[LC] 304. Range Sum Query 2D - Immutable

本文介绍了一种高效的矩阵区间求和算法,通过预计算辅助二维数组,实现快速查询矩阵中任意子区域的元素总和。算法核心在于利用累积和的思想,避免重复计算,大幅提高查询效率。

这题做法其实就很简单了。如果说我们有一个辅助二维数组f(n, n),其中任意f(i, j)是从matrix(0, 0)到matrix(i, j)的矩阵的和

那么这一题subRegion(row1, col1, row2, col2)其实就是f(row2, col2)这个矩阵,减去f(row1, col2)这个矩阵,再减去f(row2, col1)这个矩阵,最后加上f(row1, col1)这个被重复减去了两次的矩阵就可以了。注意一下row1 = 0 或者 col1 = 0的edge case就可以了。

根据上面描述,给出代码如下:

    private int[][] _calculated;
    
    public NumMatrix(int[][] matrix) {
        if (matrix.length == 0 || matrix[0].length == 0) return;
        
        this._calculated = new int[matrix.length][matrix[0].length];
        for (int i = 0; i < matrix.length; i++) {
            int curRowSum = 0;
            for (int j = 0; j < matrix[i].length; j++) {
                curRowSum += matrix[i][j];
                this._calculated[i][j] = curRowSum;
                if (i > 0) this._calculated[i][j] += this._calculated[i - 1][j]; 
            }            
        }
    }
    
    public int sumRegion(int row1, int col1, int row2, int col2) {
        int rightTop = this._calculated[row2][col2];
        int rightBot = row1 > 0 ? this._calculated[row1 - 1][col2] : 0;
        int leftTop = col1 > 0 ? this._calculated[row2][col1 - 1] : 0;
        int leftBot = row1 > 0 && col1 > 0 ? this._calculated[row1 - 1][col1 - 1] : 0;
        return rightTop - leftTop - rightBot + leftBot;
    }

 

再來是 2) 基礎 VAP/VAPB 範本(與 Kyverno 規則等價) 說明: - labels-required:要求 Namespace 與核心工作負載具備指定 labels - immutable-namespace-meta:foundation 類命名空間 metadata 不可變更(名稱/關鍵標籤/註解) - require-signed-images:要求容器鏡像已簽章,使用 cosign 公鑰驗證(Admission 查驗 annotation/驗證報告) 2-1. labels-required.policy.yaml ```yaml apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingAdmissionPolicy metadata: name: labels-required labels: app.kubernetes.io/part-of: platform-governance app.kubernetes.io/component: policies spec: failurePolicy: Fail matchConstraints: resourceRules: - apiGroups: [""] apiVersions: ["v1"] operations: ["CREATE","UPDATE"] resources: ["namespaces"] - apiGroups: [""] apiVersions: ["v1"] operations: ["CREATE","UPDATE"] resources: ["pods"] validations: - expression: "has(object.metadata.labels) && has(object.metadata.labels[\"namespace.io/team\"])" message: "Missing required label: namespace.io/team" - expression: "has(object.metadata.labels) && has(object.metadata.labels[\"namespace.io/environment\"])" message: "Missing required label: namespace.io/environment" - expression: "has(object.metadata.labels) && has(object.metadata.labels[\"namespace.io/lifecycle\"])" message: "Missing required label: namespace.io/lifecycle" auditAnnotations: - key: governance/labels-required value: "checked" ``` 2-2. labels-required.binding.yaml ```yaml apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingAdmissionPolicyBinding metadata: name: labels-required-binding spec: policyName: labels-required validationActions: [Warn] # 將由 overlays 覆寫為 Warn/Audit/Deny matchResources: namespaceSelector: {} # 全域套用;可由 overlays 覆寫 ``` 2-3. immutable-namespace-meta.policy.yaml ```yaml apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingAdmissionPolicy metadata: name: immutable-namespace-meta labels: app.kubernetes.io/part-of: platform-governance app.kubernetes.io/component: policies spec: failurePolicy: Fail matchConstraints: resourceRules: - apiGroups: [""] apiVersions: ["v1"] operations: ["UPDATE","DELETE"] resources: ["namespaces"] validations: - expression: "!(oldObject.metadata.name in [\"foundation\",\"platform\",\"infra\"]) || (object.metadata.name == oldObject.metadata.name)" message: "Core namespace name must not change" - expression: "!(oldObject.metadata.name in [\"foundation\",\"platform\",\"infra\"]) || (object.metadata.labels == oldObject.metadata.labels)" message: "Core namespace labels are immutable" - expression: "!(oldObject.metadata.name in [\"foundation\",\"platform\",\"infra\"]) || (object.metadata.annotations == oldObject.metadata.annotations)" message: "Core namespace annotations are immutable" auditAnnotations: - key: governance/immutable-namespace-meta value: "checked" ``` 2-4. immutable-namespace-meta.binding.yaml ```yaml apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingAdmissionPolicyBinding metadata: name: immutable-namespace-meta-binding spec: policyName: immutable-namespace-meta validationActions: [Deny] # overlays 可覆寫 matchResources: namespaceSelector: {} ``` 2-5. require-signed-images.policy.yaml 說明: - 這裡示範以 image annotation 或 OCI subject annotation 作為簡化檢查條件。若您要真實串接 cosign 驗證,建議接 Admission Webhook 或使用 ImagePolicy(KEP-3299)/Kyverno verifyImages 的旁路結果。此處為與「Kyverno require-signed-images」等價邏輯的近似版:要求工作負載標註 signed=true 或帶有特定 attestation 註記。稍後可接實際驗證器。 ```yaml apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingAdmissionPolicy metadata: name: require-signed-images labels: app.kubernetes.io/part-of: platform-governance app.kubernetes.io/component: policies spec: failurePolicy: Fail matchConstraints: resourceRules: - apiGroups: ["apps"] apiVersions: ["v1"] operations: ["CREATE","UPDATE"] resources: ["deployments","statefulsets","daemonsets"] - apiGroups: [""] apiVersions: ["v1"] operations: ["CREATE","UPDATE"] resources: ["pods"] paramKind: apiVersion: v1 kind: ConfigMap # 以 ConfigMap 提供 cosign 公鑰/策略參數 validations: - expression: | has(object.spec) && ( has(object.spec.template) ? has(object.spec.template.metadata.annotations["supplychain.signed"]) && object.spec.template.metadata.annotations["supplychain.signed"] == "true" : has(object.metadata.annotations["supplychain.signed"]) && object.metadata.annotations["supplychain.signed"] == "true" ) message: "Image must be signed: add annotation supplychain.signed=true after cosign verification" # 如需更嚴格:校驗指定 registry 或 digest 格式 - expression: | has(object.spec) && ( has(object.spec.template) ? size(object.spec.template.spec.containers) > 0 : has(object.spec.containers) && size(object.spec.containers) > 0 ) message: "Workload must define at least one container" auditAnnotations: - key: governance/require-signed-images value: "checked" ``` 2-6. require-signed-images.binding.yaml ```yaml apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingAdmissionPolicyBinding metadata: name: require-signed-images-binding spec: policyName: require-signed-images validationActions: [Warn] # overlays 調整:dev=Warn, staging=Audit, prod=Deny matchResources: namespaceSelector: {} # 參數化:綁定 ConfigMap 作為參數(例如提供 cosign 公鑰/策略) params: name: cosign-root-keys namespace: governance-system ``` 3) overlays:dev/staging/prod 差異化 validationActions 每個 overlay 僅對 Binding 做 patches(保持 policy 穩定不動),並可選擇性限制套用範圍(namespaceSelector)或豁免特定 namespaces。 3-1. overlays/dev/kustomization.yaml ```yaml apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - ../../base/labels-required.policy.yaml - ../../base/labels-required.binding.yaml - ../../base/immutable-namespace-meta.policy.yaml - ../../base/immutable-namespace-meta.binding.yaml - ../../base/require-signed-images.policy.yaml - ../../base/require-signed-images.binding.yaml patches: - target: kind: ValidatingAdmissionPolicyBinding name: labels-required-binding patch: | - op: replace path: /spec/validationActions value: ["Warn"] - target: kind: ValidatingAdmissionPolicyBinding name: require-signed-images-binding patch: | - op: replace path: /spec/validationActions value: ["Warn"] - target: kind: ValidatingAdmissionPolicyBinding name: immutable-namespace-meta-binding patch: | - op: replace path: /spec/validationActions value: ["Audit"] # 觀察期,避免阻斷 ``` 3-2. overlays/staging/kustomization.yaml ```yaml apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - ../../base/labels-required.policy.yaml - ../../base/labels-required.binding.yaml - ../../base/immutable-namespace-meta.policy.yaml - ../../base/immutable-namespace-meta.binding.yaml - ../../base/require-signed-images.policy.yaml - ../../base/require-signed-images.binding.yaml patches: - target: kind: ValidatingAdmissionPolicyBinding name: labels-required-binding patch: | - op: replace path: /spec/validationActions value: ["Audit"] - target: kind: ValidatingAdmissionPolicyBinding name: require-signed-images-binding patch: | - op: replace path: /spec/validationActions value: ["Audit"] - target: kind: ValidatingAdmissionPolicyBinding name: immutable-namespace-meta-binding patch: | - op: replace path: /spec/validationActions value: ["Deny"] ``` 3-3. overlays/prod/kustomization.yaml ```yaml apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - ../../base/labels-required.policy.yaml - ../../base/labels-required.binding.yaml - ../../base/immutable-namespace-meta.policy.yaml - ../../base/immutable-namespace-meta.binding.yaml - ../../base/require-signed-images.policy.yaml - ../../base/require-signed-images.binding.yaml patches: - target: kind: ValidatingAdmissionPolicyBinding name: labels-required-binding patch: | - op: replace path: /spec/validationActions value: ["Deny"] - target: kind: ValidatingAdmissionPolicyBinding name: require-signed-images-binding patch: | - op: replace path: /spec/validationActions value: ["Deny"] - target: kind: ValidatingAdmissionPolicyBinding name: immutable-namespace-meta-binding patch: | - op: replace path: /spec/validationActions value: ["Deny"]
最新发布
10-30
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值