2019-10-30 13:39:19 -07:00
|
|
|
package webhookconfig
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
2019-12-02 17:15:47 -08:00
|
|
|
"sync"
|
2019-10-30 13:39:19 -07:00
|
|
|
|
|
|
|
"github.com/nirmata/kyverno/pkg/config"
|
|
|
|
admregapi "k8s.io/api/admissionregistration/v1beta1"
|
|
|
|
errorsapi "k8s.io/apimachinery/pkg/api/errors"
|
|
|
|
v1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
|
|
|
)
|
|
|
|
|
|
|
|
func (wrc *WebhookRegistrationClient) constructVerifyMutatingWebhookConfig(caData []byte) *admregapi.MutatingWebhookConfiguration {
|
|
|
|
return &admregapi.MutatingWebhookConfiguration{
|
|
|
|
ObjectMeta: v1.ObjectMeta{
|
|
|
|
Name: config.VerifyMutatingWebhookConfigurationName,
|
|
|
|
OwnerReferences: []v1.OwnerReference{
|
|
|
|
wrc.constructOwner(),
|
|
|
|
},
|
|
|
|
},
|
2020-03-17 11:05:20 -07:00
|
|
|
Webhooks: []admregapi.MutatingWebhook{
|
|
|
|
generateMutatingWebhook(
|
2019-10-30 13:39:19 -07:00
|
|
|
config.VerifyMutatingWebhookName,
|
|
|
|
config.VerifyMutatingWebhookServicePath,
|
|
|
|
caData,
|
|
|
|
true,
|
|
|
|
wrc.timeoutSeconds,
|
|
|
|
"deployments/*",
|
|
|
|
"apps",
|
|
|
|
"v1",
|
|
|
|
[]admregapi.OperationType{admregapi.Update},
|
|
|
|
),
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (wrc *WebhookRegistrationClient) constructDebugVerifyMutatingWebhookConfig(caData []byte) *admregapi.MutatingWebhookConfiguration {
|
2020-03-17 16:25:34 -07:00
|
|
|
logger := wrc.log
|
2019-10-30 13:39:19 -07:00
|
|
|
url := fmt.Sprintf("https://%s%s", wrc.serverIP, config.VerifyMutatingWebhookServicePath)
|
2020-03-17 16:25:34 -07:00
|
|
|
logger.V(4).Info("Debug VerifyMutatingWebhookConfig is registered with url", "url", url)
|
2019-10-30 13:39:19 -07:00
|
|
|
return &admregapi.MutatingWebhookConfiguration{
|
|
|
|
ObjectMeta: v1.ObjectMeta{
|
|
|
|
Name: config.VerifyMutatingWebhookConfigurationDebugName,
|
|
|
|
},
|
2020-03-17 11:05:20 -07:00
|
|
|
Webhooks: []admregapi.MutatingWebhook{
|
|
|
|
generateDebugMutatingWebhook(
|
2019-10-30 13:39:19 -07:00
|
|
|
config.VerifyMutatingWebhookName,
|
|
|
|
url,
|
|
|
|
caData,
|
|
|
|
true,
|
|
|
|
wrc.timeoutSeconds,
|
|
|
|
"deployments/*",
|
|
|
|
"apps",
|
|
|
|
"v1",
|
|
|
|
[]admregapi.OperationType{admregapi.Update},
|
|
|
|
),
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-12-02 17:15:47 -08:00
|
|
|
func (wrc *WebhookRegistrationClient) removeVerifyWebhookMutatingWebhookConfig(wg *sync.WaitGroup) {
|
|
|
|
defer wg.Done()
|
2020-05-17 14:37:05 -07:00
|
|
|
|
2019-10-30 13:39:19 -07:00
|
|
|
var err error
|
|
|
|
var mutatingConfig string
|
|
|
|
if wrc.serverIP != "" {
|
|
|
|
mutatingConfig = config.VerifyMutatingWebhookConfigurationDebugName
|
|
|
|
} else {
|
|
|
|
mutatingConfig = config.VerifyMutatingWebhookConfigurationName
|
|
|
|
}
|
2020-05-17 14:37:05 -07:00
|
|
|
|
2020-03-17 16:25:34 -07:00
|
|
|
logger := wrc.log.WithValues("name", mutatingConfig)
|
2019-11-19 10:13:03 -08:00
|
|
|
err = wrc.client.DeleteResource(MutatingWebhookConfigurationKind, "", mutatingConfig, false)
|
2019-10-30 13:39:19 -07:00
|
|
|
if errorsapi.IsNotFound(err) {
|
2020-05-17 14:37:05 -07:00
|
|
|
logger.V(5).Info("verify webhook configuration not found")
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
if err != nil {
|
2020-03-17 16:25:34 -07:00
|
|
|
logger.Error(err, "failed to delete verify wwebhook configuration")
|
2020-05-17 14:37:05 -07:00
|
|
|
return
|
2019-10-30 13:39:19 -07:00
|
|
|
}
|
2020-05-17 14:37:05 -07:00
|
|
|
|
|
|
|
logger.V(4).Info("successfully deleted verify webhook configuration")
|
2019-10-30 13:39:19 -07:00
|
|
|
}
|