Documentation ¶
Index ¶
- Constants
- type Attributes
- type AttributesRecord
- func (a AttributesRecord) GetAPIGroup() string
- func (a AttributesRecord) GetAPIVersion() string
- func (a AttributesRecord) GetCluster() string
- func (a AttributesRecord) GetDevOps() string
- func (a AttributesRecord) GetName() string
- func (a AttributesRecord) GetNamespace() string
- func (a AttributesRecord) GetPath() string
- func (a AttributesRecord) GetResource() string
- func (a AttributesRecord) GetResourceScope() string
- func (a AttributesRecord) GetSubresource() string
- func (a AttributesRecord) GetUser() user.Info
- func (a AttributesRecord) GetVerb() string
- func (a AttributesRecord) GetWorkspace() string
- func (a AttributesRecord) IsKubernetesRequest() bool
- func (a AttributesRecord) IsReadOnly() bool
- func (a AttributesRecord) IsResourceRequest() bool
- type Authorizer
- type AuthorizerFunc
- type Decision
- type DefaultNonResourceRuleInfo
- type DefaultResourceRuleInfo
- type NonResourceRuleInfo
- type RequestAttributesGetter
- type ResourceRuleInfo
- type RuleResolver
Constants ¶
const ( // VerbList represents the verb of listing resources VerbList = "list" // VerbCreate represents the verb of creating a resource VerbCreate = "create" // VerbGet represents the verb of getting a resource or resources VerbGet = "get" // VerbWatch represents the verb of watching a resource VerbWatch = "watch" // VerbDelete represents the verb of deleting a resource VerbDelete = "delete" )
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Attributes ¶
type Attributes interface { // GetUser returns the user.Info object to authorize GetUser() user.Info // GetVerb returns the kube verb associated with API requests (this includes get, list, watch, create, update, patch, delete, deletecollection, and proxy), // or the lowercased HTTP verb associated with non-API requests (this includes get, put, post, patch, and delete) GetVerb() string // When IsReadOnly() == true, the request has no side effects, other than // caching, logging, and other incidentals. IsReadOnly() bool // Indicates whether or not the request should be handled by kubernetes or kubesphere IsKubernetesRequest() bool // The cluster of the object, if a request is for a REST object. GetCluster() string // The workspace of the object, if a request is for a REST object. GetWorkspace() string // The namespace of the object, if a request is for a REST object. GetNamespace() string // The devops project of the object, if a request is for a REST object. GetDevOps() string // The kind of object, if a request is for a REST object. GetResource() string // GetSubresource returns the subresource being requested, if present GetSubresource() string // GetName returns the name of the object as parsed off the request. This will not be present for all request types, but // will be present for: get, update, delete GetName() string // The group of the resource, if a request is for a REST object. GetAPIGroup() string // GetAPIVersion returns the version of the group requested, if a request is for a REST object. GetAPIVersion() string // IsResourceRequest returns true for requests to API resources, like /api/v1/nodes, // and false for non-resource endpoints like /api, /healthz IsResourceRequest() bool // GetResourceScope returns the scope of the resource requested, if a request is for a REST object. GetResourceScope() string // GetPath returns the path of the request GetPath() string }
Attributes is an interface used by an Authorizer to get information about a request that is used to make an authorization decision.
type AttributesRecord ¶
type AttributesRecord struct { User user.Info Verb string Cluster string Workspace string Namespace string DevOps string APIGroup string APIVersion string Resource string Subresource string Name string KubernetesRequest bool ResourceRequest bool Path string ResourceScope string }
AttributesRecord implements Attributes interface.
func (AttributesRecord) GetAPIGroup ¶
func (a AttributesRecord) GetAPIGroup() string
func (AttributesRecord) GetAPIVersion ¶
func (a AttributesRecord) GetAPIVersion() string
func (AttributesRecord) GetCluster ¶
func (a AttributesRecord) GetCluster() string
func (AttributesRecord) GetDevOps ¶
func (a AttributesRecord) GetDevOps() string
func (AttributesRecord) GetName ¶
func (a AttributesRecord) GetName() string
func (AttributesRecord) GetNamespace ¶
func (a AttributesRecord) GetNamespace() string
func (AttributesRecord) GetPath ¶
func (a AttributesRecord) GetPath() string
func (AttributesRecord) GetResource ¶
func (a AttributesRecord) GetResource() string
func (AttributesRecord) GetResourceScope ¶
func (a AttributesRecord) GetResourceScope() string
func (AttributesRecord) GetSubresource ¶
func (a AttributesRecord) GetSubresource() string
func (AttributesRecord) GetUser ¶
func (a AttributesRecord) GetUser() user.Info
func (AttributesRecord) GetVerb ¶
func (a AttributesRecord) GetVerb() string
func (AttributesRecord) GetWorkspace ¶
func (a AttributesRecord) GetWorkspace() string
func (AttributesRecord) IsKubernetesRequest ¶
func (a AttributesRecord) IsKubernetesRequest() bool
func (AttributesRecord) IsReadOnly ¶
func (a AttributesRecord) IsReadOnly() bool
func (AttributesRecord) IsResourceRequest ¶
func (a AttributesRecord) IsResourceRequest() bool
type Authorizer ¶
type Authorizer interface {
Authorize(a Attributes) (authorized Decision, reason string, err error)
}
Authorizer makes an authorization decision based on information gained by making zero or more calls to methods of the Attributes interface. It returns nil when an action is authorized, otherwise it returns an error.
type AuthorizerFunc ¶
type AuthorizerFunc func(a Attributes) (Decision, string, error)
func (AuthorizerFunc) Authorize ¶
func (f AuthorizerFunc) Authorize(a Attributes) (Decision, string, error)
type Decision ¶
type Decision int
const ( // DecisionDeny means that an authorizer decided to deny the action. DecisionDeny Decision = iota // DecisionAllow means that an authorizer decided to allow the action. DecisionAllow // DecisionNoOpionion means that an authorizer has no opinion on whether // to allow or deny an action. DecisionNoOpinion )
type DefaultNonResourceRuleInfo ¶
DefaultNonResourceRuleInfo holds information that describes a rule for the non-resource
func (*DefaultNonResourceRuleInfo) GetNonResourceURLs ¶
func (i *DefaultNonResourceRuleInfo) GetNonResourceURLs() []string
func (*DefaultNonResourceRuleInfo) GetVerbs ¶
func (i *DefaultNonResourceRuleInfo) GetVerbs() []string
type DefaultResourceRuleInfo ¶
type DefaultResourceRuleInfo struct { Verbs []string APIGroups []string Resources []string ResourceNames []string }
DefaultResourceRuleInfo holds information that describes a rule for the resource
func (*DefaultResourceRuleInfo) GetAPIGroups ¶
func (i *DefaultResourceRuleInfo) GetAPIGroups() []string
func (*DefaultResourceRuleInfo) GetResourceNames ¶
func (i *DefaultResourceRuleInfo) GetResourceNames() []string
func (*DefaultResourceRuleInfo) GetResources ¶
func (i *DefaultResourceRuleInfo) GetResources() []string
func (*DefaultResourceRuleInfo) GetVerbs ¶
func (i *DefaultResourceRuleInfo) GetVerbs() []string
type NonResourceRuleInfo ¶
type RequestAttributesGetter ¶
type RequestAttributesGetter interface {
GetRequestAttributes(user.Info, *http.Request) Attributes
}
RequestAttributesGetter provides a function that extracts Attributes from an http.Request
type ResourceRuleInfo ¶
type ResourceRuleInfo interface { // GetVerbs returns a list of kubernetes resource API verbs. GetVerbs() []string // GetAPIGroups return the names of the APIGroup that contains the resources. GetAPIGroups() []string // GetResources return a list of resources the rule applies to. GetResources() []string // GetResourceNames return a white list of names that the rule applies to. GetResourceNames() []string }
type RuleResolver ¶
type RuleResolver interface { // RulesFor get the list of cluster wide rules, the list of rules in the specific namespace, incomplete status and errors. RulesFor(user user.Info, namespace string) ([]ResourceRuleInfo, []NonResourceRuleInfo, bool, error) }
RuleResolver provides a mechanism for resolving the list of rules that apply to a given user within a namespace.