Admission Control

作者 grafana1ccacf29049fApache-2.0279 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Use when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming resources", "implement admission logic", "add admission webhooks", "write ingress validation", or asks how to validate or mutate resources before they are persisted in a grafana-app-sdk app. Provides guidance on implementing validation and mutation admission handlers for grafana-app-sdk apps.

AI 生成的概览

指导为 grafana-app-sdk 应用实现校验与变更准入处理器。

功能
该技能为在 grafana-app-sdk 应用中编写准入控制处理器提供指导和代码模式。内容涵盖 Validator 与 Mutator 接口、示例实现、在应用构建器中注册处理器、准入请求字段,以及不可变性和跨字段校验等常见校验模式。它还说明了独立 operator 与 grafana/apps 部署方式下准入运行方式的差异。
适用场景
当用户要求编写校验器、添加校验、实现准入控制、编写变更 webhook,或在 grafana-app-sdk 应用中于资源持久化前校验或变更资源时使用。它面向使用 grafana-app-sdk 类型和准入逻辑的开发者。
运行要求
需要一个 grafana-app-sdk Go 项目;该技能仅为说明文档,不附带脚本。它引用 grafana-app-sdk 的 Go 包以及用于生成 operator 脚手架的 grafana-app-sdk 命令行工具,并提及 Kubernetes 准入 webhook 和 CUE 类型定义。

Admission Control

Admission control intercepts resource create/update requests before they are persisted. In grafana-app-sdk there are two types:

  • Validation — accept or reject a request; cannot modify the resource
  • Mutation — modify the resource before it is persisted (e.g. set defaults, normalize fields)

The app business logic for admission is identical whether the app runs as a standalone operator or inside grafana/apps. The only difference is the runtime: standalone apps stand up their own webhook server; grafana/apps apps have admission auto-registered as a Kubernetes plugin.

Getting Stubs

For standalone apps, if pkg/app/app.go does not yet exist, a stub App can be generated with:

bash
grafana-app-sdk project component add operator

This creates scaffolded simple.App which admission handlers can be added to for each kind in ManagedKinds.

Validator Interface

go
// Implement this interface for each kind you want to validatetype Validator interface {    Validate(ctx context.Context, request *app.AdmissionRequest) error}
  • Return nil to admit the request
  • Return an error to reject it (the error message is returned to the API caller)
  • app.AdmissionRequest provides access to the incoming object and operation type
  • You can use k8s.NewAdmissionError(err error, statusCode int, reason string) (from "github.com/grafana/grafana-app-sdk/k8s") to better control the returned error information

Validator Example

go
type MyKindValidator struct{}
func (v *MyKindValidator) Validate(ctx context.Context, req *app.AdmissionRequest) error {    obj, ok := req.Object.(*v1.MyKind)    if !ok {        return fmt.Errorf("admission request object was of invalid type %T (expected *v1.MyKind)", req.Object)    }
    // Validate spec fields    if obj.Spec.Title == "" {        return fmt.Errorf("spec.title is required")    }
    if obj.Spec.Count < 0 {        return fmt.Errorf("spec.count must be non-negative, got %d", obj.Spec.Count)    }
    // Distinguish create vs update    if req.Action == resource.AdmissionActionUpdate && req.OldObject != nil {        old, ok := req.OldObject.(*v1.MyKind)        if !ok {            return fmt.Errorf("admission request old object was of invalid type %T (expected *v1.MyKind)", req.OldObject)        }        if old.Spec.Title != obj.Spec.Title {            return fmt.Errorf("spec.title is immutable after creation")        }    }
    return nil}

Mutating Admission (Mutator)

go
// Implement this interface to mutate resources before persistencetype Mutator interface {    Mutate(ctx context.Context, request *app.AdmissionRequest) (*app.MutatingResponse, error)}
  • Return a MutatingResponse containing the (optionally modified) object
  • Return an error to reject the request entirely
  • Best practice is to reject requests from validators, not mutators

Mutating Handler Example

go
type MyKindMutator struct{}
func (m *MyKindMutator) Mutate(    ctx context.Context,    req *app.AdmissionRequest,) (*app.MutatingResponse, error) {    obj, ok := req.Object.(*v1.MyKind)    if !ok {        return nil, fmt.Errorf("admission request object was of invalid type %T (expected *v1.MyKind)", req.Object)    }
    // Set defaults on create    if req.Action == resource.AdmissionActionCreate {        if obj.Spec.Description == "" {            obj.Spec.Description = "No description provided"        }    }
    return &app.MutatingResponse{UpdatedObject: obj}, nil}

Registering Admission Handlers

Register validators and mutators when building the app in pkg/app/app.go:

go
func New(cfg app.Config) (app.App, error) {    cfg.KubeConfig.APIPath = "/apis"    a, err := simple.NewApp(simple.AppConfig{        ManagedKinds: []simple.AppManagedKind{            {                Kind:      v1.MyKindKind(),                Validator: &MyKindValidator{},                Mutator:   &MyKindMutator{},            },        },    })    if err != nil {      return nil, fmt.Errorf("error creating app: %w", err)    }    if err = a.ValidateManifest(cfg.ManifestData); err != nil {        return nil, fmt.Errorf("app manifest validation failed: %w", err)    }    return a, nil}

Note that mutation and validation must also be enabled in the kind's CUE definition (mutation.operations and validation.operations fields) — see the cue-kind-definition skill for details.

Admission Request Fields

Key fields available on app.AdmissionRequest:

FieldTypeDescription
Objectresource.ObjectThe incoming resource (after decoding)
OldObjectresource.ObjectPrevious state (only on UPDATE operations)
Actionresource.AdmissionActionAdmissionActionCreate, AdmissionActionUpdate, AdmissionActionDelete, AdmissionActionConnect
UserInforesource.AdmissionUserInfoThe user making the request
KindstringThe Object kind
GroupstringThe Object API Group
VersionstringThe Object API Version

Validation Patterns

Common patterns to implement:

go
// Immutability checkif req.Action == resource.AdmissionActionUpdate && old.Spec.ImmutableField != obj.Spec.ImmutableField {    return fmt.Errorf("spec.immutableField cannot be changed after creation")}
// Cross-field validationif obj.Spec.StartTime.After(obj.Spec.EndTime) {    return fmt.Errorf("spec.startTime must be before spec.endTime")}
// Referential validation (e.g. check referenced resource exists)if _, err := v.client.Get(ctx, resource.Identifier{Name: obj.Spec.RefName, Namespace: obj.Namespace}); err != nil {    return fmt.Errorf("referenced resource %q not found", obj.Spec.RefName)}

Deployment Difference

ModeAdmission runtime
Standalone operatorApp starts a webhook server; Kubernetes routes admission requests to it
grafana/appsAdmission handlers are auto-registered as a Kubernetes in-process plugin — no separate server required

The handler code itself is identical in both cases.

Resources

来源与署名

来源:grafana/skills位于skills/grafana-app-sdk/admission-control提交1ccacf2

许可证: Apache-2.0

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架

更多来自 grafana/skills 的技能

React 19 Plugin Migration

grafana

指导将 Grafana 插件迁移至 React 19 兼容,按顺序完成构建、依赖与源码修改步骤。

Software Development279今天更新

Plugin Bundle Size

grafana

指导使用 React.lazy、Suspense 和 webpack 代码分割来优化 Grafana 应用插件包体积。

Software Development279今天更新

Grafana Scenes

grafana

使用 @grafana/scenes 框架构建 Grafana 插件页面,涵盖场景、面板、变量与下钻导航。

Software Development279今天更新

Check Npm

grafana

对 JS/TS 仓库的 npm、yarn 或 pnpm 配置进行只读供应链加固审计。

Security279今天更新

Mimir

grafana

指导搭建和运维 Grafana Mimir,用于可扩展、多租户、长期的 Prometheus 与 OTLP 指标存储。

DevOps & Cloud279今天更新

K6 Trend Analysis

grafana

Analyze Grafana Cloud k6 test run trends over time. Detects slow metric drift (e.g., P95 latency creeping up while still passing thresholds), computes headroom to thresholds, flags anomalies, and recommends threshold tightening. Use when the user asks about test performance trends, wants to know if metrics are degrading, asks whether thresholds should be tightened, or wants a health check across recent runs for a specific test. Trigger on phrases like "how is my test trending", "is P95 getting worse", "check for performance regression", "should I tighten thresholds", "are my tests degrading", "show me trends for test X", "analyze my k6 test runs", or "is my test getting slower". Also trigger when a user asks to check all tests in a project -- run this skill once per test and synthesize.

待分类279今天更新