tenant.go 25.3 KB
Newer Older
H
hongming 已提交
1
/*
H
hongming 已提交
2
Copyright 2019 The KubeSphere Authors.
H
hongming 已提交
3

H
hongming 已提交
4 5 6
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
H
hongming 已提交
7

H
hongming 已提交
8
    http://www.apache.org/licenses/LICENSE-2.0
H
hongming 已提交
9

H
hongming 已提交
10 11 12 13 14
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
H
hongming 已提交
15
*/
H
hongming 已提交
16

H
hongming 已提交
17 18 19
package tenant

import (
H
hongming 已提交
20
	"encoding/json"
H
hongming 已提交
21
	"fmt"
H
huanggze 已提交
22
	"io"
H
update  
hongming 已提交
23 24
	corev1 "k8s.io/api/core/v1"
	"k8s.io/apimachinery/pkg/api/errors"
H
hongming 已提交
25
	metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
26
	"k8s.io/apimachinery/pkg/labels"
H
hongming 已提交
27
	"k8s.io/apimachinery/pkg/runtime"
H
hongming 已提交
28
	"k8s.io/apimachinery/pkg/types"
H
hongming 已提交
29
	"k8s.io/apiserver/pkg/authentication/user"
H
hongming 已提交
30
	"k8s.io/client-go/kubernetes"
H
update  
hongming 已提交
31 32
	"k8s.io/klog"
	"kubesphere.io/kubesphere/pkg/api"
R
root 已提交
33
	auditingv1alpha1 "kubesphere.io/kubesphere/pkg/api/auditing/v1alpha1"
J
junotx 已提交
34
	eventsv1alpha1 "kubesphere.io/kubesphere/pkg/api/events/v1alpha1"
H
huanggze 已提交
35
	loggingv1alpha2 "kubesphere.io/kubesphere/pkg/api/logging/v1alpha2"
H
hongming 已提交
36
	clusterv1alpha1 "kubesphere.io/kubesphere/pkg/apis/cluster/v1alpha1"
H
update  
hongming 已提交
37
	tenantv1alpha1 "kubesphere.io/kubesphere/pkg/apis/tenant/v1alpha1"
H
hongming 已提交
38
	tenantv1alpha2 "kubesphere.io/kubesphere/pkg/apis/tenant/v1alpha2"
H
hongming 已提交
39 40
	"kubesphere.io/kubesphere/pkg/apiserver/authorization/authorizer"
	"kubesphere.io/kubesphere/pkg/apiserver/authorization/authorizerfactory"
H
hongming 已提交
41
	"kubesphere.io/kubesphere/pkg/apiserver/query"
H
hongming 已提交
42
	"kubesphere.io/kubesphere/pkg/apiserver/request"
H
hongming 已提交
43
	kubesphere "kubesphere.io/kubesphere/pkg/client/clientset/versioned"
H
update  
hongming 已提交
44
	"kubesphere.io/kubesphere/pkg/informers"
R
root 已提交
45
	"kubesphere.io/kubesphere/pkg/models/auditing"
J
junotx 已提交
46
	"kubesphere.io/kubesphere/pkg/models/events"
H
update  
hongming 已提交
47
	"kubesphere.io/kubesphere/pkg/models/iam/am"
H
huanggze 已提交
48
	"kubesphere.io/kubesphere/pkg/models/logging"
H
hongming 已提交
49 50
	resources "kubesphere.io/kubesphere/pkg/models/resources/v1alpha3"
	resourcesv1alpha3 "kubesphere.io/kubesphere/pkg/models/resources/v1alpha3/resource"
R
root 已提交
51
	auditingclient "kubesphere.io/kubesphere/pkg/simple/client/auditing"
J
junotx 已提交
52
	eventsclient "kubesphere.io/kubesphere/pkg/simple/client/events"
H
huanggze 已提交
53
	loggingclient "kubesphere.io/kubesphere/pkg/simple/client/logging"
J
junotx 已提交
54 55 56
	"kubesphere.io/kubesphere/pkg/utils/stringutils"
	"strings"
	"time"
H
hongming 已提交
57 58
)

H
hongming 已提交
59
type Interface interface {
H
hongming 已提交
60 61
	ListWorkspaces(user user.Info, query *query.Query) (*api.ListResult, error)
	ListNamespaces(user user.Info, workspace string, query *query.Query) (*api.ListResult, error)
H
hongming 已提交
62 63 64 65 66 67
	CreateNamespace(workspace string, namespace *corev1.Namespace) (*corev1.Namespace, error)
	CreateWorkspace(workspace *tenantv1alpha2.WorkspaceTemplate) (*tenantv1alpha2.WorkspaceTemplate, error)
	DeleteWorkspace(workspace string) error
	UpdateWorkspace(workspace *tenantv1alpha2.WorkspaceTemplate) (*tenantv1alpha2.WorkspaceTemplate, error)
	DescribeWorkspace(workspace string) (*tenantv1alpha2.WorkspaceTemplate, error)
	ListWorkspaceClusters(workspace string) (*api.ListResult, error)
J
junotx 已提交
68
	Events(user user.Info, queryParam *eventsv1alpha1.Query) (*eventsv1alpha1.APIResponse, error)
H
huanggze 已提交
69 70
	QueryLogs(user user.Info, query *loggingv1alpha2.Query) (*loggingv1alpha2.APIResponse, error)
	ExportLogs(user user.Info, query *loggingv1alpha2.Query, writer io.Writer) error
R
root 已提交
71
	Auditing(user user.Info, queryParam *auditingv1alpha1.Query) (*auditingv1alpha1.APIResponse, error)
H
hongming 已提交
72 73 74 75 76
	DescribeNamespace(workspace, namespace string) (*corev1.Namespace, error)
	DeleteNamespace(workspace, namespace string) error
	UpdateNamespace(workspace string, namespace *corev1.Namespace) (*corev1.Namespace, error)
	PatchNamespace(workspace string, namespace *corev1.Namespace) (*corev1.Namespace, error)
	PatchWorkspace(workspace *tenantv1alpha2.WorkspaceTemplate) (*tenantv1alpha2.WorkspaceTemplate, error)
77
	ListClusters(info user.Info) (*api.ListResult, error)
H
hongming 已提交
78
}
H
hongming 已提交
79

H
hongming 已提交
80
type tenantOperator struct {
H
hongming 已提交
81 82
	am             am.AccessManagementInterface
	authorizer     authorizer.Authorizer
H
hongming 已提交
83 84
	k8sclient      kubernetes.Interface
	ksclient       kubesphere.Interface
H
hongming 已提交
85
	resourceGetter *resourcesv1alpha3.ResourceGetter
J
junotx 已提交
86
	events         events.Interface
H
huanggze 已提交
87
	lo             logging.LoggingOperator
R
root 已提交
88
	auditing       auditing.Interface
H
hongming 已提交
89 90
}

R
root 已提交
91
func New(informers informers.InformerFactory, k8sclient kubernetes.Interface, ksclient kubesphere.Interface, evtsClient eventsclient.Client, loggingClient loggingclient.Interface, auditingclient auditingclient.Client) Interface {
H
hongming 已提交
92 93
	amOperator := am.NewReadOnlyOperator(informers)
	authorizer := authorizerfactory.NewRBACAuthorizer(amOperator)
H
update  
hongming 已提交
94
	return &tenantOperator{
H
hongming 已提交
95
		am:             amOperator,
H
hongming 已提交
96
		authorizer:     authorizer,
H
hongming 已提交
97
		resourceGetter: resourcesv1alpha3.NewResourceGetter(informers),
H
hongming 已提交
98 99
		k8sclient:      k8sclient,
		ksclient:       ksclient,
J
junotx 已提交
100
		events:         events.NewEventsOperator(evtsClient),
H
huanggze 已提交
101
		lo:             logging.NewLoggingOperator(loggingClient),
R
root 已提交
102
		auditing:       auditing.NewEventsOperator(auditingclient),
H
update  
hongming 已提交
103
	}
H
hongming 已提交
104 105
}

H
hongming 已提交
106
func (t *tenantOperator) ListWorkspaces(user user.Info, queryParam *query.Query) (*api.ListResult, error) {
H
hongming 已提交
107 108

	listWS := authorizer.AttributesRecord{
H
hongming 已提交
109 110
		User:            user,
		Verb:            "list",
H
hongming 已提交
111
		APIGroup:        "*",
H
hongming 已提交
112 113
		Resource:        "workspaces",
		ResourceRequest: true,
H
hongming 已提交
114
		ResourceScope:   request.GlobalScope,
H
hongming 已提交
115 116 117
	}

	decision, _, err := t.authorizer.Authorize(listWS)
H
hongming 已提交
118

H
update  
hongming 已提交
119 120 121 122
	if err != nil {
		klog.Error(err)
		return nil, err
	}
H
hongming 已提交
123

H
hongming 已提交
124
	if decision == authorizer.DecisionAllow {
H
update  
hongming 已提交
125

H
hongming 已提交
126
		result, err := t.resourceGetter.List(tenantv1alpha2.ResourcePluralWorkspaceTemplate, "", queryParam)
H
hongming 已提交
127

H
update  
hongming 已提交
128 129 130 131
		if err != nil {
			klog.Error(err)
			return nil, err
		}
H
hongming 已提交
132

H
hongming 已提交
133 134 135 136 137 138 139 140 141
		return result, nil
	}

	workspaceRoleBindings, err := t.am.ListWorkspaceRoleBindings(user.GetName(), "")

	if err != nil {
		klog.Error(err)
		return nil, err
	}
H
hongming 已提交
142

H
hongming 已提交
143
	workspaces := make([]runtime.Object, 0)
H
hongming 已提交
144

H
hongming 已提交
145
	for _, roleBinding := range workspaceRoleBindings {
H
hongming 已提交
146

H
hongming 已提交
147
		workspaceName := roleBinding.Labels[tenantv1alpha1.WorkspaceLabel]
H
hongming 已提交
148
		workspace, err := t.resourceGetter.Get(tenantv1alpha2.ResourcePluralWorkspaceTemplate, "", workspaceName)
H
hongming 已提交
149

H
hongming 已提交
150
		if errors.IsNotFound(err) {
H
hongming 已提交
151
			klog.Warningf("workspace role binding: %+v found but workspace not exist", roleBinding.ObjectMeta.String())
H
hongming 已提交
152 153 154 155 156 157 158 159 160 161
			continue
		}

		if err != nil {
			klog.Error(err)
			return nil, err
		}

		if !contains(workspaces, workspace) {
			workspaces = append(workspaces, workspace)
H
update  
hongming 已提交
162
		}
H
hongming 已提交
163
	}
H
hongming 已提交
164

H
hongming 已提交
165
	result := resources.DefaultList(workspaces, queryParam, func(left runtime.Object, right runtime.Object, field query.Field) bool {
H
hongming 已提交
166
		return resources.DefaultObjectMetaCompare(left.(*tenantv1alpha2.WorkspaceTemplate).ObjectMeta, right.(*tenantv1alpha2.WorkspaceTemplate).ObjectMeta, field)
H
hongming 已提交
167
	}, func(workspace runtime.Object, filter query.Filter) bool {
H
hongming 已提交
168
		return resources.DefaultObjectMetaFilter(workspace.(*tenantv1alpha2.WorkspaceTemplate).ObjectMeta, filter)
H
hongming 已提交
169 170 171
	})

	return result, nil
H
hongming 已提交
172 173
}

H
hongming 已提交
174
func (t *tenantOperator) ListNamespaces(user user.Info, workspace string, queryParam *query.Query) (*api.ListResult, error) {
175 176 177 178
	nsScope := request.ClusterScope
	if workspace != "" {
		nsScope = request.WorkspaceScope
	}
H
hongming 已提交
179

180
	listNS := authorizer.AttributesRecord{
H
hongming 已提交
181 182 183 184 185
		User:            user,
		Verb:            "list",
		Workspace:       workspace,
		Resource:        "namespaces",
		ResourceRequest: true,
186
		ResourceScope:   nsScope,
H
hongming 已提交
187
	}
H
update  
hongming 已提交
188

189
	decision, _, err := t.authorizer.Authorize(listNS)
H
hongming 已提交
190 191

	if err != nil {
H
update  
hongming 已提交
192
		klog.Error(err)
H
hongming 已提交
193 194 195
		return nil, err
	}

H
hongming 已提交
196
	if decision == authorizer.DecisionAllow {
H
hongming 已提交
197

H
hongming 已提交
198 199 200
		if workspace != "" {
			queryParam.Filters[query.FieldLabel] = query.Value(fmt.Sprintf("%s=%s", tenantv1alpha1.WorkspaceLabel, workspace))
		}
H
hongming 已提交
201 202

		result, err := t.resourceGetter.List("namespaces", "", queryParam)
H
hongming 已提交
203

H
update  
hongming 已提交
204 205 206 207
		if err != nil {
			klog.Error(err)
			return nil, err
		}
H
hongming 已提交
208

H
hongming 已提交
209 210 211 212
		return result, nil
	}

	roleBindings, err := t.am.ListRoleBindings(user.GetName(), "")
H
hongming 已提交
213

H
hongming 已提交
214 215 216 217
	if err != nil {
		klog.Error(err)
		return nil, err
	}
H
hongming 已提交
218

H
hongming 已提交
219
	namespaces := make([]runtime.Object, 0)
H
hongming 已提交
220

H
hongming 已提交
221
	for _, roleBinding := range roleBindings {
H
hongming 已提交
222
		namespace, err := t.resourceGetter.Get("namespaces", "", roleBinding.Namespace)
H
update  
hongming 已提交
223

H
hongming 已提交
224 225 226 227
		if err != nil {
			klog.Error(err)
			return nil, err
		}
H
update  
hongming 已提交
228

H
hongming 已提交
229
		// skip if not controlled by the specified workspace
H
hongming 已提交
230
		if ns := namespace.(*corev1.Namespace); workspace != "" && ns.Labels[tenantv1alpha1.WorkspaceLabel] != workspace {
H
hongming 已提交
231 232 233
			continue
		}

H
hongming 已提交
234 235
		if !contains(namespaces, namespace) {
			namespaces = append(namespaces, namespace)
H
update  
hongming 已提交
236
		}
H
hongming 已提交
237 238
	}

H
hongming 已提交
239 240 241 242
	result := resources.DefaultList(namespaces, queryParam, func(left runtime.Object, right runtime.Object, field query.Field) bool {
		return resources.DefaultObjectMetaCompare(left.(*corev1.Namespace).ObjectMeta, right.(*corev1.Namespace).ObjectMeta, field)
	}, func(object runtime.Object, filter query.Filter) bool {
		namespace := object.(*corev1.Namespace).ObjectMeta
243 244 245 246
		if workspace != "" {
			if workspaceLabel, ok := namespace.Labels[tenantv1alpha1.WorkspaceLabel]; !ok || workspaceLabel != workspace {
				return false
			}
H
hongming 已提交
247
		}
H
hongming 已提交
248 249
		return resources.DefaultObjectMetaFilter(namespace, filter)
	})
H
hongming 已提交
250

H
hongming 已提交
251
	return result, nil
H
update  
hongming 已提交
252 253
}

H
hongming 已提交
254 255
func (t *tenantOperator) CreateNamespace(workspace string, namespace *corev1.Namespace) (*corev1.Namespace, error) {
	_, err := t.resourceGetter.Get(tenantv1alpha1.ResourcePluralWorkspace, "", workspace)
H
hongming 已提交
256 257 258 259 260 261 262 263 264 265 266 267 268 269
	if err != nil {
		return nil, err
	}
	namespace = appendWorkspaceLabel(namespace, workspace)
	return t.k8sclient.CoreV1().Namespaces().Create(namespace)
}

func appendWorkspaceLabel(namespace *corev1.Namespace, workspace string) *corev1.Namespace {
	if namespace.Labels == nil {
		namespace.Labels = make(map[string]string, 0)
	}
	namespace.Labels[tenantv1alpha1.WorkspaceLabel] = workspace
	return namespace
}
H
hongming 已提交
270

H
hongming 已提交
271 272
func (t *tenantOperator) DescribeNamespace(workspace, namespace string) (*corev1.Namespace, error) {
	obj, err := t.resourceGetter.Get("namespaces", "", namespace)
H
hongming 已提交
273 274 275
	if err != nil {
		return nil, err
	}
H
hongming 已提交
276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291
	ns := obj.(*corev1.Namespace)
	if ns.Labels[tenantv1alpha1.WorkspaceLabel] != workspace {
		err := errors.NewNotFound(corev1.Resource("namespace"), namespace)
		klog.Error(err)
		return nil, err
	}
	return ns, nil
}

func (t *tenantOperator) DeleteNamespace(workspace, namespace string) error {
	_, err := t.DescribeNamespace(workspace, namespace)
	if err != nil {
		return err
	}
	return t.k8sclient.CoreV1().Namespaces().Delete(namespace, metav1.NewDeleteOptions(0))
}
H
hongming 已提交
292

H
hongming 已提交
293
func (t *tenantOperator) UpdateNamespace(workspace string, namespace *corev1.Namespace) (*corev1.Namespace, error) {
H
hongming 已提交
294
	_, err := t.DescribeNamespace(workspace, namespace.Name)
H
hongming 已提交
295 296
	if err != nil {
		return nil, err
H
hongming 已提交
297
	}
H
hongming 已提交
298 299 300
	namespace = appendWorkspaceLabel(namespace, workspace)
	return t.k8sclient.CoreV1().Namespaces().Update(namespace)
}
H
hongming 已提交
301

H
hongming 已提交
302 303 304 305 306 307 308 309 310 311 312 313 314 315
func (t *tenantOperator) PatchNamespace(workspace string, namespace *corev1.Namespace) (*corev1.Namespace, error) {
	_, err := t.DescribeNamespace(workspace, namespace.Name)
	if err != nil {
		return nil, err
	}
	if namespace.Labels != nil {
		namespace.Labels[tenantv1alpha1.WorkspaceLabel] = workspace
	}
	data, err := json.Marshal(namespace)
	if err != nil {
		return nil, err
	}
	return t.k8sclient.CoreV1().Namespaces().Patch(namespace.Name, types.MergePatchType, data)
}
H
hongming 已提交
316

H
hongming 已提交
317 318 319 320 321 322 323 324 325 326
func (t *tenantOperator) PatchWorkspace(workspace *tenantv1alpha2.WorkspaceTemplate) (*tenantv1alpha2.WorkspaceTemplate, error) {
	_, err := t.DescribeWorkspace(workspace.Name)
	if err != nil {
		return nil, err
	}
	data, err := json.Marshal(workspace)
	if err != nil {
		return nil, err
	}
	return t.ksclient.TenantV1alpha2().WorkspaceTemplates().Patch(workspace.Name, types.MergePatchType, data)
H
hongming 已提交
327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350
}

func (t *tenantOperator) CreateWorkspace(workspace *tenantv1alpha2.WorkspaceTemplate) (*tenantv1alpha2.WorkspaceTemplate, error) {
	return t.ksclient.TenantV1alpha2().WorkspaceTemplates().Create(workspace)
}

func (t *tenantOperator) UpdateWorkspace(workspace *tenantv1alpha2.WorkspaceTemplate) (*tenantv1alpha2.WorkspaceTemplate, error) {
	return t.ksclient.TenantV1alpha2().WorkspaceTemplates().Update(workspace)
}

func (t *tenantOperator) DescribeWorkspace(workspace string) (*tenantv1alpha2.WorkspaceTemplate, error) {
	obj, err := t.resourceGetter.Get(tenantv1alpha2.ResourcePluralWorkspaceTemplate, "", workspace)
	if err != nil {
		klog.Error(err)
		return nil, err
	}
	return obj.(*tenantv1alpha2.WorkspaceTemplate), nil
}
func (t *tenantOperator) ListWorkspaceClusters(workspaceName string) (*api.ListResult, error) {
	workspace, err := t.DescribeWorkspace(workspaceName)
	if err != nil {
		klog.Error(err)
		return nil, err
	}
351 352 353 354 355 356 357 358 359 360 361 362

	// In this case, spec.placement.clusterSelector will be ignored, since spec.placement.clusters is provided.
	if workspace.Spec.Placement.Clusters != nil {
		clusters := make([]interface{}, 0)
		for _, cluster := range workspace.Spec.Placement.Clusters {
			obj, err := t.resourceGetter.Get(clusterv1alpha1.ResourcesPluralCluster, "", cluster.Name)
			if err != nil {
				klog.Error(err)
				if errors.IsNotFound(err) {
					continue
				}
				return nil, err
H
hongming 已提交
363
			}
364
			clusters = append(clusters, obj)
H
hongming 已提交
365
		}
366
		return &api.ListResult{Items: clusters, TotalItems: len(clusters)}, nil
H
hongming 已提交
367
	}
368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384

	if workspace.Spec.Placement.ClusterSelector != nil {
		// In this case, the resource will be propagated to all member clusters.
		if workspace.Spec.Placement.ClusterSelector.MatchLabels == nil {
			return t.resourceGetter.List(clusterv1alpha1.ResourcesPluralCluster, "", query.New())
		} else {
			// In this case, the resource will only be propagated to member clusters that are labeled with foo: bar.
			return t.resourceGetter.List(clusterv1alpha1.ResourcesPluralCluster, "", &query.Query{
				Pagination:    query.NoPagination,
				Ascending:     false,
				LabelSelector: labels.SelectorFromSet(workspace.Spec.Placement.ClusterSelector.MatchLabels).String(),
			})
		}
	}

	// In this case, you can either set spec: {} as above or remove spec field from your placement policy. The resource will not be propagated to member clusters.
	return &api.ListResult{Items: []interface{}{}, TotalItems: 0}, nil
H
hongming 已提交
385
}
386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444
func (t *tenantOperator) ListClusters(user user.Info) (*api.ListResult, error) {

	listClustersInGlobalScope := authorizer.AttributesRecord{
		User:            user,
		Verb:            "list",
		Resource:        "clusters",
		ResourceScope:   request.GlobalScope,
		ResourceRequest: true,
	}

	allowedListClustersInGlobalScope, _, err := t.authorizer.Authorize(listClustersInGlobalScope)

	if err != nil {
		klog.Error(err)
		return nil, err
	}

	listWorkspacesInGlobalScope := authorizer.AttributesRecord{
		User:            user,
		Verb:            "list",
		Resource:        "workspaces",
		ResourceScope:   request.GlobalScope,
		ResourceRequest: true,
	}

	allowedListWorkspacesInGlobalScope, _, err := t.authorizer.Authorize(listWorkspacesInGlobalScope)

	if err != nil {
		klog.Error(err)
		return nil, err
	}

	if allowedListClustersInGlobalScope == authorizer.DecisionAllow ||
		allowedListWorkspacesInGlobalScope == authorizer.DecisionAllow {
		result, err := t.resourceGetter.List(clusterv1alpha1.ResourcesPluralCluster, "", query.New())
		if err != nil {
			klog.Error(err)
			return nil, err
		}
		return result, nil
	}

	workspaceRoleBindings, err := t.am.ListWorkspaceRoleBindings(user.GetName(), "")

	if err != nil {
		klog.Error(err)
		return nil, err
	}

	clusters := map[string]*clusterv1alpha1.Cluster{}

	for _, roleBinding := range workspaceRoleBindings {
		workspaceName := roleBinding.Labels[tenantv1alpha1.WorkspaceLabel]
		workspace, err := t.DescribeWorkspace(workspaceName)
		if err != nil {
			klog.Error(err)
			return nil, err
		}

H
hongming 已提交
445
		for _, grantedCluster := range workspace.Spec.Placement.Clusters {
446
			// skip if cluster exist
H
hongming 已提交
447
			if clusters[grantedCluster.Name] != nil {
448 449
				continue
			}
H
hongming 已提交
450
			obj, err := t.resourceGetter.Get(clusterv1alpha1.ResourcesPluralCluster, "", grantedCluster.Name)
451 452 453 454 455 456 457 458
			if err != nil {
				klog.Error(err)
				if errors.IsNotFound(err) {
					continue
				}
				return nil, err
			}
			cluster := obj.(*clusterv1alpha1.Cluster)
H
hongming 已提交
459
			clusters[cluster.Name] = cluster
460 461 462 463 464 465 466 467 468 469
		}
	}

	items := make([]interface{}, 0)
	for _, cluster := range clusters {
		items = append(items, cluster)
	}

	return &api.ListResult{Items: items, TotalItems: len(items)}, nil
}
H
hongming 已提交
470 471 472 473 474

func (t *tenantOperator) DeleteWorkspace(workspace string) error {
	return t.ksclient.TenantV1alpha2().WorkspaceTemplates().Delete(workspace, metav1.NewDeleteOptions(0))
}

J
junotx 已提交
475 476 477 478 479 480 481 482 483 484 485 486 487 488
// listIntersectedNamespaces lists the namespaces which meet all the following conditions at the same time
// 1. the namespace which belongs to user.
// 2. the namespace in workspace which is in workspaces when workspaces is not empty.
// 3. the namespace in workspace which contains one of workspaceSubstrs when workspaceSubstrs is not empty.
// 4. the namespace which is in namespaces when namespaces is not empty.
// 5. the namespace which contains one of namespaceSubstrs when namespaceSubstrs is not empty.
func (t *tenantOperator) listIntersectedNamespaces(user user.Info,
	workspaces, workspaceSubstrs, namespaces, namespaceSubstrs []string) ([]*corev1.Namespace, error) {
	var (
		namespaceSet = stringSet(namespaces)
		workspaceSet = stringSet(workspaces)

		iNamespaces []*corev1.Namespace
	)
J
junotx 已提交
489
	includeNsWithoutWs := len(workspaceSet) == 0 && len(workspaceSubstrs) == 0
J
junotx 已提交
490

491
	result, err := t.ListNamespaces(user, "", query.New())
J
junotx 已提交
492 493 494
	if err != nil {
		return nil, err
	}
495 496 497 498 499 500
	for _, obj := range result.Items {
		ns, ok := obj.(*corev1.Namespace)
		if !ok {
			continue
		}

J
junotx 已提交
501
		if len(namespaceSet) > 0 {
502
			if _, ok := namespaceSet[ns.Name]; !ok {
J
junotx 已提交
503 504 505
				continue
			}
		}
506
		if len(namespaceSubstrs) > 0 && !stringContains(ns.Name, namespaceSubstrs) {
J
junotx 已提交
507 508
			continue
		}
509 510 511
		if ws := ns.Labels[tenantv1alpha1.WorkspaceLabel]; ws != "" {
			if len(workspaceSet) > 0 {
				if _, ok := workspaceSet[ws]; !ok {
J
junotx 已提交
512 513
					continue
				}
514 515
			}
			if len(workspaceSubstrs) > 0 && !stringContains(ws, workspaceSubstrs) {
J
junotx 已提交
516 517
				continue
			}
518 519
		} else if !includeNsWithoutWs {
			continue
J
junotx 已提交
520
		}
521
		iNamespaces = append(iNamespaces, ns)
J
junotx 已提交
522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547
	}
	return iNamespaces, nil
}

func (t *tenantOperator) Events(user user.Info, queryParam *eventsv1alpha1.Query) (*eventsv1alpha1.APIResponse, error) {
	iNamespaces, err := t.listIntersectedNamespaces(user,
		stringutils.Split(queryParam.WorkspaceFilter, ","),
		stringutils.Split(queryParam.WorkspaceSearch, ","),
		stringutils.Split(queryParam.InvolvedObjectNamespaceFilter, ","),
		stringutils.Split(queryParam.InvolvedObjectNamespaceSearch, ","))
	if err != nil {
		klog.Error(err)
		return nil, err
	}

	namespaceCreateTimeMap := make(map[string]time.Time)

	for _, ns := range iNamespaces {
		listEvts := authorizer.AttributesRecord{
			User:            user,
			Verb:            "list",
			APIGroup:        "",
			APIVersion:      "v1",
			Namespace:       ns.Name,
			Resource:        "events",
			ResourceRequest: true,
548
			ResourceScope:   request.NamespaceScope,
J
junotx 已提交
549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569
		}
		decision, _, err := t.authorizer.Authorize(listEvts)
		if err != nil {
			klog.Error(err)
			return nil, err
		}
		if decision == authorizer.DecisionAllow {
			namespaceCreateTimeMap[ns.Name] = ns.CreationTimestamp.Time
		}
	}
	// If there are no ns and ws query conditions,
	// those events with empty `involvedObject.namespace` will also be listed when user can list all events
	if len(queryParam.WorkspaceFilter) == 0 && len(queryParam.InvolvedObjectNamespaceFilter) == 0 &&
		len(queryParam.WorkspaceSearch) == 0 && len(queryParam.InvolvedObjectNamespaceSearch) == 0 {
		listEvts := authorizer.AttributesRecord{
			User:            user,
			Verb:            "list",
			APIGroup:        "",
			APIVersion:      "v1",
			Resource:        "events",
			ResourceRequest: true,
570
			ResourceScope:   request.ClusterScope,
J
junotx 已提交
571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586
		}
		decision, _, err := t.authorizer.Authorize(listEvts)
		if err != nil {
			klog.Error(err)
			return nil, err
		}
		if decision == authorizer.DecisionAllow {
			namespaceCreateTimeMap[""] = time.Time{}
		}
	}

	return t.events.Events(queryParam, func(filter *eventsclient.Filter) {
		filter.InvolvedObjectNamespaceMap = namespaceCreateTimeMap
	})
}

H
huanggze 已提交
587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608
func (t *tenantOperator) QueryLogs(user user.Info, query *loggingv1alpha2.Query) (*loggingv1alpha2.APIResponse, error) {
	iNamespaces, err := t.listIntersectedNamespaces(user,
		stringutils.Split(query.WorkspaceFilter, ","),
		stringutils.Split(query.WorkspaceSearch, ","),
		stringutils.Split(query.NamespaceFilter, ","),
		stringutils.Split(query.NamespaceSearch, ","))
	if err != nil {
		klog.Error(err)
		return nil, err
	}

	namespaceCreateTimeMap := make(map[string]time.Time)
	for _, ns := range iNamespaces {
		podLogs := authorizer.AttributesRecord{
			User:            user,
			Verb:            "get",
			APIGroup:        "",
			APIVersion:      "v1",
			Namespace:       ns.Name,
			Resource:        "pods",
			Subresource:     "log",
			ResourceRequest: true,
H
huanggze 已提交
609
			ResourceScope:   request.NamespaceScope,
H
huanggze 已提交
610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679
		}
		decision, _, err := t.authorizer.Authorize(podLogs)
		if err != nil {
			klog.Error(err)
			return nil, err
		}
		if decision == authorizer.DecisionAllow {
			namespaceCreateTimeMap[ns.Name] = ns.CreationTimestamp.Time
		}
	}

	sf := loggingclient.SearchFilter{
		NamespaceFilter: namespaceCreateTimeMap,
		WorkloadSearch:  stringutils.Split(query.WorkloadSearch, ","),
		WorkloadFilter:  stringutils.Split(query.WorkloadFilter, ","),
		PodSearch:       stringutils.Split(query.PodSearch, ","),
		PodFilter:       stringutils.Split(query.PodFilter, ","),
		ContainerSearch: stringutils.Split(query.ContainerSearch, ","),
		ContainerFilter: stringutils.Split(query.ContainerFilter, ","),
		LogSearch:       stringutils.Split(query.LogSearch, ","),
		Starttime:       query.StartTime,
		Endtime:         query.EndTime,
	}

	var ar loggingv1alpha2.APIResponse
	switch query.Operation {
	case loggingv1alpha2.OperationStatistics:
		if len(namespaceCreateTimeMap) == 0 {
			ar.Statistics = &loggingclient.Statistics{}
		} else {
			ar, err = t.lo.GetCurrentStats(sf)
		}
	case loggingv1alpha2.OperationHistogram:
		if len(namespaceCreateTimeMap) == 0 {
			ar.Histogram = &loggingclient.Histogram{}
		} else {
			ar, err = t.lo.CountLogsByInterval(sf, query.Interval)
		}
	default:
		if len(namespaceCreateTimeMap) == 0 {
			ar.Logs = &loggingclient.Logs{}
		} else {
			ar, err = t.lo.SearchLogs(sf, query.From, query.Size, query.Sort)
		}
	}
	return &ar, err
}

func (t *tenantOperator) ExportLogs(user user.Info, query *loggingv1alpha2.Query, writer io.Writer) error {
	iNamespaces, err := t.listIntersectedNamespaces(user,
		stringutils.Split(query.WorkspaceFilter, ","),
		stringutils.Split(query.WorkspaceSearch, ","),
		stringutils.Split(query.NamespaceFilter, ","),
		stringutils.Split(query.NamespaceSearch, ","))
	if err != nil {
		klog.Error(err)
		return err
	}

	namespaceCreateTimeMap := make(map[string]time.Time)
	for _, ns := range iNamespaces {
		podLogs := authorizer.AttributesRecord{
			User:            user,
			Verb:            "get",
			APIGroup:        "",
			APIVersion:      "v1",
			Namespace:       ns.Name,
			Resource:        "pods",
			Subresource:     "log",
			ResourceRequest: true,
H
huanggze 已提交
680
			ResourceScope:   request.NamespaceScope,
H
huanggze 已提交
681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711
		}
		decision, _, err := t.authorizer.Authorize(podLogs)
		if err != nil {
			klog.Error(err)
			return err
		}
		if decision == authorizer.DecisionAllow {
			namespaceCreateTimeMap[ns.Name] = ns.CreationTimestamp.Time
		}
	}

	sf := loggingclient.SearchFilter{
		NamespaceFilter: namespaceCreateTimeMap,
		WorkloadSearch:  stringutils.Split(query.WorkloadSearch, ","),
		WorkloadFilter:  stringutils.Split(query.WorkloadFilter, ","),
		PodSearch:       stringutils.Split(query.PodSearch, ","),
		PodFilter:       stringutils.Split(query.PodFilter, ","),
		ContainerSearch: stringutils.Split(query.ContainerSearch, ","),
		ContainerFilter: stringutils.Split(query.ContainerFilter, ","),
		LogSearch:       stringutils.Split(query.LogSearch, ","),
		Starttime:       query.StartTime,
		Endtime:         query.EndTime,
	}

	if len(namespaceCreateTimeMap) == 0 {
		return nil
	} else {
		return t.lo.ExportLogs(sf, writer)
	}
}

R
root 已提交
712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730
func (t *tenantOperator) Auditing(user user.Info, queryParam *auditingv1alpha1.Query) (*auditingv1alpha1.APIResponse, error) {
	iNamespaces, err := t.listIntersectedNamespaces(user,
		stringutils.Split(queryParam.WorkspaceFilter, ","),
		stringutils.Split(queryParam.WorkspaceSearch, ","),
		stringutils.Split(queryParam.ObjectRefNamespaceFilter, ","),
		stringutils.Split(queryParam.ObjectRefNamespaceSearch, ","))
	if err != nil {
		klog.Error(err)
		return nil, err
	}

	namespaceCreateTimeMap := make(map[string]time.Time)
	for _, ns := range iNamespaces {
		namespaceCreateTimeMap[ns.Name] = ns.CreationTimestamp.Time
	}
	// If there are no ns and ws query conditions,
	// those events with empty `ObjectRef.Namespace` will also be listed when user can list all namespaces
	if len(queryParam.WorkspaceFilter) == 0 && len(queryParam.ObjectRefNamespaceFilter) == 0 &&
		len(queryParam.WorkspaceSearch) == 0 && len(queryParam.ObjectRefNamespaceSearch) == 0 {
731
		listNs := authorizer.AttributesRecord{
R
root 已提交
732 733 734 735
			User:            user,
			Verb:            "list",
			Resource:        "namespaces",
			ResourceRequest: true,
736
			ResourceScope:   request.ClusterScope,
R
root 已提交
737
		}
738
		decision, _, err := t.authorizer.Authorize(listNs)
R
root 已提交
739 740 741 742 743 744 745 746 747 748 749 750 751 752
		if err != nil {
			klog.Error(err)
			return nil, err
		}
		if decision == authorizer.DecisionAllow {
			namespaceCreateTimeMap[""] = time.Time{}
		}
	}

	return t.auditing.Events(queryParam, func(filter *auditingclient.Filter) {
		filter.ObjectRefNamespaceMap = namespaceCreateTimeMap
	})
}

H
hongming 已提交
753 754 755 756 757
func contains(objects []runtime.Object, object runtime.Object) bool {
	for _, item := range objects {
		if item == object {
			return true
		}
H
update  
hongming 已提交
758
	}
H
hongming 已提交
759
	return false
H
hongming 已提交
760
}
J
junotx 已提交
761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777

func stringSet(strs []string) map[string]struct{} {
	m := make(map[string]struct{})
	for _, str := range strs {
		m[str] = struct{}{}
	}
	return m
}

func stringContains(str string, subStrs []string) bool {
	for _, sub := range subStrs {
		if strings.Contains(str, sub) {
			return true
		}
	}
	return false
}