Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions Cargo.nix

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ resolver = "2"
version = "0.0.0-dev"
authors = ["Stackable GmbH <info@stackable.tech>"]
license = "OSL-3.0"
edition = "2021"
edition = "2024"
repository = "https://github.com/stackabletech/opa-operator"

[workspace.dependencies]
Expand Down
5 changes: 3 additions & 2 deletions rust/bundle-builder/src/main.rs
Original file line number Diff line number Diff line change
Expand Up @@ -210,7 +210,8 @@ async fn main() -> Result<(), StartupError> {
.context(RunServerSnafu)
});

future::select(reflector, server).await.factor_first().0
future::select(reflector, server).await.factor_first().0?;
Ok(())
}

#[derive(Snafu, Debug)]
Expand Down Expand Up @@ -244,7 +245,7 @@ enum BundleError {
}

impl BundleError {
fn to_http_response(&self) -> impl IntoResponse {
fn to_http_response(&self) -> impl IntoResponse + use<> {
(
http::StatusCode::INTERNAL_SERVER_ERROR,
"failed to build bundle, see opa-bundle-builder logs for more details",
Expand Down
21 changes: 8 additions & 13 deletions rust/operator-binary/src/controller.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1203,10 +1203,9 @@ fn build_config_file(
if let Some(ContainerLogConfig {
choice: Some(ContainerLogConfigChoice::Automatic(log_config)),
}) = merged_config.logging.containers.get(&Container::Opa)
&& let Some(config) = log_config.loggers.get("decision")
{
if let Some(config) = log_config.loggers.get("decision") {
decision_logging_enabled = config.level != LogLevel::NONE;
}
decision_logging_enabled = config.level != LogLevel::NONE;
}

let decision_logging = if decision_logging_enabled {
Expand Down Expand Up @@ -1341,13 +1340,11 @@ fn build_bundle_builder_start_command(merged_config: &OpaConfig, container_name:
.logging
.containers
.get(&Container::BundleBuilder)
{
if let Some(AppenderConfig {
&& let Some(AppenderConfig {
level: Some(log_level),
}) = log_config.console
{
console_logging_off = log_level == LogLevel::NONE
}
{
console_logging_off = log_level == LogLevel::NONE
};

formatdoc! {"
Expand Down Expand Up @@ -1401,13 +1398,11 @@ fn sidecar_container_log_level(
if let Some(ContainerLogConfig {
choice: Some(ContainerLogConfigChoice::Automatic(log_config)),
}) = merged_config.logging.containers.get(sidecar_container)
{
if let Some(logger) = log_config
&& let Some(logger) = log_config
.loggers
.get(AutomaticContainerLogConfig::ROOT_LOGGER)
{
return BundleBuilderLogLevel::from(logger.level);
}
{
return BundleBuilderLogLevel::from(logger.level);
}

BundleBuilderLogLevel::Info
Expand Down
2 changes: 1 addition & 1 deletion rust/operator-binary/src/webhooks/conversion.rs
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ pub async fn create_webhook_server(
disable_crd_maintenance,
};

let (conversion_webhook, _initial_reconcile_rx) =
let (conversion_webhook, _) =
ConversionWebhook::new(crds_and_handlers, client, conversion_webhook_options);

let webhook_server_options = WebhookServerOptions {
Expand Down
5 changes: 3 additions & 2 deletions rust/user-info-fetcher/src/backend/active_directory.rs
Original file line number Diff line number Diff line change
Expand Up @@ -181,14 +181,15 @@ pub(crate) async fn get_user_info(
.context(UserNotFoundSnafu { request })?;
let user = SearchEntry::construct(user);
tracing::debug!(?user, "got user from LDAP");
user_attributes(
let attrs = user_attributes(
&mut ldap,
base_distinguished_name,
&user,
custom_attribute_mappings,
additional_group_attribute_filters,
)
.await
.await?;
Ok(attrs)
}

/// Constructs a user filter that searches both the UPN as well as the sAMAccountName attributes.
Expand Down
5 changes: 3 additions & 2 deletions rust/user-info-fetcher/src/backend/openldap.rs
Original file line number Diff line number Diff line change
Expand Up @@ -178,14 +178,15 @@ impl ResolvedOpenLdapBackend {
// Search for groups that contain this user
let groups = search_user_groups(&mut ldap, &user, &self.config).await?;

user_attributes(
let attrs = user_attributes(
user_id_attribute,
user_name_attribute,
&user,
groups,
&self.config.custom_attribute_mappings,
)
.await
.await?;
Ok(attrs)
}
}

Expand Down
121 changes: 61 additions & 60 deletions rust/user-info-fetcher/src/main.rs
Original file line number Diff line number Diff line change
Expand Up @@ -209,7 +209,8 @@ async fn main() -> Result<(), StartupError> {
axum::serve(listener, app.into_make_service())
.with_graceful_shutdown(shutdown_requested)
.await
.context(RunServerSnafu)
.context(RunServerSnafu)?;
Ok(())
}

#[derive(Debug, Deserialize, PartialEq, Eq, Hash, Clone)]
Expand Down Expand Up @@ -315,64 +316,64 @@ async fn get_user_info(
backend,
user_info_cache,
} = state;
Ok(Json(
user_info_cache
.try_get_with_by_ref(&req, async {
match backend.as_ref() {
ResolvedBackend::None => {
let user_id = match &req {
UserInfoRequest::UserInfoRequestById(UserInfoRequestById { id }) => {
Some(id)
}
_ => None,
};
let username = match &req {
UserInfoRequest::UserInfoRequestByName(UserInfoRequestByName {
username,
}) => Some(username),
_ => None,
};
Ok(UserInfo {
id: user_id.cloned(),
username: username.cloned(),
groups: vec![],
custom_attributes: HashMap::new(),
})
}
ResolvedBackend::Keycloak(keycloak) => keycloak
.get_user_info(&req)
.await
.context(get_user_info_error::KeycloakSnafu),
ResolvedBackend::ExperimentalXfscAas(aas) => aas
.get_user_info(&req)
.await
.context(get_user_info_error::ExperimentalXfscAasSnafu),
ResolvedBackend::ActiveDirectory {
ldap_server,
tls,
base_distinguished_name,
custom_attribute_mappings,
additional_group_attribute_filters,
} => backend::active_directory::get_user_info(
&req,
ldap_server,
tls,
base_distinguished_name,
custom_attribute_mappings,
additional_group_attribute_filters,
)
.await
.context(get_user_info_error::ActiveDirectorySnafu),
ResolvedBackend::Entra(entra) => entra
.get_user_info(&req)
.await
.context(get_user_info_error::EntraSnafu),
ResolvedBackend::OpenLdap(openldap) => openldap
.get_user_info(&req)
.await
.context(get_user_info_error::OpenLdapSnafu),
let user_info = user_info_cache
.try_get_with_by_ref(&req, async {
match backend.as_ref() {
ResolvedBackend::None => {
let user_id = match &req {
UserInfoRequest::UserInfoRequestById(UserInfoRequestById { id }) => {
Some(id)
}
_ => None,
};
let username = match &req {
UserInfoRequest::UserInfoRequestByName(UserInfoRequestByName {
username,
}) => Some(username),
_ => None,
};
Ok(UserInfo {
id: user_id.cloned(),
username: username.cloned(),
groups: vec![],
custom_attributes: HashMap::new(),
})
}
})
.await?,
))
ResolvedBackend::Keycloak(keycloak) => keycloak
.get_user_info(&req)
.await
.context(get_user_info_error::KeycloakSnafu),
ResolvedBackend::ExperimentalXfscAas(aas) => aas
.get_user_info(&req)
.await
.context(get_user_info_error::ExperimentalXfscAasSnafu),
ResolvedBackend::ActiveDirectory {
ldap_server,
tls,
base_distinguished_name,
custom_attribute_mappings,
additional_group_attribute_filters,
} => backend::active_directory::get_user_info(
&req,
ldap_server,
tls,
base_distinguished_name,
custom_attribute_mappings,
additional_group_attribute_filters,
)
.await
.context(get_user_info_error::ActiveDirectorySnafu),
ResolvedBackend::Entra(entra) => entra
.get_user_info(&req)
.await
.context(get_user_info_error::EntraSnafu),
ResolvedBackend::OpenLdap(openldap) => openldap
.get_user_info(&req)
.await
.context(get_user_info_error::OpenLdapSnafu),
}
})
.await?;

Ok(Json(user_info))
}
Loading