Documentation
¶
Overview ¶
Package operator contains UDS Core operator monitoring logic for UDS CLI Next.
Index ¶
Examples ¶
Constants ¶
This section is empty.
Variables ¶
var ( ErrNoTargetsFound = errors.New("no potential targets for monitoring found") ErrConnectCluster = errors.New("connecting to cluster") ErrCreateKubernetesClient = errors.New("creating Kubernetes client") ErrListPeprPods = errors.New("listing Pepr pods") ErrOpenLogStream = errors.New("opening log stream") ErrStreamPodLogs = errors.New("streaming logs for pod") ErrProcessPodLogs = errors.New("processing logs for pod") ErrFlushMonitorOutput = errors.New("flushing monitor output") ErrMutationPatchMissing = errors.New("mutation patch is missing") ErrDecodeMutationPatch = errors.New("decoding mutation patch") ErrParseMutationPatch = errors.New("parsing mutation patch") )
These sentinels classify monitor failure stages for errors.Is without coupling callers to Kubernetes errors.
Functions ¶
Types ¶
type Event ¶
type Event struct {
Kind EventKind
Resource string
Timestamp string
Repeated int
Message string
Patch []PatchOperation
}
Event is a display-oriented Pepr event.
type EventKind ¶
type EventKind string
EventKind identifies the high-level Pepr event shown to users.
const ( // EventAllowed represents an allowed Pepr policy decision. EventAllowed EventKind = "ALLOWED" // EventDenied represents a denied Pepr policy decision. EventDenied EventKind = "DENIED" // EventMutated represents a Pepr mutation. EventMutated EventKind = "MUTATED" // EventOperator represents a UDS operator event from Pepr. EventOperator EventKind = "OPERATOR" )
type Formatter ¶
type Formatter struct {
NoColor bool
}
Formatter renders Pepr events as structured terminal text.
func (Formatter) WriteEvent ¶
WriteEvent writes one self-contained event. Patch values remain JSON-encoded so their scalar and object representations are preserved instead of being reformatted as terminal text.
func (Formatter) WriteEvents ¶
WriteEvents writes complete events separated by blank lines. Each event owns its terminating newline.
Example ¶
events := []Event{
{
Kind: EventMutated,
Resource: "istio-system/istiod",
Patch: []PatchOperation{
{Kind: "ADDED", Path: "/metadata/annotations/uds-core.pepr.dev~1uds-core-operator", Value: `"succeeded"`},
{Kind: "ADDED", Path: "/metadata/annotations/uds-core.pepr.dev~1uds-core-policies", Value: `"succeeded"`},
},
},
{
Kind: EventAllowed,
Resource: "istio-system/istiod",
Repeated: 1,
},
{
Kind: EventMutated,
Resource: "istio-system",
Patch: []PatchOperation{
{Kind: "ADDED", Path: "/spec/securityContext/runAsNonRoot", Value: "true"},
{Kind: "ADDED", Path: "/spec/securityContext/runAsUser", Value: "1000"},
{Kind: "ADDED", Path: "/spec/securityContext/runAsGroup", Value: "1000"},
{Kind: "ADDED", Path: "/metadata/annotations/uds-core.pepr.dev~1mutated", Value: `"[\"require-non-root-user\",\"drop-all-capabilities\"]"`},
},
},
{
Kind: EventDenied,
Resource: "default/bad-pod",
Message: "Pod violates UDS policy",
},
}
var out bytes.Buffer
formatter := Formatter{NoColor: true}
_ = formatter.WriteEvents(&out, events)
fmt.Print(out.String())
Output: MUTATED resource=istio-system/istiod ADDED path=/metadata/annotations/uds-core.pepr.dev~1uds-core-operator value="succeeded" ADDED path=/metadata/annotations/uds-core.pepr.dev~1uds-core-policies value="succeeded" ALLOWED resource=istio-system/istiod repeated=1 MUTATED resource=istio-system ADDED path=/spec/securityContext/runAsNonRoot value=true ADDED path=/spec/securityContext/runAsUser value=1000 ADDED path=/spec/securityContext/runAsGroup value=1000 ADDED path=/metadata/annotations/uds-core.pepr.dev~1mutated value="[\"require-non-root-user\",\"drop-all-capabilities\"]" DENIED resource=default/bad-pod message="Pod violates UDS policy"
type MonitorOptions ¶
type MonitorOptions struct {
Stream StreamKind
Namespace string
Follow bool
Timestamps bool
Since time.Duration
JSON bool
NoColor bool
LogLevel string
// contains filtered or unexported fields
}
MonitorOptions configures operator monitoring.
type PatchOperation ¶
PatchOperation describes one rendered JSON patch operation.
type StreamKind ¶
type StreamKind string
StreamKind identifies the operator events included in a monitor stream.
const ( // StreamAll includes operator and policy events. StreamAll StreamKind = "" // StreamPolicies includes all policy decisions. StreamPolicies StreamKind = "policies" // StreamOperator includes UDS Core operator events. StreamOperator StreamKind = "operator" // StreamAllowed includes allowed policy decisions. StreamAllowed StreamKind = "allowed" // StreamDenied includes denied policy decisions. StreamDenied StreamKind = "denied" // StreamFailed includes denied policy decisions and operator failures. StreamFailed StreamKind = "failed" // StreamMutated includes policy mutations. StreamMutated StreamKind = "mutated" )