`hack/ark/test-e2e.sh` (run via `make ark-test-e2e`) only exercises the legacy username/password auth path: it hard-requires `ARK_USERNAME`/`ARK_SECRET`/`ARK_SUBDOMAIN` and always writes them into a Secret. The `helm upgrade` it runs never sets `config.cyberark.serviceId`, so Conjur JWT auth has no live e2e coverage at all.
Since #838 added `config.cyberark.subdomain`, a Conjur-JWT-only install (`config.cyberark.serviceId` set, `config.cyberark.subdomain` set, no Secret whatsoever) is possible but has never been exercised against a live cluster.
Add a second e2e path alongside the existing one:
- Sets `config.cyberark.serviceId` and `config.cyberark.subdomain` via `--set`, no Secret created.
- Reuses the same onboarding/authenticator setup the existing script assumes, or documents what's needed.
- Asserts the same "Data sent successfully" log line as the legacy path.
Leave the existing legacy-path script untouched — it's the backward-compatibility path and should keep testing exactly what it tests today.
`hack/ark/test-e2e.sh` (run via `make ark-test-e2e`) only exercises the legacy username/password auth path: it hard-requires `ARK_USERNAME`/`ARK_SECRET`/`ARK_SUBDOMAIN` and always writes them into a Secret. The `helm upgrade` it runs never sets `config.cyberark.serviceId`, so Conjur JWT auth has no live e2e coverage at all.
Since #838 added `config.cyberark.subdomain`, a Conjur-JWT-only install (`config.cyberark.serviceId` set, `config.cyberark.subdomain` set, no Secret whatsoever) is possible but has never been exercised against a live cluster.
Add a second e2e path alongside the existing one:
Leave the existing legacy-path script untouched — it's the backward-compatibility path and should keep testing exactly what it tests today.