tenant.go 28.2 KB
Newer Older
H
hongming 已提交
1
/*
H
hongming 已提交
2
Copyright 2019 The KubeSphere Authors.
H
hongming 已提交
3

H
hongming 已提交
4 5 6
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
H
hongming 已提交
7

H
hongming 已提交
8
    http://www.apache.org/licenses/LICENSE-2.0
H
hongming 已提交
9

H
hongming 已提交
10 11 12 13 14
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
H
hongming 已提交
15
*/
H
hongming 已提交
16

H
hongming 已提交
17 18 19
package tenant

import (
H
hongming 已提交
20
	"encoding/json"
H
hongming 已提交
21
	"fmt"
H
huanggze 已提交
22
	"io"
H
update  
hongming 已提交
23 24
	corev1 "k8s.io/api/core/v1"
	"k8s.io/apimachinery/pkg/api/errors"
H
hongming 已提交
25
	metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
26
	"k8s.io/apimachinery/pkg/labels"
H
hongming 已提交
27
	"k8s.io/apimachinery/pkg/runtime"
H
hongming 已提交
28
	"k8s.io/apimachinery/pkg/types"
H
hongming 已提交
29
	"k8s.io/apiserver/pkg/authentication/user"
H
hongming 已提交
30
	"k8s.io/client-go/kubernetes"
H
update  
hongming 已提交
31 32
	"k8s.io/klog"
	"kubesphere.io/kubesphere/pkg/api"
R
root 已提交
33
	auditingv1alpha1 "kubesphere.io/kubesphere/pkg/api/auditing/v1alpha1"
J
junotx 已提交
34
	eventsv1alpha1 "kubesphere.io/kubesphere/pkg/api/events/v1alpha1"
H
huanggze 已提交
35
	loggingv1alpha2 "kubesphere.io/kubesphere/pkg/api/logging/v1alpha2"
H
hongming 已提交
36
	clusterv1alpha1 "kubesphere.io/kubesphere/pkg/apis/cluster/v1alpha1"
H
update  
hongming 已提交
37
	tenantv1alpha1 "kubesphere.io/kubesphere/pkg/apis/tenant/v1alpha1"
H
hongming 已提交
38
	tenantv1alpha2 "kubesphere.io/kubesphere/pkg/apis/tenant/v1alpha2"
H
hongming 已提交
39
	typesv1beta1 "kubesphere.io/kubesphere/pkg/apis/types/v1beta1"
H
hongming 已提交
40 41
	"kubesphere.io/kubesphere/pkg/apiserver/authorization/authorizer"
	"kubesphere.io/kubesphere/pkg/apiserver/authorization/authorizerfactory"
H
hongming 已提交
42
	"kubesphere.io/kubesphere/pkg/apiserver/query"
H
hongming 已提交
43
	"kubesphere.io/kubesphere/pkg/apiserver/request"
H
hongming 已提交
44
	kubesphere "kubesphere.io/kubesphere/pkg/client/clientset/versioned"
H
update  
hongming 已提交
45
	"kubesphere.io/kubesphere/pkg/informers"
R
root 已提交
46
	"kubesphere.io/kubesphere/pkg/models/auditing"
J
junotx 已提交
47
	"kubesphere.io/kubesphere/pkg/models/events"
H
update  
hongming 已提交
48
	"kubesphere.io/kubesphere/pkg/models/iam/am"
H
huanggze 已提交
49
	"kubesphere.io/kubesphere/pkg/models/logging"
H
hongming 已提交
50 51
	resources "kubesphere.io/kubesphere/pkg/models/resources/v1alpha3"
	resourcesv1alpha3 "kubesphere.io/kubesphere/pkg/models/resources/v1alpha3/resource"
R
root 已提交
52
	auditingclient "kubesphere.io/kubesphere/pkg/simple/client/auditing"
J
junotx 已提交
53
	eventsclient "kubesphere.io/kubesphere/pkg/simple/client/events"
H
huanggze 已提交
54
	loggingclient "kubesphere.io/kubesphere/pkg/simple/client/logging"
J
junotx 已提交
55 56 57
	"kubesphere.io/kubesphere/pkg/utils/stringutils"
	"strings"
	"time"
H
hongming 已提交
58 59
)

H
hongming 已提交
60
type Interface interface {
H
hongming 已提交
61 62
	ListWorkspaces(user user.Info, query *query.Query) (*api.ListResult, error)
	ListNamespaces(user user.Info, workspace string, query *query.Query) (*api.ListResult, error)
H
hongming 已提交
63
	ListFederatedNamespaces(info user.Info, workspace string, param *query.Query) (*api.ListResult, error)
H
hongming 已提交
64 65 66 67 68 69
	CreateNamespace(workspace string, namespace *corev1.Namespace) (*corev1.Namespace, error)
	CreateWorkspace(workspace *tenantv1alpha2.WorkspaceTemplate) (*tenantv1alpha2.WorkspaceTemplate, error)
	DeleteWorkspace(workspace string) error
	UpdateWorkspace(workspace *tenantv1alpha2.WorkspaceTemplate) (*tenantv1alpha2.WorkspaceTemplate, error)
	DescribeWorkspace(workspace string) (*tenantv1alpha2.WorkspaceTemplate, error)
	ListWorkspaceClusters(workspace string) (*api.ListResult, error)
J
junotx 已提交
70
	Events(user user.Info, queryParam *eventsv1alpha1.Query) (*eventsv1alpha1.APIResponse, error)
H
huanggze 已提交
71 72
	QueryLogs(user user.Info, query *loggingv1alpha2.Query) (*loggingv1alpha2.APIResponse, error)
	ExportLogs(user user.Info, query *loggingv1alpha2.Query, writer io.Writer) error
R
root 已提交
73
	Auditing(user user.Info, queryParam *auditingv1alpha1.Query) (*auditingv1alpha1.APIResponse, error)
H
hongming 已提交
74 75 76 77 78
	DescribeNamespace(workspace, namespace string) (*corev1.Namespace, error)
	DeleteNamespace(workspace, namespace string) error
	UpdateNamespace(workspace string, namespace *corev1.Namespace) (*corev1.Namespace, error)
	PatchNamespace(workspace string, namespace *corev1.Namespace) (*corev1.Namespace, error)
	PatchWorkspace(workspace *tenantv1alpha2.WorkspaceTemplate) (*tenantv1alpha2.WorkspaceTemplate, error)
79
	ListClusters(info user.Info) (*api.ListResult, error)
H
hongming 已提交
80
}
H
hongming 已提交
81

H
hongming 已提交
82
type tenantOperator struct {
H
hongming 已提交
83 84
	am             am.AccessManagementInterface
	authorizer     authorizer.Authorizer
H
hongming 已提交
85 86
	k8sclient      kubernetes.Interface
	ksclient       kubesphere.Interface
H
hongming 已提交
87
	resourceGetter *resourcesv1alpha3.ResourceGetter
J
junotx 已提交
88
	events         events.Interface
H
huanggze 已提交
89
	lo             logging.LoggingOperator
R
root 已提交
90
	auditing       auditing.Interface
H
hongming 已提交
91 92
}

R
root 已提交
93
func New(informers informers.InformerFactory, k8sclient kubernetes.Interface, ksclient kubesphere.Interface, evtsClient eventsclient.Client, loggingClient loggingclient.Interface, auditingclient auditingclient.Client) Interface {
H
hongming 已提交
94 95
	amOperator := am.NewReadOnlyOperator(informers)
	authorizer := authorizerfactory.NewRBACAuthorizer(amOperator)
H
update  
hongming 已提交
96
	return &tenantOperator{
H
hongming 已提交
97
		am:             amOperator,
H
hongming 已提交
98
		authorizer:     authorizer,
H
hongming 已提交
99
		resourceGetter: resourcesv1alpha3.NewResourceGetter(informers),
H
hongming 已提交
100 101
		k8sclient:      k8sclient,
		ksclient:       ksclient,
J
junotx 已提交
102
		events:         events.NewEventsOperator(evtsClient),
H
huanggze 已提交
103
		lo:             logging.NewLoggingOperator(loggingClient),
R
root 已提交
104
		auditing:       auditing.NewEventsOperator(auditingclient),
H
update  
hongming 已提交
105
	}
H
hongming 已提交
106 107
}

H
hongming 已提交
108
func (t *tenantOperator) ListWorkspaces(user user.Info, queryParam *query.Query) (*api.ListResult, error) {
H
hongming 已提交
109 110

	listWS := authorizer.AttributesRecord{
H
hongming 已提交
111 112
		User:            user,
		Verb:            "list",
H
hongming 已提交
113
		APIGroup:        "*",
H
hongming 已提交
114 115
		Resource:        "workspaces",
		ResourceRequest: true,
H
hongming 已提交
116
		ResourceScope:   request.GlobalScope,
H
hongming 已提交
117 118 119
	}

	decision, _, err := t.authorizer.Authorize(listWS)
H
hongming 已提交
120

H
update  
hongming 已提交
121 122 123 124
	if err != nil {
		klog.Error(err)
		return nil, err
	}
H
hongming 已提交
125

H
hongming 已提交
126
	if decision == authorizer.DecisionAllow {
H
update  
hongming 已提交
127

H
hongming 已提交
128
		result, err := t.resourceGetter.List(tenantv1alpha2.ResourcePluralWorkspaceTemplate, "", queryParam)
H
hongming 已提交
129

H
update  
hongming 已提交
130 131 132 133
		if err != nil {
			klog.Error(err)
			return nil, err
		}
H
hongming 已提交
134

H
hongming 已提交
135 136 137 138 139 140 141 142 143
		return result, nil
	}

	workspaceRoleBindings, err := t.am.ListWorkspaceRoleBindings(user.GetName(), "")

	if err != nil {
		klog.Error(err)
		return nil, err
	}
H
hongming 已提交
144

H
hongming 已提交
145
	workspaces := make([]runtime.Object, 0)
H
hongming 已提交
146

H
hongming 已提交
147
	for _, roleBinding := range workspaceRoleBindings {
H
hongming 已提交
148

H
hongming 已提交
149
		workspaceName := roleBinding.Labels[tenantv1alpha1.WorkspaceLabel]
H
hongming 已提交
150
		workspace, err := t.resourceGetter.Get(tenantv1alpha2.ResourcePluralWorkspaceTemplate, "", workspaceName)
H
hongming 已提交
151

H
hongming 已提交
152
		if errors.IsNotFound(err) {
H
hongming 已提交
153
			klog.Warningf("workspace role binding: %+v found but workspace not exist", roleBinding.ObjectMeta.String())
H
hongming 已提交
154 155 156 157 158 159 160 161 162 163
			continue
		}

		if err != nil {
			klog.Error(err)
			return nil, err
		}

		if !contains(workspaces, workspace) {
			workspaces = append(workspaces, workspace)
H
update  
hongming 已提交
164
		}
H
hongming 已提交
165
	}
H
hongming 已提交
166

H
hongming 已提交
167
	result := resources.DefaultList(workspaces, queryParam, func(left runtime.Object, right runtime.Object, field query.Field) bool {
H
hongming 已提交
168
		return resources.DefaultObjectMetaCompare(left.(*tenantv1alpha2.WorkspaceTemplate).ObjectMeta, right.(*tenantv1alpha2.WorkspaceTemplate).ObjectMeta, field)
H
hongming 已提交
169
	}, func(workspace runtime.Object, filter query.Filter) bool {
H
hongming 已提交
170
		return resources.DefaultObjectMetaFilter(workspace.(*tenantv1alpha2.WorkspaceTemplate).ObjectMeta, filter)
H
hongming 已提交
171 172 173
	})

	return result, nil
H
hongming 已提交
174 175
}

H
hongming 已提交
176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225
func (t *tenantOperator) ListFederatedNamespaces(user user.Info, workspace string, queryParam *query.Query) (*api.ListResult, error) {
	nsScope := request.ClusterScope
	if workspace != "" {
		nsScope = request.WorkspaceScope
	}

	listNS := authorizer.AttributesRecord{
		User:            user,
		Verb:            "list",
		Workspace:       workspace,
		Resource:        "namespaces",
		ResourceRequest: true,
		ResourceScope:   nsScope,
	}

	decision, _, err := t.authorizer.Authorize(listNS)

	if err != nil {
		klog.Error(err)
		return nil, err
	}

	if decision == authorizer.DecisionAllow {

		if workspace != "" {
			queryParam.Filters[query.FieldLabel] = query.Value(fmt.Sprintf("%s=%s", tenantv1alpha1.WorkspaceLabel, workspace))
		}

		result, err := t.resourceGetter.List(typesv1beta1.ResourcesPluralFedNamespace, "", queryParam)

		if err != nil {
			klog.Error(err)
			return nil, err
		}

		return result, nil
	}

	roleBindings, err := t.am.ListRoleBindings(user.GetName(), "")

	if err != nil {
		klog.Error(err)
		return nil, err
	}

	namespaces := make([]runtime.Object, 0)

	for _, roleBinding := range roleBindings {
		namespace, err := t.resourceGetter.Get(typesv1beta1.ResourcesPluralFedNamespace, roleBinding.Namespace, roleBinding.Namespace)
		if err != nil {
H
hongming 已提交
226 227 228
			if errors.IsNotFound(err) {
				continue
			}
H
hongming 已提交
229 230 231 232 233 234 235 236 237 238 239 240 241 242 243
			klog.Error(err)
			return nil, err
		}

		// skip if not controlled by the specified workspace
		if ns := namespace.(*typesv1beta1.FederatedNamespace); workspace != "" && ns.Labels[tenantv1alpha1.WorkspaceLabel] != workspace {
			continue
		}

		if !contains(namespaces, namespace) {
			namespaces = append(namespaces, namespace)
		}
	}

	result := resources.DefaultList(namespaces, queryParam, func(left runtime.Object, right runtime.Object, field query.Field) bool {
H
hongming 已提交
244
		return resources.DefaultObjectMetaCompare(left.(*typesv1beta1.FederatedNamespace).ObjectMeta, right.(*typesv1beta1.FederatedNamespace).ObjectMeta, field)
H
hongming 已提交
245 246 247 248 249 250 251 252 253 254 255 256
	}, func(object runtime.Object, filter query.Filter) bool {
		namespace := object.(*typesv1beta1.FederatedNamespace).ObjectMeta
		if workspace != "" {
			if workspaceLabel, ok := namespace.Labels[tenantv1alpha1.WorkspaceLabel]; !ok || workspaceLabel != workspace {
				return false
			}
		}
		return resources.DefaultObjectMetaFilter(namespace, filter)
	})
	return result, nil
}

H
hongming 已提交
257
func (t *tenantOperator) ListNamespaces(user user.Info, workspace string, queryParam *query.Query) (*api.ListResult, error) {
258 259 260 261
	nsScope := request.ClusterScope
	if workspace != "" {
		nsScope = request.WorkspaceScope
	}
H
hongming 已提交
262

263
	listNS := authorizer.AttributesRecord{
H
hongming 已提交
264 265 266 267 268
		User:            user,
		Verb:            "list",
		Workspace:       workspace,
		Resource:        "namespaces",
		ResourceRequest: true,
269
		ResourceScope:   nsScope,
H
hongming 已提交
270
	}
H
update  
hongming 已提交
271

272
	decision, _, err := t.authorizer.Authorize(listNS)
H
hongming 已提交
273 274

	if err != nil {
H
update  
hongming 已提交
275
		klog.Error(err)
H
hongming 已提交
276 277 278
		return nil, err
	}

H
hongming 已提交
279
	if decision == authorizer.DecisionAllow {
H
hongming 已提交
280

H
hongming 已提交
281 282 283
		if workspace != "" {
			queryParam.Filters[query.FieldLabel] = query.Value(fmt.Sprintf("%s=%s", tenantv1alpha1.WorkspaceLabel, workspace))
		}
H
hongming 已提交
284 285

		result, err := t.resourceGetter.List("namespaces", "", queryParam)
H
hongming 已提交
286

H
update  
hongming 已提交
287 288 289 290
		if err != nil {
			klog.Error(err)
			return nil, err
		}
H
hongming 已提交
291

H
hongming 已提交
292 293 294 295
		return result, nil
	}

	roleBindings, err := t.am.ListRoleBindings(user.GetName(), "")
H
hongming 已提交
296

H
hongming 已提交
297 298 299 300
	if err != nil {
		klog.Error(err)
		return nil, err
	}
H
hongming 已提交
301

H
hongming 已提交
302
	namespaces := make([]runtime.Object, 0)
H
hongming 已提交
303

H
hongming 已提交
304
	for _, roleBinding := range roleBindings {
H
hongming 已提交
305
		namespace, err := t.resourceGetter.Get("namespaces", "", roleBinding.Namespace)
H
update  
hongming 已提交
306

H
hongming 已提交
307 308 309 310
		if err != nil {
			klog.Error(err)
			return nil, err
		}
H
update  
hongming 已提交
311

H
hongming 已提交
312
		// skip if not controlled by the specified workspace
H
hongming 已提交
313
		if ns := namespace.(*corev1.Namespace); workspace != "" && ns.Labels[tenantv1alpha1.WorkspaceLabel] != workspace {
H
hongming 已提交
314 315 316
			continue
		}

H
hongming 已提交
317 318
		if !contains(namespaces, namespace) {
			namespaces = append(namespaces, namespace)
H
update  
hongming 已提交
319
		}
H
hongming 已提交
320 321
	}

H
hongming 已提交
322 323 324 325
	result := resources.DefaultList(namespaces, queryParam, func(left runtime.Object, right runtime.Object, field query.Field) bool {
		return resources.DefaultObjectMetaCompare(left.(*corev1.Namespace).ObjectMeta, right.(*corev1.Namespace).ObjectMeta, field)
	}, func(object runtime.Object, filter query.Filter) bool {
		namespace := object.(*corev1.Namespace).ObjectMeta
326 327 328 329
		if workspace != "" {
			if workspaceLabel, ok := namespace.Labels[tenantv1alpha1.WorkspaceLabel]; !ok || workspaceLabel != workspace {
				return false
			}
H
hongming 已提交
330
		}
H
hongming 已提交
331 332
		return resources.DefaultObjectMetaFilter(namespace, filter)
	})
H
hongming 已提交
333

H
hongming 已提交
334
	return result, nil
H
update  
hongming 已提交
335 336
}

337 338 339
// CreateNamespace adds a workspace label to namespace which indicates namespace is under the workspace
// The reason here why don't check the existence of workspace anymore is this function is only executed in host cluster.
// but if the host cluster is not authorized to workspace, there will be no workspace in host cluster.
H
hongming 已提交
340
func (t *tenantOperator) CreateNamespace(workspace string, namespace *corev1.Namespace) (*corev1.Namespace, error) {
341
	return t.k8sclient.CoreV1().Namespaces().Create(labelNamespaceWithWorkspaceName(namespace, workspace))
H
hongming 已提交
342 343
}

344 345 346
// labelNamespaceWithWorkspaceName adds a kubesphere.io/workspace=[workspaceName] label to namespace which
// indicates namespace is under the workspace
func labelNamespaceWithWorkspaceName(namespace *corev1.Namespace, workspaceName string) *corev1.Namespace {
H
hongming 已提交
347 348 349
	if namespace.Labels == nil {
		namespace.Labels = make(map[string]string, 0)
	}
350 351 352

	namespace.Labels[tenantv1alpha1.WorkspaceLabel] = workspaceName // label namespace with workspace name

H
hongming 已提交
353 354
	return namespace
}
H
hongming 已提交
355

H
hongming 已提交
356 357
func (t *tenantOperator) DescribeNamespace(workspace, namespace string) (*corev1.Namespace, error) {
	obj, err := t.resourceGetter.Get("namespaces", "", namespace)
H
hongming 已提交
358 359 360
	if err != nil {
		return nil, err
	}
H
hongming 已提交
361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376
	ns := obj.(*corev1.Namespace)
	if ns.Labels[tenantv1alpha1.WorkspaceLabel] != workspace {
		err := errors.NewNotFound(corev1.Resource("namespace"), namespace)
		klog.Error(err)
		return nil, err
	}
	return ns, nil
}

func (t *tenantOperator) DeleteNamespace(workspace, namespace string) error {
	_, err := t.DescribeNamespace(workspace, namespace)
	if err != nil {
		return err
	}
	return t.k8sclient.CoreV1().Namespaces().Delete(namespace, metav1.NewDeleteOptions(0))
}
H
hongming 已提交
377

H
hongming 已提交
378
func (t *tenantOperator) UpdateNamespace(workspace string, namespace *corev1.Namespace) (*corev1.Namespace, error) {
H
hongming 已提交
379
	_, err := t.DescribeNamespace(workspace, namespace.Name)
H
hongming 已提交
380 381
	if err != nil {
		return nil, err
H
hongming 已提交
382
	}
383
	namespace = labelNamespaceWithWorkspaceName(namespace, workspace)
H
hongming 已提交
384 385
	return t.k8sclient.CoreV1().Namespaces().Update(namespace)
}
H
hongming 已提交
386

H
hongming 已提交
387 388 389 390 391 392 393 394 395 396 397 398 399 400
func (t *tenantOperator) PatchNamespace(workspace string, namespace *corev1.Namespace) (*corev1.Namespace, error) {
	_, err := t.DescribeNamespace(workspace, namespace.Name)
	if err != nil {
		return nil, err
	}
	if namespace.Labels != nil {
		namespace.Labels[tenantv1alpha1.WorkspaceLabel] = workspace
	}
	data, err := json.Marshal(namespace)
	if err != nil {
		return nil, err
	}
	return t.k8sclient.CoreV1().Namespaces().Patch(namespace.Name, types.MergePatchType, data)
}
H
hongming 已提交
401

H
hongming 已提交
402 403 404 405 406 407 408 409 410 411
func (t *tenantOperator) PatchWorkspace(workspace *tenantv1alpha2.WorkspaceTemplate) (*tenantv1alpha2.WorkspaceTemplate, error) {
	_, err := t.DescribeWorkspace(workspace.Name)
	if err != nil {
		return nil, err
	}
	data, err := json.Marshal(workspace)
	if err != nil {
		return nil, err
	}
	return t.ksclient.TenantV1alpha2().WorkspaceTemplates().Patch(workspace.Name, types.MergePatchType, data)
H
hongming 已提交
412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435
}

func (t *tenantOperator) CreateWorkspace(workspace *tenantv1alpha2.WorkspaceTemplate) (*tenantv1alpha2.WorkspaceTemplate, error) {
	return t.ksclient.TenantV1alpha2().WorkspaceTemplates().Create(workspace)
}

func (t *tenantOperator) UpdateWorkspace(workspace *tenantv1alpha2.WorkspaceTemplate) (*tenantv1alpha2.WorkspaceTemplate, error) {
	return t.ksclient.TenantV1alpha2().WorkspaceTemplates().Update(workspace)
}

func (t *tenantOperator) DescribeWorkspace(workspace string) (*tenantv1alpha2.WorkspaceTemplate, error) {
	obj, err := t.resourceGetter.Get(tenantv1alpha2.ResourcePluralWorkspaceTemplate, "", workspace)
	if err != nil {
		klog.Error(err)
		return nil, err
	}
	return obj.(*tenantv1alpha2.WorkspaceTemplate), nil
}
func (t *tenantOperator) ListWorkspaceClusters(workspaceName string) (*api.ListResult, error) {
	workspace, err := t.DescribeWorkspace(workspaceName)
	if err != nil {
		klog.Error(err)
		return nil, err
	}
436 437 438 439 440 441 442 443 444 445 446 447

	// In this case, spec.placement.clusterSelector will be ignored, since spec.placement.clusters is provided.
	if workspace.Spec.Placement.Clusters != nil {
		clusters := make([]interface{}, 0)
		for _, cluster := range workspace.Spec.Placement.Clusters {
			obj, err := t.resourceGetter.Get(clusterv1alpha1.ResourcesPluralCluster, "", cluster.Name)
			if err != nil {
				klog.Error(err)
				if errors.IsNotFound(err) {
					continue
				}
				return nil, err
H
hongming 已提交
448
			}
449
			clusters = append(clusters, obj)
H
hongming 已提交
450
		}
451
		return &api.ListResult{Items: clusters, TotalItems: len(clusters)}, nil
H
hongming 已提交
452
	}
453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469

	if workspace.Spec.Placement.ClusterSelector != nil {
		// In this case, the resource will be propagated to all member clusters.
		if workspace.Spec.Placement.ClusterSelector.MatchLabels == nil {
			return t.resourceGetter.List(clusterv1alpha1.ResourcesPluralCluster, "", query.New())
		} else {
			// In this case, the resource will only be propagated to member clusters that are labeled with foo: bar.
			return t.resourceGetter.List(clusterv1alpha1.ResourcesPluralCluster, "", &query.Query{
				Pagination:    query.NoPagination,
				Ascending:     false,
				LabelSelector: labels.SelectorFromSet(workspace.Spec.Placement.ClusterSelector.MatchLabels).String(),
			})
		}
	}

	// In this case, you can either set spec: {} as above or remove spec field from your placement policy. The resource will not be propagated to member clusters.
	return &api.ListResult{Items: []interface{}{}, TotalItems: 0}, nil
H
hongming 已提交
470
}
471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529
func (t *tenantOperator) ListClusters(user user.Info) (*api.ListResult, error) {

	listClustersInGlobalScope := authorizer.AttributesRecord{
		User:            user,
		Verb:            "list",
		Resource:        "clusters",
		ResourceScope:   request.GlobalScope,
		ResourceRequest: true,
	}

	allowedListClustersInGlobalScope, _, err := t.authorizer.Authorize(listClustersInGlobalScope)

	if err != nil {
		klog.Error(err)
		return nil, err
	}

	listWorkspacesInGlobalScope := authorizer.AttributesRecord{
		User:            user,
		Verb:            "list",
		Resource:        "workspaces",
		ResourceScope:   request.GlobalScope,
		ResourceRequest: true,
	}

	allowedListWorkspacesInGlobalScope, _, err := t.authorizer.Authorize(listWorkspacesInGlobalScope)

	if err != nil {
		klog.Error(err)
		return nil, err
	}

	if allowedListClustersInGlobalScope == authorizer.DecisionAllow ||
		allowedListWorkspacesInGlobalScope == authorizer.DecisionAllow {
		result, err := t.resourceGetter.List(clusterv1alpha1.ResourcesPluralCluster, "", query.New())
		if err != nil {
			klog.Error(err)
			return nil, err
		}
		return result, nil
	}

	workspaceRoleBindings, err := t.am.ListWorkspaceRoleBindings(user.GetName(), "")

	if err != nil {
		klog.Error(err)
		return nil, err
	}

	clusters := map[string]*clusterv1alpha1.Cluster{}

	for _, roleBinding := range workspaceRoleBindings {
		workspaceName := roleBinding.Labels[tenantv1alpha1.WorkspaceLabel]
		workspace, err := t.DescribeWorkspace(workspaceName)
		if err != nil {
			klog.Error(err)
			return nil, err
		}

H
hongming 已提交
530
		for _, grantedCluster := range workspace.Spec.Placement.Clusters {
531
			// skip if cluster exist
H
hongming 已提交
532
			if clusters[grantedCluster.Name] != nil {
533 534
				continue
			}
H
hongming 已提交
535
			obj, err := t.resourceGetter.Get(clusterv1alpha1.ResourcesPluralCluster, "", grantedCluster.Name)
536 537 538 539 540 541 542 543
			if err != nil {
				klog.Error(err)
				if errors.IsNotFound(err) {
					continue
				}
				return nil, err
			}
			cluster := obj.(*clusterv1alpha1.Cluster)
H
hongming 已提交
544
			clusters[cluster.Name] = cluster
545 546 547 548 549 550 551 552 553 554
		}
	}

	items := make([]interface{}, 0)
	for _, cluster := range clusters {
		items = append(items, cluster)
	}

	return &api.ListResult{Items: items, TotalItems: len(items)}, nil
}
H
hongming 已提交
555 556 557 558 559

func (t *tenantOperator) DeleteWorkspace(workspace string) error {
	return t.ksclient.TenantV1alpha2().WorkspaceTemplates().Delete(workspace, metav1.NewDeleteOptions(0))
}

J
junotx 已提交
560 561 562 563 564 565 566 567 568 569 570 571 572 573
// listIntersectedNamespaces lists the namespaces which meet all the following conditions at the same time
// 1. the namespace which belongs to user.
// 2. the namespace in workspace which is in workspaces when workspaces is not empty.
// 3. the namespace in workspace which contains one of workspaceSubstrs when workspaceSubstrs is not empty.
// 4. the namespace which is in namespaces when namespaces is not empty.
// 5. the namespace which contains one of namespaceSubstrs when namespaceSubstrs is not empty.
func (t *tenantOperator) listIntersectedNamespaces(user user.Info,
	workspaces, workspaceSubstrs, namespaces, namespaceSubstrs []string) ([]*corev1.Namespace, error) {
	var (
		namespaceSet = stringSet(namespaces)
		workspaceSet = stringSet(workspaces)

		iNamespaces []*corev1.Namespace
	)
J
junotx 已提交
574
	includeNsWithoutWs := len(workspaceSet) == 0 && len(workspaceSubstrs) == 0
J
junotx 已提交
575

576
	result, err := t.ListNamespaces(user, "", query.New())
J
junotx 已提交
577 578 579
	if err != nil {
		return nil, err
	}
580 581 582 583 584 585
	for _, obj := range result.Items {
		ns, ok := obj.(*corev1.Namespace)
		if !ok {
			continue
		}

J
junotx 已提交
586
		if len(namespaceSet) > 0 {
587
			if _, ok := namespaceSet[ns.Name]; !ok {
J
junotx 已提交
588 589 590
				continue
			}
		}
591
		if len(namespaceSubstrs) > 0 && !stringContains(ns.Name, namespaceSubstrs) {
J
junotx 已提交
592 593
			continue
		}
594 595 596
		if ws := ns.Labels[tenantv1alpha1.WorkspaceLabel]; ws != "" {
			if len(workspaceSet) > 0 {
				if _, ok := workspaceSet[ws]; !ok {
J
junotx 已提交
597 598
					continue
				}
599 600
			}
			if len(workspaceSubstrs) > 0 && !stringContains(ws, workspaceSubstrs) {
J
junotx 已提交
601 602
				continue
			}
603 604
		} else if !includeNsWithoutWs {
			continue
J
junotx 已提交
605
		}
606
		iNamespaces = append(iNamespaces, ns)
J
junotx 已提交
607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632
	}
	return iNamespaces, nil
}

func (t *tenantOperator) Events(user user.Info, queryParam *eventsv1alpha1.Query) (*eventsv1alpha1.APIResponse, error) {
	iNamespaces, err := t.listIntersectedNamespaces(user,
		stringutils.Split(queryParam.WorkspaceFilter, ","),
		stringutils.Split(queryParam.WorkspaceSearch, ","),
		stringutils.Split(queryParam.InvolvedObjectNamespaceFilter, ","),
		stringutils.Split(queryParam.InvolvedObjectNamespaceSearch, ","))
	if err != nil {
		klog.Error(err)
		return nil, err
	}

	namespaceCreateTimeMap := make(map[string]time.Time)

	for _, ns := range iNamespaces {
		listEvts := authorizer.AttributesRecord{
			User:            user,
			Verb:            "list",
			APIGroup:        "",
			APIVersion:      "v1",
			Namespace:       ns.Name,
			Resource:        "events",
			ResourceRequest: true,
633
			ResourceScope:   request.NamespaceScope,
J
junotx 已提交
634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654
		}
		decision, _, err := t.authorizer.Authorize(listEvts)
		if err != nil {
			klog.Error(err)
			return nil, err
		}
		if decision == authorizer.DecisionAllow {
			namespaceCreateTimeMap[ns.Name] = ns.CreationTimestamp.Time
		}
	}
	// If there are no ns and ws query conditions,
	// those events with empty `involvedObject.namespace` will also be listed when user can list all events
	if len(queryParam.WorkspaceFilter) == 0 && len(queryParam.InvolvedObjectNamespaceFilter) == 0 &&
		len(queryParam.WorkspaceSearch) == 0 && len(queryParam.InvolvedObjectNamespaceSearch) == 0 {
		listEvts := authorizer.AttributesRecord{
			User:            user,
			Verb:            "list",
			APIGroup:        "",
			APIVersion:      "v1",
			Resource:        "events",
			ResourceRequest: true,
655
			ResourceScope:   request.ClusterScope,
J
junotx 已提交
656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671
		}
		decision, _, err := t.authorizer.Authorize(listEvts)
		if err != nil {
			klog.Error(err)
			return nil, err
		}
		if decision == authorizer.DecisionAllow {
			namespaceCreateTimeMap[""] = time.Time{}
		}
	}

	return t.events.Events(queryParam, func(filter *eventsclient.Filter) {
		filter.InvolvedObjectNamespaceMap = namespaceCreateTimeMap
	})
}

H
huanggze 已提交
672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692 693
func (t *tenantOperator) QueryLogs(user user.Info, query *loggingv1alpha2.Query) (*loggingv1alpha2.APIResponse, error) {
	iNamespaces, err := t.listIntersectedNamespaces(user,
		stringutils.Split(query.WorkspaceFilter, ","),
		stringutils.Split(query.WorkspaceSearch, ","),
		stringutils.Split(query.NamespaceFilter, ","),
		stringutils.Split(query.NamespaceSearch, ","))
	if err != nil {
		klog.Error(err)
		return nil, err
	}

	namespaceCreateTimeMap := make(map[string]time.Time)
	for _, ns := range iNamespaces {
		podLogs := authorizer.AttributesRecord{
			User:            user,
			Verb:            "get",
			APIGroup:        "",
			APIVersion:      "v1",
			Namespace:       ns.Name,
			Resource:        "pods",
			Subresource:     "log",
			ResourceRequest: true,
H
huanggze 已提交
694
			ResourceScope:   request.NamespaceScope,
H
huanggze 已提交
695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764
		}
		decision, _, err := t.authorizer.Authorize(podLogs)
		if err != nil {
			klog.Error(err)
			return nil, err
		}
		if decision == authorizer.DecisionAllow {
			namespaceCreateTimeMap[ns.Name] = ns.CreationTimestamp.Time
		}
	}

	sf := loggingclient.SearchFilter{
		NamespaceFilter: namespaceCreateTimeMap,
		WorkloadSearch:  stringutils.Split(query.WorkloadSearch, ","),
		WorkloadFilter:  stringutils.Split(query.WorkloadFilter, ","),
		PodSearch:       stringutils.Split(query.PodSearch, ","),
		PodFilter:       stringutils.Split(query.PodFilter, ","),
		ContainerSearch: stringutils.Split(query.ContainerSearch, ","),
		ContainerFilter: stringutils.Split(query.ContainerFilter, ","),
		LogSearch:       stringutils.Split(query.LogSearch, ","),
		Starttime:       query.StartTime,
		Endtime:         query.EndTime,
	}

	var ar loggingv1alpha2.APIResponse
	switch query.Operation {
	case loggingv1alpha2.OperationStatistics:
		if len(namespaceCreateTimeMap) == 0 {
			ar.Statistics = &loggingclient.Statistics{}
		} else {
			ar, err = t.lo.GetCurrentStats(sf)
		}
	case loggingv1alpha2.OperationHistogram:
		if len(namespaceCreateTimeMap) == 0 {
			ar.Histogram = &loggingclient.Histogram{}
		} else {
			ar, err = t.lo.CountLogsByInterval(sf, query.Interval)
		}
	default:
		if len(namespaceCreateTimeMap) == 0 {
			ar.Logs = &loggingclient.Logs{}
		} else {
			ar, err = t.lo.SearchLogs(sf, query.From, query.Size, query.Sort)
		}
	}
	return &ar, err
}

func (t *tenantOperator) ExportLogs(user user.Info, query *loggingv1alpha2.Query, writer io.Writer) error {
	iNamespaces, err := t.listIntersectedNamespaces(user,
		stringutils.Split(query.WorkspaceFilter, ","),
		stringutils.Split(query.WorkspaceSearch, ","),
		stringutils.Split(query.NamespaceFilter, ","),
		stringutils.Split(query.NamespaceSearch, ","))
	if err != nil {
		klog.Error(err)
		return err
	}

	namespaceCreateTimeMap := make(map[string]time.Time)
	for _, ns := range iNamespaces {
		podLogs := authorizer.AttributesRecord{
			User:            user,
			Verb:            "get",
			APIGroup:        "",
			APIVersion:      "v1",
			Namespace:       ns.Name,
			Resource:        "pods",
			Subresource:     "log",
			ResourceRequest: true,
H
huanggze 已提交
765
			ResourceScope:   request.NamespaceScope,
H
huanggze 已提交
766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796
		}
		decision, _, err := t.authorizer.Authorize(podLogs)
		if err != nil {
			klog.Error(err)
			return err
		}
		if decision == authorizer.DecisionAllow {
			namespaceCreateTimeMap[ns.Name] = ns.CreationTimestamp.Time
		}
	}

	sf := loggingclient.SearchFilter{
		NamespaceFilter: namespaceCreateTimeMap,
		WorkloadSearch:  stringutils.Split(query.WorkloadSearch, ","),
		WorkloadFilter:  stringutils.Split(query.WorkloadFilter, ","),
		PodSearch:       stringutils.Split(query.PodSearch, ","),
		PodFilter:       stringutils.Split(query.PodFilter, ","),
		ContainerSearch: stringutils.Split(query.ContainerSearch, ","),
		ContainerFilter: stringutils.Split(query.ContainerFilter, ","),
		LogSearch:       stringutils.Split(query.LogSearch, ","),
		Starttime:       query.StartTime,
		Endtime:         query.EndTime,
	}

	if len(namespaceCreateTimeMap) == 0 {
		return nil
	} else {
		return t.lo.ExportLogs(sf, writer)
	}
}

R
root 已提交
797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815
func (t *tenantOperator) Auditing(user user.Info, queryParam *auditingv1alpha1.Query) (*auditingv1alpha1.APIResponse, error) {
	iNamespaces, err := t.listIntersectedNamespaces(user,
		stringutils.Split(queryParam.WorkspaceFilter, ","),
		stringutils.Split(queryParam.WorkspaceSearch, ","),
		stringutils.Split(queryParam.ObjectRefNamespaceFilter, ","),
		stringutils.Split(queryParam.ObjectRefNamespaceSearch, ","))
	if err != nil {
		klog.Error(err)
		return nil, err
	}

	namespaceCreateTimeMap := make(map[string]time.Time)
	for _, ns := range iNamespaces {
		namespaceCreateTimeMap[ns.Name] = ns.CreationTimestamp.Time
	}
	// If there are no ns and ws query conditions,
	// those events with empty `ObjectRef.Namespace` will also be listed when user can list all namespaces
	if len(queryParam.WorkspaceFilter) == 0 && len(queryParam.ObjectRefNamespaceFilter) == 0 &&
		len(queryParam.WorkspaceSearch) == 0 && len(queryParam.ObjectRefNamespaceSearch) == 0 {
816
		listNs := authorizer.AttributesRecord{
R
root 已提交
817 818 819 820
			User:            user,
			Verb:            "list",
			Resource:        "namespaces",
			ResourceRequest: true,
821
			ResourceScope:   request.ClusterScope,
R
root 已提交
822
		}
823
		decision, _, err := t.authorizer.Authorize(listNs)
R
root 已提交
824 825 826 827 828 829 830 831 832 833 834 835 836 837
		if err != nil {
			klog.Error(err)
			return nil, err
		}
		if decision == authorizer.DecisionAllow {
			namespaceCreateTimeMap[""] = time.Time{}
		}
	}

	return t.auditing.Events(queryParam, func(filter *auditingclient.Filter) {
		filter.ObjectRefNamespaceMap = namespaceCreateTimeMap
	})
}

H
hongming 已提交
838 839 840 841 842
func contains(objects []runtime.Object, object runtime.Object) bool {
	for _, item := range objects {
		if item == object {
			return true
		}
H
update  
hongming 已提交
843
	}
H
hongming 已提交
844
	return false
H
hongming 已提交
845
}
J
junotx 已提交
846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862

func stringSet(strs []string) map[string]struct{} {
	m := make(map[string]struct{})
	for _, str := range strs {
		m[str] = struct{}{}
	}
	return m
}

func stringContains(str string, subStrs []string) bool {
	for _, sub := range subStrs {
		if strings.Contains(str, sub) {
			return true
		}
	}
	return false
}