-
Notifications
You must be signed in to change notification settings - Fork 784
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Handle processing of policies in background #569
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…are verified in the first iteration
fix mutation patch bytes
shivdudhani
changed the title
[WIP] Handle processing of policies in background
Handle processing of policies in background
Dec 25, 2019
realshuting
reviewed
Dec 27, 2019
@realshuting are there any more pending review comments? |
/lgtm |
shivdudhani
pushed a commit
that referenced
this pull request
Dec 31, 2019
* initial commit * variable substitution * update tests * update test * refactor engine packages for validate & generate * update vendor * update toml * support variable substitution in overlay mutation * missing update * fix indentation in logs * store context values as single JSON document using merge patches. * remove duplicate functions * fix message string * Handle processing of policies in background (#569) * remove condition check while generating mutation patch as conditions are verified in the first iteration * initial commit * background policy validation * correct message * skip non-background policy process for add/update * fix order to correct policy registration * update comment Co-authored-by: shuting <shutting06@gmail.com> * refactor Co-authored-by: shuting <shutting06@gmail.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Introduced a new flag in CRD for background execution
policy.spec.background
. IfTrue
will be used by policy controller for the processing policies in background.This is needed as policies using user information cannot be processed in the background because the information is not available.
If a policy is set for background mode, then the rule cannot container userInfo in the match and exclude blocks, and also no variables with path
request.userInfo
can be used(regex matching). The policy validation returns an error with the path of the use. The variable filtering expects a list of variables to be filtered.Policy controller will no process non-background policies during add/update event but will handle them for delete event as we the policy violation cleanup needs to be done.
Move the userInfo into a struct, as they have common structure and can be reused. As embedded types as not auto-promoted in Go, updated the tests to handle the initialization.
Generate
rules with userInfo cannot be processed. As the userInfo is not available.fixes #566