Comments (6)
Could anyone explain current expected dev flow? I can create src.rego and src_test.rego and run opa test src.rego src_test.rego
to test it. But how can i test constraint template?
from gatekeeper-library.
That's a good question and one we've started working on answering!
The draft design for building a constraint template build/test workflow is here:
https://docs.google.com/document/d/1uQlkIBQcgNNyth8o9ufYaVSfUq_JLJGy9fcuW3VB7vU/edit
Definitely interested in feedback and help implementing :)
from gatekeeper-library.
This may be complicated by us not knowing where the library will actually live in the long term. Moving them out of this Repo would be harder if we rely on them for e2e tests.
from gatekeeper-library.
While they're here though it would be good to have confidence that they all work as expected. And presumably the tests could move with the library when it finds its new home, with a bit of refactoring.
from gatekeeper-library.
My concern is flakiness. Currently we are running into timeouts b/c presumably the VM Travis CI provides has low enough resources that it takes a while for initialization to happen. Higher #s of flaky tests => lower probability of a good run even with valid code.
I'd like to keep the e2e tests in the GK project focused on whether GK itself works. Unit tests should be sufficient for the library. Plus they'd have zero flakiness as they wouldn't rely on a live service.
In order to have unit tests, however, we need a unit test framework, which implies that the library repo has been implemented.
from gatekeeper-library.
This issue/PR has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.
from gatekeeper-library.
Related Issues (20)
- poddisruptionbudget constraint template query HOT 1
- gatekeeper and PSS HOT 4
- Extend PodDisruptionPolicy to Include MinAvailable and MaxAvailable Percentages HOT 1
- Migrate require-sync CI to future gatekeeper 3.13 requires-sync-data unmarshal function
- Apply constraints for immutable fields only to CREATE operations HOT 10
- enforcementAction: deny is not respected when creating/changing to an incorrect PDB HOT 1
- Update Privileged Container Policy HOT 3
- Host networking constraint template does not respect exempt images HOT 2
- Refresh the content in Artifact-hub whenever any of the files within the policy are modified HOT 2
- docs: explicitly call out samples are provided as an example
- add cel-based policies HOT 5
- Match everything in a constraint HOT 2
- Docs exclude kind: AdmissionReview
- Problem with creating a mutation for deployments HOT 4
- replicalimits unit tests do not include checks for Scale resources HOT 4
- Consider validating pod generic ephemerals in K8sStorageClass HOT 2
- Consolidating Kubernetes PSP-related ConstraintTemplates into a Single Template for Streamlined Migration HOT 1
- bump mutate assign api version from alpha to v1
- Website generator appears to only retain the final mutation sample per directory HOT 2
- Any interest in policies/constraints that apply to custom resources? HOT 6
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from gatekeeper-library.