aboutsummaryrefslogtreecommitdiff
path: root/vendor/k8s.io/kubernetes/pkg/security/apparmor/helpers.go
diff options
context:
space:
mode:
authorMatthew Heon <matthew.heon@gmail.com>2017-11-01 11:24:59 -0400
committerMatthew Heon <matthew.heon@gmail.com>2017-11-01 11:24:59 -0400
commita031b83a09a8628435317a03f199cdc18b78262f (patch)
treebc017a96769ce6de33745b8b0b1304ccf38e9df0 /vendor/k8s.io/kubernetes/pkg/security/apparmor/helpers.go
parent2b74391cd5281f6fdf391ff8ad50fd1490f6bf89 (diff)
downloadpodman-a031b83a09a8628435317a03f199cdc18b78262f.tar.gz
podman-a031b83a09a8628435317a03f199cdc18b78262f.tar.bz2
podman-a031b83a09a8628435317a03f199cdc18b78262f.zip
Initial checkin from CRI-O repo
Signed-off-by: Matthew Heon <matthew.heon@gmail.com>
Diffstat (limited to 'vendor/k8s.io/kubernetes/pkg/security/apparmor/helpers.go')
-rw-r--r--vendor/k8s.io/kubernetes/pkg/security/apparmor/helpers.go77
1 files changed, 77 insertions, 0 deletions
diff --git a/vendor/k8s.io/kubernetes/pkg/security/apparmor/helpers.go b/vendor/k8s.io/kubernetes/pkg/security/apparmor/helpers.go
new file mode 100644
index 000000000..4412d2a9a
--- /dev/null
+++ b/vendor/k8s.io/kubernetes/pkg/security/apparmor/helpers.go
@@ -0,0 +1,77 @@
+/*
+Copyright 2016 The Kubernetes Authors.
+
+Licensed under the Apache License, Version 2.0 (the "License");
+you may not use this file except in compliance with the License.
+You may obtain a copy of the License at
+
+ http://www.apache.org/licenses/LICENSE-2.0
+
+Unless required by applicable law or agreed to in writing, software
+distributed under the License is distributed on an "AS IS" BASIS,
+WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+See the License for the specific language governing permissions and
+limitations under the License.
+*/
+
+package apparmor
+
+import (
+ "strings"
+
+ "k8s.io/kubernetes/pkg/api/v1"
+)
+
+// TODO: Move these values into the API package.
+const (
+ // The prefix to an annotation key specifying a container profile.
+ ContainerAnnotationKeyPrefix = "container.apparmor.security.beta.kubernetes.io/"
+ // The annotation key specifying the default AppArmor profile.
+ DefaultProfileAnnotationKey = "apparmor.security.beta.kubernetes.io/defaultProfileName"
+ // The annotation key specifying the allowed AppArmor profiles.
+ AllowedProfilesAnnotationKey = "apparmor.security.beta.kubernetes.io/allowedProfileNames"
+
+ // The profile specifying the runtime default.
+ ProfileRuntimeDefault = "runtime/default"
+ // The prefix for specifying profiles loaded on the node.
+ ProfileNamePrefix = "localhost/"
+)
+
+// Checks whether app armor is required for pod to be run.
+func isRequired(pod *v1.Pod) bool {
+ for key := range pod.Annotations {
+ if strings.HasPrefix(key, ContainerAnnotationKeyPrefix) {
+ return true
+ }
+ }
+ return false
+}
+
+// Returns the name of the profile to use with the container.
+func GetProfileName(pod *v1.Pod, containerName string) string {
+ return GetProfileNameFromPodAnnotations(pod.Annotations, containerName)
+}
+
+// GetProfileNameFromPodAnnotations gets the name of the profile to use with container from
+// pod annotations
+func GetProfileNameFromPodAnnotations(annotations map[string]string, containerName string) string {
+ return annotations[ContainerAnnotationKeyPrefix+containerName]
+}
+
+// Sets the name of the profile to use with the container.
+func SetProfileName(pod *v1.Pod, containerName, profileName string) error {
+ if pod.Annotations == nil {
+ pod.Annotations = map[string]string{}
+ }
+ pod.Annotations[ContainerAnnotationKeyPrefix+containerName] = profileName
+ return nil
+}
+
+// Sets the name of the profile to use with the container.
+func SetProfileNameFromPodAnnotations(annotations map[string]string, containerName, profileName string) error {
+ if annotations == nil {
+ return nil
+ }
+ annotations[ContainerAnnotationKeyPrefix+containerName] = profileName
+ return nil
+}