1package v1
2
3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
4
5// FieldSelectorAttributes indicates a field limited access. Webhook authors are
6// encouraged to * ensure rawSelector and requirements are not both set *
7// consider the requirements field if set * not try to parse or consider the
8// rawSelector field if set. This is to avoid another CVE-2022-2880 (i.e.
9// getting different systems to agree on how exactly to parse a query is not
10// something we want), see
11// https://www.oxeye.io/resources/golang-parameter-smuggling-attack for more
12// details. For the *SubjectAccessReview endpoints of the kube-apiserver: * If
13// rawSelector is empty and requirements are empty, the request is not limited.
14// * If rawSelector is present and requirements are empty, the rawSelector will
15// be parsed and limited if the parsing succeeds. * If rawSelector is empty and
16// requirements are present, the requirements should be honored * If
17// rawSelector is present and requirements are present, the request is invalid.
18#FieldSelectorAttributes: {
19 // rawSelector is the serialization of a field selector that would be included
20 // in a query parameter. Webhook implementations are encouraged to ignore
21 // rawSelector. The kube-apiserver's *SubjectAccessReview will parse the
22 // rawSelector as long as the requirements are not present.
23 "rawSelector"?: string
24
25 // requirements is the parsed interpretation of a field selector. All
26 // requirements must be met for a resource instance to match the selector.
27 // Webhook implementations should handle requirements, but how to handle them
28 // is up to the webhook. Since requirements can only limit the request, it is
29 // safe to authorize as unlimited request if the requirements are not
30 // understood.
31 "requirements"?: [...v1.#FieldSelectorRequirement]
32}
33
34// LabelSelectorAttributes indicates a label limited access. Webhook authors are
35// encouraged to * ensure rawSelector and requirements are not both set *
36// consider the requirements field if set * not try to parse or consider the
37// rawSelector field if set. This is to avoid another CVE-2022-2880 (i.e.
38// getting different systems to agree on how exactly to parse a query is not
39// something we want), see
40// https://www.oxeye.io/resources/golang-parameter-smuggling-attack for more
41// details. For the *SubjectAccessReview endpoints of the kube-apiserver: * If
42// rawSelector is empty and requirements are empty, the request is not limited.
43// * If rawSelector is present and requirements are empty, the rawSelector will
44// be parsed and limited if the parsing succeeds. * If rawSelector is empty and
45// requirements are present, the requirements should be honored * If
46// rawSelector is present and requirements are present, the request is invalid.
47#LabelSelectorAttributes: {
48 // rawSelector is the serialization of a field selector that would be included
49 // in a query parameter. Webhook implementations are encouraged to ignore
50 // rawSelector. The kube-apiserver's *SubjectAccessReview will parse the
51 // rawSelector as long as the requirements are not present.
52 "rawSelector"?: string
53
54 // requirements is the parsed interpretation of a label selector. All
55 // requirements must be met for a resource instance to match the selector.
56 // Webhook implementations should handle requirements, but how to handle them
57 // is up to the webhook. Since requirements can only limit the request, it is
58 // safe to authorize as unlimited request if the requirements are not
59 // understood.
60 "requirements"?: [...v1.#LabelSelectorRequirement]
61}
62
63// LocalSubjectAccessReview checks whether or not a user or group can perform an
64// action in a given namespace. Having a namespace scoped resource makes it
65// much easier to grant namespace scoped policy that includes permissions
66// checking.
67#LocalSubjectAccessReview: {
68 // APIVersion defines the versioned schema of this representation of an object.
69 // Servers should convert recognized schemas to the latest internal value, and
70 // may reject unrecognized values. More info:
71 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
72 "apiVersion": "authorization.k8s.io/v1"
73
74 // Kind is a string value representing the REST resource this object represents.
75 // Servers may infer this from the endpoint the client submits requests to.
76 // Cannot be updated. In CamelCase. More info:
77 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
78 "kind": "LocalSubjectAccessReview"
79
80 // metadata is the standard list metadata. More info:
81 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
82 "metadata"?: v1.#ObjectMeta
83
84 // spec holds information about the request being evaluated. spec.namespace must
85 // be equal to the namespace you made the request against. If empty, it is
86 // defaulted.
87 "spec"!: #SubjectAccessReviewSpec
88
89 // status is filled in by the server and indicates whether the request is allowed or not
90 "status"?: #SubjectAccessReviewStatus
91}
92
93// NonResourceAttributes includes the authorization attributes available for
94// non-resource requests to the Authorizer interface
95#NonResourceAttributes: {
96 // path is the URL path of the request
97 "path"?: string
98
99 // verb is the standard HTTP verb
100 "verb"?: string
101}
102
103// NonResourceRule holds information that describes a rule for the non-resource
104#NonResourceRule: {
105 // nonResourceURLs is a set of partial urls that a user should have access to.
106 // *s are allowed, but only as the full, final step in the path. "*" means all.
107 "nonResourceURLs"?: [...string]
108
109 // verbs is a list of kubernetes non-resource API verbs, like: get, post, put,
110 // delete, patch, head, options. "*" means all.
111 "verbs"!: [...string]
112}
113
114// ResourceAttributes includes the authorization attributes available for
115// resource requests to the Authorizer interface
116#ResourceAttributes: {
117 // fieldSelector describes the limitation on access based on field. It can only
118 // limit access, not broaden it.
119 "fieldSelector"?: #FieldSelectorAttributes
120
121 // group is the API Group of the Resource. "*" means all.
122 "group"?: string
123
124 // labelSelector describes the limitation on access based on labels. It can only
125 // limit access, not broaden it.
126 "labelSelector"?: #LabelSelectorAttributes
127
128 // name is the name of the resource being requested for a "get" or deleted for a
129 // "delete". "" (empty) means all.
130 "name"?: string
131
132 // namespace is the namespace of the action being requested. Currently, there is
133 // no distinction between no namespace and all namespaces "" (empty) is
134 // defaulted for LocalSubjectAccessReviews "" (empty) is empty for
135 // cluster-scoped resources "" (empty) means "all" for namespace scoped
136 // resources from a SubjectAccessReview or SelfSubjectAccessReview
137 "namespace"?: string
138
139 // resource is one of the existing resource types. "*" means all.
140 "resource"?: string
141
142 // subresource is one of the existing resource types. "" means none.
143 "subresource"?: string
144
145 // verb is a kubernetes resource API verb, like: get, list, watch, create,
146 // update, delete, proxy. "*" means all.
147 "verb"?: string
148
149 // version is the API Version of the Resource. "*" means all.
150 "version"?: string
151}
152
153// ResourceRule is the list of actions the subject is allowed to perform on
154// resources. The list ordering isn't significant, may contain duplicates, and
155// possibly be incomplete.
156#ResourceRule: {
157 // apiGroups is the name of the APIGroup that contains the resources. If
158 // multiple API groups are specified, any action requested against one of the
159 // enumerated resources in any API group will be allowed. "*" means all.
160 "apiGroups"?: [...string]
161
162 // resourceNames is an optional white list of names that the rule applies to. An
163 // empty set means that everything is allowed. "*" means all.
164 "resourceNames"?: [...string]
165
166 // resources is a list of resources this rule applies to. "*" means all in the specified apiGroups.
167 // "*/foo" represents the subresource 'foo' for all resources in the specified apiGroups.
168 "resources"?: [...string]
169
170 // verbs is a list of kubernetes resource API verbs, like: get, list, watch,
171 // create, update, delete, proxy. "*" means all.
172 "verbs"!: [...string]
173}
174
175// SelfSubjectAccessReview checks whether or the current user can perform an
176// action. Not filling in a spec.namespace means "in all namespaces". Self is a
177// special case, because users should always be able to check whether they can
178// perform an action
179#SelfSubjectAccessReview: {
180 // APIVersion defines the versioned schema of this representation of an object.
181 // Servers should convert recognized schemas to the latest internal value, and
182 // may reject unrecognized values. More info:
183 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
184 "apiVersion": "authorization.k8s.io/v1"
185
186 // Kind is a string value representing the REST resource this object represents.
187 // Servers may infer this from the endpoint the client submits requests to.
188 // Cannot be updated. In CamelCase. More info:
189 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
190 "kind": "SelfSubjectAccessReview"
191
192 // metadata is the standard list metadata. More info:
193 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
194 "metadata"?: v1.#ObjectMeta
195
196 // spec holds information about the request being evaluated. user and groups must be empty
197 "spec"!: #SelfSubjectAccessReviewSpec
198
199 // status is filled in by the server and indicates whether the request is allowed or not
200 "status"?: #SubjectAccessReviewStatus
201}
202
203// SelfSubjectAccessReviewSpec is a description of the access request. Exactly
204// one of resourceAttributes and nonResourceAttributes must be set
205#SelfSubjectAccessReviewSpec: {
206 // nonResourceAttributes describes information for a non-resource access request
207 "nonResourceAttributes"?: #NonResourceAttributes
208
209 // resourceAttributes describes information for a resource access request
210 "resourceAttributes"?: #ResourceAttributes
211}
212
213// SelfSubjectRulesReview enumerates the set of actions the current user can
214// perform within a namespace. The returned list of actions may be incomplete
215// depending on the server's authorization mode, and any errors experienced
216// during the evaluation. SelfSubjectRulesReview should be used by UIs to
217// show/hide actions, or to quickly let an end user reason about their
218// permissions. It should NOT Be used by external systems to drive
219// authorization decisions as this raises confused deputy, cache
220// lifetime/revocation, and correctness concerns. SubjectAccessReview, and
221// LocalAccessReview are the correct way to defer authorization decisions to
222// the API server.
223#SelfSubjectRulesReview: {
224 // APIVersion defines the versioned schema of this representation of an object.
225 // Servers should convert recognized schemas to the latest internal value, and
226 // may reject unrecognized values. More info:
227 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
228 "apiVersion": "authorization.k8s.io/v1"
229
230 // Kind is a string value representing the REST resource this object represents.
231 // Servers may infer this from the endpoint the client submits requests to.
232 // Cannot be updated. In CamelCase. More info:
233 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
234 "kind": "SelfSubjectRulesReview"
235
236 // metadata is the standard list metadata. More info:
237 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
238 "metadata"?: v1.#ObjectMeta
239
240 // spec holds information about the request being evaluated.
241 "spec"!: #SelfSubjectRulesReviewSpec
242
243 // status is filled in by the server and indicates the set of actions a user can perform.
244 "status"?: #SubjectRulesReviewStatus
245}
246
247// SelfSubjectRulesReviewSpec defines the specification for SelfSubjectRulesReview.
248#SelfSubjectRulesReviewSpec: {
249 // namespace to evaluate rules for. Required.
250 "namespace"?: string
251}
252
253// SubjectAccessReview checks whether or not a user or group can perform an action.
254#SubjectAccessReview: {
255 // APIVersion defines the versioned schema of this representation of an object.
256 // Servers should convert recognized schemas to the latest internal value, and
257 // may reject unrecognized values. More info:
258 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
259 "apiVersion": "authorization.k8s.io/v1"
260
261 // Kind is a string value representing the REST resource this object represents.
262 // Servers may infer this from the endpoint the client submits requests to.
263 // Cannot be updated. In CamelCase. More info:
264 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
265 "kind": "SubjectAccessReview"
266
267 // metadata is the standard list metadata. More info:
268 // https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
269 "metadata"?: v1.#ObjectMeta
270
271 // spec holds information about the request being evaluated
272 "spec"!: #SubjectAccessReviewSpec
273
274 // status is filled in by the server and indicates whether the request is allowed or not
275 "status"?: #SubjectAccessReviewStatus
276}
277
278// SubjectAccessReviewSpec is a description of the access request. Exactly one
279// of resourceAttributes and nonResourceAttributes must be set
280#SubjectAccessReviewSpec: {
281 // extra corresponds to the user.Info.GetExtra() method from the authenticator.
282 // Since that is input to the authorizer it needs a reflection here.
283 "extra"?: [string]: [...string]
284
285 // groups is the groups you're testing for.
286 "groups"?: [...string]
287
288 // nonResourceAttributes describes information for a non-resource access request
289 "nonResourceAttributes"?: #NonResourceAttributes
290
291 // resourceAttributes describes information for a resource access request
292 "resourceAttributes"?: #ResourceAttributes
293
294 // uid information about the requesting user.
295 "uid"?: string
296
297 // user is the user you're testing for. If you specify "User" but not "Groups",
298 // then is it interpreted as "What if User were not a member of any groups
299 "user"?: string
300}
301
302// SubjectAccessReviewStatus
303#SubjectAccessReviewStatus: {
304 // allowed is required. True if the action would be allowed, false otherwise.
305 "allowed"!: bool
306
307 // denied is optional. True if the action would be denied, otherwise false. If
308 // both allowed is false and denied is false, then the authorizer has no
309 // opinion on whether to authorize the action. Denied may not be true if
310 // Allowed is true.
311 "denied"?: bool
312
313 // evaluationError is an indication that some error occurred during the
314 // authorization check. It is entirely possible to get an error and be able to
315 // continue determine authorization status in spite of it. For instance, RBAC
316 // can be missing a role, but enough roles are still present and bound to
317 // reason about the request.
318 "evaluationError"?: string
319
320 // reason is optional. It indicates why a request was allowed or denied.
321 "reason"?: string
322}
323
324// SubjectRulesReviewStatus contains the result of a rules check. This check can
325// be incomplete depending on the set of authorizers the server is configured
326// with and any errors experienced during evaluation. Because authorization
327// rules are additive, if a rule appears in a list it's safe to assume the
328// subject has that permission, even if that list is incomplete.
329#SubjectRulesReviewStatus: {
330 // evaluationError can appear in combination with Rules. It indicates an error
331 // occurred during rule evaluation, such as an authorizer that doesn't support
332 // rule evaluation, and that ResourceRules and/or NonResourceRules may be
333 // incomplete.
334 "evaluationError"?: string
335
336 // incomplete is true when the rules returned by this call are incomplete. This
337 // is most commonly encountered when an authorizer, such as an external
338 // authorizer, doesn't support rules evaluation.
339 "incomplete"!: bool
340
341 // nonResourceRules is the list of actions the subject is allowed to perform on
342 // non-resources. The list ordering isn't significant, may contain duplicates,
343 // and possibly be incomplete.
344 "nonResourceRules"!: [...#NonResourceRule]
345
346 // resourceRules is the list of actions the subject is allowed to perform on
347 // resources. The list ordering isn't significant, may contain duplicates, and
348 // possibly be incomplete.
349 "resourceRules"!: [...#ResourceRule]
350}