2021-07-23 21:46:50 +05:30
package policyexecutionduration
2021-05-15 19:15:04 +05:30
import (
2021-09-11 03:09:12 +05:30
"fmt"
2021-10-29 18:13:20 +02:00
kyverno "github.com/kyverno/kyverno/api/kyverno/v1"
2021-05-15 19:15:04 +05:30
"github.com/kyverno/kyverno/pkg/engine/response"
"github.com/kyverno/kyverno/pkg/metrics"
2022-04-04 17:31:33 +02:00
"github.com/kyverno/kyverno/pkg/utils"
2021-05-15 19:15:04 +05:30
prom "github.com/prometheus/client_golang/prometheus"
)
2022-04-06 20:14:13 +02:00
func registerPolicyExecutionDurationMetric (
pc * metrics . PromConfig ,
2021-05-15 19:15:04 +05:30
policyValidationMode metrics . PolicyValidationMode ,
policyType metrics . PolicyType ,
policyBackgroundMode metrics . PolicyBackgroundMode ,
policyNamespace , policyName string ,
2021-09-02 06:56:25 +05:30
resourceKind , resourceNamespace string ,
2021-05-15 19:15:04 +05:30
resourceRequestOperation metrics . ResourceRequestOperation ,
ruleName string ,
ruleResult metrics . RuleResult ,
ruleType metrics . RuleType ,
ruleExecutionCause metrics . RuleExecutionCause ,
2021-07-23 21:46:50 +05:30
generateRuleLatencyType string ,
ruleExecutionLatency float64 ,
2021-05-15 19:15:04 +05:30
) error {
if policyType == metrics . Cluster {
policyNamespace = "-"
}
2021-07-23 21:46:50 +05:30
if ruleType != metrics . Generate || generateRuleLatencyType == "" {
generateRuleLatencyType = "-"
}
2021-09-11 03:09:12 +05:30
includeNamespaces , excludeNamespaces := pc . Config . GetIncludeNamespaces ( ) , pc . Config . GetExcludeNamespaces ( )
2022-04-04 17:31:33 +02:00
if ( resourceNamespace != "" && resourceNamespace != "-" ) && utils . ContainsString ( excludeNamespaces , resourceNamespace ) {
2022-04-29 19:33:08 +02:00
metrics . Logger ( ) . Info ( fmt . Sprintf ( "Skipping the registration of kyverno_policy_execution_duration_seconds metric as the operation belongs to the namespace '%s' which is one of 'namespaces.exclude' %+v in values.yaml" , resourceNamespace , excludeNamespaces ) )
2021-09-11 03:09:12 +05:30
return nil
}
2022-04-04 17:31:33 +02:00
if ( resourceNamespace != "" && resourceNamespace != "-" ) && len ( includeNamespaces ) > 0 && ! utils . ContainsString ( includeNamespaces , resourceNamespace ) {
2022-04-29 19:33:08 +02:00
metrics . Logger ( ) . Info ( fmt . Sprintf ( "Skipping the registration of kyverno_policy_execution_duration_seconds metric as the operation belongs to the namespace '%s' which is not one of 'namespaces.include' %+v in values.yaml" , resourceNamespace , includeNamespaces ) )
2021-09-11 03:09:12 +05:30
return nil
}
pc . Metrics . PolicyExecutionDuration . With ( prom . Labels {
2021-07-23 21:46:50 +05:30
"policy_validation_mode" : string ( policyValidationMode ) ,
"policy_type" : string ( policyType ) ,
"policy_background_mode" : string ( policyBackgroundMode ) ,
"policy_namespace" : policyNamespace ,
"policy_name" : policyName ,
"resource_kind" : resourceKind ,
"resource_namespace" : resourceNamespace ,
"resource_request_operation" : string ( resourceRequestOperation ) ,
"rule_name" : ruleName ,
"rule_result" : string ( ruleResult ) ,
"rule_type" : string ( ruleType ) ,
"rule_execution_cause" : string ( ruleExecutionCause ) ,
"generate_rule_latency_type" : generateRuleLatencyType ,
} ) . Observe ( ruleExecutionLatency )
2021-05-15 19:15:04 +05:30
return nil
}
2022-05-17 08:19:03 +02:00
// policy - policy related data
// engineResponse - resource and rule related data
2022-04-06 20:14:13 +02:00
func ProcessEngineResponse ( pc * metrics . PromConfig , policy kyverno . PolicyInterface , engineResponse response . EngineResponse , executionCause metrics . RuleExecutionCause , generateRuleLatencyType string , resourceRequestOperation metrics . ResourceRequestOperation ) error {
name , namespace , policyType , backgroundMode , validationMode , err := metrics . GetPolicyInfos ( policy )
2021-05-15 19:15:04 +05:30
if err != nil {
return err
}
resourceSpec := engineResponse . PolicyResponse . Resource
resourceKind := resourceSpec . Kind
resourceNamespace := resourceSpec . Namespace
ruleResponses := engineResponse . PolicyResponse . Rules
for _ , rule := range ruleResponses {
ruleName := rule . Name
2022-04-06 20:14:13 +02:00
ruleType := metrics . ParseRuleTypeFromEngineRuleResponse ( rule )
2021-10-30 02:56:04 +05:30
var ruleResult metrics . RuleResult
switch rule . Status {
case response . RuleStatusPass :
2021-05-15 19:15:04 +05:30
ruleResult = metrics . Pass
2021-10-30 02:56:04 +05:30
case response . RuleStatusFail :
ruleResult = metrics . Fail
case response . RuleStatusWarn :
ruleResult = metrics . Warn
case response . RuleStatusError :
ruleResult = metrics . Error
case response . RuleStatusSkip :
ruleResult = metrics . Skip
default :
ruleResult = metrics . Fail
2021-05-15 19:15:04 +05:30
}
2021-07-23 21:46:50 +05:30
ruleExecutionLatencyInSeconds := float64 ( rule . RuleStats . ProcessingTime ) / float64 ( 1000 * 1000 * 1000 )
2022-04-06 20:14:13 +02:00
if err := registerPolicyExecutionDurationMetric (
pc ,
validationMode ,
2021-05-15 19:15:04 +05:30
policyType ,
2022-04-06 20:14:13 +02:00
backgroundMode ,
namespace , name ,
2021-09-02 06:56:25 +05:30
resourceKind , resourceNamespace ,
2021-05-15 19:15:04 +05:30
resourceRequestOperation ,
ruleName ,
ruleResult ,
ruleType ,
executionCause ,
2021-07-23 21:46:50 +05:30
generateRuleLatencyType ,
ruleExecutionLatencyInSeconds ,
2021-05-15 19:15:04 +05:30
) ; err != nil {
return err
}
}
return nil
}