Skip to content

Commit

Permalink
Backport of Fix duplicate key in connect-inject ACL policy into relea…
Browse files Browse the repository at this point in the history
…se/1.4.x (#4435)

* backport of commit 8852d07

* backport of commit 10a2592

* backport of commit f420441

* backport of commit 9babfc1

---------

Co-authored-by: Nathan Coleman <[email protected]>
  • Loading branch information
1 parent 2c5831f commit 6451fc1
Show file tree
Hide file tree
Showing 3 changed files with 78 additions and 8 deletions.
3 changes: 3 additions & 0 deletions .changelog/4434.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect-inject: fix issue where the ACL policy for the connect-injector included the `acl = "write"` rule twice when namespaces were not enabled.
```
2 changes: 1 addition & 1 deletion control-plane/subcommand/server-acl-init/rules.go
Original file line number Diff line number Diff line change
Expand Up @@ -342,11 +342,11 @@ partition "{{ .PartitionName }}" {
}
{{- if .EnableNamespaces }}
namespace_prefix "" {
acl = "write"
{{- end }}
{{- if .EnablePartitions }}
policy = "write"
{{- end }}
acl = "write"
service_prefix "" {
policy = "write"
intentions = "write"
Expand Down
81 changes: 74 additions & 7 deletions control-plane/subcommand/server-acl-init/rules_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -960,7 +960,6 @@ func TestInjectRules(t *testing.T) {
node_prefix "" {
policy = "write"
}
acl = "write"
service_prefix "" {
policy = "write"
intentions = "write"
Expand Down Expand Up @@ -994,7 +993,30 @@ func TestInjectRules(t *testing.T) {
}`,
},
{
EnableNamespaces: true,
EnableNamespaces: false,
EnablePartitions: true,
EnablePeering: false,
PartitionName: "part-1",
Expected: `
partition "part-1" {
mesh = "write"
acl = "write"
node_prefix "" {
policy = "write"
}
policy = "write"
service_prefix "" {
policy = "write"
intentions = "write"
}
identity_prefix "" {
policy = "write"
intentions = "write"
}
}`,
},
{
EnableNamespaces: false,
EnablePartitions: false,
EnablePeering: true,
Expected: `
Expand All @@ -1005,17 +1027,14 @@ func TestInjectRules(t *testing.T) {
node_prefix "" {
policy = "write"
}
namespace_prefix "" {
acl = "write"
service_prefix "" {
policy = "write"
intentions = "write"
}
identity_prefix "" {
policy = "write"
intentions = "write"
}
}`,
}`,
},
{
EnableNamespaces: true,
Expand All @@ -1030,7 +1049,32 @@ partition "part-1" {
policy = "write"
}
namespace_prefix "" {
acl = "write"
policy = "write"
service_prefix "" {
policy = "write"
intentions = "write"
}
identity_prefix "" {
policy = "write"
intentions = "write"
}
}
}`,
},
{
EnableNamespaces: true,
EnablePartitions: false,
EnablePeering: true,
Expected: `
mesh = "write"
operator = "write"
acl = "write"
peering = "write"
node_prefix "" {
policy = "write"
}
namespace_prefix "" {
acl = "write"
service_prefix "" {
policy = "write"
Expand All @@ -1040,7 +1084,30 @@ partition "part-1" {
policy = "write"
intentions = "write"
}
}`,
},
{
EnableNamespaces: false,
EnablePartitions: true,
EnablePeering: true,
PartitionName: "part-1",
Expected: `
partition "part-1" {
mesh = "write"
acl = "write"
peering = "write"
node_prefix "" {
policy = "write"
}
policy = "write"
service_prefix "" {
policy = "write"
intentions = "write"
}
identity_prefix "" {
policy = "write"
intentions = "write"
}
}`,
},
{
Expand All @@ -1057,8 +1124,8 @@ partition "part-1" {
policy = "write"
}
namespace_prefix "" {
policy = "write"
acl = "write"
policy = "write"
service_prefix "" {
policy = "write"
intentions = "write"
Expand Down

0 comments on commit 6451fc1

Please sign in to comment.