From dbb9a803300caad56d6d208a37fa8de6f657b515 Mon Sep 17 00:00:00 2001 From: Abu Kashem Date: Thu, 23 Jul 2020 10:51:19 -0400 Subject: [PATCH 1/2] vendor openshift/api --- go.mod | 2 +- go.sum | 2 + ...0_10_config-operator_01_apiserver.crd.yaml | 19 ++ ...config-operator_01_infrastructure.crd.yaml | 17 +- .../api/config/v1/types_apiserver.go | 35 ++++ .../api/config/v1/types_infrastructure.go | 8 +- .../api/config/v1/zz_generated.deepcopy.go | 17 ++ .../v1/zz_generated.swagger_doc_generated.go | 13 +- ...0_90_cluster_csi_driver_01_config.crd.yaml | 164 ++++++++++++++++++ ..._csi_driver_01_config.crd.yaml-merge-patch | 12 ++ .../openshift/api/operator/v1/register.go | 2 + .../operator/v1/types_csi_cluster_driver.go | 80 +++++++++ .../api/operator/v1/zz_generated.deepcopy.go | 112 ++++++++++++ .../v1/zz_generated.swagger_doc_generated.go | 43 +++++ vendor/modules.txt | 2 +- 15 files changed, 512 insertions(+), 16 deletions(-) create mode 100644 vendor/github.com/openshift/api/operator/v1/0000_90_cluster_csi_driver_01_config.crd.yaml create mode 100644 vendor/github.com/openshift/api/operator/v1/0000_90_cluster_csi_driver_01_config.crd.yaml-merge-patch create mode 100644 vendor/github.com/openshift/api/operator/v1/types_csi_cluster_driver.go diff --git a/go.mod b/go.mod index 56c559eb1c..aa4757b08f 100644 --- a/go.mod +++ b/go.mod @@ -36,7 +36,7 @@ require ( github.com/opencontainers/go-digest v1.0.0-rc1 github.com/opencontainers/image-spec v1.0.1 // indirect github.com/opencontainers/runc v0.0.0-20191031171055-b133feaeeb2e // indirect - github.com/openshift/api v0.0.0-20200722170803-0ba2c3658da6 + github.com/openshift/api v0.0.0-20200723134351-89de68875e7c github.com/openshift/build-machinery-go v0.0.0-20200713135615-1f43d26dccc7 github.com/openshift/client-go v0.0.0-20200722173614-5a1b0aaeff15 github.com/pkg/errors v0.9.1 diff --git a/go.sum b/go.sum index e62babcfe7..f186b45e38 100644 --- a/go.sum +++ b/go.sum @@ -396,6 +396,8 @@ github.com/opencontainers/runc v0.0.0-20191031171055-b133feaeeb2e h1:NKMVwQeEqNO github.com/opencontainers/runc v0.0.0-20191031171055-b133feaeeb2e/go.mod h1:qT5XzbpPznkRYVz/mWwUaVBUv2rmF59PVA73FjuZG0U= github.com/openshift/api v0.0.0-20200722170803-0ba2c3658da6 h1:h2zOwAA/Zg7mc9d16q6W7/mcJppctFyqvHeE6vz1Qys= github.com/openshift/api v0.0.0-20200722170803-0ba2c3658da6/go.mod h1:IXsT3F4NjLtRzfnQvwU+g/oPWpoNsVV5vd5aaOMO8eU= +github.com/openshift/api v0.0.0-20200723134351-89de68875e7c h1:qsj/GaQ1sdT584yIcGmqqRpR5xtX5jTw5Gis3/09YI4= +github.com/openshift/api v0.0.0-20200723134351-89de68875e7c/go.mod h1:IXsT3F4NjLtRzfnQvwU+g/oPWpoNsVV5vd5aaOMO8eU= github.com/openshift/build-machinery-go v0.0.0-20200713135615-1f43d26dccc7 h1:iP7TOaN+tEVNUQ0ODEbN1ukjLz918lsIt7Czf8giWlM= github.com/openshift/build-machinery-go v0.0.0-20200713135615-1f43d26dccc7/go.mod h1:b1BuldmJlbA/xYtdZvKi+7j5YGB44qJUJDZ9zwiNCfE= github.com/openshift/client-go v0.0.0-20200722173614-5a1b0aaeff15 h1:b2QkHrmaYtY6kzy2VrYLc+KBmCuTpJjgvBahPqpt6V0= diff --git a/vendor/github.com/openshift/api/config/v1/0000_10_config-operator_01_apiserver.crd.yaml b/vendor/github.com/openshift/api/config/v1/0000_10_config-operator_01_apiserver.crd.yaml index 398292f0df..a4f505e103 100644 --- a/vendor/github.com/openshift/api/config/v1/0000_10_config-operator_01_apiserver.crd.yaml +++ b/vendor/github.com/openshift/api/config/v1/0000_10_config-operator_01_apiserver.crd.yaml @@ -53,6 +53,25 @@ spec: type: array items: type: string + audit: + description: audit specifies the settings for audit configuration to + be applied to all OpenShift-provided API servers in the cluster. + type: object + default: + profile: Default + properties: + profile: + description: "profile specifies the name of the desired audit policy + configuration to be deployed to all OpenShift-provided API servers + in the cluster \n We provide the following profiles - Default + - WriteRequestBodies - AllRequestBodies If unset, the 'Default' + profile is used as the default." + type: string + default: Default + enum: + - Default + - WriteRequestBodies + - AllRequestBodies clientCA: description: 'clientCA references a ConfigMap containing a certificate bundle for the signers that will be recognized for incoming client diff --git a/vendor/github.com/openshift/api/config/v1/0000_10_config-operator_01_infrastructure.crd.yaml b/vendor/github.com/openshift/api/config/v1/0000_10_config-operator_01_infrastructure.crd.yaml index 4c9a9e25e3..2ef761958a 100644 --- a/vendor/github.com/openshift/api/config/v1/0000_10_config-operator_01_infrastructure.crd.yaml +++ b/vendor/github.com/openshift/api/config/v1/0000_10_config-operator_01_infrastructure.crd.yaml @@ -151,16 +151,17 @@ spec: type: object properties: apiServerInternalURI: - description: apiServerInternalURL is a valid URI with scheme(http/https), - address and port. apiServerInternalURL can be used by components - like kubelets, to contact the Kubernetes API server using the infrastructure - provider rather than Kubernetes networking. + description: apiServerInternalURL is a valid URI with scheme 'https', + address and optionally a port (defaulting to 443). apiServerInternalURL + can be used by components like kubelets, to contact the Kubernetes + API server using the infrastructure provider rather than Kubernetes + networking. type: string apiServerURL: - description: apiServerURL is a valid URI with scheme(http/https), address - and optionally a port (defaulting to 80 for http and 443 for https). apiServerURL - can be used by components like the web console to tell users where - to find the Kubernetes API. + description: apiServerURL is a valid URI with scheme 'https', address + and optionally a port (defaulting to 443). apiServerURL can be used + by components like the web console to tell users where to find the + Kubernetes API. type: string etcdDiscoveryDomain: description: 'etcdDiscoveryDomain is the domain used to fetch the SRV diff --git a/vendor/github.com/openshift/api/config/v1/types_apiserver.go b/vendor/github.com/openshift/api/config/v1/types_apiserver.go index 2fffa794b3..58dc811db9 100644 --- a/vendor/github.com/openshift/api/config/v1/types_apiserver.go +++ b/vendor/github.com/openshift/api/config/v1/types_apiserver.go @@ -51,6 +51,41 @@ type APIServerSpec struct { // is VersionTLS12. // +optional TLSSecurityProfile *TLSSecurityProfile `json:"tlsSecurityProfile,omitempty"` + // audit specifies the settings for audit configuration to be applied to all OpenShift-provided + // API servers in the cluster. + // +optional + // +kubebuilder:default={profile: Default} + Audit Audit `json:"audit"` +} + +// AuditProfileType defines the audit policy profile type. +// +kubebuilder:validation:Enum=Default;WriteRequestBodies;AllRequestBodies +type AuditProfileType string + +const ( + // "Default" is the existing default audit configuration policy. + AuditProfileDefaultType AuditProfileType = "Default" + + // "WriteRequestBodies" is similar to Default but it logs request and response + // HTTP payloads for write requests (create, update, patch) + WriteRequestBodiesAuditProfileType AuditProfileType = "WriteRequestBodies" + + // "AllRequestBodies" is similar to WriteRequestBodies, but also logs request + // and response HTTP payloads for read requests (get, list). + AllRequestBodiesAuditProfileType AuditProfileType = "AllRequestBodies" +) + +type Audit struct { + // profile specifies the name of the desired audit policy configuration to be deployed to + // all OpenShift-provided API servers in the cluster + // + // We provide the following profiles + // - Default + // - WriteRequestBodies + // - AllRequestBodies + // If unset, the 'Default' profile is used as the default. + // +kubebuilder:default=Default + Profile AuditProfileType `json:"profile,omitempty"` } type APIServerServingCerts struct { diff --git a/vendor/github.com/openshift/api/config/v1/types_infrastructure.go b/vendor/github.com/openshift/api/config/v1/types_infrastructure.go index 97761549d3..3c4bd788ff 100644 --- a/vendor/github.com/openshift/api/config/v1/types_infrastructure.go +++ b/vendor/github.com/openshift/api/config/v1/types_infrastructure.go @@ -66,13 +66,13 @@ type InfrastructureStatus struct { // For more info: https://github.com/etcd-io/etcd/blob/329be66e8b3f9e2e6af83c123ff89297e49ebd15/Documentation/op-guide/clustering.md#dns-discovery EtcdDiscoveryDomain string `json:"etcdDiscoveryDomain"` - // apiServerURL is a valid URI with scheme(http/https), address and - // optionally a port (defaulting to 80 for http and 443 for https). apiServerURL can be used by components like the web console + // apiServerURL is a valid URI with scheme 'https', address and + // optionally a port (defaulting to 443). apiServerURL can be used by components like the web console // to tell users where to find the Kubernetes API. APIServerURL string `json:"apiServerURL"` - // apiServerInternalURL is a valid URI with scheme(http/https), - // address and port. apiServerInternalURL can be used by components + // apiServerInternalURL is a valid URI with scheme 'https', + // address and optionally a port (defaulting to 443). apiServerInternalURL can be used by components // like kubelets, to contact the Kubernetes API server using the // infrastructure provider rather than Kubernetes networking. APIServerInternalURL string `json:"apiServerInternalURI"` diff --git a/vendor/github.com/openshift/api/config/v1/zz_generated.deepcopy.go b/vendor/github.com/openshift/api/config/v1/zz_generated.deepcopy.go index 24a4fd27cb..b81e4cc1fd 100644 --- a/vendor/github.com/openshift/api/config/v1/zz_generated.deepcopy.go +++ b/vendor/github.com/openshift/api/config/v1/zz_generated.deepcopy.go @@ -148,6 +148,7 @@ func (in *APIServerSpec) DeepCopyInto(out *APIServerSpec) { *out = new(TLSSecurityProfile) (*in).DeepCopyInto(*out) } + out.Audit = in.Audit return } @@ -285,6 +286,22 @@ func (in *AdmissionPluginConfig) DeepCopy() *AdmissionPluginConfig { return out } +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *Audit) DeepCopyInto(out *Audit) { + *out = *in + return +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Audit. +func (in *Audit) DeepCopy() *Audit { + if in == nil { + return nil + } + out := new(Audit) + in.DeepCopyInto(out) + return out +} + // DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. func (in *AuditConfig) DeepCopyInto(out *AuditConfig) { *out = *in diff --git a/vendor/github.com/openshift/api/config/v1/zz_generated.swagger_doc_generated.go b/vendor/github.com/openshift/api/config/v1/zz_generated.swagger_doc_generated.go index dc72d5f9ba..e1a47303a4 100644 --- a/vendor/github.com/openshift/api/config/v1/zz_generated.swagger_doc_generated.go +++ b/vendor/github.com/openshift/api/config/v1/zz_generated.swagger_doc_generated.go @@ -285,12 +285,21 @@ var map_APIServerSpec = map[string]string{ "additionalCORSAllowedOrigins": "additionalCORSAllowedOrigins lists additional, user-defined regular expressions describing hosts for which the API server allows access using the CORS headers. This may be needed to access the API and the integrated OAuth server from JavaScript applications. The values are regular expressions that correspond to the Golang regular expression language.", "encryption": "encryption allows the configuration of encryption of resources at the datastore layer.", "tlsSecurityProfile": "tlsSecurityProfile specifies settings for TLS connections for externally exposed servers.\n\nIf unset, a default (which may change between releases) is chosen. Note that only Old and Intermediate profiles are currently supported, and the maximum available MinTLSVersions is VersionTLS12.", + "audit": "audit specifies the settings for audit configuration to be applied to all OpenShift-provided API servers in the cluster.", } func (APIServerSpec) SwaggerDoc() map[string]string { return map_APIServerSpec } +var map_Audit = map[string]string{ + "profile": "profile specifies the name of the desired audit policy configuration to be deployed to all OpenShift-provided API servers in the cluster\n\nWe provide the following profiles - Default - WriteRequestBodies - AllRequestBodies If unset, the 'Default' profile is used as the default.", +} + +func (Audit) SwaggerDoc() map[string]string { + return map_Audit +} + var map_Authentication = map[string]string{ "": "Authentication specifies cluster-wide settings for authentication (like OAuth and webhook token authenticators). The canonical name of an instance is `cluster`.", "spec": "spec holds user settable values for configuration", @@ -828,8 +837,8 @@ var map_InfrastructureStatus = map[string]string{ "platform": "platform is the underlying infrastructure provider for the cluster.\n\nDeprecated: Use platformStatus.type instead.", "platformStatus": "platformStatus holds status information specific to the underlying infrastructure provider.", "etcdDiscoveryDomain": "etcdDiscoveryDomain is the domain used to fetch the SRV records for discovering etcd servers and clients. For more info: https://github.com/etcd-io/etcd/blob/329be66e8b3f9e2e6af83c123ff89297e49ebd15/Documentation/op-guide/clustering.md#dns-discovery", - "apiServerURL": "apiServerURL is a valid URI with scheme(http/https), address and optionally a port (defaulting to 80 for http and 443 for https). apiServerURL can be used by components like the web console to tell users where to find the Kubernetes API.", - "apiServerInternalURI": "apiServerInternalURL is a valid URI with scheme(http/https), address and port. apiServerInternalURL can be used by components like kubelets, to contact the Kubernetes API server using the infrastructure provider rather than Kubernetes networking.", + "apiServerURL": "apiServerURL is a valid URI with scheme 'https', address and optionally a port (defaulting to 443). apiServerURL can be used by components like the web console to tell users where to find the Kubernetes API.", + "apiServerInternalURI": "apiServerInternalURL is a valid URI with scheme 'https', address and optionally a port (defaulting to 443). apiServerInternalURL can be used by components like kubelets, to contact the Kubernetes API server using the infrastructure provider rather than Kubernetes networking.", } func (InfrastructureStatus) SwaggerDoc() map[string]string { diff --git a/vendor/github.com/openshift/api/operator/v1/0000_90_cluster_csi_driver_01_config.crd.yaml b/vendor/github.com/openshift/api/operator/v1/0000_90_cluster_csi_driver_01_config.crd.yaml new file mode 100644 index 0000000000..b58c93ed28 --- /dev/null +++ b/vendor/github.com/openshift/api/operator/v1/0000_90_cluster_csi_driver_01_config.crd.yaml @@ -0,0 +1,164 @@ +apiVersion: apiextensions.k8s.io/v1beta1 +kind: CustomResourceDefinition +metadata: + name: clustercsidrivers.operator.openshift.io +spec: + group: operator.openshift.io + names: + kind: ClusterCSIDriver + plural: clustercsidrivers + singular: clustercsidriver + preserveUnknownFields: false + scope: Cluster + subresources: + status: {} + validation: + openAPIV3Schema: + description: ClusterCSIDriver object allows management and configuration of + a CSI driver operator installed by default in OpenShift. + properties: + apiVersion: + description: 'APIVersion defines the versioned schema of this representation + of an object. Servers should convert recognized schemas to the latest + internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources' + type: string + kind: + description: 'Kind is a string value representing the REST resource this + object represents. Servers may infer this from the endpoint the client + submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds' + type: string + metadata: + properties: + name: + enum: + - ebs.csi.aws.com-ebs + - manila.csi.openstack.org + - csi.ovirt.org + type: string + type: object + spec: + description: spec holds user settable values for configuration + properties: + driverConfig: + description: CSIDriverConfig is the CSI driver specific configuration + properties: + driverName: + description: DriverName holds the name of the CSI driver + enum: + - ebs.csi.aws.com-ebs + - manila.csi.openstack.org + - csi.ovirt.org + type: string + required: + - driverName + type: object + logLevel: + description: logLevel is an intent based logging for an overall component. It + does not give fine grained control, but it is a simple way to manage + coarse grained logging choices that operators have to interpret for + their operands. + type: string + managementState: + description: managementState indicates whether and how the operator + should manage the component + pattern: ^(Managed|Unmanaged|Force|Removed)$ + type: string + observedConfig: + description: observedConfig holds a sparse config that controller has + observed from the cluster state. It exists in spec because it is + an input to the level for the operator + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + operatorLogLevel: + description: operatorLogLevel is an intent based logging for the operator + itself. It does not give fine grained control, but it is a simple + way to manage coarse grained logging choices that operators have to + interpret for themselves. + type: string + unsupportedConfigOverrides: + description: 'unsupportedConfigOverrides holds a sparse config that + will override any previously set options. It only needs to be the + fields to override it will end up overlaying in the following order: + 1. hardcoded defaults 2. observedConfig 3. unsupportedConfigOverrides' + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + required: + - driverConfig + type: object + status: + description: status holds observed values from the cluster. They may not + be overridden. + properties: + conditions: + description: conditions is a list of conditions and their status + items: + description: OperatorCondition is just the standard condition fields. + properties: + lastTransitionTime: + format: date-time + type: string + message: + type: string + reason: + type: string + status: + type: string + type: + type: string + type: object + type: array + generations: + description: generations are used to determine when an item needs to + be reconciled or has changed in a way that needs a reaction. + items: + description: GenerationStatus keeps track of the generation for a + given resource so that decisions about forced updates can be made. + properties: + group: + description: group is the group of the thing you're tracking + type: string + hash: + description: hash is an optional field set for resources without + generation that are content sensitive like secrets and configmaps + type: string + lastGeneration: + description: lastGeneration is the last generation of the workload + controller involved + format: int64 + type: integer + name: + description: name is the name of the thing you're tracking + type: string + namespace: + description: namespace is where the thing you're tracking is + type: string + resource: + description: resource is the resource type of the thing you're + tracking + type: string + type: object + type: array + observedGeneration: + description: observedGeneration is the last generation change you've + dealt with + format: int64 + type: integer + readyReplicas: + description: readyReplicas indicates how many replicas are ready and + at the desired state + format: int32 + type: integer + version: + description: version is the level this availability applies to + type: string + type: object + required: + - spec + type: object + version: v1 + versions: + - name: v1 + served: true + storage: true diff --git a/vendor/github.com/openshift/api/operator/v1/0000_90_cluster_csi_driver_01_config.crd.yaml-merge-patch b/vendor/github.com/openshift/api/operator/v1/0000_90_cluster_csi_driver_01_config.crd.yaml-merge-patch new file mode 100644 index 0000000000..d092b41102 --- /dev/null +++ b/vendor/github.com/openshift/api/operator/v1/0000_90_cluster_csi_driver_01_config.crd.yaml-merge-patch @@ -0,0 +1,12 @@ +spec: + validation: + openAPIV3Schema: + properties: + metadata: + properties: + name: + type: string + enum: + - ebs.csi.aws.com-ebs + - manila.csi.openstack.org + - csi.ovirt.org diff --git a/vendor/github.com/openshift/api/operator/v1/register.go b/vendor/github.com/openshift/api/operator/v1/register.go index 140cb5854d..b7b13b76a6 100644 --- a/vendor/github.com/openshift/api/operator/v1/register.go +++ b/vendor/github.com/openshift/api/operator/v1/register.go @@ -36,6 +36,8 @@ func addKnownTypes(scheme *runtime.Scheme) error { &AuthenticationList{}, &DNS{}, &DNSList{}, + &ClusterCSIDriver{}, + &ClusterCSIDriverList{}, &Console{}, &ConsoleList{}, &CSISnapshotController{}, diff --git a/vendor/github.com/openshift/api/operator/v1/types_csi_cluster_driver.go b/vendor/github.com/openshift/api/operator/v1/types_csi_cluster_driver.go new file mode 100644 index 0000000000..befd3da6da --- /dev/null +++ b/vendor/github.com/openshift/api/operator/v1/types_csi_cluster_driver.go @@ -0,0 +1,80 @@ +package v1 + +import ( + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" +) + +// ClusterCSIDriver is used to manage and configure CSI driver installed by default +// in OpenShift. An example configuration may look like: +// apiVersion: operator.openshift.io/v1alpha1 +// kind: "ClusterCSIDriver" +// metadata: +// name: "ebs.csi.aws.com-ebs" +// spec: +// logLevel: Debug +// driverConfig: +// driverName: "ebs.csi.aws.com-ebs" + +// +genclient +// +genclient:nonNamespaced +// +k8s:deepcopy-gen:interfaces=k8s.io/apimachinery/pkg/runtime.Object + +// ClusterCSIDriver object allows management and configuration of a CSI driver operator +// installed by default in OpenShift. +type ClusterCSIDriver struct { + metav1.TypeMeta `json:",inline"` + metav1.ObjectMeta `json:"metadata,omitempty"` + + // spec holds user settable values for configuration + // +kubebuilder:validation:Required + // +required + Spec ClusterCSIDriverSpec `json:"spec"` + + // status holds observed values from the cluster. They may not be overridden. + // +optional + Status ClusterCSIDriverStatus `json:"status"` +} + +// CSIDriverName is the name of the CSI driver +// +kubebuilder:validation:Enum=ebs.csi.aws.com-ebs;manila.csi.openstack.org;csi.ovirt.org +type CSIDriverName string + +// If you are adding a new driver name here, ensure that kubebuilder:validation:Enum is updated above +// and 0000_90_cluster_csi_driver_01_config.crd.yaml-merge-patch file is also updated with new driver name. +const ( + AWSEBSCSIDriver CSIDriverName = "ebs.csi.aws.com-ebs" + ManilaCSIDriver CSIDriverName = "manila.csi.openstack.org" + OvirtCSIDriver CSIDriverName = "csi.ovirt.org" +) + +// ClusterCSIDriverSpec is the desired behavior of CSI driver operator +type ClusterCSIDriverSpec struct { + OperatorSpec `json:",inline"` + // +kubebuilder:validation:Required + // +required + DriverConfig CSIDriverConfig `json:"driverConfig"` +} + +// ClusterCSIDriverStatus is the observed status of CSI driver operator +type ClusterCSIDriverStatus struct { + OperatorStatus `json:",inline"` +} + +// CSIDriverConfig is the CSI driver specific configuration +type CSIDriverConfig struct { + // DriverName holds the name of the CSI driver + // +kubebuilder:validation:Required + // +unionDiscriminator + // +required + DriverName CSIDriverName `json:"driverName"` +} + +// +k8s:deepcopy-gen:interfaces=k8s.io/apimachinery/pkg/runtime.Object +// +kubebuilder:object:root=true + +// ClusterCSIDriverList contains a list of ClusterCSIDriver +type ClusterCSIDriverList struct { + metav1.TypeMeta `json:",inline"` + metav1.ListMeta `json:"metadata,omitempty"` + Items []ClusterCSIDriver `json:"items"` +} diff --git a/vendor/github.com/openshift/api/operator/v1/zz_generated.deepcopy.go b/vendor/github.com/openshift/api/operator/v1/zz_generated.deepcopy.go index f05daeea05..ab73668bc2 100644 --- a/vendor/github.com/openshift/api/operator/v1/zz_generated.deepcopy.go +++ b/vendor/github.com/openshift/api/operator/v1/zz_generated.deepcopy.go @@ -203,6 +203,22 @@ func (in *AuthenticationStatus) DeepCopy() *AuthenticationStatus { return out } +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *CSIDriverConfig) DeepCopyInto(out *CSIDriverConfig) { + *out = *in + return +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new CSIDriverConfig. +func (in *CSIDriverConfig) DeepCopy() *CSIDriverConfig { + if in == nil { + return nil + } + out := new(CSIDriverConfig) + in.DeepCopyInto(out) + return out +} + // DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. func (in *CSISnapshotController) DeepCopyInto(out *CSISnapshotController) { *out = *in @@ -298,6 +314,102 @@ func (in *CSISnapshotControllerStatus) DeepCopy() *CSISnapshotControllerStatus { return out } +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *ClusterCSIDriver) DeepCopyInto(out *ClusterCSIDriver) { + *out = *in + out.TypeMeta = in.TypeMeta + in.ObjectMeta.DeepCopyInto(&out.ObjectMeta) + in.Spec.DeepCopyInto(&out.Spec) + in.Status.DeepCopyInto(&out.Status) + return +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ClusterCSIDriver. +func (in *ClusterCSIDriver) DeepCopy() *ClusterCSIDriver { + if in == nil { + return nil + } + out := new(ClusterCSIDriver) + in.DeepCopyInto(out) + return out +} + +// DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object. +func (in *ClusterCSIDriver) DeepCopyObject() runtime.Object { + if c := in.DeepCopy(); c != nil { + return c + } + return nil +} + +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *ClusterCSIDriverList) DeepCopyInto(out *ClusterCSIDriverList) { + *out = *in + out.TypeMeta = in.TypeMeta + in.ListMeta.DeepCopyInto(&out.ListMeta) + if in.Items != nil { + in, out := &in.Items, &out.Items + *out = make([]ClusterCSIDriver, len(*in)) + for i := range *in { + (*in)[i].DeepCopyInto(&(*out)[i]) + } + } + return +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ClusterCSIDriverList. +func (in *ClusterCSIDriverList) DeepCopy() *ClusterCSIDriverList { + if in == nil { + return nil + } + out := new(ClusterCSIDriverList) + in.DeepCopyInto(out) + return out +} + +// DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object. +func (in *ClusterCSIDriverList) DeepCopyObject() runtime.Object { + if c := in.DeepCopy(); c != nil { + return c + } + return nil +} + +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *ClusterCSIDriverSpec) DeepCopyInto(out *ClusterCSIDriverSpec) { + *out = *in + in.OperatorSpec.DeepCopyInto(&out.OperatorSpec) + out.DriverConfig = in.DriverConfig + return +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ClusterCSIDriverSpec. +func (in *ClusterCSIDriverSpec) DeepCopy() *ClusterCSIDriverSpec { + if in == nil { + return nil + } + out := new(ClusterCSIDriverSpec) + in.DeepCopyInto(out) + return out +} + +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *ClusterCSIDriverStatus) DeepCopyInto(out *ClusterCSIDriverStatus) { + *out = *in + in.OperatorStatus.DeepCopyInto(&out.OperatorStatus) + return +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ClusterCSIDriverStatus. +func (in *ClusterCSIDriverStatus) DeepCopy() *ClusterCSIDriverStatus { + if in == nil { + return nil + } + out := new(ClusterCSIDriverStatus) + in.DeepCopyInto(out) + return out +} + // DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. func (in *ClusterNetworkEntry) DeepCopyInto(out *ClusterNetworkEntry) { *out = *in diff --git a/vendor/github.com/openshift/api/operator/v1/zz_generated.swagger_doc_generated.go b/vendor/github.com/openshift/api/operator/v1/zz_generated.swagger_doc_generated.go index 144e714e0c..c3ba371d1d 100644 --- a/vendor/github.com/openshift/api/operator/v1/zz_generated.swagger_doc_generated.go +++ b/vendor/github.com/openshift/api/operator/v1/zz_generated.swagger_doc_generated.go @@ -220,6 +220,49 @@ func (StatuspageProvider) SwaggerDoc() map[string]string { return map_StatuspageProvider } +var map_CSIDriverConfig = map[string]string{ + "": "CSIDriverConfig is the CSI driver specific configuration", + "driverName": "DriverName holds the name of the CSI driver", +} + +func (CSIDriverConfig) SwaggerDoc() map[string]string { + return map_CSIDriverConfig +} + +var map_ClusterCSIDriver = map[string]string{ + "": "ClusterCSIDriver object allows management and configuration of a CSI driver operator installed by default in OpenShift.", + "spec": "spec holds user settable values for configuration", + "status": "status holds observed values from the cluster. They may not be overridden.", +} + +func (ClusterCSIDriver) SwaggerDoc() map[string]string { + return map_ClusterCSIDriver +} + +var map_ClusterCSIDriverList = map[string]string{ + "": "ClusterCSIDriverList contains a list of ClusterCSIDriver", +} + +func (ClusterCSIDriverList) SwaggerDoc() map[string]string { + return map_ClusterCSIDriverList +} + +var map_ClusterCSIDriverSpec = map[string]string{ + "": "ClusterCSIDriverSpec is the desired behavior of CSI driver operator", +} + +func (ClusterCSIDriverSpec) SwaggerDoc() map[string]string { + return map_ClusterCSIDriverSpec +} + +var map_ClusterCSIDriverStatus = map[string]string{ + "": "ClusterCSIDriverStatus is the observed status of CSI driver operator", +} + +func (ClusterCSIDriverStatus) SwaggerDoc() map[string]string { + return map_ClusterCSIDriverStatus +} + var map_CSISnapshotController = map[string]string{ "": "CSISnapshotController provides a means to configure an operator to manage the CSI snapshots. `cluster` is the canonical name.", "spec": "spec holds user settable values for configuration", diff --git a/vendor/modules.txt b/vendor/modules.txt index 9dd6b259d4..cd7431d0bc 100644 --- a/vendor/modules.txt +++ b/vendor/modules.txt @@ -226,7 +226,7 @@ github.com/opencontainers/image-spec/specs-go/v1 # github.com/opencontainers/runc v0.0.0-20191031171055-b133feaeeb2e github.com/opencontainers/runc/libcontainer/system github.com/opencontainers/runc/libcontainer/user -# github.com/openshift/api v0.0.0-20200722170803-0ba2c3658da6 +# github.com/openshift/api v0.0.0-20200723134351-89de68875e7c github.com/openshift/api github.com/openshift/api/apps github.com/openshift/api/apps/v1 From 4c05a68a45315ac19b27976e3eef20a494896118 Mon Sep 17 00:00:00 2001 From: Abu Kashem Date: Wed, 22 Jul 2020 14:09:20 -0400 Subject: [PATCH 2/2] add an audit policy observer --- .../configobserver/apiserver/observe_audit.go | 88 +++++++ .../apiserver/observe_audit_test.go | 218 ++++++++++++++++++ 2 files changed, 306 insertions(+) create mode 100644 pkg/operator/configobserver/apiserver/observe_audit.go create mode 100644 pkg/operator/configobserver/apiserver/observe_audit_test.go diff --git a/pkg/operator/configobserver/apiserver/observe_audit.go b/pkg/operator/configobserver/apiserver/observe_audit.go new file mode 100644 index 0000000000..39aa79cb62 --- /dev/null +++ b/pkg/operator/configobserver/apiserver/observe_audit.go @@ -0,0 +1,88 @@ +package apiserver + +import ( + "fmt" + + k8serrors "k8s.io/apimachinery/pkg/api/errors" + "k8s.io/apimachinery/pkg/apis/meta/v1/unstructured" + "k8s.io/klog/v2" + + "github.com/openshift/library-go/pkg/operator/configobserver" + "github.com/openshift/library-go/pkg/operator/events" +) + +// AuditPolicyPathGetterFunc allows the observer to be agnostic of the source of audit profile(s). +// The function returns the path to the audit policy file (associated with the +// given profile) in the static manifest folder. +type AuditPolicyPathGetterFunc func(profile string) (string, error) + +// NewAuditObserver returns an ObserveConfigFunc that observes the audit field of the APIServer resource +// and sets the apiServerArguments:audit-policy-file field for the apiserver appropriately. +func NewAuditObserver(pathGetter AuditPolicyPathGetterFunc) configobserver.ObserveConfigFunc { + var ( + apiServerArgumentsAuditPath = []string{"apiServerArguments", "audit-policy-file"} + ) + + return func(genericListers configobserver.Listers, recorder events.Recorder, existingConfig map[string]interface{}) (observed map[string]interface{}, _ []error) { + defer func() { + observed = configobserver.Pruned(observed, apiServerArgumentsAuditPath) + }() + + errs := []error{} + + // if the function encounters an error it returns existing/current config, which means that + // some other entity (default config in bindata ) must ensure to default the configuration. + // otherwise, the apiserver won't have a path to audit policy file and it will fail to start. + listers := genericListers.(APIServerLister) + apiServer, err := listers.APIServerLister().Get("cluster") + if err != nil { + if k8serrors.IsNotFound(err) { + klog.Warningf("apiserver.config.openshift.io/cluster: not found") + + return existingConfig, errs + } + + return existingConfig, append(errs, err) + } + + desiredProfile := string(apiServer.Spec.Audit.Profile) + if len(desiredProfile) == 0 { + // The specified Profile is empty, so let the defaulting layer choose a default for us. + return map[string]interface{}{}, errs + } + + desiredAuditPolicyPath, err := pathGetter(desiredProfile) + if err != nil { + return existingConfig, append(errs, fmt.Errorf("audit profile is not valid name=%s", desiredProfile)) + } + + currentAuditPolicyPath, err := getCurrentPolicyPath(existingConfig, apiServerArgumentsAuditPath...) + if err != nil { + return existingConfig, append(errs, fmt.Errorf("audit profile is not valid name=%s", desiredProfile)) + } + if desiredAuditPolicyPath == currentAuditPolicyPath { + return existingConfig, errs + } + + // we have a change of audit policy here! + observedConfig := map[string]interface{}{} + if err := unstructured.SetNestedStringSlice(observedConfig, []string{desiredAuditPolicyPath}, apiServerArgumentsAuditPath...); err != nil { + return existingConfig, append(errs, fmt.Errorf("failed to set desired audit profile in observed config name=%s", desiredProfile)) + } + + recorder.Eventf("ObserveAPIServerArgumentsAudit", "audit policy has been set to profile=%s", desiredProfile) + return observedConfig, errs + } +} + +func getCurrentPolicyPath(existing map[string]interface{}, fields ...string) (string, error) { + current, _, err := unstructured.NestedStringSlice(existing, fields...) + if err != nil { + return "", err + } + if len(current) == 0 { + return "", nil + } + + return current[0], nil +} diff --git a/pkg/operator/configobserver/apiserver/observe_audit_test.go b/pkg/operator/configobserver/apiserver/observe_audit_test.go new file mode 100644 index 0000000000..fb5f9db444 --- /dev/null +++ b/pkg/operator/configobserver/apiserver/observe_audit_test.go @@ -0,0 +1,218 @@ +package apiserver + +import ( + "fmt" + "strings" + "testing" + + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" + "k8s.io/apimachinery/pkg/apis/meta/v1/unstructured" + "k8s.io/client-go/tools/cache" + + configv1 "github.com/openshift/api/config/v1" + configlistersv1 "github.com/openshift/client-go/config/listers/config/v1" + "github.com/openshift/library-go/pkg/operator/events" +) + +var ( + auditPolicyFilePath = []string{"apiServerArguments", "audit-policy-file"} +) + +func TestAuditObserver(t *testing.T) { + tests := []struct { + name string + existingConfig map[string]interface{} + desiredProfile *string + expectedPath string + errExpected bool + }{ + { + name: "WithCurrentAndDesiredBothEmpty", + existingConfig: map[string]interface{}{}, + desiredProfile: stringPointer(""), + expectedPath: "", + }, + { + name: "WithCurrentSetAndDesiredEmpty", + existingConfig: map[string]interface{}{ + "apiServerArguments": map[string]interface{}{ + "audit-policy-file": []interface{}{ + path("AllRequestBodies"), + }, + }, + }, + desiredProfile: stringPointer(""), + expectedPath: "", + }, + { + name: "WithCurrentEmpty", + existingConfig: map[string]interface{}{}, + desiredProfile: stringPointer("WriteRequestBodies"), + expectedPath: path("WriteRequestBodies"), + }, + { + name: "WithCurrentAndDesiredAtDifferentValues", + existingConfig: map[string]interface{}{ + "apiServerArguments": map[string]interface{}{ + "audit-policy-file": []interface{}{ + path("AllRequestBodies"), + }, + }, + }, + desiredProfile: stringPointer("WriteRequestBodies"), + expectedPath: path("WriteRequestBodies"), + }, + { + // we expect the function to return just the keys it is responsible for. + name: "WithOtherKeysDropped", + existingConfig: map[string]interface{}{ + "apiServerArguments": map[string]interface{}{ + "audit-policy-file": []interface{}{ + path("AllRequestBodies"), + }, + }, + "foo": []interface{}{ + "should not be returned", + }, + }, + desiredProfile: stringPointer("WriteRequestBodies"), + expectedPath: path("WriteRequestBodies"), + }, + { + // if the user specifies an invalid audit profile we expect the current config to be set. + name: "WithCurrentSetAndDesiredInvalid", + existingConfig: map[string]interface{}{ + "apiServerArguments": map[string]interface{}{ + "audit-policy-file": []interface{}{ + path("AllRequestBodies"), + }, + }, + }, + desiredProfile: stringPointer("NotExist"), + expectedPath: path("AllRequestBodies"), + errExpected: true, + }, + { + name: "WithCurrentEmptyAndDesiredInvalid", + existingConfig: map[string]interface{}{}, + desiredProfile: stringPointer("NotExist"), + expectedPath: "", + errExpected: true, + }, + { + name: "WithCurrentAndDesiredBothSame", + existingConfig: map[string]interface{}{ + "apiServerArguments": map[string]interface{}{ + "audit-policy-file": []interface{}{ + path("AllRequestBodies"), + }, + }, + }, + desiredProfile: stringPointer("AllRequestBodies"), + expectedPath: path("AllRequestBodies"), + }, + { + name: "WithCurrentSetAndAPIServerResourceMissing", + existingConfig: map[string]interface{}{ + "apiServerArguments": map[string]interface{}{ + "audit-policy-file": []interface{}{ + path("AllRequestBodies"), + }, + }, + }, + expectedPath: path("AllRequestBodies"), + }, + { + name: "WithCurrentNotSetAndAPIServerResourceMissing", + existingConfig: map[string]interface{}{}, + expectedPath: "", + }, + } + + for _, test := range tests { + t.Run(test.name, func(t *testing.T) { + indexer := cache.NewIndexer(cache.MetaNamespaceKeyFunc, cache.Indexers{}) + if test.desiredProfile != nil { + if err := indexer.Add(&configv1.APIServer{ + ObjectMeta: metav1.ObjectMeta{ + Name: "cluster", + }, + Spec: configv1.APIServerSpec{ + Audit: configv1.Audit{ + Profile: configv1.AuditProfileType(*test.desiredProfile), + }, + }, + }); err != nil { + t.Fatal(err) + } + } + listers := testLister{ + apiLister: configlistersv1.NewAPIServerLister(indexer), + } + + observer := NewAuditObserver(getter) + recorder := events.NewInMemoryRecorder(t.Name()) + for i := 1; i <= 2; i++ { + gotConfig, errs := observer(listers, recorder, test.existingConfig) + + if test.errExpected && len(errs) == 0 { + t.Errorf("expected errors, got %v", errs) + } + if !test.errExpected && len(errs) > 0 { + t.Errorf("expected no errors, got %v", errs) + } + + gotPath := read(t, gotConfig) + if test.expectedPath != gotPath { + t.Errorf("audit path expected=%s got=%s", test.expectedPath, gotPath) + } + + // put the observed config back into existingConfig. + if err := unstructured.SetNestedStringSlice(test.existingConfig, []string{gotPath}, auditPolicyFilePath...); err != nil { + t.Errorf("failed to put the observed config into the current conig -%s", err) + } + } + }) + } +} + +func path(profile string) string { + return fmt.Sprintf("%s/%s", "/etc/kubernetes/static-pod-resources/configmaps/kube-apiserver-audit-policies", + strings.ToLower(profile)) +} + +func getter(profile string) (string, error) { + if profile == "NotExist" { + return "", fmt.Errorf("invalid profile - name=%s", profile) + } + + path := path(profile) + return path, nil +} + +func stringPointer(s string) *string { + p := &s + return p +} + +func read(t *testing.T, config map[string]interface{}) string { + // we expect only one key returned in the observed config. + if len(config) > 1 { + t.Fatal("expected observed config to have a single key 'apiServerArguments'") + } + + current, found, err := unstructured.NestedStringSlice(config, auditPolicyFilePath...) + if err != nil { + t.Fatal(err) + } + + if !found { + return "" + } + + if len(current) != 1 { + t.Fatal("expected config to have only audit policy path defined") + } + + return current[0] +}