-
Notifications
You must be signed in to change notification settings - Fork 141
/
auth.go
132 lines (123 loc) · 3.9 KB
/
auth.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
package e2e
import (
"context"
"fmt"
clolog "github.com/ViaQ/logerr/v2/log/static"
"github.com/openshift/cluster-logging-operator/internal/constants"
"github.com/openshift/cluster-logging-operator/internal/runtime"
corev1 "k8s.io/api/core/v1"
rbacv1 "k8s.io/api/rbac/v1"
"k8s.io/apimachinery/pkg/api/errors"
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
"math/rand"
"time"
)
type AuthorizationBuilder struct {
tc *E2ETestFramework
saNamespace string
saName string
roleNames []string
}
func (tc *E2ETestFramework) BuildAuthorizationFor(saNamespace, saName string) *AuthorizationBuilder {
return &AuthorizationBuilder{
tc: tc,
saNamespace: saNamespace,
saName: saName,
}
}
func (b *AuthorizationBuilder) AllowClusterRole(roleName string) *AuthorizationBuilder {
b.roleNames = append(b.roleNames, roleName)
return b
}
func (b *AuthorizationBuilder) Create() (sa *corev1.ServiceAccount, err error) {
sa, err = b.tc.createServiceAccount(b.saNamespace, b.saName)
if err != nil && !errors.IsAlreadyExists(err) {
return nil, err
}
for _, role := range b.roleNames {
crb := runtime.NewClusterRoleBinding(fmt.Sprintf("%s-%s-%d%d", sa.Namespace, sa.Name, time.Now().Unix(), rand.Intn(100)),
rbacv1.RoleRef{
APIGroup: "rbac.authorization.k8s.io",
Kind: "ClusterRole",
Name: role,
},
rbacv1.Subject{
Kind: "ServiceAccount",
Name: sa.Name,
Namespace: sa.Namespace,
},
)
b.tc.AddCleanup(func() error {
var zerograce int64
opts := metav1.DeleteOptions{
GracePeriodSeconds: &zerograce,
}
return b.tc.KubeClient.RbacV1().ClusterRoleBindings().Delete(context.TODO(), crb.GetName(), opts)
})
opts := metav1.CreateOptions{}
clolog.V(3).Info("Creating", "clusterrolebinding", crb.Name, "namespace", sa.Namespace, "name", sa.Name)
if _, err = b.tc.KubeClient.RbacV1().ClusterRoleBindings().Create(context.TODO(), crb, opts); err != nil && !errors.IsAlreadyExists(err) {
return nil, err
}
}
return sa, nil
}
func (tc *E2ETestFramework) createServiceAccount(namespace, name string) (serviceAccount *corev1.ServiceAccount, err error) {
opts := metav1.CreateOptions{}
serviceAccount = runtime.NewServiceAccount(namespace, name)
clolog.V(3).Info("Creating serviceaccount", "serviceaccount", serviceAccount)
if serviceAccount, err = tc.KubeClient.CoreV1().ServiceAccounts(namespace).Create(context.TODO(), serviceAccount, opts); err != nil {
return nil, err
}
tc.AddCleanup(func() error {
opts := metav1.DeleteOptions{}
return tc.KubeClient.CoreV1().ServiceAccounts(namespace).Delete(context.TODO(), serviceAccount.Name, opts)
})
return serviceAccount, nil
}
func (tc *E2ETestFramework) createRbac(name string) (err error) {
opts := metav1.CreateOptions{}
saRole := runtime.NewRole(
constants.OpenshiftNS,
name,
runtime.NewPolicyRules(
runtime.NewPolicyRule(
[]string{"security.openshift.io"},
[]string{"securitycontextconstraints"},
[]string{"privileged"},
[]string{"use"},
),
)...,
)
if _, err = tc.KubeClient.RbacV1().Roles(constants.OpenshiftNS).Create(context.TODO(), saRole, opts); err != nil {
return err
}
tc.AddCleanup(func() error {
opts := metav1.DeleteOptions{}
return tc.KubeClient.RbacV1().Roles(constants.OpenshiftNS).Delete(context.TODO(), name, opts)
})
subject := runtime.NewSubject(
"ServiceAccount",
name,
)
subject.APIGroup = ""
roleBinding := runtime.NewRoleBinding(
constants.OpenshiftNS,
name,
rbacv1.RoleRef{
Kind: "Role",
Name: saRole.Name,
APIGroup: rbacv1.GroupName,
}, runtime.NewSubjects(
subject,
)...,
)
if _, err = tc.KubeClient.RbacV1().RoleBindings(constants.OpenshiftNS).Create(context.TODO(), roleBinding, opts); err != nil {
return err
}
tc.AddCleanup(func() error {
opts := metav1.DeleteOptions{}
return tc.KubeClient.RbacV1().RoleBindings(constants.OpenshiftNS).Delete(context.TODO(), name, opts)
})
return nil
}