Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion charts/workflows/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ name: workflows
description: Data Analysis workflow orchestration
type: application

version: 0.13.25
version: 0.13.26

dependencies:
- name: argo-workflows
Expand Down
2 changes: 1 addition & 1 deletion charts/workflows/templates/sessionspace-clusterpolicy.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -127,7 +127,7 @@ spec:
apiVersions: ["v1"]
operations: ["CREATE"]
resources: ["namespaces"]
namespaceSelector:
objectSelector:
matchLabels:
app.kubernetes.io/managed-by: sessionspaces
variables:
Expand Down
68 changes: 65 additions & 3 deletions charts/workflows/test-policy/artifact-s3-clone/chainsaw-test.yaml
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
apiVersion: chainsaw.kyverno.io/v1alpha1
kind: Test
metadata:
name: artifact-s3-clone
name: artifact-s3-clone-on-namespace-creation
spec:
concurrent: false
steps:
- try:
- apply:
Expand All @@ -29,12 +30,73 @@ spec:
name: session
labels:
app.kubernetes.io/managed-by: sessionspaces
- sleep:
duration: 10s
- assert:
resource:
apiVersion: v1
kind: Secret
metadata:
name: artifact-s3
namespace: session
---
apiVersion: chainsaw.kyverno.io/v1alpha1
kind: Test
metadata:
name: artifact-s3-clone-on-secret-update
spec:
concurrent: false
steps:
- try:
- apply:
resource:
apiVersion: v1
kind: Namespace
metadata:
name: workflows
- apply:
resource:
apiVersion: v1
kind: Secret
metadata:
name: artifact-s3
namespace: workflows
data:
access-key: aWQ=
secret-key: c2VjcmV0
- apply:
resource:
apiVersion: v1
kind: Namespace
metadata:
name: session
labels:
app.kubernetes.io/managed-by: sessionspaces
- assert:
resource:
apiVersion: v1
kind: Secret
metadata:
name: artifact-s3
namespace: session
data:
access-key: aWQ=
secret-key: c2VjcmV0
- apply:
resource:
apiVersion: v1
kind: Secret
metadata:
name: artifact-s3
namespace: workflows
data:
access-key: aWQ=
secret-key: dXBkYXRlZC1zZWNyZXQK
- assert:
resource:
apiVersion: v1
kind: Secret
metadata:
name: artifact-s3
namespace: session
data:
access-key: aWQ=
secret-key: dXBkYXRlZC1zZWNyZXQK