Added config.getString() method to check if kubernetes.config has googleServiceAccount property

Signed-off-by: armandocomellas1 <cgarmando@google.com>
This commit is contained in:
armandocomellas1
2024-01-12 16:09:42 -06:00
parent 86baccb2d7
commit 87737a8155
2 changed files with 29 additions and 1 deletions
+13
View File
@@ -341,6 +341,7 @@ For example:
- type: 'gke'
projectId: 'gke-clusters'
region: 'europe-west1' # optional
authProvider: 'google' # optional
skipTLSVerify: false # optional
skipMetricsLookup: false # optional
exposeDashboard: false # optional
@@ -365,6 +366,18 @@ The Google Cloud project to look for Kubernetes clusters in.
The Google Cloud region to look for Kubernetes clusters in. Defaults to all
regions.
##### `authProvider` (optional)
Set the authentication method for discovering clusters and gathering information
about resources.
Defaults to `google` which leverages the logged in user's Google OAuth credentials.
Set to `googleServiceAccount` to leverage
Application Default Credentials (https://cloud.google.com/docs/authentication/application-default-credentials).
To use a service account JSON key (not recommended), set the `GOOGLE_APPLICATION_CREDENTIALS` environment variable
on the Backstage backend to the path of the service account key file.
##### `skipTLSVerify` (optional)
This determines whether the Kubernetes client verifies the TLS certificate
@@ -29,6 +29,7 @@ interface MatchResourceLabelEntry {
type GkeClusterLocatorOptions = {
projectId: string;
authProvider: string;
region?: string;
skipTLSVerify?: boolean;
skipMetricsLookup?: boolean;
@@ -54,8 +55,21 @@ export class GkeClusterLocator implements KubernetesClustersSupplier {
return { key: mrl.getString('key'), value: mrl.getString('value') };
}) ?? [];
let storeAuthProviderString: string;
let getGkeProperty;
try {
getGkeProperty = config.getString('authProvider');
} catch (err) {
getGkeProperty = 'google';
}
if (getGkeProperty === 'googleServiceAccount') {
storeAuthProviderString = 'googleServiceAccount';
} else {
storeAuthProviderString = 'google';
}
const options = {
projectId: config.getString('projectId'),
authProvider: storeAuthProviderString,
region: config.getOptionalString('region') ?? '-',
skipTLSVerify: config.getOptionalBoolean('skipTLSVerify') ?? false,
skipMetricsLookup:
@@ -97,6 +111,7 @@ export class GkeClusterLocator implements KubernetesClustersSupplier {
const {
projectId,
region,
authProvider,
skipTLSVerify,
skipMetricsLookup,
exposeDashboard,
@@ -121,7 +136,7 @@ export class GkeClusterLocator implements KubernetesClustersSupplier {
// TODO filter out clusters which don't have name or endpoint
name: r.name ?? 'unknown',
url: `https://${r.endpoint ?? ''}`,
authMetadata: { [ANNOTATION_KUBERNETES_AUTH_PROVIDER]: 'google' },
authMetadata: { [ANNOTATION_KUBERNETES_AUTH_PROVIDER]: authProvider },
skipTLSVerify,
skipMetricsLookup,
...(exposeDashboard