func validateContainers(containers []Container, volumes util.StringSet) errs.ErrorList { allErrs := errs.ErrorList{} allNames := util.StringSet{} for i := range containers { cErrs := errs.ErrorList{} ctr := &containers[i] // so we can set default values if len(ctr.Name) == 0 { cErrs = append(cErrs, errs.NewRequired("name", ctr.Name)) } else if !util.IsDNSLabel(ctr.Name) { cErrs = append(cErrs, errs.NewInvalid("name", ctr.Name)) } else if allNames.Has(ctr.Name) { cErrs = append(cErrs, errs.NewDuplicate("name", ctr.Name)) } else { allNames.Insert(ctr.Name) } if len(ctr.Image) == 0 { cErrs = append(cErrs, errs.NewRequired("image", ctr.Image)) } cErrs = append(cErrs, validatePorts(ctr.Ports).Prefix("ports")...) cErrs = append(cErrs, validateEnv(ctr.Env).Prefix("env")...) cErrs = append(cErrs, validateVolumeMounts(ctr.VolumeMounts, volumes).Prefix("volumeMounts")...) allErrs = append(allErrs, cErrs.PrefixIndex(i)...) } // Check for colliding ports across all containers. // TODO(thockin): This really is dependent on the network config of the host (IP per pod?) // and the config of the new manifest. But we have not specced that out yet, so we'll just // make some assumptions for now. As of now, pods share a network namespace, which means that // every Port.HostPort across the whole pod must be unique. allErrs = append(allErrs, checkHostPortConflicts(containers)...) return allErrs }
// ValidateService tests if required fields in the service are set. func ValidateService(service *Service) errs.ErrorList { allErrs := errs.ErrorList{} if len(service.ID) == 0 { allErrs = append(allErrs, errs.NewRequired("id", service.ID)) } else if !util.IsDNS952Label(service.ID) { allErrs = append(allErrs, errs.NewInvalid("id", service.ID)) } if !util.IsValidPortNum(service.Port) { allErrs = append(allErrs, errs.NewInvalid("Service.Port", service.Port)) } if labels.Set(service.Selector).AsSelector().Empty() { allErrs = append(allErrs, errs.NewRequired("selector", service.Selector)) } return allErrs }
func validatePorts(ports []Port) errs.ErrorList { allErrs := errs.ErrorList{} allNames := util.StringSet{} for i := range ports { pErrs := errs.ErrorList{} port := &ports[i] // so we can set default values if len(port.Name) > 0 { if len(port.Name) > 63 || !util.IsDNSLabel(port.Name) { pErrs = append(pErrs, errs.NewInvalid("name", port.Name)) } else if allNames.Has(port.Name) { pErrs = append(pErrs, errs.NewDuplicate("name", port.Name)) } else { allNames.Insert(port.Name) } } if port.ContainerPort == 0 { pErrs = append(pErrs, errs.NewRequired("containerPort", port.ContainerPort)) } else if !util.IsValidPortNum(port.ContainerPort) { pErrs = append(pErrs, errs.NewInvalid("containerPort", port.ContainerPort)) } if port.HostPort != 0 && !util.IsValidPortNum(port.HostPort) { pErrs = append(pErrs, errs.NewInvalid("hostPort", port.HostPort)) } if len(port.Protocol) == 0 { port.Protocol = "TCP" } else if !supportedPortProtocols.Has(strings.ToUpper(port.Protocol)) { pErrs = append(pErrs, errs.NewNotSupported("protocol", port.Protocol)) } allErrs = append(allErrs, pErrs.PrefixIndex(i)...) } return allErrs }
func validateVolumes(volumes []Volume) (util.StringSet, errs.ErrorList) { allErrs := errs.ErrorList{} allNames := util.StringSet{} for i := range volumes { vol := &volumes[i] // so we can set default values el := errs.ErrorList{} // TODO(thockin) enforce that a source is set once we deprecate the implied form. if vol.Source != nil { el = validateSource(vol.Source).Prefix("source") } if len(vol.Name) == 0 { el = append(el, errs.NewRequired("name", vol.Name)) } else if !util.IsDNSLabel(vol.Name) { el = append(el, errs.NewInvalid("name", vol.Name)) } else if allNames.Has(vol.Name) { el = append(el, errs.NewDuplicate("name", vol.Name)) } if len(el) == 0 { allNames.Insert(vol.Name) } else { allErrs = append(allErrs, el.PrefixIndex(i)...) } } return allNames, allErrs }
// Pod tests if required fields in the pod are set. func ValidatePod(pod *Pod) errs.ErrorList { allErrs := errs.ErrorList{} if len(pod.ID) == 0 { allErrs = append(allErrs, errs.NewRequired("id", pod.ID)) } allErrs = append(allErrs, ValidatePodState(&pod.DesiredState).Prefix("desiredState")...) return allErrs }
func validateVolumeMounts(mounts []VolumeMount, volumes util.StringSet) errs.ErrorList { allErrs := errs.ErrorList{} for i := range mounts { mErrs := errs.ErrorList{} mnt := &mounts[i] // so we can set default values if len(mnt.Name) == 0 { mErrs = append(mErrs, errs.NewRequired("name", mnt.Name)) } else if !volumes.Has(mnt.Name) { mErrs = append(mErrs, errs.NewNotFound("name", mnt.Name)) } if len(mnt.MountPath) == 0 { mErrs = append(mErrs, errs.NewRequired("mountPath", mnt.MountPath)) } allErrs = append(allErrs, mErrs.PrefixIndex(i)...) } return allErrs }
// ValidateReplicationController tests if required fields in the replication controller are set. func ValidateReplicationController(controller *ReplicationController) errs.ErrorList { allErrs := errs.ErrorList{} if len(controller.ID) == 0 { allErrs = append(allErrs, errs.NewRequired("id", controller.ID)) } if labels.Set(controller.DesiredState.ReplicaSelector).AsSelector().Empty() { allErrs = append(allErrs, errs.NewRequired("desiredState.replicaSelector", controller.DesiredState.ReplicaSelector)) } selector := labels.Set(controller.DesiredState.ReplicaSelector).AsSelector() labels := labels.Set(controller.DesiredState.PodTemplate.Labels) if !selector.Matches(labels) { allErrs = append(allErrs, errs.NewInvalid("desiredState.podTemplate.labels", controller.DesiredState.PodTemplate)) } if controller.DesiredState.Replicas < 0 { allErrs = append(allErrs, errs.NewInvalid("desiredState.replicas", controller.DesiredState.Replicas)) } allErrs = append(allErrs, ValidateManifest(&controller.DesiredState.PodTemplate.DesiredState.Manifest).Prefix("desiredState.podTemplate.desiredState.manifest")...) return allErrs }
// ValidateManifest tests that the specified ContainerManifest has valid data. // This includes checking formatting and uniqueness. It also canonicalizes the // structure by setting default values and implementing any backwards-compatibility // tricks. func ValidateManifest(manifest *ContainerManifest) errs.ErrorList { allErrs := errs.ErrorList{} if len(manifest.Version) == 0 { allErrs = append(allErrs, errs.NewRequired("version", manifest.Version)) } else if !supportedManifestVersions.Has(strings.ToLower(manifest.Version)) { allErrs = append(allErrs, errs.NewNotSupported("version", manifest.Version)) } allVolumes, errs := validateVolumes(manifest.Volumes) allErrs = append(allErrs, errs.Prefix("volumes")...) allErrs = append(allErrs, validateContainers(manifest.Containers, allVolumes).Prefix("containers")...) return allErrs }
func validateEnv(vars []EnvVar) errs.ErrorList { allErrs := errs.ErrorList{} for i := range vars { vErrs := errs.ErrorList{} ev := &vars[i] // so we can set default values if len(ev.Name) == 0 { vErrs = append(vErrs, errs.NewRequired("name", ev.Name)) } if !util.IsCIdentifier(ev.Name) { vErrs = append(vErrs, errs.NewInvalid("name", ev.Name)) } allErrs = append(allErrs, vErrs.PrefixIndex(i)...) } return allErrs }
func TestNewInvalidErr(t *testing.T) { testCases := []struct { Err apierrors.ValidationError Details *api.StatusDetails }{ { apierrors.NewDuplicate("field[0].name", "bar"), &api.StatusDetails{ Kind: "kind", ID: "name", Causes: []api.StatusCause{{ Type: api.CauseTypeFieldValueDuplicate, Field: "field[0].name", }}, }, }, { apierrors.NewInvalid("field[0].name", "bar"), &api.StatusDetails{ Kind: "kind", ID: "name", Causes: []api.StatusCause{{ Type: api.CauseTypeFieldValueInvalid, Field: "field[0].name", }}, }, }, { apierrors.NewNotFound("field[0].name", "bar"), &api.StatusDetails{ Kind: "kind", ID: "name", Causes: []api.StatusCause{{ Type: api.CauseTypeFieldValueNotFound, Field: "field[0].name", }}, }, }, { apierrors.NewNotSupported("field[0].name", "bar"), &api.StatusDetails{ Kind: "kind", ID: "name", Causes: []api.StatusCause{{ Type: api.CauseTypeFieldValueNotSupported, Field: "field[0].name", }}, }, }, { apierrors.NewRequired("field[0].name", "bar"), &api.StatusDetails{ Kind: "kind", ID: "name", Causes: []api.StatusCause{{ Type: api.CauseTypeFieldValueRequired, Field: "field[0].name", }}, }, }, } for i := range testCases { vErr, expected := testCases[i].Err, testCases[i].Details expected.Causes[0].Message = vErr.Error() err := NewInvalidErr("kind", "name", apierrors.ErrorList{vErr}) status := errToAPIStatus(err) if status.Code != 422 || status.Reason != api.StatusReasonInvalid { t.Errorf("unexpected status: %#v", status) } if !reflect.DeepEqual(expected, status.Details) { t.Errorf("expected %#v, got %#v", expected, status.Details) } } }