Merge pull request #5313 from trumant/k8s-backend-skipTLSVerify-configurable

Configuration of the kubernetes-backend should be able to toggle TLS verification
This commit is contained in:
Fredrik Adelöw
2021-04-16 15:19:04 +02:00
committed by GitHub
8 changed files with 24 additions and 2 deletions
@@ -52,6 +52,7 @@ describe('ConfigClusterLocator', () => {
serviceAccountToken: undefined,
url: 'http://localhost:8080',
authProvider: 'serviceAccount',
skipTLSVerify: false,
},
]);
});
@@ -64,11 +65,13 @@ describe('ConfigClusterLocator', () => {
serviceAccountToken: 'token',
url: 'http://localhost:8080',
authProvider: 'serviceAccount',
skipTLSVerify: false,
},
{
name: 'cluster2',
url: 'http://localhost:8081',
authProvider: 'google',
skipTLSVerify: true,
},
],
});
@@ -83,12 +86,14 @@ describe('ConfigClusterLocator', () => {
serviceAccountToken: 'token',
url: 'http://localhost:8080',
authProvider: 'serviceAccount',
skipTLSVerify: false,
},
{
name: 'cluster2',
serviceAccountToken: undefined,
url: 'http://localhost:8081',
authProvider: 'google',
skipTLSVerify: true,
},
]);
});
@@ -33,6 +33,7 @@ export class ConfigClusterLocator implements KubernetesClustersSupplier {
name: c.getString('name'),
url: c.getString('url'),
serviceAccountToken: c.getOptionalString('serviceAccountToken'),
skipTLSVerify: c.getOptionalBoolean('skipTLSVerify') ?? false,
authProvider: c.getString('authProvider'),
};
}),
@@ -53,12 +53,14 @@ describe('getCombinedClusterDetails', () => {
serviceAccountToken: 'token',
url: 'http://localhost:8080',
authProvider: 'serviceAccount',
skipTLSVerify: false,
},
{
name: 'cluster2',
serviceAccountToken: undefined,
url: 'http://localhost:8081',
authProvider: 'google',
skipTLSVerify: false,
},
]);
});
@@ -34,6 +34,7 @@ describe('KubernetesClientProvider', () => {
url: 'http://localhost:9999',
serviceAccountToken: 'TOKEN',
authProvider: 'serviceAccount',
skipTLSVerify: false,
});
expect(result.basePath).toBe('http://localhost:9999');
@@ -41,6 +42,7 @@ describe('KubernetesClientProvider', () => {
const auth = (result as any).authentications.default;
expect(auth.users[0].token).toBe('TOKEN');
expect(auth.clusters[0].name).toBe('cluster-name');
expect(auth.clusters[0].skipTLSVerify).toBe(false);
expect(mockGetKubeConfig.mock.calls.length).toBe(1);
});
@@ -57,6 +59,7 @@ describe('KubernetesClientProvider', () => {
url: 'http://localhost:9999',
serviceAccountToken: 'TOKEN',
authProvider: 'serviceAccount',
skipTLSVerify: false,
});
expect(result.basePath).toBe('http://localhost:9999');
@@ -30,8 +30,7 @@ export class KubernetesClientProvider {
const cluster = {
name: clusterDetails.name,
server: clusterDetails.url,
// TODO configure this
skipTLSVerify: true,
skipTLSVerify: clusterDetails.skipTLSVerify,
};
// TODO configure
@@ -30,6 +30,7 @@ export interface ClusterDetails {
url: string;
authProvider: string;
serviceAccountToken?: string | undefined;
skipTLSVerify?: boolean;
}
export interface KubernetesRequestBody {