forked from rook/rook
object: make OBC genUserID unique across clusters
Rook's implementation of OBC's GenerateUserID could generate colliding user IDs for multisite clusters where each site is configured with the same namespace/name of CephObjectStore. Add the Ceph cluster FSID to the generated name to ensure the names won't conflict for multiple sites. Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
This commit is contained in:
@@ -68,7 +68,10 @@ func (p Provisioner) GenerateUserID(obc *v1alpha1.ObjectBucketClaim, ob *v1alpha
|
||||
return getCephUser(ob), nil
|
||||
}
|
||||
|
||||
username := p.genUserName(obc.Name, obc.Namespace)
|
||||
username, err := p.genUserName(obc.Name, obc.Namespace)
|
||||
if err != nil {
|
||||
return "", errors.Wrap(err, "failed to generate user id for OBC")
|
||||
}
|
||||
|
||||
return username, nil
|
||||
}
|
||||
|
||||
@@ -47,10 +47,15 @@ func (p *Provisioner) createCephUser(username string) (accKey string, secKey str
|
||||
return u.Keys[0].AccessKey, u.Keys[0].SecretKey, nil
|
||||
}
|
||||
|
||||
func (p *Provisioner) genUserName(obcName, obcNamespace string) string {
|
||||
// user name can be deterministically generated by obc name and namespace
|
||||
// since there can't be 2 obcs in the same namespace with the same name, this will not collide
|
||||
return "obc-" + obcNamespace + "-" + obcName
|
||||
func (p *Provisioner) genUserName(obcName, obcNamespace string) (string, error) {
|
||||
// user name can be deterministically generated by obc name and namespace. since there can't be
|
||||
// 2 obcs in the same namespace w/ the same name, this won't collide w/in the same k8s cluster.
|
||||
// However, it can collide in multisite setups, so use the Ceph cluster FSID
|
||||
fsid := p.clusterInfo.FSID
|
||||
if p.clusterInfo.FSID == "" {
|
||||
return "", errors.Errorf("failed to find ceph cluster FSID")
|
||||
}
|
||||
return "obc-" + obcNamespace + "-" + obcName + "-" + fsid, nil
|
||||
}
|
||||
|
||||
// Delete the user and bucket created by OBC with help of radosgw-admin commands
|
||||
|
||||
Reference in New Issue
Block a user