Commit 4a61733
fix(rbac,nr-test): grant worker jobs/pods/events read; resolve NR test conflict (#71)
FIX 1 (P1, rule-27 regression live in prod): the instant-worker SA in
instant-infra could only `get apps/deployments`, so DeployStatusReconciler's
`BatchV1().Jobs(ns).Get` was denied every ~30s
(jobs.deploy_status_reconcile.job_query_failed: cannot get resource "jobs" in
API group "batch") and the rule-27 silent-build-failure detection path was
disabled in prod. Extend the existing instant-worker-deploy-reader ClusterRole
with the minimal read-only verbs the deploy status + autopsy path actually
call (no create/delete/patch/watch):
batch/jobs get ← deploy_status_reconcile.go:256 Jobs().Get
pods list ← deploy_failure_autopsy.go:208 Pods().List
pods/log get ← deploy_failure_autopsy.go:220,230 Pods().GetLogs
events list ← deploy_failure_autopsy.go:215 Events().List
ClusterRole-scoped because per-app namespaces (instant-deploy-<appID>) are
created on demand and can't be enumerated at bind time. RBAC-only — no
Deployment / secret / image change. APPLY-CHECKLIST.md gains an operator
apply + `kubectl auth can-i` verification row (this repo has no auto-apply).
FIX 2 (P2): newrelic/tests/apply.test.sh carried committed merge-conflict
markers around line 174 (from PR #14) plus stale hardcoded artifact counts
(33 dry-run entries, 26/16 JSON files), leaving the NR apply test suite
un-runnable. Resolve the markers and replace every hardcoded count with one
derived from the on-disk JSON glob (15 dashboards + 83 alerts = 98 today),
so the assertions track the registry instead of going stale again. Suite now
passes 49/0.
Local validation: kubeconform -strict (5/5 valid) + CI-equivalent yamllint
on the RBAC manifest; bash -n + full run of the NR test suite (49 passed,
0 failed).
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>1 parent 58b7bca commit 4a61733
3 files changed
Lines changed: 117 additions & 16 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
254 | 254 | | |
255 | 255 | | |
256 | 256 | | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
257 | 315 | | |
258 | 316 | | |
259 | 317 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
50 | | - | |
51 | | - | |
52 | | - | |
53 | | - | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
54 | 56 | | |
55 | 57 | | |
56 | 58 | | |
57 | | - | |
58 | | - | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
59 | 90 | | |
60 | 91 | | |
61 | 92 | | |
| |||
64 | 95 | | |
65 | 96 | | |
66 | 97 | | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
67 | 110 | | |
68 | 111 | | |
69 | 112 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
93 | 93 | | |
94 | 94 | | |
95 | 95 | | |
96 | | - | |
| 96 | + | |
97 | 97 | | |
98 | 98 | | |
99 | 99 | | |
| |||
145 | 145 | | |
146 | 146 | | |
147 | 147 | | |
148 | | - | |
149 | | - | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
150 | 152 | | |
151 | | - | |
| 153 | + | |
152 | 154 | | |
153 | 155 | | |
154 | 156 | | |
| |||
158 | 160 | | |
159 | 161 | | |
160 | 162 | | |
161 | | - | |
| 163 | + | |
162 | 164 | | |
163 | 165 | | |
164 | 166 | | |
165 | 167 | | |
166 | 168 | | |
| 169 | + | |
167 | 170 | | |
| 171 | + | |
168 | 172 | | |
169 | 173 | | |
170 | 174 | | |
171 | 175 | | |
172 | 176 | | |
173 | 177 | | |
174 | | - | |
175 | | - | |
176 | | - | |
177 | | - | |
178 | | - | |
| 178 | + | |
179 | 179 | | |
180 | 180 | | |
181 | 181 | | |
| |||
0 commit comments