1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
use super::Result;
#[derive(Serialize, Deserialize, Debug, Clone)]
#[cfg_attr(feature = "filesystem", serde(deny_unknown_fields))]
pub struct Rbac {
pub apiGroups: Vec<String>,
pub resources: Vec<String>,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub resourceNames: Vec<String>,
pub verbs: Vec<String>,
}
impl Rbac {
pub fn verify(&self) -> Result<()> {
if self.apiGroups.is_empty() {
bail!("RBAC needs to have at least one item in apiGroups");
}
if self.resources.is_empty() {
bail!("RBAC needs to have at least one item in resources");
}
if self.verbs.is_empty() {
bail!("RBAC needs to have at least one item in verbs");
}
Ok(())
}
}