Documentation
¶
Index ¶
- Constants
- type AddDirective
- type ArgDirective
- type AuditException
- type CmdDirective
- type CopyDirective
- type DfDirective
- type Dockerfile
- func (df *Dockerfile) AddDirective(directive DfDirective)
- func (df *Dockerfile) GetDirectives() map[string][]DfDirective
- func (df *Dockerfile) GetFilename() string
- func (df *Dockerfile) GetMaintainers() string
- func (df *Dockerfile) GetPath() string
- func (df *Dockerfile) GetRaw() []map[string]interface{}
- func (df *Dockerfile) GetRunDirectivesLastStage() []DfDirective
- type DockerfileAuditor
- type DockerfileDirectiveType
- type DockerfileObject
- type DockerfileVisitor
- type EnforceRegistryPolicy
- type EntrypointDirective
- type EnvDirective
- type ExposeDirective
- type ForbidInsecureRegistries
- type ForbidPackages
- type ForbidPrivilegedPorts
- type ForbidRoot
- type ForbidSecrets
- type ForbidTags
- type FromDirective
- type GenericPolicyRule
- type HealthcheckDirective
- type LabelDirective
- type MaintainerDirective
- type ParseResult
- type Policy
- type PolicyResult
- type PolicyRule
- type PolicyRuleType
- type PolicyTestResult
- type Rule
- type RunDirective
- type ShellDirective
- type StopsignalDirective
- type UserDirective
- type VolumeDirective
- type WorkdirDirective
Constants ¶
View Source
const ( FROM = iota + 1 RUN CMD LABEL MAINTAINER EXPOSE ENV ADD COPY ENTRYPOINT VOLUME USER WORKDIR ARG ONBUILD STOPSIGNAL HEALTHCHECK SHELL )
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type AddDirective ¶
type AddDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
Chown string `json:"chown"`
Source string `json:"source"`
Destination string `json:"destination"`
}
func NewAddDirective ¶
func NewAddDirective(rawContent string) *AddDirective
func (AddDirective) Get ¶
func (d AddDirective) Get() map[string]interface{}
func (*AddDirective) GetType ¶
func (d *AddDirective) GetType() DockerfileDirectiveType
type ArgDirective ¶
type ArgDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
Argument string `json:"argument"`
}
func NewArgDirective ¶
func NewArgDirective(rawContent string) *ArgDirective
func (ArgDirective) Get ¶
func (d ArgDirective) Get() map[string]interface{}
func (*ArgDirective) GetType ¶
func (d *ArgDirective) GetType() DockerfileDirectiveType
type AuditException ¶
type AuditException struct {
Message string
}
AuditException is an error type for audit exceptions.
func (*AuditException) Error ¶
func (e *AuditException) Error() string
type CmdDirective ¶
type CmdDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
}
func NewCmdDirective ¶
func NewCmdDirective(rawContent string) *CmdDirective
func (CmdDirective) Get ¶
func (d CmdDirective) Get() map[string]interface{}
func (*CmdDirective) GetType ¶
func (d *CmdDirective) GetType() DockerfileDirectiveType
type CopyDirective ¶
type CopyDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
Chown string `json:"chown"`
Source string `json:"source"`
Destination string `json:"destination"`
}
func NewCopyDirective ¶
func NewCopyDirective(rawContent string) *CopyDirective
func (CopyDirective) Get ¶
func (d CopyDirective) Get() map[string]interface{}
func (*CopyDirective) GetType ¶
func (d *CopyDirective) GetType() DockerfileDirectiveType
type DfDirective ¶
type DfDirective interface {
GetType() DockerfileDirectiveType
Get() map[string]interface{}
}
type Dockerfile ¶
type Dockerfile struct {
Directives []DfDirective
Path string
Filename string
Maintainers []string
}
func NewDockerfile ¶
func NewDockerfile(path string) (*Dockerfile, error)
func (*Dockerfile) AddDirective ¶
func (df *Dockerfile) AddDirective(directive DfDirective)
func (*Dockerfile) GetDirectives ¶
func (df *Dockerfile) GetDirectives() map[string][]DfDirective
func (*Dockerfile) GetFilename ¶
func (df *Dockerfile) GetFilename() string
func (*Dockerfile) GetMaintainers ¶
func (df *Dockerfile) GetMaintainers() string
func (*Dockerfile) GetPath ¶
func (df *Dockerfile) GetPath() string
func (*Dockerfile) GetRaw ¶
func (df *Dockerfile) GetRaw() []map[string]interface{}
func (*Dockerfile) GetRunDirectivesLastStage ¶
func (df *Dockerfile) GetRunDirectivesLastStage() []DfDirective
type DockerfileAuditor ¶
type DockerfileAuditor struct {
Policy Policy
}
DockerfileAuditor is a struct for DockerfileMsg auditing.
func NewDockerfileAuditor ¶
func NewDockerfileAuditor(policy Policy) *DockerfileAuditor
NewDockerfileAuditor creates a new instance of DfAuditor with the given policy.
func (*DockerfileAuditor) Audit ¶
func (auditor *DockerfileAuditor) Audit(path string) (PolicyResult, error)
Audit performs the audit operation on the specified file path.
func (*DockerfileAuditor) ParseOnly ¶
func (auditor *DockerfileAuditor) ParseOnly(path string) (ParseResult, error)
ParseOnly 仅对指定的文件路径执行分析操作。
type DockerfileDirectiveType ¶
type DockerfileDirectiveType int
func (DockerfileDirectiveType) String ¶
func (d DockerfileDirectiveType) String() string
type DockerfileObject ¶
type DockerfileObject struct {
From string
Platform string
Registry string
ImageName string
ImageTag string
Digest string
LocalName string
User string
RunCommands []string
LabelCommands []string
ExposeCommands []string
MaintainerCommands []string
AddCommands []string
CopyCommands []string
EnvCommands []string
CmdCommands []string
EntrypointCommands []string
WorkdirCommand string
VolumeCommands []string
ShellCommand string
StopsignalCommand string
ArgCommands []string
HealthcheckCommand string
HealthcheckOptions string
}
type DockerfileVisitor ¶
type DockerfileVisitor struct {
Dockerfile *Dockerfile
}
func NewDockerfileVisitor ¶
func NewDockerfileVisitor(dockerfile *Dockerfile) *DockerfileVisitor
func (*DockerfileVisitor) VisitDockerfile ¶
func (v *DockerfileVisitor) VisitDockerfile(visitedChildren *parser.Node) interface{}
type EnforceRegistryPolicy ¶
type EnforceRegistryPolicy struct {
GenericPolicyRule
AllowedRegistries []string
Enabled bool
}
func NewEnforceRegistryPolicy ¶
func NewEnforceRegistryPolicy(allowedRegistries []string, enabled bool) *EnforceRegistryPolicy
func (*EnforceRegistryPolicy) Details ¶
func (r *EnforceRegistryPolicy) Details() string
func (*EnforceRegistryPolicy) Test ¶
func (r *EnforceRegistryPolicy) Test(dockerfileDirectives map[string][]DfDirective) *[]Rule
type EntrypointDirective ¶
type EntrypointDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
}
func NewEntrypointDirective ¶
func NewEntrypointDirective(rawContent string) *EntrypointDirective
func (EntrypointDirective) Get ¶
func (d EntrypointDirective) Get() map[string]interface{}
func (*EntrypointDirective) GetType ¶
func (d *EntrypointDirective) GetType() DockerfileDirectiveType
type EnvDirective ¶
type EnvDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
Variables map[string]string `json:"variables"`
}
func NewEnvDirective ¶
func NewEnvDirective(rawContent string) *EnvDirective
func (EnvDirective) Get ¶
func (d EnvDirective) Get() map[string]interface{}
func (*EnvDirective) GetType ¶
func (d *EnvDirective) GetType() DockerfileDirectiveType
type ExposeDirective ¶
type ExposeDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
Ports []string `json:"ports"`
}
func NewExposeDirective ¶
func NewExposeDirective(rawContent string) *ExposeDirective
func (ExposeDirective) Get ¶
func (d ExposeDirective) Get() map[string]interface{}
func (*ExposeDirective) GetType ¶
func (d *ExposeDirective) GetType() DockerfileDirectiveType
type ForbidInsecureRegistries ¶
type ForbidInsecureRegistries struct {
GenericPolicyRule
Enabled bool
}
func NewForbidInsecureRegistries ¶
func NewForbidInsecureRegistries(enabled bool) *ForbidInsecureRegistries
func (*ForbidInsecureRegistries) Test ¶
func (rule *ForbidInsecureRegistries) Test(dockerfileStatements map[string][]DfDirective) *[]Rule
type ForbidPackages ¶
type ForbidPackages struct {
ForbiddenPackages []string
GenericPolicyRule
}
func NewForbidPackages ¶
func NewForbidPackages(forbiddenPackages []string) *ForbidPackages
func (*ForbidPackages) Details ¶
func (rule *ForbidPackages) Details() string
func (*ForbidPackages) Test ¶
func (rule *ForbidPackages) Test(mapDirectives map[string][]DfDirective) *[]Rule
type ForbidPrivilegedPorts ¶
type ForbidPrivilegedPorts struct {
GenericPolicyRule
Enabled bool
}
func NewForbidPrivilegedPorts ¶
func NewForbidPrivilegedPorts(enabled bool) *ForbidPrivilegedPorts
func (*ForbidPrivilegedPorts) Test ¶
func (rule *ForbidPrivilegedPorts) Test(dockerfileDirective map[string][]DfDirective) *[]Rule
type ForbidRoot ¶
type ForbidRoot struct {
GenericPolicyRule
Enabled bool
}
func NewForbidRoot ¶
func NewForbidRoot(enabled bool) *ForbidRoot
func (*ForbidRoot) Test ¶
func (rule *ForbidRoot) Test(dockerfileStatements map[string][]DfDirective) *[]Rule
type ForbidSecrets ¶
type ForbidSecrets struct {
GenericPolicyRule
// contains filtered or unexported fields
}
func NewForbidSecrets ¶
func NewForbidSecrets(secretsPatterns, allowedPatterns []string) *ForbidSecrets
func (*ForbidSecrets) Details ¶
func (fs *ForbidSecrets) Details() string
func (*ForbidSecrets) Test ¶
func (fs *ForbidSecrets) Test(dockerfileStatements map[string][]DfDirective) *[]Rule
type ForbidTags ¶
type ForbidTags struct {
GenericPolicyRule
ForbiddenTags []string
}
func NewForbidTags ¶
func NewForbidTags(tags []string) *ForbidTags
func (*ForbidTags) Details ¶
func (rule *ForbidTags) Details() string
func (*ForbidTags) Test ¶
func (r *ForbidTags) Test(directives map[string][]DfDirective) *[]Rule
type FromDirective ¶
type FromDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
Platform string `json:"platform"`
Registry string `json:"registry"`
ImageLocalName string `json:"local_name"`
ImageTag string `json:"tag"`
ImageName string `json:"image"`
}
func NewFromDirective ¶
func NewFromDirective(rawContent string) *FromDirective
func (*FromDirective) Get ¶
func (d *FromDirective) Get() map[string]interface{}
func (*FromDirective) GetType ¶
func (d *FromDirective) GetType() DockerfileDirectiveType
type GenericPolicyRule ¶
type GenericPolicyRule struct {
Type PolicyRuleType
TestResult PolicyTestResult
Description string
}
func (*GenericPolicyRule) Describe ¶
func (r *GenericPolicyRule) Describe() string
func (*GenericPolicyRule) Details ¶
func (r *GenericPolicyRule) Details() string
func (*GenericPolicyRule) GetType ¶
func (r *GenericPolicyRule) GetType() PolicyRuleType
func (*GenericPolicyRule) Test ¶
func (r *GenericPolicyRule) Test(directives map[string][]DfDirective) *[]Rule
type HealthcheckDirective ¶
type HealthcheckDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
}
func NewHealthcheckDirective ¶
func NewHealthcheckDirective(rawContent string) *HealthcheckDirective
func (HealthcheckDirective) Get ¶
func (d HealthcheckDirective) Get() map[string]interface{}
func (*HealthcheckDirective) GetType ¶
func (d *HealthcheckDirective) GetType() DockerfileDirectiveType
type LabelDirective ¶
type LabelDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
Labels map[string]string `json:"labels"`
}
func NewLabelDirective ¶
func NewLabelDirective(rawContent string) *LabelDirective
func (*LabelDirective) Get ¶
func (d *LabelDirective) Get() map[string]interface{}
func (*LabelDirective) GetType ¶
func (d *LabelDirective) GetType() DockerfileDirectiveType
type MaintainerDirective ¶
type MaintainerDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
Maintainers []string `json:"maintainers"`
}
func NewMaintainerDirective ¶
func NewMaintainerDirective(rawContent string) *MaintainerDirective
func (MaintainerDirective) Get ¶
func (d MaintainerDirective) Get() map[string]interface{}
func (MaintainerDirective) GetMaintainers ¶
func (d MaintainerDirective) GetMaintainers() []string
func (*MaintainerDirective) GetType ¶
func (d *MaintainerDirective) GetType() DockerfileDirectiveType
type ParseResult ¶
type ParseResult struct {
Filename string `json:"filename"`
Path string `json:"path"`
Maintainers string `json:"maintainers"`
Directives map[string][]DfDirective `json:"directives"`
}
type Policy ¶
type Policy struct {
PolicyRules []PolicyRule
PolicyFile string
}
func NewDockerfilePolicy ¶
func (*Policy) EvaluateDockerfile ¶
func (p *Policy) EvaluateDockerfile(dockerfileObject Dockerfile) PolicyResult
func (*Policy) GetPolicyRulesEnabled ¶
type PolicyResult ¶
type PolicyRule ¶
type PolicyRule interface {
GetType() PolicyRuleType
Details() string
Describe() string
Test(directives map[string][]DfDirective) *[]Rule
}
type PolicyRuleType ¶
type PolicyRuleType int
const ( GENERIC_POLICY PolicyRuleType = iota + 1 ENFORCE_REGISTRY FORBID_TAGS FORBID_INSECURE_REGISTRIES FORBID_ROOT FORBID_PRIVILEGED_PORTS FORBID_PACKAGES FORBID_SECRETS FORBID_LAX_CHMOD )
func (PolicyRuleType) String ¶
func (t PolicyRuleType) String() string
type PolicyTestResult ¶
type PolicyTestResult struct {
Results []Rule
}
func NewPolicyTestResult ¶
func NewPolicyTestResult() PolicyTestResult
func (*PolicyTestResult) AddPassResult ¶
func (r *PolicyTestResult) AddPassResult(details string, ruleType PolicyRuleType, content string)
func (*PolicyTestResult) AddResult ¶
func (r *PolicyTestResult) AddResult(details, mitigations string, ruleType PolicyRuleType, content string, directiveType ...string)
func (*PolicyTestResult) GetResult ¶
func (r *PolicyTestResult) GetResult() *[]Rule
type Rule ¶
type Rule struct {
Type PolicyRuleType `json:"Type"`
Details string `json:"Details"`
Mitigations string `json:"Mitigations"`
Statement []string `json:"Statement,omitempty"`
Line int `json:"Line,omitempty"`
Directive string `json:"Directive,omitempty"`
Level string `json:"Level,omitempty"`
Status string `json:"Status"` // 新增:"pass" 或 "fail"
}
type RunDirective ¶
type RunDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
}
func NewRunDirective ¶
func NewRunDirective(rawContent string) *RunDirective
func (*RunDirective) Get ¶
func (d *RunDirective) Get() map[string]interface{}
func (*RunDirective) GetType ¶
func (d *RunDirective) GetType() DockerfileDirectiveType
type ShellDirective ¶
type ShellDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
}
func NewShellDirective ¶
func NewShellDirective(rawContent string) *ShellDirective
func (ShellDirective) Get ¶
func (d ShellDirective) Get() map[string]interface{}
func (*ShellDirective) GetType ¶
func (d *ShellDirective) GetType() DockerfileDirectiveType
type StopsignalDirective ¶
type StopsignalDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
Signal string `json:"stopsignal"`
}
func NewStopsignalDirective ¶
func NewStopsignalDirective(rawContent string) *StopsignalDirective
func (StopsignalDirective) Get ¶
func (d StopsignalDirective) Get() map[string]interface{}
func (*StopsignalDirective) GetType ¶
func (d *StopsignalDirective) GetType() DockerfileDirectiveType
type UserDirective ¶
type UserDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
User string `json:"user"`
Group string `json:"group"`
}
func NewUserDirective ¶
func NewUserDirective(rawContent string) *UserDirective
func (UserDirective) Get ¶
func (d UserDirective) Get() map[string]interface{}
func (*UserDirective) GetType ¶
func (d *UserDirective) GetType() DockerfileDirectiveType
type VolumeDirective ¶
type VolumeDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
Volumes []string `json:"volumes"`
}
func NewVolumeDirective ¶
func NewVolumeDirective(rawContent string) *VolumeDirective
func (VolumeDirective) Get ¶
func (d VolumeDirective) Get() map[string]interface{}
func (*VolumeDirective) GetType ¶
func (d *VolumeDirective) GetType() DockerfileDirectiveType
type WorkdirDirective ¶
type WorkdirDirective struct {
Type DockerfileDirectiveType `json:"type"`
Content string `json:"raw_content"`
RunLastStage []map[string]string
}
func NewWorkdirDirective ¶
func NewWorkdirDirective(rawContent string) *WorkdirDirective
func (WorkdirDirective) Get ¶
func (d WorkdirDirective) Get() map[string]interface{}
func (*WorkdirDirective) GetType ¶
func (d *WorkdirDirective) GetType() DockerfileDirectiveType
Click to show internal directories.
Click to hide internal directories.