Files
ayatori/config/crd/bases/database.ayatori.ddupan.top_postgresqldatabases.yaml
T
panxiao81 7e9e8e828b
Verify / test (pull_request) Successful in 11m39s
Verify / lint (pull_request) Successful in 12m51s
Verify / database-integration (pull_request) Successful in 13m12s
feat: 接入 Database 三资源 API 与分层绑定协调
确定单库单账号、集群级 Database、资源侧先写绑定和凭据定位合同。领域层承载纯规则,service 协調流程,Kubernetes adapter 负责资源呈现与版本保护。

验证:全量 make test、三轮 race、真实 API server 并发与重启补写、最小 RBAC/watch、lint 和文档检查通过。供应、凭据交付及删除清理尚未实现,保留 DeletionPending/finalizer 边界。
2026-09-25 04:09:43 +00:00

227 lines
9.9 KiB
YAML

---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.22.0
name: postgresqldatabases.database.ayatori.ddupan.top
spec:
group: database.ayatori.ddupan.top
names:
kind: PostgreSQLDatabase
listKind: PostgreSQLDatabaseList
plural: postgresqldatabases
singular: postgresqldatabase
scope: Cluster
versions:
- additionalPrinterColumns:
- jsonPath: .spec.instanceRef.name
name: Instance
type: string
- jsonPath: .spec.database
name: Database
type: string
- jsonPath: .status.conditions[?(@.type=='Ready')].status
name: Ready
type: string
name: v1alpha1
schema:
openAPIV3Schema:
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
description: PostgreSQLDatabaseSpec 是一库、一个 login owner 及凭据的独立资源声明。
properties:
credentialRef:
description: |-
CredentialReference 定位已有 OpenBao KV v2 凭据,不包含任何秘密值。
只由资源管理员在导入时填写;controller 必须检查部署允许的 mount/path 范围。
properties:
mount:
maxLength: 253
minLength: 1
type: string
path:
description: Path 是 mount 内的逻辑路径,不含 KV v2 的 data/ API 前缀。
maxLength: 1024
minLength: 1
type: string
required:
- mount
- path
type: object
database:
description: PostgreSQLIdentifier 是第一版受管 database 与 login role 使用的名称。
maxLength: 63
pattern: ^[a-z][a-z0-9_]{0,62}$
type: string
instanceRef:
description: InstanceReference 仅引用同 API group 的集群级 PostgreSQLInstance。
properties:
name:
description: ObjectName 定位集群级资源,不携带 namespace 或隐式跨 API group 引用。
maxLength: 253
minLength: 1
pattern: ^[a-z0-9]([-a-z0-9.]*[a-z0-9])?$
type: string
required:
- name
type: object
loginRole:
description: PostgreSQLIdentifier 是第一版受管 database 与 login role 使用的名称。
maxLength: 63
pattern: ^[a-z][a-z0-9_]{0,62}$
type: string
reclaimPolicy:
default: Retain
description: ReclaimPolicy 控制资源释放后的处置,只有资源管理者可以修改。
enum:
- Retain
- Delete
type: string
source:
description: Source 明确区分创建与只读导入,不从后端同名对象推断。
enum:
- Provision
- Import
type: string
tenantRef:
description: TenantRef 由 controller 先写入;Released 时仍保留旧身份。
properties:
name:
description: ObjectName 定位集群级资源,不携带 namespace 或隐式跨 API group 引用。
maxLength: 253
minLength: 1
pattern: ^[a-z0-9]([-a-z0-9.]*[a-z0-9])?$
type: string
namespace:
maxLength: 63
minLength: 1
pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
type: string
uid:
description: |-
UID is a type that holds unique ID values, including UUIDs. Because we
don't ONLY use UUIDs, this is an alias to string. Being a type captures
intent and helps make sure that UIDs and names do not get conflated.
maxLength: 128
minLength: 1
type: string
required:
- name
- namespace
- uid
type: object
required:
- database
- instanceRef
- loginRole
- source
type: object
x-kubernetes-validations:
- message: only imported databases require an existing credentialRef
rule: (self.source == 'Import') == has(self.credentialRef)
status:
properties:
conditions:
items:
description: Condition contains details for one aspect of the current
state of this API Resource.
properties:
lastTransitionTime:
description: |-
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: |-
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
x-kubernetes-list-map-keys:
- type
x-kubernetes-list-type: map
instanceUID:
description: InstanceUID 记录观察时的实例身份,不把同名新实例视为原目标。
type: string
observedGeneration:
format: int64
type: integer
phase:
description: Phase 暂不冻结供应子阶段枚举;它不是操作授权或绑定的替代记录。
type: string
type: object
required:
- spec
type: object
x-kubernetes-validations:
- message: managed database target cannot change after observation or binding
starts
rule: '!(has(oldSelf.spec.tenantRef) || (has(oldSelf.status) && has(oldSelf.status.instanceUID)))
|| (self.spec.instanceRef == oldSelf.spec.instanceRef && self.spec.database
== oldSelf.spec.database && self.spec.loginRole == oldSelf.spec.loginRole
&& self.spec.source == oldSelf.spec.source && has(self.spec.credentialRef)
== has(oldSelf.spec.credentialRef) && (!has(oldSelf.spec.credentialRef)
|| self.spec.credentialRef == oldSelf.spec.credentialRef))'
served: true
storage: true
subresources:
status: {}