2022-09-28 13:45:16 +02:00
|
|
|
package report
|
|
|
|
|
|
|
|
import (
|
|
|
|
kyvernov1alpha2 "github.com/kyverno/kyverno/api/kyverno/v1alpha2"
|
|
|
|
policyreportv1alpha2 "github.com/kyverno/kyverno/api/policyreport/v1alpha2"
|
2023-01-30 12:41:09 +01:00
|
|
|
engineapi "github.com/kyverno/kyverno/pkg/engine/api"
|
2022-09-28 13:45:16 +02:00
|
|
|
controllerutils "github.com/kyverno/kyverno/pkg/utils/controller"
|
|
|
|
admissionv1 "k8s.io/api/admission/v1"
|
2023-09-20 08:51:32 +02:00
|
|
|
corev1 "k8s.io/api/core/v1"
|
2022-09-28 13:45:16 +02:00
|
|
|
"k8s.io/apimachinery/pkg/apis/meta/v1/unstructured"
|
|
|
|
"k8s.io/apimachinery/pkg/runtime/schema"
|
|
|
|
"k8s.io/apimachinery/pkg/types"
|
|
|
|
)
|
|
|
|
|
2023-03-17 13:07:17 +01:00
|
|
|
func NewAdmissionReport(namespace, name string, gvr schema.GroupVersionResource, resource unstructured.Unstructured) kyvernov1alpha2.ReportInterface {
|
2022-09-28 13:45:16 +02:00
|
|
|
var report kyvernov1alpha2.ReportInterface
|
|
|
|
if namespace == "" {
|
2023-03-17 13:07:17 +01:00
|
|
|
report = &kyvernov1alpha2.ClusterAdmissionReport{Spec: kyvernov1alpha2.AdmissionReportSpec{}}
|
2022-09-28 13:45:16 +02:00
|
|
|
} else {
|
2023-03-17 13:07:17 +01:00
|
|
|
report = &kyvernov1alpha2.AdmissionReport{Spec: kyvernov1alpha2.AdmissionReportSpec{}}
|
2022-09-28 13:45:16 +02:00
|
|
|
}
|
|
|
|
report.SetName(name)
|
|
|
|
report.SetNamespace(namespace)
|
2023-03-17 13:07:17 +01:00
|
|
|
SetResourceUid(report, resource.GetUID())
|
|
|
|
SetResourceGVR(report, gvr)
|
|
|
|
SetResourceNamespaceAndName(report, resource.GetNamespace(), resource.GetName())
|
2022-11-24 14:21:08 +01:00
|
|
|
SetManagedByKyvernoLabel(report)
|
|
|
|
return report
|
|
|
|
}
|
|
|
|
|
2023-04-04 07:11:18 +02:00
|
|
|
func BuildAdmissionReport(resource unstructured.Unstructured, request admissionv1.AdmissionRequest, responses ...engineapi.EngineResponse) kyvernov1alpha2.ReportInterface {
|
2023-03-17 13:07:17 +01:00
|
|
|
report := NewAdmissionReport(resource.GetNamespace(), string(request.UID), schema.GroupVersionResource(request.Resource), resource)
|
2022-09-28 13:45:16 +02:00
|
|
|
SetResponses(report, responses...)
|
|
|
|
return report
|
|
|
|
}
|
|
|
|
|
|
|
|
func NewBackgroundScanReport(namespace, name string, gvk schema.GroupVersionKind, owner string, uid types.UID) kyvernov1alpha2.ReportInterface {
|
|
|
|
var report kyvernov1alpha2.ReportInterface
|
|
|
|
if namespace == "" {
|
|
|
|
report = &kyvernov1alpha2.ClusterBackgroundScanReport{}
|
|
|
|
} else {
|
|
|
|
report = &kyvernov1alpha2.BackgroundScanReport{}
|
|
|
|
}
|
|
|
|
report.SetName(name)
|
|
|
|
report.SetNamespace(namespace)
|
|
|
|
controllerutils.SetOwner(report, gvk.GroupVersion().String(), gvk.Kind, owner, uid)
|
2023-03-17 13:07:17 +01:00
|
|
|
SetResourceUid(report, uid)
|
2022-09-28 13:45:16 +02:00
|
|
|
SetManagedByKyvernoLabel(report)
|
|
|
|
return report
|
|
|
|
}
|
|
|
|
|
2023-09-20 08:51:32 +02:00
|
|
|
func NewPolicyReport(namespace, name string, scope *corev1.ObjectReference, results ...policyreportv1alpha2.PolicyReportResult) kyvernov1alpha2.ReportInterface {
|
2022-09-28 13:45:16 +02:00
|
|
|
var report kyvernov1alpha2.ReportInterface
|
|
|
|
if namespace == "" {
|
2023-09-20 08:51:32 +02:00
|
|
|
report = &policyreportv1alpha2.ClusterPolicyReport{
|
|
|
|
Scope: scope,
|
|
|
|
}
|
2022-09-28 13:45:16 +02:00
|
|
|
} else {
|
2023-09-20 08:51:32 +02:00
|
|
|
report = &policyreportv1alpha2.PolicyReport{
|
|
|
|
Scope: scope,
|
|
|
|
}
|
2022-09-28 13:45:16 +02:00
|
|
|
}
|
|
|
|
report.SetName(name)
|
|
|
|
report.SetNamespace(namespace)
|
|
|
|
SetManagedByKyvernoLabel(report)
|
|
|
|
SetResults(report, results...)
|
|
|
|
return report
|
|
|
|
}
|