operator

package
v0.37.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 8, 2026 License: AGPL-3.0 Imports: 19 Imported by: 0

Documentation

Overview

Package operator contains UDS Core operator monitoring logic for UDS CLI Next.

Index

Examples

Constants

This section is empty.

Variables

View Source
var (
	ErrNoTargetsFound         = errors.New("no potential targets for monitoring found")
	ErrConnectCluster         = errors.New("connecting to cluster")
	ErrCreateKubernetesClient = errors.New("creating Kubernetes client")
	ErrListPeprPods           = errors.New("listing Pepr pods")
	ErrOpenLogStream          = errors.New("opening log stream")
	ErrStreamPodLogs          = errors.New("streaming logs for pod")
	ErrProcessPodLogs         = errors.New("processing logs for pod")
	ErrFlushMonitorOutput     = errors.New("flushing monitor output")
	ErrMutationPatchMissing   = errors.New("mutation patch is missing")
	ErrDecodeMutationPatch    = errors.New("decoding mutation patch")
	ErrParseMutationPatch     = errors.New("parsing mutation patch")
)

These sentinels classify monitor failure stages for errors.Is without coupling callers to Kubernetes errors.

Functions

func Monitor

func Monitor(ctx context.Context, streams iostreams.IOStreams, opts MonitorOptions) error

Monitor streams UDS Core operator and policy events from Pepr controller pods.

Types

type Event

type Event struct {
	Kind      EventKind
	Resource  string
	Timestamp string
	Repeated  int
	Message   string
	Patch     []PatchOperation
}

Event is a display-oriented Pepr event.

type EventKind

type EventKind string

EventKind identifies the high-level Pepr event shown to users.

const (
	// EventAllowed represents an allowed Pepr policy decision.
	EventAllowed EventKind = "ALLOWED"
	// EventDenied represents a denied Pepr policy decision.
	EventDenied EventKind = "DENIED"
	// EventMutated represents a Pepr mutation.
	EventMutated EventKind = "MUTATED"
	// EventOperator represents a UDS operator event from Pepr.
	EventOperator EventKind = "OPERATOR"
)

type Formatter

type Formatter struct {
	NoColor bool
}

Formatter renders Pepr events as structured terminal text.

func (Formatter) WriteEvent

func (f Formatter) WriteEvent(w io.Writer, event Event) error

WriteEvent writes one self-contained event. Patch values remain JSON-encoded so their scalar and object representations are preserved instead of being reformatted as terminal text.

func (Formatter) WriteEvents

func (f Formatter) WriteEvents(w io.Writer, events []Event) error

WriteEvents writes complete events separated by blank lines. Each event owns its terminating newline.

Example
events := []Event{
	{
		Kind:     EventMutated,
		Resource: "istio-system/istiod",
		Patch: []PatchOperation{
			{Kind: "ADDED", Path: "/metadata/annotations/uds-core.pepr.dev~1uds-core-operator", Value: `"succeeded"`},
			{Kind: "ADDED", Path: "/metadata/annotations/uds-core.pepr.dev~1uds-core-policies", Value: `"succeeded"`},
		},
	},
	{
		Kind:     EventAllowed,
		Resource: "istio-system/istiod",
		Repeated: 1,
	},
	{
		Kind:     EventMutated,
		Resource: "istio-system",
		Patch: []PatchOperation{
			{Kind: "ADDED", Path: "/spec/securityContext/runAsNonRoot", Value: "true"},
			{Kind: "ADDED", Path: "/spec/securityContext/runAsUser", Value: "1000"},
			{Kind: "ADDED", Path: "/spec/securityContext/runAsGroup", Value: "1000"},
			{Kind: "ADDED", Path: "/metadata/annotations/uds-core.pepr.dev~1mutated", Value: `"[\"require-non-root-user\",\"drop-all-capabilities\"]"`},
		},
	},
	{
		Kind:     EventDenied,
		Resource: "default/bad-pod",
		Message:  "Pod violates UDS policy",
	},
}

var out bytes.Buffer
formatter := Formatter{NoColor: true}
_ = formatter.WriteEvents(&out, events)
fmt.Print(out.String())
Output:
MUTATED  resource=istio-system/istiod
  ADDED path=/metadata/annotations/uds-core.pepr.dev~1uds-core-operator value="succeeded"
  ADDED path=/metadata/annotations/uds-core.pepr.dev~1uds-core-policies value="succeeded"

ALLOWED  resource=istio-system/istiod repeated=1

MUTATED  resource=istio-system
  ADDED path=/spec/securityContext/runAsNonRoot value=true
  ADDED path=/spec/securityContext/runAsUser value=1000
  ADDED path=/spec/securityContext/runAsGroup value=1000
  ADDED path=/metadata/annotations/uds-core.pepr.dev~1mutated value="[\"require-non-root-user\",\"drop-all-capabilities\"]"

DENIED   resource=default/bad-pod
  message="Pod violates UDS policy"

type MonitorOptions

type MonitorOptions struct {
	Stream     StreamKind
	Namespace  string
	Follow     bool
	Timestamps bool
	Since      time.Duration
	JSON       bool
	NoColor    bool
	LogLevel   string
	// contains filtered or unexported fields
}

MonitorOptions configures operator monitoring.

type PatchOperation

type PatchOperation struct {
	Kind  string
	Path  string
	Value string
}

PatchOperation describes one rendered JSON patch operation.

type StreamKind

type StreamKind string

StreamKind identifies the operator events included in a monitor stream.

const (
	// StreamAll includes operator and policy events.
	StreamAll StreamKind = ""
	// StreamPolicies includes all policy decisions.
	StreamPolicies StreamKind = "policies"
	// StreamOperator includes UDS Core operator events.
	StreamOperator StreamKind = "operator"
	// StreamAllowed includes allowed policy decisions.
	StreamAllowed StreamKind = "allowed"
	// StreamDenied includes denied policy decisions.
	StreamDenied StreamKind = "denied"
	// StreamFailed includes denied policy decisions and operator failures.
	StreamFailed StreamKind = "failed"
	// StreamMutated includes policy mutations.
	StreamMutated StreamKind = "mutated"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL