-
Notifications
You must be signed in to change notification settings - Fork 2
/
seccomp_profile.go
88 lines (73 loc) · 2.3 KB
/
seccomp_profile.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
// This Source Code Form is subject to the terms of the Mozilla Public
// License, v. 2.0. If a copy of the MPL was not distributed with this
// file, You can obtain one at http://mozilla.org/MPL/2.0/.
package cri
import (
"context"
"fmt"
"github.com/cosi-project/runtime/pkg/controller"
"github.com/cosi-project/runtime/pkg/safe"
"github.com/cosi-project/runtime/pkg/state"
"github.com/siderolabs/gen/optional"
"go.uber.org/zap"
"github.com/siderolabs/talos/pkg/machinery/resources/config"
"github.com/siderolabs/talos/pkg/machinery/resources/cri"
)
// SeccompProfileController manages SeccompProfiles.
type SeccompProfileController struct{}
// Name implements controller.StatsController interface.
func (ctrl *SeccompProfileController) Name() string {
return "cri.SeccompProfileController"
}
// Inputs implements controller.StatsController interface.
func (ctrl *SeccompProfileController) Inputs() []controller.Input {
return []controller.Input{
{
Namespace: config.NamespaceName,
Type: config.MachineConfigType,
ID: optional.Some(config.V1Alpha1ID),
Kind: controller.InputWeak,
},
}
}
// Outputs implements controller.StatsController interface.
func (ctrl *SeccompProfileController) Outputs() []controller.Output {
return []controller.Output{
{
Type: cri.SeccompProfileType,
Kind: controller.OutputExclusive,
},
}
}
// Run implements controller.StatsController interface.
func (ctrl *SeccompProfileController) Run(ctx context.Context, r controller.Runtime, logger *zap.Logger) error {
for {
select {
case <-ctx.Done():
return nil
case <-r.EventCh():
}
cfg, err := safe.ReaderGetByID[*config.MachineConfig](ctx, r, config.V1Alpha1ID)
if err != nil {
if state.IsNotFoundError(err) {
continue
}
return fmt.Errorf("error getting config: %w", err)
}
r.StartTrackingOutputs()
if cfg.Config().Machine() != nil {
for _, profile := range cfg.Config().Machine().SeccompProfiles() {
if err = safe.WriterModify(ctx, r, cri.NewSeccompProfile(profile.Name()), func(cri *cri.SeccompProfile) error {
cri.TypedSpec().Name = profile.Name()
cri.TypedSpec().Value = profile.Value()
return nil
}); err != nil {
return err
}
}
}
if err = safe.CleanupOutputs[*cri.SeccompProfile](ctx, r); err != nil {
return err
}
}
}