Uploaded image for project: 'OpenShift Pipelines'
  1. OpenShift Pipelines
  2. SRVKP-10244

[Downstream CI] Add tests to verify legacyPipelineRbac Control for Namespace Permissions

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • QA
    • None
    • 3
    • False
    • Hide

      None

      Show
      None
    • False

      Story (Required)

      OpenShift Pipelines automatically grants the edit ClusterRole to the pipeline ServiceAccount in every namespace where the operator is active. To align with "Least Privilege" security principles, a new parameter legacyPipelineRbac has been introduced in the TektonConfig CRD. We need automated tests to ensure that toggling this parameter correctly controls the creation (or omission) of these RoleBindings in new and existing namespaces.

      Done Checklist

      • Code is completed, reviewed, documented and checked in
      • Unit and integration test automation have been delivered and running cleanly in continuous integration/staging/canary environment
      • Continuous Delivery pipeline(s) is able to proceed with new code included
      • Customer facing documentation, API docs etc. are produced/updated, reviewed and published
      • Acceptance criteria are met

              Unassigned Unassigned
              rhn-support-sselvan Sri Vignesh Selvan
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: