webhook

package
v2.0.51 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 8, 2026 License: Apache-2.0 Imports: 35 Imported by: 0

Documentation

Overview

Package webhook is the executor's mutating admission webhook. It always serves the secrets mutator, which injects secret references into pods that carry the inject-flyte-secrets label; deployments can add their own pod and node mutators (WithPodMutators, WithNodeMutators), each served as its own MutatingWebhook with its own path and selector.

Index

Constants

View Source
const (
	PodNameEnvVar      = "POD_NAME"
	PodNamespaceEnvVar = "POD_NAMESPACE"
)
View Source
const (
	CaCertKey            = "ca.crt"
	ServerCertKey        = "tls.crt"
	ServerCertPrivateKey = "tls.key"
)
View Source
const InvalidateSecretPath = "/invalidate-secret"

InvalidateSecretPath is the HTTP path for the cache invalidation endpoint.

Variables

This section is empty.

Functions

func InitCerts

func InitCerts(ctx context.Context, kubeClient kubernetes.Interface, cfg *webhookConfig.Config, podNamespace string) error

InitCerts makes sure the webhook's TLS cert Secret exists and is usable, and (with LocalCert) writes its contents to the cert dir.

An existing Secret is kept as-is when it holds a CA, server cert and key that are mutually consistent, unexpired, and valid for the service's DNS names. Keeping it matters: the CA bundle in the MutatingWebhookConfiguration and the certs mounted into other running webhook replicas come from this Secret, so replacing it on every start would break admission until everything converges. Only a missing, incomplete or unusable Secret is (re)generated.

podNamespace must be the namespace the webhook service runs in — the cert's DNS names are derived from it.

func StartCacheInvalidationServer added in v2.0.32

func StartCacheInvalidationServer(ctx context.Context, port int, mutator *secret.SecretsPodMutator) error

StartCacheInvalidationServer starts a plain HTTP server that listens for cache invalidation requests. It exposes POST /invalidate-secret so other services (the secret service) can drop secret values cached in the webhook process instead of waiting out the cache TTL.

The server is plain HTTP and unauthenticated, so it must stay cluster-internal: it is bound to its own port and never routed through an ingress. Blocks until ctx is cancelled.

Types

type HandlerOption added in v2.0.51

type HandlerOption func(*handlerOptions)

HandlerOption customizes a handler built by NewPodHandler or NewNodeHandler.

func WithExtraPaths added in v2.0.51

func WithExtraPaths(paths ...string) HandlerOption

WithExtraPaths serves the handler at additional paths, after the default.

func WithPaths added in v2.0.51

func WithPaths(paths ...string) HandlerOption

WithPaths overrides the paths the handler is served at; the first one goes into the generated MutatingWebhookConfiguration.

func WithWebhookName added in v2.0.51

func WithWebhookName(name string) HandlerOption

WithWebhookName overrides the MutatingWebhook name (default <id>.flyte.org).

type InvalidateRequest added in v2.0.32

type InvalidateRequest struct {
	Org     string `json:"org"`
	Domain  string `json:"domain"`
	Project string `json:"project"`
	Name    string `json:"name"`
}

InvalidateRequest is the body of a POST to InvalidateSecretPath.

type NodeMutator added in v2.0.51

type NodeMutator interface {
	ID() string
	Mutate(ctx context.Context, n *corev1.Node) (newN *corev1.Node, changed bool, err *admission.Response)
	LabelSelector() *metav1.LabelSelector
}

NodeMutator is one kind of Node mutation served by the webhook.

type Option added in v2.0.51

type Option func(*options)

Option adds to or customizes the webhook built by Setup / NewWebhook.

func WithHandlers added in v2.0.51

func WithHandlers(handlers ...ResourceHandler) Option

WithHandlers serves fully custom handlers (e.g. ones built with NewPodHandler and a custom name or path).

func WithLimitNamespace added in v2.0.51

func WithLimitNamespace(namespace string) Option

WithLimitNamespace scopes the secrets mutator's Secret informer to one namespace, for deployments that run every task pod there.

func WithNodeMutators added in v2.0.51

func WithNodeMutators(mutators ...NodeMutator) Option

WithNodeMutators serves node mutators.

func WithPodMutators added in v2.0.51

func WithPodMutators(mutators ...PodMutator) Option

WithPodMutators serves additional pod mutators, after the secrets mutator.

type PodMutator

type PodMutator interface {
	// ID names the mutator; it is part of the default webhook name and path.
	ID() string
	// Mutate returns the mutated pod and whether it changed, or an admission
	// response that rejects the request.
	Mutate(ctx context.Context, p *corev1.Pod) (newP *corev1.Pod, changed bool, err *admission.Response)
	// LabelSelector selects the pods this mutator applies to.
	LabelSelector() *metav1.LabelSelector
}

PodMutator is one kind of Pod mutation served by the webhook. Each mutator gets its own MutatingWebhook entry, path and object selector, so a mutator only sees the pods it selects.

type ResourceHandler added in v2.0.51

type ResourceHandler interface {
	// Paths are the URL paths the handler is served at. The first is the one
	// written into a generated MutatingWebhookConfiguration; the others keep
	// externally managed configurations that use another path working.
	Paths() []string
	// MutatingWebhook is the handler's entry in the MutatingWebhookConfiguration.
	MutatingWebhook(namespace string, caBytes []byte, cfg *webhookConfig.Config) admissionregistrationv1.MutatingWebhook
	// AdmissionHandler handles the admission request.
	AdmissionHandler() admission.Handler
}

ResourceHandler serves one MutatingWebhook: its admission handler, the paths it is served at and its entry in the MutatingWebhookConfiguration.

func NewNodeHandler added in v2.0.51

func NewNodeHandler(decoder admission.Decoder, mutator NodeMutator, opts ...HandlerOption) ResourceHandler

NewNodeHandler serves a NodeMutator at /mutate--v1-node/<id>.

func NewPodHandler added in v2.0.51

func NewPodHandler(decoder admission.Decoder, mutator PodMutator, opts ...HandlerOption) ResourceHandler

NewPodHandler serves a PodMutator at /mutate--v1-pod/<id>.

type Webhook added in v2.0.51

type Webhook struct {
	// contains filtered or unexported fields
}

Webhook is the set of handlers the webhook server serves.

func NewWebhook added in v2.0.51

func NewWebhook(ctx context.Context, cfg *webhookConfig.Config, podNamespace string, scheme *runtime.Scheme,
	scope promutils.Scope, opts ...Option) (*Webhook, error)

NewWebhook builds the secrets handler plus any extra handlers.

func Setup

func Setup(ctx context.Context, kubeClient kubernetes.Interface, cfg *webhookConfig.Config,
	defaultNamespace string, scope promutils.Scope, mgr manager.Manager, opts ...Option) (*Webhook, error)

Setup initializes the webhook: generates certs, registers the MutatingWebhookConfiguration, and registers the HTTP handlers. It is called before mgr.Start() so that the webhook server is ready to receive requests. The returned Webhook owns the secret cache and can be used to invalidate it.

func (*Webhook) CreateMutationWebhookConfiguration added in v2.0.51

func (w *Webhook) CreateMutationWebhookConfiguration(
	namespace string,
) (*admissionregistrationv1.MutatingWebhookConfiguration, error)

CreateMutationWebhookConfiguration builds the configuration that points the API server at every handler.

func (*Webhook) Handlers added in v2.0.51

func (w *Webhook) Handlers() []ResourceHandler

Handlers returns every handler the webhook serves.

func (*Webhook) Register added in v2.0.51

func (w *Webhook) Register(ctx context.Context, mgr manager.Manager) error

Register serves every handler on the manager's webhook server.

func (*Webhook) SecretsMutator added in v2.0.51

func (w *Webhook) SecretsMutator() *secret.SecretsPodMutator

SecretsMutator returns the mutator that owns the secret caches, so the cache invalidation server can clear them.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL