A collection of example Kuadrant policy extensions,
showing how to implement, build, and deploy a Kuadrant extension using the
Extension SDK
provided by kuadrant-operator.
A Kuadrant extension defines a new policy CRD (e.g. ThreatPolicy) that
targets Gateway API resources (Gateway, HTTPRoute) and, on reconcile,
registers HTTP request/response behavior with the Kuadrant operator over
gRPC. The extension runs as its own controller process, separate from the
operator itself.
Extensions in this repo are meant to be read as reference material - each one is a small, complete, runnable example rather than a library.
Each extension lives in its own top-level directory and is a standalone Go module:
example-extensions/
└── threat-policy/ # example extension
├── go.mod
├── main.go
├── Dockerfile
├── Makefile
├── api/v1alpha1/ # CRD Go types
├── internal/controller/ # reconciler
└── config/
├── crd/ # generated CRD manifests
├── rbac/ # ClusterRole for the extension's own resources
└── deploy/ # kustomize bases for deploying the extension
An extension is laid out like an ordinary kubebuilder/ controller-runtime project, and the pieces will look familiar if you've worked with one:
api/v1alpha1/- the policy CRD's Go types and scheme registration boilerplate, generated withcontroller-genthe same way as any kubebuilder API package.internal/controller/- the reconciler for the policy type.config/crd/andconfig/rbac/- generated CRD and RBAC manifests, produced withmake manifestsas usual.main.go- wires up the scheme and starts the controller.config/deploy/- kustomize bases for running the extension (see Deploying, below).Dockerfile/Makefile- build the extension binary/image.
Where it differs from a plain kubebuilder project is in how the reconciler is
built and how it talks to Kuadrant: rather than a controller-runtime.Manager
reconciling directly against the cluster, the reconciler is wired up through
kuadrant-operator's Extension SDK
(source: pkg/extension),
which supplies the Reconcile entrypoint and a KuadrantCtx for registering
gRPC-backed action methods and request/response pipelines against the target
Gateway/HTTPRoute. See the SDK developer guide for details -
threat-policy's internal/controller/threatpolicy_reconciler.go is a
worked example of using it.
This repo isn't a framework you install a dependency on - it's reference
material. To build your own extension, copy threat-policy/ (or the layout
above) into your own project and adapt it.
An extension runs as its own Deployment, with its own ServiceAccount, and
authenticates to the Kuadrant operator's extension gRPC service using a
projected ServiceAccount token.
Prerequisites:
- A cluster with the Kuadrant operator v1.6.0 or newer installed and running
in the
kuadrant-systemnamespace, with its extensions gRPC service reachable atkuadrant-operator-extensions.kuadrant-system.svc:50052. - Gateway API CRDs installed.
Steps (from an extension's directory, e.g. threat-policy/):
-
Build and publish the extension image (or load it into the cluster directly, e.g.
kind load docker-imagefor a local kind cluster):make docker-build
-
Apply the deploy overlay:
kubectl apply -k config/deploy/standalone
This creates, in order:
- the extension's namespace (e.g.
threat-policy-system) andServiceAccount; - the extension's own CRD (
config/crd) andClusterRole(config/rbac), bound to thatServiceAccount; - a
ClusterRole/ClusterRoleBindinggranting theregisterverb onpolicyregistrationsfor this policy kind, so the operator accepts the extension registering itself; - the extension
Deployment, which mounts a projectedServiceAccounttoken (audiencekuadrant-extensions) and pointsKUADRANT_EXTENSION_ADDRESSat the operator's extensions service; - a
NetworkPolicyinkuadrant-systemallowing ingress from the extension's pods to the operator's controller-manager on port50052.
- the extension's namespace (e.g.
-
Create an instance of the policy CRD targeting a
GatewayorHTTPRoute, and check itsstatus.conditionsforAccepted/Enforced.