Mariam Fahmy
d688af2539
fix: allow cleanup controller to update the policy status ( #8681 )
...
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-18 21:22:42 +08:00
Mariam Fahmy
c5dbb572c2
remove duplicated log messages ( #8673 )
...
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-17 16:08:44 +00:00
Vishal Choudhary
15a8970e23
feat: add support for days in ttl labels ( #8660 )
2023-10-16 13:01:07 +00:00
Mariam Fahmy
e969248483
chore: bump cleanup policies to v2beta1 ( #8621 )
...
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-12 19:45:33 +08:00
Rodrigo Fior Kuntzer
9c64b10cd2
fix: allow dropping metrics, labels and configuring histogram bucket boundaries to avoid high cardinality. ( #8569 )
...
Signed-off-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
Co-authored-by: shuting <shuting@nirmata.com>
2023-10-12 09:50:27 +00:00
shuting
360bcc83ee
Revert "chore: bump cleanup policies to v2beta1 ( #8594 )" ( #8609 )
...
This reverts commit fff3ad047e
.
2023-10-09 15:01:24 +00:00
Mariam Fahmy
fff3ad047e
chore: bump cleanup policies to v2beta1 ( #8594 )
...
* chore: bump cleanup policies to v2beta1
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
* chore: remove the support of v2alpha1 cleanup policies
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
---------
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-09 19:37:15 +08:00
Mariam Fahmy
8cbe66a06a
feat: generate events for CEL policies that generate VAPs ( #8564 )
...
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-09 10:16:35 +00:00
Vishal Choudhary
5882ed32a3
refactor: common remote authenticator for notary and cosign ( #8494 )
...
* refactor: common remote authenticator for notary and cosign
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* fix: add user agent
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* refactor: move getGCRRemoteOption out of BuildGCRRemoteOption
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
---------
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: shuting <shuting@nirmata.com>
2023-10-09 09:07:00 +00:00
Mariam Fahmy
adb789247a
refactor: use GetKind() from the cleanup policy interface ( #8565 )
...
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-09 08:06:32 +00:00
Mariam Fahmy
cd986849d5
fix: use v2beta1 of policy exceptions ( #8587 )
...
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-09 15:27:25 +08:00
AdamKorcz
080a96fed4
Refactor fuzzing utils and add 3 fuzzers ( #8555 )
...
* Refactor fuzzing utils and add 3 fuzzers
Signed-off-by: AdamKorcz <adam@adalogics.com>
* Fix lint issues
Signed-off-by: AdamKorcz <adam@adalogics.com>
* use latest go-jmespath
Signed-off-by: AdamKorcz <adam@adalogics.com>
* Check layer size (#8552 )
* fix excessive logs
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* check fetched layer size
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* check sig layer size
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
---------
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
Signed-off-by: AdamKorcz <adam@adalogics.com>
* fix lint issues
Signed-off-by: AdamKorcz <adam@adalogics.com>
---------
Signed-off-by: AdamKorcz <adam@adalogics.com>
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
Co-authored-by: Jim Bugwadia <jim@nirmata.com>
2023-10-05 16:33:26 +00:00
Jim Bugwadia
2fe07f694e
Check layer size ( #8552 )
...
* fix excessive logs
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* check fetched layer size
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* check sig layer size
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
---------
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
2023-09-28 22:12:13 +05:30
Charles-Edouard Brétéché
482c243517
refactor: remove openapi package ( #8538 )
...
* refactor: openapi package
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* kubectl validate
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* rm
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* fix
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* fix
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* go mod
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* fix vscode
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
---------
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-27 16:21:47 +00:00
Mariam Fahmy
eedc993ed9
fix: apply exceptions after executing the policy itself ( #8544 )
...
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-09-27 14:52:39 +00:00
Mariam Fahmy
538e8958aa
refactor: get the last execution time from the cleanup policy interface ( #8531 )
...
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-09-27 08:55:25 +02:00
Charles-Edouard Brétéché
15630ffaaa
fix: creating ClusterAdmissionReports fails for resources with colon in name ( #8530 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-26 11:44:35 +00:00
Mariam Fahmy
7add300ffa
feat: remove the creation of cronjobs in cleanup controller ( #8526 )
...
* feat: remove the creation of cronjobs in cleanup controller
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
* fix: use lastExecutionTime instead of nextExecutionTime
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
---------
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-09-26 12:02:17 +02:00
Vishal Choudhary
e5c004a6b4
fix: only fetch pub keys when tlogs and scts are not ignored ( #8521 )
2023-09-25 08:16:10 +00:00
Charles-Edouard Brétéché
61aa713d27
fix: image cache panic and cleanup ( #8512 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-22 10:40:16 +00:00
Charles-Edouard Brétéché
6cf57ee81f
fix: make sure we don't modify reports not owned by kyverno ( #8502 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-22 04:01:21 +00:00
Vishal Choudhary
e6bebeae9b
feat: improve assertion and error messages ( #8489 )
2023-09-21 12:39:54 +00:00
Charles-Edouard Brétéché
f38011cd8e
fix: check subjects func ( #8470 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-21 03:22:01 +00:00
Vishal Choudhary
fd01e50280
fix: image verify cache test ( #8462 )
...
* fix: image verify cache test
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: print err message
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: clear mock
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: defer clear mock
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
---------
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-20 14:03:58 +02:00
Charles-Edouard Brétéché
c1978d97a6
fix: use vap map in report aggregation ( #8458 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-20 08:32:38 +00:00
Charles-Edouard Brétéché
2444b7c670
refactor: add per resource reports aggregation ( #8426 )
...
* refactor: add per resource reports aggregation
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* added controller implementation
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* clean
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* fix
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* fix
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* fix
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* fix kuttl tests
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* fix
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* fix kuttl tests
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* vaps
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
---------
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-20 14:51:32 +08:00
Vishal Choudhary
b4861015f0
feat: add check for digest mismatch ( #8443 )
...
* feat: add check for digest mismatch
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: add unit test
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
---------
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-09-20 05:29:20 +00:00
Charles-Edouard Brétéché
fb90d0935d
fix: use go 1.21 new packages ( #8452 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-19 12:06:53 +00:00
Jim Bugwadia
fb12f7330b
skip other checks if operations do not match ( #8324 )
...
* skip other checks if operations do not match
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* copy resource/rule as match seems to mutate for wildcard checks
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* fix deepcopy
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
---------
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-19 08:01:49 +00:00
shuting
ca62b37886
chore: improve log messages ( #8442 )
...
Signed-off-by: ShutingZhao <shuting@nirmata.com>
2023-09-19 08:54:40 +02:00
Vishal Choudhary
828807bddb
feat: add a new wrapper logger for debugging ( #8436 )
...
* feat: add a new debug logger
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* fix: duplicate first messages
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: add checks in info()
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* add debug logger to notary package
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: update info func
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: add error func
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: update wrapper to use right fmt functions
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* fix: use sprintln not sprint
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: remove V(4)
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* refactor: removed common code
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* Update pkg/notary/log.go
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* Update pkg/notary/log.go
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* Update pkg/notary/log.go
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* fix: update names
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* Update pkg/notary/log.go
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: add verbosity levels
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* Update pkg/notary/log.go
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* fix: lint
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: use errors new
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
---------
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-18 19:47:59 +00:00
Vishal Choudhary
b6c959bfac
style: improve descriptions in notary verifier ( #8444 )
...
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
2023-09-18 18:09:48 +00:00
Vishal Choudhary
fec2992e3f
fix: address vulnerability issues in notary implementations ( #8428 )
...
* fix: set max limit on referrers count
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: add limit to max size of payload
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: add max count limit on listsignatures
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: add max signature size limit in FetchSignatureBlob
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
---------
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: shuting <shuting@nirmata.com>
2023-09-18 15:02:31 +08:00
Jim Bugwadia
cef9a7a3d0
fix excessive logs ( #8431 )
...
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
2023-09-18 10:19:06 +05:30
Charles-Edouard Brétéché
fa36f76cf9
refactor: move per namespace reports aggregator in a sub package ( #8419 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-15 08:41:36 +00:00
Charles-Edouard Brétéché
e43b78c6c7
fix: bump golang exp lib ( #8408 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-14 21:46:47 +00:00
Charles-Edouard Brétéché
5181deaf2e
fix: load policies ( #8403 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
Co-authored-by: kyverno-bot <104836976+kyverno-bot@users.noreply.github.com>
2023-09-14 16:54:54 +00:00
Mariam Fahmy
7db8800b87
chore: move policy exceptions to beta ( #8378 )
...
* chore: move policy exceptions to beta
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
* fix kuttl test
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
* fix: keep v2alpha1 as the storage version
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
* fix: avoid using type aliases
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
---------
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-09-14 14:23:51 +00:00
Mariam Fahmy
d3dbd52f75
fix typo ( #8399 )
...
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-09-14 13:52:24 +00:00
Vishal Choudhary
6a62613d5b
feat: add CTLogs verification to cosign ( #8130 )
...
* feat: add TUF and CTlogs to types
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: add tuf init and custom ctlogs to cosign verify
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: update tests with new types
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* fix: reduce description size
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: add ctlogs negative test
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: add validate for ignoresct
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: update codegen files
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: update codegen
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
* feat: remove TUF changes
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
---------
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: shuting <shuting@nirmata.com>
2023-09-14 04:18:44 +00:00
Charles-Edouard Brétéché
37bbf33bd5
fix: CLI test command should validate the policy under test ( #8387 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-14 00:30:23 +00:00
Charles-Edouard Brétéché
c88f8e8638
fix: Testing a generate rule for a custom resource fails ( #8373 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-13 08:45:40 +00:00
Mariam Fahmy
9b0e6b6e9e
fix: ignore generating backgroundscan reports for Kyverno policies in case VAPs are generated ( #8356 )
...
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-09-12 11:08:28 +00:00
Chandan-DK
fc7eb295ef
test: add tests for isAnyNotIn function and lazy evaluate it ( #7972 )
...
* Lazy evaluate isAnyNotIn function
Signed-off-by: Chandan-DK <chandandk468@gmail.com>
* Add unit tests
Signed-off-by: Chandan-DK <chandandk468@gmail.com>
* add empty string test and rephrase a test name
Signed-off-by: Chandan-DK <chandandk468@gmail.com>
---------
Signed-off-by: Chandan-DK <chandandk468@gmail.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: shuting <shuting@nirmata.com>
2023-09-11 16:10:49 +00:00
Charles-Edouard Brétéché
30598c64d8
fix: TODOs in cli ( #8333 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-11 15:24:10 +00:00
Vishal Choudhary
aeabe7048d
feat: update condition in image verify cache tests ( #8318 )
...
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: kyverno-bot <104836976+kyverno-bot@users.noreply.github.com>
Co-authored-by: shuting <shuting@nirmata.com>
2023-09-11 14:22:10 +00:00
Charles-Edouard Brétéché
7a982a4c2c
fix: generate flake ( #8332 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-11 13:04:57 +00:00
Charles-Edouard Brétéché
5beaec677f
fix: cache invalidation in FindResources ( #8316 )
...
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-08 15:51:25 +02:00
Ved Ratan
10dacd5292
fix: use controller utils package in ttl controller ( #8169 )
...
* included controller-util
Signed-off-by: Ved Ratan <vedratan8@gmail.com>
* refactor
Signed-off-by: Ved Ratan <vedratan8@gmail.com>
* updated event handlers
Signed-off-by: Ved Ratan <vedratan8@gmail.com>
* added registration
Signed-off-by: Ved Ratan <vedratan8@gmail.com>
* fix
Signed-off-by: Ved Ratan <vedratan8@gmail.com>
* fix
Signed-off-by: Ved Ratan <vedratan8@gmail.com>
* event handler refactor
Signed-off-by: Ved Ratan <vedratan8@gmail.com>
* lint
Signed-off-by: Ved Ratan <vedratan8@gmail.com>
* enhancements
Signed-off-by: Ved Ratan <vedratan8@gmail.com>
* util refactor
Signed-off-by: Ved Ratan <vedratan8@gmail.com>
* removed comments
Signed-off-by: Ved Ratan <vedratan8@gmail.com>
* fix
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
* fix handler
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
---------
Signed-off-by: Ved Ratan <vedratan8@gmail.com>
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
Co-authored-by: shuting <shuting@nirmata.com>
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-08 09:12:34 +02:00
Mariam Fahmy
00fda95642
fix: add matchConditions and variables when generating VAPs ( #8308 )
...
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-09-07 13:03:36 +00:00