Show / Hide Table of Contents

Class V1ValidatingAdmissionPolicySpec

ValidatingAdmissionPolicySpec is the specification of the desired behavior of the AdmissionPolicy.

Inheritance
object
V1ValidatingAdmissionPolicySpec
Implements
IEquatable<V1ValidatingAdmissionPolicySpec>
Inherited Members
object.GetType()
object.MemberwiseClone()
object.Equals(object, object)
object.ReferenceEquals(object, object)
Namespace: k8s.Models
Assembly: KubernetesClient.dll
Syntax
public record V1ValidatingAdmissionPolicySpec : IEquatable<V1ValidatingAdmissionPolicySpec>

Constructors

View Source

V1ValidatingAdmissionPolicySpec()

Declaration
public V1ValidatingAdmissionPolicySpec()
View Source

V1ValidatingAdmissionPolicySpec(V1ValidatingAdmissionPolicySpec)

Declaration
protected V1ValidatingAdmissionPolicySpec(V1ValidatingAdmissionPolicySpec original)
Parameters
Type Name Description
V1ValidatingAdmissionPolicySpec original

Properties

View Source

AuditAnnotations

auditAnnotations contains CEL expressions which are used to produce audit annotations for the audit event of the API request. validations and auditAnnotations may not both be empty; a least one of validations or auditAnnotations is required.

Declaration
[JsonPropertyName("auditAnnotations")]
public IList<V1AuditAnnotation> AuditAnnotations { get; set; }
Property Value
Type Description
IList<V1AuditAnnotation>
View Source

EqualityContract

Declaration
protected virtual Type EqualityContract { get; }
Property Value
Type Description
Type
View Source

FailurePolicy

failurePolicy defines how to handle failures for the admission policy. Failures can occur from CEL expression parse errors, type check errors, runtime errors and invalid or mis-configured policy definitions or bindings.

A policy is invalid if spec.paramKind refers to a non-existent Kind. A binding is invalid if spec.paramRef.name refers to a non-existent resource.

failurePolicy does not define how validations that evaluate to false are handled.

When failurePolicy is set to Fail, ValidatingAdmissionPolicyBinding validationActions define how failures are enforced.

Allowed values are Ignore or Fail. Defaults to Fail.

Declaration
[JsonPropertyName("failurePolicy")]
public string FailurePolicy { get; set; }
Property Value
Type Description
string
View Source

MatchConditions

MatchConditions is a list of conditions that must be met for a request to be validated. Match conditions filter requests that have already been matched by the rules, namespaceSelector, and objectSelector. An empty list of matchConditions matches all requests. There are a maximum of 64 match conditions allowed.

If a parameter object is provided, it can be accessed via the params handle in the same manner as validation expressions.

The exact matching logic is (in order):

  1. If ANY matchCondition evaluates to FALSE, the policy is skipped.
  2. If ALL matchConditions evaluate to TRUE, the policy is evaluated.
  3. If any matchCondition evaluates to an error (but none are FALSE):
  • If failurePolicy=Fail, reject the request
  • If failurePolicy=Ignore, the policy is skipped
Declaration
[JsonPropertyName("matchConditions")]
public IList<V1MatchCondition> MatchConditions { get; set; }
Property Value
Type Description
IList<V1MatchCondition>
View Source

MatchConstraints

MatchConstraints specifies what resources this policy is designed to validate. The AdmissionPolicy cares about a request if it matches all Constraints. However, in order to prevent clusters from being put into an unstable state that cannot be recovered from via the API ValidatingAdmissionPolicy cannot match ValidatingAdmissionPolicy and ValidatingAdmissionPolicyBinding. Required.

Declaration
[JsonPropertyName("matchConstraints")]
public V1MatchResources MatchConstraints { get; set; }
Property Value
Type Description
V1MatchResources
View Source

ParamKind

ParamKind specifies the kind of resources used to parameterize this policy. If absent, there are no parameters for this policy and the param CEL variable will not be provided to validation expressions. If ParamKind refers to a non-existent kind, this policy definition is mis-configured and the FailurePolicy is applied. If paramKind is specified but paramRef is unset in ValidatingAdmissionPolicyBinding, the params variable will be null.

Declaration
[JsonPropertyName("paramKind")]
public V1ParamKind ParamKind { get; set; }
Property Value
Type Description
V1ParamKind
View Source

Validations

Validations contain CEL expressions which is used to apply the validation. Validations and AuditAnnotations may not both be empty; a minimum of one Validations or AuditAnnotations is required.

Declaration
[JsonPropertyName("validations")]
public IList<V1Validation> Validations { get; set; }
Property Value
Type Description
IList<V1Validation>
View Source

Variables

Variables contain definitions of variables that can be used in composition of other expressions. Each variable is defined as a named CEL expression. The variables defined here will be available under variables in other expressions of the policy except MatchConditions because MatchConditions are evaluated before the rest of the policy.

The expression of a variable can refer to other variables defined earlier in the list but not those after. Thus, Variables must be sorted by the order of first appearance and acyclic.

Declaration
[JsonPropertyName("variables")]
public IList<V1Variable> Variables { get; set; }
Property Value
Type Description
IList<V1Variable>

Methods

View Source

Equals(object?)

Declaration
public override bool Equals(object? obj)
Parameters
Type Name Description
object obj
Returns
Type Description
bool
Overrides
object.Equals(object)
View Source

Equals(V1ValidatingAdmissionPolicySpec?)

Declaration
public virtual bool Equals(V1ValidatingAdmissionPolicySpec? other)
Parameters
Type Name Description
V1ValidatingAdmissionPolicySpec other
Returns
Type Description
bool
View Source

GetHashCode()

Declaration
public override int GetHashCode()
Returns
Type Description
int
Overrides
object.GetHashCode()
View Source

PrintMembers(StringBuilder)

Declaration
protected virtual bool PrintMembers(StringBuilder builder)
Parameters
Type Name Description
StringBuilder builder
Returns
Type Description
bool
View Source

ToString()

Declaration
public override string ToString()
Returns
Type Description
string
Overrides
object.ToString()

Operators

View Source

operator ==(V1ValidatingAdmissionPolicySpec?, V1ValidatingAdmissionPolicySpec?)

Declaration
public static bool operator ==(V1ValidatingAdmissionPolicySpec? left, V1ValidatingAdmissionPolicySpec? right)
Parameters
Type Name Description
V1ValidatingAdmissionPolicySpec left
V1ValidatingAdmissionPolicySpec right
Returns
Type Description
bool
View Source

operator !=(V1ValidatingAdmissionPolicySpec?, V1ValidatingAdmissionPolicySpec?)

Declaration
public static bool operator !=(V1ValidatingAdmissionPolicySpec? left, V1ValidatingAdmissionPolicySpec? right)
Parameters
Type Name Description
V1ValidatingAdmissionPolicySpec left
V1ValidatingAdmissionPolicySpec right
Returns
Type Description
bool

Implements

IEquatable<T>
  • View Source
In this article
Back to top Generated by DocFX