webhook

package
v0.16.5 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 28, 2024 License: Apache-2.0 Imports: 9 Imported by: 11

Documentation

Overview

Package webhook contains libraries for generating webhookconfig manifests from markers in Go source files.

The markers take the form:

+kubebuilder:webhook:webhookVersions=<[]string>,failurePolicy=<string>,matchPolicy=<string>,groups=<[]string>,resources=<[]string>,verbs=<[]string>,versions=<[]string>,name=<string>,path=<string>,mutating=<bool>,sideEffects=<string>,timeoutSeconds=<int>,admissionReviewVersions=<[]string>,reinvocationPolicy=<string>

Index

Constants

This section is empty.

Variables

View Source
var (
	// ConfigDefinition is a marker for defining Webhook manifests.
	// Call ToWebhook on the value to get a Kubernetes Webhook.
	ConfigDefinition = markers.Must(markers.MakeDefinition("kubebuilder:webhook", markers.DescribesPackage, Config{}))
	// WebhookConfigDefinition is a marker for defining MutatingWebhookConfiguration or ValidatingWebhookConfiguration manifests.
	WebhookConfigDefinition = markers.Must(markers.MakeDefinition("kubebuilder:webhookconfiguration", markers.DescribesPackage, WebhookConfig{}))
)

Functions

This section is empty.

Types

type Config added in v0.2.0

type Config struct {
	// Mutating marks this as a mutating webhook (it's validating only if false)
	//
	// Mutating webhooks are allowed to change the object in their response,
	// and are called *before* all validating webhooks.  Mutating webhooks may
	// choose to reject an object, similarly to a validating webhook.
	Mutating bool
	// FailurePolicy specifies what should happen if the API server cannot reach the webhook.
	//
	// It may be either "ignore" (to skip the webhook and continue on) or "fail" (to reject
	// the object in question).
	FailurePolicy string
	// MatchPolicy defines how the "rules" list is used to match incoming requests.
	// Allowed values are "Exact" (match only if it exactly matches the specified rule)
	// or "Equivalent" (match a request if it modifies a resource listed in rules, even via another API group or version).
	MatchPolicy string `marker:",optional"`
	// SideEffects specify whether calling the webhook will have side effects.
	// This has an impact on dry runs and `kubectl diff`: if the sideEffect is "Unknown" (the default) or "Some", then
	// the API server will not call the webhook on a dry-run request and fails instead.
	// If the value is "None", then the webhook has no side effects and the API server will call it on dry-run.
	// If the value is "NoneOnDryRun", then the webhook is responsible for inspecting the "dryRun" property of the
	// AdmissionReview sent in the request, and avoiding side effects if that value is "true."
	SideEffects string `marker:",optional"`
	// TimeoutSeconds allows configuring how long the API server should wait for a webhook to respond before treating the call as a failure.
	// If the timeout expires before the webhook responds, the webhook call will be ignored or the API call will be rejected based on the failure policy.
	// The timeout value must be between 1 and 30 seconds.
	// The timeout for an admission webhook defaults to 10 seconds.
	TimeoutSeconds int `marker:",optional"`

	// Groups specifies the API groups that this webhook receives requests for.
	Groups []string
	// Resources specifies the API resources that this webhook receives requests for.
	Resources []string
	// Verbs specifies the Kubernetes API verbs that this webhook receives requests for.
	//
	// Only modification-like verbs may be specified.
	// May be "create", "update", "delete", "connect", or "*" (for all).
	Verbs []string
	// Versions specifies the API versions that this webhook receives requests for.
	Versions []string

	// Name indicates the name of this webhook configuration. Should be a domain with at least three segments separated by dots
	Name string

	// Path specifies that path that the API server should connect to this webhook on. Must be
	// prefixed with a '/validate-' or '/mutate-' depending on the type, and followed by
	// $GROUP-$VERSION-$KIND where all values are lower-cased and the periods in the group
	// are substituted for hyphens. For example, a validating webhook path for type
	// batch.tutorial.kubebuilder.io/v1,Kind=CronJob would be
	// /validate-batch-tutorial-kubebuilder-io-v1-cronjob
	Path string `marker:"path,optional"`

	// WebhookVersions specifies the target API versions of the {Mutating,Validating}WebhookConfiguration objects
	// itself to generate. The only supported value is v1. Defaults to v1.
	WebhookVersions []string `marker:"webhookVersions,optional"`

	// AdmissionReviewVersions is an ordered list of preferred `AdmissionReview`
	// versions the Webhook expects.
	AdmissionReviewVersions []string `marker:"admissionReviewVersions"`

	// ReinvocationPolicy allows mutating webhooks to request reinvocation after other mutations
	//
	// To allow mutating admission plugins to observe changes made by other plugins,
	// built-in mutating admission plugins are re-run if a mutating webhook modifies
	// an object, and mutating webhooks can specify a reinvocationPolicy to control
	// whether they are reinvoked as well.
	ReinvocationPolicy string `marker:"reinvocationPolicy,optional"`

	// URL allows mutating webhooks configuration to specify an external URL when generating
	// the manifests, instead of using the internal service communication. Should be in format of
	// https://address:port/path
	// When this option is specified, the serviceConfig.Service is removed from webhook the manifest.
	// The URL configuration should be between quotes.
	// `url` cannot be specified when `path` is specified.
	URL string `marker:"url,optional"`
}

Config specifies how a webhook should be served.

It specifies only the details that are intrinsic to the application serving it (e.g. the resources it can handle, or the path it serves on).

func (Config) Help added in v0.2.0

func (Config) Help() *markers.DefinitionHelp

func (Config) ToMutatingWebhook added in v0.2.2

func (c Config) ToMutatingWebhook() (admissionregv1.MutatingWebhook, error)

ToMutatingWebhook converts this rule to its Kubernetes API form.

func (Config) ToValidatingWebhook added in v0.2.2

func (c Config) ToValidatingWebhook() (admissionregv1.ValidatingWebhook, error)

ToValidatingWebhook converts this rule to its Kubernetes API form.

type Generator added in v0.2.0

type Generator struct {
	// HeaderFile specifies the header text (e.g. license) to prepend to generated files.
	HeaderFile string `marker:",optional"`

	// Year specifies the year to substitute for " YEAR" in the header file.
	Year string `marker:",optional"`
}

Generator generates (partial) {Mutating,Validating}WebhookConfiguration objects.

func (Generator) Generate added in v0.2.0

func (g Generator) Generate(ctx *genall.GenerationContext) error

func (Generator) Help added in v0.2.0

func (Generator) RegisterMarkers added in v0.2.0

func (Generator) RegisterMarkers(into *markers.Registry) error

type WebhookConfig added in v0.16.3

type WebhookConfig struct {
	// Mutating marks this as a mutating webhook (it's validating only if false)
	//
	// Mutating webhooks are allowed to change the object in their response,
	// and are called *before* all validating webhooks.  Mutating webhooks may
	// choose to reject an object, similarly to a validating webhook.
	Mutating bool
	// Name indicates the name of the K8s MutatingWebhookConfiguration or ValidatingWebhookConfiguration object.
	Name string `marker:"name,optional"`
}

func (WebhookConfig) Help added in v0.16.3

func (WebhookConfig) ToMutatingWebhookConfiguration added in v0.16.3

func (c WebhookConfig) ToMutatingWebhookConfiguration() (admissionregv1.MutatingWebhookConfiguration, error)

ToMutatingWebhookConfiguration converts this WebhookConfig to its Kubernetes API form.

func (WebhookConfig) ToValidatingWebhookConfiguration added in v0.16.3

func (c WebhookConfig) ToValidatingWebhookConfiguration() (admissionregv1.ValidatingWebhookConfiguration, error)

ToValidatingWebhookConfiguration converts this WebhookConfig to its Kubernetes API form.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL