ac18c98385
core/policy_engine.py: PolicyEngine Protocol (PEP 544, runtime_checkable)
+ PolicyEngineRegistry (selects from config.json.policy.engine) + NullEngine
fallback (NULL_ENGINE_INACTIVE when policy key absent).
adapters/kyverno-json/: KyvernoJsonEngine — shells to , translates
native output → list[dict] PCR records (engine: "kyverno", ruleId KJ_ prefix,
severity via nova.cloudinit.dev/severity annotation, default info).
is_configured() guards on → KJ_ENGINE_NOT_CONFIGURED SKIPPED PCR
(distinct from NullEngine). Defensive parsing (malformed → error PCR).
config.json: new object {engine: kyverno-json, policy_root}.
scripts/install-kyverno-json.sh: go install kj@latest (D-115).
CI (.gitea + .github): install Go + kj for policy-engine tests (best-effort;
tests skip when kj absent).
tests: 24 pass, 2 skip (kj not installed). 132 existing tests unchanged.
NullEngine satisfies PolicyEngine Protocol (G-Q8a — proves swap boundary).
---ci---
project: acdl
phase: 1
milestone: v1.25
status: execute
phase_role: execution
requirements:
covered: [REQ-291, REQ-292, REQ-293, REQ-294, REQ-308, REQ-309]
partial: []
---/ci---
27 lines
1017 B
Python
27 lines
1017 B
Python
"""Nova kyverno-json adapter package (v1.25, REQ-294).
|
|
|
|
The directory name ``kyverno-json`` has a hyphen, so it is not a valid
|
|
Python package name and cannot be imported via ``import
|
|
adapters.kyverno-json``. The ``PolicyEngineRegistry`` loads the engine
|
|
by file path (``importlib.util.spec_from_file_location``). This
|
|
``__init__`` is a convenience for direct-script use and for ``pip
|
|
install -e .`` style discovery if the package is ever renamed.
|
|
"""
|
|
|
|
|
|
def _load_engine():
|
|
import importlib.util
|
|
import os
|
|
engine_path = os.path.join(os.path.dirname(os.path.abspath(__file__)),
|
|
"kyverno_json_engine.py")
|
|
spec = importlib.util.spec_from_file_location("kyverno_json_engine", engine_path)
|
|
if spec is None or spec.loader is None:
|
|
raise ImportError(f"could not load {engine_path}")
|
|
mod = importlib.util.module_from_spec(spec)
|
|
spec.loader.exec_module(mod)
|
|
return mod.KyvernoJsonEngine
|
|
|
|
|
|
KyvernoJsonEngine = _load_engine()
|
|
|
|
__all__ = ["KyvernoJsonEngine"] |