Files
my-rook-config/deploy/examples/multus-validation-test-openshift.yaml
Blaine Gardner 33f5407dd4 multus: add host checking to validation tool
In order to help users check that they have implemented the newly-added
Multus host configuration prerequisites, add a check to the validation
tool to verify connectivity.

Because users who are already running clusters with Multus enabled, add
a flag that allows users to only check for host configuration
prerequisites. This mode will not start the large number of clients that
would normally be started because those clients could disrupt a running
Rook cluster negatively.

Host checking pods require host network access. Many Kubernetes
distributions have pod security features enabled. In order to allow
non-Vanilla distros to run this tool, allow specifying a service account
that pods will run as, which can be configured by the admin to allow
test pods.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-07-10 13:41:38 -06:00

39 lines
933 B
YAML

# ServiceAccount and RBAC to support running multus validation test on OpenShift
# Deploy these resources, then use `serviceAccountName: multus-validation-test` in the validation
# test config file.
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: multus-validation-test
namespace: openshift-storage
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: multus-validation-test
namespace: openshift-storage
rules:
- apiGroups:
- security.openshift.io
resourceNames:
- hostnetwork-v2
resources:
- securitycontextconstraints
verbs:
- use
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: multus-validation-test
namespace: openshift-storage
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: multus-validation-test
subjects:
- kind: ServiceAccount
name: multus-validation-test
namespace: openshift-storage