-
Notifications
You must be signed in to change notification settings - Fork 26
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Make the admission webhook run #3
Changes from 1 commit
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -31,6 +31,7 @@ func NewNamespaceReservationServerOptions(out, errOut io.Writer) *NamespaceReser | |
StdOut: out, | ||
StdErr: errOut, | ||
} | ||
o.RecommendedOptions.Etcd = nil | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Thanks @sttts |
||
|
||
return o | ||
} | ||
|
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,78 @@ | ||
package admissionreview | ||
|
||
import ( | ||
"fmt" | ||
|
||
"net/http" | ||
|
||
"encoding/json" | ||
|
||
admissionv1alpha1 "k8s.io/api/admission/v1alpha1" | ||
"k8s.io/apimachinery/pkg/api/errors" | ||
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" | ||
"k8s.io/apimachinery/pkg/runtime" | ||
apirequest "k8s.io/apiserver/pkg/endpoints/request" | ||
"k8s.io/apiserver/pkg/registry/rest" | ||
) | ||
|
||
type REST struct { | ||
} | ||
|
||
var _ rest.Creater = &REST{} | ||
|
||
func NewREST() *REST { | ||
return &REST{} | ||
} | ||
|
||
func (r *REST) New() runtime.Object { | ||
return &admissionv1alpha1.AdmissionReview{} | ||
} | ||
|
||
func (r *REST) Create(ctx apirequest.Context, obj runtime.Object, _ bool) (runtime.Object, error) { | ||
fmt.Printf("#### got %#v\n", obj) | ||
|
||
admissionReview := obj.(*admissionv1alpha1.AdmissionReview) | ||
if admissionReview.Spec.Resource.Group != "project.openshift.io" || | ||
admissionReview.Spec.Resource.Resource != "projectrequests" || | ||
len(admissionReview.Spec.SubResource) != 0 || | ||
admissionReview.Spec.Operation != admissionv1alpha1.Create { | ||
|
||
admissionReview.Status.Allowed = true | ||
return admissionReview, nil | ||
} | ||
|
||
admittingObjectName := &NamedThing{} | ||
err := json.Unmarshal(admissionReview.Spec.Object.Raw, admittingObjectName) | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Can't use a normal metadata path because the admission webhook is broken. |
||
if err != nil { | ||
return nil, errors.NewBadRequest(err.Error()) | ||
} | ||
|
||
if len(admittingObjectName.Name) == 0 { | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fail closed on empty name. might be generated later, but this fails anyway. |
||
admissionReview.Status.Allowed = false | ||
admissionReview.Status.Result = &metav1.Status{ | ||
Status: metav1.StatusFailure, | ||
Code: http.StatusForbidden, | ||
Reason: metav1.StatusReasonForbidden, | ||
Message: "name is required", | ||
} | ||
return admissionReview, nil | ||
} | ||
|
||
if admittingObjectName.Name == "fail-me" { | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. proof that it works. To be updated later |
||
admissionReview.Status.Allowed = false | ||
admissionReview.Status.Result = &metav1.Status{ | ||
Status: metav1.StatusFailure, | ||
Code: http.StatusForbidden, | ||
Reason: metav1.StatusReasonForbidden, | ||
Message: fmt.Sprintf("%q is reserved", admittingObjectName.Name), | ||
} | ||
return admissionReview, nil | ||
} | ||
|
||
admissionReview.Status.Allowed = true | ||
return admissionReview, nil | ||
} | ||
|
||
type NamedThing struct { | ||
Name string `json:name` | ||
} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@smarterclayton this tricks the REST handler code into decoding the object we want, but it is a side-effect, not intent. I think we should officially allow the intent.