123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022 |
- /*
- Copyright 2017 The Kubernetes Authors.
- Licensed under the Apache License, Version 2.0 (the "License");
- you may not use this file except in compliance with the License.
- You may obtain a copy of the License at
- http://www.apache.org/licenses/LICENSE-2.0
- Unless required by applicable law or agreed to in writing, software
- distributed under the License is distributed on an "AS IS" BASIS,
- WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
- See the License for the specific language governing permissions and
- limitations under the License.
- */
- package validation
- import (
- "strings"
- "testing"
- metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
- "k8s.io/apimachinery/pkg/runtime/schema"
- "k8s.io/kubernetes/pkg/apis/admissionregistration"
- )
- func strPtr(s string) *string { return &s }
- func int32Ptr(i int32) *int32 { return &i }
- func newValidatingWebhookConfiguration(hooks []admissionregistration.ValidatingWebhook, defaultAdmissionReviewVersions bool) *admissionregistration.ValidatingWebhookConfiguration {
- // If the test case did not specify an AdmissionReviewVersions, default it so the test passes as
- // this field will be defaulted in production code.
- for i := range hooks {
- if defaultAdmissionReviewVersions && len(hooks[i].AdmissionReviewVersions) == 0 {
- hooks[i].AdmissionReviewVersions = []string{"v1beta1"}
- }
- }
- return &admissionregistration.ValidatingWebhookConfiguration{
- ObjectMeta: metav1.ObjectMeta{
- Name: "config",
- },
- Webhooks: hooks,
- }
- }
- func TestValidateValidatingWebhookConfiguration(t *testing.T) {
- unknownSideEffect := admissionregistration.SideEffectClassUnknown
- validClientConfig := admissionregistration.WebhookClientConfig{
- URL: strPtr("https://example.com"),
- }
- tests := []struct {
- name string
- config *admissionregistration.ValidatingWebhookConfiguration
- gv schema.GroupVersion
- expectedError string
- }{
- {
- name: "AdmissionReviewVersions are required",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, false),
- expectedError: `webhooks[0].admissionReviewVersions: Required value: must specify one of v1, v1beta1`,
- }, {
- name: "should fail on bad AdmissionReviewVersion value",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- AdmissionReviewVersions: []string{"0v"},
- },
- }, true),
- expectedError: `Invalid value: "0v": a DNS-1035 label`,
- },
- {
- name: "should pass on valid AdmissionReviewVersion",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"v1beta1"},
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: ``,
- },
- {
- name: "should pass on mix of accepted and unaccepted AdmissionReviewVersion",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"v1beta1", "invalid-version"},
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: ``,
- },
- {
- name: "should fail on invalid AdmissionReviewVersion",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- AdmissionReviewVersions: []string{"invalidVersion"},
- },
- }, true),
- expectedError: `Invalid value: []string{"invalidVersion"}`,
- },
- {
- name: "should fail on duplicate AdmissionReviewVersion",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- AdmissionReviewVersions: []string{"v1beta1", "v1beta1"},
- },
- }, true),
- expectedError: `Invalid value: "v1beta1": duplicate version`,
- },
- {
- name: "all Webhooks must have a fully qualified name",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: `webhooks[1].name: Invalid value: "k8s.io": should be a domain with at least three segments separated by dots, webhooks[2].name: Required value`,
- },
- {
- name: "Webhooks must have unique names when not created via v1beta1",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "foo", Version: "bar"},
- expectedError: `webhooks[1].name: Duplicate value: "webhook.k8s.io"`,
- },
- {
- name: "Webhooks can have duplicate names when created via v1beta1",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: ``,
- },
- {
- name: "Operations must not be empty or nil",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a"},
- },
- },
- {
- Operations: nil,
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a"},
- },
- },
- },
- },
- }, true),
- expectedError: `webhooks[0].rules[0].operations: Required value, webhooks[0].rules[1].operations: Required value`,
- },
- {
- name: "\"\" is NOT a valid operation",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE", ""},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a"},
- },
- },
- },
- },
- }, true),
- expectedError: `Unsupported value: ""`,
- },
- {
- name: "operation must be either create/update/delete/connect",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"PATCH"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a"},
- },
- },
- },
- },
- }, true),
- expectedError: `Unsupported value: "PATCH"`,
- },
- {
- name: "wildcard operation cannot be mixed with other strings",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE", "*"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a"},
- },
- },
- },
- },
- }, true),
- expectedError: `if '*' is present, must not specify other operations`,
- },
- {
- name: `resource "*" can co-exist with resources that have subresources`,
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"*", "a/b", "a/*", "*/b"},
- },
- },
- },
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- },
- {
- name: `resource "*" cannot mix with resources that don't have subresources`,
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"*", "a"},
- },
- },
- },
- },
- }, true),
- expectedError: `if '*' is present, must not specify other resources without subresources`,
- },
- {
- name: "resource a/* cannot mix with a/x",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a/*", "a/x"},
- },
- },
- },
- },
- }, true),
- expectedError: `webhooks[0].rules[0].resources[1]: Invalid value: "a/x": if 'a/*' is present, must not specify a/x`,
- },
- {
- name: "resource a/* can mix with a",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a/*", "a"},
- },
- },
- },
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- },
- {
- name: "resource */a cannot mix with x/a",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"*/a", "x/a"},
- },
- },
- },
- },
- }, true),
- expectedError: `webhooks[0].rules[0].resources[1]: Invalid value: "x/a": if '*/a' is present, must not specify x/a`,
- },
- {
- name: "resource */* cannot mix with other resources",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"*/*", "a"},
- },
- },
- },
- },
- }, true),
- expectedError: `webhooks[0].rules[0].resources: Invalid value: []string{"*/*", "a"}: if '*/*' is present, must not specify other resources`,
- },
- {
- name: "FailurePolicy can only be \"Ignore\" or \"Fail\"",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- FailurePolicy: func() *admissionregistration.FailurePolicyType {
- r := admissionregistration.FailurePolicyType("other")
- return &r
- }(),
- },
- }, true),
- expectedError: `webhooks[0].failurePolicy: Unsupported value: "other": supported values: "Fail", "Ignore"`,
- },
- {
- name: "AdmissionReviewVersions are required",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, false),
- expectedError: `webhooks[0].admissionReviewVersions: Required value: must specify one of v1, v1beta1`,
- },
- {
- name: "SideEffects are required",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: nil,
- },
- }, true),
- expectedError: `webhooks[0].sideEffects: Required value: must specify one of None, NoneOnDryRun`,
- },
- {
- name: "SideEffects can only be \"Unknown\", \"None\", \"Some\", or \"NoneOnDryRun\" via v1beta1",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: func() *admissionregistration.SideEffectClass {
- r := admissionregistration.SideEffectClass("other")
- return &r
- }(),
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: `webhooks[0].sideEffects: Unsupported value: "other": supported values: "None", "NoneOnDryRun", "Some", "Unknown"`,
- },
- {
- name: "SideEffects can only be \"None\" or \"NoneOnDryRun\" via v1",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: func() *admissionregistration.SideEffectClass {
- r := admissionregistration.SideEffectClass("other")
- return &r
- }(),
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1"},
- expectedError: `webhooks[0].sideEffects: Unsupported value: "other": supported values: "None", "NoneOnDryRun"`,
- },
- {
- name: "both service and URL missing",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{},
- },
- }, true),
- expectedError: `exactly one of`,
- },
- {
- name: "both service and URL provided",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Port: 443,
- },
- URL: strPtr("example.com/k8s/webhook"),
- },
- },
- }, true),
- expectedError: `[0].clientConfig: Required value: exactly one of url or service is required`,
- },
- {
- name: "blank URL",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr(""),
- },
- },
- }, true),
- expectedError: `[0].clientConfig.url: Invalid value: "": host must be provided`,
- },
- {
- name: "wrong scheme",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr("http://example.com"),
- },
- },
- }, true),
- expectedError: `https`,
- },
- {
- name: "missing host",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr("https:///fancy/webhook"),
- },
- },
- }, true),
- expectedError: `host must be provided`,
- },
- {
- name: "fragment",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr("https://example.com/#bookmark"),
- },
- },
- }, true),
- expectedError: `"bookmark": fragments are not permitted`,
- },
- {
- name: "query",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr("https://example.com?arg=value"),
- },
- },
- }, true),
- expectedError: `"arg=value": query parameters are not permitted`,
- },
- {
- name: "user",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr("https://harry.potter@example.com/"),
- },
- },
- }, true),
- expectedError: `"harry.potter": user information is not permitted`,
- },
- {
- name: "just totally wrong",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr("arg#backwards=thisis?html.index/port:host//:https"),
- },
- },
- }, true),
- expectedError: `host must be provided`,
- },
- {
- name: "path must start with slash",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("foo/"),
- Port: 443,
- },
- },
- },
- }, true),
- expectedError: `clientConfig.service.path: Invalid value: "foo/": must start with a '/'`,
- },
- {
- name: "path accepts slash",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("/"),
- Port: 443,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: ``,
- },
- {
- name: "path accepts no trailing slash",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("/foo"),
- Port: 443,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: ``,
- },
- {
- name: "path fails //",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("//"),
- Port: 443,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: `clientConfig.service.path: Invalid value: "//": segment[0] may not be empty`,
- },
- {
- name: "path no empty step",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("/foo//bar/"),
- Port: 443,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: `clientConfig.service.path: Invalid value: "/foo//bar/": segment[1] may not be empty`,
- }, {
- name: "path no empty step 2",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("/foo/bar//"),
- Port: 443,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: `clientConfig.service.path: Invalid value: "/foo/bar//": segment[2] may not be empty`,
- },
- {
- name: "path no non-subdomain",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("/apis/foo.bar/v1alpha1/--bad"),
- Port: 443,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: `clientConfig.service.path: Invalid value: "/apis/foo.bar/v1alpha1/--bad": segment[3]: a DNS-1123 subdomain`,
- },
- {
- name: "invalid port 0",
- config: newValidatingWebhookConfiguration(
- []admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("https://apis/foo.bar"),
- Port: 0,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: `Invalid value: 0: port is not valid: must be between 1 and 65535, inclusive`,
- },
- {
- name: "invalid port >65535",
- config: newValidatingWebhookConfiguration(
- []admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("https://apis/foo.bar"),
- Port: 65536,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: `Invalid value: 65536: port is not valid: must be between 1 and 65535, inclusive`,
- },
- {
- name: "timeout seconds cannot be greater than 30",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- TimeoutSeconds: int32Ptr(31),
- },
- }, true),
- expectedError: `webhooks[0].timeoutSeconds: Invalid value: 31: the timeout value must be between 1 and 30 seconds`,
- },
- {
- name: "timeout seconds cannot be smaller than 1",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- TimeoutSeconds: int32Ptr(0),
- },
- }, true),
- expectedError: `webhooks[0].timeoutSeconds: Invalid value: 0: the timeout value must be between 1 and 30 seconds`,
- },
- {
- name: "timeout seconds must be positive",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- TimeoutSeconds: int32Ptr(-1),
- },
- }, true),
- expectedError: `webhooks[0].timeoutSeconds: Invalid value: -1: the timeout value must be between 1 and 30 seconds`,
- },
- {
- name: "valid timeout seconds",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- TimeoutSeconds: int32Ptr(1),
- },
- {
- Name: "webhook2.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- TimeoutSeconds: int32Ptr(15),
- },
- {
- Name: "webhook3.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- TimeoutSeconds: int32Ptr(30),
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- },
- }
- for _, test := range tests {
- t.Run(test.name, func(t *testing.T) {
- errs := ValidateValidatingWebhookConfiguration(test.config, test.gv)
- err := errs.ToAggregate()
- if err != nil {
- if e, a := test.expectedError, err.Error(); !strings.Contains(a, e) || e == "" {
- t.Errorf("expected to contain %s, got %s", e, a)
- }
- } else {
- if test.expectedError != "" {
- t.Errorf("unexpected no error, expected to contain %s", test.expectedError)
- }
- }
- })
- }
- }
- func TestValidateValidatingWebhookConfigurationUpdate(t *testing.T) {
- unknownSideEffect := admissionregistration.SideEffectClassUnknown
- validClientConfig := admissionregistration.WebhookClientConfig{
- URL: strPtr("https://example.com"),
- }
- tests := []struct {
- name string
- oldconfig *admissionregistration.ValidatingWebhookConfiguration
- config *admissionregistration.ValidatingWebhookConfiguration
- gv schema.GroupVersion
- expectedError string
- }{
- {
- name: "should pass on valid new AdmissionReviewVersion",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"v1beta1"},
- },
- }, true),
- oldconfig: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: ``,
- },
- {
- name: "should pass on invalid AdmissionReviewVersion with invalid previous versions",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"invalid-v1", "invalid-v2"},
- },
- }, true),
- oldconfig: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"invalid-v0"},
- },
- }, true),
- expectedError: ``,
- },
- {
- name: "should fail on invalid AdmissionReviewVersion with valid previous versions",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"invalid-v1"},
- },
- }, true),
- oldconfig: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"v1beta1", "invalid-v1"},
- },
- }, true),
- expectedError: `Invalid value: []string{"invalid-v1"}`,
- },
- {
- name: "should fail on invalid AdmissionReviewVersion with missing previous versions",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"invalid-v1"},
- },
- }, true),
- oldconfig: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, false),
- expectedError: `Invalid value: []string{"invalid-v1"}`,
- },
- {
- name: "Webhooks must have unique names when not updated via v1beta1",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- oldconfig: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, false),
- gv: schema.GroupVersion{Group: "foo", Version: "bar"},
- expectedError: `webhooks[1].name: Duplicate value: "webhook.k8s.io"`,
- },
- {
- name: "Webhooks can have duplicate names when old config has duplicate names",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- oldconfig: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "foo", Version: "bar"},
- expectedError: ``,
- },
- {
- name: "Webhooks can have duplicate names when updated via v1beta1",
- config: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- oldconfig: newValidatingWebhookConfiguration([]admissionregistration.ValidatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, false),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: ``,
- },
- }
- for _, test := range tests {
- t.Run(test.name, func(t *testing.T) {
- errs := ValidateValidatingWebhookConfigurationUpdate(test.config, test.oldconfig, test.gv)
- err := errs.ToAggregate()
- if err != nil {
- if e, a := test.expectedError, err.Error(); !strings.Contains(a, e) || e == "" {
- t.Errorf("expected to contain %s, got %s", e, a)
- }
- } else {
- if test.expectedError != "" {
- t.Errorf("unexpected no error, expected to contain %s", test.expectedError)
- }
- }
- })
- }
- }
- func newMutatingWebhookConfiguration(hooks []admissionregistration.MutatingWebhook, defaultAdmissionReviewVersions bool) *admissionregistration.MutatingWebhookConfiguration {
- // If the test case did not specify an AdmissionReviewVersions, default it so the test passes as
- // this field will be defaulted in production code.
- for i := range hooks {
- if defaultAdmissionReviewVersions && len(hooks[i].AdmissionReviewVersions) == 0 {
- hooks[i].AdmissionReviewVersions = []string{"v1beta1"}
- }
- }
- return &admissionregistration.MutatingWebhookConfiguration{
- ObjectMeta: metav1.ObjectMeta{
- Name: "config",
- },
- Webhooks: hooks,
- }
- }
- func TestValidateMutatingWebhookConfiguration(t *testing.T) {
- unknownSideEffect := admissionregistration.SideEffectClassUnknown
- validClientConfig := admissionregistration.WebhookClientConfig{
- URL: strPtr("https://example.com"),
- }
- tests := []struct {
- name string
- config *admissionregistration.MutatingWebhookConfiguration
- gv schema.GroupVersion
- expectedError string
- }{
- {
- name: "AdmissionReviewVersions are required",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, false),
- expectedError: `webhooks[0].admissionReviewVersions: Required value: must specify one of v1, v1beta1`,
- }, {
- name: "should fail on bad AdmissionReviewVersion value",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- AdmissionReviewVersions: []string{"0v"},
- },
- }, true),
- expectedError: `Invalid value: "0v": a DNS-1035 label`,
- },
- {
- name: "should pass on valid AdmissionReviewVersion",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"v1beta1"},
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: ``,
- },
- {
- name: "should pass on mix of accepted and unaccepted AdmissionReviewVersion",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"v1beta1", "invalid-version"},
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: ``,
- },
- {
- name: "should fail on invalid AdmissionReviewVersion",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- AdmissionReviewVersions: []string{"invalidVersion"},
- },
- }, true),
- expectedError: `Invalid value: []string{"invalidVersion"}`,
- },
- {
- name: "should fail on duplicate AdmissionReviewVersion",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- AdmissionReviewVersions: []string{"v1beta1", "v1beta1"},
- },
- }, true),
- expectedError: `Invalid value: "v1beta1": duplicate version`,
- },
- {
- name: "all Webhooks must have a fully qualified name",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: `webhooks[1].name: Invalid value: "k8s.io": should be a domain with at least three segments separated by dots, webhooks[2].name: Required value`,
- },
- {
- name: "Webhooks must have unique names when not created via v1beta1",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "foo", Version: "bar"},
- expectedError: `webhooks[1].name: Duplicate value: "webhook.k8s.io"`,
- },
- {
- name: "Webhooks can have duplicate names when created via v1beta1",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: ``,
- },
- {
- name: "Operations must not be empty or nil",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a"},
- },
- },
- {
- Operations: nil,
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a"},
- },
- },
- },
- },
- }, true),
- expectedError: `webhooks[0].rules[0].operations: Required value, webhooks[0].rules[1].operations: Required value`,
- },
- {
- name: "\"\" is NOT a valid operation",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE", ""},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a"},
- },
- },
- },
- },
- }, true),
- expectedError: `Unsupported value: ""`,
- },
- {
- name: "operation must be either create/update/delete/connect",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"PATCH"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a"},
- },
- },
- },
- },
- }, true),
- expectedError: `Unsupported value: "PATCH"`,
- },
- {
- name: "wildcard operation cannot be mixed with other strings",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE", "*"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a"},
- },
- },
- },
- },
- }, true),
- expectedError: `if '*' is present, must not specify other operations`,
- },
- {
- name: `resource "*" can co-exist with resources that have subresources`,
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"*", "a/b", "a/*", "*/b"},
- },
- },
- },
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- },
- {
- name: `resource "*" cannot mix with resources that don't have subresources`,
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"*", "a"},
- },
- },
- },
- },
- }, true),
- expectedError: `if '*' is present, must not specify other resources without subresources`,
- },
- {
- name: "resource a/* cannot mix with a/x",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a/*", "a/x"},
- },
- },
- },
- },
- }, true),
- expectedError: `webhooks[0].rules[0].resources[1]: Invalid value: "a/x": if 'a/*' is present, must not specify a/x`,
- },
- {
- name: "resource a/* can mix with a",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"a/*", "a"},
- },
- },
- },
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- },
- {
- name: "resource */a cannot mix with x/a",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"*/a", "x/a"},
- },
- },
- },
- },
- }, true),
- expectedError: `webhooks[0].rules[0].resources[1]: Invalid value: "x/a": if '*/a' is present, must not specify x/a`,
- },
- {
- name: "resource */* cannot mix with other resources",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- Rules: []admissionregistration.RuleWithOperations{
- {
- Operations: []admissionregistration.OperationType{"CREATE"},
- Rule: admissionregistration.Rule{
- APIGroups: []string{"a"},
- APIVersions: []string{"a"},
- Resources: []string{"*/*", "a"},
- },
- },
- },
- },
- }, true),
- expectedError: `webhooks[0].rules[0].resources: Invalid value: []string{"*/*", "a"}: if '*/*' is present, must not specify other resources`,
- },
- {
- name: "FailurePolicy can only be \"Ignore\" or \"Fail\"",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- FailurePolicy: func() *admissionregistration.FailurePolicyType {
- r := admissionregistration.FailurePolicyType("other")
- return &r
- }(),
- },
- }, true),
- expectedError: `webhooks[0].failurePolicy: Unsupported value: "other": supported values: "Fail", "Ignore"`,
- },
- {
- name: "AdmissionReviewVersions are required",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, false),
- expectedError: `webhooks[0].admissionReviewVersions: Required value: must specify one of v1, v1beta1`,
- },
- {
- name: "SideEffects are required",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: nil,
- },
- }, true),
- expectedError: `webhooks[0].sideEffects: Required value: must specify one of None, NoneOnDryRun`,
- },
- {
- name: "SideEffects can only be \"Unknown\", \"None\", \"Some\", or \"NoneOnDryRun\" via v1beta1",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: func() *admissionregistration.SideEffectClass {
- r := admissionregistration.SideEffectClass("other")
- return &r
- }(),
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: `webhooks[0].sideEffects: Unsupported value: "other": supported values: "None", "NoneOnDryRun", "Some", "Unknown"`,
- },
- {
- name: "SideEffects can only be \"None\" or \"NoneOnDryRun\" via v1",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: func() *admissionregistration.SideEffectClass {
- r := admissionregistration.SideEffectClass("other")
- return &r
- }(),
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1"},
- expectedError: `webhooks[0].sideEffects: Unsupported value: "other": supported values: "None", "NoneOnDryRun"`,
- },
- {
- name: "both service and URL missing",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{},
- },
- }, true),
- expectedError: `exactly one of`,
- },
- {
- name: "both service and URL provided",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Port: 443,
- },
- URL: strPtr("example.com/k8s/webhook"),
- },
- },
- }, true),
- expectedError: `[0].clientConfig: Required value: exactly one of url or service is required`,
- },
- {
- name: "blank URL",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr(""),
- },
- },
- }, true),
- expectedError: `[0].clientConfig.url: Invalid value: "": host must be provided`,
- },
- {
- name: "wrong scheme",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr("http://example.com"),
- },
- },
- }, true),
- expectedError: `https`,
- },
- {
- name: "missing host",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr("https:///fancy/webhook"),
- },
- },
- }, true),
- expectedError: `host must be provided`,
- },
- {
- name: "fragment",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr("https://example.com/#bookmark"),
- },
- },
- }, true),
- expectedError: `"bookmark": fragments are not permitted`,
- },
- {
- name: "query",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr("https://example.com?arg=value"),
- },
- },
- }, true),
- expectedError: `"arg=value": query parameters are not permitted`,
- },
- {
- name: "user",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr("https://harry.potter@example.com/"),
- },
- },
- }, true),
- expectedError: `"harry.potter": user information is not permitted`,
- },
- {
- name: "just totally wrong",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- URL: strPtr("arg#backwards=thisis?html.index/port:host//:https"),
- },
- },
- }, true),
- expectedError: `host must be provided`,
- },
- {
- name: "path must start with slash",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("foo/"),
- Port: 443,
- },
- },
- },
- }, true),
- expectedError: `clientConfig.service.path: Invalid value: "foo/": must start with a '/'`,
- },
- {
- name: "path accepts slash",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("/"),
- Port: 443,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: ``,
- },
- {
- name: "path accepts no trailing slash",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("/foo"),
- Port: 443,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: ``,
- },
- {
- name: "path fails //",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("//"),
- Port: 443,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: `clientConfig.service.path: Invalid value: "//": segment[0] may not be empty`,
- },
- {
- name: "path no empty step",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("/foo//bar/"),
- Port: 443,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: `clientConfig.service.path: Invalid value: "/foo//bar/": segment[1] may not be empty`,
- }, {
- name: "path no empty step 2",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("/foo/bar//"),
- Port: 443,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: `clientConfig.service.path: Invalid value: "/foo/bar//": segment[2] may not be empty`,
- },
- {
- name: "path no non-subdomain",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("/apis/foo.bar/v1alpha1/--bad"),
- Port: 443,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: `clientConfig.service.path: Invalid value: "/apis/foo.bar/v1alpha1/--bad": segment[3]: a DNS-1123 subdomain`,
- },
- {
- name: "invalid port 0",
- config: newMutatingWebhookConfiguration(
- []admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("https://apis/foo.bar"),
- Port: 0,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: `Invalid value: 0: port is not valid: must be between 1 and 65535, inclusive`,
- },
- {
- name: "invalid port >65535",
- config: newMutatingWebhookConfiguration(
- []admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: admissionregistration.WebhookClientConfig{
- Service: &admissionregistration.ServiceReference{
- Namespace: "ns",
- Name: "n",
- Path: strPtr("https://apis/foo.bar"),
- Port: 65536,
- },
- },
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: `Invalid value: 65536: port is not valid: must be between 1 and 65535, inclusive`,
- },
- {
- name: "timeout seconds cannot be greater than 30",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- TimeoutSeconds: int32Ptr(31),
- },
- }, true),
- expectedError: `webhooks[0].timeoutSeconds: Invalid value: 31: the timeout value must be between 1 and 30 seconds`,
- },
- {
- name: "timeout seconds cannot be smaller than 1",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- TimeoutSeconds: int32Ptr(0),
- },
- }, true),
- expectedError: `webhooks[0].timeoutSeconds: Invalid value: 0: the timeout value must be between 1 and 30 seconds`,
- },
- {
- name: "timeout seconds must be positive",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- TimeoutSeconds: int32Ptr(-1),
- },
- }, true),
- expectedError: `webhooks[0].timeoutSeconds: Invalid value: -1: the timeout value must be between 1 and 30 seconds`,
- },
- {
- name: "valid timeout seconds",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- TimeoutSeconds: int32Ptr(1),
- },
- {
- Name: "webhook2.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- TimeoutSeconds: int32Ptr(15),
- },
- {
- Name: "webhook3.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- TimeoutSeconds: int32Ptr(30),
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- },
- }
- for _, test := range tests {
- t.Run(test.name, func(t *testing.T) {
- errs := ValidateMutatingWebhookConfiguration(test.config, test.gv)
- err := errs.ToAggregate()
- if err != nil {
- if e, a := test.expectedError, err.Error(); !strings.Contains(a, e) || e == "" {
- t.Errorf("expected to contain %s, got %s", e, a)
- }
- } else {
- if test.expectedError != "" {
- t.Errorf("unexpected no error, expected to contain %s", test.expectedError)
- }
- }
- })
- }
- }
- func TestValidateMutatingWebhookConfigurationUpdate(t *testing.T) {
- unknownSideEffect := admissionregistration.SideEffectClassUnknown
- noSideEffect := admissionregistration.SideEffectClassNone
- validClientConfig := admissionregistration.WebhookClientConfig{
- URL: strPtr("https://example.com"),
- }
- tests := []struct {
- name string
- oldconfig *admissionregistration.MutatingWebhookConfiguration
- config *admissionregistration.MutatingWebhookConfiguration
- gv schema.GroupVersion
- expectedError string
- }{
- {
- name: "should pass on valid new AdmissionReviewVersion (v1beta1)",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"v1beta1"},
- },
- }, true),
- oldconfig: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: ``,
- },
- {
- name: "should pass on valid new AdmissionReviewVersion (v1)",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"v1"},
- },
- }, true),
- oldconfig: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- expectedError: ``,
- },
- {
- name: "should pass on invalid AdmissionReviewVersion with invalid previous versions",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"invalid-v1", "invalid-v2"},
- },
- }, true),
- oldconfig: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"invalid-v0"},
- },
- }, true),
- expectedError: ``,
- },
- {
- name: "should fail on invalid AdmissionReviewVersion with valid previous versions",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"invalid-v1"},
- },
- }, true),
- oldconfig: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"v1beta1", "invalid-v1"},
- },
- }, true),
- expectedError: `Invalid value: []string{"invalid-v1"}`,
- },
- {
- name: "should fail on invalid AdmissionReviewVersion with missing previous versions",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- AdmissionReviewVersions: []string{"invalid-v1"},
- },
- }, true),
- oldconfig: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, false),
- expectedError: `Invalid value: []string{"invalid-v1"}`,
- },
- {
- name: "Webhooks can have duplicate names when old config has duplicate names",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- oldconfig: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "foo", Version: "bar"},
- expectedError: ``,
- },
- {
- name: "Webhooks can have duplicate names when updated via v1beta1",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- oldconfig: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, false),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: ``,
- },
- {
- name: "Webhooks can't have side effects when old config has no side effects via v1",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- oldconfig: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &noSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1"},
- expectedError: `Unsupported value: "Unknown": supported values: "None", "NoneOnDryRun"`,
- },
- {
- name: "Webhooks can have side effects when old config has side effects",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- oldconfig: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- gv: schema.GroupVersion{Group: "foo", Version: "bar"},
- expectedError: ``,
- },
- {
- name: "Webhooks can have side effects when updated via v1beta1",
- config: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &unknownSideEffect,
- },
- }, true),
- oldconfig: newMutatingWebhookConfiguration([]admissionregistration.MutatingWebhook{
- {
- Name: "webhook.k8s.io",
- ClientConfig: validClientConfig,
- SideEffects: &noSideEffect,
- },
- }, false),
- gv: schema.GroupVersion{Group: "admissionregistration.k8s.io", Version: "v1beta1"},
- expectedError: ``,
- },
- }
- for _, test := range tests {
- t.Run(test.name, func(t *testing.T) {
- errs := ValidateMutatingWebhookConfigurationUpdate(test.config, test.oldconfig, test.gv)
- err := errs.ToAggregate()
- if err != nil {
- if e, a := test.expectedError, err.Error(); !strings.Contains(a, e) || e == "" {
- t.Errorf("expected to contain %s, got %s", e, a)
- }
- } else {
- if test.expectedError != "" {
- t.Errorf("unexpected no error, expected to contain %s", test.expectedError)
- }
- }
- })
- }
- }
|