mirror of
https://github.com/komodorio/helm-dashboard.git
synced 2026-03-21 18:58:03 +00:00
refactor: reduce cyclomatic complexity in relations extraction
Break up ExtractRelations, extractVolumes, extractEnvRefs, and extractIngressBackends into smaller focused functions to pass CI complexity checks. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -28,38 +28,28 @@ type RelationEdge struct {
|
|||||||
Type string `json:"type"`
|
Type string `json:"type"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
type edgeAdder func(sourceID, targetKind, targetName, edgeType string)
|
||||||
|
|
||||||
|
type workloadLabels struct {
|
||||||
|
id string
|
||||||
|
labels map[string]interface{}
|
||||||
|
}
|
||||||
|
|
||||||
func nodeID(kind, name string) string {
|
func nodeID(kind, name string) string {
|
||||||
return kind + "/" + name
|
return kind + "/" + name
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func docKindAndName(doc map[string]interface{}) (string, string) {
|
||||||
|
kind, _ := doc["kind"].(string)
|
||||||
|
metadata, _ := doc["metadata"].(map[string]interface{})
|
||||||
|
name, _ := metadata["name"].(string)
|
||||||
|
return kind, name
|
||||||
|
}
|
||||||
|
|
||||||
// ExtractRelations parses a manifest and returns the resource relation graph.
|
// ExtractRelations parses a manifest and returns the resource relation graph.
|
||||||
func ExtractRelations(manifest string) RelationGraph {
|
func ExtractRelations(manifest string) RelationGraph {
|
||||||
dec := yaml.NewYAMLOrJSONDecoder(strings.NewReader(manifest), 4096)
|
docs := parseManifestDocs(manifest)
|
||||||
|
nodes := buildNodeSet(docs)
|
||||||
var docs []map[string]interface{}
|
|
||||||
for {
|
|
||||||
var tmp map[string]interface{}
|
|
||||||
if err := dec.Decode(&tmp); err != nil {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
if tmp == nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
kind, _ := tmp["kind"].(string)
|
|
||||||
if kind == "" {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
docs = append(docs, tmp)
|
|
||||||
}
|
|
||||||
|
|
||||||
nodes := map[string]RelationNode{}
|
|
||||||
for _, doc := range docs {
|
|
||||||
kind, _ := doc["kind"].(string)
|
|
||||||
metadata, _ := doc["metadata"].(map[string]interface{})
|
|
||||||
name, _ := metadata["name"].(string)
|
|
||||||
id := nodeID(kind, name)
|
|
||||||
nodes[id] = RelationNode{ID: id, Kind: kind, Name: name, InRelease: true}
|
|
||||||
}
|
|
||||||
|
|
||||||
var edges []RelationEdge
|
var edges []RelationEdge
|
||||||
addEdge := func(sourceID, targetKind, targetName, edgeType string) {
|
addEdge := func(sourceID, targetKind, targetName, edgeType string) {
|
||||||
@@ -73,83 +63,11 @@ func ExtractRelations(manifest string) RelationGraph {
|
|||||||
edges = append(edges, RelationEdge{Source: sourceID, Target: tid, Type: edgeType})
|
edges = append(edges, RelationEdge{Source: sourceID, Target: tid, Type: edgeType})
|
||||||
}
|
}
|
||||||
|
|
||||||
// Build label index for selector matching: workload ID -> template labels
|
workloads := buildWorkloadIndex(docs)
|
||||||
type workloadLabels struct {
|
|
||||||
id string
|
|
||||||
labels map[string]interface{}
|
|
||||||
}
|
|
||||||
var workloads []workloadLabels
|
|
||||||
for _, doc := range docs {
|
for _, doc := range docs {
|
||||||
kind, _ := doc["kind"].(string)
|
extractDocEdges(doc, workloads, addEdge)
|
||||||
metadata, _ := doc["metadata"].(map[string]interface{})
|
|
||||||
name, _ := metadata["name"].(string)
|
|
||||||
spec, _ := doc["spec"].(map[string]interface{})
|
|
||||||
if spec == nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
tpl, _ := spec["template"].(map[string]interface{})
|
|
||||||
if tpl == nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
tplMeta, _ := tpl["metadata"].(map[string]interface{})
|
|
||||||
if tplMeta == nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
lbls, _ := tplMeta["labels"].(map[string]interface{})
|
|
||||||
if lbls != nil {
|
|
||||||
workloads = append(workloads, workloadLabels{id: nodeID(kind, name), labels: lbls})
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, doc := range docs {
|
|
||||||
kind, _ := doc["kind"].(string)
|
|
||||||
metadata, _ := doc["metadata"].(map[string]interface{})
|
|
||||||
name, _ := metadata["name"].(string)
|
|
||||||
srcID := nodeID(kind, name)
|
|
||||||
|
|
||||||
// ownerReferences
|
|
||||||
extractOwnerRefs(doc, srcID, addEdge)
|
|
||||||
|
|
||||||
// recursive *Ref fields (skip metadata to avoid self-refs from ownerReferences)
|
|
||||||
collectRefFields(doc, srcID, addEdge)
|
|
||||||
|
|
||||||
// volumes, envFrom, serviceAccount from pod specs
|
|
||||||
for _, podSpec := range findPodSpecs(kind, doc) {
|
|
||||||
extractVolumes(podSpec, srcID, addEdge)
|
|
||||||
extractEnvRefs(podSpec, srcID, addEdge)
|
|
||||||
extractServiceAccount(podSpec, srcID, addEdge)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Service selector -> workloads
|
|
||||||
if kind == "Service" {
|
|
||||||
spec, _ := doc["spec"].(map[string]interface{})
|
|
||||||
if spec != nil {
|
|
||||||
selector, _ := spec["selector"].(map[string]interface{})
|
|
||||||
if len(selector) > 0 {
|
|
||||||
for _, wl := range workloads {
|
|
||||||
if labelsMatch(selector, wl.labels) {
|
|
||||||
parts := strings.SplitN(wl.id, "/", 2)
|
|
||||||
if len(parts) == 2 {
|
|
||||||
addEdge(srcID, parts[0], parts[1], "selector")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Ingress -> Service
|
|
||||||
if kind == "Ingress" {
|
|
||||||
extractIngressBackends(doc, srcID, addEdge)
|
|
||||||
}
|
|
||||||
|
|
||||||
// RoleBinding / ClusterRoleBinding
|
|
||||||
if kind == "RoleBinding" || kind == "ClusterRoleBinding" {
|
|
||||||
extractRoleBindingRefs(doc, srcID, addEdge)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Deduplicate edges
|
|
||||||
edges = deduplicateEdges(edges)
|
edges = deduplicateEdges(edges)
|
||||||
|
|
||||||
nodeSlice := make([]RelationNode, 0, len(nodes))
|
nodeSlice := make([]RelationNode, 0, len(nodes))
|
||||||
@@ -160,7 +78,86 @@ func ExtractRelations(manifest string) RelationGraph {
|
|||||||
return RelationGraph{Nodes: nodeSlice, Edges: edges}
|
return RelationGraph{Nodes: nodeSlice, Edges: edges}
|
||||||
}
|
}
|
||||||
|
|
||||||
func extractOwnerRefs(doc map[string]interface{}, srcID string, addEdge func(string, string, string, string)) {
|
func parseManifestDocs(manifest string) []map[string]interface{} {
|
||||||
|
dec := yaml.NewYAMLOrJSONDecoder(strings.NewReader(manifest), 4096)
|
||||||
|
var docs []map[string]interface{}
|
||||||
|
for {
|
||||||
|
var tmp map[string]interface{}
|
||||||
|
if err := dec.Decode(&tmp); err != nil {
|
||||||
|
break
|
||||||
|
}
|
||||||
|
kind, _ := tmp["kind"].(string)
|
||||||
|
if kind != "" {
|
||||||
|
docs = append(docs, tmp)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return docs
|
||||||
|
}
|
||||||
|
|
||||||
|
func buildNodeSet(docs []map[string]interface{}) map[string]RelationNode {
|
||||||
|
nodes := map[string]RelationNode{}
|
||||||
|
for _, doc := range docs {
|
||||||
|
kind, name := docKindAndName(doc)
|
||||||
|
id := nodeID(kind, name)
|
||||||
|
nodes[id] = RelationNode{ID: id, Kind: kind, Name: name, InRelease: true}
|
||||||
|
}
|
||||||
|
return nodes
|
||||||
|
}
|
||||||
|
|
||||||
|
func buildWorkloadIndex(docs []map[string]interface{}) []workloadLabels {
|
||||||
|
var workloads []workloadLabels
|
||||||
|
for _, doc := range docs {
|
||||||
|
kind, name := docKindAndName(doc)
|
||||||
|
lbls := getTemplateLabels(doc)
|
||||||
|
if lbls != nil {
|
||||||
|
workloads = append(workloads, workloadLabels{id: nodeID(kind, name), labels: lbls})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return workloads
|
||||||
|
}
|
||||||
|
|
||||||
|
func getTemplateLabels(doc map[string]interface{}) map[string]interface{} {
|
||||||
|
spec, _ := doc["spec"].(map[string]interface{})
|
||||||
|
if spec == nil {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
tpl, _ := spec["template"].(map[string]interface{})
|
||||||
|
if tpl == nil {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
tplMeta, _ := tpl["metadata"].(map[string]interface{})
|
||||||
|
if tplMeta == nil {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
lbls, _ := tplMeta["labels"].(map[string]interface{})
|
||||||
|
return lbls
|
||||||
|
}
|
||||||
|
|
||||||
|
func extractDocEdges(doc map[string]interface{}, workloads []workloadLabels, addEdge edgeAdder) {
|
||||||
|
kind, name := docKindAndName(doc)
|
||||||
|
srcID := nodeID(kind, name)
|
||||||
|
|
||||||
|
extractOwnerRefs(doc, srcID, addEdge)
|
||||||
|
collectRefFields(doc, srcID, addEdge)
|
||||||
|
|
||||||
|
for _, podSpec := range findPodSpecs(kind, doc) {
|
||||||
|
extractVolumes(podSpec, srcID, addEdge)
|
||||||
|
extractEnvRefs(podSpec, srcID, addEdge)
|
||||||
|
extractServiceAccount(podSpec, srcID, addEdge)
|
||||||
|
}
|
||||||
|
|
||||||
|
if kind == "Service" {
|
||||||
|
extractServiceSelector(doc, srcID, workloads, addEdge)
|
||||||
|
}
|
||||||
|
if kind == "Ingress" {
|
||||||
|
extractIngressBackends(doc, srcID, addEdge)
|
||||||
|
}
|
||||||
|
if kind == "RoleBinding" || kind == "ClusterRoleBinding" {
|
||||||
|
extractRoleBindingRefs(doc, srcID, addEdge)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func extractOwnerRefs(doc map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
metadata, _ := doc["metadata"].(map[string]interface{})
|
metadata, _ := doc["metadata"].(map[string]interface{})
|
||||||
if metadata == nil {
|
if metadata == nil {
|
||||||
return
|
return
|
||||||
@@ -179,8 +176,7 @@ func extractOwnerRefs(doc map[string]interface{}, srcID string, addEdge func(str
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func collectRefFields(doc map[string]interface{}, srcID string, addEdge func(string, string, string, string)) {
|
func collectRefFields(doc map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
// Walk the doc but skip metadata (ownerReferences handled separately)
|
|
||||||
for key, value := range doc {
|
for key, value := range doc {
|
||||||
if key == "metadata" {
|
if key == "metadata" {
|
||||||
continue
|
continue
|
||||||
@@ -189,7 +185,7 @@ func collectRefFields(doc map[string]interface{}, srcID string, addEdge func(str
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func collectRefFieldsRecursive(obj interface{}, srcID string, addEdge func(string, string, string, string)) {
|
func collectRefFieldsRecursive(obj interface{}, srcID string, addEdge edgeAdder) {
|
||||||
switch v := obj.(type) {
|
switch v := obj.(type) {
|
||||||
case map[string]interface{}:
|
case map[string]interface{}:
|
||||||
for key, value := range v {
|
for key, value := range v {
|
||||||
@@ -206,7 +202,7 @@ func collectRefFieldsRecursive(obj interface{}, srcID string, addEdge func(strin
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func tryAddRef(value interface{}, srcID string, addEdge func(string, string, string, string)) {
|
func tryAddRef(value interface{}, srcID string, addEdge edgeAdder) {
|
||||||
switch v := value.(type) {
|
switch v := value.(type) {
|
||||||
case map[string]interface{}:
|
case map[string]interface{}:
|
||||||
kind, _ := v["kind"].(string)
|
kind, _ := v["kind"].(string)
|
||||||
@@ -227,51 +223,59 @@ func tryAddRef(value interface{}, srcID string, addEdge func(string, string, str
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func extractVolumes(podSpec map[string]interface{}, srcID string, addEdge func(string, string, string, string)) {
|
func extractVolumes(podSpec map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
volumes, _ := podSpec["volumes"].([]interface{})
|
volumes, _ := podSpec["volumes"].([]interface{})
|
||||||
for _, vol := range volumes {
|
for _, vol := range volumes {
|
||||||
v, ok := vol.(map[string]interface{})
|
v, ok := vol.(map[string]interface{})
|
||||||
if !ok {
|
if !ok {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
if cm, ok := v["configMap"].(map[string]interface{}); ok {
|
extractVolumeSource(v, srcID, addEdge)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func extractVolumeSource(v map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
|
if cm, ok := v["configMap"].(map[string]interface{}); ok {
|
||||||
|
if name, _ := cm["name"].(string); name != "" {
|
||||||
|
addEdge(srcID, "ConfigMap", name, "volume")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if sec, ok := v["secret"].(map[string]interface{}); ok {
|
||||||
|
if name, _ := sec["secretName"].(string); name != "" {
|
||||||
|
addEdge(srcID, "Secret", name, "volume")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if pvc, ok := v["persistentVolumeClaim"].(map[string]interface{}); ok {
|
||||||
|
if name, _ := pvc["claimName"].(string); name != "" {
|
||||||
|
addEdge(srcID, "PersistentVolumeClaim", name, "volume")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if proj, ok := v["projected"].(map[string]interface{}); ok {
|
||||||
|
extractProjectedSources(proj, srcID, addEdge)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func extractProjectedSources(proj map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
|
sources, _ := proj["sources"].([]interface{})
|
||||||
|
for _, s := range sources {
|
||||||
|
src, ok := s.(map[string]interface{})
|
||||||
|
if !ok {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if cm, ok := src["configMap"].(map[string]interface{}); ok {
|
||||||
if name, _ := cm["name"].(string); name != "" {
|
if name, _ := cm["name"].(string); name != "" {
|
||||||
addEdge(srcID, "ConfigMap", name, "volume")
|
addEdge(srcID, "ConfigMap", name, "volume")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if sec, ok := v["secret"].(map[string]interface{}); ok {
|
if sec, ok := src["secret"].(map[string]interface{}); ok {
|
||||||
if name, _ := sec["secretName"].(string); name != "" {
|
if name, _ := sec["name"].(string); name != "" {
|
||||||
addEdge(srcID, "Secret", name, "volume")
|
addEdge(srcID, "Secret", name, "volume")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if pvc, ok := v["persistentVolumeClaim"].(map[string]interface{}); ok {
|
|
||||||
if name, _ := pvc["claimName"].(string); name != "" {
|
|
||||||
addEdge(srcID, "PersistentVolumeClaim", name, "volume")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if proj, ok := v["projected"].(map[string]interface{}); ok {
|
|
||||||
sources, _ := proj["sources"].([]interface{})
|
|
||||||
for _, s := range sources {
|
|
||||||
src, ok := s.(map[string]interface{})
|
|
||||||
if !ok {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
if cm, ok := src["configMap"].(map[string]interface{}); ok {
|
|
||||||
if name, _ := cm["name"].(string); name != "" {
|
|
||||||
addEdge(srcID, "ConfigMap", name, "volume")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if sec, ok := src["secret"].(map[string]interface{}); ok {
|
|
||||||
if name, _ := sec["name"].(string); name != "" {
|
|
||||||
addEdge(srcID, "Secret", name, "volume")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func extractEnvRefs(podSpec map[string]interface{}, srcID string, addEdge func(string, string, string, string)) {
|
func extractEnvRefs(podSpec map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
containers, _ := podSpec["containers"].([]interface{})
|
containers, _ := podSpec["containers"].([]interface{})
|
||||||
initContainers, _ := podSpec["initContainers"].([]interface{})
|
initContainers, _ := podSpec["initContainers"].([]interface{})
|
||||||
allContainers := append(containers, initContainers...)
|
allContainers := append(containers, initContainers...)
|
||||||
@@ -281,91 +285,119 @@ func extractEnvRefs(podSpec map[string]interface{}, srcID string, addEdge func(s
|
|||||||
if !ok {
|
if !ok {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
// envFrom
|
extractContainerEnvRefs(cMap, srcID, addEdge)
|
||||||
envFrom, _ := cMap["envFrom"].([]interface{})
|
}
|
||||||
for _, ef := range envFrom {
|
}
|
||||||
e, ok := ef.(map[string]interface{})
|
|
||||||
if !ok {
|
func extractContainerEnvRefs(cMap map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
continue
|
envFrom, _ := cMap["envFrom"].([]interface{})
|
||||||
}
|
for _, ef := range envFrom {
|
||||||
if cmRef, ok := e["configMapRef"].(map[string]interface{}); ok {
|
e, ok := ef.(map[string]interface{})
|
||||||
if name, _ := cmRef["name"].(string); name != "" {
|
if !ok {
|
||||||
addEdge(srcID, "ConfigMap", name, "envRef")
|
continue
|
||||||
}
|
}
|
||||||
}
|
if cmRef, ok := e["configMapRef"].(map[string]interface{}); ok {
|
||||||
if secRef, ok := e["secretRef"].(map[string]interface{}); ok {
|
if name, _ := cmRef["name"].(string); name != "" {
|
||||||
if name, _ := secRef["name"].(string); name != "" {
|
addEdge(srcID, "ConfigMap", name, "envRef")
|
||||||
addEdge(srcID, "Secret", name, "envRef")
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
// env[].valueFrom
|
if secRef, ok := e["secretRef"].(map[string]interface{}); ok {
|
||||||
envVars, _ := cMap["env"].([]interface{})
|
if name, _ := secRef["name"].(string); name != "" {
|
||||||
for _, ev := range envVars {
|
addEdge(srcID, "Secret", name, "envRef")
|
||||||
envVar, ok := ev.(map[string]interface{})
|
|
||||||
if !ok {
|
|
||||||
continue
|
|
||||||
}
|
}
|
||||||
valueFrom, _ := envVar["valueFrom"].(map[string]interface{})
|
}
|
||||||
if valueFrom == nil {
|
}
|
||||||
continue
|
extractEnvValueFromRefs(cMap, srcID, addEdge)
|
||||||
|
}
|
||||||
|
|
||||||
|
func extractEnvValueFromRefs(cMap map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
|
envVars, _ := cMap["env"].([]interface{})
|
||||||
|
for _, ev := range envVars {
|
||||||
|
envVar, ok := ev.(map[string]interface{})
|
||||||
|
if !ok {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
valueFrom, _ := envVar["valueFrom"].(map[string]interface{})
|
||||||
|
if valueFrom == nil {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if cmKeyRef, ok := valueFrom["configMapKeyRef"].(map[string]interface{}); ok {
|
||||||
|
if name, _ := cmKeyRef["name"].(string); name != "" {
|
||||||
|
addEdge(srcID, "ConfigMap", name, "envRef")
|
||||||
}
|
}
|
||||||
if cmKeyRef, ok := valueFrom["configMapKeyRef"].(map[string]interface{}); ok {
|
}
|
||||||
if name, _ := cmKeyRef["name"].(string); name != "" {
|
if secKeyRef, ok := valueFrom["secretKeyRef"].(map[string]interface{}); ok {
|
||||||
addEdge(srcID, "ConfigMap", name, "envRef")
|
if name, _ := secKeyRef["name"].(string); name != "" {
|
||||||
}
|
addEdge(srcID, "Secret", name, "envRef")
|
||||||
}
|
|
||||||
if secKeyRef, ok := valueFrom["secretKeyRef"].(map[string]interface{}); ok {
|
|
||||||
if name, _ := secKeyRef["name"].(string); name != "" {
|
|
||||||
addEdge(srcID, "Secret", name, "envRef")
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func extractServiceAccount(podSpec map[string]interface{}, srcID string, addEdge func(string, string, string, string)) {
|
func extractServiceAccount(podSpec map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
if sa, _ := podSpec["serviceAccountName"].(string); sa != "" && sa != "default" {
|
if sa, _ := podSpec["serviceAccountName"].(string); sa != "" && sa != "default" {
|
||||||
addEdge(srcID, "ServiceAccount", sa, "serviceAccount")
|
addEdge(srcID, "ServiceAccount", sa, "serviceAccount")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func extractIngressBackends(doc map[string]interface{}, srcID string, addEdge func(string, string, string, string)) {
|
func extractServiceSelector(doc map[string]interface{}, srcID string, workloads []workloadLabels, addEdge edgeAdder) {
|
||||||
|
spec, _ := doc["spec"].(map[string]interface{})
|
||||||
|
if spec == nil {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
selector, _ := spec["selector"].(map[string]interface{})
|
||||||
|
if len(selector) == 0 {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
for _, wl := range workloads {
|
||||||
|
if labelsMatch(selector, wl.labels) {
|
||||||
|
parts := strings.SplitN(wl.id, "/", 2)
|
||||||
|
if len(parts) == 2 {
|
||||||
|
addEdge(srcID, parts[0], parts[1], "selector")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func extractIngressBackends(doc map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
spec, _ := doc["spec"].(map[string]interface{})
|
spec, _ := doc["spec"].(map[string]interface{})
|
||||||
if spec == nil {
|
if spec == nil {
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// default backend
|
|
||||||
if backend, ok := spec["defaultBackend"].(map[string]interface{}); ok {
|
if backend, ok := spec["defaultBackend"].(map[string]interface{}); ok {
|
||||||
addIngressServiceRef(backend, srcID, addEdge)
|
addIngressServiceRef(backend, srcID, addEdge)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
extractIngressRules(spec, srcID, addEdge)
|
||||||
|
extractIngressTLS(spec, srcID, addEdge)
|
||||||
|
}
|
||||||
|
|
||||||
|
func extractIngressRules(spec map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
rules, _ := spec["rules"].([]interface{})
|
rules, _ := spec["rules"].([]interface{})
|
||||||
for _, r := range rules {
|
for _, r := range rules {
|
||||||
rule, ok := r.(map[string]interface{})
|
rule, ok := r.(map[string]interface{})
|
||||||
if !ok {
|
if !ok {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
http, _ := rule["http"].(map[string]interface{})
|
httpSection, _ := rule["http"].(map[string]interface{})
|
||||||
if http == nil {
|
if httpSection == nil {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
paths, _ := http["paths"].([]interface{})
|
paths, _ := httpSection["paths"].([]interface{})
|
||||||
for _, p := range paths {
|
for _, p := range paths {
|
||||||
path, ok := p.(map[string]interface{})
|
path, ok := p.(map[string]interface{})
|
||||||
if !ok {
|
if !ok {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
backend, _ := path["backend"].(map[string]interface{})
|
if backend, ok := path["backend"].(map[string]interface{}); ok {
|
||||||
if backend == nil {
|
addIngressServiceRef(backend, srcID, addEdge)
|
||||||
continue
|
|
||||||
}
|
}
|
||||||
addIngressServiceRef(backend, srcID, addEdge)
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// TLS secrets
|
func extractIngressTLS(spec map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
tls, _ := spec["tls"].([]interface{})
|
tls, _ := spec["tls"].([]interface{})
|
||||||
for _, t := range tls {
|
for _, t := range tls {
|
||||||
tlsEntry, ok := t.(map[string]interface{})
|
tlsEntry, ok := t.(map[string]interface{})
|
||||||
@@ -378,21 +410,18 @@ func extractIngressBackends(doc map[string]interface{}, srcID string, addEdge fu
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func addIngressServiceRef(backend map[string]interface{}, srcID string, addEdge func(string, string, string, string)) {
|
func addIngressServiceRef(backend map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
// v1 Ingress: backend.service.name
|
|
||||||
if svc, ok := backend["service"].(map[string]interface{}); ok {
|
if svc, ok := backend["service"].(map[string]interface{}); ok {
|
||||||
if name, _ := svc["name"].(string); name != "" {
|
if name, _ := svc["name"].(string); name != "" {
|
||||||
addEdge(srcID, "Service", name, "ingressBackend")
|
addEdge(srcID, "Service", name, "ingressBackend")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
// v1beta1 Ingress: backend.serviceName
|
|
||||||
if name, _ := backend["serviceName"].(string); name != "" {
|
if name, _ := backend["serviceName"].(string); name != "" {
|
||||||
addEdge(srcID, "Service", name, "ingressBackend")
|
addEdge(srcID, "Service", name, "ingressBackend")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func extractRoleBindingRefs(doc map[string]interface{}, srcID string, addEdge func(string, string, string, string)) {
|
func extractRoleBindingRefs(doc map[string]interface{}, srcID string, addEdge edgeAdder) {
|
||||||
// roleRef
|
|
||||||
if roleRef, ok := doc["roleRef"].(map[string]interface{}); ok {
|
if roleRef, ok := doc["roleRef"].(map[string]interface{}); ok {
|
||||||
kind, _ := roleRef["kind"].(string)
|
kind, _ := roleRef["kind"].(string)
|
||||||
name, _ := roleRef["name"].(string)
|
name, _ := roleRef["name"].(string)
|
||||||
@@ -400,7 +429,6 @@ func extractRoleBindingRefs(doc map[string]interface{}, srcID string, addEdge fu
|
|||||||
addEdge(srcID, kind, name, "roleBinding")
|
addEdge(srcID, kind, name, "roleBinding")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
// subjects
|
|
||||||
subjects, _ := doc["subjects"].([]interface{})
|
subjects, _ := doc["subjects"].([]interface{})
|
||||||
for _, s := range subjects {
|
for _, s := range subjects {
|
||||||
subj, ok := s.(map[string]interface{})
|
subj, ok := s.(map[string]interface{})
|
||||||
|
|||||||
Reference in New Issue
Block a user