SREP-11 - Enforce informing mode on new investigations
This PR adds an informing-only status to investigations' write actions. Informing mode is set to true upon investigation creation from boilerplate. It also adds a script to test the validity of RBAC permissions (i.e write operations are restricted on informing-mode investigations)
The PR also removes an unused function in insightsoperatordown.go, and redundant info of the removed deploy directory (see #427).
Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all
Codecov Report
Attention: Patch coverage is 12.19512% with 36 lines in your changes missing coverage. Please review.
Project coverage is 31.63%. Comparing base (
656441f) to head (0e29f2d).
Additional details and impacted files
@@ Coverage Diff @@
## main #432 +/- ##
==========================================
- Coverage 31.92% 31.63% -0.30%
==========================================
Files 36 36
Lines 2487 2510 +23
==========================================
Hits 794 794
- Misses 1632 1655 +23
Partials 61 61
| Files with missing lines | Coverage Δ | |
|---|---|---|
| ...tions/insightsoperatordown/insightsoperatordown.go | 8.45% <0.00%> (ø) |
|
| ...tigations/apierrorbudgetburn/apierrorbudgetburn.go | 0.00% <0.00%> (ø) |
|
| ...nnotretrieveupdatessre/cannotretrieveupdatessre.go | 26.22% <0.00%> (-0.89%) |
:arrow_down: |
| ...e/machinehealthcheckunterminatedshortcircuitsre.go | 49.71% <0.00%> (-0.59%) |
:arrow_down: |
| ...cfailureover4hr/upgradeconfigsyncfailureover4hr.go | 19.71% <0.00%> (-0.58%) |
:arrow_down: |
| pkg/investigations/ccam/ccam.go | 36.58% <0.00%> (-1.88%) |
:arrow_down: |
| ...rrorbudgetburn/clustermonitoringerrorbudgetburn.go | 10.86% <0.00%> (-0.50%) |
:arrow_down: |
| pkg/investigations/chgm/chgm.go | 60.37% <20.00%> (-0.58%) |
:arrow_down: |
| pkg/ocm/mock/ocmmock.go | 42.66% <50.00%> (ø) |
|
| pkg/investigations/cpd/cpd.go | 0.00% <0.00%> (ø) |
|
| ... and 1 more |
:rocket: New features to boost your workflow:
- :snowflake: Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
/retest
/retest
@typeid Thanks for the review :slightly_smiling_face: Great points, a lot of this does overlap with reviews. ~~Do we think it's worth looking into implementing guidelines elsewhere (e.g. PR template akin to MR in App-interface)?~~ -> This has now been added in #471 For kube-api, I wrote a short make target script to "lint" investigations and their corresponding RBAC to ensure investigations set to informing cannot conduct write operations. Let me know your thoughts on this/if it's a sufficient solution. Thanks again!
[APPROVALNOTIFIER] This PR is APPROVED
This pull-request has been approved by: MateSaary
The full list of commands accepted by this bot can be found here.
The pull request process is described here
- ~~OWNERS~~ [MateSaary]
Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment
Linting the RBAC for write permissions is great!
@MateSaary: all tests passed!
Full PR test history. Your PR dashboard.
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.
Closing PR following discussion https://redhat-internal.slack.com/archives/C081RTBAPA9/p1751354368278599