-
Notifications
You must be signed in to change notification settings - Fork 32
/
k8s_networkpolicy.go
100 lines (87 loc) · 2.19 KB
/
k8s_networkpolicy.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
package k8s
import (
"context"
"github.com/sirupsen/logrus"
v1 "k8s.io/api/networking/v1"
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
)
func (c *Client) CreateNetworkPolicy(
ctx context.Context,
name string,
selectorMap,
ingressSelectorMap,
egressSelectorMap map[string]string,
) error {
var ingress []v1.NetworkPolicyIngressRule
if ingressSelectorMap != nil {
ingress = []v1.NetworkPolicyIngressRule{
{
From: []v1.NetworkPolicyPeer{
{
PodSelector: &metav1.LabelSelector{
MatchLabels: ingressSelectorMap,
},
},
},
},
}
}
var egress []v1.NetworkPolicyEgressRule
if egressSelectorMap != nil {
egress = []v1.NetworkPolicyEgressRule{
{
To: []v1.NetworkPolicyPeer{
{
PodSelector: &metav1.LabelSelector{
MatchLabels: egressSelectorMap,
},
},
},
},
}
}
np := &v1.NetworkPolicy{
ObjectMeta: metav1.ObjectMeta{
Namespace: c.namespace,
Name: name,
},
Spec: v1.NetworkPolicySpec{
PodSelector: metav1.LabelSelector{
MatchLabels: selectorMap,
},
PolicyTypes: []v1.PolicyType{
v1.PolicyTypeIngress,
v1.PolicyTypeEgress,
},
Ingress: ingress,
Egress: egress,
},
}
_, err := c.clientset.NetworkingV1().NetworkPolicies(c.namespace).Create(ctx, np, metav1.CreateOptions{})
if err != nil {
return ErrCreatingNetworkPolicy.WithParams(name).Wrap(err)
}
return nil
}
func (c *Client) DeleteNetworkPolicy(ctx context.Context, name string) error {
err := c.clientset.NetworkingV1().NetworkPolicies(c.namespace).Delete(ctx, name, metav1.DeleteOptions{})
if err != nil {
return ErrDeletingNetworkPolicy.WithParams(name).Wrap(err)
}
return nil
}
func (c *Client) GetNetworkPolicy(ctx context.Context, name string) (*v1.NetworkPolicy, error) {
np, err := c.clientset.NetworkingV1().NetworkPolicies(c.namespace).Get(ctx, name, metav1.GetOptions{})
if err != nil {
return nil, ErrGettingNetworkPolicy.WithParams(name).Wrap(err)
}
return np, nil
}
func (c *Client) NetworkPolicyExists(ctx context.Context, name string) bool {
_, err := c.GetNetworkPolicy(ctx, name)
if err != nil {
logrus.Debug("NetworkPolicy does not exist, err: ", err)
return false
}
return true
}