Documentation
¶
Index ¶
- func ByName(projects []argoappv1.AppProject) map[string]argoappv1.AppProject
- func NormalizeClusterServer(raw string) string
- func ValidateApplications(apps []argoappv1.Application, projects []argoappv1.AppProject, ...) []diagnostic.Diagnostic
- func ValidateRenderedResourcePolicy(app argoappv1.Application, objects []*unstructured.Unstructured, ...) []diagnostic.Diagnostic
- func ValidateRenderedResourcePolicyResources(app argoappv1.Application, resources []RenderedResource, ...) []diagnostic.Diagnostic
- func ValidateRenderedResourcePolicyResourcesWithRegistry(app argoappv1.Application, resources []RenderedResource, ...) []diagnostic.Diagnostic
- type RenderedResource
- type RepositoryMatch
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ByName ¶ added in v0.3.2
func ByName(projects []argoappv1.AppProject) map[string]argoappv1.AppProject
ByName indexes projects the way validation looks an Application's AppProject up: by name alone, the last one winning, skipping any without a name.
func NormalizeClusterServer ¶ added in v0.3.4
NormalizeClusterServer normalizes a cluster server the way validation looks a destination server up among the cluster Secrets.
func ValidateApplications ¶
func ValidateApplications(apps []argoappv1.Application, projects []argoappv1.AppProject, settings config.ArgoSettings) []diagnostic.Diagnostic
func ValidateRenderedResourcePolicy ¶ added in v0.1.18
func ValidateRenderedResourcePolicy(app argoappv1.Application, objects []*unstructured.Unstructured, projects []argoappv1.AppProject, settings config.ArgoSettings) []diagnostic.Diagnostic
ValidateRenderedResourcePolicy validates rendered Kubernetes objects for one Application against its effective AppProject resource policy.
func ValidateRenderedResourcePolicyResources ¶ added in v0.1.18
func ValidateRenderedResourcePolicyResources(app argoappv1.Application, resources []RenderedResource, projects []argoappv1.AppProject, settings config.ArgoSettings) []diagnostic.Diagnostic
ValidateRenderedResourcePolicyResources validates rendered Kubernetes objects with pre-normalization metadata.
func ValidateRenderedResourcePolicyResourcesWithRegistry ¶ added in v0.2.1
func ValidateRenderedResourcePolicyResourcesWithRegistry(app argoappv1.Application, resources []RenderedResource, projects []argoappv1.AppProject, settings config.ArgoSettings, registry manifest.CRDScopeRegistry) []diagnostic.Diagnostic
ValidateRenderedResourcePolicyResourcesWithRegistry validates rendered Kubernetes objects with pre-normalization metadata, consulting the provided CRDScopeRegistry to resolve CR scope before falling back to deferral. A nil registry is safe and preserves the existing deferral behavior.
Types ¶
type RenderedResource ¶ added in v0.1.18
type RenderedResource struct {
Object *unstructured.Unstructured
NamespaceBeforeNormalization string
}
RenderedResource carries rendered object metadata that can be lost during Argo-style normalization.
type RepositoryMatch ¶ added in v0.3.4
type RepositoryMatch struct {
// contains filtered or unexported fields
}
RepositoryMatch is one repository entry, normalized once, as validation applies it: as the repository metadata of a source URL (repositorySettingsForURL) and as the sourceRepos entry it adds to its AppProject (effectiveProject).
func NewRepositoryMatch ¶ added in v0.3.4
func NewRepositoryMatch(key string, repo config.RepositorySettings) RepositoryMatch
NewRepositoryMatch normalizes the repository entry key and repo.
func (RepositoryMatch) Reaches ¶ added in v0.3.4
func (m RepositoryMatch) Reaches(app argoappv1.Application) bool
Reaches reports whether validation applies the entry to app: as the repository metadata of one of its sources, or, when app is in the entry's project, through the sourceRepos entry it adds there, which Argo CD matches as a normalized glob. A deny pattern (!url) there reaches every source: it denies the sources it names and, through Argo CD's negation, permits the rest (AppProject.IsSourcePermitted). One scoped to the default project reaches every Application: with no AppProject declared, each validates against the implicit default project, whatever project it names.