Skip to content

Commit

Permalink
feat: initial WIP version
Browse files Browse the repository at this point in the history
  • Loading branch information
dirien committed Oct 30, 2024
1 parent 37a54e8 commit 59deaba
Show file tree
Hide file tree
Showing 14 changed files with 961 additions and 0 deletions.
12 changes: 12 additions & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
FROM golang:1.23-alpine AS builder
WORKDIR /usr/src/app
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN go build -o /usr/local/bin/app .


FROM alpine:3.20.3
COPY --from=builder /usr/local/bin/app /usr/local/bin/secrets-store-csi-driver-provider-pulumi-esc

CMD ["secrets-store-csi-driver-provider-pulumi-esc"]
23 changes: 23 additions & 0 deletions Tiltfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
docker_build(
'dirien/secrets-store-csi-driver-provider-pulumi-esc',
context='.',
dockerfile='./Dockerfile',
live_update=[
sync('./pkg/', '/main.go'),
],
)

k8s_yaml(
'deployment/pulumi-esc-csi-provider.yaml'
)

k8s_yaml(
listdir('examples')
)

k8s_resource(
'secrets-store-csi-driver-provider-pulumi-esc',
labels=['secrets-store-csi-driver-provider-pulumi-esc']
)

tiltfile_path = config.main_path
83 changes: 83 additions & 0 deletions deployment/pulumi-esc-csi-provider.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,83 @@
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: secrets-store-csi-driver-provider-pulumi-esc
namespace: kube-system
labels:
app.kubernetes.io/name: secrets-store-csi-driver-provider-pulumi-esc
app.kubernetes.io/instance: secrets-store-csi-driver-provider-pulumi-esc
app.kubernetes.io/version: "0.4.2"
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: secrets-store-csi-driver-provider-pulumi-esc
namespace: kube-system
labels:
app.kubernetes.io/name: secrets-store-csi-driver-provider-pulumi-esc
app.kubernetes.io/instance: secrets-store-csi-driver-provider-pulumi-esc
app.kubernetes.io/version: "0.4.2"
rules:
- apiGroups: [""]
resources: ["secrets"]
verbs: ["get"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: secrets-store-csi-driver-provider-pulumi-esc
namespace: kube-system
labels:
app.kubernetes.io/name: secrets-store-csi-driver-provider-pulumi-esc
app.kubernetes.io/instance: secrets-store-csi-driver-provider-pulumi-esc
app.kubernetes.io/version: "0.4.2"
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: secrets-store-csi-driver-provider-pulumi-esc
subjects:
- kind: ServiceAccount
namespace: kube-system
name: secrets-store-csi-driver-provider-pulumi-esc
---
apiVersion: apps/v1
kind: DaemonSet
metadata:
name: secrets-store-csi-driver-provider-pulumi-esc
namespace: kube-system
labels:
app.kubernetes.io/name: secrets-store-csi-driver-provider-pulumi-esc
app.kubernetes.io/instance: secrets-store-csi-driver-provider-pulumi-esc
app.kubernetes.io/version: "0.4.2"
spec:
selector:
matchLabels:
app.kubernetes.io/name: secrets-store-csi-driver-provider-pulumi-esc
app.kubernetes.io/instance: secrets-store-csi-driver-provider-pulumi-esc
template:
metadata:
labels:
app.kubernetes.io/name: secrets-store-csi-driver-provider-pulumi-esc
app.kubernetes.io/instance: secrets-store-csi-driver-provider-pulumi-esc
app.kubernetes.io/version: "0.4.2"
spec:
serviceAccountName: secrets-store-csi-driver-provider-pulumi-esc
securityContext:
{}
containers:
- name: secrets-store-csi-driver-provider-pulumi-esc
image: "dirien/secrets-store-csi-driver-provider-pulumi-esc"
imagePullPolicy: Always
resources:
{}
volumeMounts:
- name: socket
mountPath: /etc/kubernetes/secrets-store-csi-providers
volumes:
- name: socket
hostPath:
path: /etc/kubernetes/secrets-store-csi-providers
type: DirectoryOrCreate
nodeSelector:
kubernetes.io/os: linux
44 changes: 44 additions & 0 deletions examples/deployment.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@

apiVersion: apps/v1
kind: Deployment
metadata:
name: example-provider-pulumi-esc
namespace: default
labels:
app: example-provider-pulumi-esc
spec:
replicas: 1
selector:
matchLabels:
app: example-provider-pulumi-esc
template:
metadata:
labels:
app: example-provider-pulumi-esc
spec:
containers:
- name: client
image: busybox:latest
command: ["sh", "-c"]
env:
- name: SECRET_FROM_K8S_SECRET
valueFrom:
secretKeyRef:
name: example-provider-secret
key: password
args:
- |
set -eux
ls /run/secrets
find /run/secrets/ -mindepth 1 -maxdepth 1 -not -name '.*' | xargs -t -I {} sh -c 'echo "$(cat "{}")"'
tail -f /dev/null
volumeMounts:
- name: data
mountPath: /run/secrets
volumes:
- name: data
csi:
driver: secrets-store.csi.k8s.io
readOnly: true
volumeAttributes:
secretProviderClass: "example-provider-pulumi-esc"
9 changes: 9 additions & 0 deletions examples/secret.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
apiVersion: v1
kind: Secret
metadata:
name: pulumi-secret-provider-auth-credentials
namespace: default
type: Opaque
stringData:
pulumi-access-token: xxx

22 changes: 22 additions & 0 deletions examples/secretproviderclass.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
apiVersion: secrets-store.csi.x-k8s.io/v1
kind: SecretProviderClass
metadata:
name: example-provider-pulumi-esc
namespace: default
spec:
provider: pulumi
parameters:
apiUrl: https://api.pulumi.com/api/esc
organization: dirien
project: voting-app
environment: db
authSecretName: pulumi-secret-provider-auth-credentials
authSecretNamespace: default
objects: |
- objectName: postgres
secretObjects:
- secretName: example-provider-secret
type: Opaque
data:
- objectName: postgres
key: password
58 changes: 58 additions & 0 deletions go.mod
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
module github.com/dirien/pulumi-esc-csi-provider

go 1.23.1

require (
github.com/go-playground/validator/v10 v10.22.1
github.com/pulumi/esc-sdk/sdk v0.10.0
google.golang.org/grpc v1.63.2
gopkg.in/yaml.v3 v3.0.1
k8s.io/apimachinery v0.30.0
k8s.io/client-go v0.30.0
sigs.k8s.io/secrets-store-csi-driver v1.4.2
)

require (
github.com/davecgh/go-spew v1.1.1 // indirect
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
github.com/gabriel-vasile/mimetype v1.4.3 // indirect
github.com/go-logr/logr v1.4.1 // indirect
github.com/go-openapi/jsonpointer v0.19.6 // indirect
github.com/go-openapi/jsonreference v0.20.2 // indirect
github.com/go-openapi/swag v0.22.3 // indirect
github.com/go-playground/locales v0.14.1 // indirect
github.com/go-playground/universal-translator v0.18.1 // indirect
github.com/gogo/protobuf v1.3.2 // indirect
github.com/golang/protobuf v1.5.4 // indirect
github.com/google/gnostic-models v0.6.8 // indirect
github.com/google/gofuzz v1.2.0 // indirect
github.com/google/uuid v1.6.0 // indirect
github.com/josharian/intern v1.0.0 // indirect
github.com/json-iterator/go v1.1.12 // indirect
github.com/leodido/go-urn v1.4.0 // indirect
github.com/mailru/easyjson v0.7.7 // indirect
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
github.com/modern-go/reflect2 v1.0.2 // indirect
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
github.com/stretchr/testify v1.9.0 // indirect
golang.org/x/crypto v0.21.0 // indirect
golang.org/x/net v0.23.0 // indirect
golang.org/x/oauth2 v0.17.0 // indirect
golang.org/x/sys v0.18.0 // indirect
golang.org/x/term v0.18.0 // indirect
golang.org/x/text v0.14.0 // indirect
golang.org/x/time v0.3.0 // indirect
google.golang.org/appengine v1.6.8 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20240227224415-6ceb2ff114de // indirect
google.golang.org/protobuf v1.33.0 // indirect
gopkg.in/ghodss/yaml.v1 v1.0.0 // indirect
gopkg.in/inf.v0 v0.9.1 // indirect
gopkg.in/yaml.v2 v2.4.0 // indirect
k8s.io/api v0.30.0 // indirect
k8s.io/klog/v2 v2.120.1 // indirect
k8s.io/kube-openapi v0.0.0-20240228011516-70dd3763d340 // indirect
k8s.io/utils v0.0.0-20230726121419-3b25d923346b // indirect
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect
sigs.k8s.io/yaml v1.3.0 // indirect
)
Loading

0 comments on commit 59deaba

Please sign in to comment.