Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions charts/deployment-operator/templates/rbac.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ roleRef:
name: {{ .Values.rbac.clusterRole }}
apiGroup: rbac.authorization.k8s.io
---
{{ if .Values.rbac.consoleReader.enabled }}
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
Expand All @@ -37,6 +38,7 @@ roleRef:
name: plrl-console-reader
apiGroup: rbac.authorization.k8s.io
---
{{ end }}
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
Expand Down
3 changes: 3 additions & 0 deletions charts/deployment-operator/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -93,6 +93,9 @@ serviceAccount:

rbac:
clusterRole: cluster-admin
consoleReader:
# Creates the console@plural.sh ClusterRoleBinding and its dedicated ClusterRole.
enabled: true

podLabels: {}
podAnnotations: {}
Expand Down
34 changes: 34 additions & 0 deletions test/helm/test-chart-install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,19 @@ echo "Validating Helm chart..."
helm lint "$CHART_DIR"

# Verify template rendering
has_resource() {
local manifest="$1"
local resource_kind="$2"
local resource_name="$3"

echo "$manifest" | awk -v kind="$resource_kind" -v name="$resource_name" '
$1 == "kind:" { current_kind = $2; in_metadata = 0; next }
current_kind == kind && $1 == "metadata:" { in_metadata = 1; next }
in_metadata && $1 == "name:" && $2 == name { found = 1 }
END { exit !found }
'
}

echo "Verifying template rendering..."
DEFAULT_RENDER=$(helm template "$RELEASE_NAME" "$CHART_DIR" \
--set secrets.deployToken=test-token \
Expand All @@ -75,7 +88,28 @@ echo "$DEFAULT_RENDER" | grep -q "cache-dir" && {
echo "Error: default template should not pass cache-dir"
exit 1
}
has_resource "$DEFAULT_RENDER" "ClusterRoleBinding" "console-read-binding" || {
echo "Error: default template should include the console reader binding"
exit 1
}
has_resource "$DEFAULT_RENDER" "ClusterRole" "plrl-console-reader" || {
echo "Error: default template should include the console reader role"
exit 1
}

echo "Verifying disabled console reader template rendering..."
DISABLED_CONSOLE_READER_RENDER=$(helm template "$RELEASE_NAME" "$CHART_DIR" \
--set secrets.deployToken=test-token \
--set fullnameOverride="$RELEASE_NAME" \
--set rbac.consoleReader.enabled=false)
if has_resource "$DISABLED_CONSOLE_READER_RENDER" "ClusterRoleBinding" "console-read-binding"; then
echo "Error: disabled console reader should not include the console reader binding"
exit 1
fi
if has_resource "$DISABLED_CONSOLE_READER_RENDER" "ClusterRole" "plrl-console-reader"; then
echo "Error: disabled console reader should not include the console reader role"
exit 1
fi
echo "Verifying hostPath cache template rendering..."
CACHE_RENDER=$(helm template "$RELEASE_NAME" "$CHART_DIR" \
--set secrets.deployToken=test-token \
Expand Down
Loading