Add validation/mutating webhook server for Fission custom resources (#2608)
* add webhook server * add metrics port * Add self-signed cert generation in helm chart for webhooks (#2611) * remove cert-manager installation * update fission webhook charts * remove extra cluster role * add mutating webhook for pkg creation * Service name and bundle fixes (#2614) * caBundle templating * Rename fission.svc to fission-webhook.svc * update package build status Co-authored-by: shaunak_deshmukh <shaunak@infracloud.io>
This commit is contained in:
co-authored by
shaunak_deshmukh
parent
31dfc3e4d3
commit
9a07d7d96b
@@ -0,0 +1,85 @@
|
||||
/*
|
||||
Copyright 2022.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
package webhook
|
||||
|
||||
import (
|
||||
"context"
|
||||
"os"
|
||||
|
||||
// Import all Kubernetes client auth plugins (e.g. Azure, GCP, OIDC, etc.)
|
||||
// to ensure that exec-entrypoint and run can make use of them.
|
||||
|
||||
"go.uber.org/zap"
|
||||
_ "k8s.io/client-go/plugin/pkg/client/auth"
|
||||
"sigs.k8s.io/controller-runtime/pkg/client/config"
|
||||
"sigs.k8s.io/controller-runtime/pkg/manager"
|
||||
|
||||
v1 "github.com/fission/fission/pkg/apis/core/v1"
|
||||
"github.com/fission/fission/pkg/generated/clientset/versioned/scheme"
|
||||
//+kubebuilder:scaffold:imports
|
||||
)
|
||||
|
||||
type WebhookInjector interface {
|
||||
SetupWebhookWithManager(mgr manager.Manager) error
|
||||
}
|
||||
|
||||
func Start(ctx context.Context, logger *zap.Logger, port int) (err error) {
|
||||
|
||||
wLogger := logger.Named("webhook")
|
||||
|
||||
metricsAddr := os.Getenv("METRICS_ADDR")
|
||||
if metricsAddr == "" {
|
||||
metricsAddr = ":8080"
|
||||
}
|
||||
// Setup a Manager
|
||||
mgr, err := manager.New(config.GetConfigOrDie(), manager.Options{
|
||||
Scheme: scheme.Scheme,
|
||||
Port: port,
|
||||
MetricsBindAddress: metricsAddr,
|
||||
})
|
||||
if err != nil {
|
||||
wLogger.Error("unable to set up overall controller manager", zap.Error(err))
|
||||
return err
|
||||
}
|
||||
|
||||
// Setup webhooks
|
||||
|
||||
webhookInjectors := []WebhookInjector{
|
||||
&v1.CanaryConfig{},
|
||||
&v1.Environment{},
|
||||
&v1.Package{},
|
||||
&v1.Function{},
|
||||
&v1.HTTPTrigger{},
|
||||
&v1.MessageQueueTrigger{},
|
||||
&v1.TimeTrigger{},
|
||||
&v1.KubernetesWatchTrigger{},
|
||||
}
|
||||
|
||||
for _, injector := range webhookInjectors {
|
||||
if err := injector.SetupWebhookWithManager(mgr); err != nil {
|
||||
wLogger.Error("unable to create webhook", zap.Error(err))
|
||||
return err
|
||||
}
|
||||
}
|
||||
|
||||
wLogger.Info("starting manager")
|
||||
if err := mgr.Start(ctx); err != nil {
|
||||
wLogger.Error("unable to run manager", zap.Error(err))
|
||||
return err
|
||||
}
|
||||
return nil
|
||||
}
|
||||
Reference in New Issue
Block a user