Repository navigation
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
Unit Tests 2 files 461 suites 13m 2s ⏱️ Results for commit 76df1ef. ♻️ This comment has been updated with latest results. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## sk593-authz-error-codes #13214 +/- ##
==========================================================
Coverage ? 60.49%
==========================================================
Files ? 777
Lines ? 45752
Branches ? 0
==========================================================
Hits ? 27676
Misses ? 18076
Partials ? 0 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
30cad0b to
0640241
Compare
0640241 to
e709074
Compare
e709074 to
688cda1
Compare
There was a problem hiding this comment.
🟡 Changes recommended
The rogue image violates the repository mirror policy, and several security-test and documentation gaps require correction.
4 open findings
What changed in this PR
Adds authorization functional-test foundations and a hardened rogue HTTP client without changing product behavior.
Changes:
- Adds authz mode smoke tests and future boundary placeholders.
- Adds and tests the in-cluster rogue client.
- Wires the suite into Make and CI with dry-run authorization enabled.
| File | Description |
|---|---|
test/rogue/rogue.go |
Implements the rogue pod client. |
test/rogue/rogue_test.go |
Tests request construction, parsing, and pod configuration. |
test/functional-portable/authz/noncloud/mode_test.go |
Verifies component authorization-mode logging. |
test/functional-portable/authz/noncloud/boundaries_test.go |
Adds planned authorization boundary tests. |
build/test.mk |
Adds the authz functional-test target. |
.github/workflows/functional-test-noncloud.yaml |
Adds the authz CI matrix leg and dry-run installation. |
🧠 Review effort: Balanced
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
44647d3 to
c808f29
Compare
Add the authz noncloud functional suite with a smoke test that checks every Radius component logs the authorization mode selected by the installed Helm values, and skipped placeholders for the trust boundaries later changes implement. Add unit tests for the rogue client helper. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Add test/rogue, which runs a curl pod in a namespace and calls internal Radius endpoints from it through pod exec, optionally presenting a certificate from a mounted TLS Secret. Add the test-functional-authz-noncloud make target, include it in test-functional-all-noncloud, and add the authz-noncloud leg to the noncloud functional test workflow, installed with the authorization dry run enabled. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
c808f29 to
76df1ef
Compare
Radius functional test overviewClick here to see the test run details
Test Status⌛ Building Radius and pushing container images for functional tests... |


Layer 3 of the Stack 0 (Foundation) PR stack for the internal component authorization design (#13086). Stacked on #13213. No product behavior change.
Summary
test/functional-portable/authz/noncloud/Test_AuthzMode_LoggedByEveryComponent(smoke): reads the installedradiusHelm release values (global.rbac.enabled/global.rbac.dryRun), derives the expected mode the same way the chart helper does, checks that theucp,applications-rp,dynamic-rp, andcontrollerDeployments are ready, and checks that every running pod logsauthz mode=<mode>. This exercises layer 1 end to end.PeerCertificateInvalid/InvalidAuthenticationInfo), A6 (forgedx-remote-user→InvalidAuthenticationInfo), B3 (GrantScopeExceeded), B5 (OperationInputMismatch), C3 (controller mapping →AuthorizationFailed), D2 (OperationNotAssigned), D7 (template ClusterRole →AuthorizationFailed), E2 (AdmissionPolicyDenied).test/rogue:rogue.New(t, k8s, restConfig, rogue.Options{Namespace, Image, TLSSecretName})creates a locked-downcurlimages/curlpod (non-root, no service account token, all capabilities dropped) and deletes it witht.Cleanup.Client.Do(ctx, rogue.Request{...})runs curl through pod exec and returns the HTTP status, body, curl exit code, and stderr. IfTLSSecretNameis set, the Secret is mounted at/etc/radius-rogue/tls, andClientCert/CACertpresenttls.crt/tls.keyor verify withca.crt, so later PRs can make calls as a component. Request building, output parsing, and the pod spec are unit tested.test-functional-authz-noncloudmake target (copied fromtest-functional-ucp-noncloud), includes it intest-functional-all-noncloud, and adds theauthz-noncloudmatrix leg. The workflow runsmake test-functional-${MATRIX_NAME}. This leg installs with--set global.rbac.dryRun=trueso the smoke test checks a non-default mode.How to test
🔍 Manual verification
On a kind cluster with Radius installed from this stack's images and
--set global.rbac.dryRun=true(for examplerad install kubernetes --set global.rbac.dryRun=trueplus your image overrides):Check that
Test_AuthzMode_LoggedByEveryComponentpasses for all four components and that the eightTest_Boundary_*tests show as skipped (enabled by <id>).To use the rogue helper once, put this file in a temporary directory, for example
test/rogue/manual/manual_test.go:go test -v -run TestRogueUnauthenticated ./test/rogue/manual/The request currently succeeds without authentication (an HTTP response,
exit=0). That gap is what A4 closes. Delete the file when you are done.