|
1 | 1 | from .common import random_str |
2 | 2 | from rancher import ApiError |
3 | 3 | import pytest |
| 4 | +import time |
| 5 | +import kubernetes |
4 | 6 |
|
5 | 7 |
|
6 | 8 | def test_dns_fqdn_unique(admin_mc): |
@@ -42,12 +44,125 @@ def test_dns_provider_deletion(admin_mc): |
42 | 44 | 'rootDomain': "example.com"}) |
43 | 45 |
|
44 | 46 | fqdn = random_str() + ".example.com" |
| 47 | + provider_id = "cattle-global-data:"+provider_name |
45 | 48 | globaldns_entry = \ |
46 | | - client.create_global_dns(fqdn=fqdn, providerId=provider_name) |
| 49 | + client.create_global_dns(fqdn=fqdn, providerId=provider_id) |
47 | 50 |
|
48 | 51 | with pytest.raises(ApiError) as e: |
49 | 52 | client.delete(globaldns_provider) |
50 | 53 | assert e.value.error.status == 403 |
51 | 54 |
|
52 | 55 | client.delete(globaldns_entry) |
53 | 56 | client.delete(globaldns_provider) |
| 57 | + |
| 58 | + |
| 59 | +def test_share_globaldns_provider_entry(admin_mc, user_factory, |
| 60 | + remove_resource): |
| 61 | + client = admin_mc.client |
| 62 | + provider_name = random_str() |
| 63 | + access = random_str() |
| 64 | + secret = random_str() |
| 65 | + # Add regular user as member to gdns provider |
| 66 | + user_member = user_factory() |
| 67 | + remove_resource(user_member) |
| 68 | + user_client = user_member.client |
| 69 | + members = [{"userPrincipalId": "local://" + user_member.user.id, |
| 70 | + "accessType": "owner"}] |
| 71 | + globaldns_provider = \ |
| 72 | + client.create_global_dns_provider( |
| 73 | + name=provider_name, |
| 74 | + route53ProviderConfig={ |
| 75 | + 'accessKey': access, |
| 76 | + 'secretKey': secret, |
| 77 | + 'rootDomain': "example.com"}, |
| 78 | + members=members) |
| 79 | + |
| 80 | + remove_resource(globaldns_provider) |
| 81 | + fqdn = random_str() + ".example.com" |
| 82 | + globaldns_entry = \ |
| 83 | + client.create_global_dns(fqdn=fqdn, providerId=provider_name, |
| 84 | + members=members) |
| 85 | + remove_resource(globaldns_entry) |
| 86 | + # Make sure creator can access both, provider and entry |
| 87 | + gdns_provider_id = "cattle-global-data:" + provider_name |
| 88 | + gdns_provider = client.by_id_global_dns_provider(gdns_provider_id) |
| 89 | + assert gdns_provider is not None |
| 90 | + |
| 91 | + gdns_entry_id = "cattle-global-data:" + globaldns_entry.name |
| 92 | + gdns = client.by_id_global_dns(gdns_entry_id) |
| 93 | + assert gdns is not None |
| 94 | + # user should be able to list this gdns provider |
| 95 | + api_instance = kubernetes.client.RbacAuthorizationV1Api( |
| 96 | + admin_mc.k8s_client) |
| 97 | + provider_rb_name = provider_name + "-gp-a" |
| 98 | + wait_to_ensure_user_in_rb_subject(api_instance, provider_rb_name, |
| 99 | + user_member.user.id) |
| 100 | + gdns_provider = user_client.by_id_global_dns_provider(gdns_provider_id) |
| 101 | + assert gdns_provider is not None |
| 102 | + |
| 103 | + # user should be able to list this gdns entry |
| 104 | + entry_rb_name = globaldns_entry.name + "-g-a" |
| 105 | + wait_to_ensure_user_in_rb_subject(api_instance, entry_rb_name, |
| 106 | + user_member.user.id) |
| 107 | + gdns = user_client.by_id_global_dns(gdns_entry_id) |
| 108 | + assert gdns is not None |
| 109 | + |
| 110 | + |
| 111 | +def test_user_access_global_dns(admin_mc, user_factory, remove_resource): |
| 112 | + user1 = user_factory() |
| 113 | + remove_resource(user1) |
| 114 | + user_client = user1.client |
| 115 | + provider_name = random_str() |
| 116 | + access = random_str() |
| 117 | + secret = random_str() |
| 118 | + globaldns_provider = \ |
| 119 | + user_client.create_global_dns_provider( |
| 120 | + name=provider_name, |
| 121 | + route53ProviderConfig={ |
| 122 | + 'accessKey': access, |
| 123 | + 'secretKey': secret, |
| 124 | + 'rootDomain': "example.com"}) |
| 125 | + |
| 126 | + remove_resource(globaldns_provider) |
| 127 | + fqdn = random_str() + ".example.com" |
| 128 | + globaldns_entry = \ |
| 129 | + user_client.create_global_dns(fqdn=fqdn, providerId=provider_name) |
| 130 | + |
| 131 | + remove_resource(globaldns_entry) |
| 132 | + # Make sure creator can access both, provider and entry |
| 133 | + api_instance = kubernetes.client.RbacAuthorizationV1Api( |
| 134 | + admin_mc.k8s_client) |
| 135 | + provider_rb_name = provider_name + "-gp-a" |
| 136 | + wait_to_ensure_user_in_rb_subject(api_instance, provider_rb_name, |
| 137 | + user1.user.id) |
| 138 | + |
| 139 | + gdns_provider_id = "cattle-global-data:" + provider_name |
| 140 | + gdns_provider = user_client.by_id_global_dns_provider(gdns_provider_id) |
| 141 | + assert gdns_provider is not None |
| 142 | + |
| 143 | + entry_rb_name = globaldns_entry.name + "-g-a" |
| 144 | + wait_to_ensure_user_in_rb_subject(api_instance, entry_rb_name, |
| 145 | + user1.user.id) |
| 146 | + gdns_entry_id = "cattle-global-data:" + globaldns_entry.name |
| 147 | + gdns = user_client.by_id_global_dns(gdns_entry_id) |
| 148 | + assert gdns is not None |
| 149 | + |
| 150 | + |
| 151 | +def wait_to_ensure_user_in_rb_subject(api, name, |
| 152 | + userId, timeout=60): |
| 153 | + found = False |
| 154 | + interval = 0.5 |
| 155 | + start = time.time() |
| 156 | + while not found: |
| 157 | + time.sleep(interval) |
| 158 | + interval *= 2 |
| 159 | + try: |
| 160 | + rb = api.read_namespaced_role_binding(name, "cattle-global-data") |
| 161 | + for i in range(0, len(rb.subjects)): |
| 162 | + if rb.subjects[i].name == userId: |
| 163 | + found = True |
| 164 | + except kubernetes.client.rest.ApiException: |
| 165 | + found = False |
| 166 | + if time.time() - start > timeout: |
| 167 | + raise AssertionError( |
| 168 | + "Timed out waiting for user to get added to rb") |
0 commit comments