Struct gapi_grpc::google::cloud::binaryauthorization::v1beta1::Policy[][src]

pub struct Policy {
    pub name: String,
    pub description: String,
    pub global_policy_evaluation_mode: i32,
    pub admission_whitelist_patterns: Vec<AdmissionWhitelistPattern>,
    pub cluster_admission_rules: HashMap<String, AdmissionRule>,
    pub default_admission_rule: Option<AdmissionRule>,
    pub update_time: Option<Timestamp>,
}

A [policy][google.cloud.binaryauthorization.v1beta1.Policy] for container image binary authorization.

Fields

name: String

Output only. The resource name, in the format projects/*/policy. There is at most one policy per project.

description: String

Optional. A descriptive comment.

global_policy_evaluation_mode: i32

Optional. Controls the evaluation of a Google-maintained global admission policy for common system-level images. Images not covered by the global policy will be subject to the project admission policy. This setting has no effect when specified inside a global admission policy.

admission_whitelist_patterns: Vec<AdmissionWhitelistPattern>

Optional. Admission policy allowlisting. A matching admission request will always be permitted. This feature is typically used to exclude Google or third-party infrastructure images from Binary Authorization policies.

cluster_admission_rules: HashMap<String, AdmissionRule>

Optional. Per-cluster admission rules. Cluster spec format: location.clusterId. There can be at most one admission rule per cluster spec. A location is either a compute zone (e.g. us-central1-a) or a region (e.g. us-central1). For clusterId syntax restrictions see https://cloud.google.com/container-engine/reference/rest/v1/projects.zones.clusters.

default_admission_rule: Option<AdmissionRule>

Required. Default admission rule for a cluster without a per-cluster, per- kubernetes-service-account, or per-istio-service-identity admission rule.

update_time: Option<Timestamp>

Output only. Time when the policy was last updated.

Implementations

impl Policy[src]

pub fn global_policy_evaluation_mode(&self) -> GlobalPolicyEvaluationMode[src]

Returns the enum value of global_policy_evaluation_mode, or the default if the field is set to an invalid enum value.

pub fn set_global_policy_evaluation_mode(
    &mut self,
    value: GlobalPolicyEvaluationMode
)
[src]

Sets global_policy_evaluation_mode to the provided enum value.

Trait Implementations

impl Clone for Policy[src]

impl Debug for Policy[src]

impl Default for Policy[src]

impl Message for Policy[src]

impl PartialEq<Policy> for Policy[src]

impl StructuralPartialEq for Policy[src]

Auto Trait Implementations

impl RefUnwindSafe for Policy

impl Send for Policy

impl Sync for Policy

impl Unpin for Policy

impl UnwindSafe for Policy

Blanket Implementations

impl<T> Any for T where
    T: 'static + ?Sized
[src]

impl<T> Borrow<T> for T where
    T: ?Sized
[src]

impl<T> BorrowMut<T> for T where
    T: ?Sized
[src]

impl<T> From<T> for T[src]

impl<T> Instrument for T[src]

impl<T> Instrument for T[src]

impl<T, U> Into<U> for T where
    U: From<T>, 
[src]

impl<T> IntoRequest<T> for T[src]

impl<T> ToOwned for T where
    T: Clone
[src]

type Owned = T

The resulting type after obtaining ownership.

impl<T, U> TryFrom<U> for T where
    U: Into<T>, 
[src]

type Error = Infallible

The type returned in the event of a conversion error.

impl<T, U> TryInto<U> for T where
    U: TryFrom<T>, 
[src]

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.

impl<V, T> VZip<V> for T where
    V: MultiLane<T>, 
[src]

impl<T> WithSubscriber for T[src]