2022-09-01 16:52:36 +02:00
|
|
|
package utils
|
|
|
|
|
|
|
|
import (
|
2024-06-20 11:44:43 +02:00
|
|
|
kyvernov2 "github.com/kyverno/kyverno/api/kyverno/v2"
|
2022-09-01 16:52:36 +02:00
|
|
|
"github.com/kyverno/kyverno/pkg/config"
|
|
|
|
"github.com/kyverno/kyverno/pkg/engine"
|
2023-04-13 13:29:40 +02:00
|
|
|
"github.com/kyverno/kyverno/pkg/engine/jmespath"
|
2022-09-01 16:52:36 +02:00
|
|
|
admissionv1 "k8s.io/api/admission/v1"
|
2023-04-04 12:23:20 +02:00
|
|
|
"k8s.io/apimachinery/pkg/runtime/schema"
|
2022-09-01 16:52:36 +02:00
|
|
|
)
|
|
|
|
|
|
|
|
type PolicyContextBuilder interface {
|
2023-04-04 12:23:20 +02:00
|
|
|
Build(admissionv1.AdmissionRequest, []string, []string, schema.GroupVersionKind) (*engine.PolicyContext, error)
|
2022-09-01 16:52:36 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
type policyContextBuilder struct {
|
2023-02-03 06:01:11 +01:00
|
|
|
configuration config.Configuration
|
2023-04-13 13:29:40 +02:00
|
|
|
jp jmespath.Interface
|
2022-09-01 16:52:36 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
func NewPolicyContextBuilder(
|
|
|
|
configuration config.Configuration,
|
2023-04-13 13:29:40 +02:00
|
|
|
jp jmespath.Interface,
|
2022-09-01 16:52:36 +02:00
|
|
|
) PolicyContextBuilder {
|
|
|
|
return &policyContextBuilder{
|
2023-02-03 06:01:11 +01:00
|
|
|
configuration: configuration,
|
2023-04-13 13:29:40 +02:00
|
|
|
jp: jp,
|
2022-09-01 16:52:36 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-04-04 12:23:20 +02:00
|
|
|
func (b *policyContextBuilder) Build(request admissionv1.AdmissionRequest, roles, clusterRoles []string, gvk schema.GroupVersionKind) (*engine.PolicyContext, error) {
|
2024-06-20 11:44:43 +02:00
|
|
|
userRequestInfo := kyvernov2.RequestInfo{
|
2022-09-01 16:52:36 +02:00
|
|
|
AdmissionUserInfo: *request.UserInfo.DeepCopy(),
|
2023-04-04 12:23:20 +02:00
|
|
|
Roles: roles,
|
|
|
|
ClusterRoles: clusterRoles,
|
2022-09-01 16:52:36 +02:00
|
|
|
}
|
2023-04-13 13:29:40 +02:00
|
|
|
return engine.NewPolicyContextFromAdmissionRequest(b.jp, request, userRequestInfo, gvk, b.configuration)
|
2022-09-01 16:52:36 +02:00
|
|
|
}
|