Update from the upstream and include fix for BZ#1585533
This commit is contained in:
parent
47080824e8
commit
5fceb7e6cd
23 changed files with 1380 additions and 101 deletions
37
Dockerfile
37
Dockerfile
|
|
@ -1,4 +1,4 @@
|
|||
FROM registry.fedoraproject.org/f27/s2i-base
|
||||
FROM registry.fedoraproject.org/f27/s2i-core:latest
|
||||
|
||||
# Apache HTTP Server image.
|
||||
#
|
||||
|
|
@ -8,10 +8,14 @@ FROM registry.fedoraproject.org/f27/s2i-base
|
|||
# Environment:
|
||||
# * $HTTPD_LOG_TO_VOLUME (optional) - When set, httpd will log into /var/log/httpd
|
||||
|
||||
ENV HTTPD_VERSION=2.4
|
||||
ENV HTTPD_VERSION=2.4 \
|
||||
NAME=httpd \
|
||||
VERSION=$HTTPD_VERSION \
|
||||
RELEASE=1 \
|
||||
ARCH=x86_64
|
||||
|
||||
ENV SUMMARY="Platform for running Apache httpd $HTTPD_VERSION or building httpd-based application" \
|
||||
DESCRIPTION="Apache httpd $HTTPD_VERSION available as docker container, is a powerful, efficient, \
|
||||
DESCRIPTION="Apache httpd $HTTPD_VERSION available as container, is a powerful, efficient, \
|
||||
and extensible web server. Apache supports a variety of features, many implemented as compiled modules \
|
||||
which extend the core functionality. \
|
||||
These can range from server-side programming language support to authentication schemes. \
|
||||
|
|
@ -22,20 +26,15 @@ LABEL summary="$SUMMARY" \
|
|||
io.k8s.description="$SUMMARY" \
|
||||
io.k8s.display-name="Apache httpd $HTTPD_VERSION" \
|
||||
io.openshift.expose-services="8080:http,8443:https" \
|
||||
io.openshift.tags="builder,httpd,httpd24"
|
||||
|
||||
ENV NAME=httpd VERSION=0 RELEASE=5 ARCH=x86_64
|
||||
|
||||
LABEL com.redhat.component="$NAME" \
|
||||
io.openshift.tags="builder,httpd,httpd24" \
|
||||
com.redhat.component="$NAME" \
|
||||
name="$FGC/$NAME" \
|
||||
version="$VERSION" \
|
||||
release="$RELEASE.$DISTTAG" \
|
||||
architecture="$ARCH" \
|
||||
usage="docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z 27/httpd" \
|
||||
help="help.1"
|
||||
usage="s2i build https://github.com/sclorg/httpd-container.git --context-dir=examples/sample-test-app/ $FGC/$NAME sample-server" \
|
||||
maintainer="SoftwareCollections.org <sclorg@redhat.com>"
|
||||
|
||||
EXPOSE 80
|
||||
EXPOSE 443
|
||||
EXPOSE 8080
|
||||
EXPOSE 8443
|
||||
|
||||
|
|
@ -46,8 +45,8 @@ RUN dnf install -y yum-utils gettext hostname && \
|
|||
dnf clean all
|
||||
|
||||
ENV HTTPD_CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/httpd/ \
|
||||
HTTPD_APP_ROOT=/opt/app-root \
|
||||
HTTPD_CONFIGURATION_PATH=${HTTPD_APP_ROOT}/etc/httpd.d \
|
||||
HTTPD_APP_ROOT=${APP_ROOT} \
|
||||
HTTPD_CONFIGURATION_PATH=${APP_ROOT}/etc/httpd.d \
|
||||
HTTPD_MAIN_CONF_PATH=/etc/httpd/conf \
|
||||
HTTPD_MAIN_CONF_D_PATH=/etc/httpd/conf.d \
|
||||
HTTPD_VAR_RUN=/var/run/httpd \
|
||||
|
|
@ -58,11 +57,15 @@ ENV HTTPD_CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/httpd/ \
|
|||
COPY ./s2i/bin/ $STI_SCRIPTS_PATH
|
||||
COPY ./root /
|
||||
|
||||
RUN /usr/libexec/httpd-prepare
|
||||
# Generate SSL certs and reset permissions of filesystem to default values
|
||||
RUN /usr/libexec/httpd-ssl-gencerts && \
|
||||
/usr/libexec/httpd-prepare && rpm-file-permissions
|
||||
|
||||
USER 1001
|
||||
|
||||
VOLUME ["${HTTPD_DATA_PATH}"]
|
||||
VOLUME ["${HTTPD_LOG_PATH}"]
|
||||
# Not using VOLUME statement since it's not working in OpenShift Online:
|
||||
# https://github.com/sclorg/httpd-container/issues/30
|
||||
# VOLUME ["${HTTPD_DATA_PATH}"]
|
||||
# VOLUME ["${HTTPD_LOG_PATH}"]
|
||||
|
||||
CMD ["/usr/bin/run-httpd"]
|
||||
|
|
|
|||
106
root/help.1
106
root/help.1
|
|
@ -1,28 +1,26 @@
|
|||
.TH "HTTPD-24-RHEL7" "1" " Container Image Pages" "Red Hat" "April 07, 2017" ""
|
||||
|
||||
|
||||
.SH Apache HTTP Server 2.4
|
||||
.TH Apache HTTP Server 2.4 Container Image
|
||||
.PP
|
||||
This container image includes Apache HTTP Server 2.4 for OpenShift and general usage.
|
||||
Users can choose between RHEL, CentOS, and Fedora based images.
|
||||
The RHEL image is available in the
|
||||
\[la]https://access.redhat.com/containers\[ra]
|
||||
Users can choose between RHEL, CentOS and Fedora based images.
|
||||
The RHEL image is available in the Red Hat Container Catalog
|
||||
\[la]https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/httpd-24-rhel7\[ra]
|
||||
as registry.access.redhat.com/rhscl/httpd\-24\-rhel7.
|
||||
The CentOS image is then available on
|
||||
The CentOS image is then available on Docker Hub
|
||||
\[la]https://hub.docker.com/r/centos/httpd-24-centos7/\[ra]
|
||||
as centos/httpd\-24\-centos7.
|
||||
|
||||
.SH DESCRIPTION
|
||||
.SH Description
|
||||
.PP
|
||||
Apache HTTP Server 2.4 available as docker container, is a powerful, efficient,
|
||||
Apache HTTP Server 2.4 available as container, is a powerful, efficient,
|
||||
and extensible web server. Apache supports a variety of features, many implemented as compiled modules
|
||||
which extend the core functionality.
|
||||
These can range from server\-side programming language support to authentication schemes.
|
||||
Virtual hosting allows one Apache installation to serve many different Web sites."
|
||||
|
||||
.SH USAGE
|
||||
.SH Usage
|
||||
.PP
|
||||
For this, we will assume that you are using the \fB\fCrhscl/httpd\-24\-rhel7\fR image.
|
||||
For this, we will assume that you are using the Apache HTTP Server 2.4 container image from the
|
||||
Red Hat Container Catalog called \fB\fCrhscl/httpd\-24\-rhel7\fR\&.
|
||||
The image can be used as a base image for other applications based on Apache HTTP web server.
|
||||
|
||||
.PP
|
||||
|
|
@ -42,7 +40,7 @@ $ ls \-lZ /wwwdata/html
|
|||
|
||||
.PP
|
||||
If you want to run the image and mount the static pages available in \fB\fC/wwwdata\fR on the host
|
||||
as a docker volume, execute the following command:
|
||||
as a container volume, execute the following command:
|
||||
|
||||
.PP
|
||||
.RS
|
||||
|
|
@ -58,8 +56,8 @@ This will create a container named \fB\fChttpd\fR running Apache HTTP Server, se
|
|||
\fB\fC/wwwdata\fR directory. Port 8080 will be exposed and mapped to the host.
|
||||
|
||||
.PP
|
||||
If you want to create a new Docker layered image, use
|
||||
\[la]https://github.com/openshift/source-to-image\[ra], a tool for building/building artifacts from source and injecting into docker images. To create a new Docker image named \fB\fChttpd\-app\fR using Source\-to\-Image, while using data available in \fB\fC/wwwdata\fR on the host, execute the following command:
|
||||
If you want to create a new container layered image, use Source\-to\-Image
|
||||
\[la]https://github.com/openshift/source-to-image\[ra], a tool for building/building artifacts from source and injecting into container images. To create a new container image named \fB\fChttpd\-app\fR using Source\-to\-Image, while using data available in \fB\fC/wwwdata\fR on the host, execute the following command:
|
||||
|
||||
.PP
|
||||
.RS
|
||||
|
|
@ -82,19 +80,41 @@ $ docker run \-d \-\-name httpd \-p 8080:8080 httpd\-app
|
|||
.fi
|
||||
.RE
|
||||
|
||||
.SH CONFIGURATION
|
||||
.PP
|
||||
The structure of httpd\-app can look like this:
|
||||
|
||||
.PP
|
||||
\fB\fB\fC\&./httpd\-\&cfg\fR\fP
|
||||
.br
|
||||
Can contain additional Apache configuration files (\fB\fC*.conf\fR)
|
||||
|
||||
.PP
|
||||
\fB\fB\fC\&./httpd\-\&pre\-\&init\fR\fP
|
||||
.br
|
||||
Can contain shell scripts (\fB\fC*.sh\fR) that are sourced before \fB\fChttpd\fR is started
|
||||
|
||||
.PP
|
||||
\fB\fB\fC\&./httpd\-\&ssl\fR\fP
|
||||
.br
|
||||
Can contain own SSL certificate (in \fB\fCcerts/\fR subdirectory) and key (in \fB\fCprivate/\fR subdirectory)
|
||||
|
||||
.PP
|
||||
\fB\fB\fC\&./\fR\fP
|
||||
.br
|
||||
Application source code
|
||||
|
||||
.SH Environment variables and volumes
|
||||
.PP
|
||||
The Apache HTTP Server container image supports the following configuration variable, which can be set by using the \fB\fC\-e\fR option with the docker run command:
|
||||
.TS
|
||||
allbox;
|
||||
Variable name Description
|
||||
\fB\fCHTTPD\_LOG\_TO\_VOLUME\fR By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When \fB\fCHTTPD\_LOG\_TO\_VOLUME\fR is set, httpd logs into \fB\fC/var/log/httpd24\fR, which can be mounted to host system using the Docker volumes. This option is only allowed when container is run as UID 0.
|
||||
|
||||
.TE
|
||||
.PP
|
||||
\fB\fB\fCHTTPD\_LOG\_TO\_VOLUME\fR\fP
|
||||
.br
|
||||
By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When \fB\fCHTTPD\_LOG\_TO\_VOLUME\fR is set, httpd logs into \fB\fC/var/log/httpd24\fR, which can be mounted to host system using the container volumes. This option is only allowed when container is run as UID 0.
|
||||
|
||||
.PP
|
||||
If you want to run the image and mount the log files into \fB\fC/wwwlogs\fR on the host
|
||||
as a docker volume, execute the following command:
|
||||
as a container volume, execute the following command:
|
||||
|
||||
.PP
|
||||
.RS
|
||||
|
|
@ -105,24 +125,42 @@ $ docker run \-d \-u 0 \-e HTTPD\_LOG\_TO\_VOLUME=1 \-\-name httpd \-v /wwwlogs:
|
|||
.fi
|
||||
.RE
|
||||
|
||||
.SH VOLUMES
|
||||
.PP
|
||||
You can also set the following mount points by passing the \fB\fC\-v /host:/container\fR flag to Docker.
|
||||
.TS
|
||||
allbox;
|
||||
Volume mount point Description
|
||||
\fB\fC/var/www\fR Apache HTTP Server data directory
|
||||
|
||||
\fB\fC/var/log/httpd24\fR Apache HTTP Server log directory (available only when running as root, path \fB\fC/var/log/httpd\fR is used in case of Fedora based image)
|
||||
.PP
|
||||
\fB\fB\fC/var/www\fR\fP
|
||||
.br
|
||||
Apache HTTP Server data directory
|
||||
|
||||
.TE
|
||||
.PP
|
||||
\fB\fB\fC/var/log/httpd24\fR\fP
|
||||
.br
|
||||
Apache HTTP Server log directory (available only when running as root, path \fB\fC/var/log/httpd\fR is used in case of Fedora based image)
|
||||
|
||||
.PP
|
||||
\fBNotice: When mouting a directory from the host into the container, ensure that the mounted
|
||||
directory has the appropriate permissions and that the owner and group of the directory
|
||||
matches the user UID or name which is running inside the container.\fP
|
||||
|
||||
.SH DEFAULT USER
|
||||
.SH Using own SSL certificates
|
||||
.PP
|
||||
In order to provide own SSL certificates for securing the connection with SSL, use the extending feature described above. In particular, put the SSL certificates into a separate directory inside your application:
|
||||
|
||||
.PP
|
||||
.RS
|
||||
|
||||
.nf
|
||||
\&./httpd\-\&ssl/certs/server\-\&cert\-\&selfsigned.pem
|
||||
./httpd\-\&ssl/private/server\-\&key.pem
|
||||
|
||||
.fi
|
||||
.RE
|
||||
|
||||
.PP
|
||||
The default behaviour is to look for the certificate and the private key in subdirectories certs/ and private/; those files will be used for the ssl settings in the httpd.
|
||||
|
||||
.SH Default user
|
||||
.PP
|
||||
By default, Apache HTTP Server container runs as UID 1001. That means the volume mounted directories for the files (if mounted using \fB\fC\-v\fR option) need to be prepared properly, so the UID 1001 can read them.
|
||||
|
||||
|
|
@ -141,7 +179,7 @@ docker run \-d \-u 1234 rhscl/httpd\-24\-rhel7
|
|||
.PP
|
||||
To log into a volume mounted directory, the container needs to be run as UID 0 (see above).
|
||||
|
||||
.SH TROUBLESHOOTING
|
||||
.SH Troubleshooting
|
||||
.PP
|
||||
The httpd deamon in the container logs to the standard output by default, so the log is available in the container log. The log can be examined by running:
|
||||
|
||||
|
|
@ -154,10 +192,10 @@ docker logs <container>
|
|||
.fi
|
||||
.RE
|
||||
|
||||
.SH SEE ALSO
|
||||
.SH See also
|
||||
.PP
|
||||
Dockerfile and other sources for this container image are available on
|
||||
|
||||
\[la]https://github.com/sclorg/httpd-container\[ra].
|
||||
\[la]https://github.com/sclorg/httpd-container\[ra]\&.
|
||||
In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile
|
||||
for RHEL is called Dockerfile.rhel7.
|
||||
for RHEL is called Dockerfile.rhel7 and Dockerfile for Fedora is called Dockerfile.fedora.
|
||||
|
|
|
|||
3
root/opt/app-root/scl_enable
Normal file
3
root/opt/app-root/scl_enable
Normal file
|
|
@ -0,0 +1,3 @@
|
|||
# This will make scl collection binaries work out of box.
|
||||
unset BASH_ENV PROMPT_COMMAND ENV
|
||||
source scl_source enable httpd24
|
||||
|
|
@ -13,4 +13,6 @@ else
|
|||
generate_container_user
|
||||
fi
|
||||
|
||||
process_extending_files ${HTTPD_APP_ROOT}/src/httpd-pre-init/ ${HTTPD_CONTAINER_SCRIPTS_PATH}/pre-init/
|
||||
|
||||
exec httpd -D FOREGROUND $@
|
||||
|
|
|
|||
|
|
@ -23,8 +23,8 @@ fi
|
|||
mkdir -p ${HTTPD_CONFIGURATION_PATH}
|
||||
chmod -R a+rwx ${HTTPD_MAIN_CONF_PATH}
|
||||
chmod -R a+rwx ${HTTPD_MAIN_CONF_D_PATH}
|
||||
#chmod -R a+r /etc/pki/tls/certs/localhost.crt
|
||||
#chmod -R a+r /etc/pki/tls/private/localhost.key
|
||||
chmod -R a+r /etc/pki/tls/certs/localhost.crt
|
||||
chmod -R a+r /etc/pki/tls/private/localhost.key
|
||||
mkdir -p ${HTTPD_APP_ROOT}/etc
|
||||
chmod -R a+rwx ${HTTPD_APP_ROOT}/etc
|
||||
chmod -R a+rwx ${HTTPD_VAR_RUN}
|
||||
|
|
@ -32,5 +32,7 @@ chown -R 1001:0 ${HTTPD_APP_ROOT}
|
|||
chown -R 1001:0 ${HTTPD_DATA_PATH}
|
||||
chown -R 1001:0 ${HTTPD_LOG_PATH}
|
||||
|
||||
mkdir -p ${HTTPD_CONTAINER_SCRIPTS_PATH}/pre-init
|
||||
|
||||
config_general
|
||||
|
||||
|
|
|
|||
|
|
@ -1,28 +1,29 @@
|
|||
Apache HTTP Server 2.4
|
||||
Apache HTTP Server 2.4 Container Image
|
||||
======================
|
||||
|
||||
This container image includes Apache HTTP Server 2.4 for OpenShift and general usage.
|
||||
Users can choose between RHEL, CentOS, and Fedora based images.
|
||||
The RHEL image is available in the [Red Hat Registry](https://access.redhat.com/containers)
|
||||
Users can choose between RHEL, CentOS and Fedora based images.
|
||||
The RHEL image is available in the [Red Hat Container Catalog](https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/httpd-24-rhel7)
|
||||
as registry.access.redhat.com/rhscl/httpd-24-rhel7.
|
||||
The CentOS image is then available on [Docker Hub](https://hub.docker.com/r/centos/httpd-24-centos7/)
|
||||
as centos/httpd-24-centos7.
|
||||
|
||||
|
||||
DESCRIPTION
|
||||
Description
|
||||
-----------
|
||||
|
||||
Apache HTTP Server 2.4 available as docker container, is a powerful, efficient,
|
||||
Apache HTTP Server 2.4 available as container, is a powerful, efficient,
|
||||
and extensible web server. Apache supports a variety of features, many implemented as compiled modules
|
||||
which extend the core functionality.
|
||||
These can range from server-side programming language support to authentication schemes.
|
||||
Virtual hosting allows one Apache installation to serve many different Web sites."
|
||||
|
||||
|
||||
USAGE
|
||||
Usage
|
||||
-----
|
||||
|
||||
For this, we will assume that you are using the `rhscl/httpd-24-rhel7` image.
|
||||
For this, we will assume that you are using the Apache HTTP Server 2.4 container image from the
|
||||
Red Hat Container Catalog called `rhscl/httpd-24-rhel7`.
|
||||
The image can be used as a base image for other applications based on Apache HTTP web server.
|
||||
|
||||
An example of the data on the host for both the examples above, that will be served by
|
||||
|
|
@ -35,7 +36,7 @@ $ ls -lZ /wwwdata/html
|
|||
```
|
||||
|
||||
If you want to run the image and mount the static pages available in `/wwwdata` on the host
|
||||
as a docker volume, execute the following command:
|
||||
as a container volume, execute the following command:
|
||||
|
||||
```
|
||||
$ docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z rhscl/httpd-24-rhel7
|
||||
|
|
@ -44,7 +45,7 @@ $ docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z rhscl/httpd-24-
|
|||
This will create a container named `httpd` running Apache HTTP Server, serving data from
|
||||
`/wwwdata` directory. Port 8080 will be exposed and mapped to the host.
|
||||
|
||||
If you want to create a new Docker layered image, use [Source-to-Image](https://github.com/openshift/source-to-image), a tool for building/building artifacts from source and injecting into docker images. To create a new Docker image named `httpd-app` using Source-to-Image, while using data available in `/wwwdata` on the host, execute the following command:
|
||||
If you want to create a new container layered image, use [Source-to-Image](https://github.com/openshift/source-to-image), a tool for building/building artifacts from source and injecting into container images. To create a new container image named `httpd-app` using Source-to-Image, while using data available in `/wwwdata` on the host, execute the following command:
|
||||
|
||||
```
|
||||
$ s2i build file:///wwwdata/html rhscl/httpd-24-rhel7 httpd-app
|
||||
|
|
@ -56,41 +57,63 @@ To run such a new image, execute the following command:
|
|||
$ docker run -d --name httpd -p 8080:8080 httpd-app
|
||||
```
|
||||
|
||||
The structure of httpd-app can look like this:
|
||||
|
||||
CONFIGURATION
|
||||
-------------
|
||||
**`./httpd-cfg`**
|
||||
Can contain additional Apache configuration files (`*.conf`)
|
||||
|
||||
**`./httpd-pre-init`**
|
||||
Can contain shell scripts (`*.sh`) that are sourced before `httpd` is started
|
||||
|
||||
**`./httpd-ssl`**
|
||||
Can contain own SSL certificate (in `certs/` subdirectory) and key (in `private/` subdirectory)
|
||||
|
||||
**`./`**
|
||||
Application source code
|
||||
|
||||
|
||||
Environment variables and volumes
|
||||
---------------------------------
|
||||
|
||||
The Apache HTTP Server container image supports the following configuration variable, which can be set by using the `-e` option with the docker run command:
|
||||
|
||||
| Variable name | Description |
|
||||
| :---------------------- | ----------------------------------------- |
|
||||
| `HTTPD_LOG_TO_VOLUME` | By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When `HTTPD_LOG_TO_VOLUME` is set, httpd logs into `/var/log/httpd24`, which can be mounted to host system using the Docker volumes. This option is only allowed when container is run as UID 0. |
|
||||
**`HTTPD_LOG_TO_VOLUME`**
|
||||
By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When `HTTPD_LOG_TO_VOLUME` is set, httpd logs into `/var/log/httpd24`, which can be mounted to host system using the container volumes. This option is only allowed when container is run as UID 0.
|
||||
|
||||
|
||||
|
||||
If you want to run the image and mount the log files into `/wwwlogs` on the host
|
||||
as a docker volume, execute the following command:
|
||||
as a container volume, execute the following command:
|
||||
|
||||
```
|
||||
$ docker run -d -u 0 -e HTTPD_LOG_TO_VOLUME=1 --name httpd -v /wwwlogs:/var/log/httpd24:Z rhscl/httpd-24-rhel7
|
||||
```
|
||||
|
||||
|
||||
VOLUMES
|
||||
-------
|
||||
|
||||
You can also set the following mount points by passing the `-v /host:/container` flag to Docker.
|
||||
|
||||
| Volume mount point | Description |
|
||||
| :----------------------- | ---------------------------------------------------------------------- |
|
||||
| `/var/www` | Apache HTTP Server data directory |
|
||||
| `/var/log/httpd24` | Apache HTTP Server log directory (available only when running as root, path `/var/log/httpd` is used in case of Fedora based image) |
|
||||
**`/var/www`**
|
||||
Apache HTTP Server data directory
|
||||
|
||||
**`/var/log/httpd24`**
|
||||
Apache HTTP Server log directory (available only when running as root, path `/var/log/httpd` is used in case of Fedora based image)
|
||||
|
||||
|
||||
**Notice: When mouting a directory from the host into the container, ensure that the mounted
|
||||
directory has the appropriate permissions and that the owner and group of the directory
|
||||
matches the user UID or name which is running inside the container.**
|
||||
|
||||
|
||||
DEFAULT USER
|
||||
Using own SSL certificates
|
||||
--------------------------
|
||||
In order to provide own SSL certificates for securing the connection with SSL, use the extending feature described above. In particular, put the SSL certificates into a separate directory inside your application:
|
||||
|
||||
./httpd-ssl/certs/server-cert-selfsigned.pem
|
||||
./httpd-ssl/private/server-key.pem
|
||||
|
||||
The default behaviour is to look for the certificate and the private key in subdirectories certs/ and private/; those files will be used for the ssl settings in the httpd.
|
||||
|
||||
|
||||
Default user
|
||||
------------
|
||||
|
||||
By default, Apache HTTP Server container runs as UID 1001. That means the volume mounted directories for the files (if mounted using `-v` option) need to be prepared properly, so the UID 1001 can read them.
|
||||
|
|
@ -104,18 +127,16 @@ docker run -d -u 1234 rhscl/httpd-24-rhel7
|
|||
To log into a volume mounted directory, the container needs to be run as UID 0 (see above).
|
||||
|
||||
|
||||
|
||||
TROUBLESHOOTING
|
||||
Troubleshooting
|
||||
---------------
|
||||
The httpd deamon in the container logs to the standard output by default, so the log is available in the container log. The log can be examined by running:
|
||||
|
||||
docker logs <container>
|
||||
|
||||
|
||||
SEE ALSO
|
||||
See also
|
||||
--------
|
||||
Dockerfile and other sources for this container image are available on
|
||||
https://github.com/sclorg/httpd-container.
|
||||
In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile
|
||||
for RHEL is called Dockerfile.rhel7.
|
||||
|
||||
for RHEL is called Dockerfile.rhel7 and Dockerfile for Fedora is called Dockerfile.fedora.
|
||||
|
|
|
|||
|
|
@ -4,6 +4,7 @@ config_general() {
|
|||
sed -i -e 's/^Listen 80/Listen 0.0.0.0:8080/' ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \
|
||||
sed -i -e '151s%AllowOverride None%AllowOverride All%' ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \
|
||||
sed -i -e 's/^Listen 443/Listen 0.0.0.0:8443/' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
|
||||
sed -i -e 's/_default_:443/_default_:8443/' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
|
||||
}
|
||||
|
||||
config_log_to_stdout() {
|
||||
|
|
@ -34,7 +35,6 @@ config_privileged() {
|
|||
config_s2i() {
|
||||
sed -i -e "s%^DocumentRoot \"${HTTPD_DATA_ORIG_PATH}/html\"%DocumentRoot \"${HTTPD_APP_ROOT}/src\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
|
||||
sed -i -e "s%^<Directory \"${HTTPD_DATA_ORIG_PATH}/html\"%<Directory \"${HTTPD_APP_ROOT}/src\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
|
||||
sed -i -e "s%^<Directory \"${HTTPD_VAR_PATH}/html\"%<Directory \"${HTTPD_APP_ROOT}/src\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
|
||||
echo "IncludeOptional ${HTTPD_CONFIGURATION_PATH}/*.conf" >> ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \
|
||||
head -n151 ${HTTPD_MAIN_CONF_PATH}/httpd.conf | tail -n1 | grep "AllowOverride All" || exit
|
||||
}
|
||||
|
|
@ -49,6 +49,34 @@ config_non_privileged() {
|
|||
fi
|
||||
}
|
||||
|
||||
# get_matched_files finds file for image extending
|
||||
function get_matched_files() {
|
||||
local custom_dir default_dir
|
||||
custom_dir="$1"
|
||||
default_dir="$2"
|
||||
files_matched="$3"
|
||||
find "$default_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n"
|
||||
[ -d "$custom_dir" ] && find "$custom_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n"
|
||||
}
|
||||
|
||||
# process_extending_files process extending files in $1 and $2 directories
|
||||
# - source all *.sh files
|
||||
# (if there are files with same name source only file from $1)
|
||||
function process_extending_files() {
|
||||
local custom_dir default_dir
|
||||
custom_dir=$1
|
||||
default_dir=$2
|
||||
while read filename ; do
|
||||
echo "=> sourcing $filename ..."
|
||||
# Custom file is prefered
|
||||
if [ -f $custom_dir/$filename ]; then
|
||||
source $custom_dir/$filename
|
||||
elif [ -f $default_dir/$filename ]; then
|
||||
source $default_dir/$filename
|
||||
fi
|
||||
done <<<"$(get_matched_files "$custom_dir" "$default_dir" '*.sh' | sort -u)"
|
||||
}
|
||||
|
||||
# Set current user in nss_wrapper
|
||||
generate_container_user() {
|
||||
local passwd_output_dir="${HTTPD_APP_ROOT}/etc"
|
||||
|
|
@ -61,3 +89,48 @@ generate_container_user() {
|
|||
export NSS_WRAPPER_GROUP=/etc/group
|
||||
}
|
||||
|
||||
# Copy config files from application to the location where httd expects them
|
||||
# Param sets the directory where to look for files
|
||||
process_config_files() {
|
||||
local dir=${1:-.}
|
||||
if [ -d ${dir}/httpd-cfg ]; then
|
||||
echo "---> Copying httpd configuration files..."
|
||||
if [ "$(ls -A ${dir}/httpd-cfg/*.conf)" ]; then
|
||||
cp -v ${dir}/httpd-cfg/*.conf "${HTTPD_CONFIGURATION_PATH}"
|
||||
rm -rf ${dir}/httpd-cfg
|
||||
fi
|
||||
else
|
||||
if [ -d ${dir}/cfg ]; then
|
||||
echo "---> Copying httpd configuration files from deprecated './cfg' directory, use './httpd-cfg' instead..."
|
||||
if [ "$(ls -A ${dir}/cfg/*.conf)" ]; then
|
||||
cp -v ${dir}/cfg/*.conf "${HTTPD_CONFIGURATION_PATH}"
|
||||
rm -rf ${dir}/cfg
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
# Copy SSL files provided in application source
|
||||
process_ssl_certs() {
|
||||
local dir=${1:-.}
|
||||
if [ -d ${dir}/httpd-ssl/private ] && [ -d ${dir}/httpd-ssl/certs ]; then
|
||||
echo "---> Looking for SSL certs for httpd..."
|
||||
cp -r ${dir}/httpd-ssl ${HTTPD_APP_ROOT}
|
||||
local ssl_cert="$(ls -A ${HTTPD_APP_ROOT}/httpd-ssl/certs/*.pem | head -n 1)"
|
||||
local ssl_private="$(ls -A ${HTTPD_APP_ROOT}/httpd-ssl/private/*.pem | head -n 1)"
|
||||
if [ -f "${ssl_cert}" ] ; then
|
||||
# do sed for SSLCertificateFile and SSLCertificateKeyFile
|
||||
echo "---> Setting SSL cert file for httpd..."
|
||||
sed -i -e "s|^SSLCertificateFile .*$|SSLCertificateFile ${ssl_cert}|" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
|
||||
if [ -f "${ssl_private}" ]; then
|
||||
echo "---> Setting SSL key file for httpd..."
|
||||
sed -i -e "s|^SSLCertificateKeyFile .*$|SSLCertificateKeyFile ${ssl_private}|" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
|
||||
else
|
||||
echo "---> Removing SSL key file settings for httpd..."
|
||||
sed -i '/^SSLCertificateKeyFile .*/d' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
|
||||
fi
|
||||
fi
|
||||
rm -rf ${dir}/httpd-ssl
|
||||
fi
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -0,0 +1,4 @@
|
|||
source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh
|
||||
|
||||
# Copy config files from application to the location where httpd expects them
|
||||
process_config_files
|
||||
|
|
@ -0,0 +1,4 @@
|
|||
source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh
|
||||
|
||||
# Copy SSL files provided in application source
|
||||
process_ssl_certs
|
||||
|
|
@ -0,0 +1,4 @@
|
|||
source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh
|
||||
|
||||
# Copy config files from application to the location where httd expects them
|
||||
process_config_files ${HTTPD_APP_ROOT}/src
|
||||
|
|
@ -0,0 +1,4 @@
|
|||
source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh
|
||||
|
||||
# Copy SSL files provided in application source
|
||||
process_ssl_certs ${HTTPD_APP_ROOT}/src
|
||||
|
|
@ -11,21 +11,7 @@ config_s2i
|
|||
echo "---> Installing application source"
|
||||
cp -Rf /tmp/src/. ./
|
||||
|
||||
if [ -d ./httpd-cfg ]; then
|
||||
echo "---> Copying httpd configuration files..."
|
||||
if [ "$(ls -A ./httpd-cfg/*.conf)" ]; then
|
||||
cp -v ./httpd-cfg/*.conf "${HTTPD_CONFIGURATION_PATH}"
|
||||
rm -rf ./httpd-cfg
|
||||
fi
|
||||
else
|
||||
if [ -d ./cfg ]; then
|
||||
echo "---> Copying httpd configuration files from deprecated './cfg' directory, use './httpd-cfg' instead..."
|
||||
if [ "$(ls -A ./cfg/*.conf)" ]; then
|
||||
cp -v ./cfg/*.conf "${HTTPD_CONFIGURATION_PATH}"
|
||||
rm -rf ./cfg
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
process_extending_files ${HTTPD_APP_ROOT}/src/httpd-post-assemble/ ${HTTPD_CONTAINER_SCRIPTS_PATH}/post-assemble/
|
||||
|
||||
# Fix source directory permissions
|
||||
fix-permissions ./
|
||||
|
|
|
|||
|
|
@ -4,4 +4,4 @@ source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh
|
|||
|
||||
export HTTPD_RUN_BY_S2I=1
|
||||
|
||||
run-httpd $@
|
||||
exec run-httpd $@
|
||||
|
|
|
|||
|
|
@ -10,7 +10,7 @@ To use it, install S2I: https://github.com/openshift/source-to-image
|
|||
|
||||
Sample invocation:
|
||||
|
||||
s2i build https://github.com/sclorg/httpd-container.git --context-dir=2.4/test/sample-test-app/ ${NAMESPACE}/httpd-24-${DISTRO}7 httpd-sample-app
|
||||
s2i build https://github.com/sclorg/httpd-container.git --context-dir=examples/sample-test-app/ ${NAMESPACE}/httpd-24-${DISTRO}7 httpd-sample-app
|
||||
|
||||
You can then run the resulting image via:
|
||||
docker run -p 8080:8080 httpd-sample-app
|
||||
|
|
|
|||
1
test/pre-init-test-app/httpd-pre-init/modify_index.sh
Normal file
1
test/pre-init-test-app/httpd-pre-init/modify_index.sh
Normal file
|
|
@ -0,0 +1 @@
|
|||
echo 'This content was replaced by pre-init script.' > ${HTTPD_APP_ROOT}/src/index.html
|
||||
1
test/pre-init-test-app/index.html
Normal file
1
test/pre-init-test-app/index.html
Normal file
|
|
@ -0,0 +1 @@
|
|||
This is a sample s2i application with static content.
|
||||
42
test/run
42
test/run
|
|
@ -162,7 +162,7 @@ function run_s2i_test() {
|
|||
# Test s2i use case
|
||||
# Since we built the candidate image locally, we don't want S2I attempt to pull
|
||||
# it from Docker hub
|
||||
s2i_args="--force-pull=false"
|
||||
s2i_args="--pull-policy=never"
|
||||
run "s2i usage ${s2i_args} ${IMAGE_NAME}" 0 "Testing 's2i usage'"
|
||||
run "s2i build ${s2i_args} file://${test_dir}/sample-test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp" 0 "Testing 's2i build'"
|
||||
DOCKER_ARGS='-u 1000'
|
||||
|
|
@ -176,6 +176,42 @@ function run_s2i_test() {
|
|||
sleep 2
|
||||
}
|
||||
|
||||
function run_pre_init_test() {
|
||||
# Test s2i use case #2 - testing pre-init script
|
||||
# Since we built the candidate image locally, we don't want S2I attempt to pull
|
||||
# it from Docker hub
|
||||
s2i_args="--pull-policy=never"
|
||||
run "s2i build ${s2i_args} file://${test_dir}/pre-init-test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp2" 0 "Testing 's2i build' with pre-init script"
|
||||
DOCKER_ARGS='-u 1000'
|
||||
create_container testing-app-pre-init ${IMAGE_NAME}-testapp2
|
||||
DOCKER_ARGS=
|
||||
sleep 5
|
||||
cip=$(get_container_ip 'testing-app-pre-init')
|
||||
run "curl ${cip}:8080 > output_pre_init"
|
||||
run "fgrep -e 'This content was replaced by pre-init script.' output_pre_init"
|
||||
# 0 "Checking page served by s2i feature and edited by pre-init script"
|
||||
sleep 2
|
||||
}
|
||||
|
||||
function run_self_cert_test() {
|
||||
# Test s2i use case #3 - using own ssl certs
|
||||
# Since we built the candidate image locally, we don't want S2I attempt to pull
|
||||
# it from Docker hub
|
||||
s2i_args="--pull-policy=never"
|
||||
run "s2i build ${s2i_args} file://${test_dir}/self-signed-ssl ${IMAGE_NAME} ${IMAGE_NAME}-self-signed" 0 "Testing 's2i build' with self-signed cert"
|
||||
DOCKER_ARGS='-u 1000'
|
||||
create_container testing-self-signed ${IMAGE_NAME}-self-signed
|
||||
DOCKER_ARGS=
|
||||
sleep 5
|
||||
cip=$(get_container_ip 'testing-self-signed')
|
||||
run "curl -k https://${cip}:8443 > output_ssl_cert"
|
||||
run "fgrep -e 'SSL test works' output_ssl_cert"
|
||||
echo | openssl s_client -showcerts -servername ${cip} -connect ${cip}:8443 2>/dev/null | openssl x509 -inform pem -noout -text >./servercert
|
||||
openssl x509 -in ${test_dir}/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem -inform pem -noout -text >./configcert
|
||||
run "diff ./configcert ./servercert"
|
||||
run "diff ./configcert ./servercert >cert.diff"
|
||||
sleep 2
|
||||
}
|
||||
|
||||
function run_all_tests() {
|
||||
for test_case in $TEST_LIST; do
|
||||
|
|
@ -224,11 +260,13 @@ run "docker inspect $IMAGE_NAME >/dev/null || docker pull $IMAGE_NAME" 0
|
|||
|
||||
|
||||
TEST_LIST="\
|
||||
run_self_cert_test
|
||||
run_default_page_test
|
||||
run_as_root_test
|
||||
run_log_to_volume_test
|
||||
run_data_volume_test
|
||||
run_s2i_test"
|
||||
run_s2i_test
|
||||
run_pre_init_test"
|
||||
|
||||
test $# -eq 1 -a "${1-}" == --list && echo "$TEST_LIST" && exit 0
|
||||
|
||||
|
|
|
|||
35
test/run-openshift
Executable file
35
test/run-openshift
Executable file
|
|
@ -0,0 +1,35 @@
|
|||
#!/bin/bash
|
||||
#
|
||||
# Test the httpd image in OpenShift.
|
||||
#
|
||||
# IMAGE_NAME specifies a name of the candidate image used for testing.
|
||||
# VERSION specifies a version of the python in the candidate image.
|
||||
# The image has to be available before this script is executed.
|
||||
|
||||
THISDIR=$(dirname ${BASH_SOURCE[0]})
|
||||
|
||||
source "${THISDIR}/test-lib.sh"
|
||||
source "${THISDIR}/test-lib-openshift.sh"
|
||||
|
||||
BRANCH_TO_TEST=master
|
||||
|
||||
set -eo nounset
|
||||
|
||||
test -n "${IMAGE_NAME-}" || false 'make sure $IMAGE_NAME is defined'
|
||||
test -n "${VERSION-}" || false 'make sure $VERSION is defined'
|
||||
|
||||
ct_os_cluster_up
|
||||
|
||||
# test local app
|
||||
ct_os_test_s2i_app "${IMAGE_NAME}" "${THISDIR}/sample-test-app" . 'This is a sample s2i application with static content'
|
||||
|
||||
# test remote example app
|
||||
ct_os_test_s2i_app "${IMAGE_NAME}" "https://github.com/openshift/httpd-ex#${BRANCH_TO_TEST}" . 'Welcome to your static httpd application on OpenShift'
|
||||
|
||||
# test template from the example app
|
||||
ct_os_test_template_app "${IMAGE_NAME}" \
|
||||
"https://raw.githubusercontent.com/openshift/httpd-ex/${BRANCH_TO_TEST}/openshift/templates/httpd.json" \
|
||||
httpd \
|
||||
'Welcome to your static httpd application on OpenShift' \
|
||||
8080 http 200 "-p SOURCE_REPOSITORY_REF=${BRANCH_TO_TEST}"
|
||||
|
||||
|
|
@ -0,0 +1,20 @@
|
|||
-----BEGIN CERTIFICATE-----
|
||||
MIIDWjCCAkKgAwIBAgIJAI4x7HuBG49oMA0GCSqGSIb3DQEBCwUAMEIxCzAJBgNV
|
||||
BAYTAlhYMRUwEwYDVQQHDAxEZWZhdWx0IENpdHkxHDAaBgNVBAoME0RlZmF1bHQg
|
||||
Q29tcGFueSBMdGQwHhcNMTcxMjAzMjMzMzU3WhcNMTgwMTAyMjMzMzU3WjBCMQsw
|
||||
CQYDVQQGEwJYWDEVMBMGA1UEBwwMRGVmYXVsdCBDaXR5MRwwGgYDVQQKDBNEZWZh
|
||||
dWx0IENvbXBhbnkgTHRkMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA
|
||||
vH4Vdq0a3UWUQd8Z6s2csxhxjAOyUx0rszGL0m3uTjQido6JRBdjN2dXiZc3LFoq
|
||||
YeOKR3CeHsn7UdrlzaboHFDfjAaextse0740mB1g14H1bAS0POuTPeKa+3wGfzCb
|
||||
sTSXnfSrICl3n2D/3KSO93WwmS90kBD6HmKt5nfkLpJnROM/4bHmuoV0Ry8CDjzj
|
||||
mka7pQU4yzyMKLU3sHpncZU6g7o4Vezic9ksVzIAbdPCSbF7ktVz/hisyCuzyKN6
|
||||
s2327jq593vBgGOsNU5PDPDjKW74Q0Bv/FxPK4nx+o4IkcRW1QEb+yAx8XOM7CDZ
|
||||
ViKvI/A0b+Y4Y3rIQ465+wIDAQABo1MwUTAdBgNVHQ4EFgQUAY1i6ZNbqO1+46aw
|
||||
pldCyPaWoYswHwYDVR0jBBgwFoAUAY1i6ZNbqO1+46awpldCyPaWoYswDwYDVR0T
|
||||
AQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEADhGjnYGq9JvQcygMYEQiIdyS
|
||||
t06Nu7NUkWz52GJp7WFognWyG+0jAomBR0GSUchfubvVZ7cHIaVKLhiGOqg+HIol
|
||||
7tNRfvE6x/Idk674g6OTRAWxO/wOlgnRMpRy6XhHOtb4HcPcpWFZJS8MC8+HRWIs
|
||||
kzMErXe0/obnKn9O04kcEREfmB7kfcD4ooqk5gwbdQk1W6a44LcN6AB5qYPjOzgF
|
||||
Qnb2aLQW9XhgNhiMsYqDzCZsy0az0rz7NgkVOnKrGJ8x3kVX13GR2joVVHOazms9
|
||||
Gd90z+mLMDTbqCRGIPMLvEp4HtAmBxbgsj/zHyinajIqV96B3Cr3zTdW29lHJg==
|
||||
-----END CERTIFICATE-----
|
||||
28
test/self-signed-ssl/httpd-ssl/private/server-key.pem
Normal file
28
test/self-signed-ssl/httpd-ssl/private/server-key.pem
Normal file
|
|
@ -0,0 +1,28 @@
|
|||
-----BEGIN PRIVATE KEY-----
|
||||
MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQC8fhV2rRrdRZRB
|
||||
3xnqzZyzGHGMA7JTHSuzMYvSbe5ONCJ2jolEF2M3Z1eJlzcsWiph44pHcJ4eyftR
|
||||
2uXNpugcUN+MBp7G2x7TvjSYHWDXgfVsBLQ865M94pr7fAZ/MJuxNJed9KsgKXef
|
||||
YP/cpI73dbCZL3SQEPoeYq3md+QukmdE4z/hsea6hXRHLwIOPOOaRrulBTjLPIwo
|
||||
tTewemdxlTqDujhV7OJz2SxXMgBt08JJsXuS1XP+GKzIK7PIo3qzbfbuOrn3e8GA
|
||||
Y6w1Tk8M8OMpbvhDQG/8XE8rifH6jgiRxFbVARv7IDHxc4zsINlWIq8j8DRv5jhj
|
||||
eshDjrn7AgMBAAECggEARZxeutxE/pCypv0IqkFS7IVLccTvt2gfemcC1yzIBFOW
|
||||
oqgTI3Vrq8tbdbHFq3iFDG+m4qlBi+dWDC3GDoPkVoi7dg//1TqZEOO+sqqu2Afj
|
||||
pge6tIDfeMxWJifwkkpWRURB9hCknhUSW2bMNyUCs3rgREJVTtsmM9CHnoSKXXQL
|
||||
aOeYXalFVpx3ceK+xdp0VGfpsqEabBKs0yy3EDiQy2huoWce3EVFLVrwx/IkhcsZ
|
||||
JlI5LPpoiTglSs1g9i88JHS2slBtKtb1lWl/yXHhK1g7s34c6f9jP8snuFE5ddMn
|
||||
0L4GDA9teaPGvB533eb2RIFy2kUYgpr5c03G6rpoOQKBgQDpY6BFJkPGENnC5Bdb
|
||||
fJCuN2nyRdC1qvv6ESFaQYb0s6QjKDqpb0dUSYN3+zNgtiAysbQLeU/d9mmt4UR8
|
||||
ohjRkOySU0eQ/YNFokjw6g6GPoiMHJJ9cP75NA94uIMIUTY7uHEWWZwXI5UphdPC
|
||||
p5/3MaF1VlYQys9a5wtiEaDSfQKBgQDOwPV0zQjUabkVQ4yV0amP8xybvHH8ghG0
|
||||
RMStHg96RfDmg35JQaw22A2xiVROCoZgLqiE1DFSl/3gBF/vfqBh/uzdxwNerJC6
|
||||
ROdCxyS4rys5d/02P4aNOa73sD+ZKyEZRTF1v3bmOGKidRFF5oxIpuHjFWlJFKx1
|
||||
O/b3AI0v1wKBgQC/L4N84emm+OrKAfs4UIRckrxRYOulxhmAMkQ2IXOiRP5yZmQX
|
||||
pDa0TzxJLxhZYxhhLr0koQ3R8CeF7wEhb9AQ7D0/aMU5etLsWhKSd8nKIrPMwyMl
|
||||
a0kTb5g09kEwsQZSSbcp7eI1+koYp65eyN37q0ZuTnlWbC0MdDQY9APgKQKBgQCb
|
||||
HqaKNXLUe2XDkGSf2ygOumXSanZS7vt9dsLg59bQ9DyjljBfogglNcBAXTqFOtxK
|
||||
uXbyAYnn3+U399BKjYSjQXJRioj6tRn4xs2DiooAjlwtx9qQouS+fHLLns54iqVQ
|
||||
oltTbo00eUV3gcGt4iWKNLrxdxUBIaOqaY0HEMDdDQKBgQCRvcHDF7JSPuBiO3Tw
|
||||
PSOUD4q6dD/dhI+X2ZKg83w94SZXXms6eMSbedUkLoJ8TDunmdRUUWb6rgP/pJwr
|
||||
zKRTskItF15i9IWCwC6jBrSfx5n2JcSoBALyc0aR9heF0GQjWwqURd+PC/msomrW
|
||||
z9SCl8mpQVFtBlui7PcnDLTFAg==
|
||||
-----END PRIVATE KEY-----
|
||||
1
test/self-signed-ssl/index.html
Normal file
1
test/self-signed-ssl/index.html
Normal file
|
|
@ -0,0 +1 @@
|
|||
SSL test works
|
||||
609
test/test-lib-openshift.sh
Normal file
609
test/test-lib-openshift.sh
Normal file
|
|
@ -0,0 +1,609 @@
|
|||
# Set of functions for testing docker images in OpenShift using 'oc' command
|
||||
|
||||
# ct_os_get_status
|
||||
# --------------------
|
||||
# Returns status of all objects to make debugging easier.
|
||||
function ct_os_get_status() {
|
||||
oc get all
|
||||
oc status
|
||||
}
|
||||
|
||||
# ct_os_print_logs
|
||||
# --------------------
|
||||
# Returns status of all objects and logs from all pods.
|
||||
function ct_os_print_logs() {
|
||||
ct_os_get_status
|
||||
while read pod_name; do
|
||||
echo "INFO: printing logs for pod ${pod_name}"
|
||||
oc logs ${pod_name}
|
||||
done < <(oc get pods --no-headers=true -o custom-columns=NAME:.metadata.name)
|
||||
}
|
||||
|
||||
# ct_os_enable_print_logs
|
||||
# --------------------
|
||||
# Enables automatic printing of pod logs on ERR.
|
||||
function ct_os_enable_print_logs() {
|
||||
set -E
|
||||
trap ct_os_print_logs ERR
|
||||
}
|
||||
|
||||
# ct_get_public_ip
|
||||
# --------------------
|
||||
# Returns best guess for the IP that the node is accessible from other computers.
|
||||
# This is a bit funny heuristic, simply goes through all IPv4 addresses that
|
||||
# hostname -I returns and de-prioritizes IP addresses commonly used for local
|
||||
# addressing. The rest of addresses are taken as public with higher probability.
|
||||
function ct_get_public_ip() {
|
||||
local hostnames=$(hostname -I)
|
||||
local public_ip=''
|
||||
local found_ip
|
||||
for guess_exp in '127\.0\.0\.1' '192\.168\.[0-9\.]*' '172\.[0-9\.]*' \
|
||||
'10\.[0-9\.]*' '[0-9\.]*' ; do
|
||||
found_ip=$(echo "${hostnames}" | grep -oe "${guess_exp}")
|
||||
if [ -n "${found_ip}" ] ; then
|
||||
hostnames=$(echo "${hostnames}" | sed -e "s/${found_ip}//")
|
||||
public_ip="${found_ip}"
|
||||
fi
|
||||
done
|
||||
if [ -z "${public_ip}" ] ; then
|
||||
echo "ERROR: public IP could not be guessed." >&2
|
||||
return 1
|
||||
fi
|
||||
echo "${public_ip}"
|
||||
}
|
||||
|
||||
# ct_os_run_in_pod POD_NAME CMD
|
||||
# --------------------
|
||||
# Runs [cmd] in the pod specified by prefix [pod_prefix].
|
||||
# Arguments: pod_name - full name of the pod
|
||||
# Arguments: cmd - command to be run in the pod
|
||||
function ct_os_run_in_pod() {
|
||||
local pod_name="$1" ; shift
|
||||
|
||||
oc exec "$pod_name" -- "$@"
|
||||
}
|
||||
|
||||
# ct_os_get_service_ip SERVICE_NAME
|
||||
# --------------------
|
||||
# Returns IP of the service specified by [service_name].
|
||||
# Arguments: service_name - name of the service
|
||||
function ct_os_get_service_ip() {
|
||||
local service_name="${1}" ; shift
|
||||
oc get "svc/${service_name}" -o yaml | grep clusterIP | \
|
||||
cut -d':' -f2 | grep -oe '172\.30\.[0-9\.]*'
|
||||
}
|
||||
|
||||
|
||||
# ct_os_get_all_pods_status
|
||||
# --------------------
|
||||
# Returns status of all pods.
|
||||
function ct_os_get_all_pods_status() {
|
||||
oc get pods -o custom-columns=Ready:status.containerStatuses[0].ready,NAME:.metadata.name
|
||||
}
|
||||
|
||||
# ct_os_get_all_pods_name
|
||||
# --------------------
|
||||
# Returns the full name of all pods.
|
||||
function ct_os_get_all_pods_name() {
|
||||
oc get pods --no-headers -o custom-columns=NAME:.metadata.name
|
||||
}
|
||||
|
||||
# ct_os_get_pod_status POD_PREFIX
|
||||
# --------------------
|
||||
# Returns status of the pod specified by prefix [pod_prefix].
|
||||
# Note: Ignores -build and -deploy pods
|
||||
# Arguments: pod_prefix - prefix or whole ID of the pod
|
||||
function ct_os_get_pod_status() {
|
||||
local pod_prefix="${1}" ; shift
|
||||
ct_os_get_all_pods_status | grep -e "${pod_prefix}" | grep -Ev "(build|deploy)$" \
|
||||
| awk '{print $1}' | head -n 1
|
||||
}
|
||||
|
||||
# ct_os_get_pod_name POD_PREFIX
|
||||
# --------------------
|
||||
# Returns the full name of pods specified by prefix [pod_prefix].
|
||||
# Note: Ignores -build and -deploy pods
|
||||
# Arguments: pod_prefix - prefix or whole ID of the pod
|
||||
function ct_os_get_pod_name() {
|
||||
local pod_prefix="${1}" ; shift
|
||||
ct_os_get_all_pods_name | grep -e "^${pod_prefix}" | grep -Ev "(build|deploy)$"
|
||||
}
|
||||
|
||||
# ct_os_get_pod_ip POD_NAME
|
||||
# --------------------
|
||||
# Returns the ip of the pod specified by [pod_name].
|
||||
# Arguments: pod_name - full name of the pod
|
||||
function ct_os_get_pod_ip() {
|
||||
local pod_name="${1}"
|
||||
oc get pod "$pod_name" --no-headers -o custom-columns=IP:status.podIP
|
||||
}
|
||||
|
||||
# ct_os_check_pod_readiness POD_PREFIX STATUS
|
||||
# --------------------
|
||||
# Checks whether the pod is ready.
|
||||
# Arguments: pod_prefix - prefix or whole ID of the pod
|
||||
# Arguments: status - expected status (true, false)
|
||||
function ct_os_check_pod_readiness() {
|
||||
local pod_prefix="${1}" ; shift
|
||||
local status="${1}" ; shift
|
||||
test "$(ct_os_get_pod_status ${pod_prefix})" == "${status}"
|
||||
}
|
||||
|
||||
# ct_os_wait_pod_ready POD_PREFIX TIMEOUT
|
||||
# --------------------
|
||||
# Wait maximum [timeout] for the pod becomming ready.
|
||||
# Arguments: pod_prefix - prefix or whole ID of the pod
|
||||
# Arguments: timeout - how many seconds to wait seconds
|
||||
function ct_os_wait_pod_ready() {
|
||||
local pod_prefix="${1}" ; shift
|
||||
local timeout="${1}" ; shift
|
||||
SECONDS=0
|
||||
echo -n "Waiting for ${pod_prefix} pod becoming ready ..."
|
||||
while ! ct_os_check_pod_readiness "${pod_prefix}" "true" ; do
|
||||
echo -n "."
|
||||
[ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1
|
||||
sleep 3
|
||||
done
|
||||
echo " DONE"
|
||||
}
|
||||
|
||||
# ct_os_wait_rc_ready POD_PREFIX TIMEOUT
|
||||
# --------------------
|
||||
# Wait maximum [timeout] for the rc having desired number of replicas ready.
|
||||
# Arguments: pod_prefix - prefix of the replication controller
|
||||
# Arguments: timeout - how many seconds to wait seconds
|
||||
function ct_os_wait_rc_ready() {
|
||||
local pod_prefix="${1}" ; shift
|
||||
local timeout="${1}" ; shift
|
||||
SECONDS=0
|
||||
echo -n "Waiting for ${pod_prefix} pod becoming ready ..."
|
||||
while ! test "$((oc get --no-headers statefulsets; oc get --no-headers rc) 2>/dev/null \
|
||||
| grep "^${pod_prefix}" | awk '$2==$3 {print "ready"}')" == "ready" ; do
|
||||
echo -n "."
|
||||
[ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1
|
||||
sleep 3
|
||||
done
|
||||
echo " DONE"
|
||||
}
|
||||
|
||||
# ct_os_deploy_pure_image IMAGE [ENV_PARAMS, ...]
|
||||
# --------------------
|
||||
# Runs [image] in the openshift and optionally specifies env_params
|
||||
# as environment variables to the image.
|
||||
# Arguments: image - prefix or whole ID of the pod to run the cmd in
|
||||
# Arguments: env_params - environment variables parameters for the images.
|
||||
function ct_os_deploy_pure_image() {
|
||||
local image="${1}" ; shift
|
||||
# ignore error exit code, because oc new-app returns error when image exists
|
||||
oc new-app ${image} "$@" || :
|
||||
# let openshift cluster to sync to avoid some race condition errors
|
||||
sleep 3
|
||||
}
|
||||
|
||||
# ct_os_deploy_s2i_image IMAGE APP [ENV_PARAMS, ... ]
|
||||
# --------------------
|
||||
# Runs [image] and [app] in the openshift and optionally specifies env_params
|
||||
# as environment variables to the image.
|
||||
# Arguments: image - prefix or whole ID of the pod to run the cmd in
|
||||
# Arguments: app - url or local path to git repo with the application sources.
|
||||
# Arguments: env_params - environment variables parameters for the images.
|
||||
function ct_os_deploy_s2i_image() {
|
||||
local image="${1}" ; shift
|
||||
local app="${1}" ; shift
|
||||
# ignore error exit code, because oc new-app returns error when image exists
|
||||
oc new-app "${image}~${app}" "$@" || :
|
||||
|
||||
# let openshift cluster to sync to avoid some race condition errors
|
||||
sleep 3
|
||||
}
|
||||
|
||||
# ct_os_deploy_template_image TEMPLATE [ENV_PARAMS, ...]
|
||||
# --------------------
|
||||
# Runs template in the openshift and optionally gives env_params to use
|
||||
# specific values in the template.
|
||||
# Arguments: template - prefix or whole ID of the pod to run the cmd in
|
||||
# Arguments: env_params - environment variables parameters for the template.
|
||||
# Example usage: ct_os_deploy_template_image mariadb-ephemeral-template.yaml \
|
||||
# DATABASE_SERVICE_NAME=mysql-57-centos7 \
|
||||
# DATABASE_IMAGE=mysql-57-centos7 \
|
||||
# MYSQL_USER=testu \
|
||||
# MYSQL_PASSWORD=testp \
|
||||
# MYSQL_DATABASE=testdb
|
||||
function ct_os_deploy_template_image() {
|
||||
local template="${1}" ; shift
|
||||
oc process -f "${template}" "$@" | oc create -f -
|
||||
# let openshift cluster to sync to avoid some race condition errors
|
||||
sleep 3
|
||||
}
|
||||
|
||||
# _ct_os_get_uniq_project_name
|
||||
# --------------------
|
||||
# Returns a uniq name of the OpenShift project.
|
||||
function _ct_os_get_uniq_project_name() {
|
||||
local r
|
||||
while true ; do
|
||||
r=${RANDOM}
|
||||
mkdir /var/tmp/os-test-${r} &>/dev/null && echo test-${r} && break
|
||||
done
|
||||
}
|
||||
|
||||
# ct_os_new_project [PROJECT]
|
||||
# --------------------
|
||||
# Creates a new project in the openshfit using 'os' command.
|
||||
# Arguments: project - project name, uses a new random name if omitted
|
||||
# Expects 'os' command that is properly logged in to the OpenShift cluster.
|
||||
# Not using mktemp, because we cannot use uppercase characters.
|
||||
function ct_os_new_project() {
|
||||
local project_name="${1:-$(_ct_os_get_uniq_project_name)}" ; shift || :
|
||||
oc new-project ${project_name}
|
||||
# let openshift cluster to sync to avoid some race condition errors
|
||||
sleep 3
|
||||
}
|
||||
|
||||
# ct_os_delete_project [PROJECT]
|
||||
# --------------------
|
||||
# Deletes the specified project in the openshfit
|
||||
# Arguments: project - project name, uses the current project if omitted
|
||||
function ct_os_delete_project() {
|
||||
local project_name="${1:-$(oc project -q)}" ; shift || :
|
||||
oc delete project "${project_name}"
|
||||
}
|
||||
|
||||
# ct_os_docker_login
|
||||
# --------------------
|
||||
# Logs in into docker daemon
|
||||
function ct_os_docker_login() {
|
||||
# docker login fails with "404 page not found" error sometimes, just try it more times
|
||||
for i in `seq 12` ; do
|
||||
docker login -u developer -p $(oc whoami -t) 172.30.1.1:5000 && return 0 || :
|
||||
sleep 5
|
||||
done
|
||||
return 1
|
||||
}
|
||||
|
||||
# ct_os_upload_image IMAGE [IMAGESTREAM]
|
||||
# --------------------
|
||||
# Uploads image from local registry to the OpenShift internal registry.
|
||||
# Arguments: image - image name to upload
|
||||
# Arguments: imagestream - name and tag to use for the internal registry.
|
||||
# In the format of name:tag ($image_name:latest by default)
|
||||
function ct_os_upload_image() {
|
||||
local input_name="${1}" ; shift
|
||||
local image_name=${input_name##*/}
|
||||
local imagestream=${1:-$image_name:latest}
|
||||
local output_name="172.30.1.1:5000/$(oc project -q)/$imagestream"
|
||||
|
||||
ct_os_docker_login
|
||||
docker tag ${input_name} ${output_name}
|
||||
docker push ${output_name}
|
||||
}
|
||||
|
||||
# ct_os_install_in_centos
|
||||
# --------------------
|
||||
# Installs os cluster in CentOS
|
||||
function ct_os_install_in_centos() {
|
||||
yum install -y centos-release-openshift-origin
|
||||
yum install -y wget git net-tools bind-utils iptables-services bridge-utils\
|
||||
bash-completion origin-clients docker origin-clients
|
||||
}
|
||||
|
||||
# ct_os_cluster_up [DIR, IS_PUBLIC, CLUSTER_VERSION]
|
||||
# --------------------
|
||||
# Runs the local OpenShift cluster using 'oc cluster up' and logs in as developer.
|
||||
# Arguments: dir - directory to keep configuration data in, random if omitted
|
||||
# Arguments: is_public - sets either private or public hostname for web-UI,
|
||||
# use "true" for allow remote access to the web-UI,
|
||||
# "false" is default
|
||||
# Arguments: cluster_version - version of the OpenShift cluster to use, empty
|
||||
# means default version of `oc`; example value: v3.7.0;
|
||||
# also can be specified outside by OC_CLUSTER_VERSION
|
||||
function ct_os_cluster_up() {
|
||||
ct_os_cluster_running && echo "Cluster already running. Nothing is done." && return 0
|
||||
mkdir -p /var/tmp/openshift
|
||||
local dir="${1:-$(mktemp -d /var/tmp/openshift/os-data-XXXXXX)}" ; shift || :
|
||||
local is_public="${1:-'false'}" ; shift || :
|
||||
local default_cluster_version=${OC_CLUSTER_VERSION:-}
|
||||
local cluster_version=${1:-${default_cluster_version}} ; shift || :
|
||||
if ! grep -qe '--insecure-registry.*172\.30\.0\.0' /etc/sysconfig/docker ; then
|
||||
sed -i "s|OPTIONS='|OPTIONS='--insecure-registry 172.30.0.0/16 |" /etc/sysconfig/docker
|
||||
fi
|
||||
|
||||
systemctl stop firewalld
|
||||
setenforce 0
|
||||
iptables -F
|
||||
|
||||
systemctl restart docker
|
||||
local cluster_ip="127.0.0.1"
|
||||
[ "${is_public}" == "true" ] && cluster_ip=$(ct_get_public_ip)
|
||||
|
||||
mkdir -p ${dir}/{config,data,pv}
|
||||
oc cluster up --host-data-dir=${dir}/data --host-config-dir=${dir}/config \
|
||||
--host-pv-dir=${dir}/pv --use-existing-config --public-hostname=${cluster_ip} \
|
||||
${cluster_version:+--version=$cluster_version }
|
||||
oc version
|
||||
oc login -u system:admin
|
||||
oc project default
|
||||
ct_os_wait_rc_ready docker-registry 180
|
||||
ct_os_wait_rc_ready router 30
|
||||
oc login -u developer -p developer
|
||||
# let openshift cluster to sync to avoid some race condition errors
|
||||
sleep 3
|
||||
}
|
||||
|
||||
# ct_os_cluster_down
|
||||
# --------------------
|
||||
# Shuts down the local OpenShift cluster using 'oc cluster down'
|
||||
function ct_os_cluster_down() {
|
||||
oc cluster down
|
||||
}
|
||||
|
||||
# ct_os_cluster_running
|
||||
# --------------------
|
||||
# Returns 0 if oc cluster is running
|
||||
function ct_os_cluster_running() {
|
||||
oc cluster status &>/dev/null
|
||||
}
|
||||
|
||||
# ct_os_test_s2i_app_func IMAGE APP CONTEXT_DIR CHECK_CMD [OC_ARGS]
|
||||
# --------------------
|
||||
# Runs [image] and [app] in the openshift and optionally specifies env_params
|
||||
# as environment variables to the image. Then check the container by arbitrary
|
||||
# function given as argument (such an argument may include <IP> string,
|
||||
# that will be replaced with actual IP).
|
||||
# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory)
|
||||
# Arguments: app - url or local path to git repo with the application sources (compulsory)
|
||||
# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory)
|
||||
# Arguments: check_command - CMD line that checks whether the container works (compulsory; '<IP>' will be replaced with actual IP)
|
||||
# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app`
|
||||
# command, typically environment variables (optional)
|
||||
function ct_os_test_s2i_app_func() {
|
||||
local image_name=${1}
|
||||
local app=${2}
|
||||
local context_dir=${3}
|
||||
local check_command=${4}
|
||||
local oc_args=${5:-}
|
||||
local image_name_no_namespace=${image_name##*/}
|
||||
local service_name="${image_name_no_namespace}-testing"
|
||||
local image_tagged="${image_name_no_namespace}:testing"
|
||||
|
||||
if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then
|
||||
echo "ERROR: ct_os_test_s2i_app_func() requires at least 4 arguments that cannot be emtpy." >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
ct_os_new_project
|
||||
# Create a specific imagestream tag for the image so that oc cannot use anything else
|
||||
ct_os_upload_image "${image_name}" "${image_tagged}"
|
||||
|
||||
local app_param="${app}"
|
||||
if [ -d "${app}" ] ; then
|
||||
# for local directory, we need to copy the content, otherwise too smart os command
|
||||
# pulls the git remote repository instead
|
||||
app_param=$(ct_obtain_input "${app}")
|
||||
fi
|
||||
|
||||
ct_os_deploy_s2i_image "${image_tagged}" "${app_param}" \
|
||||
--context-dir="${context_dir}" \
|
||||
--name "${service_name}" \
|
||||
${oc_args}
|
||||
|
||||
if [ -d "${app}" ] ; then
|
||||
# in order to avoid weird race seen sometimes, let's wait shortly
|
||||
# before starting the build explicitly
|
||||
sleep 5
|
||||
oc start-build "${service_name}" --from-dir="${app_param}"
|
||||
fi
|
||||
|
||||
ct_os_wait_pod_ready "${service_name}" 300
|
||||
|
||||
local ip=$(ct_os_get_service_ip "${service_name}")
|
||||
local check_command_exp=$(echo "$check_command" | sed -e "s/<IP>/$ip/g")
|
||||
|
||||
echo " Checking APP using $check_command_exp ..."
|
||||
local result=0
|
||||
eval "$check_command_exp" || result=1
|
||||
|
||||
if [ $result -eq 0 ] ; then
|
||||
echo " Check passed."
|
||||
else
|
||||
echo " Check failed."
|
||||
fi
|
||||
|
||||
ct_os_delete_project
|
||||
return $result
|
||||
}
|
||||
|
||||
# ct_os_test_s2i_app IMAGE APP CONTEXT_DIR EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ]
|
||||
# --------------------
|
||||
# Runs [image] and [app] in the openshift and optionally specifies env_params
|
||||
# as environment variables to the image. Then check the http response.
|
||||
# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory)
|
||||
# Arguments: app - url or local path to git repo with the application sources (compulsory)
|
||||
# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory)
|
||||
# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory)
|
||||
# Arguments: port - which port to use (optional; default: 8080)
|
||||
# Arguments: protocol - which protocol to use (optional; default: http)
|
||||
# Arguments: response_code - what http response code to expect (optional; default: 200)
|
||||
# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app`
|
||||
# command, typically environment variables (optional)
|
||||
function ct_os_test_s2i_app() {
|
||||
local image_name=${1}
|
||||
local app=${2}
|
||||
local context_dir=${3}
|
||||
local expected_output=${4}
|
||||
local port=${5:-8080}
|
||||
local protocol=${6:-http}
|
||||
local response_code=${7:-200}
|
||||
local oc_args=${8:-}
|
||||
|
||||
if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then
|
||||
echo "ERROR: ct_os_test_s2i_app() requires at least 4 arguments that cannot be emtpy." >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
ct_os_test_s2i_app_func "${image_name}" \
|
||||
"${app}" \
|
||||
"${context_dir}" \
|
||||
"ct_test_response '${protocol}://<IP>:${port}' '${response_code}' '${expected_output}'" \
|
||||
"${oc_args}"
|
||||
}
|
||||
|
||||
# ct_os_test_template_app_func IMAGE APP IMAGE_IN_TEMPLATE CHECK_CMD [OC_ARGS]
|
||||
# --------------------
|
||||
# Runs [image] and [app] in the openshift and optionally specifies env_params
|
||||
# as environment variables to the image. Then check the container by arbitrary
|
||||
# function given as argument (such an argument may include <IP> string,
|
||||
# that will be replaced with actual IP).
|
||||
# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory)
|
||||
# Arguments: template - url or local path to a template to use (compulsory)
|
||||
# Arguments: name_in_template - image name used in the template
|
||||
# Arguments: check_command - CMD line that checks whether the container works (compulsory; '<IP>' will be replaced with actual IP)
|
||||
# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app`
|
||||
# command, typically environment variables (optional)
|
||||
# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry,
|
||||
# specify them in this parameter as "<image>|<tag>", where "<image>" is a full image name
|
||||
# (including registry if needed) and "<tag>" is a tag under which the image should be available
|
||||
# in the OpenShift registry.
|
||||
function ct_os_test_template_app_func() {
|
||||
local image_name=${1}
|
||||
local template=${2}
|
||||
local name_in_template=${3}
|
||||
local check_command=${4}
|
||||
local oc_args=${5:-}
|
||||
local other_images=${6:-}
|
||||
|
||||
if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then
|
||||
echo "ERROR: ct_os_test_template_app_func() requires at least 4 arguments that cannot be emtpy." >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
local service_name="${name_in_template}-testing"
|
||||
local image_tagged="${name_in_template}:${VERSION}"
|
||||
|
||||
ct_os_new_project
|
||||
# Create a specific imagestream tag for the image so that oc cannot use anything else
|
||||
ct_os_upload_image "${image_name}" "${image_tagged}"
|
||||
|
||||
# upload also other images, that template might need (list of pairs in the format <image>|<tag>
|
||||
local images_tags_a
|
||||
local i_t
|
||||
for i_t in ${other_images} ; do
|
||||
echo "${i_t}"
|
||||
IFS='|' read -ra image_tag_a <<< "${i_t}"
|
||||
docker pull "${image_tag_a[0]}"
|
||||
ct_os_upload_image "${image_tag_a[0]}" "${image_tag_a[1]}"
|
||||
done
|
||||
|
||||
local local_template=$(ct_obtain_input "${template}")
|
||||
oc new-app ${local_template} \
|
||||
-p NAME="${service_name}" \
|
||||
-p NAMESPACE="$(oc project -q)" \
|
||||
${oc_args}
|
||||
|
||||
oc start-build "${service_name}"
|
||||
|
||||
ct_os_wait_pod_ready "${service_name}" 300
|
||||
|
||||
local ip=$(ct_os_get_service_ip "${service_name}")
|
||||
local check_command_exp=$(echo "$check_command" | sed -e "s/<IP>/$ip/g")
|
||||
|
||||
echo " Checking APP using $check_command_exp ..."
|
||||
local result=0
|
||||
eval "$check_command_exp" || result=1
|
||||
|
||||
if [ $result -eq 0 ] ; then
|
||||
echo " Check passed."
|
||||
else
|
||||
echo " Check failed."
|
||||
fi
|
||||
|
||||
ct_os_delete_project
|
||||
return $result
|
||||
}
|
||||
|
||||
# params:
|
||||
# ct_os_test_template_app IMAGE APP IMAGE_IN_TEMPLATE EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ]
|
||||
# --------------------
|
||||
# Runs [image] and [app] in the openshift and optionally specifies env_params
|
||||
# as environment variables to the image. Then check the http response.
|
||||
# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory)
|
||||
# Arguments: template - url or local path to a template to use (compulsory)
|
||||
# Arguments: name_in_template - image name used in the template
|
||||
# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory)
|
||||
# Arguments: port - which port to use (optional; default: 8080)
|
||||
# Arguments: protocol - which protocol to use (optional; default: http)
|
||||
# Arguments: response_code - what http response code to expect (optional; default: 200)
|
||||
# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app`
|
||||
# command, typically environment variables (optional)
|
||||
# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry,
|
||||
# specify them in this parameter as "<image>|<tag>", where "<image>" is a full image name
|
||||
# (including registry if needed) and "<tag>" is a tag under which the image should be available
|
||||
# in the OpenShift registry.
|
||||
function ct_os_test_template_app() {
|
||||
local image_name=${1}
|
||||
local template=${2}
|
||||
local name_in_template=${3}
|
||||
local expected_output=${4}
|
||||
local port=${5:-8080}
|
||||
local protocol=${6:-http}
|
||||
local response_code=${7:-200}
|
||||
local oc_args=${8:-}
|
||||
local other_images=${9:-}
|
||||
|
||||
if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then
|
||||
echo "ERROR: ct_os_test_template_app() requires at least 4 arguments that cannot be emtpy." >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
ct_os_test_template_app_func "${image_name}" \
|
||||
"${template}" \
|
||||
"${name_in_template}" \
|
||||
"ct_test_response '${protocol}://<IP>:${port}' '${response_code}' '${expected_output}'" \
|
||||
"${oc_args}" \
|
||||
"${other_images}"
|
||||
}
|
||||
|
||||
# ct_os_test_image_update IMAGE IS CHECK_CMD OC_ARGS
|
||||
# --------------------
|
||||
# Runs an image update test with [image] uploaded to [is] imagestream
|
||||
# and checks the services using an arbitrary function provided in [check_cmd].
|
||||
# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory)
|
||||
# Arguments: is - imagestream to upload the images into (compulsory)
|
||||
# Arguments: check_cmd - command to be run to check functionality of created services (compulsory)
|
||||
# Arguments: oc_args - arguments to use during oc new-app (compulsory)
|
||||
ct_os_test_image_update() {
|
||||
local image_name=$1; shift
|
||||
local istag=$1; shift
|
||||
local check_function=$1; shift
|
||||
local service_name=${image_name##*/}
|
||||
local old_image="" ip="" check_command_exp="" registry=""
|
||||
registry=$(ct_registry_from_os "$OS")
|
||||
old_image="$registry/$image_name"
|
||||
|
||||
echo "Running image update test for: $image_name"
|
||||
ct_os_new_project
|
||||
|
||||
# Get current image from repository and create an imagestream
|
||||
docker pull "$old_image:latest" 2>/dev/null
|
||||
ct_os_upload_image "$old_image" "$istag"
|
||||
|
||||
# Setup example application with curent image
|
||||
oc new-app "$@" --name "$service_name"
|
||||
ct_os_wait_pod_ready "$service_name" 60
|
||||
|
||||
# Check application output
|
||||
ip=$(ct_os_get_service_ip "$service_name")
|
||||
check_command_exp=${check_function//<IP>/$ip}
|
||||
ct_assert_cmd_success "$check_command_exp"
|
||||
|
||||
# Tag built image into the imagestream and wait for rebuild
|
||||
ct_os_upload_image "$image_name" "$istag"
|
||||
ct_os_wait_pod_ready "${service_name}-2" 60
|
||||
|
||||
# Check application output
|
||||
ip=$(ct_os_get_service_ip "$service_name")
|
||||
check_command_exp=${check_function//<IP>/$ip}
|
||||
ct_assert_cmd_success "$check_command_exp"
|
||||
|
||||
ct_os_delete_project
|
||||
}
|
||||
402
test/test-lib.sh
Normal file
402
test/test-lib.sh
Normal file
|
|
@ -0,0 +1,402 @@
|
|||
#
|
||||
# Test a container image.
|
||||
#
|
||||
# Always use sourced from a specific container testfile
|
||||
#
|
||||
# reguires definition of CID_FILE_DIR
|
||||
# CID_FILE_DIR=$(mktemp --suffix=<container>_test_cidfiles -d)
|
||||
# reguires definition of TEST_LIST
|
||||
# TEST_LIST="\
|
||||
# ctest_container_creation
|
||||
# ctest_doc_content"
|
||||
|
||||
# Container CI tests
|
||||
# abbreviated as "ct"
|
||||
|
||||
# may be redefined in the specific container testfile
|
||||
EXPECTED_EXIT_CODE=0
|
||||
|
||||
# ct_cleanup
|
||||
# --------------------
|
||||
# Cleans up containers used during tests. Stops and removes all containers
|
||||
# referenced by cid_files in CID_FILE_DIR. Dumps logs if a container exited
|
||||
# unexpectedly. Removes the cid_files and CID_FILE_DIR as well.
|
||||
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
||||
# Uses: $EXPECTED_EXIT_CODE - expected container exit code
|
||||
function ct_cleanup() {
|
||||
for cid_file in $CID_FILE_DIR/* ; do
|
||||
local container=$(cat $cid_file)
|
||||
|
||||
: "Stopping and removing container $container..."
|
||||
docker stop $container
|
||||
exit_status=$(docker inspect -f '{{.State.ExitCode}}' $container)
|
||||
if [ "$exit_status" != "$EXPECTED_EXIT_CODE" ]; then
|
||||
: "Dumping logs for $container"
|
||||
docker logs $container
|
||||
fi
|
||||
docker rm -v $container
|
||||
rm $cid_file
|
||||
done
|
||||
rmdir $CID_FILE_DIR
|
||||
: "Done."
|
||||
}
|
||||
|
||||
# ct_enable_cleanup
|
||||
# --------------------
|
||||
# Enables automatic container cleanup after tests.
|
||||
function ct_enable_cleanup() {
|
||||
trap ct_cleanup EXIT SIGINT
|
||||
}
|
||||
|
||||
# ct_get_cid [name]
|
||||
# --------------------
|
||||
# Prints container id from cid_file based on the name of the file.
|
||||
# Argument: name - name of cid_file where the container id will be stored
|
||||
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
||||
function ct_get_cid() {
|
||||
local name="$1" ; shift || return 1
|
||||
echo $(cat "$CID_FILE_DIR/$name")
|
||||
}
|
||||
|
||||
# ct_get_cip [id]
|
||||
# --------------------
|
||||
# Prints container ip address based on the container id.
|
||||
# Argument: id - container id
|
||||
function ct_get_cip() {
|
||||
local id="$1" ; shift
|
||||
docker inspect --format='{{.NetworkSettings.IPAddress}}' $(ct_get_cid "$id")
|
||||
}
|
||||
|
||||
# ct_wait_for_cid [cid_file]
|
||||
# --------------------
|
||||
# Holds the execution until the cid_file is created. Usually run after container
|
||||
# creation.
|
||||
# Argument: cid_file - name of the cid_file that should be created
|
||||
function ct_wait_for_cid() {
|
||||
local cid_file=$1
|
||||
local max_attempts=10
|
||||
local sleep_time=1
|
||||
local attempt=1
|
||||
local result=1
|
||||
while [ $attempt -le $max_attempts ]; do
|
||||
[ -f $cid_file ] && [ -s $cid_file ] && return 0
|
||||
: "Waiting for container start..."
|
||||
attempt=$(( $attempt + 1 ))
|
||||
sleep $sleep_time
|
||||
done
|
||||
return 1
|
||||
}
|
||||
|
||||
# ct_assert_container_creation_fails [container_args]
|
||||
# --------------------
|
||||
# The invocation of docker run should fail based on invalid container_args
|
||||
# passed to the function. Returns 0 when container fails to start properly.
|
||||
# Argument: container_args - all arguments are passed directly to dokcer run
|
||||
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
||||
function ct_assert_container_creation_fails() {
|
||||
local ret=0
|
||||
local max_attempts=10
|
||||
local attempt=1
|
||||
local cid_file=assert
|
||||
set +e
|
||||
local old_container_args="${CONTAINER_ARGS-}"
|
||||
CONTAINER_ARGS="$@"
|
||||
ct_create_container $cid_file
|
||||
if [ $? -eq 0 ]; then
|
||||
local cid=$(ct_get_cid $cid_file)
|
||||
|
||||
while [ "$(docker inspect -f '{{.State.Running}}' $cid)" == "true" ] ; do
|
||||
sleep 2
|
||||
attempt=$(( $attempt + 1 ))
|
||||
if [ $attempt -gt $max_attempts ]; then
|
||||
docker stop $cid
|
||||
ret=1
|
||||
break
|
||||
fi
|
||||
done
|
||||
exit_status=$(docker inspect -f '{{.State.ExitCode}}' $cid)
|
||||
if [ "$exit_status" == "0" ]; then
|
||||
ret=1
|
||||
fi
|
||||
docker rm -v $cid
|
||||
rm $CID_FILE_DIR/$cid_file
|
||||
fi
|
||||
[ ! -z $old_container_args ] && CONTAINER_ARGS="$old_container_args"
|
||||
set -e
|
||||
return $ret
|
||||
}
|
||||
|
||||
# ct_create_container [name, command]
|
||||
# --------------------
|
||||
# Creates a container using the IMAGE_NAME and CONTAINER_ARGS variables. Also
|
||||
# stores the container id to a cid_file located in the CID_FILE_DIR, and waits
|
||||
# for the creation of the file.
|
||||
# Argument: name - name of cid_file where the container id will be stored
|
||||
# Argument: command - optional command to be executed in the container
|
||||
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
||||
# Uses: $CONTAINER_ARGS - optional arguments passed directly to docker run
|
||||
# Uses: $IMAGE_NAME - name of the image being tested
|
||||
function ct_create_container() {
|
||||
local cid_file="$CID_FILE_DIR/$1" ; shift
|
||||
# create container with a cidfile in a directory for cleanup
|
||||
docker run --cidfile="$cid_file" -d ${CONTAINER_ARGS:-} $IMAGE_NAME "$@"
|
||||
ct_wait_for_cid $cid_file || return 1
|
||||
: "Created container $(cat $cid_file)"
|
||||
}
|
||||
|
||||
# ct_scl_usage_old [name, command, expected]
|
||||
# --------------------
|
||||
# Tests three ways of running the SCL, by looking for an expected string
|
||||
# in the output of the command
|
||||
# Argument: name - name of cid_file where the container id will be stored
|
||||
# Argument: command - executed inside the container
|
||||
# Argument: expected - string that is expected to be in the command output
|
||||
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
||||
# Uses: $IMAGE_NAME - name of the image being tested
|
||||
function ct_scl_usage_old() {
|
||||
local name="$1"
|
||||
local command="$2"
|
||||
local expected="$3"
|
||||
local out=""
|
||||
: " Testing the image SCL enable"
|
||||
out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${command}")
|
||||
if ! echo "${out}" | grep -q "${expected}"; then
|
||||
echo "ERROR[/bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2
|
||||
return 1
|
||||
fi
|
||||
out=$(docker exec $(ct_get_cid $name) /bin/bash -c "${command}" 2>&1)
|
||||
if ! echo "${out}" | grep -q "${expected}"; then
|
||||
echo "ERROR[exec /bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2
|
||||
return 1
|
||||
fi
|
||||
out=$(docker exec $(ct_get_cid $name) /bin/sh -ic "${command}" 2>&1)
|
||||
if ! echo "${out}" | grep -q "${expected}"; then
|
||||
echo "ERROR[exec /bin/sh -ic "${command}"] Expected '${expected}', got '${out}'" >&2
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# ct_doc_content_old [strings]
|
||||
# --------------------
|
||||
# Looks for occurence of stirngs in the documentation files and checks
|
||||
# the format of the files. Files examined: help.1
|
||||
# Argument: strings - strings expected to appear in the documentation
|
||||
# Uses: $IMAGE_NAME - name of the image being tested
|
||||
function ct_doc_content_old() {
|
||||
local tmpdir=$(mktemp -d)
|
||||
local f
|
||||
: " Testing documentation in the container image"
|
||||
# Extract the help files from the container
|
||||
for f in help.1 ; do
|
||||
docker run --rm ${IMAGE_NAME} /bin/bash -c "cat /${f}" >${tmpdir}/$(basename ${f})
|
||||
# Check whether the files contain some important information
|
||||
for term in $@ ; do
|
||||
if ! cat ${tmpdir}/$(basename ${f}) | grep -F -q -e "${term}" ; then
|
||||
echo "ERROR: File /${f} does not include '${term}'." >&2
|
||||
return 1
|
||||
fi
|
||||
done
|
||||
# Check whether the files use the correct format
|
||||
for term in TH PP SH ; do
|
||||
if ! grep -q "^\.${term}" ${tmpdir}/help.1 ; then
|
||||
echo "ERROR: /help.1 is probably not in troff or groff format, since '${term}' is missing." >&2
|
||||
return 1
|
||||
fi
|
||||
done
|
||||
done
|
||||
: " Success!"
|
||||
}
|
||||
|
||||
|
||||
# ct_path_append PATH_VARNAME DIRECTORY
|
||||
# -------------------------------------
|
||||
# Append DIRECTORY to VARIABLE of name PATH_VARNAME, the VARIABLE must consist
|
||||
# of colon-separated list of directories.
|
||||
ct_path_append ()
|
||||
{
|
||||
if eval "test -n \"\${$1-}\""; then
|
||||
eval "$1=\$2:\$$1"
|
||||
else
|
||||
eval "$1=\$2"
|
||||
fi
|
||||
}
|
||||
|
||||
|
||||
# ct_path_foreach PATH ACTION [ARGS ...]
|
||||
# --------------------------------------
|
||||
# For each DIR in PATH execute ACTION (path is colon separated list of
|
||||
# directories). The particular calls to ACTION will look like
|
||||
# '$ ACTION directory [ARGS ...]'
|
||||
ct_path_foreach ()
|
||||
{
|
||||
local dir dirlist action save_IFS
|
||||
save_IFS=$IFS
|
||||
IFS=:
|
||||
dirlist=$1
|
||||
action=$2
|
||||
shift 2
|
||||
for dir in $dirlist; do "$action" "$dir" "$@" ; done
|
||||
IFS=$save_IFS
|
||||
}
|
||||
|
||||
|
||||
# ct_run_test_list
|
||||
# --------------------
|
||||
# Execute the tests specified by TEST_LIST
|
||||
# Uses: $TEST_LIST - list of test names
|
||||
function ct_run_test_list() {
|
||||
for test_case in $TEST_LIST; do
|
||||
: "Running test $test_case"
|
||||
[ -f test/$test_case ] && source test/$test_case
|
||||
[ -f ../test/$test_case ] && source ../test/$test_case
|
||||
$test_case
|
||||
done;
|
||||
}
|
||||
|
||||
# ct_gen_self_signed_cert_pem
|
||||
# ---------------------------
|
||||
# Generates a self-signed PEM certificate pair into specified directory.
|
||||
# Argument: output_dir - output directory path
|
||||
# Argument: base_name - base name of the certificate files
|
||||
# Resulted files will be those:
|
||||
# <output_dir>/<base_name>-cert-selfsigned.pem -- public PEM cert
|
||||
# <output_dir>/<base_name>-key.pem -- PEM private key
|
||||
ct_gen_self_signed_cert_pem() {
|
||||
local output_dir=$1 ; shift
|
||||
local base_name=$1 ; shift
|
||||
mkdir -p ${output_dir}
|
||||
openssl req -newkey rsa:2048 -nodes -keyout ${output_dir}/${base_name}-key.pem -subj '/C=GB/ST=Berkshire/L=Newbury/O=My Server Company' > ${base_name}-req.pem
|
||||
openssl req -new -x509 -nodes -key ${output_dir}/${base_name}-key.pem -batch > ${output_dir}/${base_name}-cert-selfsigned.pem
|
||||
}
|
||||
|
||||
# ct_obtain_input FILE|DIR|URL
|
||||
# --------------------
|
||||
# Either copies a file or a directory to a tmp location for local copies, or
|
||||
# downloads the file from remote location.
|
||||
# Resulted file path is printed, so it can be later used by calling function.
|
||||
# Arguments: input - local file, directory or remote URL
|
||||
function ct_obtain_input() {
|
||||
local input=$1
|
||||
local extension="${input##*.}"
|
||||
|
||||
# Try to use same extension for the temporary file if possible
|
||||
[[ "${extension}" =~ ^[a-z0-9]*$ ]] && extension=".${extension}" || extension=""
|
||||
|
||||
local output=$(mktemp "/var/tmp/test-input-XXXXXX$extension")
|
||||
if [ -f "${input}" ] ; then
|
||||
cp "${input}" "${output}"
|
||||
elif [ -d "${input}" ] ; then
|
||||
rm -f "${output}"
|
||||
cp -r -LH "${input}" "${output}"
|
||||
elif echo "${input}" | grep -qe '^http\(s\)\?://' ; then
|
||||
curl "${input}" > "${output}"
|
||||
else
|
||||
echo "ERROR: file type not known: ${input}" >&2
|
||||
return 1
|
||||
fi
|
||||
echo "${output}"
|
||||
}
|
||||
|
||||
# ct_test_response
|
||||
# ----------------
|
||||
# Perform GET request to the application container, checks output with
|
||||
# a reg-exp and HTTP response code.
|
||||
# Argument: url - request URL path
|
||||
# Argument: expected_code - expected HTTP response code
|
||||
# Argument: body_regexp - PCRE regular expression that must match the response body
|
||||
# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between
|
||||
# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10)
|
||||
ct_test_response() {
|
||||
local url="$1"
|
||||
local expected_code="$2"
|
||||
local body_regexp="$3"
|
||||
local max_attempts=${4:-20}
|
||||
local ignore_error_attempts=${5:-10}
|
||||
|
||||
: " Testing the HTTP(S) response for <${url}>"
|
||||
local sleep_time=3
|
||||
local attempt=1
|
||||
local result=1
|
||||
local status
|
||||
local response_code
|
||||
local response_file=$(mktemp /tmp/ct_test_response_XXXXXX)
|
||||
while [ ${attempt} -le ${max_attempts} ]; do
|
||||
curl --connect-timeout 10 -s -w '%{http_code}' "${url}" >${response_file} && status=0 || status=1
|
||||
if [ ${status} -eq 0 ]; then
|
||||
response_code=$(cat ${response_file} | tail -c 3)
|
||||
if [ "${response_code}" -eq "${expected_code}" ]; then
|
||||
result=0
|
||||
fi
|
||||
cat ${response_file} | grep -qP -e "${body_regexp}" || result=1;
|
||||
# Some services return 40x code until they are ready, so let's give them
|
||||
# some chance and not end with failure right away
|
||||
# Do not wait if we already have expected outcome though
|
||||
if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then
|
||||
break
|
||||
fi
|
||||
fi
|
||||
attempt=$(( ${attempt} + 1 ))
|
||||
sleep ${sleep_time}
|
||||
done
|
||||
rm -f ${response_file}
|
||||
return ${result}
|
||||
}
|
||||
|
||||
# ct_registry_from_os OS
|
||||
# ----------------
|
||||
# Transform operating system string [os] into registry url
|
||||
# Argument: OS - string containing the os version
|
||||
ct_registry_from_os() {
|
||||
local registry=""
|
||||
case $1 in
|
||||
rhel7)
|
||||
registry=registry.access.redhat.com
|
||||
;;
|
||||
*)
|
||||
registry=docker.io
|
||||
;;
|
||||
esac
|
||||
echo "$registry"
|
||||
}
|
||||
|
||||
# ct_assert_cmd_success CMD
|
||||
# ----------------
|
||||
# Evaluates [cmd] and fails if it does not succeed.
|
||||
# Argument: CMD - Command to be run
|
||||
function ct_assert_cmd_success() {
|
||||
echo "Checking '$*' for success ..."
|
||||
if ! eval "$@" &>/dev/null; then
|
||||
echo " FAIL"
|
||||
return 1
|
||||
fi
|
||||
echo " PASS"
|
||||
return 0
|
||||
}
|
||||
|
||||
# ct_assert_cmd_failure CMD
|
||||
# ----------------
|
||||
# Evaluates [cmd] and fails if it succeeds.
|
||||
# Argument: CMD - Command to be run
|
||||
function ct_assert_cmd_failure() {
|
||||
echo "Checking '$*' for failure ..."
|
||||
if eval "$@" &>/dev/null; then
|
||||
echo " FAIL"
|
||||
return 1
|
||||
fi
|
||||
echo " PASS"
|
||||
return 0
|
||||
}
|
||||
|
||||
|
||||
# ct_random_string [LENGTH=10]
|
||||
# ----------------------------
|
||||
# Generate pseudorandom alphanumeric string of LENGTH bytes, the
|
||||
# default length is 10. The string is printed on stdout.
|
||||
ct_random_string()
|
||||
(
|
||||
export LC_ALL=C
|
||||
dd if=/dev/urandom count=1 bs=10k 2>/dev/null \
|
||||
| tr -dc 'a-z0-9' \
|
||||
| fold -w "${1-10}" \
|
||||
| head -n 1
|
||||
)
|
||||
Loading…
Add table
Add a link
Reference in a new issue