mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-06 16:06:56 +00:00
40 lines
1.1 KiB
Go
40 lines
1.1 KiB
Go
|
package main
|
||
|
|
||
|
import (
|
||
|
"time"
|
||
|
|
||
|
"github.com/go-logr/logr"
|
||
|
"github.com/kyverno/kyverno/cmd/cleanup-controller/validate"
|
||
|
"github.com/kyverno/kyverno/pkg/clients/dclient"
|
||
|
admissionutils "github.com/kyverno/kyverno/pkg/utils/admission"
|
||
|
admissionv1 "k8s.io/api/admission/v1"
|
||
|
)
|
||
|
|
||
|
type cleanupPolicyHandlers struct {
|
||
|
client dclient.Interface
|
||
|
}
|
||
|
|
||
|
func NewHandlers(client dclient.Interface) CleanupPolicyHandlers {
|
||
|
return &cleanupPolicyHandlers{
|
||
|
client: client,
|
||
|
}
|
||
|
}
|
||
|
|
||
|
func (h *cleanupPolicyHandlers) Validate(logger logr.Logger, request *admissionv1.AdmissionRequest, _ time.Time) *admissionv1.AdmissionResponse {
|
||
|
if request.SubResource != "" {
|
||
|
logger.V(4).Info("skip policy validation on status update")
|
||
|
return admissionutils.ResponseSuccess()
|
||
|
}
|
||
|
policy, _, err := admissionutils.GetCleanupPolicies(request)
|
||
|
if err != nil {
|
||
|
logger.Error(err, "failed to unmarshal policies from admission request")
|
||
|
return admissionutils.Response(err)
|
||
|
}
|
||
|
err = validate.ValidateCleanupPolicy(policy, h.client, false)
|
||
|
if err != nil {
|
||
|
logger.Error(err, "policy validation errors")
|
||
|
return admissionutils.Response(err)
|
||
|
}
|
||
|
return admissionutils.Response(err)
|
||
|
}
|