|
9 | 9 |
|
10 | 10 | log "github.com/sirupsen/logrus"
|
11 | 11 | admissionregistrationv1 "k8s.io/api/admissionregistration/v1"
|
12 |
| - k8serrors "k8s.io/apimachinery/pkg/api/errors" |
13 | 12 | metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
14 | 13 | "k8s.io/apimachinery/pkg/labels"
|
15 | 14 | )
|
@@ -69,80 +68,108 @@ func (i *StrategyDeploymentInstaller) createOrUpdateWebhook(caPEM []byte, desc v
|
69 | 68 | }
|
70 | 69 |
|
71 | 70 | func (i *StrategyDeploymentInstaller) createOrUpdateMutatingWebhook(ogNamespacelabelSelector *metav1.LabelSelector, caPEM []byte, desc v1alpha1.WebhookDescription) error {
|
72 |
| - webhooks := []admissionregistrationv1.MutatingWebhook{ |
73 |
| - desc.GetMutatingWebhook(i.owner.GetNamespace(), ogNamespacelabelSelector, caPEM), |
74 |
| - } |
75 |
| - existingHook, err := i.strategyClient.GetOpClient().KubernetesInterface().AdmissionregistrationV1().MutatingWebhookConfigurations().Get(context.TODO(), desc.Name, metav1.GetOptions{}) |
76 |
| - if err == nil { |
77 |
| - // Check if the only owners are this CSV or in this CSV's replacement chain |
78 |
| - if ownerutil.Adoptable(i.owner, existingHook.GetOwnerReferences()) { |
79 |
| - ownerutil.AddNonBlockingOwner(existingHook, i.owner) |
80 |
| - } |
| 71 | + webhookLabels := ownerutil.OwnerLabel(i.owner, i.owner.GetObjectKind().GroupVersionKind().Kind) |
| 72 | + webhookLabels[WebhookDescKey] = desc.Name |
| 73 | + webhookSelector := labels.SelectorFromSet(webhookLabels).String() |
81 | 74 |
|
82 |
| - // Update the list of webhooks |
83 |
| - existingHook.Webhooks = webhooks |
| 75 | + existingWebhooks, err := i.strategyClient.GetOpClient().KubernetesInterface().AdmissionregistrationV1().MutatingWebhookConfigurations().List(context.TODO(), metav1.ListOptions{LabelSelector: webhookSelector}) |
| 76 | + if err != nil { |
| 77 | + return err |
| 78 | + } |
84 | 79 |
|
85 |
| - // Attempt an update |
86 |
| - if _, err := i.strategyClient.GetOpClient().KubernetesInterface().AdmissionregistrationV1().MutatingWebhookConfigurations().Update(context.TODO(), existingHook, metav1.UpdateOptions{}); err != nil { |
87 |
| - log.Warnf("could not update MutatingWebhookConfiguration %s", existingHook.GetName()) |
88 |
| - return err |
89 |
| - } |
90 |
| - } else if k8serrors.IsNotFound(err) { |
| 80 | + if len(existingWebhooks.Items) == 0 { |
| 81 | + // Create a ValidatingWebhookConfiguration |
91 | 82 | hook := admissionregistrationv1.MutatingWebhookConfiguration{
|
92 |
| - ObjectMeta: metav1.ObjectMeta{Name: desc.Name, |
93 |
| - Namespace: i.owner.GetNamespace(), |
| 83 | + ObjectMeta: metav1.ObjectMeta{ |
| 84 | + GenerateName: desc.Name + "-", |
| 85 | + Namespace: i.owner.GetNamespace(), |
| 86 | + Labels: ownerutil.OwnerLabel(i.owner, i.owner.GetObjectKind().GroupVersionKind().Kind), |
| 87 | + }, |
| 88 | + Webhooks: []admissionregistrationv1.MutatingWebhook{ |
| 89 | + desc.GetMutatingWebhook(i.owner.GetNamespace(), ogNamespacelabelSelector, caPEM), |
94 | 90 | },
|
95 |
| - Webhooks: webhooks, |
96 | 91 | }
|
97 |
| - // Add an owner |
98 |
| - ownerutil.AddNonBlockingOwner(&hook, i.owner) |
| 92 | + addWebhookLabels(&hook, desc) |
| 93 | + |
99 | 94 | if _, err := i.strategyClient.GetOpClient().KubernetesInterface().AdmissionregistrationV1().MutatingWebhookConfigurations().Create(context.TODO(), &hook, metav1.CreateOptions{}); err != nil {
|
100 |
| - log.Errorf("Webhooks: Error creating mutating MutatingVebhookConfiguration: %v", err) |
| 95 | + log.Errorf("Webhooks: Error creating ValidationWebhookConfiguration: %v", err) |
101 | 96 | return err
|
102 | 97 | }
|
103 | 98 | } else {
|
104 |
| - return err |
105 |
| - } |
| 99 | + for _, webhook := range existingWebhooks.Items { |
| 100 | + // Update the list of webhooks |
| 101 | + webhook.Webhooks = []admissionregistrationv1.MutatingWebhook{ |
| 102 | + desc.GetMutatingWebhook(i.owner.GetNamespace(), ogNamespacelabelSelector, caPEM), |
| 103 | + } |
| 104 | + |
| 105 | + // Attempt an update |
| 106 | + if _, err := i.strategyClient.GetOpClient().KubernetesInterface().AdmissionregistrationV1().MutatingWebhookConfigurations().Update(context.TODO(), &webhook, metav1.UpdateOptions{}); err != nil { |
| 107 | + log.Warnf("could not update MutatingWebhookConfiguration %s", webhook.GetName()) |
| 108 | + return err |
| 109 | + } |
106 | 110 |
|
| 111 | + } |
| 112 | + } |
107 | 113 | return nil
|
108 | 114 | }
|
109 | 115 |
|
110 | 116 | func (i *StrategyDeploymentInstaller) createOrUpdateValidatingWebhook(ogNamespacelabelSelector *metav1.LabelSelector, caPEM []byte, desc v1alpha1.WebhookDescription) error {
|
111 |
| - webhooks := []admissionregistrationv1.ValidatingWebhook{ |
112 |
| - desc.GetValidatingWebhook(i.owner.GetNamespace(), ogNamespacelabelSelector, caPEM), |
113 |
| - } |
114 |
| - existingHook, err := i.strategyClient.GetOpClient().KubernetesInterface().AdmissionregistrationV1().ValidatingWebhookConfigurations().Get(context.TODO(), desc.Name, metav1.GetOptions{}) |
115 |
| - if err == nil { |
116 |
| - // Check if the only owners are this CSV or in this CSV's replacement chain |
117 |
| - if ownerutil.Adoptable(i.owner, existingHook.GetOwnerReferences()) { |
118 |
| - ownerutil.AddNonBlockingOwner(existingHook, i.owner) |
119 |
| - } |
| 117 | + webhookLabels := ownerutil.OwnerLabel(i.owner, i.owner.GetObjectKind().GroupVersionKind().Kind) |
| 118 | + webhookLabels[WebhookDescKey] = desc.Name |
| 119 | + webhookSelector := labels.SelectorFromSet(webhookLabels).String() |
120 | 120 |
|
121 |
| - // Update the list of webhooks |
122 |
| - existingHook.Webhooks = webhooks |
| 121 | + existingWebhooks, err := i.strategyClient.GetOpClient().KubernetesInterface().AdmissionregistrationV1().ValidatingWebhookConfigurations().List(context.TODO(), metav1.ListOptions{LabelSelector: webhookSelector}) |
| 122 | + if err != nil { |
| 123 | + return err |
| 124 | + } |
123 | 125 |
|
124 |
| - // Attempt an update |
125 |
| - if _, err := i.strategyClient.GetOpClient().KubernetesInterface().AdmissionregistrationV1().ValidatingWebhookConfigurations().Update(context.TODO(), existingHook, metav1.UpdateOptions{}); err != nil { |
126 |
| - log.Warnf("could not update ValidatingWebhookConfiguration %s", existingHook.GetName()) |
127 |
| - return err |
128 |
| - } |
129 |
| - } else if k8serrors.IsNotFound(err) { |
| 126 | + if len(existingWebhooks.Items) == 0 { |
130 | 127 | // Create a ValidatingWebhookConfiguration
|
131 | 128 | hook := admissionregistrationv1.ValidatingWebhookConfiguration{
|
132 |
| - ObjectMeta: metav1.ObjectMeta{Name: desc.Name, |
133 |
| - Namespace: i.owner.GetNamespace(), |
| 129 | + ObjectMeta: metav1.ObjectMeta{ |
| 130 | + GenerateName: desc.Name + "-", |
| 131 | + Namespace: i.owner.GetNamespace(), |
| 132 | + Labels: ownerutil.OwnerLabel(i.owner, i.owner.GetObjectKind().GroupVersionKind().Kind), |
| 133 | + }, |
| 134 | + Webhooks: []admissionregistrationv1.ValidatingWebhook{ |
| 135 | + desc.GetValidatingWebhook(i.owner.GetNamespace(), ogNamespacelabelSelector, caPEM), |
134 | 136 | },
|
135 |
| - Webhooks: webhooks, |
136 | 137 | }
|
| 138 | + addWebhookLabels(&hook, desc) |
137 | 139 |
|
138 |
| - // Add an owner |
139 |
| - ownerutil.AddNonBlockingOwner(&hook, i.owner) |
140 | 140 | if _, err := i.strategyClient.GetOpClient().KubernetesInterface().AdmissionregistrationV1().ValidatingWebhookConfigurations().Create(context.TODO(), &hook, metav1.CreateOptions{}); err != nil {
|
141 |
| - log.Errorf("Webhooks: Error create creating ValidationVebhookConfiguration: %v", err) |
| 141 | + log.Errorf("Webhooks: Error creating ValidatingWebhookConfiguration: %v", err) |
142 | 142 | return err
|
143 | 143 | }
|
144 | 144 | } else {
|
145 |
| - return err |
| 145 | + for _, webhook := range existingWebhooks.Items { |
| 146 | + |
| 147 | + // Update the list of webhooks |
| 148 | + webhook.Webhooks = []admissionregistrationv1.ValidatingWebhook{ |
| 149 | + desc.GetValidatingWebhook(i.owner.GetNamespace(), ogNamespacelabelSelector, caPEM), |
| 150 | + } |
| 151 | + |
| 152 | + // Attempt an update |
| 153 | + if _, err := i.strategyClient.GetOpClient().KubernetesInterface().AdmissionregistrationV1().ValidatingWebhookConfigurations().Update(context.TODO(), &webhook, metav1.UpdateOptions{}); err != nil { |
| 154 | + log.Warnf("could not update ValidatingWebhookConfiguration %s", webhook.GetName()) |
| 155 | + return err |
| 156 | + } |
| 157 | + |
| 158 | + } |
146 | 159 | }
|
147 | 160 | return nil
|
148 | 161 | }
|
| 162 | + |
| 163 | +const WebhookDescKey = "webhookDescriptionName" |
| 164 | + |
| 165 | +// addWebhookLabels adds webhook labels to an object |
| 166 | +func addWebhookLabels(object metav1.Object, webhookDesc v1alpha1.WebhookDescription) error { |
| 167 | + labels := object.GetLabels() |
| 168 | + if labels == nil { |
| 169 | + labels = map[string]string{} |
| 170 | + } |
| 171 | + labels[WebhookDescKey] = webhookDesc.Name |
| 172 | + object.SetLabels(labels) |
| 173 | + |
| 174 | + return nil |
| 175 | +} |
0 commit comments