Repository navigation
Conversation
|
This PR requires exactly 1 of the following labels: pr:standard, pr:important. Label descriptions:
@sk593, please add the appropriate label to this PR before merging. |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## sk593-authz-error-codes #13214 +/- ##
========================================================
Coverage 60.48% 60.48%
========================================================
Files 777 777
Lines 45747 45747
========================================================
+ Hits 27670 27671 +1
+ Misses 18077 18076 -1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
30cad0b to
0640241
Compare
Add the authz noncloud functional suite with a smoke test that checks every Radius component logs the authorization mode selected by the installed Helm values, and skipped placeholders for the trust boundaries later changes implement. Add unit tests for the rogue client helper. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Add test/rogue, which runs a curl pod in a namespace and calls internal Radius endpoints from it through pod exec, optionally presenting a certificate from a mounted TLS Secret. Add the test-functional-authz-noncloud make target, include it in test-functional-all-noncloud, and add the authz-noncloud leg to the noncloud functional test workflow, installed with the authorization dry run enabled. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
0640241 to
e709074
Compare
Radius functional test overviewClick here to see the test run details
Test Status⌛ Building Radius and pushing container images for functional tests... |
Layer 3 of the Stack 0 (Foundation) PR stack for the internal component authorization design (#13086). Stacked on #13213. No product behavior change.
Summary
test/functional-portable/authz/noncloud/Test_AuthzMode_LoggedByEveryComponent(smoke): reads the installedradiusHelm release values (global.rbac.enabled/global.rbac.dryRun), derives the expected mode the same way the chart helper does, checks that theucp,applications-rp,dynamic-rp, andcontrollerDeployments are ready, and checks that every running pod logsauthz mode=<mode>. This exercises layer 1 end to end.PeerCertificateInvalid/InvalidAuthenticationInfo), A6 (forgedx-remote-user→InvalidAuthenticationInfo), B3 (GrantScopeExceeded), B5 (OperationInputMismatch), C3 (controller mapping →AuthorizationFailed), D2 (OperationNotAssigned), D7 (template ClusterRole →AuthorizationFailed), E2 (AdmissionPolicyDenied).test/rogue:rogue.New(t, k8s, restConfig, rogue.Options{Namespace, Image, TLSSecretName})creates a locked-downcurlimages/curlpod (non-root, no service account token, all capabilities dropped) and deletes it witht.Cleanup.Client.Do(ctx, rogue.Request{...})runs curl through pod exec and returns the HTTP status, body, curl exit code, and stderr. IfTLSSecretNameis set, the Secret is mounted at/etc/radius-rogue/tls, andClientCert/CACertpresenttls.crt/tls.keyor verify withca.crt, so later PRs can make calls as a component. Request building, output parsing, and the pod spec are unit tested.test-functional-authz-noncloudmake target (copied fromtest-functional-ucp-noncloud), includes it intest-functional-all-noncloud, and adds theauthz-noncloudmatrix leg. The workflow runsmake test-functional-${MATRIX_NAME}. This leg installs with--set global.rbac.dryRun=trueso the smoke test checks a non-default mode.How to test
🔍 Manual verification
On a kind cluster with Radius installed from this stack's images and
--set global.rbac.dryRun=true(for examplerad install kubernetes --set global.rbac.dryRun=trueplus your image overrides):Check that
Test_AuthzMode_LoggedByEveryComponentpasses for all four components and that the eightTest_Boundary_*tests show as skipped (enabled by <id>).To use the rogue helper once, put this file in a temporary directory, for example
test/rogue/manual/manual_test.go:go test -v -run TestRogueUnauthenticated ./test/rogue/manual/The request currently succeeds without authentication (an HTTP response,
exit=0). That gap is what A4 closes. Delete the file when you are done.