You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OPA/Conftest解析含点号的ResourceQuota YAML文件异常问题

ResourceQuota带点号limits键的Rego规则取值异常问题

在编写OPA Rego规则校验ResourceQuota的内存限制单位时,会遇到一个典型问题:当ResourceQuota使用K8s官方支持的带点号的键名格式(如limits.memory)时,规则无法正确读取对应值,导致校验逻辑失效;只有使用K8s不支持的嵌套limits结构时,规则才会按预期触发校验。

问题Rego规则(policy.rego)

package main

deny_incorrect_memory_unit[msg] {
  input.kind == "ResourceQuota"
  memoryLimit := input.spec.hard.limits.memory

  not regex.match("^[0-9]+M$", memoryLimit)
  msg := sprintf("%s: 内存限制值%s格式错误。ResourceQuota的内存限制必须使用兆字节(M)作为单位", [input.metadata.namespace, memoryLimit])
}

K8s官方支持的ResourceQuota定义(resource-quota.yaml)

apiVersion: v1
kind: ResourceQuota
metadata:
  name: app
  namespace: backend
spec:
  hard:
    pods: 1
    limits.cpu: 3
    limits.memory: "1G"

问题现象

上述示例中,limits.memory使用了不符合要求的1G单位,但Rego规则校验未触发拒绝(显示校验通过);只有将spec.hard改为K8s不支持的嵌套结构时,规则才会识别到错误单位并按预期输出拒绝信息:

spec:
  hard:
    pods: 1
    limits:
        cpu: 3
        memory: "1G"

内容的提问来源于stack exchange,提问作者Kucharsky

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 12:05:00