Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
水淹萌龙
kubesphere
提交
52abbeb3
K
kubesphere
项目概览
水淹萌龙
/
kubesphere
与 Fork 源项目一致
Fork自
KubeSphere / kubesphere
通知
1
Star
0
Fork
0
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
DevOps
流水线
流水线任务
计划
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
K
kubesphere
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
DevOps
DevOps
流水线
流水线任务
计划
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
流水线任务
提交
Issue看板
未验证
提交
52abbeb3
编写于
6月 27, 2020
作者:
K
KubeSphere CI Bot
提交者:
GitHub
6月 27, 2020
浏览文件
操作
浏览文件
下载
差异文件
Merge pull request #2227 from wanjunlei/master
process audit information for resource creating requests
上级
2a053658
37346150
变更
4
隐藏空白更改
内联
并排
Showing
4 changed file
with
62 addition
and
14 deletion
+62
-14
pkg/apiserver/auditing/backend.go
pkg/apiserver/auditing/backend.go
+22
-2
pkg/apiserver/auditing/types.go
pkg/apiserver/auditing/types.go
+26
-11
pkg/apiserver/auditing/v1alpha1/event.go
pkg/apiserver/auditing/v1alpha1/event.go
+8
-1
pkg/apiserver/filters/auditing.go
pkg/apiserver/filters/auditing.go
+6
-0
未找到文件。
pkg/apiserver/auditing/backend.go
浏览文件 @
52abbeb3
...
...
@@ -86,12 +86,14 @@ func (b *Backend) worker() {
<-
b
.
semCh
}()
bs
,
err
:=
json
.
Marshal
(
event
)
bs
,
err
:=
b
.
eventToBytes
(
event
)
if
err
!=
nil
{
klog
.
Error
f
(
"json marshal error, %s"
,
err
)
klog
.
V
(
6
)
.
Info
f
(
"json marshal error, %s"
,
err
)
return
}
klog
.
V
(
8
)
.
Infof
(
"%s"
,
string
(
bs
))
response
,
err
:=
b
.
client
.
Post
(
b
.
url
,
"application/json"
,
bytes
.
NewBuffer
(
bs
))
if
err
!=
nil
{
klog
.
Errorf
(
"send audit event[%s] error, %s"
,
event
.
Items
[
0
]
.
AuditID
,
err
)
...
...
@@ -107,3 +109,21 @@ func (b *Backend) worker() {
go
send
(
event
)
}
}
func
(
b
*
Backend
)
eventToBytes
(
event
*
v1alpha1
.
EventList
)
([]
byte
,
error
)
{
bs
,
err
:=
json
.
Marshal
(
event
)
if
err
!=
nil
{
// Normally, the serialization failure is caused by the failure of ResponseObject serialization.
// To ensure the integrity of the auditing event to the greatest extent,
// it is necessary to delete ResponseObject and and then try to serialize again.
if
event
.
Items
[
0
]
.
ResponseObject
!=
nil
{
event
.
Items
[
0
]
.
ResponseObject
=
nil
return
json
.
Marshal
(
event
)
}
return
nil
,
err
}
return
bs
,
err
}
pkg/apiserver/auditing/types.go
浏览文件 @
52abbeb3
...
...
@@ -122,6 +122,19 @@ func (a *auditing) LogRequestObject(req *http.Request, info *request.RequestInfo
},
}
// Handle the devops request which request url matched /devops/{devops}/kind.
if
len
(
info
.
Parts
)
>=
3
&&
info
.
Parts
[
0
]
==
"devops"
{
e
.
ObjectRef
.
Subresource
=
""
e
.
Devops
=
info
.
Parts
[
1
]
// set resource as kind
e
.
ObjectRef
.
Resource
=
info
.
Parts
[
2
]
// If the request url matched /devops/{devops}/kind/{kind}, set resource name as {kind}
if
len
(
info
.
Parts
)
>=
4
{
e
.
ObjectRef
.
Name
=
info
.
Parts
[
3
]
}
}
ips
:=
make
([]
string
,
1
)
ips
[
0
]
=
iputil
.
RemoteIp
(
req
)
e
.
SourceIPs
=
ips
...
...
@@ -137,7 +150,7 @@ func (a *auditing) LogRequestObject(req *http.Request, info *request.RequestInfo
}
}
if
e
.
Level
.
GreaterOrEqual
(
audit
.
LevelRequest
)
&&
req
.
ContentLength
>
0
{
if
(
e
.
Level
.
GreaterOrEqual
(
audit
.
LevelRequest
)
||
e
.
Verb
==
"create"
)
&&
req
.
ContentLength
>
0
{
body
,
err
:=
ioutil
.
ReadAll
(
req
.
Body
)
if
err
!=
nil
{
klog
.
Error
(
err
)
...
...
@@ -145,7 +158,18 @@ func (a *auditing) LogRequestObject(req *http.Request, info *request.RequestInfo
}
_
=
req
.
Body
.
Close
()
req
.
Body
=
ioutil
.
NopCloser
(
bytes
.
NewBuffer
(
body
))
e
.
RequestObject
=
&
runtime
.
Unknown
{
Raw
:
body
}
if
e
.
Level
.
GreaterOrEqual
(
audit
.
LevelRequest
)
{
e
.
RequestObject
=
&
runtime
.
Unknown
{
Raw
:
body
}
}
// For resource creating request, get resource name from the request body.
if
info
.
Verb
==
"create"
{
obj
:=
&
auditv1alpha1
.
Object
{}
if
err
:=
json
.
Unmarshal
(
body
,
obj
);
err
==
nil
{
e
.
ObjectRef
.
Name
=
obj
.
Name
}
}
}
return
e
...
...
@@ -153,11 +177,6 @@ func (a *auditing) LogRequestObject(req *http.Request, info *request.RequestInfo
func
(
a
*
auditing
)
LogResponseObject
(
e
*
auditv1alpha1
.
Event
,
resp
*
ResponseCapture
,
info
*
request
.
RequestInfo
)
{
// Auditing should igonre k8s request when k8s auditing is enabled.
if
info
.
IsKubernetesRequest
&&
a
.
K8sAuditingEnabled
()
{
return
}
e
.
StageTimestamp
=
v1
.
NewMicroTime
(
time
.
Now
())
e
.
ResponseStatus
=
&
v1
.
Status
{
Code
:
int32
(
resp
.
StatusCode
())}
if
e
.
Level
.
GreaterOrEqual
(
audit
.
LevelRequestResponse
)
{
...
...
@@ -168,10 +187,6 @@ func (a *auditing) LogResponseObject(e *auditv1alpha1.Event, resp *ResponseCaptu
}
func
(
a
*
auditing
)
cacheEvent
(
e
auditv1alpha1
.
Event
)
{
if
klog
.
V
(
8
)
{
bs
,
_
:=
json
.
Marshal
(
e
)
klog
.
Infof
(
"%s"
,
string
(
bs
))
}
eventList
:=
&
auditv1alpha1
.
EventList
{}
eventList
.
Items
=
append
(
eventList
.
Items
,
e
)
...
...
pkg/apiserver/auditing/v1alpha1/event.go
浏览文件 @
52abbeb3
package
v1alpha1
import
"k8s.io/apiserver/pkg/apis/audit"
import
(
"k8s.io/apimachinery/pkg/apis/meta/v1"
"k8s.io/apiserver/pkg/apis/audit"
)
type
Event
struct
{
// Devops project
...
...
@@ -18,3 +21,7 @@ type Event struct {
type
EventList
struct
{
Items
[]
Event
}
type
Object
struct
{
v1
.
ObjectMeta
`json:"metadata,omitempty" protobuf:"bytes,1,opt,name=metadata"`
}
pkg/apiserver/filters/auditing.go
浏览文件 @
52abbeb3
...
...
@@ -26,6 +26,12 @@ func WithAuditing(handler http.Handler, a auditing.Auditing) http.Handler {
return
}
// Auditing should igonre k8s request when k8s auditing is enabled.
if
info
.
IsKubernetesRequest
&&
a
.
K8sAuditingEnabled
()
{
handler
.
ServeHTTP
(
w
,
req
)
return
}
e
:=
a
.
LogRequestObject
(
req
,
info
)
req
=
req
.
WithContext
(
request
.
WithAuditEvent
(
req
.
Context
(),
e
))
resp
:=
auditing
.
NewResponseCapture
(
w
)
...
...
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录