This template provides a kick start to making a kubernetes admission controller using TypeScript and Node.JS, uses a Validating Webhook.
The following scripts are included in the NPM project configuration
lint lints the source code using eslintlint:fix automatically fixes any lint errors that can be fixed automaticallytest uses jest to run test suitestest:e2e runs e2e test suite, this requires an active helm:deploybuild compiles the typescript into js and places it in the dist folderbuild:image builds the container imageminikube:start create a minikube k8s clusterminikube:stop stop minikube but do not deleteminikube:delete delete the minikube clusterhelm:addRepos adds helm reposhelm:deployCertManager deploy cert-manager for TLShelm:deploy deploy the app to k8s using helmhelm:template print the k8s yaml that would be applied to k8s when using helm:deployhelm:uninstall remove the app from k8shelm:uninstallCertManager remove cert-manager from the k8s clusterFirst add the helm repos helm repo add k8s https://curium-rocks.github.io/k8s-mutating-webhook fetch updates helm repo update.
Verify it worked helm search repo k8s and you should see something like.
NAME CHART VERSION APP VERSION DESCRIPTION
k8s/kube-admission-controller... 0.1.0 0.1.0 A starter template for a dynamic admission vali...
Deploy the app helm upgrade --install starter k8s/k8s-mutating-webhook
Verify it worked kubectl run testpod --image=badbox you should see an error message like this:
Error from server: admission webhook "starter-k8s-mutating-webhook.default.svc" denied the request: One of the images in [badbox] is not allowed, denied
This is meant to include service abstractions, ideally each service should provide an interface/contract exposing the functionality that other things in the application need.
Currently this is setup to house factories or other items to provide instances of third party things/modules that will be bound by the InversifyJS IoC container so they can be injected into other things with @inject()
This houses interfaces/models with little to no logic, the intent is these items can be passed/returned from the abstractions in services and avoid tight coupling to third party types.
This defines symbols for each type that will be configured in the IoC container, these are used to identify the type when using @inject(TYPES.Services.Kubernetes) for example. For more information refer to inversify.
This file maps the types defined in ./src/types.ts to interface types. For more information refer to inversify.
1) [ ] Update Sonar Project Properties For Sonar Cloud
2) [ ] Add SONARQUBE_KEY secret to your repo or org if not already present
3) [ ] Point badges in README.md to correct location for you repo
3) [ ] Update renovate.json to meet desired behavior for your needs, docs can be found here.
4) [ ] Update this readme to reflect your project name and info
5) [ ] Rename all k8s-mutating-webhook references to match your project name