Skip to content
GitLab
Menu
Projects
Groups
Snippets
Help
Projects
Groups
Snippets
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Sign in
Toggle navigation
Menu
Open sidebar
小 白蛋
Nomad
Commits
ffa79f47
Commit
ffa79f47
authored
7 years ago
by
Michael Schurter
Committed by
GitHub
7 years ago
Browse files
Options
Download
Plain Diff
Merge pull request #3315 from hashicorp/f-acl-deployment-pause
Deployment.Pause ACL enforcement
parents
3877ac62
36a543bd
Branches unavailable
v1.4.3
v1.4.2
v1.4.1
v1.4.0
v1.4.0-rc.1
v1.4.0-beta.1
v1.3.8
v1.3.7
v1.3.6
v1.3.5
v1.3.4
v1.3.3
v1.3.2
v1.3.1
v1.3.0
v1.3.0-rc.1
v1.3.0-beta.1
v1.2.15
v1.2.14
v1.2.13
v1.2.12
v1.2.11
v1.2.10
v1.2.9
v1.2.8
v1.2.7
v1.2.6
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.2.0-rc1
v1.2.0-beta1
v1.1.18
v1.1.17
v1.1.16
v1.1.15
v1.1.14
v1.1.13
v1.1.12
v1.1.11
v1.1.10
v1.1.9
v1.1.8
v1.1.7
v1.1.6
v1.1.5
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.1.0-rc1
v1.1.0-beta1
v1.0.18
v1.0.17
v1.0.16
v1.0.15
v1.0.14
v1.0.13
v1.0.12
v1.0.11
v1.0.10
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
v1.0.0-rc1
v1.0.0-beta3
v1.0.0-beta2
v0.12.12
v0.12.11
v0.12.10
v0.12.9
v0.12.8
v0.12.7
v0.12.6
v0.12.5
v0.12.4
v0.12.4-rc1
v0.12.3
v0.12.2
v0.12.1
v0.12.0
v0.12.0-rc1
v0.12.0-beta2
v0.12.0-beta1
v0.11.8
v0.11.7
v0.11.6
v0.11.5
v0.11.4
v0.11.3
v0.11.2
v0.11.1
v0.11.0
v0.11.0-rc1
v0.11.0-beta2
v0.11.0-beta1
v0.10.9
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.4-rc1
v0.10.3
v0.10.2
v0.10.2-rc1
v0.10.1
v0.10.0
v0.10.0-rc1
v0.10.0-connect1
v0.10.0-beta1
v0.9.7
v0.9.6
v0.9.5
v0.9.4
v0.9.4-rc1
v0.9.3
v0.9.2
v0.9.2-rc1
v0.9.1
v0.9.1-rc1
v0.9.0
v0.9.0-rc2
v0.9.0-rc1
v0.9.0-beta3
v0.9.0-beta2
v0.9.0-beta1
v0.8.7
v0.8.7-rc1
v0.8.6
v0.8.5
v0.8.4
v0.8.4-rc1
v0.8.3
v0.8.2
v0.8.1
v0.8.0
v0.8.0-rc1
v0.7.1
v0.7.1-rc1
v0.7.1-rc1+pro
v0.7.1-rc1+ent
v0.7.0
v0.7.0+pro
v0.7.0+ent
v0.7.0-rc3
v0.7.0-rc2
v0.7.0-rc1
nightly
No related merge requests found
Changes
3
Hide whitespace changes
Inline
Side-by-side
Showing
3 changed files
nomad/deployment_endpoint.go
+7
-0
nomad/deployment_endpoint.go
nomad/deployment_endpoint_test.go
+68
-0
nomad/deployment_endpoint_test.go
website/source/api/deployments.html.md
+3
-3
website/source/api/deployments.html.md
with
78 additions
and
3 deletions
+78
-3
nomad/deployment_endpoint.go
+
7
-
0
View file @
ffa79f47
...
...
@@ -116,6 +116,13 @@ func (d *Deployment) Pause(args *structs.DeploymentPauseRequest, reply *structs.
}
defer
metrics
.
MeasureSince
([]
string
{
"nomad"
,
"deployment"
,
"pause"
},
time
.
Now
())
// Check namespace submit-job permissions
if
aclObj
,
err
:=
d
.
srv
.
resolveToken
(
args
.
SecretID
);
err
!=
nil
{
return
err
}
else
if
aclObj
!=
nil
&&
!
aclObj
.
AllowNsOp
(
args
.
RequestNamespace
(),
acl
.
NamespaceCapabilitySubmitJob
)
{
return
structs
.
ErrPermissionDenied
}
// Validate the arguments
if
args
.
DeploymentID
==
""
{
return
fmt
.
Errorf
(
"missing deployment ID"
)
...
...
This diff is collapsed.
Click to expand it.
nomad/deployment_endpoint_test.go
+
68
-
0
View file @
ffa79f47
...
...
@@ -388,6 +388,74 @@ func TestDeploymentEndpoint_Pause(t *testing.T) {
assert
.
Equal
(
dout
.
ModifyIndex
,
resp
.
DeploymentModifyIndex
,
"wrong modify index"
)
}
func
TestDeploymentEndpoint_Pause_ACL
(
t
*
testing
.
T
)
{
t
.
Parallel
()
s1
,
_
:=
testACLServer
(
t
,
func
(
c
*
Config
)
{
c
.
NumSchedulers
=
0
// Prevent automatic dequeue
})
defer
s1
.
Shutdown
()
codec
:=
rpcClient
(
t
,
s1
)
testutil
.
WaitForLeader
(
t
,
s1
.
RPC
)
assert
:=
assert
.
New
(
t
)
// Create the deployment
j
:=
mock
.
Job
()
d
:=
mock
.
Deployment
()
d
.
JobID
=
j
.
ID
state
:=
s1
.
fsm
.
State
()
assert
.
Nil
(
state
.
UpsertJob
(
999
,
j
),
"UpsertJob"
)
assert
.
Nil
(
state
.
UpsertDeployment
(
1000
,
d
),
"UpsertDeployment"
)
// Create the namespace policy and tokens
validToken
:=
CreatePolicyAndToken
(
t
,
state
,
1001
,
"test-valid"
,
NamespacePolicy
(
structs
.
DefaultNamespace
,
""
,
[]
string
{
acl
.
NamespaceCapabilitySubmitJob
}))
invalidToken
:=
CreatePolicyAndToken
(
t
,
state
,
1003
,
"test-invalid"
,
NamespacePolicy
(
structs
.
DefaultNamespace
,
""
,
[]
string
{
acl
.
NamespaceCapabilityReadJob
}))
// Mark the deployment as failed
req
:=
&
structs
.
DeploymentPauseRequest
{
DeploymentID
:
d
.
ID
,
Pause
:
true
,
WriteRequest
:
structs
.
WriteRequest
{
Region
:
"global"
},
}
// Try with no token and expect permission denied
{
var
resp
structs
.
DeploymentUpdateResponse
err
:=
msgpackrpc
.
CallWithCodec
(
codec
,
"Deployment.Pause"
,
req
,
&
resp
)
assert
.
NotNil
(
err
)
assert
.
Equal
(
err
.
Error
(),
structs
.
ErrPermissionDenied
.
Error
())
}
// Try with an invalid token
{
req
.
SecretID
=
invalidToken
.
SecretID
var
resp
structs
.
DeploymentUpdateResponse
err
:=
msgpackrpc
.
CallWithCodec
(
codec
,
"Deployment.Pause"
,
req
,
&
resp
)
assert
.
NotNil
(
err
)
assert
.
Equal
(
err
.
Error
(),
structs
.
ErrPermissionDenied
.
Error
())
}
// Fetch the response with a valid token
{
req
.
SecretID
=
validToken
.
SecretID
var
resp
structs
.
DeploymentUpdateResponse
assert
.
Nil
(
msgpackrpc
.
CallWithCodec
(
codec
,
"Deployment.Pause"
,
req
,
&
resp
),
"RPC"
)
assert
.
NotEqual
(
resp
.
Index
,
uint64
(
0
),
"bad response index"
)
assert
.
Zero
(
resp
.
EvalCreateIndex
,
"Shouldn't create eval"
)
assert
.
Zero
(
resp
.
EvalID
,
"Shouldn't create eval"
)
// Lookup the deployment
ws
:=
memdb
.
NewWatchSet
()
dout
,
err
:=
state
.
DeploymentByID
(
ws
,
d
.
ID
)
assert
.
Nil
(
err
,
"DeploymentByID failed"
)
assert
.
Equal
(
dout
.
Status
,
structs
.
DeploymentStatusPaused
,
"wrong status"
)
assert
.
Equal
(
dout
.
StatusDescription
,
structs
.
DeploymentStatusDescriptionPaused
,
"wrong status description"
)
assert
.
Equal
(
dout
.
ModifyIndex
,
resp
.
DeploymentModifyIndex
,
"wrong modify index"
)
}
}
func
TestDeploymentEndpoint_Promote
(
t
*
testing
.
T
)
{
t
.
Parallel
()
s1
:=
testServer
(
t
,
func
(
c
*
Config
)
{
...
...
This diff is collapsed.
Click to expand it.
website/source/api/deployments.html.md
+
3
-
3
View file @
ffa79f47
...
...
@@ -315,9 +315,9 @@ The table below shows this endpoint's support for
[
blocking queries
](
/api/index.html#blocking-queries
)
and
[
required ACLs
](
/api/index.html#acls
)
.
| Blocking Queries | ACL Required |
| ---------------- | ------------ |
|
`NO`
|
`n
one`
|
| Blocking Queries | ACL Required
|
| ---------------- | ------------
----------
|
|
`NO`
|
`n
amespace:submit-job`
|
### Parameters
...
...
This diff is collapsed.
Click to expand it.
Write
Preview
Supports
Markdown
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment
Menu
Projects
Groups
Snippets
Help