Repository navigation
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #13212 +/- ##
==========================================
+ Coverage 60.37% 60.46% +0.08%
==========================================
Files 774 776 +2
Lines 45682 45715 +33
==========================================
+ Hits 27582 27641 +59
+ Misses 18100 18074 -26 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
5706483 to
fa3ded4
Compare
Add failing tests for the authz package (ParseMode, Apply, LogMode), for reading the authorization mode from UCP, dynamic-rp, and provider config, and Helm unit tests mapping global.rbac values to the mode. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Add pkg/authz with the Mode type, ParseMode, and an Apply helper that future authorization checks use to act on a Decision: off ignores denials, dryRun logs them with authzWouldDeny=true, and enforce returns a DeniedError carrying the error code. Read the mode from an authorization section in the UCP, applications-rp, dynamic-rp, and controller configuration, and log it once at startup. Render it in the Helm chart from global.rbac.enabled and global.rbac.dryRun (both default false); combining them fails rendering. Nothing checks the mode yet, so runtime behavior is unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Validate the mode before the allowed fast path, default empty denial codes to AuthorizationFailed, omit the chart authorization section in off mode so older binaries can load config, and mark the rbac values as reserved. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
fa3ded4 to
1d1ef33
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The unsupported authz: title type will fail the repository’s required Conventional Commit title check.
Review effort: Balanced
Findings: None
What changed in this PR
Adds the shared internal authorization-mode foundation without enabling authorization checks.
Changes:
- Adds
off,dryRun, andenforcemodes, decisions, logging, and denial errors. - Wires configuration and startup logging into four Go services.
- Adds Helm rendering, validation, tests, and configuration documentation.
Review note: Rename the PR to feat(authz): add authorization mode setting (off/dryRun/enforce) to satisfy the required Conventional Commit title format.
| File | Description |
|---|---|
pkg/ucp/config.go |
Adds authorization configuration. |
pkg/ucp/config_test.go |
Tests UCP mode decoding. |
pkg/dynamicrp/config.go |
Adds authorization configuration. |
pkg/dynamicrp/config_test.go |
Tests Dynamic RP mode decoding. |
pkg/authz/mode.go |
Defines modes, parsing, options, and logging. |
pkg/authz/mode_test.go |
Tests mode behavior. |
pkg/authz/doc.go |
Documents the package. |
pkg/authz/decision.go |
Implements authorization decision handling. |
pkg/authz/decision_test.go |
Tests decisions and denial errors. |
pkg/armrpc/hostoptions/providerconfig.go |
Adds shared provider authorization options. |
pkg/armrpc/hostoptions/providerconfig_test.go |
Tests provider configuration decoding. |
docs/contributing/contributing-code/contributing-code-control-plane/configSettings.md |
Documents authorization settings. |
deploy/Chart/values.yaml |
Adds reserved RBAC values. |
deploy/Chart/tests/authz_mode_test.yaml |
Tests Helm mode rendering. |
deploy/Chart/templates/ucp/configmaps.yaml |
Renders UCP authorization mode. |
deploy/Chart/templates/rp/configmaps.yaml |
Renders Applications RP mode. |
deploy/Chart/templates/dynamic-rp/configmaps.yaml |
Renders Dynamic RP mode. |
deploy/Chart/templates/controller/configmaps.yaml |
Renders controller mode. |
deploy/Chart/templates/_helpers.tpl |
Derives and validates the Helm mode. |
cmd/ucpd/cmd/root.go |
Logs UCP mode at startup. |
cmd/dynamic-rp/cmd/root.go |
Logs Dynamic RP mode at startup. |
cmd/controller/cmd/root.go |
Logs controller mode at startup. |
cmd/applications-rp/cmd/root.go |
Logs Applications RP mode at startup. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…loyments Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Services read the authorization mode only at startup, so annotate each pod template with a checksum of the mode. A helm upgrade that changes global.rbac now rolls the ucp, applications-rp, dynamic-rp, and controller deployments. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Radius functional test overviewClick here to see the test run details
Test Status⌛ Building Radius and pushing container images for functional tests... |
Description
Layer 1 of the Stack 0: Foundation stack for the internal component authorization design in #13086 (see CLI Design, Compatibility, and Error codes).
This PR adds a single authorization mode setting that every Radius Go service reads. Nothing checks the mode yet, so runtime behavior is unchanged; later PRs in the stack add the checks.
pkg/authz(new)ModewithModeOff(default),ModeDryRun,ModeEnforce;ParseMode(empty →off, case-sensitive, anything else is an error).Modevalidates itself when decoded from YAML, so a typo fails config loading.Decision{Allowed, Code, Reason}andApply(ctx, mode, decision)(the mode is validated first, so an unknown mode fails closed even for allowed decisions; a denial without a code usesAuthorizationFailed):off: returns nil and does not log.dryRun: logsauthorization check would deny requestwithauthzWouldDeny=true,authzCode,authzReasonand returns nil.enforce: returns*DeniedErrorcarrying the code and reason.LogModelogsauthz mode=<mode>once at startup.Config plumbing: an
authorization.modesection inhostoptions.ProviderConfig(applications-rp, controller),ucp.Config, anddynamicrp.Config. UCP, applications-rp, dynamic-rp, and controller log the mode at startup.Helm:
global.rbac.enabledandglobal.rbac.dryRun(both defaultfalse) renderauthorization.modeinto the four service ConfigMaps through aradius.authz.modehelper. Inoffmode the section is omitted, so older service binaries (strict YAML decoding) can still load the config during rolling upgrades or with mismatched image tags:enableddryRunoffdryRunenforceEach of the four deployments carries a
checksum/authz-configpod annotation (a hash of the mode), so ahelm upgradethat changes the mode rolls the pods. Services read the mode only at startup.The values are documented as reserved until checks land.
enabledstaysfalsefor now; per the design it becomes default-on only in the final rollout PR.Docs:
configSettings.mdlists the newauthorizationsection.Services not wired: the deployment engine (
bicep-de, .NET, in a separate repo) and the dashboard (Node.js, separate repo) do not load this Go config. They will need their own changes when they participate in the protocol.pre-upgradeandradare one-shot tools, not services.Commits are test-forward: each test commit precedes its implementation commit.
How to test
go test ./pkg/authz/... ./pkg/ucp/ ./pkg/dynamicrp/ ./pkg/armrpc/hostoptions/ go build ./cmd/... make test-helm go run github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.14.0 run ./pkg/authz/... ./pkg/ucp/ ./pkg/dynamicrp/ ./pkg/armrpc/hostoptions/ ./cmd/ucpd/... ./cmd/dynamic-rp/... ./cmd/applications-rp/... ./cmd/controller/...All of these pass locally (Helm: 152/152 tests).
🔍 Manual verification
Render the chart for each combination:
I checked these locally. I also ran it on a Podman-backed kind cluster (arm64) with the five images built from this branch (
ucpd,applications-rp,dynamic-rp,controller,pre-upgrade) loaded viakind load image-archive. For that local-only run, the two hook jobs'imagePullPolicywas set toIfNotPresentin a scratch copy of the chart so they could use the loaded images:I then switched to
offandenforcewithhelm upgrade --reuse-values --set global.rbac.enabled=... --set global.rbac.dryRun=...and all four services logged the expected mode (before the checksum annotation, these needed akubectl rollout restart). After adding the annotation, switching fromenforceback todryRunwithhelm upgradealone rolled all four deployments, and each new pod logged: