- 支持针对指定用户,指定时间段授权操作。
- 支持根据微服务的镜像地址,自动从相应的镜像仓库获取微服务的镜像标签。
注意:该权限仅控制只读用户的权限,读写用户默认已有权限操作,会忽略该文件的配置。
configmap:``kubedoor-config`
-
UPDATE_IMAGE{ "default": { "isOperationAllowed": false }, "saas-prod": { "isOperationAllowed": true, "allowedOperationPeriod": "20:00-08:00", "user": [ "a0111", "a0222" ] }, "saas-prod-hw": { "isOperationAllowed": true, "allowedOperationPeriod": "20:00-08:00", "user": [ "a0333", "a0444" ] } } -
default表示未匹配到的K8S是禁止操作的。"default": { "isOperationAllowed": false }
-
saas-prod,saas-prod-hw表示指定的K8S环境 -
allowedOperationPeriod表示可操作的时间段 -
user表示可操作的只读用户列表
配置镜像仓库的信息是为了自动从镜像仓库获取微服务的镜像标签
目前支持华为云镜像仓库,阿里云镜像仓库,以及自建的Harbor
匹配逻辑:微服务点击更新后,获取微服务镜像地址,然后从REGISTRY_SECRET中找对应的仓库地址(找不到则无法获取,需要手动填写需要部署的镜像标签),找到则再找匹配的K8S名称(找不到取default),再取到ak,sk信息,然后连接相应的仓库获取该微服务的最新的20个镜像标签。
configmap:``kubedoor-config`
-
REGISTRY_SECRET{ "swr.cn-south-1.myhuaweicloud.com": { "default": { "ak": "xxxxxxxx", "sk": "xxxxxxxxxxxxxxxxxxx" } }, "registry.cn-shenzhen.aliyuncs.com": { "default": { "ak": "xxxxxxxxx", "sk": "xxxxxxxxxxxxxxxxxxx" }, "myk8s-1": { "ak": "xxxxxxxxx", "sk": "xxxxxxxxxxxxxxxxxxx" } }, "harbor.xxxxx.com": { "default": { "ak": "username", "sk": "password" } } } -
swr.cn-south-1.myhuaweicloud.com,registry.cn-shenzhen.aliyuncs.com,harbor.xxxxx.com表示镜像仓库的地址,与微服务的image地址匹配。 -
default表示未匹配到的K8S,则从default中获取连接镜像仓库的ak,sk信息。 -
myk8s-1表示匹配到的K8S,则从该字段中获取连接镜像仓库的ak,sk信息。