mirror of
https://github.com/aquasecurity/trivy.git
synced 2025-12-22 07:10:41 -08:00
62 lines
1.5 KiB
Go
62 lines
1.5 KiB
Go
package commands
|
|
|
|
import (
|
|
"strings"
|
|
|
|
"github.com/urfave/cli/v2"
|
|
"golang.org/x/xerrors"
|
|
|
|
"github.com/aquasecurity/trivy-kubernetes/pkg/artifacts"
|
|
"github.com/aquasecurity/trivy-kubernetes/pkg/k8s"
|
|
"github.com/aquasecurity/trivy-kubernetes/pkg/trivyk8s"
|
|
cmd "github.com/aquasecurity/trivy/pkg/commands/artifact"
|
|
"github.com/aquasecurity/trivy/pkg/log"
|
|
)
|
|
|
|
// resourceRun runs scan on kubernetes cluster
|
|
func resourceRun(cliCtx *cli.Context, opt cmd.Option, cluster k8s.Cluster) error {
|
|
kind, name, err := extractKindAndName(cliCtx.Args().Slice())
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
trivyk8s := trivyk8s.New(cluster, log.Logger).Namespace(getNamespace(opt, cluster.GetCurrentNamespace()))
|
|
|
|
if len(name) == 0 { // pods or configmaps etc
|
|
if err := validateReportArguments(cliCtx); err != nil {
|
|
return err
|
|
}
|
|
|
|
targets, err := trivyk8s.Resources(kind).ListArtifacts(cliCtx.Context)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
return run(cliCtx.Context, opt, cluster.GetCurrentContext(), targets)
|
|
}
|
|
|
|
// pod/NAME or pod NAME etc
|
|
artifact, err := trivyk8s.GetArtifact(cliCtx.Context, kind, name)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
return run(cliCtx.Context, opt, cluster.GetCurrentContext(), []*artifacts.Artifact{artifact})
|
|
}
|
|
|
|
func extractKindAndName(args []string) (string, string, error) {
|
|
switch len(args) {
|
|
case 1:
|
|
s := strings.Split(args[0], "/")
|
|
if len(s) != 2 {
|
|
return args[0], "", nil
|
|
}
|
|
|
|
return s[0], s[1], nil
|
|
case 2:
|
|
return args[0], args[1], nil
|
|
}
|
|
|
|
return "", "", xerrors.Errorf("can't parse arguments %v. Please run `trivy k8s` for usage.", args)
|
|
}
|