Skip to content

feat(test): add authz functional test suite and rogue client helper - #13214

Draft
sk593 wants to merge 2 commits into
sk593-authz-error-codesfrom
sk593-authz-functional-test-suite
Draft

sk593 wants to merge 2 commits into
sk593-authz-error-codesfrom
sk593-authz-functional-test-suite

Conversation

@sk593

@sk593 sk593 commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Layer 3 of the Stack 0 (Foundation) PR stack for the internal component authorization design (#13086). Stacked on #13213. No product behavior change.

Summary

  • New suite test/functional-portable/authz/noncloud/
    • Test_AuthzMode_LoggedByEveryComponent (smoke): reads the installed radius Helm release values (global.rbac.enabled / global.rbac.dryRun), derives the expected mode the same way the chart helper does, checks that the ucp, applications-rp, dynamic-rp, and controller Deployments are ready, and checks that every running pod logs authz mode=<mode>. This exercises layer 1 end to end.
    • Skipped placeholders for later boundaries, each with its expected result and error code: A4 (unauthenticated call to applications-rp → PeerCertificateInvalid/InvalidAuthenticationInfo), A6 (forged x-remote-user → InvalidAuthenticationInfo), B3 (GrantScopeExceeded), B5 (OperationInputMismatch), C3 (controller mapping → AuthorizationFailed), D2 (OperationNotAssigned), D7 (template ClusterRole → AuthorizationFailed), E2 (AdmissionPolicyDenied).
  • Rogue client helper test/rogue: rogue.New(t, k8s, restConfig, rogue.Options{Namespace, Image, TLSSecretName}) creates a locked-down curlimages/curl pod (non-root, no service account token, all capabilities dropped) and deletes it with t.Cleanup. Client.Do(ctx, rogue.Request{...}) runs curl through pod exec and returns the HTTP status, body, curl exit code, and stderr. If TLSSecretName is set, the Secret is mounted at /etc/radius-rogue/tls, and ClientCert/CACert present tls.crt/tls.key or verify with ca.crt, so later PRs can make calls as a component. Request building, output parsing, and the pod spec are unit tested.
  • CI wiring: adds the test-functional-authz-noncloud make target (copied from test-functional-ucp-noncloud), includes it in test-functional-all-noncloud, and adds the authz-noncloud matrix leg. The workflow runs make test-functional-${MATRIX_NAME}. This leg installs with --set global.rbac.dryRun=true so the smoke test checks a non-default mode.

How to test

go test ./test/rogue/
go vet ./test/rogue/ ./test/functional-portable/authz/...
go test -run 'Test_ExpectedMode|Test_LoggedMode' ./test/functional-portable/authz/...
go test -run xxx ./test/functional-portable/authz/... ./test/rogue/   # compile check
make -n test-functional-authz-noncloud

🔍 Manual verification

On a kind cluster with Radius installed from this stack's images and --set global.rbac.dryRun=true (for example rad install kubernetes --set global.rbac.dryRun=true plus your image overrides):

make test-functional-authz-noncloud

Check that Test_AuthzMode_LoggedByEveryComponent passes for all four components and that the eight Test_Boundary_* tests show as skipped (enabled by <id>).

To use the rogue helper once, put this file in a temporary directory, for example test/rogue/manual/manual_test.go:

package manual

import (
	"testing"

	"github.com/radius-project/radius/test"
	"github.com/radius-project/radius/test/rogue"
)

func TestRogueUnauthenticated(t *testing.T) {
	o := test.NewTestOptions(t)
	c := rogue.New(t, o.K8sClient, o.K8sConfig, rogue.Options{Namespace: "default"})
	resp, err := c.Do(t.Context(), rogue.Request{
		URL: "http://applications-rp.radius-system:5443/apis/api.ucp.dev/v1alpha3/planes/radius/local/providers/Applications.Core/operations?api-version=2023-10-01-preview",
	})
	if err != nil {
		t.Fatal(err)
	}
	t.Logf("status=%d exit=%d body=%s", resp.StatusCode, resp.ExitCode, resp.Body)
}
go test -v -run TestRogueUnauthenticated ./test/rogue/manual/

The request currently succeeds without authentication (an HTTP response, exit=0). That gap is what A4 closes. Delete the file when you are done.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

This PR requires exactly 1 of the following labels: pr:standard, pr:important.
Currently applied labels: .

Label descriptions:

  • pr:important - Major features, breaking changes, deprecations, or other high-impact changes that need special attention during release and in release notes.
  • pr:standard - Ongoing maintenance, minor improvements, documentation updates, and routine development work.

@sk593, please add the appropriate label to this PR before merging.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@sk593
sk593 added this pull request to stack #13217 October 5, 2026 23:19
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Unit Tests

    2 files  ±0    461 suites  ±0   15m 28s ⏱️ -3s
7 340 tests ±0  7 338 ✅ ±0  2 💤 ±0  0 ❌ ±0 
8 819 runs  ±0  8 817 ✅ ±0  2 💤 ±0  0 ❌ ±0 

Results for commit e709074. ± Comparison against base commit e580d4b.

♻️ This comment has been updated with latest results.

@codecov

codecov Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 60.48%. Comparing base (e580d4b) to head (e709074).

Additional details and impacted files
@@                   Coverage Diff                    @@
##           sk593-authz-error-codes   #13214   +/-   ##
========================================================
  Coverage                    60.48%   60.48%           
========================================================
  Files                          777      777           
  Lines                        45747    45747           
========================================================
+ Hits                         27670    27671    +1     
+ Misses                       18077    18076    -1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@sk593
sk593 force-pushed the sk593-authz-functional-test-suite branch from 30cad0b to 0640241 Compare October 6, 2026 20:14
@github-actions github-actions Bot added the pr:needs-rebase The pull request has merge conflicts label Oct 6, 2026
sk593 and others added 2 commits October 6, 2026 19:20
Add the authz noncloud functional suite with a smoke test that checks
every Radius component logs the authorization mode selected by the
installed Helm values, and skipped placeholders for the trust
boundaries later changes implement. Add unit tests for the rogue
client helper.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: sk593 <shruthikumar@microsoft.com>
Add test/rogue, which runs a curl pod in a namespace and calls internal
Radius endpoints from it through pod exec, optionally presenting a
certificate from a mounted TLS Secret. Add the
test-functional-authz-noncloud make target, include it in
test-functional-all-noncloud, and add the authz-noncloud leg to the
noncloud functional test workflow, installed with the authorization
dry run enabled.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: sk593 <shruthikumar@microsoft.com>
@sk593
sk593 force-pushed the sk593-authz-functional-test-suite branch from 0640241 to e709074 Compare October 7, 2026 05:56
@github-actions github-actions Bot removed the pr:needs-rebase The pull request has merge conflicts label Oct 7, 2026
@radius-functional-tests

radius-functional-tests Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Radius functional test overview

🔍 Go to test action run

Click here to see the test run details
Name Value
Repository radius-project/radius
Commit ref e709074
Unique ID funcc91bf4a873
Image tag pr-funcc91bf4a873
  • Dapr: 1.14.4
  • Azure KeyVault CSI driver: 1.4.2
  • Azure Workload identity webhook: 1.3.0
  • Bicep recipe location ghcr.io/radius-project/dev/test/testrecipes/test-bicep-recipes/<name>:pr-funcc91bf4a873
  • Terraform recipe location http://tf-module-server.radius-test-tf-module-server.svc.cluster.local/<name>.zip (in cluster)
  • applications-rp test image location: ghcr.io/radius-project/dev/applications-rp:pr-funcc91bf4a873
  • dynamic-rp test image location: ghcr.io/radius-project/dev/dynamic-rp:pr-funcc91bf4a873
  • controller test image location: ghcr.io/radius-project/dev/controller:pr-funcc91bf4a873
  • ucp test image location: ghcr.io/radius-project/dev/ucpd:pr-funcc91bf4a873
  • deployment-engine test image location: ghcr.io/radius-project/deployment-engine:latest

Test Status

⌛ Building Radius and pushing container images for functional tests...
✅ Container images build succeeded
⌛ Publishing Bicep Recipes for functional tests...
✅ Recipe publishing succeeded
⌛ Starting corerp-cloud functional tests...
⌛ Starting ucp-cloud functional tests...
✅ ucp-cloud functional tests succeeded
✅ corerp-cloud functional tests succeeded

@sk593 sk593 changed the title test: add authz functional test suite and rogue client helper feat(test): add authz functional test suite and rogue client helper Oct 7, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant