-
Notifications
You must be signed in to change notification settings - Fork 13.7k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Fix badly merged impersonation in GKEPodOperator (#19696)
The #19518 was merged while we had false-positive test results due to testing memory optmisation in CI - test failures went unnoticed for the change. This PR fixes the problem (both in tests and in the code) and adds more tests to cover all scenarios
- Loading branch information
Showing
2 changed files
with
74 additions
and
2 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -313,7 +313,7 @@ def test_execute_with_impersonation_service_account( | |
type(file_mock.return_value.__enter__.return_value).name = PropertyMock( | ||
side_effect=[FILE_NAME, '/path/to/new-file'] | ||
) | ||
self.gke_op.impersonation_service_account = "[email protected]" | ||
self.gke_op.impersonation_chain = "[email protected]" | ||
self.gke_op.execute(None) | ||
|
||
mock_gcp_hook.return_value.provide_authorized_gcloud.assert_called_once() | ||
|
@@ -335,3 +335,75 @@ def test_execute_with_impersonation_service_account( | |
) | ||
|
||
assert self.gke_op.config_file == FILE_NAME | ||
|
||
@mock.patch.dict(os.environ, {}) | ||
@mock.patch( | ||
"airflow.hooks.base.BaseHook.get_connections", | ||
return_value=[ | ||
Connection( | ||
extra=json.dumps( | ||
{"extra__google_cloud_platform__keyfile_dict": '{"private_key": "r4nd0m_k3y"}'} | ||
) | ||
) | ||
], | ||
) | ||
@mock.patch('airflow.providers.cncf.kubernetes.operators.kubernetes_pod.KubernetesPodOperator.execute') | ||
@mock.patch('airflow.providers.google.cloud.operators.kubernetes_engine.GoogleBaseHook') | ||
@mock.patch('airflow.providers.google.cloud.operators.kubernetes_engine.execute_in_subprocess') | ||
@mock.patch('tempfile.NamedTemporaryFile') | ||
def test_execute_with_impersonation_service_chain_one_element( | ||
self, file_mock, mock_execute_in_subprocess, mock_gcp_hook, exec_mock, get_con_mock | ||
): | ||
type(file_mock.return_value.__enter__.return_value).name = PropertyMock( | ||
side_effect=[FILE_NAME, '/path/to/new-file'] | ||
) | ||
self.gke_op.impersonation_chain = ["[email protected]"] | ||
self.gke_op.execute(None) | ||
|
||
mock_gcp_hook.return_value.provide_authorized_gcloud.assert_called_once() | ||
|
||
mock_execute_in_subprocess.assert_called_once_with( | ||
[ | ||
'gcloud', | ||
'container', | ||
'clusters', | ||
'get-credentials', | ||
CLUSTER_NAME, | ||
'--zone', | ||
PROJECT_LOCATION, | ||
'--project', | ||
TEST_GCP_PROJECT_ID, | ||
'--impersonate-service-account', | ||
'[email protected]', | ||
] | ||
) | ||
|
||
assert self.gke_op.config_file == FILE_NAME | ||
|
||
@mock.patch.dict(os.environ, {}) | ||
@mock.patch( | ||
"airflow.hooks.base.BaseHook.get_connections", | ||
return_value=[ | ||
Connection( | ||
extra=json.dumps( | ||
{"extra__google_cloud_platform__keyfile_dict": '{"private_key": "r4nd0m_k3y"}'} | ||
) | ||
) | ||
], | ||
) | ||
@mock.patch('airflow.providers.cncf.kubernetes.operators.kubernetes_pod.KubernetesPodOperator.execute') | ||
@mock.patch('airflow.providers.google.cloud.operators.kubernetes_engine.GoogleBaseHook') | ||
@mock.patch('airflow.providers.google.cloud.operators.kubernetes_engine.execute_in_subprocess') | ||
@mock.patch('tempfile.NamedTemporaryFile') | ||
def test_execute_with_impersonation_service_chain_more_elements( | ||
self, file_mock, mock_execute_in_subprocess, mock_gcp_hook, exec_mock, get_con_mock | ||
): | ||
type(file_mock.return_value.__enter__.return_value).name = PropertyMock( | ||
side_effect=[FILE_NAME, '/path/to/new-file'] | ||
) | ||
self.gke_op.impersonation_chain = ["[email protected]", "[email protected]"] | ||
with pytest.raises( | ||
AirflowException, | ||
match="Chained list of accounts is not supported, please specify only one service account", | ||
): | ||
self.gke_op.execute(None) |