Class Resources.AdmissionRule (1.4.0)

publicstaticfinalclassResources.AdmissionRuleextendsGeneratedMessageV3implementsResources.AdmissionRuleOrBuilder

An admission rule specifies either that all container images used in a pod creation request must be attested to by one or more attestors, that all pod creations will be allowed, or that all pod creations will be denied. Images matching an admission allowlist pattern are exempted from admission rules and will never block a pod creation.

Protobuf type google.cloud.binaryauthorization.v1.AdmissionRule

Static Fields

ENFORCEMENT_MODE_FIELD_NUMBER

publicstaticfinalintENFORCEMENT_MODE_FIELD_NUMBER
Field Value
TypeDescription
int

EVALUATION_MODE_FIELD_NUMBER

publicstaticfinalintEVALUATION_MODE_FIELD_NUMBER
Field Value
TypeDescription
int

REQUIRE_ATTESTATIONS_BY_FIELD_NUMBER

publicstaticfinalintREQUIRE_ATTESTATIONS_BY_FIELD_NUMBER
Field Value
TypeDescription
int

Static Methods

getDefaultInstance()

publicstaticResources.AdmissionRulegetDefaultInstance()
Returns
TypeDescription
Resources.AdmissionRule

getDescriptor()

publicstaticfinalDescriptors.DescriptorgetDescriptor()
Returns
TypeDescription
Descriptor

newBuilder()

publicstaticResources.AdmissionRule.BuildernewBuilder()
Returns
TypeDescription
Resources.AdmissionRule.Builder

newBuilder(Resources.AdmissionRule prototype)

publicstaticResources.AdmissionRule.BuildernewBuilder(Resources.AdmissionRuleprototype)
Parameter
NameDescription
prototypeResources.AdmissionRule
Returns
TypeDescription
Resources.AdmissionRule.Builder

parseDelimitedFrom(InputStream input)

publicstaticResources.AdmissionRuleparseDelimitedFrom(InputStreaminput)
Parameter
NameDescription
inputInputStream
Returns
TypeDescription
Resources.AdmissionRule
Exceptions
TypeDescription
IOException

parseDelimitedFrom(InputStream input, ExtensionRegistryLite extensionRegistry)

publicstaticResources.AdmissionRuleparseDelimitedFrom(InputStreaminput,ExtensionRegistryLiteextensionRegistry)
Parameters
NameDescription
inputInputStream
extensionRegistryExtensionRegistryLite
Returns
TypeDescription
Resources.AdmissionRule
Exceptions
TypeDescription
IOException

parseFrom(byte[] data)

publicstaticResources.AdmissionRuleparseFrom(byte[]data)
Parameter
NameDescription
databyte[]
Returns
TypeDescription
Resources.AdmissionRule
Exceptions
TypeDescription
InvalidProtocolBufferException

parseFrom(byte[] data, ExtensionRegistryLite extensionRegistry)

publicstaticResources.AdmissionRuleparseFrom(byte[]data,ExtensionRegistryLiteextensionRegistry)
Parameters
NameDescription
databyte[]
extensionRegistryExtensionRegistryLite
Returns
TypeDescription
Resources.AdmissionRule
Exceptions
TypeDescription
InvalidProtocolBufferException

parseFrom(ByteString data)

publicstaticResources.AdmissionRuleparseFrom(ByteStringdata)
Parameter
NameDescription
dataByteString
Returns
TypeDescription
Resources.AdmissionRule
Exceptions
TypeDescription
InvalidProtocolBufferException

parseFrom(ByteString data, ExtensionRegistryLite extensionRegistry)

publicstaticResources.AdmissionRuleparseFrom(ByteStringdata,ExtensionRegistryLiteextensionRegistry)
Parameters
NameDescription
dataByteString
extensionRegistryExtensionRegistryLite
Returns
TypeDescription
Resources.AdmissionRule
Exceptions
TypeDescription
InvalidProtocolBufferException

parseFrom(CodedInputStream input)

publicstaticResources.AdmissionRuleparseFrom(CodedInputStreaminput)
Parameter
NameDescription
inputCodedInputStream
Returns
TypeDescription
Resources.AdmissionRule
Exceptions
TypeDescription
IOException

parseFrom(CodedInputStream input, ExtensionRegistryLite extensionRegistry)

publicstaticResources.AdmissionRuleparseFrom(CodedInputStreaminput,ExtensionRegistryLiteextensionRegistry)
Parameters
NameDescription
inputCodedInputStream
extensionRegistryExtensionRegistryLite
Returns
TypeDescription
Resources.AdmissionRule
Exceptions
TypeDescription
IOException

parseFrom(InputStream input)

publicstaticResources.AdmissionRuleparseFrom(InputStreaminput)
Parameter
NameDescription
inputInputStream
Returns
TypeDescription
Resources.AdmissionRule
Exceptions
TypeDescription
IOException

parseFrom(InputStream input, ExtensionRegistryLite extensionRegistry)

publicstaticResources.AdmissionRuleparseFrom(InputStreaminput,ExtensionRegistryLiteextensionRegistry)
Parameters
NameDescription
inputInputStream
extensionRegistryExtensionRegistryLite
Returns
TypeDescription
Resources.AdmissionRule
Exceptions
TypeDescription
IOException

parseFrom(ByteBuffer data)

publicstaticResources.AdmissionRuleparseFrom(ByteBufferdata)
Parameter
NameDescription
dataByteBuffer
Returns
TypeDescription
Resources.AdmissionRule
Exceptions
TypeDescription
InvalidProtocolBufferException

parseFrom(ByteBuffer data, ExtensionRegistryLite extensionRegistry)

publicstaticResources.AdmissionRuleparseFrom(ByteBufferdata,ExtensionRegistryLiteextensionRegistry)
Parameters
NameDescription
dataByteBuffer
extensionRegistryExtensionRegistryLite
Returns
TypeDescription
Resources.AdmissionRule
Exceptions
TypeDescription
InvalidProtocolBufferException

parser()

publicstaticParser<Resources.AdmissionRule>parser()
Returns
TypeDescription
Parser<AdmissionRule>

Methods

equals(Object obj)

publicbooleanequals(Objectobj)
Parameter
NameDescription
objObject
Returns
TypeDescription
boolean
Overrides

getDefaultInstanceForType()

publicResources.AdmissionRulegetDefaultInstanceForType()
Returns
TypeDescription
Resources.AdmissionRule

getEnforcementMode()

publicResources.AdmissionRule.EnforcementModegetEnforcementMode()

Required. The action when a pod creation is denied by the admission rule.

.google.cloud.binaryauthorization.v1.AdmissionRule.EnforcementMode enforcement_mode = 3 [(.google.api.field_behavior) = REQUIRED];

Returns
TypeDescription
Resources.AdmissionRule.EnforcementMode

The enforcementMode.

getEnforcementModeValue()

publicintgetEnforcementModeValue()

Required. The action when a pod creation is denied by the admission rule.

.google.cloud.binaryauthorization.v1.AdmissionRule.EnforcementMode enforcement_mode = 3 [(.google.api.field_behavior) = REQUIRED];

Returns
TypeDescription
int

The enum numeric value on the wire for enforcementMode.

getEvaluationMode()

publicResources.AdmissionRule.EvaluationModegetEvaluationMode()

Required. How this admission rule will be evaluated.

.google.cloud.binaryauthorization.v1.AdmissionRule.EvaluationMode evaluation_mode = 1 [(.google.api.field_behavior) = REQUIRED];

Returns
TypeDescription
Resources.AdmissionRule.EvaluationMode

The evaluationMode.

getEvaluationModeValue()

publicintgetEvaluationModeValue()

Required. How this admission rule will be evaluated.

.google.cloud.binaryauthorization.v1.AdmissionRule.EvaluationMode evaluation_mode = 1 [(.google.api.field_behavior) = REQUIRED];

Returns
TypeDescription
int

The enum numeric value on the wire for evaluationMode.

getParserForType()

publicParser<Resources.AdmissionRule>getParserForType()
Returns
TypeDescription
Parser<AdmissionRule>
Overrides

getRequireAttestationsBy(int index)

publicStringgetRequireAttestationsBy(intindex)

Optional. The resource names of the attestors that must attest to a container image, in the format projects/*/attestors/*. Each attestor must exist before a policy can reference it. To add an attestor to a policy the principal issuing the policy change request must be able to read the attestor resource. Note: this field must be non-empty when the evaluation_mode field specifies REQUIRE_ATTESTATION, otherwise it must be empty.

repeated string require_attestations_by = 2 [(.google.api.field_behavior) = OPTIONAL];

Parameter
NameDescription
indexint

The index of the element to return.

Returns
TypeDescription
String

The requireAttestationsBy at the given index.

getRequireAttestationsByBytes(int index)

publicByteStringgetRequireAttestationsByBytes(intindex)

Optional. The resource names of the attestors that must attest to a container image, in the format projects/*/attestors/*. Each attestor must exist before a policy can reference it. To add an attestor to a policy the principal issuing the policy change request must be able to read the attestor resource. Note: this field must be non-empty when the evaluation_mode field specifies REQUIRE_ATTESTATION, otherwise it must be empty.

repeated string require_attestations_by = 2 [(.google.api.field_behavior) = OPTIONAL];

Parameter
NameDescription
indexint

The index of the value to return.

Returns
TypeDescription
ByteString

The bytes of the requireAttestationsBy at the given index.

getRequireAttestationsByCount()

publicintgetRequireAttestationsByCount()

Optional. The resource names of the attestors that must attest to a container image, in the format projects/*/attestors/*. Each attestor must exist before a policy can reference it. To add an attestor to a policy the principal issuing the policy change request must be able to read the attestor resource. Note: this field must be non-empty when the evaluation_mode field specifies REQUIRE_ATTESTATION, otherwise it must be empty.

repeated string require_attestations_by = 2 [(.google.api.field_behavior) = OPTIONAL];

Returns
TypeDescription
int

The count of requireAttestationsBy.

getRequireAttestationsByList()

publicProtocolStringListgetRequireAttestationsByList()

Optional. The resource names of the attestors that must attest to a container image, in the format projects/*/attestors/*. Each attestor must exist before a policy can reference it. To add an attestor to a policy the principal issuing the policy change request must be able to read the attestor resource. Note: this field must be non-empty when the evaluation_mode field specifies REQUIRE_ATTESTATION, otherwise it must be empty.

repeated string require_attestations_by = 2 [(.google.api.field_behavior) = OPTIONAL];

Returns
TypeDescription
ProtocolStringList

A list containing the requireAttestationsBy.

getSerializedSize()

publicintgetSerializedSize()
Returns
TypeDescription
int
Overrides

getUnknownFields()

publicfinalUnknownFieldSetgetUnknownFields()
Returns
TypeDescription
UnknownFieldSet
Overrides

hashCode()

publicinthashCode()
Returns
TypeDescription
int
Overrides

internalGetFieldAccessorTable()

protectedGeneratedMessageV3.FieldAccessorTableinternalGetFieldAccessorTable()
Returns
TypeDescription
FieldAccessorTable
Overrides

isInitialized()

publicfinalbooleanisInitialized()
Returns
TypeDescription
boolean
Overrides

newBuilderForType()

publicResources.AdmissionRule.BuildernewBuilderForType()
Returns
TypeDescription
Resources.AdmissionRule.Builder

newBuilderForType(GeneratedMessageV3.BuilderParent parent)

protectedResources.AdmissionRule.BuildernewBuilderForType(GeneratedMessageV3.BuilderParentparent)
Parameter
NameDescription
parentBuilderParent
Returns
TypeDescription
Resources.AdmissionRule.Builder
Overrides

newInstance(GeneratedMessageV3.UnusedPrivateParameter unused)

protectedObjectnewInstance(GeneratedMessageV3.UnusedPrivateParameterunused)
Parameter
NameDescription
unusedUnusedPrivateParameter
Returns
TypeDescription
Object
Overrides

toBuilder()

publicResources.AdmissionRule.BuildertoBuilder()
Returns
TypeDescription
Resources.AdmissionRule.Builder

writeTo(CodedOutputStream output)

publicvoidwriteTo(CodedOutputStreamoutput)
Parameter
NameDescription
outputCodedOutputStream
OverridesExceptions
TypeDescription
IOException