1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-10 18:06:55 +00:00
kyverno/test/conformance/chainsaw/generate/validation/clusterpolicy/target-namespace-scope
shuting 01cc42e78a
fix: add auth check to the admission controller for generate policies (#10963)
* fix: add auth check to the admission controller for generate policies

Signed-off-by: ShutingZhao <shuting@nirmata.com>

* fix: enable auth check if sync=true

Signed-off-by: ShutingZhao <shuting@nirmata.com>

* fix: restict to list/get permissions

Signed-off-by: ShutingZhao <shuting@nirmata.com>

* fix: aggregate clusterrole to admission controller

Signed-off-by: ShutingZhao <shuting@nirmata.com>

* fix: aggregate clusterrole to admission controller

Signed-off-by: ShutingZhao <shuting@nirmata.com>

* fix: aggregate clusterrole to admission controller

Signed-off-by: ShutingZhao <shuting@nirmata.com>

* fix: aggregate clusterrole to admission controller

Signed-off-by: ShutingZhao <shuting@nirmata.com>

---------

Signed-off-by: ShutingZhao <shuting@nirmata.com>
2024-09-04 11:26:24 +00:00
..
chainsaw-step-01-apply-1-1.yaml fix: add auth check to the admission controller for generate policies (#10963) 2024-09-04 11:26:24 +00:00
chainsaw-step-01-apply-2-1.yaml chore: convert chainsaw tests to Test resource (#9113) 2023-12-07 22:38:30 +01:00
chainsaw-test.yaml chore: convert chainsaw tests to Test resource (#9113) 2023-12-07 22:38:30 +01:00
policy-fail-1-no-ns-namespaced-target.yaml chore: all chainsaw tests (#9011) 2023-11-24 11:17:58 +01:00
policy-fail-2-ns-cluster-target.yaml feat: add tests for different values of generateExisting (#10807) 2024-08-08 12:11:20 +00:00
policy-pass-1-ns-namespaced-target.yaml feat: add tests for different values of generateExisting (#10807) 2024-08-08 12:11:20 +00:00
policy-pass-2-no-ns-cluster-target.yaml feat: add tests for different values of generateExisting (#10807) 2024-08-08 12:11:20 +00:00
policy-pass-3.yaml feat: add cleanup policies v2 (#9261) 2023-12-22 20:43:27 +02:00
README.md chore: all chainsaw tests (#9011) 2023-11-24 11:17:58 +01:00

Description

This test ensures that the target namespace must be set for namespace-scoped target resource, and must not be set for cluster-wide target resources.

Expected Behavior

The test fails if the policy creation is allowed, otherwise passes.

Reference Issue(s)

https://github.com/kyverno/kyverno/issues/7038 https://github.com/kyverno/kyverno/issues/7470 https://github.com/kyverno/kyverno/issues/7750