cue.dev/x/k8s.io@v0.12.0

api/authorization/v1/schema.cue raw

  1package v1
  2
  3import "cue.dev/x/k8s.io/apimachinery/pkg/apis/meta/v1"
  4
  5// FieldSelectorAttributes indicates a field limited access. Webhook authors are
  6// encouraged to * ensure rawSelector and requirements are not both set *
  7// consider the requirements field if set * not try to parse or consider the
  8// rawSelector field if set. This is to avoid another CVE-2022-2880 (i.e.
  9// getting different systems to agree on how exactly to parse a query is not
 10// something we want), see
 11// https://www.oxeye.io/resources/golang-parameter-smuggling-attack for more
 12// details. For the *SubjectAccessReview endpoints of the kube-apiserver: * If
 13// rawSelector is empty and requirements are empty, the request is not limited.
 14// * If rawSelector is present and requirements are empty, the rawSelector will
 15// be parsed and limited if the parsing succeeds. * If rawSelector is empty and
 16// requirements are present, the requirements should be honored * If
 17// rawSelector is present and requirements are present, the request is invalid.
 18#FieldSelectorAttributes: {
 19	// rawSelector is the serialization of a field selector that would be included
 20	// in a query parameter. Webhook implementations are encouraged to ignore
 21	// rawSelector. The kube-apiserver's *SubjectAccessReview will parse the
 22	// rawSelector as long as the requirements are not present.
 23	"rawSelector"?: string
 24
 25	// requirements is the parsed interpretation of a field selector. All
 26	// requirements must be met for a resource instance to match the selector.
 27	// Webhook implementations should handle requirements, but how to handle them
 28	// is up to the webhook. Since requirements can only limit the request, it is
 29	// safe to authorize as unlimited request if the requirements are not
 30	// understood.
 31	"requirements"?: [...v1.#FieldSelectorRequirement]
 32}
 33
 34// LabelSelectorAttributes indicates a label limited access. Webhook authors are
 35// encouraged to * ensure rawSelector and requirements are not both set *
 36// consider the requirements field if set * not try to parse or consider the
 37// rawSelector field if set. This is to avoid another CVE-2022-2880 (i.e.
 38// getting different systems to agree on how exactly to parse a query is not
 39// something we want), see
 40// https://www.oxeye.io/resources/golang-parameter-smuggling-attack for more
 41// details. For the *SubjectAccessReview endpoints of the kube-apiserver: * If
 42// rawSelector is empty and requirements are empty, the request is not limited.
 43// * If rawSelector is present and requirements are empty, the rawSelector will
 44// be parsed and limited if the parsing succeeds. * If rawSelector is empty and
 45// requirements are present, the requirements should be honored * If
 46// rawSelector is present and requirements are present, the request is invalid.
 47#LabelSelectorAttributes: {
 48	// rawSelector is the serialization of a field selector that would be included
 49	// in a query parameter. Webhook implementations are encouraged to ignore
 50	// rawSelector. The kube-apiserver's *SubjectAccessReview will parse the
 51	// rawSelector as long as the requirements are not present.
 52	"rawSelector"?: string
 53
 54	// requirements is the parsed interpretation of a label selector. All
 55	// requirements must be met for a resource instance to match the selector.
 56	// Webhook implementations should handle requirements, but how to handle them
 57	// is up to the webhook. Since requirements can only limit the request, it is
 58	// safe to authorize as unlimited request if the requirements are not
 59	// understood.
 60	"requirements"?: [...v1.#LabelSelectorRequirement]
 61}
 62
 63// LocalSubjectAccessReview checks whether or not a user or group can perform an
 64// action in a given namespace. Having a namespace scoped resource makes it
 65// much easier to grant namespace scoped policy that includes permissions
 66// checking.
 67#LocalSubjectAccessReview: {
 68	// APIVersion defines the versioned schema of this representation of an object.
 69	// Servers should convert recognized schemas to the latest internal value, and
 70	// may reject unrecognized values. More info:
 71	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 72	"apiVersion": "authorization.k8s.io/v1"
 73
 74	// Kind is a string value representing the REST resource this object represents.
 75	// Servers may infer this from the endpoint the client submits requests to.
 76	// Cannot be updated. In CamelCase. More info:
 77	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 78	"kind": "LocalSubjectAccessReview"
 79
 80	// metadata is the standard list metadata. More info:
 81	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
 82	"metadata"?: v1.#ObjectMeta
 83
 84	// spec holds information about the request being evaluated. spec.namespace must
 85	// be equal to the namespace you made the request against. If empty, it is
 86	// defaulted.
 87	"spec"!: #SubjectAccessReviewSpec
 88
 89	// status is filled in by the server and indicates whether the request is allowed or not
 90	"status"?: #SubjectAccessReviewStatus
 91}
 92
 93// NonResourceAttributes includes the authorization attributes available for
 94// non-resource requests to the Authorizer interface
 95#NonResourceAttributes: {
 96	// path is the URL path of the request
 97	"path"?: string
 98
 99	// verb is the standard HTTP verb
100	"verb"?: string
101}
102
103// NonResourceRule holds information that describes a rule for the non-resource
104#NonResourceRule: {
105	// nonResourceURLs is a set of partial urls that a user should have access to.
106	// *s are allowed, but only as the full, final step in the path. "*" means all.
107	"nonResourceURLs"?: [...string]
108
109	// verbs is a list of kubernetes non-resource API verbs, like: get, post, put,
110	// delete, patch, head, options. "*" means all.
111	"verbs"!: [...string]
112}
113
114// ResourceAttributes includes the authorization attributes available for
115// resource requests to the Authorizer interface
116#ResourceAttributes: {
117	// fieldSelector describes the limitation on access based on field. It can only
118	// limit access, not broaden it.
119	"fieldSelector"?: #FieldSelectorAttributes
120
121	// group is the API Group of the Resource. "*" means all.
122	"group"?: string
123
124	// labelSelector describes the limitation on access based on labels. It can only
125	// limit access, not broaden it.
126	"labelSelector"?: #LabelSelectorAttributes
127
128	// name is the name of the resource being requested for a "get" or deleted for a
129	// "delete". "" (empty) means all.
130	"name"?: string
131
132	// namespace is the namespace of the action being requested. Currently, there is
133	// no distinction between no namespace and all namespaces "" (empty) is
134	// defaulted for LocalSubjectAccessReviews "" (empty) is empty for
135	// cluster-scoped resources "" (empty) means "all" for namespace scoped
136	// resources from a SubjectAccessReview or SelfSubjectAccessReview
137	"namespace"?: string
138
139	// resource is one of the existing resource types. "*" means all.
140	"resource"?: string
141
142	// subresource is one of the existing resource types. "" means none.
143	"subresource"?: string
144
145	// verb is a kubernetes resource API verb, like: get, list, watch, create,
146	// update, delete, proxy. "*" means all.
147	"verb"?: string
148
149	// version is the API Version of the Resource. "*" means all.
150	"version"?: string
151}
152
153// ResourceRule is the list of actions the subject is allowed to perform on
154// resources. The list ordering isn't significant, may contain duplicates, and
155// possibly be incomplete.
156#ResourceRule: {
157	// apiGroups is the name of the APIGroup that contains the resources. If
158	// multiple API groups are specified, any action requested against one of the
159	// enumerated resources in any API group will be allowed. "*" means all.
160	"apiGroups"?: [...string]
161
162	// resourceNames is an optional white list of names that the rule applies to. An
163	// empty set means that everything is allowed. "*" means all.
164	"resourceNames"?: [...string]
165
166	// resources is a list of resources this rule applies to. "*" means all in the specified apiGroups.
167	// "*/foo" represents the subresource 'foo' for all resources in the specified apiGroups.
168	"resources"?: [...string]
169
170	// verbs is a list of kubernetes resource API verbs, like: get, list, watch,
171	// create, update, delete, proxy. "*" means all.
172	"verbs"!: [...string]
173}
174
175// SelfSubjectAccessReview checks whether or the current user can perform an
176// action. Not filling in a spec.namespace means "in all namespaces". Self is a
177// special case, because users should always be able to check whether they can
178// perform an action
179#SelfSubjectAccessReview: {
180	// APIVersion defines the versioned schema of this representation of an object.
181	// Servers should convert recognized schemas to the latest internal value, and
182	// may reject unrecognized values. More info:
183	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
184	"apiVersion": "authorization.k8s.io/v1"
185
186	// Kind is a string value representing the REST resource this object represents.
187	// Servers may infer this from the endpoint the client submits requests to.
188	// Cannot be updated. In CamelCase. More info:
189	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
190	"kind": "SelfSubjectAccessReview"
191
192	// metadata is the standard list metadata. More info:
193	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
194	"metadata"?: v1.#ObjectMeta
195
196	// spec holds information about the request being evaluated. user and groups must be empty
197	"spec"!: #SelfSubjectAccessReviewSpec
198
199	// status is filled in by the server and indicates whether the request is allowed or not
200	"status"?: #SubjectAccessReviewStatus
201}
202
203// SelfSubjectAccessReviewSpec is a description of the access request. Exactly
204// one of resourceAttributes and nonResourceAttributes must be set
205#SelfSubjectAccessReviewSpec: {
206	// nonResourceAttributes describes information for a non-resource access request
207	"nonResourceAttributes"?: #NonResourceAttributes
208
209	// resourceAttributes describes information for a resource access request
210	"resourceAttributes"?: #ResourceAttributes
211}
212
213// SelfSubjectRulesReview enumerates the set of actions the current user can
214// perform within a namespace. The returned list of actions may be incomplete
215// depending on the server's authorization mode, and any errors experienced
216// during the evaluation. SelfSubjectRulesReview should be used by UIs to
217// show/hide actions, or to quickly let an end user reason about their
218// permissions. It should NOT Be used by external systems to drive
219// authorization decisions as this raises confused deputy, cache
220// lifetime/revocation, and correctness concerns. SubjectAccessReview, and
221// LocalAccessReview are the correct way to defer authorization decisions to
222// the API server.
223#SelfSubjectRulesReview: {
224	// APIVersion defines the versioned schema of this representation of an object.
225	// Servers should convert recognized schemas to the latest internal value, and
226	// may reject unrecognized values. More info:
227	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
228	"apiVersion": "authorization.k8s.io/v1"
229
230	// Kind is a string value representing the REST resource this object represents.
231	// Servers may infer this from the endpoint the client submits requests to.
232	// Cannot be updated. In CamelCase. More info:
233	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
234	"kind": "SelfSubjectRulesReview"
235
236	// metadata is the standard list metadata. More info:
237	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
238	"metadata"?: v1.#ObjectMeta
239
240	// spec holds information about the request being evaluated.
241	"spec"!: #SelfSubjectRulesReviewSpec
242
243	// status is filled in by the server and indicates the set of actions a user can perform.
244	"status"?: #SubjectRulesReviewStatus
245}
246
247// SelfSubjectRulesReviewSpec defines the specification for SelfSubjectRulesReview.
248#SelfSubjectRulesReviewSpec: {
249	// namespace to evaluate rules for. Required.
250	"namespace"?: string
251}
252
253// SubjectAccessReview checks whether or not a user or group can perform an action.
254#SubjectAccessReview: {
255	// APIVersion defines the versioned schema of this representation of an object.
256	// Servers should convert recognized schemas to the latest internal value, and
257	// may reject unrecognized values. More info:
258	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
259	"apiVersion": "authorization.k8s.io/v1"
260
261	// Kind is a string value representing the REST resource this object represents.
262	// Servers may infer this from the endpoint the client submits requests to.
263	// Cannot be updated. In CamelCase. More info:
264	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
265	"kind": "SubjectAccessReview"
266
267	// metadata is the standard list metadata. More info:
268	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
269	"metadata"?: v1.#ObjectMeta
270
271	// spec holds information about the request being evaluated
272	"spec"!: #SubjectAccessReviewSpec
273
274	// status is filled in by the server and indicates whether the request is allowed or not
275	"status"?: #SubjectAccessReviewStatus
276}
277
278// SubjectAccessReviewSpec is a description of the access request. Exactly one
279// of resourceAttributes and nonResourceAttributes must be set
280#SubjectAccessReviewSpec: {
281	// extra corresponds to the user.Info.GetExtra() method from the authenticator.
282	// Since that is input to the authorizer it needs a reflection here.
283	"extra"?: [string]: [...string]
284
285	// groups is the groups you're testing for.
286	"groups"?: [...string]
287
288	// nonResourceAttributes describes information for a non-resource access request
289	"nonResourceAttributes"?: #NonResourceAttributes
290
291	// resourceAttributes describes information for a resource access request
292	"resourceAttributes"?: #ResourceAttributes
293
294	// uid information about the requesting user.
295	"uid"?: string
296
297	// user is the user you're testing for. If you specify "User" but not "Groups",
298	// then is it interpreted as "What if User were not a member of any groups
299	"user"?: string
300}
301
302// SubjectAccessReviewStatus
303#SubjectAccessReviewStatus: {
304	// allowed is required. True if the action would be allowed, false otherwise.
305	"allowed"!: bool
306
307	// denied is optional. True if the action would be denied, otherwise false. If
308	// both allowed is false and denied is false, then the authorizer has no
309	// opinion on whether to authorize the action. Denied may not be true if
310	// Allowed is true.
311	"denied"?: bool
312
313	// evaluationError is an indication that some error occurred during the
314	// authorization check. It is entirely possible to get an error and be able to
315	// continue determine authorization status in spite of it. For instance, RBAC
316	// can be missing a role, but enough roles are still present and bound to
317	// reason about the request.
318	"evaluationError"?: string
319
320	// reason is optional. It indicates why a request was allowed or denied.
321	"reason"?: string
322}
323
324// SubjectRulesReviewStatus contains the result of a rules check. This check can
325// be incomplete depending on the set of authorizers the server is configured
326// with and any errors experienced during evaluation. Because authorization
327// rules are additive, if a rule appears in a list it's safe to assume the
328// subject has that permission, even if that list is incomplete.
329#SubjectRulesReviewStatus: {
330	// evaluationError can appear in combination with Rules. It indicates an error
331	// occurred during rule evaluation, such as an authorizer that doesn't support
332	// rule evaluation, and that ResourceRules and/or NonResourceRules may be
333	// incomplete.
334	"evaluationError"?: string
335
336	// incomplete is true when the rules returned by this call are incomplete. This
337	// is most commonly encountered when an authorizer, such as an external
338	// authorizer, doesn't support rules evaluation.
339	"incomplete"!: bool
340
341	// nonResourceRules is the list of actions the subject is allowed to perform on
342	// non-resources. The list ordering isn't significant, may contain duplicates,
343	// and possibly be incomplete.
344	"nonResourceRules"!: [...#NonResourceRule]
345
346	// resourceRules is the list of actions the subject is allowed to perform on
347	// resources. The list ordering isn't significant, may contain duplicates, and
348	// possibly be incomplete.
349	"resourceRules"!: [...#ResourceRule]
350}