pluginpolicy

package
v0.3.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 2, 2026 License: Apache-2.0 Imports: 20 Imported by: 0

Documentation

Index

Constants

View Source
const (
	NoPolicyFingerprint = ""

	ExecWorkdirSource          = "source"
	ExecCopyScopeSource        = "source"
	ExecCopyScopeRepository    = "repository"
	DefaultInitTimeout         = 10 * time.Second
	DefaultGenerateTimeout     = 60 * time.Second
	DefaultPostRendererTimeout = 30 * time.Second
	DefaultMaxStdoutBytes      = int64(10 * 1024 * 1024)
	DefaultMaxStderrBytes      = int64(64 * 1024)
	DefaultContainerRuntime    = ContainerRuntimeDocker
	DefaultContainerNetwork    = ContainerNetworkNone
	ContainerCacheTargetRoot   = "/drydock-cache"
)
View Source
const (
	ExecParameterPathBaseSource     = "source"
	ExecParameterPathBaseRepository = "repository"
)
View Source
const ApplicationEnvPrefix = "ARGOCD_ENV_"

ApplicationEnvPrefix prefixes every Application env name on delivery: an applicationEnv.allow entry NAME reaches the plugin as ARGOCD_ENV_NAME, the way an Argo CD repo-server delivers spec.source.plugin.env. IsManagedEnvName, managedEnvNameWarning, and the delivery code must agree on this prefix.

Variables

This section is empty.

Functions

func Fingerprint

func Fingerprint(policy Policy) (string, error)

func IsManagedEnvName added in v0.3.0

func IsManagedEnvName(name string) bool

IsManagedEnvName reports whether drydock sets name itself for command-backed plugins (case-insensitive, like the reserved-name check).

func IsValidEnvName added in v0.3.0

func IsValidEnvName(name string) bool

IsValidEnvName reports whether name is a POSIX environment identifier.

func ValidateEnvName added in v0.3.0

func ValidateEnvName(name string) error

ValidateEnvName returns an error if name may not appear in policy env.allow: it must be an identifier and must not be a reserved loader/interpreter variable or a name the Application parameter environment owns (PATH, ARGOCD_APP_PARAMETERS, PARAM_*, LD_*, DYLD_*, ...).

Types

type ApplicationEnv added in v0.3.0

type ApplicationEnv struct {
	Allow []string
}

ApplicationEnv allowlists Application-authored spec.source.plugin.env NAMES for command-backed engines. Allowed entries reach the plugin as ARGOCD_ENV_<name> after substitution against the Argo CD build environment, exactly as a repo-server delivers them; the prefix keeps them apart from env.allow (drydock's own process environment) and from every reserved name.

type Bootstrap added in v0.1.14

type Bootstrap struct {
	Entrypoints []BootstrapEntrypoint
}

type BootstrapEntrypoint added in v0.1.14

type BootstrapEntrypoint struct {
	Name       string
	Plugin     string
	SourcePath string
	Parameters []BootstrapParameter
}

type BootstrapParameter added in v0.1.14

type BootstrapParameter struct {
	Name   string
	String *string
	Array  *BootstrapParameterArray
	Map    *BootstrapParameterMap
}

type BootstrapParameterArray added in v0.1.14

type BootstrapParameterArray struct {
	Values []string
}

type BootstrapParameterMap added in v0.1.14

type BootstrapParameterMap struct {
	Values map[string]string
}

type ConfigManagementPluginGenerate added in v0.1.14

type ConfigManagementPluginGenerate struct {
	Command []string
	Args    []string
}

type ConfigManagementPluginSeed added in v0.1.14

type ConfigManagementPluginSeed struct {
	Discover *PluginDiscoverMatch
	Generate *ConfigManagementPluginGenerate
}

type ContainerCacheMount added in v0.1.14

type ContainerCacheMount struct {
	Name   string
	Target string
}

type ContainerConfig added in v0.1.14

type ContainerConfig struct {
	Runtime              ContainerRuntime
	Image                string
	AllowMutableImageTag bool
	Network              ContainerNetwork
	CacheMounts          []ContainerCacheMount
	Lifecycle            ExecConfig
}

type ContainerNetwork added in v0.1.14

type ContainerNetwork string
const (
	ContainerNetworkNone    ContainerNetwork = "none"
	ContainerNetworkDefault ContainerNetwork = "default"
)

type ContainerRuntime added in v0.1.14

type ContainerRuntime string
const (
	ContainerRuntimeDocker ContainerRuntime = "docker"
)

type Engine

type Engine string
const (
	EngineAVPCompat       Engine = "avp-compat"
	EngineNativeKustomize Engine = "native-kustomize"
	EngineExec            Engine = "exec"
	EngineContainer       Engine = "container"
)

type ExecCommand

type ExecCommand struct {
	Command []string
	Timeout time.Duration
}

type ExecConfig

type ExecConfig struct {
	Workdir        string
	Copy           ExecCopy
	Init           *ExecCommand
	Generate       ExecCommand
	PostRenderers  []ExecCommand
	Env            ExecEnv
	ApplicationEnv ApplicationEnv
	Parameters     ExecParameters
	Output         ExecOutput
}

type ExecCopy added in v0.1.14

type ExecCopy struct {
	Scope   string
	Include []string
}

type ExecEnv

type ExecEnv struct {
	Allow []string
}

type ExecOutput

type ExecOutput struct {
	MaxStdoutBytes int64
	MaxStderrBytes int64
}

type ExecParameter added in v0.1.14

type ExecParameter struct {
	Name     string
	Type     ExecParameterType
	Required bool
	Path     *ExecParameterPath
}

type ExecParameterPath added in v0.1.14

type ExecParameterPath struct {
	Base  string
	Allow []string
}

type ExecParameterType added in v0.1.14

type ExecParameterType string
const (
	ExecParameterTypeString ExecParameterType = "string"
	ExecParameterTypeArray  ExecParameterType = "array"
	ExecParameterTypeMap    ExecParameterType = "map"
)

type ExecParameters added in v0.1.14

type ExecParameters struct {
	Allow []ExecParameter
}

type Plugin

type Plugin struct {
	Engine                 Engine
	Match                  *PluginMatch
	ConfigManagementPlugin *ConfigManagementPluginSeed
	Exec                   *ExecConfig
	Container              *ContainerConfig
}

type PluginDiscoverMatch added in v0.1.14

type PluginDiscoverMatch struct {
	FileName string
	FindGlob string
}

type PluginMatch added in v0.1.14

type PluginMatch struct {
	Discover PluginDiscoverMatch
}

type Policy

type Policy struct {
	Bootstrap Bootstrap
	Plugins   map[string]Plugin
	// Warnings are non-fatal findings from Parse, such as env.allow entries
	// drydock manages itself; callers surface them as warning diagnostics.
	Warnings []string
}

func Parse

func Parse(path string, data []byte) (Policy, error)

func (Policy) Plugin

func (p Policy) Plugin(name string) (Plugin, bool)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL