From ee70d8a9405ec63ea78e7b752536094657f4f153 Mon Sep 17 00:00:00 2001 From: Gus Luxton Date: Fri, 9 Jul 2021 19:09:23 -0300 Subject: [PATCH] integration: Add teletest namespace and instructions for Kubernetes tests (#7447) --- fixtures/ci-teleport-rbac/README.md | 25 ++++++++++++++++++++++ fixtures/ci-teleport-rbac/ci-teleport.yaml | 6 ++++++ 2 files changed, 31 insertions(+) create mode 100644 fixtures/ci-teleport-rbac/README.md diff --git a/fixtures/ci-teleport-rbac/README.md b/fixtures/ci-teleport-rbac/README.md new file mode 100644 index 00000000000..3ca1c294e80 --- /dev/null +++ b/fixtures/ci-teleport-rbac/README.md @@ -0,0 +1,25 @@ +## Generating a ServiceAccount to use for Teleport integration tests + +This should be done on a 'clean' k8s cluster i.e. one that doesn't already have Teleport installed for +Kubernetes forwarding (and doesn't require it), as we delete the default Teleport `ClusterRole` and +`ClusterRoleBinding` for security. + +``` +# Check out the Teleport repo and change dir to it +git clone https://github.com/gravitational/teleport +cd teleport + +# generate a ServiceAccount using the get-kubeconfig script +TELEPORT_NAMESPACE="ci-teleport" examples/k8s-auth/get-kubeconfig.sh + +# copy the generated kubeconfig, then add it to CI as a secret (out of band) +mv kubeconfig INTEGRATION_CI_KUBECONFIG + +# add the additional required RBAC fixtures +kubectl create -f fixtures/ci-teleport-rbac/ci-teleport.yaml + +# remove the additional teleport permissions that were added by the get-kubeconfig script +# (as these are not needed for CI, we can remove them for greater security) +kubectl delete clusterrole/teleport-role +kubectl delete clusterrolebinding/teleport-crb +``` \ No newline at end of file diff --git a/fixtures/ci-teleport-rbac/ci-teleport.yaml b/fixtures/ci-teleport-rbac/ci-teleport.yaml index 25311d97807..6d0825c5f46 100644 --- a/fixtures/ci-teleport-rbac/ci-teleport.yaml +++ b/fixtures/ci-teleport-rbac/ci-teleport.yaml @@ -1,4 +1,10 @@ # defines the permissions needed for Teleport k8s integration tests to run in a cluster +# namespace for teleport tests +apiVersion: v1 +kind: Namespace +metadata: + name: teletest +--- # clusterrole granting overarching privileges apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole