smolnar82 opened a new pull request, #1434: URL: https://github.com/apache/knox/pull/1434
[KNOX-3493](https://issues.apache.org/jira/browse/KNOX-3493) - k8s delegation E2E: policy-enforced SA actor-token delegation and headless requested_subject exchange ## What changes were proposed in this pull request? Extends the k8s ServiceAccount delegation harness (`test_k8s_delegation.py`) with the two policy-enforced RFC 8693 scenarios that were out of scope for the sibling harness ticket: - **AC4 — interactive delegation:** a k3s SA projected `actor_token` acting on behalf of a Knox-user `subject_token`. Succeeds (HTTP 200) under a matching `K8S_SA` delegation policy and is rejected (HTTP 400 `invalid_request`, "rejected by policy") when the policy authorizes a different subject. - **AC5 — headless delegation:** an SA `subject_token` + `requested_subject`. Succeeds when the policy sets `allowHeadlessExchange=true` and is rejected when it does not. Policies are seeded per-test through the KNOXIDF_ADMIN delegation-policy REST API via the existing `DelegationPolicyAdmin` helper; the SA actor key (`K8S_SA`, `<iss>:<ns>:<sa-name>`) is derived from the token itself, mirroring `ActorIdentity.fromJwt`. The exchange runs on the delegation-enabled `knoxidf-token-delegation-policy` topology; success paths assert the minted token records the impersonation (`sub` = impersonated user, nested `act.sub` = SA identity, requested resource as `aud`). Issuer registration and seeded policies are bracketed with `addCleanup`, so each test is self-contained regardless of run order. No existing test or `delegation_helpers.py` was modified. ## How was this patch tested? - `pylint *.py` (as CI runs it) — 10.00/10, no new findings; `py_compile` clean. - Runs in CI in the k8s-delegation Docker Compose stack (real k3s cluster) alongside the existing same-subject and negative-path tests: ``` tests-1 | ------------------------------------ tests-1 | Your code has been rated at 10.00/10 tests-1 | tests-1 | Waiting for knox... tests-1 | ============================= test session starts ============================== tests-1 | platform linux -- Python 3.10.20, pytest-9.0.3, pluggy-1.6.0 tests-1 | rootdir: /tests tests-1 | plugins: platformdirs-4.12.1 tests-1 | collected 124 items tests-1 | tests-1 | test_clientid_credentials.py ....... [ 5%] tests-1 | test_delegation.py ......... [ 12%] tests-1 | test_health.py ..... [ 16%] tests-1 | test_k8s_delegation.py ....... [ 22%] tests-1 | test_k8s_serviceaccount_validation.py ...... [ 27%] tests-1 | test_knox_admin_path_traversal.py ... [ 29%] tests-1 | test_knox_auth_service_and_ldap.py ... [ 32%] tests-1 | test_knox_configs.py . [ 33%] tests-1 | test_knox_ldap_cache.py ... [ 35%] tests-1 | test_knox_ldap_injection.py ....... [ 41%] tests-1 | test_knox_ldap_proxy_search.py ......... [ 48%] tests-1 | test_knoxauth_preauth_and_paths.py ...... [ 53%] tests-1 | test_knoxauth_token_forwarding.py ........... [ 62%] tests-1 | test_knoxidf.py ....... [ 67%] tests-1 | test_knoxsso_redirect.py . [ 68%] tests-1 | test_knoxtoken_jwt.py .................... [ 84%] tests-1 | test_remote_auth.py ... [ 87%] tests-1 | test_remoteauth_extauthz_additional_path.py .... [ 90%] tests-1 | test_token_exchange.py ............ [100%] tests-1 | tests-1 | =============================== warnings summary =============================== ... tests-1 | -- Docs: https://docs.pytest.org/en/stable/how-to/capture-warnings.html tests-1 | ----------------- generated xml file: /tests/test-results.xml ------------------ tests-1 | ====================== 124 passed, 116 warnings in 31.39s ====================== ``` ## Integration Tests This PR is integration tests only - the four scenarios are added to [`.github/workflows/tests/test_k8s_delegation.py`](.github/workflows/tests/test_k8s_delegation.py), reusing the compose overlay, CA/issuer export, and KNOXIDF_ADMIN topology delivered by the sibling harness ticket. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
