webhook

package
v0.0.0-...-844b0b5 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 29, 2026 License: AGPL-3.0 Imports: 49 Imported by: 0

Documentation

Index

Constants

View Source
const MacvlanInitContainerName = "macvlan-reply-via-eth0"

MacvlanInitContainerName is the name of the init container injected for pods that need to reply via eth0 in macvlan setups.

Variables

View Source
var (

	// Deserializer is used to decode the admission request body.
	Deserializer = codecs.UniversalDeserializer()

	// UUIDAnnotation uuid key for annotation.
	UUIDAnnotation = "sidecar.bytetrade.io/proxy-uuid"
)

Functions

func CreateCleanupPatchForDeployment

func CreateCleanupPatchForDeployment(tpl *corev1.PodTemplateSpec) ([]byte, error)

CreateCleanupPatchForDeployment scans the workload template for any GPU-related fields that may have been added by a previous run of the gpu-limit mutating webhook (nvidia.com/gpu, nvidia.com/gpumem, amd.com/gpu, amd.com/apu in both resources.limits and resources.requests, plus runtimeClassName="nvidia") and returns an RFC 6902 JSON Patch that removes them. Returns nil when nothing needs to be cleaned up.

This is the counterpart of addGpuResourceLimits: when an app no longer needs GPU (e.g., its OlaresManifest dropped requiredGpu on upgrade), the inject path used to early-return without emitting any patch. Helm upgrade then preserves the previously-injected GPU keys as "live-only" fields via strategic merge, leaving stale resources on the pod. By emitting explicit remove ops the desired object that K8s sees no longer carries the GPU keys, so 3-way merge can drop them.

func CreatePatchForDeployment

func CreatePatchForDeployment(tpl *corev1.PodTemplateSpec, injectAll bool, injectContainer []string, gpuTypeKey string, gpumem *string, envKeyValues []EnvKeyValue) ([]byte, error)

CreatePatchForDeployment add gpu env for deployment and returns patch bytes.

func FormatWaitSummary

func FormatWaitSummary(namespace, service, podIP string, port int32) string

FormatWaitSummary is used by tests.

func GetAppConfigForNamespace

func GetAppConfigForNamespace(ctx context.Context, appClient versioned.Interface, kubeClient kubernetes.Interface, namespace string) (
	appMgr *v1alpha1.ApplicationManager, appConfig *appcfg.ApplicationConfig, isShared, isSharedApp bool, err error)

GetAppConfigForNamespace resolves the application that owns namespace, returning api.ErrApplicationManagerNotFound when the namespace belongs to no application.

Both reads go straight to the API server rather than through an informer cache. Admission decides what a pod becomes at the moment it is created, and an app's pods can follow its ApplicationManager or its namespace labels by milliseconds; reading a stale cache would silently treat a just-installed app as belonging to nothing.

It is a package-level function taking the clients explicitly so callers that hold clients but not a *Webhook -- notably the runasuser admission path -- resolve namespaces through this exact logic instead of a parallel reimplementation that would drift. The parameters are the client interfaces rather than the concrete clientsets so tests can inject the generated fakes.

func GetMacvlanInitContainer

func GetMacvlanInitContainer() corev1.Container

GetMacvlanInitContainer returns the init container spec used to set up a dedicated routing table so that reply traffic flows back via eth0 for pods participating in a macvlan / overlay-gateway setup.

func ParseServiceEndpointWaitConfig

func ParseServiceEndpointWaitConfig() (timeout, interval time.Duration)

ParseServiceEndpointWaitConfig reads timeout/interval envs with defaults.

func ResolvePodIP

func ResolvePodIP() string

ResolvePodIP returns POD_IP from the environment (Downward API).

func WaitForServiceEndpointReady

func WaitForServiceEndpointReady(
	ctx context.Context,
	kubeClient kubernetes.Interface,
	namespace, serviceName, podIP string,
	port int32,
	timeout, interval time.Duration,
) error

WaitForServiceEndpointReady polls EndpointSlices until podIP appears as a ready address for the given service port, or until timeout. On timeout it returns nil after logging so callers can still start controllers (Parts 2/3 provide safety nets).

Types

type EnvKeyValue

type EnvKeyValue struct {
	Key   string
	Value string
}

type Webhook

type Webhook struct {
	// contains filtered or unexported fields
}

Webhook used to implement a webhook.

func New

func New(config *rest.Config) (*Webhook, error)

New create a webhook client.

func (*Webhook) AdmissionError

func (wh *Webhook) AdmissionError(uid types.UID, err error) *admissionv1.AdmissionResponse

AdmissionError wraps error as AdmissionResponse

func (*Webhook) CreateMacvlanInitPatch

func (wh *Webhook) CreateMacvlanInitPatch(req *admissionv1.AdmissionRequest, pod *corev1.Pod) ([]byte, error)

CreateMacvlanInitPatch appends the macvlan init container to the pod's init containers (idempotent — does nothing if the container is already present) and returns the JSON merge patch to send back in the admission response.

func (*Webhook) CreateOrUpdateAppLabelMutatingWebhook

func (wh *Webhook) CreateOrUpdateAppLabelMutatingWebhook() error

CreateOrUpdateAppLabelMutatingWebhook creates or updates app mutating webhook.

func (*Webhook) CreateOrUpdateAppNamespaceValidatingWebhook

func (wh *Webhook) CreateOrUpdateAppNamespaceValidatingWebhook() error

CreateOrUpdateAppNamespaceValidatingWebhook creates or updates app namespace validating webhook.

func (*Webhook) CreateOrUpdateApplicationManagerValidatingWebhook

func (wh *Webhook) CreateOrUpdateApplicationManagerValidatingWebhook() error

CreateOrUpdateApplicationManagerValidatingWebhook creates or updates the ApplicationManager validating webhook.

func (*Webhook) CreateOrUpdateArgoResourceValidatingWebhook

func (wh *Webhook) CreateOrUpdateArgoResourceValidatingWebhook() error

CreateOrUpdateArgoResourceValidatingWebhook creates or updates the argo resource validating webhook.

func (*Webhook) CreateOrUpdateCliCredentialMutatingWebhook

func (wh *Webhook) CreateOrUpdateCliCredentialMutatingWebhook() error

CreateOrUpdateCliCredentialMutatingWebhook registers the admission webhook that mounts the olares-cli credential Secret into pods of apps that declared permission.loginOlaresCLI. It is a separate configuration from run-as-user so the two mutations can fail and be versioned independently.

func (*Webhook) CreateOrUpdateCronWorkflowMutatingWebhook

func (wh *Webhook) CreateOrUpdateCronWorkflowMutatingWebhook() error

func (*Webhook) CreateOrUpdateGpuLimitMutatingWebhook

func (wh *Webhook) CreateOrUpdateGpuLimitMutatingWebhook() error

CreateOrUpdateGpuLimitMutatingWebhook creates or updates gpu limit mutating webhook.

func (*Webhook) CreateOrUpdateMacvlanInitMutatingWebhook

func (wh *Webhook) CreateOrUpdateMacvlanInitMutatingWebhook() error

CreateOrUpdateMacvlanInitMutatingWebhook creates or updates the macvlan init container mutating webhook. It only fires for pods labeled applications.app.bytetrade.io/macvlan-init=true on Create. FailurePolicy is Ignore so that a transient webhook outage never blocks pod creation, because the macvlan-init container is an additive networking concern.

func (*Webhook) CreateOrUpdatePodArchNodeSelectorMutatingWebhook

func (wh *Webhook) CreateOrUpdatePodArchNodeSelectorMutatingWebhook() error

CreateOrUpdatePodArchNodeSelectorMutatingWebhook creates or updates the pod architecture nodeSelector mutating webhook. It fires for pods on Create and, when the owning app's OlaresManifest declares exactly one spec.supportArch, injects a kubernetes.io/arch nodeSelector so the pod lands on a matching node. FailurePolicy is Ignore so a transient webhook outage never blocks pod creation, because the arch nodeSelector is an additive scheduling hint.

func (*Webhook) CreateOrUpdateProviderRegistryValidatingWebhook

func (wh *Webhook) CreateOrUpdateProviderRegistryValidatingWebhook() error

func (*Webhook) CreateOrUpdateRunAsUserMutatingWebhook

func (wh *Webhook) CreateOrUpdateRunAsUserMutatingWebhook() error

CreateOrUpdateRunAsUserMutatingWebhook creates or updates gpu limit mutating webhook.

func (*Webhook) CreateOrUpdateSandboxMutatingWebhook

func (wh *Webhook) CreateOrUpdateSandboxMutatingWebhook() error

CreateOrUpdateSandboxMutatingWebhook creates or updates the sandbox mutating webhook.

func (*Webhook) CreateOrUpdateTLSReplicaMountValidatingWebhook

func (wh *Webhook) CreateOrUpdateTLSReplicaMountValidatingWebhook() error

CreateOrUpdateTLSReplicaMountValidatingWebhook creates or updates the WI-T1-8 validating webhook that blocks cross-tenant tls-replica private-key bypass mounts. It is scoped to opted-in caller namespaces via namespaceSelector and uses failurePolicy=Fail so a webhook outage fail-closes admission (private-key red line over availability) without affecting non-caller namespaces.

func (*Webhook) CreateOrUpdateUserValidatingWebhook

func (wh *Webhook) CreateOrUpdateUserValidatingWebhook() error

CreateOrUpdateUserValidatingWebhook creates or updates user validating webhook.

func (*Webhook) CreatePatch

func (wh *Webhook) CreatePatch(
	ctx context.Context,
	pod *corev1.Pod,
	req *admissionv1.AdmissionRequest,
	proxyUUID uuid.UUID, injectPolicy, injectMeshInAgent, injectMeshOutAgent bool,
	injectSharedPod *bool,
	appmgr *v1alpha1.ApplicationManager,
	appConfig *appcfg.ApplicationConfig,
	perms []appcfg.ProviderPermission,
) ([]byte, error)

CreatePatch create a patch for a pod.

func (*Webhook) DeleteAppManagerMutatingWebhook

func (wh *Webhook) DeleteAppManagerMutatingWebhook() error

func (*Webhook) DeleteKubeletEvictionValidatingWebhook

func (wh *Webhook) DeleteKubeletEvictionValidatingWebhook() error

func (*Webhook) GetAdmissionRequestBody

func (wh *Webhook) GetAdmissionRequestBody(req *restful.Request, resp *restful.Response) ([]byte, bool)

GetAdmissionRequestBody returns admission request body.

func (*Webhook) GetAppConfig

func (wh *Webhook) GetAppConfig(namespace string) (appMgr *v1alpha1.ApplicationManager, appConfig *appcfg.ApplicationConfig, isShared, isSharedApp bool, err error)

GetAppConfig get app config by namespace.

func (*Webhook) MustInject

func (wh *Webhook) MustInject(ctx context.Context, pod *corev1.Pod, namespace string) (
	injectPolicy, injectMeshInAgent, injectMeshOutAgent bool, injectSharedPod *bool, perms []appcfg.ProviderPermission,
	appConfig *appcfg.ApplicationConfig, appMgr *v1alpha1.ApplicationManager, err error)

MustInject checks which inject operation should do for a pod.

func (*Webhook) PatchAdmissionResponse

func (wh *Webhook) PatchAdmissionResponse(resp *admissionv1.AdmissionResponse, patchBytes []byte)

PatchAdmissionResponse returns an admission response with patch data.

func (*Webhook) PatchLinkerdAdminProbesOnly

func (wh *Webhook) PatchLinkerdAdminProbesOnly(
	ctx context.Context,
	req *admissionv1.AdmissionRequest,
	pod *corev1.Pod,
) (patchBytes []byte, patched bool, err error)

PatchLinkerdAdminProbesOnly hardens linkerd-proxy admin probes when no other sidecar work is required. Returns patched=false when nothing changed.

func (*Webhook) ShouldInjectMacvlanInit

func (wh *Webhook) ShouldInjectMacvlanInit(ctx context.Context, pod *corev1.Pod, ns string) (bool, error)

ShouldInjectMacvlanInit reports whether the macvlan init container should be injected for the given pod. It returns true only when the owning Application can be resolved from the pod's app name/owner labels and has `spec.settings.enableOverlayGateway == "true"`.

func (*Webhook) ValidateTLSReplicaMount

func (wh *Webhook) ValidateTLSReplicaMount(ctx context.Context, pod *corev1.Pod, namespace string) (bool, string)

ValidateTLSReplicaMount enforces that any volume referencing a tls-replica private-key Secret is mounted only by the platform-injected d2 sidecar.

requirement: WI-T1-8 §2.2 — a tls-replica=true Secret may be consumed only by the olares-d2-sidecar container via the olares-d2-certs volume; any reference by another container (raw secret or projected source) is a cross-tenant private-key bypass and is denied.

behavior: fail-closed — a Secret label lookup API error denies admission (private-key red line over availability). Pods with no tls-replica volume take an allow fast path. Returns (allowed, errorCode); errorCode is empty on allow.

Directories

Path Synopsis
Package clicredential mounts the Olares credential that app-service provisions for apps declaring permission.loginOlaresCLI, so that olares-cli running inside the container starts out logged in as the app's owner.
Package clicredential mounts the Olares credential that app-service provisions for apps declaring permission.loginOlaresCLI, so that olares-cli running inside the container starts out logged in as the app's owner.
Package userspaceprep computes what the platform-injected olares-prepare-userspace init container has to do for a given pod.
Package userspaceprep computes what the platform-injected olares-prepare-userspace init container has to do for a given pod.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL