-
Notifications
You must be signed in to change notification settings - Fork 51
Implement Limit controller #868
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
35aae67
6fa31b6
04aba64
baf4495
8025b90
e535421
03e4d2c
13d4d9a
9695342
7d4b66f
9b0a8e9
60bb5b3
2da7215
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,121 @@ | ||
| /* | ||
| Copyright The ORC Authors. | ||
|
|
||
| Licensed under the Apache License, Version 2.0 (the "License"); | ||
| you may not use this file except in compliance with the License. | ||
| You may obtain a copy of the License at | ||
|
|
||
| http://www.apache.org/licenses/LICENSE-2.0 | ||
|
|
||
| Unless required by applicable law or agreed to in writing, software | ||
| distributed under the License is distributed on an "AS IS" BASIS, | ||
| WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| See the License for the specific language governing permissions and | ||
| limitations under the License. | ||
| */ | ||
|
|
||
| package v1alpha1 | ||
|
|
||
| // LimitResourceSpec contains the desired state of the resource. | ||
| // +kubebuilder:validation:XValidation:rule="has(self.projectRef) || has(self.domainRef)",message="either projectRef or domainRef must be specified" | ||
| // +kubebuilder:validation:XValidation:rule="!(has(self.projectRef) && has(self.domainRef))",message="projectRef and domainRef are mutually exclusive" | ||
| type LimitResourceSpec struct { | ||
| // description is a human-readable description for the resource. | ||
| // +kubebuilder:validation:MinLength:=1 | ||
| // +kubebuilder:validation:MaxLength:=255 | ||
| // +optional | ||
| Description *string `json:"description,omitempty"` | ||
|
|
||
| // serviceRef is a reference to the ORC Service which this resource is associated with. | ||
| // +required | ||
| // +kubebuilder:validation:XValidation:rule="self == oldSelf",message="serviceRef is immutable" | ||
| ServiceRef KubernetesNameRef `json:"serviceRef,omitempty"` | ||
|
|
||
| // projectRef is a reference to the ORC Project which this resource is associated with. | ||
| // Either Domain ID or Project ID must be provided. | ||
| // https://opendev.org/openstack/keystone/src/commit/30ef2ffa65a3486ef882f00538e20f2253c57d4c/keystone/limit/schema.py#L323-L340 | ||
| // +optional | ||
| // +kubebuilder:validation:XValidation:rule="self == oldSelf",message="projectRef is immutable" | ||
| ProjectRef *KubernetesNameRef `json:"projectRef,omitempty"` | ||
|
|
||
| // domainRef is a reference to the ORC Domain which this resource is associated with. | ||
| // Either Domain ID or Project ID must be provided. | ||
| // https://opendev.org/openstack/keystone/src/commit/30ef2ffa65a3486ef882f00538e20f2253c57d4c/keystone/limit/schema.py#L323-L340 | ||
| // +optional | ||
| // +kubebuilder:validation:XValidation:rule="self == oldSelf",message="domainRef is immutable" | ||
| DomainRef *KubernetesNameRef `json:"domainRef,omitempty"` | ||
|
|
||
| // resourceName is the name of the resource this limit is associated with. | ||
| // +kubebuilder:validation:MinLength:=1 | ||
| // +kubebuilder:validation:MaxLength:=255 | ||
| // +kubebuilder:validation:Pattern=`^[\S]+$` | ||
| // +required | ||
| // +kubebuilder:validation:XValidation:rule="self == oldSelf",message="resourceName is immutable" | ||
| ResourceName string `json:"resourceName,omitempty"` | ||
|
|
||
| // resourceLimit is the override value of the limit. | ||
| // +kubebuilder:validation:Minimum=-1 | ||
| // +required | ||
| ResourceLimit int32 `json:"resourceLimit"` | ||
| } | ||
|
|
||
| // LimitFilter defines an existing resource by its properties | ||
| // +kubebuilder:validation:MinProperties:=1 | ||
| type LimitFilter struct { | ||
| // description of the existing resource | ||
| // +kubebuilder:validation:MinLength:=1 | ||
| // +kubebuilder:validation:MaxLength:=255 | ||
| // +optional | ||
| Description *string `json:"description,omitempty"` | ||
|
|
||
| // serviceRef is a reference to the ORC Service which this resource is associated with. | ||
| // +optional | ||
| ServiceRef *KubernetesNameRef `json:"serviceRef,omitempty"` | ||
|
|
||
| // projectRef is a reference to the ORC Project which this resource is associated with. | ||
| // +optional | ||
| ProjectRef *KubernetesNameRef `json:"projectRef,omitempty"` | ||
|
|
||
| // domainRef is a reference to the ORC Domain which this resource is associated with. | ||
| // +optional | ||
| DomainRef *KubernetesNameRef `json:"domainRef,omitempty"` | ||
|
|
||
| // resourceName is the name of the resource this limit is associated with. | ||
| // +kubebuilder:validation:MinLength:=1 | ||
| // +kubebuilder:validation:MaxLength:=255 | ||
| // +kubebuilder:validation:Pattern=`^[\S]+$` | ||
| // +optional | ||
| ResourceName string `json:"resourceName,omitempty"` | ||
| } | ||
|
|
||
| // LimitResourceStatus represents the observed state of the resource. | ||
| type LimitResourceStatus struct { | ||
| // description is a human-readable description for the resource. | ||
| // +kubebuilder:validation:MaxLength=1024 | ||
| // +optional | ||
| Description string `json:"description,omitempty"` | ||
|
|
||
| // serviceID is the ID of the Service to which the resource is associated. | ||
| // +kubebuilder:validation:MaxLength=1024 | ||
| // +optional | ||
| ServiceID string `json:"serviceID,omitempty"` | ||
|
|
||
| // projectID is the ID of the Project to which the resource is associated. | ||
| // +kubebuilder:validation:MaxLength=1024 | ||
| // +optional | ||
| ProjectID string `json:"projectID,omitempty"` | ||
|
|
||
| // domainID is the ID of the Domain to which the resource is associated. | ||
| // +kubebuilder:validation:MaxLength=1024 | ||
| // +optional | ||
| DomainID string `json:"domainID,omitempty"` | ||
|
|
||
| // resourceLimit is the override value of the limit. | ||
| // +optional | ||
| ResourceLimit int32 `json:"resourceLimit,omitempty"` | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I think this should be a pointer. If the
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Can you elaborate the part about Here is a test I made. It was shown correctly in the apiVersion: openstack.k-orc.cloud/v1alpha1
kind: Limit
metadata:
annotations:
...
creationTimestamp: "2026-08-04T10:08:32Z"
finalizers:
- openstack.k-orc.cloud/limit
generation: 1
name: limit-managed-domain
namespace: default
resourceVersion: "562155"
uid: defec55e-42a9-4e8e-b1a1-54b59af42405
spec:
cloudCredentialsRef:
cloudName: openstack-admin
secretName: openstack-clouds
managementPolicy: managed
resource:
projectRef: project-admin
resourceLimit: 0
resourceName: servers
serviceRef: nova
status:
conditions:
- lastTransitionTime: "2026-08-04T10:08:35Z"
message: OpenStack resource is available
observedGeneration: 1
reason: Success
status: "True"
type: Available
- lastTransitionTime: "2026-08-04T10:08:35Z"
message: OpenStack resource is up to date
observedGeneration: 1
reason: Success
status: "False"
type: Progressing
id: 22471bb8f6524711be117d40667c0bda
lastSyncTime: "2026-08-04T10:08:35Z"
resource:
projectID: 6fd7df4cf061469ab27d39d6c91b25a0
resourceLimit: 0
resourceName: servers
serviceID: b8e6f8f3a9264fcaa5dc99e34aea1e31 |
||
|
|
||
| // resourceName is the name of the resource this limit is associated with. | ||
| // +kubebuilder:validation:MaxLength=1024 | ||
| // +optional | ||
| ResourceName string `json:"resourceName,omitempty"` | ||
| } | ||
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
When we have RegionRef on this controller, I believe we will be pretty much done.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes. After Region controller is merged, we can add the
RegionReffield.