Skip to content

feat(test): add authz functional test suite and rogue client helper - #13214

Open
sk593 wants to merge 6 commits into
sk593-authz-error-codesfrom
sk593-authz-functional-test-suite
Open

sk593 wants to merge 6 commits into
sk593-authz-error-codesfrom
sk593-authz-functional-test-suite

Conversation

@sk593

@sk593 sk593 commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Layer 3 of the Stack 0 (Foundation) PR stack for the internal component authorization design (#13086). Stacked on #13213. No product behavior change.

Summary

  • New suite test/functional-portable/authz/noncloud/
    • Test_AuthzMode_LoggedByEveryComponent (smoke): reads the installed radius Helm release values (global.rbac.enabled / global.rbac.dryRun), derives the expected mode the same way the chart helper does, checks that the ucp, applications-rp, dynamic-rp, and controller Deployments are ready, and checks that every running pod logs authz mode=<mode>. This exercises layer 1 end to end.
    • Skipped placeholders for later boundaries, each with its expected result and error code: A4 (unauthenticated call to applications-rp → PeerCertificateInvalid/InvalidAuthenticationInfo), A6 (forged x-remote-user → InvalidAuthenticationInfo), B3 (GrantScopeExceeded), B5 (OperationInputMismatch), C3 (controller mapping → AuthorizationFailed), D2 (OperationNotAssigned), D7 (template ClusterRole → AuthorizationFailed), E2 (AdmissionPolicyDenied).
  • Rogue client helper test/rogue: rogue.New(t, k8s, restConfig, rogue.Options{Namespace, Image, TLSSecretName}) creates a locked-down curlimages/curl pod (non-root, no service account token, all capabilities dropped) and deletes it with t.Cleanup. Client.Do(ctx, rogue.Request{...}) runs curl through pod exec and returns the HTTP status, body, curl exit code, and stderr. If TLSSecretName is set, the Secret is mounted at /etc/radius-rogue/tls, and ClientCert/CACert present tls.crt/tls.key or verify with ca.crt, so later PRs can make calls as a component. Request building, output parsing, and the pod spec are unit tested.
  • CI wiring: adds the test-functional-authz-noncloud make target (copied from test-functional-ucp-noncloud), includes it in test-functional-all-noncloud, and adds the authz-noncloud matrix leg. The workflow runs make test-functional-${MATRIX_NAME}. This leg installs with --set global.rbac.dryRun=true so the smoke test checks a non-default mode.

How to test

go test ./test/rogue/
go vet ./test/rogue/ ./test/functional-portable/authz/...
go test -run 'Test_ExpectedMode|Test_LoggedMode' ./test/functional-portable/authz/...
go test -run xxx ./test/functional-portable/authz/... ./test/rogue/   # compile check
make -n test-functional-authz-noncloud

🔍 Manual verification

On a kind cluster with Radius installed from this stack's images and --set global.rbac.dryRun=true (for example rad install kubernetes --set global.rbac.dryRun=true plus your image overrides):

make test-functional-authz-noncloud

Check that Test_AuthzMode_LoggedByEveryComponent passes for all four components and that the eight Test_Boundary_* tests show as skipped (enabled by <id>).

To use the rogue helper once, put this file in a temporary directory, for example test/rogue/manual/manual_test.go:

package manual

import (
	"testing"

	"github.com/radius-project/radius/test"
	"github.com/radius-project/radius/test/rogue"
)

func TestRogueUnauthenticated(t *testing.T) {
	o := test.NewTestOptions(t)
	c := rogue.New(t, o.K8sClient, o.K8sConfig, rogue.Options{Namespace: "default"})
	resp, err := c.Do(t.Context(), rogue.Request{
		URL: "http://applications-rp.radius-system:5443/apis/api.ucp.dev/v1alpha3/planes/radius/local/providers/Applications.Core/operations?api-version=2023-10-01-preview",
	})
	if err != nil {
		t.Fatal(err)
	}
	t.Logf("status=%d exit=%d body=%s", resp.StatusCode, resp.ExitCode, resp.Body)
}
go test -v -run TestRogueUnauthenticated ./test/rogue/manual/

The request currently succeeds without authentication (an HTTP response, exit=0). That gap is what A4 closes. Delete the file when you are done.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@sk593
sk593 added this pull request to stack #13217 October 5, 2026 23:19
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Unit Tests

    2 files    461 suites   13m 2s ⏱️
7 350 tests 7 348 ✅ 2 💤 0 ❌
8 829 runs  8 827 ✅ 2 💤 0 ❌

Results for commit 76df1ef.

♻️ This comment has been updated with latest results.

@codecov

codecov Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (sk593-authz-error-codes@54bb703). Learn more about missing BASE report.

Additional details and impacted files
@@                    Coverage Diff                     @@
##             sk593-authz-error-codes   #13214   +/-   ##
==========================================================
  Coverage                           ?   60.49%           
==========================================================
  Files                              ?      777           
  Lines                              ?    45752           
  Branches                           ?        0           
==========================================================
  Hits                               ?    27676           
  Misses                             ?    18076           
  Partials                           ?        0           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@sk593
sk593 force-pushed the sk593-authz-functional-test-suite branch from 30cad0b to 0640241 Compare October 6, 2026 20:14
@github-actions github-actions Bot added the pr:needs-rebase The pull request has merge conflicts label Oct 6, 2026
@sk593
sk593 force-pushed the sk593-authz-functional-test-suite branch from 0640241 to e709074 Compare October 7, 2026 05:56
@github-actions github-actions Bot removed the pr:needs-rebase The pull request has merge conflicts label Oct 7, 2026
@sk593 sk593 changed the title test: add authz functional test suite and rogue client helper feat(test): add authz functional test suite and rogue client helper Oct 7, 2026
@sk593
sk593 force-pushed the sk593-authz-functional-test-suite branch from e709074 to 688cda1 Compare October 8, 2026 17:28
@sk593
sk593 marked this pull request as ready for review October 8, 2026 17:28
Copilot AI balanced review requested due to automatic review settings October 8, 2026 17:28
@sk593
sk593 requested review from a team as code owners October 8, 2026 17:28
@sk593 sk593 added the pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work label Oct 8, 2026
@github-actions github-actions Bot added the pr:waiting-for-review A reviewer owns the next action; required approval is pending or unverifiable label Oct 8, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The rogue image violates the repository mirror policy, and several security-test and documentation gaps require correction.

4 open findings
What changed in this PR

Adds authorization functional-test foundations and a hardened rogue HTTP client without changing product behavior.

Changes:

  • Adds authz mode smoke tests and future boundary placeholders.
  • Adds and tests the in-cluster rogue client.
  • Wires the suite into Make and CI with dry-run authorization enabled.
File Description
test/​rogue/​rogue.go Implements the rogue pod client.
test/​rogue/​rogue_test.go Tests request construction, parsing, and pod configuration.
test/​functional-portable/​authz/​noncloud/​mode_test.go Verifies component authorization-mode logging.
test/​functional-portable/​authz/​noncloud/​boundaries_test.go Adds planned authorization boundary tests.
build/​test.mk Adds the authz functional-test target.
.github/​workflows/​functional-test-noncloud.yaml Adds the authz CI matrix leg and dry-run installation.

🧠 Review effort: Balanced


💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread test/rogue/rogue.go Outdated
Comment thread test/rogue/rogue_test.go
Comment thread build/test.mk
Comment thread test/functional-portable/authz/noncloud/boundaries_test.go Outdated
@sk593
sk593 force-pushed the sk593-authz-functional-test-suite branch from 44647d3 to c808f29 Compare October 8, 2026 18:03
sk593 and others added 6 commits October 9, 2026 11:39
Add the authz noncloud functional suite with a smoke test that checks
every Radius component logs the authorization mode selected by the
installed Helm values, and skipped placeholders for the trust
boundaries later changes implement. Add unit tests for the rogue
client helper.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: sk593 <shruthikumar@microsoft.com>
Add test/rogue, which runs a curl pod in a namespace and calls internal
Radius endpoints from it through pod exec, optionally presenting a
certificate from a mounted TLS Secret. Add the
test-functional-authz-noncloud make target, include it in
test-functional-all-noncloud, and add the authz-noncloud leg to the
noncloud functional test workflow, installed with the authorization
dry run enabled.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: sk593 <shruthikumar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: sk593 <shruthikumar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: sk593 <shruthikumar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: sk593 <shruthikumar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: sk593 <shruthikumar@microsoft.com>
@sk593
sk593 force-pushed the sk593-authz-functional-test-suite branch from c808f29 to 76df1ef Compare October 9, 2026 18:40
@radius-functional-tests

radius-functional-tests Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Radius functional test overview

🔍 Go to test action run

Click here to see the test run details
Name Value
Repository radius-project/radius
Commit ref 76df1ef
Unique ID func0e93f6a173
Image tag pr-func0e93f6a173
  • Dapr: 1.14.4
  • Azure KeyVault CSI driver: 1.4.2
  • Azure Workload identity webhook: 1.3.0
  • Bicep recipe location ghcr.io/radius-project/dev/test/testrecipes/test-bicep-recipes/<name>:pr-func0e93f6a173
  • Terraform recipe location http://tf-module-server.radius-test-tf-module-server.svc.cluster.local/<name>.zip (in cluster)
  • applications-rp test image location: ghcr.io/radius-project/dev/applications-rp:pr-func0e93f6a173
  • dynamic-rp test image location: ghcr.io/radius-project/dev/dynamic-rp:pr-func0e93f6a173
  • controller test image location: ghcr.io/radius-project/dev/controller:pr-func0e93f6a173
  • ucp test image location: ghcr.io/radius-project/dev/ucpd:pr-func0e93f6a173
  • deployment-engine test image location: ghcr.io/radius-project/deployment-engine:latest

Test Status

⌛ Building Radius and pushing container images for functional tests...
✅ Container images build succeeded
⌛ Publishing Bicep Recipes for functional tests...
✅ Recipe publishing succeeded
⌛ Starting ucp-cloud functional tests...
⌛ Starting corerp-cloud functional tests...
✅ ucp-cloud functional tests succeeded
✅ corerp-cloud functional tests succeeded

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work pr:waiting-for-review A reviewer owns the next action; required approval is pending or unverifiable

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants