Gracefully handle broken base64 policies in non-diff mode#64
Merged
Conversation
hgarvison
approved these changes
Sep 20, 2024
hgarvison
approved these changes
Sep 27, 2024
b290a0c to
99c04fd
Compare
SethHollandsworth
pushed a commit
that referenced
this pull request
Nov 5, 2024
* handle broken base64 * address style fixes
SethHollandsworth
added a commit
that referenced
this pull request
Nov 11, 2024
* read only logic for some mount types (#62) * offloading error checking and updating tests * Gracefully handle broken base64 policies in non-diff mode (#64) * handle broken base64 * address style fixes * adding flag to omit ID from policy * adding ability to not use sidecars via ARM tag * adding workload identity support for vn2 * Add user prompt to confirm policy overwrite for VN2 YAMLs * support for image attached fragments * updating locations where executables are found * updating version to 1.1.0 * updating test value * taking out unused dependency * fixing errors in docs and types * getting rid of whitespace * updating kata tests for linux * updating kata tests for windows * can't have binary files --------- Co-authored-by: Khalil Sayid <30742855+ksayid@users.noreply.github.com> Co-authored-by: Khalil Sayid <khalilsayid@microsoft.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previously, broken base64 policies in the ARM template or YAML caused the tool to exit unconditionally, even when generating a new policy without diff mode.
Now:
Explored a few approaches, but after talking with Seth, landed on this one:
base64_to_str) and handle them at a higher level (e.g.,load_policy_from_arm_template_strandload_policy_from_virtual_node_yaml_str)diff_mode. high-level functions decide how to handle the error (e.g., ignore in non-diff mode, exit in diff mode).Other explored ideas:
diff_modedown to utility functionsdiff_modeflag down to functions likedecompose_confidential_propertiesandbase64_to_strto handle errors differently based on the mode.decompose_confidential_propertiesandextract_confidential_propertiesTested manually and with


azdev test confcomandazdev style confcom