Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
水淹萌龙
kubesphere
提交
69a27e40
K
kubesphere
项目概览
水淹萌龙
/
kubesphere
与 Fork 源项目一致
Fork自
KubeSphere / kubesphere
通知
1
Star
0
Fork
0
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
DevOps
流水线
流水线任务
计划
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
K
kubesphere
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
DevOps
DevOps
流水线
流水线任务
计划
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
流水线任务
提交
Issue看板
提交
69a27e40
编写于
11月 16, 2020
作者:
Y
yuswift
浏览文件
操作
浏览文件
下载
电子邮件补丁
差异文件
Feat: support runnig ks-controller-manager without ldap option
Signed-off-by:
N
yuswift
<
yuswiftli@yunify.com
>
上级
0b18c571
变更
3
隐藏空白更改
内联
并排
Showing
3 changed file
with
17 addition
and
9 deletion
+17
-9
cmd/controller-manager/app/server.go
cmd/controller-manager/app/server.go
+4
-3
pkg/apiserver/authentication/authenticators/jwttoken/jwt_token.go
...erver/authentication/authenticators/jwttoken/jwt_token.go
+1
-0
pkg/controller/user/user_controller.go
pkg/controller/user/user_controller.go
+12
-6
未找到文件。
cmd/controller-manager/app/server.go
浏览文件 @
69a27e40
...
...
@@ -118,9 +118,8 @@ func run(s *options.KubeSphereControllerManagerOptions, stopCh <-chan struct{})
}
var
ldapClient
ldapclient
.
Interface
if
s
.
LdapOptions
==
nil
||
len
(
s
.
LdapOptions
.
Host
)
==
0
{
return
fmt
.
Errorf
(
"ldap service address MUST not be empty"
)
}
else
{
// when there is no ldapOption, we set ldapClient as nil, which means we don't need to sync user info into ldap.
if
s
.
LdapOptions
!=
nil
&&
len
(
s
.
LdapOptions
.
Host
)
!=
0
{
if
s
.
LdapOptions
.
Host
==
ldapclient
.
FAKE_HOST
{
// for debug only
ldapClient
=
ldapclient
.
NewSimpleLdap
()
}
else
{
...
...
@@ -129,6 +128,8 @@ func run(s *options.KubeSphereControllerManagerOptions, stopCh <-chan struct{})
return
fmt
.
Errorf
(
"failed to connect to ldap service, please check ldap status, error: %v"
,
err
)
}
}
}
else
{
klog
.
Info
(
"Kubesphere-controller-manager starts without ldap option, it will not sync user into ldap"
)
}
var
openpitrixClient
openpitrix
.
Client
...
...
pkg/apiserver/authentication/authenticators/jwttoken/jwt_token.go
浏览文件 @
69a27e40
...
...
@@ -22,6 +22,7 @@ import (
"k8s.io/apiserver/pkg/authentication/authenticator"
"k8s.io/apiserver/pkg/authentication/user"
"k8s.io/klog"
iamv1alpha2listers
"kubesphere.io/kubesphere/pkg/client/listers/iam/v1alpha2"
"kubesphere.io/kubesphere/pkg/models/iam/im"
)
...
...
pkg/controller/user/user_controller.go
浏览文件 @
69a27e40
...
...
@@ -287,9 +287,12 @@ func (c *Controller) reconcile(key string) error {
if
sliceutil
.
HasString
(
user
.
ObjectMeta
.
Finalizers
,
finalizer
)
{
klog
.
V
(
4
)
.
Infof
(
"delete user %s"
,
key
)
if
err
=
c
.
ldapClient
.
Delete
(
key
);
err
!=
nil
&&
err
!=
ldapclient
.
ErrUserNotExists
{
klog
.
Error
(
err
)
return
err
// we do not need to delete the user from ldapServer when ldapClient is nil
if
c
.
ldapClient
!=
nil
{
if
err
=
c
.
ldapClient
.
Delete
(
key
);
err
!=
nil
&&
err
!=
ldapclient
.
ErrUserNotExists
{
klog
.
Error
(
err
)
return
err
}
}
if
err
=
c
.
deleteRoleBindings
(
user
);
err
!=
nil
{
...
...
@@ -329,9 +332,12 @@ func (c *Controller) reconcile(key string) error {
return
nil
}
if
err
=
c
.
ldapSync
(
user
);
err
!=
nil
{
klog
.
Error
(
err
)
return
err
// we do not need to sync ldap info when ldapClient is nil
if
c
.
ldapClient
!=
nil
{
if
err
=
c
.
ldapSync
(
user
);
err
!=
nil
{
klog
.
Error
(
err
)
return
err
}
}
if
user
,
err
=
c
.
ensurePasswordIsEncrypted
(
user
);
err
!=
nil
{
...
...
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录