Skip to content

Commit

Permalink
Merge pull request #3012 from neolit123/1.30-update-super-admin-test-…
Browse files Browse the repository at this point in the history
…after-upgrade

kinder: update super-admin workflow for 1.30
  • Loading branch information
k8s-ci-robot authored Feb 7, 2024
2 parents 1193b1d + de6d835 commit 49d7749
Show file tree
Hide file tree
Showing 2 changed files with 6 additions and 6 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -128,7 +128,7 @@ tasks:
# Check certificate subject for apiserver-kubelet-client.crt
${CMD} openssl x509 -subject -noout -in /etc/kubernetes/pki/apiserver-kubelet-client.crt | grep "subject=O = kubeadm:cluster-admins, CN = kube-apiserver-kubelet-client" || exit 1
# Delete super-admin.conf to make sure this version of kubeadm creates it on upgrade
# Delete super-admin.conf, simulating the user moving the file to a safe location
${CMD} rm -f "/etc/kubernetes/super-admin.conf" || exit 1
# Ensure exit status of 0
Expand Down Expand Up @@ -196,9 +196,9 @@ tasks:
set -x
CMD="docker exec {{ .vars.clusterName }}-control-plane-1"
# Both admin.conf and super-admin.conf must exist
# admin.conf must exist, super-admin.conf must not exist as we deleted it after init
${CMD} test -f /etc/kubernetes/admin.conf || exit 1
${CMD} test -f /etc/kubernetes/super-admin.conf || exit 1
${CMD} test -f /etc/kubernetes/super-admin.conf && exit 1
# Check certificate subject for .conf files
${CMD} grep 'client-certificate-data' /etc/kubernetes/admin.conf | awk '{print $2}' | base64 -d | openssl x509 -subject -noout | grep "subject=O = kubeadm:cluster-admins, CN = kubernetes-admin" || exit 1
Expand Down
6 changes: 3 additions & 3 deletions kinder/ci/workflows/super-admin-tasks.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -129,7 +129,7 @@ tasks:
# Check certificate subject for apiserver-kubelet-client.crt
${CMD} openssl x509 -subject -noout -in /etc/kubernetes/pki/apiserver-kubelet-client.crt | grep "subject=O = kubeadm:cluster-admins, CN = kube-apiserver-kubelet-client" || exit 1
# Delete super-admin.conf to make sure this version of kubeadm creates it on upgrade
# Delete super-admin.conf, simulating the user moving the file to a safe location
${CMD} rm -f "/etc/kubernetes/super-admin.conf" || exit 1
# Ensure exit status of 0
Expand Down Expand Up @@ -197,9 +197,9 @@ tasks:
set -x
CMD="docker exec {{ .vars.clusterName }}-control-plane-1"
# Both admin.conf and super-admin.conf must exist
# admin.conf must exist, super-admin.conf must not exist as we deleted it after init
${CMD} test -f /etc/kubernetes/admin.conf || exit 1
${CMD} test -f /etc/kubernetes/super-admin.conf || exit 1
${CMD} test -f /etc/kubernetes/super-admin.conf && exit 1
# Check certificate subject for .conf files
${CMD} grep 'client-certificate-data' /etc/kubernetes/admin.conf | awk '{print $2}' | base64 -d | openssl x509 -subject -noout | grep "subject=O = kubeadm:cluster-admins, CN = kubernetes-admin" || exit 1
Expand Down

0 comments on commit 49d7749

Please sign in to comment.