Skip to content

Commit

Permalink
added demo resources for ValidatingAdmissionPolicy and Validation Rul…
Browse files Browse the repository at this point in the history
…es functionality
  • Loading branch information
olensmar committed Oct 18, 2023
1 parent c81cd8e commit 1b3ef9c
Show file tree
Hide file tree
Showing 6 changed files with 145 additions and 0 deletions.
32 changes: 32 additions & 0 deletions crd-validation-rules/crd.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: mycustomresources.example.com
spec:
group: example.com
names:
kind: MyCustomResource
plural: mycustomresources
singular: mycustomresource
shortNames:
- mcr
scope: Namespaced
versions:
- name: v1
schema:
openAPIV3Schema:
type: object
properties:
spec:
type: object
x-kubernetes-validation:
- rule: "self.replicas <= self.maxReplicas"
message: "replicas must be less than or equal to maxReplicas"
properties:
replicas:
type: integer
maxReplicas:
type: integer
required:
- replicas
- maxReplicas
7 changes: 7 additions & 0 deletions crd-validation-rules/custom-resource.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
apiVersion: example.com/v1
kind: MyCustomResource
metadata:
name: example-demo
spec:
replicas: 20
maxReplicas: 10
29 changes: 29 additions & 0 deletions validating-admission-policies/demo.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
apiVersion: v1
kind: Namespace
metadata:
name: demo
labels:
# env: production
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: nginx-deployment
namespace: demo
labels:
app: nginx
spec:
replicas: 2
selector:
matchLabels:
app: nginx
template:
metadata:
labels:
app: nginx
spec:
containers:
- name: nginx
image: nginx:1.14.2
ports:
- containerPort: 80
41 changes: 41 additions & 0 deletions validating-admission-policies/ha-params.policy.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
apiVersion: admissionregistration.k8s.io/v1beta1
kind: ValidatingAdmissionPolicy
metadata:
name: high-available-params
spec:
failurePolicy: Fail
paramKind:
apiVersion: v1
kind: ConfigMap
matchConstraints:
resourceRules:
- apiGroups: ["*"]
apiVersions: ["v1"]
operations: ["CREATE", "UPDATE"]
resources: ["deployments"]
validations:
- expression: "object.spec.replicas <= params.data.maxReplicas"
---
apiVersion: v1
kind: ConfigMap
metadata:
name: rule-config
namespace: demo
data:
maxReplicas: "3"
---
apiVersion: admissionregistration.k8s.io/v1beta1
kind: ValidatingAdmissionPolicyBinding
metadata:
name: high-available-params
spec:
policyName: high-available-params
validationActions:
- Deny
paramRef:
name: rule-config
namespace: demo
matchResources:
namespaceSelector:
matchLabels:
env: production
22 changes: 22 additions & 0 deletions validating-admission-policies/ha.policy.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
apiVersion: admissionregistration.k8s.io/v1beta1
kind: ValidatingAdmissionPolicy
metadata:
name: high-available
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups: ["*"]
apiVersions: ["v1"]
operations: ["CREATE", "UPDATE"]
resources: ["deployments"]
validations:
- expression: "object.spec.replicas > 3"
---
apiVersion: admissionregistration.k8s.io/v1beta1
kind: ValidatingAdmissionPolicyBinding
metadata:
name: high-available
spec:
policyName: high-available
validationActions: [Deny]
14 changes: 14 additions & 0 deletions validating-admission-policies/labels.policy.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
apiVersion: admissionregistration.k8s.io/v1beta1
kind: ValidatingAdmissionPolicy
metadata:
name: env-label
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups: ["*"]
apiVersions: ["*"]
operations: ["CREATE", "UPDATE"]
resources: ["*"]
validations:
- expression: "has(object.metadata.labels) && has(object.metadata.labels.env) && object.metadata.labels.env in ['production', 'staging']"

0 comments on commit 1b3ef9c

Please sign in to comment.