2019-08-21 01:07:32 -07:00
|
|
|
package webhookconfig
|
2019-03-21 15:57:30 +02:00
|
|
|
|
2019-03-19 21:32:31 +02:00
|
|
|
import (
|
2019-03-25 10:11:50 +02:00
|
|
|
"errors"
|
2020-03-17 11:05:20 -07:00
|
|
|
"fmt"
|
2020-11-26 16:07:06 -08:00
|
|
|
"strings"
|
2019-11-18 11:41:37 -08:00
|
|
|
"sync"
|
2019-08-27 16:44:10 -07:00
|
|
|
"time"
|
2019-03-19 21:32:31 +02:00
|
|
|
|
2020-03-17 11:05:20 -07:00
|
|
|
"github.com/go-logr/logr"
|
2020-10-07 11:12:31 -07:00
|
|
|
"github.com/kyverno/kyverno/pkg/config"
|
|
|
|
client "github.com/kyverno/kyverno/pkg/dclient"
|
2021-02-05 09:58:10 -08:00
|
|
|
"github.com/kyverno/kyverno/pkg/resourcecache"
|
2021-03-16 11:31:04 -07:00
|
|
|
"github.com/kyverno/kyverno/pkg/tls"
|
2019-03-25 10:11:50 +02:00
|
|
|
admregapi "k8s.io/api/admissionregistration/v1beta1"
|
2021-03-30 16:46:01 -04:00
|
|
|
corev1 "k8s.io/api/core/v1"
|
2019-08-14 11:51:01 -07:00
|
|
|
errorsapi "k8s.io/apimachinery/pkg/api/errors"
|
2021-02-05 09:58:10 -08:00
|
|
|
v1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
2021-03-16 11:31:04 -07:00
|
|
|
"k8s.io/apimachinery/pkg/apis/meta/v1/unstructured"
|
2021-03-30 16:46:01 -04:00
|
|
|
"k8s.io/apimachinery/pkg/runtime"
|
2019-03-21 18:14:26 +02:00
|
|
|
rest "k8s.io/client-go/rest"
|
2019-03-19 21:32:31 +02:00
|
|
|
)
|
|
|
|
|
2019-11-15 14:01:40 -08:00
|
|
|
const (
|
2020-11-26 16:07:06 -08:00
|
|
|
kindMutating string = "MutatingWebhookConfiguration"
|
|
|
|
kindValidating string = "ValidatingWebhookConfiguration"
|
2019-11-15 14:01:40 -08:00
|
|
|
)
|
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
// Register manages webhook registration. There are five webhooks:
|
|
|
|
// 1. Policy Validation
|
|
|
|
// 2. Policy Mutation
|
|
|
|
// 3. Resource Validation
|
|
|
|
// 4. Resource Mutation
|
|
|
|
// 5. Webhook Status Mutation
|
|
|
|
type Register struct {
|
2020-12-04 10:04:46 -08:00
|
|
|
client *client.Client
|
|
|
|
clientConfig *rest.Config
|
2021-02-05 09:58:10 -08:00
|
|
|
resCache resourcecache.ResourceCache
|
2020-11-26 16:07:06 -08:00
|
|
|
serverIP string // when running outside a cluster
|
2019-09-04 13:43:12 -07:00
|
|
|
timeoutSeconds int32
|
2020-03-17 11:05:20 -07:00
|
|
|
log logr.Logger
|
2019-03-25 10:11:50 +02:00
|
|
|
}
|
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
// NewRegister creates new Register instance
|
|
|
|
func NewRegister(
|
2019-11-15 14:01:40 -08:00
|
|
|
clientConfig *rest.Config,
|
|
|
|
client *client.Client,
|
2021-02-05 09:58:10 -08:00
|
|
|
resCache resourcecache.ResourceCache,
|
2019-11-15 14:01:40 -08:00
|
|
|
serverIP string,
|
2020-03-17 11:05:20 -07:00
|
|
|
webhookTimeout int32,
|
2020-11-26 16:07:06 -08:00
|
|
|
log logr.Logger) *Register {
|
|
|
|
return &Register{
|
2019-12-04 12:31:27 -08:00
|
|
|
clientConfig: clientConfig,
|
|
|
|
client: client,
|
2021-02-05 09:58:10 -08:00
|
|
|
resCache: resCache,
|
2019-12-04 12:31:27 -08:00
|
|
|
serverIP: serverIP,
|
|
|
|
timeoutSeconds: webhookTimeout,
|
2020-11-26 16:07:06 -08:00
|
|
|
log: log.WithName("Register"),
|
2019-11-15 14:01:40 -08:00
|
|
|
}
|
2019-03-25 15:44:53 +02:00
|
|
|
}
|
2019-03-25 10:11:50 +02:00
|
|
|
|
2020-12-08 15:04:24 -08:00
|
|
|
// Register clean up the old webhooks and re-creates admission webhooks configs on cluster
|
2020-11-26 16:07:06 -08:00
|
|
|
func (wrc *Register) Register() error {
|
|
|
|
logger := wrc.log
|
2019-06-10 18:10:51 -07:00
|
|
|
if wrc.serverIP != "" {
|
2020-11-26 16:07:06 -08:00
|
|
|
logger.Info("Registering webhook", "url", fmt.Sprintf("https://%s", wrc.serverIP))
|
2019-06-10 18:10:51 -07:00
|
|
|
}
|
2021-03-30 16:46:01 -04:00
|
|
|
if err := wrc.checkEndpoint(); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2019-08-07 18:01:28 -07:00
|
|
|
|
2020-12-08 15:04:24 -08:00
|
|
|
wrc.removeWebhookConfigurations()
|
|
|
|
|
2021-03-16 11:31:04 -07:00
|
|
|
caData := wrc.readCaData()
|
|
|
|
if caData == nil {
|
|
|
|
return errors.New("Unable to extract CA data from configuration")
|
|
|
|
}
|
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
errors := make([]string, 0)
|
2021-03-16 11:31:04 -07:00
|
|
|
if err := wrc.createVerifyMutatingWebhookConfiguration(caData); err != nil {
|
2020-11-26 16:07:06 -08:00
|
|
|
errors = append(errors, err.Error())
|
2019-11-25 18:22:05 -08:00
|
|
|
}
|
|
|
|
|
2021-03-16 11:31:04 -07:00
|
|
|
if err := wrc.createPolicyValidatingWebhookConfiguration(caData); err != nil {
|
2020-11-26 16:07:06 -08:00
|
|
|
errors = append(errors, err.Error())
|
2019-05-14 18:10:25 +03:00
|
|
|
}
|
2020-11-26 16:07:06 -08:00
|
|
|
|
2021-03-16 11:31:04 -07:00
|
|
|
if err := wrc.createPolicyMutatingWebhookConfiguration(caData); err != nil {
|
2020-11-26 16:07:06 -08:00
|
|
|
errors = append(errors, err.Error())
|
|
|
|
}
|
|
|
|
|
2021-03-16 11:31:04 -07:00
|
|
|
if err := wrc.createResourceValidatingWebhookConfiguration(caData); err != nil {
|
2020-11-26 16:07:06 -08:00
|
|
|
errors = append(errors, err.Error())
|
|
|
|
}
|
|
|
|
|
2021-03-16 11:31:04 -07:00
|
|
|
if err := wrc.createResourceMutatingWebhookConfiguration(caData); err != nil {
|
2020-11-26 16:07:06 -08:00
|
|
|
errors = append(errors, err.Error())
|
|
|
|
}
|
|
|
|
|
|
|
|
if len(errors) > 0 {
|
|
|
|
return fmt.Errorf("%s", strings.Join(errors, ","))
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2021-02-05 09:58:10 -08:00
|
|
|
// Check returns an error if any of the webhooks are not configured
|
2020-11-26 16:07:06 -08:00
|
|
|
func (wrc *Register) Check() error {
|
2021-02-05 09:58:10 -08:00
|
|
|
mutatingCache, _ := wrc.resCache.GetGVRCache(kindMutating)
|
|
|
|
validatingCache, _ := wrc.resCache.GetGVRCache(kindValidating)
|
2020-11-26 16:07:06 -08:00
|
|
|
|
2021-02-05 09:58:10 -08:00
|
|
|
if _, err := mutatingCache.Lister().Get(wrc.getVerifyWebhookMutatingWebhookName()); err != nil {
|
2020-11-26 16:07:06 -08:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2021-02-05 09:58:10 -08:00
|
|
|
if _, err := mutatingCache.Lister().Get(wrc.getResourceMutatingWebhookConfigName()); err != nil {
|
2020-11-26 16:07:06 -08:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2021-02-05 09:58:10 -08:00
|
|
|
if _, err := validatingCache.Lister().Get(wrc.getResourceValidatingWebhookConfigName()); err != nil {
|
2020-11-26 16:07:06 -08:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2021-02-05 09:58:10 -08:00
|
|
|
if _, err := mutatingCache.Lister().Get(wrc.getPolicyMutatingWebhookConfigurationName()); err != nil {
|
2020-11-26 16:07:06 -08:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2021-02-05 09:58:10 -08:00
|
|
|
if _, err := validatingCache.Lister().Get(wrc.getPolicyValidatingWebhookConfigurationName()); err != nil {
|
2019-03-25 15:44:53 +02:00
|
|
|
return err
|
2019-03-19 21:32:31 +02:00
|
|
|
}
|
2019-10-30 13:39:19 -07:00
|
|
|
|
2019-08-07 18:01:28 -07:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
// Remove removes all webhook configurations
|
|
|
|
func (wrc *Register) Remove(cleanUp chan<- struct{}) {
|
2021-03-16 11:31:04 -07:00
|
|
|
defer close(cleanUp)
|
|
|
|
if !wrc.cleanupKyvernoResource() {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2019-08-27 16:44:10 -07:00
|
|
|
wrc.removeWebhookConfigurations()
|
2021-03-16 11:31:04 -07:00
|
|
|
wrc.removeSecrets()
|
2019-08-27 16:44:10 -07:00
|
|
|
}
|
|
|
|
|
2021-03-16 11:31:04 -07:00
|
|
|
// cleanupKyvernoResource returns true if Kyverno deployment is terminating
|
|
|
|
func (wrc *Register) cleanupKyvernoResource() bool {
|
|
|
|
logger := wrc.log.WithName("cleanupKyvernoResource")
|
|
|
|
deploy, err := wrc.client.GetResource("", "Deployment", deployNamespace, deployName)
|
|
|
|
if err != nil {
|
2021-03-25 12:28:03 -07:00
|
|
|
logger.Error(err, "failed to get deployment, cleanup kyverno resources anyway")
|
|
|
|
return true
|
2021-03-16 11:31:04 -07:00
|
|
|
}
|
2020-11-03 16:07:02 -08:00
|
|
|
|
2021-03-16 11:31:04 -07:00
|
|
|
if deploy.GetDeletionTimestamp() != nil {
|
2021-03-25 12:28:03 -07:00
|
|
|
logger.Info("Kyverno is terminating, cleanup Kyverno resources")
|
2021-03-16 11:31:04 -07:00
|
|
|
return true
|
|
|
|
}
|
2019-05-14 18:10:25 +03:00
|
|
|
|
2021-03-16 11:31:04 -07:00
|
|
|
replicas, _, err := unstructured.NestedInt64(deploy.UnstructuredContent(), "spec", "replicas")
|
|
|
|
if err != nil {
|
|
|
|
logger.Error(err, "unable to fetch spec.replicas of Kyverno deployment")
|
2019-03-19 21:32:31 +02:00
|
|
|
}
|
2020-11-26 16:07:06 -08:00
|
|
|
|
2021-03-16 11:31:04 -07:00
|
|
|
if replicas == 0 {
|
2021-03-25 12:28:03 -07:00
|
|
|
logger.Info("Kyverno is scaled to zero, cleanup Kyverno resources")
|
2021-03-16 11:31:04 -07:00
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
|
|
|
logger.Info("updating Kyverno Pod, won't clean up Kyverno resources")
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
|
|
|
func (wrc *Register) createResourceMutatingWebhookConfiguration(caData []byte) error {
|
|
|
|
var config *admregapi.MutatingWebhookConfiguration
|
|
|
|
|
2019-08-27 14:52:56 -07:00
|
|
|
if wrc.serverIP != "" {
|
2020-01-11 18:33:11 +05:30
|
|
|
config = wrc.constructDebugMutatingWebhookConfig(caData)
|
2019-08-27 14:52:56 -07:00
|
|
|
} else {
|
|
|
|
config = wrc.constructMutatingWebhookConfig(caData)
|
2019-07-02 18:42:07 -07:00
|
|
|
}
|
2020-11-26 16:07:06 -08:00
|
|
|
|
|
|
|
logger := wrc.log.WithValues("kind", kindMutating, "name", config.Name)
|
|
|
|
|
|
|
|
_, err := wrc.client.CreateResource("", kindMutating, "", *config, false)
|
2019-09-04 13:43:12 -07:00
|
|
|
if errorsapi.IsAlreadyExists(err) {
|
2020-05-18 21:16:48 -07:00
|
|
|
logger.V(6).Info("resource mutating webhook configuration already exists", "name", config.Name)
|
2019-09-04 13:43:12 -07:00
|
|
|
return nil
|
|
|
|
}
|
2020-11-26 16:07:06 -08:00
|
|
|
|
2019-09-04 13:43:12 -07:00
|
|
|
if err != nil {
|
2020-03-17 11:05:20 -07:00
|
|
|
logger.Error(err, "failed to create resource mutating webhook configuration", "name", config.Name)
|
2019-07-02 18:42:07 -07:00
|
|
|
return err
|
|
|
|
}
|
2020-11-03 16:07:02 -08:00
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
logger.Info("created webhook")
|
2019-03-25 15:44:53 +02:00
|
|
|
return nil
|
2019-03-25 10:11:50 +02:00
|
|
|
}
|
|
|
|
|
2021-03-16 11:31:04 -07:00
|
|
|
func (wrc *Register) createResourceValidatingWebhookConfiguration(caData []byte) error {
|
2020-01-11 18:33:11 +05:30
|
|
|
var config *admregapi.ValidatingWebhookConfiguration
|
|
|
|
|
|
|
|
if wrc.serverIP != "" {
|
|
|
|
config = wrc.constructDebugValidatingWebhookConfig(caData)
|
|
|
|
} else {
|
|
|
|
config = wrc.constructValidatingWebhookConfig(caData)
|
|
|
|
}
|
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
logger := wrc.log.WithValues("kind", kindValidating, "name", config.Name)
|
|
|
|
|
|
|
|
_, err := wrc.client.CreateResource("", kindValidating, "", *config, false)
|
2020-01-11 18:33:11 +05:30
|
|
|
if errorsapi.IsAlreadyExists(err) {
|
2020-05-18 21:16:48 -07:00
|
|
|
logger.V(6).Info("resource validating webhook configuration already exists", "name", config.Name)
|
2020-01-11 18:33:11 +05:30
|
|
|
return nil
|
|
|
|
}
|
2020-11-26 16:07:06 -08:00
|
|
|
|
2020-01-11 18:33:11 +05:30
|
|
|
if err != nil {
|
2020-03-17 11:05:20 -07:00
|
|
|
logger.Error(err, "failed to create resource")
|
2020-01-11 18:33:11 +05:30
|
|
|
return err
|
|
|
|
}
|
2020-11-03 16:07:02 -08:00
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
logger.Info("created webhook")
|
2020-01-11 18:33:11 +05:30
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2019-08-27 14:52:56 -07:00
|
|
|
//registerPolicyValidatingWebhookConfiguration create a Validating webhook configuration for Policy CRD
|
2021-03-16 11:31:04 -07:00
|
|
|
func (wrc *Register) createPolicyValidatingWebhookConfiguration(caData []byte) error {
|
2019-08-27 14:52:56 -07:00
|
|
|
var config *admregapi.ValidatingWebhookConfiguration
|
2019-06-10 18:10:51 -07:00
|
|
|
|
2019-08-08 13:09:40 -07:00
|
|
|
if wrc.serverIP != "" {
|
2019-08-27 14:52:56 -07:00
|
|
|
config = wrc.contructDebugPolicyValidatingWebhookConfig(caData)
|
|
|
|
} else {
|
|
|
|
config = wrc.contructPolicyValidatingWebhookConfig(caData)
|
2019-08-08 13:09:40 -07:00
|
|
|
}
|
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
if _, err := wrc.client.CreateResource("", kindValidating, "", *config, false); err != nil {
|
|
|
|
if errorsapi.IsAlreadyExists(err) {
|
|
|
|
wrc.log.V(6).Info("webhook already exists", "kind", kindValidating, "name", config.Name)
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2019-08-27 14:52:56 -07:00
|
|
|
return err
|
2019-08-07 18:01:28 -07:00
|
|
|
}
|
2020-11-26 16:07:06 -08:00
|
|
|
|
|
|
|
wrc.log.Info("created webhook", "kind", kindValidating, "name", config.Name)
|
2019-08-27 14:52:56 -07:00
|
|
|
return nil
|
2019-03-19 21:32:31 +02:00
|
|
|
}
|
|
|
|
|
2021-03-16 11:31:04 -07:00
|
|
|
func (wrc *Register) createPolicyMutatingWebhookConfiguration(caData []byte) error {
|
2019-08-27 14:52:56 -07:00
|
|
|
var config *admregapi.MutatingWebhookConfiguration
|
2020-11-26 16:07:06 -08:00
|
|
|
|
2019-08-27 14:52:56 -07:00
|
|
|
if wrc.serverIP != "" {
|
|
|
|
config = wrc.contructDebugPolicyMutatingWebhookConfig(caData)
|
|
|
|
} else {
|
|
|
|
config = wrc.contructPolicyMutatingWebhookConfig(caData)
|
2019-03-25 15:44:53 +02:00
|
|
|
}
|
|
|
|
|
2019-08-27 14:52:56 -07:00
|
|
|
// create mutating webhook configuration resource
|
2020-11-26 16:07:06 -08:00
|
|
|
if _, err := wrc.client.CreateResource("", kindMutating, "", *config, false); err != nil {
|
|
|
|
if errorsapi.IsAlreadyExists(err) {
|
|
|
|
wrc.log.V(6).Info("webhook already exists", "kind", kindMutating, "name", config.Name)
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2019-08-27 14:52:56 -07:00
|
|
|
return err
|
2019-06-10 18:10:51 -07:00
|
|
|
}
|
2020-11-26 16:07:06 -08:00
|
|
|
|
|
|
|
wrc.log.Info("created webhook", "kind", kindMutating, "name", config.Name)
|
2019-08-27 14:52:56 -07:00
|
|
|
return nil
|
2019-05-14 18:10:25 +03:00
|
|
|
}
|
|
|
|
|
2021-03-16 11:31:04 -07:00
|
|
|
func (wrc *Register) createVerifyMutatingWebhookConfiguration(caData []byte) error {
|
2019-10-30 13:39:19 -07:00
|
|
|
var config *admregapi.MutatingWebhookConfiguration
|
|
|
|
|
|
|
|
if wrc.serverIP != "" {
|
|
|
|
config = wrc.constructDebugVerifyMutatingWebhookConfig(caData)
|
|
|
|
} else {
|
|
|
|
config = wrc.constructVerifyMutatingWebhookConfig(caData)
|
|
|
|
}
|
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
if _, err := wrc.client.CreateResource("", kindMutating, "", *config, false); err != nil {
|
|
|
|
if errorsapi.IsAlreadyExists(err) {
|
|
|
|
wrc.log.V(6).Info("webhook already exists", "kind", kindMutating, "name", config.Name)
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2019-10-30 13:39:19 -07:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
wrc.log.Info("created webhook", "kind", kindMutating, "name", config.Name)
|
2019-10-30 13:39:19 -07:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
func (wrc *Register) removeWebhookConfigurations() {
|
2019-08-27 16:44:10 -07:00
|
|
|
startTime := time.Now()
|
2020-11-26 16:07:06 -08:00
|
|
|
wrc.log.Info("deleting all webhook configurations")
|
2019-08-27 16:44:10 -07:00
|
|
|
defer func() {
|
2020-11-26 16:07:06 -08:00
|
|
|
wrc.log.V(4).Info("removed webhook configurations", "processingTime", time.Since(startTime).String())
|
2019-08-27 16:44:10 -07:00
|
|
|
}()
|
2019-11-18 11:41:37 -08:00
|
|
|
|
|
|
|
var wg sync.WaitGroup
|
2020-01-11 18:33:11 +05:30
|
|
|
wg.Add(5)
|
2020-05-17 14:37:05 -07:00
|
|
|
|
2019-11-18 11:41:37 -08:00
|
|
|
go wrc.removeResourceMutatingWebhookConfiguration(&wg)
|
2020-01-11 18:33:11 +05:30
|
|
|
go wrc.removeResourceValidatingWebhookConfiguration(&wg)
|
2019-11-18 11:41:37 -08:00
|
|
|
go wrc.removePolicyMutatingWebhookConfiguration(&wg)
|
|
|
|
go wrc.removePolicyValidatingWebhookConfiguration(&wg)
|
2019-11-25 13:07:36 -08:00
|
|
|
go wrc.removeVerifyWebhookMutatingWebhookConfig(&wg)
|
2019-11-18 11:41:37 -08:00
|
|
|
|
|
|
|
wg.Wait()
|
|
|
|
}
|
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
func (wrc *Register) removePolicyMutatingWebhookConfiguration(wg *sync.WaitGroup) {
|
2020-01-11 18:33:11 +05:30
|
|
|
defer wg.Done()
|
2019-08-27 14:52:56 -07:00
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
mutatingConfig := wrc.getPolicyMutatingWebhookConfigurationName()
|
|
|
|
|
|
|
|
logger := wrc.log.WithValues("kind", kindMutating, "name", mutatingConfig)
|
|
|
|
err := wrc.client.DeleteResource("", kindMutating, "", mutatingConfig, false)
|
|
|
|
if errorsapi.IsNotFound(err) {
|
|
|
|
logger.V(5).Info("policy mutating webhook configuration not found")
|
|
|
|
return
|
2020-12-04 10:04:46 -08:00
|
|
|
}
|
2020-11-26 16:07:06 -08:00
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
logger.Error(err, "failed to delete policy mutating webhook configuration")
|
|
|
|
return
|
|
|
|
}
|
2020-05-17 14:37:05 -07:00
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
logger.Info("webhook configuration deleted")
|
|
|
|
}
|
|
|
|
|
|
|
|
func (wrc *Register) getPolicyMutatingWebhookConfigurationName() string {
|
2019-11-18 11:41:37 -08:00
|
|
|
var mutatingConfig string
|
|
|
|
if wrc.serverIP != "" {
|
|
|
|
mutatingConfig = config.PolicyMutatingWebhookConfigurationDebugName
|
|
|
|
} else {
|
|
|
|
mutatingConfig = config.PolicyMutatingWebhookConfigurationName
|
|
|
|
}
|
2020-11-26 16:07:06 -08:00
|
|
|
return mutatingConfig
|
|
|
|
}
|
|
|
|
|
|
|
|
func (wrc *Register) removePolicyValidatingWebhookConfiguration(wg *sync.WaitGroup) {
|
|
|
|
defer wg.Done()
|
|
|
|
|
|
|
|
validatingConfig := wrc.getPolicyValidatingWebhookConfigurationName()
|
2020-05-17 14:37:05 -07:00
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
logger := wrc.log.WithValues("kind", kindValidating, "name", validatingConfig)
|
|
|
|
logger.V(4).Info("removing validating webhook configuration")
|
|
|
|
err := wrc.client.DeleteResource("", kindValidating, "", validatingConfig, false)
|
2019-11-18 11:41:37 -08:00
|
|
|
if errorsapi.IsNotFound(err) {
|
2020-11-26 16:07:06 -08:00
|
|
|
logger.V(5).Info("policy validating webhook configuration not found")
|
2020-05-17 14:37:05 -07:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
if err != nil {
|
2020-11-26 16:07:06 -08:00
|
|
|
logger.Error(err, "failed to delete policy validating webhook configuration")
|
2020-05-17 14:37:05 -07:00
|
|
|
return
|
2019-11-18 11:41:37 -08:00
|
|
|
}
|
2020-05-17 14:37:05 -07:00
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
logger.Info("webhook configuration deleted")
|
2019-11-18 11:41:37 -08:00
|
|
|
}
|
2019-06-10 18:10:51 -07:00
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
func (wrc *Register) getPolicyValidatingWebhookConfigurationName() string {
|
2019-11-18 11:41:37 -08:00
|
|
|
var validatingConfig string
|
|
|
|
if wrc.serverIP != "" {
|
|
|
|
validatingConfig = config.PolicyValidatingWebhookConfigurationDebugName
|
|
|
|
} else {
|
|
|
|
validatingConfig = config.PolicyValidatingWebhookConfigurationName
|
|
|
|
}
|
2020-11-26 16:07:06 -08:00
|
|
|
return validatingConfig
|
|
|
|
}
|
2020-05-17 14:37:05 -07:00
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
func (wrc *Register) constructVerifyMutatingWebhookConfig(caData []byte) *admregapi.MutatingWebhookConfiguration {
|
|
|
|
return &admregapi.MutatingWebhookConfiguration{
|
|
|
|
ObjectMeta: v1.ObjectMeta{
|
|
|
|
Name: config.VerifyMutatingWebhookConfigurationName,
|
|
|
|
OwnerReferences: []v1.OwnerReference{
|
|
|
|
wrc.constructOwner(),
|
|
|
|
},
|
|
|
|
},
|
|
|
|
Webhooks: []admregapi.MutatingWebhook{
|
|
|
|
generateMutatingWebhook(
|
|
|
|
config.VerifyMutatingWebhookName,
|
|
|
|
config.VerifyMutatingWebhookServicePath,
|
|
|
|
caData,
|
|
|
|
true,
|
|
|
|
wrc.timeoutSeconds,
|
|
|
|
[]string{"deployments/*"},
|
|
|
|
"apps",
|
|
|
|
"v1",
|
|
|
|
[]admregapi.OperationType{admregapi.Update},
|
|
|
|
),
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (wrc *Register) constructDebugVerifyMutatingWebhookConfig(caData []byte) *admregapi.MutatingWebhookConfiguration {
|
|
|
|
logger := wrc.log
|
|
|
|
url := fmt.Sprintf("https://%s%s", wrc.serverIP, config.VerifyMutatingWebhookServicePath)
|
|
|
|
logger.V(4).Info("Debug VerifyMutatingWebhookConfig is registered with url", "url", url)
|
|
|
|
return &admregapi.MutatingWebhookConfiguration{
|
|
|
|
ObjectMeta: v1.ObjectMeta{
|
|
|
|
Name: config.VerifyMutatingWebhookConfigurationDebugName,
|
|
|
|
},
|
|
|
|
Webhooks: []admregapi.MutatingWebhook{
|
|
|
|
generateDebugMutatingWebhook(
|
|
|
|
config.VerifyMutatingWebhookName,
|
|
|
|
url,
|
|
|
|
caData,
|
|
|
|
true,
|
|
|
|
wrc.timeoutSeconds,
|
|
|
|
[]string{"deployments/*"},
|
|
|
|
"apps",
|
|
|
|
"v1",
|
|
|
|
[]admregapi.OperationType{admregapi.Update},
|
|
|
|
),
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (wrc *Register) removeVerifyWebhookMutatingWebhookConfig(wg *sync.WaitGroup) {
|
|
|
|
defer wg.Done()
|
|
|
|
|
|
|
|
var err error
|
|
|
|
mutatingConfig := wrc.getVerifyWebhookMutatingWebhookName()
|
|
|
|
|
|
|
|
logger := wrc.log.WithValues("kind", kindMutating, "name", mutatingConfig)
|
|
|
|
err = wrc.client.DeleteResource("", kindMutating, "", mutatingConfig, false)
|
2019-11-18 11:41:37 -08:00
|
|
|
if errorsapi.IsNotFound(err) {
|
2020-11-26 16:07:06 -08:00
|
|
|
logger.V(5).Info("verify webhook configuration not found")
|
2020-05-17 14:37:05 -07:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
if err != nil {
|
2020-11-26 16:07:06 -08:00
|
|
|
logger.Error(err, "failed to delete verify webhook configuration")
|
2020-05-17 14:37:05 -07:00
|
|
|
return
|
2019-11-18 11:41:37 -08:00
|
|
|
}
|
2020-05-17 14:37:05 -07:00
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
logger.Info("webhook configuration deleted")
|
2019-05-14 18:10:25 +03:00
|
|
|
}
|
2020-05-18 17:00:52 -07:00
|
|
|
|
2020-11-26 16:07:06 -08:00
|
|
|
func (wrc *Register) getVerifyWebhookMutatingWebhookName() string {
|
|
|
|
var mutatingConfig string
|
|
|
|
if wrc.serverIP != "" {
|
|
|
|
mutatingConfig = config.VerifyMutatingWebhookConfigurationDebugName
|
|
|
|
} else {
|
|
|
|
mutatingConfig = config.VerifyMutatingWebhookConfigurationName
|
|
|
|
}
|
|
|
|
return mutatingConfig
|
|
|
|
}
|
|
|
|
|
2020-05-18 17:00:52 -07:00
|
|
|
// GetWebhookTimeOut returns the value of webhook timeout
|
2020-11-26 16:07:06 -08:00
|
|
|
func (wrc *Register) GetWebhookTimeOut() time.Duration {
|
2020-05-18 17:00:52 -07:00
|
|
|
return time.Duration(wrc.timeoutSeconds)
|
|
|
|
}
|
2021-03-16 11:31:04 -07:00
|
|
|
|
|
|
|
// removeSecrets removes Kyverno managed secrets
|
|
|
|
func (wrc *Register) removeSecrets() {
|
|
|
|
selector := &v1.LabelSelector{
|
|
|
|
MatchLabels: map[string]string{
|
|
|
|
tls.ManagedByLabel: "kyverno",
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
secretList, err := wrc.client.ListResource("", "Secret", config.KyvernoNamespace, selector)
|
|
|
|
if err != nil && errorsapi.IsNotFound(err) {
|
|
|
|
wrc.log.Error(err, "failed to clean up Kyverno managed secrets")
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, secret := range secretList.Items {
|
|
|
|
if err := wrc.client.DeleteResource("", "Secret", secret.GetNamespace(), secret.GetName(), false); err != nil {
|
|
|
|
wrc.log.Error(err, "failed to delete secret", "ns", secret.GetNamespace(), "name", secret.GetName())
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2021-03-30 16:46:01 -04:00
|
|
|
|
|
|
|
func (wrc *Register) checkEndpoint() error {
|
|
|
|
obj, err := wrc.client.GetResource("", "Endpoints", config.KyvernoNamespace, config.KyvernoServiceName)
|
|
|
|
if err != nil {
|
|
|
|
wrc.log.Error(err, "failed to get endpoint", "ns", config.KyvernoNamespace, "name", config.KyvernoServiceName)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
var endpoint corev1.Endpoints
|
|
|
|
err = runtime.DefaultUnstructuredConverter.FromUnstructured(obj.UnstructuredContent(), &endpoint)
|
|
|
|
if err != nil {
|
|
|
|
wrc.log.Error(err, "failed to convert endpoint from unstructured", "ns", config.KyvernoNamespace, "name", config.KyvernoServiceName)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
for _, subset := range endpoint.Subsets {
|
|
|
|
if len(subset.Addresses) == 0 {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
if subset.Addresses[0].IP != "" {
|
|
|
|
wrc.log.Info("Endpoint ready", "ns", config.KyvernoNamespace, "name", config.KyvernoServiceName)
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
}
|
|
|
|
err = fmt.Errorf("Endpoint not ready")
|
2021-03-31 13:24:36 -07:00
|
|
|
wrc.log.V(3).Info(err.Error(), "ns", config.KyvernoNamespace, "name", config.KyvernoServiceName)
|
2021-03-30 16:46:01 -04:00
|
|
|
return err
|
|
|
|
}
|