Shuting Zhao
|
472fa29fce
|
move mutation to subpackage pkg/engine/mutate
|
2020-01-07 17:06:17 -08:00 |
|
Shivkumar Dudhani
|
3cf9141f4d
|
593 feature (#594)
* initial commit
* background policy validation
* correct message
* skip non-background policy process for add/update
* add Generate Request CR
* generate Request Generator Initial
* test generate request CR generation
* initial commit gr generator
* generate controller initial framework
* add crd for generate request
* gr cleanup controller initial commit
* cleanup controller initial
* generate mid-commit
* generate rule processing
* create PV on generate error
* embed resource type
* testing phase 1- generate resources with variable substitution
* fix tests
* comment broken test #586
* add printer column for state
* return if existing resource for clone
* set resync time to 2 mins & remove resource version check in update handler for gr
* generate events for reporting
* fix logs
* initial commit
* fix trailing quote in patch
* remove comments
* initial condition (equal & notequal)
* initial support for conditions
* initial support fo conditions in generate
* support precondition checks
* cleanup
* re-evaluate GR on namespace update using dynamic informers
* add status for generated resources
* display loaded variable SA
* support delete cleanup of generate request main resources
* fix log
* remove namespace from SA username
* support multiple variables per statement for scalar values
* fix fail variables
* add check for userInfo
* validation checks for conditions
* update policy
* refactor logs
* code review
* add openapispec for clusterpolicy preconditions
* Update documentation
* CR fixes
* documentation
* CR fixes
* update variable
* fix logs
* update policy
* pre-defined variables (serviceAccountName & serviceAccountNamespace)
* update test
|
2020-01-07 15:13:57 -08:00 |
|
Shuting Zhao
|
08491df046
|
Merge commit 'ffd2179b0332738a088b362e94147a981f0d02ed' into 600_bug
# Conflicts:
# pkg/webhooks/mutation.go
|
2020-01-07 14:17:25 -08:00 |
|
Shuting Zhao
|
259c8839e5
|
remove duplicate import pkg
|
2020-01-07 11:33:18 -08:00 |
|
Shuting Zhao
|
cafc3883a4
|
- fix validation to process on patched resource; - format code
|
2020-01-07 11:32:52 -08:00 |
|
Shivkumar Dudhani
|
ffd2179b03
|
538 (#587)
* initial commit
* background policy validation
* correct message
* skip non-background policy process for add/update
* add Generate Request CR
* generate Request Generator Initial
* test generate request CR generation
* initial commit gr generator
* generate controller initial framework
* add crd for generate request
* gr cleanup controller initial commit
* cleanup controller initial
* generate mid-commit
* generate rule processing
* create PV on generate error
* embed resource type
* testing phase 1- generate resources with variable substitution
* fix tests
* comment broken test #586
* add printer column for state
* return if existing resource for clone
* set resync time to 2 mins & remove resource version check in update handler for gr
* generate events for reporting
* fix logs
* cleanup
* CR fixes
* fix logs
|
2020-01-07 10:33:28 -08:00 |
|
Shuting Zhao
|
c97b3ce5b0
|
fetch annotation from resource annotation map
|
2020-01-06 19:24:24 -08:00 |
|
Shuting Zhao
|
dcc3179b09
|
remove dclient from pvbuilder
|
2020-01-06 18:53:36 -08:00 |
|
Shuting Zhao
|
ecbbd04bc5
|
- remove policy violation created on owner and related logic; - use generic call to create violation info
|
2020-01-06 17:07:11 -08:00 |
|
shivkumar dudhani
|
38dcb2e94f
|
flag to use FQDN as CommonName in CSR
|
2020-01-06 16:12:53 -08:00 |
|
Shuting Zhao
|
9194251a38
|
fix pod controller annotation to "none"
|
2020-01-06 14:41:25 -08:00 |
|
Shuting Zhao
|
77955ff212
|
change the policy action to operate on it's own validationFailureAction
|
2020-01-06 14:41:02 -08:00 |
|
Shuting Zhao
|
f5411c1c76
|
update policymutation_test
|
2020-01-03 15:19:33 -08:00 |
|
Shuting Zhao
|
dce1e0555a
|
move helper to pkg/utils
|
2020-01-03 10:41:47 -08:00 |
|
Shuting Zhao
|
0c9053d50d
|
register resource webhook in policy control loop
|
2020-01-02 20:25:30 -08:00 |
|
Shuting Zhao
|
956cb0559a
|
- register resource webhook when policy controller starts; - add debug log
|
2020-01-02 19:12:45 -08:00 |
|
Shuting Zhao
|
b5192dc559
|
remove old crd namespacedpolicyviolation
|
2020-01-02 15:33:57 -08:00 |
|
Shuting Zhao
|
b493600754
|
remove omitemptu on pocliy.spec and policy.spec.rules
|
2020-01-02 12:17:47 -08:00 |
|
Shuting Zhao
|
d36934fe11
|
Merge commit '5b8ab3842b43a72cc675b93b8b72e290adfca1d2' into 518_pod_controller
# Conflicts:
# pkg/api/kyverno/v1/types.go
# pkg/engine/mutation.go
# pkg/engine/mutation_test.go
# pkg/engine/validation.go
# pkg/policy/existing.go
|
2020-01-02 10:32:17 -08:00 |
|
Shivkumar Dudhani
|
5b8ab3842b
|
Support variable substitution (#549)
* initial commit
* variable substitution
* update tests
* update test
* refactor engine packages for validate & generate
* update vendor
* update toml
* support variable substitution in overlay mutation
* missing update
* fix indentation in logs
* store context values as single JSON document using merge patches.
* remove duplicate functions
* fix message string
* Handle processing of policies in background (#569)
* remove condition check while generating mutation patch as conditions are verified in the first iteration
* initial commit
* background policy validation
* correct message
* skip non-background policy process for add/update
* fix order to correct policy registration
* update comment
Co-authored-by: shuting <shutting06@gmail.com>
* refactor
Co-authored-by: shuting <shutting06@gmail.com>
|
2019-12-30 17:08:50 -08:00 |
|
Shuting Zhao
|
56c03f712a
|
only generate rule on policy creation
|
2019-12-27 15:57:43 -08:00 |
|
Shuting Zhao
|
bae2865550
|
- add =() to volumes; - update error msg
|
2019-12-27 14:59:12 -08:00 |
|
Shuting Zhao
|
340dee24bc
|
Merge branch 'master' into 544_documentation
# Conflicts:
# pkg/engine/overlay_test.go
|
2019-12-27 13:04:07 -08:00 |
|
Shuting Zhao
|
f2a0f0e3dc
|
replace annotation match by regexp
|
2019-12-27 12:57:06 -08:00 |
|
Shuting Zhao
|
eb6ab9d2d8
|
fix rule mis-application
|
2019-12-26 19:05:12 -08:00 |
|
Shuting Zhao
|
076196688e
|
skip process existing pod if annotation present
|
2019-12-26 18:41:14 -08:00 |
|
Shuting Zhao
|
f0d943e970
|
Merge branch 'master' into 518_pod_controller
|
2019-12-26 15:35:23 -08:00 |
|
Shuting Zhao
|
54ecb7738a
|
- insert annotation to podTemplate; - skip apply rule on pod if annotation exists
|
2019-12-26 15:34:19 -08:00 |
|
Shivkumar Dudhani
|
085856baa1
|
add event source and format event messages (#565)
|
2019-12-26 11:50:41 -08:00 |
|
Shuting Zhao
|
b5255893e3
|
update autogen annotation for pod controllers
|
2019-12-26 10:09:49 -08:00 |
|
Shuting Zhao
|
a8aa83573b
|
fix merge error
|
2019-12-20 19:08:26 -08:00 |
|
Shuting Zhao
|
1f0187e8ea
|
Merge commit 'f1330ede8234eb4d449eb9ec72b41c627488350d' into 518_pod_controller
|
2019-12-20 19:06:35 -08:00 |
|
Shuting Zhao
|
8be4db3de3
|
Merge branch '529_query' into 518_pod_controller
|
2019-12-20 18:55:08 -08:00 |
|
Shuting Zhao
|
cc87ea7339
|
add unit test
|
2019-12-20 18:53:44 -08:00 |
|
Shuting Zhao
|
74b85d8143
|
generate rule for pod controllers
|
2019-12-20 18:53:29 -08:00 |
|
Shuting Zhao
|
e3a8cabe8d
|
add omitempty to types
|
2019-12-20 18:51:07 -08:00 |
|
shivkumar dudhani
|
d04f49b5d8
|
fix message string
|
2019-12-17 17:16:50 -08:00 |
|
shivkumar dudhani
|
2a56a8e043
|
remove duplicate functions
|
2019-12-17 16:37:52 -08:00 |
|
shivkumar dudhani
|
a86aa06e28
|
Merge branch 'master' into 529_query
|
2019-12-17 16:36:58 -08:00 |
|
shivkumar dudhani
|
615f1ae940
|
Merge branch 'master' into 529_query
|
2019-12-17 16:22:00 -08:00 |
|
shivkumar dudhani
|
38987d50c3
|
store context values as single JSON document using merge patches.
|
2019-12-17 16:06:13 -08:00 |
|
Shuting Zhao
|
0d71e4a669
|
remove condition check while generating mutation patch as conditions are verified in the first iteration
|
2019-12-16 18:26:38 -08:00 |
|
shuting
|
4149d706e8
|
Merge pull request #558 from nirmata/428_quantity
implement quantity comparison
|
2019-12-16 15:53:09 -08:00 |
|
Shivkumar Dudhani
|
39e08aa1fc
|
76 cache invalidate (#557)
* invalidate local cache of registererd resources
* update client in initContainer
* update message
|
2019-12-16 12:55:44 -08:00 |
|
Shuting Zhao
|
35adbbe0df
|
convert type boolean to string in /metadata/annotation
|
2019-12-13 18:04:19 -08:00 |
|
Shuting Zhao
|
5ced2409a3
|
update test
|
2019-12-13 13:30:24 -08:00 |
|
Shuting Zhao
|
0969aa9bf9
|
implement quantity comparison
|
2019-12-13 13:17:22 -08:00 |
|
shivkumar dudhani
|
793d878b18
|
correct webhook endpoint
|
2019-12-13 11:13:58 -08:00 |
|
shivkumar dudhani
|
c4da72ad3e
|
fix indentation in logs
|
2019-12-13 09:49:09 -08:00 |
|
Shuting Zhao
|
625e45c847
|
remove duplicate code
|
2019-12-12 18:55:40 -08:00 |
|