gatekeeper

Updated at:

Gatekeeper integrates Open Policy Agent (OPA) into Container Service for Kubernetes (ACK) clusters, letting you define and enforce admission policies for Kubernetes resources. Use it to control pod deployments based on namespace labels.

image

To install gatekeeper, see Manage components.

Key concepts

OPA is an open source, general-purpose policy engine used in Kubernetes to enforce admission policies in a standardized, context-aware way. For details, see Open Policy Agent.

ConstraintTemplate defines the policy logic (written in Rego) and the schema of parameters that the policy accepts—think of it as a function definition.

Constraint is an instance of a ConstraintTemplate with specific parameter values applied—think of it as a function call with arguments. Before creating a Constraint, you must first create the corresponding ConstraintTemplate.

Enforce pod label requirements

This example constrains pod creation in a specific namespace: any pod created in that namespace must carry a required label. For more usage patterns, see How to use Gatekeeper.

Prerequisites

Before you begin, ensure that you have:

  • An ACK cluster with gatekeeper installed

  • kubectl configured to connect to the cluster

  • Permissions to create namespaces and apply custom resources

Create the namespace and label it

Run the following commands to create a test-gatekeeper namespace and add the name=test-gatekeeper label:

kubectl create ns test-gatekeeper
kubectl label ns test-gatekeeper name=test-gatekeeper

Create a ConstraintTemplate

Apply the following ConstraintTemplate. It defines a policy that checks whether pods have all required labels:

kubectl apply -f - <<EOF
apiVersion: templates.gatekeeper.sh/v1beta1
kind: ConstraintTemplate
metadata:
  name: k8srequiredlabels
spec:
  crd:
    spec:
      names:
        kind: K8sRequiredLabels
      validation:
        openAPIV3Schema:
          properties:
            labels:
              type: array
              items:
                type: string
  targets:
    - target: admission.k8s.gatekeeper.sh
      rego: |
        package k8srequiredlabels
        violation[{"msg": msg, "details": {"missing_labels": missing}}] {
          provided := {label | input.review.object.metadata.labels[label]}
          required := {label | label := input.parameters.labels[_]}
          missing := required - provided
          count(missing) > 0
          msg := sprintf("you must provide labels: %v", [missing])
        }
EOF

The ConstraintTemplate takes about 10 seconds to initialize.

Create a Constraint

Apply the following Constraint. It uses the K8sRequiredLabels template to require the gatekeeper-test-label label on all pods created in any namespace with the name=test-gatekeeper label:

kubectl apply -f - <<EOF
apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sRequiredLabels
metadata:
  name: pod-must-have-gatekeeper-test-label
spec:
  match:
    kinds:
      - apiGroups: [""]
        kinds: ["Pod"]
    namespaceSelector:
      matchExpressions:
      - key: name
        operator: In
        values: ["test-gatekeeper"]
  parameters:
    labels: ["gatekeeper-test-label"]
EOF

The Constraint takes about 10 seconds to initialize.

Verify the constraint

Run three test commands to confirm the constraint is working:

Deny: pod without the required label in the constrained namespace

kubectl -n test-gatekeeper run test-deny --image=nginx --restart=Never

Expected output:

Error from server (Forbidden): admission webhook "validation.gatekeeper.sh" denied the request: [pod-must-have-gatekeeper-test-label] you must provide labels: {"gatekeeper-test-label"}

Pass: pod with the required label in the constrained namespace

kubectl -n test-gatekeeper run test-pass-1 -l gatekeeper-test-label=pass --image=nginx --restart=Never

Expected output:

pod/test-pass-1 created

Pass: pod without the label in an unconstrained namespace

kubectl -n default run test-pass-2 --image=nginx --restart=Never

Expected output:

pod/test-pass-2 created

The results confirm that gatekeeper enforces the label requirement only in namespaces that match the Constraint's match criteria—other namespaces are unaffected.

Release notes

March 2024

Version number

Image address

Release date

Description

Impact

v3.15.1.150-g29b8b2a8-aliyun

registry-cn-hangzhou.ack.aliyuncs.com/acs/gatekeeper:v3.15.1.150-g29b8b2a8-aliyun

2024-03-27

This version is in canary release.

OPA Gatekeeper is updated to 3.15.1. The gatekeeper component depends on OPA Gatekeeper. For more information about the OPA Gatekeeper 3.15.1, see v3.15.1.

If exceptions occur during the component update, changes to cluster resources may fail. Perform the update during off-peak hours.