From da93413c862fa792b77c4d3f40c9854b898e6a02 Mon Sep 17 00:00:00 2001 From: Michael Guarino Date: Tue, 15 Sep 2026 01:27:20 +0000 Subject: [PATCH 1/2] feat(helm): add console reader RBAC toggle --- .../deployment-operator/templates/rbac.yaml | 2 ++ charts/deployment-operator/values.yaml | 3 +++ test/helm/test-chart-install.sh | 22 +++++++++++++++++++ 3 files changed, 27 insertions(+) diff --git a/charts/deployment-operator/templates/rbac.yaml b/charts/deployment-operator/templates/rbac.yaml index 3bfe0c56b..2dad03afe 100644 --- a/charts/deployment-operator/templates/rbac.yaml +++ b/charts/deployment-operator/templates/rbac.yaml @@ -13,6 +13,7 @@ roleRef: name: {{ .Values.rbac.clusterRole }} apiGroup: rbac.authorization.k8s.io --- +{{ if .Values.rbac.consoleReader.enabled }} apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: @@ -37,6 +38,7 @@ roleRef: name: plrl-console-reader apiGroup: rbac.authorization.k8s.io --- +{{ end }} apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: diff --git a/charts/deployment-operator/values.yaml b/charts/deployment-operator/values.yaml index 8c128107d..21a1f1a60 100644 --- a/charts/deployment-operator/values.yaml +++ b/charts/deployment-operator/values.yaml @@ -93,6 +93,9 @@ serviceAccount: rbac: clusterRole: cluster-admin + consoleReader: + # Creates the console@plural.sh ClusterRoleBinding and its dedicated ClusterRole. + enabled: true podLabels: {} podAnnotations: {} diff --git a/test/helm/test-chart-install.sh b/test/helm/test-chart-install.sh index b5ed01b53..74cf1fa1f 100755 --- a/test/helm/test-chart-install.sh +++ b/test/helm/test-chart-install.sh @@ -75,6 +75,28 @@ echo "$DEFAULT_RENDER" | grep -q "cache-dir" && { echo "Error: default template should not pass cache-dir" exit 1 } +echo "$DEFAULT_RENDER" | grep -q "name: console-read-binding" || { + echo "Error: default template should include the console reader binding" + exit 1 +} +echo "$DEFAULT_RENDER" | grep -q "name: plrl-console-reader" || { + echo "Error: default template should include the console reader role" + exit 1 +} + +echo "Verifying disabled console reader template rendering..." +DISABLED_CONSOLE_READER_RENDER=$(helm template "$RELEASE_NAME" "$CHART_DIR" \ + --set secrets.deployToken=test-token \ + --set fullnameOverride="$RELEASE_NAME" \ + --set rbac.consoleReader.enabled=false) +echo "$DISABLED_CONSOLE_READER_RENDER" | grep -q "console-read-binding" && { + echo "Error: disabled console reader should not include the console reader binding" + exit 1 +} +echo "$DISABLED_CONSOLE_READER_RENDER" | grep -q "plrl-console-reader" && { + echo "Error: disabled console reader should not include the console reader role" + exit 1 +} echo "Verifying hostPath cache template rendering..." CACHE_RENDER=$(helm template "$RELEASE_NAME" "$CHART_DIR" \ From 755887a4ed186a4921419807a407a657d547e0df Mon Sep 17 00:00:00 2001 From: Michael Guarino Date: Tue, 15 Sep 2026 01:31:00 +0000 Subject: [PATCH 2/2] test(helm): assert console reader role resource --- test/helm/test-chart-install.sh | 26 +++++++++++++++++++------- 1 file changed, 19 insertions(+), 7 deletions(-) diff --git a/test/helm/test-chart-install.sh b/test/helm/test-chart-install.sh index 74cf1fa1f..d4c29e638 100755 --- a/test/helm/test-chart-install.sh +++ b/test/helm/test-chart-install.sh @@ -62,6 +62,19 @@ echo "Validating Helm chart..." helm lint "$CHART_DIR" # Verify template rendering +has_resource() { + local manifest="$1" + local resource_kind="$2" + local resource_name="$3" + + echo "$manifest" | awk -v kind="$resource_kind" -v name="$resource_name" ' + $1 == "kind:" { current_kind = $2; in_metadata = 0; next } + current_kind == kind && $1 == "metadata:" { in_metadata = 1; next } + in_metadata && $1 == "name:" && $2 == name { found = 1 } + END { exit !found } + ' +} + echo "Verifying template rendering..." DEFAULT_RENDER=$(helm template "$RELEASE_NAME" "$CHART_DIR" \ --set secrets.deployToken=test-token \ @@ -75,11 +88,11 @@ echo "$DEFAULT_RENDER" | grep -q "cache-dir" && { echo "Error: default template should not pass cache-dir" exit 1 } -echo "$DEFAULT_RENDER" | grep -q "name: console-read-binding" || { +has_resource "$DEFAULT_RENDER" "ClusterRoleBinding" "console-read-binding" || { echo "Error: default template should include the console reader binding" exit 1 } -echo "$DEFAULT_RENDER" | grep -q "name: plrl-console-reader" || { +has_resource "$DEFAULT_RENDER" "ClusterRole" "plrl-console-reader" || { echo "Error: default template should include the console reader role" exit 1 } @@ -89,15 +102,14 @@ DISABLED_CONSOLE_READER_RENDER=$(helm template "$RELEASE_NAME" "$CHART_DIR" \ --set secrets.deployToken=test-token \ --set fullnameOverride="$RELEASE_NAME" \ --set rbac.consoleReader.enabled=false) -echo "$DISABLED_CONSOLE_READER_RENDER" | grep -q "console-read-binding" && { +if has_resource "$DISABLED_CONSOLE_READER_RENDER" "ClusterRoleBinding" "console-read-binding"; then echo "Error: disabled console reader should not include the console reader binding" exit 1 -} -echo "$DISABLED_CONSOLE_READER_RENDER" | grep -q "plrl-console-reader" && { +fi +if has_resource "$DISABLED_CONSOLE_READER_RENDER" "ClusterRole" "plrl-console-reader"; then echo "Error: disabled console reader should not include the console reader role" exit 1 -} - +fi echo "Verifying hostPath cache template rendering..." CACHE_RENDER=$(helm template "$RELEASE_NAME" "$CHART_DIR" \ --set secrets.deployToken=test-token \