Documentation
¶
Overview ¶
Package webhook is the executor's mutating admission webhook. It always serves the secrets mutator, which injects secret references into pods that carry the inject-flyte-secrets label; deployments can add their own pod and node mutators (WithPodMutators, WithNodeMutators), each served as its own MutatingWebhook with its own path and selector.
Index ¶
- Constants
- func InitCerts(ctx context.Context, kubeClient kubernetes.Interface, ...) error
- func StartCacheInvalidationServer(ctx context.Context, port int, mutator *secret.SecretsPodMutator) error
- type HandlerOption
- type InvalidateRequest
- type NodeMutator
- type Option
- type PodMutator
- type ResourceHandler
- type Webhook
- func (w *Webhook) CreateMutationWebhookConfiguration(namespace string) (*admissionregistrationv1.MutatingWebhookConfiguration, error)
- func (w *Webhook) Handlers() []ResourceHandler
- func (w *Webhook) Register(ctx context.Context, mgr manager.Manager) error
- func (w *Webhook) SecretsMutator() *secret.SecretsPodMutator
Constants ¶
const ( PodNameEnvVar = "POD_NAME" PodNamespaceEnvVar = "POD_NAMESPACE" )
const ( CaCertKey = "ca.crt" ServerCertKey = "tls.crt" ServerCertPrivateKey = "tls.key" )
const InvalidateSecretPath = "/invalidate-secret"
InvalidateSecretPath is the HTTP path for the cache invalidation endpoint.
Variables ¶
This section is empty.
Functions ¶
func InitCerts ¶
func InitCerts(ctx context.Context, kubeClient kubernetes.Interface, cfg *webhookConfig.Config, podNamespace string) error
InitCerts makes sure the webhook's TLS cert Secret exists and is usable, and (with LocalCert) writes its contents to the cert dir.
An existing Secret is kept as-is when it holds a CA, server cert and key that are mutually consistent, unexpired, and valid for the service's DNS names. Keeping it matters: the CA bundle in the MutatingWebhookConfiguration and the certs mounted into other running webhook replicas come from this Secret, so replacing it on every start would break admission until everything converges. Only a missing, incomplete or unusable Secret is (re)generated.
podNamespace must be the namespace the webhook service runs in — the cert's DNS names are derived from it.
func StartCacheInvalidationServer ¶ added in v2.0.32
func StartCacheInvalidationServer(ctx context.Context, port int, mutator *secret.SecretsPodMutator) error
StartCacheInvalidationServer starts a plain HTTP server that listens for cache invalidation requests. It exposes POST /invalidate-secret so other services (the secret service) can drop secret values cached in the webhook process instead of waiting out the cache TTL.
The server is plain HTTP and unauthenticated, so it must stay cluster-internal: it is bound to its own port and never routed through an ingress. Blocks until ctx is cancelled.
Types ¶
type HandlerOption ¶ added in v2.0.51
type HandlerOption func(*handlerOptions)
HandlerOption customizes a handler built by NewPodHandler or NewNodeHandler.
func WithExtraPaths ¶ added in v2.0.51
func WithExtraPaths(paths ...string) HandlerOption
WithExtraPaths serves the handler at additional paths, after the default.
func WithPaths ¶ added in v2.0.51
func WithPaths(paths ...string) HandlerOption
WithPaths overrides the paths the handler is served at; the first one goes into the generated MutatingWebhookConfiguration.
func WithWebhookName ¶ added in v2.0.51
func WithWebhookName(name string) HandlerOption
WithWebhookName overrides the MutatingWebhook name (default <id>.flyte.org).
type InvalidateRequest ¶ added in v2.0.32
type InvalidateRequest struct {
Org string `json:"org"`
Domain string `json:"domain"`
Project string `json:"project"`
Name string `json:"name"`
}
InvalidateRequest is the body of a POST to InvalidateSecretPath.
type NodeMutator ¶ added in v2.0.51
type NodeMutator interface {
ID() string
Mutate(ctx context.Context, n *corev1.Node) (newN *corev1.Node, changed bool, err *admission.Response)
LabelSelector() *metav1.LabelSelector
}
NodeMutator is one kind of Node mutation served by the webhook.
type Option ¶ added in v2.0.51
type Option func(*options)
Option adds to or customizes the webhook built by Setup / NewWebhook.
func WithHandlers ¶ added in v2.0.51
func WithHandlers(handlers ...ResourceHandler) Option
WithHandlers serves fully custom handlers (e.g. ones built with NewPodHandler and a custom name or path).
func WithLimitNamespace ¶ added in v2.0.51
WithLimitNamespace scopes the secrets mutator's Secret informer to one namespace, for deployments that run every task pod there.
func WithNodeMutators ¶ added in v2.0.51
func WithNodeMutators(mutators ...NodeMutator) Option
WithNodeMutators serves node mutators.
func WithPodMutators ¶ added in v2.0.51
func WithPodMutators(mutators ...PodMutator) Option
WithPodMutators serves additional pod mutators, after the secrets mutator.
type PodMutator ¶
type PodMutator interface {
// ID names the mutator; it is part of the default webhook name and path.
ID() string
// Mutate returns the mutated pod and whether it changed, or an admission
// response that rejects the request.
Mutate(ctx context.Context, p *corev1.Pod) (newP *corev1.Pod, changed bool, err *admission.Response)
// LabelSelector selects the pods this mutator applies to.
LabelSelector() *metav1.LabelSelector
}
PodMutator is one kind of Pod mutation served by the webhook. Each mutator gets its own MutatingWebhook entry, path and object selector, so a mutator only sees the pods it selects.
type ResourceHandler ¶ added in v2.0.51
type ResourceHandler interface {
// Paths are the URL paths the handler is served at. The first is the one
// written into a generated MutatingWebhookConfiguration; the others keep
// externally managed configurations that use another path working.
Paths() []string
// MutatingWebhook is the handler's entry in the MutatingWebhookConfiguration.
MutatingWebhook(namespace string, caBytes []byte, cfg *webhookConfig.Config) admissionregistrationv1.MutatingWebhook
// AdmissionHandler handles the admission request.
AdmissionHandler() admission.Handler
}
ResourceHandler serves one MutatingWebhook: its admission handler, the paths it is served at and its entry in the MutatingWebhookConfiguration.
func NewNodeHandler ¶ added in v2.0.51
func NewNodeHandler(decoder admission.Decoder, mutator NodeMutator, opts ...HandlerOption) ResourceHandler
NewNodeHandler serves a NodeMutator at /mutate--v1-node/<id>.
func NewPodHandler ¶ added in v2.0.51
func NewPodHandler(decoder admission.Decoder, mutator PodMutator, opts ...HandlerOption) ResourceHandler
NewPodHandler serves a PodMutator at /mutate--v1-pod/<id>.
type Webhook ¶ added in v2.0.51
type Webhook struct {
// contains filtered or unexported fields
}
Webhook is the set of handlers the webhook server serves.
func NewWebhook ¶ added in v2.0.51
func NewWebhook(ctx context.Context, cfg *webhookConfig.Config, podNamespace string, scheme *runtime.Scheme, scope promutils.Scope, opts ...Option) (*Webhook, error)
NewWebhook builds the secrets handler plus any extra handlers.
func Setup ¶
func Setup(ctx context.Context, kubeClient kubernetes.Interface, cfg *webhookConfig.Config, defaultNamespace string, scope promutils.Scope, mgr manager.Manager, opts ...Option) (*Webhook, error)
Setup initializes the webhook: generates certs, registers the MutatingWebhookConfiguration, and registers the HTTP handlers. It is called before mgr.Start() so that the webhook server is ready to receive requests. The returned Webhook owns the secret cache and can be used to invalidate it.
func (*Webhook) CreateMutationWebhookConfiguration ¶ added in v2.0.51
func (w *Webhook) CreateMutationWebhookConfiguration( namespace string, ) (*admissionregistrationv1.MutatingWebhookConfiguration, error)
CreateMutationWebhookConfiguration builds the configuration that points the API server at every handler.
func (*Webhook) Handlers ¶ added in v2.0.51
func (w *Webhook) Handlers() []ResourceHandler
Handlers returns every handler the webhook serves.
func (*Webhook) Register ¶ added in v2.0.51
Register serves every handler on the manager's webhook server.
func (*Webhook) SecretsMutator ¶ added in v2.0.51
func (w *Webhook) SecretsMutator() *secret.SecretsPodMutator
SecretsMutator returns the mutator that owns the secret caches, so the cache invalidation server can clear them.