Skip to content

Commit

Permalink
feat: add NamespacedVerifier CRD [multi-tenancy PR 11] (#1428)
Browse files Browse the repository at this point in the history
Co-authored-by: Akash Singhal <[email protected]>
  • Loading branch information
binbin-li and akashsinghal authored May 4, 2024
1 parent ebdf969 commit e13af40
Show file tree
Hide file tree
Showing 61 changed files with 1,953 additions and 191 deletions.
8 changes: 8 additions & 0 deletions PROJECT
Original file line number Diff line number Diff line change
Expand Up @@ -104,4 +104,12 @@ resources:
kind: NamespacedKeyManagementProvider
path: github.com/deislabs/ratify/api/v1beta1
version: v1beta1
- api:
crdVersion: v1
namespaced: true
domain: ratify.deislabs.io
group: config
kind: NamespacedVerifier
path: github.com/deislabs/ratify/api/v1beta1
version: v1beta1
version: "3"
78 changes: 78 additions & 0 deletions api/unversioned/namespacedverifier_types.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
/*
Copyright The Ratify Authors.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

// +kubebuilder:skip
package unversioned

import (
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
runtime "k8s.io/apimachinery/pkg/runtime"
)

// NamespacedVerifierSpec defines the desired state of NamespacedVerifier
type NamespacedVerifierSpec struct {
// INSERT ADDITIONAL SPEC FIELDS - desired state of cluster
// Important: Run "make" to regenerate code after modifying this file

// Name of the verifier
Name string `json:"name"`

// Version of the verifier plugin. Optional
Version string `json:"version,omitempty"`

// The type of artifact this verifier handles
ArtifactTypes string `json:"artifactTypes"`

// # Optional. URL/file path
Address string `json:"address,omitempty"`

// OCI Artifact source to download the plugin from, optional
Source *PluginSource `json:"source,omitempty"`

// Parameters for this verifier
Parameters runtime.RawExtension `json:"parameters,omitempty"`
}

// NamespacedVerifierStatus defines the observed state of NamespacedVerifier
type NamespacedVerifierStatus struct {
// INSERT ADDITIONAL STATUS FIELD - define observed state of cluster
// Important: Run "make" to regenerate code after modifying this file

// Is successful in finding the plugin
IsSuccess bool `json:"issuccess"`
// Error message if operation was unsuccessful
// +optional
Error string `json:"error,omitempty"`
// Truncated error message if the message is too long
// +optional
BriefError string `json:"brieferror,omitempty"`
}

// NamespacedVerifier is the Schema for the namespacedverifiers API
type NamespacedVerifier struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`

Spec NamespacedVerifierSpec `json:"spec,omitempty"`
Status NamespacedVerifierStatus `json:"status,omitempty"`
}

// NamespacedVerifierList contains a list of NamespacedVerifier
type NamespacedVerifierList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []NamespacedVerifier `json:"items"`
}
79 changes: 79 additions & 0 deletions api/unversioned/zz_generated.deepcopy.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

93 changes: 93 additions & 0 deletions api/v1beta1/namespacedverifier_types.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,93 @@
/*
Copyright The Ratify Authors.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

package v1beta1

import (
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
runtime "k8s.io/apimachinery/pkg/runtime"
)

// EDIT THIS FILE! THIS IS SCAFFOLDING FOR YOU TO OWN!
// NOTE: json tags are required. Any new fields you add must have json tags for the fields to be serialized.

// NamespacedVerifierSpec defines the desired state of NamespacedVerifier
type NamespacedVerifierSpec struct {
// INSERT ADDITIONAL SPEC FIELDS - desired state of cluster
// Important: Run "make" to regenerate code after modifying this file

// Name of the verifier
Name string `json:"name"`

// Version of the verifier plugin. Optional
Version string `json:"version,omitempty"`

// The type of artifact this verifier handles
ArtifactTypes string `json:"artifactTypes"`

// # Optional. URL/file path
Address string `json:"address,omitempty"`

// OCI Artifact source to download the plugin from, optional
Source *PluginSource `json:"source,omitempty"`

// +kubebuilder:pruning:PreserveUnknownFields
// Parameters for this verifier
Parameters runtime.RawExtension `json:"parameters,omitempty"`
}

// NamespacedVerifierStatus defines the observed state of NamespacedVerifier
type NamespacedVerifierStatus struct {
// INSERT ADDITIONAL STATUS FIELD - define observed state of cluster
// Important: Run "make" to regenerate code after modifying this file

// Is successful in finding the plugin
IsSuccess bool `json:"issuccess"`
// Error message if operation was unsuccessful
// +optional
Error string `json:"error,omitempty"`
// Truncated error message if the message is too long
// +optional
BriefError string `json:"brieferror,omitempty"`
}

// +kubebuilder:object:root=true
// +kubebuilder:resource:scope="Namespaced"
// +kubebuilder:subresource:status
// +kubebuilder:storageversion
// +kubebuilder:printcolumn:name="IsSuccess",type=boolean,JSONPath=`.status.issuccess`
// +kubebuilder:printcolumn:name="Error",type=string,JSONPath=`.status.brieferror`
// NamespacedVerifier is the Schema for the namespacedverifiers API
type NamespacedVerifier struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`

Spec NamespacedVerifierSpec `json:"spec,omitempty"`
Status NamespacedVerifierStatus `json:"status,omitempty"`
}

// +kubebuilder:object:root=true
// +kubebuilder:storageversion
// NamespacedVerifierList contains a list of NamespacedVerifier
type NamespacedVerifierList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []NamespacedVerifier `json:"items"`
}

func init() {
SchemeBuilder.Register(&NamespacedVerifier{}, &NamespacedVerifierList{})
}
Loading

0 comments on commit e13af40

Please sign in to comment.