Documentation
¶
Overview ¶
Package v1alpha1 contains API Schema definitions for the policy v1alpha1 API group +kubebuilder:object:generate=true +groupName=policy.giantswarm.io
Index ¶
- Constants
- Variables
- type AutomatedException
- type AutomatedExceptionList
- type AutomatedExceptionStatus
- type GeneratedException
- type Policy
- type PolicyConfig
- type PolicyConfigList
- type PolicyConfigSpec
- type PolicyException
- type PolicyExceptionList
- type PolicyExceptionSpec
- type PolicyExceptionStatus
- type PolicyList
- type PolicyManifest
- type PolicyManifestList
- type PolicyManifestSpec
- type PolicySpec
- type PolicyStatus
- type Target
Constants ¶
const ( // PolicyExceptionReady is True when every Kyverno PolicyException generated for it is applied, // stale ones are removed, and every target is translated. It does not check that the listed // policies exist; PoliciesResolved reports that. PolicyExceptionReady = "Ready" // PolicyExceptionPoliciesResolved is False when a listed policy matches no CEL policy. It is // informational and does not affect Ready, so health checks on Ready (Flux wait, kstatus) // are not blocked by policies still being migrated. PolicyExceptionPoliciesResolved = "PoliciesResolved" // PolicyExceptionTargetsTranslated is False when a target cannot be expressed in a CEL exception. PolicyExceptionTargetsTranslated = "TargetsTranslated" )
Condition types of a PolicyException, written by kyverno-policy-operator.
const ( ReasonReconciled = "Reconciled" ReasonInvalidNamespace = "InvalidNamespace" ReasonNameTaken = "NameTaken" ReasonLookupFailed = "LookupFailed" ReasonApplyFailed = "ApplyFailed" ReasonDeleteFailed = "DeleteFailed" )
Reasons of the Ready condition. When several checks fail, Ready takes the first failing reason in the order InvalidNamespace, NameTaken, LookupFailed, ApplyFailed, DeleteFailed, UnsupportedKind, and its message lists all of them.
const ( // ReasonResolved means every listed policy matches a CEL policy. ReasonResolved = "Resolved" // ReasonNotMigrated means a listed policy matches only a legacy ClusterPolicy. The legacy // exception covers it, and the CEL exception takes over once the policy is migrated. // This is expected during the migration. ReasonNotMigrated = "NotMigrated" // ReasonPolicyNotFound means a listed policy matches no policy at all, for example a typo, // a removed policy, or a policy not installed yet. ReasonPolicyNotFound = "PolicyNotFound" )
Reasons of the PoliciesResolved condition. PolicyNotFound wins over NotMigrated, and the message names the policies for each.
const ( ReasonTranslated = "Translated" // ReasonUnsupportedKind means a target kind cannot be expressed in a CEL exception. It is a // reason of both TargetsTranslated and Ready. ReasonUnsupportedKind = "UnsupportedKind" )
Reasons of the TargetsTranslated condition.
Variables ¶
var ( // GroupVersion is group version used to register these objects GroupVersion = schema.GroupVersion{Group: "policy.giantswarm.io", Version: "v1alpha1"} // SchemeBuilder is used to add go types to the GroupVersionKind scheme SchemeBuilder = &runtime.SchemeBuilder{} // AddToScheme adds the types in this group-version to the given scheme. AddToScheme = SchemeBuilder.AddToScheme )
Functions ¶
This section is empty.
Types ¶
type AutomatedException ¶
type AutomatedException struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
Spec PolicyExceptionSpec `json:"spec,omitempty"`
Status AutomatedExceptionStatus `json:"status,omitempty"`
}
AutomatedException is the Schema for the automatedexceptions API
func (*AutomatedException) DeepCopy ¶
func (in *AutomatedException) DeepCopy() *AutomatedException
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AutomatedException.
func (*AutomatedException) DeepCopyInto ¶
func (in *AutomatedException) DeepCopyInto(out *AutomatedException)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*AutomatedException) DeepCopyObject ¶
func (in *AutomatedException) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type AutomatedExceptionList ¶
type AutomatedExceptionList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []AutomatedException `json:"items"`
}
AutomatedExceptionList contains a list of AutomatedException
func (*AutomatedExceptionList) DeepCopy ¶
func (in *AutomatedExceptionList) DeepCopy() *AutomatedExceptionList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AutomatedExceptionList.
func (*AutomatedExceptionList) DeepCopyInto ¶
func (in *AutomatedExceptionList) DeepCopyInto(out *AutomatedExceptionList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*AutomatedExceptionList) DeepCopyObject ¶
func (in *AutomatedExceptionList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type AutomatedExceptionStatus ¶
type AutomatedExceptionStatus struct {
}
AutomatedExceptionStatus defines the observed state of AutomatedException
func (*AutomatedExceptionStatus) DeepCopy ¶
func (in *AutomatedExceptionStatus) DeepCopy() *AutomatedExceptionStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AutomatedExceptionStatus.
func (*AutomatedExceptionStatus) DeepCopyInto ¶
func (in *AutomatedExceptionStatus) DeepCopyInto(out *AutomatedExceptionStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type GeneratedException ¶ added in v0.1.0
type GeneratedException struct {
// APIVersion is policies.kyverno.io/v1 or kyverno.io/v2.
APIVersion string `json:"apiVersion"`
Namespace string `json:"namespace"`
Name string `json:"name"`
}
GeneratedException references a Kyverno PolicyException generated for a PolicyException.
func (*GeneratedException) DeepCopy ¶ added in v0.1.0
func (in *GeneratedException) DeepCopy() *GeneratedException
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new GeneratedException.
func (*GeneratedException) DeepCopyInto ¶ added in v0.1.0
func (in *GeneratedException) DeepCopyInto(out *GeneratedException)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Policy ¶ added in v0.0.3
type Policy struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
Spec PolicySpec `json:"spec,omitempty"`
Status PolicyStatus `json:"status,omitempty"`
}
Policy is the Schema for the Policies API +kubebuilder:object:root=true +kubebuilder:resource:shortName=gspol;gspolicy,scope=Cluster +kubebuilder:printcolumn:name="Mode",type=string,JSONPath=`.spec.defaultPolicyState` +k8s:openapi-gen=true
func (*Policy) DeepCopy ¶ added in v0.0.3
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Policy.
func (*Policy) DeepCopyInto ¶ added in v0.0.3
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*Policy) DeepCopyObject ¶ added in v0.0.3
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type PolicyConfig ¶ added in v0.0.3
type PolicyConfig struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
Spec PolicyConfigSpec `json:"spec,omitempty"`
}
PolicyConfig is the Schema for the PolicyConfigs API +kubebuilder:object:root=true +kubebuilder:resource:shortName=gspolconfig,scope=Cluster +k8s:openapi-gen=true
func (*PolicyConfig) DeepCopy ¶ added in v0.0.3
func (in *PolicyConfig) DeepCopy() *PolicyConfig
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyConfig.
func (*PolicyConfig) DeepCopyInto ¶ added in v0.0.3
func (in *PolicyConfig) DeepCopyInto(out *PolicyConfig)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*PolicyConfig) DeepCopyObject ¶ added in v0.0.3
func (in *PolicyConfig) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type PolicyConfigList ¶ added in v0.0.3
type PolicyConfigList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []PolicyConfig `json:"items"`
}
PolicyConfigList contains a list of PolicyConfigs +kubebuilder:object:root=true
func (*PolicyConfigList) DeepCopy ¶ added in v0.0.3
func (in *PolicyConfigList) DeepCopy() *PolicyConfigList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyConfigList.
func (*PolicyConfigList) DeepCopyInto ¶ added in v0.0.3
func (in *PolicyConfigList) DeepCopyInto(out *PolicyConfigList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*PolicyConfigList) DeepCopyObject ¶ added in v0.0.3
func (in *PolicyConfigList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type PolicyConfigSpec ¶ added in v0.0.3
type PolicyConfigSpec struct {
PolicyName string `json:"policyName,omitempty"`
PolicyState string `json:"policyState,omitempty"`
}
PolicyConfigSpec defines the desired state of PolicyConfig
func (*PolicyConfigSpec) DeepCopy ¶ added in v0.0.3
func (in *PolicyConfigSpec) DeepCopy() *PolicyConfigSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyConfigSpec.
func (*PolicyConfigSpec) DeepCopyInto ¶ added in v0.0.3
func (in *PolicyConfigSpec) DeepCopyInto(out *PolicyConfigSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type PolicyException ¶
type PolicyException struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
Spec PolicyExceptionSpec `json:"spec,omitempty"`
Status PolicyExceptionStatus `json:"status,omitempty"`
}
PolicyException is the Schema for the policyexceptions API +k8s:openapi-gen=true
func (*PolicyException) DeepCopy ¶
func (in *PolicyException) DeepCopy() *PolicyException
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyException.
func (*PolicyException) DeepCopyInto ¶
func (in *PolicyException) DeepCopyInto(out *PolicyException)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*PolicyException) DeepCopyObject ¶
func (in *PolicyException) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type PolicyExceptionList ¶
type PolicyExceptionList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []PolicyException `json:"items"`
}
PolicyExceptionList contains a list of PolicyException
func (*PolicyExceptionList) DeepCopy ¶
func (in *PolicyExceptionList) DeepCopy() *PolicyExceptionList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyExceptionList.
func (*PolicyExceptionList) DeepCopyInto ¶
func (in *PolicyExceptionList) DeepCopyInto(out *PolicyExceptionList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*PolicyExceptionList) DeepCopyObject ¶
func (in *PolicyExceptionList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type PolicyExceptionSpec ¶
type PolicyExceptionSpec struct {
// Policies defines the list of policies to be excluded
Policies []string `json:"policies"`
// Targes defines the list of target workloads where the exceptions will be applied
Targets []Target `json:"targets"`
}
PolicyExceptionSpec defines the desired state of PolicyException
func (*PolicyExceptionSpec) DeepCopy ¶
func (in *PolicyExceptionSpec) DeepCopy() *PolicyExceptionSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyExceptionSpec.
func (*PolicyExceptionSpec) DeepCopyInto ¶
func (in *PolicyExceptionSpec) DeepCopyInto(out *PolicyExceptionSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type PolicyExceptionStatus ¶ added in v0.1.0
type PolicyExceptionStatus struct {
// ObservedGeneration is the metadata.generation the status was computed for.
// +optional
ObservedGeneration int64 `json:"observedGeneration,omitempty"`
// Conditions are Ready, PoliciesResolved and TargetsTranslated.
// +listType=map
// +listMapKey=type
// +optional
Conditions []metav1.Condition `json:"conditions,omitempty"`
// GeneratedExceptions are the Kyverno PolicyExceptions written for this PolicyException.
// +listType=atomic
// +optional
GeneratedExceptions []GeneratedException `json:"generatedExceptions,omitempty"`
// UnresolvedPolicies are listed policies that match no CEL policy: those that match only a
// legacy ClusterPolicy and those that match no policy at all.
// +listType=atomic
// +optional
UnresolvedPolicies []string `json:"unresolvedPolicies,omitempty"`
// UnsupportedTargetKinds are target kinds left out of the CEL exception, such as "Pod/exec".
// +listType=atomic
// +optional
UnsupportedTargetKinds []string `json:"unsupportedTargetKinds,omitempty"`
}
PolicyExceptionStatus defines the observed state of PolicyException. kyverno-policy-operator writes it.
func (*PolicyExceptionStatus) DeepCopy ¶ added in v0.1.0
func (in *PolicyExceptionStatus) DeepCopy() *PolicyExceptionStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyExceptionStatus.
func (*PolicyExceptionStatus) DeepCopyInto ¶ added in v0.1.0
func (in *PolicyExceptionStatus) DeepCopyInto(out *PolicyExceptionStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type PolicyList ¶ added in v0.0.3
type PolicyList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []Policy `json:"items"`
}
PolicyList contains a list of Policy +kubebuilder:object:root=true
func (*PolicyList) DeepCopy ¶ added in v0.0.3
func (in *PolicyList) DeepCopy() *PolicyList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyList.
func (*PolicyList) DeepCopyInto ¶ added in v0.0.3
func (in *PolicyList) DeepCopyInto(out *PolicyList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*PolicyList) DeepCopyObject ¶ added in v0.0.3
func (in *PolicyList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type PolicyManifest ¶
type PolicyManifest struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
Spec PolicyManifestSpec `json:"spec,omitempty"`
}
PolicyManifest is the Schema for the policymanifests API +kubebuilder:object:root=true +kubebuilder:resource:shortName=polman,scope=Cluster +kubebuilder:printcolumn:name="Mode",type=string,JSONPath=`.spec.mode` +k8s:openapi-gen=true
func (*PolicyManifest) DeepCopy ¶
func (in *PolicyManifest) DeepCopy() *PolicyManifest
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyManifest.
func (*PolicyManifest) DeepCopyInto ¶
func (in *PolicyManifest) DeepCopyInto(out *PolicyManifest)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*PolicyManifest) DeepCopyObject ¶
func (in *PolicyManifest) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type PolicyManifestList ¶
type PolicyManifestList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []PolicyManifest `json:"items"`
}
PolicyManifestList contains a list of PolicyManifest +kubebuilder:object:root=true
func (*PolicyManifestList) DeepCopy ¶
func (in *PolicyManifestList) DeepCopy() *PolicyManifestList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyManifestList.
func (*PolicyManifestList) DeepCopyInto ¶
func (in *PolicyManifestList) DeepCopyInto(out *PolicyManifestList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*PolicyManifestList) DeepCopyObject ¶
func (in *PolicyManifestList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type PolicyManifestSpec ¶
type PolicyManifestSpec struct {
// Foo is an example field of PolicyManifest. Edit policymanifest_types.go to remove/update
Mode string `json:"mode,omitempty"`
Args []string `json:"args,omitempty"`
Exceptions []Target `json:"exceptions,omitempty"`
AutomatedExceptions []Target `json:"automatedExceptions,omitempty"`
}
PolicyManifestSpec defines the desired state of PolicyManifest
func (*PolicyManifestSpec) DeepCopy ¶
func (in *PolicyManifestSpec) DeepCopy() *PolicyManifestSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyManifestSpec.
func (*PolicyManifestSpec) DeepCopyInto ¶
func (in *PolicyManifestSpec) DeepCopyInto(out *PolicyManifestSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type PolicySpec ¶ added in v0.0.3
type PolicySpec struct {
DefaultPolicyState string `json:"defaultPolicyState,omitempty"`
}
PolicySpec defines the desired state of Policy
func (*PolicySpec) DeepCopy ¶ added in v0.0.3
func (in *PolicySpec) DeepCopy() *PolicySpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicySpec.
func (*PolicySpec) DeepCopyInto ¶ added in v0.0.3
func (in *PolicySpec) DeepCopyInto(out *PolicySpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type PolicyStatus ¶ added in v0.0.3
type PolicyStatus struct {
TargetPolicyState string `json:"targetPolicyState,omitempty"`
ActualPolicyState string `json:"actualPolicyState,omitempty"`
}
PolicyStatus defines the observed state of Policy +kubebuilder:subresource:status
func (*PolicyStatus) DeepCopy ¶ added in v0.0.3
func (in *PolicyStatus) DeepCopy() *PolicyStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyStatus.
func (*PolicyStatus) DeepCopyInto ¶ added in v0.0.3
func (in *PolicyStatus) DeepCopyInto(out *PolicyStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Target ¶
type Target struct {
// +listType=atomic
Namespaces []string `json:"namespaces"`
// +listType=atomic
Names []string `json:"names"`
Kind string `json:"kind"`
}
Target defines a resource to which a PolicyException applies +k8s:openapi-gen=true
func (*Target) DeepCopy ¶
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Target.
func (*Target) DeepCopyInto ¶
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.