@@ -63,32 +63,33 @@ var (
63
63
type Operator struct {
64
64
queueinformer.Operator
65
65
66
- clock utilclock.Clock
67
- logger * logrus.Logger
68
- opClient operatorclient.ClientInterface
69
- client versioned.Interface
70
- lister operatorlister.OperatorLister
71
- copiedCSVLister operatorsv1alpha1listers.ClusterServiceVersionLister
72
- ogQueueSet * queueinformer.ResourceQueueSet
73
- csvQueueSet * queueinformer.ResourceQueueSet
74
- olmConfigQueue workqueue.RateLimitingInterface
75
- csvCopyQueueSet * queueinformer.ResourceQueueSet
76
- copiedCSVGCQueueSet * queueinformer.ResourceQueueSet
77
- objGCQueueSet * queueinformer.ResourceQueueSet
78
- nsQueueSet workqueue.RateLimitingInterface
79
- apiServiceQueue workqueue.RateLimitingInterface
80
- csvIndexers map [string ]cache.Indexer
81
- recorder record.EventRecorder
82
- resolver install.StrategyResolverInterface
83
- apiReconciler APIIntersectionReconciler
84
- apiLabeler labeler.Labeler
85
- csvSetGenerator csvutility.SetGenerator
86
- csvReplaceFinder csvutility.ReplaceFinder
87
- csvNotification csvutility.WatchNotification
88
- serviceAccountSyncer * scoped.UserDefinedServiceAccountSyncer
89
- clientAttenuator * scoped.ClientAttenuator
90
- serviceAccountQuerier * scoped.UserDefinedServiceAccountQuerier
91
- clientFactory clients.Factory
66
+ clock utilclock.Clock
67
+ logger * logrus.Logger
68
+ opClient operatorclient.ClientInterface
69
+ client versioned.Interface
70
+ lister operatorlister.OperatorLister
71
+ protectedCopiedCSVNamespaces map [string ]struct {}
72
+ copiedCSVLister operatorsv1alpha1listers.ClusterServiceVersionLister
73
+ ogQueueSet * queueinformer.ResourceQueueSet
74
+ csvQueueSet * queueinformer.ResourceQueueSet
75
+ olmConfigQueue workqueue.RateLimitingInterface
76
+ csvCopyQueueSet * queueinformer.ResourceQueueSet
77
+ copiedCSVGCQueueSet * queueinformer.ResourceQueueSet
78
+ objGCQueueSet * queueinformer.ResourceQueueSet
79
+ nsQueueSet workqueue.RateLimitingInterface
80
+ apiServiceQueue workqueue.RateLimitingInterface
81
+ csvIndexers map [string ]cache.Indexer
82
+ recorder record.EventRecorder
83
+ resolver install.StrategyResolverInterface
84
+ apiReconciler APIIntersectionReconciler
85
+ apiLabeler labeler.Labeler
86
+ csvSetGenerator csvutility.SetGenerator
87
+ csvReplaceFinder csvutility.ReplaceFinder
88
+ csvNotification csvutility.WatchNotification
89
+ serviceAccountSyncer * scoped.UserDefinedServiceAccountSyncer
90
+ clientAttenuator * scoped.ClientAttenuator
91
+ serviceAccountQuerier * scoped.UserDefinedServiceAccountQuerier
92
+ clientFactory clients.Factory
92
93
}
93
94
94
95
func NewOperator (ctx context.Context , options ... OperatorOption ) (* Operator , error ) {
@@ -121,30 +122,31 @@ func newOperatorWithConfig(ctx context.Context, config *operatorConfig) (*Operat
121
122
}
122
123
123
124
op := & Operator {
124
- Operator : queueOperator ,
125
- clock : config .clock ,
126
- logger : config .logger ,
127
- opClient : config .operatorClient ,
128
- client : config .externalClient ,
129
- ogQueueSet : queueinformer .NewEmptyResourceQueueSet (),
130
- csvQueueSet : queueinformer .NewEmptyResourceQueueSet (),
131
- olmConfigQueue : workqueue .NewNamedRateLimitingQueue (workqueue .DefaultControllerRateLimiter (), "olmConfig" ),
132
- csvCopyQueueSet : queueinformer .NewEmptyResourceQueueSet (),
133
- copiedCSVGCQueueSet : queueinformer .NewEmptyResourceQueueSet (),
134
- objGCQueueSet : queueinformer .NewEmptyResourceQueueSet (),
135
- apiServiceQueue : workqueue .NewNamedRateLimitingQueue (workqueue .DefaultControllerRateLimiter (), "apiservice" ),
136
- resolver : config .strategyResolver ,
137
- apiReconciler : config .apiReconciler ,
138
- lister : lister ,
139
- recorder : eventRecorder ,
140
- apiLabeler : config .apiLabeler ,
141
- csvIndexers : map [string ]cache.Indexer {},
142
- csvSetGenerator : csvutility .NewSetGenerator (config .logger , lister ),
143
- csvReplaceFinder : csvutility .NewReplaceFinder (config .logger , config .externalClient ),
144
- serviceAccountSyncer : scoped .NewUserDefinedServiceAccountSyncer (config .logger , scheme , config .operatorClient , config .externalClient ),
145
- clientAttenuator : scoped .NewClientAttenuator (config .logger , config .restConfig , config .operatorClient ),
146
- serviceAccountQuerier : scoped .NewUserDefinedServiceAccountQuerier (config .logger , config .externalClient ),
147
- clientFactory : clients .NewFactory (config .restConfig ),
125
+ Operator : queueOperator ,
126
+ clock : config .clock ,
127
+ logger : config .logger ,
128
+ opClient : config .operatorClient ,
129
+ client : config .externalClient ,
130
+ ogQueueSet : queueinformer .NewEmptyResourceQueueSet (),
131
+ csvQueueSet : queueinformer .NewEmptyResourceQueueSet (),
132
+ olmConfigQueue : workqueue .NewNamedRateLimitingQueue (workqueue .DefaultControllerRateLimiter (), "olmConfig" ),
133
+ csvCopyQueueSet : queueinformer .NewEmptyResourceQueueSet (),
134
+ copiedCSVGCQueueSet : queueinformer .NewEmptyResourceQueueSet (),
135
+ objGCQueueSet : queueinformer .NewEmptyResourceQueueSet (),
136
+ apiServiceQueue : workqueue .NewNamedRateLimitingQueue (workqueue .DefaultControllerRateLimiter (), "apiservice" ),
137
+ resolver : config .strategyResolver ,
138
+ apiReconciler : config .apiReconciler ,
139
+ lister : lister ,
140
+ recorder : eventRecorder ,
141
+ apiLabeler : config .apiLabeler ,
142
+ csvIndexers : map [string ]cache.Indexer {},
143
+ csvSetGenerator : csvutility .NewSetGenerator (config .logger , lister ),
144
+ csvReplaceFinder : csvutility .NewReplaceFinder (config .logger , config .externalClient ),
145
+ serviceAccountSyncer : scoped .NewUserDefinedServiceAccountSyncer (config .logger , scheme , config .operatorClient , config .externalClient ),
146
+ clientAttenuator : scoped .NewClientAttenuator (config .logger , config .restConfig , config .operatorClient ),
147
+ serviceAccountQuerier : scoped .NewUserDefinedServiceAccountQuerier (config .logger , config .externalClient ),
148
+ clientFactory : clients .NewFactory (config .restConfig ),
149
+ protectedCopiedCSVNamespaces : config .protectedCopiedCSVNamespaces ,
148
150
}
149
151
150
152
// Set up syncing for namespace-scoped resources
@@ -1277,20 +1279,29 @@ func (a *Operator) syncOLMConfig(obj interface{}) (syncError error) {
1277
1279
return err
1278
1280
}
1279
1281
1280
- // Filter to unique copies
1281
- uniqueCopiedCSVs := map [string ]struct {}{}
1282
+ copiedCSVCount := map [string ]int {}
1282
1283
for _ , copiedCSV := range copiedCSVs {
1283
- uniqueCopiedCSVs [copiedCSV .GetName ()] = struct {}{}
1284
+ copiedCSVCount [copiedCSV .GetName ()] = copiedCSVCount [ copiedCSV . GetName ()] + 1
1284
1285
}
1285
1286
1286
1287
csvs , err := a .lister .OperatorsV1alpha1 ().ClusterServiceVersionLister ().ClusterServiceVersions (og .GetNamespace ()).List (labels .NewSelector ().Add (* nonCopiedCSVRequirement ))
1287
1288
if err != nil {
1288
1289
return err
1289
1290
}
1290
1291
1292
+ namespaces , err := a .lister .CoreV1 ().NamespaceLister ().List (labels .Everything ())
1293
+ if err != nil {
1294
+ return err
1295
+ }
1296
+
1291
1297
for _ , csv := range csvs {
1292
- // If the correct number of copied CSVs were found, continue
1293
- if _ , ok := uniqueCopiedCSVs [csv .GetName ()]; ok == olmConfig .CopiedCSVsAreEnabled () {
1298
+ numberOfCopiedCSVs := copiedCSVCount [csv .GetName ()]
1299
+ // Ignore NS where actual CSV is installed
1300
+ if olmConfig .CopiedCSVsAreEnabled () && numberOfCopiedCSVs == len (namespaces )- 1 {
1301
+ continue
1302
+ }
1303
+
1304
+ if ! olmConfig .CopiedCSVsAreEnabled () && numberOfCopiedCSVs == len (a .protectedCopiedCSVNamespaces ) {
1294
1305
continue
1295
1306
}
1296
1307
@@ -1302,7 +1313,7 @@ func (a *Operator) syncOLMConfig(obj interface{}) (syncError error) {
1302
1313
}
1303
1314
1304
1315
// Update the olmConfig status if it has changed.
1305
- condition := getCopiedCSVsCondition (! olmConfig .CopiedCSVsAreEnabled (), csvIsRequeued )
1316
+ condition := getCopiedCSVsCondition (olmConfig .CopiedCSVsAreEnabled (), csvIsRequeued )
1306
1317
if ! isStatusConditionPresentAndAreTypeReasonMessageStatusEqual (olmConfig .Status .Conditions , condition ) {
1307
1318
meta .SetStatusCondition (& olmConfig .Status .Conditions , condition )
1308
1319
if _ , err := a .client .OperatorsV1 ().OLMConfigs ().UpdateStatus (context .TODO (), olmConfig , metav1.UpdateOptions {}); err != nil {
@@ -1324,13 +1335,13 @@ func isStatusConditionPresentAndAreTypeReasonMessageStatusEqual(conditions []met
1324
1335
foundCondition .Status == condition .Status
1325
1336
}
1326
1337
1327
- func getCopiedCSVsCondition (isDisabled , csvIsRequeued bool ) metav1.Condition {
1338
+ func getCopiedCSVsCondition (enabled , csvIsRequeued bool ) metav1.Condition {
1328
1339
condition := metav1.Condition {
1329
1340
Type : operatorsv1 .DisabledCopiedCSVsConditionType ,
1330
1341
LastTransitionTime : metav1 .Now (),
1331
1342
Status : metav1 .ConditionFalse ,
1332
1343
}
1333
- if ! isDisabled {
1344
+ if enabled {
1334
1345
condition .Reason = "CopiedCSVsEnabled"
1335
1346
condition .Message = "Copied CSVs are enabled and present across the cluster"
1336
1347
if csvIsRequeued {
@@ -1339,15 +1350,14 @@ func getCopiedCSVsCondition(isDisabled, csvIsRequeued bool) metav1.Condition {
1339
1350
return condition
1340
1351
}
1341
1352
1353
+ condition .Reason = "CopiedCSVsDisabled"
1342
1354
if csvIsRequeued {
1343
- condition .Reason = "CopiedCSVsFound"
1344
- condition .Message = "Copied CSVs are disabled and at least one copied CSV was found for an operator installed in AllNamespace mode"
1355
+ condition .Message = "Copied CSVs are disabled and at least one unexpected copied CSV was found for an operator installed in AllNamespace mode"
1345
1356
return condition
1346
1357
}
1347
1358
1348
1359
condition .Status = metav1 .ConditionTrue
1349
- condition .Reason = "NoCopiedCSVsFound"
1350
- condition .Message = "Copied CSVs are disabled and none were found for operators installed in AllNamespace mode"
1360
+ condition .Message = "Copied CSVs are disabled and no unexpected copied CSVs were found for operators installed in AllNamespace mode"
1351
1361
1352
1362
return condition
1353
1363
}
@@ -1422,7 +1432,25 @@ func (a *Operator) syncCopyCSV(obj interface{}) (syncError error) {
1422
1432
return err
1423
1433
}
1424
1434
1435
+ // Ensure that the Copied CSVs exist in the protected namespaces.
1436
+ protectedNamespaces := []string {}
1437
+ for ns := range a .protectedCopiedCSVNamespaces {
1438
+ if ns == clusterServiceVersion .GetNamespace () {
1439
+ continue
1440
+ }
1441
+ protectedNamespaces = append (protectedNamespaces , ns )
1442
+ }
1443
+
1444
+ if err := a .ensureCSVsInNamespaces (clusterServiceVersion , operatorGroup , NewNamespaceSet (protectedNamespaces )); err != nil {
1445
+ logger .WithError (err ).Info ("couldn't copy CSV to protected Copied CSV namespaces" )
1446
+ syncError = err
1447
+ }
1448
+
1449
+ // Delete Copied CSVs in namespaces that are not protected.
1425
1450
for _ , copiedCSV := range copiedCSVs {
1451
+ if _ , ok := a .protectedCopiedCSVNamespaces [copiedCSV .Namespace ]; ok {
1452
+ continue
1453
+ }
1426
1454
err := a .client .OperatorsV1alpha1 ().ClusterServiceVersions (copiedCSV .Namespace ).Delete (context .TODO (), copiedCSV .Name , metav1.DeleteOptions {})
1427
1455
if err != nil && ! apierrors .IsNotFound (err ) {
1428
1456
return err
0 commit comments