From 83bf63e43386fb389194cab079b286ba45d714e7 Mon Sep 17 00:00:00 2001 From: Tiago Silva Date: Thu, 13 Jul 2023 16:15:48 +0100 Subject: [PATCH] Correct the clock passed to `dynamicCredsConfig` (#29054) This PR corrects the clock passed to `dynamicCredsConfig` and used for generating credentials for dynamic clusters. --- lib/kube/proxy/cluster_details.go | 4 +++- lib/kube/proxy/watcher.go | 27 +++++++++++++-------------- 2 files changed, 16 insertions(+), 15 deletions(-) diff --git a/lib/kube/proxy/cluster_details.go b/lib/kube/proxy/cluster_details.go index dda7ff3b4e9..6d2f9fc069e 100644 --- a/lib/kube/proxy/cluster_details.go +++ b/lib/kube/proxy/cluster_details.go @@ -60,6 +60,8 @@ type clusterDetailsConfig struct { // resourceMatchers is the list of resource matchers to match the cluster against // to determine if we should assume the role or not for AWS. resourceMatchers []services.ResourceMatcher + // clock is the clock to use. + clock clockwork.Clock } // newClusterDetails creates a proxied kubeDetails structure given a dynamic cluster. @@ -102,7 +104,7 @@ func (k *kubeDetails) Close() { // getKubeClusterCredentials generates kube credentials for dynamic clusters. func getKubeClusterCredentials(ctx context.Context, cfg clusterDetailsConfig) (kubeCreds, error) { - dynCredsCfg := dynamicCredsConfig{kubeCluster: cfg.cluster, log: cfg.log, checker: cfg.checker, resourceMatchers: cfg.resourceMatchers} + dynCredsCfg := dynamicCredsConfig{kubeCluster: cfg.cluster, log: cfg.log, checker: cfg.checker, resourceMatchers: cfg.resourceMatchers, clock: cfg.clock} switch { case cfg.cluster.IsKubeconfig(): return getStaticCredentialsFromKubeconfig(ctx, cfg.cluster, cfg.log, cfg.checker) diff --git a/lib/kube/proxy/watcher.go b/lib/kube/proxy/watcher.go index 7ab5f8d3289..ade55a5dbe3 100644 --- a/lib/kube/proxy/watcher.go +++ b/lib/kube/proxy/watcher.go @@ -178,16 +178,21 @@ func (m *monitoredKubeClusters) get() types.ResourcesWithLabelsMap { return append(m.static, m.resources...).AsResources().ToMap() } +func (s *TLSServer) buildClusterDetailsConfigForCluster(cluster types.KubeCluster) clusterDetailsConfig { + return clusterDetailsConfig{ + cloudClients: s.CloudClients, + cluster: cluster, + log: s.log, + checker: s.CheckImpersonationPermissions, + resourceMatchers: s.ResourceMatchers, + clock: s.Clock, + } +} + func (s *TLSServer) registerKubeCluster(ctx context.Context, cluster types.KubeCluster) error { clusterDetails, err := newClusterDetails( ctx, - clusterDetailsConfig{ - cloudClients: s.CloudClients, - cluster: cluster, - log: s.log, - checker: s.CheckImpersonationPermissions, - resourceMatchers: s.ResourceMatchers, - }, + s.buildClusterDetailsConfigForCluster(cluster), ) if err != nil { return trace.Wrap(err) @@ -199,13 +204,7 @@ func (s *TLSServer) registerKubeCluster(ctx context.Context, cluster types.KubeC func (s *TLSServer) updateKubeCluster(ctx context.Context, cluster types.KubeCluster) error { clusterDetails, err := newClusterDetails( ctx, - clusterDetailsConfig{ - cloudClients: s.CloudClients, - cluster: cluster, - log: s.log, - checker: s.CheckImpersonationPermissions, - resourceMatchers: s.ResourceMatchers, - }, + s.buildClusterDetailsConfigForCluster(cluster), ) if err != nil { return trace.Wrap(err)