2022-12-15 09:34:44 +01:00
|
|
|
package exception
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
|
|
|
"time"
|
|
|
|
|
|
|
|
"github.com/go-logr/logr"
|
|
|
|
admissionutils "github.com/kyverno/kyverno/pkg/utils/admission"
|
|
|
|
validation "github.com/kyverno/kyverno/pkg/validation/exception"
|
2023-04-04 07:11:18 +02:00
|
|
|
"github.com/kyverno/kyverno/pkg/webhooks/handlers"
|
2022-12-15 09:34:44 +01:00
|
|
|
)
|
|
|
|
|
2023-04-04 07:11:18 +02:00
|
|
|
type exceptionHandlers struct {
|
2023-01-23 10:48:54 +01:00
|
|
|
validationOptions validation.ValidationOptions
|
|
|
|
}
|
2022-12-15 10:53:22 +01:00
|
|
|
|
2025-02-04 13:52:48 +01:00
|
|
|
func NewHandlers(validationOptions validation.ValidationOptions) *exceptionHandlers {
|
2023-04-04 07:11:18 +02:00
|
|
|
return &exceptionHandlers{
|
2023-01-23 10:48:54 +01:00
|
|
|
validationOptions: validationOptions,
|
|
|
|
}
|
2022-12-15 10:53:22 +01:00
|
|
|
}
|
2022-12-15 09:34:44 +01:00
|
|
|
|
|
|
|
// Validate performs the validation check on policy exception resources
|
2025-02-04 13:52:48 +01:00
|
|
|
func (h *exceptionHandlers) Validate(ctx context.Context, logger logr.Logger, request handlers.AdmissionRequest, _ string, startTime time.Time) handlers.AdmissionResponse {
|
2023-04-04 07:11:18 +02:00
|
|
|
polex, _, err := admissionutils.GetPolicyExceptions(request.AdmissionRequest)
|
2022-12-15 09:34:44 +01:00
|
|
|
if err != nil {
|
|
|
|
logger.Error(err, "failed to unmarshal policy exceptions from admission request")
|
|
|
|
return admissionutils.Response(request.UID, err)
|
|
|
|
}
|
2025-02-05 17:01:11 +02:00
|
|
|
warnings := validation.ValidateNamespace(ctx, logger, polex.GetNamespace(), h.validationOptions)
|
|
|
|
errs := polex.Validate()
|
|
|
|
return admissionutils.Response(request.UID, errs.ToAggregate(), warnings...)
|
2022-12-15 09:34:44 +01:00
|
|
|
}
|