Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions templates/_helpers.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,8 @@ if this chart gets DeleteSpokeChildApps, it will set deletePattern to DeleteChil
{{- else }}
value: {{ $.Values.global.deletePattern }}
{{- end }}
- name: global.gitOpsSubNamespace
value: {{ $.Values.global.gitOpsSubNamespace }}
{{- end }} {{- /*acm.app.policies.helmparameters */}}

{{- define "acm.app.clusterSelector" -}}
Expand Down
20 changes: 17 additions & 3 deletions templates/policies/ocp-gitops-policy.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -26,16 +26,30 @@ spec:
include:
- default
object-templates:
{{- if $.Values.global.gitOpsSubNamespace }}
- complianceType: mustonlyhave
objectDefinition:
apiVersion: v1
kind: Namespace
metadata:
name: {{ $.Values.global.gitOpsSubNamespace }}
- complianceType: mustonlyhave
objectDefinition:
apiVersion: operators.coreos.com/v1
kind: OperatorGroup
metadata:
name: {{ $.Values.global.gitOpsSubNamespace }}-operator-group
namespace: {{ $.Values.global.gitOpsSubNamespace }}
spec:
{{- end }}
- complianceType: mustonlyhave
objectDefinition:
# This is an auto-generated file. DO NOT EDIT
apiVersion: operators.coreos.com/v1alpha1
kind: Subscription
metadata:
name: openshift-gitops-operator
namespace: openshift-operators
labels:
operators.coreos.com/openshift-gitops-operator.openshift-operators: ''
namespace: {{ if $.Values.global.gitOpsSubNamespace }}{{ $.Values.global.gitOpsSubNamespace }}{{ else }}openshift-operators{{ end }}
spec:
channel: {{- if and $.Values.acm.spokeGitops $.Values.acm.spokeGitops.channel }} {{ $.Values.acm.spokeGitops.channel }}{{- else if and $.Values.main $.Values.main.gitops $.Values.main.gitops.channel }} {{ $.Values.main.gitops.channel }}{{- else }} gitops-1.18{{- end }}
installPlanApproval: Automatic
Expand Down
4 changes: 2 additions & 2 deletions tests/application_policy_test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -209,7 +209,7 @@ tests:
value: group-one-clustergroup-policy
lengthEqual:
path: spec.policy-templates[0].objectDefinition.spec.object-templates[0].objectDefinition.spec.sources[1].helm.parameters
count: 19 # 17 (in the helper) +2 (1 override, and 1 clusterGroup.name)
count: 20 # 17 (in the helper) +3 (1 override, and 1 clusterGroup.name)
- documentSelector:
path: metadata.name
value: group-one-clustergroup-policy
Expand Down Expand Up @@ -244,7 +244,7 @@ tests:
value: group-one-clustergroup-policy
lengthEqual:
path: spec.policy-templates[0].objectDefinition.spec.object-templates[0].objectDefinition.spec.sources[1].helm.parameters
count: 19 # 17 (in the helper) +2 (1 override, and 1 clusterGroup.name)
count: 20 # 17 (in the helper) +3 (1 override, and 1 clusterGroup.name)
- documentSelector:
path: metadata.name
value: group-one-clustergroup-policy
Expand Down
138 changes: 138 additions & 0 deletions tests/gitops_sub_namespace_test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,138 @@
suite: Test gitOpsSubNamespace in gitops policy
templates:
- templates/policies/ocp-gitops-policy.yaml
release:
name: release-test
tests:
- it: should default subscription namespace to openshift-operators when gitOpsSubNamespace is not set
set:
clusterGroup:
managedClusterGroups:
region-one:
name: region-one
acmlabels:
- name: clusterGroup
value: region-one
asserts:
- documentSelector:
path: metadata.name
value: region-one-gitops-policy
isKind:
of: Policy
- documentSelector:
path: metadata.name
value: region-one-gitops-policy
matchRegex:
path: spec.policy-templates[0].objectDefinition.spec.object-templates[0].objectDefinition.metadata.namespace
pattern: ^openshift-operators$

- it: should not create namespace or operatorgroup object-templates when gitOpsSubNamespace is not set
set:
clusterGroup:
managedClusterGroups:
region-one:
name: region-one
acmlabels:
- name: clusterGroup
value: region-one
asserts:
- documentSelector:
path: metadata.name
value: region-one-gitops-policy
equal:
path: spec.policy-templates[0].objectDefinition.spec.object-templates[0].objectDefinition.kind
value: Subscription

- it: should default subscription namespace to openshift-operators when gitOpsSubNamespace is empty
set:
global:
gitOpsSubNamespace: ""
clusterGroup:
managedClusterGroups:
region-one:
name: region-one
acmlabels:
- name: clusterGroup
value: region-one
asserts:
- documentSelector:
path: metadata.name
value: region-one-gitops-policy
matchRegex:
path: spec.policy-templates[0].objectDefinition.spec.object-templates[0].objectDefinition.metadata.namespace
pattern: ^openshift-operators$

- it: should create namespace object-template when gitOpsSubNamespace is set
set:
global:
gitOpsSubNamespace: my-gitops-ns
clusterGroup:
managedClusterGroups:
region-one:
name: region-one
acmlabels:
- name: clusterGroup
value: region-one
asserts:
- documentSelector:
path: metadata.name
value: region-one-gitops-policy
equal:
path: spec.policy-templates[0].objectDefinition.spec.object-templates[0].objectDefinition.kind
value: Namespace
- documentSelector:
path: metadata.name
value: region-one-gitops-policy
equal:
path: spec.policy-templates[0].objectDefinition.spec.object-templates[0].objectDefinition.metadata.name
value: my-gitops-ns

- it: should create operatorgroup object-template when gitOpsSubNamespace is set
set:
global:
gitOpsSubNamespace: my-gitops-ns
clusterGroup:
managedClusterGroups:
region-one:
name: region-one
acmlabels:
- name: clusterGroup
value: region-one
asserts:
- documentSelector:
path: metadata.name
value: region-one-gitops-policy
equal:
path: spec.policy-templates[0].objectDefinition.spec.object-templates[1].objectDefinition.kind
value: OperatorGroup
- documentSelector:
path: metadata.name
value: region-one-gitops-policy
equal:
path: spec.policy-templates[0].objectDefinition.spec.object-templates[1].objectDefinition.metadata.name
value: my-gitops-ns-operator-group
- documentSelector:
path: metadata.name
value: region-one-gitops-policy
equal:
path: spec.policy-templates[0].objectDefinition.spec.object-templates[1].objectDefinition.metadata.namespace
value: my-gitops-ns

- it: should use gitOpsSubNamespace as subscription namespace when set
set:
global:
gitOpsSubNamespace: my-gitops-ns
clusterGroup:
managedClusterGroups:
region-one:
name: region-one
acmlabels:
- name: clusterGroup
value: region-one
asserts:
- documentSelector:
path: metadata.name
value: region-one-gitops-policy
matchRegex:
path: spec.policy-templates[0].objectDefinition.spec.object-templates[2].objectDefinition.metadata.namespace
pattern: ^my-gitops-ns$
Loading