-
Notifications
You must be signed in to change notification settings - Fork 4.8k
CNTRLPLANE-3789: Add e2e tests for authentication component proxy #31446
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
tchap
wants to merge
8
commits into
openshift:main
Choose a base branch
from
tchap:auth-proxy-e2e
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+1,050
−3
Open
Changes from 3 commits
Commits
Show all changes
8 commits
Select commit
Hold shift + click to select a range
247fdd6
Add component-scoped proxy e2e tests
tchap 9c7ac0b
Wait for namespace deletion and extract trustedCA helper
tchap 76503f3
Fix attribute clobbering and trustedCA volume diagnostic
tchap bdb030d
Nitpick cleanups: logformat comment, reuse serviceHost, avoid mutatin…
tchap 1fa87c6
Only set Authorization header on authenticated Keycloak requests
tchap cbf9e99
Match trustedCA volume mount by volume name, not ConfigMap name
tchap 66b07f1
Reverse cleanup order to LIFO so resources are torn down before auth …
tchap 5a56cf6
Verify OAuth deployment has no stale proxy config before each test
tchap File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,172 @@ | ||
| package authentication | ||
|
|
||
| import ( | ||
| "context" | ||
| "time" | ||
|
|
||
| g "github.com/onsi/ginkgo/v2" | ||
| o "github.com/onsi/gomega" | ||
|
|
||
| metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" | ||
|
|
||
| operatorv1 "github.com/openshift/api/operator/v1" | ||
|
|
||
| exutil "github.com/openshift/origin/test/extended/util" | ||
| operator "github.com/openshift/origin/test/extended/util/operator" | ||
| ) | ||
|
|
||
| var _ = g.Describe("[sig-auth][Suite:openshift/conformance/serial][OCPFeatureGate:AuthenticationComponentProxy][Serial]", func() { | ||
| oc := exutil.NewCLIWithoutNamespace("component-proxy") | ||
|
|
||
| var ( | ||
| ctx context.Context | ||
| httpProxyURL string | ||
| httpsProxyURL string | ||
| caCertPEM []byte | ||
| proxyNamespace string | ||
| kcSetup *keycloakProxySetup | ||
| cleanups []removalFunc | ||
| ) | ||
|
|
||
| g.BeforeEach(func() { | ||
| ctx = context.Background() | ||
| cleanups = nil | ||
|
|
||
| g.By("Saving auth state for restore after test") | ||
| authRestore, err := saveAndRestoreAuthState(ctx, oc) | ||
| cleanups = append(cleanups, authRestore) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| g.By("Deploying Squid forward proxy") | ||
| var proxyCleanup removalFunc | ||
| httpProxyURL, httpsProxyURL, caCertPEM, proxyNamespace, proxyCleanup, err = deploySquidProxy(ctx, oc) | ||
| cleanups = append(cleanups, proxyCleanup) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| g.By("Deploying Keycloak (without registering IdP yet)") | ||
| var kcCleanups []removalFunc | ||
| kcSetup, kcCleanups, err = deployKeycloakForProxy(ctx, oc) | ||
| cleanups = append(cleanups, kcCleanups...) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| g.By("Waiting for operators to be stable before test") | ||
| err = operator.WaitForOperatorsToSettle(ctx, oc.AdminConfigClient(), 10) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| g.GinkgoWriter.Printf("Squid proxy URL: http=%s https=%s\n", httpProxyURL, httpsProxyURL) | ||
| g.GinkgoWriter.Printf("Keycloak issuer URL: %s\n", kcSetup.issuerURL) | ||
| g.GinkgoWriter.Printf("Keycloak namespace: %s\n", kcSetup.namespace) | ||
| }) | ||
|
|
||
| g.AfterEach(func() { | ||
| _ = removeResources(ctx, cleanups...) | ||
|
|
||
| g.By("Waiting for operators to be stable after test") | ||
| err := operator.WaitForOperatorsToSettle(ctx, oc.AdminConfigClient(), 10) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
| }) | ||
|
|
||
| g.It("operator should validate OIDC IdP through component proxy", func() { | ||
| testOIDCIdPThroughComponentProxy(ctx, oc, kcSetup, httpProxyURL, nil, proxyNamespace) | ||
| }) | ||
| g.It("operator should validate OIDC IdP through component proxy with trustedCA", func() { | ||
| testOIDCIdPThroughComponentProxy(ctx, oc, kcSetup, httpsProxyURL, caCertPEM, proxyNamespace) | ||
| }) | ||
| g.It("operator should fall back to original configuration on spec.proxy removal", func() { | ||
| testFallbackOnProxyRemoval(ctx, oc, kcSetup, httpProxyURL, proxyNamespace) | ||
| }) | ||
| }) | ||
|
|
||
| func testOIDCIdPThroughComponentProxy(ctx context.Context, oc *exutil.CLI, kcSetup *keycloakProxySetup, proxyURL string, trustedCACertPEM []byte, proxyNamespace string) { | ||
| withTrustedCA := len(trustedCACertPEM) > 0 | ||
|
|
||
| var trustedCAConfigMapName string | ||
| if withTrustedCA { | ||
| g.By("Creating trustedCA ConfigMap in openshift-config") | ||
| cmName, cmCleanup, err := createTrustedCAConfigMap(ctx, oc, trustedCACertPEM) | ||
| g.DeferCleanup(cmCleanup) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
| trustedCAConfigMapName = cmName | ||
| } | ||
|
|
||
| proxyTrafficStart := time.Now() | ||
|
|
||
| g.By("Setting component-scoped proxy") | ||
| proxyConfig := operatorv1.AuthenticationProxyConfig{ | ||
| HTTPSProxy: proxyURL, | ||
| } | ||
| if withTrustedCA { | ||
| proxyConfig.TrustedCA = operatorv1.AuthenticationConfigMapReference{Name: trustedCAConfigMapName} | ||
| } | ||
| err := updateAuthenticationProxy(ctx, oc, proxyConfig) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| if withTrustedCA { | ||
| g.By("Waiting for trustedCA ConfigMap to be synced before registering IdP") | ||
| err = verifyTrustedCAConfigMapSynced(ctx, oc) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
| } | ||
|
|
||
| g.By("Registering Keycloak as OIDC IdP (operator discovers it through the proxy)") | ||
| idpCleanups, err := addKeycloakOIDCIdPForProxy(ctx, oc, kcSetup) | ||
| g.DeferCleanup(func() { | ||
| _ = removeResources(ctx, idpCleanups...) | ||
| }) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| g.By("Waiting for operator to pick up IdP changes and stabilize") | ||
| err = waitForOperatorToPickUpChanges(ctx, oc, "authentication") | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| g.By("Verifying OAuth server deployment has proxy env vars and trustedCA volume/mount") | ||
| err = verifyOAuthServerDeploymentProxyConfig(ctx, oc, "", proxyURL, ".cluster.local,.svc,127.0.0.1,localhost", withTrustedCA) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| g.By("Looking up operator pod IP") | ||
| operatorPods, err := oc.AdminKubeClient().CoreV1().Pods("openshift-authentication-operator").List(ctx, metav1.ListOptions{ | ||
| LabelSelector: "app=authentication-operator", | ||
| }) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
| o.Expect(operatorPods.Items).NotTo(o.BeEmpty()) | ||
| operatorIP := operatorPods.Items[0].Status.PodIP | ||
| o.Expect(operatorIP).NotTo(o.BeEmpty()) | ||
|
|
||
| g.By("Verifying operator traffic went through the Squid proxy") | ||
| err = waitForProxyTrafficFrom(ctx, oc, proxyNamespace, operatorIP, proxyTrafficStart, 5*time.Minute) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
| } | ||
|
|
||
| func testFallbackOnProxyRemoval(ctx context.Context, oc *exutil.CLI, kcSetup *keycloakProxySetup, httpProxyURL string, proxyNamespace string) { | ||
| g.By("Setting component-scoped proxy") | ||
| err := updateAuthenticationProxy(ctx, oc, operatorv1.AuthenticationProxyConfig{ | ||
| HTTPSProxy: httpProxyURL, | ||
| }) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| g.By("Registering Keycloak as OIDC IdP") | ||
| idpCleanups, err := addKeycloakOIDCIdPForProxy(ctx, oc, kcSetup) | ||
| g.DeferCleanup(func() { | ||
| _ = removeResources(ctx, idpCleanups...) | ||
| }) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| g.By("Waiting for operator to pick up IdP changes and stabilize") | ||
| err = waitForOperatorToPickUpChanges(ctx, oc, "authentication") | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| g.By("Removing spec.proxy from Authentication CR") | ||
| err = updateAuthenticationProxy(ctx, oc, operatorv1.AuthenticationProxyConfig{}) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| g.By("Deleting Squid to prove the operator no longer routes through it") | ||
| err = deleteNamespaceSync(ctx, oc, proxyNamespace, 5*time.Minute) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| g.By("Waiting for operator to pick up proxy removal and stabilize") | ||
| err = waitForOperatorToPickUpChanges(ctx, oc, "authentication") | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
|
||
| g.By("Verifying proxy env vars are no longer set on OAuth server deployment") | ||
| err = verifyOAuthServerDeploymentProxyConfig(ctx, oc, "", "", "", false) | ||
| o.Expect(err).NotTo(o.HaveOccurred()) | ||
|
tchap marked this conversation as resolved.
|
||
| } | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📐 Maintainability & Code Quality | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: openshift/origin
Length of output: 218
🏁 Script executed:
Repository: openshift/origin
Length of output: 50372
🏁 Script executed:
Repository: openshift/origin
Length of output: 11130
Register and classify the component-proxy suite.
test/extended/authenticationis already registered intest/extended/include.go. Add theopenshift/auth/component-proxyentry tostandard_suites.go, update theDescribelabel, and add[Disruptive]because the tests mutate cluster authentication and OAuth configuration.🤖 Prompt for AI Agents
Source: Coding guidelines