You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
MLE-33163 : provision operator user and implement test - #213
This pull request introduces support for a dedicated MarkLogic Kubernetes Operator user and credential management, enhancing security and least-privilege practices. It adds the ability to use a user-managed operator Secret, documents the new behavior, and updates the controller logic and CRDs to track and react to operator credential changes. Comprehensive tests are included to verify correct group reconciliation on Secret updates.
Operator credential management and role separation:
Added support for a dedicated MarkLogic user (marklogic-kubernetes-operator) and role (marklogic-operator) with least-privilege access for Management API operations; the Operator manages this user and its credential, stored in a cluster-owned Secret, and falls back to the admin Secret for recovery if needed. [1][2]
Introduced the operatorSecretName field in the CRD and AdminAuth struct, allowing users to supply their own Secret for the operator credential, and updated all related CRDs and sample manifests with documentation and schema changes. [1][2][3][4][5][6]
Status tracking and reconciliation:
Added credentialSecretName to MarklogicGroupStatus and CRD to record the active operator credential Secret after bootstrap handoff. [1][2]
Controller logic enhancements:
Updated the controller to watch for Secret updates and reconcile affected MarklogicGroup resources, including a new mapping function to associate Secrets with groups based on ownership or reference. [1][2][3]
Testing:
Added unit tests for Secret-to-group mapping and event filtering to ensure correct reconciliation behavior when operator credentials are rotated or updated. [1][2][3]
Documentation:
Updated the README.md and design documentation to explain the new operator user, credential handoff, rotation procedures, and least-privilege rationale. [1][2]
Secret resolution trims operatorSecretName, but this watch mapping compares the raw value. A value such as " custom-operator-auth " is accepted and read successfully by reconciliation, yet rotations of custom-operator-auth never enqueue the group. Apply the same strings.TrimSpace normalization here (and to the admin Secret comparison) so watch behavior matches lookup behavior.
Wait for replacement pod before deleting another stale pod
pkg/k8sutil/statefulset.go:229
After deleting one stale pod, the next reconcile may run before its replacement appears in the list. In that window every listed peer can be Ready, so another stale pod is deleted and the promised one-at-a-time rotation can reduce availability. Wait until the observed pod count is back at the desired replica count; then the existing peer-readiness check also ensures the replacement is Ready.
Credential lookup normalizes operatorSecretName with TrimSpace, but this event mapper compares the untrimmed value. A value such as " custom-operator-auth " is therefore read successfully as custom-operator-auth, yet later Secret rotations do not enqueue the group, so the MarkLogic password and pod revision remain stale. Normalize the reference consistently here.
Require only the joined host to be online
pkg/k8sutil/scripts/cluster-config.sh:175
This gate requires every host in the cluster to be online, not just the host that has just joined. During a partial outage or planned maintenance, an unrelated offline host therefore makes a new/restarting pod fail its startup script after a successful join, reducing recovery capacity. Validate the joined host's own online status instead of total-hosts-offline == 0.
Preserve credential state to rotate stale OnDelete pods during admin fallback
pkg/k8sutil/statefulset.go:210
Clearing the active credential status here breaks admin fallback for OnDelete StatefulSets. This reconcile updates only the pod template to use the admin Secret; the existing pods are not restarted automatically. Subsequent reconciles cannot rotate them because rotateCredentialPodsIfNeeded requires a non-empty CredentialSecretName, and the handler returns early while the operator Secret remains missing. Those pods therefore keep MARKLOGIC_OPERATOR_CREDENTIALS_ACTIVE=true with a vanished optional Secret, so pre-stop shutdown cannot authenticate. Preserve enough fallback/rotation state and allow the handler to serially replace stale OnDelete pods before considering the handoff cleared.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request introduces support for a dedicated MarkLogic Kubernetes Operator user and credential management, enhancing security and least-privilege practices. It adds the ability to use a user-managed operator Secret, documents the new behavior, and updates the controller logic and CRDs to track and react to operator credential changes. Comprehensive tests are included to verify correct group reconciliation on Secret updates.
Operator credential management and role separation:
marklogic-kubernetes-operator) and role (marklogic-operator) with least-privilege access for Management API operations; the Operator manages this user and its credential, stored in a cluster-owned Secret, and falls back to the admin Secret for recovery if needed. [1] [2]operatorSecretNamefield in the CRD andAdminAuthstruct, allowing users to supply their own Secret for the operator credential, and updated all related CRDs and sample manifests with documentation and schema changes. [1] [2] [3] [4] [5] [6]Status tracking and reconciliation:
credentialSecretNametoMarklogicGroupStatusand CRD to record the active operator credential Secret after bootstrap handoff. [1] [2]Controller logic enhancements:
MarklogicGroupresources, including a new mapping function to associate Secrets with groups based on ownership or reference. [1] [2] [3]Testing:
Documentation:
README.mdand design documentation to explain the new operator user, credential handoff, rotation procedures, and least-privilege rationale. [1] [2]