From 8e55583c27a9fcf77f379d2ba21ac48836956cef Mon Sep 17 00:00:00 2001 From: Madhu Rajanna Date: Fri, 2 Sep 2022 10:33:48 +0530 Subject: [PATCH] e2e: set privileged as pod security enforcement level setting privileged as pod security enforcement level to run test on kubernetes 1.25 Signed-off-by: Madhu Rajanna (cherry picked from commit 607c654263d99d94d74d9040f85d6881fbcb4853) --- e2e/cephfs.go | 2 ++ e2e/nfs.go | 2 ++ e2e/rbd.go | 2 ++ e2e/upgrade-cephfs.go | 2 ++ e2e/upgrade-rbd.go | 2 ++ 5 files changed, 10 insertions(+) diff --git a/e2e/cephfs.go b/e2e/cephfs.go index c21a06ac5..b411a32e2 100644 --- a/e2e/cephfs.go +++ b/e2e/cephfs.go @@ -29,6 +29,7 @@ import ( clientset "k8s.io/client-go/kubernetes" "k8s.io/kubernetes/test/e2e/framework" e2elog "k8s.io/kubernetes/test/e2e/framework/log" + "k8s.io/pod-security-admission/api" ) var ( @@ -146,6 +147,7 @@ func validateSubvolumePath(f *framework.Framework, pvcName, pvcNamespace, fileSy var _ = Describe(cephfsType, func() { f := framework.NewDefaultFramework(cephfsType) + f.NamespacePodSecurityEnforceLevel = api.LevelPrivileged var c clientset.Interface // deploy CephFS CSI BeforeEach(func() { diff --git a/e2e/nfs.go b/e2e/nfs.go index 54753f677..6e884217b 100644 --- a/e2e/nfs.go +++ b/e2e/nfs.go @@ -32,6 +32,7 @@ import ( clientset "k8s.io/client-go/kubernetes" "k8s.io/kubernetes/test/e2e/framework" e2elog "k8s.io/kubernetes/test/e2e/framework/log" + "k8s.io/pod-security-admission/api" ) var ( @@ -236,6 +237,7 @@ func unmountNFSVolume(f *framework.Framework, appName, pvcName string) error { var _ = Describe("nfs", func() { f := framework.NewDefaultFramework("nfs") + f.NamespacePodSecurityEnforceLevel = api.LevelPrivileged var c clientset.Interface // deploy CephFS CSI BeforeEach(func() { diff --git a/e2e/rbd.go b/e2e/rbd.go index d611d8788..3eef190ed 100644 --- a/e2e/rbd.go +++ b/e2e/rbd.go @@ -33,6 +33,7 @@ import ( clientset "k8s.io/client-go/kubernetes" "k8s.io/kubernetes/test/e2e/framework" e2elog "k8s.io/kubernetes/test/e2e/framework/log" + "k8s.io/pod-security-admission/api" ) var ( @@ -234,6 +235,7 @@ func checkClusternameInMetadata(f *framework.Framework, ns, pool, image string) var _ = Describe("RBD", func() { f := framework.NewDefaultFramework(rbdType) + f.NamespacePodSecurityEnforceLevel = api.LevelPrivileged var c clientset.Interface var kernelRelease string // deploy RBD CSI diff --git a/e2e/upgrade-cephfs.go b/e2e/upgrade-cephfs.go index 23815e792..a19e98f3c 100644 --- a/e2e/upgrade-cephfs.go +++ b/e2e/upgrade-cephfs.go @@ -30,10 +30,12 @@ import ( clientset "k8s.io/client-go/kubernetes" "k8s.io/kubernetes/test/e2e/framework" e2elog "k8s.io/kubernetes/test/e2e/framework/log" + "k8s.io/pod-security-admission/api" ) var _ = Describe("CephFS Upgrade Testing", func() { f := framework.NewDefaultFramework("upgrade-test-cephfs") + f.NamespacePodSecurityEnforceLevel = api.LevelPrivileged var ( c clientset.Interface pvc *v1.PersistentVolumeClaim diff --git a/e2e/upgrade-rbd.go b/e2e/upgrade-rbd.go index ee9fc2051..d6976b72b 100644 --- a/e2e/upgrade-rbd.go +++ b/e2e/upgrade-rbd.go @@ -30,10 +30,12 @@ import ( clientset "k8s.io/client-go/kubernetes" "k8s.io/kubernetes/test/e2e/framework" e2elog "k8s.io/kubernetes/test/e2e/framework/log" + "k8s.io/pod-security-admission/api" ) var _ = Describe("RBD Upgrade Testing", func() { f := framework.NewDefaultFramework("upgrade-test-rbd") + f.NamespacePodSecurityEnforceLevel = api.LevelPrivileged var ( // cwd stores the initial working directory. cwd string