mirror of
https://github.com/k3s-io/kubernetes.git
synced 2025-08-03 09:22:44 +00:00
Added ability to execute subsets of cli tests
This commit is contained in:
parent
69cb938a6a
commit
163844cb13
@ -291,7 +291,6 @@ test-cmd:
|
|||||||
@echo "$$TEST_CMD_HELP_INFO"
|
@echo "$$TEST_CMD_HELP_INFO"
|
||||||
else
|
else
|
||||||
test-cmd: generated_files
|
test-cmd: generated_files
|
||||||
hack/make-rules/test-kubeadm-cmd.sh
|
|
||||||
hack/make-rules/test-cmd.sh
|
hack/make-rules/test-cmd.sh
|
||||||
endif
|
endif
|
||||||
|
|
||||||
|
44
test/cmd/README.md
Normal file
44
test/cmd/README.md
Normal file
@ -0,0 +1,44 @@
|
|||||||
|
# Kubernetes Command-Line Integration Test Suite
|
||||||
|
|
||||||
|
This document describes how Kubernetes should interact with the Kubernetes command-line integration test suite.
|
||||||
|
|
||||||
|
## Running Tests
|
||||||
|
|
||||||
|
### All Tests
|
||||||
|
|
||||||
|
To run this entire suite, execute `make test-cmd` from the top level. This will import each file containing tests functions
|
||||||
|
|
||||||
|
### Specific Tests
|
||||||
|
|
||||||
|
To run a subset of tests( e.g. `run_deployment_test` and `run_impersonation_test`), execute `make test-cmd WHAT="deployment impersonation"`. Running specific
|
||||||
|
tests will not try and validate any required resources are available on the server.
|
||||||
|
|
||||||
|
## Adding Tests
|
||||||
|
|
||||||
|
Test functions need to have the format `run_*_test` so they can executed individually. Once a test has been added, insert a section in `legacy-script.sh` like
|
||||||
|
|
||||||
|
```bash
|
||||||
|
######################
|
||||||
|
# Replica Sets #
|
||||||
|
######################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${replicasets}" ; then
|
||||||
|
record_command run_rs_tests
|
||||||
|
fi
|
||||||
|
```
|
||||||
|
|
||||||
|
Be sure to validate any supported resouces required for the test by using the `kue::test::if_supports_resource` function.
|
||||||
|
|
||||||
|
|
||||||
|
### New File
|
||||||
|
|
||||||
|
If the test resides in a new file, source the file in the top of the `legacy-script.sh` file by adding a new line in
|
||||||
|
```bash
|
||||||
|
source "${KUBE_ROOT}/test/cmd/apply.sh"
|
||||||
|
source "${KUBE_ROOT}/test/cmd/apps.sh"
|
||||||
|
source "${KUBE_ROOT}/test/cmd/authorization.sh"
|
||||||
|
source "${KUBE_ROOT}/test/cmd/batch.sh"
|
||||||
|
...
|
||||||
|
```
|
||||||
|
|
||||||
|
Please keep the order of the source list alphabetical.
|
@ -18,15 +18,20 @@ set -o errexit
|
|||||||
set -o nounset
|
set -o nounset
|
||||||
set -o pipefail
|
set -o pipefail
|
||||||
|
|
||||||
KUBE_ROOT=$(dirname "${BASH_SOURCE}")/../..
|
run_kubeadm_tests() {
|
||||||
source "${KUBE_ROOT}/hack/lib/init.sh"
|
set -o nounset
|
||||||
|
set -o errexit
|
||||||
|
KUBE_ROOT=$(dirname "${BASH_SOURCE}")/../..
|
||||||
|
|
||||||
KUBEADM_PATH="${KUBEADM_PATH:=$(kube::realpath "${KUBE_ROOT}")/cluster/kubeadm.sh}"
|
KUBEADM_PATH="${KUBEADM_PATH:=$(kube::realpath "${KUBE_ROOT}")/cluster/kubeadm.sh}"
|
||||||
|
|
||||||
# If testing a different version of kubeadm than the current build, you can
|
# If testing a different version of kubeadm than the current build, you can
|
||||||
# comment this out to save yourself from needlessly building here.
|
# comment this out to save yourself from needlessly building here.
|
||||||
make -C "${KUBE_ROOT}" WHAT=cmd/kubeadm
|
make -C "${KUBE_ROOT}" WHAT=cmd/kubeadm
|
||||||
|
|
||||||
make -C "${KUBE_ROOT}" test \
|
make -C "${KUBE_ROOT}" test \
|
||||||
WHAT=k8s.io/kubernetes/cmd/kubeadm/test/cmd \
|
WHAT=k8s.io/kubernetes/cmd/kubeadm/test/cmd \
|
||||||
KUBE_TEST_ARGS="--kubeadm-path '${KUBEADM_PATH}'"
|
KUBE_TEST_ARGS="--kubeadm-path '${KUBEADM_PATH}'"
|
||||||
|
set +o nounset
|
||||||
|
set +o errexit
|
||||||
|
}
|
@ -20,6 +20,15 @@ set -o errexit
|
|||||||
set -o nounset
|
set -o nounset
|
||||||
set -o pipefail
|
set -o pipefail
|
||||||
|
|
||||||
|
if [ ! -z "$WHAT" ]; then #ccheck not empty
|
||||||
|
for pkg in ${WHAT}
|
||||||
|
do
|
||||||
|
echo ${pkg}
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
exit 0
|
||||||
|
|
||||||
|
|
||||||
# Set locale to ensure english responses from kubectl commands
|
# Set locale to ensure english responses from kubectl commands
|
||||||
export LANG=C
|
export LANG=C
|
||||||
|
|
||||||
@ -40,6 +49,7 @@ source "${KUBE_ROOT}/test/cmd/discovery.sh"
|
|||||||
source "${KUBE_ROOT}/test/cmd/generic-resources.sh"
|
source "${KUBE_ROOT}/test/cmd/generic-resources.sh"
|
||||||
source "${KUBE_ROOT}/test/cmd/get.sh"
|
source "${KUBE_ROOT}/test/cmd/get.sh"
|
||||||
source "${KUBE_ROOT}/test/cmd/initializers.sh"
|
source "${KUBE_ROOT}/test/cmd/initializers.sh"
|
||||||
|
source "${KUBE_ROOT}/test/cmd/kubeadm.sh"
|
||||||
source "${KUBE_ROOT}/test/cmd/kubeconfig.sh"
|
source "${KUBE_ROOT}/test/cmd/kubeconfig.sh"
|
||||||
source "${KUBE_ROOT}/test/cmd/node-management.sh"
|
source "${KUBE_ROOT}/test/cmd/node-management.sh"
|
||||||
source "${KUBE_ROOT}/test/cmd/old-print.sh"
|
source "${KUBE_ROOT}/test/cmd/old-print.sh"
|
||||||
@ -384,455 +394,462 @@ runTests() {
|
|||||||
kubectl get "${kube_flags[@]}" -f hack/testdata/kubernetes-service.yaml
|
kubectl get "${kube_flags[@]}" -f hack/testdata/kubernetes-service.yaml
|
||||||
fi
|
fi
|
||||||
|
|
||||||
#########################
|
if [ ! -z "$WHAT" ]; then #ccheck not empty
|
||||||
# Kubectl version #
|
for pkg in ${WHAT}
|
||||||
#########################
|
do
|
||||||
|
record_command run_${pkg}_tests
|
||||||
|
done
|
||||||
|
else
|
||||||
|
|
||||||
record_command run_kubectl_version_tests
|
#########################
|
||||||
|
# Kubectl version #
|
||||||
|
#########################
|
||||||
|
|
||||||
#######################
|
record_command run_kubectl_version_tests
|
||||||
# kubectl config set #
|
|
||||||
#######################
|
|
||||||
|
|
||||||
record_command run_kubectl_config_set_tests
|
#######################
|
||||||
|
# kubectl config set #
|
||||||
|
#######################
|
||||||
|
|
||||||
#######################
|
record_command run_kubectl_config_set_tests
|
||||||
# kubectl local proxy #
|
|
||||||
#######################
|
|
||||||
|
|
||||||
record_command run_kubectl_local_proxy_tests
|
#######################
|
||||||
|
# kubectl local proxy #
|
||||||
|
#######################
|
||||||
|
|
||||||
#########################
|
record_command run_kubectl_local_proxy_tests
|
||||||
# RESTMapper evaluation #
|
|
||||||
#########################
|
|
||||||
|
|
||||||
record_command run_RESTMapper_evaluation_tests
|
#########################
|
||||||
|
# RESTMapper evaluation #
|
||||||
|
#########################
|
||||||
|
|
||||||
# find all resources
|
record_command run_RESTMapper_evaluation_tests
|
||||||
kubectl "${kube_flags[@]}" api-resources
|
|
||||||
# find all namespaced resources that support list by name and get them
|
|
||||||
kubectl "${kube_flags[@]}" api-resources --verbs=list --namespaced -o name | xargs -n 1 kubectl "${kube_flags[@]}" get -o name
|
|
||||||
|
|
||||||
################
|
# find all resources
|
||||||
# Cluster Role #
|
kubectl "${kube_flags[@]}" api-resources
|
||||||
################
|
# find all namespaced resources that support list by name and get them
|
||||||
|
kubectl "${kube_flags[@]}" api-resources --verbs=list --namespaced -o name | xargs -n 1 kubectl "${kube_flags[@]}" get -o name
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${clusterroles}" ; then
|
################
|
||||||
record_command run_clusterroles_tests
|
# Cluster Role #
|
||||||
fi
|
################
|
||||||
|
|
||||||
########
|
if kube::test::if_supports_resource "${clusterroles}" ; then
|
||||||
# Role #
|
record_command run_clusterroles_tests
|
||||||
########
|
|
||||||
if kube::test::if_supports_resource "${roles}" ; then
|
|
||||||
record_command run_role_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
#########################
|
|
||||||
# Assert short name #
|
|
||||||
#########################
|
|
||||||
|
|
||||||
record_command run_assert_short_name_tests
|
|
||||||
|
|
||||||
#########################
|
|
||||||
# Assert categories #
|
|
||||||
#########################
|
|
||||||
|
|
||||||
## test if a category is exported during discovery
|
|
||||||
if kube::test::if_supports_resource "${pods}" ; then
|
|
||||||
record_command run_assert_categories_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
###########################
|
|
||||||
# POD creation / deletion #
|
|
||||||
###########################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${pods}" ; then
|
|
||||||
record_command run_pod_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${pods}" ; then
|
|
||||||
record_command run_save_config_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${pods}" ; then
|
|
||||||
record_command run_kubectl_create_error_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${pods}" ; then
|
|
||||||
record_command run_kubectl_apply_tests
|
|
||||||
record_command run_kubectl_run_tests
|
|
||||||
record_command run_kubectl_create_filter_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${deployments}" ; then
|
|
||||||
record_command run_kubectl_apply_deployments_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
################
|
|
||||||
# Kubectl diff #
|
|
||||||
################
|
|
||||||
record_command run_kubectl_diff_tests
|
|
||||||
record_command run_kubectl_diff_same_names
|
|
||||||
|
|
||||||
###############
|
|
||||||
# Kubectl get #
|
|
||||||
###############
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${pods}" ; then
|
|
||||||
record_command run_kubectl_get_tests
|
|
||||||
record_command run_kubectl_old_print_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
|
|
||||||
######################
|
|
||||||
# Create #
|
|
||||||
######################
|
|
||||||
if kube::test::if_supports_resource "${secrets}" ; then
|
|
||||||
record_command run_create_secret_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
##################
|
|
||||||
# Global timeout #
|
|
||||||
##################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${pods}" ; then
|
|
||||||
record_command run_kubectl_request_timeout_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
#####################################
|
|
||||||
# CustomResourceDefinitions #
|
|
||||||
#####################################
|
|
||||||
|
|
||||||
# customresourcedefinitions cleanup after themselves.
|
|
||||||
if kube::test::if_supports_resource "${customresourcedefinitions}" ; then
|
|
||||||
record_command run_crd_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
#################
|
|
||||||
# Run cmd w img #
|
|
||||||
#################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${deployments}" ; then
|
|
||||||
record_command run_cmd_with_img_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
|
|
||||||
#####################################
|
|
||||||
# Recursive Resources via directory #
|
|
||||||
#####################################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${pods}" ; then
|
|
||||||
run_recursive_resources_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
|
|
||||||
##############
|
|
||||||
# Namespaces #
|
|
||||||
##############
|
|
||||||
if kube::test::if_supports_resource "${namespaces}" ; then
|
|
||||||
record_command run_namespace_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
|
|
||||||
###########
|
|
||||||
# Secrets #
|
|
||||||
###########
|
|
||||||
if kube::test::if_supports_resource "${namespaces}" ; then
|
|
||||||
if kube::test::if_supports_resource "${secrets}" ; then
|
|
||||||
record_command run_secrets_test
|
|
||||||
fi
|
fi
|
||||||
fi
|
|
||||||
|
|
||||||
|
########
|
||||||
######################
|
# Role #
|
||||||
# ConfigMap #
|
########
|
||||||
######################
|
if kube::test::if_supports_resource "${roles}" ; then
|
||||||
|
record_command run_role_tests
|
||||||
if kube::test::if_supports_resource "${namespaces}"; then
|
|
||||||
if kube::test::if_supports_resource "${configmaps}" ; then
|
|
||||||
record_command run_configmap_tests
|
|
||||||
fi
|
fi
|
||||||
fi
|
|
||||||
|
|
||||||
####################
|
#########################
|
||||||
# Client Config #
|
# Assert short name #
|
||||||
####################
|
#########################
|
||||||
|
|
||||||
record_command run_client_config_tests
|
record_command run_assert_short_name_tests
|
||||||
|
|
||||||
####################
|
#########################
|
||||||
# Service Accounts #
|
# Assert categories #
|
||||||
####################
|
#########################
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${namespaces}" && kube::test::if_supports_resource "${serviceaccounts}" ; then
|
## test if a category is exported during discovery
|
||||||
record_command run_service_accounts_tests
|
if kube::test::if_supports_resource "${pods}" ; then
|
||||||
fi
|
record_command run_assert_categories_tests
|
||||||
|
|
||||||
####################
|
|
||||||
# Job #
|
|
||||||
####################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${job}" ; then
|
|
||||||
record_command run_job_tests
|
|
||||||
record_command run_create_job_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
#################
|
|
||||||
# Pod templates #
|
|
||||||
#################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${podtemplates}" ; then
|
|
||||||
record_command run_pod_templates_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
############
|
|
||||||
# Services #
|
|
||||||
############
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${services}" ; then
|
|
||||||
record_command run_service_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
##################
|
|
||||||
# DaemonSets #
|
|
||||||
##################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${daemonsets}" ; then
|
|
||||||
record_command run_daemonset_tests
|
|
||||||
if kube::test::if_supports_resource "${controllerrevisions}"; then
|
|
||||||
record_command run_daemonset_history_tests
|
|
||||||
fi
|
fi
|
||||||
fi
|
|
||||||
|
|
||||||
###########################
|
###########################
|
||||||
# Replication controllers #
|
# POD creation / deletion #
|
||||||
###########################
|
###########################
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${namespaces}" ; then
|
if kube::test::if_supports_resource "${pods}" ; then
|
||||||
if kube::test::if_supports_resource "${replicationcontrollers}" ; then
|
record_command run_pod_tests
|
||||||
record_command run_rc_tests
|
|
||||||
fi
|
fi
|
||||||
fi
|
|
||||||
|
|
||||||
######################
|
if kube::test::if_supports_resource "${pods}" ; then
|
||||||
# Deployments #
|
record_command run_save_config_tests
|
||||||
######################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${deployments}" ; then
|
|
||||||
record_command run_deployment_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
######################
|
|
||||||
# Replica Sets #
|
|
||||||
######################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${replicasets}" ; then
|
|
||||||
record_command run_rs_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
#################
|
|
||||||
# Stateful Sets #
|
|
||||||
#################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${statefulsets}" ; then
|
|
||||||
record_command run_stateful_set_tests
|
|
||||||
if kube::test::if_supports_resource "${controllerrevisions}"; then
|
|
||||||
record_command run_statefulset_history_tests
|
|
||||||
fi
|
fi
|
||||||
fi
|
|
||||||
|
|
||||||
######################
|
if kube::test::if_supports_resource "${pods}" ; then
|
||||||
# Lists #
|
record_command run_kubectl_create_error_tests
|
||||||
######################
|
fi
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${pods}" ; then
|
||||||
|
record_command run_kubectl_apply_tests
|
||||||
|
record_command run_kubectl_run_tests
|
||||||
|
record_command run_kubectl_create_filter_tests
|
||||||
|
fi
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${services}" ; then
|
|
||||||
if kube::test::if_supports_resource "${deployments}" ; then
|
if kube::test::if_supports_resource "${deployments}" ; then
|
||||||
record_command run_lists_tests
|
record_command run_kubectl_apply_deployments_tests
|
||||||
fi
|
fi
|
||||||
fi
|
|
||||||
|
|
||||||
|
################
|
||||||
|
# Kubectl diff #
|
||||||
|
################
|
||||||
|
record_command run_kubectl_diff_tests
|
||||||
|
record_command run_kubectl_diff_same_names
|
||||||
|
|
||||||
######################
|
###############
|
||||||
# Multiple Resources #
|
# Kubectl get #
|
||||||
######################
|
###############
|
||||||
if kube::test::if_supports_resource "${services}" ; then
|
|
||||||
if kube::test::if_supports_resource "${replicationcontrollers}" ; then
|
if kube::test::if_supports_resource "${pods}" ; then
|
||||||
record_command run_multi_resources_tests
|
record_command run_kubectl_get_tests
|
||||||
|
record_command run_kubectl_old_print_tests
|
||||||
fi
|
fi
|
||||||
fi
|
|
||||||
|
|
||||||
######################
|
|
||||||
# Persistent Volumes #
|
|
||||||
######################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${persistentvolumes}" ; then
|
|
||||||
record_command run_persistent_volumes_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
############################
|
|
||||||
# Persistent Volume Claims #
|
|
||||||
############################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${persistentvolumeclaims}" ; then
|
|
||||||
record_command run_persistent_volume_claims_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
############################
|
|
||||||
# Storage Classes #
|
|
||||||
############################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${storageclass}" ; then
|
|
||||||
record_command run_storage_class_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
#########
|
|
||||||
# Nodes #
|
|
||||||
#########
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${nodes}" ; then
|
|
||||||
record_command run_nodes_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
|
|
||||||
########################
|
######################
|
||||||
# authorization.k8s.io #
|
# Create #
|
||||||
########################
|
######################
|
||||||
|
if kube::test::if_supports_resource "${secrets}" ; then
|
||||||
|
record_command run_create_secret_tests
|
||||||
|
fi
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${subjectaccessreviews}" ; then
|
##################
|
||||||
record_command run_authorization_tests
|
# Global timeout #
|
||||||
fi
|
##################
|
||||||
|
|
||||||
# kubectl auth can-i
|
if kube::test::if_supports_resource "${pods}" ; then
|
||||||
# kube-apiserver is started with authorization mode AlwaysAllow, so kubectl can-i always returns yes
|
record_command run_kubectl_request_timeout_tests
|
||||||
if kube::test::if_supports_resource "${subjectaccessreviews}" ; then
|
fi
|
||||||
output_message=$(kubectl auth can-i '*' '*' 2>&1 "${kube_flags[@]}")
|
|
||||||
kube::test::if_has_string "${output_message}" "yes"
|
|
||||||
|
|
||||||
output_message=$(kubectl auth can-i get pods --subresource=log 2>&1 "${kube_flags[@]}")
|
#####################################
|
||||||
kube::test::if_has_string "${output_message}" "yes"
|
# CustomResourceDefinitions #
|
||||||
|
#####################################
|
||||||
|
|
||||||
output_message=$(kubectl auth can-i get invalid_resource 2>&1 "${kube_flags[@]}")
|
# customresourcedefinitions cleanup after themselves.
|
||||||
kube::test::if_has_string "${output_message}" "the server doesn't have a resource type"
|
if kube::test::if_supports_resource "${customresourcedefinitions}" ; then
|
||||||
|
record_command run_crd_tests
|
||||||
|
fi
|
||||||
|
|
||||||
output_message=$(kubectl auth can-i get /logs/ 2>&1 "${kube_flags[@]}")
|
#################
|
||||||
kube::test::if_has_string "${output_message}" "yes"
|
# Run cmd w img #
|
||||||
|
#################
|
||||||
|
|
||||||
output_message=$(! kubectl auth can-i get /logs/ --subresource=log 2>&1 "${kube_flags[@]}")
|
if kube::test::if_supports_resource "${deployments}" ; then
|
||||||
kube::test::if_has_string "${output_message}" "subresource can not be used with NonResourceURL"
|
record_command run_cmd_with_img_tests
|
||||||
|
fi
|
||||||
|
|
||||||
output_message=$(kubectl auth can-i list jobs.batch/bar -n foo --quiet 2>&1 "${kube_flags[@]}")
|
|
||||||
kube::test::if_empty_string "${output_message}"
|
|
||||||
|
|
||||||
output_message=$(kubectl auth can-i get pods --subresource=log 2>&1 "${kube_flags[@]}"; echo $?)
|
#####################################
|
||||||
kube::test::if_has_string "${output_message}" '0'
|
# Recursive Resources via directory #
|
||||||
|
#####################################
|
||||||
|
|
||||||
output_message=$(kubectl auth can-i get pods --subresource=log --quiet 2>&1 "${kube_flags[@]}"; echo $?)
|
if kube::test::if_supports_resource "${pods}" ; then
|
||||||
kube::test::if_has_string "${output_message}" '0'
|
run_recursive_resources_tests
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# kubectl auth reconcile
|
|
||||||
if kube::test::if_supports_resource "${clusterroles}" ; then
|
|
||||||
kubectl auth reconcile "${kube_flags[@]}" -f test/fixtures/pkg/kubectl/cmd/auth/rbac-resource-plus.yaml
|
|
||||||
kube::test::get_object_assert 'rolebindings -n some-other-random -l test-cmd=auth' "{{range.items}}{{$id_field}}:{{end}}" 'testing-RB:'
|
|
||||||
kube::test::get_object_assert 'roles -n some-other-random -l test-cmd=auth' "{{range.items}}{{$id_field}}:{{end}}" 'testing-R:'
|
|
||||||
kube::test::get_object_assert 'clusterrolebindings -l test-cmd=auth' "{{range.items}}{{$id_field}}:{{end}}" 'testing-CRB:'
|
|
||||||
kube::test::get_object_assert 'clusterroles -l test-cmd=auth' "{{range.items}}{{$id_field}}:{{end}}" 'testing-CR:'
|
|
||||||
|
|
||||||
failure_message=$(! kubectl auth reconcile "${kube_flags[@]}" -f test/fixtures/pkg/kubectl/cmd/auth/rbac-v1beta1.yaml 2>&1 )
|
##############
|
||||||
kube::test::if_has_string "${failure_message}" 'only rbac.authorization.k8s.io/v1 is supported'
|
# Namespaces #
|
||||||
|
##############
|
||||||
|
if kube::test::if_supports_resource "${namespaces}" ; then
|
||||||
|
record_command run_namespace_tests
|
||||||
|
fi
|
||||||
|
|
||||||
kubectl delete "${kube_flags[@]}" rolebindings,role,clusterroles,clusterrolebindings -n some-other-random -l test-cmd=auth
|
|
||||||
fi
|
|
||||||
|
|
||||||
#####################
|
###########
|
||||||
# Retrieve multiple #
|
# Secrets #
|
||||||
#####################
|
###########
|
||||||
|
if kube::test::if_supports_resource "${namespaces}" ; then
|
||||||
|
if kube::test::if_supports_resource "${secrets}" ; then
|
||||||
|
record_command run_secrets_test
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
|
||||||
|
######################
|
||||||
|
# ConfigMap #
|
||||||
|
######################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${namespaces}"; then
|
||||||
|
if kube::test::if_supports_resource "${configmaps}" ; then
|
||||||
|
record_command run_configmap_tests
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
####################
|
||||||
|
# Client Config #
|
||||||
|
####################
|
||||||
|
|
||||||
|
record_command run_client_config_tests
|
||||||
|
|
||||||
|
####################
|
||||||
|
# Service Accounts #
|
||||||
|
####################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${namespaces}" && kube::test::if_supports_resource "${serviceaccounts}" ; then
|
||||||
|
record_command run_service_accounts_tests
|
||||||
|
fi
|
||||||
|
|
||||||
|
####################
|
||||||
|
# Job #
|
||||||
|
####################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${job}" ; then
|
||||||
|
record_command run_job_tests
|
||||||
|
record_command run_create_job_tests
|
||||||
|
fi
|
||||||
|
|
||||||
|
#################
|
||||||
|
# Pod templates #
|
||||||
|
#################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${podtemplates}" ; then
|
||||||
|
record_command run_pod_templates_tests
|
||||||
|
fi
|
||||||
|
|
||||||
|
############
|
||||||
|
# Services #
|
||||||
|
############
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${nodes}" ; then
|
|
||||||
if kube::test::if_supports_resource "${services}" ; then
|
if kube::test::if_supports_resource "${services}" ; then
|
||||||
record_command run_retrieve_multiple_tests
|
record_command run_service_tests
|
||||||
fi
|
fi
|
||||||
fi
|
|
||||||
|
|
||||||
|
##################
|
||||||
|
# DaemonSets #
|
||||||
|
##################
|
||||||
|
|
||||||
#####################
|
if kube::test::if_supports_resource "${daemonsets}" ; then
|
||||||
# Resource aliasing #
|
record_command run_daemonset_tests
|
||||||
#####################
|
if kube::test::if_supports_resource "${controllerrevisions}"; then
|
||||||
|
record_command run_daemonset_history_tests
|
||||||
if kube::test::if_supports_resource "${services}" ; then
|
fi
|
||||||
if kube::test::if_supports_resource "${replicationcontrollers}" ; then
|
|
||||||
record_command run_resource_aliasing_tests
|
|
||||||
fi
|
fi
|
||||||
fi
|
|
||||||
|
|
||||||
###########
|
###########################
|
||||||
# Explain #
|
# Replication controllers #
|
||||||
###########
|
###########################
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${pods}" ; then
|
if kube::test::if_supports_resource "${namespaces}" ; then
|
||||||
record_command run_kubectl_explain_tests
|
if kube::test::if_supports_resource "${replicationcontrollers}" ; then
|
||||||
fi
|
record_command run_rc_tests
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
######################
|
||||||
|
# Deployments #
|
||||||
|
######################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${deployments}" ; then
|
||||||
|
record_command run_deployment_tests
|
||||||
|
fi
|
||||||
|
|
||||||
|
######################
|
||||||
|
# Replica Sets #
|
||||||
|
######################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${replicasets}" ; then
|
||||||
|
record_command run_rs_tests
|
||||||
|
fi
|
||||||
|
|
||||||
|
#################
|
||||||
|
# Stateful Sets #
|
||||||
|
#################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${statefulsets}" ; then
|
||||||
|
record_command run_stateful_set_tests
|
||||||
|
if kube::test::if_supports_resource "${controllerrevisions}"; then
|
||||||
|
record_command run_statefulset_history_tests
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
######################
|
||||||
|
# Lists #
|
||||||
|
######################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${services}" ; then
|
||||||
|
if kube::test::if_supports_resource "${deployments}" ; then
|
||||||
|
record_command run_lists_tests
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
|
||||||
###########
|
######################
|
||||||
# Swagger #
|
# Multiple Resources #
|
||||||
###########
|
######################
|
||||||
|
if kube::test::if_supports_resource "${services}" ; then
|
||||||
|
if kube::test::if_supports_resource "${replicationcontrollers}" ; then
|
||||||
|
record_command run_multi_resources_tests
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
record_command run_swagger_tests
|
######################
|
||||||
|
# Persistent Volumes #
|
||||||
|
######################
|
||||||
|
|
||||||
#####################
|
if kube::test::if_supports_resource "${persistentvolumes}" ; then
|
||||||
# Kubectl --sort-by #
|
record_command run_persistent_volumes_tests
|
||||||
#####################
|
fi
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${pods}" ; then
|
############################
|
||||||
record_command run_kubectl_sort_by_tests
|
# Persistent Volume Claims #
|
||||||
fi
|
############################
|
||||||
|
|
||||||
############################
|
if kube::test::if_supports_resource "${persistentvolumeclaims}" ; then
|
||||||
# Kubectl --all-namespaces #
|
record_command run_persistent_volume_claims_tests
|
||||||
############################
|
fi
|
||||||
|
|
||||||
|
############################
|
||||||
|
# Storage Classes #
|
||||||
|
############################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${storageclass}" ; then
|
||||||
|
record_command run_storage_class_tests
|
||||||
|
fi
|
||||||
|
|
||||||
|
#########
|
||||||
|
# Nodes #
|
||||||
|
#########
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${pods}" ; then
|
|
||||||
if kube::test::if_supports_resource "${nodes}" ; then
|
if kube::test::if_supports_resource "${nodes}" ; then
|
||||||
record_command run_kubectl_all_namespace_tests
|
record_command run_nodes_tests
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|
||||||
|
########################
|
||||||
|
# authorization.k8s.io #
|
||||||
|
########################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${subjectaccessreviews}" ; then
|
||||||
|
record_command run_authorization_tests
|
||||||
|
fi
|
||||||
|
|
||||||
|
# kubectl auth can-i
|
||||||
|
# kube-apiserver is started with authorization mode AlwaysAllow, so kubectl can-i always returns yes
|
||||||
|
if kube::test::if_supports_resource "${subjectaccessreviews}" ; then
|
||||||
|
output_message=$(kubectl auth can-i '*' '*' 2>&1 "${kube_flags[@]}")
|
||||||
|
kube::test::if_has_string "${output_message}" "yes"
|
||||||
|
|
||||||
|
output_message=$(kubectl auth can-i get pods --subresource=log 2>&1 "${kube_flags[@]}")
|
||||||
|
kube::test::if_has_string "${output_message}" "yes"
|
||||||
|
|
||||||
|
output_message=$(kubectl auth can-i get invalid_resource 2>&1 "${kube_flags[@]}")
|
||||||
|
kube::test::if_has_string "${output_message}" "the server doesn't have a resource type"
|
||||||
|
|
||||||
|
output_message=$(kubectl auth can-i get /logs/ 2>&1 "${kube_flags[@]}")
|
||||||
|
kube::test::if_has_string "${output_message}" "yes"
|
||||||
|
|
||||||
|
output_message=$(! kubectl auth can-i get /logs/ --subresource=log 2>&1 "${kube_flags[@]}")
|
||||||
|
kube::test::if_has_string "${output_message}" "subresource can not be used with NonResourceURL"
|
||||||
|
|
||||||
|
output_message=$(kubectl auth can-i list jobs.batch/bar -n foo --quiet 2>&1 "${kube_flags[@]}")
|
||||||
|
kube::test::if_empty_string "${output_message}"
|
||||||
|
|
||||||
|
output_message=$(kubectl auth can-i get pods --subresource=log 2>&1 "${kube_flags[@]}"; echo $?)
|
||||||
|
kube::test::if_has_string "${output_message}" '0'
|
||||||
|
|
||||||
|
output_message=$(kubectl auth can-i get pods --subresource=log --quiet 2>&1 "${kube_flags[@]}"; echo $?)
|
||||||
|
kube::test::if_has_string "${output_message}" '0'
|
||||||
|
fi
|
||||||
|
|
||||||
|
# kubectl auth reconcile
|
||||||
|
if kube::test::if_supports_resource "${clusterroles}" ; then
|
||||||
|
kubectl auth reconcile "${kube_flags[@]}" -f test/fixtures/pkg/kubectl/cmd/auth/rbac-resource-plus.yaml
|
||||||
|
kube::test::get_object_assert 'rolebindings -n some-other-random -l test-cmd=auth' "{{range.items}}{{$id_field}}:{{end}}" 'testing-RB:'
|
||||||
|
kube::test::get_object_assert 'roles -n some-other-random -l test-cmd=auth' "{{range.items}}{{$id_field}}:{{end}}" 'testing-R:'
|
||||||
|
kube::test::get_object_assert 'clusterrolebindings -l test-cmd=auth' "{{range.items}}{{$id_field}}:{{end}}" 'testing-CRB:'
|
||||||
|
kube::test::get_object_assert 'clusterroles -l test-cmd=auth' "{{range.items}}{{$id_field}}:{{end}}" 'testing-CR:'
|
||||||
|
|
||||||
|
failure_message=$(! kubectl auth reconcile "${kube_flags[@]}" -f test/fixtures/pkg/kubectl/cmd/auth/rbac-v1beta1.yaml 2>&1 )
|
||||||
|
kube::test::if_has_string "${failure_message}" 'only rbac.authorization.k8s.io/v1 is supported'
|
||||||
|
|
||||||
|
kubectl delete "${kube_flags[@]}" rolebindings,role,clusterroles,clusterrolebindings -n some-other-random -l test-cmd=auth
|
||||||
|
fi
|
||||||
|
|
||||||
|
#####################
|
||||||
|
# Retrieve multiple #
|
||||||
|
#####################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${nodes}" ; then
|
||||||
|
if kube::test::if_supports_resource "${services}" ; then
|
||||||
|
record_command run_retrieve_multiple_tests
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
|
||||||
|
#####################
|
||||||
|
# Resource aliasing #
|
||||||
|
#####################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${services}" ; then
|
||||||
|
if kube::test::if_supports_resource "${replicationcontrollers}" ; then
|
||||||
|
record_command run_resource_aliasing_tests
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
###########
|
||||||
|
# Explain #
|
||||||
|
###########
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${pods}" ; then
|
||||||
|
record_command run_kubectl_explain_tests
|
||||||
|
fi
|
||||||
|
|
||||||
|
|
||||||
|
###########
|
||||||
|
# Swagger #
|
||||||
|
###########
|
||||||
|
|
||||||
|
record_command run_swagger_tests
|
||||||
|
|
||||||
|
#####################
|
||||||
|
# Kubectl --sort-by #
|
||||||
|
#####################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${pods}" ; then
|
||||||
|
record_command run_kubectl_sort_by_tests
|
||||||
|
fi
|
||||||
|
|
||||||
|
############################
|
||||||
|
# Kubectl --all-namespaces #
|
||||||
|
############################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${pods}" ; then
|
||||||
|
if kube::test::if_supports_resource "${nodes}" ; then
|
||||||
|
record_command run_kubectl_all_namespace_tests
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
######################
|
||||||
|
# kubectl --template #
|
||||||
|
######################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${pods}" ; then
|
||||||
|
record_command run_template_output_tests
|
||||||
|
fi
|
||||||
|
|
||||||
|
################
|
||||||
|
# Certificates #
|
||||||
|
################
|
||||||
|
|
||||||
|
if kube::test::if_supports_resource "${csr}" ; then
|
||||||
|
record_command run_certificates_tests
|
||||||
|
fi
|
||||||
|
|
||||||
|
######################
|
||||||
|
# Cluster Management #
|
||||||
|
######################
|
||||||
|
if kube::test::if_supports_resource "${nodes}" ; then
|
||||||
|
record_command run_cluster_management_tests
|
||||||
|
fi
|
||||||
|
|
||||||
|
###########
|
||||||
|
# Plugins #
|
||||||
|
###########
|
||||||
|
|
||||||
|
record_command run_plugins_tests
|
||||||
|
|
||||||
|
#################
|
||||||
|
# Impersonation #
|
||||||
|
#################
|
||||||
|
record_command run_impersonation_tests
|
||||||
fi
|
fi
|
||||||
|
|
||||||
######################
|
|
||||||
# kubectl --template #
|
|
||||||
######################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${pods}" ; then
|
|
||||||
record_command run_template_output_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
################
|
|
||||||
# Certificates #
|
|
||||||
################
|
|
||||||
|
|
||||||
if kube::test::if_supports_resource "${csr}" ; then
|
|
||||||
record_command run_certificates_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
######################
|
|
||||||
# Cluster Management #
|
|
||||||
######################
|
|
||||||
if kube::test::if_supports_resource "${nodes}" ; then
|
|
||||||
record_command run_cluster_management_tests
|
|
||||||
fi
|
|
||||||
|
|
||||||
###########
|
|
||||||
# Plugins #
|
|
||||||
###########
|
|
||||||
|
|
||||||
record_command run_plugins_tests
|
|
||||||
|
|
||||||
#################
|
|
||||||
# Impersonation #
|
|
||||||
#################
|
|
||||||
record_command run_impersonation_tests
|
|
||||||
|
|
||||||
kube::test::clear_all
|
kube::test::clear_all
|
||||||
|
|
||||||
if [[ -n "${foundError}" ]]; then
|
if [[ -n "${foundError}" ]]; then
|
||||||
|
Loading…
Reference in New Issue
Block a user