@pulumi/kubernetes-compliance-policies
Version:
This repository contains a growing set of Compliance Policies to validate your infrastructure using Pulumi's Crossguard Policy-as-Code framework.
87 lines (86 loc) • 4.43 kB
JavaScript
;
// Copyright 2016-2024, Pulumi Corporation.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
//
// ------------------------------- WARNING -------------------------------------
// This file was programmatically generated. Do not edit unless you know what
// you're doing.
// ------------------------------- WARNING -------------------------------------
Object.defineProperty(exports, "__esModule", { value: true });
exports.PodDisruptionBudget = void 0;
const v1_1 = require("@pulumi/kubernetes/policy/v1");
const policy_1 = require("@pulumi/policy");
const compliance_policy_manager_1 = require("@pulumi/compliance-policy-manager");
var PodDisruptionBudget;
(function (PodDisruptionBudget) {
/**
* Checks that Kubernetes PodDisruptionBudgets have a voluntary disruption.
*
* @severity high
* @frameworks none
* @topics availability
* @link https://kubernetes.io/docs/tasks/run-application/configure-pdb/
*/
PodDisruptionBudget.disallowZeroVoluntaryDisruption = compliance_policy_manager_1.policyManager.registerPolicy({
resourceValidationPolicy: {
name: "kubernetes-policy-v1-poddisruptionbudget-disallow-zero-voluntary-disruption",
description: "Checks that Kubernetes PodDisruptionBudgets have a voluntary disruption.",
configSchema: compliance_policy_manager_1.policyManager.policyConfigSchema,
enforcementLevel: "advisory",
validateResource: (0, policy_1.validateResourceOfType)(v1_1.PodDisruptionBudget, (podDisruptionBudget, args, reportViolation) => {
if (!compliance_policy_manager_1.policyManager.shouldEvalPolicy(args)) {
return;
}
if (podDisruptionBudget.spec) {
if (podDisruptionBudget.spec.maxUnavailable !== undefined) {
switch (typeof podDisruptionBudget.spec.maxUnavailable) {
case "string":
// value is expressed in %
const v = parseFloat(podDisruptionBudget.spec.maxUnavailable);
if (v === 0) {
reportViolation("Kubernetes PodDisruptionBudgets should allow voluntary pod disruption when setting 'maxUnavailable'.");
}
break;
case "number":
if (podDisruptionBudget.spec.maxUnavailable === 0) {
reportViolation("Kubernetes PodDisruptionBudgets should allow voluntary pod disruption when setting 'maxUnavailable'.");
}
break;
default:
break;
}
}
if (podDisruptionBudget.spec.minAvailable !== undefined) {
switch (typeof podDisruptionBudget.spec.minAvailable) {
case "string":
// value is expressed in %
const v = parseFloat(podDisruptionBudget.spec.minAvailable);
if (v === 100) {
reportViolation("Kubernetes PodDisruptionBudgets should allow voluntary pod disruption when setting 'minAvailable'.");
}
break;
default:
break;
}
}
}
}),
},
vendors: ["kubernetes"],
services: ["policy"],
severity: "high",
topics: ["availability"],
});
})(PodDisruptionBudget || (PodDisruptionBudget = {}));
exports.PodDisruptionBudget = PodDisruptionBudget;