File: iampolicygenerator_test.go

package info (click to toggle)
golang-k8s-sigs-kustomize-api 0.19.0%2Bds-1
  • links: PTS, VCS
  • area: main
  • in suites: sid, trixie
  • size: 3,732 kB
  • sloc: makefile: 206; sh: 67
file content (127 lines) | stat: -rw-r--r-- 2,638 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
// Copyright 2022 The Kubernetes Authors.
// SPDX-License-Identifier: Apache-2.0

package krusty_test

import (
	"testing"

	kusttest_test "sigs.k8s.io/kustomize/api/testutils/kusttest"
)

func TestGkeGenerator(t *testing.T) {
	th := kusttest_test.MakeEnhancedHarness(t)
	defer th.Reset()

	th.WriteK(".", `
generators:
- |-
  apiVersion: builtin
  kind: IAMPolicyGenerator
  metadata:
    name: my-gke-generator
  cloud: gke
  kubernetesService:
    name: k8s-sa-name
  serviceAccount:
    name: gsa-name
    projectId: project-id
`)
	expected := `
apiVersion: v1
kind: ServiceAccount
metadata:
  annotations:
    iam.gke.io/gcp-service-account: gsa-name@project-id.iam.gserviceaccount.com
  name: k8s-sa-name
`
	m := th.Run(".", th.MakeDefaultOptions())
	th.AssertActualEqualsExpected(m, expected)
}

func TestGkeGeneratorWithNamespace(t *testing.T) {
	th := kusttest_test.MakeEnhancedHarness(t)
	defer th.Reset()

	th.WriteK(".", `
generators:
- |-
  apiVersion: builtin
  kind: IAMPolicyGenerator
  metadata:
    name: my-gke-generator
  cloud: gke
  kubernetesService: 
    namespace: k8s-namespace
    name: k8s-sa-name
  serviceAccount:
    name: gsa-name
    projectId: project-id
`)
	expected := `
apiVersion: v1
kind: ServiceAccount
metadata:
  annotations:
    iam.gke.io/gcp-service-account: gsa-name@project-id.iam.gserviceaccount.com
  name: k8s-sa-name
  namespace: k8s-namespace
`
	m := th.Run(".", th.MakeDefaultOptions())
	th.AssertActualEqualsExpected(m, expected)
}

func TestGkeGeneratorWithTwo(t *testing.T) {
	th := kusttest_test.MakeEnhancedHarness(t)
	defer th.Reset()

	th.WriteK(".", `
generators:
- gkegenerator1.yaml
- gkegenerator2.yaml
`)

	th.WriteF("gkegenerator1.yaml", `
apiVersion: builtin
kind: IAMPolicyGenerator
metadata:
  name: my-gke-generator1
cloud: gke
kubernetesService: 
  namespace: k8s-namespace-1
  name: k8s-sa-name-1
serviceAccount:
  name: gsa-name-1
  projectId: project-id-1
`)
	th.WriteF("gkegenerator2.yaml", `
apiVersion: builtin
kind: IAMPolicyGenerator
metadata:
  name: my-gke-generator2
cloud: gke
kubernetesService:
  name: k8s-sa-name-2
serviceAccount:
  name: gsa-name-2
  projectId: project-id-2
`)
	expected := `
apiVersion: v1
kind: ServiceAccount
metadata:
  annotations:
    iam.gke.io/gcp-service-account: gsa-name-1@project-id-1.iam.gserviceaccount.com
  name: k8s-sa-name-1
  namespace: k8s-namespace-1
---
apiVersion: v1
kind: ServiceAccount
metadata:
  annotations:
    iam.gke.io/gcp-service-account: gsa-name-2@project-id-2.iam.gserviceaccount.com
  name: k8s-sa-name-2
`
	m := th.Run(".", th.MakeDefaultOptions())
	th.AssertActualEqualsExpected(m, expected)
}