2017-09-20 09:35:16 +00:00
/ *
Copyright 2016 The Kubernetes Authors .
Licensed under the Apache License , Version 2.0 ( the "License" ) ;
you may not use this file except in compliance with the License .
You may obtain a copy of the License at
http : //www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing , software
distributed under the License is distributed on an "AS IS" BASIS ,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND , either express or implied .
See the License for the specific language governing permissions and
limitations under the License .
* /
package serversnippet
import (
2021-08-21 20:42:00 +00:00
networking "k8s.io/api/networking/v1"
2017-09-20 09:35:16 +00:00
2017-11-07 22:02:12 +00:00
"k8s.io/ingress-nginx/internal/ingress/annotations/parser"
2017-11-08 20:58:57 +00:00
"k8s.io/ingress-nginx/internal/ingress/resolver"
2017-09-20 09:35:16 +00:00
)
2023-07-22 03:32:07 +00:00
const (
serverSnippetAnnotation = "server-snippet"
)
var serverSnippetAnnotations = parser . Annotation {
Group : "snippets" ,
Annotations : parser . AnnotationFields {
serverSnippetAnnotation : {
Validator : parser . ValidateNull ,
Scope : parser . AnnotationScopeIngress ,
Risk : parser . AnnotationRiskCritical , // Critical, this annotation is not validated at all and allows arbitrary configutations
Documentation : ` This annotation allows setting a custom NGINX configuration on a server block. This annotation does not contain any validation and it's usage is not recommended! ` ,
} ,
} ,
}
2017-09-20 09:35:16 +00:00
type serverSnippet struct {
2023-07-22 03:32:07 +00:00
r resolver . Resolver
annotationConfig parser . Annotation
2017-09-20 09:35:16 +00:00
}
2017-09-27 06:59:10 +00:00
// NewParser creates a new server snippet annotation parser
2017-11-08 20:58:57 +00:00
func NewParser ( r resolver . Resolver ) parser . IngressAnnotation {
2023-07-22 03:32:07 +00:00
return serverSnippet {
r : r ,
annotationConfig : serverSnippetAnnotations ,
}
2017-09-20 09:35:16 +00:00
}
// Parse parses the annotations contained in the ingress rule
// used to indicate if the location/s contains a fragment of
// configuration to be included inside the paths of the rules
2019-06-09 22:49:59 +00:00
func ( a serverSnippet ) Parse ( ing * networking . Ingress ) ( interface { } , error ) {
2023-07-22 03:32:07 +00:00
return parser . GetStringAnnotation ( serverSnippetAnnotation , ing , a . annotationConfig . Annotations )
}
func ( a serverSnippet ) GetDocumentation ( ) parser . AnnotationFields {
return a . annotationConfig . Annotations
}
func ( a serverSnippet ) Validate ( anns map [ string ] string ) error {
maxrisk := parser . StringRiskToRisk ( a . r . GetSecurityConfiguration ( ) . AnnotationsRiskLevel )
return parser . CheckAnnotationRisk ( anns , maxrisk , serverSnippetAnnotations . Annotations )
2017-09-20 09:35:16 +00:00
}