mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-05 15:37:19 +00:00
This PR refactors the reports generation code. It removes RCR and CRCR crds and replaces them with AdmissionReport, ClusterAdmissionReport, BackgroundScanReport and ClusterBackgroundScanReport crds. The new reports system is based on 4 controllers: Admission reports controller is responsible for cleaning up admission reports and attaching admission reports to their corresponding resource in case of a creation Background scan reports controller is responsible for creating background scan reports when a resource and/or policy changes Aggregation controller takes care of aggregation per resource reports into higher level reports (per namespace) Resources controller is responsible for watching reports that need background scan reports I added two new flags to disable admission reports and/or background scan reports, the whole reporting system can be disabled if something goes wrong. I also added a flag to split reports in chunks to avoid creating too large resources. Signed-off-by: Charles-Edouard Brétéché <charled.breteche@gmail.com> Signed-off-by: prateekpandey14 <prateek.pandey@nirmata.com> Signed-off-by: Charles-Edouard Brétéché <charled.breteche@gmail.com> Signed-off-by: prateekpandey14 <prateek.pandey@nirmata.com> Co-authored-by: prateekpandey14 <prateek.pandey@nirmata.com>
44 lines
1.4 KiB
Go
44 lines
1.4 KiB
Go
package report
|
|
|
|
import (
|
|
kyvernov1 "github.com/kyverno/kyverno/api/kyverno/v1"
|
|
"k8s.io/apimachinery/pkg/labels"
|
|
"k8s.io/apimachinery/pkg/selection"
|
|
"k8s.io/apimachinery/pkg/types"
|
|
)
|
|
|
|
func SelectorResourceUidEquals(uid types.UID) (labels.Selector, error) {
|
|
selector := labels.Everything()
|
|
requirement, err := labels.NewRequirement(LabelResourceUid, selection.Equals, []string{string(uid)})
|
|
if err == nil {
|
|
selector = selector.Add(*requirement)
|
|
}
|
|
return selector, err
|
|
}
|
|
|
|
func SelectorPolicyDoesNotExist(policy kyvernov1.PolicyInterface) (labels.Selector, error) {
|
|
selector := labels.Everything()
|
|
requirement, err := labels.NewRequirement(PolicyLabel(policy), selection.DoesNotExist, nil)
|
|
if err == nil {
|
|
selector = selector.Add(*requirement)
|
|
}
|
|
return selector, err
|
|
}
|
|
|
|
func SelectorPolicyExists(policy kyvernov1.PolicyInterface) (labels.Selector, error) {
|
|
selector := labels.Everything()
|
|
requirement, err := labels.NewRequirement(PolicyLabel(policy), selection.Exists, nil)
|
|
if err == nil {
|
|
selector = selector.Add(*requirement)
|
|
}
|
|
return selector, err
|
|
}
|
|
|
|
func SelectorPolicyNotEquals(policy kyvernov1.PolicyInterface) (labels.Selector, error) {
|
|
selector := labels.Everything()
|
|
requirement, err := labels.NewRequirement(PolicyLabel(policy), selection.NotEquals, []string{policy.GetResourceVersion()})
|
|
if err == nil {
|
|
selector = selector.Add(*requirement)
|
|
}
|
|
return selector, err
|
|
}
|