summaryrefslogtreecommitdiff
path: root/app/services/clusters/gcp/kubernetes/create_service_account_service.rb
blob: be2740d0c4e86b0513b66ad650860c43e2b4e56f (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
# frozen_string_literal: true

module Clusters
  module Gcp
    module Kubernetes
      class CreateServiceAccountService
        attr_reader :kubeclient, :name, :namespace, :rbac

        def initialize(kubeclient, name:, namespace:, rbac:)
          @kubeclient = kubeclient
          @name = name
          @namespace = namespace
          @rbac = rbac
        end

        def execute
          kubeclient.create_service_account(service_account_resource)
          kubeclient.create_secret(service_account_token_resource)
          kubeclient.create_role_binding(role_binding_resource) if rbac
        end

        private

        def service_account_resource
          Gitlab::Kubernetes::ServiceAccount.new(name, namespace).generate
        end

        def service_account_token_resource
          Gitlab::Kubernetes::ServiceAccountToken.new(
            service_account_token_name, name, namespace).generate
        end

        def service_account_token_name
          SERVICE_ACCOUNT_TOKEN_NAME
        end

        def edit_role_name
          EDIT_ROLE_NAME
        end

        def role_binding_resource
          Gitlab::Kubernetes::RoleBinding.new(
            role_name: edit_role_name,
            namespace: namespace,
            service_account_name: name
          ).generate
        end
      end
    end
  end
end