-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathvalidate.go
102 lines (86 loc) · 2.68 KB
/
validate.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
package main
import (
"context"
"encoding/json"
"fmt"
"log"
"strings"
kyvernov1 "github.com/kyverno/kyverno/api/kyverno/v1"
"github.com/kyverno/kyverno/pkg/config"
"github.com/kyverno/kyverno/pkg/engine"
enginecontext "github.com/kyverno/kyverno/pkg/engine/context"
"github.com/kyverno/kyverno/pkg/engine/factories"
"github.com/kyverno/kyverno/pkg/engine/jmespath"
admissionutils "github.com/kyverno/kyverno/pkg/utils/admission"
admissionv1 "k8s.io/api/admission/v1"
"k8s.io/apimachinery/pkg/util/yaml"
)
func validate(input []byte) []byte {
var validationRequest ValidationRequest
var response ValidationResponse
err := json.Unmarshal(input, &validationRequest)
if err != nil {
response = RejectRequest(
Message(fmt.Sprintf("Error deserializing validation request: %v", err)),
Code(400))
} else {
response = validateAdmissionReview(validationRequest.Settings, validationRequest.Request)
}
responseBytes, err := json.Marshal(&response)
if err != nil {
log.Fatalf("cannot marshal validation response: %v", err)
}
return responseBytes
}
func validateAdmissionReview(policySettings CliPolicySettings, request admissionv1.AdmissionRequest) ValidationResponse {
policyBytes, err := yaml.ToJSON([]byte(policySettings.Policy))
if err != nil {
return RejectRequest(
Message(fmt.Sprintf("failed to convert policy to JSON: %v", err)),
Code(400))
}
policy := &kyvernov1.ClusterPolicy{}
err = json.Unmarshal(policyBytes, &policy)
if err != nil {
return RejectRequest(
Message(fmt.Sprintf("cannot unmarshal policy: %v", err)),
Code(400))
}
cfg := config.NewDefaultConfiguration(false)
jp := jmespath.New(cfg)
// TODO: handle userInfo
engineContext := enginecontext.NewContext(jp)
if err = engineContext.AddRequest(request); err != nil {
return RejectRequest(
Message(fmt.Sprintf("engine context: cannot add request %v", err)),
Code(500))
}
e := engine.NewEngine(
cfg,
config.NewDefaultMetricsConfiguration(),
jp,
nil,
nil,
factories.DefaultContextLoaderFactory(nil),
nil,
)
newR, oldR, err := admissionutils.ExtractResources(nil, request)
if err != nil {
return RejectRequest(
Message(fmt.Sprintf("cannot extract resources %v", err)),
Code(500))
}
policyContext := engine.NewPolicyContextWithJsonContext(kyvernov1.Create, engineContext).
WithPolicy(policy).
WithNewResource(newR).
WithOldResource(oldR)
er := e.Validate(context.Background(), policyContext)
errorMsgs := []string{}
for index, r := range er.PolicyResponse.Rules {
errorMsgs = append(errorMsgs, fmt.Sprintf("[%d] - %s", index, r.Message()))
}
if er.IsSuccessful() {
return AcceptRequest()
}
return RejectRequest(Message(strings.Join(errorMsgs, ",")), NoCode)
}