mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-31 03:45:17 +00:00
This commit is contained in:
parent
2344b2c305
commit
6e1be1c901
3 changed files with 30 additions and 11 deletions
|
@ -111,14 +111,12 @@ func main() {
|
||||||
os.Exit(1)
|
os.Exit(1)
|
||||||
}
|
}
|
||||||
|
|
||||||
// ======================= resource cache ====================
|
|
||||||
rCache, err := resourcecache.NewResourceCache(log.Log, clientConfig, client, []string{"configmaps"}, []string{})
|
rCache, err := resourcecache.NewResourceCache(log.Log, clientConfig, client, []string{"configmaps"}, []string{})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
setupLog.Error(err, "Failed to create resource cache")
|
setupLog.Error(err, "ConfigMap lookup disabled: failed to create resource cache")
|
||||||
os.Exit(1)
|
} else {
|
||||||
|
rCache.RunAllInformers(log.Log)
|
||||||
}
|
}
|
||||||
rCache.RunAllInformers(log.Log)
|
|
||||||
// ===========================================================
|
|
||||||
|
|
||||||
// CRD CHECK
|
// CRD CHECK
|
||||||
// - verify if Kyverno CRDs are available
|
// - verify if Kyverno CRDs are available
|
||||||
|
|
|
@ -54,6 +54,7 @@ func applyPolicy(policy kyverno.ClusterPolicy, resource unstructured.Unstructure
|
||||||
//TODO: GENERATION
|
//TODO: GENERATION
|
||||||
return engineResponses
|
return engineResponses
|
||||||
}
|
}
|
||||||
|
|
||||||
func mutation(policy kyverno.ClusterPolicy, resource unstructured.Unstructured, ctx context.EvalInterface, log logr.Logger, resCache resourcecache.ResourceCacheIface, jsonContext *context.Context) (response.EngineResponse, error) {
|
func mutation(policy kyverno.ClusterPolicy, resource unstructured.Unstructured, ctx context.EvalInterface, log logr.Logger, resCache resourcecache.ResourceCacheIface, jsonContext *context.Context) (response.EngineResponse, error) {
|
||||||
|
|
||||||
engineResponse := engine.Mutate(engine.PolicyContext{Policy: policy, NewResource: resource, Context: ctx, ResourceCache: resCache, JSONContext: jsonContext})
|
engineResponse := engine.Mutate(engine.PolicyContext{Policy: policy, NewResource: resource, Context: ctx, ResourceCache: resCache, JSONContext: jsonContext})
|
||||||
|
|
|
@ -1,8 +1,6 @@
|
||||||
package resourcecache
|
package resourcecache
|
||||||
|
|
||||||
import (
|
import (
|
||||||
// "fmt"
|
|
||||||
// "time"
|
|
||||||
"github.com/go-logr/logr"
|
"github.com/go-logr/logr"
|
||||||
dclient "github.com/kyverno/kyverno/pkg/dclient"
|
dclient "github.com/kyverno/kyverno/pkg/dclient"
|
||||||
"k8s.io/apimachinery/pkg/runtime/schema"
|
"k8s.io/apimachinery/pkg/runtime/schema"
|
||||||
|
@ -47,19 +45,40 @@ func NewResourceCache(log logr.Logger, config *rest.Config, dclient *dclient.Cli
|
||||||
|
|
||||||
resCache := &ResourceCache{GVRCacheData: cacheData, dinformer: dInformer, match: match, exclude: exclude}
|
resCache := &ResourceCache{GVRCacheData: cacheData, dinformer: dInformer, match: match, exclude: exclude}
|
||||||
|
|
||||||
err := udateGVRCache(logger, resCache, discoveryIface)
|
if resCache.matchGVRKey("configmaps") {
|
||||||
if err != nil {
|
_, ok := resCache.GVRCacheData["configmaps"]
|
||||||
logger.Error(err, "error in udateGVRCache function")
|
if !ok {
|
||||||
return nil, err
|
updateGVRCacheForConfigMap(resCache)
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
err := udateGVRCache(logger, resCache, discoveryIface)
|
||||||
|
if err != nil {
|
||||||
|
logger.Error(err, "error in udateGVRCache function")
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
return resCache, nil
|
return resCache, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func updateGVRCacheForConfigMap(resc *ResourceCache) {
|
||||||
|
gvrc := &GVRCache{
|
||||||
|
GVR: schema.GroupVersionResource{
|
||||||
|
Version: "v1",
|
||||||
|
Resource: "configmaps",
|
||||||
|
},
|
||||||
|
Namespaced: true,
|
||||||
|
}
|
||||||
|
|
||||||
|
resc.GVRCacheData["configmaps"] = gvrc
|
||||||
|
}
|
||||||
|
|
||||||
func udateGVRCache(log logr.Logger, resc *ResourceCache, discoveryIface discovery.CachedDiscoveryInterface) error {
|
func udateGVRCache(log logr.Logger, resc *ResourceCache, discoveryIface discovery.CachedDiscoveryInterface) error {
|
||||||
serverResources, err := discoveryIface.ServerPreferredResources()
|
serverResources, err := discoveryIface.ServerPreferredResources()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, serverResource := range serverResources {
|
for _, serverResource := range serverResources {
|
||||||
groupVersion := serverResource.GroupVersion
|
groupVersion := serverResource.GroupVersion
|
||||||
for _, resource := range serverResource.APIResources {
|
for _, resource := range serverResource.APIResources {
|
||||||
|
@ -82,5 +101,6 @@ func udateGVRCache(log logr.Logger, resc *ResourceCache, discoveryIface discover
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
Loading…
Add table
Reference in a new issue