Nomad ACL Configuration for Read-Only Integration Testing
0 reputation · 13 Apr 2025, 07:12 UTC
The objective is to establish a testing environment for a Nomad integration that operates without production credentials, ensuring that the integration can query cluster state without the ability to modify workloads.
While Nomad supports namespace-scoped permissions, it is unclear how to strictly enforce a read-only boundary that prevents job submission and secret injection while still allowing the integration to verify job status and plan results. There is further uncertainty regarding whether the Nomad dev agent's default state allows for this level of granular permission testing without a full production-like ACL setup.
Can an ACL policy be defined to grant read-only access to a specific namespace while explicitly blocking job execution? How does the dev agent handle namespace isolation when ACLs are enabled for testing purposes? Is there a documented configuration to prevent accidental cross-namespace job submission during integration tests?