Skip to content

Commit f14cb24

Browse files
committed
Fix user-provided namespace ownership e2e assertion
check that the namespace has no owner references after successful installation instead of asserting that PSA labels are absent. Signed-off-by: Nader Ziada <nziada@redhat.com>
1 parent a632214 commit f14cb24

2 files changed

Lines changed: 25 additions & 3 deletions

File tree

‎test/e2e/features/namespace.feature‎

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,8 @@ Feature: Namespace PSA Management
22

33
As an OLM user, when I install an operator that declares PSA requirements
44
via the suggested-namespace-template CSV annotation, operator-controller
5-
should create a managed namespace with PSA labels applied.
5+
should create a managed namespace with PSA labels applied and leave
6+
user-provided namespaces unmanaged.
67

78
Background:
89
Given OLM is available
@@ -36,7 +37,7 @@ Feature: Namespace PSA Management
3637
| pod-security.kubernetes.io/audit | privileged |
3738
| pod-security.kubernetes.io/warn | privileged |
3839

39-
Scenario: User-provided namespace does not get PSA labels
40+
Scenario: User-provided namespace remains unmanaged
4041
Given namespace "${TEST_NAMESPACE}" is available
4142
And a catalog "test" with packages:
4243
| package | version | channel | replaces | contents |
@@ -59,4 +60,5 @@ Feature: Namespace PSA Management
5960
"""
6061
Then ClusterExtension is rolled out
6162
And ClusterExtension is available
62-
And namespace "${TEST_NAMESPACE}" does not have label "pod-security.kubernetes.io/enforce"
63+
# Other cluster controllers may apply PSA labels to user-provided namespaces.
64+
And namespace "${TEST_NAMESPACE}" has no owner references

‎test/e2e/steps/steps.go‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -187,6 +187,7 @@ func RegisterSteps(sc *godog.ScenarioContext) {
187187

188188
sc.Step(`^(?i)namespace "([^"]+)" has labels$`, NamespaceHasLabels)
189189
sc.Step(`^(?i)namespace "([^"]+)" does not have label "([^"]+)"$`, NamespaceDoesNotHaveLabel)
190+
sc.Step(`^(?i)namespace "([^"]+)" has no owner references$`, NamespaceHasNoOwnerReferences)
190191

191192
sc.Step(`^(?i)operator "([^"]+)" target namespace is "([^"]+)"$`, OperatorTargetNamespace)
192193
sc.Step(`^(?i)Prometheus metrics are returned in the response$`, PrometheusMetricsAreReturned)
@@ -2513,6 +2514,25 @@ func NamespaceDoesNotHaveLabel(ctx context.Context, nsName string, labelKey stri
25132514
return nil
25142515
}
25152516

2517+
// NamespaceHasNoOwnerReferences verifies a namespace remains unmanaged after installation.
2518+
func NamespaceHasNoOwnerReferences(ctx context.Context, nsName string) error {
2519+
sc := scenarioCtx(ctx)
2520+
nsName = substituteScenarioVars(nsName, sc)
2521+
2522+
out, err := k8sClient(ctx, "get", "namespace", nsName, "-o", "json")
2523+
if err != nil {
2524+
return fmt.Errorf("failed to get namespace %q: %w", nsName, err)
2525+
}
2526+
var obj unstructured.Unstructured
2527+
if err := json.Unmarshal([]byte(out), &obj); err != nil {
2528+
return fmt.Errorf("failed to unmarshal namespace: %w", err)
2529+
}
2530+
if refs := obj.GetOwnerReferences(); len(refs) != 0 {
2531+
return fmt.Errorf("namespace %q has unexpected owner references: %v", nsName, refs)
2532+
}
2533+
return nil
2534+
}
2535+
25162536
// nestedString traverses a nested map[string]interface{} by the given keys
25172537
// and returns the leaf value as a string.
25182538
func nestedString(obj map[string]interface{}, keys ...string) (string, bool) {

0 commit comments

Comments
 (0)