tenant.go 5.4 KB
Newer Older
H
hongming 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
/*

 Copyright 2019 The KubeSphere Authors.

 Licensed under the Apache License, Version 2.0 (the "License");
 you may not use this file except in compliance with the License.
 You may obtain a copy of the License at

     http://www.apache.org/licenses/LICENSE-2.0

 Unless required by applicable law or agreed to in writing, software
 distributed under the License is distributed on an "AS IS" BASIS,
 WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 See the License for the specific language governing permissions and
 limitations under the License.

*/
package tenant

import (
H
update  
hongming 已提交
21 22 23
	corev1 "k8s.io/api/core/v1"
	"k8s.io/apimachinery/pkg/api/errors"
	"k8s.io/apimachinery/pkg/labels"
H
hongming 已提交
24
	"k8s.io/apiserver/pkg/authentication/user"
H
update  
hongming 已提交
25 26 27 28
	"k8s.io/klog"
	"kubesphere.io/kubesphere/pkg/api"
	iamv1alpha2 "kubesphere.io/kubesphere/pkg/apis/iam/v1alpha2"
	tenantv1alpha1 "kubesphere.io/kubesphere/pkg/apis/tenant/v1alpha1"
H
hongming 已提交
29 30
	"kubesphere.io/kubesphere/pkg/apiserver/authorization/authorizer"
	"kubesphere.io/kubesphere/pkg/apiserver/authorization/authorizerfactory"
H
update  
hongming 已提交
31
	"kubesphere.io/kubesphere/pkg/informers"
H
update  
hongming 已提交
32
	"kubesphere.io/kubesphere/pkg/models/iam/am"
H
update  
hongming 已提交
33
	"kubesphere.io/kubesphere/pkg/simple/client/k8s"
H
hongming 已提交
34 35
)

H
hongming 已提交
36
type Interface interface {
H
hongming 已提交
37 38
	ListWorkspaces(user user.Info) (*api.ListResult, error)
	ListNamespaces(user user.Info, workspace string) (*api.ListResult, error)
H
hongming 已提交
39
}
H
hongming 已提交
40

H
hongming 已提交
41
type tenantOperator struct {
H
hongming 已提交
42 43 44
	informers  informers.InformerFactory
	am         am.AccessManagementInterface
	authorizer authorizer.Authorizer
H
hongming 已提交
45 46
}

H
update  
hongming 已提交
47
func New(k8sClient k8s.Client, informers informers.InformerFactory) Interface {
H
hongming 已提交
48 49
	amOperator := am.NewAMOperator(k8sClient.KubeSphere(), informers.KubeSphereSharedInformerFactory())
	opaAuthorizer := authorizerfactory.NewOPAAuthorizer(amOperator)
H
update  
hongming 已提交
50
	return &tenantOperator{
H
hongming 已提交
51 52 53
		informers:  informers,
		am:         amOperator,
		authorizer: opaAuthorizer,
H
update  
hongming 已提交
54
	}
H
hongming 已提交
55 56
}

H
hongming 已提交
57 58 59 60 61 62 63 64 65 66 67 68 69
func (t *tenantOperator) ListWorkspaces(user user.Info) (*api.ListResult, error) {

	workspaces := make([]*tenantv1alpha1.Workspace, 0)

	listWS := authorizer.AttributesRecord{
		User:       user,
		Verb:       "list",
		APIGroup:   "tenant.kubesphere.io",
		APIVersion: "v1alpha2",
		Resource:   "workspaces",
	}

	decision, _, err := t.authorizer.Authorize(listWS)
H
hongming 已提交
70

H
update  
hongming 已提交
71 72 73 74
	if err != nil {
		klog.Error(err)
		return nil, err
	}
H
hongming 已提交
75

H
hongming 已提交
76 77 78
	if decision == authorizer.DecisionAllow {
		workspaces, err = t.informers.KubeSphereSharedInformerFactory().
			Tenant().V1alpha1().Workspaces().Lister().List(labels.Everything())
H
update  
hongming 已提交
79

H
hongming 已提交
80 81 82
		if err != nil {
			klog.Error(err)
			return nil, err
H
update  
hongming 已提交
83
		}
H
hongming 已提交
84 85
	} else {
		workspaceRoles, err := t.am.ListRolesOfUser(iamv1alpha2.WorkspaceScope, user.GetName())
H
update  
hongming 已提交
86 87 88 89
		if err != nil {
			klog.Error(err)
			return nil, err
		}
H
hongming 已提交
90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108

		for _, role := range workspaceRoles {

			workspace, err := t.informers.KubeSphereSharedInformerFactory().
				Tenant().V1alpha1().Workspaces().Lister().Get(role.Target.Name)

			if errors.IsNotFound(err) {
				klog.Warningf("workspace role: %s found but workspace not exist", role.Target)
				continue
			}

			if err != nil {
				klog.Error(err)
				return nil, err
			}

			if !containsWorkspace(workspaces, workspace) {
				workspaces = append(workspaces, workspace)
			}
H
update  
hongming 已提交
109
		}
H
hongming 已提交
110
	}
H
hongming 已提交
111

H
update  
hongming 已提交
112 113 114 115
	return &api.ListResult{
		TotalItems: len(workspaces),
		Items:      workspacesToInterfaces(workspaces),
	}, nil
H
hongming 已提交
116 117
}

H
hongming 已提交
118 119 120 121 122 123 124 125 126 127 128
func (t *tenantOperator) ListNamespaces(user user.Info, workspace string) (*api.ListResult, error) {
	namespaces := make([]*corev1.Namespace, 0)

	listNSInWS := authorizer.AttributesRecord{
		User:       user,
		Verb:       "list",
		APIGroup:   "",
		APIVersion: "v1",
		Workspace:  workspace,
		Resource:   "namespaces",
	}
H
update  
hongming 已提交
129

H
hongming 已提交
130
	decision, _, err := t.authorizer.Authorize(listNSInWS)
H
hongming 已提交
131 132

	if err != nil {
H
update  
hongming 已提交
133
		klog.Error(err)
H
hongming 已提交
134 135 136
		return nil, err
	}

H
hongming 已提交
137 138 139
	if decision == authorizer.DecisionAllow {
		namespaces, err = t.informers.KubernetesSharedInformerFactory().
			Core().V1().Namespaces().Lister().List(labels.Everything())
H
hongming 已提交
140

H
hongming 已提交
141 142 143
		if err != nil {
			klog.Error(err)
			return nil, err
H
update  
hongming 已提交
144
		}
H
hongming 已提交
145 146
	} else {
		namespaceRoles, err := t.am.ListRolesOfUser(iamv1alpha2.NamespaceScope, workspace)
H
hongming 已提交
147

H
update  
hongming 已提交
148 149 150 151
		if err != nil {
			klog.Error(err)
			return nil, err
		}
H
hongming 已提交
152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170

		for _, role := range namespaceRoles {

			namespace, err := t.informers.KubernetesSharedInformerFactory().
				Core().V1().Namespaces().Lister().Get(role.Target.Name)

			if errors.IsNotFound(err) {
				klog.Warningf("workspace role: %s found but workspace not exist", role.Target)
				continue
			}

			if err != nil {
				klog.Error(err)
				return nil, err
			}

			if !containsNamespace(namespaces, namespace) {
				namespaces = append(namespaces, namespace)
			}
H
update  
hongming 已提交
171 172 173 174 175 176 177 178 179 180 181 182 183 184
		}
	}

	return &api.ListResult{
		TotalItems: len(namespaces),
		Items:      namespacesToInterfaces(namespaces),
	}, nil
}

func containsWorkspace(workspaces []*tenantv1alpha1.Workspace, workspace *tenantv1alpha1.Workspace) bool {
	for _, item := range workspaces {
		if item.Name == workspace.Name {
			return true
		}
H
hongming 已提交
185
	}
H
update  
hongming 已提交
186 187
	return false
}
H
hongming 已提交
188

H
update  
hongming 已提交
189 190 191 192
func containsNamespace(namespaces []*corev1.Namespace, namespace *corev1.Namespace) bool {
	for _, item := range namespaces {
		if item.Name == namespace.Name {
			return true
H
hongming 已提交
193 194
		}
	}
H
update  
hongming 已提交
195 196
	return false
}
H
hongming 已提交
197

H
update  
hongming 已提交
198 199 200 201 202 203 204 205 206 207 208 209 210 211
func workspacesToInterfaces(workspaces []*tenantv1alpha1.Workspace) []interface{} {
	ret := make([]interface{}, len(workspaces))
	for index, v := range workspaces {
		ret[index] = v
	}
	return ret
}

func namespacesToInterfaces(namespaces []*corev1.Namespace) []interface{} {
	ret := make([]interface{}, len(namespaces))
	for index, v := range namespaces {
		ret[index] = v
	}
	return ret
H
hongming 已提交
212
}