Skip to content

Commit a34247b

Browse files
Merge branch 'main' into feat/clarify-subject-in-scs-0004
Signed-off-by: Marvin Frommhold <depressiveRobot@users.noreply.github.com>
2 parents d73befa + 18e6d92 commit a34247b

28 files changed

Lines changed: 674 additions & 63 deletions

.zuul.d/secure.yaml

Lines changed: 95 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -101,7 +101,7 @@
101101
gY6QHocYpATL46iLkv97QANNUxTdxL7hQjdl/tf3TAHjCclmxdWhBJdvCJN/1xCM6EgVp
102102
NykBYxJ+kxSmkcFCSdUM8Td75bA/UzkPCdix1reJMdEAxTE9fC55XQ/liTLlGquQDnZty
103103
VLDH7x3ZJcxZsvqKR6vNbYYzJvDPTBYpHrhD7kx3ubyO9KX+SzZ+Dfhe9M8T8U=
104-
focis_ac_id: !encrypted/pkcs1-oaep
104+
cah_dd8a_ac_id: !encrypted/pkcs1-oaep
105105
- KB/tDE/a07eU+xtwor1iLxhvRdA/6bgkZn2aCPvkYtKKoVmT6sXpfRl1t319WqZRIRkoh
106106
GK0d9KMJkVT+Q5sbZiSxMD24yMBvwaImIBG6OCzxjyklqal1SOt6CLx4q/uGoGl7QrPOM
107107
WcRoluG1FCoDeUewgaZ50TQD0TQ8YGxuhRZi6s8KldDrYVkB/9HBUmwNhgd2LhExmNbtR
@@ -112,7 +112,7 @@
112112
YbdI4KBz6CcfrNdtut9XlmNLT91emT9ayC+XDqBypksHXHcypuqoOHMQUdjSPtXDLsI//
113113
dsSRxDL+4TtWaVovPAxaLGsiVohsoCEdAxBmYxbkA2DNYdOMf6glu7O4wMtEIjaBdzdfP
114114
CKfkOiwdCjtq++Ofn/C+3zI+2H+58TosQdCXcYIGmyKw5WSN7/sCosWDUtcsq4=
115-
focis_ac_secret: !encrypted/pkcs1-oaep
115+
cah_dd8a_ac_secret: !encrypted/pkcs1-oaep
116116
- E8fpHXVmMa7ptAndyV8fqgC6tmGL9qmtpI10q1Yh6Qo0iIt09HNl8aZLtupmavTqYJg+D
117117
7BI3ziTG4PNfc6MK0rvsQE/jGCf/XGW7yyfrmcvok+8mwD7foya5gEDLvbxFuIUopdTEt
118118
Wk+5qLHNv87fKtQVGoda1qZXQ2ZjEw3sLv5eENLEft+u3XZnPLMVJ3p9ZGK0mvBcIfAlk
@@ -364,3 +364,96 @@
364364
uUgvW2Lghmg0+upQ1OfAV24lRryyUcpSYZ6yfohTgJsIMdy7r/Hn5GDnpZn2Um8rHkWxC
365365
rk7h2aWsD5IifYyt43ZHZdEdBX99NW+TMawXNZRevlmjoqgR4RGjo0Hxi4zSaqkNPHm/T
366366
YJcPPaJvKONZzrL3d+AWnhp6x/wi2uOBTFkrg8VmnZDiFf5YCZu/XMHYT5cjd0=
367+
noris_api_server: !encrypted/pkcs1-oaep
368+
- s9igorN8BJsXlQiQ0UUl038/8kw2qNO5Uf1vVTctedulJfWy+vSYBe8L7r+AVfaJ5c1vL
369+
2Fa91q00QQL0k6BV08WJYiK5leSWcbP7mYUveysUX4itDLo9xIYMCicNKW2UugNFzG2pE
370+
+h7zmoTuZlnE/25ajGQt83XLn3G24pUW+S5mWat7wC37rZOGpJ4SVS/XiIkFDJwzrvR3Y
371+
onZ3XdewFHybT6fa3UdVLhd1Wg2SFmyAJLkLCkVtr7c9GdUyl6ZBIYMqAlCKHJODp3Irg
372+
pwPGJo3RZJ9y+aKrRmrNM8S/clzBh3v/ANIyOSMMGQ0cZqmHi+2DstE8U+FQzrJWZVQCn
373+
mjU5S4TqIJfjopvliJjHsvjk5vRHCVPTw+kCRO2RYy8WS7mzaY7KQxF0a978KGewGVCE4
374+
mwaIz97YwCRl+YBPpjLArrhquG/lScs+vtevccaigJdlHp2tFiTfvNg66dsCmr3o1DJGY
375+
2bBWW6xV6lh+gtSEPXk6xqinsKkK/b822minK+bFUgtjrhB/GyuPgbpl5SRfq1n/RoTR4
376+
KwCKxn+wHBuQ2Fm/v6ECroUjV6XwIh5vPMsFCzy2zLL20xnZx9KRJpmsi6JEVhkT9zTJZ
377+
AoQagaWgkhNywrFo1orKqRefZ+hrqHXTRbSZ+StGjpmvjxkDkU883+1qfIqYzE=
378+
noris_ca_data: !encrypted/pkcs1-oaep
379+
- PF9wdJf+bvxM2fHL7QhRWFjumyBa+sJxfIp17ThsbPB4k9GHIlVWAhONHx3QjVUYpbk8Q
380+
SKQKMa751bdZETTlWtZRg2KuzZ9z/H2tdhe+mvVliZ+xq2LewU90KibxSfk1lhhXCwJnX
381+
SpUZovtouWEZGUMJjtGyIs0573dth0E71EHGCDTUiPctAzCVAwLom5C09rC+Y8S7av4s6
382+
Mv1TKOD62gloXRzisvBQljhDgYu7QM2e+8QhR1nlFP3TxbgSuJ7GJs6eK/YCZecfkmXm5
383+
ed2iQL5Knq9X+DEnIk6p6hWJzuhAb6526kiSO+yCTUMF7wnDxanJ3Eu07PdqmwGp+f0Qe
384+
5Koix0o5NxCPs6ghCs6rmSyjzW1unCfuRegXx512d/vwMI4Wl2INz2p4dNng4gR1gNOSB
385+
9nOXscFn9yelq0HFFWz5C77Y0EDpUN6fYnjdBtDa6HqcUsh5lmkuLQ98MuazcoYqT0w2w
386+
kv1oaWFGHeMAmfPdBu/u8oNT3u9AaV5uf38TAJahYOye+Lt8wLbRGC1pvx9gCxpn4CgX+
387+
UyMKaSLu0BZJEAOzbm/GEWBXpI8DiiQ4d/drtg/ihXwG1MMQZfKipRRnw5pUieypJ21Ff
388+
WlIU3rjeZEr1c0HhEMUTGVM/EM41xU5jpUB2Ug3oWDcvV/FRss4dITn1un9/LM=
389+
- YQVORY0vdHLj+bMqoJbPXT+U+B45x/7nk7JzkkS9Be2H08GLa3PPxEu2LSkZCgjWSShug
390+
1Y2ji/hC3DDye3h5NvdWe4M9asdMH47L1SWmi5evUI8+PfdT20noBcGgPym9xaJujgVCo
391+
S/ufP8xOIiM9uMq6g77qmscNQmCk48TF1r7DyOVG0YZ2Pg+sQvrkxsS1DtCtNolUidOQK
392+
WRfSxEdWcJlL3Om8JzrxmuhdmJeDV/KTw/93m0t+qrmE1qJCbkqS0pFXeE0jN1J/diIAD
393+
LoMkOq/vEWQXWb+yUsuKoaZUnntDXF23G23cF6o+aYeIFwyn5fkMotel/zNySMEzZQWM8
394+
w1jKpIoguUPOYMQMoo+wKoNTjD8fS7juDMSRG0lPgwvO3T8CEUuwOAcwbLTBOyl3foDoh
395+
PmYOLp7HNwlgJYM6YdFzYkASVNRz7+xIaQhQITb9vNlz8wEC8Pt4NlXQ+6MwJ/TreGTiK
396+
3IK8dq52KTJWC/mPfjyZx4tlSa3nblHbQLp+oMxpsIF6XtvaieInH5UpV+i/ES2K/lScm
397+
WUtPdbZA+wUVIClhYsLoLgYY0t5NdNxiikgB4FCMKHCIUpT2jOoJqgO54ztCcv7ehuBmE
398+
ceuWQJxA6J4xK2a17KNOnLvLFvG8rFA7jexWeb1/9rTrzkKmlVemTRgH1oclf8=
399+
- KqXIEBGifQyAl4EpKi0u6kFIIAcsOxkOL3J5Np/HkqZK2RmW89XoZMsuUEd51L5CECBTd
400+
48K3aJhk59I9mg+vH9HTYM/3tdEeMjvWXkvglNJl2hEZutYKqRQGXhK/ekdp3ihTRW09k
401+
eElT24LjiOsDZXOZkSeapvR3CWUFfaDZnLojUGggXDCHmyMmvz1Efg6gw4OfQDpa8awWc
402+
o7gcLwv5KBLTk+0dEkmY448Ou2agcPwbWKTzXm76HV1/gD1OWqh7B04d796szHGr1dH3X
403+
erlCMgJYuYFkxWzDJlSj3SIRPqqLie5aH0lLZqnFd8EzAbnQXgKcV9GcifR9A3um01U5q
404+
ngrGx1ARfWPx7TZpHgM7J2akenVHN2lhSJTnG2vxzyH8TfmHTfEM4xZB0NI31vKJ1jw2K
405+
pupavVeDcOUsWvbj+0hMiklQuJ6jJKurEzHY0cBMUKauL48j3c3IdLA7svbHUWi7pA7R+
406+
hVSPef1swlnwJUY3ZpJnf4DMbFLysZHyZsaA2ErCKvg5CfrtYXPrbsRIi2eovp2C+i9Rc
407+
n1ijjWgqWdolN3neasQKwxfpZP9KHFodEsaVBarDs4FdMI6hkASYI7P10fMd0S9GMaY18
408+
F33u9MC9ZCOEQgS2OTWX3GVXQ9sFQP45kchaov4TSrgsnMpS6t5yHrfPPJrkTs=
409+
- Dw3GFRbVvRauxXqZyQbly9hzYZlSt64TwnnG3qgAU1EWW77msHWEFUNfYlFx4aJO4Chkt
410+
vhQ+fuYXX5ZowU4MFAtd3vPTXAtOA8dJ+lAzfcnN4sc0dg7BsKjjPRHbcA/CqCdb1cMfv
411+
vyJCiEYpf80Wn0hfh9VifSgEt5VI3UyXrwCzBWDXcTR6qzFdKvQ0KpLKnqNRgFtgPozZu
412+
1quy8gaDR+OY+lGrU3x0IBRyxpK9UX5MSFRpk+81JCAuPBWxRtUu5vOi+BE5auv9Yd7nq
413+
AsXi4G2FzwobQES0Y6fQgJlr1ii8WpS7m/9FsXubeTEKJi6aa+MkUYEWzObJYCbbQ75vg
414+
eyquTcLKiGuKPQM+Nxlo4BjD5iVlRTC+5DEk+5qaJwjqmnf04wdlch2UtnNne1I1jshxC
415+
H4FD4wfAIDBwkAMgol8UKO5sDp+uWn14hGF7KNoaRFfCaY89D0rOL/oxBxjzSq013hiBb
416+
yCrtFkFLkcvk75G0kbIeQcQQIOYOWaypNN6aS/6+eRbhG751XTGN11qkYwcnBMCvGyXc3
417+
sK4k3Fp7ewsIKsCsdJdwbsX8qpDLN6Mss0d4ftkkti20jw2ey4ymJrfPNcjq8SPay3YTG
418+
yOCRZJKGEhbq4jht34WpLUQz3bbKmeN1LRkST+vitAEI2rkbedIE7BtURbL444=
419+
- HdgKO7AY2aEWPIhizhSNKaTs1nnXwLCavzSJmBVk+nitwOdf2YD1SNfWOUGGIhzbIKAmy
420+
28u46hML/Z1zfylAWAEgig08c++43IV/JIgryGSJHNTjM40laA/KH4NvjZ7ZdZN5DURVN
421+
45iP01F5FwRtzy+aJtfrkIt8Rrpi3Bi+tiXIcGZrfJodhcmCbDjLkWfwPvyPVpAkr5rSP
422+
N2nijJL2jb5jPND0d3xHY3YQCSSSUDg4o9CYRoL60O432J5Jx42XAYQzHqdT+qr8vQe9P
423+
E2Ye+xYFzinP4gldpLg/8n4/CbfxND7bSkBopwBjZKdgACCRw7/ratFzXiUTQJsdBPJtR
424+
XA0f2O+InI0WCU0dIyQCollczRcIR15YQXVnrD5XrIjYBfQTJTwtD5eCKgO1/DyHTfbK3
425+
edZXuArEG7HrHzpo/di5t/0c3CNvOkpWjmoF4VW0jwIOhb0mOytBK+LEtalgiGIN+fLqC
426+
Iek4Bf2Vsh3IcXe4WPgooBm9y0wejEmRVwApwcsArxILaa/VUJQO6zVeaLKTGTBNVKolm
427+
pP2x748l+uFWMUGjmzao4OTyfjBKx2cXNqe/OmIyscCr7lDZkipFdDTWrR1p/FLHQiCIc
428+
jBsgwuDMuVcVslw+cy3CPiPKZNWSJLop5cIvCEzGPBzXto9YTVQwPwnmcl+Rnc=
429+
noris_token: !encrypted/pkcs1-oaep
430+
- o3ipramOzntQWHvfA11URFQfJa1z8ycIH8ax1GFBDkYxwlvLcTnzruleYjP5glU3v7cLK
431+
ycjGb0BvhEKy72cmTKrI7NnbL88VKngEGhkCG8hLr5cy8cfLvXHHERul2CiTGRPwYf5gy
432+
JTAPNCohIJRcKIw93lRiMDGLDIOLf+EH1Y0KlTXalMf52q4TRq6EMEmkxPQf6JZ44zSUt
433+
DbqCac79RGSIji7OJdSlxl/eZotl8cGqJQGQDxZRtZrQghmeAqMGsf2o9wLMqmrX+qzAv
434+
Xwy466KgXSGDqJCjCbEvPP6qLt6MEyECOrAOdo2ZxssoYNAY7gTSnYRInXhZKzA/M/V18
435+
e49sJcLNzT0Y9K0SQN6dLMwA6Dp+R3+YgM0eqfv2/Xa2Su8FfKSZ3PRI7fdg1dWS+FlgI
436+
rKPwV0J245Jn+GdokGOvxZHN6TtAjkqJiodddxIC0a1YryuYvNVUeDjV02hoPBbQIwa0k
437+
lfqaPrPJZZ3CN55tJzZK2SKQRRS7BM1mX5GbzysVaGQEs7dfhlmzusQ5GBgebTXstbCJz
438+
S7uW/VznvgsLmehN1EsnquTqfGJys653FHiq0SM6gMwGcdFhs3Xs22IN25SEDx8TdUj9X
439+
dk68afz9FX4LTNKn+zQhB2Q/zAbLpG22Pap/695R7MP+YkdzdAtnDjjt80q7lg=
440+
- WADyzPT2qxjfGcL/5+sPnIX+Rk3CZ5kBfAN5NryolzSNdsqM4k53ZSHeCWlqOY4C51MNy
441+
cdMGiTKW6264wdoBJD4D7VvERwsO5x9SOJg0nm0MK5l32htOmDtKU19JnvPT0bB+mukwv
442+
JedmI9SvyzUou3S+a/ALOj8+r84Ob5gK9622D2un4icGhYPsNomlGmOgjV0aZWOjPOcpc
443+
VhJhWUMOYRl9dJPM630DAgB5Vx3EiLa7V573VizuX4Zp3+b+gJXDenyaUEdlvYlNTDTgJ
444+
pMf68UQ57pm+vemw4bGkeyfB2FLdabaNh/2gcq9jjc/5VqoNbU+zerXQFjOPUvQPIdbVr
445+
jSdybBn3u2iXDLnsUGzG9FQ4kSdWTtJOOc8McwzsNCS9vJK49sJmw33WYlS/5VMw7mDiB
446+
dwtvJkxKcu7XdiwfsMCpI14X+hjfaUMAbQ53duCYhb+CA+S7H9gbRGIHnOycoQ0NW04Jc
447+
IJgaHr1pDS2FDeV6pq8evyDH5oAa5UuOS88a9KSArxicSPUnLj0YK5rz/RhUcS2rOFXZJ
448+
SlvEpLMlzBmqN++LOUpG12aAD4ADXAAfE+QJEVDXW6/GmVksaJRZe0/7xnIlHU4gNydcd
449+
e8RpZIBTn6GwW0S52mWnUpPtA+38I4dTPjNhGm9auYM2CVAHLeWlrYRWr3CyWg=
450+
- LOJeDQtl2MKPcYyrJGqMSq/ElqU0SwCFQQsMXC3SSRcvYVWEeGn3zL6t22Xk6B1Do6zsH
451+
7MU636sMsZ2uMchiP3IVS827oExv9vlLufmOdM0dOaQbCN1s4amHEjk0dOa7LOpebwDZj
452+
E2cz+tdSQTTx3c237oQO5cfwxUHwwAIPUzhFAAAuVLxOyUqS10vFrKPskqH1LfYNLNUMK
453+
9J7CRgcUAPfzWN2EowZj0IpQL/wK3vy02KGXl9nYa24DGM7S3ZcnwjM4aNlgv5h3FQruq
454+
kR9VMljtHtEhXh7zECa40MepsiJLYu2P7R34tzHJ9Z6fjlrVkwy8Zrn9Rurqu9ZyA0+zQ
455+
BsTBGBJXbxhhpgJ8014VmWBSm1nB55vCEGa9V1pnSKBgEPRlQyo5vAwIyPtAmjXmTqiol
456+
bqmRI0V+wzJpmd94Xhxo2QlKZhFXOmNo6PH93wAx0fCqm/V/96mhFJYvgPmtGj93rNMLu
457+
pmn42PxOsmXVXHYsRNlgHGQzrvTPSnC4zfQYr2fG3hh81+vbfQawpQ4eeyKNdcqTjubhF
458+
/Lt6+yMJMB7AUVpwXkI7cMmf+QXbDnnE6eX0UBosTM6MjdA/zhkjJ6PK9E0FnngW4HRDZ
459+
eAiVSQiN4CSa9bylrwLhvarAEhR+5avRv4yTurgAYe6I6Gh05pBPCgTXmCNxPU=
Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
---
2+
title: CNCF Kubernetes conformance
3+
type: Standard
4+
status: Draft
5+
track: KaaS
6+
description: |
7+
SCS-0201 describes conformance testing of Kubernetes environments using the upstream CNCF Kubernetes e2e suite.
8+
---
9+
10+
## Introduction
11+
12+
Interoperability, consistency, and traceability play a crucial role in the deployment and use of a Kubernetes environment. Testing ensures this conformance across different Kubernetes environments.
13+
14+
The SCS project always intends to reuse existing standards whenever possible. For this reason, the upstream test suite of the [Certified Kubernetes Conformance Program](https://github.com/cncf/k8s-conformance) is used for conformance testing.
15+
16+
## Motivation
17+
18+
As an operator as well as an user, I want to check the conformance of a Kubernetes environment in order to ensure the interoperability, consistency, and traceability of it.
19+
20+
## Regulations
21+
22+
The conformance testing is performed as part of the [SCS compliance check suite](https://github.com/SovereignCloudStack/standards/tree/main/Tests) executing the standard set of conformance tests defined by the `[Conformance]` tag in the [Kubernetes e2e suite](https://github.com/kubernetes/kubernetes/tree/master/test/e2e). All conformance tests MUST be passed successfully.
23+
24+
We allow exceptions from the Kubernetes e2e tests if it is reasonable, e.g. [bugs in certain tests](https://github.com/SovereignCloudStack/standards/blob/74a3197d37cbfae3f8f0ed45644e6611186639da/Tests/kaas/scs-sonobuoy-config.yaml#L12). Please note that exceptions may be added and/or removed in such reasonable cases and thereby allowing the standard to be updated without the need for a new version of it. If the reason for an exception goes away, so does the exception and it will therefore be removed.
25+
26+
The exceptions are listed under the key `okToFail` in
27+
[Tests/kaas/scs-sonobuoy-config-v1.yaml](https://raw.githubusercontent.com/SovereignCloudStack/standards/main/Tests/kaas/scs-sonobuoy-config-v1.yaml).
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
---
2+
title: "CNCF Kubernetes conformance: Implementation and Testing Notes"
3+
type: Supplement
4+
track: KaaS
5+
supplements:
6+
- scs-0201-v1-cncf-conformance.md
7+
---
8+
9+
## Implementation notes
10+
11+
The actual execution of the conformance tests is performed by the [SCS compliance check suite](https://github.com/SovereignCloudStack/standards/tree/main/Tests) using [Sonobuoy](https://sonobuoy.io).
12+
13+
## Automated tests
14+
15+
The script [`run_sonobuoy.py`](https://github.com/SovereignCloudStack/standards/blob/main/Tests/kaas/sonobuoy_handler/run_sonobuoy.py) connects to an existing K8s cluster and handles both the execution of Sonobuoy and the generation of the results for a test report. See [`scs-compatible-kaas.yaml`](https://github.com/SovereignCloudStack/standards/blob/c1e9a1b761a0bb201e80d9207f4a1dd0a68ff57f/Tests/scs-compatible-kaas.yaml#L15) for the test configuration.
16+
17+
## Manual tests
18+
19+
None.

Standards/scs-0210-v2-k8s-version-policy.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -57,11 +57,12 @@ In order to keep up-to-date with the latest Kubernetes features, bug fixes and s
5757
the provided Kubernetes versions should be kept up-to-date with new upstream releases:
5858

5959
- The latest minor version MUST be provided no later than 4 months after release.
60-
- The latest patch version MUST be provided no later than 2 weeks after release.
61-
- This time period MUST be even shorter for patches that fix critical CVEs.
60+
- The latest patch version MUST be provided no later than 1 month after release.
61+
- This time period (for providing the latest patch version) MUST not be longer than
62+
2 weeks if the patch addresses critical CVEs and it is RECOMMENDED to be provided
63+
within 2 days of the release.
6264
In this context, a critical CVE is a CVE with a CVSS base score >= 8 according
6365
to the CVSS version used in the original CVE record (e.g., CVSSv3.1).
64-
It is RECOMMENDED to provide a new patch version in a 2-day time period after their release.
6566
- New versions MUST be tested before being rolled out on productive infrastructure;
6667
at least the [CNCF E2E tests][cncf-conformance] should be passed beforehand.
6768

Standards/scs-0214-v2-k8s-node-distribution.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -69,9 +69,7 @@ to provide a fault-tolerant and available Kubernetes cluster infrastructure.
6969

7070
The control plane nodes MUST be distributed over multiple physical machines.
7171
Kubernetes provides [best-practices][k8s-zones] on this topic, which are also RECOMMENDED by SCS.
72-
73-
At least one control plane instance MUST be run in each "failure zone" used for the cluster,
74-
more instances per "failure zone" are possible to provide fault-tolerance inside a zone.
72+
In particular, the control plane nodes SHOULD be distributed over multiple failure zones.
7573

7674
Worker nodes are RECOMMENDED to be distributed over multiple zones. This policy makes
7775
it OPTIONAL to provide a worker node in each "failure zone", meaning that worker nodes

Standards/scs-0214-w1-k8s-node-distribution-implementation-testing.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,11 +20,12 @@ Node distribution metadata is provided through the usage of the labels
2020
## Automated tests
2121

2222
Currently, automated testing is not readily possible because we cannot access information about
23-
the underlying host of a node (as opposed to its region and zone). Therefore, the test will only output
24-
a tentative result.
23+
the underlying host of a node (as opposed to its region and zone). Besides, access to
24+
control-plane nodes is problematic outside of a kubeadm-based setup.
2525

26-
The current implementation can be found in the script [`k8s_node_distribution_check.py`](https://github.com/SovereignCloudStack/standards/blob/main/Tests/kaas/k8s-node-distribution/k8s_node_distribution_check.py).
26+
Therefore, no automated tests are performed at this time.
2727

2828
## Manual tests
2929

30-
None.
30+
Cloud-service providers must confirm that control plane nodes are indeed distributed over
31+
multiple physical machines.

Standards/scs-0219-v1-kaas-networking.md

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -94,7 +94,3 @@ CSPs SHOULD provide a network plugin that supports or is working on support for
9494
CSPs SHOULD offer the option for a managed, `networking.k8s.io/v1`-compliant Ingress controller and a default `IngressClass` resource for this controller.
9595

9696
CSPs MAY add default networking restrictions, using either `networking.k8s.io/v1`-compliant `NetworkPolicy` resources with a policy operator, or alternatively any cluster-wide network policy extensions provided by the CNI plugin.
97-
98-
## Conformance Tests
99-
100-
Required support for network policies will be tested using the upstream e2e tests via Sonobuoy.

Standards/scs-0219-w1-kaas-networking.md

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,21 @@
11
---
2-
title: "KaaS Networking Standard: Implementation Notes"
2+
title: "KaaS Networking Standard: Implementation and Testing Notes"
33
type: Supplement
44
track: KaaS
55
supplements:
66
- scs-0219-v1-kaas-networking.md
77
---
8+
9+
## Automated tests
10+
11+
We test _full support_ for network policies using the upstream e2e tests via Sonobuoy with `--e2e-focus NetworkPolicy`.
12+
13+
All testcases of this set must be passed, with some well-founded exceptions (e.g., due to bugs), that are listed in
14+
[scs-sonobuoy-config-v1.yaml](https://raw.githubusercontent.com/SovereignCloudStack/standards/main/Tests/kaas/scs-sonobuoy-config-v1.yaml).
15+
This list will be adapted if and when new exceptions become necessary or old ones become obsolete. Since we only react
16+
to bugs and other well-founded circumstances, these exceptions are not deemed part of the normative text, and therefore
17+
these changes do not require proportionate changes in the standard document.
18+
819
## List of compliant CNI Plugins
920

1021
The Kubernetes Network Policy API working group maintains a [list of work-in-progress implementations](https://network-policy-api.sigs.k8s.io/implementations/) of the AdminNetworkPolicy and BaselineAdminNetworkPolicy resources.

Tests/config.toml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ subjects = [
2121
"artcodix",
2222
"artcodix-ro",
2323
# currently not reachable from outside: "cc-rrze",
24-
"focis",
24+
"cah-dd8a",
2525
"pco-prod1",
2626
"pco-prod2",
2727
"pco-prod3",
@@ -40,6 +40,7 @@ scopes = [
4040
"scs-compatible-kaas",
4141
]
4242
subjects = [
43+
"noris-1.34",
4344
"syself-1.33",
4445
"syself-1.34",
4546
]

Tests/iaas/scs_0123_mandatory_services/mandatory_services.py

Lines changed: 12 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -28,12 +28,19 @@ def compute_scs_0123_service_presence(services_lookup, *names):
2828

2929
def s3_conn(creds, conn):
3030
"""Return an s3 client conn"""
31-
cacert = conn.config.config.get("cacert")
32-
# TODO: Handle self-signed certs (from ca_cert in openstack config)
33-
if cacert:
34-
logger.warning(f"Trust all Certificates in S3, OpenStack uses {cacert}")
31+
cfg = conn.config.config
32+
# Take insecure/verify/cacert parameter from clouds.yaml and pass it to boto3.resource.
33+
# If insecure is False/None and verify is True/None in clouds.yaml, fall back to cacert or None.
34+
# In the latter case (None), the default boto3 behavior is applied (where config file or env
35+
# variables can still be used, and otherwise, boto3 defaults to verify=True).
36+
# Note: cacert must be used to pass the certificate; don't use verify for that; cf.
37+
# https://docs.openstack.org/openstacksdk/latest/user/config/configuration.html#ssl-settings
38+
if cfg.get("insecure") or not cfg.get("verify", True):
39+
verify = False
40+
else:
41+
verify = cfg.get("cacert")
3542
return boto3.resource(
36-
's3', endpoint_url=creds["HOST"], verify=not cacert,
43+
's3', endpoint_url=creds["HOST"], verify=verify,
3744
aws_access_key_id=creds["AK"], aws_secret_access_key=creds["SK"],
3845
)
3946

0 commit comments

Comments
 (0)