Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions PROJECT
Original file line number Diff line number Diff line change
Expand Up @@ -104,6 +104,14 @@ resources:
kind: Project
path: github.com/k-orc/openstack-resource-controller/api/v1alpha1
version: v1alpha1
- api:
crdVersion: v1
namespaced: true
domain: k-orc.cloud
group: openstack
kind: RegisteredLimit
path: github.com/k-orc/openstack-resource-controller/api/v1alpha1
version: v1alpha1
- api:
crdVersion: v1
namespaced: true
Expand Down
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -85,6 +85,7 @@ kubectl delete -f $ORC_RELEASE
| network | | ◐ | ◐ |
| port | | ◐ | ◐ |
| project | | ◐ | ◐ |
| registered limits | | | ◐ |
| role | | ✔ | ✔ |
| router | | ◐ | ◐ |
| security group (incl. rule) | | ✔ | ✔ |
Expand Down
92 changes: 92 additions & 0 deletions api/v1alpha1/registeredlimit_types.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,92 @@
/*
Copyright The ORC Authors.

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

package v1alpha1

// RegisteredLimitResourceSpec contains the desired state of the resource.
type RegisteredLimitResourceSpec struct {
// description is a human-readable description for the resource.
// +kubebuilder:validation:MinLength:=1
// +kubebuilder:validation:MaxLength:=255
// +optional
Description *string `json:"description,omitempty"`

// serviceRef is a reference to the ORC Service which this resource is associated with.
// +required
// +kubebuilder:validation:XValidation:rule="self == oldSelf",message="serviceRef is immutable"
ServiceRef KubernetesNameRef `json:"serviceRef,omitempty"`

// resourceName is name of the resource to be limited.
// +kubebuilder:validation:MinLength:=1
// +kubebuilder:validation:MaxLength:=255
// +required
// +kubebuilder:validation:XValidation:rule="self == oldSelf",message="resourceName is immutable"
ResourceName string `json:"resourceName,omitempty"`

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It looks like keystone enforces names with non-whitespaces chars only:

name: dict[str, Any] = {
    "type": "string",
    "minLength": 1,
    "maxLength": 255,
    "pattern": r"[\S]+",
    "description": "The resource name.",
}

https://github.com/openstack/keystone/blob/50d266e/keystone/api/validation/parameter_types.py#L19-L25

We should also have the same validation pattern otherwise we may end up in a situation where we get endless reconciles that can never succeed if someone sets a name with a whitespace.

In other words: our API for resource specs can be stricter than the OpenStack API, never the other way around.


// defaultLimit is limit of the specified resource in the given context.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we perhaps explain that -1 means unlimited (no quota), while 0 means hard blocking the usage of this resource? It's easy to wrongly assume that 0 means unlimited.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should also note the limitation of setting 0 at creation pointing to the gophercloud issue.

It seems we can't reliably write a CEL validation that would prevent that (we need the CRDValidationRatcheting gate that's only enabled by default starting from kube 1.30, and we target 1.29 as our floor version). So we would need to add a check in the actuator, at resource creation.

// +kubebuilder:validation:Minimum=-1
// +kubebuilder:validation:Maximum=2147483647
// +required
DefaultLimit *int32 `json:"defaultLimit,omitempty"`
}

// RegisteredLimitFilter defines an existing resource by its properties
// +kubebuilder:validation:MinProperties:=1
type RegisteredLimitFilter struct {
// description of the existing resource
// +kubebuilder:validation:MinLength:=1
// +kubebuilder:validation:MaxLength:=255
// +optional
Description *string `json:"description,omitempty"`
Comment thread
gndrmnn marked this conversation as resolved.

// serviceRef is a reference to the ORC Service which this resource is associated with.
// +optional
ServiceRef *KubernetesNameRef `json:"serviceRef,omitempty"`

// resourceName is name of the resource to be limited.
// +kubebuilder:validation:MinLength:=1
// +kubebuilder:validation:MaxLength:=255
// +optional
ResourceName *string `json:"resourceName,omitempty"`
}

// RegisteredLimitResourceStatus represents the observed state of the resource.
type RegisteredLimitResourceStatus struct {
// description is a human-readable description for the resource.
// +kubebuilder:validation:MaxLength=1024
// +optional
Description string `json:"description,omitempty"`

// resourceName is name of the resource to be limited.
// +kubebuilder:validation:MinLength:=1
// +kubebuilder:validation:MaxLength:=255
// +optional
ResourceName string `json:"resourceName,omitempty"`

// regionID is the ID of the region that contains the service endpoint.
// +kubebuilder:validation:MaxLength:=1024
// +optional
RegionID string `json:"regionID,omitempty"`

// serviceID is a reference to the ORC Service which this resource is associated with.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy & paste error I assume :)
It should be

Suggested change
// serviceID is a reference to the ORC Service which this resource is associated with.
// serviceID is the UUID of the service to which the registered limit belongs.

// +kubebuilder:validation:MaxLength:=1024
// +optional
ServiceID string `json:"serviceID,omitempty"`

// defaultLimit is limit of the specified resource in the given context.
// +optional
DefaultLimit int32 `json:"defaultLimit,omitempty"`
}
226 changes: 226 additions & 0 deletions api/v1alpha1/zz_generated.deepcopy.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading
Loading