diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..e69de29 diff --git a/2.4 b/2.4 new file mode 120000 index 0000000..945c9b4 --- /dev/null +++ b/2.4 @@ -0,0 +1 @@ +. \ No newline at end of file diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..1f47576 --- /dev/null +++ b/Dockerfile @@ -0,0 +1,69 @@ +FROM registry.fedoraproject.org/f30/s2i-core:latest + +# Apache HTTP Server image. +# +# Volumes: +# * /var/www - Datastore for httpd +# * /var/log/httpd - Storage for logs when $HTTPD_LOG_TO_VOLUME is set +# Environment: +# * $HTTPD_LOG_TO_VOLUME (optional) - When set, httpd will log into /var/log/httpd + +ENV HTTPD_VERSION=2.4 \ + NAME=httpd \ + ARCH=x86_64 + +ENV SUMMARY="Platform for running Apache httpd $HTTPD_VERSION or building httpd-based application" \ + DESCRIPTION="Apache httpd $HTTPD_VERSION available as container, is a powerful, efficient, \ +and extensible web server. Apache supports a variety of features, many implemented as compiled modules \ +which extend the core functionality. \ +These can range from server-side programming language support to authentication schemes. \ +Virtual hosting allows one Apache installation to serve many different Web sites." + +LABEL summary="$SUMMARY" \ + description="$DESCRIPTION" \ + io.k8s.description="$SUMMARY" \ + io.k8s.display-name="Apache httpd $HTTPD_VERSION" \ + io.openshift.expose-services="8080:http,8443:https" \ + io.openshift.tags="builder,httpd,httpd24" \ + com.redhat.component="$NAME" \ + name="$FGC/$NAME" \ + version="$HTTPD_VERSION" \ + usage="s2i build https://github.com/sclorg/httpd-container.git --context-dir=examples/sample-test-app/ $FGC/$NAME sample-server" \ + maintainer="SoftwareCollections.org " + +EXPOSE 8080 +EXPOSE 8443 + +RUN dnf install -y yum-utils gettext hostname && \ + INSTALL_PKGS="nss_wrapper bind-utils httpd mod_ssl" && \ + dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \ + rpm -V $INSTALL_PKGS && \ + dnf clean all + +ENV HTTPD_CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/httpd/ \ + HTTPD_APP_ROOT=${APP_ROOT} \ + HTTPD_CONFIGURATION_PATH=${APP_ROOT}/etc/httpd.d \ + HTTPD_MAIN_CONF_PATH=/etc/httpd/conf \ + HTTPD_MAIN_CONF_MODULES_D_PATH=/etc/httpd/conf.modules.d \ + HTTPD_MAIN_CONF_D_PATH=/etc/httpd/conf.d \ + HTTPD_VAR_RUN=/var/run/httpd \ + HTTPD_DATA_PATH=/var/www \ + HTTPD_DATA_ORIG_PATH=/var/www \ + HTTPD_LOG_PATH=/var/log/httpd + +COPY ./s2i/bin/ $STI_SCRIPTS_PATH +COPY ./root / + +# Generate SSL certs and reset permissions of filesystem to default values +# Reset permissions of filesystem to default values +RUN /usr/libexec/httpd-ssl-gencerts && \ + /usr/libexec/httpd-prepare && rpm-file-permissions + +USER 1001 + +# Not using VOLUME statement since it's not working in OpenShift Online: +# https://github.com/sclorg/httpd-container/issues/30 +# VOLUME ["${HTTPD_DATA_PATH}"] +# VOLUME ["${HTTPD_LOG_PATH}"] + +CMD ["/usr/bin/run-httpd"] diff --git a/Dockerfile.fedora b/Dockerfile.fedora new file mode 120000 index 0000000..1d1fe94 --- /dev/null +++ b/Dockerfile.fedora @@ -0,0 +1 @@ +Dockerfile \ No newline at end of file diff --git a/README.md b/README.md new file mode 120000 index 0000000..299cf2b --- /dev/null +++ b/README.md @@ -0,0 +1 @@ +root/usr/share/container-scripts/httpd/README.md \ No newline at end of file diff --git a/dead.package b/dead.package deleted file mode 100644 index 2e10e65..0000000 --- a/dead.package +++ /dev/null @@ -1 +0,0 @@ -This container component is no longer used for anything, retiring to make it explicit. diff --git a/help.md b/help.md new file mode 120000 index 0000000..42061c0 --- /dev/null +++ b/help.md @@ -0,0 +1 @@ +README.md \ No newline at end of file diff --git a/root/help.1 b/root/help.1 new file mode 100644 index 0000000..ddf8343 --- /dev/null +++ b/root/help.1 @@ -0,0 +1,217 @@ +.TH Apache HTTP Server 2.4 Container Image +.PP +This container image includes Apache HTTP Server 2.4 for OpenShift and general usage. +Users can choose between RHEL, CentOS and Fedora based images. +The RHEL image is available in the Red Hat Container Catalog +\[la]https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/httpd-24-rhel7\[ra] +as registry.access.redhat.com/rhscl/httpd\-24\-rhel7. +The CentOS image is then available on Docker Hub +\[la]https://hub.docker.com/r/centos/httpd-24-centos7/\[ra] +as centos/httpd\-24\-centos7. + +.SH Description +.PP +Apache HTTP Server 2.4 available as container, is a powerful, efficient, +and extensible web server. Apache supports a variety of features, many implemented as compiled modules +which extend the core functionality. +These can range from server\-side programming language support to authentication schemes. +Virtual hosting allows one Apache installation to serve many different Web sites." + +.SH Usage +.PP +For this, we will assume that you are using the Apache HTTP Server 2.4 container image from the +Red Hat Container Catalog called \fB\fCrhscl/httpd\-24\-rhel7\fR\&. +The image can be used as a base image for other applications based on Apache HTTP web server. + +.PP +An example of the data on the host for both the examples above, that will be served by +Apache HTTP web server: + +.PP +.RS + +.nf +$ ls \-lZ /wwwdata/html +\-rw\-r\-\-r\-\-. 1 1001 1001 54321 Jan 01 12:34 index.html +\-rw\-r\-\-r\-\-. 1 1001 1001 5678 Jan 01 12:34 page.html + +.fi +.RE + +.PP +If you want to run the image and mount the static pages available in \fB\fC/wwwdata\fR on the host +as a container volume, execute the following command: + +.PP +.RS + +.nf +$ docker run \-d \-\-name httpd \-p 8080:8080 \-v /wwwdata:/var/www:Z rhscl/httpd\-24\-rhel7 + +.fi +.RE + +.PP +This will create a container named \fB\fChttpd\fR running Apache HTTP Server, serving data from +\fB\fC/wwwdata\fR directory. Port 8080 will be exposed and mapped to the host. + +.PP +If you want to create a new container layered image, use Source\-to\-Image +\[la]https://github.com/openshift/source-to-image\[ra], a tool for building/building artifacts from source and injecting into container images. To create a new container image named \fB\fChttpd\-app\fR using Source\-to\-Image, while using data available in \fB\fC/wwwdata\fR on the host, execute the following command: + +.PP +.RS + +.nf +$ s2i build file:///wwwdata/html rhscl/httpd\-24\-rhel7 httpd\-app + +.fi +.RE + +.PP +To run such a new image, execute the following command: + +.PP +.RS + +.nf +$ docker run \-d \-\-name httpd \-p 8080:8080 httpd\-app + +.fi +.RE + +.PP +The structure of httpd\-app can look like this: + +.PP +\fB\fB\fC\&./httpd\-\&cfg\fR\fP +.br + Can contain additional Apache configuration files (\fB\fC*.conf\fR) + +.PP +\fB\fB\fC\&./httpd\-\&pre\-\&init\fR\fP +.br + Can contain shell scripts (\fB\fC*.sh\fR) that are sourced before \fB\fChttpd\fR is started + +.PP +\fB\fB\fC\&./httpd\-\&ssl\fR\fP +.br + Can contain own SSL certificate (in \fB\fCcerts/\fR subdirectory) and key (in \fB\fCprivate/\fR subdirectory) + +.PP +\fB\fB\fC\&./\fR\fP +.br + Application source code + +.SH Environment variables and volumes +.PP +The Apache HTTP Server container image supports the following configuration variable, which can be set by using the \fB\fC\-e\fR option with the docker run command: + +.PP +\fB\fB\fCHTTPD\_LOG\_TO\_VOLUME\fR\fP +.br + By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When \fB\fCHTTPD\_LOG\_TO\_VOLUME\fR is set, httpd logs into \fB\fC/var/log/httpd24\fR, which can be mounted to host system using the container volumes. This option is only allowed when container is run as UID 0. + +.PP +\fB\fB\fCHTTPD\_MPM\fR\fP + The variable \fB\fCHTTPD\_MPM\fR can be set to change the default Multi\-Processing Module (MPM) from the package default MPM. + +.PP +If you want to run the image and mount the log files into \fB\fC/wwwlogs\fR on the host +as a container volume, execute the following command: + +.PP +.RS + +.nf +$ docker run \-d \-u 0 \-e HTTPD\_LOG\_TO\_VOLUME=1 \-\-name httpd \-v /wwwlogs:/var/log/httpd24:Z rhscl/httpd\-24\-rhel7 + +.fi +.RE + +.PP +To run an image using the \fB\fCevent\fR MPM (rather than the default \fB\fCprefork\fR), execute the following command: + +.PP +.RS + +.nf +$ docker run \-d \-e HTTPD\_MPM=event \-\-name httpd rhscl/httpd\-24\-rhel7 + +.fi +.RE + +.PP +You can also set the following mount points by passing the \fB\fC\-v /host:/container\fR flag to Docker. + +.PP +\fB\fB\fC/var/www\fR\fP +.br + Apache HTTP Server data directory + +.PP +\fB\fB\fC/var/log/httpd24\fR\fP +.br + Apache HTTP Server log directory (available only when running as root, path \fB\fC/var/log/httpd\fR is used in case of Fedora based image) + +.PP +\fBNotice: When mouting a directory from the host into the container, ensure that the mounted +directory has the appropriate permissions and that the owner and group of the directory +matches the user UID or name which is running inside the container.\fP + +.SH Using own SSL certificates +.PP +In order to provide own SSL certificates for securing the connection with SSL, use the extending feature described above. In particular, put the SSL certificates into a separate directory inside your application: + +.PP +.RS + +.nf +\&./httpd\-\&ssl/certs/server\-\&cert\-\&selfsigned.pem +./httpd\-\&ssl/private/server\-\&key.pem + +.fi +.RE + +.PP +The default behaviour is to look for the certificate and the private key in subdirectories certs/ and private/; those files will be used for the ssl settings in the httpd. + +.SH Default user +.PP +By default, Apache HTTP Server container runs as UID 1001. That means the volume mounted directories for the files (if mounted using \fB\fC\-v\fR option) need to be prepared properly, so the UID 1001 can read them. + +.PP +To run the container as a different UID, use \fB\fC\-u\fR option. For example if you want to run the container as UID 1234, execute the following command: + +.PP +.RS + +.nf +docker run \-d \-u 1234 rhscl/httpd\-24\-rhel7 + +.fi +.RE + +.PP +To log into a volume mounted directory, the container needs to be run as UID 0 (see above). + +.SH Troubleshooting +.PP +The httpd deamon in the container logs to the standard output by default, so the log is available in the container log. The log can be examined by running: + +.PP +.RS + +.nf +docker logs + +.fi +.RE + +.SH See also +.PP +Dockerfile and other sources for this container image are available on + +\[la]https://github.com/sclorg/httpd-container\[ra]\&. +In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile +for RHEL is called Dockerfile.rhel7 and Dockerfile for Fedora is called Dockerfile.fedora. diff --git a/root/opt/app-root/scl_enable b/root/opt/app-root/scl_enable new file mode 100644 index 0000000..373330d --- /dev/null +++ b/root/opt/app-root/scl_enable @@ -0,0 +1,3 @@ +# This will make scl collection binaries work out of box. +unset BASH_ENV PROMPT_COMMAND ENV +source scl_source enable httpd24 diff --git a/root/usr/bin/run-httpd b/root/usr/bin/run-httpd new file mode 100755 index 0000000..e03578f --- /dev/null +++ b/root/usr/bin/run-httpd @@ -0,0 +1,18 @@ +#!/bin/bash + +set -eu + +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +# Check whether we run as s2i +if ! [ -v HTTPD_RUN_BY_S2I ] && runs_privileged ; then + config_privileged +else + # We run as non-root or as s2i + config_non_privileged + generate_container_user +fi + +process_extending_files ${HTTPD_APP_ROOT}/src/httpd-pre-init/ ${HTTPD_CONTAINER_SCRIPTS_PATH}/pre-init/ + +exec httpd -D FOREGROUND $@ diff --git a/root/usr/libexec/httpd-prepare b/root/usr/libexec/httpd-prepare new file mode 100755 index 0000000..e2857da --- /dev/null +++ b/root/usr/libexec/httpd-prepare @@ -0,0 +1,39 @@ +#!/bin/bash + +set -e + +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +# compatibility symlinks so we hide SCL paths +if [ -v HTTPD_SCL ] ; then + # /opt/rh/httpd24/root/etc/httpd will be symlink to /etc/httpd + mv /opt/rh/httpd24/root/etc/httpd /etc/httpd + ln -s /etc/httpd /opt/rh/httpd24/root/etc/httpd + + # /opt/rh/httpd24/root/var/run/httpd will be symlink to /var/run/httpd + mv /opt/rh/httpd24/root/var/run/httpd /var/run/httpd + ln -s /var/run/httpd /opt/rh/httpd24/root/var/run/httpd + + # /opt/rh/httpd24/root/var/www will be symlink to /var/www + rm -rf /var/www + mv /opt/rh/httpd24/root/var/www /var/www + ln -s /var/www /opt/rh/httpd24/root/var/www +fi + +mkdir -p ${HTTPD_CONFIGURATION_PATH} +chmod -R a+rwx ${HTTPD_MAIN_CONF_PATH} +chmod -R a+rwx ${HTTPD_MAIN_CONF_D_PATH} +chmod -R a+rwx ${HTTPD_MAIN_CONF_MODULES_D_PATH} +chmod -R a+r /etc/pki/tls/certs/localhost.crt +chmod -R a+r /etc/pki/tls/private/localhost.key +mkdir -p ${HTTPD_APP_ROOT}/etc +chmod -R a+rwx ${HTTPD_APP_ROOT}/etc +chmod -R a+rwx ${HTTPD_VAR_RUN} +chown -R 1001:0 ${HTTPD_APP_ROOT} +chown -R 1001:0 ${HTTPD_DATA_PATH} +chown -R 1001:0 ${HTTPD_LOG_PATH} + +mkdir -p ${HTTPD_CONTAINER_SCRIPTS_PATH}/pre-init + +config_general + diff --git a/root/usr/share/container-scripts/httpd/README.md b/root/usr/share/container-scripts/httpd/README.md new file mode 100644 index 0000000..99eceed --- /dev/null +++ b/root/usr/share/container-scripts/httpd/README.md @@ -0,0 +1,150 @@ +Apache HTTP Server 2.4 Container Image +====================== + +This container image includes Apache HTTP Server 2.4 for OpenShift and general usage. +Users can choose between RHEL, CentOS and Fedora based images. +The RHEL image is available in the [Red Hat Container Catalog](https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/httpd-24-rhel7) +as registry.access.redhat.com/rhscl/httpd-24-rhel7. +The CentOS image is then available on [Docker Hub](https://hub.docker.com/r/centos/httpd-24-centos7/) +as centos/httpd-24-centos7. + + +Description +----------- + +Apache HTTP Server 2.4 available as container, is a powerful, efficient, +and extensible web server. Apache supports a variety of features, many implemented as compiled modules +which extend the core functionality. +These can range from server-side programming language support to authentication schemes. +Virtual hosting allows one Apache installation to serve many different Web sites." + + +Usage +----- + +For this, we will assume that you are using the Apache HTTP Server 2.4 container image from the +Red Hat Container Catalog called `rhscl/httpd-24-rhel7`. +The image can be used as a base image for other applications based on Apache HTTP web server. + +An example of the data on the host for both the examples above, that will be served by +Apache HTTP web server: + +``` +$ ls -lZ /wwwdata/html +-rw-r--r--. 1 1001 1001 54321 Jan 01 12:34 index.html +-rw-r--r--. 1 1001 1001 5678 Jan 01 12:34 page.html +``` + +If you want to run the image and mount the static pages available in `/wwwdata` on the host +as a container volume, execute the following command: + +``` +$ docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z rhscl/httpd-24-rhel7 +``` + +This will create a container named `httpd` running Apache HTTP Server, serving data from +`/wwwdata` directory. Port 8080 will be exposed and mapped to the host. + +If you want to create a new container layered image, use [Source-to-Image](https://github.com/openshift/source-to-image), a tool for building/building artifacts from source and injecting into container images. To create a new container image named `httpd-app` using Source-to-Image, while using data available in `/wwwdata` on the host, execute the following command: + +``` +$ s2i build file:///wwwdata/html rhscl/httpd-24-rhel7 httpd-app +``` + +To run such a new image, execute the following command: + +``` +$ docker run -d --name httpd -p 8080:8080 httpd-app +``` + +The structure of httpd-app can look like this: + +**`./httpd-cfg`** + Can contain additional Apache configuration files (`*.conf`) + +**`./httpd-pre-init`** + Can contain shell scripts (`*.sh`) that are sourced before `httpd` is started + +**`./httpd-ssl`** + Can contain own SSL certificate (in `certs/` subdirectory) and key (in `private/` subdirectory) + +**`./`** + Application source code + + +Environment variables and volumes +--------------------------------- + +The Apache HTTP Server container image supports the following configuration variable, which can be set by using the `-e` option with the docker run command: + +**`HTTPD_LOG_TO_VOLUME`** + By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When `HTTPD_LOG_TO_VOLUME` is set, httpd logs into `/var/log/httpd24`, which can be mounted to host system using the container volumes. This option is only allowed when container is run as UID 0. + +**`HTTPD_MPM`** + The variable `HTTPD_MPM` can be set to change the default Multi-Processing Module (MPM) from the package default MPM. + + +If you want to run the image and mount the log files into `/wwwlogs` on the host +as a container volume, execute the following command: + +``` +$ docker run -d -u 0 -e HTTPD_LOG_TO_VOLUME=1 --name httpd -v /wwwlogs:/var/log/httpd24:Z rhscl/httpd-24-rhel7 +``` + +To run an image using the `event` MPM (rather than the default `prefork`), execute the following command: + +``` +$ docker run -d -e HTTPD_MPM=event --name httpd rhscl/httpd-24-rhel7 +``` + +You can also set the following mount points by passing the `-v /host:/container` flag to Docker. + +**`/var/www`** + Apache HTTP Server data directory + +**`/var/log/httpd24`** + Apache HTTP Server log directory (available only when running as root, path `/var/log/httpd` is used in case of Fedora based image) + + +**Notice: When mouting a directory from the host into the container, ensure that the mounted +directory has the appropriate permissions and that the owner and group of the directory +matches the user UID or name which is running inside the container.** + + +Using own SSL certificates +-------------------------- +In order to provide own SSL certificates for securing the connection with SSL, use the extending feature described above. In particular, put the SSL certificates into a separate directory inside your application: + + ./httpd-ssl/certs/server-cert-selfsigned.pem + ./httpd-ssl/private/server-key.pem + +The default behaviour is to look for the certificate and the private key in subdirectories certs/ and private/; those files will be used for the ssl settings in the httpd. + + +Default user +------------ + +By default, Apache HTTP Server container runs as UID 1001. That means the volume mounted directories for the files (if mounted using `-v` option) need to be prepared properly, so the UID 1001 can read them. + +To run the container as a different UID, use `-u` option. For example if you want to run the container as UID 1234, execute the following command: + +``` +docker run -d -u 1234 rhscl/httpd-24-rhel7 +``` + +To log into a volume mounted directory, the container needs to be run as UID 0 (see above). + + +Troubleshooting +--------------- +The httpd deamon in the container logs to the standard output by default, so the log is available in the container log. The log can be examined by running: + + docker logs + + +See also +-------- +Dockerfile and other sources for this container image are available on +https://github.com/sclorg/httpd-container. +In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile +for RHEL is called Dockerfile.rhel7 and Dockerfile for Fedora is called Dockerfile.fedora. diff --git a/root/usr/share/container-scripts/httpd/common.sh b/root/usr/share/container-scripts/httpd/common.sh new file mode 100644 index 0000000..1cdeee9 --- /dev/null +++ b/root/usr/share/container-scripts/httpd/common.sh @@ -0,0 +1,149 @@ +# Set of functions used in other scripts + +config_general() { + sed -i -e 's/^Listen 80/Listen 0.0.0.0:8080/' ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \ + sed -i -e '151s%AllowOverride None%AllowOverride All%' ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \ + sed -i -e 's/^Listen 443/Listen 0.0.0.0:8443/' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf + sed -i -e 's/_default_:443/_default_:8443/' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf +} + +config_log_to_stdout() { + sed -ri " s!^(\s*CustomLog)\s+\S+!\1 |/usr/bin/cat!g; s!^(\s*ErrorLog)\s+\S+!\1 |/usr/bin/cat!g;" ${HTTPD_MAIN_CONF_PATH}/httpd.conf + sed -ri " s!^(\s*CustomLog)\s+\S+!\1 |/usr/bin/cat!g; s!^(\s*TransferLog)\s+\S+!\1 |/usr/bin/cat!g; s!^(\s*ErrorLog)\s+\S+!\1 |/usr/bin/cat!g;" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf +} + +runs_privileged() { + test "$(id -u)" == "0" + return $? +} + +config_privileged() { + # Change the s2i permissions back to the normal ones + chmod 644 ${HTTPD_MAIN_CONF_PATH}/* && \ + chmod 755 ${HTTPD_MAIN_CONF_PATH} && \ + chmod 644 ${HTTPD_MAIN_CONF_D_PATH}/* && \ + chmod 755 ${HTTPD_MAIN_CONF_D_PATH} && \ + chmod 644 ${HTTPD_MAIN_CONF_MODULES_D_PATH}/* && \ + chmod 755 ${HTTPD_MAIN_CONF_MODULES_D_PATH} && \ + chmod 600 /etc/pki/tls/certs/localhost.crt && \ + chmod 600 /etc/pki/tls/private/localhost.key && \ + chmod 710 ${HTTPD_VAR_RUN} + + if ! [ -v HTTPD_LOG_TO_VOLUME ] ; then + config_log_to_stdout + fi +} + +config_s2i() { + sed -i -e "s%^DocumentRoot \"${HTTPD_DATA_ORIG_PATH}/html\"%DocumentRoot \"${HTTPD_APP_ROOT}/src\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf + sed -i -e "s%^> ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \ + head -n151 ${HTTPD_MAIN_CONF_PATH}/httpd.conf | tail -n1 | grep "AllowOverride All" || exit +} + +config_non_privileged() { + sed -i -e "s/^User apache/User default/" ${HTTPD_MAIN_CONF_PATH}/httpd.conf + sed -i -e "s/^Group apache/Group root/" ${HTTPD_MAIN_CONF_PATH}/httpd.conf + config_log_to_stdout + if [ -v HTTPD_LOG_TO_VOLUME ] ; then + echo "Error: Option HTTPD_LOG_TO_VOLUME is only valid for privileged runs (as UID 0)." + return 1 + fi +} + +config_mpm() { + if [ -v HTTPD_MPM -a -f ${HTTPD_MAIN_CONF_MODULES_D_PATH}/00-mpm.conf ]; then + local mpmconf=${HTTPD_MAIN_CONF_MODULES_D_PATH}/00-mpm.conf + sed -i -e 's,^LoadModule,#LoadModule,' ${mpmconf} + sed -i -e "/LoadModule mpm_${HTTPD_MPM}/s,^#LoadModule,LoadModule," ${mpmconf} + echo "---> Set MPM to ${HTTPD_MPM} in ${mpmconf}" + fi +} + +# get_matched_files finds file for image extending +function get_matched_files() { + local custom_dir default_dir + custom_dir="$1" + default_dir="$2" + files_matched="$3" + find "$default_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n" + [ -d "$custom_dir" ] && find "$custom_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n" +} + +# process_extending_files process extending files in $1 and $2 directories +# - source all *.sh files +# (if there are files with same name source only file from $1) +function process_extending_files() { + local custom_dir default_dir + custom_dir=$1 + default_dir=$2 + while read filename ; do + echo "=> sourcing $filename ..." + # Custom file is prefered + if [ -f $custom_dir/$filename ]; then + source $custom_dir/$filename + elif [ -f $default_dir/$filename ]; then + source $default_dir/$filename + fi + done <<<"$(get_matched_files "$custom_dir" "$default_dir" '*.sh' | sort -u)" +} + +# Set current user in nss_wrapper +generate_container_user() { + local passwd_output_dir="${HTTPD_APP_ROOT}/etc" + + export USER_ID=$(id -u) + export GROUP_ID=$(id -g) + envsubst < ${HTTPD_CONTAINER_SCRIPTS_PATH}/passwd.template > ${passwd_output_dir}/passwd + export LD_PRELOAD=libnss_wrapper.so + export NSS_WRAPPER_PASSWD=${passwd_output_dir}/passwd + export NSS_WRAPPER_GROUP=/etc/group +} + +# Copy config files from application to the location where httd expects them +# Param sets the directory where to look for files +process_config_files() { + local dir=${1:-.} + if [ -d ${dir}/httpd-cfg ]; then + echo "---> Copying httpd configuration files..." + if [ "$(ls -A ${dir}/httpd-cfg/*.conf)" ]; then + cp -v ${dir}/httpd-cfg/*.conf "${HTTPD_CONFIGURATION_PATH}" + rm -rf ${dir}/httpd-cfg + fi + else + if [ -d ${dir}/cfg ]; then + echo "---> Copying httpd configuration files from deprecated './cfg' directory, use './httpd-cfg' instead..." + if [ "$(ls -A ${dir}/cfg/*.conf)" ]; then + cp -v ${dir}/cfg/*.conf "${HTTPD_CONFIGURATION_PATH}" + rm -rf ${dir}/cfg + fi + fi + fi +} + +# Copy SSL files provided in application source +process_ssl_certs() { + local dir=${1:-.} + if [ -d ${dir}/httpd-ssl/private ] && [ -d ${dir}/httpd-ssl/certs ]; then + echo "---> Moving the httpd-ssl directory included in the source to a directory that isn't exposed by httpd..." + mv ${dir}/httpd-ssl ${HTTPD_APP_ROOT} + fi + if [ -d ${HTTPD_APP_ROOT}/httpd-ssl/private ] && [ -d ${HTTPD_APP_ROOT}/httpd-ssl/certs ]; then + echo "---> Looking for SSL certs for httpd..." + local ssl_cert="$(ls -A ${HTTPD_APP_ROOT}/httpd-ssl/certs/*.pem | head -n 1)" + local ssl_private="$(ls -A ${HTTPD_APP_ROOT}/httpd-ssl/private/*.pem | head -n 1)" + if [ -f "${ssl_cert}" ] ; then + # do sed for SSLCertificateFile and SSLCertificateKeyFile + echo "---> Setting SSL cert file for httpd..." + sed -i -e "s|^SSLCertificateFile .*$|SSLCertificateFile ${ssl_cert}|" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf + if [ -f "${ssl_private}" ]; then + echo "---> Setting SSL key file for httpd..." + sed -i -e "s|^SSLCertificateKeyFile .*$|SSLCertificateKeyFile ${ssl_private}|" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf + else + echo "---> Removing SSL key file settings for httpd..." + sed -i '/^SSLCertificateKeyFile .*/d' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf + fi + fi + fi +} + diff --git a/root/usr/share/container-scripts/httpd/passwd.template b/root/usr/share/container-scripts/httpd/passwd.template new file mode 100644 index 0000000..7ad0b78 --- /dev/null +++ b/root/usr/share/container-scripts/httpd/passwd.template @@ -0,0 +1,15 @@ +root:x:0:0:root:/root:/bin/bash +bin:x:1:1:bin:/bin:/sbin/nologin +daemon:x:2:2:daemon:/sbin:/sbin/nologin +adm:x:3:4:adm:/var/adm:/sbin/nologin +lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin +sync:x:5:0:sync:/sbin:/bin/sync +shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown +halt:x:7:0:halt:/sbin:/sbin/halt +mail:x:8:12:mail:/var/spool/mail:/sbin/nologin +operator:x:11:0:operator:/root:/sbin/nologin +games:x:12:100:games:/usr/games:/sbin/nologin +ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin +nobody:x:99:99:Nobody:/:/sbin/nologin +default:x:${USER_ID}:${GROUP_ID}:Default Application User:${HOME}:/sbin/nologin +apache:x:48:48:Apache:/usr/share/httpd:/sbin/nologin diff --git a/root/usr/share/container-scripts/httpd/post-assemble/20-copy-config.sh b/root/usr/share/container-scripts/httpd/post-assemble/20-copy-config.sh new file mode 100644 index 0000000..2fd03c7 --- /dev/null +++ b/root/usr/share/container-scripts/httpd/post-assemble/20-copy-config.sh @@ -0,0 +1,4 @@ +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +# Copy config files from application to the location where httpd expects them +process_config_files diff --git a/root/usr/share/container-scripts/httpd/post-assemble/40-ssl-certs.sh b/root/usr/share/container-scripts/httpd/post-assemble/40-ssl-certs.sh new file mode 100644 index 0000000..cbad2c3 --- /dev/null +++ b/root/usr/share/container-scripts/httpd/post-assemble/40-ssl-certs.sh @@ -0,0 +1,4 @@ +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +# Copy SSL files provided in application source +process_ssl_certs diff --git a/root/usr/share/container-scripts/httpd/pre-init/10-set-mpm.sh b/root/usr/share/container-scripts/httpd/pre-init/10-set-mpm.sh new file mode 100644 index 0000000..f7de495 --- /dev/null +++ b/root/usr/share/container-scripts/httpd/pre-init/10-set-mpm.sh @@ -0,0 +1,3 @@ +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +config_mpm diff --git a/root/usr/share/container-scripts/httpd/pre-init/20-copy-config.sh b/root/usr/share/container-scripts/httpd/pre-init/20-copy-config.sh new file mode 100644 index 0000000..f7ce08b --- /dev/null +++ b/root/usr/share/container-scripts/httpd/pre-init/20-copy-config.sh @@ -0,0 +1,4 @@ +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +# Copy config files from application to the location where httd expects them +process_config_files ${HTTPD_APP_ROOT}/src diff --git a/root/usr/share/container-scripts/httpd/pre-init/40-ssl-certs.sh b/root/usr/share/container-scripts/httpd/pre-init/40-ssl-certs.sh new file mode 100644 index 0000000..38bc8cf --- /dev/null +++ b/root/usr/share/container-scripts/httpd/pre-init/40-ssl-certs.sh @@ -0,0 +1,4 @@ +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +# Copy SSL files provided in application source +process_ssl_certs ${HTTPD_APP_ROOT}/src diff --git a/s2i/bin/assemble b/s2i/bin/assemble new file mode 100755 index 0000000..d8b61ee --- /dev/null +++ b/s2i/bin/assemble @@ -0,0 +1,17 @@ +#!/bin/bash + +set -e + +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +echo "---> Enabling s2i support in httpd24 image" + +config_s2i + +echo "---> Installing application source" +cp -Rf /tmp/src/. ./ + +process_extending_files ${HTTPD_APP_ROOT}/src/httpd-post-assemble/ ${HTTPD_CONTAINER_SCRIPTS_PATH}/post-assemble/ + +# Fix source directory permissions +fix-permissions ./ diff --git a/s2i/bin/run b/s2i/bin/run new file mode 100755 index 0000000..f8f8aa3 --- /dev/null +++ b/s2i/bin/run @@ -0,0 +1,7 @@ +#!/bin/bash + +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +export HTTPD_RUN_BY_S2I=1 + +exec run-httpd $@ diff --git a/s2i/bin/usage b/s2i/bin/usage new file mode 100755 index 0000000..69ed8de --- /dev/null +++ b/s2i/bin/usage @@ -0,0 +1,17 @@ +#!/bin/sh + +DISTRO=`cat /etc/*-release | grep ^ID= | grep -Po '".*?"' | tr -d '"'` +NAMESPACE=centos +[[ $DISTRO =~ rhel* ]] && NAMESPACE=rhscl + +cat < ${HTTPD_APP_ROOT}/src/index.html diff --git a/test/pre-init-test-app/index.html b/test/pre-init-test-app/index.html new file mode 100644 index 0000000..38f417d --- /dev/null +++ b/test/pre-init-test-app/index.html @@ -0,0 +1 @@ +This is a sample s2i application with static content. diff --git a/test/run b/test/run new file mode 100755 index 0000000..d73bc3b --- /dev/null +++ b/test/run @@ -0,0 +1,297 @@ +#!/usr/bin/env bash + +set -e +IMAGE_NAME="${IMAGE_NAME:-rhscl/httpd-24-rhel7}" + +THISDIR=$(dirname ${BASH_SOURCE[0]}) +. ${THISDIR}/utils.sh +test_dir="$(readlink -zf $(dirname "${BASH_SOURCE[0]}"))" + +. "$test_dir/test-lib.sh" + +function _container_is_scl() { + docker inspect --format='{{.ContainerConfig.Env}}' "${1-$IMAGE_NAME}" | grep -q HTTPD_SCL + return $? +} + +function create_container() { + local name="$1" ; shift + local image="${1-$IMAGE_NAME}" + [ -n "$1" ] && shift + cidfile="$CIDFILE_DIR/$name" + # create container with a cidfile in a directory for cleanup + docker run ${DOCKER_ARGS:-} --cidfile $cidfile -d $image || return 1 + echo docker run ${DOCKER_ARGS:-} --cidfile $cidfile -d $image + echo "Created container $(cat $cidfile)" +} + +function update_overall() { + res="$1" + if [ "$res" != 0 ]; then + overall="$res" + fi +} + +function get_cid() { + local id="$1" ; shift || return 1 + echo $(cat "$CIDFILE_DIR/$id") +} + +function get_container_ip() { + local id="$1" ; shift + docker inspect --format='{{.NetworkSettings.IPAddress}}' $(get_cid "$id") +} + +function rm_container() { + local name="$1" + local cid="`get_cid $name`" + docker kill "$cid" || : + docker rm "$cid" + rm -f "$CIDFILE_DIR/$name" +} + +function run() { + cmd="$1" + expected_res="${2:-0}" + msg="${3:-Running command '$cmd'}" + set +e + run_command "$cmd" "$expected_res" "$msg" + res=$? + set -e + test "$res" -eq "$expected_res" && res=0 || res=1 + update_overall $res + return $res +} + + +function _check_test_page() { + run "curl ${1}:8080 > output" + if ! run "fgrep -e 'Test Page for the Apache HTTP Server on' output" ; then + cat output + return 1 + fi +} + +function run_default_page_test() { + # Check default page + run "create_container test_default_page" + sleep 2 + cip=$(get_container_ip 'test_default_page') + _check_test_page ${cip} +} + +function run_as_root_test() { + # Try running as root + DOCKER_ARGS="--user 0" + run "create_container test_run_as_root" + DOCKER_ARGS= + sleep 2 + cip=$(get_container_ip 'test_run_as_root') + _check_test_page ${cip} +} + + +function run_log_to_volume_test() { + _run_invalid_log_volume_test + if _container_is_scl ; then + _run_log_to_volume_test old /var/log/httpd24 + else + _run_log_to_volume_test new /var/log/httpd + fi +} + +function _run_log_to_volume_test() { + # Check the HTTP_LOG_TO_VOLUME env variable + local variant=${1} + local volume_dir=${2} + local logs_dir=$(mktemp -d /tmp/httpd-test-volume-XXXXXX) + run "ls -d ${logs_dir} || mkdir ${logs_dir}" 0 'Create log directory' + run "chown -R 1001:1001 ${logs_dir}" + run "chcon -Rvt svirt_sandbox_file_t ${logs_dir}" 0 'Change SELinux context on the log dir' + DOCKER_ARGS="-e HTTPD_LOG_TO_VOLUME=1 --user 0 -v ${logs_dir}:${volume_dir}" + run "create_container test_log_dir_${variant}" + DOCKER_ARGS= + sleep 2 + cip=$(get_container_ip "test_log_dir_${variant}") + run "curl ${cip}:8080 > /dev/null" + ls ${logs_dir} > output + run "grep -e '^access_log$' output" 0 "Checking that file access_log exists" + run "grep -e '^error_log$' output" 0 "Checking that file error_log exists" + run "grep -e '^ssl_access_log$' output" 0 "Checking that file ssl_access_log exists" + run "grep -e '^ssl_error_log$' output" 0 "Checking that file ssl_error_log exists" + run "grep -e '^ssl_request_log$' output" 0 "Checking that file ssl_request_log exists" +} + +function _run_invalid_log_volume_test() { + # Check wrong usage of the HTTP_LOG_TO_VOLUME env variable + DOCKER_ARGS="-e HTTPD_LOG_TO_VOLUME=1 --user 1001" + run "create_container test_log_dir_fail" + DOCKER_ARGS= + sleep 2 + cid=$(get_cid "test_log_dir_fail") + exit_status=$(docker inspect -f '{{.State.ExitCode}}' ${cid}) + run "test $exit_status == 1" 0 "Checking that setting HTTPD_LOG_TO_VOLUME is not allowed if UID is not 0" +} + + +function run_data_volume_test() { + if _container_is_scl ; then + _run_data_volume_test old /opt/rh/httpd24/root/var/www + fi + _run_data_volume_test new /var/www +} + +function _run_data_volume_test() { + local variant=${1} + local volume_dir=${2} + # Test that docker volume for DocumentRoot works + datadir=$(mktemp -d /tmp/httpd-test-data-XXXXXX) + run "mkdir -p ${datadir}/html" 0 'Create document root' + run "echo hello > ${datadir}/html/index.html" + run "chown -R 1001:1001 ${datadir}" + run "chcon -Rvt svirt_sandbox_file_t ${datadir}/" 0 'Change SELinux context on the document root' + DOCKER_ARGS="-v ${datadir}:${volume_dir}" + run "create_container test_doc_root_${variant}" + DOCKER_ARGS= + sleep 2 + cip=$(get_container_ip "test_doc_root_${variant}") + run "curl ${cip}:8080 > output" + run "grep -e '^hello$' output" +} + +function _run_mpm_config_test() { + local mpm=$1 + # Check worker MPM can be configured + DOCKER_ARGS="-e HTTPD_MPM=$mpm --user 1001" + run "create_container test_mpm_${mpm}" + DOCKER_ARGS= + sleep 2 + cid=$(get_cid "test_mpm_$mpm") + run "docker logs $cid | grep -s mpm_${mpm}':notice.*resuming normal operations'" +} + +function run_mpm_config_test() { + for m in worker event prefork; do + _run_mpm_config_test $m + done +} + +function run_s2i_test() { + # Test s2i use case + # Since we built the candidate image locally, we don't want S2I attempt to pull + # it from Docker hub + s2i_args="--pull-policy=never" + run "ct_s2i_usage ${IMAGE_NAME} ${s2i_args}" 0 "Testing 's2i usage'" + run "ct_s2i_build_as_df file://${test_dir}/sample-test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp ${s2i_args}" 0 "Testing 's2i build'" + DOCKER_ARGS='--user 1000' + create_container testing-app-s2i ${IMAGE_NAME}-testapp + DOCKER_ARGS= + sleep 5 + cip=$(get_container_ip 'testing-app-s2i') + run "curl ${cip}:8080 > output_s2i" + run "fgrep -e 'This is a sample s2i application with static content.' output_s2i" + # 0 "Checking page served by s2i feature" + sleep 2 +} + +function run_pre_init_test() { + # Test s2i use case #2 - testing pre-init script + # Since we built the candidate image locally, we don't want S2I attempt to pull + # it from Docker hub + s2i_args="--pull-policy=never" + run "ct_s2i_build_as_df file://${test_dir}/pre-init-test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp2 ${s2i_args}" 0 "Testing 's2i build' with pre-init script" + DOCKER_ARGS='--user 1000' + create_container testing-app-pre-init ${IMAGE_NAME}-testapp2 + DOCKER_ARGS= + sleep 5 + cip=$(get_container_ip 'testing-app-pre-init') + run "curl ${cip}:8080 > output_pre_init" + run "fgrep -e 'This content was replaced by pre-init script.' output_pre_init" + # 0 "Checking page served by s2i feature and edited by pre-init script" + sleep 2 +} + +function run_self_cert_test() { + # Test s2i use case #3 - using own ssl certs + # Since we built the candidate image locally, we don't want S2I attempt to pull + # it from Docker hub + s2i_args="--pull-policy=never" + run "ct_s2i_build_as_df file://${test_dir}/self-signed-ssl ${IMAGE_NAME} ${IMAGE_NAME}-self-signed ${s2i_args}" 0 "Testing 's2i build' with self-signed cert" + DOCKER_ARGS='--user 1000' + create_container testing-self-signed ${IMAGE_NAME}-self-signed + DOCKER_ARGS= + sleep 5 + cip=$(get_container_ip 'testing-self-signed') + run "curl -k https://${cip}:8443 > output_ssl_cert" + run "fgrep -e 'SSL test works' output_ssl_cert" + echo | openssl s_client -showcerts -servername ${cip} -connect ${cip}:8443 2>/dev/null | openssl x509 -inform pem -noout -text >./servercert + openssl x509 -in ${test_dir}/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem -inform pem -noout -text >./configcert + run "diff ./configcert ./servercert" + run "diff ./configcert ./servercert >cert.diff" + sleep 2 +} + +function run_all_tests() { + for test_case in $TEST_LIST; do + : "Running test $test_case" + $test_case + done; +} + + +function cleanup() { + for cidfile in $CIDFILE_DIR/* ; do + CONTAINER=$(cat $cidfile) + + echo "Stopping and removing container $CONTAINER..." + docker stop $CONTAINER + exit_status=$(docker inspect -f '{{.State.ExitCode}}' $CONTAINER) + if [ "$exit_status" != "0" ]; then + echo "Dumping logs for $CONTAINER" + docker logs $CONTAINER + fi + docker rm $CONTAINER + rm $cidfile + echo "Done." + done + if [ "$overall" -eq 0 ] ; then + print_result "pass" "All tests passed." + else + print_result "fail" "Tests failed." + fi + rmdir $CIDFILE_DIR + rm -Rf "$working_dir" + return "$overall" +} +trap cleanup EXIT + + +working_dir=`mktemp -d` +pushd $working_dir > /dev/null || exit 1 + +CIDFILE_DIR=`pwd`/cid_files +mkdir "$CIDFILE_DIR" + +overall=0 + +run "docker inspect $IMAGE_NAME >/dev/null || docker pull $IMAGE_NAME" 0 + + +TEST_LIST="\ +run_self_cert_test +run_default_page_test +run_as_root_test +run_log_to_volume_test +run_data_volume_test +run_s2i_test +run_pre_init_test +run_mpm_config_test +" + +test $# -eq 1 -a "${1-}" == --list && echo "$TEST_LIST" && exit 0 + +TEST_LIST=${@:-$TEST_LIST} run_all_tests + +popd > /dev/null + +exit "$overall" diff --git a/test/run-openshift b/test/run-openshift new file mode 100755 index 0000000..c72bc64 --- /dev/null +++ b/test/run-openshift @@ -0,0 +1,35 @@ +#!/bin/bash +# +# Test the httpd image in OpenShift. +# +# IMAGE_NAME specifies a name of the candidate image used for testing. +# VERSION specifies a version of the python in the candidate image. +# The image has to be available before this script is executed. + +THISDIR=$(dirname ${BASH_SOURCE[0]}) + +source "${THISDIR}/test-lib.sh" +source "${THISDIR}/test-lib-openshift.sh" + +BRANCH_TO_TEST=master + +set -eo nounset + +test -n "${IMAGE_NAME-}" || false 'make sure $IMAGE_NAME is defined' +test -n "${VERSION-}" || false 'make sure $VERSION is defined' + +ct_os_cluster_up + +# test local app +ct_os_test_s2i_app "${IMAGE_NAME}" "${THISDIR}/sample-test-app" . 'This is a sample s2i application with static content' + +# test remote example app +ct_os_test_s2i_app "${IMAGE_NAME}" "https://github.com/sclorg/httpd-ex#${BRANCH_TO_TEST}" . 'Welcome to your static httpd application on OpenShift' + +# test template from the example app +ct_os_test_template_app "${IMAGE_NAME}" \ + "https://raw.githubusercontent.com/openshift/httpd-ex/${BRANCH_TO_TEST}/openshift/templates/httpd.json" \ + httpd \ + 'Welcome to your static httpd application on OpenShift' \ + 8080 http 200 "-p SOURCE_REPOSITORY_REF=${BRANCH_TO_TEST} -p NAME=httpd-testing" + diff --git a/test/sample-test-app/index.html b/test/sample-test-app/index.html new file mode 100644 index 0000000..38f417d --- /dev/null +++ b/test/sample-test-app/index.html @@ -0,0 +1 @@ +This is a sample s2i application with static content. diff --git a/test/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem b/test/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem new file mode 100644 index 0000000..8495b88 --- /dev/null +++ b/test/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem @@ -0,0 +1,20 @@ +-----BEGIN CERTIFICATE----- +MIIDWjCCAkKgAwIBAgIJAI4x7HuBG49oMA0GCSqGSIb3DQEBCwUAMEIxCzAJBgNV +BAYTAlhYMRUwEwYDVQQHDAxEZWZhdWx0IENpdHkxHDAaBgNVBAoME0RlZmF1bHQg +Q29tcGFueSBMdGQwHhcNMTcxMjAzMjMzMzU3WhcNMTgwMTAyMjMzMzU3WjBCMQsw +CQYDVQQGEwJYWDEVMBMGA1UEBwwMRGVmYXVsdCBDaXR5MRwwGgYDVQQKDBNEZWZh +dWx0IENvbXBhbnkgTHRkMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA +vH4Vdq0a3UWUQd8Z6s2csxhxjAOyUx0rszGL0m3uTjQido6JRBdjN2dXiZc3LFoq +YeOKR3CeHsn7UdrlzaboHFDfjAaextse0740mB1g14H1bAS0POuTPeKa+3wGfzCb +sTSXnfSrICl3n2D/3KSO93WwmS90kBD6HmKt5nfkLpJnROM/4bHmuoV0Ry8CDjzj +mka7pQU4yzyMKLU3sHpncZU6g7o4Vezic9ksVzIAbdPCSbF7ktVz/hisyCuzyKN6 +s2327jq593vBgGOsNU5PDPDjKW74Q0Bv/FxPK4nx+o4IkcRW1QEb+yAx8XOM7CDZ +ViKvI/A0b+Y4Y3rIQ465+wIDAQABo1MwUTAdBgNVHQ4EFgQUAY1i6ZNbqO1+46aw +pldCyPaWoYswHwYDVR0jBBgwFoAUAY1i6ZNbqO1+46awpldCyPaWoYswDwYDVR0T +AQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEADhGjnYGq9JvQcygMYEQiIdyS +t06Nu7NUkWz52GJp7WFognWyG+0jAomBR0GSUchfubvVZ7cHIaVKLhiGOqg+HIol +7tNRfvE6x/Idk674g6OTRAWxO/wOlgnRMpRy6XhHOtb4HcPcpWFZJS8MC8+HRWIs +kzMErXe0/obnKn9O04kcEREfmB7kfcD4ooqk5gwbdQk1W6a44LcN6AB5qYPjOzgF +Qnb2aLQW9XhgNhiMsYqDzCZsy0az0rz7NgkVOnKrGJ8x3kVX13GR2joVVHOazms9 +Gd90z+mLMDTbqCRGIPMLvEp4HtAmBxbgsj/zHyinajIqV96B3Cr3zTdW29lHJg== +-----END CERTIFICATE----- diff --git a/test/self-signed-ssl/httpd-ssl/private/server-key.pem b/test/self-signed-ssl/httpd-ssl/private/server-key.pem new file mode 100644 index 0000000..ff2ac89 --- /dev/null +++ b/test/self-signed-ssl/httpd-ssl/private/server-key.pem @@ -0,0 +1,28 @@ +-----BEGIN PRIVATE KEY----- +MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQC8fhV2rRrdRZRB +3xnqzZyzGHGMA7JTHSuzMYvSbe5ONCJ2jolEF2M3Z1eJlzcsWiph44pHcJ4eyftR +2uXNpugcUN+MBp7G2x7TvjSYHWDXgfVsBLQ865M94pr7fAZ/MJuxNJed9KsgKXef +YP/cpI73dbCZL3SQEPoeYq3md+QukmdE4z/hsea6hXRHLwIOPOOaRrulBTjLPIwo +tTewemdxlTqDujhV7OJz2SxXMgBt08JJsXuS1XP+GKzIK7PIo3qzbfbuOrn3e8GA +Y6w1Tk8M8OMpbvhDQG/8XE8rifH6jgiRxFbVARv7IDHxc4zsINlWIq8j8DRv5jhj +eshDjrn7AgMBAAECggEARZxeutxE/pCypv0IqkFS7IVLccTvt2gfemcC1yzIBFOW +oqgTI3Vrq8tbdbHFq3iFDG+m4qlBi+dWDC3GDoPkVoi7dg//1TqZEOO+sqqu2Afj +pge6tIDfeMxWJifwkkpWRURB9hCknhUSW2bMNyUCs3rgREJVTtsmM9CHnoSKXXQL +aOeYXalFVpx3ceK+xdp0VGfpsqEabBKs0yy3EDiQy2huoWce3EVFLVrwx/IkhcsZ +JlI5LPpoiTglSs1g9i88JHS2slBtKtb1lWl/yXHhK1g7s34c6f9jP8snuFE5ddMn +0L4GDA9teaPGvB533eb2RIFy2kUYgpr5c03G6rpoOQKBgQDpY6BFJkPGENnC5Bdb +fJCuN2nyRdC1qvv6ESFaQYb0s6QjKDqpb0dUSYN3+zNgtiAysbQLeU/d9mmt4UR8 +ohjRkOySU0eQ/YNFokjw6g6GPoiMHJJ9cP75NA94uIMIUTY7uHEWWZwXI5UphdPC +p5/3MaF1VlYQys9a5wtiEaDSfQKBgQDOwPV0zQjUabkVQ4yV0amP8xybvHH8ghG0 +RMStHg96RfDmg35JQaw22A2xiVROCoZgLqiE1DFSl/3gBF/vfqBh/uzdxwNerJC6 +ROdCxyS4rys5d/02P4aNOa73sD+ZKyEZRTF1v3bmOGKidRFF5oxIpuHjFWlJFKx1 +O/b3AI0v1wKBgQC/L4N84emm+OrKAfs4UIRckrxRYOulxhmAMkQ2IXOiRP5yZmQX +pDa0TzxJLxhZYxhhLr0koQ3R8CeF7wEhb9AQ7D0/aMU5etLsWhKSd8nKIrPMwyMl +a0kTb5g09kEwsQZSSbcp7eI1+koYp65eyN37q0ZuTnlWbC0MdDQY9APgKQKBgQCb +HqaKNXLUe2XDkGSf2ygOumXSanZS7vt9dsLg59bQ9DyjljBfogglNcBAXTqFOtxK +uXbyAYnn3+U399BKjYSjQXJRioj6tRn4xs2DiooAjlwtx9qQouS+fHLLns54iqVQ +oltTbo00eUV3gcGt4iWKNLrxdxUBIaOqaY0HEMDdDQKBgQCRvcHDF7JSPuBiO3Tw +PSOUD4q6dD/dhI+X2ZKg83w94SZXXms6eMSbedUkLoJ8TDunmdRUUWb6rgP/pJwr +zKRTskItF15i9IWCwC6jBrSfx5n2JcSoBALyc0aR9heF0GQjWwqURd+PC/msomrW +z9SCl8mpQVFtBlui7PcnDLTFAg== +-----END PRIVATE KEY----- diff --git a/test/self-signed-ssl/index.html b/test/self-signed-ssl/index.html new file mode 100644 index 0000000..82ff698 --- /dev/null +++ b/test/self-signed-ssl/index.html @@ -0,0 +1 @@ +SSL test works diff --git a/test/test-lib-openshift.sh b/test/test-lib-openshift.sh new file mode 100644 index 0000000..f988ac5 --- /dev/null +++ b/test/test-lib-openshift.sh @@ -0,0 +1,925 @@ +# Set of functions for testing docker images in OpenShift using 'oc' command + +# ct_os_get_status +# -------------------- +# Returns status of all objects to make debugging easier. +function ct_os_get_status() { + oc get all + oc status +} + +# ct_os_print_logs +# -------------------- +# Returns status of all objects and logs from all pods. +function ct_os_print_logs() { + ct_os_get_status + while read pod_name; do + echo "INFO: printing logs for pod ${pod_name}" + oc logs ${pod_name} + done < <(oc get pods --no-headers=true -o custom-columns=NAME:.metadata.name) +} + +# ct_os_enable_print_logs +# -------------------- +# Enables automatic printing of pod logs on ERR. +function ct_os_enable_print_logs() { + set -E + trap ct_os_print_logs ERR +} + +# ct_get_public_ip +# -------------------- +# Returns best guess for the IP that the node is accessible from other computers. +# This is a bit funny heuristic, simply goes through all IPv4 addresses that +# hostname -I returns and de-prioritizes IP addresses commonly used for local +# addressing. The rest of addresses are taken as public with higher probability. +function ct_get_public_ip() { + local hostnames=$(hostname -I) + local public_ip='' + local found_ip + for guess_exp in '127\.0\.0\.1' '192\.168\.[0-9\.]*' '172\.[0-9\.]*' \ + '10\.[0-9\.]*' '[0-9\.]*' ; do + found_ip=$(echo "${hostnames}" | grep -oe "${guess_exp}") + if [ -n "${found_ip}" ] ; then + hostnames=$(echo "${hostnames}" | sed -e "s/${found_ip}//") + public_ip="${found_ip}" + fi + done + if [ -z "${public_ip}" ] ; then + echo "ERROR: public IP could not be guessed." >&2 + return 1 + fi + echo "${public_ip}" +} + +# ct_os_run_in_pod POD_NAME CMD +# -------------------- +# Runs [cmd] in the pod specified by prefix [pod_prefix]. +# Arguments: pod_name - full name of the pod +# Arguments: cmd - command to be run in the pod +function ct_os_run_in_pod() { + local pod_name="$1" ; shift + + oc exec "$pod_name" -- "$@" +} + +# ct_os_get_service_ip SERVICE_NAME +# -------------------- +# Returns IP of the service specified by [service_name]. +# Arguments: service_name - name of the service +function ct_os_get_service_ip() { + local service_name="${1}" ; shift + oc get "svc/${service_name}" -o yaml | grep clusterIP | \ + cut -d':' -f2 | grep -oe '172\.30\.[0-9\.]*' +} + + +# ct_os_get_all_pods_status +# -------------------- +# Returns status of all pods. +function ct_os_get_all_pods_status() { + oc get pods -o custom-columns=Ready:status.containerStatuses[0].ready,NAME:.metadata.name +} + +# ct_os_get_all_pods_name +# -------------------- +# Returns the full name of all pods. +function ct_os_get_all_pods_name() { + oc get pods --no-headers -o custom-columns=NAME:.metadata.name +} + +# ct_os_get_pod_status POD_PREFIX +# -------------------- +# Returns status of the pod specified by prefix [pod_prefix]. +# Note: Ignores -build and -deploy pods +# Arguments: pod_prefix - prefix or whole ID of the pod +function ct_os_get_pod_status() { + local pod_prefix="${1}" ; shift + ct_os_get_all_pods_status | grep -e "${pod_prefix}" | grep -Ev "(build|deploy)$" \ + | awk '{print $1}' | head -n 1 +} + +# ct_os_get_pod_name POD_PREFIX +# -------------------- +# Returns the full name of pods specified by prefix [pod_prefix]. +# Note: Ignores -build and -deploy pods +# Arguments: pod_prefix - prefix or whole ID of the pod +function ct_os_get_pod_name() { + local pod_prefix="${1}" ; shift + ct_os_get_all_pods_name | grep -e "^${pod_prefix}" | grep -Ev "(build|deploy)$" +} + +# ct_os_get_pod_ip POD_NAME +# -------------------- +# Returns the ip of the pod specified by [pod_name]. +# Arguments: pod_name - full name of the pod +function ct_os_get_pod_ip() { + local pod_name="${1}" + oc get pod "$pod_name" --no-headers -o custom-columns=IP:status.podIP +} + +# ct_os_check_pod_readiness POD_PREFIX STATUS +# -------------------- +# Checks whether the pod is ready. +# Arguments: pod_prefix - prefix or whole ID of the pod +# Arguments: status - expected status (true, false) +function ct_os_check_pod_readiness() { + local pod_prefix="${1}" ; shift + local status="${1}" ; shift + test "$(ct_os_get_pod_status ${pod_prefix})" == "${status}" +} + +# ct_os_wait_pod_ready POD_PREFIX TIMEOUT +# -------------------- +# Wait maximum [timeout] for the pod becomming ready. +# Arguments: pod_prefix - prefix or whole ID of the pod +# Arguments: timeout - how many seconds to wait seconds +function ct_os_wait_pod_ready() { + local pod_prefix="${1}" ; shift + local timeout="${1}" ; shift + SECONDS=0 + echo -n "Waiting for ${pod_prefix} pod becoming ready ..." + while ! ct_os_check_pod_readiness "${pod_prefix}" "true" ; do + echo -n "." + [ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1 + sleep 3 + done + echo " DONE" +} + +# ct_os_wait_rc_ready POD_PREFIX TIMEOUT +# -------------------- +# Wait maximum [timeout] for the rc having desired number of replicas ready. +# Arguments: pod_prefix - prefix of the replication controller +# Arguments: timeout - how many seconds to wait seconds +function ct_os_wait_rc_ready() { + local pod_prefix="${1}" ; shift + local timeout="${1}" ; shift + SECONDS=0 + echo -n "Waiting for ${pod_prefix} pod becoming ready ..." + while ! test "$((oc get --no-headers statefulsets; oc get --no-headers rc) 2>/dev/null \ + | grep "^${pod_prefix}" | awk '$2==$3 {print "ready"}')" == "ready" ; do + echo -n "." + [ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1 + sleep 3 + done + echo " DONE" +} + +# ct_os_deploy_pure_image IMAGE [ENV_PARAMS, ...] +# -------------------- +# Runs [image] in the openshift and optionally specifies env_params +# as environment variables to the image. +# Arguments: image - prefix or whole ID of the pod to run the cmd in +# Arguments: env_params - environment variables parameters for the images. +function ct_os_deploy_pure_image() { + local image="${1}" ; shift + # ignore error exit code, because oc new-app returns error when image exists + oc new-app ${image} "$@" || : + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_deploy_s2i_image IMAGE APP [ENV_PARAMS, ... ] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. +# Arguments: image - prefix or whole ID of the pod to run the cmd in +# Arguments: app - url or local path to git repo with the application sources. +# Arguments: env_params - environment variables parameters for the images. +function ct_os_deploy_s2i_image() { + local image="${1}" ; shift + local app="${1}" ; shift + # ignore error exit code, because oc new-app returns error when image exists + oc new-app "${image}~${app}" "$@" || : + + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_deploy_template_image TEMPLATE [ENV_PARAMS, ...] +# -------------------- +# Runs template in the openshift and optionally gives env_params to use +# specific values in the template. +# Arguments: template - prefix or whole ID of the pod to run the cmd in +# Arguments: env_params - environment variables parameters for the template. +# Example usage: ct_os_deploy_template_image mariadb-ephemeral-template.yaml \ +# DATABASE_SERVICE_NAME=mysql-57-centos7 \ +# DATABASE_IMAGE=mysql-57-centos7 \ +# MYSQL_USER=testu \ +# MYSQL_PASSWORD=testp \ +# MYSQL_DATABASE=testdb +function ct_os_deploy_template_image() { + local template="${1}" ; shift + oc process -f "${template}" "$@" | oc create -f - + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# _ct_os_get_uniq_project_name +# -------------------- +# Returns a uniq name of the OpenShift project. +function _ct_os_get_uniq_project_name() { + local r + while true ; do + r=${RANDOM} + mkdir /var/tmp/sclorg-test-${r} &>/dev/null && echo sclorg-test-${r} && break + done +} + +# ct_os_new_project [PROJECT] +# -------------------- +# Creates a new project in the openshfit using 'os' command. +# Arguments: project - project name, uses a new random name if omitted +# Expects 'os' command that is properly logged in to the OpenShift cluster. +# Not using mktemp, because we cannot use uppercase characters. +function ct_os_new_project() { + if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then + echo "Creating project skipped." + return + fi + local project_name="${1:-$(_ct_os_get_uniq_project_name)}" ; shift || : + oc new-project ${project_name} + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_delete_project [PROJECT] +# -------------------- +# Deletes the specified project in the openshfit +# Arguments: project - project name, uses the current project if omitted +function ct_os_delete_project() { + if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then + echo "Deleting project skipped, cleaning objects only." + ct_delete_all_objects + return + fi + local project_name="${1:-$(oc project -q)}" ; shift || : + oc delete project "${project_name}" +} + +# ct_delete_all_objects +# ----------------- +# Deletes all objects within the project. +# Handy when we have one project and want to run more tests. +function ct_delete_all_objects() { + for x in bc builds dc is isimage istag po pv pvc rc routes secrets svc ; do + oc delete $x --all + done + # for some objects it takes longer to be really deleted, so a dummy sleep + # to avoid some races when other test can see not-yet-deleted objects and can fail + sleep 10 +} + +# ct_os_docker_login +# -------------------- +# Logs in into docker daemon +# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address. +# Does not do anything if REGISTRY_ADDRESS is set. +function ct_os_docker_login() { + [ -n "${REGISTRY_ADDRESS:-}" ] && "REGISTRY_ADDRESS set, not trying to docker login." && return 0 + # docker login fails with "404 page not found" error sometimes, just try it more times + for i in `seq 12` ; do + docker login -u developer -p $(oc whoami -t) ${REGISRTY_ADDRESS:-172.30.1.1:5000} && return 0 || : + sleep 5 + done + return 1 +} + +# ct_os_upload_image IMAGE [IMAGESTREAM] +# -------------------- +# Uploads image from local registry to the OpenShift internal registry. +# Arguments: image - image name to upload +# Arguments: imagestream - name and tag to use for the internal registry. +# In the format of name:tag ($image_name:latest by default) +# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address. +function ct_os_upload_image() { + local input_name="${1}" ; shift + local image_name=${input_name##*/} + local imagestream=${1:-$image_name:latest} + local output_name="${REGISRTY_ADDRESS:-172.30.1.1:5000}/$(oc project -q)/$imagestream" + + ct_os_docker_login + docker tag ${input_name} ${output_name} + docker push ${output_name} +} + +# ct_os_install_in_centos +# -------------------- +# Installs os cluster in CentOS +function ct_os_install_in_centos() { + yum install -y centos-release-openshift-origin + yum install -y wget git net-tools bind-utils iptables-services bridge-utils\ + bash-completion origin-clients docker origin-clients +} + +# ct_os_cluster_up [DIR, IS_PUBLIC, CLUSTER_VERSION] +# -------------------- +# Runs the local OpenShift cluster using 'oc cluster up' and logs in as developer. +# Arguments: dir - directory to keep configuration data in, random if omitted +# Arguments: is_public - sets either private or public hostname for web-UI, +# use "true" for allow remote access to the web-UI, +# "false" is default +# Arguments: cluster_version - version of the OpenShift cluster to use, empty +# means default version of `oc`; example value: 3.7; +# also can be specified outside by OC_CLUSTER_VERSION +function ct_os_cluster_up() { + ct_os_cluster_running && echo "Cluster already running. Nothing is done." && return 0 + ct_os_logged_in && echo "Already logged in to a cluster. Nothing is done." && return 0 + + mkdir -p /var/tmp/openshift + local dir="${1:-$(mktemp -d /var/tmp/openshift/os-data-XXXXXX)}" ; shift || : + local is_public="${1:-'false'}" ; shift || : + local default_cluster_version=${OC_CLUSTER_VERSION:-} + local cluster_version=${1:-${default_cluster_version}} ; shift || : + if ! grep -qe '--insecure-registry.*172\.30\.0\.0' /etc/sysconfig/docker ; then + sed -i "s|OPTIONS='|OPTIONS='--insecure-registry 172.30.0.0/16 |" /etc/sysconfig/docker + fi + + systemctl stop firewalld || : + setenforce 0 + iptables -F + + systemctl restart docker + local cluster_ip="127.0.0.1" + [ "${is_public}" == "true" ] && cluster_ip=$(ct_get_public_ip) + + if [ -n "${cluster_version}" ] ; then + # if $cluster_version is not set, we simply use oc that is available + ct_os_set_path_oc "${cluster_version}" + fi + + mkdir -p ${dir}/{config,data,pv} + case $(oc version| head -n 1) in + "oc v3.1"?.*) + oc cluster up --base-dir="${dir}/data" --public-hostname="${cluster_ip}" + ;; + "oc v3."*) + oc cluster up --host-data-dir="${dir}/data" --host-config-dir="${dir}/config" \ + --host-pv-dir="${dir}/pv" --use-existing-config --public-hostname="${cluster_ip}" + ;; + *) + echo "ERROR: Unexpected oc version." >&2 + return 1 + ;; + esac + oc version + oc login -u system:admin + oc project default + ct_os_wait_rc_ready docker-registry 180 + ct_os_wait_rc_ready router 30 + oc login -u developer -p developer + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_cluster_down +# -------------------- +# Shuts down the local OpenShift cluster using 'oc cluster down' +function ct_os_cluster_down() { + oc cluster down +} + +# ct_os_cluster_running +# -------------------- +# Returns 0 if oc cluster is running +function ct_os_cluster_running() { + oc cluster status &>/dev/null +} + +# ct_os_logged_in +# --------------- +# Returns 0 if logged in to a cluster (remote or local) +function ct_os_logged_in() { + oc whoami >/dev/null +} + +# ct_os_set_path_oc OC_VERSION +# -------------------- +# This is a trick that helps using correct version of the `oc`: +# The input is version of the openshift in format v3.6.0 etc. +# If the currently available version of oc is not of this version, +# it first takes a look into /usr/local/oc-/bin directory, +# and if not found there it downloads the community release from github. +# In the end the PATH variable is changed, so the other tests can still use just 'oc'. +# Arguments: oc_version - X.Y part of the version of OSE (e.g. 3.9) +function ct_os_set_path_oc() { + local oc_version=$(ct_os_get_latest_ver $1) + local oc_path + + if oc version | grep -q "oc ${oc_version%.*}." ; then + echo "Binary oc found already available in version ${oc_version}: `which oc` Doing noting." + return 0 + fi + + # first check whether we already have oc available in /usr/local + local installed_oc_path="/usr/local/oc-${oc_version%.*}/bin" + + if [ -x "${installed_oc_path}/oc" ] ; then + oc_path="${installed_oc_path}" + echo "Binary oc found in ${installed_oc_path}" >&2 + else + # oc not available in /usr/local, try to download it from github (community release) + oc_path="/tmp/oc-${oc_version}-bin" + ct_os_download_upstream_oc "${oc_version}" "${oc_path}" + fi + if [ -z "${oc_path}/oc" ] ; then + echo "ERROR: oc not found installed, nor downloaded" >&1 + return 1 + fi + export PATH="${oc_path}:${PATH}" + if ! oc version | grep -q "oc ${oc_version%.*}." ; then + echo "ERROR: something went wrong, oc located at ${oc_path}, but oc of version ${oc_version} not found in PATH ($PATH)" >&1 + return 1 + else + echo "PATH set correctly, binary oc found in version ${oc_version}: `which oc`" + fi +} + +# ct_os_get_latest_ver VERSION_PART_X +# -------------------- +# Returns full version (vX.Y.Z) from part of the version (X.Y) +# Arguments: vxy - X.Y part of the version +# Returns vX.Y.Z variant of the version +function ct_os_get_latest_ver(){ + local vxy="v$1" + for vz in {3..0} ; do + curl -sif "https://github.com/openshift/origin/releases/tag/${vxy}.${vz}" >/dev/null && echo "${vxy}.${vz}" && return 0 + done + echo "ERROR: version ${vxy} not found in https://github.com/openshift/origin/tags" >&2 + return 1 +} + +# ct_os_download_upstream_oc OC_VERSION OUTPUT_DIR +# -------------------- +# Downloads a particular version of openshift-origin-client-tools from +# github into specified output directory +# Arguments: oc_version - version of OSE (e.g. v3.7.2) +# Arguments: output_dir - output directory +function ct_os_download_upstream_oc() { + local oc_version=$1 + local output_dir=$2 + + # check whether we already have the binary in place + [ -x "${output_dir}/oc" ] && return 0 + + mkdir -p "${output_dir}" + # using html output instead of https://api.github.com/repos/openshift/origin/releases/tags/${oc_version}, + # because API is limited for number of queries if not authenticated + tarball=$(curl -si "https://github.com/openshift/origin/releases/tag/${oc_version}" | grep -o -e "openshift-origin-client-tools-${oc_version}-[a-f0-9]*-linux-64bit.tar.gz" | head -n 1) + + # download, unpack the binaries and then put them into output directory + echo "Downloading https://github.com/openshift/origin/releases/download/${oc_version}/${tarball} into ${output_dir}/" >&2 + curl -sL https://github.com/openshift/origin/releases/download/${oc_version}/"${tarball}" | tar -C "${output_dir}" -xz + mv -f "${output_dir}"/"${tarball%.tar.gz}"/* "${output_dir}/" + + rmdir "${output_dir}"/"${tarball%.tar.gz}" +} + + +# ct_os_test_s2i_app_func IMAGE APP CONTEXT_DIR CHECK_CMD [OC_ARGS] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the container by arbitrary +# function given as argument (such an argument may include string, +# that will be replaced with actual IP). +# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: app - url or local path to git repo with the application sources (compulsory) +# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory) +# Arguments: check_command - CMD line that checks whether the container works (compulsory; '' will be replaced with actual IP) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +function ct_os_test_s2i_app_func() { + local image_name=${1} + local app=${2} + local context_dir=${3} + local check_command=${4} + local oc_args=${5:-} + local import_image=${6:-} + local image_name_no_namespace=${image_name##*/} + local service_name="${image_name_no_namespace}-testing" + local image_tagged="${image_name_no_namespace}:${VERSION}" + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_s2i_app_func() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + ct_os_new_project + # Create a specific imagestream tag for the image so that oc cannot use anything else + if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then + if [ -n "${import_image}" ] ; then + echo "Importing image ${import_image} as ${image_name}:${VERSION}" + oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm + else + echo "Uploading and importing image skipped." + fi + else + if [ -n "${import_image}" ] ; then + echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead." + fi + ct_os_upload_image "${image_name}" "${image_tagged}" + fi + + local app_param="${app}" + if [ -d "${app}" ] ; then + # for local directory, we need to copy the content, otherwise too smart os command + # pulls the git remote repository instead + app_param=$(ct_obtain_input "${app}") + fi + + ct_os_deploy_s2i_image "${image_tagged}" "${app_param}" \ + --context-dir="${context_dir}" \ + --name "${service_name}" \ + ${oc_args} + + if [ -d "${app}" ] ; then + # in order to avoid weird race seen sometimes, let's wait shortly + # before starting the build explicitly + sleep 5 + oc start-build "${service_name}" --from-dir="${app_param}" + fi + + ct_os_wait_pod_ready "${service_name}" 300 + + local ip=$(ct_os_get_service_ip "${service_name}") + local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") + + echo " Checking APP using $check_command_exp ..." + local result=0 + eval "$check_command_exp" || result=1 + + if [ $result -eq 0 ] ; then + echo " Check passed." + else + echo " Check failed." + fi + + ct_os_delete_project + return $result +} + +# ct_os_test_s2i_app IMAGE APP CONTEXT_DIR EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the http response. +# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: app - url or local path to git repo with the application sources (compulsory) +# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory) +# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory) +# Arguments: port - which port to use (optional; default: 8080) +# Arguments: protocol - which protocol to use (optional; default: http) +# Arguments: response_code - what http response code to expect (optional; default: 200) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +function ct_os_test_s2i_app() { + local image_name=${1} + local app=${2} + local context_dir=${3} + local expected_output=${4} + local port=${5:-8080} + local protocol=${6:-http} + local response_code=${7:-200} + local oc_args=${8:-} + local import_image=${9:-} + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_s2i_app() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + ct_os_test_s2i_app_func "${image_name}" \ + "${app}" \ + "${context_dir}" \ + "ct_os_test_response_internal '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ + "${oc_args}" "${import_image}" +} + +# ct_os_test_template_app_func IMAGE APP IMAGE_IN_TEMPLATE CHECK_CMD [OC_ARGS] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the container by arbitrary +# function given as argument (such an argument may include string, +# that will be replaced with actual IP). +# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: template - url or local path to a template to use (compulsory) +# Arguments: name_in_template - image name used in the template +# Arguments: check_command - CMD line that checks whether the container works (compulsory; '' will be replaced with actual IP) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry, +# specify them in this parameter as "|", where "" is a full image name +# (including registry if needed) and "" is a tag under which the image should be available +# in the OpenShift registry. +function ct_os_test_template_app_func() { + local image_name=${1} + local template=${2} + local name_in_template=${3} + local check_command=${4} + local oc_args=${5:-} + local other_images=${6:-} + local import_image=${7:-} + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_template_app_func() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + local service_name="${name_in_template}-testing" + local image_tagged="${name_in_template}:${VERSION}" + + ct_os_new_project + + # Create a specific imagestream tag for the image so that oc cannot use anything else + if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then + if [ -n "${import_image}" ] ; then + echo "Importing image ${import_image} as ${image_name}:${VERSION}" + oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm + else + echo "Uploading and importing image skipped." + fi + else + if [ -n "${import_image}" ] ; then + echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead." + fi + ct_os_upload_image "${image_name}" "${image_tagged}" + + # upload also other images, that template might need (list of pairs in the format | + local images_tags_a + local i_t + for i_t in ${other_images} ; do + echo "${i_t}" + IFS='|' read -ra image_tag_a <<< "${i_t}" + docker pull "${image_tag_a[0]}" + ct_os_upload_image "${image_tag_a[0]}" "${image_tag_a[1]}" + done + fi + + local local_template=$(ct_obtain_input "${template}") + local namespace=${CT_NAMESPACE:-$(oc project -q)} + oc new-app ${local_template} \ + --name "${name_in_template}" \ + -p NAMESPACE="${namespace}" \ + ${oc_args} + + ct_os_wait_pod_ready "${service_name}" 300 + + local ip=$(ct_os_get_service_ip "${service_name}") + local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") + + echo " Checking APP using $check_command_exp ..." + local result=0 + eval "$check_command_exp" || result=1 + + if [ $result -eq 0 ] ; then + echo " Check passed." + else + echo " Check failed." + fi + + ct_os_delete_project + return $result +} + +# params: +# ct_os_test_template_app IMAGE APP IMAGE_IN_TEMPLATE EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the http response. +# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: template - url or local path to a template to use (compulsory) +# Arguments: name_in_template - image name used in the template +# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory) +# Arguments: port - which port to use (optional; default: 8080) +# Arguments: protocol - which protocol to use (optional; default: http) +# Arguments: response_code - what http response code to expect (optional; default: 200) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry, +# specify them in this parameter as "|", where "" is a full image name +# (including registry if needed) and "" is a tag under which the image should be available +# in the OpenShift registry. +function ct_os_test_template_app() { + local image_name=${1} + local template=${2} + local name_in_template=${3} + local expected_output=${4} + local port=${5:-8080} + local protocol=${6:-http} + local response_code=${7:-200} + local oc_args=${8:-} + local other_images=${9:-} + local import_image=${10:-} + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_template_app() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + ct_os_test_template_app_func "${image_name}" \ + "${template}" \ + "${name_in_template}" \ + "ct_os_test_response_internal '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ + "${oc_args}" \ + "${other_images}" \ + "${import_image}" +} + +# ct_os_test_image_update IMAGE_NAME OLD_IMAGE ISTAG CHECK_FUNCTION OC_ARGS +# -------------------- +# Runs an image update test with [image] uploaded to [is] imagestream +# and checks the services using an arbitrary function provided in [check_function]. +# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: old_image - valid name of the image from the registry +# Arguments: istag - imagestream to upload the images into (compulsory) +# Arguments: check_function - command to be run to check functionality of created services (compulsory) +# Arguments: oc_args - arguments to use during oc new-app (compulsory) +ct_os_test_image_update() { + local image_name=$1; shift + local old_image=$1; shift + local istag=$1; shift + local check_function=$1; shift + local service_name=${image_name##*/} + local ip="" check_command_exp="" + + echo "Running image update test for: $image_name" + ct_os_new_project + + # Get current image from repository and create an imagestream + docker pull "$old_image:latest" 2>/dev/null + ct_os_upload_image "$old_image" "$istag" + + # Setup example application with curent image + oc new-app "$@" --name "$service_name" + ct_os_wait_pod_ready "$service_name" 60 + + # Check application output + ip=$(ct_os_get_service_ip "$service_name") + check_command_exp=${check_function///$ip} + ct_assert_cmd_success "$check_command_exp" + + # Tag built image into the imagestream and wait for rebuild + ct_os_upload_image "$image_name" "$istag" + ct_os_wait_pod_ready "${service_name}-2" 60 + + # Check application output + ip=$(ct_os_get_service_ip "$service_name") + check_command_exp=${check_function///$ip} + ct_assert_cmd_success "$check_command_exp" + + ct_os_delete_project +} + +# ct_os_deploy_cmd_image IMAGE_NAME +# -------------------- +# Runs a special command pod, a pod that does nothing, but includes utilities for testing. +# A typical usage is a mysql pod that includes mysql commandline, that we need for testing. +# Running commands inside this command pod is done via ct_os_cmd_image_run function. +# The pod is not run again if already running. +# Arguments: image_name - image to be used as a command pod +function ct_os_deploy_cmd_image() { + local image_name=${1} + oc get pod command-app &>/dev/null && echo "command POD already running" && return 0 + echo "command POD not running yet, will start one called command-app" + oc create -f - <" + local sleep_time=3 + local attempt=1 + local result=1 + local status + local response_code + local response_file=$(mktemp /tmp/ct_test_response_XXXXXX) + local util_image_name='python:3.6' + + ct_os_deploy_cmd_image "${util_image_name}" + + while [ ${attempt} -le ${max_attempts} ]; do + ct_os_cmd_image_run "curl --connect-timeout 10 -s -w '%{http_code}' '${url}'" >${response_file} && status=0 || status=1 + if [ ${status} -eq 0 ]; then + response_code=$(cat ${response_file} | tail -c 3) + if [ "${response_code}" -eq "${expected_code}" ]; then + result=0 + fi + cat ${response_file} | grep -qP -e "${body_regexp}" || result=1; + # Some services return 40x code until they are ready, so let's give them + # some chance and not end with failure right away + # Do not wait if we already have expected outcome though + if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then + break + fi + fi + attempt=$(( ${attempt} + 1 )) + sleep ${sleep_time} + done + rm -f ${response_file} + return ${result} +} + +# ct_os_get_image_from_pod +# ------------------------ +# Print image identifier from an existing pod to stdout +# Argument: pod_prefix - prefix or full name of the pod to get image from +ct_os_get_image_from_pod() { + local pod_prefix=$1 ; shift + local pod_name=$(ct_os_get_pod_name $pod_prefix) + oc get "po/${pod_name}" -o yaml | sed -ne 's/^\s*image:\s*\(.*\)\s*$/\1/ p' | head -1 +} + +# ct_os_check_cmd_internal +# ---------------- +# Runs a specified command, checks exit code and compares the output with expected regexp. +# That all is done inside an image in the cluster, so the function is used +# typically in clusters that are not accessible outside. +# The check is repeated until timeout. +# Argument: util_image_name - name of the image in the cluster that is used for running the cmd +# Argument: service_name - kubernetes' service name to work with (IP address is taken from this one) +# Argument: check_command - command that is run within the util_image_name container +# Argument: expected_content_match - regexp that must be in the output (use .* to ignore check) +# Argument: timeout - number of seconds to wait till the check succeeds +function ct_os_check_cmd_internal() { + local util_image_name=$1 ; shift + local service_name=$1 ; shift + local check_command=$1 ; shift + local expected_content_match=${1:-.*} ; shift + local timeout=${1:-60} ; shift || : + + : " Service ${service_name} check ..." + + local output + local ret + local ip=$(ct_os_get_service_ip "${service_name}") + local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") + + ct_os_deploy_cmd_image $(ct_os_get_image_from_pod "${util_image_name}" | head -n 1) + SECONDS=0 + + echo -n "Waiting for ${service_name} service becoming ready ..." + while true ; do + output=$(ct_os_cmd_image_run "$check_command_exp") + ret=$? + echo "${output}" | grep -qe "${expected_content_match}" || ret=1 + if [ ${ret} -eq 0 ] ; then + echo " PASS" + return 0 + fi + echo -n "." + [ ${SECONDS} -gt ${timeout} ] && break + sleep 3 + done + echo " FAIL" + return 1 +} + diff --git a/test/test-lib.sh b/test/test-lib.sh new file mode 100644 index 0000000..e372870 --- /dev/null +++ b/test/test-lib.sh @@ -0,0 +1,507 @@ +# +# Test a container image. +# +# Always use sourced from a specific container testfile +# +# reguires definition of CID_FILE_DIR +# CID_FILE_DIR=$(mktemp --suffix=_test_cidfiles -d) +# reguires definition of TEST_LIST +# TEST_LIST="\ +# ctest_container_creation +# ctest_doc_content" + +# Container CI tests +# abbreviated as "ct" + +# may be redefined in the specific container testfile +EXPECTED_EXIT_CODE=0 + +# ct_cleanup +# -------------------- +# Cleans up containers used during tests. Stops and removes all containers +# referenced by cid_files in CID_FILE_DIR. Dumps logs if a container exited +# unexpectedly. Removes the cid_files and CID_FILE_DIR as well. +# Uses: $CID_FILE_DIR - path to directory containing cid_files +# Uses: $EXPECTED_EXIT_CODE - expected container exit code +function ct_cleanup() { + for cid_file in $CID_FILE_DIR/* ; do + local container=$(cat $cid_file) + + : "Stopping and removing container $container..." + docker stop $container + exit_status=$(docker inspect -f '{{.State.ExitCode}}' $container) + if [ "$exit_status" != "$EXPECTED_EXIT_CODE" ]; then + : "Dumping logs for $container" + docker logs $container + fi + docker rm -v $container + rm $cid_file + done + rmdir $CID_FILE_DIR + : "Done." +} + +# ct_enable_cleanup +# -------------------- +# Enables automatic container cleanup after tests. +function ct_enable_cleanup() { + trap ct_cleanup EXIT SIGINT +} + +# ct_get_cid [name] +# -------------------- +# Prints container id from cid_file based on the name of the file. +# Argument: name - name of cid_file where the container id will be stored +# Uses: $CID_FILE_DIR - path to directory containing cid_files +function ct_get_cid() { + local name="$1" ; shift || return 1 + echo $(cat "$CID_FILE_DIR/$name") +} + +# ct_get_cip [id] +# -------------------- +# Prints container ip address based on the container id. +# Argument: id - container id +function ct_get_cip() { + local id="$1" ; shift + docker inspect --format='{{.NetworkSettings.IPAddress}}' $(ct_get_cid "$id") +} + +# ct_wait_for_cid [cid_file] +# -------------------- +# Holds the execution until the cid_file is created. Usually run after container +# creation. +# Argument: cid_file - name of the cid_file that should be created +function ct_wait_for_cid() { + local cid_file=$1 + local max_attempts=10 + local sleep_time=1 + local attempt=1 + local result=1 + while [ $attempt -le $max_attempts ]; do + [ -f $cid_file ] && [ -s $cid_file ] && return 0 + : "Waiting for container start..." + attempt=$(( $attempt + 1 )) + sleep $sleep_time + done + return 1 +} + +# ct_assert_container_creation_fails [container_args] +# -------------------- +# The invocation of docker run should fail based on invalid container_args +# passed to the function. Returns 0 when container fails to start properly. +# Argument: container_args - all arguments are passed directly to dokcer run +# Uses: $CID_FILE_DIR - path to directory containing cid_files +function ct_assert_container_creation_fails() { + local ret=0 + local max_attempts=10 + local attempt=1 + local cid_file=assert + set +e + local old_container_args="${CONTAINER_ARGS-}" + CONTAINER_ARGS="$@" + ct_create_container $cid_file + if [ $? -eq 0 ]; then + local cid=$(ct_get_cid $cid_file) + + while [ "$(docker inspect -f '{{.State.Running}}' $cid)" == "true" ] ; do + sleep 2 + attempt=$(( $attempt + 1 )) + if [ $attempt -gt $max_attempts ]; then + docker stop $cid + ret=1 + break + fi + done + exit_status=$(docker inspect -f '{{.State.ExitCode}}' $cid) + if [ "$exit_status" == "0" ]; then + ret=1 + fi + docker rm -v $cid + rm $CID_FILE_DIR/$cid_file + fi + [ ! -z $old_container_args ] && CONTAINER_ARGS="$old_container_args" + set -e + return $ret +} + +# ct_create_container [name, command] +# -------------------- +# Creates a container using the IMAGE_NAME and CONTAINER_ARGS variables. Also +# stores the container id to a cid_file located in the CID_FILE_DIR, and waits +# for the creation of the file. +# Argument: name - name of cid_file where the container id will be stored +# Argument: command - optional command to be executed in the container +# Uses: $CID_FILE_DIR - path to directory containing cid_files +# Uses: $CONTAINER_ARGS - optional arguments passed directly to docker run +# Uses: $IMAGE_NAME - name of the image being tested +function ct_create_container() { + local cid_file="$CID_FILE_DIR/$1" ; shift + # create container with a cidfile in a directory for cleanup + docker run --cidfile="$cid_file" -d ${CONTAINER_ARGS:-} $IMAGE_NAME "$@" + ct_wait_for_cid $cid_file || return 1 + : "Created container $(cat $cid_file)" +} + +# ct_scl_usage_old [name, command, expected] +# -------------------- +# Tests three ways of running the SCL, by looking for an expected string +# in the output of the command +# Argument: name - name of cid_file where the container id will be stored +# Argument: command - executed inside the container +# Argument: expected - string that is expected to be in the command output +# Uses: $CID_FILE_DIR - path to directory containing cid_files +# Uses: $IMAGE_NAME - name of the image being tested +function ct_scl_usage_old() { + local name="$1" + local command="$2" + local expected="$3" + local out="" + : " Testing the image SCL enable" + out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${command}") + if ! echo "${out}" | grep -q "${expected}"; then + echo "ERROR[/bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2 + return 1 + fi + out=$(docker exec $(ct_get_cid $name) /bin/bash -c "${command}" 2>&1) + if ! echo "${out}" | grep -q "${expected}"; then + echo "ERROR[exec /bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2 + return 1 + fi + out=$(docker exec $(ct_get_cid $name) /bin/sh -ic "${command}" 2>&1) + if ! echo "${out}" | grep -q "${expected}"; then + echo "ERROR[exec /bin/sh -ic "${command}"] Expected '${expected}', got '${out}'" >&2 + return 1 + fi +} + +# ct_doc_content_old [strings] +# -------------------- +# Looks for occurence of stirngs in the documentation files and checks +# the format of the files. Files examined: help.1 +# Argument: strings - strings expected to appear in the documentation +# Uses: $IMAGE_NAME - name of the image being tested +function ct_doc_content_old() { + local tmpdir=$(mktemp -d) + local f + : " Testing documentation in the container image" + # Extract the help files from the container + for f in help.1 ; do + docker run --rm ${IMAGE_NAME} /bin/bash -c "cat /${f}" >${tmpdir}/$(basename ${f}) + # Check whether the files contain some important information + for term in $@ ; do + if ! cat ${tmpdir}/$(basename ${f}) | grep -F -q -e "${term}" ; then + echo "ERROR: File /${f} does not include '${term}'." >&2 + return 1 + fi + done + # Check whether the files use the correct format + for term in TH PP SH ; do + if ! grep -q "^\.${term}" ${tmpdir}/help.1 ; then + echo "ERROR: /help.1 is probably not in troff or groff format, since '${term}' is missing." >&2 + return 1 + fi + done + done + : " Success!" +} + + +# ct_npm_works +# -------------------- +# Checks existance of the npm tool and runs it. +function ct_npm_works() { + local tmpdir=$(mktemp -d) + : " Testing npm in the container image" + docker run --rm ${IMAGE_NAME} /bin/bash -c "npm --version" >${tmpdir}/version + + if [ $? -ne 0 ] ; then + echo "ERROR: 'npm --version' does not work inside the image ${IMAGE_NAME}." >&2 + return 1 + fi + + docker run --rm ${IMAGE_NAME} /bin/bash -c "npm install jquery && test -f node_modules/jquery/src/jquery.js" + if [ $? -ne 0 ] ; then + echo "ERROR: npm could not install jquery inside the image ${IMAGE_NAME}." >&2 + return 1 + fi + + : " Success!" +} + + +# ct_path_append PATH_VARNAME DIRECTORY +# ------------------------------------- +# Append DIRECTORY to VARIABLE of name PATH_VARNAME, the VARIABLE must consist +# of colon-separated list of directories. +ct_path_append () +{ + if eval "test -n \"\${$1-}\""; then + eval "$1=\$2:\$$1" + else + eval "$1=\$2" + fi +} + + +# ct_path_foreach PATH ACTION [ARGS ...] +# -------------------------------------- +# For each DIR in PATH execute ACTION (path is colon separated list of +# directories). The particular calls to ACTION will look like +# '$ ACTION directory [ARGS ...]' +ct_path_foreach () +{ + local dir dirlist action save_IFS + save_IFS=$IFS + IFS=: + dirlist=$1 + action=$2 + shift 2 + for dir in $dirlist; do "$action" "$dir" "$@" ; done + IFS=$save_IFS +} + + +# ct_run_test_list +# -------------------- +# Execute the tests specified by TEST_LIST +# Uses: $TEST_LIST - list of test names +function ct_run_test_list() { + for test_case in $TEST_LIST; do + : "Running test $test_case" + [ -f test/$test_case ] && source test/$test_case + [ -f ../test/$test_case ] && source ../test/$test_case + $test_case + done; +} + +# ct_gen_self_signed_cert_pem +# --------------------------- +# Generates a self-signed PEM certificate pair into specified directory. +# Argument: output_dir - output directory path +# Argument: base_name - base name of the certificate files +# Resulted files will be those: +# /-cert-selfsigned.pem -- public PEM cert +# /-key.pem -- PEM private key +ct_gen_self_signed_cert_pem() { + local output_dir=$1 ; shift + local base_name=$1 ; shift + mkdir -p ${output_dir} + openssl req -newkey rsa:2048 -nodes -keyout ${output_dir}/${base_name}-key.pem -subj '/C=GB/ST=Berkshire/L=Newbury/O=My Server Company' > ${base_name}-req.pem + openssl req -new -x509 -nodes -key ${output_dir}/${base_name}-key.pem -batch > ${output_dir}/${base_name}-cert-selfsigned.pem +} + +# ct_obtain_input FILE|DIR|URL +# -------------------- +# Either copies a file or a directory to a tmp location for local copies, or +# downloads the file from remote location. +# Resulted file path is printed, so it can be later used by calling function. +# Arguments: input - local file, directory or remote URL +function ct_obtain_input() { + local input=$1 + local extension="${input##*.}" + + # Try to use same extension for the temporary file if possible + [[ "${extension}" =~ ^[a-z0-9]*$ ]] && extension=".${extension}" || extension="" + + local output=$(mktemp "/var/tmp/test-input-XXXXXX$extension") + if [ -f "${input}" ] ; then + cp -f "${input}" "${output}" + elif [ -d "${input}" ] ; then + rm -f "${output}" + cp -r -LH "${input}" "${output}" + elif echo "${input}" | grep -qe '^http\(s\)\?://' ; then + curl "${input}" > "${output}" + else + echo "ERROR: file type not known: ${input}" >&2 + return 1 + fi + echo "${output}" +} + +# ct_test_response +# ---------------- +# Perform GET request to the application container, checks output with +# a reg-exp and HTTP response code. +# Argument: url - request URL path +# Argument: expected_code - expected HTTP response code +# Argument: body_regexp - PCRE regular expression that must match the response body +# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between +# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10) +ct_test_response() { + local url="$1" + local expected_code="$2" + local body_regexp="$3" + local max_attempts=${4:-20} + local ignore_error_attempts=${5:-10} + + : " Testing the HTTP(S) response for <${url}>" + local sleep_time=3 + local attempt=1 + local result=1 + local status + local response_code + local response_file=$(mktemp /tmp/ct_test_response_XXXXXX) + while [ ${attempt} -le ${max_attempts} ]; do + curl --connect-timeout 10 -s -w '%{http_code}' "${url}" >${response_file} && status=0 || status=1 + if [ ${status} -eq 0 ]; then + response_code=$(cat ${response_file} | tail -c 3) + if [ "${response_code}" -eq "${expected_code}" ]; then + result=0 + fi + cat ${response_file} | grep -qP -e "${body_regexp}" || result=1; + # Some services return 40x code until they are ready, so let's give them + # some chance and not end with failure right away + # Do not wait if we already have expected outcome though + if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then + break + fi + fi + attempt=$(( ${attempt} + 1 )) + sleep ${sleep_time} + done + rm -f ${response_file} + return ${result} +} + +# ct_registry_from_os OS +# ---------------- +# Transform operating system string [os] into registry url +# Argument: OS - string containing the os version +ct_registry_from_os() { + local registry="" + case $1 in + rhel7) + registry=registry.access.redhat.com + ;; + *) + registry=docker.io + ;; + esac + echo "$registry" +} + +# ct_assert_cmd_success CMD +# ---------------- +# Evaluates [cmd] and fails if it does not succeed. +# Argument: CMD - Command to be run +function ct_assert_cmd_success() { + echo "Checking '$*' for success ..." + if ! eval "$@" &>/dev/null; then + echo " FAIL" + return 1 + fi + echo " PASS" + return 0 +} + +# ct_assert_cmd_failure CMD +# ---------------- +# Evaluates [cmd] and fails if it succeeds. +# Argument: CMD - Command to be run +function ct_assert_cmd_failure() { + echo "Checking '$*' for failure ..." + if eval "$@" &>/dev/null; then + echo " FAIL" + return 1 + fi + echo " PASS" + return 0 +} + + +# ct_random_string [LENGTH=10] +# ---------------------------- +# Generate pseudorandom alphanumeric string of LENGTH bytes, the +# default length is 10. The string is printed on stdout. +ct_random_string() +( + export LC_ALL=C + dd if=/dev/urandom count=1 bs=10k 2>/dev/null \ + | tr -dc 'a-z0-9' \ + | fold -w "${1-10}" \ + | head -n 1 +) + +# ct_s2i_usage IMG_NAME [S2I_ARGS] +# ---------------------------- +# Create a container and run the usage script inside +# Argument: IMG_NAME - name of the image to be used for the container run +# Argument: S2I_ARGS - Additional list of source-to-image arguments, currently unused. +ct_s2i_usage() +{ + local img_name=$1; shift + local s2i_args="$*"; + local usage_command="/usr/libexec/s2i/usage" + docker run --rm "$img_name" bash -c "$usage_command" +} + +# ct_s2i_build_as_df APP_PATH SRC_IMAGE DST_IMAGE [S2I_ARGS] +# ---------------------------- +# Create a new s2i app image from local sources in a similar way as source-to-image would have used. +# Argument: APP_PATH - local path to the app sources to be used in the test +# Argument: SRC_IMAGE - image to be used as a base for the s2i build +# Argument: DST_IMAGE - image name to be used during the tagging of the s2i build result +# Argument: S2I_ARGS - Additional list of source-to-image arguments. +# Only used to check for pull-policy=never and environment variable definitions. +ct_s2i_build_as_df() +{ + local app_path=$1; shift + local src_image=$1; shift + local dst_image=$1; shift + local s2i_args="$*"; + local local_app=upload/src/ + local local_scripts=upload/scripts/ + local user_id= + local df_name= + local tmpdir= + # Use /tmp to not pollute cwd + tmpdir=$(mktemp -d) + df_name=$(mktemp -p "$tmpdir" Dockerfile.XXXX) + pushd "$tmpdir" + # Check if the image is available locally and try to pull it if it is not + docker images "$src_image" &>/dev/null || echo "$s2i_args" | grep -q "pull-policy=never" || docker pull "$src_image" + user_id=$(docker inspect -f "{{.ContainerConfig.User}}" "$src_image") + # Strip file:// from APP_PATH and copy its contents into current context + mkdir -p "$local_app" + cp -r "${app_path/file:\/\//}/." "$local_app" + [ -d "$local_app/.s2i/bin/" ] && mv "$local_app/.s2i/bin" "$local_scripts" + # Create a Dockerfile named df_name and fill it with proper content + #FIXME: Some commands could be combined into a single layer but not sure if worth the trouble for testing purposes + cat <"$df_name" +FROM $src_image +LABEL "io.openshift.s2i.build.image"="$src_image" \\ + "io.openshift.s2i.build.source-location"="$app_path" +USER root +COPY $local_app /tmp/src +EOF + [ -d "$local_scripts" ] && echo "COPY $local_scripts /tmp/scripts" >> "$df_name" && + echo "RUN chown -R $user_id:0 /tmp/scripts" >>"$df_name" + echo "RUN chown -R $user_id:0 /tmp/src" >>"$df_name" + # Check for custom environment variables inside .s2i/ folder + if [ -e "$local_app/.s2i/environment" ]; then + # Remove any comments and add the contents as ENV commands to the Dockerfile + sed '/^\s*#.*$/d' "$local_app/.s2i/environment" | while read -r line; do + echo "ENV $line" >>"$df_name" + done + fi + # Filter out env var definitions from $s2i_args and create Dockerfile ENV commands out of them + echo "$s2i_args" | grep -o -e '\(-e\|--env\)[[:space:]=]\S*=\S*' | sed -e 's/-e /ENV /' -e 's/--env[ =]/ENV /' >>"$df_name" + echo "USER $user_id" >>"$df_name" + # If exists, run the custom assemble script, else default to /usr/libexec/s2i/assemble + if [ -x "$local_scripts/assemble" ]; then + echo "RUN /tmp/scripts/assemble" >>"$df_name" + else + echo "RUN /usr/libexec/s2i/assemble" >>"$df_name" + fi + # If exists, set the custom run script as CMD, else default to /usr/libexec/s2i/run + if [ -x "$local_scripts/run" ]; then + echo "CMD /tmp/scripts/run" >>"$df_name" + else + echo "CMD /usr/libexec/s2i/run" >>"$df_name" + fi + # Run the build and tag the result + docker build -f "$df_name" -t "$dst_image" . + popd +} diff --git a/test/utils.sh b/test/utils.sh new file mode 100755 index 0000000..525c3e2 --- /dev/null +++ b/test/utils.sh @@ -0,0 +1,46 @@ +#!/usr/bin/env bash + +function print_result { + local RESET='\e[0m' + local RED='\e[0;31m' + local GREEN='\e[0;32m' + local YELLOW='\e[1;33m' + local PASS="${RESET}${GREEN}[PASS]" + local FAIL="${RESET}${RED}[FAIL]" + local WORKING="${RESET}${YELLOW}[....]" + local STATUS="$1" + shift + + if [ "${STATUS}" = pass ]; then + echo -en "${PASS}" + elif [ "${STATUS}" = fail ]; then + echo -en "${FAIL}" + elif [ "${STATUS}" = working ]; then + echo -en "${WORKING}" + else + return + fi + + echo -en " ${@}${RESET}" + echo +} + +function get_status { + if [ "$1" = "$2" ]; then + echo pass + else + echo fail + fi +} + +function run_command { + local cmd="$1" + local expected="${2:-0}" + local msg="${3:-Running command '$cmd'}" + print_result working "$msg" + eval $cmd + local res="$?" + status=`get_status "$res" "$expected"` + print_result "$status" "$msg" + return "$res" +}