mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
feat(helm): scope ClusterRole/ClusterRoleBinding names by release namespace (#2939)
* feat(helm): scope ClusterRole/ClusterRoleBinding names by release namespace The chart creates cluster-scoped ClusterRole and ClusterRoleBinding resources with a fixed name derived from the release name. When multiple Helm releases coexist on the same cluster (multi-tenant), only one release can own these resources due to Helm ownership annotations -- the second install fails with a conflict. Append .Release.Namespace to the ClusterRole and ClusterRoleBinding names so each release gets its own cluster-scoped resources. The duplication is harmless (the rules are identical and small) and eliminates multi-tenant conflicts entirely without requiring external RBAC management. Signed-off-by: Brandon Squizzato <bsquizza@redhat.com> * test(helm): add regression tests for namespace-scoped ClusterRole names Assert the generated ClusterRole name, ClusterRoleBinding name, and roleRef all include the release namespace suffix so multi-namespace installations cannot silently regress to conflicting fixed names. Signed-off-by: Brandon Squizzato <bsquizza@redhat.com> --------- Signed-off-by: Brandon Squizzato <bsquizza@redhat.com>
This commit is contained in:
@@ -5,7 +5,7 @@
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ include "openshell.fullname" . }}-node-reader
|
||||
name: {{ include "openshell.fullname" . }}-node-reader-{{ .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "openshell.labels" . | nindent 4 }}
|
||||
rules:
|
||||
|
||||
@@ -4,13 +4,13 @@
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ include "openshell.fullname" . }}-node-reader
|
||||
name: {{ include "openshell.fullname" . }}-node-reader-{{ .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "openshell.labels" . | nindent 4 }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: {{ include "openshell.fullname" . }}-node-reader
|
||||
name: {{ include "openshell.fullname" . }}-node-reader-{{ .Release.Namespace }}
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ include "openshell.serviceAccountName" . }}
|
||||
|
||||
@@ -9,6 +9,12 @@ release:
|
||||
namespace: my-namespace
|
||||
|
||||
tests:
|
||||
- it: includes the release namespace in the ClusterRole name
|
||||
asserts:
|
||||
- equal:
|
||||
path: metadata.name
|
||||
value: openshell-node-reader-my-namespace
|
||||
|
||||
- it: grants managed namespace NetworkPolicy apply permissions
|
||||
set:
|
||||
server.drivers.kubernetes.workspaceMode: managed
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
suite: ClusterRoleBinding RBAC
|
||||
templates:
|
||||
- templates/clusterrolebinding.yaml
|
||||
release:
|
||||
name: openshell
|
||||
namespace: my-namespace
|
||||
|
||||
tests:
|
||||
- it: includes the release namespace in the ClusterRoleBinding name
|
||||
asserts:
|
||||
- equal:
|
||||
path: metadata.name
|
||||
value: openshell-node-reader-my-namespace
|
||||
|
||||
- it: references the namespace-scoped ClusterRole in roleRef
|
||||
asserts:
|
||||
- equal:
|
||||
path: roleRef.name
|
||||
value: openshell-node-reader-my-namespace
|
||||
|
||||
- it: binds the service account in the release namespace
|
||||
asserts:
|
||||
- contains:
|
||||
path: subjects
|
||||
content:
|
||||
kind: ServiceAccount
|
||||
name: openshell
|
||||
namespace: my-namespace
|
||||
Reference in New Issue
Block a user