Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@

### Changed
- Adapt webhook proxy to use HMAC ([#1403](https://github.com/opendevstack/ods-core/pull/1403))
- Remove excesive permisions ([#1407](https://github.com/opendevstack/ods-core/pull/1407))

### Fixed
- Fixes VIT0089540 ([#1395](https://github.com/opendevstack/ods-core/pull/1395))
Expand Down
2 changes: 1 addition & 1 deletion create-projects/create-projects.sh
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,7 @@ fi
if [ -n "${PROJECT_GROUPS}" ]; then
echo "Seeding special permission groups (${PROJECT_GROUPS}) ..."

cd_usergroup_role="edit-atlassian-team"
cd_usergroup_role="view"
usergroup_role="edit"
admingroup_role="admin"
readonlygroup_role="view"
Expand Down
2 changes: 1 addition & 1 deletion create-projects/tests/run.sh
Original file line number Diff line number Diff line change
Expand Up @@ -77,7 +77,7 @@ oc mock --receive 'policy add-role-to-group view baz -n foo-cd' --times 1

oc mock --receive 'policy add-role-to-group edit foo -n foo-dev' --times 1
oc mock --receive 'policy add-role-to-group edit foo -n foo-test' --times 1
oc mock --receive 'policy add-role-to-group edit-atlassian-team foo -n foo-cd' --times 1
oc mock --receive 'policy add-role-to-group view foo -n foo-cd' --times 1

oc mock --receive 'policy add-role-to-group admin bar -n foo-dev' --times 1
oc mock --receive 'policy add-role-to-group admin bar -n foo-test' --times 1
Expand Down
152 changes: 14 additions & 138 deletions ods-setup/setup-ods-project.sh
Original file line number Diff line number Diff line change
Expand Up @@ -52,9 +52,6 @@ else
oc new-project ${NAMESPACE} --description="Central ODS namespace with shared resources" --display-name="OpenDevStack"
fi

# Allow system:authenticated group to view resources in central namespace
oc adm policy add-role-to-group view system:authenticated -n ${NAMESPACE}

# Create ods-edit service account and grant edit permissions
if ! oc get serviceaccount ods-edit -n ${NAMESPACE} > /dev/null 2>&1; then
echo "Creating service account 'ods-edit' ..."
Expand All @@ -64,6 +61,20 @@ else
echo "Service account 'ods-edit' already exists"
fi

# Allow authenticated users to read the SonarQube and Aqua ConfigMaps
if ! oc get role configmap-reader -n ${NAMESPACE} > /dev/null 2>&1; then
oc create role configmap-reader \
--verb=get \
--resource=configmaps \
--resource-name=sonarqube-scan \
--resource-name=aqua \
-n ${NAMESPACE}
else
echo "Role 'configmap-reader' already exists"
fi
oc adm policy add-role-to-group configmap-reader system:authenticated -n ${NAMESPACE} --role-namespace=${NAMESPACE}


# Allow system:authenticated group to pull images from central namespace
if ! oc adm policy add-cluster-role-to-group system:image-puller system:authenticated -n ${NAMESPACE}; then
echo "You might not have enough rights to assign 'system:image-puller' to 'system:authenticated'."
Expand All @@ -78,141 +89,6 @@ if ! oc adm policy add-cluster-role-to-user self-provisioner system:serviceaccou
exit 1
fi

# Create a new role 'edit-atlassian-team' without secret-related resources access
if ! oc get clusterrole edit-atlassian-team > /dev/null 2>&1; then
echo "You might not have enough rights to create the new role 'edit-atlassian-team'."
echo "This script needs to be run by a cluster admin."

# Create a temporary file
TEMP_FILE=$(mktemp 2>/dev/null || echo "/tmp/tempfile_$$")

# Get the edit role YAML and rename it
oc get clusterrole edit -o yaml | sed 's/name: edit/name: edit-atlassian-team/' > $TEMP_FILE

# Process the YAML to remove secret-related resources, empty sections, and metadata fields
PROCESSED_FILE=$(mktemp 2>/dev/null || echo "/tmp/tempfile_$$")

awk '
BEGIN {
skip_current_group = 0;
inside_api_group = 0;
api_group_buffer = "";
skip_section = 0;
in_metadata = 0;
contains_secret = 0;
}

# Skip metadata fields and sections
/creationTimestamp:/ || /resourceVersion:/ || /uid:/ {
next;
}

# Detect start of aggregationRule section and skip it
/^aggregationRule:/ {
skip_section = 1;
next;
}

# Detect end of aggregationRule section (when we see apiVersion)
/^apiVersion:/ {
skip_section = 0;
print $0;
next;
}

# Track if we are in metadata section
/^metadata:/ {
in_metadata = 1;
print $0;
next;
}

# Detect start of annotations or labels in metadata and skip them
/^ annotations:/ || /^ labels:/ {
if (in_metadata) {
skip_section = 1;
next;
}
}

# Detect when we leave annotations or labels section (any line with single indent level)
/^ [a-zA-Z]/ {
if (skip_section && in_metadata && $0 !~ /^ annotations:/ && $0 !~ /^ labels:/) {
skip_section = 0;
}
}

# Detect end of metadata section
/^[a-zA-Z]/ && in_metadata && $0 !~ /^metadata:/ {
in_metadata = 0;
}

# Skip lines while in a section we want to skip
{
if (skip_section) {
next;
}
}

# Detect API Groups line
/^- apiGroups:/ {
# If we were previously in an API group, print it if it wasnt being skipped and has no secrets
if (inside_api_group && !skip_current_group && !contains_secret && api_group_buffer != "") {
print api_group_buffer;
}

# Reset variables for new group
inside_api_group = 1;
api_group_buffer = $0;
skip_current_group = 0;
contains_secret = 0;

# Check if this apiGroup itself contains "secret"
if ($0 ~ /secret/ || $0 ~ /external-secrets\.io/) {
skip_current_group = 1;
}
next;
}

# Look for resources section that might contain secrets
/^ resources:/ {
api_group_buffer = api_group_buffer "\n" $0;
next;
}

# Check for secret in resource names
/^ - / && inside_api_group {
# If this resource contains "secret", mark the group for skipping
if ($0 ~ /secret/) {
contains_secret = 1;
}
api_group_buffer = api_group_buffer "\n" $0;
next;
}

# Process all other lines
{
if (inside_api_group) {
# Add to buffer
api_group_buffer = api_group_buffer "\n" $0;
} else {
# Not in an API group, print directly
print $0;
}
}

END {
# Print the last API group if it wasnt being skipped and has no secrets
if (inside_api_group && !skip_current_group && !contains_secret && api_group_buffer != "") {
print api_group_buffer;
}
}' $TEMP_FILE > $PROCESSED_FILE

# Create the role and clean up
oc create -f $PROCESSED_FILE
rm $TEMP_FILE $PROCESSED_FILE
fi

# Create cd-user secret
cd ${SCRIPT_DIR}/ocp-config/cd-user
${TAILOR} -n ${NAMESPACE} apply ${NON_INTERACTIVE} ${REVEAL_SECRETS}
Expand Down
Loading