mirror of
https://github.com/ansible-collections/kubernetes.core.git
synced 2026-05-06 21:12:37 +00:00
SelfSubjectAccessReviews now work with the k8s module (#237)
* SelfSubjectAccessReviews now work with the k8s module
This commit is contained in:
committed by
GitHub
parent
5de49373b7
commit
0f3fef927e
@@ -28,6 +28,7 @@
|
||||
- include_tasks: tasks/exec.yml
|
||||
- include_tasks: tasks/log.yml
|
||||
- include_tasks: tasks/cluster_info.yml
|
||||
- include_tasks: tasks/access_review.yml
|
||||
|
||||
roles:
|
||||
- helm
|
||||
|
||||
22
molecule/default/tasks/access_review.yml
Normal file
22
molecule/default/tasks/access_review.yml
Normal file
@@ -0,0 +1,22 @@
|
||||
---
|
||||
- name: Create a SelfSubjectAccessReview resource
|
||||
register: can_i_create_namespaces
|
||||
ignore_errors: yes
|
||||
k8s:
|
||||
state: present
|
||||
definition:
|
||||
apiVersion: authorization.k8s.io/v1
|
||||
kind: SelfSubjectAccessReview
|
||||
spec:
|
||||
resourceAttributes:
|
||||
group: v1
|
||||
resource: Namespace
|
||||
verb: create
|
||||
|
||||
- name: Assert that the SelfSubjectAccessReview request succeded
|
||||
assert:
|
||||
that:
|
||||
- can_i_create_namespaces is successful
|
||||
- can_i_create_namespaces.result.status is defined
|
||||
- can_i_create_namespaces.result.status.allowed is defined
|
||||
- can_i_create_namespaces.result.status.allowed
|
||||
Reference in New Issue
Block a user