2022-05-13 07:33:20 +02:00
|
|
|
package policy
|
|
|
|
|
|
|
|
import (
|
2022-11-17 16:17:52 +01:00
|
|
|
"context"
|
2022-05-13 07:33:20 +02:00
|
|
|
"time"
|
|
|
|
|
|
|
|
"github.com/go-logr/logr"
|
2022-08-31 14:03:47 +08:00
|
|
|
"github.com/kyverno/kyverno/pkg/clients/dclient"
|
2022-05-13 07:33:20 +02:00
|
|
|
admissionutils "github.com/kyverno/kyverno/pkg/utils/admission"
|
2023-04-28 21:54:17 +08:00
|
|
|
policyvalidate "github.com/kyverno/kyverno/pkg/validation/policy"
|
2022-05-16 16:36:21 +02:00
|
|
|
"github.com/kyverno/kyverno/pkg/webhooks"
|
2023-04-04 07:11:18 +02:00
|
|
|
"github.com/kyverno/kyverno/pkg/webhooks/handlers"
|
2022-05-13 07:33:20 +02:00
|
|
|
)
|
|
|
|
|
2023-04-04 07:11:18 +02:00
|
|
|
type policyHandlers struct {
|
2023-04-24 18:31:42 +08:00
|
|
|
client dclient.Interface
|
|
|
|
backgroungServiceAccountName string
|
2022-05-13 07:33:20 +02:00
|
|
|
}
|
|
|
|
|
2023-09-27 18:21:47 +02:00
|
|
|
func NewHandlers(client dclient.Interface, serviceaccount string) webhooks.PolicyHandlers {
|
2023-04-04 07:11:18 +02:00
|
|
|
return &policyHandlers{
|
2023-04-24 18:31:42 +08:00
|
|
|
client: client,
|
|
|
|
backgroungServiceAccountName: serviceaccount,
|
2022-05-13 07:33:20 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-04-04 07:11:18 +02:00
|
|
|
func (h *policyHandlers) Validate(ctx context.Context, logger logr.Logger, request handlers.AdmissionRequest, _ time.Time) handlers.AdmissionResponse {
|
|
|
|
policy, oldPolicy, err := admissionutils.GetPolicies(request.AdmissionRequest)
|
2022-05-13 07:33:20 +02:00
|
|
|
if err != nil {
|
|
|
|
logger.Error(err, "failed to unmarshal policies from admission request")
|
2022-11-30 16:37:42 +01:00
|
|
|
return admissionutils.Response(request.UID, err)
|
2022-05-13 07:33:20 +02:00
|
|
|
}
|
2023-09-27 18:21:47 +02:00
|
|
|
warnings, err := policyvalidate.Validate(policy, oldPolicy, h.client, false, h.backgroungServiceAccountName)
|
2022-05-13 07:33:20 +02:00
|
|
|
if err != nil {
|
|
|
|
logger.Error(err, "policy validation errors")
|
|
|
|
}
|
2022-11-30 16:37:42 +01:00
|
|
|
return admissionutils.Response(request.UID, err, warnings...)
|
2022-05-13 07:33:20 +02:00
|
|
|
}
|
|
|
|
|
2023-04-04 07:11:18 +02:00
|
|
|
func (h *policyHandlers) Mutate(_ context.Context, _ logr.Logger, request handlers.AdmissionRequest, _ time.Time) handlers.AdmissionResponse {
|
2023-04-03 20:08:57 +02:00
|
|
|
return admissionutils.ResponseSuccess(request.UID)
|
2022-05-13 07:33:20 +02:00
|
|
|
}
|