2022-05-13 07:33:20 +02:00
|
|
|
package policy
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"strings"
|
|
|
|
"time"
|
|
|
|
|
|
|
|
"github.com/go-logr/logr"
|
2022-08-31 14:03:47 +08:00
|
|
|
"github.com/kyverno/kyverno/pkg/clients/dclient"
|
2022-05-13 07:33:20 +02:00
|
|
|
"github.com/kyverno/kyverno/pkg/openapi"
|
|
|
|
policyvalidate "github.com/kyverno/kyverno/pkg/policy"
|
|
|
|
"github.com/kyverno/kyverno/pkg/policymutation"
|
2022-05-24 19:37:01 +02:00
|
|
|
"github.com/kyverno/kyverno/pkg/toggle"
|
2022-05-13 07:33:20 +02:00
|
|
|
admissionutils "github.com/kyverno/kyverno/pkg/utils/admission"
|
2022-05-16 16:36:21 +02:00
|
|
|
"github.com/kyverno/kyverno/pkg/webhooks"
|
2022-05-13 07:33:20 +02:00
|
|
|
admissionv1 "k8s.io/api/admission/v1"
|
|
|
|
)
|
|
|
|
|
|
|
|
type handlers struct {
|
2022-10-12 13:38:48 +02:00
|
|
|
client dclient.Interface
|
|
|
|
openApiManager *openapi.Manager
|
2022-05-13 07:33:20 +02:00
|
|
|
}
|
|
|
|
|
2022-10-12 13:38:48 +02:00
|
|
|
func NewHandlers(client dclient.Interface, openAPIController *openapi.Manager) webhooks.PolicyHandlers {
|
2022-05-13 07:33:20 +02:00
|
|
|
return &handlers{
|
2022-10-12 13:38:48 +02:00
|
|
|
client: client,
|
|
|
|
openApiManager: openAPIController,
|
2022-05-13 07:33:20 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-09-08 09:34:55 +02:00
|
|
|
func (h *handlers) Validate(logger logr.Logger, request *admissionv1.AdmissionRequest, _ time.Time) *admissionv1.AdmissionResponse {
|
2022-05-17 14:15:02 +02:00
|
|
|
if request.SubResource != "" {
|
|
|
|
logger.V(4).Info("skip policy validation on status update")
|
|
|
|
return admissionutils.Response(true)
|
|
|
|
}
|
|
|
|
policy, _, err := admissionutils.GetPolicies(request)
|
2022-05-13 07:33:20 +02:00
|
|
|
if err != nil {
|
|
|
|
logger.Error(err, "failed to unmarshal policies from admission request")
|
|
|
|
return admissionutils.ResponseWithMessage(true, fmt.Sprintf("failed to validate policy, check kyverno controller logs for details: %v", err))
|
|
|
|
}
|
2022-10-12 13:38:48 +02:00
|
|
|
response, err := policyvalidate.Validate(policy, h.client, false, h.openApiManager)
|
2022-05-13 07:33:20 +02:00
|
|
|
if err != nil {
|
|
|
|
logger.Error(err, "policy validation errors")
|
|
|
|
return admissionutils.ResponseWithMessage(false, err.Error())
|
|
|
|
}
|
|
|
|
if response != nil && len(response.Warnings) != 0 {
|
|
|
|
return response
|
|
|
|
}
|
|
|
|
return admissionutils.Response(true)
|
|
|
|
}
|
|
|
|
|
2022-09-08 09:34:55 +02:00
|
|
|
func (h *handlers) Mutate(logger logr.Logger, request *admissionv1.AdmissionRequest, _ time.Time) *admissionv1.AdmissionResponse {
|
2022-08-31 08:41:14 +02:00
|
|
|
if toggle.AutogenInternals.Enabled() {
|
2022-05-24 19:37:01 +02:00
|
|
|
return admissionutils.Response(true)
|
|
|
|
}
|
2022-05-17 14:15:02 +02:00
|
|
|
if request.SubResource != "" {
|
|
|
|
logger.V(4).Info("skip policy validation on status update")
|
|
|
|
return admissionutils.Response(true)
|
|
|
|
}
|
|
|
|
policy, _, err := admissionutils.GetPolicies(request)
|
2022-05-13 07:33:20 +02:00
|
|
|
if err != nil {
|
|
|
|
logger.Error(err, "failed to unmarshal policies from admission request")
|
|
|
|
return admissionutils.ResponseWithMessage(true, fmt.Sprintf("failed to default value, check kyverno controller logs for details: %v", err))
|
|
|
|
}
|
|
|
|
if patches, updateMsgs := policymutation.GenerateJSONPatchesForDefaults(policy, logger); len(patches) != 0 {
|
|
|
|
return admissionutils.ResponseWithMessageAndPatch(true, strings.Join(updateMsgs, "'"), patches)
|
|
|
|
}
|
|
|
|
return admissionutils.Response(true)
|
|
|
|
}
|