mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: improve resources_monitoring for OOM & OOD monitoring (#16241)
As requested for [this issue](https://github.com/coder/internal/issues/245) we need to have a new resource `resources_monitoring` in the agent. It needs to be parsed from the provisioner and inserted into a new db table.
This commit is contained in:
@@ -295,6 +295,14 @@ var (
|
||||
Type: "workspace",
|
||||
}
|
||||
|
||||
// ResourceWorkspaceAgentResourceMonitor
|
||||
// Valid Actions
|
||||
// - "ActionCreate" :: create workspace agent resource monitor
|
||||
// - "ActionRead" :: read workspace agent resource monitor
|
||||
ResourceWorkspaceAgentResourceMonitor = Object{
|
||||
Type: "workspace_agent_resource_monitor",
|
||||
}
|
||||
|
||||
// ResourceWorkspaceDormant
|
||||
// Valid Actions
|
||||
// - "ActionApplicationConnect" :: connect to workspace apps via browser
|
||||
@@ -353,6 +361,7 @@ func AllResources() []Objecter {
|
||||
ResourceTemplate,
|
||||
ResourceUser,
|
||||
ResourceWorkspace,
|
||||
ResourceWorkspaceAgentResourceMonitor,
|
||||
ResourceWorkspaceDormant,
|
||||
ResourceWorkspaceProxy,
|
||||
}
|
||||
|
||||
@@ -302,4 +302,10 @@ var RBACPermissions = map[string]PermissionDefinition{
|
||||
ActionUpdate: actDef("update IdP sync settings"),
|
||||
},
|
||||
},
|
||||
"workspace_agent_resource_monitor": {
|
||||
Actions: map[Action]ActionDefinition{
|
||||
ActionRead: actDef("read workspace agent resource monitor"),
|
||||
ActionCreate: actDef("create workspace agent resource monitor"),
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
@@ -777,6 +777,21 @@ func TestRolePermissions(t *testing.T) {
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
Name: "ResourceMonitor",
|
||||
Actions: []policy.Action{policy.ActionRead, policy.ActionCreate},
|
||||
Resource: rbac.ResourceWorkspaceAgentResourceMonitor,
|
||||
AuthorizeMap: map[bool][]hasAuthSubjects{
|
||||
true: {owner},
|
||||
false: {
|
||||
memberMe, orgMemberMe, otherOrgMember,
|
||||
orgAdmin, otherOrgAdmin,
|
||||
orgAuditor, otherOrgAuditor,
|
||||
templateAdmin, orgTemplateAdmin, otherOrgTemplateAdmin,
|
||||
userAdmin, orgUserAdmin, otherOrgUserAdmin,
|
||||
},
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
// We expect every permission to be tested above.
|
||||
|
||||
Reference in New Issue
Block a user