2019-08-13 13:15:04 -07:00
|
|
|
package policy
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
|
2020-03-17 16:25:34 -07:00
|
|
|
"github.com/go-logr/logr"
|
2020-10-07 11:12:31 -07:00
|
|
|
"github.com/kyverno/kyverno/pkg/engine/response"
|
|
|
|
"github.com/kyverno/kyverno/pkg/event"
|
2020-11-09 11:26:12 -08:00
|
|
|
"github.com/kyverno/kyverno/pkg/policyreport"
|
2019-08-13 13:15:04 -07:00
|
|
|
)
|
|
|
|
|
2020-12-21 11:04:19 -08:00
|
|
|
func (pc *PolicyController) report(policy string, engineResponses []response.EngineResponse, logger logr.Logger) {
|
|
|
|
eventInfos := generateEvents(logger, engineResponses)
|
2019-11-12 14:41:29 -08:00
|
|
|
pc.eventGen.Add(eventInfos...)
|
2020-12-21 11:04:19 -08:00
|
|
|
|
2020-11-09 11:26:12 -08:00
|
|
|
pvInfos := policyreport.GeneratePRsFromEngineResponse(engineResponses, logger)
|
2020-02-26 00:26:09 +05:30
|
|
|
|
2020-12-21 11:04:19 -08:00
|
|
|
// as engineResponses holds the results for all matched resources in one namespace
|
|
|
|
// we can merge pvInfos into a single object to reduce update frequency (throttling request) on RCR
|
|
|
|
info := mergePvInfos(pvInfos)
|
|
|
|
pc.prGenerator.Add(info)
|
|
|
|
logger.V(4).Info("added a request to RCR generator", "key", info.ToKey())
|
2019-11-12 14:41:29 -08:00
|
|
|
}
|
|
|
|
|
2020-03-17 16:25:34 -07:00
|
|
|
func generateEvents(log logr.Logger, ers []response.EngineResponse) []event.Info {
|
2019-11-12 14:41:29 -08:00
|
|
|
var eventInfos []event.Info
|
|
|
|
for _, er := range ers {
|
2020-06-30 11:53:27 -07:00
|
|
|
if er.IsSuccessful() {
|
2019-11-12 14:41:29 -08:00
|
|
|
continue
|
|
|
|
}
|
2020-03-17 16:25:34 -07:00
|
|
|
eventInfos = append(eventInfos, generateEventsPerEr(log, er)...)
|
2019-11-12 14:41:29 -08:00
|
|
|
}
|
|
|
|
return eventInfos
|
|
|
|
}
|
2019-08-13 13:15:04 -07:00
|
|
|
|
2020-03-17 16:25:34 -07:00
|
|
|
func generateEventsPerEr(log logr.Logger, er response.EngineResponse) []event.Info {
|
2019-11-12 14:41:29 -08:00
|
|
|
var eventInfos []event.Info
|
2020-07-20 08:00:02 -07:00
|
|
|
|
|
|
|
logger := log.WithValues("policy", er.PolicyResponse.Policy, "kind", er.PolicyResponse.Resource.Kind, "namespace", er.PolicyResponse.Resource.Namespace, "name", er.PolicyResponse.Resource.Name)
|
2020-03-17 16:25:34 -07:00
|
|
|
logger.V(4).Info("reporting results for policy")
|
2020-07-20 08:00:02 -07:00
|
|
|
|
2019-11-12 14:41:29 -08:00
|
|
|
for _, rule := range er.PolicyResponse.Rules {
|
|
|
|
if rule.Success {
|
|
|
|
continue
|
|
|
|
}
|
2019-08-13 13:15:04 -07:00
|
|
|
// generate event on resource for each failed rule
|
2020-03-17 16:25:34 -07:00
|
|
|
logger.V(4).Info("generating event on resource")
|
2019-08-26 13:34:42 -07:00
|
|
|
e := event.Info{}
|
2019-11-12 14:41:29 -08:00
|
|
|
e.Kind = er.PolicyResponse.Resource.Kind
|
|
|
|
e.Namespace = er.PolicyResponse.Resource.Namespace
|
|
|
|
e.Name = er.PolicyResponse.Resource.Name
|
2019-11-18 17:13:48 -08:00
|
|
|
e.Reason = event.PolicyViolation.String()
|
2019-12-26 11:50:41 -08:00
|
|
|
e.Source = event.PolicyController
|
2020-07-20 08:00:02 -07:00
|
|
|
e.Message = fmt.Sprintf("policy '%s' (%s) rule '%s' failed. %v", er.PolicyResponse.Policy, rule.Type, rule.Name, rule.Message)
|
2019-11-12 14:41:29 -08:00
|
|
|
eventInfos = append(eventInfos, e)
|
|
|
|
}
|
|
|
|
|
|
|
|
return eventInfos
|
2019-08-13 13:15:04 -07:00
|
|
|
}
|
2020-12-21 11:04:19 -08:00
|
|
|
|
|
|
|
func mergePvInfos(infos []policyreport.Info) policyreport.Info {
|
|
|
|
aggregatedInfo := policyreport.Info{}
|
|
|
|
if len(infos) == 0 {
|
|
|
|
return aggregatedInfo
|
|
|
|
}
|
|
|
|
|
|
|
|
var results []policyreport.EngineResponseResult
|
|
|
|
for _, info := range infos {
|
|
|
|
for _, res := range info.Results {
|
|
|
|
results = append(results, res)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
aggregatedInfo.PolicyName = infos[0].PolicyName
|
|
|
|
aggregatedInfo.Namespace = infos[0].Namespace
|
|
|
|
aggregatedInfo.Results = results
|
|
|
|
return aggregatedInfo
|
|
|
|
}
|