multi-tenant: EnsureNamespaceSA + ns_watcher SA provisioning (v8)

This commit is contained in:
Naeel
2026-04-26 07:41:46 +03:00
parent 82e1ff76a5
commit 161de70576
24 changed files with 970 additions and 1 deletions
+7
View File
@@ -308,3 +308,10 @@ func getSAInterval() time.Duration {
SAInterval, _ := GetUIntValueFromEnv(ENV_SA_INTERVAL)
return time.Duration(SAInterval) * time.Minute
}
// EnsureNamespaceSA creates the fission-fetcher ServiceAccount and its Role/RoleBinding
// in the given namespace if they do not already exist. Safe to call repeatedly.
// Used by the multi-tenant NS watcher to provision per-namespace SA on NS registration.
func EnsureNamespaceSA(ctx context.Context, client kubernetes.Interface, logger *zap.Logger, ns string) {
setupSAAndRoleBindings(ctx, client, logger, ns, fetcherCheck)
}