Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
172 changes: 172 additions & 0 deletions test/extended/authentication/component_proxy.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,172 @@
package authentication

import (
"context"

g "github.com/onsi/ginkgo/v2"
o "github.com/onsi/gomega"

corev1 "k8s.io/api/core/v1"
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"

operatorv1 "github.com/openshift/api/operator/v1"

exutil "github.com/openshift/origin/test/extended/util"
operator "github.com/openshift/origin/test/extended/util/operator"
)

var _ = g.Describe("[sig-auth][Suite:openshift/conformance/serial][OCPFeatureGate:AuthenticationComponentProxy][Serial][Slow]", func() {
Comment thread
tchap marked this conversation as resolved.
oc := exutil.NewCLIWithoutNamespace("component-proxy")

var (
ctx context.Context
httpProxyURL string
httpsProxyURL string
caCertPEM []byte
proxyNamespace string
kcSetup *keycloakProxySetup
cleanups []removalFunc
)

g.BeforeEach(func() {
ctx = context.Background()
cleanups = nil

g.By("Saving auth state for restore after test")
authRestore, err := saveAndRestoreAuthState(ctx, oc)
cleanups = append(cleanups, authRestore)
o.Expect(err).NotTo(o.HaveOccurred())

g.By("Deploying Squid forward proxy")
var proxyCleanup removalFunc
httpProxyURL, httpsProxyURL, caCertPEM, proxyNamespace, proxyCleanup, err = deploySquidProxy(ctx, oc)
cleanups = append(cleanups, proxyCleanup)
o.Expect(err).NotTo(o.HaveOccurred())

g.By("Deploying Keycloak (without registering IdP yet)")
var kcCleanups []removalFunc
kcSetup, kcCleanups, err = deployKeycloakForProxy(ctx, oc)
cleanups = append(cleanups, kcCleanups...)
o.Expect(err).NotTo(o.HaveOccurred())

g.By("Waiting for operators to be stable before test")
err = operator.WaitForOperatorsToSettle(ctx, oc.AdminConfigClient(), 10)
o.Expect(err).NotTo(o.HaveOccurred())

g.GinkgoWriter.Printf("Squid proxy URL: http=%s https=%s\n", httpProxyURL, httpsProxyURL)
g.GinkgoWriter.Printf("Keycloak issuer URL: %s\n", kcSetup.issuerURL)
g.GinkgoWriter.Printf("Keycloak namespace: %s\n", kcSetup.namespace)
})

g.AfterEach(func() {
_ = removeResources(ctx, cleanups...)

g.By("Waiting for operators to be stable after test")
err := operator.WaitForOperatorsToSettle(ctx, oc.AdminConfigClient(), 10)
o.Expect(err).NotTo(o.HaveOccurred())
})

g.It("should validate OIDC IdP through component proxy", func() {
testOIDCIdPThroughComponentProxy(ctx, oc, kcSetup, httpProxyURL, nil, proxyNamespace)
})
g.It("should validate OIDC IdP through component proxy with trustedCA", func() {
testOIDCIdPThroughComponentProxy(ctx, oc, kcSetup, httpsProxyURL, caCertPEM, proxyNamespace)
})
g.It("should fall back on spec.proxy removal", func() {
testFallbackOnProxyRemoval(ctx, oc, kcSetup, httpProxyURL, proxyNamespace)
})
})

func testOIDCIdPThroughComponentProxy(ctx context.Context, oc *exutil.CLI, kcSetup *keycloakProxySetup, proxyURL string, trustedCACertPEM []byte, proxyNamespace string) {
withTrustedCA := len(trustedCACertPEM) > 0

const trustedCAConfigMapName = "e2e-proxy-ca"
if withTrustedCA {
g.By("Creating trustedCA ConfigMap in openshift-config")
_, err := oc.AdminKubeClient().CoreV1().ConfigMaps("openshift-config").Create(ctx, &corev1.ConfigMap{
ObjectMeta: metav1.ObjectMeta{
Name: trustedCAConfigMapName,
Labels: componentProxyTestLabels(),
},
Data: map[string]string{
"ca-bundle.crt": string(trustedCACertPEM),
},
}, metav1.CreateOptions{})
o.Expect(err).NotTo(o.HaveOccurred())
g.DeferCleanup(func(ctx context.Context) error {
return oc.AdminKubeClient().CoreV1().ConfigMaps("openshift-config").Delete(ctx, trustedCAConfigMapName, metav1.DeleteOptions{})
})
}

g.By("Deploying NetworkPolicy to restrict Keycloak ingress to proxy namespace only")
// We don't need to call the cleanup function since the whole namespace is removed in AfterEach.
_, err := deployProxyNetworkPolicies(ctx, oc, proxyNamespace, kcSetup.namespace)
o.Expect(err).NotTo(o.HaveOccurred())

g.By("Setting component-scoped proxy")
proxyConfig := operatorv1.AuthenticationProxyConfig{
HTTPSProxy: proxyURL,
}
if withTrustedCA {
proxyConfig.TrustedCA = operatorv1.AuthenticationConfigMapReference{Name: trustedCAConfigMapName}
}
err = updateAuthenticationProxy(ctx, oc, proxyConfig)
o.Expect(err).NotTo(o.HaveOccurred())

g.By("Registering Keycloak as OIDC IdP (operator discovers it through the proxy)")
idpCleanups, err := addKeycloakOIDCIdPForProxy(ctx, oc, kcSetup)
g.DeferCleanup(func() {
_ = removeResources(ctx, idpCleanups...)
})
o.Expect(err).NotTo(o.HaveOccurred())

g.By("Waiting for operator to pick up IdP changes and stabilize")
err = waitForOperatorToPickUpChanges(ctx, oc, "authentication")
o.Expect(err).NotTo(o.HaveOccurred())

g.By("Verifying OAuth server deployment has proxy env vars and trustedCA volume/mount")
err = verifyOAuthServerDeploymentProxyConfig(ctx, oc, "", proxyURL, ".cluster.local,.svc,127.0.0.1,localhost", withTrustedCA)
o.Expect(err).NotTo(o.HaveOccurred())

if withTrustedCA {
g.By("Verifying trustedCA ConfigMap was synced to openshift-authentication")
err = verifyTrustedCAConfigMapSynced(ctx, oc)
o.Expect(err).NotTo(o.HaveOccurred())
}

}

func testFallbackOnProxyRemoval(ctx context.Context, oc *exutil.CLI, kcSetup *keycloakProxySetup, httpProxyURL string, proxyNamespace string) {
g.By("Setting component-scoped proxy")
err := updateAuthenticationProxy(ctx, oc, operatorv1.AuthenticationProxyConfig{
HTTPSProxy: httpProxyURL,
})
o.Expect(err).NotTo(o.HaveOccurred())

g.By("Registering Keycloak as OIDC IdP")
idpCleanups, err := addKeycloakOIDCIdPForProxy(ctx, oc, kcSetup)
g.DeferCleanup(func() {
_ = removeResources(ctx, idpCleanups...)
})
o.Expect(err).NotTo(o.HaveOccurred())

g.By("Waiting for operator to pick up IdP changes and stabilize")
err = waitForOperatorToPickUpChanges(ctx, oc, "authentication")
o.Expect(err).NotTo(o.HaveOccurred())

g.By("Removing spec.proxy from Authentication CR")
err = updateAuthenticationProxy(ctx, oc, operatorv1.AuthenticationProxyConfig{})
o.Expect(err).NotTo(o.HaveOccurred())

g.By("Deleting Squid to prove the operator no longer routes through it")
err = oc.AdminKubeClient().CoreV1().Namespaces().Delete(ctx, proxyNamespace, metav1.DeleteOptions{})
o.Expect(err).NotTo(o.HaveOccurred())

g.By("Waiting for operator to pick up proxy removal and stabilize")
err = waitForOperatorToPickUpChanges(ctx, oc, "authentication")
o.Expect(err).NotTo(o.HaveOccurred())

g.By("Verifying proxy env vars are no longer set on OAuth server deployment")
err = verifyOAuthServerDeploymentProxyConfig(ctx, oc, "", "", "", false)
o.Expect(err).NotTo(o.HaveOccurred())
}
Loading