gatekeeper
Gatekeeper integrates Open Policy Agent (OPA) into Container Service for Kubernetes (ACK) clusters, letting you define and enforce admission policies for Kubernetes resources. Use it to control pod deployments based on namespace labels.
To install gatekeeper, see Manage components.
Key concepts
OPA is an open source, general-purpose policy engine used in Kubernetes to enforce admission policies in a standardized, context-aware way. For details, see Open Policy Agent.
ConstraintTemplate defines the policy logic (written in Rego) and the schema of parameters that the policy accepts—think of it as a function definition.
Constraint is an instance of a ConstraintTemplate with specific parameter values applied—think of it as a function call with arguments. Before creating a Constraint, you must first create the corresponding ConstraintTemplate.
Enforce pod label requirements
This example constrains pod creation in a specific namespace: any pod created in that namespace must carry a required label. For more usage patterns, see How to use Gatekeeper.
Prerequisites
Before you begin, ensure that you have:
-
An ACK cluster with gatekeeper installed
-
kubectlconfigured to connect to the cluster -
Permissions to create namespaces and apply custom resources
Create the namespace and label it
Run the following commands to create a test-gatekeeper namespace and add the name=test-gatekeeper label:
kubectl create ns test-gatekeeper
kubectl label ns test-gatekeeper name=test-gatekeeper
Create a ConstraintTemplate
Apply the following ConstraintTemplate. It defines a policy that checks whether pods have all required labels:
kubectl apply -f - <<EOF
apiVersion: templates.gatekeeper.sh/v1beta1
kind: ConstraintTemplate
metadata:
name: k8srequiredlabels
spec:
crd:
spec:
names:
kind: K8sRequiredLabels
validation:
openAPIV3Schema:
properties:
labels:
type: array
items:
type: string
targets:
- target: admission.k8s.gatekeeper.sh
rego: |
package k8srequiredlabels
violation[{"msg": msg, "details": {"missing_labels": missing}}] {
provided := {label | input.review.object.metadata.labels[label]}
required := {label | label := input.parameters.labels[_]}
missing := required - provided
count(missing) > 0
msg := sprintf("you must provide labels: %v", [missing])
}
EOF
The ConstraintTemplate takes about 10 seconds to initialize.
Create a Constraint
Apply the following Constraint. It uses the K8sRequiredLabels template to require the gatekeeper-test-label label on all pods created in any namespace with the name=test-gatekeeper label:
kubectl apply -f - <<EOF
apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sRequiredLabels
metadata:
name: pod-must-have-gatekeeper-test-label
spec:
match:
kinds:
- apiGroups: [""]
kinds: ["Pod"]
namespaceSelector:
matchExpressions:
- key: name
operator: In
values: ["test-gatekeeper"]
parameters:
labels: ["gatekeeper-test-label"]
EOF
The Constraint takes about 10 seconds to initialize.
Verify the constraint
Run three test commands to confirm the constraint is working:
Deny: pod without the required label in the constrained namespace
kubectl -n test-gatekeeper run test-deny --image=nginx --restart=Never
Expected output:
Error from server (Forbidden): admission webhook "validation.gatekeeper.sh" denied the request: [pod-must-have-gatekeeper-test-label] you must provide labels: {"gatekeeper-test-label"}
Pass: pod with the required label in the constrained namespace
kubectl -n test-gatekeeper run test-pass-1 -l gatekeeper-test-label=pass --image=nginx --restart=Never
Expected output:
pod/test-pass-1 created
Pass: pod without the label in an unconstrained namespace
kubectl -n default run test-pass-2 --image=nginx --restart=Never
Expected output:
pod/test-pass-2 created
The results confirm that gatekeeper enforces the label requirement only in namespaces that match the Constraint's match criteria—other namespaces are unaffected.
Release notes
March 2024
|
Version number |
Image address |
Release date |
Description |
Impact |
|
v3.15.1.150-g29b8b2a8-aliyun |
registry-cn-hangzhou.ack.aliyuncs.com/acs/gatekeeper:v3.15.1.150-g29b8b2a8-aliyun |
2024-03-27 |
This version is in canary release. OPA Gatekeeper is updated to 3.15.1. The gatekeeper component depends on OPA Gatekeeper. For more information about the OPA Gatekeeper 3.15.1, see v3.15.1. |
If exceptions occur during the component update, changes to cluster resources may fail. Perform the update during off-peak hours. |