1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-09 09:26:54 +00:00
kyverno/pkg/engine/generation.go

54 lines
1.7 KiB
Go
Raw Normal View History

2019-05-13 18:17:28 -07:00
package engine
import (
"fmt"
2019-05-31 17:59:36 -07:00
"github.com/golang/glog"
2019-05-21 11:00:09 -07:00
kubepolicy "github.com/nirmata/kyverno/pkg/apis/policy/v1alpha1"
client "github.com/nirmata/kyverno/pkg/dclient"
"github.com/nirmata/kyverno/pkg/info"
2019-05-14 18:20:41 -07:00
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
)
2019-05-14 18:20:41 -07:00
// Generate should be called to process generate rules on the resource
2019-06-26 12:19:11 -07:00
func Generate(client *client.Client, policy kubepolicy.Policy, rawResource []byte, gvk metav1.GroupVersionKind, processExisting bool) []*info.RuleInfo {
ris := []*info.RuleInfo{}
2019-05-14 18:20:41 -07:00
for _, rule := range policy.Spec.Rules {
if rule.Generation == nil {
continue
}
2019-05-14 18:20:41 -07:00
2019-06-25 23:58:28 -07:00
ri := info.NewRuleInfo(rule.Name, info.Generation)
ok := ResourceMeetsDescription(rawResource, rule.ResourceDescription, gvk)
2019-05-14 18:20:41 -07:00
if !ok {
2019-05-31 17:59:36 -07:00
glog.Infof("Rule is not applicable to the request: rule name = %s in policy %s \n", rule.Name, policy.ObjectMeta.Name)
2019-05-14 18:20:41 -07:00
continue
}
2019-06-26 12:19:11 -07:00
err := applyRuleGenerator(client, rawResource, rule.Generation, gvk, processExisting)
2019-05-14 18:20:41 -07:00
if err != nil {
ri.Fail()
2019-06-26 18:04:50 -07:00
ri.Addf("Rule %s: Failed to apply rule generator, err %v.", rule.Name, err)
} else {
2019-06-26 18:04:50 -07:00
ri.Addf("Rule %s: Generation succesfully.", rule.Name)
}
ris = append(ris, ri)
}
return ris
}
2019-06-26 12:19:11 -07:00
func applyRuleGenerator(client *client.Client, rawResource []byte, generator *kubepolicy.Generation, gvk metav1.GroupVersionKind, processExistingResources bool) error {
var err error
namespace := ParseNameFromObject(rawResource)
2019-06-26 12:19:11 -07:00
err = client.GenerateResource(*generator, namespace, processExistingResources)
if err != nil {
return fmt.Errorf("Unable to apply generator for %s '%s/%s' : %v", generator.Kind, namespace, generator.Name, err)
}
glog.Infof("Successfully applied generator %s '%s/%s'", generator.Kind, namespace, generator.Name)
return nil
}