diff --git a/openshift/helm/experimental.yaml b/openshift/helm/experimental.yaml index e349431aab..e41919e02d 100644 --- a/openshift/helm/experimental.yaml +++ b/openshift/helm/experimental.yaml @@ -11,7 +11,6 @@ options: enabled: - WebhookProviderOpenshiftServiceCA - SingleOwnNamespaceInstallSupport - - PreflightPermissions disabled: - WebhookProviderCertManager - BoxcutterRuntime diff --git a/openshift/operator-controller/manifests-experimental.yaml b/openshift/operator-controller/manifests-experimental.yaml index 2403424ae5..db52c56990 100644 --- a/openshift/operator-controller/manifests-experimental.yaml +++ b/openshift/operator-controller/manifests-experimental.yaml @@ -1235,7 +1235,6 @@ spec: - --leader-elect - --feature-gates=WebhookProviderOpenshiftServiceCA=true - --feature-gates=SingleOwnNamespaceInstallSupport=true - - --feature-gates=PreflightPermissions=true - --feature-gates=WebhookProviderCertManager=false - --feature-gates=BoxcutterRuntime=false - --tls-cert=/var/certs/tls.crt diff --git a/openshift/tests-extension/.openshift-tests-extension/openshift_payload_olmv1.json b/openshift/tests-extension/.openshift-tests-extension/openshift_payload_olmv1.json index 0fafc151b0..f7e7cb2f8f 100644 --- a/openshift/tests-extension/.openshift-tests-extension/openshift_payload_olmv1.json +++ b/openshift/tests-extension/.openshift-tests-extension/openshift_payload_olmv1.json @@ -263,76 +263,6 @@ "lifecycle": "blocking", "environmentSelector": {} }, - { - "name": "[sig-olmv1][OCPFeatureGate:NewOLMPreflightPermissionChecks][Skipped:Disconnected] OLMv1 operator preflight checks should report error when {services} are not specified", - "labels": {}, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": {} - }, - { - "name": "[sig-olmv1][OCPFeatureGate:NewOLMPreflightPermissionChecks][Skipped:Disconnected] OLMv1 operator preflight checks should report error when {create} verb is not specified", - "labels": {}, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": {} - }, - { - "name": "[sig-olmv1][OCPFeatureGate:NewOLMPreflightPermissionChecks][Skipped:Disconnected] OLMv1 operator preflight checks should report error when {ClusterRoleBindings} are not specified", - "labels": {}, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": {} - }, - { - "name": "[sig-olmv1][OCPFeatureGate:NewOLMPreflightPermissionChecks][Skipped:Disconnected] OLMv1 operator preflight checks should report error when {ConfigMap:resourceNames} are not all specified", - "labels": {}, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": {} - }, - { - "name": "[sig-olmv1][OCPFeatureGate:NewOLMPreflightPermissionChecks][Skipped:Disconnected] OLMv1 operator preflight checks should report error when {clusterextension/finalizer} is not specified", - "labels": {}, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": {} - }, - { - "name": "[sig-olmv1][OCPFeatureGate:NewOLMPreflightPermissionChecks][Skipped:Disconnected] OLMv1 operator preflight checks should report error when {clusterobjectsets/finalizer} is not specified", - "labels": {}, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": {} - }, - { - "name": "[sig-olmv1][OCPFeatureGate:NewOLMPreflightPermissionChecks][Skipped:Disconnected] OLMv1 operator preflight checks should report error when {escalate, bind} is not specified", - "labels": {}, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": {} - }, { "name": "[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace] OLMv1 operator installation support for singleNamespace watch mode with operator should install a cluster extension successfully", "originalName": "[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace][Skipped:Disconnected] OLMv1 operator installation support for singleNamespace watch mode with quay-operator should install a cluster extension successfully", @@ -917,40 +847,6 @@ "exclude": "topology==\"External\"" } }, - { - "name": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:68936-[OTP]cluster extension can not be installed with insufficient permission sa for operand", - "originalName": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:68936-[Skipped:Disconnected]cluster extension can not be installed with insufficient permission sa for operand", - "labels": { - "Extended": {}, - "NonHyperShiftHOST": {}, - "original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:68936-[Skipped:Disconnected]cluster extension can not be installed with insufficient permission sa for operand": {} - }, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": { - "exclude": "topology==\"External\"" - } - }, - { - "name": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:68937-[OTP]cluster extension can not be installed with insufficient permission sa for operand rbac object", - "originalName": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:68937-[Skipped:Disconnected]cluster extension can not be installed with insufficient permission sa for operand rbac object", - "labels": { - "Extended": {}, - "NonHyperShiftHOST": {}, - "original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:68937-[Skipped:Disconnected]cluster extension can not be installed with insufficient permission sa for operand rbac object": {} - }, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": { - "exclude": "topology==\"External\"" - } - }, { "name": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:70723-[OTP][Skipped:Disconnected]olmv1 downgrade version", "labels": { @@ -966,91 +862,6 @@ "exclude": "topology==\"External\"" } }, - { - "name": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:75492-[OTP][Level0]cluster extension can not be installed with wrong sa or insufficient permission sa", - "originalName": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:75492-[Skipped:Disconnected]cluster extension can not be installed with wrong sa or insufficient permission sa", - "labels": { - "Extended": {}, - "NonHyperShiftHOST": {}, - "original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:75492-[Skipped:Disconnected]cluster extension can not be installed with wrong sa or insufficient permission sa": {} - }, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": { - "exclude": "topology==\"External\"" - } - }, - { - "name": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:75493-[OTP][Level0]cluster extension can be installed with enough permission sa", - "originalName": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:75493-[Skipped:Disconnected]cluster extension can be installed with enough permission sa", - "labels": { - "Extended": {}, - "NonHyperShiftHOST": {}, - "original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:75493-[Skipped:Disconnected]cluster extension can be installed with enough permission sa": {} - }, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": { - "exclude": "topology==\"External\"" - } - }, - { - "name": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:81538-[OTP]preflight check on permission on allns mode", - "originalName": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:81538-[Skipped:Disconnected]preflight check on permission on allns mode", - "labels": { - "Extended": {}, - "NonHyperShiftHOST": {}, - "original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:81538-[Skipped:Disconnected]preflight check on permission on allns mode": {} - }, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": { - "exclude": "topology==\"External\"" - } - }, - { - "name": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:81664-[OTP]preflight check on permission on own ns mode", - "originalName": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:81664-[Skipped:Disconnected]preflight check on permission on own ns mode", - "labels": { - "Extended": {}, - "NonHyperShiftHOST": {}, - "original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:81664-[Skipped:Disconnected]preflight check on permission on own ns mode": {} - }, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": { - "exclude": "topology==\"External\"" - } - }, - { - "name": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:81696-[OTP]preflight check on permission on single ns mode", - "originalName": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:81696-[Skipped:Disconnected]preflight check on permission on single ns mode", - "labels": { - "Extended": {}, - "NonHyperShiftHOST": {}, - "original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:81696-[Skipped:Disconnected]preflight check on permission on single ns mode": {} - }, - "resources": { - "isolation": {} - }, - "source": "openshift:payload:olmv1", - "lifecycle": "blocking", - "environmentSelector": { - "exclude": "topology==\"External\"" - } - }, { "name": "[sig-olmv1][Jira:OLM] clusterextension PolarionID:87224-[Skipped:Disconnected]Upgrade version support [Serial]", "labels": { diff --git a/openshift/tests-extension/pkg/bindata/qe/bindata.go b/openshift/tests-extension/pkg/bindata/qe/bindata.go index f57893af57..a7e1d5199a 100644 --- a/openshift/tests-extension/pkg/bindata/qe/bindata.go +++ b/openshift/tests-extension/pkg/bindata/qe/bindata.go @@ -2,8 +2,6 @@ // sources: // test/qe/testdata/olm/basic-bd-plain-image.yaml // test/qe/testdata/olm/basic-bd-registry-image.yaml -// test/qe/testdata/olm/binding-prefligth.yaml -// test/qe/testdata/olm/binding-prefligth_multirole.yaml // test/qe/testdata/olm/cip.yaml // test/qe/testdata/olm/clustercatalog-secret-withlabel.yaml // test/qe/testdata/olm/clustercatalog-secret.yaml @@ -28,17 +26,6 @@ // test/qe/testdata/olm/crd-nginxolm74923.yaml // test/qe/testdata/olm/icsp-single-mirror.yaml // test/qe/testdata/olm/itdms-full-mirror.yaml -// test/qe/testdata/olm/prefligth-clusterrole.yaml -// test/qe/testdata/olm/sa-admin.yaml -// test/qe/testdata/olm/sa-nginx-insufficient-bundle-boxcutter.yaml -// test/qe/testdata/olm/sa-nginx-insufficient-bundle.yaml -// test/qe/testdata/olm/sa-nginx-insufficient-operand-clusterrole-boxcutter.yaml -// test/qe/testdata/olm/sa-nginx-insufficient-operand-clusterrole.yaml -// test/qe/testdata/olm/sa-nginx-insufficient-operand-rbac-boxcutter.yaml -// test/qe/testdata/olm/sa-nginx-insufficient-operand-rbac.yaml -// test/qe/testdata/olm/sa-nginx-limited-boxcutter.yaml -// test/qe/testdata/olm/sa-nginx-limited.yaml -// test/qe/testdata/olm/sa.yaml package testdata import ( @@ -166,128 +153,6 @@ func testQeTestdataOlmBasicBdRegistryImageYaml() (*asset, error) { return a, nil } -var _testQeTestdataOlmBindingPrefligthYaml = []byte(`apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-binding-preflight-template -objects: - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${CLUSTERROLESANAME}-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${CLUSTERROLESANAME}" - subjects: - - kind: ServiceAccount - name: "${SANAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${ROLENAME}-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${ROLENAME}" - namespace: "${NAMESPACE}" - subjects: - - kind: ServiceAccount - name: "${SANAME}" - namespace: "${NAMESPACE}" -parameters: - - name: SANAME - - name: ROLENAME - - name: CLUSTERROLESANAME - - name: NAMESPACE -`) - -func testQeTestdataOlmBindingPrefligthYamlBytes() ([]byte, error) { - return _testQeTestdataOlmBindingPrefligthYaml, nil -} - -func testQeTestdataOlmBindingPrefligthYaml() (*asset, error) { - bytes, err := testQeTestdataOlmBindingPrefligthYamlBytes() - if err != nil { - return nil, err - } - - info := bindataFileInfo{name: "test/qe/testdata/olm/binding-prefligth.yaml", size: 0, mode: os.FileMode(0), modTime: time.Unix(0, 0)} - a := &asset{bytes: bytes, info: info} - return a, nil -} - -var _testQeTestdataOlmBindingPrefligth_multiroleYaml = []byte(`apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-binding-preflight-template -objects: - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${CLUSTERROLESANAME}-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${CLUSTERROLESANAME}" - subjects: - - kind: ServiceAccount - name: "${SANAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${ROLENAME}-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${ROLENAME}" - namespace: "${NAMESPACE}" - subjects: - - kind: ServiceAccount - name: "${SANAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${WATCHROLENAME}-binding" - namespace: "${WATCHNAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${WATCHROLENAME}" - namespace: "${WATCHNAMESPACE}" - subjects: - - kind: ServiceAccount - name: "${SANAME}" - namespace: "${NAMESPACE}" -parameters: - - name: SANAME - - name: ROLENAME - - name: CLUSTERROLESANAME - - name: NAMESPACE - - name: WATCHROLENAME - - name: WATCHNAMESPACE -`) - -func testQeTestdataOlmBindingPrefligth_multiroleYamlBytes() ([]byte, error) { - return _testQeTestdataOlmBindingPrefligth_multiroleYaml, nil -} - -func testQeTestdataOlmBindingPrefligth_multiroleYaml() (*asset, error) { - bytes, err := testQeTestdataOlmBindingPrefligth_multiroleYamlBytes() - if err != nil { - return nil, err - } - - info := bindataFileInfo{name: "test/qe/testdata/olm/binding-prefligth_multirole.yaml", size: 0, mode: os.FileMode(0), modTime: time.Unix(0, 0)} - a := &asset{bytes: bytes, info: info} - return a, nil -} - var _testQeTestdataOlmCipYaml = []byte(`kind: Template apiVersion: template.openshift.io/v1 metadata: @@ -551,8 +416,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" config: configType: Inline inline: @@ -574,7 +437,6 @@ parameters: - name: PACKAGE - name: CHANNEL - name: VERSION -- name: SANAME - name: WATCHNS value: "" - name: POLICY @@ -613,8 +475,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -630,7 +490,6 @@ parameters: - name: NAME - name: INSTALLNAMESPACE - name: PACKAGE -- name: SANAME - name: POLICY value: "CatalogProvided" - name: EXPRESSIONSVALUE1 @@ -668,8 +527,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -689,7 +546,6 @@ parameters: - name: NAME - name: INSTALLNAMESPACE - name: PACKAGE -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE @@ -732,8 +588,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" config: configType: Inline inline: @@ -756,7 +610,6 @@ parameters: - name: PACKAGE - name: CHANNEL - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE @@ -794,8 +647,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -810,7 +661,6 @@ parameters: - name: INSTALLNAMESPACE - name: PACKAGE - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE @@ -848,8 +698,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -862,7 +710,6 @@ parameters: - name: NAME - name: INSTALLNAMESPACE - name: PACKAGE -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE @@ -900,8 +747,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -917,7 +762,6 @@ parameters: - name: INSTALLNAMESPACE - name: PACKAGE - name: CHANNEL -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE @@ -954,8 +798,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" config: configType: Inline inline: @@ -977,7 +819,6 @@ parameters: - name: PACKAGE - name: CHANNEL - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE @@ -1016,8 +857,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" config: configType: Inline inline: @@ -1037,7 +876,6 @@ parameters: - name: WATCHNS - name: PACKAGE - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: SOURCETYPE @@ -1078,8 +916,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -1097,7 +933,6 @@ parameters: - name: PACKAGE - name: CHANNEL - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE @@ -1135,8 +970,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -1151,7 +984,6 @@ parameters: - name: PACKAGE - name: CHANNEL - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: SOURCETYPE @@ -1185,8 +1017,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -1198,7 +1028,6 @@ parameters: - name: INSTALLNAMESPACE - name: PACKAGE - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: SOURCETYPE @@ -1233,8 +1062,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -1243,7 +1070,6 @@ parameters: - name: NAME - name: INSTALLNAMESPACE - name: PACKAGE -- name: SANAME - name: SOURCETYPE value: "Catalog" @@ -1277,8 +1103,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -1291,7 +1115,6 @@ parameters: - name: INSTALLNAMESPACE - name: PACKAGE - name: CHANNEL -- name: SANAME - name: POLICY value: "CatalogProvided" - name: SOURCETYPE @@ -1503,1813 +1326,6 @@ func testQeTestdataOlmItdmsFullMirrorYaml() (*asset, error) { return a, nil } -var _testQeTestdataOlmPrefligthClusterroleYaml = []byte(`apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-preflight-clusterrole-template -objects: - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}" - rules: -parameters: - - name: NAME -`) - -func testQeTestdataOlmPrefligthClusterroleYamlBytes() ([]byte, error) { - return _testQeTestdataOlmPrefligthClusterroleYaml, nil -} - -func testQeTestdataOlmPrefligthClusterroleYaml() (*asset, error) { - bytes, err := testQeTestdataOlmPrefligthClusterroleYamlBytes() - if err != nil { - return nil, err - } - - info := bindataFileInfo{name: "test/qe/testdata/olm/prefligth-clusterrole.yaml", size: 0, mode: os.FileMode(0), modTime: time.Unix(0, 0)} - a := &asset{bytes: bytes, info: info} - return a, nil -} - -var _testQeTestdataOlmSaAdminYaml = []byte(`apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-admin-template -objects: - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-admin-clusterrole" - rules: - - apiGroups: - - "*" - resources: - - "*" - verbs: - - "*" - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-admin-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-admin-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - -`) - -func testQeTestdataOlmSaAdminYamlBytes() ([]byte, error) { - return _testQeTestdataOlmSaAdminYaml, nil -} - -func testQeTestdataOlmSaAdminYaml() (*asset, error) { - bytes, err := testQeTestdataOlmSaAdminYamlBytes() - if err != nil { - return nil, err - } - - info := bindataFileInfo{name: "test/qe/testdata/olm/sa-admin.yaml", size: 0, mode: os.FileMode(0), modTime: time.Unix(0, 0)} - a := &asset{bytes: bytes, info: info} - return a, nil -} - -var _testQeTestdataOlmSaNginxInsufficientBundleBoxcutterYaml = []byte(`apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-insufficient-bundle-boxcutter-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - # resourceNames: - # - nginx-ok-v3283-754-15pkpuong3owt1jn01uoyj8lm6p8jlxh03kuouq67dmv - # - nginx-ok-v3283-754-2r5zqsa9t9nk0tln1f8x36ws3ks9r8cgwi70s2dgnl82 - # - nginx-ok-v3283-75493-metrics-reader - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - # resourceNames: - # - nginx-ok-v3283-754-15pkpuong3owt1jn01uoyj8lm6p8jlxh03kuouq67dmv - # - nginx-ok-v3283-754-2r5zqsa9t9nk0tln1f8x36ws3ks9r8cgwi70s2dgnl82 - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - # resourceNames: [nginx-ok-v3283-75493-controller-manager] - # - apiGroups: [""] - # resources: [serviceaccounts] - # verbs: [create] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - # resourceNames: [nginx-ok-v3283-75493-controller-manager-metrics-service] - - apiGroups: [""] - resources: [services] - verbs: [create] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - # resourceNames: [nginx-ok-v3283-75493-controller-manager] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - "" - resources: - - secrets - - pods - - pods/exec - - pods/log - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS -`) - -func testQeTestdataOlmSaNginxInsufficientBundleBoxcutterYamlBytes() ([]byte, error) { - return _testQeTestdataOlmSaNginxInsufficientBundleBoxcutterYaml, nil -} - -func testQeTestdataOlmSaNginxInsufficientBundleBoxcutterYaml() (*asset, error) { - bytes, err := testQeTestdataOlmSaNginxInsufficientBundleBoxcutterYamlBytes() - if err != nil { - return nil, err - } - - info := bindataFileInfo{name: "test/qe/testdata/olm/sa-nginx-insufficient-bundle-boxcutter.yaml", size: 0, mode: os.FileMode(0), modTime: time.Unix(0, 0)} - a := &asset{bytes: bytes, info: info} - return a, nil -} - -var _testQeTestdataOlmSaNginxInsufficientBundleYaml = []byte(`apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-insufficient-bundle-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - # resourceNames: - # - nginx-ok-v3283-754-15pkpuong3owt1jn01uoyj8lm6p8jlxh03kuouq67dmv - # - nginx-ok-v3283-754-2r5zqsa9t9nk0tln1f8x36ws3ks9r8cgwi70s2dgnl82 - # - nginx-ok-v3283-75493-metrics-reader - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - # resourceNames: - # - nginx-ok-v3283-754-15pkpuong3owt1jn01uoyj8lm6p8jlxh03kuouq67dmv - # - nginx-ok-v3283-754-2r5zqsa9t9nk0tln1f8x36ws3ks9r8cgwi70s2dgnl82 - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - # resourceNames: [nginx-ok-v3283-75493-controller-manager] - # - apiGroups: [""] - # resources: [serviceaccounts] - # verbs: [create] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - # resourceNames: [nginx-ok-v3283-75493-controller-manager-metrics-service] - - apiGroups: [""] - resources: [services] - verbs: [create] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - # resourceNames: [nginx-ok-v3283-75493-controller-manager] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - "" - resources: - - secrets - - pods - - pods/exec - - pods/log - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS -`) - -func testQeTestdataOlmSaNginxInsufficientBundleYamlBytes() ([]byte, error) { - return _testQeTestdataOlmSaNginxInsufficientBundleYaml, nil -} - -func testQeTestdataOlmSaNginxInsufficientBundleYaml() (*asset, error) { - bytes, err := testQeTestdataOlmSaNginxInsufficientBundleYamlBytes() - if err != nil { - return nil, err - } - - info := bindataFileInfo{name: "test/qe/testdata/olm/sa-nginx-insufficient-bundle.yaml", size: 0, mode: os.FileMode(0), modTime: time.Unix(0, 0)} - a := &asset{bytes: bytes, info: info} - return a, nil -} - -var _testQeTestdataOlmSaNginxInsufficientOperandClusterroleBoxcutterYaml = []byte(`apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-insufficient-operand-clusterrole-boxcutter-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [create, list, watch] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [get, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [create] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [create] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS -`) - -func testQeTestdataOlmSaNginxInsufficientOperandClusterroleBoxcutterYamlBytes() ([]byte, error) { - return _testQeTestdataOlmSaNginxInsufficientOperandClusterroleBoxcutterYaml, nil -} - -func testQeTestdataOlmSaNginxInsufficientOperandClusterroleBoxcutterYaml() (*asset, error) { - bytes, err := testQeTestdataOlmSaNginxInsufficientOperandClusterroleBoxcutterYamlBytes() - if err != nil { - return nil, err - } - - info := bindataFileInfo{name: "test/qe/testdata/olm/sa-nginx-insufficient-operand-clusterrole-boxcutter.yaml", size: 0, mode: os.FileMode(0), modTime: time.Unix(0, 0)} - a := &asset{bytes: bytes, info: info} - return a, nil -} - -var _testQeTestdataOlmSaNginxInsufficientOperandClusterroleYaml = []byte(`apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-insufficient-operand-clusterrole-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [create, list, watch] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [get, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [create] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [create] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS -`) - -func testQeTestdataOlmSaNginxInsufficientOperandClusterroleYamlBytes() ([]byte, error) { - return _testQeTestdataOlmSaNginxInsufficientOperandClusterroleYaml, nil -} - -func testQeTestdataOlmSaNginxInsufficientOperandClusterroleYaml() (*asset, error) { - bytes, err := testQeTestdataOlmSaNginxInsufficientOperandClusterroleYamlBytes() - if err != nil { - return nil, err - } - - info := bindataFileInfo{name: "test/qe/testdata/olm/sa-nginx-insufficient-operand-clusterrole.yaml", size: 0, mode: os.FileMode(0), modTime: time.Unix(0, 0)} - a := &asset{bytes: bytes, info: info} - return a, nil -} - -var _testQeTestdataOlmSaNginxInsufficientOperandRbacBoxcutterYaml = []byte(`apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-insufficient-operand-rbac-boxcutter-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [olm.operatorframework.io] - resources: [clusterobjectsets/finalizers] - verbs: [update] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [create, list, watch] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [get, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [create] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [create] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS -`) - -func testQeTestdataOlmSaNginxInsufficientOperandRbacBoxcutterYamlBytes() ([]byte, error) { - return _testQeTestdataOlmSaNginxInsufficientOperandRbacBoxcutterYaml, nil -} - -func testQeTestdataOlmSaNginxInsufficientOperandRbacBoxcutterYaml() (*asset, error) { - bytes, err := testQeTestdataOlmSaNginxInsufficientOperandRbacBoxcutterYamlBytes() - if err != nil { - return nil, err - } - - info := bindataFileInfo{name: "test/qe/testdata/olm/sa-nginx-insufficient-operand-rbac-boxcutter.yaml", size: 0, mode: os.FileMode(0), modTime: time.Unix(0, 0)} - a := &asset{bytes: bytes, info: info} - return a, nil -} - -var _testQeTestdataOlmSaNginxInsufficientOperandRbacYaml = []byte(`apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-insufficient-operand-rbac-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [olm.operatorframework.io] - resources: [clusterextensions/finalizers] - verbs: [update] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [create, list, watch] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [get, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [create] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [create] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS -`) - -func testQeTestdataOlmSaNginxInsufficientOperandRbacYamlBytes() ([]byte, error) { - return _testQeTestdataOlmSaNginxInsufficientOperandRbacYaml, nil -} - -func testQeTestdataOlmSaNginxInsufficientOperandRbacYaml() (*asset, error) { - bytes, err := testQeTestdataOlmSaNginxInsufficientOperandRbacYamlBytes() - if err != nil { - return nil, err - } - - info := bindataFileInfo{name: "test/qe/testdata/olm/sa-nginx-insufficient-operand-rbac.yaml", size: 0, mode: os.FileMode(0), modTime: time.Unix(0, 0)} - a := &asset{bytes: bytes, info: info} - return a, nil -} - -var _testQeTestdataOlmSaNginxLimitedBoxcutterYaml = []byte(`apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-limited-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [olm.operatorframework.io] - resources: [clusterobjectsets/finalizers] - verbs: [update] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [create, list, watch] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [get, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts/finalizers] - verbs: [update] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts/finalizers] - verbs: [update] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - namespaces - verbs: - - get - - list - - watch - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - "" - resources: - - secrets - - pods - - pods/exec - - pods/log - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS -`) - -func testQeTestdataOlmSaNginxLimitedBoxcutterYamlBytes() ([]byte, error) { - return _testQeTestdataOlmSaNginxLimitedBoxcutterYaml, nil -} - -func testQeTestdataOlmSaNginxLimitedBoxcutterYaml() (*asset, error) { - bytes, err := testQeTestdataOlmSaNginxLimitedBoxcutterYamlBytes() - if err != nil { - return nil, err - } - - info := bindataFileInfo{name: "test/qe/testdata/olm/sa-nginx-limited-boxcutter.yaml", size: 0, mode: os.FileMode(0), modTime: time.Unix(0, 0)} - a := &asset{bytes: bytes, info: info} - return a, nil -} - -var _testQeTestdataOlmSaNginxLimitedYaml = []byte(`apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-limited-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [olm.operatorframework.io] - resources: [clusterextensions/finalizers] - verbs: [update] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [create, list, watch] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [get, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - namespaces - verbs: - - get - - list - - watch - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - "" - resources: - - secrets - - pods - - pods/exec - - pods/log - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS -`) - -func testQeTestdataOlmSaNginxLimitedYamlBytes() ([]byte, error) { - return _testQeTestdataOlmSaNginxLimitedYaml, nil -} - -func testQeTestdataOlmSaNginxLimitedYaml() (*asset, error) { - bytes, err := testQeTestdataOlmSaNginxLimitedYamlBytes() - if err != nil { - return nil, err - } - - info := bindataFileInfo{name: "test/qe/testdata/olm/sa-nginx-limited.yaml", size: 0, mode: os.FileMode(0), modTime: time.Unix(0, 0)} - a := &asset{bytes: bytes, info: info} - return a, nil -} - -var _testQeTestdataOlmSaYaml = []byte(`apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE -`) - -func testQeTestdataOlmSaYamlBytes() ([]byte, error) { - return _testQeTestdataOlmSaYaml, nil -} - -func testQeTestdataOlmSaYaml() (*asset, error) { - bytes, err := testQeTestdataOlmSaYamlBytes() - if err != nil { - return nil, err - } - - info := bindataFileInfo{name: "test/qe/testdata/olm/sa.yaml", size: 0, mode: os.FileMode(0), modTime: time.Unix(0, 0)} - a := &asset{bytes: bytes, info: info} - return a, nil -} - // Asset loads and returns the asset for the given name. // It returns an error if the asset could not be found or // could not be loaded. @@ -3364,8 +1380,6 @@ func AssetNames() []string { var _bindata = map[string]func() (*asset, error){ "test/qe/testdata/olm/basic-bd-plain-image.yaml": testQeTestdataOlmBasicBdPlainImageYaml, "test/qe/testdata/olm/basic-bd-registry-image.yaml": testQeTestdataOlmBasicBdRegistryImageYaml, - "test/qe/testdata/olm/binding-prefligth.yaml": testQeTestdataOlmBindingPrefligthYaml, - "test/qe/testdata/olm/binding-prefligth_multirole.yaml": testQeTestdataOlmBindingPrefligth_multiroleYaml, "test/qe/testdata/olm/cip.yaml": testQeTestdataOlmCipYaml, "test/qe/testdata/olm/clustercatalog-secret-withlabel.yaml": testQeTestdataOlmClustercatalogSecretWithlabelYaml, "test/qe/testdata/olm/clustercatalog-secret.yaml": testQeTestdataOlmClustercatalogSecretYaml, @@ -3390,17 +1404,6 @@ var _bindata = map[string]func() (*asset, error){ "test/qe/testdata/olm/crd-nginxolm74923.yaml": testQeTestdataOlmCrdNginxolm74923Yaml, "test/qe/testdata/olm/icsp-single-mirror.yaml": testQeTestdataOlmIcspSingleMirrorYaml, "test/qe/testdata/olm/itdms-full-mirror.yaml": testQeTestdataOlmItdmsFullMirrorYaml, - "test/qe/testdata/olm/prefligth-clusterrole.yaml": testQeTestdataOlmPrefligthClusterroleYaml, - "test/qe/testdata/olm/sa-admin.yaml": testQeTestdataOlmSaAdminYaml, - "test/qe/testdata/olm/sa-nginx-insufficient-bundle-boxcutter.yaml": testQeTestdataOlmSaNginxInsufficientBundleBoxcutterYaml, - "test/qe/testdata/olm/sa-nginx-insufficient-bundle.yaml": testQeTestdataOlmSaNginxInsufficientBundleYaml, - "test/qe/testdata/olm/sa-nginx-insufficient-operand-clusterrole-boxcutter.yaml": testQeTestdataOlmSaNginxInsufficientOperandClusterroleBoxcutterYaml, - "test/qe/testdata/olm/sa-nginx-insufficient-operand-clusterrole.yaml": testQeTestdataOlmSaNginxInsufficientOperandClusterroleYaml, - "test/qe/testdata/olm/sa-nginx-insufficient-operand-rbac-boxcutter.yaml": testQeTestdataOlmSaNginxInsufficientOperandRbacBoxcutterYaml, - "test/qe/testdata/olm/sa-nginx-insufficient-operand-rbac.yaml": testQeTestdataOlmSaNginxInsufficientOperandRbacYaml, - "test/qe/testdata/olm/sa-nginx-limited-boxcutter.yaml": testQeTestdataOlmSaNginxLimitedBoxcutterYaml, - "test/qe/testdata/olm/sa-nginx-limited.yaml": testQeTestdataOlmSaNginxLimitedYaml, - "test/qe/testdata/olm/sa.yaml": testQeTestdataOlmSaYaml, } // AssetDir returns the file names below a certain @@ -3452,8 +1455,6 @@ var _bintree = &bintree{nil, map[string]*bintree{ "olm": {nil, map[string]*bintree{ "basic-bd-plain-image.yaml": {testQeTestdataOlmBasicBdPlainImageYaml, map[string]*bintree{}}, "basic-bd-registry-image.yaml": {testQeTestdataOlmBasicBdRegistryImageYaml, map[string]*bintree{}}, - "binding-prefligth.yaml": {testQeTestdataOlmBindingPrefligthYaml, map[string]*bintree{}}, - "binding-prefligth_multirole.yaml": {testQeTestdataOlmBindingPrefligth_multiroleYaml, map[string]*bintree{}}, "cip.yaml": {testQeTestdataOlmCipYaml, map[string]*bintree{}}, "clustercatalog-secret-withlabel.yaml": {testQeTestdataOlmClustercatalogSecretWithlabelYaml, map[string]*bintree{}}, "clustercatalog-secret.yaml": {testQeTestdataOlmClustercatalogSecretYaml, map[string]*bintree{}}, @@ -3470,25 +1471,14 @@ var _bintree = &bintree{nil, map[string]*bintree{ "clusterextension-withselectorlabel-inlineconfig.yaml": {testQeTestdataOlmClusterextensionWithselectorlabelInlineconfigYaml, map[string]*bintree{}}, "clusterextension-withselectorlabel-withoutChannel-OwnSingle.yaml": {testQeTestdataOlmClusterextensionWithselectorlabelWithoutchannelOwnsingleYaml, map[string]*bintree{}}, "clusterextension-withselectorlabel.yaml": {testQeTestdataOlmClusterextensionWithselectorlabelYaml, map[string]*bintree{}}, - "clusterextension.yaml": {testQeTestdataOlmClusterextensionYaml, map[string]*bintree{}}, - "clusterextensionWithoutChannel.yaml": {testQeTestdataOlmClusterextensionwithoutchannelYaml, map[string]*bintree{}}, - "clusterextensionWithoutChannelVersion.yaml": {testQeTestdataOlmClusterextensionwithoutchannelversionYaml, map[string]*bintree{}}, - "clusterextensionWithoutVersion.yaml": {testQeTestdataOlmClusterextensionwithoutversionYaml, map[string]*bintree{}}, - "cr-webhookTest.yaml": {testQeTestdataOlmCrWebhooktestYaml, map[string]*bintree{}}, - "crd-nginxolm74923.yaml": {testQeTestdataOlmCrdNginxolm74923Yaml, map[string]*bintree{}}, - "icsp-single-mirror.yaml": {testQeTestdataOlmIcspSingleMirrorYaml, map[string]*bintree{}}, - "itdms-full-mirror.yaml": {testQeTestdataOlmItdmsFullMirrorYaml, map[string]*bintree{}}, - "prefligth-clusterrole.yaml": {testQeTestdataOlmPrefligthClusterroleYaml, map[string]*bintree{}}, - "sa-admin.yaml": {testQeTestdataOlmSaAdminYaml, map[string]*bintree{}}, - "sa-nginx-insufficient-bundle-boxcutter.yaml": {testQeTestdataOlmSaNginxInsufficientBundleBoxcutterYaml, map[string]*bintree{}}, - "sa-nginx-insufficient-bundle.yaml": {testQeTestdataOlmSaNginxInsufficientBundleYaml, map[string]*bintree{}}, - "sa-nginx-insufficient-operand-clusterrole-boxcutter.yaml": {testQeTestdataOlmSaNginxInsufficientOperandClusterroleBoxcutterYaml, map[string]*bintree{}}, - "sa-nginx-insufficient-operand-clusterrole.yaml": {testQeTestdataOlmSaNginxInsufficientOperandClusterroleYaml, map[string]*bintree{}}, - "sa-nginx-insufficient-operand-rbac-boxcutter.yaml": {testQeTestdataOlmSaNginxInsufficientOperandRbacBoxcutterYaml, map[string]*bintree{}}, - "sa-nginx-insufficient-operand-rbac.yaml": {testQeTestdataOlmSaNginxInsufficientOperandRbacYaml, map[string]*bintree{}}, - "sa-nginx-limited-boxcutter.yaml": {testQeTestdataOlmSaNginxLimitedBoxcutterYaml, map[string]*bintree{}}, - "sa-nginx-limited.yaml": {testQeTestdataOlmSaNginxLimitedYaml, map[string]*bintree{}}, - "sa.yaml": {testQeTestdataOlmSaYaml, map[string]*bintree{}}, + "clusterextension.yaml": {testQeTestdataOlmClusterextensionYaml, map[string]*bintree{}}, + "clusterextensionWithoutChannel.yaml": {testQeTestdataOlmClusterextensionwithoutchannelYaml, map[string]*bintree{}}, + "clusterextensionWithoutChannelVersion.yaml": {testQeTestdataOlmClusterextensionwithoutchannelversionYaml, map[string]*bintree{}}, + "clusterextensionWithoutVersion.yaml": {testQeTestdataOlmClusterextensionwithoutversionYaml, map[string]*bintree{}}, + "cr-webhookTest.yaml": {testQeTestdataOlmCrWebhooktestYaml, map[string]*bintree{}}, + "crd-nginxolm74923.yaml": {testQeTestdataOlmCrdNginxolm74923Yaml, map[string]*bintree{}}, + "icsp-single-mirror.yaml": {testQeTestdataOlmIcspSingleMirrorYaml, map[string]*bintree{}}, + "itdms-full-mirror.yaml": {testQeTestdataOlmItdmsFullMirrorYaml, map[string]*bintree{}}, }}, }}, }}, diff --git a/openshift/tests-extension/pkg/helpers/cluster_extension.go b/openshift/tests-extension/pkg/helpers/cluster_extension.go index ae193f9080..b051a5077e 100644 --- a/openshift/tests-extension/pkg/helpers/cluster_extension.go +++ b/openshift/tests-extension/pkg/helpers/cluster_extension.go @@ -3,15 +3,12 @@ package helpers import ( "context" "fmt" - "time" //nolint:staticcheck // ST1001: dot-imports for readability . "github.com/onsi/ginkgo/v2" //nolint:staticcheck // ST1001: dot-imports for readability . "github.com/onsi/gomega" - corev1 "k8s.io/api/core/v1" - rbacv1 "k8s.io/api/rbac/v1" apiextensionsv1 "k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1" "k8s.io/apimachinery/pkg/api/errors" "k8s.io/apimachinery/pkg/api/meta" @@ -56,7 +53,7 @@ func WithProgressDeadlineMinutes(minutes int32) ClusterExtensionOption { } } -// CreateClusterExtension creates a ServiceAccount, ClusterRoleBinding, and ClusterExtension using typed APIs. +// CreateClusterExtension creates a ClusterExtension using typed APIs. // It returns the unique suffix and a cleanup function. func CreateClusterExtension(packageName, version, namespace, unique string, opts ...ClusterExtensionOption) (string, func()) { ctx := context.TODO() @@ -65,72 +62,25 @@ func CreateClusterExtension(packageName, version, namespace, unique string, opts unique = rand.String(4) } - saName := "install-test-sa-" + unique - crbName := "install-test-crb-" + unique ceName := "install-test-ce-" + unique - // 1. Create ServiceAccount - sa := NewServiceAccount(saName, namespace) - Expect(k8sClient.Create(ctx, sa)).To(Succeed(), - "failed to create ServiceAccount") - By("ensuring ServiceAccount is available before proceeding") - ExpectServiceAccountExists(ctx, saName, namespace) - - // 2. Create ClusterRoleBinding - crb := NewClusterRoleBinding(crbName, "cluster-admin", saName, namespace) - Expect(k8sClient.Create(ctx, crb)).To(Succeed(), "failed to create ClusterRoleBinding") - By("ensuring ClusterRoleBinding is available before proceeding") - ExpectClusterRoleBindingExists(ctx, crbName) - // 3. Create ClusterExtension - ce := NewClusterExtensionObject(packageName, version, ceName, saName, namespace, opts...) + ce := NewClusterExtensionObject(packageName, version, ceName, namespace, opts...) Expect(k8sClient.Create(ctx, ce)).To(Succeed(), "failed to create ClusterExtension") // Cleanup closure return ceName, func() { - By("deleting CluserExtension, ClusterRoleBinding and ServiceAccount") + By("deleting CluserExtension") _ = k8sClient.Delete(ctx, ce) - _ = k8sClient.Delete(ctx, crb) - _ = k8sClient.Delete(ctx, sa) } } -// NewServiceAccount creates a new ServiceAccount. -func NewServiceAccount(name, namespace string) *corev1.ServiceAccount { - return &corev1.ServiceAccount{ - ObjectMeta: metav1.ObjectMeta{ - Name: name, - Namespace: namespace, - }, - } -} - -// NewClusterRoleBinding creates a new ClusterRoleBinding object that binds a ClusterRole to a ServiceAccount. -func NewClusterRoleBinding(name, roleName, saName, namespace string) *rbacv1.ClusterRoleBinding { - return &rbacv1.ClusterRoleBinding{ - ObjectMeta: metav1.ObjectMeta{Name: name}, - RoleRef: rbacv1.RoleRef{ - APIGroup: "rbac.authorization.k8s.io", - Kind: "ClusterRole", - Name: roleName, - }, - Subjects: []rbacv1.Subject{{ - Kind: "ServiceAccount", - Name: saName, - Namespace: namespace, - }}, - } -} - -// NewClusterExtensionObject creates a new ClusterExtension object with the specified package, version, name, and ServiceAccount. -func NewClusterExtensionObject(pkg, version, ceName, saName, namespace string, opts ...ClusterExtensionOption) *olmv1.ClusterExtension { +// NewClusterExtensionObject creates a new ClusterExtension object with the specified package, version, and name. +func NewClusterExtensionObject(pkg, version, ceName, namespace string, opts ...ClusterExtensionOption) *olmv1.ClusterExtension { ext := &olmv1.ClusterExtension{ ObjectMeta: metav1.ObjectMeta{Name: ceName}, Spec: olmv1.ClusterExtensionSpec{ Namespace: namespace, - ServiceAccount: olmv1.ServiceAccountReference{ - Name: saName, - }, Source: olmv1.SourceConfig{ SourceType: olmv1.SourceTypeCatalog, Catalog: &olmv1.CatalogFilter{ @@ -234,23 +184,3 @@ func EnsureCleanupClusterExtension(ctx context.Context, packageName, crdName str } } } - -// ExpectServiceAccountExists waits for a ServiceAccount to be available and visible to the client. -func ExpectServiceAccountExists(ctx context.Context, name, namespace string) { - k8sClient := env.Get().K8sClient - sa := &corev1.ServiceAccount{} - Eventually(func(g Gomega) { - err := k8sClient.Get(ctx, client.ObjectKey{Name: name, Namespace: namespace}, sa) - g.Expect(err).ToNot(HaveOccurred(), fmt.Sprintf("failed to get ServiceAccount %q/%q: %v", namespace, name, err)) - }).WithTimeout(DefaultTimeout).WithPolling(DefaultPolling).Should(Succeed(), "ServiceAccount %q/%q did not become visible within timeout", namespace, name) -} - -// ExpectClusterRoleBindingExists waits for a ClusterRoleBinding to be available and visible to the client. -func ExpectClusterRoleBindingExists(ctx context.Context, name string) { - k8sClient := env.Get().K8sClient - crb := &rbacv1.ClusterRoleBinding{} - Eventually(func(g Gomega) { - err := k8sClient.Get(ctx, client.ObjectKey{Name: name}, crb) - g.Expect(err).ToNot(HaveOccurred(), fmt.Sprintf("failed to get ClusterRoleBinding %q: %v", name, err)) - }).WithTimeout(2*time.Minute).WithPolling(DefaultPolling).Should(Succeed(), "ClusterRoleBinding %q did not become visible within timeout", name) -} diff --git a/openshift/tests-extension/pkg/helpers/in_cluster_bundles.go b/openshift/tests-extension/pkg/helpers/in_cluster_bundles.go index 68a7296bae..9ab0619470 100644 --- a/openshift/tests-extension/pkg/helpers/in_cluster_bundles.go +++ b/openshift/tests-extension/pkg/helpers/in_cluster_bundles.go @@ -235,6 +235,16 @@ func CreateNamespace(namespace string) { Expect(k8sClient.Create(ctx, ns)).To(Succeed(), "failed to create Namespace: %q", namespace) } +// ExpectServiceAccountExists waits for a ServiceAccount to be available and visible to the client. +func ExpectServiceAccountExists(ctx context.Context, name, namespace string) { + k8sClient := env.Get().K8sClient + sa := &corev1.ServiceAccount{} + Eventually(func(g Gomega) { + err := k8sClient.Get(ctx, client.ObjectKey{Name: name, Namespace: namespace}, sa) + g.Expect(err).ToNot(HaveOccurred(), fmt.Sprintf("failed to get ServiceAccount %q/%q: %v", namespace, name, err)) + }).WithTimeout(DefaultTimeout).WithPolling(DefaultPolling).Should(Succeed(), "ServiceAccount %q/%q did not become visible within timeout", namespace, name) +} + func createImageStream(name, namespace string) { ctx := context.Background() k8sClient := env.Get().K8sClient diff --git a/openshift/tests-extension/test/olmv1-deploymentconfig.go b/openshift/tests-extension/test/olmv1-deploymentconfig.go index 893126ad8c..95e94da6ed 100644 --- a/openshift/tests-extension/test/olmv1-deploymentconfig.go +++ b/openshift/tests-extension/test/olmv1-deploymentconfig.go @@ -66,9 +66,9 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMConfigAPI][Skipped:Disconnect } }) - // installAndVerify is a helper that creates an install namespace, ServiceAccount, - // ClusterRoleBinding and ClusterExtension, waits for successful installation, and - // then calls verify against the resulting DeploymentList. All resources are + // installAndVerify is a helper that creates an install namespace and + // ClusterExtension, waits for successful installation, and then calls + // verify against the resulting DeploymentList. All resources are // cleaned up via DeferCleanup. installAndVerify := func( ctx SpecContext, @@ -86,21 +86,9 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMConfigAPI][Skipped:Disconnect _ = k8sClient.Delete(context.Background(), ns, client.PropagationPolicy(metav1.DeletePropagationForeground)) }) - saName := fmt.Sprintf("dc-%s-sa-%s", namePrefix, suffix) - crbName := fmt.Sprintf("dc-%s-crb-%s", namePrefix, suffix) ceName := fmt.Sprintf("dc-%s-ce-%s", namePrefix, suffix) - sa := helpers.NewServiceAccount(saName, installNamespace) - Expect(k8sClient.Create(ctx, sa)).To(Succeed()) - helpers.ExpectServiceAccountExists(ctx, saName, installNamespace) - DeferCleanup(func() { _ = k8sClient.Delete(context.Background(), sa) }) - - crb := helpers.NewClusterRoleBinding(crbName, "cluster-admin", saName, installNamespace) - Expect(k8sClient.Create(ctx, crb)).To(Succeed()) - helpers.ExpectClusterRoleBindingExists(ctx, crbName) - DeferCleanup(func() { _ = k8sClient.Delete(context.Background(), crb) }) - - ce := helpers.NewClusterExtensionObject(opName, "", ceName, saName, installNamespace, + ce := helpers.NewClusterExtensionObject(opName, "", ceName, installNamespace, helpers.WithCatalogNameSelector(ccName)) ce.Spec.Config = &olmv1.ClusterExtensionConfig{ ConfigType: olmv1.ClusterExtensionConfigTypeInline, @@ -226,21 +214,9 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMConfigAPI][Skipped:Disconnect _ = k8sClient.Delete(context.Background(), ns, client.PropagationPolicy(metav1.DeletePropagationForeground)) }) - saName := fmt.Sprintf("dc-%s-sa-%s", namePrefix, suffix) - crbName := fmt.Sprintf("dc-%s-crb-%s", namePrefix, suffix) ceName := fmt.Sprintf("dc-%s-ce-%s", namePrefix, suffix) - sa := helpers.NewServiceAccount(saName, installNamespace) - Expect(k8sClient.Create(ctx, sa)).To(Succeed()) - helpers.ExpectServiceAccountExists(ctx, saName, installNamespace) - DeferCleanup(func() { _ = k8sClient.Delete(context.Background(), sa) }) - - crb := helpers.NewClusterRoleBinding(crbName, "cluster-admin", saName, installNamespace) - Expect(k8sClient.Create(ctx, crb)).To(Succeed()) - helpers.ExpectClusterRoleBindingExists(ctx, crbName) - DeferCleanup(func() { _ = k8sClient.Delete(context.Background(), crb) }) - - ce := helpers.NewClusterExtensionObject(opName, "", ceName, saName, installNamespace, + ce := helpers.NewClusterExtensionObject(opName, "", ceName, installNamespace, helpers.WithCatalogNameSelector(ccName)) ce.Spec.Config = &olmv1.ClusterExtensionConfig{ ConfigType: olmv1.ClusterExtensionConfigTypeInline, diff --git a/openshift/tests-extension/test/olmv1-preflight.go b/openshift/tests-extension/test/olmv1-preflight.go deleted file mode 100644 index 1d58edf21b..0000000000 --- a/openshift/tests-extension/test/olmv1-preflight.go +++ /dev/null @@ -1,324 +0,0 @@ -package test - -import ( - "context" - "fmt" - - //nolint:staticcheck // ST1001: dot-imports for readability - . "github.com/onsi/ginkgo/v2" - //nolint:staticcheck // ST1001: dot-imports for readability - . "github.com/onsi/gomega" - - "github.com/openshift/api/features" - "github.com/openshift/origin/test/extended/util/image" - corev1 "k8s.io/api/core/v1" - rbacv1 "k8s.io/api/rbac/v1" - apiextensionsv1 "k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1" - "k8s.io/apimachinery/pkg/api/meta" - metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" - "k8s.io/apimachinery/pkg/util/rand" - "sigs.k8s.io/controller-runtime/pkg/client" - - olmv1 "github.com/operator-framework/operator-controller/api/v1" - - singleownbundle "github.com/openshift/operator-framework-operator-controller/openshift/tests-extension/pkg/bindata/singleown/bundle" - singleownindex "github.com/openshift/operator-framework-operator-controller/openshift/tests-extension/pkg/bindata/singleown/index" - "github.com/openshift/operator-framework-operator-controller/openshift/tests-extension/pkg/env" - "github.com/openshift/operator-framework-operator-controller/openshift/tests-extension/pkg/helpers" -) - -type preflightAuthTestScenario int - -const ( - scenarioMissingServicePerms preflightAuthTestScenario = 0 - scenarioMissingCreateVerb preflightAuthTestScenario = 1 - scenarioMissingClusterRoleBindingsPerms preflightAuthTestScenario = 2 - scenarioMissingNamedConfigMapPerms preflightAuthTestScenario = 3 - scenarioMissingClusterExtensionsFinalizerPerms preflightAuthTestScenario = 4 - scenarioMissingEscalateAndBindPerms preflightAuthTestScenario = 5 - scenarioMissingClusterObjectSetsFinalizerPerms preflightAuthTestScenario = 6 -) - -const preflightBundleVersion = "0.0.5" - -var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMPreflightPermissionChecks][Skipped:Disconnected] OLMv1 operator preflight checks", func() { - var ( - namespace string - k8sClient client.Client - catalogName string - packageName string - ) - BeforeEach(func(ctx SpecContext) { - helpers.RequireOLMv1CapabilityOnOpenshift() - helpers.RequireImageRegistry(ctx) - k8sClient = env.Get().K8sClient - namespace = "preflight-test-ns-" + rand.String(4) - - // Use an in-cluster catalog and bundle so tests do not depend on external indexes. - crdSuffix := rand.String(4) - packageName = fmt.Sprintf("preflight-operator-%s", crdSuffix) - crdName := fmt.Sprintf("webhooktests-%s.webhook.operators.coreos.io", crdSuffix) - helpers.EnsureCleanupClusterExtension(context.Background(), packageName, crdName) - - singleownImage := image.LocationFor("quay.io/olmtest/webhook-operator:v0.0.5") - replacements := map[string]string{ - "{{ TEST-BUNDLE }}": "", - "{{ NAMESPACE }}": "", - "{{ TEST-CONTROLLER }}": singleownImage, - "{{ CRD-SUFFIX }}": crdSuffix, - "{{ PACKAGE-NAME }}": packageName, - } - _, _, catalogName, _ = helpers.NewCatalogAndClusterBundles(ctx, replacements, - singleownindex.AssetNames, singleownindex.Asset, - singleownbundle.AssetNames, singleownbundle.Asset, - ) - By(fmt.Sprintf("catalog %q and package %q are ready", catalogName, packageName)) - - By(fmt.Sprintf("creating namespace %s", namespace)) - ns := &corev1.Namespace{ - ObjectMeta: metav1.ObjectMeta{ - Name: namespace, - }, - } - Expect(k8sClient.Create(context.Background(), ns)).To(Succeed(), "failed to create test namespace") - DeferCleanup(func() { - _ = k8sClient.Delete(context.Background(), ns) - }) - }) - - It("should report error when {services} are not specified", func(ctx SpecContext) { - runNegativePreflightTest(ctx, scenarioMissingServicePerms, namespace, packageName, catalogName) - }) - - It("should report error when {create} verb is not specified", func(ctx SpecContext) { - runNegativePreflightTest(ctx, scenarioMissingCreateVerb, namespace, packageName, catalogName) - }) - - It("should report error when {ClusterRoleBindings} are not specified", func(ctx SpecContext) { - runNegativePreflightTest(ctx, scenarioMissingClusterRoleBindingsPerms, namespace, packageName, catalogName) - }) - - It("should report error when {ConfigMap:resourceNames} are not all specified", func(ctx SpecContext) { - runNegativePreflightTest(ctx, scenarioMissingNamedConfigMapPerms, namespace, packageName, catalogName) - }) - - It("should report error when {clusterextension/finalizer} is not specified", func(ctx SpecContext) { - helpers.RequireFeatureGateDisabled(features.FeatureGateNewOLMBoxCutterRuntime) - runNegativePreflightTest(ctx, scenarioMissingClusterExtensionsFinalizerPerms, namespace, packageName, catalogName) - }) - - It("should report error when {clusterobjectsets/finalizer} is not specified", func(ctx SpecContext) { - helpers.RequireFeatureGateEnabled(features.FeatureGateNewOLMBoxCutterRuntime) - runNegativePreflightTest(ctx, scenarioMissingClusterObjectSetsFinalizerPerms, namespace, packageName, catalogName) - }) - - It("should report error when {escalate, bind} is not specified", func(ctx SpecContext) { - runNegativePreflightTest(ctx, scenarioMissingEscalateAndBindPerms, namespace, packageName, catalogName) - }) -}) - -// runNegativePreflightTest creates a ClusterRole that is missing one required permission, -// a ClusterExtension that uses it (via the in-cluster catalog), then waits for the preflight failure. -func runNegativePreflightTest(ctx context.Context, scenario preflightAuthTestScenario, namespace, packageName, catalogName string) { - k8sClient := env.Get().K8sClient - unique := rand.String(8) - - // Define names - crName := fmt.Sprintf("install-test-cr-%s", unique) - saName := fmt.Sprintf("install-test-sa-%s", unique) - crbName := fmt.Sprintf("install-test-crb-%s", unique) - ceName := fmt.Sprintf("install-test-ce-%s", unique) - - // Step 1: Create deficient ClusterRole - defCR := createDeficientClusterRole(scenario, crName, ceName) - Expect(k8sClient.Create(ctx, defCR)).To(Succeed(), "failed to create ClusterRole") - DeferCleanup(func(ctx SpecContext) { - _ = k8sClient.Delete(ctx, defCR) - }) - - // Step 2: Create matching ServiceAccount - sa := helpers.NewServiceAccount(saName, namespace) - Expect(k8sClient.Create(ctx, sa)).To(Succeed(), "failed to create ServiceAccount") - DeferCleanup(func(ctx SpecContext) { - _ = k8sClient.Delete(ctx, sa) - }) - - // Step 3: Bind SA to the deficient ClusterRole - crb := helpers.NewClusterRoleBinding(crbName, crName, saName, namespace) - Expect(k8sClient.Create(ctx, crb)).To(Succeed(), "failed to create ClusterRoleBinding") - DeferCleanup(func(ctx SpecContext) { - _ = k8sClient.Delete(ctx, crb) - }) - - // Step 4: Create ClusterExtension for that SA using the in-cluster catalog. - // Set watchNamespace in config so the controller can run preflight; otherwise it fails on config validation first. - ce := helpers.NewClusterExtensionObject(packageName, preflightBundleVersion, ceName, saName, namespace, helpers.WithCatalogNameSelector(catalogName)) - ce.Spec.Config = &olmv1.ClusterExtensionConfig{ - ConfigType: "Inline", - Inline: &apiextensionsv1.JSON{ - Raw: []byte(fmt.Sprintf(`{"watchNamespace": "%s"}`, namespace)), - }, - } - Expect(k8sClient.Create(ctx, ce)).To(Succeed(), "failed to create ClusterExtension") - DeferCleanup(func(ctx SpecContext) { - _ = k8sClient.Delete(ctx, ce) - }) - - // Step 5: Wait for the controller to report preflight failure. - // The error is in the Progressing condition. We only check the message, not True/False, so the test stays stable. - By("waiting for ClusterExtension to report preflight failure") - Eventually(func(g Gomega) { - latest := &olmv1.ClusterExtension{} - err := k8sClient.Get(ctx, client.ObjectKey{Name: ce.Name}, latest) - g.Expect(err).NotTo(HaveOccurred()) - - c := meta.FindStatusCondition(latest.Status.Conditions, olmv1.TypeProgressing) - g.Expect(c).NotTo(BeNil(), "Progressing condition should be set") - g.Expect(c.Message).To(ContainSubstring("pre-authorization failed"), "message should report pre-authorization failure") - }).WithTimeout(helpers.DefaultTimeout).WithPolling(helpers.DefaultPolling).Should(Succeed()) -} - -// createDeficientClusterRole returns a ClusterRole that is missing one permission needed by the test scenario. -func createDeficientClusterRole(scenario preflightAuthTestScenario, name, ceName string) *rbacv1.ClusterRole { - var baseRules []rbacv1.PolicyRule - if helpers.IsFeatureGateEnabled(features.FeatureGateNewOLMBoxCutterRuntime) { - baseRules = []rbacv1.PolicyRule{ - { - APIGroups: []string{"olm.operatorframework.io"}, - Resources: []string{"clusterobjectsets/finalizers"}, - Verbs: []string{"update"}, - ResourceNames: []string{fmt.Sprintf("%s-1", ceName)}, - }, - } - } else { - baseRules = []rbacv1.PolicyRule{ - { - APIGroups: []string{"olm.operatorframework.io"}, - Resources: []string{"clusterextensions/finalizers"}, - Verbs: []string{"update"}, - ResourceNames: []string{ceName}, - }, - } - } - - baseRules = append(baseRules, []rbacv1.PolicyRule{ - { - APIGroups: []string{""}, - Resources: []string{"nodes"}, - Verbs: []string{"list"}, - }, - { - APIGroups: []string{""}, - Resources: []string{"pods", "pods/finalizers", "services", "services/finalizers", "endpoints", "endpoints/finalizers", "persistentvolumeclaims", "persistentvolumeclaims/finalizers", "events", "events/finalizers", "configmaps", "configmaps/finalizers", "secrets", "secrets/finalizers", "pods/log", "limitranges", "limitranges/finalizers", "namespaces", "namespaces/finalizers", "serviceaccounts", "serviceaccounts/finalizers"}, - Verbs: []string{"delete", "deletecollection", "create", "patch", "get", "list", "update", "watch"}, - }, - { - APIGroups: []string{"rbac.authorization.k8s.io"}, - Resources: []string{"clusterroles", "clusterroles/finalizers", "roles", "roles/finalizers", "clusterrolebindings", "clusterrolebindings/finalizers", "rolebindings", "rolebindings/finalizers"}, - Verbs: []string{"delete", "deletecollection", "create", "patch", "get", "list", "update", "watch", "bind", "escalate"}, - }, - }...) - - // Copy rules to avoid mutation - rules := make([]rbacv1.PolicyRule, len(baseRules)) - copy(rules, baseRules) - - switch scenario { - case scenarioMissingServicePerms: - // Remove services and services/finalizers so preflight fails. - for i, r := range rules { - if r.APIGroups[0] == "" { - filtered := []string{} - for _, res := range r.Resources { - if res != "services" && res != "services/finalizers" { - filtered = append(filtered, res) - } - } - rules[i].Resources = filtered - } - } - case scenarioMissingCreateVerb: - // Remove the create verb so preflight fails. - for i, r := range rules { - if r.APIGroups[0] == "" { - filtered := []string{} - for _, v := range r.Verbs { - if v != "create" { - filtered = append(filtered, v) - } - } - rules[i].Verbs = filtered - } - } - case scenarioMissingClusterRoleBindingsPerms: - // Remove clusterrolebindings so preflight fails. - for i, r := range rules { - if r.APIGroups[0] == "rbac.authorization.k8s.io" { - filtered := []string{} - for _, res := range r.Resources { - if res != "clusterrolebindings" && res != "clusterrolebindings/finalizers" { - filtered = append(filtered, res) - } - } - rules[i].Resources = filtered - } - } - case scenarioMissingNamedConfigMapPerms: - // Allow only one ClusterRole by name so the SA cannot manage the rest; preflight then fails. - // The singleown bundle uses ClusterRoles like webhook-operator-metrics-reader. - for i := range rules { - if rules[i].APIGroups[0] == "rbac.authorization.k8s.io" { - filtered := []string{} - for _, res := range rules[i].Resources { - if res != "clusterroles" && res != "clusterroles/finalizers" { - filtered = append(filtered, res) - } - } - rules[i].Resources = filtered - rules = append(rules, rbacv1.PolicyRule{ - APIGroups: []string{"rbac.authorization.k8s.io"}, - Resources: []string{"clusterroles", "clusterroles/finalizers"}, - Verbs: []string{"delete", "deletecollection", "create", "patch", "get", "list", "update", "watch"}, - ResourceNames: []string{"webhook-operator-metrics-reader"}, - }) - break - } - } - case scenarioMissingClusterExtensionsFinalizerPerms: - // Remove permission for clusterextensions/finalizers so preflight fails. - filtered := []rbacv1.PolicyRule{} - for _, r := range rules { - if len(r.APIGroups) != 1 || r.APIGroups[0] != "olm.operatorframework.io" { - filtered = append(filtered, r) - } - } - rules = filtered - case scenarioMissingClusterObjectSetsFinalizerPerms: - // Remove permission for clusterobjectsets/finalizers so preflight fails. - filtered := []rbacv1.PolicyRule{} - for _, r := range rules { - if len(r.APIGroups) != 1 || r.APIGroups[0] != "olm.operatorframework.io" { - filtered = append(filtered, r) - } - } - rules = filtered - case scenarioMissingEscalateAndBindPerms: - // Remove bind and escalate verbs so preflight fails. - for i, r := range rules { - if r.APIGroups[0] == "rbac.authorization.k8s.io" { - filtered := []string{} - for _, v := range r.Verbs { - if v != "bind" && v != "escalate" { - filtered = append(filtered, v) - } - } - rules[i].Verbs = filtered - } - } - } - - return &rbacv1.ClusterRole{ - ObjectMeta: metav1.ObjectMeta{Name: name}, - Rules: rules, - } -} diff --git a/openshift/tests-extension/test/olmv1-singleownnamespace.go b/openshift/tests-extension/test/olmv1-singleownnamespace.go index 4fb4a547ed..a4c05608bf 100644 --- a/openshift/tests-extension/test/olmv1-singleownnamespace.go +++ b/openshift/tests-extension/test/olmv1-singleownnamespace.go @@ -38,7 +38,7 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace] OLMv1 ope crdSuffix string ) - var unique, saName, crbName, ceName string + var unique, ceName string BeforeEach(func(ctx SpecContext) { helpers.RequireOLMv1CapabilityOnOpenshift() helpers.RequireImageRegistry(ctx) @@ -46,8 +46,6 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace] OLMv1 ope unique = rand.String(4) namespace = fmt.Sprintf("olmv1-%s-ns-%s", testPrefix, unique) - saName = fmt.Sprintf("install-%s-sa-%s", testPrefix, unique) - crbName = fmt.Sprintf("install-%s-crb-%s", testPrefix, unique) ceName = fmt.Sprintf("install-%s-ce-%s", testPrefix, unique) crdSuffix = unique @@ -97,30 +95,8 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace] OLMv1 ope It("should install a cluster extension successfully", Label("original-name:[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace][Skipped:Disconnected] OLMv1 operator installation support for singleNamespace watch mode with quay-operator should install a cluster extension successfully"), func(ctx SpecContext) { - By("creating ServiceAccount") - sa := helpers.NewServiceAccount(saName, namespace) - Expect(k8sClient.Create(ctx, sa)).To(Succeed(), "failed to create ServiceAccount %q", saName) - By("ensuring ServiceAccount is available before proceeding") - helpers.ExpectServiceAccountExists(ctx, saName, namespace) - By("registering cleanup for ServiceAccount") - DeferCleanup(func() { - By(fmt.Sprintf("cleanup: deleting ServiceAccount %s in namespace %s", sa.Name, sa.Namespace)) - _ = k8sClient.Delete(context.Background(), sa, client.PropagationPolicy(metav1.DeletePropagationForeground)) - }) - - By("creating ClusterRoleBinding") - crb := helpers.NewClusterRoleBinding(crbName, "cluster-admin", saName, namespace) - Expect(k8sClient.Create(ctx, crb)).To(Succeed(), "failed to create ClusterRoleBinding %q", crbName) - By("ensuring ClusterRoleBinding is available before proceeding") - helpers.ExpectClusterRoleBindingExists(ctx, crbName) - By("registering cleanup for ClusterRoleBinding") - DeferCleanup(func() { - By(fmt.Sprintf("cleanup: deleting ClusterRoleBinding %s", crb.Name)) - _ = k8sClient.Delete(context.Background(), crb, client.PropagationPolicy(metav1.DeletePropagationForeground)) - }) - By("creating ClusterExtension with the watch-namespace configured") - ce := helpers.NewClusterExtensionObject(packageName, "0.0.5", ceName, saName, namespace) + ce := helpers.NewClusterExtensionObject(packageName, "0.0.5", ceName, namespace) ce.Spec.Source.Catalog.Selector = &metav1.LabelSelector{ MatchLabels: map[string]string{ "olm.operatorframework.io/metadata.name": catalogName, @@ -157,15 +133,13 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace] OLMv1 ope crdSuffix string ) - var unique, saName, crbName, ceName string + var unique, ceName string BeforeEach(func(ctx SpecContext) { helpers.RequireOLMv1CapabilityOnOpenshift() helpers.RequireImageRegistry(ctx) k8sClient = env.Get().K8sClient unique = rand.String(4) namespace = fmt.Sprintf("olmv1-%s-ns-%s", testPrefix, unique) - saName = fmt.Sprintf("install-%s-sa-%s", testPrefix, unique) - crbName = fmt.Sprintf("install-%s-crb-%s", testPrefix, unique) ceName = fmt.Sprintf("install-%s-ce-%s", testPrefix, unique) crdSuffix = unique @@ -215,30 +189,8 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace] OLMv1 ope It("should install a cluster extension successfully", Label("original-name:[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace][Skipped:Disconnected] OLMv1 operator installation support for ownNamespace watch mode with quay-operator should install a cluster extension successfully"), func(ctx SpecContext) { - By("creating ServiceAccount") - sa := helpers.NewServiceAccount(saName, namespace) - Expect(k8sClient.Create(ctx, sa)).To(Succeed(), "failed to create ServiceAccount %q", saName) - By("ensuring ServiceAccount is available before proceeding") - helpers.ExpectServiceAccountExists(ctx, saName, namespace) - By("registering cleanup for ServiceAccount") - DeferCleanup(func() { - By(fmt.Sprintf("cleanup: deleting ServiceAccount %s in namespace %s", sa.Name, sa.Namespace)) - _ = k8sClient.Delete(context.Background(), sa, client.PropagationPolicy(metav1.DeletePropagationForeground)) - }) - - By("creating ClusterRoleBinding") - crb := helpers.NewClusterRoleBinding(crbName, "cluster-admin", saName, namespace) - Expect(k8sClient.Create(ctx, crb)).To(Succeed(), "failed to create ClusterRoleBinding %q", crbName) - By("ensuring ClusterRoleBinding is available before proceeding") - helpers.ExpectClusterRoleBindingExists(ctx, crbName) - By("registering cleanup for ClusterRoleBinding") - DeferCleanup(func() { - By(fmt.Sprintf("cleanup: deleting ClusterRoleBinding %s", crb.Name)) - _ = k8sClient.Delete(context.Background(), crb, client.PropagationPolicy(metav1.DeletePropagationForeground)) - }) - By("creating ClusterExtension with the watch-namespace configured") - ce := helpers.NewClusterExtensionObject(packageName, "0.0.5", ceName, saName, namespace) + ce := helpers.NewClusterExtensionObject(packageName, "0.0.5", ceName, namespace) ce.Spec.Source.Catalog.Selector = &metav1.LabelSelector{ MatchLabels: map[string]string{ "olm.operatorframework.io/metadata.name": catalogName, @@ -378,29 +330,9 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace] OLMv1 ope }) } - saName := fmt.Sprintf("install-webhook-bothns-%s-sa-%s", sc.id, suffix) - By(fmt.Sprintf("creating ServiceAccount %s for %s scenario", saName, sc.label)) - sa := helpers.NewServiceAccount(saName, installNamespace) - Expect(k8sClient.Create(ctx, sa)).To(Succeed(), "failed to create ServiceAccount %q", saName) - helpers.ExpectServiceAccountExists(ctx, saName, installNamespace) - DeferCleanup(func() { - By(fmt.Sprintf("cleanup: deleting ServiceAccount %s in namespace %s", sa.Name, sa.Namespace)) - _ = k8sClient.Delete(context.Background(), sa, client.PropagationPolicy(metav1.DeletePropagationForeground)) - }) - - crbName := fmt.Sprintf("install-webhook-bothns-%s-crb-%s", sc.id, suffix) - By(fmt.Sprintf("creating ClusterRoleBinding %s for %s scenario", crbName, sc.label)) - crb := helpers.NewClusterRoleBinding(crbName, "cluster-admin", saName, installNamespace) - Expect(k8sClient.Create(ctx, crb)).To(Succeed(), "failed to create ClusterRoleBinding %q", crbName) - helpers.ExpectClusterRoleBindingExists(ctx, crbName) - DeferCleanup(func() { - By(fmt.Sprintf("cleanup: deleting ClusterRoleBinding %s", crb.Name)) - _ = k8sClient.Delete(context.Background(), crb, client.PropagationPolicy(metav1.DeletePropagationForeground)) - }) - ceName := fmt.Sprintf("install-webhook-bothns-%s-ce-%s", sc.id, suffix) By(fmt.Sprintf("creating ClusterExtension %s for %s scenario", ceName, sc.label)) - ce := helpers.NewClusterExtensionObject(packageName, "0.0.5", ceName, saName, installNamespace) + ce := helpers.NewClusterExtensionObject(packageName, "0.0.5", ceName, installNamespace) ce.Spec.Source.Catalog.Selector = &metav1.LabelSelector{ MatchLabels: map[string]string{ "olm.operatorframework.io/metadata.name": catalogName, @@ -453,9 +385,6 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace] OLMv1 ope Expect(k8sClient.Delete(ctx, ce, client.PropagationPolicy(deletePolicy))).To(Succeed(), "failed to delete ClusterExtension %q", ceName) helpers.EnsureCleanupClusterExtension(context.Background(), packageName, crdName) - Expect(k8sClient.Delete(ctx, crb, client.PropagationPolicy(deletePolicy))).To(Succeed(), "failed to delete ClusterRoleBinding %q", crbName) - Expect(k8sClient.Delete(ctx, sa, client.PropagationPolicy(deletePolicy))).To(Succeed(), "failed to delete ServiceAccount %q", saName) - // Trigger namespace deletion and proceed without blocking. By this point // EnsureCleanupClusterExtension has completed, meaning the ClusterObjectSet // teardown has deleted all managed resources (Deployment, Service, etc.) and the @@ -478,15 +407,13 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace][Serial] O crdSuffix string ) - var unique, saName, crbName, ceName string + var unique, ceName string BeforeEach(func(ctx SpecContext) { helpers.RequireOLMv1CapabilityOnOpenshift() helpers.RequireImageRegistry(ctx) k8sClient = env.Get().K8sClient unique = rand.String(4) namespace = fmt.Sprintf("olmv1-%s-ns-%s", testPrefix, unique) - saName = fmt.Sprintf("install-%s-sa-%s", testPrefix, unique) - crbName = fmt.Sprintf("install-%s-crb-%s", testPrefix, unique) ceName = fmt.Sprintf("install-%s-ce-%s", testPrefix, unique) // Build in-cluster bundle and catalog using webhook testdata (supports AllNamespaces mode only) @@ -533,30 +460,8 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace][Serial] O It("should fail to install a cluster extension successfully", Label("original-name:[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace][Skipped:Disconnected] OLMv1 operator installation support for ownNamespace watch mode with an operator that does not support ownNamespace installation mode should fail to install a cluster extension successfully"), func(ctx SpecContext) { - By("creating ServiceAccount") - sa := helpers.NewServiceAccount(saName, namespace) - Expect(k8sClient.Create(ctx, sa)).To(Succeed(), "failed to create ServiceAccount %q", saName) - By("ensuring ServiceAccount is available before proceeding") - helpers.ExpectServiceAccountExists(ctx, saName, namespace) - By("registering cleanup for ServiceAccount") - DeferCleanup(func() { - By(fmt.Sprintf("cleanup: deleting ServiceAccount %s in namespace %s", sa.Name, sa.Namespace)) - _ = k8sClient.Delete(context.Background(), sa, client.PropagationPolicy(metav1.DeletePropagationForeground)) - }) - - By("creating ClusterRoleBinding") - crb := helpers.NewClusterRoleBinding(crbName, "cluster-admin", saName, namespace) - Expect(k8sClient.Create(ctx, crb)).To(Succeed(), "failed to create ClusterRoleBinding %q", crbName) - By("ensuring ClusterRoleBinding is available before proceeding") - helpers.ExpectClusterRoleBindingExists(ctx, crbName) - By("registering cleanup for ClusterRoleBinding") - DeferCleanup(func() { - By(fmt.Sprintf("cleanup: deleting ClusterRoleBinding %s", crb.Name)) - _ = k8sClient.Delete(context.Background(), crb, client.PropagationPolicy(metav1.DeletePropagationForeground)) - }) - By("creating ClusterExtension with the watch-namespace configured using webhook operator that only supports AllNamespaces mode") - ce := helpers.NewClusterExtensionObject("webhook-operator", "0.0.5", ceName, saName, namespace) + ce := helpers.NewClusterExtensionObject("webhook-operator", "0.0.5", ceName, namespace) ce.Spec.Source.Catalog.Selector = &metav1.LabelSelector{ MatchLabels: map[string]string{ "olm.operatorframework.io/metadata.name": catalogName, @@ -605,15 +510,13 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace] OLMv1 ope crdSuffix string ) - var unique, saName, crbName, ceName string + var unique, ceName string BeforeEach(func(ctx SpecContext) { helpers.RequireOLMv1CapabilityOnOpenshift() helpers.RequireImageRegistry(ctx) k8sClient = env.Get().K8sClient unique = rand.String(4) namespace = fmt.Sprintf("olmv1-%s-ns-%s", testPrefix, unique) - saName = fmt.Sprintf("install-%s-sa-%s", testPrefix, unique) - crbName = fmt.Sprintf("install-%s-crb-%s", testPrefix, unique) ceName = fmt.Sprintf("install-%s-ce-%s", testPrefix, unique) // Generate unique CRD suffix for parallel execution @@ -669,30 +572,10 @@ var _ = Describe("[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace] OLMv1 ope It("should fail to install the ClusterExtension when watch namespace is invalid", Label("original-name:[sig-olmv1][OCPFeatureGate:NewOLMOwnSingleNamespace][Skipped:Disconnected][Serial] OLMv1 operator installation should reject invalid watch namespace configuration and update the status conditions accordingly should fail to install the ClusterExtension when watch namespace is invalid"), func(ctx SpecContext) { - By("creating ServiceAccount") - sa := helpers.NewServiceAccount(saName, namespace) - Expect(k8sClient.Create(ctx, sa)).To(Succeed(), "failed to create ServiceAccount %q", saName) - By("ensuring ServiceAccount is available before proceeding") - helpers.ExpectServiceAccountExists(ctx, saName, namespace) - DeferCleanup(func() { - By(fmt.Sprintf("cleanup: deleting ServiceAccount %s in namespace %s", sa.Name, sa.Namespace)) - _ = k8sClient.Delete(context.Background(), sa, client.PropagationPolicy(metav1.DeletePropagationForeground)) - }) - - By("creating ClusterRoleBinding") - crb := helpers.NewClusterRoleBinding(crbName, "cluster-admin", saName, namespace) - Expect(k8sClient.Create(ctx, crb)).To(Succeed(), "failed to create ClusterRoleBinding %q", crbName) - By("ensuring ClusterRoleBinding is available before proceeding") - helpers.ExpectClusterRoleBindingExists(ctx, crbName) - DeferCleanup(func() { - By(fmt.Sprintf("cleanup: deleting ClusterRoleBinding %s", crb.Name)) - _ = k8sClient.Delete(context.Background(), crb, client.PropagationPolicy(metav1.DeletePropagationForeground)) - }) - invalidWatchNamespace := fmt.Sprintf("%s-", namespace) By("creating ClusterExtension with an invalid watch namespace configured") - ce := helpers.NewClusterExtensionObject(packageName, "0.0.5", ceName, saName, namespace) + ce := helpers.NewClusterExtensionObject(packageName, "0.0.5", ceName, namespace) ce.Spec.Source.Catalog.Selector = &metav1.LabelSelector{ MatchLabels: map[string]string{ "olm.operatorframework.io/metadata.name": catalogName, diff --git a/openshift/tests-extension/test/qe/specs/olmv1_cc.go b/openshift/tests-extension/test/qe/specs/olmv1_cc.go index f2fbbec3c9..c282a6fc2d 100644 --- a/openshift/tests-extension/test/qe/specs/olmv1_cc.go +++ b/openshift/tests-extension/test/qe/specs/olmv1_cc.go @@ -647,20 +647,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif g.It("PolarionID:73289-[OTP][Skipped:Disconnected]Check the deprecation conditions and messages", func() { var ( - caseID = "73289" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-73289" - sa = "sa73289" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "73289" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + ns = "ns-73289" + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-73289", Imageref: "quay.io/olmqe/olmtest-operator-index:nginxolm73289", LabelValue: labelValue, @@ -672,7 +665,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif PackageName: "nginx73289v1", Channel: "candidate-v1.0", Version: "1.0.1", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -684,10 +676,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif err := oc.WithoutNamespace().AsAdmin().Run("create").Args("ns", ns).Execute() o.Expect(err).NotTo(o.HaveOccurred()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -787,20 +775,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif g.It("PolarionID:74948-[OTP][Skipped:Disconnected]catalog offer the operator content through https server", func() { var ( - caseID = "74948" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-74948" - sa = "sa74948" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "74948" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + ns = "ns-74948" + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-74948", Imageref: "quay.io/openshifttest/nginxolm-operator-index:nginxolm74948", LabelValue: labelValue, @@ -812,7 +793,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif PackageName: "nginx74948", Channel: "candidate-v1.0", Version: "1.0.3", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -829,10 +809,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Examine the service to confirm that the annotations are present") describe, err := oc.WithoutNamespace().AsAdmin().Run("describe").Args("service", "catalogd-service", "-n", "openshift-catalogd").Output() o.Expect(err).NotTo(o.HaveOccurred()) @@ -866,20 +842,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif g.It("PolarionID:74978-[OTP][Level0][Skipped:Disconnected]CRD upgrade will be prevented if the Scope is switched between Namespaced and Cluster", func() { var ( - caseID = "74978" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-74978" - sa = "sa74978" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "74978" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + ns = "ns-74978" + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-74978", Imageref: "quay.io/openshifttest/nginxolm-operator-index:nginxolm74978", LabelValue: labelValue, @@ -891,7 +860,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif PackageName: "nginx74978", Channel: "candidate-v1.0", Version: "1.0.1", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -908,10 +876,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clusterextension v1.0.1") defer clusterextension.Delete(oc) clusterextension.Create(oc) @@ -941,20 +905,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif g.It("PolarionID:75218-[OTP][Skipped:Disconnected]Disabling the CRD Upgrade Safety preflight checks", func() { var ( - caseID = "75218" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-75218" - sa = "sa75218" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "75218" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + ns = "ns-75218" + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-75218", Imageref: "quay.io/openshifttest/nginxolm-operator-index:nginxolm75218", LabelValue: labelValue, @@ -966,7 +923,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif PackageName: "nginx75218", Channel: "candidate-v1.0", Version: "1.0.1", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -983,10 +939,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clusterextension v1.0.1") defer clusterextension.Delete(oc) clusterextension.Create(oc) @@ -1045,20 +997,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif g.It("PolarionID:75122-[OTP][Skipped:Disconnected]CRD upgrade check Removing an existing stored version and add a new CRD with no modifications to existing versions", func() { exutil.SkipForSNOCluster(oc) var ( - caseID = "75122" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-75122" - sa = "sa75122" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "75122" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + ns = "ns-75122" + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-75122", Imageref: "quay.io/openshifttest/nginxolm-operator-index:nginxolm75122", LabelValue: labelValue, @@ -1070,7 +1015,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif PackageName: "nginx75122", Channel: "candidate-v1.0", Version: "1.0.1", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1087,10 +1031,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clusterextension v1.0.1") defer clusterextension.Delete(oc) clusterextension.Create(oc) @@ -1128,20 +1068,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif g.It("PolarionID:75123-[OTP][Skipped:Disconnected]CRD upgrade checks for changes in required field and field type", func() { exutil.SkipForSNOCluster(oc) var ( - caseID = "75123" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-75123" - sa = "sa75123" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "75123" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + ns = "ns-75123" + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-75123", Imageref: "quay.io/openshifttest/nginxolm-operator-index:nginxolm75123", LabelValue: labelValue, @@ -1153,7 +1086,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif PackageName: "nginx75123", Channel: "candidate-v1.0", Version: "1.0.1", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1170,10 +1102,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clusterextension v1.0.1") defer clusterextension.Delete(oc) clusterextension.Create(oc) @@ -1218,20 +1146,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif g.It("PolarionID:75124-[OTP][Skipped:Disconnected]CRD upgrade checks for changes in default values", func() { exutil.SkipForSNOCluster(oc) var ( - caseID = "75124" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-75124" - sa = "sa75124" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "75124" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + ns = "ns-75124" + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-75124", Imageref: "quay.io/openshifttest/nginxolm-operator-index:nginxolm75124", LabelValue: labelValue, @@ -1243,7 +1164,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif PackageName: "nginx75124", Channel: "candidate-v1.0", Version: "1.0.1", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1260,10 +1180,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clusterextension v1.0.1") defer clusterextension.Delete(oc) clusterextension.Create(oc) @@ -1295,20 +1211,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif g.It("PolarionID:75515-[OTP][Skipped:Disconnected]CRD upgrade checks for changes in enumeration values", func() { exutil.SkipForSNOCluster(oc) var ( - caseID = "75515" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-75515" - sa = "sa75515" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "75515" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + ns = "ns-75515" + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-75515", Imageref: "quay.io/openshifttest/nginxolm-operator-index:nginxolm75515", LabelValue: labelValue, @@ -1320,7 +1229,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif PackageName: "nginx75515", Channel: "candidate-v1.0", Version: "1.0.1", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1337,10 +1245,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clusterextension v1.0.1") defer clusterextension.Delete(oc) clusterextension.Create(oc) @@ -1373,20 +1277,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif g.It("PolarionID:75516-[OTP][Skipped:Disconnected]CRD upgrade checks for the field maximum minimum changes", func() { exutil.SkipForSNOCluster(oc) var ( - caseID = "75516" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-75516" - sa = "sa75516" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "75516" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + ns = "ns-75516" + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-75516", Imageref: "quay.io/openshifttest/nginxolm-operator-index:nginxolm75516", LabelValue: labelValue, @@ -1398,7 +1295,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif PackageName: "nginx75516", Channel: "candidate-v1.0", Version: "1.0.1", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1415,10 +1311,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clustercatalog", g.Label("NonHyperShif o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clusterextension v1.0.1") defer clusterextension.Delete(oc) clusterextension.Create(oc) diff --git a/openshift/tests-extension/test/qe/specs/olmv1_ce.go b/openshift/tests-extension/test/qe/specs/olmv1_ce.go index f4706a19e0..5bbea2e08d 100644 --- a/openshift/tests-extension/test/qe/specs/olmv1_ce.go +++ b/openshift/tests-extension/test/qe/specs/olmv1_ce.go @@ -161,202 +161,16 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh }) - g.It("PolarionID:68936-[OTP]cluster extension can not be installed with insufficient permission sa for operand", g.Label("original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:68936-[Skipped:Disconnected]cluster extension can not be installed with insufficient permission sa for operand"), func() { - e2e.Logf("Testing ClusterExtension installation failure when ServiceAccount lacks sufficient permissions for operand resources. Originally case 75492, using 68936 for faster execution.") - exutil.SkipForSNOCluster(oc) - olmv1util.ValidateAccessEnvironment(oc) - var ( - caseID = "68936" - ns = "ns-" + caseID - sa = caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - // Select template based on Boxcutter runtime feature gate - saClusterRoleBindingOperandTemplate string - ) - - // Use Boxcutter template if BoxcutterRuntime is enabled, otherwise use Helm template - // Note: Both templates have the same content for this test (both lack finalizers permissions) - if olmv1util.IsFeaturegateEnabled(oc, "NewOLMBoxCutterRuntime") { - saClusterRoleBindingOperandTemplate = filepath.Join(baseDir, "sa-nginx-insufficient-operand-clusterrole-boxcutter.yaml") - } else { - saClusterRoleBindingOperandTemplate = filepath.Join(baseDir, "sa-nginx-insufficient-operand-clusterrole.yaml") - } - - saCrb := olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - RBACObjects: []olmv1util.ChildResource{ - {Kind: "RoleBinding", Ns: ns, Names: []string{fmt.Sprintf("%s-installer-role-binding", sa)}}, - {Kind: "Role", Ns: ns, Names: []string{fmt.Sprintf("%s-installer-role", sa)}}, - {Kind: "ClusterRoleBinding", Ns: "", Names: []string{fmt.Sprintf("%s-installer-rbac-clusterrole-binding", sa), - fmt.Sprintf("%s-installer-clusterrole-binding", sa)}}, - {Kind: "ClusterRole", Ns: "", Names: []string{fmt.Sprintf("%s-installer-rbac-clusterrole", sa), - fmt.Sprintf("%s-installer-clusterrole", sa)}}, - {Kind: "ServiceAccount", Ns: ns, Names: []string{sa}}, - }, - Kinds: "okv68936s", - Template: saClusterRoleBindingOperandTemplate, - } - clustercatalog := olmv1util.ClusterCatalogDescription{ - Name: "clustercatalog-68936", - Imageref: "quay.io/olmqe/nginx-ok-index:vokv68936", - LabelValue: labelValue, - Template: clustercatalogTemplate, - } - ceInsufficient := olmv1util.ClusterExtensionDescription{ - Name: "insufficient-68936", - PackageName: "nginx-ok-v68936", - Channel: "alpha", - Version: ">=0.0.1", - InstallNamespace: ns, - SaName: sa, - LabelValue: labelValue, - Template: clusterextensionTemplate, - } - - g.By("Create namespace") - defer func() { - _ = oc.WithoutNamespace().AsAdmin().Run("delete").Args("ns", ns, "--ignore-not-found", "--force").Execute() - }() - err := oc.WithoutNamespace().AsAdmin().Run("create").Args("ns", ns).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - - g.By("Create clustercatalog") - defer clustercatalog.Delete(oc) - clustercatalog.Create(oc) - - g.By("check Insufficient sa from operand") - defer ceInsufficient.Delete(oc) - _ = ceInsufficient.CreateWithoutCheck(oc) - if olmv1util.IsFeaturegateEnabled(oc, "NewOLMPreflightPermissionChecks") { - // Env2 (Helm, preflight) or Env3 (Boxcutter, preflight): Both return same preflight error - ceInsufficient.CheckClusterExtensionCondition(oc, "Progressing", "message", "pre-authorization failed", 10, 60, 0) - } else { - // Env1 (Helm, no preflight) or Env4 (Boxcutter, no preflight) - // Error checking order differs between runtimes: - // - Helm (Env1): checks blockOwnerDeletion first, then privilege escalation - // - Boxcutter (Env4): checks privilege escalation first, then blockOwnerDeletion - if olmv1util.IsFeaturegateEnabled(oc, "NewOLMBoxCutterRuntime") { - // Env4: Boxcutter encounters privilege escalation error before blockOwnerDeletion check - ceInsufficient.CheckClusterExtensionCondition(oc, "Progressing", "message", "is attempting to grant RBAC permissions not currently held", 10, 60, 0) - } else { - // Env1: Helm encounters blockOwnerDeletion error - ceInsufficient.CheckClusterExtensionCondition(oc, "Progressing", "message", "cannot set blockOwnerDeletion", 10, 60, 0) - } - } - - }) - - g.It("PolarionID:68937-[OTP]cluster extension can not be installed with insufficient permission sa for operand rbac object", g.Label("original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:68937-[Skipped:Disconnected]cluster extension can not be installed with insufficient permission sa for operand rbac object"), func() { - e2e.Logf("Testing ClusterExtension installation failure when ServiceAccount lacks sufficient permissions for operand RBAC objects. Originally case 75492, using 68937 for faster execution.") - exutil.SkipForSNOCluster(oc) + g.It("PolarionID:70723-[OTP][Skipped:Disconnected]olmv1 downgrade version", func() { olmv1util.ValidateAccessEnvironment(oc) var ( - caseID = "68937" - ns = "ns-" + caseID - sa = caseID + caseID = "70723" labelValue = caseID + ns = "ns-70723" baseDir = exutil.FixturePath("testdata", "olm") clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - // Select template based on Boxcutter runtime feature gate - saClusterRoleBindingOperandTemplate string - ) - - // Use Boxcutter template if BoxcutterRuntime is enabled, otherwise use Helm template - if olmv1util.IsFeaturegateEnabled(oc, "NewOLMBoxCutterRuntime") { - saClusterRoleBindingOperandTemplate = filepath.Join(baseDir, "sa-nginx-insufficient-operand-rbac-boxcutter.yaml") - } else { - saClusterRoleBindingOperandTemplate = filepath.Join(baseDir, "sa-nginx-insufficient-operand-rbac.yaml") - } - - saCrb := olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - RBACObjects: []olmv1util.ChildResource{ - {Kind: "RoleBinding", Ns: ns, Names: []string{fmt.Sprintf("%s-installer-role-binding", sa)}}, - {Kind: "Role", Ns: ns, Names: []string{fmt.Sprintf("%s-installer-role", sa)}}, - {Kind: "ClusterRoleBinding", Ns: "", Names: []string{fmt.Sprintf("%s-installer-rbac-clusterrole-binding", sa), - fmt.Sprintf("%s-installer-clusterrole-binding", sa)}}, - {Kind: "ClusterRole", Ns: "", Names: []string{fmt.Sprintf("%s-installer-rbac-clusterrole", sa), - fmt.Sprintf("%s-installer-clusterrole", sa)}}, - {Kind: "ServiceAccount", Ns: ns, Names: []string{sa}}, - }, - Kinds: "okv68937s", - Template: saClusterRoleBindingOperandTemplate, - } - clustercatalog := olmv1util.ClusterCatalogDescription{ - Name: "clustercatalog-68937", - Imageref: "quay.io/olmqe/nginx-ok-index:vokv68937", - LabelValue: labelValue, - Template: clustercatalogTemplate, - } - ceInsufficient := olmv1util.ClusterExtensionDescription{ - Name: "insufficient-68937", - PackageName: "nginx-ok-v68937", - Channel: "alpha", - Version: ">=0.0.1", - InstallNamespace: ns, - SaName: sa, - LabelValue: labelValue, - Template: clusterextensionTemplate, - } - - g.By("Create namespace") - defer func() { - _ = oc.WithoutNamespace().AsAdmin().Run("delete").Args("ns", ns, "--ignore-not-found", "--force").Execute() - }() - err := oc.WithoutNamespace().AsAdmin().Run("create").Args("ns", ns).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - - g.By("Create clustercatalog") - defer clustercatalog.Delete(oc) - clustercatalog.Create(oc) - - g.By("check Insufficient sa from operand rbac") - defer ceInsufficient.Delete(oc) - _ = ceInsufficient.CreateWithoutCheck(oc) - if olmv1util.IsFeaturegateEnabled(oc, "NewOLMPreflightPermissionChecks") { - // Env2 (Helm, preflight) or Env3 (Boxcutter, preflight): Both return same preflight error - ceInsufficient.CheckClusterExtensionCondition(oc, "Progressing", "message", "pre-authorization failed", 10, 60, 0) - } else { - // Env1 (Helm, no preflight) or Env4 (Boxcutter, no preflight): Both return K8s API RBAC error - // The specific error message is the same for both runtimes when encountering the same permission issue - ceInsufficient.CheckClusterExtensionCondition(oc, "Progressing", "message", "permissions not currently held", 10, 60, 0) - } - - }) - - g.It("PolarionID:70723-[OTP][Skipped:Disconnected]olmv1 downgrade version", func() { - olmv1util.ValidateAccessEnvironment(oc) - var ( - caseID = "70723" - labelValue = caseID - ns = "ns-70723" - sa = "sa70723" - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-70723", Imageref: "quay.io/openshifttest/nginxolm-operator-index:nginxolm70723", LabelValue: labelValue, @@ -368,7 +182,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh PackageName: "nginx70723", Channel: "candidate-v2", Version: "2.2.1", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -382,10 +195,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -404,606 +213,16 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh clusterextension.WaitClusterExtensionVersion(oc, "2.0.0") }) - g.It("PolarionID:75492-[OTP][Level0]cluster extension can not be installed with wrong sa or insufficient permission sa", g.Label("original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:75492-[Skipped:Disconnected]cluster extension can not be installed with wrong sa or insufficient permission sa"), func() { - exutil.SkipForSNOCluster(oc) - olmv1util.ValidateAccessEnvironment(oc) - var ( - caseID = "75492" - ns = "ns-" + caseID - sa = "sa" + caseID - labelValue = caseID - catalogName = "clustercatalog-" + caseID - ceInsufficientName = "ce-insufficient-" + caseID - ceWrongSaName = "ce-wrongsa-" + caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - // Select template based on Boxcutter runtime feature gate - saClusterRoleBindingTemplate string - ) - - // Use Boxcutter template if BoxcutterRuntime is enabled, otherwise use Helm template - // Note: Both templates have the same content for this test (both lack finalizers permissions) - if olmv1util.IsFeaturegateEnabled(oc, "NewOLMBoxCutterRuntime") { - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-nginx-insufficient-bundle-boxcutter.yaml") - } else { - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-nginx-insufficient-bundle.yaml") - } - - saCrb := olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - RBACObjects: []olmv1util.ChildResource{ - {Kind: "RoleBinding", Ns: ns, Names: []string{fmt.Sprintf("%s-installer-role-binding", sa)}}, - {Kind: "Role", Ns: ns, Names: []string{fmt.Sprintf("%s-installer-role", sa)}}, - {Kind: "ClusterRoleBinding", Ns: "", Names: []string{fmt.Sprintf("%s-installer-rbac-clusterrole-binding", sa), - fmt.Sprintf("%s-installer-clusterrole-binding", sa)}}, - {Kind: "ClusterRole", Ns: "", Names: []string{fmt.Sprintf("%s-installer-rbac-clusterrole", sa), - fmt.Sprintf("%s-installer-clusterrole", sa)}}, - {Kind: "ServiceAccount", Ns: ns, Names: []string{sa}}, - }, - Kinds: "okv3277775492s", - Template: saClusterRoleBindingTemplate, - } - clustercatalog := olmv1util.ClusterCatalogDescription{ - Name: catalogName, - Imageref: "quay.io/olmqe/nginx-ok-index:vokv3283", - LabelValue: labelValue, - Template: clustercatalogTemplate, - } - ce75492Insufficient := olmv1util.ClusterExtensionDescription{ - Name: ceInsufficientName, - PackageName: "nginx-ok-v3277775492", - Channel: "alpha", - Version: ">=0.0.1", - InstallNamespace: ns, - SaName: sa, - LabelValue: labelValue, - Template: clusterextensionTemplate, - } - ce75492WrongSa := olmv1util.ClusterExtensionDescription{ - Name: ceWrongSaName, - PackageName: "nginx-ok-v3277775492", - Channel: "alpha", - Version: ">=0.0.1", - InstallNamespace: ns, - SaName: sa + "1", - LabelValue: labelValue, - Template: clusterextensionTemplate, - } - - g.By("Create namespace") - defer func() { - _ = oc.WithoutNamespace().AsAdmin().Run("delete").Args("ns", ns, "--ignore-not-found", "--force").Execute() - }() - err := oc.WithoutNamespace().AsAdmin().Run("create").Args("ns", ns).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - - g.By("Create clustercatalog") - defer clustercatalog.Delete(oc) - clustercatalog.Create(oc) - - g.By("check Insufficient sa from bundle") - defer ce75492Insufficient.Delete(oc) - _ = ce75492Insufficient.CreateWithoutCheck(oc) - if olmv1util.IsFeaturegateEnabled(oc, "NewOLMPreflightPermissionChecks") { - // Env2 (Helm, preflight) or Env3 (Boxcutter, preflight): Both return same preflight error - ce75492Insufficient.CheckClusterExtensionCondition(oc, "Progressing", "message", "pre-authorization failed", 10, 60, 0) - } else { - // Env1 (Helm, no preflight) or Env4 (Boxcutter, no preflight) - // Error checking order differs between runtimes: - // - Helm (Env1): may encounter CRD creation errors first - // - Boxcutter (Env4): encounters privilege escalation errors first - if olmv1util.IsFeaturegateEnabled(oc, "NewOLMBoxCutterRuntime") { - // Env4: Boxcutter encounters privilege escalation error (missing namespace permissions) - ce75492Insufficient.CheckClusterExtensionCondition(oc, "Progressing", "message", "is attempting to grant RBAC permissions not currently held", 10, 60, 0) - } else { - // Env1: Helm may encounter CRD-related errors - ce75492Insufficient.CheckClusterExtensionCondition(oc, "Progressing", "message", "could not get information about the resource CustomResourceDefinition", 10, 60, 0) - } - } - g.By("check wrong sa") - defer ce75492WrongSa.Delete(oc) - _ = ce75492WrongSa.CreateWithoutCheck(oc) - // All environments now validate ServiceAccount existence at the start of the reconciliation - // pipeline (after finalizer handling, before revision state retrieval). This provides: - // - Consistent error messages across all feature gate combinations - // - Fail-fast behavior (no wasted reconciliation cycles) - // - User-facing error format: "operation cannot proceed due to the following validation error(s): - // service account \"xxx\" not found in namespace \"yyy\"" - // - // The validation uses ServiceAccountValidator which performs a direct CoreV1 API Get call. - ce75492WrongSa.CheckClusterExtensionCondition(oc, "Progressing", "message", "not found", 10, 60, 0) - }) - - g.It("PolarionID:75493-[OTP][Level0]cluster extension can be installed with enough permission sa", g.Label("original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:75493-[Skipped:Disconnected]cluster extension can be installed with enough permission sa"), func() { - exutil.SkipForSNOCluster(oc) - olmv1util.ValidateAccessEnvironment(oc) - var ( - caseID = "75493" - ns = "ns-" + caseID - sa = "sa" + caseID - labelValue = caseID - catalogName = "clustercatalog-" + caseID - ceSufficientName = "ce-sufficient" + caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - // Select template based on runtime: Boxcutter needs clusterobjectsets/finalizers, Helm needs clusterextensions/finalizers - saTemplate string - ) - if olmv1util.IsFeaturegateEnabled(oc, "NewOLMBoxCutterRuntime") { - saTemplate = filepath.Join(baseDir, "sa-nginx-limited-boxcutter.yaml") - } else { - saTemplate = filepath.Join(baseDir, "sa-nginx-limited.yaml") - } - var ( - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - RBACObjects: []olmv1util.ChildResource{ - {Kind: "RoleBinding", Ns: ns, Names: []string{fmt.Sprintf("%s-installer-role-binding", sa)}}, - {Kind: "Role", Ns: ns, Names: []string{fmt.Sprintf("%s-installer-role", sa)}}, - {Kind: "ClusterRoleBinding", Ns: "", Names: []string{fmt.Sprintf("%s-installer-rbac-clusterrole-binding", sa), - fmt.Sprintf("%s-installer-clusterrole-binding", sa)}}, - {Kind: "ClusterRole", Ns: "", Names: []string{fmt.Sprintf("%s-installer-rbac-clusterrole", sa), - fmt.Sprintf("%s-installer-clusterrole", sa)}}, - {Kind: "ServiceAccount", Ns: ns, Names: []string{sa}}, - }, - Kinds: "okv3277775493s", - Template: saTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ - Name: catalogName, - Imageref: "quay.io/olmqe/nginx-ok-index:vokv3283", - LabelValue: labelValue, - Template: clustercatalogTemplate, - } - ce75493 = olmv1util.ClusterExtensionDescription{ - Name: ceSufficientName, - PackageName: "nginx-ok-v3277775493", - Channel: "alpha", - Version: ">=0.0.1", - InstallNamespace: ns, - SaName: sa, - LabelValue: labelValue, - Template: clusterextensionTemplate, - } - ) - - g.By("Create namespace") - defer func() { - _ = oc.WithoutNamespace().AsAdmin().Run("delete").Args("ns", ns, "--ignore-not-found", "--force").Execute() - }() - err := oc.WithoutNamespace().AsAdmin().Run("create").Args("ns", ns).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - - g.By("Create clustercatalog") - defer clustercatalog.Delete(oc) - clustercatalog.Create(oc) - - g.By("check if ce is installed with limited permission") - defer ce75493.Delete(oc) - ce75493.Create(oc) - o.Expect(olmv1util.Appearance(oc, exutil.Appear, "customresourcedefinitions.apiextensions.k8s.io", "okv3277775493s.cache.example.com")).To(o.BeTrue()) - o.Expect(olmv1util.Appearance(oc, exutil.Appear, "services", "nginx-ok-v3283-75493-controller-manager-metrics-service", "-n", ns)).To(o.BeTrue()) - ce75493.Delete(oc) - o.Expect(olmv1util.Appearance(oc, exutil.Disappear, "customresourcedefinitions.apiextensions.k8s.io", "okv3277775493s.cache.example.com")).To(o.BeTrue()) - o.Expect(olmv1util.Appearance(oc, exutil.Disappear, "services", "nginx-ok-v3283-75493-controller-manager-metrics-service", "-n", ns)).To(o.BeTrue()) - }) - - g.It("PolarionID:81538-[OTP]preflight check on permission on allns mode", g.Label("original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:81538-[Skipped:Disconnected]preflight check on permission on allns mode"), func() { - if !olmv1util.IsFeaturegateEnabled(oc, "NewOLMPreflightPermissionChecks") { - g.Skip("NewOLMPreflightPermissionChecks feature gate is disabled. This test requires preflight permission validation to be enabled.") - } - exutil.SkipForSNOCluster(oc) - olmv1util.ValidateAccessEnvironment(oc) + g.It("PolarionID:87224-[Skipped:Disconnected]Upgrade version support [Serial]", func() { var ( - caseID = "81538" + caseID = "87224" ns = "ns-" + caseID - sa = "sa" + caseID - labelValue = caseID - catalogName = "clustercatalog-" + caseID ceName = "ce-" + caseID - clusterroleName = ceName + "-clusterrole" - roleName = ceName + "-role" + "-" + ns - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saTemplate = filepath.Join(baseDir, "sa.yaml") - bindingTemplate = filepath.Join(baseDir, "binding-prefligth.yaml") - clusterroleTemplate = filepath.Join(baseDir, "prefligth-clusterrole.yaml") - clustercatalog = olmv1util.ClusterCatalogDescription{ - Name: catalogName, - Imageref: "quay.io/olmqe/nginx-ok-index:vokv81538", - LabelValue: labelValue, - Template: clustercatalogTemplate, - } - ce = olmv1util.ClusterExtensionDescription{ - Name: ceName, - PackageName: "nginx-ok-v81538", - Channel: "alpha", - Version: ">=0.0.1", - InstallNamespace: ns, - SaName: sa, - LabelValue: labelValue, - Template: clusterextensionTemplate, - } - ) - - g.By("Create namespace") - defer func() { - _ = oc.WithoutNamespace().AsAdmin().Run("delete").Args("ns", ns, "--ignore-not-found", "--force").Execute() - }() - err := oc.WithoutNamespace().AsAdmin().Run("create").Args("ns", ns).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - - g.By("Create clustercatalog") - defer clustercatalog.Delete(oc) - clustercatalog.Create(oc) - - g.By("create sa") - paremeters := []string{"-n", "default", "--ignore-unknown-parameters=true", "-f", saTemplate, "-p", - "NAME=" + sa, "NAMESPACE=" + ns} - configFileSa, errApplySa := olmv1util.ApplyNamepsaceResourceFromTemplate(oc, ns, paremeters...) - o.Expect(errApplySa).NotTo(o.HaveOccurred()) - defer func() { _ = oc.AsAdmin().WithoutNamespace().Run("delete").Args("-f", configFileSa).Execute() }() - - g.By("create clusterrole with wrong rule") - paremeters = []string{"-n", "default", "--ignore-unknown-parameters=true", "-f", clusterroleTemplate, "-p", - "NAME=" + clusterroleName} - configFileCLusterroe, errApplyCLusterrole := olmv1util.ApplyClusterResourceFromTemplate(oc, paremeters...) - o.Expect(errApplyCLusterrole).NotTo(o.HaveOccurred()) - defer func() { _ = oc.AsAdmin().WithoutNamespace().Run("delete").Args("-f", configFileCLusterroe).Execute() }() - - g.By("create binding") - paremeters = []string{"-n", "default", "--ignore-unknown-parameters=true", "-f", bindingTemplate, "-p", - "SANAME=" + sa, "NAMESPACE=" + ns, "ROLENAME=" + roleName, "CLUSTERROLESANAME=" + clusterroleName} - configFileBinding, errApplyBinding := olmv1util.ApplyClusterResourceFromTemplate(oc, paremeters...) - o.Expect(errApplyBinding).NotTo(o.HaveOccurred()) - defer func() { _ = oc.AsAdmin().WithoutNamespace().Run("delete").Args("-f", configFileBinding).Execute() }() - - g.By("check missing rule") - defer ce.Delete(oc) - _ = ce.CreateWithoutCheck(oc) - ce.CheckClusterExtensionCondition(oc, "Progressing", "message", - `Namespace:"" Verbs:[get] NonResourceURLs:[/metrics]`, 3, 150, 0) - ce.CheckClusterExtensionCondition(oc, "Progressing", "message", - `Namespace:"ns-81538" APIGroups:[] Resources:[services] ResourceNames:[nginx-ok-v81538-controller-manager-metrics-service] Verbs:[delete,get,patch,update]`, 3, 150, 0) - // Check finalizers permission based on Boxcutter runtime feature gate - if olmv1util.IsFeaturegateEnabled(oc, "NewOLMBoxCutterRuntime") { - // Env3: Boxcutter with preflight - expects clusterobjectsets/finalizers - // Note: In Boxcutter, the ResourceName is the ClusterObjectSet name (ce-81538-1 for first revision) - ce.CheckClusterExtensionCondition(oc, "Progressing", "message", - `Namespace:"" APIGroups:[olm.operatorframework.io] Resources:[clusterobjectsets/finalizers] ResourceNames:[ce-81538-1] Verbs:[update]`, 3, 150, 0) - } else { - // Env2: Helm with preflight - expects clusterextensions/finalizers - ce.CheckClusterExtensionCondition(oc, "Progressing", "message", - `Namespace:"" APIGroups:[olm.operatorframework.io] Resources:[clusterextensions/finalizers] ResourceNames:[ce-81538] Verbs:[update]`, 3, 150, 0) - } - - g.By("generate rbac per missing rule and delete ce") - jsonpath := fmt.Sprintf(`jsonpath={.status.conditions[?(@.type=="%s")].%s}`, "Progressing", "message") - output, errGet := olmv1util.GetNoEmpty(oc, "clusterextension", ce.Name, "-o", jsonpath) - o.Expect(errGet).NotTo(o.HaveOccurred()) - e2e.Logf("====%v====", output) - - start := "permissions to manage cluster extension:" - end1 := "authorization evaluation error:" - end2 := "for resolved bundle" - filtered := olmv1util.FilterPermissions(output, start, end1, end2) - e2e.Logf("===============================================================================") - e2e.Logf("%v", filtered) - e2e.Logf("===============================================================================") - rabcDir := e2e.TestContext.OutputDir - clusterroleFile := filepath.Join(rabcDir, fmt.Sprintf("%s.yaml", clusterroleName)) - roleFile := filepath.Join(rabcDir, fmt.Sprintf("%s.yaml", roleName)) - errGen := olmv1util.GenerateRBACFromMissingRules(filtered, ceName, rabcDir) - o.Expect(errGen).NotTo(o.HaveOccurred()) - - g.By("create clusterrole") - err = oc.AsAdmin().WithoutNamespace().Run("apply").Args("-f", clusterroleFile).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - - g.By("create role") - defer func() { _ = oc.AsAdmin().WithoutNamespace().Run("delete").Args("-f", roleFile).Execute() }() - err = oc.AsAdmin().WithoutNamespace().Run("apply").Args("-f", roleFile).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - - g.By("check ce again afrer applying correct rules") - ce.CheckClusterExtensionCondition(oc, "Progressing", "reason", "Succeeded", 10, 600, 0) - }) - - g.It("PolarionID:81664-[OTP]preflight check on permission on own ns mode", g.Label("original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:81664-[Skipped:Disconnected]preflight check on permission on own ns mode"), func() { - if !olmv1util.IsFeaturegateEnabled(oc, "NewOLMPreflightPermissionChecks") || - !olmv1util.IsFeaturegateEnabled(oc, "NewOLMOwnSingleNamespace") { - g.Skip("Required feature gates are disabled: NewOLMPreflightPermissionChecks and NewOLMOwnSingleNamespace must both be enabled for this test.") - } - exutil.SkipForSNOCluster(oc) - olmv1util.ValidateAccessEnvironment(oc) - var ( - caseID = "81664" - ns = "ns-" + caseID - sa = "sa" + caseID labelValue = caseID - catalogName = "clustercatalog-" + caseID - ceName = "ce-" + caseID - clusterroleName = ceName + "-clusterrole" - roleName = ceName + "-role" + "-" + ns baseDir = exutil.FixturePath("testdata", "olm") clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-OwnSingle.yaml") - saTemplate = filepath.Join(baseDir, "sa.yaml") - bindingTemplate = filepath.Join(baseDir, "binding-prefligth.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannel.yaml") clustercatalog = olmv1util.ClusterCatalogDescription{ - Name: catalogName, - Imageref: "quay.io/olmqe/nginx-ok-index:vokv81664", - LabelValue: labelValue, - Template: clustercatalogTemplate, - } - ce = olmv1util.ClusterExtensionDescription{ - Name: ceName, - PackageName: "nginx-ok-v81664", - Channel: "alpha", - Version: ">=0.0.1", - InstallNamespace: ns, - WatchNamespace: ns, - SaName: sa, - LabelValue: labelValue, - Template: clusterextensionTemplate, - } - ) - - g.By("Create namespace") - defer func() { - _ = oc.WithoutNamespace().AsAdmin().Run("delete").Args("ns", ns, "--ignore-not-found", "--force").Execute() - }() - err := oc.WithoutNamespace().AsAdmin().Run("create").Args("ns", ns).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - - g.By("Create clustercatalog") - defer clustercatalog.Delete(oc) - clustercatalog.Create(oc) - - g.By("create sa") - paremeters := []string{"-n", "default", "--ignore-unknown-parameters=true", "-f", saTemplate, "-p", - "NAME=" + sa, "NAMESPACE=" + ns} - configFileSa, errApplySa := olmv1util.ApplyNamepsaceResourceFromTemplate(oc, ns, paremeters...) - o.Expect(errApplySa).NotTo(o.HaveOccurred()) - defer func() { _ = oc.AsAdmin().WithoutNamespace().Run("delete").Args("-f", configFileSa).Execute() }() - - g.By("check missing rule") - defer ce.Delete(oc) - _ = ce.CreateWithoutCheck(oc) - ce.CheckClusterExtensionCondition(oc, "Progressing", "message", - `Namespace:"" Verbs:[get] NonResourceURLs:[/metrics]`, 3, 150, 0) - ce.CheckClusterExtensionCondition(oc, "Progressing", "message", - `Namespace:"ns-81664" APIGroups:[] Resources:[services] ResourceNames:[nginx-ok-v81664-controller-manager-metrics-service] Verbs:[delete,get,patch,update]`, 3, 150, 0) - // Check finalizers permission based on Boxcutter runtime feature gate - if olmv1util.IsFeaturegateEnabled(oc, "NewOLMBoxCutterRuntime") { - // Env3: Boxcutter with preflight - expects clusterobjectsets/finalizers - // Note: In Boxcutter, the ResourceName is the ClusterObjectSet name (ce-81664-1 for first revision) - ce.CheckClusterExtensionCondition(oc, "Progressing", "message", - `Namespace:"" APIGroups:[olm.operatorframework.io] Resources:[clusterobjectsets/finalizers] ResourceNames:[ce-81664-1] Verbs:[update]`, 3, 150, 0) - } else { - // Env2: Helm with preflight - expects clusterextensions/finalizers - ce.CheckClusterExtensionCondition(oc, "Progressing", "message", - `Namespace:"" APIGroups:[olm.operatorframework.io] Resources:[clusterextensions/finalizers] ResourceNames:[ce-81664] Verbs:[update]`, 3, 150, 0) - } - - g.By("generate rbac per missing rule and delete ce") - jsonpath := fmt.Sprintf(`jsonpath={.status.conditions[?(@.type=="%s")].%s}`, "Progressing", "message") - output, errGet := olmv1util.GetNoEmpty(oc, "clusterextension", ce.Name, "-o", jsonpath) - o.Expect(errGet).NotTo(o.HaveOccurred()) - ce.Delete(oc) - e2e.Logf("====%v====", output) - - start := "permissions to manage cluster extension:" - end1 := "authorization evaluation error:" - end2 := "for resolved bundle" - filtered := olmv1util.FilterPermissions(output, start, end1, end2) - e2e.Logf("===============================================================================") - e2e.Logf("%v", filtered) - e2e.Logf("===============================================================================") - rabcDir := e2e.TestContext.OutputDir - clusterroleFile := filepath.Join(rabcDir, fmt.Sprintf("%s.yaml", clusterroleName)) - roleFile := filepath.Join(rabcDir, fmt.Sprintf("%s.yaml", roleName)) - errGen := olmv1util.GenerateRBACFromMissingRules(filtered, ceName, rabcDir) - o.Expect(errGen).NotTo(o.HaveOccurred()) - - g.By("create clusterrole") - defer func() { _ = oc.AsAdmin().WithoutNamespace().Run("delete").Args("-f", clusterroleFile).Execute() }() - err = oc.AsAdmin().WithoutNamespace().Run("apply").Args("-f", clusterroleFile).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - - g.By("create role") - defer func() { _ = oc.AsAdmin().WithoutNamespace().Run("delete").Args("-f", roleFile).Execute() }() - err = oc.AsAdmin().WithoutNamespace().Run("apply").Args("-f", roleFile).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - - g.By("create binding") - paremeters = []string{"-n", "default", "--ignore-unknown-parameters=true", "-f", bindingTemplate, "-p", - "SANAME=" + sa, "NAMESPACE=" + ns, "ROLENAME=" + roleName, "CLUSTERROLESANAME=" + clusterroleName} - configFileBinding, errApplyBinding := olmv1util.ApplyClusterResourceFromTemplate(oc, paremeters...) - o.Expect(errApplyBinding).NotTo(o.HaveOccurred()) - defer func() { _ = oc.AsAdmin().WithoutNamespace().Run("delete").Args("-f", configFileBinding).Execute() }() - - g.By("check ce again afrer applying correct rules") - ce.Create(oc) - }) - - g.It("PolarionID:81696-[OTP]preflight check on permission on single ns mode", g.Label("original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:81696-[Skipped:Disconnected]preflight check on permission on single ns mode"), func() { - if !olmv1util.IsFeaturegateEnabled(oc, "NewOLMPreflightPermissionChecks") || - !olmv1util.IsFeaturegateEnabled(oc, "NewOLMOwnSingleNamespace") { - g.Skip("Required feature gates are disabled: NewOLMPreflightPermissionChecks and NewOLMOwnSingleNamespace must both be enabled for this test.") - } - exutil.SkipForSNOCluster(oc) - olmv1util.ValidateAccessEnvironment(oc) - var ( - caseID = "81696" - ns = "ns-" + caseID - nsWatch = "ns-" + caseID + "-watch" - sa = "sa" + caseID - labelValue = caseID - catalogName = "clustercatalog-" + caseID - ceName = "ce-" + caseID - clusterroleName = ceName + "-clusterrole" - roleNsName = ceName + "-role" + "-" + ns - roleNsWatchName = ceName + "-role" + "-" + nsWatch - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-OwnSingle.yaml") - saTemplate = filepath.Join(baseDir, "sa.yaml") - bindingTemplate = filepath.Join(baseDir, "binding-prefligth_multirole.yaml") - clustercatalog = olmv1util.ClusterCatalogDescription{ - Name: catalogName, - Imageref: "quay.io/olmqe/nginx-ok-index:vokv81696", - LabelValue: labelValue, - Template: clustercatalogTemplate, - } - ce = olmv1util.ClusterExtensionDescription{ - Name: ceName, - PackageName: "nginx-ok-v81696", - Channel: "alpha", - Version: ">=0.0.1", - InstallNamespace: ns, - WatchNamespace: nsWatch, - SaName: sa, - LabelValue: labelValue, - Template: clusterextensionTemplate, - } - ) - - g.By("Create namespace") - defer func() { - _ = oc.WithoutNamespace().AsAdmin().Run("delete").Args("ns", ns, "--ignore-not-found", "--force").Execute() - }() - err := oc.WithoutNamespace().AsAdmin().Run("create").Args("ns", ns).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - - g.By("Create watch namespace") - defer func() { - _ = oc.WithoutNamespace().AsAdmin().Run("delete").Args("ns", nsWatch, "--ignore-not-found", "--force").Execute() - }() - err = oc.WithoutNamespace().AsAdmin().Run("create").Args("ns", nsWatch).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", nsWatch)).To(o.BeTrue()) - - g.By("Create clustercatalog") - defer clustercatalog.Delete(oc) - clustercatalog.Create(oc) - - g.By("create sa") - paremeters := []string{"-n", "default", "--ignore-unknown-parameters=true", "-f", saTemplate, "-p", - "NAME=" + sa, "NAMESPACE=" + ns} - configFileSa, errApplySa := olmv1util.ApplyNamepsaceResourceFromTemplate(oc, ns, paremeters...) - o.Expect(errApplySa).NotTo(o.HaveOccurred()) - defer func() { _ = oc.AsAdmin().WithoutNamespace().Run("delete").Args("-f", configFileSa).Execute() }() - - g.By("check missing rule") - defer ce.Delete(oc) - _ = ce.CreateWithoutCheck(oc) - ce.CheckClusterExtensionCondition(oc, "Progressing", "message", - `Namespace:"" Verbs:[get] NonResourceURLs:[/metrics]`, 3, 150, 0) - ce.CheckClusterExtensionCondition(oc, "Progressing", "message", - `Namespace:"ns-81696" APIGroups:[] Resources:[services] ResourceNames:[nginx-ok-v81696-controller-manager-metrics-service] Verbs:[delete,get,patch,update]`, 3, 150, 0) - // Check finalizers permission based on Boxcutter runtime feature gate - if olmv1util.IsFeaturegateEnabled(oc, "NewOLMBoxCutterRuntime") { - // Env3: Boxcutter with preflight - expects clusterobjectsets/finalizers - // Note: In Boxcutter, the ResourceName is the ClusterObjectSet name (ce-81696-1 for first revision) - ce.CheckClusterExtensionCondition(oc, "Progressing", "message", - `Namespace:"" APIGroups:[olm.operatorframework.io] Resources:[clusterobjectsets/finalizers] ResourceNames:[ce-81696-1] Verbs:[update]`, 3, 150, 0) - } else { - // Env2: Helm with preflight - expects clusterextensions/finalizers - ce.CheckClusterExtensionCondition(oc, "Progressing", "message", - `Namespace:"" APIGroups:[olm.operatorframework.io] Resources:[clusterextensions/finalizers] ResourceNames:[ce-81696] Verbs:[update]`, 3, 150, 0) - } - - g.By("generate rbac per missing rule and delete ce") - jsonpath := fmt.Sprintf(`jsonpath={.status.conditions[?(@.type=="%s")].%s}`, "Progressing", "message") - output, errGet := olmv1util.GetNoEmpty(oc, "clusterextension", ce.Name, "-o", jsonpath) - o.Expect(errGet).NotTo(o.HaveOccurred()) - ce.Delete(oc) - e2e.Logf("====%v====", output) - - start := "permissions to manage cluster extension:" - end1 := "authorization evaluation error:" - end2 := "for resolved bundle" - filtered := olmv1util.FilterPermissions(output, start, end1, end2) - e2e.Logf("===============================================================================") - e2e.Logf("%v", filtered) - e2e.Logf("===============================================================================") - rbacDir := e2e.TestContext.OutputDir - clusterroleFile := filepath.Join(rbacDir, fmt.Sprintf("%s.yaml", clusterroleName)) - roleNsFile := filepath.Join(rbacDir, fmt.Sprintf("%s.yaml", roleNsName)) - roleNsWatchFile := filepath.Join(rbacDir, fmt.Sprintf("%s.yaml", roleNsWatchName)) - - errGen := olmv1util.GenerateRBACFromMissingRules(filtered, ceName, rbacDir) - o.Expect(errGen).NotTo(o.HaveOccurred()) - - g.By("create clusterrole") - defer func() { _ = oc.AsAdmin().WithoutNamespace().Run("delete").Args("-f", clusterroleFile).Execute() }() - err = oc.AsAdmin().WithoutNamespace().Run("apply").Args("-f", clusterroleFile).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - - g.By("create role for ns") - defer func() { _ = oc.AsAdmin().WithoutNamespace().Run("delete").Args("-f", roleNsFile).Execute() }() - err = oc.AsAdmin().WithoutNamespace().Run("apply").Args("-f", roleNsFile).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - - g.By("create role for ns watch") - // Check if the watch namespace role file exists before trying to apply it - // The file may not exist if no permissions are needed for the watch namespace - if _, err := os.Stat(roleNsWatchFile); err == nil { - defer func() { _ = oc.AsAdmin().WithoutNamespace().Run("delete").Args("-f", roleNsWatchFile).Execute() }() - err = oc.AsAdmin().WithoutNamespace().Run("apply").Args("-f", roleNsWatchFile).Execute() - o.Expect(err).NotTo(o.HaveOccurred()) - } else { - e2e.Logf("Watch namespace role file %s does not exist, skipping creation", roleNsWatchFile) - } - - g.By("create binding") - paremeters = []string{"-n", "default", "--ignore-unknown-parameters=true", "-f", bindingTemplate, "-p", - "SANAME=" + sa, "NAMESPACE=" + ns, "ROLENAME=" + roleNsName, "CLUSTERROLESANAME=" + clusterroleName, - "WATCHNAMESPACE=" + nsWatch, "WATCHROLENAME=" + roleNsWatchName} - configFileBinding, errApplyBinding := olmv1util.ApplyClusterResourceFromTemplate(oc, paremeters...) - o.Expect(errApplyBinding).NotTo(o.HaveOccurred()) - defer func() { _ = oc.AsAdmin().WithoutNamespace().Run("delete").Args("-f", configFileBinding).Execute() }() - - g.By("check ce again afrer applying correct rules") - ce.Create(oc) - }) - - g.It("PolarionID:87224-[Skipped:Disconnected]Upgrade version support [Serial]", func() { - var ( - caseID = "87224" - ns = "ns-" + caseID - sa = "sa" + caseID - ceName = "ce-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-87224", LabelValue: labelValue, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87224", @@ -1015,7 +234,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh PackageName: "nginx-ok-v87224", Version: "0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1043,9 +261,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - defer saCrb.Delete(oc) - saCrb.Create(oc) - defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -1092,20 +307,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh exutil.SkipForSNOCluster(oc) olmv1util.ValidateAccessEnvironment(oc) var ( - caseID = "74618" - ns = "ns-" + caseID - sa = "sa" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "74618" + ns = "ns-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-74618", Imageref: "quay.io/olmqe/nginx-ok-index:vokv32777", LabelValue: labelValue, @@ -1117,7 +325,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1128,7 +335,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Version: ">=0.0.1", InstallNamespace: ns, UpgradeConstraintPolicy: "SelfCertified", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1138,7 +344,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1149,7 +354,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Version: ">=0.0.1", InstallNamespace: ns, UpgradeConstraintPolicy: "SelfCertified", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1159,7 +363,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1173,10 +376,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -1222,19 +421,17 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh g.It("PolarionID:76843-[OTP][Skipped:Disconnected]support disc with icsp[Timeout:40m] [Disruptive][Slow]", g.Label("original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:76843-[Skipped:Disconnected]support disc with icsp[Timeout:30m] [Serial][Disruptive][Slow]"), func() { exutil.SkipForSNOCluster(oc) var ( - caseID = "76843" - ns = "ns-" + caseID - sa = "sa" + caseID - labelValue = caseID - catalogName = "clustercatalog-" + caseID - ceName = "ce-" + caseID - iscpName = "icsp-" + caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - icspTemplate = filepath.Join(baseDir, "icsp-single-mirror.yaml") - icsp = olmv1util.IcspDescription{ + caseID = "76843" + ns = "ns-" + caseID + labelValue = caseID + catalogName = "clustercatalog-" + caseID + ceName = "ce-" + caseID + iscpName = "icsp-" + caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + icspTemplate = filepath.Join(baseDir, "icsp-single-mirror.yaml") + icsp = olmv1util.IcspDescription{ Name: iscpName, Mirror: "quay.io/olmqe", Source: "qe76843.myregistry.io/olmqe", @@ -1246,18 +443,12 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh LabelValue: labelValue, Template: clustercatalogTemplate, } - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } ce76843 = olmv1util.ClusterExtensionDescription{ Name: ceName, PackageName: "nginx-ok-v76843", Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1291,10 +482,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("check ce to be installed") defer ce76843.Delete(oc) ce76843.Create(oc) @@ -1305,19 +492,17 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh exutil.SkipOnProxyCluster(oc) exutil.SkipForSNOCluster(oc) var ( - caseID = "76844" - ns = "ns-" + caseID - sa = "sa" + caseID - labelValue = caseID - catalogName = "clustercatalog-" + caseID - ceName = "ce-" + caseID - itdmsName = "itdms-" + caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - itdmsTemplate = filepath.Join(baseDir, "itdms-full-mirror.yaml") - itdms = olmv1util.ItdmsDescription{ + caseID = "76844" + ns = "ns-" + caseID + labelValue = caseID + catalogName = "clustercatalog-" + caseID + ceName = "ce-" + caseID + itdmsName = "itdms-" + caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + itdmsTemplate = filepath.Join(baseDir, "itdms-full-mirror.yaml") + itdms = olmv1util.ItdmsDescription{ Name: itdmsName, MirrorSite: "quay.io", SourceSite: "qe76844.myregistry.io", @@ -1331,18 +516,12 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh LabelValue: labelValue, Template: clustercatalogTemplate, } - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } ce76844 = olmv1util.ClusterExtensionDescription{ Name: ceName, PackageName: "nginx-ok-v76844", Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1374,10 +553,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("check ce to be installed") defer ce76844.Delete(oc) ce76844.Create(oc) @@ -1392,20 +567,18 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh architecture.SkipNonAmd64SingleArch(oc) exutil.SkipForSNOCluster(oc) var ( - caseID = "78193" - ns = "ns-" + caseID - sa = "sa" + caseID - labelValue = caseID - catalogName = "clustercatalog-" + caseID - catalog1Name = "clustercatalog-" + caseID + "1" - ceName = "ce-" + caseID - cipName = "cip-" + caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - cipTemplate = filepath.Join(baseDir, "cip.yaml") - cip = olmv1util.CipDescription{ + caseID = "78193" + ns = "ns-" + caseID + labelValue = caseID + catalogName = "clustercatalog-" + caseID + catalog1Name = "clustercatalog-" + caseID + "1" + ceName = "ce-" + caseID + cipName = "cip-" + caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + cipTemplate = filepath.Join(baseDir, "cip.yaml") + cip = olmv1util.CipDescription{ Name: cipName, Repo1: "quay.io/olmqe/nginx-ok-bundle-sigstore", Repo2: "quay.io/olmqe/nginx-ok-bundle-sigstore1", @@ -1425,18 +598,12 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh LabelValue: labelValue, Template: clustercatalogTemplate, } - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } ce = olmv1util.ClusterExtensionDescription{ Name: ceName, PackageName: "nginx-ok-v78193", Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1462,10 +629,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clusterextension with olmsigkey signed successfully") defer ce.Delete(oc) ce.Create(oc) @@ -1484,21 +647,19 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh } exutil.SkipForSNOCluster(oc) var ( - caseID = "781932" - ns = "ns-" + caseID - sa = "sa" + caseID - imageRef = "quay.io/olmqe/nginx-ok-index-sigstore:vokv" + caseID - packageName = "nginx-ok-v" + caseID - labelValue = caseID - catalogName = "clustercatalog-" + caseID - ceName = "ce-" + caseID - cipName = "cip-" + caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - cipTemplate = filepath.Join(baseDir, "cip.yaml") - cip = olmv1util.CipDescription{ + caseID = "781932" + ns = "ns-" + caseID + imageRef = "quay.io/olmqe/nginx-ok-index-sigstore:vokv" + caseID + packageName = "nginx-ok-v" + caseID + labelValue = caseID + catalogName = "clustercatalog-" + caseID + ceName = "ce-" + caseID + cipName = "cip-" + caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + cipTemplate = filepath.Join(baseDir, "cip.yaml") + cip = olmv1util.CipDescription{ Name: cipName, Repo1: "quay.io/olmqe/nginx-ok-bundle-sigstore", Repo2: "quay.io/olmqe/nginx-ok-bundle-sigstore1", @@ -1513,18 +674,12 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh LabelValue: labelValue, Template: clustercatalogTemplate, } - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } ce = olmv1util.ClusterExtensionDescription{ Name: ceName, PackageName: packageName, Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1550,10 +705,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clusterextension with olmsigkey signed successfully") defer ce.Delete(oc) ce.Create(oc) @@ -1564,34 +715,26 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh exutil.SkipForSNOCluster(oc) // This test validates installation from private container images and depends on cluster-wide pull secrets var ( - caseID = "76983" - ns = "ns-" + caseID - sa = "sa" + caseID - labelValue = caseID - catalogName = "clustercatalog-" + caseID - ceName = "ce-" + caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "76983" + ns = "ns-" + caseID + labelValue = caseID + catalogName = "clustercatalog-" + caseID + ceName = "ce-" + caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index-private:vokv76983", LabelValue: labelValue, Template: clustercatalogTemplate, } - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } ce = olmv1util.ClusterExtensionDescription{ Name: ceName, PackageName: "nginx-ok-v76983", Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1624,10 +767,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("check ce to be installed") defer ce.Delete(oc) ce.Create(oc) @@ -1742,26 +881,15 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh g.It("PolarionID:83026-[OTP][Skipped:Disconnected]clusterextension updates sometimes failed with the following error from the CRDUpgradeCheck resource unknown change and refusing to determine that change is safe", g.Label("original-name:[sig-olmv1][Jira:OLM] clusterextension PolarionID:83026-[Skipped:Disconnected]clusterextension updates sometimes failed with the following error from the CRDUpgradeCheck resource unknown change and refusing to determine that change is safe"), func() { baseDir := exutil.FixturePath("testdata", "olm") clusterextensionTemplate := filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saAdminTemplate := filepath.Join(baseDir, "sa-admin.yaml") g.By("1)install Argocd operator v0.4.0 in a random namespace") - sa := "argocd-83026" oc.SetupProject() - saCrb := olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: oc.Namespace(), - Template: saAdminTemplate, - } - defer saCrb.Delete(oc) - saCrb.Create(oc) - ceArgocd := olmv1util.ClusterExtensionDescription{ Name: "extension-argocd-83026", PackageName: "argocd-operator", Channel: "alpha", Version: "v0.4.0", InstallNamespace: oc.Namespace(), - SaName: sa, LabelKey: "olm.operatorframework.io/metadata.name", LabelValue: "openshift-community-operators", Template: clusterextensionTemplate, @@ -1783,20 +911,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh g.It("PolarionID:69196-[OTP][Level0][Skipped:Disconnected]Supports Version Ranges during clusterextension upgrade", func() { var ( - caseID = "69196" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-69196" - sa = "sa69196" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "69196" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + ns = "ns-69196" + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-69196", LabelValue: labelValue, Imageref: "quay.io/olmqe/olmtest-operator-index:nginxolm69196", @@ -1808,7 +929,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh PackageName: "nginx69196", Channel: "candidate-v1.0", Version: "1.0.1", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -1822,10 +942,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -1890,15 +1006,8 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") clusterextensionWithoutChannelTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannel.yaml") clusterextensionWithoutChannelVersionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannelVersion.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") ns = "ns-68821" - sa = "sa68821" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-68821", LabelValue: labelValue, Imageref: "quay.io/olmqe/olmtest-operator-index:nginxolm68821", @@ -1911,7 +1020,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Version: ">=0.0.1", LabelValue: labelValue, InstallNamespace: ns, - SaName: sa, Template: clusterextensionTemplate, } ) @@ -1924,10 +1032,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -1971,20 +1075,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh g.It("PolarionID:74108-[OTP][Skipped:Disconnected][Slow]olm v1 supports legacy upgrade edges", func() { var ( - caseID = "74108" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutVersion.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-74108" - sa = "sa74108" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "74108" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutVersion.yaml") + ns = "ns-74108" + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-74108", Imageref: "quay.io/openshifttest/nginxolm-operator-index:nginxolm74108", LabelValue: labelValue, @@ -1996,7 +1093,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh PackageName: "nginx74108", Channel: "candidate-v0.0", LabelValue: labelValue, - SaName: sa, Template: clusterextensionTemplate, } ) @@ -2009,10 +1105,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("1) Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -2155,27 +1247,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh g.It("PolarionID:74923-[OTP][Skipped:Disconnected]no two ClusterExtensions can manage the same underlying object", func() { var ( - caseID = "74923" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannelVersion.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns1 = "ns-74923-1" - ns2 = "ns-74923-2" - sa1 = "sa74923-1" - sa2 = "sa74923-2" - saCrb1 = olmv1util.SaCLusterRolebindingDescription{ - Name: sa1, - Namespace: ns1, - Template: saClusterRoleBindingTemplate, - } - saCrb2 = olmv1util.SaCLusterRolebindingDescription{ - Name: sa2, - Namespace: ns2, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "74923" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannelVersion.yaml") + ns1 = "ns-74923-1" + ns2 = "ns-74923-2" + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-74923-1", Imageref: "quay.io/openshifttest/nginxolm-operator-index:nginxolm74923", LabelValue: labelValue, @@ -2185,7 +1264,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Name: "clusterextension-74923-1", PackageName: "nginx74923", InstallNamespace: ns1, - SaName: sa1, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -2193,7 +1271,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Name: "clusterextension-74923-2", PackageName: "nginx74923", InstallNamespace: ns2, - SaName: sa2, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -2212,10 +1289,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns1)).To(o.BeTrue()) - g.By("2.2 Create SA for clusterextension1") - defer saCrb1.Delete(oc) - saCrb1.Create(oc) - g.By("2.3 Create clusterextension1") defer clusterextension1.Delete(oc) clusterextension1.Create(oc) @@ -2230,10 +1303,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns2)).To(o.BeTrue()) - g.By("3.2 Create SA for clusterextension2") - defer saCrb2.Delete(oc) - saCrb2.Create(oc) - g.By("3.3 Create clusterextension2") defer clusterextension2.Delete(oc) _ = clusterextension2.CreateWithoutCheck(oc) @@ -2284,20 +1353,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh g.It("PolarionID:75501-[OTP][Skipped:Disconnected]the updates of various status fields is orthogonal", func() { var ( - caseID = "75501" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-75501" - sa = "sa75501" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "75501" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") + ns = "ns-75501" + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: "clustercatalog-75501", Imageref: "quay.io/openshifttest/nginxolm-operator-index:nginxolm75501", LabelValue: labelValue, @@ -2309,7 +1371,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh PackageName: "nginx75501", Channel: "candidate-v2.1", Version: "2.1.0", - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -2323,10 +1384,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -2414,14 +1471,7 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh clusterextensionExpressionsTemplate = filepath.Join(baseDir, "clusterextension-withselectorExpressions-WithoutChannelVersion.yaml") clusterextensionLableExpressionsTemplate = filepath.Join(baseDir, "clusterextension-withselectorLableExpressions-WithoutChannelVersion.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-76685" - sa = "sa76685" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } + ns = "ns-76685" clustercatalog1 = olmv1util.ClusterCatalogDescription{ LabelKey: "olmv1-test", LabelValue: "ocp-76685-1", @@ -2447,7 +1497,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Name: "clusterextension-76685", InstallNamespace: ns, PackageName: "nginx76685", - SaName: sa, Template: clusterextensionTemplate, } ) @@ -2460,9 +1509,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - defer saCrb.Delete(oc) - saCrb.Create(oc) - defer clustercatalog1.Delete(oc) clustercatalog1.Create(oc) defer clustercatalog2.Delete(oc) @@ -2541,20 +1587,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh g.It("PolarionID:77972-[OTP][Skipped:Disconnected]olm v1 Supports MaxOCPVersion in properties file", func() { var ( - caseID = "77972" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-77972" - sa = "sa77972" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "77972" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannel.yaml") + ns = "ns-77972" + clustercatalog = olmv1util.ClusterCatalogDescription{ LabelKey: "olmv1-test", LabelValue: labelValue, Name: "clustercatalog-77972", @@ -2566,7 +1605,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Name: "clusterextension-77972", InstallNamespace: ns, PackageName: "nginx77972", - SaName: sa, Version: "0.0.1", LabelValue: labelValue, Template: clusterextensionTemplate, @@ -2581,9 +1619,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - defer saCrb.Delete(oc) - saCrb.Create(oc) - defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -2651,20 +1686,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh g.It("PolarionID:82249-[OTP][Skipped:Disconnected]Verify olmv1 support for float type maxOCPVersion in properties file", func() { var ( - caseID = "82249" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-82249" - sa = "sa82249" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "82249" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannel.yaml") + ns = "ns-82249" + clustercatalog = olmv1util.ClusterCatalogDescription{ LabelKey: "olmv1-test", Name: "clustercatalog-82249", LabelValue: labelValue, @@ -2676,7 +1704,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Name: "clusterextension-82249", InstallNamespace: ns, PackageName: "nginx82249", - SaName: sa, Version: "0.0.1", LabelValue: labelValue, Template: clusterextensionTemplate, @@ -2691,9 +1718,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - defer saCrb.Delete(oc) - saCrb.Create(oc) - defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -2774,15 +1798,8 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh clusterextensionOwnSingleTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-withoutChannel-OwnSingle.yaml") clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-80117" - nsWatch = "ns-80117-watch" - sa = "sa80117" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } + ns = "ns-80117" + nsWatch = "ns-80117-watch" clustercatalog = olmv1util.ClusterCatalogDescription{ LabelKey: "olmv1-test", LabelValue: labelValue, @@ -2795,7 +1812,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Name: "clusterextension-80117", InstallNamespace: ns, PackageName: "nginx80117", - SaName: sa, Version: "1.0.1", WatchNamespace: nsWatch, LabelValue: labelValue, @@ -2805,7 +1821,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Name: "clusterextension-80117", InstallNamespace: ns, PackageName: "nginx80117", - SaName: sa, Version: "1.1.0", LabelValue: labelValue, Template: clusterextensionTemplate, @@ -2820,9 +1835,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - defer saCrb.Delete(oc) - saCrb.Create(oc) - defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -2917,12 +1929,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh g.By("8) check not support install two same clusterextensions") ns2 := ns + "-2" nsWatch2 := nsWatch + "-2" - sa2 := "sa80117-2" - saCrb2 := olmv1util.SaCLusterRolebindingDescription{ - Name: sa2, - Namespace: ns2, - Template: saClusterRoleBindingTemplate, - } defer func() { _ = oc.WithoutNamespace().AsAdmin().Run("delete").Args("ns", ns2, "--ignore-not-found").Execute() @@ -2937,13 +1943,10 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", nsWatch2)).To(o.BeTrue()) - defer saCrb2.Delete(oc) - saCrb2.Create(oc) clusterextension2 := olmv1util.ClusterExtensionDescription{ Name: "clusterextension-80117-2", InstallNamespace: ns2, PackageName: "nginx80117", - SaName: sa2, Version: "2.0.0", WatchNamespace: nsWatch2, LabelKey: "olmv1-test", @@ -2979,14 +1982,7 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh clusterextensionOwnSingleTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-withoutChannel-OwnSingle.yaml") clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-80120" - sa = "sa80120" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } + ns = "ns-80120" clustercatalog = olmv1util.ClusterCatalogDescription{ LabelKey: "olmv1-test", LabelValue: labelValue, @@ -2999,7 +1995,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Name: "clusterextension-80120", InstallNamespace: ns, PackageName: "nginx80120", - SaName: sa, Version: "1.0.1", LabelKey: "olmv1-test", LabelValue: labelValue, @@ -3010,7 +2005,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Name: "clusterextension-80120", InstallNamespace: ns, PackageName: "nginx80120", - SaName: sa, Version: "3.0.0", LabelKey: "olmv1-test", LabelValue: labelValue, @@ -3026,9 +2020,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - defer saCrb.Delete(oc) - saCrb.Create(oc) - defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -3098,7 +2089,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Name: "clusterextension-80120", InstallNamespace: ns, PackageName: "nginx80120", - SaName: sa, Version: "1.0.1", WatchNamespace: ns + "flake", LabelKey: "olmv1-test", @@ -3122,20 +2112,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh g.It("PolarionID:82136-[OTP][Skipped:Disconnected]olm v1 supports NetworkPolicy resources", func() { var ( - caseID = "82136" - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - ns = "ns-82136" - sa = "sa82136" - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "82136" + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-WithoutChannel.yaml") + ns = "ns-82136" + clustercatalog = olmv1util.ClusterCatalogDescription{ LabelKey: "olmv1-test", LabelValue: labelValue, Name: "clustercatalog-82136", @@ -3147,7 +2130,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh InstallNamespace: ns, PackageName: "nginx82136", Version: "1.0.1", - SaName: sa, LabelKey: "olmv1-test", LabelValue: labelValue, Template: clusterextensionTemplate, @@ -3162,10 +2144,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("1) Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -3248,7 +2226,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh var ( caseID = "83979" ns = "ns-" + caseID - saName = "sa-" + caseID catalogName = "clustercatalog-" + caseID ceName = "ce-" + caseID validatingName = "validating-webhook-test-" + caseID @@ -3258,7 +2235,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh baseDir = exutil.FixturePath("testdata", "olm") clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog.yaml") clusterextensionTemplate = filepath.Join(baseDir, "clusterextension.yaml") - saTemplate = filepath.Join(baseDir, "sa-admin.yaml") webhookTemplate = filepath.Join(baseDir, "cr-webhookTest.yaml") clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, @@ -3271,14 +2247,8 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh Channel: "alpha", Version: "0.0.1", InstallNamespace: ns, - SaName: saName, Template: clusterextensionTemplate, } - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: saName, - Namespace: ns, - Template: saTemplate, - } ) g.By("Create namespace") @@ -3289,10 +2259,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension", g.Label("NonHyperSh o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) - g.By("Create service account with admin permissions") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) diff --git a/openshift/tests-extension/test/qe/specs/olmv1_ce_deploymentconfig.go b/openshift/tests-extension/test/qe/specs/olmv1_ce_deploymentconfig.go index 2f64fe03ba..f9834788e6 100644 --- a/openshift/tests-extension/test/qe/specs/olmv1_ce_deploymentconfig.go +++ b/openshift/tests-extension/test/qe/specs/olmv1_ce_deploymentconfig.go @@ -35,16 +35,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87536-deploymentConfig env vars are applied to operator deployment and available in pod", func() { olmv1util.ValidateAccessEnvironment(oc) var ( - caseID = "87536" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87536" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Define inline config as JSON string (for ${{}} template parsing) inlineConfig = `{ @@ -64,11 +62,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi "ANOTHER_VAR": "another-value", } - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87536", @@ -81,7 +74,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -98,11 +90,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -149,16 +136,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87537-deploymentConfig env vars override existing bundle env vars with same name", func() { olmv1util.ValidateAccessEnvironment(oc) var ( - caseID = "87537" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87537" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Define inline config as JSON string (for ${{}} template parsing) // ENV1: will override bundle's ENV1=bundle_value1 @@ -183,11 +168,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi "ENV3": "config_value3", // Test Point 3: Add new env var } - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87537", @@ -200,7 +180,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -217,11 +196,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -267,20 +241,18 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87539-[Skipped:Disconnected]deploymentConfig envFrom sources are appended to operator deployment without duplicates", func() { var ( - caseID = "87539" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - cmBundle1 = "test-cm-bundle-1" // Predefined in bundle CSV - cmBundle2 = "test-cm-bundle-2" // Predefined in bundle CSV - cmConfigNew = "test-cm-config-new" // New CM from config - secretConfig = "test-secret-config" // New Secret from config - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87539" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + cmBundle1 = "test-cm-bundle-1" // Predefined in bundle CSV + cmBundle2 = "test-cm-bundle-2" // Predefined in bundle CSV + cmConfigNew = "test-cm-config-new" // New CM from config + secretConfig = "test-secret-config" // New Secret from config + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Define inline config as JSON string (for ${{}} template parsing) // test-cm-bundle-1: Duplicate with bundle - should NOT be added again (deduplication) @@ -296,11 +268,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi } }` - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87539", @@ -313,7 +280,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -367,11 +333,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(err).NotTo(o.HaveOccurred()) e2e.Logf("Created Secret: %s", secretConfig) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -453,18 +414,16 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87541-[Skipped:Disconnected]deploymentConfig volumes are appended to operator deployment", func() { var ( - caseID = "87541" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - cmVolume = "test-cm-vol" // ConfigMap for volume - secretVolume = "test-secret-vol" // Secret for volume - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87541" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + cmVolume = "test-cm-vol" // ConfigMap for volume + secretVolume = "test-secret-vol" // Secret for volume + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Define inline config as JSON string (for ${{}} template parsing) // Volume 1: Same name as bundle (bundle-emptydir-vol) but different type (ConfigMap vs emptyDir) @@ -489,11 +448,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi } }` - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87541", @@ -506,7 +460,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -545,11 +498,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(err).NotTo(o.HaveOccurred()) e2e.Logf("Created Secret: %s", secretVolume) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -653,18 +601,16 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87542-[Skipped:Disconnected]deploymentConfig volumeMounts are appended to all operator containers", func() { var ( - caseID = "87542" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - cmVolume = "test-cm-vol" // ConfigMap for volume - secretVolume = "test-secret-vol" // Secret for volume - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87542" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + cmVolume = "test-cm-vol" // ConfigMap for volume + secretVolume = "test-secret-vol" // Secret for volume + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Define inline config as JSON string (for ${{}} template parsing) // Volume 1: Same name as bundle (bundle-emptydir-vol) - matches volumeMount 1 @@ -701,11 +647,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi } }` - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87542", @@ -718,7 +659,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -757,11 +697,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(err).NotTo(o.HaveOccurred()) e2e.Logf("Created Secret: %s", secretVolume) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -874,16 +809,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87543-[Skipped:Disconnected]deploymentConfig tolerations are appended to operator deployment without duplicates", func() { var ( - caseID = "87543" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87543" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Define inline config as JSON string (for ${{}} template parsing) // bundle-key: Duplicate with bundle - should NOT be added again (deduplication) @@ -914,11 +847,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi } }` - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87543", @@ -931,7 +859,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -948,11 +875,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -1018,16 +940,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87544-[Skipped:Disconnected]deploymentConfig resources completely replace existing resource requirements", func() { var ( - caseID = "87544" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87544" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Define inline config as JSON string (for ${{}} template parsing) // Config resources COMPLETELY REPLACE bundle resources (no merge) @@ -1049,11 +969,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi } }` - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87544", @@ -1066,7 +981,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -1083,11 +997,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -1182,16 +1091,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87545-[Skipped:Disconnected]deploymentConfig nodeSelector completely replaces existing node selector", func() { var ( - caseID = "87545" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87545" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Define inline config as JSON string (for ${{}} template parsing) // Config nodeSelector COMPLETELY REPLACES bundle nodeSelector (no merge, no partial override) @@ -1207,11 +1114,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi } }` - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87545", @@ -1224,7 +1126,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -1241,11 +1142,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -1333,16 +1229,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87546-[Skipped:Disconnected]deploymentConfig nodeAffinity overrides existing nodeAffinity", func() { var ( - caseID = "87546" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87546" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Define inline config as JSON string (for ${{}} template parsing) // This test has TWO phases: @@ -1377,11 +1271,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi } }` - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87546", @@ -1394,7 +1283,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -1411,11 +1299,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -1611,16 +1494,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87547-[Skipped:Disconnected]deploymentConfig podAffinity overrides existing podAffinity", func() { var ( - caseID = "87547" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87547" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Define inline config as JSON string (for ${{}} template parsing) // CRITICAL: Only specify podAffinity, NOT nodeAffinity or podAntiAffinity @@ -1655,11 +1536,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi } }` - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87546", // Reuse same bundle as 87546 @@ -1672,7 +1548,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -1689,11 +1564,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -1800,16 +1670,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87548-[Skipped:Disconnected]deploymentConfig podAntiAffinity overrides existing podAntiAffinity", func() { var ( - caseID = "87548" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87548" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Define inline config as JSON string (for ${{}} template parsing) // CRITICAL: This tests TWO behaviors: @@ -1847,11 +1715,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi } }` - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87548", @@ -1864,7 +1727,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -1881,11 +1743,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -2015,16 +1872,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87549-[Skipped:Disconnected]deploymentConfig annotations are merged with existing taking precedence", func() { var ( - caseID = "87549" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87549" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Define inline config as JSON string (for ${{}} template parsing) // NOTE: Due to CSV API limitation, deployment-level and pod-level behave differently: @@ -2046,11 +1901,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi } }` - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87549", @@ -2063,7 +1913,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -2080,11 +1929,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -2195,16 +2039,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87550-[Skipped:Disconnected]deploymentConfig with resources and nodeSelector both work correctly", func() { var ( - caseID = "87550" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87550" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Configure resources and nodeSelector together // Test Point 1: Resources applied to all containers in Deployment @@ -2229,11 +2071,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi } }` - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87550", @@ -2246,7 +2083,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -2263,11 +2099,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -2387,16 +2218,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87551-[Skipped:Disconnected]deploymentConfig with env tolerations and resources all work correctly", func() { var ( - caseID = "87551" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87551" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Configure env, tolerations, and resources together // Test Point 1: Env vars applied to containers and accessible in pod @@ -2441,11 +2270,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi "TEST_ENV2": "value2", } - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87551", @@ -2458,7 +2282,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -2475,11 +2298,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -2606,16 +2424,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87552-[Skipped:Disconnected]deploymentConfig works correctly when combined with watchNamespace configuration", func() { var ( - caseID = "87552" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87552" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Configure watchNamespace (SingleNamespace mode) and deploymentConfig together // Test Point 1: WatchNamespace configuration verified (operator scoped to specific namespace) @@ -2646,11 +2462,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi "TEST_ENV_WATCH": "watchvalue", } - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87552", @@ -2663,7 +2474,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: inlineConfig, @@ -2691,11 +2501,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", watchNs)).To(o.BeTrue()) e2e.Logf("Created watch namespace: %s (for config test only)", watchNs) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -2811,16 +2616,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87553-[Skipped:Disconnected]adding deploymentConfig multiple fields to existing ClusterExtension works correctly", func() { var ( - caseID = "87553" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87553" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") // Configuration to add (env + resources) // Test Point 1: Adding config triggers reconcile @@ -2850,11 +2653,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi "ADDED_ENV": "added_value", } - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87553", @@ -2867,7 +2665,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, // NO InlineConfig initially - will be added later @@ -2884,11 +2681,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -3072,16 +2864,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87554-[Skipped:Disconnected]modifying deploymentConfig multiple fields in existing ClusterExtension works correctly", func() { var ( - caseID = "87554" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87554" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Initial configuration (env + resources) initialConfig = `{ @@ -3129,11 +2919,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi "MODIFIED_ENV": "modified_value", } - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87554", @@ -3146,7 +2931,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: initialConfig, @@ -3163,11 +2947,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -3351,16 +3130,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87555-[Skipped:Disconnected]removing entire deploymentConfig from ClusterExtension reverts all settings to bundle defaults", func() { var ( - caseID = "87555" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87555" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Initial configuration with multiple fields // This tests comprehensive removal of all custom configurations @@ -3416,11 +3193,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi ) var ( - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87555", @@ -3433,7 +3205,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: initialConfig, @@ -3450,11 +3221,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -3689,16 +3455,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi g.It("PolarionID:87556-[Skipped:Disconnected]removing partial fields from deploymentConfig reverts those fields to bundle defaults while keeping others", func() { var ( - caseID = "87556" - ns = "test-ns-" + caseID - sa = "test-sa-" + caseID - catalogName = "test-catalog-" + caseID - extName = "test-ext-" + caseID - labelValue = caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "87556" + ns = "test-ns-" + caseID + catalogName = "test-catalog-" + caseID + extName = "test-ext-" + caseID + labelValue = caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel-inlineconfig.yaml") // Initial configuration with multiple fields (env + resources + tolerations) // We'll later remove resources and tolerations while keeping env @@ -3732,11 +3496,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi ) var ( - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv87556", @@ -3749,7 +3508,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, InlineConfig: initialConfig, @@ -3766,11 +3524,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLMv1 ClusterExtension DeploymentConfi o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", ns)).To(o.BeTrue()) e2e.Logf("Created namespace: %s", ns) - g.By("Create ServiceAccount and RBAC for ClusterExtension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("Created ServiceAccount and RBAC: %s", sa) - g.By("Create ClusterCatalog with test operator") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) diff --git a/openshift/tests-extension/test/qe/specs/olmv1_ce_watchns.go b/openshift/tests-extension/test/qe/specs/olmv1_ce_watchns.go index 840e32586a..54a67571cb 100644 --- a/openshift/tests-extension/test/qe/specs/olmv1_ce_watchns.go +++ b/openshift/tests-extension/test/qe/specs/olmv1_ce_watchns.go @@ -31,20 +31,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config caseID = "85510" ns = "ns-" + caseID nsTarget = "ns-" + caseID + "-target" - sa = "sa" + caseID labelValue = caseID catalogName = "clustercatalog-" + caseID baseDir = exutil.FixturePath("testdata", "olm") clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") clusterextensionConfigTemplate = filepath.Join(baseDir, "clusterextension-watchns-config.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv85510", LabelValue: labelValue, @@ -68,16 +61,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", nsTarget)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - e2e.Logf("=== ServiceAccount resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ServiceAccount", sa, "-n", ns, "-o", "yaml").Execute() - e2e.Logf("=== ClusterRole resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ClusterRole", sa+"-installer-admin-clusterrole", "-o", "yaml").Execute() - e2e.Logf("=== ClusterRoleBinding resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ClusterRoleBinding", sa+"-installer-admin-clusterrole-binding", "-o", "yaml").Execute() - g.By("Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -92,7 +75,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -111,7 +93,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: "", Template: clusterextensionConfigTemplate, @@ -131,7 +112,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: ns, Template: clusterextensionConfigTemplate, @@ -151,7 +131,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: nsTarget, Template: clusterextensionConfigTemplate, @@ -173,20 +152,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config caseID = "85543" ns = "ns-" + caseID nsTarget = "ns-" + caseID + "-target" - sa = "sa" + caseID labelValue = caseID catalogName = "clustercatalog-" + caseID baseDir = exutil.FixturePath("testdata", "olm") clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") clusterextensionConfigTemplate = filepath.Join(baseDir, "clusterextension-watchns-config.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv85543", LabelValue: labelValue, @@ -210,17 +182,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", nsTarget)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - // Print full RBAC resources for manual test documentation - e2e.Logf("=== ServiceAccount resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ServiceAccount", sa, "-n", ns, "-o", "yaml").Execute() - e2e.Logf("=== ClusterRole resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ClusterRole", sa+"-installer-admin-clusterrole", "-o", "yaml").Execute() - e2e.Logf("=== ClusterRoleBinding resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ClusterRoleBinding", sa+"-installer-admin-clusterrole-binding", "-o", "yaml").Execute() - g.By("Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -236,7 +197,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -258,7 +218,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: "", Template: clusterextensionConfigTemplate, @@ -282,7 +241,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: ns, Template: clusterextensionConfigTemplate, @@ -304,7 +262,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: nsTarget, Template: clusterextensionConfigTemplate, @@ -327,20 +284,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config caseID = "85546" ns = "ns-" + caseID nsTarget = "ns-" + caseID + "-target" - sa = "sa" + caseID labelValue = caseID catalogName = "clustercatalog-" + caseID baseDir = exutil.FixturePath("testdata", "olm") clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") clusterextensionConfigTemplate = filepath.Join(baseDir, "clusterextension-watchns-config.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv85546", LabelValue: labelValue, @@ -364,17 +314,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", nsTarget)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - // Print full RBAC resources for manual test documentation - e2e.Logf("=== ServiceAccount resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ServiceAccount", sa, "-n", ns, "-o", "yaml").Execute() - e2e.Logf("=== ClusterRole resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ClusterRole", sa+"-installer-admin-clusterrole", "-o", "yaml").Execute() - e2e.Logf("=== ClusterRoleBinding resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ClusterRoleBinding", sa+"-installer-admin-clusterrole-binding", "-o", "yaml").Execute() - g.By("Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -392,7 +331,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -416,7 +354,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: "", Template: clusterextensionConfigTemplate, @@ -440,7 +377,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: ns, Template: clusterextensionConfigTemplate, @@ -462,7 +398,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: nsTarget, Template: clusterextensionConfigTemplate, @@ -485,20 +420,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config caseID = "85547" ns = "ns-" + caseID nsTarget = "ns-" + caseID + "-target" - sa = "sa" + caseID labelValue = caseID catalogName = "clustercatalog-" + caseID baseDir = exutil.FixturePath("testdata", "olm") clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") clusterextensionConfigTemplate = filepath.Join(baseDir, "clusterextension-watchns-config.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv85547", LabelValue: labelValue, @@ -524,17 +452,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", nsTarget)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - // Print full RBAC resources for manual test documentation - e2e.Logf("=== ServiceAccount resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ServiceAccount", sa, "-n", ns, "-o", "yaml").Execute() - e2e.Logf("=== ClusterRole resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ClusterRole", sa+"-installer-admin-clusterrole", "-o", "yaml").Execute() - e2e.Logf("=== ClusterRoleBinding resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ClusterRoleBinding", sa+"-installer-admin-clusterrole-binding", "-o", "yaml").Execute() - g.By("Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -555,7 +472,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -577,7 +493,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: "", Template: clusterextensionConfigTemplate, @@ -603,7 +518,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: ns, Template: clusterextensionConfigTemplate, @@ -626,7 +540,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: nsTarget, Template: clusterextensionConfigTemplate, @@ -649,20 +562,13 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config caseID = "85549" ns = "ns-" + caseID nsTarget = "ns-" + caseID + "-target" - sa = "sa" + caseID labelValue = caseID catalogName = "clustercatalog-" + caseID baseDir = exutil.FixturePath("testdata", "olm") clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") clusterextensionTemplate = filepath.Join(baseDir, "clusterextension-withselectorlabel.yaml") clusterextensionConfigTemplate = filepath.Join(baseDir, "clusterextension-watchns-config.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv85549", LabelValue: labelValue, @@ -688,17 +594,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", nsTarget)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - // Print full RBAC resources for manual test documentation - e2e.Logf("=== ServiceAccount resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ServiceAccount", sa, "-n", ns, "-o", "yaml").Execute() - e2e.Logf("=== ClusterRole resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ClusterRole", sa+"-installer-admin-clusterrole", "-o", "yaml").Execute() - e2e.Logf("=== ClusterRoleBinding resource ===") - _ = oc.AsAdmin().WithoutNamespace().Run("get").Args("ClusterRoleBinding", sa+"-installer-admin-clusterrole-binding", "-o", "yaml").Execute() - g.By("Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -719,7 +614,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, Template: clusterextensionTemplate, } @@ -744,7 +638,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: "", Template: clusterextensionConfigTemplate, @@ -769,7 +662,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: ns, Template: clusterextensionConfigTemplate, @@ -794,7 +686,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: sa, LabelValue: labelValue, WatchNamespace: nsTarget, Template: clusterextensionConfigTemplate, @@ -816,21 +707,14 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config g.It("PolarionID:85650-[Skipped:Disconnected]API-level error validation for watchNamespace configuration", func() { var ( - caseID = "85650" - ns = "ns-" + caseID - nsTarget = "ns-" + caseID + "-target" - sa = "sa" + caseID - labelValue = caseID - catalogName = "clustercatalog-" + caseID - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") - saCrb = olmv1util.SaCLusterRolebindingDescription{ - Name: sa, - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } - clustercatalog = olmv1util.ClusterCatalogDescription{ + caseID = "85650" + ns = "ns-" + caseID + nsTarget = "ns-" + caseID + "-target" + labelValue = caseID + catalogName = "clustercatalog-" + caseID + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog-withlabel.yaml") + clustercatalog = olmv1util.ClusterCatalogDescription{ Name: catalogName, Imageref: "quay.io/olmqe/nginx-ok-index:vokv85650", LabelValue: labelValue, @@ -854,10 +738,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] clusterextension watchNamespace config o.Expect(err).NotTo(o.HaveOccurred()) o.Expect(olmv1util.Appearance(oc, exutil.Appear, "ns", nsTarget)).To(o.BeTrue()) - g.By("Create SA for clusterextension") - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By("Create clustercatalog") defer clustercatalog.Delete(oc) clustercatalog.Create(oc) @@ -875,8 +755,6 @@ spec: channel: alpha version: ">=0.0.1" installNamespace: ` + ns + ` - serviceAccount: - name: ` + sa + ` selector: matchLabels: test: ` + labelValue + ` @@ -900,8 +778,6 @@ spec: channel: alpha version: ">=0.0.1" installNamespace: ` + ns + ` - serviceAccount: - name: ` + sa + ` selector: matchLabels: test: ` + labelValue + ` @@ -926,8 +802,6 @@ spec: channel: alpha version: ">=0.0.1" installNamespace: ` + ns + ` - serviceAccount: - name: ` + sa + ` selector: matchLabels: test: ` + labelValue + ` @@ -952,8 +826,6 @@ spec: channel: alpha version: ">=0.0.1" installNamespace: ` + ns + ` - serviceAccount: - name: ` + sa + ` selector: matchLabels: test: ` + labelValue + ` diff --git a/openshift/tests-extension/test/qe/specs/olmv1_stress.go b/openshift/tests-extension/test/qe/specs/olmv1_stress.go index ae6baf7df4..0c008d2403 100644 --- a/openshift/tests-extension/test/qe/specs/olmv1_stress.go +++ b/openshift/tests-extension/test/qe/specs/olmv1_stress.go @@ -28,21 +28,19 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLM v1 for stress", func() { // author: kuiwang@redhat.com g.It("PolarionID:81509-[OTP][Skipped:Disconnected][OlmStress]olmv1 create mass operator to see if they all are installed successfully [Slow][Timeout:330m]", g.Label("StressTest"), g.Label("NonHyperShiftHOST"), func() { var ( - caseID = "81509" - prefixCatalog = "catalog-" + caseID - prefixSa = "sa-" + caseID - prefixCe = "ce-" + caseID - prefixNs = "ns-" + caseID - prefixPackage = "stress-olmv1-c" - prefixImage = "quay.io/olmqe/stress-index:vokv" - nsOc = "openshift-operator-controller" - nsCatalog = "openshift-catalogd" - catalogLabel = "control-plane=catalogd-controller-manager" - ocLabel = "control-plane=operator-controller-controller-manager" - baseDir = exutil.FixturePath("testdata", "olm") - clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog.yaml") - clusterextensionTemplate = filepath.Join(baseDir, "clusterextension.yaml") - saClusterRoleBindingTemplate = filepath.Join(baseDir, "sa-admin.yaml") + caseID = "81509" + prefixCatalog = "catalog-" + caseID + prefixCe = "ce-" + caseID + prefixNs = "ns-" + caseID + prefixPackage = "stress-olmv1-c" + prefixImage = "quay.io/olmqe/stress-index:vokv" + nsOc = "openshift-operator-controller" + nsCatalog = "openshift-catalogd" + catalogLabel = "control-plane=catalogd-controller-manager" + ocLabel = "control-plane=operator-controller-controller-manager" + baseDir = exutil.FixturePath("testdata", "olm") + clustercatalogTemplate = filepath.Join(baseDir, "clustercatalog.yaml") + clusterextensionTemplate = filepath.Join(baseDir, "clusterextension.yaml") ) if !olmv1util.IsPodReady(oc, nsCatalog, catalogLabel) { @@ -67,18 +65,12 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLM v1 for stress", func() { Imageref: fmt.Sprintf("%s%d", prefixImage, i), Template: clustercatalogTemplate, } - saCrb := olmv1util.SaCLusterRolebindingDescription{ - Name: fmt.Sprintf("%s-%d", prefixSa, i), - Namespace: ns, - Template: saClusterRoleBindingTemplate, - } ce := olmv1util.ClusterExtensionDescription{ Name: fmt.Sprintf("%s-%d", prefixCe, i), PackageName: fmt.Sprintf("%s%d", prefixPackage, i), Channel: "alpha", Version: ">=0.0.1", InstallNamespace: ns, - SaName: fmt.Sprintf("%s-%d", prefixSa, i), Template: clusterextensionTemplate, } g.By(fmt.Sprintf("Create namespace for %d", i)) @@ -97,10 +89,6 @@ var _ = g.Describe("[sig-olmv1][Jira:OLM] OLM v1 for stress", func() { o.Expect(err).NotTo(o.HaveOccurred()) clustercatalog.WaitCatalogStatus(oc, "true", "Serving", 0) - g.By(fmt.Sprintf("Create SA for clusterextension for %d", i)) - defer saCrb.Delete(oc) - saCrb.Create(oc) - g.By(fmt.Sprintf("check ce to be installed for %d", i)) e2e.Logf("=========Create clusterextension %v=========", ce.Name) defer ce.Delete(oc) diff --git a/openshift/tests-extension/test/qe/testdata/olm/binding-prefligth.yaml b/openshift/tests-extension/test/qe/testdata/olm/binding-prefligth.yaml deleted file mode 100644 index e819eeb1e2..0000000000 --- a/openshift/tests-extension/test/qe/testdata/olm/binding-prefligth.yaml +++ /dev/null @@ -1,36 +0,0 @@ -apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-binding-preflight-template -objects: - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${CLUSTERROLESANAME}-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${CLUSTERROLESANAME}" - subjects: - - kind: ServiceAccount - name: "${SANAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${ROLENAME}-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${ROLENAME}" - namespace: "${NAMESPACE}" - subjects: - - kind: ServiceAccount - name: "${SANAME}" - namespace: "${NAMESPACE}" -parameters: - - name: SANAME - - name: ROLENAME - - name: CLUSTERROLESANAME - - name: NAMESPACE diff --git a/openshift/tests-extension/test/qe/testdata/olm/binding-prefligth_multirole.yaml b/openshift/tests-extension/test/qe/testdata/olm/binding-prefligth_multirole.yaml deleted file mode 100644 index 92b72baf12..0000000000 --- a/openshift/tests-extension/test/qe/testdata/olm/binding-prefligth_multirole.yaml +++ /dev/null @@ -1,52 +0,0 @@ -apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-binding-preflight-template -objects: - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${CLUSTERROLESANAME}-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${CLUSTERROLESANAME}" - subjects: - - kind: ServiceAccount - name: "${SANAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${ROLENAME}-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${ROLENAME}" - namespace: "${NAMESPACE}" - subjects: - - kind: ServiceAccount - name: "${SANAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${WATCHROLENAME}-binding" - namespace: "${WATCHNAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${WATCHROLENAME}" - namespace: "${WATCHNAMESPACE}" - subjects: - - kind: ServiceAccount - name: "${SANAME}" - namespace: "${NAMESPACE}" -parameters: - - name: SANAME - - name: ROLENAME - - name: CLUSTERROLESANAME - - name: NAMESPACE - - name: WATCHROLENAME - - name: WATCHNAMESPACE diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-watchns-config.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-watchns-config.yaml index 137a9c1660..0898f41bfe 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-watchns-config.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-watchns-config.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" config: configType: Inline inline: @@ -32,7 +30,6 @@ parameters: - name: PACKAGE - name: CHANNEL - name: VERSION -- name: SANAME - name: WATCHNS value: "" - name: POLICY diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorExpressions-WithoutChannelVersion.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorExpressions-WithoutChannelVersion.yaml index 8b004bc077..9cd539521e 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorExpressions-WithoutChannelVersion.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorExpressions-WithoutChannelVersion.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -26,7 +24,6 @@ parameters: - name: NAME - name: INSTALLNAMESPACE - name: PACKAGE -- name: SANAME - name: POLICY value: "CatalogProvided" - name: EXPRESSIONSVALUE1 diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorLableExpressions-WithoutChannelVersion.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorLableExpressions-WithoutChannelVersion.yaml index 6210f67695..cbd2eab125 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorLableExpressions-WithoutChannelVersion.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorLableExpressions-WithoutChannelVersion.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -30,7 +28,6 @@ parameters: - name: NAME - name: INSTALLNAMESPACE - name: PACKAGE -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-OwnSingle.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-OwnSingle.yaml index a786070f4a..1546581430 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-OwnSingle.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-OwnSingle.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" config: configType: Inline inline: @@ -33,7 +31,6 @@ parameters: - name: PACKAGE - name: CHANNEL - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-WithoutChannel.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-WithoutChannel.yaml index c19df321bf..6fc35c6faf 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-WithoutChannel.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-WithoutChannel.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -25,7 +23,6 @@ parameters: - name: INSTALLNAMESPACE - name: PACKAGE - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-WithoutChannelVersion.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-WithoutChannelVersion.yaml index a9acb1d80b..62c74d60e7 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-WithoutChannelVersion.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-WithoutChannelVersion.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -23,7 +21,6 @@ parameters: - name: NAME - name: INSTALLNAMESPACE - name: PACKAGE -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-WithoutVersion.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-WithoutVersion.yaml index fcccd8e72f..15d9bcbc36 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-WithoutVersion.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-WithoutVersion.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -26,7 +24,6 @@ parameters: - name: INSTALLNAMESPACE - name: PACKAGE - name: CHANNEL -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-inlineconfig.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-inlineconfig.yaml index 1fa335ee4f..57bcfc25e8 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-inlineconfig.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-inlineconfig.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" config: configType: Inline inline: @@ -32,7 +30,6 @@ parameters: - name: PACKAGE - name: CHANNEL - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-withoutChannel-OwnSingle.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-withoutChannel-OwnSingle.yaml index 7a7dec1ec6..48c3a9e1d2 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-withoutChannel-OwnSingle.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel-withoutChannel-OwnSingle.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" config: configType: Inline inline: @@ -30,7 +28,6 @@ parameters: - name: WATCHNS - name: PACKAGE - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: SOURCETYPE diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel.yaml index a3299e826d..0c465ac890 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextension-withselectorlabel.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -28,7 +26,6 @@ parameters: - name: PACKAGE - name: CHANNEL - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: LABELVALUE diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextension.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextension.yaml index 805b32a557..1e7758274e 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextension.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextension.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -25,7 +23,6 @@ parameters: - name: PACKAGE - name: CHANNEL - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: SOURCETYPE diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextensionWithoutChannel.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextensionWithoutChannel.yaml index 3966fc018a..47e496f53f 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextensionWithoutChannel.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextensionWithoutChannel.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -22,7 +20,6 @@ parameters: - name: INSTALLNAMESPACE - name: PACKAGE - name: VERSION -- name: SANAME - name: POLICY value: "CatalogProvided" - name: SOURCETYPE diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextensionWithoutChannelVersion.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextensionWithoutChannelVersion.yaml index aba55b9f00..01dc3b8a26 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextensionWithoutChannelVersion.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextensionWithoutChannelVersion.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -19,7 +17,6 @@ parameters: - name: NAME - name: INSTALLNAMESPACE - name: PACKAGE -- name: SANAME - name: SOURCETYPE value: "Catalog" diff --git a/openshift/tests-extension/test/qe/testdata/olm/clusterextensionWithoutVersion.yaml b/openshift/tests-extension/test/qe/testdata/olm/clusterextensionWithoutVersion.yaml index 0a8cd9e996..9b707b3a3c 100644 --- a/openshift/tests-extension/test/qe/testdata/olm/clusterextensionWithoutVersion.yaml +++ b/openshift/tests-extension/test/qe/testdata/olm/clusterextensionWithoutVersion.yaml @@ -9,8 +9,6 @@ objects: name: "${NAME}" spec: namespace: "${INSTALLNAMESPACE}" - serviceAccount: - name: "${SANAME}" source: sourceType: "${SOURCETYPE}" catalog: @@ -23,7 +21,6 @@ parameters: - name: INSTALLNAMESPACE - name: PACKAGE - name: CHANNEL -- name: SANAME - name: POLICY value: "CatalogProvided" - name: SOURCETYPE diff --git a/openshift/tests-extension/test/qe/testdata/olm/prefligth-clusterrole.yaml b/openshift/tests-extension/test/qe/testdata/olm/prefligth-clusterrole.yaml deleted file mode 100644 index df5d334e67..0000000000 --- a/openshift/tests-extension/test/qe/testdata/olm/prefligth-clusterrole.yaml +++ /dev/null @@ -1,12 +0,0 @@ -apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-preflight-clusterrole-template -objects: - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}" - rules: -parameters: - - name: NAME diff --git a/openshift/tests-extension/test/qe/testdata/olm/sa-admin.yaml b/openshift/tests-extension/test/qe/testdata/olm/sa-admin.yaml deleted file mode 100644 index ccc593a3ee..0000000000 --- a/openshift/tests-extension/test/qe/testdata/olm/sa-admin.yaml +++ /dev/null @@ -1,37 +0,0 @@ -apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-admin-template -objects: - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-admin-clusterrole" - rules: - - apiGroups: - - "*" - resources: - - "*" - verbs: - - "*" - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-admin-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-admin-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - diff --git a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-bundle-boxcutter.yaml b/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-bundle-boxcutter.yaml deleted file mode 100644 index 6fd8cf7bb0..0000000000 --- a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-bundle-boxcutter.yaml +++ /dev/null @@ -1,198 +0,0 @@ -apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-insufficient-bundle-boxcutter-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - # resourceNames: - # - nginx-ok-v3283-754-15pkpuong3owt1jn01uoyj8lm6p8jlxh03kuouq67dmv - # - nginx-ok-v3283-754-2r5zqsa9t9nk0tln1f8x36ws3ks9r8cgwi70s2dgnl82 - # - nginx-ok-v3283-75493-metrics-reader - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - # resourceNames: - # - nginx-ok-v3283-754-15pkpuong3owt1jn01uoyj8lm6p8jlxh03kuouq67dmv - # - nginx-ok-v3283-754-2r5zqsa9t9nk0tln1f8x36ws3ks9r8cgwi70s2dgnl82 - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - # resourceNames: [nginx-ok-v3283-75493-controller-manager] - # - apiGroups: [""] - # resources: [serviceaccounts] - # verbs: [create] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - # resourceNames: [nginx-ok-v3283-75493-controller-manager-metrics-service] - - apiGroups: [""] - resources: [services] - verbs: [create] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - # resourceNames: [nginx-ok-v3283-75493-controller-manager] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - "" - resources: - - secrets - - pods - - pods/exec - - pods/log - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS diff --git a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-bundle.yaml b/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-bundle.yaml deleted file mode 100644 index 656502f68f..0000000000 --- a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-bundle.yaml +++ /dev/null @@ -1,198 +0,0 @@ -apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-insufficient-bundle-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - # resourceNames: - # - nginx-ok-v3283-754-15pkpuong3owt1jn01uoyj8lm6p8jlxh03kuouq67dmv - # - nginx-ok-v3283-754-2r5zqsa9t9nk0tln1f8x36ws3ks9r8cgwi70s2dgnl82 - # - nginx-ok-v3283-75493-metrics-reader - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - # resourceNames: - # - nginx-ok-v3283-754-15pkpuong3owt1jn01uoyj8lm6p8jlxh03kuouq67dmv - # - nginx-ok-v3283-754-2r5zqsa9t9nk0tln1f8x36ws3ks9r8cgwi70s2dgnl82 - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - # resourceNames: [nginx-ok-v3283-75493-controller-manager] - # - apiGroups: [""] - # resources: [serviceaccounts] - # verbs: [create] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - # resourceNames: [nginx-ok-v3283-75493-controller-manager-metrics-service] - - apiGroups: [""] - resources: [services] - verbs: [create] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - # resourceNames: [nginx-ok-v3283-75493-controller-manager] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - "" - resources: - - secrets - - pods - - pods/exec - - pods/log - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS diff --git a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-operand-clusterrole-boxcutter.yaml b/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-operand-clusterrole-boxcutter.yaml deleted file mode 100644 index 84b673ae70..0000000000 --- a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-operand-clusterrole-boxcutter.yaml +++ /dev/null @@ -1,185 +0,0 @@ -apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-insufficient-operand-clusterrole-boxcutter-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [create, list, watch] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [get, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [create] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [create] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS diff --git a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-operand-clusterrole.yaml b/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-operand-clusterrole.yaml deleted file mode 100644 index 0f3bbdb2ed..0000000000 --- a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-operand-clusterrole.yaml +++ /dev/null @@ -1,185 +0,0 @@ -apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-insufficient-operand-clusterrole-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [create, list, watch] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [get, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [create] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [create] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS diff --git a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-operand-rbac-boxcutter.yaml b/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-operand-rbac-boxcutter.yaml deleted file mode 100644 index 1521d43480..0000000000 --- a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-operand-rbac-boxcutter.yaml +++ /dev/null @@ -1,188 +0,0 @@ -apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-insufficient-operand-rbac-boxcutter-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [olm.operatorframework.io] - resources: [clusterobjectsets/finalizers] - verbs: [update] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [create, list, watch] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [get, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [create] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [create] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS diff --git a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-operand-rbac.yaml b/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-operand-rbac.yaml deleted file mode 100644 index 05694c9270..0000000000 --- a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-insufficient-operand-rbac.yaml +++ /dev/null @@ -1,188 +0,0 @@ -apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-insufficient-operand-rbac-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [olm.operatorframework.io] - resources: [clusterextensions/finalizers] - verbs: [update] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [create, list, watch] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [get, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [create] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [create] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS diff --git a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-limited-boxcutter.yaml b/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-limited-boxcutter.yaml deleted file mode 100644 index 0d16d5382e..0000000000 --- a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-limited-boxcutter.yaml +++ /dev/null @@ -1,211 +0,0 @@ -apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-limited-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [olm.operatorframework.io] - resources: [clusterobjectsets/finalizers] - verbs: [update] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [create, list, watch] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [get, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts/finalizers] - verbs: [update] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts/finalizers] - verbs: [update] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - namespaces - verbs: - - get - - list - - watch - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - "" - resources: - - secrets - - pods - - pods/exec - - pods/log - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS diff --git a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-limited.yaml b/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-limited.yaml deleted file mode 100644 index a52367094f..0000000000 --- a/openshift/tests-extension/test/qe/testdata/olm/sa-nginx-limited.yaml +++ /dev/null @@ -1,205 +0,0 @@ -apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-nginx-limited-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-clusterrole" - rules: - - apiGroups: [olm.operatorframework.io] - resources: [clusterextensions/finalizers] - verbs: [update] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [create, list, watch] - - apiGroups: [apiextensions.k8s.io] - resources: [customresourcedefinitions] - verbs: [get, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterroles] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [create] - - apiGroups: [rbac.authorization.k8s.io] - resources: [clusterrolebindings] - verbs: [get, list, watch, update, patch, delete] - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: "${NAME}-installer-role" - namespace: "${NAMESPACE}" - rules: - - apiGroups: [""] - resources: [serviceaccounts] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [""] - resources: [services] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [get, list, watch, create, update, patch, delete] - - apiGroups: [apps] - resources: [deployments] - verbs: [create] - - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: "${NAME}-installer-role-binding" - namespace: "${NAMESPACE}" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: "${NAME}-installer-role" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: "${NAME}-installer-rbac-clusterrole" - rules: - - apiGroups: - - "" - resources: - - namespaces - verbs: - - get - - list - - watch - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - "" - resources: - - secrets - - pods - - pods/exec - - pods/log - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - apps - resources: - - deployments - - daemonsets - - replicasets - - statefulsets - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - cache.example.com - resources: - - "${KINDS}" - - "${KINDS}/status" - - "${KINDS}/finalizers" - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - authentication.k8s.io - resources: - - tokenreviews - verbs: - - create - - apiGroups: - - authorization.k8s.io - resources: - - subjectaccessreviews - verbs: - - create - - nonResourceURLs: - - /metrics - verbs: - - get - - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: "${NAME}-installer-rbac-clusterrole-binding" - roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "${NAME}-installer-rbac-clusterrole" - subjects: - - kind: ServiceAccount - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE - - name: KINDS diff --git a/openshift/tests-extension/test/qe/testdata/olm/sa.yaml b/openshift/tests-extension/test/qe/testdata/olm/sa.yaml deleted file mode 100644 index ba814c0cbd..0000000000 --- a/openshift/tests-extension/test/qe/testdata/olm/sa.yaml +++ /dev/null @@ -1,13 +0,0 @@ -apiVersion: template.openshift.io/v1 -kind: Template -metadata: - name: olmv1-sa-template -objects: - - apiVersion: v1 - kind: ServiceAccount - metadata: - name: "${NAME}" - namespace: "${NAMESPACE}" -parameters: - - name: NAME - - name: NAMESPACE diff --git a/openshift/tests-extension/test/qe/util/olmv1util/clusterextension.go b/openshift/tests-extension/test/qe/util/olmv1util/clusterextension.go index d010067af3..6570967229 100644 --- a/openshift/tests-extension/test/qe/util/olmv1util/clusterextension.go +++ b/openshift/tests-extension/test/qe/util/olmv1util/clusterextension.go @@ -20,7 +20,6 @@ type ClusterExtensionDescription struct { Version string InstallNamespace string WatchNamespace string - SaName string UpgradeConstraintPolicy string LabelKey string // default is olmv1-test LabelValue string // suggest to use case id @@ -82,9 +81,6 @@ func (clusterextension *ClusterExtensionDescription) CreateWithoutCheck(oc *exut if len(clusterextension.WatchNamespace) > 0 { parameters = append(parameters, "WATCHNS="+clusterextension.WatchNamespace) } - if len(clusterextension.SaName) > 0 { - parameters = append(parameters, "SANAME="+clusterextension.SaName) - } if len(clusterextension.UpgradeConstraintPolicy) > 0 { parameters = append(parameters, "POLICY="+clusterextension.UpgradeConstraintPolicy) } diff --git a/openshift/tests-extension/test/qe/util/olmv1util/sa-clusterrolebinding.go b/openshift/tests-extension/test/qe/util/olmv1util/sa-clusterrolebinding.go deleted file mode 100644 index 5cc0db827e..0000000000 --- a/openshift/tests-extension/test/qe/util/olmv1util/sa-clusterrolebinding.go +++ /dev/null @@ -1,152 +0,0 @@ -package olmv1util - -import ( - "fmt" - "strings" - - o "github.com/onsi/gomega" - e2e "k8s.io/kubernetes/test/e2e/framework" - - exutil "github.com/openshift/operator-framework-operator-controller/openshift/tests-extension/test/qe/util" -) - -type ChildResource struct { - Kind string - Ns string - Names []string -} - -type SaCLusterRolebindingDescription struct { - Name string - Namespace string - // if it take admin permission, no need to setup RBACObjects and take default value - RBACObjects []ChildResource - Kinds string - Template string -} - -// Create creates ServiceAccount, ClusterRole, and ClusterRoleBinding resources and waits for their appearance -// Parameters: -// - oc: CLI client for interacting with the OpenShift cluster -func (sacrb *SaCLusterRolebindingDescription) Create(oc *exutil.CLI) { - o.Expect(oc).NotTo(o.BeNil(), "CLI client cannot be nil") - o.Expect(sacrb.Name).NotTo(o.BeEmpty(), "ServiceAccount ClusterRoleBinding name cannot be empty") - e2e.Logf("=========Create sacrb %v=========", sacrb.Name) - err := sacrb.CreateWithoutCheck(oc) - o.Expect(err).NotTo(o.HaveOccurred()) - - if len(sacrb.RBACObjects) != 0 { - sacrb.validateCustomRBACObjects(oc) - } else { - sacrb.validateDefaultRBACObjects(oc) - } -} - -// CreateWithoutCheck creates RBAC resources from template without waiting for appearance verification -// Parameters: -// - oc: CLI client for interacting with the OpenShift cluster -// -// Returns: -// - error: error if template application fails, nil on success -func (sacrb *SaCLusterRolebindingDescription) CreateWithoutCheck(oc *exutil.CLI) error { - if oc == nil { - return fmt.Errorf("CLI client cannot be nil") - } - if sacrb.Template == "" { - return fmt.Errorf("template path cannot be empty") - } - e2e.Logf("=========CreateWithoutCheck sacrb %v=========", sacrb.Name) - parameters := []string{"-n", "default", "--ignore-unknown-parameters=true", "-f", sacrb.Template, "-p"} - if len(sacrb.Name) > 0 { - parameters = append(parameters, "NAME="+sacrb.Name) - } - if len(sacrb.Namespace) > 0 { - parameters = append(parameters, "NAMESPACE="+sacrb.Namespace) - } - if len(sacrb.Kinds) > 0 { - parameters = append(parameters, "KINDS="+sacrb.Kinds) - } - err := exutil.ApplyClusterResourceFromTemplateWithError(oc, parameters...) - return err -} - -// Delete removes ServiceAccount, ClusterRole, and ClusterRoleBinding resources -// Parameters: -// - oc: CLI client for interacting with the OpenShift cluster -func (sacrb *SaCLusterRolebindingDescription) Delete(oc *exutil.CLI) { - o.Expect(oc).NotTo(o.BeNil(), "CLI client cannot be nil") - e2e.Logf("=========Delete sacrb %v=========", sacrb.Name) - if len(sacrb.RBACObjects) != 0 { - sacrb.cleanupCustomRBACObjects(oc) - } else { - sacrb.cleanupDefaultRBACObjects(oc) - } -} - -// validateCustomRBACObjects validates custom RBAC objects appearance -func (sacrb *SaCLusterRolebindingDescription) validateCustomRBACObjects(oc *exutil.CLI) { - for _, object := range sacrb.RBACObjects { - if strings.TrimSpace(object.Kind) == "" { - e2e.Logf("Warning: empty Kind found in RBACObjects, skipping") - continue - } - sacrb.validateObjectNames(oc, object) - } -} - -// validateDefaultRBACObjects validates default RBAC objects appearance -func (sacrb *SaCLusterRolebindingDescription) validateDefaultRBACObjects(oc *exutil.CLI) { - o.Expect(Appearance(oc, exutil.Appear, "ServiceAccount", sacrb.Name, "-n", sacrb.Namespace)).To(o.BeTrue()) - o.Expect(Appearance(oc, exutil.Appear, "ClusterRole", fmt.Sprintf("%s-installer-admin-clusterrole", sacrb.Name))).To(o.BeTrue()) - o.Expect(Appearance(oc, exutil.Appear, "ClusterRoleBinding", fmt.Sprintf("%s-installer-admin-clusterrole-binding", sacrb.Name))).To(o.BeTrue()) -} - -// validateObjectNames validates each name in an RBAC object -func (sacrb *SaCLusterRolebindingDescription) validateObjectNames(oc *exutil.CLI, object ChildResource) { - for _, name := range object.Names { - if strings.TrimSpace(name) == "" { - e2e.Logf("Warning: empty name found in RBACObjects for kind %s, skipping", object.Kind) - continue - } - - if object.Ns == "" { - o.Expect(Appearance(oc, exutil.Appear, object.Kind, name)).To(o.BeTrue()) - } else { - o.Expect(Appearance(oc, exutil.Appear, object.Kind, name, "-n", object.Ns)).To(o.BeTrue()) - } - } -} - -// cleanupCustomRBACObjects cleans up custom RBAC objects -func (sacrb *SaCLusterRolebindingDescription) cleanupCustomRBACObjects(oc *exutil.CLI) { - for _, object := range sacrb.RBACObjects { - if strings.TrimSpace(object.Kind) == "" { - e2e.Logf("Warning: empty Kind found in RBACObjects, skipping cleanup") - continue - } - sacrb.cleanupObjectNames(oc, object) - } -} - -// cleanupDefaultRBACObjects cleans up default RBAC objects -func (sacrb *SaCLusterRolebindingDescription) cleanupDefaultRBACObjects(oc *exutil.CLI) { - Cleanup(oc, "ClusterRoleBinding", fmt.Sprintf("%s-installer-admin-clusterrole-binding", sacrb.Name)) - Cleanup(oc, "ClusterRole", fmt.Sprintf("%s-installer-admin-clusterrole", sacrb.Name)) - Cleanup(oc, "ServiceAccount", sacrb.Name, "-n", sacrb.Namespace) -} - -// cleanupObjectNames cleans up each name in an RBAC object -func (sacrb *SaCLusterRolebindingDescription) cleanupObjectNames(oc *exutil.CLI, object ChildResource) { - for _, name := range object.Names { - if strings.TrimSpace(name) == "" { - e2e.Logf("Warning: empty name found in RBACObjects for kind %s, skipping cleanup", object.Kind) - continue - } - - if object.Ns == "" { - Cleanup(oc, object.Kind, name) - } else { - Cleanup(oc, object.Kind, name, "-n", object.Ns) - } - } -} diff --git a/openshift/tests-extension/test/qe/util/stress/manifests/config/pkg-ins-v1/templates/ce.yml b/openshift/tests-extension/test/qe/util/stress/manifests/config/pkg-ins-v1/templates/ce.yml index ccd94ba702..ccfe1663e9 100644 --- a/openshift/tests-extension/test/qe/util/stress/manifests/config/pkg-ins-v1/templates/ce.yml +++ b/openshift/tests-extension/test/qe/util/stress/manifests/config/pkg-ins-v1/templates/ce.yml @@ -4,8 +4,6 @@ metadata: name: "ce-{{.Iteration}}" spec: namespace: "{{.prefixNamespace}}-{{.Iteration}}" - serviceAccount: - name: "ins-sa-{{.Iteration}}" source: sourceType: Catalog catalog: diff --git a/openshift/tests-extension/test/qe/util/stress/manifests/config/pkg-ins-v1/templates/clusterrole.yml b/openshift/tests-extension/test/qe/util/stress/manifests/config/pkg-ins-v1/templates/clusterrole.yml deleted file mode 100644 index bcf19157d3..0000000000 --- a/openshift/tests-extension/test/qe/util/stress/manifests/config/pkg-ins-v1/templates/clusterrole.yml +++ /dev/null @@ -1,11 +0,0 @@ -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole -metadata: - name: "ins-admin-clusterrole-{{.Iteration}}" -rules: - - apiGroups: - - "*" - resources: - - "*" - verbs: - - "*" diff --git a/openshift/tests-extension/test/qe/util/stress/manifests/config/pkg-ins-v1/templates/clusterrolebinding.yml b/openshift/tests-extension/test/qe/util/stress/manifests/config/pkg-ins-v1/templates/clusterrolebinding.yml deleted file mode 100644 index cc5b181fc9..0000000000 --- a/openshift/tests-extension/test/qe/util/stress/manifests/config/pkg-ins-v1/templates/clusterrolebinding.yml +++ /dev/null @@ -1,12 +0,0 @@ -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding -metadata: - name: "ins-admin-clusterrole-binding-{{.Iteration}}" -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: "ins-admin-clusterrole-{{.Iteration}}" -subjects: - - kind: ServiceAccount - name: "ins-sa-{{.Iteration}}" - namespace: "{{.prefixNamespace}}-{{.Iteration}}" diff --git a/openshift/tests-extension/test/qe/util/stress/manifests/config/pkg-ins-v1/templates/sa.yml b/openshift/tests-extension/test/qe/util/stress/manifests/config/pkg-ins-v1/templates/sa.yml deleted file mode 100644 index 2f194c7541..0000000000 --- a/openshift/tests-extension/test/qe/util/stress/manifests/config/pkg-ins-v1/templates/sa.yml +++ /dev/null @@ -1,4 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - name: "ins-sa-{{.Iteration}}" diff --git a/openshift/tests-extension/test/webhooks.go b/openshift/tests-extension/test/webhooks.go index 34c2d3dcab..58ba83992c 100644 --- a/openshift/tests-extension/test/webhooks.go +++ b/openshift/tests-extension/test/webhooks.go @@ -433,29 +433,8 @@ func setupWebhookOperator(ctx SpecContext, k8sClient client.Client, webhookOpera }).WithTimeout(helpers.DefaultTimeout).WithPolling(helpers.DefaultPolling).Should(Succeed()) }) - saName := fmt.Sprintf("%s-installer", webhookOperatorInstallNamespace) - sa := helpers.NewServiceAccount(saName, webhookOperatorInstallNamespace) - err = k8sClient.Create(ctx, sa) - Expect(err).ToNot(HaveOccurred()) - helpers.ExpectServiceAccountExists(ctx, saName, webhookOperatorInstallNamespace) - // ServiceAccount will be deleted with the namespace, no separate cleanup needed - - By("creating a ClusterRoleBinding to cluster-admin for the webhook operator") - operatorClusterRoleBindingName := fmt.Sprintf("%s-operator-crb", webhookOperatorInstallNamespace) - operatorClusterRoleBinding := helpers.NewClusterRoleBinding(operatorClusterRoleBindingName, "cluster-admin", saName, webhookOperatorInstallNamespace) - err = k8sClient.Create(ctx, operatorClusterRoleBinding) - Expect(err).ToNot(HaveOccurred(), fmt.Sprintf("failed to create ClusterRoleBinding %s", - operatorClusterRoleBindingName)) - helpers.ExpectClusterRoleBindingExists(ctx, operatorClusterRoleBindingName) - // Register cleanup for ClusterRoleBinding (cluster-scoped resource) - DeferCleanup(func(ctx context.Context) { - By(" NOW cleaning up ClusterRoleBinding (DeferCleanup executing) ") - By(fmt.Sprintf("cleanup: deleting ClusterRoleBinding %s", operatorClusterRoleBinding.Name)) - _ = k8sClient.Delete(ctx, operatorClusterRoleBinding, client.PropagationPolicy(metav1.DeletePropagationBackground)) - }) - ceName := webhookOperatorInstallNamespace - ce := helpers.NewClusterExtensionObject("webhook-operator", "0.0.5", ceName, saName, webhookOperatorInstallNamespace) + ce := helpers.NewClusterExtensionObject("webhook-operator", "0.0.5", ceName, webhookOperatorInstallNamespace) ce.Spec.Source.Catalog.Selector = &metav1.LabelSelector{ MatchLabels: map[string]string{ "olm.operatorframework.io/metadata.name": catalogName,