Repository navigation
Add --validate-config so the image can check its own config - #68
Merged
Merged
Conversation
manifest-validator is growing a check that runs an application's own image over the ConfigMap a manifest tree carries, because the application is the only thing that can say whether its config means anything. idcat already had the deciding code — Config::load then validate, both pure and offline — with no way to reach it but starting the service. --disable-auth composes with the flag rather than being ignored under it: a config that only validates with auth disabled must not pass a check run without.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
manifest-validator is growing a check that runs an application's own image over the ConfigMap a manifest tree carries, on the grounds that the application is the only thing that can say whether its config means anything. idcat already had the deciding code —
Config::loadthenvalidate, both pure and offline — with no way to reach it but starting the service.--validate-configloads the config, validates it and exits: 0 if valid, non-zero with the reason otherwise. No socket is bound, KMS is not reached and GitHub is not contacted. The early return sits ahead of the TLS setup, so nothing is initialised either.--disable-authcomposes with it rather than being ignored under it, because a config that is only valid with auth disabled must not pass a check run without it. That is one of the four tests.Two things worth a reviewer's eye:
permissionstable on[[installation-policy]], nor[[owner-policy]].Config::validateenforces both; these tests just don't exercise them.cargo test --workspace(85 tests),cargo fmt --checkandcargo clippy --workspace --all-targetsall pass locally.