/
handler.go
108 lines (94 loc) · 3.74 KB
/
handler.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
package validator
import (
"encoding/json"
"fmt"
"io/ioutil"
"net/http"
"time"
"github.com/giantswarm/microerror"
admissionv1 "k8s.io/api/admission/v1"
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
"k8s.io/apimachinery/pkg/runtime"
"k8s.io/apimachinery/pkg/runtime/serializer"
"k8s.io/apimachinery/pkg/types"
"github.com/giantswarm/aws-admission-controller/v3/pkg/handler"
"github.com/giantswarm/aws-admission-controller/v3/pkg/metrics"
)
type Validator interface {
Log(keyVals ...interface{})
Resource() string
Validate(review *admissionv1.AdmissionRequest) (bool, error)
}
var (
scheme = runtime.NewScheme()
codecs = serializer.NewCodecFactory(scheme)
Deserializer = codecs.UniversalDeserializer()
)
func Handler(validator Validator) http.HandlerFunc {
return func(writer http.ResponseWriter, request *http.Request) {
start := time.Now()
defer metrics.DurationRequests.WithLabelValues("validating", validator.Resource()).Observe(float64(time.Since(start)) / float64(time.Second))
if request.Header.Get("Content-Type") != "application/json" {
validator.Log("level", "error", "message", fmt.Sprintf("invalid content-type: %s", request.Header.Get("Content-Type")))
metrics.InvalidRequests.WithLabelValues("validating", validator.Resource()).Inc()
writer.WriteHeader(http.StatusBadRequest)
return
}
data, err := ioutil.ReadAll(request.Body)
if err != nil {
validator.Log("level", "error", "message", "unable to read request")
metrics.InternalError.WithLabelValues("validating", validator.Resource()).Inc()
writer.WriteHeader(http.StatusInternalServerError)
return
}
review := admissionv1.AdmissionReview{}
if _, _, err := Deserializer.Decode(data, nil, &review); err != nil {
validator.Log("level", "error", "message", "unable to parse admission review request")
metrics.InvalidRequests.WithLabelValues("validating", validator.Resource()).Inc()
writer.WriteHeader(http.StatusBadRequest)
return
}
resourceName := fmt.Sprintf("%s %s/%s", review.Request.Kind, review.Request.Namespace, handler.ExtractName(review.Request, Deserializer))
allowed, err := validator.Validate(review.Request)
if err != nil {
validator.Log("level", "error", "message", fmt.Sprintf("error during validation process of %s: %v", resourceName, err))
writeResponse(validator, writer, errorResponse(review.Request.UID, microerror.Mask(err)))
metrics.RejectedRequests.WithLabelValues("validating", validator.Resource()).Inc()
return
}
validator.Log("level", "debug", "message", fmt.Sprintf("validator admitted %s", resourceName))
metrics.SuccessfulRequests.WithLabelValues("validating", validator.Resource()).Inc()
writeResponse(validator, writer, &admissionv1.AdmissionResponse{
Allowed: allowed,
UID: review.Request.UID,
})
}
}
func writeResponse(validator Validator, writer http.ResponseWriter, response *admissionv1.AdmissionResponse) {
resp, err := json.Marshal(admissionv1.AdmissionReview{
TypeMeta: metav1.TypeMeta{
Kind: "AdmissionReview",
APIVersion: "admission.k8s.io/v1",
},
Response: response,
})
if err != nil {
validator.Log("level", "error", "message", "unable to serialize response", microerror.JSON(err))
metrics.InternalError.WithLabelValues("validating", validator.Resource()).Inc()
writer.WriteHeader(http.StatusInternalServerError)
}
if _, err := writer.Write(resp); err != nil {
validator.Log("level", "error", "message", "unable to write response", microerror.JSON(err))
}
}
func errorResponse(uid types.UID, err error) *admissionv1.AdmissionResponse {
return &admissionv1.AdmissionResponse{
Allowed: false,
UID: uid,
Result: &metav1.Status{
Reason: metav1.StatusReasonBadRequest,
Code: http.StatusBadRequest,
Message: err.Error(),
},
}
}