From dac5f48c774a96c5630a1cc90c43f5d911d0b6fe Mon Sep 17 00:00:00 2001 From: Chai Bot Date: Tue, 29 Sep 2026 16:44:18 +0000 Subject: [PATCH] Allow opendatahub service accounts in privileged groups --- .../networkpolicies/networkpolicies_test.go | 12 +++++++++++ pkg/webhooks/utils/utils.go | 2 +- pkg/webhooks/utils/utils_test.go | 20 +++++++++++++++++++ 3 files changed, 33 insertions(+), 1 deletion(-) diff --git a/pkg/webhooks/networkpolicies/networkpolicies_test.go b/pkg/webhooks/networkpolicies/networkpolicies_test.go index 4261da98..c4a69a06 100644 --- a/pkg/webhooks/networkpolicies/networkpolicies_test.go +++ b/pkg/webhooks/networkpolicies/networkpolicies_test.go @@ -88,6 +88,12 @@ func (t crudTest) rhoaiServiceAccount() crudTest { return t } +func (t crudTest) opendatahubServiceAccount() crudTest { + t.testData.username = "system:serviceaccount:opendatahub:operator" + t.testData.userGroups = []string{"system:serviceaccounts:opendatahub", "system:authenticated", "system:authenticated:oauth"} + return t +} + func (t crudTest) namespace(namespace string) crudTest { t.testData.targetNamespace = namespace return t @@ -234,6 +240,8 @@ func TestUsers(t *testing.T) { namespace("openshift-kube-apiserver").allowedServiceAccount().shouldBeAllowedCRUD()...) tests = append(tests, newCrudTest("serviceaccount-managed-namespace-redhat-rhoam-observability"). namespace("redhat-rhoam-observability").redhatServiceAccount().shouldBeAllowedCRUD()...) + tests = append(tests, newCrudTest("opendatahub-sa-managed-namespace"). + namespace("openshift-kube-apiserver").opendatahubServiceAccount().shouldBeAllowedCRUD()...) tests = append(tests, newCrudTest("regular-user-openshift-ingress-no-podselector"). namespace("openshift-ingress").regularUser().shouldBeDeniedCRUD()...) @@ -259,6 +267,10 @@ func TestUsers(t *testing.T) { namespace("openshift-ingress"). podSelector("app", "kube-auth-proxy"). rhoaiServiceAccount().shouldBeAllowedCRUD()...) + tests = append(tests, newCrudTest("opendatahub-sa-openshift-ingress-no-ingress-label"). + namespace("openshift-ingress"). + podSelector("app", "kube-auth-proxy"). + opendatahubServiceAccount().shouldBeAllowedCRUD()...) tests = append(tests, newCrudTest("privileged-sa-openshift-ingress-no-ingress-label"). namespace("openshift-ingress"). podSelector("app", "payload-processing"). diff --git a/pkg/webhooks/utils/utils.go b/pkg/webhooks/utils/utils.go index b33fd584..dc9254d4 100644 --- a/pkg/webhooks/utils/utils.go +++ b/pkg/webhooks/utils/utils.go @@ -22,7 +22,7 @@ const ( // perform restricted actions. // Centralized osde2e tests have a serviceaccount like "system:serviceaccounts:osde2e-abcde" // Decentralized osde2e tests have a serviceaccount like "system:serviceaccounts:osde2e-h-abcde" - PrivilegedServiceAccountGroups string = `^system:serviceaccounts:(kube-.*|openshift|openshift-.*|default|redhat-.*|osde2e-(h-)?[a-z0-9]{5})` + PrivilegedServiceAccountGroups string = `^system:serviceaccounts:(kube-.*|openshift|openshift-.*|default|redhat-.*|osde2e-(h-)?[a-z0-9]{5}|opendatahub$)` ) var ( diff --git a/pkg/webhooks/utils/utils_test.go b/pkg/webhooks/utils/utils_test.go index 16336dbb..eb2e94ae 100644 --- a/pkg/webhooks/utils/utils_test.go +++ b/pkg/webhooks/utils/utils_test.go @@ -1,6 +1,7 @@ package utils import ( + "regexp" "testing" admissionv1 "k8s.io/api/admission/v1" @@ -8,6 +9,25 @@ import ( admissionctl "sigs.k8s.io/controller-runtime/pkg/webhook/admission" ) +func TestPrivilegedServiceAccountGroups(t *testing.T) { + pattern := regexp.MustCompile(PrivilegedServiceAccountGroups) + for _, test := range []struct { + group string + allowed bool + }{ + {group: "system:serviceaccounts:opendatahub", allowed: true}, + {group: "system:serviceaccounts:opendatahub-other", allowed: false}, + {group: "system:serviceaccounts:other-opendatahub", allowed: false}, + {group: "system:serviceaccounts:redhat-ods-operator", allowed: true}, + } { + t.Run(test.group, func(t *testing.T) { + if actual := pattern.MatchString(test.group); actual != test.allowed { + t.Errorf("group %q: expected allowed %v, got %v", test.group, test.allowed, actual) + } + }) + } +} + func TestRequestMatchesGroupKind(t *testing.T) { tests := []struct { name string