+kubebuilder:rbac:groups="coordination.k8s.io",resources="leases",verbs={get,create,update,watch} +kubebuilder:rbac:groups="authentication.k8s.io",resources="tokenreviews",verbs={create} +kubebuilder:rbac:groups="authorization.k8s.io",resources="subjectaccessreviews",verbs={create}
(ctx context.Context)
| 94 | //+kubebuilder:rbac:groups="authorization.k8s.io",resources="subjectaccessreviews",verbs={create} |
| 95 | |
| 96 | func initManager(ctx context.Context) (runtime.Options, error) { |
| 97 | log := logging.FromContext(ctx).WithName("manager") |
| 98 | |
| 99 | options := runtime.Options{} |
| 100 | options.Cache.SyncPeriod = initialize.Pointer(time.Hour) |
| 101 | |
| 102 | // If we aren't using it, http/2 should be disabled |
| 103 | // due to its vulnerabilities. More specifically, disabling http/2 will |
| 104 | // prevent from being vulnerable to the HTTP/2 Stream Cancellation and |
| 105 | // Rapid Reset CVEs. For more information see: |
| 106 | // - https://github.com/advisories/GHSA-qppj-fm5r-hxr3 |
| 107 | // - https://github.com/advisories/GHSA-4374-p667-p6c8 |
| 108 | options.Metrics.TLSOpts = append(options.Metrics.TLSOpts, func(c *tls.Config) { |
| 109 | log.Info("enabling metrics via http/1.1") |
| 110 | c.NextProtos = []string{"http/1.1"} |
| 111 | }) |
| 112 | |
| 113 | // Use https port |
| 114 | options.Metrics.BindAddress = ":8443" |
| 115 | options.Metrics.SecureServing = true |
| 116 | |
| 117 | // FilterProvider is used to protect the metrics endpoint with authn/authz. |
| 118 | // These configurations ensure that only authorized users and service accounts |
| 119 | // can access the metrics endpoint. The RBAC are configured in 'config/rbac/kustomization.yaml'. More info: |
| 120 | // https://pkg.go.dev/sigs.k8s.io/controller-runtime@v0.19.3/pkg/metrics/filters#WithAuthenticationAndAuthorization |
| 121 | options.Metrics.FilterProvider = filters.WithAuthenticationAndAuthorization |
| 122 | |
| 123 | // Set health probe port |
| 124 | options.HealthProbeBindAddress = ":8081" |
| 125 | |
| 126 | // Enable leader elections when configured with a valid Lease.coordination.k8s.io name. |
| 127 | // - https://docs.k8s.io/concepts/architecture/leases |
| 128 | // - https://releases.k8s.io/v1.30.0/pkg/apis/coordination/validation/validation.go#L26 |
| 129 | if lease := os.Getenv("PGO_CONTROLLER_LEASE_NAME"); len(lease) > 0 { |
| 130 | if errs := validation.IsDNS1123Subdomain(lease); len(errs) > 0 { |
| 131 | return options, fmt.Errorf("value for PGO_CONTROLLER_LEASE_NAME is invalid: %v", errs) |
| 132 | } |
| 133 | |
| 134 | options.LeaderElection = true |
| 135 | options.LeaderElectionID = lease |
| 136 | options.LeaderElectionNamespace = os.Getenv("PGO_NAMESPACE") |
| 137 | } |
| 138 | |
| 139 | // Check PGO_TARGET_NAMESPACE for backwards compatibility with |
| 140 | // "singlenamespace" installations |
| 141 | singlenamespace := strings.TrimSpace(os.Getenv("PGO_TARGET_NAMESPACE")) |
| 142 | |
| 143 | // Check PGO_TARGET_NAMESPACES for non-cluster-wide, multi-namespace |
| 144 | // installations |
| 145 | multinamespace := strings.TrimSpace(os.Getenv("PGO_TARGET_NAMESPACES")) |
| 146 | |
| 147 | // Initialize DefaultNamespaces if any target namespaces are set |
| 148 | if len(singlenamespace) > 0 || len(multinamespace) > 0 { |
| 149 | options.Cache.DefaultNamespaces = map[string]runtime.CacheConfig{} |
| 150 | } |
| 151 | |
| 152 | if len(singlenamespace) > 0 { |
| 153 | options.Cache.DefaultNamespaces[singlenamespace] = runtime.CacheConfig{} |