diff --git a/charts/deployment-operator/templates/rbac.yaml b/charts/deployment-operator/templates/rbac.yaml index 3bfe0c56b..2dad03afe 100644 --- a/charts/deployment-operator/templates/rbac.yaml +++ b/charts/deployment-operator/templates/rbac.yaml @@ -13,6 +13,7 @@ roleRef: name: {{ .Values.rbac.clusterRole }} apiGroup: rbac.authorization.k8s.io --- +{{ if .Values.rbac.consoleReader.enabled }} apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: @@ -37,6 +38,7 @@ roleRef: name: plrl-console-reader apiGroup: rbac.authorization.k8s.io --- +{{ end }} apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: diff --git a/charts/deployment-operator/values.yaml b/charts/deployment-operator/values.yaml index 8c128107d..21a1f1a60 100644 --- a/charts/deployment-operator/values.yaml +++ b/charts/deployment-operator/values.yaml @@ -93,6 +93,9 @@ serviceAccount: rbac: clusterRole: cluster-admin + consoleReader: + # Creates the console@plural.sh ClusterRoleBinding and its dedicated ClusterRole. + enabled: true podLabels: {} podAnnotations: {} diff --git a/test/helm/test-chart-install.sh b/test/helm/test-chart-install.sh index b5ed01b53..d4c29e638 100755 --- a/test/helm/test-chart-install.sh +++ b/test/helm/test-chart-install.sh @@ -62,6 +62,19 @@ echo "Validating Helm chart..." helm lint "$CHART_DIR" # Verify template rendering +has_resource() { + local manifest="$1" + local resource_kind="$2" + local resource_name="$3" + + echo "$manifest" | awk -v kind="$resource_kind" -v name="$resource_name" ' + $1 == "kind:" { current_kind = $2; in_metadata = 0; next } + current_kind == kind && $1 == "metadata:" { in_metadata = 1; next } + in_metadata && $1 == "name:" && $2 == name { found = 1 } + END { exit !found } + ' +} + echo "Verifying template rendering..." DEFAULT_RENDER=$(helm template "$RELEASE_NAME" "$CHART_DIR" \ --set secrets.deployToken=test-token \ @@ -75,7 +88,28 @@ echo "$DEFAULT_RENDER" | grep -q "cache-dir" && { echo "Error: default template should not pass cache-dir" exit 1 } +has_resource "$DEFAULT_RENDER" "ClusterRoleBinding" "console-read-binding" || { + echo "Error: default template should include the console reader binding" + exit 1 +} +has_resource "$DEFAULT_RENDER" "ClusterRole" "plrl-console-reader" || { + echo "Error: default template should include the console reader role" + exit 1 +} +echo "Verifying disabled console reader template rendering..." +DISABLED_CONSOLE_READER_RENDER=$(helm template "$RELEASE_NAME" "$CHART_DIR" \ + --set secrets.deployToken=test-token \ + --set fullnameOverride="$RELEASE_NAME" \ + --set rbac.consoleReader.enabled=false) +if has_resource "$DISABLED_CONSOLE_READER_RENDER" "ClusterRoleBinding" "console-read-binding"; then + echo "Error: disabled console reader should not include the console reader binding" + exit 1 +fi +if has_resource "$DISABLED_CONSOLE_READER_RENDER" "ClusterRole" "plrl-console-reader"; then + echo "Error: disabled console reader should not include the console reader role" + exit 1 +fi echo "Verifying hostPath cache template rendering..." CACHE_RENDER=$(helm template "$RELEASE_NAME" "$CHART_DIR" \ --set secrets.deployToken=test-token \