feat(helm): add console reader RBAC toggle - #825
Conversation
There was a problem hiding this comment.
This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:
| Name | Details |
|---|---|
| 💬 Prompt | Implement the Helm RBAC toggle in this standalone repository and open exactly one PR.... |
| 🔗 Run history | View run history |
|
| echo "$DEFAULT_RENDER" | grep -q "name: plrl-console-reader" || { | ||
| echo "Error: default template should include the console reader role" | ||
| exit 1 |
There was a problem hiding this comment.
The default check does not independently confirm that the plrl-console-reader ClusterRole was rendered. The same name: plrl-console-reader text appears in the binding's roleRef, so removing the role while retaining the binding would still pass this check. Validate the resource kind and metadata name together so this test covers the intended object.
Summary
rbac.consoleReader.enabled, a documented Helm value that defaults totrue.false, the chart omits theconsole-read-bindingClusterRoleBindingwhose subject isconsole@plural.sh.Default compatibility
The default remains
true, so existing installations render the same console reader RBAC resources as before.ClusterRole scope decision
plrl-console-readeris gated by the same value. An exhaustive repository reference inspection found one definition and only one consumer:console-read-binding; that binding's only subject isconsole@plural.sh. No templates, values files, docs, tests, CI configuration, or other repository files reference the role. The operator'scluster-adminbinding andplrl-agent-gate-operatorRBAC remain unconditional.Test coverage and validation
test/helm/test-chart-install.shto assert that the default render containsconsole-read-bindingandplrl-console-reader.--set rbac.consoleReader.enabled=falseand assert that both are absent.timeout 3m docker run --rm -v "$PWD:/work" -w /work alpine/helm:3.12.3 lint charts/deployment-operator--set rbac.consoleReader.enabled=falsebash -n test/helm/test-chart-install.shgit diff --checkLimitations
./test/helm/test-chart-install.shwas attempted but could not execute its Kind installation flow because Helm is not installed on the host (exit 1). Docker is available and was used to run Helm lint and render validation. The chart has no values schema.