opa.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452
  1. package opa
  2. import (
  3. "context"
  4. "fmt"
  5. "os"
  6. "strings"
  7. "github.com/mitchellh/mapstructure"
  8. "github.com/open-policy-agent/opa/rego"
  9. "github.com/porter-dev/porter/api/types"
  10. "github.com/porter-dev/porter/internal/helm"
  11. "github.com/porter-dev/porter/internal/kubernetes"
  12. "github.com/porter-dev/porter/pkg/logger"
  13. "helm.sh/helm/v3/pkg/release"
  14. v1 "k8s.io/apimachinery/pkg/apis/meta/v1"
  15. "k8s.io/apimachinery/pkg/runtime"
  16. "k8s.io/apimachinery/pkg/runtime/schema"
  17. "k8s.io/client-go/dynamic"
  18. )
  19. type KubernetesPolicies struct {
  20. Policies map[string]KubernetesOPAQueryCollection
  21. }
  22. type KubernetesOPARunner struct {
  23. *KubernetesPolicies
  24. k8sAgent *kubernetes.Agent
  25. dynamicClient dynamic.Interface
  26. }
  27. type KubernetesBuiltInKind string
  28. const (
  29. HelmRelease KubernetesBuiltInKind = "helm_release"
  30. Pod KubernetesBuiltInKind = "pod"
  31. CRDList KubernetesBuiltInKind = "crd_list"
  32. Daemonset KubernetesBuiltInKind = "daemonset"
  33. )
  34. type KubernetesOPAQueryCollection struct {
  35. Kind KubernetesBuiltInKind
  36. Match MatchParameters
  37. MustExist bool
  38. OverrideSeverity string
  39. Queries []rego.PreparedEvalQuery
  40. }
  41. type MatchParameters struct {
  42. Name string `json:"name"`
  43. Namespace string `json:"namespace"`
  44. ChartName string `json:"chart_name"`
  45. Labels map[string]string `json:"labels"`
  46. // parameters for CRDs
  47. Group string `json:"group"`
  48. Version string `json:"version"`
  49. Resource string `json:"resource"`
  50. }
  51. type OPARecommenderQueryResult struct {
  52. Allow bool
  53. CategoryName string
  54. ObjectID string
  55. PolicyVersion string
  56. PolicySeverity string
  57. PolicyTitle string
  58. PolicyMessage string
  59. }
  60. type rawQueryResult struct {
  61. Allow bool `mapstructure:"ALLOW"`
  62. PolicyID string `mapstructure:"POLICY_ID"`
  63. PolicyVersion string `mapstructure:"POLICY_VERSION"`
  64. PolicySeverity string `mapstructure:"POLICY_SEVERITY"`
  65. PolicyTitle string `mapstructure:"POLICY_TITLE"`
  66. SuccessMessage string `mapstructure:"POLICY_SUCCESS_MESSAGE"`
  67. FailureMessage []string `mapstructure:"FAILURE_MESSAGE"`
  68. }
  69. func NewRunner(policies *KubernetesPolicies, k8sAgent *kubernetes.Agent, dynamicClient dynamic.Interface) *KubernetesOPARunner {
  70. return &KubernetesOPARunner{policies, k8sAgent, dynamicClient}
  71. }
  72. func (runner *KubernetesOPARunner) GetRecommendations(categories []string) ([]*OPARecommenderQueryResult, error) {
  73. collectionNames := categories
  74. if len(categories) == 0 {
  75. for catName, _ := range runner.Policies {
  76. collectionNames = append(collectionNames, catName)
  77. }
  78. }
  79. res := make([]*OPARecommenderQueryResult, 0)
  80. // ping the cluster with a version check to make sure it's reachable - if not, return an error
  81. _, err := runner.k8sAgent.Clientset.Discovery().ServerVersion()
  82. if err != nil {
  83. fmt.Printf("discovery check failed: %v\n", err.Error())
  84. } else {
  85. for _, name := range collectionNames {
  86. // look up to determine if the name is registered
  87. queryCollection, exists := runner.Policies[name]
  88. if !exists {
  89. return nil, fmt.Errorf("No policies for %s found", name)
  90. }
  91. var currResults []*OPARecommenderQueryResult
  92. var err error
  93. switch queryCollection.Kind {
  94. case HelmRelease:
  95. currResults, err = runner.runHelmReleaseQueries(name, queryCollection)
  96. case Pod:
  97. currResults, err = runner.runPodQueries(name, queryCollection)
  98. case CRDList:
  99. currResults, err = runner.runCRDListQueries(name, queryCollection)
  100. case Daemonset:
  101. currResults, err = runner.runDaemonsetQueries(name, queryCollection)
  102. default:
  103. fmt.Printf("%s is not a supported query kind", queryCollection.Kind)
  104. continue
  105. }
  106. if err != nil {
  107. fmt.Printf("%s", err.Error())
  108. continue
  109. }
  110. res = append(res, currResults...)
  111. }
  112. }
  113. return res, nil
  114. }
  115. func (runner *KubernetesOPARunner) SetK8sAgent(k8sAgent *kubernetes.Agent) {
  116. runner.k8sAgent = k8sAgent
  117. }
  118. func (runner *KubernetesOPARunner) runHelmReleaseQueries(name string, collection KubernetesOPAQueryCollection) ([]*OPARecommenderQueryResult, error) {
  119. res := make([]*OPARecommenderQueryResult, 0)
  120. helmAgent, err := helm.GetAgentFromK8sAgent("secret", collection.Match.Namespace, logger.New(false, os.Stdout), runner.k8sAgent)
  121. if err != nil {
  122. return nil, err
  123. }
  124. // get the matching helm release(s) based on the match
  125. var helmReleases []*release.Release
  126. if collection.Match.Name != "" {
  127. helmRelease, err := helmAgent.GetRelease(collection.Match.Name, 0, false)
  128. if err != nil {
  129. if collection.MustExist && strings.Contains(err.Error(), "not found") {
  130. return []*OPARecommenderQueryResult{
  131. {
  132. Allow: false,
  133. ObjectID: fmt.Sprintf("helm_release/%s/%s/%s", collection.Match.Namespace, collection.Match.Name, "exists"),
  134. CategoryName: name,
  135. PolicyVersion: "v0.0.1",
  136. PolicySeverity: getSeverity("high", collection),
  137. PolicyTitle: fmt.Sprintf("The helm release %s must exist", collection.Match.Name),
  138. PolicyMessage: "The helm release was not found on the cluster",
  139. },
  140. }, nil
  141. } else {
  142. return nil, err
  143. }
  144. } else if collection.MustExist {
  145. res = append(res, &OPARecommenderQueryResult{
  146. Allow: true,
  147. ObjectID: fmt.Sprintf("helm_release/%s/%s/%s", collection.Match.Namespace, collection.Match.Name, "exists"),
  148. CategoryName: name,
  149. PolicyVersion: "v0.0.1",
  150. PolicySeverity: getSeverity("high", collection),
  151. PolicyTitle: fmt.Sprintf("The helm release %s must exist", collection.Match.Name),
  152. PolicyMessage: "The helm release was found",
  153. })
  154. }
  155. helmReleases = append(helmReleases, helmRelease)
  156. } else if collection.Match.ChartName != "" {
  157. prefilterReleases, err := helmAgent.ListReleases(collection.Match.Namespace, &types.ReleaseListFilter{
  158. ByDate: true,
  159. StatusFilter: []string{
  160. "deployed",
  161. "pending",
  162. "pending-install",
  163. "pending-upgrade",
  164. "pending-rollback",
  165. "failed",
  166. },
  167. })
  168. if err != nil {
  169. return nil, err
  170. }
  171. for _, prefilterRelease := range prefilterReleases {
  172. if prefilterRelease.Chart.Name() == collection.Match.ChartName {
  173. helmReleases = append(helmReleases, prefilterRelease)
  174. }
  175. }
  176. } else {
  177. return nil, fmt.Errorf("invalid match parameters")
  178. }
  179. for _, helmRelease := range helmReleases {
  180. for _, query := range collection.Queries {
  181. results, err := query.Eval(
  182. context.Background(),
  183. rego.EvalInput(map[string]interface{}{
  184. "version": helmRelease.Chart.Metadata.Version,
  185. "values": helmRelease.Config,
  186. "name": helmRelease.Name,
  187. "namespace": helmRelease.Namespace,
  188. }),
  189. )
  190. if err != nil {
  191. return nil, err
  192. }
  193. if len(results) == 1 {
  194. rawQueryRes := &rawQueryResult{}
  195. err = mapstructure.Decode(results[0].Expressions[0].Value, rawQueryRes)
  196. if err != nil {
  197. return nil, err
  198. }
  199. res = append(res, rawQueryResToRecommenderQueryResult(
  200. rawQueryRes,
  201. fmt.Sprintf("helm_release/%s/%s/%s", helmRelease.Namespace, helmRelease.Name, rawQueryRes.PolicyID),
  202. name,
  203. collection,
  204. ))
  205. }
  206. }
  207. }
  208. return res, nil
  209. }
  210. func getSeverity(defaultSeverity string, collection KubernetesOPAQueryCollection) string {
  211. if collection.OverrideSeverity != "" {
  212. return collection.OverrideSeverity
  213. }
  214. return defaultSeverity
  215. }
  216. func (runner *KubernetesOPARunner) runPodQueries(name string, collection KubernetesOPAQueryCollection) ([]*OPARecommenderQueryResult, error) {
  217. res := make([]*OPARecommenderQueryResult, 0)
  218. lselArr := make([]string, 0)
  219. for k, v := range collection.Match.Labels {
  220. lselArr = append(lselArr, fmt.Sprintf("%s=%s", k, v))
  221. }
  222. lsel := strings.Join(lselArr, ",")
  223. pods, err := runner.k8sAgent.GetPodsByLabel(lsel, collection.Match.Namespace)
  224. if err != nil {
  225. return nil, err
  226. }
  227. for _, pod := range pods.Items {
  228. unstructuredPod, err := runtime.DefaultUnstructuredConverter.ToUnstructured(&pod)
  229. if err != nil {
  230. return nil, err
  231. }
  232. for _, query := range collection.Queries {
  233. results, err := query.Eval(
  234. context.Background(),
  235. rego.EvalInput(unstructuredPod),
  236. )
  237. if err != nil {
  238. return nil, err
  239. }
  240. if len(results) == 1 {
  241. rawQueryRes := &rawQueryResult{}
  242. err = mapstructure.Decode(results[0].Expressions[0].Value, rawQueryRes)
  243. if err != nil {
  244. return nil, err
  245. }
  246. res = append(res, rawQueryResToRecommenderQueryResult(
  247. rawQueryRes,
  248. fmt.Sprintf("pod/%s/%s", pod.Namespace, pod.Name),
  249. name,
  250. collection,
  251. ))
  252. }
  253. }
  254. }
  255. return res, nil
  256. }
  257. func (runner *KubernetesOPARunner) runDaemonsetQueries(name string, collection KubernetesOPAQueryCollection) ([]*OPARecommenderQueryResult, error) {
  258. res := make([]*OPARecommenderQueryResult, 0)
  259. lselArr := make([]string, 0)
  260. for k, v := range collection.Match.Labels {
  261. lselArr = append(lselArr, fmt.Sprintf("%s=%s", k, v))
  262. }
  263. lsel := strings.Join(lselArr, ",")
  264. daemonsets, err := runner.k8sAgent.Clientset.AppsV1().DaemonSets(collection.Match.Namespace).List(context.Background(), v1.ListOptions{
  265. LabelSelector: lsel,
  266. })
  267. if err != nil {
  268. return nil, err
  269. }
  270. for _, ds := range daemonsets.Items {
  271. unstructuredDS, err := runtime.DefaultUnstructuredConverter.ToUnstructured(&ds)
  272. if err != nil {
  273. return nil, err
  274. }
  275. for _, query := range collection.Queries {
  276. results, err := query.Eval(
  277. context.Background(),
  278. rego.EvalInput(unstructuredDS),
  279. )
  280. if err != nil {
  281. return nil, err
  282. }
  283. if len(results) == 1 {
  284. rawQueryRes := &rawQueryResult{}
  285. err = mapstructure.Decode(results[0].Expressions[0].Value, rawQueryRes)
  286. if err != nil {
  287. return nil, err
  288. }
  289. res = append(res, rawQueryResToRecommenderQueryResult(
  290. rawQueryRes,
  291. fmt.Sprintf("daemonset/%s/%s", ds.Namespace, ds.Name),
  292. name,
  293. collection,
  294. ))
  295. }
  296. }
  297. }
  298. return res, nil
  299. }
  300. func (runner *KubernetesOPARunner) runCRDListQueries(name string, collection KubernetesOPAQueryCollection) ([]*OPARecommenderQueryResult, error) {
  301. res := make([]*OPARecommenderQueryResult, 0)
  302. objRes := schema.GroupVersionResource{
  303. Group: collection.Match.Group,
  304. Version: collection.Match.Version,
  305. Resource: collection.Match.Resource,
  306. }
  307. // just case on the "core" group and unset it
  308. if collection.Match.Group == "core" {
  309. objRes.Group = ""
  310. }
  311. crdList, err := runner.dynamicClient.Resource(objRes).Namespace(collection.Match.Namespace).List(context.Background(), v1.ListOptions{})
  312. if err != nil {
  313. return nil, err
  314. }
  315. for _, crd := range crdList.Items {
  316. for _, query := range collection.Queries {
  317. results, err := query.Eval(
  318. context.Background(),
  319. rego.EvalInput(crd.Object),
  320. )
  321. if err != nil {
  322. return nil, err
  323. }
  324. if len(results) == 1 {
  325. rawQueryRes := &rawQueryResult{}
  326. err = mapstructure.Decode(results[0].Expressions[0].Value, rawQueryRes)
  327. if err != nil {
  328. return nil, err
  329. }
  330. res = append(res, rawQueryResToRecommenderQueryResult(
  331. rawQueryRes,
  332. fmt.Sprintf("%s/%s/%s/%s", collection.Match.Group, collection.Match.Version, collection.Match.Resource, rawQueryRes.PolicyID),
  333. name,
  334. collection,
  335. ))
  336. }
  337. }
  338. }
  339. return res, nil
  340. }
  341. func rawQueryResToRecommenderQueryResult(rawQueryRes *rawQueryResult, objectID, categoryName string, collection KubernetesOPAQueryCollection) *OPARecommenderQueryResult {
  342. queryRes := &OPARecommenderQueryResult{
  343. ObjectID: objectID,
  344. CategoryName: categoryName,
  345. }
  346. message := rawQueryRes.SuccessMessage
  347. // if failure, compose failure messages into single string
  348. if !rawQueryRes.Allow {
  349. message = strings.Join(rawQueryRes.FailureMessage, ". ")
  350. }
  351. queryRes.PolicyMessage = message
  352. queryRes.Allow = rawQueryRes.Allow
  353. queryRes.PolicySeverity = getSeverity(rawQueryRes.PolicySeverity, collection)
  354. queryRes.PolicyTitle = rawQueryRes.PolicyTitle
  355. queryRes.PolicyVersion = rawQueryRes.PolicyVersion
  356. return queryRes
  357. }