-
Notifications
You must be signed in to change notification settings - Fork 1.5k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
* Release 6.2.2 Signed-off-by: Sebastian Malton <[email protected]> * fix: getAllowedResources for all namespaces using SelfSubjectRulesReview (#6614) * fix: getAllowedResources for all namespaces using SelfSubjectRulesReview Signed-off-by: Andreas Hippler <[email protected]> * fix: refresh accessibility every 15 min Signed-off-by: Andreas Hippler <[email protected]> * chore: remove unused clusterRefreshHandler Signed-off-by: Andreas Hippler <[email protected]> * fix: resolve SelfSubjectRulesReview globs Signed-off-by: Andreas Hippler <[email protected]> Signed-off-by: Andreas Hippler <[email protected]> Co-authored-by: Andreas Hippler <[email protected]> Signed-off-by: Sebastian Malton <[email protected]> * Add missing gutter between sections in cluster settings (#6631) Signed-off-by: Janne Savolainen <[email protected]> Signed-off-by: Janne Savolainen <[email protected]> * Adding spacing between Metrics Settings sections (#6632) Signed-off-by: Alex Andreev <[email protected]> Signed-off-by: Alex Andreev <[email protected]> * Fix crash when upgrading release (#6626) * Fix crash when upgrading release Signed-off-by: Sebastian Malton <[email protected]> * Fix crash when upgrading helm releases - Fixes not being able to upgrade helm releases as well. Signed-off-by: Sebastian Malton <[email protected]> * Fix tests Signed-off-by: Sebastian Malton <[email protected]> * Fix test failures Signed-off-by: Sebastian Malton <[email protected]> Signed-off-by: Sebastian Malton <[email protected]> * Removing big padding after cluster settings avatar (#6634) Signed-off-by: Alex Andreev <[email protected]> Signed-off-by: Alex Andreev <[email protected]> * Fix KubeApi watch retry on timeout (#6640) * fix KubeApi watch retry on timeout Signed-off-by: Jari Kolehmainen <[email protected]> * Fix tests Signed-off-by: Sebastian Malton <[email protected]> Signed-off-by: Jari Kolehmainen <[email protected]> Signed-off-by: Sebastian Malton <[email protected]> Co-authored-by: Sebastian Malton <[email protected]> * Bump electron from 19.1.6 to 19.1.7 (#6637) Bumps [electron](https://github.com/electron/electron) from 19.1.6 to 19.1.7. - [Release notes](https://github.com/electron/electron/releases) - [Changelog](https://github.com/electron/electron/blob/main/docs/breaking-changes.md) - [Commits](electron/electron@v19.1.6...v19.1.7) --- updated-dependencies: - dependency-name: electron dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Sebastian Malton <[email protected]> Signed-off-by: Andreas Hippler <[email protected]> Signed-off-by: Janne Savolainen <[email protected]> Signed-off-by: Alex Andreev <[email protected]> Signed-off-by: Jari Kolehmainen <[email protected]> Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: Andreas Hippler <[email protected]> Co-authored-by: Andreas Hippler <[email protected]> Co-authored-by: Janne Savolainen <[email protected]> Co-authored-by: Alex Andreev <[email protected]> Co-authored-by: Jari Kolehmainen <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- Loading branch information
1 parent
da4afc9
commit 4a13f51
Showing
36 changed files
with
490 additions
and
198 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
87 changes: 87 additions & 0 deletions
87
src/common/cluster/authorization-namespace-review.injectable.ts
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,87 @@ | ||
/** | ||
* Copyright (c) OpenLens Authors. All rights reserved. | ||
* Licensed under MIT License. See LICENSE in root directory for more information. | ||
*/ | ||
|
||
import type { KubeConfig } from "@kubernetes/client-node"; | ||
import { AuthorizationV1Api } from "@kubernetes/client-node"; | ||
import { getInjectable } from "@ogre-tools/injectable"; | ||
import type { Logger } from "../logger"; | ||
import loggerInjectable from "../logger.injectable"; | ||
import type { KubeApiResource } from "../rbac"; | ||
|
||
/** | ||
* Requests the permissions for actions on the kube cluster | ||
* @param namespace The namespace of the resources | ||
* @param availableResources List of available resources in the cluster to resolve glob values fir api groups | ||
* @returns list of allowed resources names | ||
*/ | ||
export type RequestNamespaceResources = (namespace: string, availableResources: KubeApiResource[]) => Promise<string[]>; | ||
|
||
/** | ||
* @param proxyConfig This config's `currentContext` field must be set, and will be used as the target cluster | ||
*/ | ||
export type AuthorizationNamespaceReview = (proxyConfig: KubeConfig) => RequestNamespaceResources; | ||
|
||
interface Dependencies { | ||
logger: Logger; | ||
} | ||
|
||
const authorizationNamespaceReview = ({ logger }: Dependencies): AuthorizationNamespaceReview => { | ||
return (proxyConfig) => { | ||
|
||
const api = proxyConfig.makeApiClient(AuthorizationV1Api); | ||
|
||
return async (namespace, availableResources) => { | ||
try { | ||
const { body } = await api.createSelfSubjectRulesReview({ | ||
apiVersion: "authorization.k8s.io/v1", | ||
kind: "SelfSubjectRulesReview", | ||
spec: { namespace }, | ||
}); | ||
|
||
const resources = new Set<string>(); | ||
|
||
body.status?.resourceRules.forEach(resourceRule => { | ||
if (!resourceRule.verbs.some(verb => ["*", "list"].includes(verb)) || !resourceRule.resources) { | ||
return; | ||
} | ||
|
||
const apiGroups = resourceRule.apiGroups; | ||
|
||
if (resourceRule.resources.length === 1 && resourceRule.resources[0] === "*" && apiGroups) { | ||
if (apiGroups[0] === "*") { | ||
availableResources.forEach(resource => resources.add(resource.apiName)); | ||
} else { | ||
availableResources.forEach((apiResource)=> { | ||
if (apiGroups.includes(apiResource.group || "")) { | ||
resources.add(apiResource.apiName); | ||
} | ||
}); | ||
} | ||
} else { | ||
resourceRule.resources.forEach(resource => resources.add(resource)); | ||
} | ||
|
||
}); | ||
|
||
return [...resources]; | ||
} catch (error) { | ||
logger.error(`[AUTHORIZATION-NAMESPACE-REVIEW]: failed to create subject rules review: ${error}`, { namespace }); | ||
|
||
return []; | ||
} | ||
}; | ||
}; | ||
}; | ||
|
||
const authorizationNamespaceReviewInjectable = getInjectable({ | ||
id: "authorization-namespace-review", | ||
instantiate: (di) => { | ||
const logger = di.inject(loggerInjectable); | ||
|
||
return authorizationNamespaceReview({ logger }); | ||
}, | ||
}); | ||
|
||
export default authorizationNamespaceReviewInjectable; |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.