Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: Gator sync test support #3098

Merged
merged 45 commits into from
Oct 29, 2024

Conversation

anlandu
Copy link
Member

@anlandu anlandu commented Oct 21, 2023

What this PR does / why we need it:
Certain templates require replicating into OPA to enable correct evaluation. These templates can use the annotation metadata.gatekeeper.sh/requires-sync-data to indicate which resources need to be synced. This template annotation is descriptive, not prescriptive. The prescription of which resources to sync is done in SyncSet resources and/or the Gatekeeper Config resource. The management of these various requirements can get challenging as the number of templates requiring replicated data increases.

gator sync test aims to mitigate this challenge by enabling the user to verify their sync configuration is correct. The user passes in any number of Constraint Templates, SyncSets, and a Gatekeeper Config object, along with a GVK manifest listing the GVKs supported by the cluster under test, and the command will determine which requirements enumerated by the Constraint Templates are unfulfilled by the given SyncSet(s), Config, and/or manifest.

PRD

Which issue(s) this PR fixes (optional, using fixes #<issue number>(, fixes #<issue_number>, ...) format, will close the issue(s) when the PR gets merged):
xref #2393

Special notes for your reviewer:

Signed-off-by: Anlan Du <adu47249@gmail.com>
Signed-off-by: Anlan Du <adu47249@gmail.com>
Signed-off-by: Anlan Du <adu47249@gmail.com>
Signed-off-by: Anlan Du <adu47249@gmail.com>
@codecov-commenter
Copy link

codecov-commenter commented Oct 21, 2023

Codecov Report

Attention: Patch coverage is 35.67961% with 265 lines in your changes missing coverage. Please review.

Project coverage is 47.48%. Comparing base (3350319) to head (3854ad2).
Report is 168 commits behind head on master.

Files with missing lines Patch % Lines
apis/gvkmanifest/v1alpha1/zz_generated.deepcopy.go 0.00% 120 Missing ⚠️
pkg/gator/reader/read_resources.go 0.00% 69 Missing ⚠️
cmd/gator/sync/test/test.go 0.00% 31 Missing ⚠️
pkg/gator/sync/test/test.go 78.57% 17 Missing and 7 partials ⚠️
pkg/cachemanager/parser/syncannotationreader.go 27.27% 16 Missing ⚠️
cmd/gator/sync/sync.go 0.00% 5 Missing ⚠️

❗ There is a different number of reports uploaded between BASE (3350319) and HEAD (3854ad2). Click for more details.

HEAD has 1 upload less than BASE
Flag BASE (3350319) HEAD (3854ad2)
unittests 2 1
Additional details and impacted files
@@            Coverage Diff             @@
##           master    #3098      +/-   ##
==========================================
- Coverage   54.49%   47.48%   -7.02%     
==========================================
  Files         134      228      +94     
  Lines       12329    19086    +6757     
==========================================
+ Hits         6719     9063    +2344     
- Misses       5116     9177    +4061     
- Partials      494      846     +352     
Flag Coverage Δ
unittests 47.48% <35.67%> (-7.02%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@anlandu
Copy link
Member Author

anlandu commented Oct 23, 2023

@julianKatz @acpana

@julianKatz julianKatz self-requested a review October 23, 2023 20:21
Copy link
Contributor

@acpana acpana left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks really good 💯 !! Thanks for working on it.

A few questions and suggestions.

cmd/gator/sync/sync.go Outdated Show resolved Hide resolved
cmd/gator/sync/sync.go Outdated Show resolved Hide resolved
cmd/gator/sync/sync.go Outdated Show resolved Hide resolved
cmd/gator/sync/verify/verify.go Outdated Show resolved Hide resolved
cmd/gator/sync/verify/verify.go Outdated Show resolved Hide resolved
pkg/gator/sync/verify/verify_test.go Outdated Show resolved Hide resolved
pkg/gator/sync/verify/verify.go Outdated Show resolved Hide resolved
pkg/gator/sync/verify/verify.go Outdated Show resolved Hide resolved
pkg/gator/sync/verify/verify.go Outdated Show resolved Hide resolved
pkg/gator/sync/verify/verify.go Outdated Show resolved Hide resolved
@anlandu anlandu requested a review from acpana October 23, 2023 20:48
Signed-off-by: Anlan Du <adu47249@gmail.com>
Signed-off-by: Anlan Du <adu47249@gmail.com>
cmd/gator/sync/verify/verify.go Outdated Show resolved Hide resolved
cmd/gator/sync/verify/verify.go Outdated Show resolved Hide resolved
cmd/gator/sync/verify/verify.go Outdated Show resolved Hide resolved
pkg/gator/fixtures/fixtures.go Show resolved Hide resolved
pkg/gator/fixtures/fixtures.go Outdated Show resolved Hide resolved
pkg/gator/sync/verify/verify.go Outdated Show resolved Hide resolved
pkg/gator/sync/verify/verify.go Outdated Show resolved Hide resolved
pkg/gator/sync/verify/verify_test.go Outdated Show resolved Hide resolved
website/docs/gator.md Outdated Show resolved Hide resolved
website/docs/gator.md Outdated Show resolved Hide resolved
Signed-off-by: Anlan Du <adu47249@gmail.com>
Signed-off-by: Anlan Du <adu47249@gmail.com>
@anlandu anlandu requested a review from a team as a code owner November 4, 2023 00:19
Signed-off-by: Anlan Du <adu47249@gmail.com>
Signed-off-by: Anlan Du <adu47249@gmail.com>
@anlandu anlandu changed the title feat: Gator sync verify support feat: Gator sync test support Nov 9, 2023
Signed-off-by: Anlan Du <adu47249@gmail.com>
@stale stale bot removed the stale label Apr 5, 2024
Copy link

stale bot commented Jun 25, 2024

This issue has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.

@stale stale bot added the stale label Jun 25, 2024
@stale stale bot removed the stale label Jun 25, 2024
Copy link

stale bot commented Aug 24, 2024

This issue has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.

@stale stale bot added the stale label Aug 24, 2024
@sozercan
Copy link
Member

sozercan commented Sep 4, 2024

@anlandu are you still interested in getting this to be merged?

@stale stale bot removed the stale label Sep 4, 2024
@anlandu
Copy link
Member Author

anlandu commented Sep 4, 2024

@sozercan yep! Happy to update the branch and address any comments anyone has, or Alex and Julian took a pretty thorough look so I can just merge it without waiting for another review

Signed-off-by: Anlan Du <adu47249@gmail.com>
@ritazh
Copy link
Member

ritazh commented Sep 5, 2024

@anlandu looks like there are some lint and unit test failures. can you PTAL?

@anlandu
Copy link
Member Author

anlandu commented Sep 17, 2024

@anlandu looks like there are some lint and unit test failures. can you PTAL?

@ritazh sorry for the delay during oncall! I've fixed them now

anlandu and others added 3 commits September 17, 2024 11:32
Co-authored-by: Rita Zhang <rita.z.zhang@gmail.com>
Signed-off-by: Anlan Du <adu47249@gmail.com>
Copy link
Member

@ritazh ritazh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ritazh
Copy link
Member

ritazh commented Oct 23, 2024

@maxsmythe LGTY?

Copy link
Contributor

@maxsmythe maxsmythe left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM with one nit

cmd/gator/sync/test/test.go Outdated Show resolved Hide resolved
Signed-off-by: Anlan Du <adu47249@gmail.com>
@anlandu anlandu merged commit 3cc730e into open-policy-agent:master Oct 29, 2024
20 checks passed
@anlandu anlandu deleted the gator-sync-support branch October 29, 2024 02:15
wyattfry pushed a commit to wyattfry/gatekeeper that referenced this pull request Nov 7, 2024
Signed-off-by: Anlan Du <adu47249@gmail.com>
Co-authored-by: alex <8968914+acpana@users.noreply.github.com>
Co-authored-by: Sertaç Özercan <852750+sozercan@users.noreply.github.com>
Co-authored-by: Rita Zhang <rita.z.zhang@gmail.com>
Signed-off-by: Wyatt Fry <wyattfry@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

8 participants