mirror of
https://github.com/kubevela/kubevela.git
synced 2026-08-18 20:17:04 +00:00
* Feat: ref component Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Feat: support topology and override Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Feat: add support for external policy and workflow Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Feat: add admission control Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: disable cross namespace ref object Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Chore: refactor Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Feat: support labelSelector in ref-objects Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Feat: add pre approve for deploy step Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Chore: refactor Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: test Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Feat: support comp/trait type in override policy even not used by prototype Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Feat: support regex match for patch component name Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: labelSelector not work for cluster Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: ref workflow contains external policy Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: revision test Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Feat: parallel apply components Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Feat: add test for oam provider Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: service ref-comp & indirect trait ns Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: align namespace setting for chart Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: add strict unmarshal and reformat Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: merge with cluster rework Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Feat: patch trait-def Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: apply components + load dynamic component Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: add test for loadPoliciesInOrder Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Feat: add test for open merge Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: reformat & add test for step generator Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: add test for parse override policy related defs Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: add test for multicluster provider (expandTopology and overrideConfiguration) Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: add admission test Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: revert trait status pass in component status Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: add test for dependency in workflowstep & standalone multicluster test Signed-off-by: Somefive <yd219913@alibaba-inc.com> * Fix: add check for ref and steps in WorkflowStep & enhance ref-objects scheme check Signed-off-by: Somefive <yd219913@alibaba-inc.com>
82 lines
2.5 KiB
Go
82 lines
2.5 KiB
Go
/*
|
|
Copyright 2021 The KubeVela Authors.
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/
|
|
|
|
package resourcekeeper
|
|
|
|
import (
|
|
"context"
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/require"
|
|
v1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
|
"k8s.io/apimachinery/pkg/apis/meta/v1/unstructured"
|
|
|
|
"github.com/oam-dev/kubevela/apis/core.oam.dev/v1beta1"
|
|
)
|
|
|
|
func TestNamespaceAdmissionHandler_Validate(t *testing.T) {
|
|
AllowCrossNamespaceResource = false
|
|
defer func() {
|
|
AllowCrossNamespaceResource = true
|
|
}()
|
|
handler := &NamespaceAdmissionHandler{
|
|
app: &v1beta1.Application{ObjectMeta: v1.ObjectMeta{Namespace: "test"}},
|
|
}
|
|
objs := []*unstructured.Unstructured{{
|
|
Object: map[string]interface{}{
|
|
"metadata": map[string]interface{}{
|
|
"name": "demo",
|
|
"namespace": "demo",
|
|
},
|
|
},
|
|
}}
|
|
err := handler.Validate(context.Background(), objs)
|
|
r := require.New(t)
|
|
r.NotNil(err)
|
|
r.Contains(err.Error(), "forbidden resource")
|
|
AllowCrossNamespaceResource = true
|
|
r.NoError(handler.Validate(context.Background(), objs))
|
|
}
|
|
|
|
func TestResourceTypeAdmissionHandler_Validate(t *testing.T) {
|
|
defer func() {
|
|
AllowResourceTypes = ""
|
|
}()
|
|
r := require.New(t)
|
|
objs := []*unstructured.Unstructured{{
|
|
Object: map[string]interface{}{
|
|
"apiVersion": "v1",
|
|
"kind": "Secret",
|
|
"metadata": map[string]interface{}{
|
|
"name": "demo",
|
|
"namespace": "demo",
|
|
},
|
|
},
|
|
}}
|
|
AllowResourceTypes = "blacklist:Service.v1,Secret.v1"
|
|
err := (&ResourceTypeAdmissionHandler{}).Validate(context.Background(), objs)
|
|
r.NotNil(err)
|
|
r.Contains(err.Error(), "forbidden resource")
|
|
AllowResourceTypes = "blacklist:ConfigMap.v1,Deployment.v1.apps"
|
|
r.NoError((&ResourceTypeAdmissionHandler{}).Validate(context.Background(), objs))
|
|
AllowResourceTypes = "whitelist:ConfigMap.v1,Deployment.v1.apps"
|
|
err = (&ResourceTypeAdmissionHandler{}).Validate(context.Background(), objs)
|
|
r.NotNil(err)
|
|
r.Contains(err.Error(), "forbidden resource")
|
|
AllowResourceTypes = "whitelist:Service.v1,Secret.v1"
|
|
r.NoError((&ResourceTypeAdmissionHandler{}).Validate(context.Background(), objs))
|
|
}
|