deckhand/deckhand/tests/unit/engine
Phil Sphicas 4ccb4368ce Barbican driver simplification
Under some circumstances, the payloads retrieved from Barbican do not
match what was stored. This primarily affects surrounding whitespace[0],
but the implications for passphrases are significant, and even for PEM
encoded data, a difference in whitespace in a configmap is enough to
trigger a chart upgrade.

In general, the effort to align Deckhand document types with Barbican
secret types adds complexity without tangible benefit. Barbican does no
enforcement of the contents of the data, and if it did, that could lead
to further incompatibilities.

This change uses the 'opaque' secret type for all secret document types.
Before storage (or caching), the payload is serialized using `repr`, and
base64 encoded. Upon retrieval, the payload is base64 decoded and parsed
back into an object with `ast.literal_eval`.

[0]: https://storyboard.openstack.org/#!/story/2007017

Change-Id: I9c2f3427f52a87aad718f95160cf688db35e1b83
2020-01-24 22:26:29 +00:00
..
__init__.py Initial engine framework 2017-07-17 20:46:49 +01:00
base.py Improve document validation module. 2018-01-15 16:51:52 -05:00
test_cache.py optimization: Skip post-validation for rendered document cache hit 2018-10-02 18:58:07 -05:00
test_document_layering.py Merge "integration tests: Add Barbican validation/assertions" 2018-08-02 18:23:03 +00:00
test_document_layering_and_replacement.py Validate additional 'metadata.replacement' scenarios 2018-10-30 10:23:14 -04:00
test_document_layering_and_replacement_negative.py fix: Use schema instead of metadata.schema for replacement check 2018-10-31 15:02:28 -04:00
test_document_layering_and_substitution.py [fix] Substitution source documents accidentally modified 2018-09-04 21:58:45 +01:00
test_document_layering_and_substitution_negative.py integration tests: Add Barbican validation/assertions 2018-07-22 16:32:57 +00:00
test_document_layering_negative.py Fix document is_control method 2018-10-30 09:59:38 -04:00
test_document_validation.py fix: Add validation logic to check for duplicate documents in engine 2018-10-11 22:33:01 +00:00
test_document_validation_negative.py Simplify schema validation 2018-07-03 02:07:33 +00:00
test_revision_deepdiffing.py Validate bucket diffing works with revision rollback 2018-10-18 19:07:42 +01:00
test_revision_diffing.py Validate bucket diffing works with revision rollback 2018-10-18 19:07:42 +01:00
test_secrets_manager.py Barbican driver simplification 2020-01-24 22:26:29 +00:00