Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/configmap/pod-cm1.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/configmap/pod-cm2.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/configmap/pod-cm3.yaml

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/job/test-job.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/job/test-job2.yaml

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/pod/pod-exec.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/pod/pod-lifecycle.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/pod/pod-one-container.yaml

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/pod/pod-spark.yaml

Large diffs are not rendered by default.

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/pod/pod-ubuntu.yaml

Large diffs are not rendered by default.

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/replica-set/replica2.yaml

Large diffs are not rendered by default.

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/stateful-set/web.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/stateful-set/web2.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/webhook/webhook-pod1.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/webhook/webhook-pod2.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/webhook/webhook-pod3.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/webhook/webhook-pod4.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/webhook/webhook-pod5.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/webhook/webhook-pod6.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/webhook/webhook-pod7.yaml

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/webhook2/webhook-pod8.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/webhook2/webhook-pod9.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/webhook3/dns-test.yaml

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion src/agent/samples/policy/yaml/webhook3/many-layers.yaml

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions src/tools/genpolicy/genpolicy-settings.json
Original file line number Diff line number Diff line change
Expand Up @@ -277,6 +277,7 @@
"CAP_CHECKPOINT_RESTORE"
],
"virtio_blk_storage_classes": [
"cc-local-csi",
"cc-managed-csi",
"cc-managed-premium-csi"
]
Expand Down
121 changes: 82 additions & 39 deletions src/tools/genpolicy/src/mount_and_storage.rs
Original file line number Diff line number Diff line change
Expand Up @@ -149,6 +149,15 @@ pub fn get_mount_and_storage(
get_shared_bind_mount(yaml_mount, p_mounts, ("rprivate", "ro"));
} else if yaml_volume.downwardAPI.is_some() {
get_downward_api_mount(yaml_mount, p_mounts);
} else if yaml_volume.ephemeral.is_some() {
get_ephemeral_mount(
settings,
yaml_mount,
yaml_volume,
p_mounts,
storages,
mount_options,
);
} else {
todo!("Unsupported volume type {:?}", yaml_volume);
}
Expand Down Expand Up @@ -233,45 +242,7 @@ fn get_persistent_volume_claim_mount(
.and_then(|pvc_resource| pvc_resource.spec.storageClassName.as_ref())
.is_some_and(|sc| settings.common.virtio_blk_storage_classes.contains(sc));

if is_blk_mount {
let source = "$(spath)/$(b64-pci-device-id)".to_string();

storages.push(agent::Storage {
driver: "blk".to_string(),
driver_options: Vec::new(),
fs_group: None,
source: "$(pci-device-id)".to_string(),
mount_point: source.to_string(),
fstype: "$(fs-type)".to_string(),
options: Vec::new(),
});

let dest = yaml_mount.mountPath.clone();
let type_ = "bind".to_string();
let (propagation, access) = mount_options;
let options = vec![
"rbind".to_string(),
propagation.to_string(),
access.to_string(),
];

if let Some(policy_mount) = p_mounts.iter_mut().find(|m| m.destination == dest) {
debug!("get_persistent_volume_claim_mount: updating dest = {dest}, source = {source}");
policy_mount.type_ = type_;
policy_mount.source = source;
policy_mount.options = options;
} else {
debug!("get_persistent_volume_claim_mount: adding dest = {dest}, source = {source}");
p_mounts.push(policy::KataMount {
destination: dest,
type_,
source,
options,
});
}
} else {
get_shared_bind_mount(yaml_mount, p_mounts, mount_options);
}
handle_persistent_volume_claim(is_blk_mount, yaml_mount, p_mounts, storages, mount_options);
}

fn get_host_path_mount(
Expand Down Expand Up @@ -428,3 +399,75 @@ fn get_downward_api_mount(yaml_mount: &pod::VolumeMount, p_mounts: &mut Vec<poli
});
}
}

fn get_ephemeral_mount(
settings: &settings::Settings,
yaml_mount: &pod::VolumeMount,
yaml_volume: &volume::Volume,
p_mounts: &mut Vec<policy::KataMount>,
storages: &mut Vec<agent::Storage>,
mount_options: (&str, &str),
) {
let storage_class = &yaml_volume
.ephemeral
.as_ref()
.unwrap()
.volumeClaimTemplate
.spec
.storageClassName;

let is_blk_mount = storage_class
.as_ref()
.map(|sc| settings.common.virtio_blk_storage_classes.contains(sc))
.unwrap_or(false);

handle_persistent_volume_claim(is_blk_mount, yaml_mount, p_mounts, storages, mount_options);
}

fn handle_persistent_volume_claim(
is_blk_mount: bool,
yaml_mount: &pod::VolumeMount,
p_mounts: &mut Vec<policy::KataMount>,
storages: &mut Vec<agent::Storage>,
mount_options: (&str, &str),
) {
if is_blk_mount {
let source = "$(spath)/$(b64-pci-device-id)".to_string();

storages.push(agent::Storage {
driver: "blk".to_string(),
driver_options: Vec::new(),
fs_group: None,
source: "$(pci-device-id)".to_string(),
mount_point: source.to_string(),
fstype: "$(fs-type)".to_string(),
options: Vec::new(),
});

let dest = yaml_mount.mountPath.clone();
let type_ = "bind".to_string();
let (propagation, access) = mount_options;
let options = vec![
"rbind".to_string(),
propagation.to_string(),
access.to_string(),
];

if let Some(policy_mount) = p_mounts.iter_mut().find(|m| m.destination == dest) {
debug!("handle_persistent_volume_claim: updating dest = {dest}, source = {source}");
policy_mount.type_ = type_;
policy_mount.source = source;
policy_mount.options = options;
} else {
debug!("handle_persistent_volume_claim: adding dest = {dest}, source = {source}");
p_mounts.push(policy::KataMount {
destination: dest,
type_,
source,
options,
});
}
} else {
get_shared_bind_mount(yaml_mount, p_mounts, mount_options);
}
}
23 changes: 21 additions & 2 deletions src/tools/genpolicy/src/volume.rs
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
// Allow K8s YAML field names.
#![allow(non_snake_case)]

use crate::pod;
use crate::{obj_meta, pod, pvc};

use serde::{Deserialize, Serialize};

Expand Down Expand Up @@ -37,7 +37,11 @@ pub struct Volume {
pub secret: Option<SecretVolumeSource>,

#[serde(skip_serializing_if = "Option::is_none")]
pub downwardAPI: Option<DownwardAPIVolumeSource>, // TODO: additional fields.
pub downwardAPI: Option<DownwardAPIVolumeSource>,

#[serde(skip_serializing_if = "Option::is_none")]
pub ephemeral: Option<EphemeralVolumeSource>,
// TODO: additional fields.
}

/// See Reference / Kubernetes API / Config and Storage Resources / Volume.
Expand Down Expand Up @@ -129,3 +133,18 @@ pub struct DownwardAPIVolumeFile {
#[serde(skip_serializing_if = "Option::is_none")]
pub fieldRef: Option<pod::ObjectFieldSelector>,
}

/// See Reference / Kubernetes API / Config and Storage Resources / Volume.
#[derive(Clone, Debug, Serialize, Deserialize)]
pub struct EphemeralVolumeSource {
pub volumeClaimTemplate: PersistentVolumeClaimTemplate,
}

/// See Reference / Kubernetes API / Config and Storage Resources / Volume.
#[derive(Clone, Debug, Serialize, Deserialize)]
pub struct PersistentVolumeClaimTemplate {
#[serde(skip_serializing_if = "Option::is_none")]
pub metadata: Option<obj_meta::ObjectMeta>,

pub spec: pvc::PersistentVolumeClaimSpec,
}