Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 17 additions & 6 deletions api/v1/ocirepository_types.go
Original file line number Diff line number Diff line change
Expand Up @@ -58,8 +58,8 @@ type OCIRepositorySpec struct {
// URL is a reference to an OCI artifact repository hosted
// on a remote container registry.
// +kubebuilder:validation:Pattern="^oci://.*$"
// +required
URL string `json:"url"`
// +optional
URL string `json:"url,omitempty"`

// The OCI reference to pull and monitor for changes,
// defaults to the latest tag.
Expand All @@ -74,7 +74,6 @@ type OCIRepositorySpec struct {
// The provider used for authentication, can be 'aws', 'azure', 'gcp' or 'generic'.
// When not specified, defaults to 'generic'.
// +kubebuilder:validation:Enum=generic;aws;azure;gcp
// +kubebuilder:default:=generic
// +optional
Provider string `json:"provider,omitempty"`

Expand Down Expand Up @@ -121,11 +120,10 @@ type OCIRepositorySpec struct {
// efficient use of resources.
// +kubebuilder:validation:Type=string
// +kubebuilder:validation:Pattern="^([0-9]+(\\.[0-9]+)?(ms|s|m|h))+$"
// +required
Interval metav1.Duration `json:"interval"`
// +optional
Interval *metav1.Duration `json:"interval,omitempty"`

// The timeout for remote OCI Repository operations like pulling, defaults to 60s.
// +kubebuilder:default="60s"
// +kubebuilder:validation:Type=string
// +kubebuilder:validation:Pattern="^([0-9]+(\\.[0-9]+)?(ms|s|m))+$"
// +optional
Expand Down Expand Up @@ -236,6 +234,9 @@ func (in *OCIRepository) SetConditions(conditions []metav1.Condition) {
// GetRequeueAfter returns the duration after which the OCIRepository must be
// reconciled again.
func (in OCIRepository) GetRequeueAfter() time.Duration {
if in.Spec.Interval == nil {
return 0
}
return in.Spec.Interval.Duration
}

Expand Down Expand Up @@ -263,6 +264,14 @@ func (in *OCIRepository) GetLayerOperation() string {
return in.Spec.LayerSelector.Operation
}

// GetTimeout applies the 60s default via code to avoid using the CRD schema default.
func (in *OCIRepository) GetTimeout() time.Duration {
if in.Spec.Timeout == nil {
return 60 * time.Second
}
return in.Spec.Timeout.Duration
}

// +genclient
// +kubebuilder:storageversion
// +kubebuilder:object:root=true
Expand All @@ -273,6 +282,8 @@ func (in *OCIRepository) GetLayerOperation() string {
// +kubebuilder:printcolumn:name="Status",type="string",JSONPath=".status.conditions[?(@.type==\"Ready\")].message",description=""
// +kubebuilder:printcolumn:name="Age",type="date",JSONPath=".metadata.creationTimestamp",description=""
// +kubebuilder:metadata:annotations="kustomize.toolkit.fluxcd.io/substitute=disabled"
// +kubebuilder:validation:XValidation:rule="has(self.spec) && has(self.spec.url)",message="spec.url is required"
// +kubebuilder:validation:XValidation:rule="has(self.spec) && has(self.spec.interval)",message="spec.interval is required"

// OCIRepository is the Schema for the ocirepositories API
type OCIRepository struct {
Expand Down
6 changes: 5 additions & 1 deletion api/v1/zz_generated.deepcopy.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion api/v1beta1/zz_generated.deepcopy.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

10 changes: 5 additions & 5 deletions config/crd/bases/source.toolkit.fluxcd.io_ocirepositories.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -120,7 +120,6 @@ spec:
type: string
type: object
provider:
default: generic
description: |-
The provider used for authentication, can be 'aws', 'azure', 'gcp' or 'generic'.
When not specified, defaults to 'generic'.
Expand Down Expand Up @@ -187,7 +186,6 @@ spec:
of this source.
type: boolean
timeout:
default: 60s
description: The timeout for remote OCI Repository operations like
pulling, defaults to 60s.
pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$
Expand Down Expand Up @@ -267,9 +265,6 @@ spec:
required:
- provider
type: object
required:
- interval
- url
type: object
status:
default:
Expand Down Expand Up @@ -423,6 +418,11 @@ spec:
type: string
type: object
type: object
x-kubernetes-validations:
- message: spec.url is required
rule: has(self.spec) && has(self.spec.url)
- message: spec.interval is required
rule: has(self.spec) && has(self.spec.interval)
served: true
storage: true
subresources:
Expand Down
4 changes: 4 additions & 0 deletions docs/api/v1/source.md
Original file line number Diff line number Diff line change
Expand Up @@ -1108,6 +1108,7 @@ string
</em>
</td>
<td>
<em>(Optional)</em>
<p>URL is a reference to an OCI artifact repository hosted
on a remote container registry.</p>
</td>
Expand Down Expand Up @@ -1251,6 +1252,7 @@ Kubernetes meta/v1.Duration
</em>
</td>
<td>
<em>(Optional)</em>
<p>Interval at which the OCIRepository URL is checked for updates.
This interval is approximate and may be subject to jitter to ensure
efficient use of resources.</p>
Expand Down Expand Up @@ -3350,6 +3352,7 @@ string
</em>
</td>
<td>
<em>(Optional)</em>
<p>URL is a reference to an OCI artifact repository hosted
on a remote container registry.</p>
</td>
Expand Down Expand Up @@ -3493,6 +3496,7 @@ Kubernetes meta/v1.Duration
</em>
</td>
<td>
<em>(Optional)</em>
<p>Interval at which the OCIRepository URL is checked for updates.
This interval is approximate and may be subject to jitter to ensure
efficient use of resources.</p>
Expand Down
4 changes: 2 additions & 2 deletions internal/controller/ocirepository_controller.go
Original file line number Diff line number Diff line change
Expand Up @@ -328,7 +328,7 @@ func (r *OCIRepositoryReconciler) reconcileSource(ctx context.Context, sp *patch
obj *sourcev1.OCIRepository, metadata *meta.Artifact, dir string) (sreconcile.Result, error) {
var authenticator authn.Authenticator

ctxTimeout, cancel := context.WithTimeout(ctx, obj.Spec.Timeout.Duration)
ctxTimeout, cancel := context.WithTimeout(ctx, obj.GetTimeout())
defer cancel()

// Remove previously failed source verification status conditions. The
Expand Down Expand Up @@ -671,7 +671,7 @@ func (r *OCIRepositoryReconciler) verifySignature(ctx context.Context, obj *sour
ref name.Reference, keychain authn.Keychain, auth authn.Authenticator,
transport *http.Transport, opt ...remote.Option) (soci.VerificationResult, error) {

ctxTimeout, cancel := context.WithTimeout(ctx, obj.Spec.Timeout.Duration)
ctxTimeout, cancel := context.WithTimeout(ctx, obj.GetTimeout())
defer cancel()

provider := obj.Spec.Verify.Provider
Expand Down
Loading
Loading