mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: add usage tracking package (#19095)
Not used in coderd yet, see stack. Adds two new packages: - `coderd/usage`: provides an interface for the "Collector" as well as a stub implementation for AGPL - `enterprise/coderd/usage`: provides an interface for the "Publisher" as well as a Tallyman implementation Relates to https://github.com/coder/internal/issues/814
This commit is contained in:
@@ -76,6 +76,7 @@ const (
|
||||
SubjectTypeNotifier SubjectType = "notifier"
|
||||
SubjectTypeSubAgentAPI SubjectType = "sub_agent_api"
|
||||
SubjectTypeFileReader SubjectType = "file_reader"
|
||||
SubjectTypeUsageTracker SubjectType = "usage_tracker"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
@@ -289,6 +289,15 @@ var (
|
||||
Type: "template",
|
||||
}
|
||||
|
||||
// ResourceUsageEvent
|
||||
// Valid Actions
|
||||
// - "ActionCreate" :: create a usage event
|
||||
// - "ActionRead" :: read usage events
|
||||
// - "ActionUpdate" :: update usage events
|
||||
ResourceUsageEvent = Object{
|
||||
Type: "usage_event",
|
||||
}
|
||||
|
||||
// ResourceUser
|
||||
// Valid Actions
|
||||
// - "ActionCreate" :: create a new user
|
||||
@@ -412,6 +421,7 @@ func AllResources() []Objecter {
|
||||
ResourceSystem,
|
||||
ResourceTailnetCoordinator,
|
||||
ResourceTemplate,
|
||||
ResourceUsageEvent,
|
||||
ResourceUser,
|
||||
ResourceUserSecret,
|
||||
ResourceWebpushSubscription,
|
||||
|
||||
@@ -351,4 +351,11 @@ var RBACPermissions = map[string]PermissionDefinition{
|
||||
ActionDelete: "delete a user secret",
|
||||
},
|
||||
},
|
||||
"usage_event": {
|
||||
Actions: map[Action]ActionDefinition{
|
||||
ActionCreate: "create a usage event",
|
||||
ActionRead: "read usage events",
|
||||
ActionUpdate: "update usage events",
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
@@ -271,7 +271,7 @@ func ReloadBuiltinRoles(opts *RoleOptions) {
|
||||
// Workspace dormancy and workspace are omitted.
|
||||
// Workspace is specifically handled based on the opts.NoOwnerWorkspaceExec.
|
||||
// Owners cannot access other users' secrets.
|
||||
allPermsExcept(ResourceWorkspaceDormant, ResourcePrebuiltWorkspace, ResourceWorkspace, ResourceUserSecret),
|
||||
allPermsExcept(ResourceWorkspaceDormant, ResourcePrebuiltWorkspace, ResourceWorkspace, ResourceUserSecret, ResourceUsageEvent),
|
||||
// This adds back in the Workspace permissions.
|
||||
Permissions(map[string][]policy.Action{
|
||||
ResourceWorkspace.Type: ownerWorkspaceActions,
|
||||
|
||||
@@ -872,6 +872,22 @@ func TestRolePermissions(t *testing.T) {
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
Name: "UsageEvents",
|
||||
Actions: []policy.Action{policy.ActionCreate, policy.ActionRead, policy.ActionUpdate},
|
||||
Resource: rbac.ResourceUsageEvent,
|
||||
AuthorizeMap: map[bool][]hasAuthSubjects{
|
||||
true: {},
|
||||
false: {
|
||||
owner,
|
||||
memberMe, orgMemberMe, otherOrgMember,
|
||||
orgAdmin, otherOrgAdmin,
|
||||
orgAuditor, otherOrgAuditor,
|
||||
templateAdmin, orgTemplateAdmin, otherOrgTemplateAdmin,
|
||||
userAdmin, orgUserAdmin, otherOrgUserAdmin,
|
||||
},
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
// We expect every permission to be tested above.
|
||||
|
||||
Reference in New Issue
Block a user