|
| 1 | +package alert |
| 2 | + |
| 3 | +import ( |
| 4 | + "bytes" |
| 5 | + "fmt" |
| 6 | + "text/template" |
| 7 | + |
| 8 | + meta1 "k8s.io/apimachinery/pkg/apis/meta/v1" |
| 9 | + |
| 10 | + monitoringv1 "github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring/v1" |
| 11 | + k8Yaml "k8s.io/apimachinery/pkg/util/yaml" |
| 12 | + |
| 13 | + cisoperatorapiv1 "github.com/rancher/cis-operator/pkg/apis/cis.cattle.io/v1" |
| 14 | + "github.com/rancher/wrangler/pkg/name" |
| 15 | +) |
| 16 | + |
| 17 | +const templateName = "prometheusrule.template" |
| 18 | +const templatePath = "./pkg/securityscan/alert/templates/prometheusrule.template" |
| 19 | + |
| 20 | +func NewPrometheusRule(clusterscan *cisoperatorapiv1.ClusterScan, clusterscanprofile *cisoperatorapiv1.ClusterScanProfile, imageConfig *cisoperatorapiv1.ScanImageConfig) (*monitoringv1.PrometheusRule, error) { |
| 21 | + configdata := map[string]interface{}{ |
| 22 | + "namespace": cisoperatorapiv1.ClusterScanNS, |
| 23 | + "name": name.SafeConcatName("rancher-cis-alerts", clusterscan.Name), |
| 24 | + "severity": imageConfig.AlertSeverity, |
| 25 | + "scanName": clusterscan.Name, |
| 26 | + "scanProfileName": clusterscanprofile.Name, |
| 27 | + "alertOnFailure": clusterscan.Spec.ScheduledScanConfig.ScanAlertRule.AlertOnFailure, |
| 28 | + "alertOnComplete": clusterscan.Spec.ScheduledScanConfig.ScanAlertRule.AlertOnComplete, |
| 29 | + } |
| 30 | + scanAlertRule, err := generatePrometheusRule(clusterscan, templateName, templatePath, configdata) |
| 31 | + if err != nil { |
| 32 | + return scanAlertRule, err |
| 33 | + } |
| 34 | + |
| 35 | + return scanAlertRule, nil |
| 36 | +} |
| 37 | + |
| 38 | +func generatePrometheusRule(clusterscan *cisoperatorapiv1.ClusterScan, templateName string, templateFile string, data map[string]interface{}) (*monitoringv1.PrometheusRule, error) { |
| 39 | + scanAlertRule := &monitoringv1.PrometheusRule{} |
| 40 | + obj, err := parseTemplate(clusterscan, templateName, templateFile, data) |
| 41 | + if err != nil { |
| 42 | + return nil, fmt.Errorf("Error parsing the template %v", err) |
| 43 | + } |
| 44 | + |
| 45 | + if err := obj.Decode(&scanAlertRule); err != nil { |
| 46 | + return nil, fmt.Errorf("Error decoding to template %v", err) |
| 47 | + } |
| 48 | + |
| 49 | + ownerRef := meta1.OwnerReference{ |
| 50 | + APIVersion: "cis.cattle.io/v1", |
| 51 | + Kind: "ClusterScan", |
| 52 | + Name: clusterscan.Name, |
| 53 | + UID: clusterscan.GetUID(), |
| 54 | + } |
| 55 | + scanAlertRule.ObjectMeta.OwnerReferences = append(scanAlertRule.ObjectMeta.OwnerReferences, ownerRef) |
| 56 | + |
| 57 | + return scanAlertRule, nil |
| 58 | +} |
| 59 | + |
| 60 | +func parseTemplate(clusterscan *cisoperatorapiv1.ClusterScan, templateName string, templateFile string, data map[string]interface{}) (*k8Yaml.YAMLOrJSONDecoder, error) { |
| 61 | + cmTemplate, err := template.New(templateName).ParseFiles(templateFile) |
| 62 | + if err != nil { |
| 63 | + return nil, err |
| 64 | + } |
| 65 | + |
| 66 | + var b bytes.Buffer |
| 67 | + err = cmTemplate.Execute(&b, data) |
| 68 | + if err != nil { |
| 69 | + return nil, err |
| 70 | + } |
| 71 | + |
| 72 | + return k8Yaml.NewYAMLOrJSONDecoder(bytes.NewReader([]byte(b.String())), 1000), nil |
| 73 | +} |
0 commit comments