]}; index += 1)); do
|
||||
printf ' - source: connector_secret_%d\n' "$((index + 1))"
|
||||
printf ' target: %s\n' "${targets[index]}"
|
||||
printf '%s\n' 'services:'
|
||||
for service in "${services[@]}"; do
|
||||
printf ' %s:\n' "$service"
|
||||
printf '%s\n' \
|
||||
' env_file:' \
|
||||
' - path: ${THT_WORKSPACE_BINDINGS_ENV_FILE:?set THT_WORKSPACE_BINDINGS_ENV_FILE}' \
|
||||
' required: true' \
|
||||
' secrets:'
|
||||
for ((index = 0; index < ${#names[@]}; index += 1)); do
|
||||
printf ' - source: connector_secret_%d\n' "$((index + 1))"
|
||||
printf ' target: %s\n' "${targets[index]}"
|
||||
done
|
||||
done
|
||||
printf '%s\n' '' 'secrets:'
|
||||
for ((index = 0; index < ${#names[@]}; index += 1)); do
|
||||
@@ -123,4 +171,5 @@ done < <(
|
||||
done
|
||||
} >"$output"
|
||||
|
||||
printf 'generated %s connector secret mount(s) at %s\n' "${#names[@]}" "$output"
|
||||
printf 'generated %s connector secret mount(s) for %s at %s\n' \
|
||||
"${#names[@]}" "$(IFS=,; printf '%s' "${services[*]}")" "$output"
|
||||
|
||||
Reference in New Issue
Block a user