2021-07-02 08:56:50 +03:00
|
|
|
package validate
|
|
|
|
|
|
|
|
import (
|
|
|
|
"errors"
|
|
|
|
"fmt"
|
|
|
|
"os"
|
|
|
|
"testing"
|
|
|
|
"time"
|
|
|
|
|
|
|
|
"github.com/kyverno/kyverno/test/e2e"
|
2021-09-08 22:33:41 +03:00
|
|
|
commonE2E "github.com/kyverno/kyverno/test/e2e/common"
|
2021-07-02 08:56:50 +03:00
|
|
|
. "github.com/onsi/ginkgo"
|
|
|
|
. "github.com/onsi/gomega"
|
2021-09-08 22:33:41 +03:00
|
|
|
k8sErrors "k8s.io/apimachinery/pkg/api/errors"
|
2021-07-02 08:56:50 +03:00
|
|
|
)
|
|
|
|
|
|
|
|
var (
|
|
|
|
// Cluster Polict GVR
|
2021-09-08 22:33:41 +03:00
|
|
|
policyGVR = e2e.GetGVR("kyverno.io", "v1", "clusterpolicies")
|
2021-07-02 08:56:50 +03:00
|
|
|
// Namespace GVR
|
2021-09-08 22:33:41 +03:00
|
|
|
namespaceGVR = e2e.GetGVR("", "v1", "namespaces")
|
2021-07-02 08:56:50 +03:00
|
|
|
|
|
|
|
crdGVR = e2e.GetGVR("apiextensions.k8s.io", "v1", "customresourcedefinitions")
|
|
|
|
|
|
|
|
// ClusterPolicy Namespace
|
2021-09-08 22:33:41 +03:00
|
|
|
policyNamespace = ""
|
2021-07-02 08:56:50 +03:00
|
|
|
// Namespace Name
|
|
|
|
// Hardcoded in YAML Definition
|
|
|
|
nspace = "test-validate"
|
|
|
|
|
|
|
|
crdName = "kustomizations.kustomize.toolkit.fluxcd.io"
|
|
|
|
)
|
|
|
|
|
2021-09-08 22:33:41 +03:00
|
|
|
func Test_Validate_Flux_Sets(t *testing.T) {
|
2021-07-02 08:56:50 +03:00
|
|
|
RegisterTestingT(t)
|
|
|
|
if os.Getenv("E2E") == "" {
|
|
|
|
t.Skip("Skipping E2E Test")
|
|
|
|
}
|
|
|
|
|
|
|
|
// Generate E2E Client
|
|
|
|
e2eClient, err := e2e.NewE2EClient()
|
|
|
|
Expect(err).To(BeNil())
|
|
|
|
|
2021-09-08 22:33:41 +03:00
|
|
|
for _, test := range FluxValidateTests {
|
2021-07-02 08:56:50 +03:00
|
|
|
By(fmt.Sprintf("Test to validate objects: \"%s\"", test.TestName))
|
|
|
|
|
|
|
|
// Clean up Resources
|
2021-10-13 11:00:04 -07:00
|
|
|
By(string("Cleaning Cluster Policies"))
|
2021-09-08 22:33:41 +03:00
|
|
|
e2eClient.CleanClusterPolicies(policyGVR)
|
2021-07-02 08:56:50 +03:00
|
|
|
// Clear Namespace
|
|
|
|
By(fmt.Sprintf("Deleting Namespace: \"%s\"", nspace))
|
2021-09-08 22:33:41 +03:00
|
|
|
e2eClient.DeleteClusteredResource(namespaceGVR, nspace)
|
2021-07-02 08:56:50 +03:00
|
|
|
//CleanUp CRDs
|
|
|
|
e2eClient.DeleteClusteredResource(crdGVR, crdName)
|
|
|
|
|
|
|
|
// Wait Till Deletion of Namespace
|
2021-07-09 18:01:46 -07:00
|
|
|
e2e.GetWithRetry(time.Duration(1*time.Second), 15, func() error {
|
2021-09-08 22:33:41 +03:00
|
|
|
_, err := e2eClient.GetClusteredResource(namespaceGVR, nspace)
|
2021-07-02 08:56:50 +03:00
|
|
|
if err != nil {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
return errors.New("Deleting Namespace")
|
|
|
|
})
|
|
|
|
|
|
|
|
// Create Namespace
|
|
|
|
By(fmt.Sprintf("Creating namespace \"%s\"", nspace))
|
2021-09-08 22:33:41 +03:00
|
|
|
_, err = e2eClient.CreateClusteredResourceYaml(namespaceGVR, namespaceYaml)
|
2021-07-02 08:56:50 +03:00
|
|
|
Expect(err).NotTo(HaveOccurred())
|
|
|
|
|
|
|
|
// Create policy
|
2021-09-08 22:33:41 +03:00
|
|
|
By(fmt.Sprintf("Creating policy in \"%s\"", policyNamespace))
|
2022-04-27 03:18:24 +08:00
|
|
|
_, err = e2eClient.CreateNamespacedResourceYaml(policyGVR, policyNamespace, "", test.PolicyRaw)
|
2021-07-02 08:56:50 +03:00
|
|
|
Expect(err).NotTo(HaveOccurred())
|
|
|
|
|
|
|
|
// Create Flux CRD
|
|
|
|
By(fmt.Sprintf("Creating Flux CRD in \"%s\"", nspace))
|
|
|
|
_, err = e2eClient.CreateClusteredResourceYaml(crdGVR, kyverno_2043_FluxCRD)
|
|
|
|
Expect(err).NotTo(HaveOccurred())
|
|
|
|
|
|
|
|
// Wait till CRD is created
|
2021-07-09 18:01:46 -07:00
|
|
|
e2e.GetWithRetry(time.Duration(1*time.Second), 15, func() error {
|
2021-07-02 08:56:50 +03:00
|
|
|
_, err := e2eClient.GetClusteredResource(crdGVR, crdName)
|
|
|
|
if err == nil {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
return errors.New("Waiting for CRD to be created...")
|
|
|
|
})
|
|
|
|
|
|
|
|
// Created CRD is not a garantee that we already can create new resources
|
|
|
|
time.Sleep(3 * time.Second)
|
|
|
|
|
|
|
|
// Create Kustomize resource
|
|
|
|
kustomizeGVR := e2e.GetGVR("kustomize.toolkit.fluxcd.io", "v1beta1", "kustomizations")
|
|
|
|
By(fmt.Sprintf("Creating Kustomize resource in \"%s\"", nspace))
|
2022-04-27 03:18:24 +08:00
|
|
|
_, err = e2eClient.CreateNamespacedResourceYaml(kustomizeGVR, nspace, "", test.ResourceRaw)
|
2021-08-21 00:44:19 +03:00
|
|
|
|
|
|
|
if test.MustSucceed {
|
|
|
|
Expect(err).NotTo(HaveOccurred())
|
|
|
|
} else {
|
|
|
|
Expect(err).To(HaveOccurred())
|
|
|
|
}
|
2021-07-02 08:56:50 +03:00
|
|
|
|
|
|
|
//CleanUp Resources
|
2021-09-08 22:33:41 +03:00
|
|
|
e2eClient.CleanClusterPolicies(policyGVR)
|
2021-07-02 08:56:50 +03:00
|
|
|
|
|
|
|
//CleanUp CRDs
|
|
|
|
e2eClient.DeleteClusteredResource(crdGVR, crdName)
|
|
|
|
|
|
|
|
// Clear Namespace
|
2021-09-08 22:33:41 +03:00
|
|
|
e2eClient.DeleteClusteredResource(namespaceGVR, nspace)
|
2021-07-02 08:56:50 +03:00
|
|
|
// Wait Till Deletion of Namespace
|
2021-07-09 18:01:46 -07:00
|
|
|
e2e.GetWithRetry(time.Duration(1*time.Second), 15, func() error {
|
2021-09-08 22:33:41 +03:00
|
|
|
_, err := e2eClient.GetClusteredResource(namespaceGVR, nspace)
|
2021-07-02 08:56:50 +03:00
|
|
|
if err != nil {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
return errors.New("Deleting Namespace")
|
|
|
|
})
|
|
|
|
|
|
|
|
By(fmt.Sprintf("Test %s Completed \n\n\n", test.TestName))
|
|
|
|
}
|
|
|
|
}
|
2021-09-08 22:33:41 +03:00
|
|
|
|
|
|
|
func TestValidate(t *testing.T) {
|
|
|
|
RegisterTestingT(t)
|
|
|
|
if os.Getenv("E2E") == "" {
|
|
|
|
t.Skip("Skipping E2E Test")
|
|
|
|
}
|
|
|
|
|
|
|
|
e2eClient, err := e2e.NewE2EClient()
|
|
|
|
Expect(err).To(BeNil())
|
|
|
|
|
|
|
|
for _, test := range ValidateTests {
|
|
|
|
By(fmt.Sprintf("Mutation Test: %s", test.TestDescription))
|
|
|
|
|
|
|
|
By("Deleting Cluster Policies...")
|
|
|
|
_ = e2eClient.CleanClusterPolicies(policyGVR)
|
|
|
|
|
|
|
|
By("Deleting Resource...")
|
|
|
|
_ = e2eClient.DeleteNamespacedResource(test.ResourceGVR, test.ResourceNamespace, test.ResourceName)
|
|
|
|
|
|
|
|
By("Deleting Namespace...")
|
|
|
|
By(fmt.Sprintf("Deleting Namespace: %s...", test.ResourceNamespace))
|
|
|
|
_ = e2eClient.DeleteClusteredResource(namespaceGVR, test.ResourceNamespace)
|
|
|
|
|
|
|
|
By("Wait Till Deletion of Namespace...")
|
|
|
|
err = e2e.GetWithRetry(1*time.Second, 15, func() error {
|
|
|
|
_, err := e2eClient.GetClusteredResource(namespaceGVR, test.ResourceNamespace)
|
|
|
|
if err != nil {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
return fmt.Errorf("failed to delete namespace: %v", err)
|
|
|
|
})
|
|
|
|
Expect(err).NotTo(HaveOccurred())
|
|
|
|
|
|
|
|
By(fmt.Sprintf("Creating Namespace: %s...", policyNamespace))
|
|
|
|
_, err = e2eClient.CreateClusteredResourceYaml(namespaceGVR, newNamespaceYaml(test.ResourceNamespace))
|
|
|
|
Expect(err).NotTo(HaveOccurred())
|
|
|
|
|
|
|
|
By("Wait Till Creation of Namespace...")
|
|
|
|
err = e2e.GetWithRetry(1*time.Second, 15, func() error {
|
|
|
|
_, err := e2eClient.GetClusteredResource(namespaceGVR, test.ResourceNamespace)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
})
|
|
|
|
Expect(err).NotTo(HaveOccurred())
|
|
|
|
|
|
|
|
By("Creating Policy...")
|
2022-04-27 03:18:24 +08:00
|
|
|
_, err = e2eClient.CreateNamespacedResourceYaml(policyGVR, policyNamespace, test.PolicyName, test.PolicyRaw)
|
2021-09-08 22:33:41 +03:00
|
|
|
Expect(err).NotTo(HaveOccurred())
|
|
|
|
|
|
|
|
err = commonE2E.PolicyCreated(test.PolicyName)
|
|
|
|
Expect(err).NotTo(HaveOccurred())
|
|
|
|
|
|
|
|
By("Creating Resource...")
|
2022-04-27 03:18:24 +08:00
|
|
|
_, err = e2eClient.CreateNamespacedResourceYaml(test.ResourceGVR, test.ResourceNamespace, test.PolicyName, test.ResourceRaw)
|
2021-09-08 22:33:41 +03:00
|
|
|
|
|
|
|
statusErr, ok := err.(*k8sErrors.StatusError)
|
|
|
|
validationError := (ok && statusErr.ErrStatus.Code == 400) // Validation error is always Bad Request
|
|
|
|
|
|
|
|
if test.MustSucceed || !validationError {
|
|
|
|
Expect(err).NotTo(HaveOccurred())
|
|
|
|
} else {
|
|
|
|
Expect(err).To(HaveOccurred())
|
|
|
|
}
|
|
|
|
|
|
|
|
By("Deleting Cluster Policies...")
|
|
|
|
err = e2eClient.CleanClusterPolicies(policyGVR)
|
|
|
|
Expect(err).NotTo(HaveOccurred())
|
|
|
|
|
|
|
|
By("Deleting Resource...") // if it is present, so ignore an error
|
|
|
|
e2eClient.DeleteNamespacedResource(test.ResourceGVR, test.ResourceNamespace, test.ResourceName)
|
|
|
|
|
|
|
|
By("Deleting Namespace...")
|
|
|
|
err = e2eClient.DeleteClusteredResource(namespaceGVR, test.ResourceNamespace)
|
|
|
|
Expect(err).NotTo(HaveOccurred())
|
|
|
|
|
|
|
|
By("Wait Till Creation of Namespace...")
|
|
|
|
e2e.GetWithRetry(1*time.Second, 15, func() error {
|
|
|
|
_, err := e2eClient.GetClusteredResource(namespaceGVR, test.ResourceNamespace)
|
|
|
|
if err != nil {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
return fmt.Errorf("failed to delete namespace: %v", err)
|
|
|
|
})
|
|
|
|
|
|
|
|
// Do not fail if waiting fails. Sometimes namespace needs time to be deleted.
|
|
|
|
|
|
|
|
By("Done")
|
|
|
|
}
|
|
|
|
}
|