-
Notifications
You must be signed in to change notification settings - Fork 598
Specify fileSystemId from K8 ConfigMap/Secret #1724
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
|
Welcome @aliyajo! |
|
Hi @aliyajo. Thanks for your PR. I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
lgtm, just leave some nit comments, up to you whether to do it in this PR or not
Add support for dynamic filesystem ID resolution from ConfigMaps and Secrets. Changes: - Add fileSystemIdConfigRef and fileSystemIdSecretRef StorageClass parameters - Add opt-in RBAC via controller.fileSystemIdRefs.enabled flag (default:false) - Add permissions to grant access to configmaps and secret - Improve error messages to detect RBAC issues and guide users to enable feature flag
Changes: - Enforce that only one fileSystem ID source must be specified - Update README documentation - Improve error handling with structured reference parsing - Update unit tests
- Seperated testing and main functionality for file id resolution - Fixed code style for getFileSystemIdFromRef
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: aliyajo, DavidXU12345 The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/ok-to-test |
|
/retest |
Is this a bug fix or adding new feature?
Adds a feature via #1615
What is this PR about? / Why do we need it?
Adds support for dynamically resolving filesystemId from K8 ConfigMaps and Secrets instead of having to manually copy the fileSystem Id.
Can reference ConfigMaps or Secrets containing FileSystemIDs, which the CSI driver will read automatically during provisioning.
New StorageClass parameters
fileSystemIdConfigRef: Reference to a ConfigMapfileSystemIdSecretRef: Reference to a SecretReference Format:
namespace/name/keyExample:
Features:
controller.fileSystemIdRefs.enabled=true(default:false)What testing is done?