mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-03 16:11:17 +08:00
Implements https://github.com/NVIDIA/OpenShell/issues/3212 Running e2e:kubernetes with the Vault credential driver failed on OpenShift in two ways: the OpenBao fixture pod was rejected by the restricted-v2 SCC, and provider-creating tests hit HTTP 403 from auth/kubernetes/login because OpenBao's Kubernetes auth was provisioned only inside a single feature-gated test. - Deploy OpenBao with the chart's OpenShift mode (global.openshift=true) when OpenShift is detected, so the pod inherits a namespace-assigned, SCC-compliant security context with no manual SCC grant. Hoist OpenShift detection ahead of the credential-driver fixtures so the flag is set before the fixture is deployed. - Provision the OpenBao KV store, Kubernetes auth method, storage policy, and gateway login role in the harness (deploy_vault_fixture), making a Vault-backed gateway usable by the whole suite instead of only the credential_drivers test. Remove the now-redundant configure_vault_storage helper from the test. - Harden openbao_exec so it tolerates only the idempotent "path is already in use" error on reruns and fails fast with output on any other error, instead of a blanket `|| true` that masked genuine failures (e.g. an unresponsive pod) until a later cryptic write. - Document the OpenShift Vault credential-store SCC and Kubernetes-auth 403 troubleshooting in the debug-openshell-cluster skill. Signed-off-by: Jorge Garcia Oncins <jgarciao@redhat.com>