Kubernetes controller that manages namespaced ConfigMaps with cluster-level ReplicatedConfigMaps
360
This controller and CRD allows cluster-level central management of ReplicatedConfigMaps that are then propegated as ConfigMaps into select Namespaces.
This is a proof of concept controller using kubebuilder. Not intended for production use.
Setup kubectl with a kubconfig that targets the desired Kubernetes cluster and has auth credentials.
Install kustomize
GO111MODULES=off go install sigs.k8s.io/kustomize/kustomize/v3
export PATH=$PATH:$(go env GOPATH)/bin
If you don't want to use the public container image, build your own.
make docker-build IMG=${YOUR_ORG}/replicated-config-map-controller:latest
make docker-push IMG=${YOUR_ORG}/replicated-config-map-controller:latest
make deploy IMG=karlkfi/replicated-config-map-controller:latest
make install
make run
# create the parent resource
kubectl create -f config/samples/repl_v1_replicatedconfigmap.yaml
# view the created parent resource
kubectl get replicatedconfigmap replicatedconfigmap-sample -o yaml
# label a namespace
kubectl label namespace default rcm-sync=true
# view the created child resource
kubectl get configmap replicatedconfigmap-sample -n default -o yaml
This controller uses a ReplicatedConfigMap CRD. The ReplicatedConfigMap has the same specification as a ConfigMap.
Example (from config/samples/repl_v1_replicatedconfigmap.yaml):
apiVersion: repl.k8s.isenberg.us/v1
kind: ReplicatedConfigMap
metadata:
name: replicatedconfigmap-sample
spec:
data:
foo: bar
The controller watches for ReplicatedConfigMap CRUD events and propegates those changes to a ConfigMap in each Namespace that has the rcm-sync: true label.
The controller also watches for Namespace CRUD events. If a namespace is created or updated to have the rcm-sync: true label, and a ReplicatedConfigMap exists, a matching ConfigMap will be created in the new/updated namespace. If the namespace or label is deleted or set to a non-true value, the managed ConfigMap(s) will be deleted.
The controller also watches for ConfigMap CRUD events. User changes to managed ConfigMap Data will be reverted (other changes are allowed). Manged ConfigMaps will have their OwnerReference set to the parent ReplicatedConfigMap.
Write a controller that synchronizes ConfigMap resources to multiple namespaces. This is designed to give an administrator central access to populate, update, and delete a single shared configuration that can then be used by multiple instances of an application deployed in separate namespaces. You should use Kubebuilder to create a cluster scoped CRD named ReplicatedConfigMap that contains a "data" map which is synchronized to a controller owned ConfigMap in each namespace. Updates and deletes to the ReplicatedConfigMap should also be propagated out to the ConfigMap in each namespace. The controller should only create ConfigMap resources in namespaces with the label "rcm-sync: true"; if a new namespace is created with the required label, or if the namespace is updated to include the label, the appropriate ConfigMap resources should be created.
$ kubectl delete replicatedconfigmap replicatedconfigmap-sample
replicatedconfigmap.repl.k8s.isenberg.us "replicatedconfigmap-sample" deleted
$ kubectl get replicatedconfigmap replicatedconfigmap-sample
Error from server (NotFound): replicatedconfigmaps.repl.k8s.isenberg.us "replicatedconfigmap-sample" not found
$ kubectl get configmap replicatedconfigmap-sample -n default
Error from server (NotFound): configmaps "replicatedconfigmap-sample" not found
$ kubectl delete configmap replicatedconfigmap-sample -n default
configmap "replicatedconfigmap-sample" deleted
$ kubectl get configmap replicatedconfigmap-sample -n default
NAME DATA AGE
replicatedconfigmap-sample 1 4s
$ kubectl label namespace default rcm-sync=false --overwrite
namespace/default labeled
$ kubectl get configmap replicatedconfigmap-sample -n default
Error from server (NotFound): configmaps "replicatedconfigmap-sample" not found
$ kubectl create namespace example
namespace/example created
$ kubectl label namespace example rcm-sync=true
namespace/example labeled
$ kubectl get configmap replicatedconfigmap-sample -n example
NAME DATA AGE
replicatedconfigmap-sample 1 4s
$ kubectl get replicatedconfigmap replicatedconfigmap-sample -o yaml
apiVersion: repl.k8s.isenberg.us/v1
kind: ReplicatedConfigMap
metadata:
name: replicatedconfigmap-sample
...
spec:
...
status:
namespaces:
- default
- example
$ kubectl delete namespace example
namespace "example" deleted
$ kubectl get configmap replicatedconfigmap-sample -n example
Error from server (NotFound): namespaces "example" not found
$ kubectl get replicatedconfigmap replicatedconfigmap-sample -o yaml
apiVersion: repl.k8s.isenberg.us/v1
kind: ReplicatedConfigMap
metadata:
name: replicatedconfigmap-sample
...
spec:
...
status:
namespaces:
- default
Content type
Image
Digest
Size
17.1 MB
Last updated
over 6 years ago
docker pull karlkfi/replicated-config-map