• Stars
    star
    521
  • Rank 84,952 (Top 2 %)
  • Language
    Go
  • License
    Apache License 2.0
  • Created over 6 years ago
  • Updated over 1 year ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Go framework to create Kubernetes mutating and validating webhooks

kubewebhook

kubewebhook

CI Go Report Card GoDoc Apache 2 licensed GitHub release (latest SemVer) Kubernetes release

Kubewebhook is a small Go framework to create external admission webhooks for Kubernetes.

With Kubewebhook you can make validating and mutating webhooks in any version, fast, easy, and focusing mainly on the domain logic of the webhook itself.

Features

  • Ready for mutating and validating webhook kinds.
  • Abstracts webhook versioning (compatible with v1beta1 and v1).
  • Resource inference (compatible with CRDs and fallbacks to Unstructured).
  • Easy and testable API.
  • Simple, extensible and flexible.
  • Multiple webhooks on the same server.
  • Webhook metrics (RED) for Prometheus with Grafana dashboard included.
  • Webhook tracing with Opentelemetry support.
  • Supports warnings.

Getting started

Use github.com/slok/kubewebhook/v2 to import Kubewebhook v2.

func run() error {
    logger := &kwhlog.Std{Debug: true}

    // Create our mutator
    mt := kwhmutating.MutatorFunc(func(_ context.Context, _ *kwhmodel.AdmissionReview, obj metav1.Object) (*kwhmutating.MutatorResult, error) {
        pod, ok := obj.(*corev1.Pod)
        if !ok {
            return &kwhmutating.MutatorResult{}, nil
        }

        // Mutate our object with the required annotations.
        if pod.Annotations == nil {
            pod.Annotations = make(map[string]string)
        }
        pod.Annotations["mutated"] = "true"
        pod.Annotations["mutator"] = "pod-annotate"

        return &kwhmutating.MutatorResult{MutatedObject: pod}, nil
    })

    // Create webhook.
    wh, err := kwhmutating.NewWebhook(kwhmutating.WebhookConfig{
        ID:      "pod-annotate",
        Mutator: mt,
        Logger:  logger,
    })
    if err != nil {
        return fmt.Errorf("error creating webhook: %w", err)
    }

    // Get HTTP handler from webhook.
    whHandler, err := kwhhttp.HandlerFor(kwhhttp.HandlerConfig{Webhook: wh, Logger: logger})
    if err != nil {
        return fmt.Errorf("error creating webhook handler: %w", err)
    }

    // Serve.
    logger.Infof("Listening on :8080")
    err = http.ListenAndServeTLS(":8080", cfg.certFile, cfg.keyFile, whHandler)
    if err != nil {
        return fmt.Errorf("error serving webhook: %w", err)
    }

    return nil

You can get more examples in here

Production ready example

This repository is a production ready webhook app: https://github.com/slok/k8s-webhook-example

It shows, different webhook use cases, app structure, testing domain logic, kubewebhook use case, how to deploy...

Static and dynamic webhooks

We have 2 kinds of webhooks:

  • Static: Common one, is a single resource type webhook.
  • Dynamic: Used when the same webhook act on multiple types, unknown types and/or is used for generic stuff (e.g labels).
    • To use this kind of webhook, don't set the type on the configuration or set to nil.
    • If a request for an unknown type is not known by the webhook libraries, it will fallback to runtime.Unstructured object type.
    • Very useful to manipulate multiple resources on the same webhook (e.g Deployments, Statefulsets).
    • CRDs are unknown types so they will fallback to runtime.Unstructured`.
    • If using CRDs, better use Static webhooks.
    • Very useful to maniputale any metadata based validation or mutations (e.g Labels, annotations...)

Compatibility matrix

The Kubernetes' version associated with Kubewebhook's versions means that this specific version is tested and supports the shown K8s version, however, this doesn't mean that doesn't work with other versions. Normally they work with multiple versions (e.g v1.18 and v1.19).

Kubewebhook Kubernetes Admission reviews Dynamic webhooks OpenTelemetry tracing
v2.5 1.25 v1beta1, v1 βœ” βœ”
v2.4 1.24 v1beta1, v1 βœ” βœ”
v2.3 1.23 v1beta1, v1 βœ” βœ”
v2.2 1.22 v1beta1, v1 βœ” βœ”
v2.1 1.21 v1beta1, v1 βœ” βœ–
v2.1 1.21 v1beta1, v1 βœ” βœ–
v2.1 1.21 v1beta1, v1 βœ” βœ–
v2.0 1.20 v1beta1, v1 βœ” βœ–
v0.11 1.19 v1beta1 βœ” βœ–
v0.10 1.18 v1beta1 βœ” βœ–
v0.9 1.18 v1beta1 βœ– βœ–
v0.8 1.17 v1beta1 βœ– βœ–
v0.7 1.16 v1beta1 βœ– βœ–
v0.6 1.15 v1beta1 βœ– βœ–
v0.5 1.14 v1beta1 βœ– βœ–
v0.4 1.13 v1beta1 βœ– βœ–
v0.3 1.12 v1beta1 βœ– βœ–
v0.2 1.11 v1beta1 βœ– βœ–
v0.2 1.10 v1beta1 βœ– βœ–

Documentation

You can access here.

More Repositories

1

sloth

πŸ¦₯ Easy and simple Prometheus SLO (service level objectives) generator
Go
1,519
star
2

grafterm

Metrics dashboards on terminal (a grafana inspired terminal version)
Go
842
star
3

go-http-metrics

Go modular http middleware to measure HTTP requests independent of metrics backend (with Prometheus and OpenCensus as backend implementations) and http framework/library
Go
319
star
4

agebox

Age based repository file encryption gitops tool
Go
161
star
5

goresilience

A library to improve the resilience of Go applications in an easy and flexible way
Go
146
star
6

ecs-exporter

Export AWS ECS cluster metrics to Prometheus
Go
136
star
7

kube-code-generator

Kubernetes code generator docker image
Go
66
star
8

k8s-webhook-example

Kubernetes production-ready admission webhook example
Go
64
star
9

brigadeterm

A simple terminal ui for brigade pipelining system
Go
63
star
10

go-jwt-example

Golang & jwt (Jason web token) example
Go
47
star
11

alertgram

Easy and simple prometheus alertmanager alerts on telegram
Go
40
star
12

rainbow-bash

Better bash prompt! you don't need zsh for cool prompts
Shell
39
star
13

Box2D-and-SFML-demo

Box2D and SFML Demo, with DebugDraw implemented with SFML
C++
34
star
14

kahoy

Simple Kubernetes raw manifests deployment tool
Go
32
star
15

iris

Pelican (the static blog generator) theme based in Flask webpage theme
CSS
31
star
16

tfe-drift

Automated Terraform cloud and enterprise drift detection
Go
31
star
17

reload

Simple managed reload mechanism for Go
Go
30
star
18

sloth-common-sli-plugins

Sloth common SLI plugins collection
Go
29
star
19

pygressbar

Flexible and customizable python progress bar
Python
27
star
20

redis-node-push-notifications-example

An example of using redis pub/sub for realtime client notifications with Redis, socket.io and node.js
JavaScript
24
star
21

gospinner

Make beautiful and fast spinners in Go
Go
19
star
22

algs4-mvn-repo

Maven repository for algorithms and data strcutures coursera course ( https://www.coursera.org/course/algs4partI )
19
star
23

prometheus-python

Prometheus metric system client for python
Python
18
star
24

bilrost

Kubernetes controller/operator to set up OAUTH2/OIDC security on any ingress based service
Go
18
star
25

devops-course

Devops course sources (Vagrant, Ansible & Docker )
Ruby
17
star
26

simple-ingress-external-auth

A very simple external authentication service for Kubernetes ingresses (ingress-nginx, traefik...)
Go
16
star
27

noglog

"Bring your own logger" replacement for github.com/golang/glog.
Go
13
star
28

go-prometheus-middleware

Go net/http configurable handler to measure requests using Prometheus metrics
Go
13
star
29

brigade-exporter

Exporter for brigade metrics
Go
11
star
30

terraform-provider-dataprocessor

Terraform provider for easy and clean data processing (JQ, YQ, Go plugins...).
Go
10
star
31

go-copy

Copy (http://copy.com) service library
Go
9
star
32

prometheus-statsd-integration-example

Simple example of statsd and prometheus integration
Shell
9
star
33

django-chameleon

Django theme (template) changer app
Python
9
star
34

favorshare-orchestration

An Ansible complete example for provisioning a whole project
Shell
8
star
35

pod-exec-guard-kubewebhook-tutorial

Kubernetes webhook development (validating admission webhook) tutorial using kubewebhook
Go
8
star
36

khronos

Modern replacement of cron for microservice architecture.
Go
6
star
37

resilience-demo

A resilience demo with different scenarios
Go
6
star
38

tracing-example

Simple Kubernetes tracing example and experiment
Go
6
star
39

flaskit

Simple git front-end powered by Flask and Dulwich
JavaScript
6
star
40

go-helm-template

Simple go library to run Helm template without executing Helm
Go
6
star
41

ragnarok-old

The new way of injecting failure
Go
5
star
42

terraform-provider-goplugin

A Terraform provider to create terraform providers 🀯, but easier and faster! (By using Small go plugins)
Go
5
star
43

external-dns-aws-migrator

Utility to adopt AWS route53 entries (record sets) so the external-dns can track and update them based on Kubernetes ingresses
Go
4
star
44

imagepull-controller-workshop

A Kubernetes controller workshop where we are creating a imagepullsecret-patcher controller
Go
4
star
45

tfe-drift-action

tfe-drift github action
4
star
46

metaproxy

A proxy that inserts and extracts metadata to/from webpages
Python
4
star
47

django-socketio-example

Django (1.4) + gevent + gevent-socketio + socketio (0.9.x) example
JavaScript
4
star
48

terraform-provider-onepasswordorg

Terraform provider for 1password user and group management
Go
4
star
49

docker-protobuf-py3

Docker protobuf-py3 image
3
star
50

asdf-sloth

Sloth asdf plugin
Shell
3
star
51

kooper-as-dependency

Simple example of a project using kooper and how you could set the dependencies for the project (using dep)
Go
3
star
52

docker-vagrant-gvm

Docker GVM image for vagrant
Shell
3
star
53

docker-mysql

Docker mysql with data only container approach
Shell
3
star
54

sloth-website

https://sloth.dev
HTML
3
star
55

kahoy-app-deploy-example

Production-ready example of application deployments using templating, Kahoy and Kubernetes
Shell
2
star
56

kahoy-kustomize-example

Kahoy and Kustomize with multiple envs (clusters) example
Shell
2
star
57

dwarf

Dwarf is a link shortener made in python and Django, also has statistics and has achievements
Python
2
star
58

mdissphoto

MDISS Master 2011-2012 project
Java
2
star
59

ecs-watcher

ecs-watcher will check periodically your ECS cluster nodes health
Go
2
star
60

daton

Daton
Go
2
star
61

role-operator

Role operator is a kubernetes controller that manages RBAC permissions on namespaces dynamically using roles.
Go
2
star
62

docker-octopress

Octopress container
Shell
2
star
63

ticketbis-dev-box

Ticketbis devel enviroment automation with ansible (Ready for vagrant too)
Shell
1
star
64

submodulo_git

A submodule for the git introduction course
Python
1
star
65

django-fancymail

Django fancy mail is a layer above django mail that add template rendering easier for the emails. The aim of this project is to be simple, nothing fancy :O.
Python
1
star
66

testing

fdafsasadsadsad
1
star
67

testing_git

1
star
68

docker-postgresql

Docker postgresql container
Shell
1
star
69

warlock

Easy and fast distributed locks for go
Go
1
star
70

custom-css

CSS
1
star
71

blackbox-helm

Docker image with blackbox and helm
Dockerfile
1
star
72

kahoy-helm-example

A production-ready Kahoy deploy example using Helm as the templating engine
Shell
1
star
73

mydumpster

Mysql dump based on a config file experiment
Go
1
star
74

introduccion_git

Introduction to Git
1
star
75

xlarrakoetxeaorg

My future blog made in Flask
Python
1
star
76

ec2-opener

Small util to open a ports on an EC2 instance rapidly.
Go
1
star
77

slackbuilds

My personal slackbuilds
1
star
78

asdf-agebox

Agebox asdf plugin
Shell
1
star
79

tetris-revivalpp

Tetris clone for the university (2007-2008)
C++
1
star
80

ladder

The new and easy way to autoscale
Go
1
star
81

favorshare-dockerfiles

Shell
1
star
82

python-challenge

Python challenge level scripts
Python
1
star
83

CASO

Project for subject CASO of the 5ΒΊ Curse of Computer engineering in Deusto University
C++
1
star
84

django-chat

Django chat made with Socketio, Gevent[-socketio] and Redis
Python
1
star
85

markdownex

Django web (demo) that renders Markdown sintax
Python
1
star
86

monf

Go
1
star
87

service-level-operator-sloth-migrator

Simple script to migrate CRs from service-level-operator to sloth
Go
1
star
88

docker-make-kubectl

Docker image with make, bash and kubectl
Makefile
1
star
89

go-http-metrics-imports

Example to check the go-http-metrics imports using different frameworks
Go
1
star