Class RBAC.Builder
java.lang.Object
com.google.protobuf.AbstractMessageLite.Builder
com.google.protobuf.AbstractMessage.Builder<RBAC.Builder>
com.google.protobuf.GeneratedMessage.Builder<RBAC.Builder>
io.envoyproxy.envoy.config.rbac.v3.RBAC.Builder
- All Implemented Interfaces:
com.google.protobuf.Message.Builder,com.google.protobuf.MessageLite.Builder,com.google.protobuf.MessageLiteOrBuilder,com.google.protobuf.MessageOrBuilder,RBACOrBuilder,Cloneable
- Enclosing class:
RBAC
public static final class RBAC.Builder
extends com.google.protobuf.GeneratedMessage.Builder<RBAC.Builder>
implements RBACOrBuilder
Role Based Access Control (RBAC) provides service-level and method-level access control for a
service. Requests are allowed or denied based on the ``action`` and whether a matching policy is
found. For instance, if the action is ALLOW and a matching policy is found the request should be
allowed.
RBAC can also be used to make access logging decisions by communicating with access loggers
through dynamic metadata. When the action is LOG and at least one policy matches, the
``access_log_hint`` value in the shared key namespace 'envoy.common' is set to ``true`` indicating
the request should be logged.
Here is an example of RBAC configuration. It has two policies:
* Service account ``cluster.local/ns/default/sa/admin`` has full access to the service, and so
does "cluster.local/ns/default/sa/superuser".
* Any user can read (``GET``) the service at paths with prefix ``/products``, so long as the
destination port is either 80 or 443.
.. code-block:: yaml
action: ALLOW
policies:
"service-admin":
permissions:
- any: true
principals:
- authenticated:
principal_name:
exact: "cluster.local/ns/default/sa/admin"
- authenticated:
principal_name:
exact: "cluster.local/ns/default/sa/superuser"
"product-viewer":
permissions:
- and_rules:
rules:
- header:
name: ":method"
string_match:
exact: "GET"
- url_path:
path: { prefix: "/products" }
- or_rules:
rules:
- destination_port: 80
- destination_port: 443
principals:
- any: true
Protobuf type envoy.config.rbac.v3.RBAC-
Nested Class Summary
Nested Classes -
Field Summary
FieldsModifier and TypeFieldDescriptionprivate intprivate RBAC.AuditLoggingOptionsprivate com.google.protobuf.SingleFieldBuilder<RBAC.AuditLoggingOptions, RBAC.AuditLoggingOptions.Builder, RBAC.AuditLoggingOptionsOrBuilder> private intprivate com.google.protobuf.MapFieldBuilder<String, PolicyOrBuilder, Policy, Policy.Builder> private static final RBAC.Builder.PoliciesConverter -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionbuild()private voidbuildPartial0(RBAC result) clear()The action to take if a policy matches.Audit logging options that include the condition for audit logging to happen and audit logger configurations.booleancontainsPolicies(String key) Maps from policy name to policy.The action to take if a policy matches.intThe action to take if a policy matches.Audit logging options that include the condition for audit logging to happen and audit logger configurations.Audit logging options that include the condition for audit logging to happen and audit logger configurations.private com.google.protobuf.SingleFieldBuilder<RBAC.AuditLoggingOptions, RBAC.AuditLoggingOptions.Builder, RBAC.AuditLoggingOptionsOrBuilder> Audit logging options that include the condition for audit logging to happen and audit logger configurations.Audit logging options that include the condition for audit logging to happen and audit logger configurations.static final com.google.protobuf.Descriptors.Descriptorcom.google.protobuf.Descriptors.DescriptorDeprecated.Deprecated.intMaps from policy name to policy.Maps from policy name to policy.getPoliciesOrDefault(String key, Policy defaultValue) Maps from policy name to policy.getPoliciesOrThrow(String key) Maps from policy name to policy.booleanAudit logging options that include the condition for audit logging to happen and audit logger configurations.protected com.google.protobuf.GeneratedMessage.FieldAccessorTableprotected com.google.protobuf.MapFieldReflectionAccessorinternalGetMapFieldReflection(int number) protected com.google.protobuf.MapFieldReflectionAccessorinternalGetMutableMapFieldReflection(int number) private com.google.protobuf.MapFieldBuilder<String, PolicyOrBuilder, Policy, Policy.Builder> private com.google.protobuf.MapFieldBuilder<String, PolicyOrBuilder, Policy, Policy.Builder> final booleanprivate voidAudit logging options that include the condition for audit logging to happen and audit logger configurations.mergeFrom(com.google.protobuf.CodedInputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry) mergeFrom(com.google.protobuf.Message other) putAllPolicies(Map<String, Policy> values) Maps from policy name to policy.putPolicies(String key, Policy value) Maps from policy name to policy.Maps from policy name to policy.removePolicies(String key) Maps from policy name to policy.setAction(RBAC.Action value) The action to take if a policy matches.setActionValue(int value) The action to take if a policy matches.Audit logging options that include the condition for audit logging to happen and audit logger configurations.setAuditLoggingOptions(RBAC.AuditLoggingOptions.Builder builderForValue) Audit logging options that include the condition for audit logging to happen and audit logger configurations.Methods inherited from class com.google.protobuf.GeneratedMessage.Builder
addRepeatedField, clearField, clearOneof, clone, getAllFields, getField, getFieldBuilder, getOneofFieldDescriptor, getParentForChildren, getRepeatedField, getRepeatedFieldBuilder, getRepeatedFieldCount, getUnknownFields, getUnknownFieldSetBuilder, hasField, hasOneof, internalGetMapField, internalGetMutableMapField, isClean, markClean, mergeUnknownFields, mergeUnknownLengthDelimitedField, mergeUnknownVarintField, newBuilderForField, onBuilt, onChanged, parseUnknownField, setField, setRepeatedField, setUnknownFields, setUnknownFieldSetBuilder, setUnknownFieldsProto3Methods inherited from class com.google.protobuf.AbstractMessage.Builder
findInitializationErrors, getInitializationErrorString, internalMergeFrom, mergeFrom, mergeFrom, mergeFrom, mergeFrom, mergeFrom, mergeFrom, mergeFrom, mergeFrom, mergeFrom, newUninitializedMessageException, toStringMethods inherited from class com.google.protobuf.AbstractMessageLite.Builder
addAll, addAll, mergeDelimitedFrom, mergeDelimitedFrom, mergeFrom, newUninitializedMessageExceptionMethods inherited from class java.lang.Object
equals, finalize, getClass, hashCode, notify, notifyAll, wait, wait, waitMethods inherited from interface com.google.protobuf.Message.Builder
mergeDelimitedFrom, mergeDelimitedFromMethods inherited from interface com.google.protobuf.MessageLite.Builder
mergeFromMethods inherited from interface com.google.protobuf.MessageOrBuilder
findInitializationErrors, getAllFields, getField, getInitializationErrorString, getOneofFieldDescriptor, getRepeatedField, getRepeatedFieldCount, getUnknownFields, hasField, hasOneof
-
Field Details
-
bitField0_
private int bitField0_ -
action_
private int action_ -
policiesConverter
-
policies_
-
auditLoggingOptions_
-
auditLoggingOptionsBuilder_
private com.google.protobuf.SingleFieldBuilder<RBAC.AuditLoggingOptions,RBAC.AuditLoggingOptions.Builder, auditLoggingOptionsBuilder_RBAC.AuditLoggingOptionsOrBuilder>
-
-
Constructor Details
-
Builder
private Builder() -
Builder
private Builder(com.google.protobuf.AbstractMessage.BuilderParent parent)
-
-
Method Details
-
getDescriptor
public static final com.google.protobuf.Descriptors.Descriptor getDescriptor() -
internalGetMapFieldReflection
protected com.google.protobuf.MapFieldReflectionAccessor internalGetMapFieldReflection(int number) - Overrides:
internalGetMapFieldReflectionin classcom.google.protobuf.GeneratedMessage.Builder<RBAC.Builder>
-
internalGetMutableMapFieldReflection
protected com.google.protobuf.MapFieldReflectionAccessor internalGetMutableMapFieldReflection(int number) - Overrides:
internalGetMutableMapFieldReflectionin classcom.google.protobuf.GeneratedMessage.Builder<RBAC.Builder>
-
internalGetFieldAccessorTable
protected com.google.protobuf.GeneratedMessage.FieldAccessorTable internalGetFieldAccessorTable()- Specified by:
internalGetFieldAccessorTablein classcom.google.protobuf.GeneratedMessage.Builder<RBAC.Builder>
-
maybeForceBuilderInitialization
private void maybeForceBuilderInitialization() -
clear
- Specified by:
clearin interfacecom.google.protobuf.Message.Builder- Specified by:
clearin interfacecom.google.protobuf.MessageLite.Builder- Overrides:
clearin classcom.google.protobuf.GeneratedMessage.Builder<RBAC.Builder>
-
getDescriptorForType
public com.google.protobuf.Descriptors.Descriptor getDescriptorForType()- Specified by:
getDescriptorForTypein interfacecom.google.protobuf.Message.Builder- Specified by:
getDescriptorForTypein interfacecom.google.protobuf.MessageOrBuilder- Overrides:
getDescriptorForTypein classcom.google.protobuf.GeneratedMessage.Builder<RBAC.Builder>
-
getDefaultInstanceForType
- Specified by:
getDefaultInstanceForTypein interfacecom.google.protobuf.MessageLiteOrBuilder- Specified by:
getDefaultInstanceForTypein interfacecom.google.protobuf.MessageOrBuilder
-
build
- Specified by:
buildin interfacecom.google.protobuf.Message.Builder- Specified by:
buildin interfacecom.google.protobuf.MessageLite.Builder
-
buildPartial
- Specified by:
buildPartialin interfacecom.google.protobuf.Message.Builder- Specified by:
buildPartialin interfacecom.google.protobuf.MessageLite.Builder
-
buildPartial0
-
mergeFrom
- Specified by:
mergeFromin interfacecom.google.protobuf.Message.Builder- Overrides:
mergeFromin classcom.google.protobuf.AbstractMessage.Builder<RBAC.Builder>
-
mergeFrom
-
isInitialized
public final boolean isInitialized()- Specified by:
isInitializedin interfacecom.google.protobuf.MessageLiteOrBuilder- Overrides:
isInitializedin classcom.google.protobuf.GeneratedMessage.Builder<RBAC.Builder>
-
mergeFrom
public RBAC.Builder mergeFrom(com.google.protobuf.CodedInputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry) throws IOException - Specified by:
mergeFromin interfacecom.google.protobuf.Message.Builder- Specified by:
mergeFromin interfacecom.google.protobuf.MessageLite.Builder- Overrides:
mergeFromin classcom.google.protobuf.AbstractMessage.Builder<RBAC.Builder>- Throws:
IOException
-
getActionValue
public int getActionValue()The action to take if a policy matches. Every action either allows or denies a request, and can also carry out action-specific operations. Actions: * ``ALLOW``: Allows the request if and only if there is a policy that matches the request. * ``DENY``: Allows the request if and only if there are no policies that match the request. * ``LOG``: Allows all requests. If at least one policy matches, the dynamic metadata key ``access_log_hint`` is set to the value ``true`` under the shared key namespace ``envoy.common``. If no policies match, it is set to ``false``. Other actions do not modify this key.
.envoy.config.rbac.v3.RBAC.Action action = 1 [(.validate.rules) = { ... }- Specified by:
getActionValuein interfaceRBACOrBuilder- Returns:
- The enum numeric value on the wire for action.
-
setActionValue
The action to take if a policy matches. Every action either allows or denies a request, and can also carry out action-specific operations. Actions: * ``ALLOW``: Allows the request if and only if there is a policy that matches the request. * ``DENY``: Allows the request if and only if there are no policies that match the request. * ``LOG``: Allows all requests. If at least one policy matches, the dynamic metadata key ``access_log_hint`` is set to the value ``true`` under the shared key namespace ``envoy.common``. If no policies match, it is set to ``false``. Other actions do not modify this key.
.envoy.config.rbac.v3.RBAC.Action action = 1 [(.validate.rules) = { ... }- Parameters:
value- The enum numeric value on the wire for action to set.- Returns:
- This builder for chaining.
-
getAction
The action to take if a policy matches. Every action either allows or denies a request, and can also carry out action-specific operations. Actions: * ``ALLOW``: Allows the request if and only if there is a policy that matches the request. * ``DENY``: Allows the request if and only if there are no policies that match the request. * ``LOG``: Allows all requests. If at least one policy matches, the dynamic metadata key ``access_log_hint`` is set to the value ``true`` under the shared key namespace ``envoy.common``. If no policies match, it is set to ``false``. Other actions do not modify this key.
.envoy.config.rbac.v3.RBAC.Action action = 1 [(.validate.rules) = { ... }- Specified by:
getActionin interfaceRBACOrBuilder- Returns:
- The action.
-
setAction
The action to take if a policy matches. Every action either allows or denies a request, and can also carry out action-specific operations. Actions: * ``ALLOW``: Allows the request if and only if there is a policy that matches the request. * ``DENY``: Allows the request if and only if there are no policies that match the request. * ``LOG``: Allows all requests. If at least one policy matches, the dynamic metadata key ``access_log_hint`` is set to the value ``true`` under the shared key namespace ``envoy.common``. If no policies match, it is set to ``false``. Other actions do not modify this key.
.envoy.config.rbac.v3.RBAC.Action action = 1 [(.validate.rules) = { ... }- Parameters:
value- The action to set.- Returns:
- This builder for chaining.
-
clearAction
The action to take if a policy matches. Every action either allows or denies a request, and can also carry out action-specific operations. Actions: * ``ALLOW``: Allows the request if and only if there is a policy that matches the request. * ``DENY``: Allows the request if and only if there are no policies that match the request. * ``LOG``: Allows all requests. If at least one policy matches, the dynamic metadata key ``access_log_hint`` is set to the value ``true`` under the shared key namespace ``envoy.common``. If no policies match, it is set to ``false``. Other actions do not modify this key.
.envoy.config.rbac.v3.RBAC.Action action = 1 [(.validate.rules) = { ... }- Returns:
- This builder for chaining.
-
internalGetPolicies
private com.google.protobuf.MapFieldBuilder<String,PolicyOrBuilder, internalGetPolicies()Policy, Policy.Builder> -
internalGetMutablePolicies
private com.google.protobuf.MapFieldBuilder<String,PolicyOrBuilder, internalGetMutablePolicies()Policy, Policy.Builder> -
getPoliciesCount
public int getPoliciesCount()Description copied from interface:RBACOrBuilderMaps from policy name to policy. A match occurs when at least one policy matches the request. The policies are evaluated in lexicographic order of the policy name.
map<string, .envoy.config.rbac.v3.Policy> policies = 2;- Specified by:
getPoliciesCountin interfaceRBACOrBuilder
-
containsPolicies
Maps from policy name to policy. A match occurs when at least one policy matches the request. The policies are evaluated in lexicographic order of the policy name.
map<string, .envoy.config.rbac.v3.Policy> policies = 2;- Specified by:
containsPoliciesin interfaceRBACOrBuilder
-
getPolicies
Deprecated.UsegetPoliciesMap()instead.- Specified by:
getPoliciesin interfaceRBACOrBuilder
-
getPoliciesMap
Maps from policy name to policy. A match occurs when at least one policy matches the request. The policies are evaluated in lexicographic order of the policy name.
map<string, .envoy.config.rbac.v3.Policy> policies = 2;- Specified by:
getPoliciesMapin interfaceRBACOrBuilder
-
getPoliciesOrDefault
Maps from policy name to policy. A match occurs when at least one policy matches the request. The policies are evaluated in lexicographic order of the policy name.
map<string, .envoy.config.rbac.v3.Policy> policies = 2;- Specified by:
getPoliciesOrDefaultin interfaceRBACOrBuilder
-
getPoliciesOrThrow
Maps from policy name to policy. A match occurs when at least one policy matches the request. The policies are evaluated in lexicographic order of the policy name.
map<string, .envoy.config.rbac.v3.Policy> policies = 2;- Specified by:
getPoliciesOrThrowin interfaceRBACOrBuilder
-
clearPolicies
-
removePolicies
Maps from policy name to policy. A match occurs when at least one policy matches the request. The policies are evaluated in lexicographic order of the policy name.
map<string, .envoy.config.rbac.v3.Policy> policies = 2; -
getMutablePolicies
Deprecated.Use alternate mutation accessors instead. -
putPolicies
Maps from policy name to policy. A match occurs when at least one policy matches the request. The policies are evaluated in lexicographic order of the policy name.
map<string, .envoy.config.rbac.v3.Policy> policies = 2; -
putAllPolicies
Maps from policy name to policy. A match occurs when at least one policy matches the request. The policies are evaluated in lexicographic order of the policy name.
map<string, .envoy.config.rbac.v3.Policy> policies = 2; -
putPoliciesBuilderIfAbsent
Maps from policy name to policy. A match occurs when at least one policy matches the request. The policies are evaluated in lexicographic order of the policy name.
map<string, .envoy.config.rbac.v3.Policy> policies = 2; -
hasAuditLoggingOptions
public boolean hasAuditLoggingOptions()Audit logging options that include the condition for audit logging to happen and audit logger configurations. [#not-implemented-hide:]
.envoy.config.rbac.v3.RBAC.AuditLoggingOptions audit_logging_options = 3;- Specified by:
hasAuditLoggingOptionsin interfaceRBACOrBuilder- Returns:
- Whether the auditLoggingOptions field is set.
-
getAuditLoggingOptions
Audit logging options that include the condition for audit logging to happen and audit logger configurations. [#not-implemented-hide:]
.envoy.config.rbac.v3.RBAC.AuditLoggingOptions audit_logging_options = 3;- Specified by:
getAuditLoggingOptionsin interfaceRBACOrBuilder- Returns:
- The auditLoggingOptions.
-
setAuditLoggingOptions
Audit logging options that include the condition for audit logging to happen and audit logger configurations. [#not-implemented-hide:]
.envoy.config.rbac.v3.RBAC.AuditLoggingOptions audit_logging_options = 3; -
setAuditLoggingOptions
Audit logging options that include the condition for audit logging to happen and audit logger configurations. [#not-implemented-hide:]
.envoy.config.rbac.v3.RBAC.AuditLoggingOptions audit_logging_options = 3; -
mergeAuditLoggingOptions
Audit logging options that include the condition for audit logging to happen and audit logger configurations. [#not-implemented-hide:]
.envoy.config.rbac.v3.RBAC.AuditLoggingOptions audit_logging_options = 3; -
clearAuditLoggingOptions
Audit logging options that include the condition for audit logging to happen and audit logger configurations. [#not-implemented-hide:]
.envoy.config.rbac.v3.RBAC.AuditLoggingOptions audit_logging_options = 3; -
getAuditLoggingOptionsBuilder
Audit logging options that include the condition for audit logging to happen and audit logger configurations. [#not-implemented-hide:]
.envoy.config.rbac.v3.RBAC.AuditLoggingOptions audit_logging_options = 3; -
getAuditLoggingOptionsOrBuilder
Audit logging options that include the condition for audit logging to happen and audit logger configurations. [#not-implemented-hide:]
.envoy.config.rbac.v3.RBAC.AuditLoggingOptions audit_logging_options = 3;- Specified by:
getAuditLoggingOptionsOrBuilderin interfaceRBACOrBuilder
-
getAuditLoggingOptionsFieldBuilder
private com.google.protobuf.SingleFieldBuilder<RBAC.AuditLoggingOptions,RBAC.AuditLoggingOptions.Builder, getAuditLoggingOptionsFieldBuilder()RBAC.AuditLoggingOptionsOrBuilder> Audit logging options that include the condition for audit logging to happen and audit logger configurations. [#not-implemented-hide:]
.envoy.config.rbac.v3.RBAC.AuditLoggingOptions audit_logging_options = 3;
-