com.pulumi.kubernetes.admissionregistration.v1alpha1.kotlin.outputs.ValidatingAdmissionPolicySpec.kt Maven / Gradle / Ivy
Go to download
Show more of this group Show more artifacts with this name
Show all versions of pulumi-kubernetes-kotlin Show documentation
Show all versions of pulumi-kubernetes-kotlin Show documentation
Build cloud applications and infrastructure by combining the safety and reliability of infrastructure as code with the power of the Kotlin programming language.
@file:Suppress("NAME_SHADOWING", "DEPRECATION")
package com.pulumi.kubernetes.admissionregistration.v1alpha1.kotlin.outputs
import kotlin.String
import kotlin.Suppress
import kotlin.collections.List
/**
* ValidatingAdmissionPolicySpec is the specification of the desired behavior of the AdmissionPolicy.
* @property auditAnnotations auditAnnotations contains CEL expressions which are used to produce audit annotations for the audit event of the API request. validations and auditAnnotations may not both be empty; a least one of validations or auditAnnotations is required.
* @property failurePolicy FailurePolicy defines how to handle failures for the admission policy. Failures can occur from invalid or mis-configured policy definitions or bindings. A policy is invalid if spec.paramKind refers to a non-existent Kind. A binding is invalid if spec.paramRef.name refers to a non-existent resource. Allowed values are Ignore or Fail. Defaults to Fail.
* @property matchConditions MatchConditions is a list of conditions that must be met for a request to be validated. Match conditions filter requests that have already been matched by the rules, namespaceSelector, and objectSelector. An empty list of matchConditions matches all requests. There are a maximum of 64 match conditions allowed.
* If a parameter object is provided, it can be accessed via the `params` handle in the same manner as validation expressions.
* The exact matching logic is (in order):
* 1. If ANY matchCondition evaluates to FALSE, the policy is skipped.
* 2. If ALL matchConditions evaluate to TRUE, the policy is evaluated.
* 3. If any matchCondition evaluates to an error (but none are FALSE):
* - If failurePolicy=Fail, reject the request
* - If failurePolicy=Ignore, the policy is skipped
* @property matchConstraints MatchConstraints specifies what resources this policy is designed to validate. The AdmissionPolicy cares about a request if it matches _all_ Constraints. However, in order to prevent clusters from being put into an unstable state that cannot be recovered from via the API ValidatingAdmissionPolicy cannot match ValidatingAdmissionPolicy and ValidatingAdmissionPolicyBinding. Required.
* @property paramKind ParamKind specifies the kind of resources used to parameterize this policy. If absent, there are no parameters for this policy and the param CEL variable will not be provided to validation expressions. If ParamKind refers to a non-existent kind, this policy definition is mis-configured and the FailurePolicy is applied. If paramKind is specified but paramRef is unset in ValidatingAdmissionPolicyBinding, the params variable will be null.
* @property validations Validations contain CEL expressions which is used to apply the validation. A minimum of one validation is required for a policy definition. Required.
* @property variables Variables contain definitions of variables that can be used in composition of other expressions. Each variable is defined as a named CEL expression. The variables defined here will be available under `variables` in other expressions of the policy except MatchConditions because MatchConditions are evaluated before the rest of the policy.
* The expression of a variable can refer to other variables defined earlier in the list but not those after. Thus, Variables must be sorted by the order of first appearance and acyclic.
*/
public data class ValidatingAdmissionPolicySpec(
public val auditAnnotations: List? = null,
public val failurePolicy: String? = null,
public val matchConditions: List? = null,
public val matchConstraints: MatchResources? = null,
public val paramKind: ParamKind? = null,
public val validations: List,
public val variables: List? = null,
) {
public companion object {
public fun toKotlin(javaType: com.pulumi.kubernetes.admissionregistration.v1alpha1.outputs.ValidatingAdmissionPolicySpec): ValidatingAdmissionPolicySpec = ValidatingAdmissionPolicySpec(
auditAnnotations = javaType.auditAnnotations().map({ args0 ->
args0.let({ args0 ->
com.pulumi.kubernetes.admissionregistration.v1alpha1.kotlin.outputs.AuditAnnotation.Companion.toKotlin(args0)
})
}),
failurePolicy = javaType.failurePolicy().map({ args0 -> args0 }).orElse(null),
matchConditions = javaType.matchConditions().map({ args0 ->
args0.let({ args0 ->
com.pulumi.kubernetes.admissionregistration.v1alpha1.kotlin.outputs.MatchCondition.Companion.toKotlin(args0)
})
}),
matchConstraints = javaType.matchConstraints().map({ args0 ->
args0.let({ args0 ->
com.pulumi.kubernetes.admissionregistration.v1alpha1.kotlin.outputs.MatchResources.Companion.toKotlin(args0)
})
}).orElse(null),
paramKind = javaType.paramKind().map({ args0 ->
args0.let({ args0 ->
com.pulumi.kubernetes.admissionregistration.v1alpha1.kotlin.outputs.ParamKind.Companion.toKotlin(args0)
})
}).orElse(null),
validations = javaType.validations().map({ args0 ->
args0.let({ args0 ->
com.pulumi.kubernetes.admissionregistration.v1alpha1.kotlin.outputs.Validation.Companion.toKotlin(args0)
})
}),
variables = javaType.variables().map({ args0 ->
args0.let({ args0 ->
com.pulumi.kubernetes.admissionregistration.v1alpha1.kotlin.outputs.Variable.Companion.toKotlin(args0)
})
}),
)
}
}
© 2015 - 2025 Weber Informatics LLC | Privacy Policy