Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #18909 from ncdc/force-image-pulls-admission
Auto commit by PR queue bot
- Loading branch information
Showing
5 changed files
with
202 additions
and
2 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,70 @@ | ||
/* | ||
Copyright 2015 The Kubernetes Authors All rights reserved. | ||
Licensed under the Apache License, Version 2.0 (the "License"); | ||
you may not use this file except in compliance with the License. | ||
You may obtain a copy of the License at | ||
http://www.apache.org/licenses/LICENSE-2.0 | ||
Unless required by applicable law or agreed to in writing, software | ||
distributed under the License is distributed on an "AS IS" BASIS, | ||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
See the License for the specific language governing permissions and | ||
limitations under the License. | ||
*/ | ||
|
||
// Package alwayspullimages contains an admission controller that modifies every new Pod to force | ||
// the image pull policy to Always. This is useful in a multitenant cluster so that users can be | ||
// assured that their private images can only be used by those who have the credentials to pull | ||
// them. Without this admission controller, once an image has been pulled to a node, any pod from | ||
// any user can use it simply by knowing the image's name (assuming the Pod is scheduled onto the | ||
// right node), without any authorization check against the image. With this admission controller | ||
// enabled, images are always pulled prior to starting containers, which means valid credentials are | ||
// required. | ||
package alwayspullimages | ||
|
||
import ( | ||
"io" | ||
|
||
"k8s.io/kubernetes/pkg/admission" | ||
"k8s.io/kubernetes/pkg/api" | ||
apierrors "k8s.io/kubernetes/pkg/api/errors" | ||
client "k8s.io/kubernetes/pkg/client/unversioned" | ||
) | ||
|
||
func init() { | ||
admission.RegisterPlugin("AlwaysPullImages", func(client client.Interface, config io.Reader) (admission.Interface, error) { | ||
return NewAlwaysPullImages(), nil | ||
}) | ||
} | ||
|
||
// alwaysPullImages is an implementation of admission.Interface. | ||
// It looks at all new pods and overrides each container's image pull policy to Always. | ||
type alwaysPullImages struct { | ||
*admission.Handler | ||
} | ||
|
||
func (a *alwaysPullImages) Admit(attributes admission.Attributes) (err error) { | ||
// Ignore all calls to subresources or resources other than pods. | ||
if len(attributes.GetSubresource()) != 0 || attributes.GetResource() != api.Resource("pods") { | ||
return nil | ||
} | ||
pod, ok := attributes.GetObject().(*api.Pod) | ||
if !ok { | ||
return apierrors.NewBadRequest("Resource was marked with kind Pod but was unable to be converted") | ||
} | ||
|
||
for i := range pod.Spec.Containers { | ||
pod.Spec.Containers[i].ImagePullPolicy = api.PullAlways | ||
} | ||
|
||
return nil | ||
} | ||
|
||
// NewAlwaysPullImages creates a new always pull images admission control handler | ||
func NewAlwaysPullImages() admission.Interface { | ||
return &alwaysPullImages{ | ||
Handler: admission.NewHandler(admission.Create, admission.Update), | ||
} | ||
} |
118 changes: 118 additions & 0 deletions
118
plugin/pkg/admission/alwayspullimages/admission_test.go
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,118 @@ | ||
/* | ||
Copyright 2015 The Kubernetes Authors All rights reserved. | ||
Licensed under the Apache License, Version 2.0 (the "License"); | ||
you may not use this file except in compliance with the License. | ||
You may obtain a copy of the License at | ||
http://www.apache.org/licenses/LICENSE-2.0 | ||
Unless required by applicable law or agreed to in writing, software | ||
distributed under the License is distributed on an "AS IS" BASIS, | ||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
See the License for the specific language governing permissions and | ||
limitations under the License. | ||
*/ | ||
|
||
package alwayspullimages | ||
|
||
import ( | ||
"testing" | ||
|
||
"k8s.io/kubernetes/pkg/admission" | ||
"k8s.io/kubernetes/pkg/api" | ||
"k8s.io/kubernetes/pkg/runtime" | ||
) | ||
|
||
// TestAdmission verifies all create requests for pods result in every container's image pull policy | ||
// set to Always | ||
func TestAdmission(t *testing.T) { | ||
namespace := "test" | ||
handler := &alwaysPullImages{} | ||
pod := api.Pod{ | ||
ObjectMeta: api.ObjectMeta{Name: "123", Namespace: namespace}, | ||
Spec: api.PodSpec{ | ||
Containers: []api.Container{ | ||
{Name: "ctr1", Image: "image"}, | ||
{Name: "ctr2", Image: "image", ImagePullPolicy: api.PullNever}, | ||
{Name: "ctr3", Image: "image", ImagePullPolicy: api.PullIfNotPresent}, | ||
{Name: "ctr4", Image: "image", ImagePullPolicy: api.PullAlways}, | ||
}, | ||
}, | ||
} | ||
err := handler.Admit(admission.NewAttributesRecord(&pod, api.Kind("Pod"), pod.Namespace, pod.Name, api.Resource("pods"), "", admission.Create, nil)) | ||
if err != nil { | ||
t.Errorf("Unexpected error returned from admission handler") | ||
} | ||
for _, c := range pod.Spec.Containers { | ||
if c.ImagePullPolicy != api.PullAlways { | ||
t.Errorf("Container %s: expected pull always, got %v", c.ImagePullPolicy) | ||
} | ||
} | ||
} | ||
|
||
// TestOtherResources ensures that this admission controller is a no-op for other resources, | ||
// subresources, and non-pods. | ||
func TestOtherResources(t *testing.T) { | ||
namespace := "testnamespace" | ||
name := "testname" | ||
pod := &api.Pod{ | ||
ObjectMeta: api.ObjectMeta{Name: name, Namespace: namespace}, | ||
Spec: api.PodSpec{ | ||
Containers: []api.Container{ | ||
{Name: "ctr2", Image: "image", ImagePullPolicy: api.PullNever}, | ||
}, | ||
}, | ||
} | ||
tests := []struct { | ||
name string | ||
kind string | ||
resource string | ||
subresource string | ||
object runtime.Object | ||
expectError bool | ||
}{ | ||
{ | ||
name: "non-pod resource", | ||
kind: "Foo", | ||
resource: "foos", | ||
object: pod, | ||
}, | ||
{ | ||
name: "pod subresource", | ||
kind: "Pod", | ||
resource: "pods", | ||
subresource: "exec", | ||
object: pod, | ||
}, | ||
{ | ||
name: "non-pod object", | ||
kind: "Pod", | ||
resource: "pods", | ||
object: &api.Service{}, | ||
expectError: true, | ||
}, | ||
} | ||
|
||
for _, tc := range tests { | ||
handler := &alwaysPullImages{} | ||
|
||
err := handler.Admit(admission.NewAttributesRecord(tc.object, api.Kind(tc.kind), namespace, name, api.Resource(tc.resource), tc.subresource, admission.Create, nil)) | ||
|
||
if tc.expectError { | ||
if err == nil { | ||
t.Errorf("%s: unexpected nil error", tc.name) | ||
} | ||
continue | ||
} | ||
|
||
if err != nil { | ||
t.Errorf("%s: unexpected error: %v", tc.name, err) | ||
continue | ||
} | ||
|
||
if e, a := api.PullNever, pod.Spec.Containers[0].ImagePullPolicy; e != a { | ||
t.Errorf("%s: image pull policy was changed to %s", tc.name, a) | ||
} | ||
} | ||
} |
e185b10
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
TeamCity OSS :: Kubernetes Mesos :: 4 - Smoke Tests Build 10274 outcome was SUCCESS
Summary: Tests passed: 1, ignored: 211 Build time: 00:09:54