Fix executor wrongly deletes rolebindings (#1517)
Executor wrongly deletes role bindings if the user creates an environment in the reserved namespaces. This PR is a quick fix to solve the problem by checking if an environment is under reserved namespaces.
This commit is contained in:
@@ -228,15 +228,19 @@ func CleanupRoleBindings(logger *zap.Logger, client *kubernetes.Clientset, fissi
|
|||||||
// the SA namespace will have the value of "fission-function"/"fission-builder" depending on the SA.
|
// the SA namespace will have the value of "fission-function"/"fission-builder" depending on the SA.
|
||||||
// so now we need to look for the objects in default namespace.
|
// so now we need to look for the objects in default namespace.
|
||||||
saNs := subj.Namespace
|
saNs := subj.Namespace
|
||||||
|
isInReservedNS := false
|
||||||
if subj.Namespace == functionNs ||
|
if subj.Namespace == functionNs ||
|
||||||
subj.Namespace == envBuilderNs {
|
subj.Namespace == envBuilderNs {
|
||||||
saNs = meta_v1.NamespaceDefault
|
saNs = meta_v1.NamespaceDefault
|
||||||
|
isInReservedNS = true
|
||||||
}
|
}
|
||||||
|
|
||||||
// go through each function and find out if there's either at least one function with env reference in the same namespace as the Service Account in this iteration
|
// go through each function and find out if there's either at least one function with env reference in the same namespace as the Service Account in this iteration
|
||||||
// or at least one function using ndm executor in the role-binding namespace and set the corresponding flags
|
// or at least one function using ndm executor in the role-binding namespace and set the corresponding flags
|
||||||
for _, fn := range funcList.Items {
|
for _, fn := range funcList.Items {
|
||||||
if fn.Spec.Environment.Namespace == saNs {
|
if fn.Spec.Environment.Namespace == saNs ||
|
||||||
|
// For the case that the environment is created in the reserved namespace.
|
||||||
|
(isInReservedNS && (fn.Spec.Environment.Namespace == functionNs || fn.Spec.Environment.Namespace == envBuilderNs)) {
|
||||||
funcEnvReference = true
|
funcEnvReference = true
|
||||||
break
|
break
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user