Documentation
¶
Index ¶
- Constants
- Variables
- func CreateCleanupPatchForDeployment(tpl *corev1.PodTemplateSpec) ([]byte, error)
- func CreatePatchForDeployment(tpl *corev1.PodTemplateSpec, injectAll bool, injectContainer []string, ...) ([]byte, error)
- func FormatWaitSummary(namespace, service, podIP string, port int32) string
- func GetAppConfigForNamespace(ctx context.Context, appClient versioned.Interface, ...) (appMgr *v1alpha1.ApplicationManager, appConfig *appcfg.ApplicationConfig, ...)
- func GetMacvlanInitContainer() corev1.Container
- func ParseServiceEndpointWaitConfig() (timeout, interval time.Duration)
- func ResolvePodIP() string
- func WaitForServiceEndpointReady(ctx context.Context, kubeClient kubernetes.Interface, ...) error
- type EnvKeyValue
- type Webhook
- func (wh *Webhook) AdmissionError(uid types.UID, err error) *admissionv1.AdmissionResponse
- func (wh *Webhook) CreateMacvlanInitPatch(req *admissionv1.AdmissionRequest, pod *corev1.Pod) ([]byte, error)
- func (wh *Webhook) CreateOrUpdateAppLabelMutatingWebhook() error
- func (wh *Webhook) CreateOrUpdateAppNamespaceValidatingWebhook() error
- func (wh *Webhook) CreateOrUpdateApplicationManagerValidatingWebhook() error
- func (wh *Webhook) CreateOrUpdateArgoResourceValidatingWebhook() error
- func (wh *Webhook) CreateOrUpdateCliCredentialMutatingWebhook() error
- func (wh *Webhook) CreateOrUpdateCronWorkflowMutatingWebhook() error
- func (wh *Webhook) CreateOrUpdateGpuLimitMutatingWebhook() error
- func (wh *Webhook) CreateOrUpdateMacvlanInitMutatingWebhook() error
- func (wh *Webhook) CreateOrUpdatePodArchNodeSelectorMutatingWebhook() error
- func (wh *Webhook) CreateOrUpdateProviderRegistryValidatingWebhook() error
- func (wh *Webhook) CreateOrUpdateRunAsUserMutatingWebhook() error
- func (wh *Webhook) CreateOrUpdateSandboxMutatingWebhook() error
- func (wh *Webhook) CreateOrUpdateTLSReplicaMountValidatingWebhook() error
- func (wh *Webhook) CreateOrUpdateUserValidatingWebhook() error
- func (wh *Webhook) CreatePatch(ctx context.Context, pod *corev1.Pod, req *admissionv1.AdmissionRequest, ...) ([]byte, error)
- func (wh *Webhook) DeleteAppManagerMutatingWebhook() error
- func (wh *Webhook) DeleteKubeletEvictionValidatingWebhook() error
- func (wh *Webhook) GetAdmissionRequestBody(req *restful.Request, resp *restful.Response) ([]byte, bool)
- func (wh *Webhook) GetAppConfig(namespace string) (appMgr *v1alpha1.ApplicationManager, appConfig *appcfg.ApplicationConfig, ...)
- func (wh *Webhook) MustInject(ctx context.Context, pod *corev1.Pod, namespace string) (injectPolicy, injectMeshInAgent, injectMeshOutAgent bool, ...)
- func (wh *Webhook) PatchAdmissionResponse(resp *admissionv1.AdmissionResponse, patchBytes []byte)
- func (wh *Webhook) PatchLinkerdAdminProbesOnly(ctx context.Context, req *admissionv1.AdmissionRequest, pod *corev1.Pod) (patchBytes []byte, patched bool, err error)
- func (wh *Webhook) ShouldInjectMacvlanInit(ctx context.Context, pod *corev1.Pod, ns string) (bool, error)
- func (wh *Webhook) ValidateTLSReplicaMount(ctx context.Context, pod *corev1.Pod, namespace string) (bool, string)
Constants ¶
const MacvlanInitContainerName = "macvlan-reply-via-eth0"
MacvlanInitContainerName is the name of the init container injected for pods that need to reply via eth0 in macvlan setups.
Variables ¶
var ( // Deserializer is used to decode the admission request body. Deserializer = codecs.UniversalDeserializer() // UUIDAnnotation uuid key for annotation. UUIDAnnotation = "sidecar.bytetrade.io/proxy-uuid" )
Functions ¶
func CreateCleanupPatchForDeployment ¶
func CreateCleanupPatchForDeployment(tpl *corev1.PodTemplateSpec) ([]byte, error)
CreateCleanupPatchForDeployment scans the workload template for any GPU-related fields that may have been added by a previous run of the gpu-limit mutating webhook (nvidia.com/gpu, nvidia.com/gpumem, amd.com/gpu, amd.com/apu in both resources.limits and resources.requests, plus runtimeClassName="nvidia") and returns an RFC 6902 JSON Patch that removes them. Returns nil when nothing needs to be cleaned up.
This is the counterpart of addGpuResourceLimits: when an app no longer needs GPU (e.g., its OlaresManifest dropped requiredGpu on upgrade), the inject path used to early-return without emitting any patch. Helm upgrade then preserves the previously-injected GPU keys as "live-only" fields via strategic merge, leaving stale resources on the pod. By emitting explicit remove ops the desired object that K8s sees no longer carries the GPU keys, so 3-way merge can drop them.
func CreatePatchForDeployment ¶
func CreatePatchForDeployment(tpl *corev1.PodTemplateSpec, injectAll bool, injectContainer []string, gpuTypeKey string, gpumem *string, envKeyValues []EnvKeyValue) ([]byte, error)
CreatePatchForDeployment add gpu env for deployment and returns patch bytes.
func FormatWaitSummary ¶
FormatWaitSummary is used by tests.
func GetAppConfigForNamespace ¶
func GetAppConfigForNamespace(ctx context.Context, appClient versioned.Interface, kubeClient kubernetes.Interface, namespace string) ( appMgr *v1alpha1.ApplicationManager, appConfig *appcfg.ApplicationConfig, isShared, isSharedApp bool, err error)
GetAppConfigForNamespace resolves the application that owns namespace, returning api.ErrApplicationManagerNotFound when the namespace belongs to no application.
Both reads go straight to the API server rather than through an informer cache. Admission decides what a pod becomes at the moment it is created, and an app's pods can follow its ApplicationManager or its namespace labels by milliseconds; reading a stale cache would silently treat a just-installed app as belonging to nothing.
It is a package-level function taking the clients explicitly so callers that hold clients but not a *Webhook -- notably the runasuser admission path -- resolve namespaces through this exact logic instead of a parallel reimplementation that would drift. The parameters are the client interfaces rather than the concrete clientsets so tests can inject the generated fakes.
func GetMacvlanInitContainer ¶
GetMacvlanInitContainer returns the init container spec used to set up a dedicated routing table so that reply traffic flows back via eth0 for pods participating in a macvlan / overlay-gateway setup.
func ParseServiceEndpointWaitConfig ¶
ParseServiceEndpointWaitConfig reads timeout/interval envs with defaults.
func ResolvePodIP ¶
func ResolvePodIP() string
ResolvePodIP returns POD_IP from the environment (Downward API).
func WaitForServiceEndpointReady ¶
func WaitForServiceEndpointReady( ctx context.Context, kubeClient kubernetes.Interface, namespace, serviceName, podIP string, port int32, timeout, interval time.Duration, ) error
WaitForServiceEndpointReady polls EndpointSlices until podIP appears as a ready address for the given service port, or until timeout. On timeout it returns nil after logging so callers can still start controllers (Parts 2/3 provide safety nets).
Types ¶
type EnvKeyValue ¶
type Webhook ¶
type Webhook struct {
// contains filtered or unexported fields
}
Webhook used to implement a webhook.
func (*Webhook) AdmissionError ¶
func (wh *Webhook) AdmissionError(uid types.UID, err error) *admissionv1.AdmissionResponse
AdmissionError wraps error as AdmissionResponse
func (*Webhook) CreateMacvlanInitPatch ¶
func (wh *Webhook) CreateMacvlanInitPatch(req *admissionv1.AdmissionRequest, pod *corev1.Pod) ([]byte, error)
CreateMacvlanInitPatch appends the macvlan init container to the pod's init containers (idempotent — does nothing if the container is already present) and returns the JSON merge patch to send back in the admission response.
func (*Webhook) CreateOrUpdateAppLabelMutatingWebhook ¶
CreateOrUpdateAppLabelMutatingWebhook creates or updates app mutating webhook.
func (*Webhook) CreateOrUpdateAppNamespaceValidatingWebhook ¶
CreateOrUpdateAppNamespaceValidatingWebhook creates or updates app namespace validating webhook.
func (*Webhook) CreateOrUpdateApplicationManagerValidatingWebhook ¶
CreateOrUpdateApplicationManagerValidatingWebhook creates or updates the ApplicationManager validating webhook.
func (*Webhook) CreateOrUpdateArgoResourceValidatingWebhook ¶
CreateOrUpdateArgoResourceValidatingWebhook creates or updates the argo resource validating webhook.
func (*Webhook) CreateOrUpdateCliCredentialMutatingWebhook ¶
CreateOrUpdateCliCredentialMutatingWebhook registers the admission webhook that mounts the olares-cli credential Secret into pods of apps that declared permission.loginOlaresCLI. It is a separate configuration from run-as-user so the two mutations can fail and be versioned independently.
func (*Webhook) CreateOrUpdateCronWorkflowMutatingWebhook ¶
func (*Webhook) CreateOrUpdateGpuLimitMutatingWebhook ¶
CreateOrUpdateGpuLimitMutatingWebhook creates or updates gpu limit mutating webhook.
func (*Webhook) CreateOrUpdateMacvlanInitMutatingWebhook ¶
CreateOrUpdateMacvlanInitMutatingWebhook creates or updates the macvlan init container mutating webhook. It only fires for pods labeled applications.app.bytetrade.io/macvlan-init=true on Create. FailurePolicy is Ignore so that a transient webhook outage never blocks pod creation, because the macvlan-init container is an additive networking concern.
func (*Webhook) CreateOrUpdatePodArchNodeSelectorMutatingWebhook ¶
CreateOrUpdatePodArchNodeSelectorMutatingWebhook creates or updates the pod architecture nodeSelector mutating webhook. It fires for pods on Create and, when the owning app's OlaresManifest declares exactly one spec.supportArch, injects a kubernetes.io/arch nodeSelector so the pod lands on a matching node. FailurePolicy is Ignore so a transient webhook outage never blocks pod creation, because the arch nodeSelector is an additive scheduling hint.
func (*Webhook) CreateOrUpdateProviderRegistryValidatingWebhook ¶
func (*Webhook) CreateOrUpdateRunAsUserMutatingWebhook ¶
CreateOrUpdateRunAsUserMutatingWebhook creates or updates gpu limit mutating webhook.
func (*Webhook) CreateOrUpdateSandboxMutatingWebhook ¶
CreateOrUpdateSandboxMutatingWebhook creates or updates the sandbox mutating webhook.
func (*Webhook) CreateOrUpdateTLSReplicaMountValidatingWebhook ¶
CreateOrUpdateTLSReplicaMountValidatingWebhook creates or updates the WI-T1-8 validating webhook that blocks cross-tenant tls-replica private-key bypass mounts. It is scoped to opted-in caller namespaces via namespaceSelector and uses failurePolicy=Fail so a webhook outage fail-closes admission (private-key red line over availability) without affecting non-caller namespaces.
func (*Webhook) CreateOrUpdateUserValidatingWebhook ¶
CreateOrUpdateUserValidatingWebhook creates or updates user validating webhook.
func (*Webhook) CreatePatch ¶
func (wh *Webhook) CreatePatch( ctx context.Context, pod *corev1.Pod, req *admissionv1.AdmissionRequest, proxyUUID uuid.UUID, injectPolicy, injectMeshInAgent, injectMeshOutAgent bool, injectSharedPod *bool, appmgr *v1alpha1.ApplicationManager, appConfig *appcfg.ApplicationConfig, perms []appcfg.ProviderPermission, ) ([]byte, error)
CreatePatch create a patch for a pod.
func (*Webhook) DeleteAppManagerMutatingWebhook ¶
func (*Webhook) DeleteKubeletEvictionValidatingWebhook ¶
func (*Webhook) GetAdmissionRequestBody ¶
func (wh *Webhook) GetAdmissionRequestBody(req *restful.Request, resp *restful.Response) ([]byte, bool)
GetAdmissionRequestBody returns admission request body.
func (*Webhook) GetAppConfig ¶
func (wh *Webhook) GetAppConfig(namespace string) (appMgr *v1alpha1.ApplicationManager, appConfig *appcfg.ApplicationConfig, isShared, isSharedApp bool, err error)
GetAppConfig get app config by namespace.
func (*Webhook) MustInject ¶
func (wh *Webhook) MustInject(ctx context.Context, pod *corev1.Pod, namespace string) ( injectPolicy, injectMeshInAgent, injectMeshOutAgent bool, injectSharedPod *bool, perms []appcfg.ProviderPermission, appConfig *appcfg.ApplicationConfig, appMgr *v1alpha1.ApplicationManager, err error)
MustInject checks which inject operation should do for a pod.
func (*Webhook) PatchAdmissionResponse ¶
func (wh *Webhook) PatchAdmissionResponse(resp *admissionv1.AdmissionResponse, patchBytes []byte)
PatchAdmissionResponse returns an admission response with patch data.
func (*Webhook) PatchLinkerdAdminProbesOnly ¶
func (wh *Webhook) PatchLinkerdAdminProbesOnly( ctx context.Context, req *admissionv1.AdmissionRequest, pod *corev1.Pod, ) (patchBytes []byte, patched bool, err error)
PatchLinkerdAdminProbesOnly hardens linkerd-proxy admin probes when no other sidecar work is required. Returns patched=false when nothing changed.
func (*Webhook) ShouldInjectMacvlanInit ¶
func (wh *Webhook) ShouldInjectMacvlanInit(ctx context.Context, pod *corev1.Pod, ns string) (bool, error)
ShouldInjectMacvlanInit reports whether the macvlan init container should be injected for the given pod. It returns true only when the owning Application can be resolved from the pod's app name/owner labels and has `spec.settings.enableOverlayGateway == "true"`.
func (*Webhook) ValidateTLSReplicaMount ¶
func (wh *Webhook) ValidateTLSReplicaMount(ctx context.Context, pod *corev1.Pod, namespace string) (bool, string)
ValidateTLSReplicaMount enforces that any volume referencing a tls-replica private-key Secret is mounted only by the platform-injected d2 sidecar.
requirement: WI-T1-8 §2.2 — a tls-replica=true Secret may be consumed only by the olares-d2-sidecar container via the olares-d2-certs volume; any reference by another container (raw secret or projected source) is a cross-tenant private-key bypass and is denied.
behavior: fail-closed — a Secret label lookup API error denies admission (private-key red line over availability). Pods with no tls-replica volume take an allow fast path. Returns (allowed, errorCode); errorCode is empty on allow.
Source Files
¶
Directories
¶
| Path | Synopsis |
|---|---|
|
Package clicredential mounts the Olares credential that app-service provisions for apps declaring permission.loginOlaresCLI, so that olares-cli running inside the container starts out logged in as the app's owner.
|
Package clicredential mounts the Olares credential that app-service provisions for apps declaring permission.loginOlaresCLI, so that olares-cli running inside the container starts out logged in as the app's owner. |
|
Package userspaceprep computes what the platform-injected olares-prepare-userspace init container has to do for a given pod.
|
Package userspaceprep computes what the platform-injected olares-prepare-userspace init container has to do for a given pod. |