reconcile_role_test.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399
  1. /*
  2. Copyright 2017 The Kubernetes Authors.
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package reconciliation
  14. import (
  15. "testing"
  16. rbacv1 "k8s.io/api/rbac/v1"
  17. metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
  18. "k8s.io/apimachinery/pkg/util/diff"
  19. "k8s.io/kubernetes/pkg/apis/core/helper"
  20. )
  21. func role(rules []rbacv1.PolicyRule, labels map[string]string, annotations map[string]string) *rbacv1.ClusterRole {
  22. return &rbacv1.ClusterRole{
  23. Rules: rules,
  24. ObjectMeta: metav1.ObjectMeta{Labels: labels, Annotations: annotations},
  25. }
  26. }
  27. func rules(resources ...string) []rbacv1.PolicyRule {
  28. r := []rbacv1.PolicyRule{}
  29. for _, resource := range resources {
  30. r = append(r, rbacv1.PolicyRule{APIGroups: []string{""}, Verbs: []string{"get"}, Resources: []string{resource}})
  31. }
  32. return r
  33. }
  34. type ss map[string]string
  35. func TestComputeReconciledRoleRules(t *testing.T) {
  36. tests := map[string]struct {
  37. expectedRole *rbacv1.ClusterRole
  38. actualRole *rbacv1.ClusterRole
  39. removeExtraPermissions bool
  40. expectedReconciledRole *rbacv1.ClusterRole
  41. expectedReconciliationNeeded bool
  42. }{
  43. "empty": {
  44. expectedRole: role(rules(), nil, nil),
  45. actualRole: role(rules(), nil, nil),
  46. removeExtraPermissions: true,
  47. expectedReconciledRole: nil,
  48. expectedReconciliationNeeded: false,
  49. },
  50. "match without union": {
  51. expectedRole: role(rules("a"), nil, nil),
  52. actualRole: role(rules("a"), nil, nil),
  53. removeExtraPermissions: true,
  54. expectedReconciledRole: nil,
  55. expectedReconciliationNeeded: false,
  56. },
  57. "match with union": {
  58. expectedRole: role(rules("a"), nil, nil),
  59. actualRole: role(rules("a"), nil, nil),
  60. removeExtraPermissions: false,
  61. expectedReconciledRole: nil,
  62. expectedReconciliationNeeded: false,
  63. },
  64. "different rules without union": {
  65. expectedRole: role(rules("a"), nil, nil),
  66. actualRole: role(rules("b"), nil, nil),
  67. removeExtraPermissions: true,
  68. expectedReconciledRole: role(rules("a"), nil, nil),
  69. expectedReconciliationNeeded: true,
  70. },
  71. "different rules with union": {
  72. expectedRole: role(rules("a"), nil, nil),
  73. actualRole: role(rules("b"), nil, nil),
  74. removeExtraPermissions: false,
  75. expectedReconciledRole: role(rules("b", "a"), nil, nil),
  76. expectedReconciliationNeeded: true,
  77. },
  78. "match labels without union": {
  79. expectedRole: role(rules("a"), ss{"1": "a"}, nil),
  80. actualRole: role(rules("a"), ss{"1": "a"}, nil),
  81. removeExtraPermissions: true,
  82. expectedReconciledRole: nil,
  83. expectedReconciliationNeeded: false,
  84. },
  85. "match labels with union": {
  86. expectedRole: role(rules("a"), ss{"1": "a"}, nil),
  87. actualRole: role(rules("a"), ss{"1": "a"}, nil),
  88. removeExtraPermissions: false,
  89. expectedReconciledRole: nil,
  90. expectedReconciliationNeeded: false,
  91. },
  92. "different labels without union": {
  93. expectedRole: role(rules("a"), ss{"1": "a"}, nil),
  94. actualRole: role(rules("a"), ss{"2": "b"}, nil),
  95. removeExtraPermissions: true,
  96. expectedReconciledRole: role(rules("a"), ss{"1": "a", "2": "b"}, nil),
  97. expectedReconciliationNeeded: true,
  98. },
  99. "different labels with union": {
  100. expectedRole: role(rules("a"), ss{"1": "a"}, nil),
  101. actualRole: role(rules("a"), ss{"2": "b"}, nil),
  102. removeExtraPermissions: false,
  103. expectedReconciledRole: role(rules("a"), ss{"1": "a", "2": "b"}, nil),
  104. expectedReconciliationNeeded: true,
  105. },
  106. "different labels and rules without union": {
  107. expectedRole: role(rules("a"), ss{"1": "a"}, nil),
  108. actualRole: role(rules("b"), ss{"2": "b"}, nil),
  109. removeExtraPermissions: true,
  110. expectedReconciledRole: role(rules("a"), ss{"1": "a", "2": "b"}, nil),
  111. expectedReconciliationNeeded: true,
  112. },
  113. "different labels and rules with union": {
  114. expectedRole: role(rules("a"), ss{"1": "a"}, nil),
  115. actualRole: role(rules("b"), ss{"2": "b"}, nil),
  116. removeExtraPermissions: false,
  117. expectedReconciledRole: role(rules("b", "a"), ss{"1": "a", "2": "b"}, nil),
  118. expectedReconciliationNeeded: true,
  119. },
  120. "conflicting labels and rules without union": {
  121. expectedRole: role(rules("a"), ss{"1": "a"}, nil),
  122. actualRole: role(rules("b"), ss{"1": "b"}, nil),
  123. removeExtraPermissions: true,
  124. expectedReconciledRole: role(rules("a"), ss{"1": "b"}, nil),
  125. expectedReconciliationNeeded: true,
  126. },
  127. "conflicting labels and rules with union": {
  128. expectedRole: role(rules("a"), ss{"1": "a"}, nil),
  129. actualRole: role(rules("b"), ss{"1": "b"}, nil),
  130. removeExtraPermissions: false,
  131. expectedReconciledRole: role(rules("b", "a"), ss{"1": "b"}, nil),
  132. expectedReconciliationNeeded: true,
  133. },
  134. "match annotations without union": {
  135. expectedRole: role(rules("a"), nil, ss{"1": "a"}),
  136. actualRole: role(rules("a"), nil, ss{"1": "a"}),
  137. removeExtraPermissions: true,
  138. expectedReconciledRole: nil,
  139. expectedReconciliationNeeded: false,
  140. },
  141. "match annotations with union": {
  142. expectedRole: role(rules("a"), nil, ss{"1": "a"}),
  143. actualRole: role(rules("a"), nil, ss{"1": "a"}),
  144. removeExtraPermissions: false,
  145. expectedReconciledRole: nil,
  146. expectedReconciliationNeeded: false,
  147. },
  148. "different annotations without union": {
  149. expectedRole: role(rules("a"), nil, ss{"1": "a"}),
  150. actualRole: role(rules("a"), nil, ss{"2": "b"}),
  151. removeExtraPermissions: true,
  152. expectedReconciledRole: role(rules("a"), nil, ss{"1": "a", "2": "b"}),
  153. expectedReconciliationNeeded: true,
  154. },
  155. "different annotations with union": {
  156. expectedRole: role(rules("a"), nil, ss{"1": "a"}),
  157. actualRole: role(rules("a"), nil, ss{"2": "b"}),
  158. removeExtraPermissions: false,
  159. expectedReconciledRole: role(rules("a"), nil, ss{"1": "a", "2": "b"}),
  160. expectedReconciliationNeeded: true,
  161. },
  162. "different annotations and rules without union": {
  163. expectedRole: role(rules("a"), nil, ss{"1": "a"}),
  164. actualRole: role(rules("b"), nil, ss{"2": "b"}),
  165. removeExtraPermissions: true,
  166. expectedReconciledRole: role(rules("a"), nil, ss{"1": "a", "2": "b"}),
  167. expectedReconciliationNeeded: true,
  168. },
  169. "different annotations and rules with union": {
  170. expectedRole: role(rules("a"), nil, ss{"1": "a"}),
  171. actualRole: role(rules("b"), nil, ss{"2": "b"}),
  172. removeExtraPermissions: false,
  173. expectedReconciledRole: role(rules("b", "a"), nil, ss{"1": "a", "2": "b"}),
  174. expectedReconciliationNeeded: true,
  175. },
  176. "conflicting annotations and rules without union": {
  177. expectedRole: role(rules("a"), nil, ss{"1": "a"}),
  178. actualRole: role(rules("b"), nil, ss{"1": "b"}),
  179. removeExtraPermissions: true,
  180. expectedReconciledRole: role(rules("a"), nil, ss{"1": "b"}),
  181. expectedReconciliationNeeded: true,
  182. },
  183. "conflicting annotations and rules with union": {
  184. expectedRole: role(rules("a"), nil, ss{"1": "a"}),
  185. actualRole: role(rules("b"), nil, ss{"1": "b"}),
  186. removeExtraPermissions: false,
  187. expectedReconciledRole: role(rules("b", "a"), nil, ss{"1": "b"}),
  188. expectedReconciliationNeeded: true,
  189. },
  190. "conflicting labels/annotations and rules without union": {
  191. expectedRole: role(rules("a"), ss{"3": "d"}, ss{"1": "a"}),
  192. actualRole: role(rules("b"), ss{"4": "e"}, ss{"1": "b"}),
  193. removeExtraPermissions: true,
  194. expectedReconciledRole: role(rules("a"), ss{"3": "d", "4": "e"}, ss{"1": "b"}),
  195. expectedReconciliationNeeded: true,
  196. },
  197. "conflicting labels/annotations and rules with union": {
  198. expectedRole: role(rules("a"), ss{"3": "d"}, ss{"1": "a"}),
  199. actualRole: role(rules("b"), ss{"4": "e"}, ss{"1": "b"}),
  200. removeExtraPermissions: false,
  201. expectedReconciledRole: role(rules("b", "a"), ss{"3": "d", "4": "e"}, ss{"1": "b"}),
  202. expectedReconciliationNeeded: true,
  203. },
  204. "complex labels/annotations and rules without union": {
  205. expectedRole: role(rules("pods", "nodes", "secrets"), ss{"env": "prod", "color": "blue"}, ss{"description": "fancy", "system": "true"}),
  206. actualRole: role(rules("nodes", "images", "projects"), ss{"color": "red", "team": "pm"}, ss{"system": "false", "owner": "admin", "vip": "yes"}),
  207. removeExtraPermissions: true,
  208. expectedReconciledRole: role(
  209. rules("pods", "nodes", "secrets"),
  210. ss{"env": "prod", "color": "red", "team": "pm"},
  211. ss{"description": "fancy", "system": "false", "owner": "admin", "vip": "yes"}),
  212. expectedReconciliationNeeded: true,
  213. },
  214. "complex labels/annotations and rules with union": {
  215. expectedRole: role(rules("pods", "nodes", "secrets"), ss{"env": "prod", "color": "blue", "manager": "randy"}, ss{"description": "fancy", "system": "true", "up": "true"}),
  216. actualRole: role(rules("nodes", "images", "projects"), ss{"color": "red", "team": "pm"}, ss{"system": "false", "owner": "admin", "vip": "yes", "rate": "down"}),
  217. removeExtraPermissions: false,
  218. expectedReconciledRole: role(
  219. rules("nodes", "images", "projects", "pods", "secrets"),
  220. ss{"env": "prod", "manager": "randy", "color": "red", "team": "pm"},
  221. ss{"description": "fancy", "system": "false", "owner": "admin", "vip": "yes", "rate": "down", "up": "true"}),
  222. expectedReconciliationNeeded: true,
  223. },
  224. }
  225. for k, tc := range tests {
  226. actualRole := ClusterRoleRuleOwner{ClusterRole: tc.actualRole}
  227. expectedRole := ClusterRoleRuleOwner{ClusterRole: tc.expectedRole}
  228. result, err := computeReconciledRole(actualRole, expectedRole, tc.removeExtraPermissions)
  229. if err != nil {
  230. t.Errorf("%s: %v", k, err)
  231. continue
  232. }
  233. reconciliationNeeded := result.Operation != ReconcileNone
  234. if reconciliationNeeded != tc.expectedReconciliationNeeded {
  235. t.Errorf("%s: Expected\n\t%v\ngot\n\t%v", k, tc.expectedReconciliationNeeded, reconciliationNeeded)
  236. continue
  237. }
  238. if reconciliationNeeded && !helper.Semantic.DeepEqual(result.Role.(ClusterRoleRuleOwner).ClusterRole, tc.expectedReconciledRole) {
  239. t.Errorf("%s: Expected\n\t%#v\ngot\n\t%#v", k, tc.expectedReconciledRole, result.Role)
  240. }
  241. }
  242. }
  243. func aggregatedRole(aggregationRule *rbacv1.AggregationRule) *rbacv1.ClusterRole {
  244. return &rbacv1.ClusterRole{
  245. AggregationRule: aggregationRule,
  246. }
  247. }
  248. func aggregationrule(selectors []map[string]string) *rbacv1.AggregationRule {
  249. ret := &rbacv1.AggregationRule{}
  250. for _, selector := range selectors {
  251. ret.ClusterRoleSelectors = append(ret.ClusterRoleSelectors,
  252. metav1.LabelSelector{MatchLabels: selector})
  253. }
  254. return ret
  255. }
  256. func TestComputeReconciledRoleAggregationRules(t *testing.T) {
  257. tests := map[string]struct {
  258. expectedRole *rbacv1.ClusterRole
  259. actualRole *rbacv1.ClusterRole
  260. removeExtraPermissions bool
  261. expectedReconciledRole *rbacv1.ClusterRole
  262. expectedReconciliationNeeded bool
  263. }{
  264. "empty": {
  265. expectedRole: aggregatedRole(&rbacv1.AggregationRule{}),
  266. actualRole: aggregatedRole(nil),
  267. removeExtraPermissions: true,
  268. expectedReconciledRole: nil,
  269. expectedReconciliationNeeded: false,
  270. },
  271. "empty-2": {
  272. expectedRole: aggregatedRole(&rbacv1.AggregationRule{}),
  273. actualRole: aggregatedRole(&rbacv1.AggregationRule{}),
  274. removeExtraPermissions: true,
  275. expectedReconciledRole: nil,
  276. expectedReconciliationNeeded: false,
  277. },
  278. "match without union": {
  279. expectedRole: aggregatedRole(aggregationrule([]map[string]string{{"foo": "bar"}})),
  280. actualRole: aggregatedRole(aggregationrule([]map[string]string{{"foo": "bar"}})),
  281. removeExtraPermissions: true,
  282. expectedReconciledRole: nil,
  283. expectedReconciliationNeeded: false,
  284. },
  285. "match with union": {
  286. expectedRole: aggregatedRole(aggregationrule([]map[string]string{{"foo": "bar"}})),
  287. actualRole: aggregatedRole(aggregationrule([]map[string]string{{"foo": "bar"}})),
  288. removeExtraPermissions: false,
  289. expectedReconciledRole: nil,
  290. expectedReconciliationNeeded: false,
  291. },
  292. "different rules without union": {
  293. expectedRole: aggregatedRole(aggregationrule([]map[string]string{{"foo": "bar"}})),
  294. actualRole: aggregatedRole(aggregationrule([]map[string]string{{"alpha": "bravo"}})),
  295. removeExtraPermissions: true,
  296. expectedReconciledRole: aggregatedRole(aggregationrule([]map[string]string{{"foo": "bar"}})),
  297. expectedReconciliationNeeded: true,
  298. },
  299. "different rules with union": {
  300. expectedRole: aggregatedRole(aggregationrule([]map[string]string{{"foo": "bar"}})),
  301. actualRole: aggregatedRole(aggregationrule([]map[string]string{{"alpha": "bravo"}})),
  302. removeExtraPermissions: false,
  303. expectedReconciledRole: aggregatedRole(aggregationrule([]map[string]string{{"alpha": "bravo"}, {"foo": "bar"}})),
  304. expectedReconciliationNeeded: true,
  305. },
  306. "unexpected aggregation": {
  307. // desired role is not aggregated
  308. expectedRole: role(rules("pods", "nodes", "secrets"), nil, nil),
  309. // existing role is aggregated
  310. actualRole: aggregatedRole(aggregationrule([]map[string]string{{"alpha": "bravo"}})),
  311. removeExtraPermissions: false,
  312. // reconciled role should have desired permissions and not be aggregated
  313. expectedReconciledRole: role(rules("pods", "nodes", "secrets"), nil, nil),
  314. expectedReconciliationNeeded: true,
  315. },
  316. "unexpected aggregation with differing permissions": {
  317. // desired role is not aggregated
  318. expectedRole: role(rules("pods", "nodes", "secrets"), nil, nil),
  319. // existing role is aggregated and has other permissions
  320. actualRole: func() *rbacv1.ClusterRole {
  321. r := aggregatedRole(aggregationrule([]map[string]string{{"alpha": "bravo"}}))
  322. r.Rules = rules("deployments")
  323. return r
  324. }(),
  325. removeExtraPermissions: false,
  326. // reconciled role should have aggregation removed, preserve differing permissions, and include desired permissions
  327. expectedReconciledRole: role(rules("deployments", "pods", "nodes", "secrets"), nil, nil),
  328. expectedReconciliationNeeded: true,
  329. },
  330. }
  331. for k, tc := range tests {
  332. actualRole := ClusterRoleRuleOwner{ClusterRole: tc.actualRole}
  333. expectedRole := ClusterRoleRuleOwner{ClusterRole: tc.expectedRole}
  334. result, err := computeReconciledRole(actualRole, expectedRole, tc.removeExtraPermissions)
  335. if err != nil {
  336. t.Errorf("%s: %v", k, err)
  337. continue
  338. }
  339. reconciliationNeeded := result.Operation != ReconcileNone
  340. if reconciliationNeeded != tc.expectedReconciliationNeeded {
  341. t.Errorf("%s: Expected\n\t%v\ngot\n\t%v", k, tc.expectedReconciliationNeeded, reconciliationNeeded)
  342. continue
  343. }
  344. if reconciliationNeeded && !helper.Semantic.DeepEqual(result.Role.(ClusterRoleRuleOwner).ClusterRole, tc.expectedReconciledRole) {
  345. t.Errorf("%s: %v", k, diff.ObjectDiff(tc.expectedReconciledRole, result.Role.(ClusterRoleRuleOwner).ClusterRole))
  346. }
  347. }
  348. }