303. Range Sum Query - Immutable [Leetcode]

本文介绍了一种使用前缀和数组优化区间和查询的方法。通过预处理整数数组的累积和,可以快速计算任意两个索引之间的元素总和,适用于数组不变而查询频繁的场景。

Problem


Given an integer array nums, find the sum of the elements between indices i and j (i ≤ j), inclusive.

Example:

Given nums = [-2, 0, 3, -5, 2, -1]

sumRange(0, 2) -> 1
sumRange(2, 5) -> -1
sumRange(0, 5) -> -3

Note:

  1. You may assume that the array does not change.
  2. There are many calls to sumRange function.


Solution

想到用另外一个同样大小的数组 sumArr[N] , 每个元素 summArr[ i ] 表示从 0 到 i (inclusive)的和。
这样求 i 到 j 的和,就是  sumArr[ j ] - sumsArr[ i -1]

class NumArray {
    vector<int> sumArr;
public:
    NumArray(vector<int> &nums)  {
        const int N = nums.size();
        sumArr.resize( N, 0);
        if(N > 0){
            sumArr[0] = nums[0];
            for( int i = 1; i < N; i++){
                sumArr[i] = sumArr[i-1] + nums[i];
            }
        }
    }

    int sumRange(int i, int j) {
        if( i == 0) return sumArr[j];
        return sumArr[j] - sumArr[i - 1];
    }
};


// Your NumArray object will be instantiated and called as such:
// NumArray numArray(nums);
// numArray.sumRange(0, 1);
// numArray.sumRange(1, 2);


再來是 2) 基礎 VAP/VAPB 範本(與 Kyverno 規則等價) 說明: - labels-required:要求 Namespace 與核心工作負載具備指定 labels - immutable-namespace-meta:foundation 類命名空間 metadata 不可變更(名稱/關鍵標籤/註解) - require-signed-images:要求容器鏡像已簽章,使用 cosign 公鑰驗證(Admission 查驗 annotation/驗證報告) 2-1. labels-required.policy.yaml ```yaml apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingAdmissionPolicy metadata: name: labels-required labels: app.kubernetes.io/part-of: platform-governance app.kubernetes.io/component: policies spec: failurePolicy: Fail matchConstraints: resourceRules: - apiGroups: [""] apiVersions: ["v1"] operations: ["CREATE","UPDATE"] resources: ["namespaces"] - apiGroups: [""] apiVersions: ["v1"] operations: ["CREATE","UPDATE"] resources: ["pods"] validations: - expression: "has(object.metadata.labels) && has(object.metadata.labels[\"namespace.io/team\"])" message: "Missing required label: namespace.io/team" - expression: "has(object.metadata.labels) && has(object.metadata.labels[\"namespace.io/environment\"])" message: "Missing required label: namespace.io/environment" - expression: "has(object.metadata.labels) && has(object.metadata.labels[\"namespace.io/lifecycle\"])" message: "Missing required label: namespace.io/lifecycle" auditAnnotations: - key: governance/labels-required value: "checked" ``` 2-2. labels-required.binding.yaml ```yaml apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingAdmissionPolicyBinding metadata: name: labels-required-binding spec: policyName: labels-required validationActions: [Warn] # 將由 overlays 覆寫為 Warn/Audit/Deny matchResources: namespaceSelector: {} # 全域套用;可由 overlays 覆寫 ``` 2-3. immutable-namespace-meta.policy.yaml ```yaml apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingAdmissionPolicy metadata: name: immutable-namespace-meta labels: app.kubernetes.io/part-of: platform-governance app.kubernetes.io/component: policies spec: failurePolicy: Fail matchConstraints: resourceRules: - apiGroups: [""] apiVersions: ["v1"] operations: ["UPDATE","DELETE"] resources: ["namespaces"] validations: - expression: "!(oldObject.metadata.name in [\"foundation\",\"platform\",\"infra\"]) || (object.metadata.name == oldObject.metadata.name)" message: "Core namespace name must not change" - expression: "!(oldObject.metadata.name in [\"foundation\",\"platform\",\"infra\"]) || (object.metadata.labels == oldObject.metadata.labels)" message: "Core namespace labels are immutable" - expression: "!(oldObject.metadata.name in [\"foundation\",\"platform\",\"infra\"]) || (object.metadata.annotations == oldObject.metadata.annotations)" message: "Core namespace annotations are immutable" auditAnnotations: - key: governance/immutable-namespace-meta value: "checked" ``` 2-4. immutable-namespace-meta.binding.yaml ```yaml apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingAdmissionPolicyBinding metadata: name: immutable-namespace-meta-binding spec: policyName: immutable-namespace-meta validationActions: [Deny] # overlays 可覆寫 matchResources: namespaceSelector: {} ``` 2-5. require-signed-images.policy.yaml 說明: - 這裡示範以 image annotation 或 OCI subject annotation 作為簡化檢查條件。若您要真實串接 cosign 驗證,建議接 Admission Webhook 或使用 ImagePolicy(KEP-3299)/Kyverno verifyImages 的旁路結果。此處為與「Kyverno require-signed-images」等價邏輯的近似版:要求工作負載標註 signed=true 或帶有特定 attestation 註記。稍後可接實際驗證器。 ```yaml apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingAdmissionPolicy metadata: name: require-signed-images labels: app.kubernetes.io/part-of: platform-governance app.kubernetes.io/component: policies spec: failurePolicy: Fail matchConstraints: resourceRules: - apiGroups: ["apps"] apiVersions: ["v1"] operations: ["CREATE","UPDATE"] resources: ["deployments","statefulsets","daemonsets"] - apiGroups: [""] apiVersions: ["v1"] operations: ["CREATE","UPDATE"] resources: ["pods"] paramKind: apiVersion: v1 kind: ConfigMap # 以 ConfigMap 提供 cosign 公鑰/策略參數 validations: - expression: | has(object.spec) && ( has(object.spec.template) ? has(object.spec.template.metadata.annotations["supplychain.signed"]) && object.spec.template.metadata.annotations["supplychain.signed"] == "true" : has(object.metadata.annotations["supplychain.signed"]) && object.metadata.annotations["supplychain.signed"] == "true" ) message: "Image must be signed: add annotation supplychain.signed=true after cosign verification" # 如需更嚴格:校驗指定 registry 或 digest 格式 - expression: | has(object.spec) && ( has(object.spec.template) ? size(object.spec.template.spec.containers) > 0 : has(object.spec.containers) && size(object.spec.containers) > 0 ) message: "Workload must define at least one container" auditAnnotations: - key: governance/require-signed-images value: "checked" ``` 2-6. require-signed-images.binding.yaml ```yaml apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingAdmissionPolicyBinding metadata: name: require-signed-images-binding spec: policyName: require-signed-images validationActions: [Warn] # overlays 調整:dev=Warn, staging=Audit, prod=Deny matchResources: namespaceSelector: {} # 參數化:綁定 ConfigMap 作為參數(例如提供 cosign 公鑰/策略) params: name: cosign-root-keys namespace: governance-system ``` 3) overlays:dev/staging/prod 差異化 validationActions 每個 overlay 僅對 Binding 做 patches(保持 policy 穩定不動),並可選擇性限制套用範圍(namespaceSelector)或豁免特定 namespaces。 3-1. overlays/dev/kustomization.yaml ```yaml apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - ../../base/labels-required.policy.yaml - ../../base/labels-required.binding.yaml - ../../base/immutable-namespace-meta.policy.yaml - ../../base/immutable-namespace-meta.binding.yaml - ../../base/require-signed-images.policy.yaml - ../../base/require-signed-images.binding.yaml patches: - target: kind: ValidatingAdmissionPolicyBinding name: labels-required-binding patch: | - op: replace path: /spec/validationActions value: ["Warn"] - target: kind: ValidatingAdmissionPolicyBinding name: require-signed-images-binding patch: | - op: replace path: /spec/validationActions value: ["Warn"] - target: kind: ValidatingAdmissionPolicyBinding name: immutable-namespace-meta-binding patch: | - op: replace path: /spec/validationActions value: ["Audit"] # 觀察期,避免阻斷 ``` 3-2. overlays/staging/kustomization.yaml ```yaml apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - ../../base/labels-required.policy.yaml - ../../base/labels-required.binding.yaml - ../../base/immutable-namespace-meta.policy.yaml - ../../base/immutable-namespace-meta.binding.yaml - ../../base/require-signed-images.policy.yaml - ../../base/require-signed-images.binding.yaml patches: - target: kind: ValidatingAdmissionPolicyBinding name: labels-required-binding patch: | - op: replace path: /spec/validationActions value: ["Audit"] - target: kind: ValidatingAdmissionPolicyBinding name: require-signed-images-binding patch: | - op: replace path: /spec/validationActions value: ["Audit"] - target: kind: ValidatingAdmissionPolicyBinding name: immutable-namespace-meta-binding patch: | - op: replace path: /spec/validationActions value: ["Deny"] ``` 3-3. overlays/prod/kustomization.yaml ```yaml apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - ../../base/labels-required.policy.yaml - ../../base/labels-required.binding.yaml - ../../base/immutable-namespace-meta.policy.yaml - ../../base/immutable-namespace-meta.binding.yaml - ../../base/require-signed-images.policy.yaml - ../../base/require-signed-images.binding.yaml patches: - target: kind: ValidatingAdmissionPolicyBinding name: labels-required-binding patch: | - op: replace path: /spec/validationActions value: ["Deny"] - target: kind: ValidatingAdmissionPolicyBinding name: require-signed-images-binding patch: | - op: replace path: /spec/validationActions value: ["Deny"] - target: kind: ValidatingAdmissionPolicyBinding name: immutable-namespace-meta-binding patch: | - op: replace path: /spec/validationActions value: ["Deny"]
10-30
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值