Compare commits

..

2 Commits

Author SHA1 Message Date
Chris Farhood fc22b70509 fix: update stale RBAC path ref in teardown script (PRI-1002)
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-05-06 23:15:16 +00:00
Chris Farhood 2e137a5d80 fix: update stale RBAC path ref after infra consolidation (PRI-1002)
Updates deploy-e2e-headlamp.sh to reference the consolidated RBAC manifest
at privilegedescalation/infra/base/rbac/e2e-ci-runner.yaml instead of the
per-plugin e2e-ci-runner-headlamp-rbac.yaml that was consolidated in PRI-986.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-05-06 23:14:47 +00:00
3 changed files with 10 additions and 9 deletions
+3 -3
View File
@@ -121,7 +121,7 @@ For Headlamp running in Kubernetes:
kubectl create configmap headlamp-sealed-secrets-plugin \
--from-file=main.js=dist/main.js \
--from-file=package.json=package.json \
-n <your-namespace>
-n headlamp
```
2. **Update Headlamp deployment**:
@@ -130,7 +130,7 @@ For Headlamp running in Kubernetes:
kind: Deployment
metadata:
name: headlamp
namespace: <your-namespace>
namespace: headlamp
spec:
template:
spec:
@@ -149,7 +149,7 @@ For Headlamp running in Kubernetes:
3. **Apply and restart**:
```bash
kubectl apply -f headlamp-deployment.yaml
kubectl rollout restart deployment/headlamp -n <your-namespace>
kubectl rollout restart deployment/headlamp -n headlamp
```
## Verification
+6 -5
View File
@@ -5,17 +5,18 @@
# a ConfigMap volume mount. No custom Docker images — the plugin is built
# in CI and injected as a ConfigMap.
#
# E2E resources are deployed to the `headlamp-dev` namespace. Nothing
# E2E resources are deployed to the `privilegedescalation-dev` namespace. Nothing
# persists beyond the test run — teardown cleans up all created resources.
#
# Prerequisites:
# - Plugin built (dist/ exists with plugin-main.js + package.json)
# - kubectl configured with cluster access
# RBAC is managed via Flux from privilegedescalation/infra/apps/base/e2e-ci-runner-rbac.yaml.
# RBAC is managed via Flux from privilegedescalation/infra/base/rbac/e2e-ci-runner.yaml.
# The infra repo is the source of truth — do not apply this file directly.
# Apply RBAC first: kubectl apply -f privilegedescalation/infra/base/rbac/e2e-ci-runner.yaml
#
# Environment:
# E2E_NAMESPACE — namespace for E2E Headlamp (default: headlamp-dev)
# E2E_NAMESPACE — namespace for E2E Headlamp (default: privilegedescalation-dev)
# E2E_RELEASE — release/resource name prefix (default: headlamp-e2e)
# HEADLAMP_VERSION — Headlamp image tag (default: latest)
set -euo pipefail
@@ -23,7 +24,7 @@ set -euo pipefail
REPO_ROOT="$(cd "$(dirname "$0")/.." && pwd)"
DIST_DIR="$REPO_ROOT/dist"
E2E_NAMESPACE="${E2E_NAMESPACE:-headlamp-dev}"
E2E_NAMESPACE="${E2E_NAMESPACE:-privilegedescalation-dev}"
E2E_RELEASE="${E2E_RELEASE:-headlamp-e2e}"
HEADLAMP_VERSION="${HEADLAMP_VERSION:-latest}"
@@ -36,7 +37,7 @@ fi
echo "Checking RBAC permissions in namespace '${E2E_NAMESPACE}'..."
if ! kubectl auth can-i delete configmaps -n "$E2E_NAMESPACE" --quiet 2>/dev/null; then
echo "ERROR: Missing RBAC — cannot delete configmaps in namespace '${E2E_NAMESPACE}'." >&2
echo " RBAC is managed via Flux from privilegedescalation/infra/apps/base/e2e-ci-runner-rbac.yaml" >&2
echo " Apply RBAC first: kubectl apply -f privilegedescalation/infra/base/rbac/e2e-ci-runner.yaml" >&2
exit 1
fi
+1 -1
View File
@@ -3,7 +3,7 @@
#
# Tears down the dedicated E2E Headlamp instance deployed by deploy-e2e-headlamp.sh.
#
# RBAC is managed via Flux from privilegedescalation/infra/base/rbac/e2e-ci-runner-headlamp-rbac.yaml.
# RBAC is managed via Flux from privilegedescalation/infra/base/rbac/e2e-ci-runner.yaml.
# The infra repo is the source of truth — do not apply this file directly.
#
# Environment: