2020-03-04 18:56:59 +05:30
|
|
|
package openapi
|
|
|
|
|
|
|
|
import (
|
2020-10-15 17:54:58 -07:00
|
|
|
"context"
|
2020-03-27 19:06:06 +05:30
|
|
|
"fmt"
|
2020-09-02 16:33:55 +05:30
|
|
|
"strings"
|
2022-10-19 10:54:48 +02:00
|
|
|
"sync"
|
2020-12-23 17:48:00 -08:00
|
|
|
"time"
|
2020-03-04 18:56:59 +05:30
|
|
|
|
2022-08-31 14:03:47 +08:00
|
|
|
"github.com/kyverno/kyverno/pkg/clients/dclient"
|
2022-10-12 18:54:16 +02:00
|
|
|
"github.com/kyverno/kyverno/pkg/controllers"
|
2022-05-17 16:14:31 +02:00
|
|
|
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
2020-10-15 17:54:58 -07:00
|
|
|
runtimeSchema "k8s.io/apimachinery/pkg/runtime/schema"
|
2020-03-04 18:56:59 +05:30
|
|
|
"k8s.io/apimachinery/pkg/util/wait"
|
2022-07-01 08:30:05 +05:30
|
|
|
"k8s.io/client-go/discovery"
|
2020-03-04 18:56:59 +05:30
|
|
|
)
|
|
|
|
|
2022-10-12 21:23:47 +02:00
|
|
|
const (
|
|
|
|
// Workers is the number of workers for this controller
|
|
|
|
Workers = 1
|
|
|
|
ControllerName = "openapi-controller"
|
|
|
|
)
|
|
|
|
|
2022-10-12 18:54:16 +02:00
|
|
|
type Controller interface {
|
|
|
|
controllers.Controller
|
|
|
|
CheckSync(context.Context)
|
|
|
|
}
|
|
|
|
|
|
|
|
type controller struct {
|
2022-10-12 13:38:48 +02:00
|
|
|
client dclient.Interface
|
2022-10-12 18:54:16 +02:00
|
|
|
manager Manager
|
2020-03-04 18:56:59 +05:30
|
|
|
}
|
|
|
|
|
2022-07-01 08:30:05 +05:30
|
|
|
const (
|
|
|
|
skipErrorMsg = "Got empty response for"
|
|
|
|
)
|
|
|
|
|
2022-10-12 18:54:16 +02:00
|
|
|
// NewController ...
|
|
|
|
func NewController(client dclient.Interface, mgr Manager) Controller {
|
2022-10-12 13:38:48 +02:00
|
|
|
if mgr == nil {
|
|
|
|
panic(fmt.Errorf("nil manager sent into crd sync"))
|
2020-03-27 19:06:06 +05:30
|
|
|
}
|
2022-10-12 18:54:16 +02:00
|
|
|
return &controller{
|
2022-10-12 13:38:48 +02:00
|
|
|
manager: mgr,
|
|
|
|
client: client,
|
2020-03-04 18:56:59 +05:30
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-10-12 18:54:16 +02:00
|
|
|
func (c *controller) Run(ctx context.Context, workers int) {
|
2021-05-13 12:03:13 -07:00
|
|
|
if err := c.updateInClusterKindToAPIVersions(); err != nil {
|
2022-10-19 10:54:48 +02:00
|
|
|
logger.Error(err, "failed to update in-cluster api versions")
|
2021-05-13 12:03:13 -07:00
|
|
|
}
|
2022-07-01 08:30:05 +05:30
|
|
|
newDoc, err := c.client.Discovery().OpenAPISchema()
|
2020-03-05 22:50:32 +05:30
|
|
|
if err != nil {
|
2022-10-19 10:54:48 +02:00
|
|
|
logger.Error(err, "cannot get OpenAPI schema")
|
2020-03-05 22:50:32 +05:30
|
|
|
}
|
2022-10-12 18:54:16 +02:00
|
|
|
err = c.manager.UseOpenAPIDocument(newDoc)
|
2020-03-05 22:50:32 +05:30
|
|
|
if err != nil {
|
2022-10-19 10:54:48 +02:00
|
|
|
logger.Error(err, "Could not set custom OpenAPI document")
|
2020-03-05 22:50:32 +05:30
|
|
|
}
|
2020-03-25 02:20:04 +05:30
|
|
|
// Sync CRD before kyverno starts
|
|
|
|
c.sync()
|
2022-10-19 10:54:48 +02:00
|
|
|
var wg sync.WaitGroup
|
2020-03-04 18:56:59 +05:30
|
|
|
for i := 0; i < workers; i++ {
|
2022-10-19 10:54:48 +02:00
|
|
|
wg.Add(1)
|
|
|
|
go func() {
|
|
|
|
defer wg.Done()
|
|
|
|
wait.UntilWithContext(ctx, c.CheckSync, 15*time.Second)
|
|
|
|
}()
|
2020-03-04 18:56:59 +05:30
|
|
|
}
|
2022-10-18 12:55:33 +02:00
|
|
|
<-ctx.Done()
|
2020-03-04 18:56:59 +05:30
|
|
|
}
|
|
|
|
|
2022-10-12 18:54:16 +02:00
|
|
|
func (c *controller) sync() {
|
2022-05-03 07:30:04 +02:00
|
|
|
c.client.Discovery().DiscoveryCache().Invalidate()
|
2020-04-02 12:19:32 +05:30
|
|
|
crds, err := c.client.GetDynamicInterface().Resource(runtimeSchema.GroupVersionResource{
|
|
|
|
Group: "apiextensions.k8s.io",
|
2021-05-13 12:03:13 -07:00
|
|
|
Version: "v1",
|
2020-04-02 12:19:32 +05:30
|
|
|
Resource: "customresourcedefinitions",
|
2022-05-17 16:14:31 +02:00
|
|
|
}).List(context.TODO(), metav1.ListOptions{})
|
2020-03-04 18:56:59 +05:30
|
|
|
if err != nil {
|
2022-10-19 10:54:48 +02:00
|
|
|
logger.Error(err, "could not fetch crd's from server")
|
2020-03-05 22:50:32 +05:30
|
|
|
return
|
2020-03-04 18:56:59 +05:30
|
|
|
}
|
|
|
|
|
2022-10-12 18:54:16 +02:00
|
|
|
c.manager.DeleteCRDFromPreviousSync()
|
2020-03-06 01:09:38 +05:30
|
|
|
|
2020-03-05 22:50:32 +05:30
|
|
|
for _, crd := range crds.Items {
|
2022-10-12 13:38:48 +02:00
|
|
|
c.manager.ParseCRD(crd)
|
2020-03-06 01:09:38 +05:30
|
|
|
}
|
2021-05-13 12:03:13 -07:00
|
|
|
|
|
|
|
if err := c.updateInClusterKindToAPIVersions(); err != nil {
|
2022-10-19 10:54:48 +02:00
|
|
|
logger.Error(err, "sync failed, unable to update in-cluster api versions")
|
2021-05-13 12:03:13 -07:00
|
|
|
}
|
2021-11-22 19:22:45 +05:30
|
|
|
|
2022-07-01 08:30:05 +05:30
|
|
|
newDoc, err := c.client.Discovery().OpenAPISchema()
|
2021-11-22 19:22:45 +05:30
|
|
|
if err != nil {
|
2022-10-19 10:54:48 +02:00
|
|
|
logger.Error(err, "cannot get OpenAPI schema")
|
2021-11-22 19:22:45 +05:30
|
|
|
}
|
|
|
|
|
2022-10-12 18:54:16 +02:00
|
|
|
err = c.manager.UseOpenAPIDocument(newDoc)
|
2021-11-22 19:22:45 +05:30
|
|
|
if err != nil {
|
2022-10-19 10:54:48 +02:00
|
|
|
logger.Error(err, "Could not set custom OpenAPI document")
|
2021-11-22 19:22:45 +05:30
|
|
|
}
|
2021-05-13 12:03:13 -07:00
|
|
|
}
|
|
|
|
|
2022-10-12 18:54:16 +02:00
|
|
|
func (c *controller) updateInClusterKindToAPIVersions() error {
|
2023-01-03 10:33:09 +01:00
|
|
|
overrideRuntimeErrorHandler()
|
2022-07-01 08:30:05 +05:30
|
|
|
_, apiResourceLists, err := discovery.ServerGroupsAndResources(c.client.Discovery().DiscoveryInterface())
|
2022-10-12 21:23:47 +02:00
|
|
|
if err != nil {
|
|
|
|
if discovery.IsGroupDiscoveryFailedError(err) {
|
|
|
|
err := err.(*discovery.ErrGroupDiscoveryFailed)
|
|
|
|
for gv, err := range err.Groups {
|
|
|
|
logger.Error(err, "failed to list api resources", "group", gv)
|
|
|
|
}
|
|
|
|
} else if !strings.Contains(err.Error(), skipErrorMsg) {
|
|
|
|
return err
|
|
|
|
}
|
2021-05-13 12:03:13 -07:00
|
|
|
}
|
2022-07-01 08:30:05 +05:30
|
|
|
preferredAPIResourcesLists, err := discovery.ServerPreferredResources(c.client.Discovery().DiscoveryInterface())
|
2022-10-12 21:23:47 +02:00
|
|
|
if err != nil {
|
|
|
|
if discovery.IsGroupDiscoveryFailedError(err) {
|
|
|
|
err := err.(*discovery.ErrGroupDiscoveryFailed)
|
|
|
|
for gv, err := range err.Groups {
|
|
|
|
logger.Error(err, "failed to list api resources", "group", gv)
|
|
|
|
}
|
|
|
|
} else if !strings.Contains(err.Error(), skipErrorMsg) {
|
|
|
|
return err
|
|
|
|
}
|
2021-05-13 12:03:13 -07:00
|
|
|
}
|
2022-10-12 18:54:16 +02:00
|
|
|
c.manager.UpdateKindToAPIVersions(apiResourceLists, preferredAPIResourcesLists)
|
2021-05-13 12:03:13 -07:00
|
|
|
return nil
|
2020-03-06 01:09:38 +05:30
|
|
|
}
|
|
|
|
|
2022-10-12 18:54:16 +02:00
|
|
|
func (c *controller) CheckSync(ctx context.Context) {
|
2022-09-12 13:44:28 +05:30
|
|
|
crds, err := c.client.GetDynamicInterface().Resource(runtimeSchema.GroupVersionResource{
|
|
|
|
Group: "apiextensions.k8s.io",
|
|
|
|
Version: "v1",
|
|
|
|
Resource: "customresourcedefinitions",
|
2022-09-30 13:56:47 +02:00
|
|
|
}).List(ctx, metav1.ListOptions{})
|
2022-09-12 13:44:28 +05:30
|
|
|
if err != nil {
|
2022-10-19 10:54:48 +02:00
|
|
|
logger.Error(err, "could not fetch crd's from server")
|
2022-09-12 13:44:28 +05:30
|
|
|
return
|
|
|
|
}
|
2022-10-12 18:54:16 +02:00
|
|
|
if len(c.manager.GetCrdList()) != len(crds.Items) {
|
2022-09-12 13:44:28 +05:30
|
|
|
c.sync()
|
|
|
|
}
|
|
|
|
}
|