From 47a18f26d6f31228ee688bae56ade82b5d794a51 Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Mon, 15 May 2017 20:59:37 +0200 Subject: [PATCH 01/15] Initial commit --- Dockerfile | 71 ++++++ README.md | 121 +++++++++ root/help.1 | 163 ++++++++++++ root/usr/bin/run-httpd | 16 ++ root/usr/libexec/httpd-prepare | 36 +++ .../share/container-scripts/httpd/README.md | 121 +++++++++ .../share/container-scripts/httpd/common.sh | 63 +++++ .../container-scripts/httpd/passwd.template | 15 ++ s2i/bin/assemble | 31 +++ s2i/bin/run | 7 + s2i/bin/usage | 17 ++ test/run | 239 ++++++++++++++++++ test/sample-test-app/index.html | 1 + test/utils.sh | 46 ++++ 14 files changed, 947 insertions(+) create mode 100644 Dockerfile create mode 100644 README.md create mode 100644 root/help.1 create mode 100755 root/usr/bin/run-httpd create mode 100755 root/usr/libexec/httpd-prepare create mode 100644 root/usr/share/container-scripts/httpd/README.md create mode 100644 root/usr/share/container-scripts/httpd/common.sh create mode 100644 root/usr/share/container-scripts/httpd/passwd.template create mode 100755 s2i/bin/assemble create mode 100755 s2i/bin/run create mode 100755 s2i/bin/usage create mode 100755 test/run create mode 100644 test/sample-test-app/index.html create mode 100755 test/utils.sh diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..a7b73ff --- /dev/null +++ b/Dockerfile @@ -0,0 +1,71 @@ +FROM registry.fedoraproject.org/f25/s2i-base + +# Apache HTTP Server image. +# +# Volumes: +# * /var/www - Datastore for httpd +# * /var/log/httpd - Storage for logs when $HTTPD_LOG_TO_VOLUME is set +# Environment: +# * $HTTPD_LOG_TO_VOLUME (optional) - When set, httpd will log into /var/log/httpd + +ENV HTTPD_VERSION=2.4 + +ENV SUMMARY="Platform for running Apache httpd $HTTPD_VERSION or building httpd-based application" \ + DESCRIPTION="Apache httpd $HTTPD_VERSION available as docker container, is a powerful, efficient, \ +and extensible web server. Apache supports a variety of features, many implemented as compiled modules \ +which extend the core functionality. \ +These can range from server-side programming language support to authentication schemes. \ +Virtual hosting allows one Apache installation to serve many different Web sites." + +LABEL summary="$SUMMARY" \ + description="$DESCRIPTION" \ + io.k8s.description="$SUMMARY" \ + io.k8s.display-name="Apache httpd $HTTPD_VERSION" \ + io.openshift.expose-services="8080:http,8443:https" \ + io.openshift.tags="builder,httpd,httpd24" + +ENV NAME=httpd \ + VERSION=0 \ + RELEASE=1 \ + ARCH=x86_64 + +LABEL com.redhat.component="$NAME" \ + name="$FGC/$NAME" \ + version="$VERSION" \ + release="$RELEASE.$DISTTAG" \ + architecture="$ARCH" \ + usage="docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z 25/httpd" \ + help="help.1" + +EXPOSE 80 +EXPOSE 443 +EXPOSE 8080 +EXPOSE 8443 + +RUN dnf install -y yum-utils gettext hostname && \ + INSTALL_PKGS="nss_wrapper bind-utils httpd mod_ssl" && \ + dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \ + rpm -V $INSTALL_PKGS && \ + dnf clean all + +ENV HTTPD_CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/httpd/ \ + HTTPD_APP_ROOT=/opt/app-root \ + HTTPD_CONFIGURATION_PATH=${HTTPD_APP_ROOT}/etc/httpd.d \ + HTTPD_MAIN_CONF_PATH=/etc/httpd/conf \ + HTTPD_MAIN_CONF_D_PATH=/etc/httpd/conf.d \ + HTTPD_VAR_RUN=/var/run/httpd \ + HTTPD_DATA_PATH=/var/www \ + HTTPD_DATA_ORIG_PATH=/var/www \ + HTTPD_LOG_PATH=/var/log/httpd + +COPY ./s2i/bin/ $STI_SCRIPTS_PATH +COPY ./root / + +RUN /usr/libexec/httpd-prepare + +USER 1001 + +VOLUME ["${HTTPD_DATA_PATH}"] +VOLUME ["${HTTPD_LOG_PATH}"] + +CMD ["/usr/bin/run-httpd"] diff --git a/README.md b/README.md new file mode 100644 index 0000000..eb97041 --- /dev/null +++ b/README.md @@ -0,0 +1,121 @@ +Apache HTTP Server 2.4 +====================== + +This container image includes Apache HTTP Server 2.4 for OpenShift and general usage. +Users can choose between RHEL, CentOS, and Fedora based images. +The RHEL image is available in the [Red Hat Registry](https://access.redhat.com/containers) +as registry.access.redhat.com/rhscl/httpd-24-rhel7. +The CentOS image is then available on [Docker Hub](https://hub.docker.com/r/centos/httpd-24-centos7/) +as centos/httpd-24-centos7. + + +DESCRIPTION +----------- + +Apache HTTP Server 2.4 available as docker container, is a powerful, efficient, +and extensible web server. Apache supports a variety of features, many implemented as compiled modules +which extend the core functionality. +These can range from server-side programming language support to authentication schemes. +Virtual hosting allows one Apache installation to serve many different Web sites." + + +USAGE +----- + +For this, we will assume that you are using the `rhscl/httpd-24-rhel7` image. +The image can be used as a base image for other applications based on Apache HTTP web server. + +An example of the data on the host for both the examples above, that will be served by +Apache HTTP web server: + +``` +$ ls -lZ /wwwdata/html +-rw-r--r--. 1 1001 1001 54321 Jan 01 12:34 index.html +-rw-r--r--. 1 1001 1001 5678 Jan 01 12:34 page.html +``` + +If you want to run the image and mount the static pages available in `/wwwdata` on the host +as a docker volume, execute the following command: + +``` +$ docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z rhscl/httpd-24-rhel7 +``` + +This will create a container named `httpd` running Apache HTTP Server, serving data from +`/wwwdata` directory. Port 8080 will be exposed and mapped to the host. + +If you want to create a new Docker layered image, use [Source-to-Image](https://github.com/openshift/source-to-image), a tool for building/building artifacts from source and injecting into docker images. To create a new Docker image named `httpd-app` using Source-to-Image, while using data available in `/wwwdata` on the host, execute the following command: + +``` +$ s2i build file:///wwwdata/html rhscl/httpd-24-rhel7 httpd-app +``` + +To run such a new image, execute the following command: + +``` +$ docker run -d --name httpd -p 8080:8080 httpd-app +``` + + +CONFIGURATION +------------- + +The Apache HTTP Server container image supports the following configuration variable, which can be set by using the `-e` option with the docker run command: + +| Variable name | Description | +| :---------------------- | ----------------------------------------- | +| `HTTPD_LOG_TO_VOLUME` | By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When `HTTPD_LOG_TO_VOLUME` is set, httpd logs into `/var/log/httpd24`, which can be mounted to host system using the Docker volumes. This option is only allowed when container is run as UID 0. | + + +If you want to run the image and mount the log files into `/wwwlogs` on the host +as a docker volume, execute the following command: + +``` +$ docker run -d -u 0 -e HTTPD_LOG_TO_VOLUME=1 --name httpd -v /wwwlogs:/var/log/httpd24:Z rhscl/httpd-24-rhel7 +``` + + +VOLUMES +------- + +You can also set the following mount points by passing the `-v /host:/container` flag to Docker. + +| Volume mount point | Description | +| :----------------------- | ---------------------------------------------------------------------- | +| `/var/www` | Apache HTTP Server data directory | +| `/var/log/httpd24` | Apache HTTP Server log directory (available only when running as root, path `/var/log/httpd` is used in case of Fedora based image) | + +**Notice: When mouting a directory from the host into the container, ensure that the mounted +directory has the appropriate permissions and that the owner and group of the directory +matches the user UID or name which is running inside the container.** + + +DEFAULT USER +------------ + +By default, Apache HTTP Server container runs as UID 1001. That means the volume mounted directories for the files (if mounted using `-v` option) need to be prepared properly, so the UID 1001 can read them. + +To run the container as a different UID, use `-u` option. For example if you want to run the container as UID 1234, execute the following command: + +``` +docker run -d -u 1234 rhscl/httpd-24-rhel7 +``` + +To log into a volume mounted directory, the container needs to be run as UID 0 (see above). + + + +TROUBLESHOOTING +--------------- +The httpd deamon in the container logs to the standard output by default, so the log is available in the container log. The log can be examined by running: + + docker logs + + +SEE ALSO +-------- +Dockerfile and other sources for this container image are available on +https://github.com/sclorg/httpd-container. +In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile +for RHEL is called Dockerfile.rhel7. + diff --git a/root/help.1 b/root/help.1 new file mode 100644 index 0000000..73f69f2 --- /dev/null +++ b/root/help.1 @@ -0,0 +1,163 @@ +.TH "HTTPD-24-RHEL7" "1" " Container Image Pages" "Red Hat" "April 07, 2017" "" + + +.SH Apache HTTP Server 2.4 +.PP +This container image includes Apache HTTP Server 2.4 for OpenShift and general usage. +Users can choose between RHEL, CentOS, and Fedora based images. +The RHEL image is available in the +\[la]https://access.redhat.com/containers\[ra] +as registry.access.redhat.com/rhscl/httpd\-24\-rhel7. +The CentOS image is then available on +\[la]https://hub.docker.com/r/centos/httpd-24-centos7/\[ra] +as centos/httpd\-24\-centos7. + +.SH DESCRIPTION +.PP +Apache HTTP Server 2.4 available as docker container, is a powerful, efficient, +and extensible web server. Apache supports a variety of features, many implemented as compiled modules +which extend the core functionality. +These can range from server\-side programming language support to authentication schemes. +Virtual hosting allows one Apache installation to serve many different Web sites." + +.SH USAGE +.PP +For this, we will assume that you are using the \fB\fCrhscl/httpd\-24\-rhel7\fR image. +The image can be used as a base image for other applications based on Apache HTTP web server. + +.PP +An example of the data on the host for both the examples above, that will be served by +Apache HTTP web server: + +.PP +.RS + +.nf +$ ls \-lZ /wwwdata/html +\-rw\-r\-\-r\-\-. 1 1001 1001 54321 Jan 01 12:34 index.html +\-rw\-r\-\-r\-\-. 1 1001 1001 5678 Jan 01 12:34 page.html + +.fi +.RE + +.PP +If you want to run the image and mount the static pages available in \fB\fC/wwwdata\fR on the host +as a docker volume, execute the following command: + +.PP +.RS + +.nf +$ docker run \-d \-\-name httpd \-p 8080:8080 \-v /wwwdata:/var/www:Z rhscl/httpd\-24\-rhel7 + +.fi +.RE + +.PP +This will create a container named \fB\fChttpd\fR running Apache HTTP Server, serving data from +\fB\fC/wwwdata\fR directory. Port 8080 will be exposed and mapped to the host. + +.PP +If you want to create a new Docker layered image, use +\[la]https://github.com/openshift/source-to-image\[ra], a tool for building/building artifacts from source and injecting into docker images. To create a new Docker image named \fB\fChttpd\-app\fR using Source\-to\-Image, while using data available in \fB\fC/wwwdata\fR on the host, execute the following command: + +.PP +.RS + +.nf +$ s2i build file:///wwwdata/html rhscl/httpd\-24\-rhel7 httpd\-app + +.fi +.RE + +.PP +To run such a new image, execute the following command: + +.PP +.RS + +.nf +$ docker run \-d \-\-name httpd \-p 8080:8080 httpd\-app + +.fi +.RE + +.SH CONFIGURATION +.PP +The Apache HTTP Server container image supports the following configuration variable, which can be set by using the \fB\fC\-e\fR option with the docker run command: +.TS +allbox; +Variable name Description +\fB\fCHTTPD\_LOG\_TO\_VOLUME\fR By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When \fB\fCHTTPD\_LOG\_TO\_VOLUME\fR is set, httpd logs into \fB\fC/var/log/httpd24\fR, which can be mounted to host system using the Docker volumes. This option is only allowed when container is run as UID 0. + +.TE + +.PP +If you want to run the image and mount the log files into \fB\fC/wwwlogs\fR on the host +as a docker volume, execute the following command: + +.PP +.RS + +.nf +$ docker run \-d \-u 0 \-e HTTPD\_LOG\_TO\_VOLUME=1 \-\-name httpd \-v /wwwlogs:/var/log/httpd24:Z rhscl/httpd\-24\-rhel7 + +.fi +.RE + +.SH VOLUMES +.PP +You can also set the following mount points by passing the \fB\fC\-v /host:/container\fR flag to Docker. +.TS +allbox; +Volume mount point Description +\fB\fC/var/www\fR Apache HTTP Server data directory + +\fB\fC/var/log/httpd24\fR Apache HTTP Server log directory (available only when running as root, path \fB\fC/var/log/httpd\fR is used in case of Fedora based image) + +.TE + +.PP +\fBNotice: When mouting a directory from the host into the container, ensure that the mounted +directory has the appropriate permissions and that the owner and group of the directory +matches the user UID or name which is running inside the container.\fP + +.SH DEFAULT USER +.PP +By default, Apache HTTP Server container runs as UID 1001. That means the volume mounted directories for the files (if mounted using \fB\fC\-v\fR option) need to be prepared properly, so the UID 1001 can read them. + +.PP +To run the container as a different UID, use \fB\fC\-u\fR option. For example if you want to run the container as UID 1234, execute the following command: + +.PP +.RS + +.nf +docker run \-d \-u 1234 rhscl/httpd\-24\-rhel7 + +.fi +.RE + +.PP +To log into a volume mounted directory, the container needs to be run as UID 0 (see above). + +.SH TROUBLESHOOTING +.PP +The httpd deamon in the container logs to the standard output by default, so the log is available in the container log. The log can be examined by running: + +.PP +.RS + +.nf +docker logs + +.fi +.RE + +.SH SEE ALSO +.PP +Dockerfile and other sources for this container image are available on + +\[la]https://github.com/sclorg/httpd-container\[ra]. +In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile +for RHEL is called Dockerfile.rhel7. diff --git a/root/usr/bin/run-httpd b/root/usr/bin/run-httpd new file mode 100755 index 0000000..ad38ce0 --- /dev/null +++ b/root/usr/bin/run-httpd @@ -0,0 +1,16 @@ +#!/bin/bash + +set -eu + +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +# Check whether we run as s2i +if ! [ -v HTTPD_RUN_BY_S2I ] && runs_privileged ; then + config_privileged +else + # We run as non-root or as s2i + config_non_privileged + generate_container_user +fi + +exec httpd -D FOREGROUND $@ diff --git a/root/usr/libexec/httpd-prepare b/root/usr/libexec/httpd-prepare new file mode 100755 index 0000000..6ca6309 --- /dev/null +++ b/root/usr/libexec/httpd-prepare @@ -0,0 +1,36 @@ +#!/bin/bash + +set -e + +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +# compatibility symlinks so we hide SCL paths +if [ -v HTTPD_SCL ] ; then + # /opt/rh/httpd24/root/etc/httpd will be symlink to /etc/httpd + mv /opt/rh/httpd24/root/etc/httpd /etc/httpd + ln -s /etc/httpd /opt/rh/httpd24/root/etc/httpd + + # /opt/rh/httpd24/root/var/run/httpd will be symlink to /var/run/httpd + mv /opt/rh/httpd24/root/var/run/httpd /var/run/httpd + ln -s /var/run/httpd /opt/rh/httpd24/root/var/run/httpd + + # /opt/rh/httpd24/root/var/www will be symlink to /var/www + rm -rf /var/www + mv /opt/rh/httpd24/root/var/www /var/www + ln -s /var/www /opt/rh/httpd24/root/var/www +fi + +mkdir -p ${HTTPD_CONFIGURATION_PATH} +chmod -R a+rwx ${HTTPD_MAIN_CONF_PATH} +chmod -R a+rwx ${HTTPD_MAIN_CONF_D_PATH} +chmod -R a+r /etc/pki/tls/certs/localhost.crt +chmod -R a+r /etc/pki/tls/private/localhost.key +mkdir -p ${HTTPD_APP_ROOT}/etc +chmod -R a+rwx ${HTTPD_APP_ROOT}/etc +chmod -R a+rwx ${HTTPD_VAR_RUN} +chown -R 1001:0 ${HTTPD_APP_ROOT} +chown -R 1001:0 ${HTTPD_DATA_PATH} +chown -R 1001:0 ${HTTPD_LOG_PATH} + +config_general + diff --git a/root/usr/share/container-scripts/httpd/README.md b/root/usr/share/container-scripts/httpd/README.md new file mode 100644 index 0000000..eb97041 --- /dev/null +++ b/root/usr/share/container-scripts/httpd/README.md @@ -0,0 +1,121 @@ +Apache HTTP Server 2.4 +====================== + +This container image includes Apache HTTP Server 2.4 for OpenShift and general usage. +Users can choose between RHEL, CentOS, and Fedora based images. +The RHEL image is available in the [Red Hat Registry](https://access.redhat.com/containers) +as registry.access.redhat.com/rhscl/httpd-24-rhel7. +The CentOS image is then available on [Docker Hub](https://hub.docker.com/r/centos/httpd-24-centos7/) +as centos/httpd-24-centos7. + + +DESCRIPTION +----------- + +Apache HTTP Server 2.4 available as docker container, is a powerful, efficient, +and extensible web server. Apache supports a variety of features, many implemented as compiled modules +which extend the core functionality. +These can range from server-side programming language support to authentication schemes. +Virtual hosting allows one Apache installation to serve many different Web sites." + + +USAGE +----- + +For this, we will assume that you are using the `rhscl/httpd-24-rhel7` image. +The image can be used as a base image for other applications based on Apache HTTP web server. + +An example of the data on the host for both the examples above, that will be served by +Apache HTTP web server: + +``` +$ ls -lZ /wwwdata/html +-rw-r--r--. 1 1001 1001 54321 Jan 01 12:34 index.html +-rw-r--r--. 1 1001 1001 5678 Jan 01 12:34 page.html +``` + +If you want to run the image and mount the static pages available in `/wwwdata` on the host +as a docker volume, execute the following command: + +``` +$ docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z rhscl/httpd-24-rhel7 +``` + +This will create a container named `httpd` running Apache HTTP Server, serving data from +`/wwwdata` directory. Port 8080 will be exposed and mapped to the host. + +If you want to create a new Docker layered image, use [Source-to-Image](https://github.com/openshift/source-to-image), a tool for building/building artifacts from source and injecting into docker images. To create a new Docker image named `httpd-app` using Source-to-Image, while using data available in `/wwwdata` on the host, execute the following command: + +``` +$ s2i build file:///wwwdata/html rhscl/httpd-24-rhel7 httpd-app +``` + +To run such a new image, execute the following command: + +``` +$ docker run -d --name httpd -p 8080:8080 httpd-app +``` + + +CONFIGURATION +------------- + +The Apache HTTP Server container image supports the following configuration variable, which can be set by using the `-e` option with the docker run command: + +| Variable name | Description | +| :---------------------- | ----------------------------------------- | +| `HTTPD_LOG_TO_VOLUME` | By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When `HTTPD_LOG_TO_VOLUME` is set, httpd logs into `/var/log/httpd24`, which can be mounted to host system using the Docker volumes. This option is only allowed when container is run as UID 0. | + + +If you want to run the image and mount the log files into `/wwwlogs` on the host +as a docker volume, execute the following command: + +``` +$ docker run -d -u 0 -e HTTPD_LOG_TO_VOLUME=1 --name httpd -v /wwwlogs:/var/log/httpd24:Z rhscl/httpd-24-rhel7 +``` + + +VOLUMES +------- + +You can also set the following mount points by passing the `-v /host:/container` flag to Docker. + +| Volume mount point | Description | +| :----------------------- | ---------------------------------------------------------------------- | +| `/var/www` | Apache HTTP Server data directory | +| `/var/log/httpd24` | Apache HTTP Server log directory (available only when running as root, path `/var/log/httpd` is used in case of Fedora based image) | + +**Notice: When mouting a directory from the host into the container, ensure that the mounted +directory has the appropriate permissions and that the owner and group of the directory +matches the user UID or name which is running inside the container.** + + +DEFAULT USER +------------ + +By default, Apache HTTP Server container runs as UID 1001. That means the volume mounted directories for the files (if mounted using `-v` option) need to be prepared properly, so the UID 1001 can read them. + +To run the container as a different UID, use `-u` option. For example if you want to run the container as UID 1234, execute the following command: + +``` +docker run -d -u 1234 rhscl/httpd-24-rhel7 +``` + +To log into a volume mounted directory, the container needs to be run as UID 0 (see above). + + + +TROUBLESHOOTING +--------------- +The httpd deamon in the container logs to the standard output by default, so the log is available in the container log. The log can be examined by running: + + docker logs + + +SEE ALSO +-------- +Dockerfile and other sources for this container image are available on +https://github.com/sclorg/httpd-container. +In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile +for RHEL is called Dockerfile.rhel7. + diff --git a/root/usr/share/container-scripts/httpd/common.sh b/root/usr/share/container-scripts/httpd/common.sh new file mode 100644 index 0000000..c949287 --- /dev/null +++ b/root/usr/share/container-scripts/httpd/common.sh @@ -0,0 +1,63 @@ +# Set of functions used in other scripts + +config_general() { + sed -i -e 's/^Listen 80/Listen 0.0.0.0:8080/' ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \ + sed -i -e '151s%AllowOverride None%AllowOverride All%' ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \ + sed -i -e 's/^Listen 443/Listen 0.0.0.0:8443/' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf +} + +config_log_to_stdout() { + sed -ri " s!^(\s*CustomLog)\s+\S+!\1 |/usr/bin/cat!g; s!^(\s*ErrorLog)\s+\S+!\1 |/usr/bin/cat!g;" ${HTTPD_MAIN_CONF_PATH}/httpd.conf + sed -ri " s!^(\s*CustomLog)\s+\S+!\1 |/usr/bin/cat!g; s!^(\s*TransferLog)\s+\S+!\1 |/usr/bin/cat!g; s!^(\s*ErrorLog)\s+\S+!\1 |/usr/bin/cat!g;" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf +} + +runs_privileged() { + test "$(id -u)" == "0" + return $? +} + +config_privileged() { + # Change the s2i permissions back to the normal ones + chmod 644 ${HTTPD_MAIN_CONF_PATH}/* && \ + chmod 755 ${HTTPD_MAIN_CONF_PATH} && \ + chmod 644 ${HTTPD_MAIN_CONF_D_PATH}/* && \ + chmod 755 ${HTTPD_MAIN_CONF_D_PATH} && \ + chmod 600 /etc/pki/tls/certs/localhost.crt && \ + chmod 600 /etc/pki/tls/private/localhost.key && \ + chmod 710 ${HTTPD_VAR_RUN} + + if ! [ -v HTTPD_LOG_TO_VOLUME ] ; then + config_log_to_stdout + fi +} + +config_s2i() { + sed -i -e "s%^DocumentRoot \"${HTTPD_DATA_ORIG_PATH}/html\"%DocumentRoot \"${HTTPD_APP_ROOT}/src\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf + sed -i -e "s%^> ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \ + head -n151 ${HTTPD_MAIN_CONF_PATH}/httpd.conf | tail -n1 | grep "AllowOverride All" || exit +} + +config_non_privileged() { + sed -i -e "s/^User apache/User default/" ${HTTPD_MAIN_CONF_PATH}/httpd.conf + sed -i -e "s/^Group apache/Group root/" ${HTTPD_MAIN_CONF_PATH}/httpd.conf + config_log_to_stdout + if [ -v HTTPD_LOG_TO_VOLUME ] ; then + echo "Error: Option HTTPD_LOG_TO_VOLUME is only valid for privileged runs (as UID 0)." + return 1 + fi +} + +# Set current user in nss_wrapper +generate_container_user() { + local passwd_output_dir="${HTTPD_APP_ROOT}/etc" + + export USER_ID=$(id -u) + export GROUP_ID=$(id -g) + envsubst < ${HTTPD_CONTAINER_SCRIPTS_PATH}/passwd.template > ${passwd_output_dir}/passwd + export LD_PRELOAD=libnss_wrapper.so + export NSS_WRAPPER_PASSWD=${passwd_output_dir}/passwd + export NSS_WRAPPER_GROUP=/etc/group +} + diff --git a/root/usr/share/container-scripts/httpd/passwd.template b/root/usr/share/container-scripts/httpd/passwd.template new file mode 100644 index 0000000..7ad0b78 --- /dev/null +++ b/root/usr/share/container-scripts/httpd/passwd.template @@ -0,0 +1,15 @@ +root:x:0:0:root:/root:/bin/bash +bin:x:1:1:bin:/bin:/sbin/nologin +daemon:x:2:2:daemon:/sbin:/sbin/nologin +adm:x:3:4:adm:/var/adm:/sbin/nologin +lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin +sync:x:5:0:sync:/sbin:/bin/sync +shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown +halt:x:7:0:halt:/sbin:/sbin/halt +mail:x:8:12:mail:/var/spool/mail:/sbin/nologin +operator:x:11:0:operator:/root:/sbin/nologin +games:x:12:100:games:/usr/games:/sbin/nologin +ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin +nobody:x:99:99:Nobody:/:/sbin/nologin +default:x:${USER_ID}:${GROUP_ID}:Default Application User:${HOME}:/sbin/nologin +apache:x:48:48:Apache:/usr/share/httpd:/sbin/nologin diff --git a/s2i/bin/assemble b/s2i/bin/assemble new file mode 100755 index 0000000..62ecc31 --- /dev/null +++ b/s2i/bin/assemble @@ -0,0 +1,31 @@ +#!/bin/bash + +set -e + +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +echo "---> Enabling s2i support in httpd24 image" + +config_s2i + +echo "---> Installing application source" +cp -Rf /tmp/src/. ./ + +if [ -d ./httpd-cfg ]; then + echo "---> Copying httpd configuration files..." + if [ "$(ls -A ./httpd-cfg/*.conf)" ]; then + cp -v ./httpd-cfg/*.conf "${HTTPD_CONFIGURATION_PATH}" + rm -rf ./httpd-cfg + fi +else + if [ -d ./cfg ]; then + echo "---> Copying httpd configuration files from deprecated './cfg' directory, use './httpd-cfg' instead..." + if [ "$(ls -A ./cfg/*.conf)" ]; then + cp -v ./cfg/*.conf "${HTTPD_CONFIGURATION_PATH}" + rm -rf ./cfg + fi + fi +fi + +# Fix source directory permissions +fix-permissions ./ diff --git a/s2i/bin/run b/s2i/bin/run new file mode 100755 index 0000000..2748f34 --- /dev/null +++ b/s2i/bin/run @@ -0,0 +1,7 @@ +#!/bin/bash + +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +export HTTPD_RUN_BY_S2I=1 + +run-httpd $@ diff --git a/s2i/bin/usage b/s2i/bin/usage new file mode 100755 index 0000000..9ace19c --- /dev/null +++ b/s2i/bin/usage @@ -0,0 +1,17 @@ +#!/bin/sh + +DISTRO=`cat /etc/*-release | grep ^ID= | grep -Po '".*?"' | tr -d '"'` +NAMESPACE=centos +[[ $DISTRO =~ rhel* ]] && NAMESPACE=rhscl + +cat < output" + if ! run "fgrep -e 'Test Page for the Apache HTTP Server on' output" ; then + cat output + return 1 + fi +} + +function run_default_page_test() { + # Check default page + run "create_container test_default_page" + sleep 2 + cip=$(get_container_ip 'test_default_page') + _check_test_page ${cip} +} + +function run_as_root_test() { + # Try running as root + DOCKER_ARGS="-u 0" + run "create_container test_run_as_root" + DOCKER_ARGS= + sleep 2 + cip=$(get_container_ip 'test_run_as_root') + _check_test_page ${cip} +} + + +function run_log_to_volume_test() { + _run_invalid_log_volume_test + if _container_is_scl ; then + _run_log_to_volume_test old /var/log/httpd24 + else + _run_log_to_volume_test new /var/log/httpd + fi +} + +function _run_log_to_volume_test() { + # Check the HTTP_LOG_TO_VOLUME env variable + local variant=${1} + local volume_dir=${2} + local logs_dir=$(mktemp -d /tmp/httpd-test-volume-XXXXXX) + run "ls -d ${logs_dir} || mkdir ${logs_dir}" 0 'Create log directory' + run "chown -R 1001:1001 ${logs_dir}" + run "chcon -Rvt svirt_sandbox_file_t ${logs_dir}" 0 'Change SELinux context on the log dir' + DOCKER_ARGS="-e HTTPD_LOG_TO_VOLUME=1 -u 0 -v ${logs_dir}:${volume_dir}" + run "create_container test_log_dir_${variant}" + DOCKER_ARGS= + sleep 2 + cip=$(get_container_ip "test_log_dir_${variant}") + run "curl ${cip}:8080 > /dev/null" + ls ${logs_dir} > output + run "grep -e '^access_log$' output" 0 "Checking that file access_log exists" + run "grep -e '^error_log$' output" 0 "Checking that file error_log exists" + run "grep -e '^ssl_access_log$' output" 0 "Checking that file ssl_access_log exists" + run "grep -e '^ssl_error_log$' output" 0 "Checking that file ssl_error_log exists" + run "grep -e '^ssl_request_log$' output" 0 "Checking that file ssl_request_log exists" +} + +function _run_invalid_log_volume_test() { + # Check wrong usage of the HTTP_LOG_TO_VOLUME env variable + DOCKER_ARGS="-e HTTPD_LOG_TO_VOLUME=1 -u 1001" + run "create_container test_log_dir_fail" + DOCKER_ARGS= + sleep 2 + cid=$(get_cid "test_log_dir_fail") + exit_status=$(docker inspect -f '{{.State.ExitCode}}' ${cid}) + run "test $exit_status == 1" 0 "Checking that setting HTTPD_LOG_TO_VOLUME is not allowed if UID is not 0" +} + + +function run_data_volume_test() { + if _container_is_scl ; then + _run_data_volume_test old /opt/rh/httpd24/root/var/www + fi + _run_data_volume_test new /var/www +} + +function _run_data_volume_test() { + local variant=${1} + local volume_dir=${2} + # Test that docker volume for DocumentRoot works + datadir=$(mktemp -d /tmp/httpd-test-data-XXXXXX) + run "mkdir -p ${datadir}/html" 0 'Create document root' + run "echo hello > ${datadir}/html/index.html" + run "chown -R 1001:1001 ${datadir}" + run "chcon -Rvt svirt_sandbox_file_t ${datadir}/" 0 'Change SELinux context on the document root' + DOCKER_ARGS="-v ${datadir}:${volume_dir}" + run "create_container test_doc_root_${variant}" + DOCKER_ARGS= + sleep 2 + cip=$(get_container_ip "test_doc_root_${variant}") + run "curl ${cip}:8080 > output" + run "grep -e '^hello$' output" +} + + +function run_s2i_test() { + # Test s2i use case + # Since we built the candidate image locally, we don't want S2I attempt to pull + # it from Docker hub + s2i_args="--force-pull=false" + run "s2i usage ${s2i_args} ${IMAGE_NAME}" 0 "Testing 's2i usage'" + run "s2i build ${s2i_args} file://${test_dir}/sample-test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp" 0 "Testing 's2i build'" + DOCKER_ARGS='-u 1000' + create_container testing-app-s2i ${IMAGE_NAME}-testapp + DOCKER_ARGS= + sleep 5 + cip=$(get_container_ip 'testing-app-s2i') + run "curl ${cip}:8080 > output_s2i" + run "fgrep -e 'This is a sample s2i application with static content.' output_s2i" + # 0 "Checking page served by s2i feature" + sleep 2 +} + + +function run_all_tests() { + for test_case in $TEST_LIST; do + : "Running test $test_case" + $test_case + done; +} + + +function cleanup() { + for cidfile in $CIDFILE_DIR/* ; do + CONTAINER=$(cat $cidfile) + + echo "Stopping and removing container $CONTAINER..." + docker stop $CONTAINER + exit_status=$(docker inspect -f '{{.State.ExitCode}}' $CONTAINER) + if [ "$exit_status" != "0" ]; then + echo "Dumping logs for $CONTAINER" + docker logs $CONTAINER + fi + docker rm $CONTAINER + rm $cidfile + echo "Done." + done + if [ "$overall" -eq 0 ] ; then + print_result "pass" "All tests passed." + else + print_result "fail" "Tests failed." + fi + rmdir $CIDFILE_DIR + rm -Rf "$working_dir" + return "$overall" +} +trap cleanup EXIT + + +working_dir=`mktemp -d` +pushd $working_dir > /dev/null || exit 1 + +CIDFILE_DIR=`pwd`/cid_files +mkdir "$CIDFILE_DIR" + +overall=0 + +run "docker inspect $IMAGE_NAME >/dev/null || docker pull $IMAGE_NAME" 0 + + +TEST_LIST="\ +run_default_page_test +run_as_root_test +run_log_to_volume_test +run_data_volume_test +run_s2i_test" + +test $# -eq 1 -a "${1-}" == --list && echo "$TEST_LIST" && exit 0 + +TEST_LIST=${@:-$TEST_LIST} run_all_tests + +popd > /dev/null + +exit "$overall" diff --git a/test/sample-test-app/index.html b/test/sample-test-app/index.html new file mode 100644 index 0000000..38f417d --- /dev/null +++ b/test/sample-test-app/index.html @@ -0,0 +1 @@ +This is a sample s2i application with static content. diff --git a/test/utils.sh b/test/utils.sh new file mode 100755 index 0000000..525c3e2 --- /dev/null +++ b/test/utils.sh @@ -0,0 +1,46 @@ +#!/usr/bin/env bash + +function print_result { + local RESET='\e[0m' + local RED='\e[0;31m' + local GREEN='\e[0;32m' + local YELLOW='\e[1;33m' + local PASS="${RESET}${GREEN}[PASS]" + local FAIL="${RESET}${RED}[FAIL]" + local WORKING="${RESET}${YELLOW}[....]" + local STATUS="$1" + shift + + if [ "${STATUS}" = pass ]; then + echo -en "${PASS}" + elif [ "${STATUS}" = fail ]; then + echo -en "${FAIL}" + elif [ "${STATUS}" = working ]; then + echo -en "${WORKING}" + else + return + fi + + echo -en " ${@}${RESET}" + echo +} + +function get_status { + if [ "$1" = "$2" ]; then + echo pass + else + echo fail + fi +} + +function run_command { + local cmd="$1" + local expected="${2:-0}" + local msg="${3:-Running command '$cmd'}" + print_result working "$msg" + eval $cmd + local res="$?" + status=`get_status "$res" "$expected"` + print_result "$status" "$msg" + return "$res" +} From 9f39c9422ba82507a65753f145baaa2da4e6d4d1 Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Tue, 16 May 2017 12:02:20 +0200 Subject: [PATCH 02/15] Change version in FROM to 26 --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index a7b73ff..d4c0173 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM registry.fedoraproject.org/f25/s2i-base +FROM registry.fedoraproject.org/f26/s2i-base # Apache HTTP Server image. # @@ -34,7 +34,7 @@ LABEL com.redhat.component="$NAME" \ version="$VERSION" \ release="$RELEASE.$DISTTAG" \ architecture="$ARCH" \ - usage="docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z 25/httpd" \ + usage="docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z 26/httpd" \ help="help.1" EXPOSE 80 From b7a845e23fc0e3c91a202f693c398f852e213b47 Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Tue, 16 May 2017 14:59:07 +0200 Subject: [PATCH 03/15] Change version in FROM to 27 --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index d4c0173..e912d17 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM registry.fedoraproject.org/f26/s2i-base +FROM registry.fedoraproject.org/f27/s2i-base # Apache HTTP Server image. # @@ -34,7 +34,7 @@ LABEL com.redhat.component="$NAME" \ version="$VERSION" \ release="$RELEASE.$DISTTAG" \ architecture="$ARCH" \ - usage="docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z 26/httpd" \ + usage="docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z 27/httpd" \ help="help.1" EXPOSE 80 From 8f6c4b381a428faf296f5e262a580fd30a3c72d0 Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Mon, 5 Mar 2018 07:22:37 +0100 Subject: [PATCH 04/15] A quick fix to make the container build-able -- do not change perms on unexisting localhost.key --- root/usr/libexec/httpd-prepare | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/root/usr/libexec/httpd-prepare b/root/usr/libexec/httpd-prepare index 6ca6309..97cdcde 100755 --- a/root/usr/libexec/httpd-prepare +++ b/root/usr/libexec/httpd-prepare @@ -23,8 +23,8 @@ fi mkdir -p ${HTTPD_CONFIGURATION_PATH} chmod -R a+rwx ${HTTPD_MAIN_CONF_PATH} chmod -R a+rwx ${HTTPD_MAIN_CONF_D_PATH} -chmod -R a+r /etc/pki/tls/certs/localhost.crt -chmod -R a+r /etc/pki/tls/private/localhost.key +#chmod -R a+r /etc/pki/tls/certs/localhost.crt +#chmod -R a+r /etc/pki/tls/private/localhost.key mkdir -p ${HTTPD_APP_ROOT}/etc chmod -R a+rwx ${HTTPD_APP_ROOT}/etc chmod -R a+rwx ${HTTPD_VAR_RUN} From d4ae4e5503638751858697031288913e237457a7 Mon Sep 17 00:00:00 2001 From: Mohan Boddu Date: Thu, 15 Mar 2018 16:12:45 +0000 Subject: [PATCH 05/15] "Bump RELEASE for automatic rebuild" --- Dockerfile | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/Dockerfile b/Dockerfile index e912d17..930c35a 100644 --- a/Dockerfile +++ b/Dockerfile @@ -24,10 +24,7 @@ LABEL summary="$SUMMARY" \ io.openshift.expose-services="8080:http,8443:https" \ io.openshift.tags="builder,httpd,httpd24" -ENV NAME=httpd \ - VERSION=0 \ - RELEASE=1 \ - ARCH=x86_64 +ENV NAME=httpd VERSION=0 RELEASE=2 ARCH=x86_64 LABEL com.redhat.component="$NAME" \ name="$FGC/$NAME" \ From 1503c46900cac28e2568039de4e84e6d941c6151 Mon Sep 17 00:00:00 2001 From: Mohan Boddu Date: Thu, 29 Mar 2018 15:33:14 +0000 Subject: [PATCH 06/15] "Bump RELEASE for automatic rebuild" --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 930c35a..924bc84 100644 --- a/Dockerfile +++ b/Dockerfile @@ -24,7 +24,7 @@ LABEL summary="$SUMMARY" \ io.openshift.expose-services="8080:http,8443:https" \ io.openshift.tags="builder,httpd,httpd24" -ENV NAME=httpd VERSION=0 RELEASE=2 ARCH=x86_64 +ENV NAME=httpd VERSION=0 RELEASE=3 ARCH=x86_64 LABEL com.redhat.component="$NAME" \ name="$FGC/$NAME" \ From 080604cf1266d1572c855add064a86e4be886fa5 Mon Sep 17 00:00:00 2001 From: Mohan Boddu Date: Fri, 20 Apr 2018 15:07:00 +0000 Subject: [PATCH 07/15] "Bump RELEASE for automatic rebuild" --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 924bc84..637385c 100644 --- a/Dockerfile +++ b/Dockerfile @@ -24,7 +24,7 @@ LABEL summary="$SUMMARY" \ io.openshift.expose-services="8080:http,8443:https" \ io.openshift.tags="builder,httpd,httpd24" -ENV NAME=httpd VERSION=0 RELEASE=3 ARCH=x86_64 +ENV NAME=httpd VERSION=0 RELEASE=4 ARCH=x86_64 LABEL com.redhat.component="$NAME" \ name="$FGC/$NAME" \ From 5b536f00b54a0735b2aedaf16b00e14cf36117ab Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Mon, 14 May 2018 11:46:26 +0200 Subject: [PATCH 08/15] Fix FROM to f28/s2i-core --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index e912d17..d2856e8 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM registry.fedoraproject.org/f27/s2i-base +FROM registry.fedoraproject.org/f28/s2i-base # Apache HTTP Server image. # From 47080824e85b3ec21b60c83161eb4962099d0c16 Mon Sep 17 00:00:00 2001 From: Mohan Boddu Date: Mon, 21 May 2018 16:52:39 +0000 Subject: [PATCH 09/15] "Bump RELEASE for automatic rebuild" --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 637385c..0dd24a3 100644 --- a/Dockerfile +++ b/Dockerfile @@ -24,7 +24,7 @@ LABEL summary="$SUMMARY" \ io.openshift.expose-services="8080:http,8443:https" \ io.openshift.tags="builder,httpd,httpd24" -ENV NAME=httpd VERSION=0 RELEASE=4 ARCH=x86_64 +ENV NAME=httpd VERSION=0 RELEASE=5 ARCH=x86_64 LABEL com.redhat.component="$NAME" \ name="$FGC/$NAME" \ From 5fceb7e6cd988948a11ca114c4191ae5d68f5e8d Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Tue, 5 Jun 2018 17:21:01 +0200 Subject: [PATCH 10/15] Update from the upstream and include fix for BZ#1585533 --- Dockerfile | 37 +- root/help.1 | 106 ++- root/opt/app-root/scl_enable | 3 + root/usr/bin/run-httpd | 2 + root/usr/libexec/httpd-prepare | 6 +- .../share/container-scripts/httpd/README.md | 79 ++- .../share/container-scripts/httpd/common.sh | 75 ++- .../httpd/post-assemble/20-copy-config.sh | 4 + .../httpd/post-assemble/40-ssl-certs.sh | 4 + .../httpd/pre-init/20-copy-config.sh | 4 + .../httpd/pre-init/40-ssl-certs.sh | 4 + s2i/bin/assemble | 16 +- s2i/bin/run | 2 +- s2i/bin/usage | 2 +- .../httpd-pre-init/modify_index.sh | 1 + test/pre-init-test-app/index.html | 1 + test/run | 42 +- test/run-openshift | 35 + .../certs/server-cert-selfsigned.pem | 20 + .../httpd-ssl/private/server-key.pem | 28 + test/self-signed-ssl/index.html | 1 + test/test-lib-openshift.sh | 609 ++++++++++++++++++ test/test-lib.sh | 402 ++++++++++++ 23 files changed, 1381 insertions(+), 102 deletions(-) create mode 100644 root/opt/app-root/scl_enable create mode 100644 root/usr/share/container-scripts/httpd/post-assemble/20-copy-config.sh create mode 100644 root/usr/share/container-scripts/httpd/post-assemble/40-ssl-certs.sh create mode 100644 root/usr/share/container-scripts/httpd/pre-init/20-copy-config.sh create mode 100644 root/usr/share/container-scripts/httpd/pre-init/40-ssl-certs.sh create mode 100644 test/pre-init-test-app/httpd-pre-init/modify_index.sh create mode 100644 test/pre-init-test-app/index.html create mode 100755 test/run-openshift create mode 100644 test/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem create mode 100644 test/self-signed-ssl/httpd-ssl/private/server-key.pem create mode 100644 test/self-signed-ssl/index.html create mode 100644 test/test-lib-openshift.sh create mode 100644 test/test-lib.sh diff --git a/Dockerfile b/Dockerfile index 0dd24a3..8a1ccd8 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM registry.fedoraproject.org/f27/s2i-base +FROM registry.fedoraproject.org/f27/s2i-core:latest # Apache HTTP Server image. # @@ -8,10 +8,14 @@ FROM registry.fedoraproject.org/f27/s2i-base # Environment: # * $HTTPD_LOG_TO_VOLUME (optional) - When set, httpd will log into /var/log/httpd -ENV HTTPD_VERSION=2.4 +ENV HTTPD_VERSION=2.4 \ + NAME=httpd \ + VERSION=$HTTPD_VERSION \ + RELEASE=1 \ + ARCH=x86_64 ENV SUMMARY="Platform for running Apache httpd $HTTPD_VERSION or building httpd-based application" \ - DESCRIPTION="Apache httpd $HTTPD_VERSION available as docker container, is a powerful, efficient, \ + DESCRIPTION="Apache httpd $HTTPD_VERSION available as container, is a powerful, efficient, \ and extensible web server. Apache supports a variety of features, many implemented as compiled modules \ which extend the core functionality. \ These can range from server-side programming language support to authentication schemes. \ @@ -22,20 +26,15 @@ LABEL summary="$SUMMARY" \ io.k8s.description="$SUMMARY" \ io.k8s.display-name="Apache httpd $HTTPD_VERSION" \ io.openshift.expose-services="8080:http,8443:https" \ - io.openshift.tags="builder,httpd,httpd24" - -ENV NAME=httpd VERSION=0 RELEASE=5 ARCH=x86_64 - -LABEL com.redhat.component="$NAME" \ + io.openshift.tags="builder,httpd,httpd24" \ + com.redhat.component="$NAME" \ name="$FGC/$NAME" \ version="$VERSION" \ release="$RELEASE.$DISTTAG" \ architecture="$ARCH" \ - usage="docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z 27/httpd" \ - help="help.1" + usage="s2i build https://github.com/sclorg/httpd-container.git --context-dir=examples/sample-test-app/ $FGC/$NAME sample-server" \ + maintainer="SoftwareCollections.org " -EXPOSE 80 -EXPOSE 443 EXPOSE 8080 EXPOSE 8443 @@ -46,8 +45,8 @@ RUN dnf install -y yum-utils gettext hostname && \ dnf clean all ENV HTTPD_CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/httpd/ \ - HTTPD_APP_ROOT=/opt/app-root \ - HTTPD_CONFIGURATION_PATH=${HTTPD_APP_ROOT}/etc/httpd.d \ + HTTPD_APP_ROOT=${APP_ROOT} \ + HTTPD_CONFIGURATION_PATH=${APP_ROOT}/etc/httpd.d \ HTTPD_MAIN_CONF_PATH=/etc/httpd/conf \ HTTPD_MAIN_CONF_D_PATH=/etc/httpd/conf.d \ HTTPD_VAR_RUN=/var/run/httpd \ @@ -58,11 +57,15 @@ ENV HTTPD_CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/httpd/ \ COPY ./s2i/bin/ $STI_SCRIPTS_PATH COPY ./root / -RUN /usr/libexec/httpd-prepare +# Generate SSL certs and reset permissions of filesystem to default values +RUN /usr/libexec/httpd-ssl-gencerts && \ + /usr/libexec/httpd-prepare && rpm-file-permissions USER 1001 -VOLUME ["${HTTPD_DATA_PATH}"] -VOLUME ["${HTTPD_LOG_PATH}"] +# Not using VOLUME statement since it's not working in OpenShift Online: +# https://github.com/sclorg/httpd-container/issues/30 +# VOLUME ["${HTTPD_DATA_PATH}"] +# VOLUME ["${HTTPD_LOG_PATH}"] CMD ["/usr/bin/run-httpd"] diff --git a/root/help.1 b/root/help.1 index 73f69f2..e9040b3 100644 --- a/root/help.1 +++ b/root/help.1 @@ -1,28 +1,26 @@ -.TH "HTTPD-24-RHEL7" "1" " Container Image Pages" "Red Hat" "April 07, 2017" "" - - -.SH Apache HTTP Server 2.4 +.TH Apache HTTP Server 2.4 Container Image .PP This container image includes Apache HTTP Server 2.4 for OpenShift and general usage. -Users can choose between RHEL, CentOS, and Fedora based images. -The RHEL image is available in the -\[la]https://access.redhat.com/containers\[ra] +Users can choose between RHEL, CentOS and Fedora based images. +The RHEL image is available in the Red Hat Container Catalog +\[la]https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/httpd-24-rhel7\[ra] as registry.access.redhat.com/rhscl/httpd\-24\-rhel7. -The CentOS image is then available on +The CentOS image is then available on Docker Hub \[la]https://hub.docker.com/r/centos/httpd-24-centos7/\[ra] as centos/httpd\-24\-centos7. -.SH DESCRIPTION +.SH Description .PP -Apache HTTP Server 2.4 available as docker container, is a powerful, efficient, +Apache HTTP Server 2.4 available as container, is a powerful, efficient, and extensible web server. Apache supports a variety of features, many implemented as compiled modules which extend the core functionality. These can range from server\-side programming language support to authentication schemes. Virtual hosting allows one Apache installation to serve many different Web sites." -.SH USAGE +.SH Usage .PP -For this, we will assume that you are using the \fB\fCrhscl/httpd\-24\-rhel7\fR image. +For this, we will assume that you are using the Apache HTTP Server 2.4 container image from the +Red Hat Container Catalog called \fB\fCrhscl/httpd\-24\-rhel7\fR\&. The image can be used as a base image for other applications based on Apache HTTP web server. .PP @@ -42,7 +40,7 @@ $ ls \-lZ /wwwdata/html .PP If you want to run the image and mount the static pages available in \fB\fC/wwwdata\fR on the host -as a docker volume, execute the following command: +as a container volume, execute the following command: .PP .RS @@ -58,8 +56,8 @@ This will create a container named \fB\fChttpd\fR running Apache HTTP Server, se \fB\fC/wwwdata\fR directory. Port 8080 will be exposed and mapped to the host. .PP -If you want to create a new Docker layered image, use -\[la]https://github.com/openshift/source-to-image\[ra], a tool for building/building artifacts from source and injecting into docker images. To create a new Docker image named \fB\fChttpd\-app\fR using Source\-to\-Image, while using data available in \fB\fC/wwwdata\fR on the host, execute the following command: +If you want to create a new container layered image, use Source\-to\-Image +\[la]https://github.com/openshift/source-to-image\[ra], a tool for building/building artifacts from source and injecting into container images. To create a new container image named \fB\fChttpd\-app\fR using Source\-to\-Image, while using data available in \fB\fC/wwwdata\fR on the host, execute the following command: .PP .RS @@ -82,19 +80,41 @@ $ docker run \-d \-\-name httpd \-p 8080:8080 httpd\-app .fi .RE -.SH CONFIGURATION +.PP +The structure of httpd\-app can look like this: + +.PP +\fB\fB\fC\&./httpd\-\&cfg\fR\fP +.br + Can contain additional Apache configuration files (\fB\fC*.conf\fR) + +.PP +\fB\fB\fC\&./httpd\-\&pre\-\&init\fR\fP +.br + Can contain shell scripts (\fB\fC*.sh\fR) that are sourced before \fB\fChttpd\fR is started + +.PP +\fB\fB\fC\&./httpd\-\&ssl\fR\fP +.br + Can contain own SSL certificate (in \fB\fCcerts/\fR subdirectory) and key (in \fB\fCprivate/\fR subdirectory) + +.PP +\fB\fB\fC\&./\fR\fP +.br + Application source code + +.SH Environment variables and volumes .PP The Apache HTTP Server container image supports the following configuration variable, which can be set by using the \fB\fC\-e\fR option with the docker run command: -.TS -allbox; -Variable name Description -\fB\fCHTTPD\_LOG\_TO\_VOLUME\fR By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When \fB\fCHTTPD\_LOG\_TO\_VOLUME\fR is set, httpd logs into \fB\fC/var/log/httpd24\fR, which can be mounted to host system using the Docker volumes. This option is only allowed when container is run as UID 0. -.TE +.PP +\fB\fB\fCHTTPD\_LOG\_TO\_VOLUME\fR\fP +.br + By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When \fB\fCHTTPD\_LOG\_TO\_VOLUME\fR is set, httpd logs into \fB\fC/var/log/httpd24\fR, which can be mounted to host system using the container volumes. This option is only allowed when container is run as UID 0. .PP If you want to run the image and mount the log files into \fB\fC/wwwlogs\fR on the host -as a docker volume, execute the following command: +as a container volume, execute the following command: .PP .RS @@ -105,24 +125,42 @@ $ docker run \-d \-u 0 \-e HTTPD\_LOG\_TO\_VOLUME=1 \-\-name httpd \-v /wwwlogs: .fi .RE -.SH VOLUMES .PP You can also set the following mount points by passing the \fB\fC\-v /host:/container\fR flag to Docker. -.TS -allbox; -Volume mount point Description -\fB\fC/var/www\fR Apache HTTP Server data directory -\fB\fC/var/log/httpd24\fR Apache HTTP Server log directory (available only when running as root, path \fB\fC/var/log/httpd\fR is used in case of Fedora based image) +.PP +\fB\fB\fC/var/www\fR\fP +.br + Apache HTTP Server data directory -.TE +.PP +\fB\fB\fC/var/log/httpd24\fR\fP +.br + Apache HTTP Server log directory (available only when running as root, path \fB\fC/var/log/httpd\fR is used in case of Fedora based image) .PP \fBNotice: When mouting a directory from the host into the container, ensure that the mounted directory has the appropriate permissions and that the owner and group of the directory matches the user UID or name which is running inside the container.\fP -.SH DEFAULT USER +.SH Using own SSL certificates +.PP +In order to provide own SSL certificates for securing the connection with SSL, use the extending feature described above. In particular, put the SSL certificates into a separate directory inside your application: + +.PP +.RS + +.nf +\&./httpd\-\&ssl/certs/server\-\&cert\-\&selfsigned.pem +./httpd\-\&ssl/private/server\-\&key.pem + +.fi +.RE + +.PP +The default behaviour is to look for the certificate and the private key in subdirectories certs/ and private/; those files will be used for the ssl settings in the httpd. + +.SH Default user .PP By default, Apache HTTP Server container runs as UID 1001. That means the volume mounted directories for the files (if mounted using \fB\fC\-v\fR option) need to be prepared properly, so the UID 1001 can read them. @@ -141,7 +179,7 @@ docker run \-d \-u 1234 rhscl/httpd\-24\-rhel7 .PP To log into a volume mounted directory, the container needs to be run as UID 0 (see above). -.SH TROUBLESHOOTING +.SH Troubleshooting .PP The httpd deamon in the container logs to the standard output by default, so the log is available in the container log. The log can be examined by running: @@ -154,10 +192,10 @@ docker logs .fi .RE -.SH SEE ALSO +.SH See also .PP Dockerfile and other sources for this container image are available on -\[la]https://github.com/sclorg/httpd-container\[ra]. +\[la]https://github.com/sclorg/httpd-container\[ra]\&. In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile -for RHEL is called Dockerfile.rhel7. +for RHEL is called Dockerfile.rhel7 and Dockerfile for Fedora is called Dockerfile.fedora. diff --git a/root/opt/app-root/scl_enable b/root/opt/app-root/scl_enable new file mode 100644 index 0000000..373330d --- /dev/null +++ b/root/opt/app-root/scl_enable @@ -0,0 +1,3 @@ +# This will make scl collection binaries work out of box. +unset BASH_ENV PROMPT_COMMAND ENV +source scl_source enable httpd24 diff --git a/root/usr/bin/run-httpd b/root/usr/bin/run-httpd index ad38ce0..e03578f 100755 --- a/root/usr/bin/run-httpd +++ b/root/usr/bin/run-httpd @@ -13,4 +13,6 @@ else generate_container_user fi +process_extending_files ${HTTPD_APP_ROOT}/src/httpd-pre-init/ ${HTTPD_CONTAINER_SCRIPTS_PATH}/pre-init/ + exec httpd -D FOREGROUND $@ diff --git a/root/usr/libexec/httpd-prepare b/root/usr/libexec/httpd-prepare index 97cdcde..f7378cf 100755 --- a/root/usr/libexec/httpd-prepare +++ b/root/usr/libexec/httpd-prepare @@ -23,8 +23,8 @@ fi mkdir -p ${HTTPD_CONFIGURATION_PATH} chmod -R a+rwx ${HTTPD_MAIN_CONF_PATH} chmod -R a+rwx ${HTTPD_MAIN_CONF_D_PATH} -#chmod -R a+r /etc/pki/tls/certs/localhost.crt -#chmod -R a+r /etc/pki/tls/private/localhost.key +chmod -R a+r /etc/pki/tls/certs/localhost.crt +chmod -R a+r /etc/pki/tls/private/localhost.key mkdir -p ${HTTPD_APP_ROOT}/etc chmod -R a+rwx ${HTTPD_APP_ROOT}/etc chmod -R a+rwx ${HTTPD_VAR_RUN} @@ -32,5 +32,7 @@ chown -R 1001:0 ${HTTPD_APP_ROOT} chown -R 1001:0 ${HTTPD_DATA_PATH} chown -R 1001:0 ${HTTPD_LOG_PATH} +mkdir -p ${HTTPD_CONTAINER_SCRIPTS_PATH}/pre-init + config_general diff --git a/root/usr/share/container-scripts/httpd/README.md b/root/usr/share/container-scripts/httpd/README.md index eb97041..9332c20 100644 --- a/root/usr/share/container-scripts/httpd/README.md +++ b/root/usr/share/container-scripts/httpd/README.md @@ -1,28 +1,29 @@ -Apache HTTP Server 2.4 +Apache HTTP Server 2.4 Container Image ====================== This container image includes Apache HTTP Server 2.4 for OpenShift and general usage. -Users can choose between RHEL, CentOS, and Fedora based images. -The RHEL image is available in the [Red Hat Registry](https://access.redhat.com/containers) +Users can choose between RHEL, CentOS and Fedora based images. +The RHEL image is available in the [Red Hat Container Catalog](https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/httpd-24-rhel7) as registry.access.redhat.com/rhscl/httpd-24-rhel7. The CentOS image is then available on [Docker Hub](https://hub.docker.com/r/centos/httpd-24-centos7/) as centos/httpd-24-centos7. -DESCRIPTION +Description ----------- -Apache HTTP Server 2.4 available as docker container, is a powerful, efficient, +Apache HTTP Server 2.4 available as container, is a powerful, efficient, and extensible web server. Apache supports a variety of features, many implemented as compiled modules which extend the core functionality. These can range from server-side programming language support to authentication schemes. Virtual hosting allows one Apache installation to serve many different Web sites." -USAGE +Usage ----- -For this, we will assume that you are using the `rhscl/httpd-24-rhel7` image. +For this, we will assume that you are using the Apache HTTP Server 2.4 container image from the +Red Hat Container Catalog called `rhscl/httpd-24-rhel7`. The image can be used as a base image for other applications based on Apache HTTP web server. An example of the data on the host for both the examples above, that will be served by @@ -35,7 +36,7 @@ $ ls -lZ /wwwdata/html ``` If you want to run the image and mount the static pages available in `/wwwdata` on the host -as a docker volume, execute the following command: +as a container volume, execute the following command: ``` $ docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z rhscl/httpd-24-rhel7 @@ -44,7 +45,7 @@ $ docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z rhscl/httpd-24- This will create a container named `httpd` running Apache HTTP Server, serving data from `/wwwdata` directory. Port 8080 will be exposed and mapped to the host. -If you want to create a new Docker layered image, use [Source-to-Image](https://github.com/openshift/source-to-image), a tool for building/building artifacts from source and injecting into docker images. To create a new Docker image named `httpd-app` using Source-to-Image, while using data available in `/wwwdata` on the host, execute the following command: +If you want to create a new container layered image, use [Source-to-Image](https://github.com/openshift/source-to-image), a tool for building/building artifacts from source and injecting into container images. To create a new container image named `httpd-app` using Source-to-Image, while using data available in `/wwwdata` on the host, execute the following command: ``` $ s2i build file:///wwwdata/html rhscl/httpd-24-rhel7 httpd-app @@ -56,41 +57,63 @@ To run such a new image, execute the following command: $ docker run -d --name httpd -p 8080:8080 httpd-app ``` +The structure of httpd-app can look like this: -CONFIGURATION -------------- +**`./httpd-cfg`** + Can contain additional Apache configuration files (`*.conf`) + +**`./httpd-pre-init`** + Can contain shell scripts (`*.sh`) that are sourced before `httpd` is started + +**`./httpd-ssl`** + Can contain own SSL certificate (in `certs/` subdirectory) and key (in `private/` subdirectory) + +**`./`** + Application source code + + +Environment variables and volumes +--------------------------------- The Apache HTTP Server container image supports the following configuration variable, which can be set by using the `-e` option with the docker run command: -| Variable name | Description | -| :---------------------- | ----------------------------------------- | -| `HTTPD_LOG_TO_VOLUME` | By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When `HTTPD_LOG_TO_VOLUME` is set, httpd logs into `/var/log/httpd24`, which can be mounted to host system using the Docker volumes. This option is only allowed when container is run as UID 0. | +**`HTTPD_LOG_TO_VOLUME`** + By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When `HTTPD_LOG_TO_VOLUME` is set, httpd logs into `/var/log/httpd24`, which can be mounted to host system using the container volumes. This option is only allowed when container is run as UID 0. + If you want to run the image and mount the log files into `/wwwlogs` on the host -as a docker volume, execute the following command: +as a container volume, execute the following command: ``` $ docker run -d -u 0 -e HTTPD_LOG_TO_VOLUME=1 --name httpd -v /wwwlogs:/var/log/httpd24:Z rhscl/httpd-24-rhel7 ``` - -VOLUMES -------- - You can also set the following mount points by passing the `-v /host:/container` flag to Docker. -| Volume mount point | Description | -| :----------------------- | ---------------------------------------------------------------------- | -| `/var/www` | Apache HTTP Server data directory | -| `/var/log/httpd24` | Apache HTTP Server log directory (available only when running as root, path `/var/log/httpd` is used in case of Fedora based image) | +**`/var/www`** + Apache HTTP Server data directory + +**`/var/log/httpd24`** + Apache HTTP Server log directory (available only when running as root, path `/var/log/httpd` is used in case of Fedora based image) + **Notice: When mouting a directory from the host into the container, ensure that the mounted directory has the appropriate permissions and that the owner and group of the directory matches the user UID or name which is running inside the container.** -DEFAULT USER +Using own SSL certificates +-------------------------- +In order to provide own SSL certificates for securing the connection with SSL, use the extending feature described above. In particular, put the SSL certificates into a separate directory inside your application: + + ./httpd-ssl/certs/server-cert-selfsigned.pem + ./httpd-ssl/private/server-key.pem + +The default behaviour is to look for the certificate and the private key in subdirectories certs/ and private/; those files will be used for the ssl settings in the httpd. + + +Default user ------------ By default, Apache HTTP Server container runs as UID 1001. That means the volume mounted directories for the files (if mounted using `-v` option) need to be prepared properly, so the UID 1001 can read them. @@ -104,18 +127,16 @@ docker run -d -u 1234 rhscl/httpd-24-rhel7 To log into a volume mounted directory, the container needs to be run as UID 0 (see above). - -TROUBLESHOOTING +Troubleshooting --------------- The httpd deamon in the container logs to the standard output by default, so the log is available in the container log. The log can be examined by running: docker logs -SEE ALSO +See also -------- Dockerfile and other sources for this container image are available on https://github.com/sclorg/httpd-container. In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile -for RHEL is called Dockerfile.rhel7. - +for RHEL is called Dockerfile.rhel7 and Dockerfile for Fedora is called Dockerfile.fedora. diff --git a/root/usr/share/container-scripts/httpd/common.sh b/root/usr/share/container-scripts/httpd/common.sh index c949287..6b6b110 100644 --- a/root/usr/share/container-scripts/httpd/common.sh +++ b/root/usr/share/container-scripts/httpd/common.sh @@ -4,6 +4,7 @@ config_general() { sed -i -e 's/^Listen 80/Listen 0.0.0.0:8080/' ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \ sed -i -e '151s%AllowOverride None%AllowOverride All%' ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \ sed -i -e 's/^Listen 443/Listen 0.0.0.0:8443/' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf + sed -i -e 's/_default_:443/_default_:8443/' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf } config_log_to_stdout() { @@ -34,7 +35,6 @@ config_privileged() { config_s2i() { sed -i -e "s%^DocumentRoot \"${HTTPD_DATA_ORIG_PATH}/html\"%DocumentRoot \"${HTTPD_APP_ROOT}/src\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf sed -i -e "s%^> ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \ head -n151 ${HTTPD_MAIN_CONF_PATH}/httpd.conf | tail -n1 | grep "AllowOverride All" || exit } @@ -49,6 +49,34 @@ config_non_privileged() { fi } +# get_matched_files finds file for image extending +function get_matched_files() { + local custom_dir default_dir + custom_dir="$1" + default_dir="$2" + files_matched="$3" + find "$default_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n" + [ -d "$custom_dir" ] && find "$custom_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n" +} + +# process_extending_files process extending files in $1 and $2 directories +# - source all *.sh files +# (if there are files with same name source only file from $1) +function process_extending_files() { + local custom_dir default_dir + custom_dir=$1 + default_dir=$2 + while read filename ; do + echo "=> sourcing $filename ..." + # Custom file is prefered + if [ -f $custom_dir/$filename ]; then + source $custom_dir/$filename + elif [ -f $default_dir/$filename ]; then + source $default_dir/$filename + fi + done <<<"$(get_matched_files "$custom_dir" "$default_dir" '*.sh' | sort -u)" +} + # Set current user in nss_wrapper generate_container_user() { local passwd_output_dir="${HTTPD_APP_ROOT}/etc" @@ -61,3 +89,48 @@ generate_container_user() { export NSS_WRAPPER_GROUP=/etc/group } +# Copy config files from application to the location where httd expects them +# Param sets the directory where to look for files +process_config_files() { + local dir=${1:-.} + if [ -d ${dir}/httpd-cfg ]; then + echo "---> Copying httpd configuration files..." + if [ "$(ls -A ${dir}/httpd-cfg/*.conf)" ]; then + cp -v ${dir}/httpd-cfg/*.conf "${HTTPD_CONFIGURATION_PATH}" + rm -rf ${dir}/httpd-cfg + fi + else + if [ -d ${dir}/cfg ]; then + echo "---> Copying httpd configuration files from deprecated './cfg' directory, use './httpd-cfg' instead..." + if [ "$(ls -A ${dir}/cfg/*.conf)" ]; then + cp -v ${dir}/cfg/*.conf "${HTTPD_CONFIGURATION_PATH}" + rm -rf ${dir}/cfg + fi + fi + fi +} + +# Copy SSL files provided in application source +process_ssl_certs() { + local dir=${1:-.} + if [ -d ${dir}/httpd-ssl/private ] && [ -d ${dir}/httpd-ssl/certs ]; then + echo "---> Looking for SSL certs for httpd..." + cp -r ${dir}/httpd-ssl ${HTTPD_APP_ROOT} + local ssl_cert="$(ls -A ${HTTPD_APP_ROOT}/httpd-ssl/certs/*.pem | head -n 1)" + local ssl_private="$(ls -A ${HTTPD_APP_ROOT}/httpd-ssl/private/*.pem | head -n 1)" + if [ -f "${ssl_cert}" ] ; then + # do sed for SSLCertificateFile and SSLCertificateKeyFile + echo "---> Setting SSL cert file for httpd..." + sed -i -e "s|^SSLCertificateFile .*$|SSLCertificateFile ${ssl_cert}|" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf + if [ -f "${ssl_private}" ]; then + echo "---> Setting SSL key file for httpd..." + sed -i -e "s|^SSLCertificateKeyFile .*$|SSLCertificateKeyFile ${ssl_private}|" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf + else + echo "---> Removing SSL key file settings for httpd..." + sed -i '/^SSLCertificateKeyFile .*/d' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf + fi + fi + rm -rf ${dir}/httpd-ssl + fi +} + diff --git a/root/usr/share/container-scripts/httpd/post-assemble/20-copy-config.sh b/root/usr/share/container-scripts/httpd/post-assemble/20-copy-config.sh new file mode 100644 index 0000000..2fd03c7 --- /dev/null +++ b/root/usr/share/container-scripts/httpd/post-assemble/20-copy-config.sh @@ -0,0 +1,4 @@ +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +# Copy config files from application to the location where httpd expects them +process_config_files diff --git a/root/usr/share/container-scripts/httpd/post-assemble/40-ssl-certs.sh b/root/usr/share/container-scripts/httpd/post-assemble/40-ssl-certs.sh new file mode 100644 index 0000000..cbad2c3 --- /dev/null +++ b/root/usr/share/container-scripts/httpd/post-assemble/40-ssl-certs.sh @@ -0,0 +1,4 @@ +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +# Copy SSL files provided in application source +process_ssl_certs diff --git a/root/usr/share/container-scripts/httpd/pre-init/20-copy-config.sh b/root/usr/share/container-scripts/httpd/pre-init/20-copy-config.sh new file mode 100644 index 0000000..f7ce08b --- /dev/null +++ b/root/usr/share/container-scripts/httpd/pre-init/20-copy-config.sh @@ -0,0 +1,4 @@ +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +# Copy config files from application to the location where httd expects them +process_config_files ${HTTPD_APP_ROOT}/src diff --git a/root/usr/share/container-scripts/httpd/pre-init/40-ssl-certs.sh b/root/usr/share/container-scripts/httpd/pre-init/40-ssl-certs.sh new file mode 100644 index 0000000..38bc8cf --- /dev/null +++ b/root/usr/share/container-scripts/httpd/pre-init/40-ssl-certs.sh @@ -0,0 +1,4 @@ +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +# Copy SSL files provided in application source +process_ssl_certs ${HTTPD_APP_ROOT}/src diff --git a/s2i/bin/assemble b/s2i/bin/assemble index 62ecc31..d8b61ee 100755 --- a/s2i/bin/assemble +++ b/s2i/bin/assemble @@ -11,21 +11,7 @@ config_s2i echo "---> Installing application source" cp -Rf /tmp/src/. ./ -if [ -d ./httpd-cfg ]; then - echo "---> Copying httpd configuration files..." - if [ "$(ls -A ./httpd-cfg/*.conf)" ]; then - cp -v ./httpd-cfg/*.conf "${HTTPD_CONFIGURATION_PATH}" - rm -rf ./httpd-cfg - fi -else - if [ -d ./cfg ]; then - echo "---> Copying httpd configuration files from deprecated './cfg' directory, use './httpd-cfg' instead..." - if [ "$(ls -A ./cfg/*.conf)" ]; then - cp -v ./cfg/*.conf "${HTTPD_CONFIGURATION_PATH}" - rm -rf ./cfg - fi - fi -fi +process_extending_files ${HTTPD_APP_ROOT}/src/httpd-post-assemble/ ${HTTPD_CONTAINER_SCRIPTS_PATH}/post-assemble/ # Fix source directory permissions fix-permissions ./ diff --git a/s2i/bin/run b/s2i/bin/run index 2748f34..f8f8aa3 100755 --- a/s2i/bin/run +++ b/s2i/bin/run @@ -4,4 +4,4 @@ source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh export HTTPD_RUN_BY_S2I=1 -run-httpd $@ +exec run-httpd $@ diff --git a/s2i/bin/usage b/s2i/bin/usage index 9ace19c..69ed8de 100755 --- a/s2i/bin/usage +++ b/s2i/bin/usage @@ -10,7 +10,7 @@ To use it, install S2I: https://github.com/openshift/source-to-image Sample invocation: -s2i build https://github.com/sclorg/httpd-container.git --context-dir=2.4/test/sample-test-app/ ${NAMESPACE}/httpd-24-${DISTRO}7 httpd-sample-app +s2i build https://github.com/sclorg/httpd-container.git --context-dir=examples/sample-test-app/ ${NAMESPACE}/httpd-24-${DISTRO}7 httpd-sample-app You can then run the resulting image via: docker run -p 8080:8080 httpd-sample-app diff --git a/test/pre-init-test-app/httpd-pre-init/modify_index.sh b/test/pre-init-test-app/httpd-pre-init/modify_index.sh new file mode 100644 index 0000000..61164c5 --- /dev/null +++ b/test/pre-init-test-app/httpd-pre-init/modify_index.sh @@ -0,0 +1 @@ +echo 'This content was replaced by pre-init script.' > ${HTTPD_APP_ROOT}/src/index.html diff --git a/test/pre-init-test-app/index.html b/test/pre-init-test-app/index.html new file mode 100644 index 0000000..38f417d --- /dev/null +++ b/test/pre-init-test-app/index.html @@ -0,0 +1 @@ +This is a sample s2i application with static content. diff --git a/test/run b/test/run index 198710e..13ac012 100755 --- a/test/run +++ b/test/run @@ -162,7 +162,7 @@ function run_s2i_test() { # Test s2i use case # Since we built the candidate image locally, we don't want S2I attempt to pull # it from Docker hub - s2i_args="--force-pull=false" + s2i_args="--pull-policy=never" run "s2i usage ${s2i_args} ${IMAGE_NAME}" 0 "Testing 's2i usage'" run "s2i build ${s2i_args} file://${test_dir}/sample-test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp" 0 "Testing 's2i build'" DOCKER_ARGS='-u 1000' @@ -176,6 +176,42 @@ function run_s2i_test() { sleep 2 } +function run_pre_init_test() { + # Test s2i use case #2 - testing pre-init script + # Since we built the candidate image locally, we don't want S2I attempt to pull + # it from Docker hub + s2i_args="--pull-policy=never" + run "s2i build ${s2i_args} file://${test_dir}/pre-init-test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp2" 0 "Testing 's2i build' with pre-init script" + DOCKER_ARGS='-u 1000' + create_container testing-app-pre-init ${IMAGE_NAME}-testapp2 + DOCKER_ARGS= + sleep 5 + cip=$(get_container_ip 'testing-app-pre-init') + run "curl ${cip}:8080 > output_pre_init" + run "fgrep -e 'This content was replaced by pre-init script.' output_pre_init" + # 0 "Checking page served by s2i feature and edited by pre-init script" + sleep 2 +} + +function run_self_cert_test() { + # Test s2i use case #3 - using own ssl certs + # Since we built the candidate image locally, we don't want S2I attempt to pull + # it from Docker hub + s2i_args="--pull-policy=never" + run "s2i build ${s2i_args} file://${test_dir}/self-signed-ssl ${IMAGE_NAME} ${IMAGE_NAME}-self-signed" 0 "Testing 's2i build' with self-signed cert" + DOCKER_ARGS='-u 1000' + create_container testing-self-signed ${IMAGE_NAME}-self-signed + DOCKER_ARGS= + sleep 5 + cip=$(get_container_ip 'testing-self-signed') + run "curl -k https://${cip}:8443 > output_ssl_cert" + run "fgrep -e 'SSL test works' output_ssl_cert" + echo | openssl s_client -showcerts -servername ${cip} -connect ${cip}:8443 2>/dev/null | openssl x509 -inform pem -noout -text >./servercert + openssl x509 -in ${test_dir}/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem -inform pem -noout -text >./configcert + run "diff ./configcert ./servercert" + run "diff ./configcert ./servercert >cert.diff" + sleep 2 +} function run_all_tests() { for test_case in $TEST_LIST; do @@ -224,11 +260,13 @@ run "docker inspect $IMAGE_NAME >/dev/null || docker pull $IMAGE_NAME" 0 TEST_LIST="\ +run_self_cert_test run_default_page_test run_as_root_test run_log_to_volume_test run_data_volume_test -run_s2i_test" +run_s2i_test +run_pre_init_test" test $# -eq 1 -a "${1-}" == --list && echo "$TEST_LIST" && exit 0 diff --git a/test/run-openshift b/test/run-openshift new file mode 100755 index 0000000..a9e9eec --- /dev/null +++ b/test/run-openshift @@ -0,0 +1,35 @@ +#!/bin/bash +# +# Test the httpd image in OpenShift. +# +# IMAGE_NAME specifies a name of the candidate image used for testing. +# VERSION specifies a version of the python in the candidate image. +# The image has to be available before this script is executed. + +THISDIR=$(dirname ${BASH_SOURCE[0]}) + +source "${THISDIR}/test-lib.sh" +source "${THISDIR}/test-lib-openshift.sh" + +BRANCH_TO_TEST=master + +set -eo nounset + +test -n "${IMAGE_NAME-}" || false 'make sure $IMAGE_NAME is defined' +test -n "${VERSION-}" || false 'make sure $VERSION is defined' + +ct_os_cluster_up + +# test local app +ct_os_test_s2i_app "${IMAGE_NAME}" "${THISDIR}/sample-test-app" . 'This is a sample s2i application with static content' + +# test remote example app +ct_os_test_s2i_app "${IMAGE_NAME}" "https://github.com/openshift/httpd-ex#${BRANCH_TO_TEST}" . 'Welcome to your static httpd application on OpenShift' + +# test template from the example app +ct_os_test_template_app "${IMAGE_NAME}" \ + "https://raw.githubusercontent.com/openshift/httpd-ex/${BRANCH_TO_TEST}/openshift/templates/httpd.json" \ + httpd \ + 'Welcome to your static httpd application on OpenShift' \ + 8080 http 200 "-p SOURCE_REPOSITORY_REF=${BRANCH_TO_TEST}" + diff --git a/test/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem b/test/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem new file mode 100644 index 0000000..8495b88 --- /dev/null +++ b/test/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem @@ -0,0 +1,20 @@ +-----BEGIN CERTIFICATE----- +MIIDWjCCAkKgAwIBAgIJAI4x7HuBG49oMA0GCSqGSIb3DQEBCwUAMEIxCzAJBgNV +BAYTAlhYMRUwEwYDVQQHDAxEZWZhdWx0IENpdHkxHDAaBgNVBAoME0RlZmF1bHQg +Q29tcGFueSBMdGQwHhcNMTcxMjAzMjMzMzU3WhcNMTgwMTAyMjMzMzU3WjBCMQsw +CQYDVQQGEwJYWDEVMBMGA1UEBwwMRGVmYXVsdCBDaXR5MRwwGgYDVQQKDBNEZWZh +dWx0IENvbXBhbnkgTHRkMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA +vH4Vdq0a3UWUQd8Z6s2csxhxjAOyUx0rszGL0m3uTjQido6JRBdjN2dXiZc3LFoq +YeOKR3CeHsn7UdrlzaboHFDfjAaextse0740mB1g14H1bAS0POuTPeKa+3wGfzCb +sTSXnfSrICl3n2D/3KSO93WwmS90kBD6HmKt5nfkLpJnROM/4bHmuoV0Ry8CDjzj +mka7pQU4yzyMKLU3sHpncZU6g7o4Vezic9ksVzIAbdPCSbF7ktVz/hisyCuzyKN6 +s2327jq593vBgGOsNU5PDPDjKW74Q0Bv/FxPK4nx+o4IkcRW1QEb+yAx8XOM7CDZ +ViKvI/A0b+Y4Y3rIQ465+wIDAQABo1MwUTAdBgNVHQ4EFgQUAY1i6ZNbqO1+46aw +pldCyPaWoYswHwYDVR0jBBgwFoAUAY1i6ZNbqO1+46awpldCyPaWoYswDwYDVR0T +AQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEADhGjnYGq9JvQcygMYEQiIdyS +t06Nu7NUkWz52GJp7WFognWyG+0jAomBR0GSUchfubvVZ7cHIaVKLhiGOqg+HIol +7tNRfvE6x/Idk674g6OTRAWxO/wOlgnRMpRy6XhHOtb4HcPcpWFZJS8MC8+HRWIs +kzMErXe0/obnKn9O04kcEREfmB7kfcD4ooqk5gwbdQk1W6a44LcN6AB5qYPjOzgF +Qnb2aLQW9XhgNhiMsYqDzCZsy0az0rz7NgkVOnKrGJ8x3kVX13GR2joVVHOazms9 +Gd90z+mLMDTbqCRGIPMLvEp4HtAmBxbgsj/zHyinajIqV96B3Cr3zTdW29lHJg== +-----END CERTIFICATE----- diff --git a/test/self-signed-ssl/httpd-ssl/private/server-key.pem b/test/self-signed-ssl/httpd-ssl/private/server-key.pem new file mode 100644 index 0000000..ff2ac89 --- /dev/null +++ b/test/self-signed-ssl/httpd-ssl/private/server-key.pem @@ -0,0 +1,28 @@ +-----BEGIN PRIVATE KEY----- +MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQC8fhV2rRrdRZRB +3xnqzZyzGHGMA7JTHSuzMYvSbe5ONCJ2jolEF2M3Z1eJlzcsWiph44pHcJ4eyftR +2uXNpugcUN+MBp7G2x7TvjSYHWDXgfVsBLQ865M94pr7fAZ/MJuxNJed9KsgKXef +YP/cpI73dbCZL3SQEPoeYq3md+QukmdE4z/hsea6hXRHLwIOPOOaRrulBTjLPIwo +tTewemdxlTqDujhV7OJz2SxXMgBt08JJsXuS1XP+GKzIK7PIo3qzbfbuOrn3e8GA +Y6w1Tk8M8OMpbvhDQG/8XE8rifH6jgiRxFbVARv7IDHxc4zsINlWIq8j8DRv5jhj +eshDjrn7AgMBAAECggEARZxeutxE/pCypv0IqkFS7IVLccTvt2gfemcC1yzIBFOW +oqgTI3Vrq8tbdbHFq3iFDG+m4qlBi+dWDC3GDoPkVoi7dg//1TqZEOO+sqqu2Afj +pge6tIDfeMxWJifwkkpWRURB9hCknhUSW2bMNyUCs3rgREJVTtsmM9CHnoSKXXQL +aOeYXalFVpx3ceK+xdp0VGfpsqEabBKs0yy3EDiQy2huoWce3EVFLVrwx/IkhcsZ +JlI5LPpoiTglSs1g9i88JHS2slBtKtb1lWl/yXHhK1g7s34c6f9jP8snuFE5ddMn +0L4GDA9teaPGvB533eb2RIFy2kUYgpr5c03G6rpoOQKBgQDpY6BFJkPGENnC5Bdb +fJCuN2nyRdC1qvv6ESFaQYb0s6QjKDqpb0dUSYN3+zNgtiAysbQLeU/d9mmt4UR8 +ohjRkOySU0eQ/YNFokjw6g6GPoiMHJJ9cP75NA94uIMIUTY7uHEWWZwXI5UphdPC +p5/3MaF1VlYQys9a5wtiEaDSfQKBgQDOwPV0zQjUabkVQ4yV0amP8xybvHH8ghG0 +RMStHg96RfDmg35JQaw22A2xiVROCoZgLqiE1DFSl/3gBF/vfqBh/uzdxwNerJC6 +ROdCxyS4rys5d/02P4aNOa73sD+ZKyEZRTF1v3bmOGKidRFF5oxIpuHjFWlJFKx1 +O/b3AI0v1wKBgQC/L4N84emm+OrKAfs4UIRckrxRYOulxhmAMkQ2IXOiRP5yZmQX +pDa0TzxJLxhZYxhhLr0koQ3R8CeF7wEhb9AQ7D0/aMU5etLsWhKSd8nKIrPMwyMl +a0kTb5g09kEwsQZSSbcp7eI1+koYp65eyN37q0ZuTnlWbC0MdDQY9APgKQKBgQCb +HqaKNXLUe2XDkGSf2ygOumXSanZS7vt9dsLg59bQ9DyjljBfogglNcBAXTqFOtxK +uXbyAYnn3+U399BKjYSjQXJRioj6tRn4xs2DiooAjlwtx9qQouS+fHLLns54iqVQ +oltTbo00eUV3gcGt4iWKNLrxdxUBIaOqaY0HEMDdDQKBgQCRvcHDF7JSPuBiO3Tw +PSOUD4q6dD/dhI+X2ZKg83w94SZXXms6eMSbedUkLoJ8TDunmdRUUWb6rgP/pJwr +zKRTskItF15i9IWCwC6jBrSfx5n2JcSoBALyc0aR9heF0GQjWwqURd+PC/msomrW +z9SCl8mpQVFtBlui7PcnDLTFAg== +-----END PRIVATE KEY----- diff --git a/test/self-signed-ssl/index.html b/test/self-signed-ssl/index.html new file mode 100644 index 0000000..82ff698 --- /dev/null +++ b/test/self-signed-ssl/index.html @@ -0,0 +1 @@ +SSL test works diff --git a/test/test-lib-openshift.sh b/test/test-lib-openshift.sh new file mode 100644 index 0000000..53bb9d3 --- /dev/null +++ b/test/test-lib-openshift.sh @@ -0,0 +1,609 @@ +# Set of functions for testing docker images in OpenShift using 'oc' command + +# ct_os_get_status +# -------------------- +# Returns status of all objects to make debugging easier. +function ct_os_get_status() { + oc get all + oc status +} + +# ct_os_print_logs +# -------------------- +# Returns status of all objects and logs from all pods. +function ct_os_print_logs() { + ct_os_get_status + while read pod_name; do + echo "INFO: printing logs for pod ${pod_name}" + oc logs ${pod_name} + done < <(oc get pods --no-headers=true -o custom-columns=NAME:.metadata.name) +} + +# ct_os_enable_print_logs +# -------------------- +# Enables automatic printing of pod logs on ERR. +function ct_os_enable_print_logs() { + set -E + trap ct_os_print_logs ERR +} + +# ct_get_public_ip +# -------------------- +# Returns best guess for the IP that the node is accessible from other computers. +# This is a bit funny heuristic, simply goes through all IPv4 addresses that +# hostname -I returns and de-prioritizes IP addresses commonly used for local +# addressing. The rest of addresses are taken as public with higher probability. +function ct_get_public_ip() { + local hostnames=$(hostname -I) + local public_ip='' + local found_ip + for guess_exp in '127\.0\.0\.1' '192\.168\.[0-9\.]*' '172\.[0-9\.]*' \ + '10\.[0-9\.]*' '[0-9\.]*' ; do + found_ip=$(echo "${hostnames}" | grep -oe "${guess_exp}") + if [ -n "${found_ip}" ] ; then + hostnames=$(echo "${hostnames}" | sed -e "s/${found_ip}//") + public_ip="${found_ip}" + fi + done + if [ -z "${public_ip}" ] ; then + echo "ERROR: public IP could not be guessed." >&2 + return 1 + fi + echo "${public_ip}" +} + +# ct_os_run_in_pod POD_NAME CMD +# -------------------- +# Runs [cmd] in the pod specified by prefix [pod_prefix]. +# Arguments: pod_name - full name of the pod +# Arguments: cmd - command to be run in the pod +function ct_os_run_in_pod() { + local pod_name="$1" ; shift + + oc exec "$pod_name" -- "$@" +} + +# ct_os_get_service_ip SERVICE_NAME +# -------------------- +# Returns IP of the service specified by [service_name]. +# Arguments: service_name - name of the service +function ct_os_get_service_ip() { + local service_name="${1}" ; shift + oc get "svc/${service_name}" -o yaml | grep clusterIP | \ + cut -d':' -f2 | grep -oe '172\.30\.[0-9\.]*' +} + + +# ct_os_get_all_pods_status +# -------------------- +# Returns status of all pods. +function ct_os_get_all_pods_status() { + oc get pods -o custom-columns=Ready:status.containerStatuses[0].ready,NAME:.metadata.name +} + +# ct_os_get_all_pods_name +# -------------------- +# Returns the full name of all pods. +function ct_os_get_all_pods_name() { + oc get pods --no-headers -o custom-columns=NAME:.metadata.name +} + +# ct_os_get_pod_status POD_PREFIX +# -------------------- +# Returns status of the pod specified by prefix [pod_prefix]. +# Note: Ignores -build and -deploy pods +# Arguments: pod_prefix - prefix or whole ID of the pod +function ct_os_get_pod_status() { + local pod_prefix="${1}" ; shift + ct_os_get_all_pods_status | grep -e "${pod_prefix}" | grep -Ev "(build|deploy)$" \ + | awk '{print $1}' | head -n 1 +} + +# ct_os_get_pod_name POD_PREFIX +# -------------------- +# Returns the full name of pods specified by prefix [pod_prefix]. +# Note: Ignores -build and -deploy pods +# Arguments: pod_prefix - prefix or whole ID of the pod +function ct_os_get_pod_name() { + local pod_prefix="${1}" ; shift + ct_os_get_all_pods_name | grep -e "^${pod_prefix}" | grep -Ev "(build|deploy)$" +} + +# ct_os_get_pod_ip POD_NAME +# -------------------- +# Returns the ip of the pod specified by [pod_name]. +# Arguments: pod_name - full name of the pod +function ct_os_get_pod_ip() { + local pod_name="${1}" + oc get pod "$pod_name" --no-headers -o custom-columns=IP:status.podIP +} + +# ct_os_check_pod_readiness POD_PREFIX STATUS +# -------------------- +# Checks whether the pod is ready. +# Arguments: pod_prefix - prefix or whole ID of the pod +# Arguments: status - expected status (true, false) +function ct_os_check_pod_readiness() { + local pod_prefix="${1}" ; shift + local status="${1}" ; shift + test "$(ct_os_get_pod_status ${pod_prefix})" == "${status}" +} + +# ct_os_wait_pod_ready POD_PREFIX TIMEOUT +# -------------------- +# Wait maximum [timeout] for the pod becomming ready. +# Arguments: pod_prefix - prefix or whole ID of the pod +# Arguments: timeout - how many seconds to wait seconds +function ct_os_wait_pod_ready() { + local pod_prefix="${1}" ; shift + local timeout="${1}" ; shift + SECONDS=0 + echo -n "Waiting for ${pod_prefix} pod becoming ready ..." + while ! ct_os_check_pod_readiness "${pod_prefix}" "true" ; do + echo -n "." + [ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1 + sleep 3 + done + echo " DONE" +} + +# ct_os_wait_rc_ready POD_PREFIX TIMEOUT +# -------------------- +# Wait maximum [timeout] for the rc having desired number of replicas ready. +# Arguments: pod_prefix - prefix of the replication controller +# Arguments: timeout - how many seconds to wait seconds +function ct_os_wait_rc_ready() { + local pod_prefix="${1}" ; shift + local timeout="${1}" ; shift + SECONDS=0 + echo -n "Waiting for ${pod_prefix} pod becoming ready ..." + while ! test "$((oc get --no-headers statefulsets; oc get --no-headers rc) 2>/dev/null \ + | grep "^${pod_prefix}" | awk '$2==$3 {print "ready"}')" == "ready" ; do + echo -n "." + [ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1 + sleep 3 + done + echo " DONE" +} + +# ct_os_deploy_pure_image IMAGE [ENV_PARAMS, ...] +# -------------------- +# Runs [image] in the openshift and optionally specifies env_params +# as environment variables to the image. +# Arguments: image - prefix or whole ID of the pod to run the cmd in +# Arguments: env_params - environment variables parameters for the images. +function ct_os_deploy_pure_image() { + local image="${1}" ; shift + # ignore error exit code, because oc new-app returns error when image exists + oc new-app ${image} "$@" || : + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_deploy_s2i_image IMAGE APP [ENV_PARAMS, ... ] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. +# Arguments: image - prefix or whole ID of the pod to run the cmd in +# Arguments: app - url or local path to git repo with the application sources. +# Arguments: env_params - environment variables parameters for the images. +function ct_os_deploy_s2i_image() { + local image="${1}" ; shift + local app="${1}" ; shift + # ignore error exit code, because oc new-app returns error when image exists + oc new-app "${image}~${app}" "$@" || : + + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_deploy_template_image TEMPLATE [ENV_PARAMS, ...] +# -------------------- +# Runs template in the openshift and optionally gives env_params to use +# specific values in the template. +# Arguments: template - prefix or whole ID of the pod to run the cmd in +# Arguments: env_params - environment variables parameters for the template. +# Example usage: ct_os_deploy_template_image mariadb-ephemeral-template.yaml \ +# DATABASE_SERVICE_NAME=mysql-57-centos7 \ +# DATABASE_IMAGE=mysql-57-centos7 \ +# MYSQL_USER=testu \ +# MYSQL_PASSWORD=testp \ +# MYSQL_DATABASE=testdb +function ct_os_deploy_template_image() { + local template="${1}" ; shift + oc process -f "${template}" "$@" | oc create -f - + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# _ct_os_get_uniq_project_name +# -------------------- +# Returns a uniq name of the OpenShift project. +function _ct_os_get_uniq_project_name() { + local r + while true ; do + r=${RANDOM} + mkdir /var/tmp/os-test-${r} &>/dev/null && echo test-${r} && break + done +} + +# ct_os_new_project [PROJECT] +# -------------------- +# Creates a new project in the openshfit using 'os' command. +# Arguments: project - project name, uses a new random name if omitted +# Expects 'os' command that is properly logged in to the OpenShift cluster. +# Not using mktemp, because we cannot use uppercase characters. +function ct_os_new_project() { + local project_name="${1:-$(_ct_os_get_uniq_project_name)}" ; shift || : + oc new-project ${project_name} + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_delete_project [PROJECT] +# -------------------- +# Deletes the specified project in the openshfit +# Arguments: project - project name, uses the current project if omitted +function ct_os_delete_project() { + local project_name="${1:-$(oc project -q)}" ; shift || : + oc delete project "${project_name}" +} + +# ct_os_docker_login +# -------------------- +# Logs in into docker daemon +function ct_os_docker_login() { + # docker login fails with "404 page not found" error sometimes, just try it more times + for i in `seq 12` ; do + docker login -u developer -p $(oc whoami -t) 172.30.1.1:5000 && return 0 || : + sleep 5 + done + return 1 +} + +# ct_os_upload_image IMAGE [IMAGESTREAM] +# -------------------- +# Uploads image from local registry to the OpenShift internal registry. +# Arguments: image - image name to upload +# Arguments: imagestream - name and tag to use for the internal registry. +# In the format of name:tag ($image_name:latest by default) +function ct_os_upload_image() { + local input_name="${1}" ; shift + local image_name=${input_name##*/} + local imagestream=${1:-$image_name:latest} + local output_name="172.30.1.1:5000/$(oc project -q)/$imagestream" + + ct_os_docker_login + docker tag ${input_name} ${output_name} + docker push ${output_name} +} + +# ct_os_install_in_centos +# -------------------- +# Installs os cluster in CentOS +function ct_os_install_in_centos() { + yum install -y centos-release-openshift-origin + yum install -y wget git net-tools bind-utils iptables-services bridge-utils\ + bash-completion origin-clients docker origin-clients +} + +# ct_os_cluster_up [DIR, IS_PUBLIC, CLUSTER_VERSION] +# -------------------- +# Runs the local OpenShift cluster using 'oc cluster up' and logs in as developer. +# Arguments: dir - directory to keep configuration data in, random if omitted +# Arguments: is_public - sets either private or public hostname for web-UI, +# use "true" for allow remote access to the web-UI, +# "false" is default +# Arguments: cluster_version - version of the OpenShift cluster to use, empty +# means default version of `oc`; example value: v3.7.0; +# also can be specified outside by OC_CLUSTER_VERSION +function ct_os_cluster_up() { + ct_os_cluster_running && echo "Cluster already running. Nothing is done." && return 0 + mkdir -p /var/tmp/openshift + local dir="${1:-$(mktemp -d /var/tmp/openshift/os-data-XXXXXX)}" ; shift || : + local is_public="${1:-'false'}" ; shift || : + local default_cluster_version=${OC_CLUSTER_VERSION:-} + local cluster_version=${1:-${default_cluster_version}} ; shift || : + if ! grep -qe '--insecure-registry.*172\.30\.0\.0' /etc/sysconfig/docker ; then + sed -i "s|OPTIONS='|OPTIONS='--insecure-registry 172.30.0.0/16 |" /etc/sysconfig/docker + fi + + systemctl stop firewalld + setenforce 0 + iptables -F + + systemctl restart docker + local cluster_ip="127.0.0.1" + [ "${is_public}" == "true" ] && cluster_ip=$(ct_get_public_ip) + + mkdir -p ${dir}/{config,data,pv} + oc cluster up --host-data-dir=${dir}/data --host-config-dir=${dir}/config \ + --host-pv-dir=${dir}/pv --use-existing-config --public-hostname=${cluster_ip} \ + ${cluster_version:+--version=$cluster_version } + oc version + oc login -u system:admin + oc project default + ct_os_wait_rc_ready docker-registry 180 + ct_os_wait_rc_ready router 30 + oc login -u developer -p developer + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_cluster_down +# -------------------- +# Shuts down the local OpenShift cluster using 'oc cluster down' +function ct_os_cluster_down() { + oc cluster down +} + +# ct_os_cluster_running +# -------------------- +# Returns 0 if oc cluster is running +function ct_os_cluster_running() { + oc cluster status &>/dev/null +} + +# ct_os_test_s2i_app_func IMAGE APP CONTEXT_DIR CHECK_CMD [OC_ARGS] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the container by arbitrary +# function given as argument (such an argument may include string, +# that will be replaced with actual IP). +# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: app - url or local path to git repo with the application sources (compulsory) +# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory) +# Arguments: check_command - CMD line that checks whether the container works (compulsory; '' will be replaced with actual IP) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +function ct_os_test_s2i_app_func() { + local image_name=${1} + local app=${2} + local context_dir=${3} + local check_command=${4} + local oc_args=${5:-} + local image_name_no_namespace=${image_name##*/} + local service_name="${image_name_no_namespace}-testing" + local image_tagged="${image_name_no_namespace}:testing" + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_s2i_app_func() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + ct_os_new_project + # Create a specific imagestream tag for the image so that oc cannot use anything else + ct_os_upload_image "${image_name}" "${image_tagged}" + + local app_param="${app}" + if [ -d "${app}" ] ; then + # for local directory, we need to copy the content, otherwise too smart os command + # pulls the git remote repository instead + app_param=$(ct_obtain_input "${app}") + fi + + ct_os_deploy_s2i_image "${image_tagged}" "${app_param}" \ + --context-dir="${context_dir}" \ + --name "${service_name}" \ + ${oc_args} + + if [ -d "${app}" ] ; then + # in order to avoid weird race seen sometimes, let's wait shortly + # before starting the build explicitly + sleep 5 + oc start-build "${service_name}" --from-dir="${app_param}" + fi + + ct_os_wait_pod_ready "${service_name}" 300 + + local ip=$(ct_os_get_service_ip "${service_name}") + local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") + + echo " Checking APP using $check_command_exp ..." + local result=0 + eval "$check_command_exp" || result=1 + + if [ $result -eq 0 ] ; then + echo " Check passed." + else + echo " Check failed." + fi + + ct_os_delete_project + return $result +} + +# ct_os_test_s2i_app IMAGE APP CONTEXT_DIR EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the http response. +# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: app - url or local path to git repo with the application sources (compulsory) +# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory) +# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory) +# Arguments: port - which port to use (optional; default: 8080) +# Arguments: protocol - which protocol to use (optional; default: http) +# Arguments: response_code - what http response code to expect (optional; default: 200) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +function ct_os_test_s2i_app() { + local image_name=${1} + local app=${2} + local context_dir=${3} + local expected_output=${4} + local port=${5:-8080} + local protocol=${6:-http} + local response_code=${7:-200} + local oc_args=${8:-} + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_s2i_app() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + ct_os_test_s2i_app_func "${image_name}" \ + "${app}" \ + "${context_dir}" \ + "ct_test_response '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ + "${oc_args}" +} + +# ct_os_test_template_app_func IMAGE APP IMAGE_IN_TEMPLATE CHECK_CMD [OC_ARGS] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the container by arbitrary +# function given as argument (such an argument may include string, +# that will be replaced with actual IP). +# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: template - url or local path to a template to use (compulsory) +# Arguments: name_in_template - image name used in the template +# Arguments: check_command - CMD line that checks whether the container works (compulsory; '' will be replaced with actual IP) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry, +# specify them in this parameter as "|", where "" is a full image name +# (including registry if needed) and "" is a tag under which the image should be available +# in the OpenShift registry. +function ct_os_test_template_app_func() { + local image_name=${1} + local template=${2} + local name_in_template=${3} + local check_command=${4} + local oc_args=${5:-} + local other_images=${6:-} + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_template_app_func() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + local service_name="${name_in_template}-testing" + local image_tagged="${name_in_template}:${VERSION}" + + ct_os_new_project + # Create a specific imagestream tag for the image so that oc cannot use anything else + ct_os_upload_image "${image_name}" "${image_tagged}" + + # upload also other images, that template might need (list of pairs in the format | + local images_tags_a + local i_t + for i_t in ${other_images} ; do + echo "${i_t}" + IFS='|' read -ra image_tag_a <<< "${i_t}" + docker pull "${image_tag_a[0]}" + ct_os_upload_image "${image_tag_a[0]}" "${image_tag_a[1]}" + done + + local local_template=$(ct_obtain_input "${template}") + oc new-app ${local_template} \ + -p NAME="${service_name}" \ + -p NAMESPACE="$(oc project -q)" \ + ${oc_args} + + oc start-build "${service_name}" + + ct_os_wait_pod_ready "${service_name}" 300 + + local ip=$(ct_os_get_service_ip "${service_name}") + local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") + + echo " Checking APP using $check_command_exp ..." + local result=0 + eval "$check_command_exp" || result=1 + + if [ $result -eq 0 ] ; then + echo " Check passed." + else + echo " Check failed." + fi + + ct_os_delete_project + return $result +} + +# params: +# ct_os_test_template_app IMAGE APP IMAGE_IN_TEMPLATE EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the http response. +# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: template - url or local path to a template to use (compulsory) +# Arguments: name_in_template - image name used in the template +# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory) +# Arguments: port - which port to use (optional; default: 8080) +# Arguments: protocol - which protocol to use (optional; default: http) +# Arguments: response_code - what http response code to expect (optional; default: 200) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry, +# specify them in this parameter as "|", where "" is a full image name +# (including registry if needed) and "" is a tag under which the image should be available +# in the OpenShift registry. +function ct_os_test_template_app() { + local image_name=${1} + local template=${2} + local name_in_template=${3} + local expected_output=${4} + local port=${5:-8080} + local protocol=${6:-http} + local response_code=${7:-200} + local oc_args=${8:-} + local other_images=${9:-} + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_template_app() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + ct_os_test_template_app_func "${image_name}" \ + "${template}" \ + "${name_in_template}" \ + "ct_test_response '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ + "${oc_args}" \ + "${other_images}" +} + +# ct_os_test_image_update IMAGE IS CHECK_CMD OC_ARGS +# -------------------- +# Runs an image update test with [image] uploaded to [is] imagestream +# and checks the services using an arbitrary function provided in [check_cmd]. +# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: is - imagestream to upload the images into (compulsory) +# Arguments: check_cmd - command to be run to check functionality of created services (compulsory) +# Arguments: oc_args - arguments to use during oc new-app (compulsory) +ct_os_test_image_update() { + local image_name=$1; shift + local istag=$1; shift + local check_function=$1; shift + local service_name=${image_name##*/} + local old_image="" ip="" check_command_exp="" registry="" + registry=$(ct_registry_from_os "$OS") + old_image="$registry/$image_name" + + echo "Running image update test for: $image_name" + ct_os_new_project + + # Get current image from repository and create an imagestream + docker pull "$old_image:latest" 2>/dev/null + ct_os_upload_image "$old_image" "$istag" + + # Setup example application with curent image + oc new-app "$@" --name "$service_name" + ct_os_wait_pod_ready "$service_name" 60 + + # Check application output + ip=$(ct_os_get_service_ip "$service_name") + check_command_exp=${check_function///$ip} + ct_assert_cmd_success "$check_command_exp" + + # Tag built image into the imagestream and wait for rebuild + ct_os_upload_image "$image_name" "$istag" + ct_os_wait_pod_ready "${service_name}-2" 60 + + # Check application output + ip=$(ct_os_get_service_ip "$service_name") + check_command_exp=${check_function///$ip} + ct_assert_cmd_success "$check_command_exp" + + ct_os_delete_project +} diff --git a/test/test-lib.sh b/test/test-lib.sh new file mode 100644 index 0000000..dfc63d9 --- /dev/null +++ b/test/test-lib.sh @@ -0,0 +1,402 @@ +# +# Test a container image. +# +# Always use sourced from a specific container testfile +# +# reguires definition of CID_FILE_DIR +# CID_FILE_DIR=$(mktemp --suffix=_test_cidfiles -d) +# reguires definition of TEST_LIST +# TEST_LIST="\ +# ctest_container_creation +# ctest_doc_content" + +# Container CI tests +# abbreviated as "ct" + +# may be redefined in the specific container testfile +EXPECTED_EXIT_CODE=0 + +# ct_cleanup +# -------------------- +# Cleans up containers used during tests. Stops and removes all containers +# referenced by cid_files in CID_FILE_DIR. Dumps logs if a container exited +# unexpectedly. Removes the cid_files and CID_FILE_DIR as well. +# Uses: $CID_FILE_DIR - path to directory containing cid_files +# Uses: $EXPECTED_EXIT_CODE - expected container exit code +function ct_cleanup() { + for cid_file in $CID_FILE_DIR/* ; do + local container=$(cat $cid_file) + + : "Stopping and removing container $container..." + docker stop $container + exit_status=$(docker inspect -f '{{.State.ExitCode}}' $container) + if [ "$exit_status" != "$EXPECTED_EXIT_CODE" ]; then + : "Dumping logs for $container" + docker logs $container + fi + docker rm -v $container + rm $cid_file + done + rmdir $CID_FILE_DIR + : "Done." +} + +# ct_enable_cleanup +# -------------------- +# Enables automatic container cleanup after tests. +function ct_enable_cleanup() { + trap ct_cleanup EXIT SIGINT +} + +# ct_get_cid [name] +# -------------------- +# Prints container id from cid_file based on the name of the file. +# Argument: name - name of cid_file where the container id will be stored +# Uses: $CID_FILE_DIR - path to directory containing cid_files +function ct_get_cid() { + local name="$1" ; shift || return 1 + echo $(cat "$CID_FILE_DIR/$name") +} + +# ct_get_cip [id] +# -------------------- +# Prints container ip address based on the container id. +# Argument: id - container id +function ct_get_cip() { + local id="$1" ; shift + docker inspect --format='{{.NetworkSettings.IPAddress}}' $(ct_get_cid "$id") +} + +# ct_wait_for_cid [cid_file] +# -------------------- +# Holds the execution until the cid_file is created. Usually run after container +# creation. +# Argument: cid_file - name of the cid_file that should be created +function ct_wait_for_cid() { + local cid_file=$1 + local max_attempts=10 + local sleep_time=1 + local attempt=1 + local result=1 + while [ $attempt -le $max_attempts ]; do + [ -f $cid_file ] && [ -s $cid_file ] && return 0 + : "Waiting for container start..." + attempt=$(( $attempt + 1 )) + sleep $sleep_time + done + return 1 +} + +# ct_assert_container_creation_fails [container_args] +# -------------------- +# The invocation of docker run should fail based on invalid container_args +# passed to the function. Returns 0 when container fails to start properly. +# Argument: container_args - all arguments are passed directly to dokcer run +# Uses: $CID_FILE_DIR - path to directory containing cid_files +function ct_assert_container_creation_fails() { + local ret=0 + local max_attempts=10 + local attempt=1 + local cid_file=assert + set +e + local old_container_args="${CONTAINER_ARGS-}" + CONTAINER_ARGS="$@" + ct_create_container $cid_file + if [ $? -eq 0 ]; then + local cid=$(ct_get_cid $cid_file) + + while [ "$(docker inspect -f '{{.State.Running}}' $cid)" == "true" ] ; do + sleep 2 + attempt=$(( $attempt + 1 )) + if [ $attempt -gt $max_attempts ]; then + docker stop $cid + ret=1 + break + fi + done + exit_status=$(docker inspect -f '{{.State.ExitCode}}' $cid) + if [ "$exit_status" == "0" ]; then + ret=1 + fi + docker rm -v $cid + rm $CID_FILE_DIR/$cid_file + fi + [ ! -z $old_container_args ] && CONTAINER_ARGS="$old_container_args" + set -e + return $ret +} + +# ct_create_container [name, command] +# -------------------- +# Creates a container using the IMAGE_NAME and CONTAINER_ARGS variables. Also +# stores the container id to a cid_file located in the CID_FILE_DIR, and waits +# for the creation of the file. +# Argument: name - name of cid_file where the container id will be stored +# Argument: command - optional command to be executed in the container +# Uses: $CID_FILE_DIR - path to directory containing cid_files +# Uses: $CONTAINER_ARGS - optional arguments passed directly to docker run +# Uses: $IMAGE_NAME - name of the image being tested +function ct_create_container() { + local cid_file="$CID_FILE_DIR/$1" ; shift + # create container with a cidfile in a directory for cleanup + docker run --cidfile="$cid_file" -d ${CONTAINER_ARGS:-} $IMAGE_NAME "$@" + ct_wait_for_cid $cid_file || return 1 + : "Created container $(cat $cid_file)" +} + +# ct_scl_usage_old [name, command, expected] +# -------------------- +# Tests three ways of running the SCL, by looking for an expected string +# in the output of the command +# Argument: name - name of cid_file where the container id will be stored +# Argument: command - executed inside the container +# Argument: expected - string that is expected to be in the command output +# Uses: $CID_FILE_DIR - path to directory containing cid_files +# Uses: $IMAGE_NAME - name of the image being tested +function ct_scl_usage_old() { + local name="$1" + local command="$2" + local expected="$3" + local out="" + : " Testing the image SCL enable" + out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${command}") + if ! echo "${out}" | grep -q "${expected}"; then + echo "ERROR[/bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2 + return 1 + fi + out=$(docker exec $(ct_get_cid $name) /bin/bash -c "${command}" 2>&1) + if ! echo "${out}" | grep -q "${expected}"; then + echo "ERROR[exec /bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2 + return 1 + fi + out=$(docker exec $(ct_get_cid $name) /bin/sh -ic "${command}" 2>&1) + if ! echo "${out}" | grep -q "${expected}"; then + echo "ERROR[exec /bin/sh -ic "${command}"] Expected '${expected}', got '${out}'" >&2 + return 1 + fi +} + +# ct_doc_content_old [strings] +# -------------------- +# Looks for occurence of stirngs in the documentation files and checks +# the format of the files. Files examined: help.1 +# Argument: strings - strings expected to appear in the documentation +# Uses: $IMAGE_NAME - name of the image being tested +function ct_doc_content_old() { + local tmpdir=$(mktemp -d) + local f + : " Testing documentation in the container image" + # Extract the help files from the container + for f in help.1 ; do + docker run --rm ${IMAGE_NAME} /bin/bash -c "cat /${f}" >${tmpdir}/$(basename ${f}) + # Check whether the files contain some important information + for term in $@ ; do + if ! cat ${tmpdir}/$(basename ${f}) | grep -F -q -e "${term}" ; then + echo "ERROR: File /${f} does not include '${term}'." >&2 + return 1 + fi + done + # Check whether the files use the correct format + for term in TH PP SH ; do + if ! grep -q "^\.${term}" ${tmpdir}/help.1 ; then + echo "ERROR: /help.1 is probably not in troff or groff format, since '${term}' is missing." >&2 + return 1 + fi + done + done + : " Success!" +} + + +# ct_path_append PATH_VARNAME DIRECTORY +# ------------------------------------- +# Append DIRECTORY to VARIABLE of name PATH_VARNAME, the VARIABLE must consist +# of colon-separated list of directories. +ct_path_append () +{ + if eval "test -n \"\${$1-}\""; then + eval "$1=\$2:\$$1" + else + eval "$1=\$2" + fi +} + + +# ct_path_foreach PATH ACTION [ARGS ...] +# -------------------------------------- +# For each DIR in PATH execute ACTION (path is colon separated list of +# directories). The particular calls to ACTION will look like +# '$ ACTION directory [ARGS ...]' +ct_path_foreach () +{ + local dir dirlist action save_IFS + save_IFS=$IFS + IFS=: + dirlist=$1 + action=$2 + shift 2 + for dir in $dirlist; do "$action" "$dir" "$@" ; done + IFS=$save_IFS +} + + +# ct_run_test_list +# -------------------- +# Execute the tests specified by TEST_LIST +# Uses: $TEST_LIST - list of test names +function ct_run_test_list() { + for test_case in $TEST_LIST; do + : "Running test $test_case" + [ -f test/$test_case ] && source test/$test_case + [ -f ../test/$test_case ] && source ../test/$test_case + $test_case + done; +} + +# ct_gen_self_signed_cert_pem +# --------------------------- +# Generates a self-signed PEM certificate pair into specified directory. +# Argument: output_dir - output directory path +# Argument: base_name - base name of the certificate files +# Resulted files will be those: +# /-cert-selfsigned.pem -- public PEM cert +# /-key.pem -- PEM private key +ct_gen_self_signed_cert_pem() { + local output_dir=$1 ; shift + local base_name=$1 ; shift + mkdir -p ${output_dir} + openssl req -newkey rsa:2048 -nodes -keyout ${output_dir}/${base_name}-key.pem -subj '/C=GB/ST=Berkshire/L=Newbury/O=My Server Company' > ${base_name}-req.pem + openssl req -new -x509 -nodes -key ${output_dir}/${base_name}-key.pem -batch > ${output_dir}/${base_name}-cert-selfsigned.pem +} + +# ct_obtain_input FILE|DIR|URL +# -------------------- +# Either copies a file or a directory to a tmp location for local copies, or +# downloads the file from remote location. +# Resulted file path is printed, so it can be later used by calling function. +# Arguments: input - local file, directory or remote URL +function ct_obtain_input() { + local input=$1 + local extension="${input##*.}" + + # Try to use same extension for the temporary file if possible + [[ "${extension}" =~ ^[a-z0-9]*$ ]] && extension=".${extension}" || extension="" + + local output=$(mktemp "/var/tmp/test-input-XXXXXX$extension") + if [ -f "${input}" ] ; then + cp "${input}" "${output}" + elif [ -d "${input}" ] ; then + rm -f "${output}" + cp -r -LH "${input}" "${output}" + elif echo "${input}" | grep -qe '^http\(s\)\?://' ; then + curl "${input}" > "${output}" + else + echo "ERROR: file type not known: ${input}" >&2 + return 1 + fi + echo "${output}" +} + +# ct_test_response +# ---------------- +# Perform GET request to the application container, checks output with +# a reg-exp and HTTP response code. +# Argument: url - request URL path +# Argument: expected_code - expected HTTP response code +# Argument: body_regexp - PCRE regular expression that must match the response body +# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between +# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10) +ct_test_response() { + local url="$1" + local expected_code="$2" + local body_regexp="$3" + local max_attempts=${4:-20} + local ignore_error_attempts=${5:-10} + + : " Testing the HTTP(S) response for <${url}>" + local sleep_time=3 + local attempt=1 + local result=1 + local status + local response_code + local response_file=$(mktemp /tmp/ct_test_response_XXXXXX) + while [ ${attempt} -le ${max_attempts} ]; do + curl --connect-timeout 10 -s -w '%{http_code}' "${url}" >${response_file} && status=0 || status=1 + if [ ${status} -eq 0 ]; then + response_code=$(cat ${response_file} | tail -c 3) + if [ "${response_code}" -eq "${expected_code}" ]; then + result=0 + fi + cat ${response_file} | grep -qP -e "${body_regexp}" || result=1; + # Some services return 40x code until they are ready, so let's give them + # some chance and not end with failure right away + # Do not wait if we already have expected outcome though + if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then + break + fi + fi + attempt=$(( ${attempt} + 1 )) + sleep ${sleep_time} + done + rm -f ${response_file} + return ${result} +} + +# ct_registry_from_os OS +# ---------------- +# Transform operating system string [os] into registry url +# Argument: OS - string containing the os version +ct_registry_from_os() { + local registry="" + case $1 in + rhel7) + registry=registry.access.redhat.com + ;; + *) + registry=docker.io + ;; + esac + echo "$registry" +} + +# ct_assert_cmd_success CMD +# ---------------- +# Evaluates [cmd] and fails if it does not succeed. +# Argument: CMD - Command to be run +function ct_assert_cmd_success() { + echo "Checking '$*' for success ..." + if ! eval "$@" &>/dev/null; then + echo " FAIL" + return 1 + fi + echo " PASS" + return 0 +} + +# ct_assert_cmd_failure CMD +# ---------------- +# Evaluates [cmd] and fails if it succeeds. +# Argument: CMD - Command to be run +function ct_assert_cmd_failure() { + echo "Checking '$*' for failure ..." + if eval "$@" &>/dev/null; then + echo " FAIL" + return 1 + fi + echo " PASS" + return 0 +} + + +# ct_random_string [LENGTH=10] +# ---------------------------- +# Generate pseudorandom alphanumeric string of LENGTH bytes, the +# default length is 10. The string is printed on stdout. +ct_random_string() +( + export LC_ALL=C + dd if=/dev/urandom count=1 bs=10k 2>/dev/null \ + | tr -dc 'a-z0-9' \ + | fold -w "${1-10}" \ + | head -n 1 +) From 0bacc709a63722885040033a6d5cc5f358faa9d6 Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Tue, 5 Jun 2018 17:34:00 +0200 Subject: [PATCH 11/15] Use version explicitely, no variables --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 846294e..7dbd29d 100644 --- a/Dockerfile +++ b/Dockerfile @@ -29,7 +29,7 @@ LABEL summary="$SUMMARY" \ io.openshift.tags="builder,httpd,httpd24" \ com.redhat.component="$NAME" \ name="$FGC/$NAME" \ - version="$VERSION" \ + version="2.4" \ release="$RELEASE.$DISTTAG" \ architecture="$ARCH" \ usage="s2i build https://github.com/sclorg/httpd-container.git --context-dir=examples/sample-test-app/ $FGC/$NAME sample-server" \ From 92843166f5d50b33cf27b7486a6294675e1501b9 Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Tue, 5 Jun 2018 17:37:41 +0200 Subject: [PATCH 12/15] Use f29 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 7dbd29d..f1778da 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM registry.fedoraproject.org/f28/s2i-core:latest +FROM registry.fedoraproject.org/f29/s2i-core:latest # Apache HTTP Server image. # From 5bfc9e82ed92ada2600a0e4bc59ef61ee42b39bf Mon Sep 17 00:00:00 2001 From: Clement Verna Date: Mon, 20 Aug 2018 19:57:51 +0200 Subject: [PATCH 13/15] Drop Release label in favor of OSBS release_bump plugin. OSBS can automatically bump the release number, for that we just need to drop the label from the Dockerfile See https://pagure.io/ContainerSIG/container-sig/issue/1 Signed-off-by: Clement Verna --- Dockerfile | 2 -- 1 file changed, 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index f1778da..fd4a1db 100644 --- a/Dockerfile +++ b/Dockerfile @@ -11,7 +11,6 @@ FROM registry.fedoraproject.org/f29/s2i-core:latest ENV HTTPD_VERSION=2.4 \ NAME=httpd \ VERSION=$HTTPD_VERSION \ - RELEASE=1 \ ARCH=x86_64 ENV SUMMARY="Platform for running Apache httpd $HTTPD_VERSION or building httpd-based application" \ @@ -30,7 +29,6 @@ LABEL summary="$SUMMARY" \ com.redhat.component="$NAME" \ name="$FGC/$NAME" \ version="2.4" \ - release="$RELEASE.$DISTTAG" \ architecture="$ARCH" \ usage="s2i build https://github.com/sclorg/httpd-container.git --context-dir=examples/sample-test-app/ $FGC/$NAME sample-server" \ maintainer="SoftwareCollections.org " From 8593e4678bd7145424da567c21103adfb9f92631 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marek=20Skalick=C3=BD?= Date: Fri, 30 Nov 2018 17:46:13 +0000 Subject: [PATCH 14/15] Pull changes from upstream and rebase for: rebuild for latest f30 --- 2.4 | 1 + Dockerfile | 8 +- Dockerfile.fedora | 1 + README.md | 122 +----- help.md | 1 + root/help.1 | 16 + root/usr/libexec/httpd-prepare | 1 + .../share/container-scripts/httpd/README.md | 8 + .../share/container-scripts/httpd/common.sh | 17 +- .../httpd/pre-init/10-set-mpm.sh | 3 + sources | 0 test/run | 44 +- test/run-openshift | 4 +- test/test-lib-openshift.sh | 390 ++++++++++++++++-- test/test-lib.sh | 107 ++++- 15 files changed, 544 insertions(+), 179 deletions(-) create mode 120000 2.4 create mode 120000 Dockerfile.fedora mode change 100644 => 120000 README.md create mode 120000 help.md create mode 100644 root/usr/share/container-scripts/httpd/pre-init/10-set-mpm.sh delete mode 100644 sources diff --git a/2.4 b/2.4 new file mode 120000 index 0000000..945c9b4 --- /dev/null +++ b/2.4 @@ -0,0 +1 @@ +. \ No newline at end of file diff --git a/Dockerfile b/Dockerfile index fd4a1db..1f47576 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM registry.fedoraproject.org/f29/s2i-core:latest +FROM registry.fedoraproject.org/f30/s2i-core:latest # Apache HTTP Server image. # @@ -10,7 +10,6 @@ FROM registry.fedoraproject.org/f29/s2i-core:latest ENV HTTPD_VERSION=2.4 \ NAME=httpd \ - VERSION=$HTTPD_VERSION \ ARCH=x86_64 ENV SUMMARY="Platform for running Apache httpd $HTTPD_VERSION or building httpd-based application" \ @@ -28,8 +27,7 @@ LABEL summary="$SUMMARY" \ io.openshift.tags="builder,httpd,httpd24" \ com.redhat.component="$NAME" \ name="$FGC/$NAME" \ - version="2.4" \ - architecture="$ARCH" \ + version="$HTTPD_VERSION" \ usage="s2i build https://github.com/sclorg/httpd-container.git --context-dir=examples/sample-test-app/ $FGC/$NAME sample-server" \ maintainer="SoftwareCollections.org " @@ -46,6 +44,7 @@ ENV HTTPD_CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/httpd/ \ HTTPD_APP_ROOT=${APP_ROOT} \ HTTPD_CONFIGURATION_PATH=${APP_ROOT}/etc/httpd.d \ HTTPD_MAIN_CONF_PATH=/etc/httpd/conf \ + HTTPD_MAIN_CONF_MODULES_D_PATH=/etc/httpd/conf.modules.d \ HTTPD_MAIN_CONF_D_PATH=/etc/httpd/conf.d \ HTTPD_VAR_RUN=/var/run/httpd \ HTTPD_DATA_PATH=/var/www \ @@ -56,6 +55,7 @@ COPY ./s2i/bin/ $STI_SCRIPTS_PATH COPY ./root / # Generate SSL certs and reset permissions of filesystem to default values +# Reset permissions of filesystem to default values RUN /usr/libexec/httpd-ssl-gencerts && \ /usr/libexec/httpd-prepare && rpm-file-permissions diff --git a/Dockerfile.fedora b/Dockerfile.fedora new file mode 120000 index 0000000..1d1fe94 --- /dev/null +++ b/Dockerfile.fedora @@ -0,0 +1 @@ +Dockerfile \ No newline at end of file diff --git a/README.md b/README.md deleted file mode 100644 index eb97041..0000000 --- a/README.md +++ /dev/null @@ -1,121 +0,0 @@ -Apache HTTP Server 2.4 -====================== - -This container image includes Apache HTTP Server 2.4 for OpenShift and general usage. -Users can choose between RHEL, CentOS, and Fedora based images. -The RHEL image is available in the [Red Hat Registry](https://access.redhat.com/containers) -as registry.access.redhat.com/rhscl/httpd-24-rhel7. -The CentOS image is then available on [Docker Hub](https://hub.docker.com/r/centos/httpd-24-centos7/) -as centos/httpd-24-centos7. - - -DESCRIPTION ------------ - -Apache HTTP Server 2.4 available as docker container, is a powerful, efficient, -and extensible web server. Apache supports a variety of features, many implemented as compiled modules -which extend the core functionality. -These can range from server-side programming language support to authentication schemes. -Virtual hosting allows one Apache installation to serve many different Web sites." - - -USAGE ------ - -For this, we will assume that you are using the `rhscl/httpd-24-rhel7` image. -The image can be used as a base image for other applications based on Apache HTTP web server. - -An example of the data on the host for both the examples above, that will be served by -Apache HTTP web server: - -``` -$ ls -lZ /wwwdata/html --rw-r--r--. 1 1001 1001 54321 Jan 01 12:34 index.html --rw-r--r--. 1 1001 1001 5678 Jan 01 12:34 page.html -``` - -If you want to run the image and mount the static pages available in `/wwwdata` on the host -as a docker volume, execute the following command: - -``` -$ docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z rhscl/httpd-24-rhel7 -``` - -This will create a container named `httpd` running Apache HTTP Server, serving data from -`/wwwdata` directory. Port 8080 will be exposed and mapped to the host. - -If you want to create a new Docker layered image, use [Source-to-Image](https://github.com/openshift/source-to-image), a tool for building/building artifacts from source and injecting into docker images. To create a new Docker image named `httpd-app` using Source-to-Image, while using data available in `/wwwdata` on the host, execute the following command: - -``` -$ s2i build file:///wwwdata/html rhscl/httpd-24-rhel7 httpd-app -``` - -To run such a new image, execute the following command: - -``` -$ docker run -d --name httpd -p 8080:8080 httpd-app -``` - - -CONFIGURATION -------------- - -The Apache HTTP Server container image supports the following configuration variable, which can be set by using the `-e` option with the docker run command: - -| Variable name | Description | -| :---------------------- | ----------------------------------------- | -| `HTTPD_LOG_TO_VOLUME` | By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When `HTTPD_LOG_TO_VOLUME` is set, httpd logs into `/var/log/httpd24`, which can be mounted to host system using the Docker volumes. This option is only allowed when container is run as UID 0. | - - -If you want to run the image and mount the log files into `/wwwlogs` on the host -as a docker volume, execute the following command: - -``` -$ docker run -d -u 0 -e HTTPD_LOG_TO_VOLUME=1 --name httpd -v /wwwlogs:/var/log/httpd24:Z rhscl/httpd-24-rhel7 -``` - - -VOLUMES -------- - -You can also set the following mount points by passing the `-v /host:/container` flag to Docker. - -| Volume mount point | Description | -| :----------------------- | ---------------------------------------------------------------------- | -| `/var/www` | Apache HTTP Server data directory | -| `/var/log/httpd24` | Apache HTTP Server log directory (available only when running as root, path `/var/log/httpd` is used in case of Fedora based image) | - -**Notice: When mouting a directory from the host into the container, ensure that the mounted -directory has the appropriate permissions and that the owner and group of the directory -matches the user UID or name which is running inside the container.** - - -DEFAULT USER ------------- - -By default, Apache HTTP Server container runs as UID 1001. That means the volume mounted directories for the files (if mounted using `-v` option) need to be prepared properly, so the UID 1001 can read them. - -To run the container as a different UID, use `-u` option. For example if you want to run the container as UID 1234, execute the following command: - -``` -docker run -d -u 1234 rhscl/httpd-24-rhel7 -``` - -To log into a volume mounted directory, the container needs to be run as UID 0 (see above). - - - -TROUBLESHOOTING ---------------- -The httpd deamon in the container logs to the standard output by default, so the log is available in the container log. The log can be examined by running: - - docker logs - - -SEE ALSO --------- -Dockerfile and other sources for this container image are available on -https://github.com/sclorg/httpd-container. -In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile -for RHEL is called Dockerfile.rhel7. - diff --git a/README.md b/README.md new file mode 120000 index 0000000..299cf2b --- /dev/null +++ b/README.md @@ -0,0 +1 @@ +root/usr/share/container-scripts/httpd/README.md \ No newline at end of file diff --git a/help.md b/help.md new file mode 120000 index 0000000..42061c0 --- /dev/null +++ b/help.md @@ -0,0 +1 @@ +README.md \ No newline at end of file diff --git a/root/help.1 b/root/help.1 index e9040b3..ddf8343 100644 --- a/root/help.1 +++ b/root/help.1 @@ -112,6 +112,10 @@ The Apache HTTP Server container image supports the following configuration vari .br By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When \fB\fCHTTPD\_LOG\_TO\_VOLUME\fR is set, httpd logs into \fB\fC/var/log/httpd24\fR, which can be mounted to host system using the container volumes. This option is only allowed when container is run as UID 0. +.PP +\fB\fB\fCHTTPD\_MPM\fR\fP + The variable \fB\fCHTTPD\_MPM\fR can be set to change the default Multi\-Processing Module (MPM) from the package default MPM. + .PP If you want to run the image and mount the log files into \fB\fC/wwwlogs\fR on the host as a container volume, execute the following command: @@ -125,6 +129,18 @@ $ docker run \-d \-u 0 \-e HTTPD\_LOG\_TO\_VOLUME=1 \-\-name httpd \-v /wwwlogs: .fi .RE +.PP +To run an image using the \fB\fCevent\fR MPM (rather than the default \fB\fCprefork\fR), execute the following command: + +.PP +.RS + +.nf +$ docker run \-d \-e HTTPD\_MPM=event \-\-name httpd rhscl/httpd\-24\-rhel7 + +.fi +.RE + .PP You can also set the following mount points by passing the \fB\fC\-v /host:/container\fR flag to Docker. diff --git a/root/usr/libexec/httpd-prepare b/root/usr/libexec/httpd-prepare index f7378cf..e2857da 100755 --- a/root/usr/libexec/httpd-prepare +++ b/root/usr/libexec/httpd-prepare @@ -23,6 +23,7 @@ fi mkdir -p ${HTTPD_CONFIGURATION_PATH} chmod -R a+rwx ${HTTPD_MAIN_CONF_PATH} chmod -R a+rwx ${HTTPD_MAIN_CONF_D_PATH} +chmod -R a+rwx ${HTTPD_MAIN_CONF_MODULES_D_PATH} chmod -R a+r /etc/pki/tls/certs/localhost.crt chmod -R a+r /etc/pki/tls/private/localhost.key mkdir -p ${HTTPD_APP_ROOT}/etc diff --git a/root/usr/share/container-scripts/httpd/README.md b/root/usr/share/container-scripts/httpd/README.md index 9332c20..99eceed 100644 --- a/root/usr/share/container-scripts/httpd/README.md +++ b/root/usr/share/container-scripts/httpd/README.md @@ -80,6 +80,8 @@ The Apache HTTP Server container image supports the following configuration vari **`HTTPD_LOG_TO_VOLUME`** By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When `HTTPD_LOG_TO_VOLUME` is set, httpd logs into `/var/log/httpd24`, which can be mounted to host system using the container volumes. This option is only allowed when container is run as UID 0. +**`HTTPD_MPM`** + The variable `HTTPD_MPM` can be set to change the default Multi-Processing Module (MPM) from the package default MPM. If you want to run the image and mount the log files into `/wwwlogs` on the host @@ -89,6 +91,12 @@ as a container volume, execute the following command: $ docker run -d -u 0 -e HTTPD_LOG_TO_VOLUME=1 --name httpd -v /wwwlogs:/var/log/httpd24:Z rhscl/httpd-24-rhel7 ``` +To run an image using the `event` MPM (rather than the default `prefork`), execute the following command: + +``` +$ docker run -d -e HTTPD_MPM=event --name httpd rhscl/httpd-24-rhel7 +``` + You can also set the following mount points by passing the `-v /host:/container` flag to Docker. **`/var/www`** diff --git a/root/usr/share/container-scripts/httpd/common.sh b/root/usr/share/container-scripts/httpd/common.sh index 6b6b110..1cdeee9 100644 --- a/root/usr/share/container-scripts/httpd/common.sh +++ b/root/usr/share/container-scripts/httpd/common.sh @@ -23,6 +23,8 @@ config_privileged() { chmod 755 ${HTTPD_MAIN_CONF_PATH} && \ chmod 644 ${HTTPD_MAIN_CONF_D_PATH}/* && \ chmod 755 ${HTTPD_MAIN_CONF_D_PATH} && \ + chmod 644 ${HTTPD_MAIN_CONF_MODULES_D_PATH}/* && \ + chmod 755 ${HTTPD_MAIN_CONF_MODULES_D_PATH} && \ chmod 600 /etc/pki/tls/certs/localhost.crt && \ chmod 600 /etc/pki/tls/private/localhost.key && \ chmod 710 ${HTTPD_VAR_RUN} @@ -49,6 +51,15 @@ config_non_privileged() { fi } +config_mpm() { + if [ -v HTTPD_MPM -a -f ${HTTPD_MAIN_CONF_MODULES_D_PATH}/00-mpm.conf ]; then + local mpmconf=${HTTPD_MAIN_CONF_MODULES_D_PATH}/00-mpm.conf + sed -i -e 's,^LoadModule,#LoadModule,' ${mpmconf} + sed -i -e "/LoadModule mpm_${HTTPD_MPM}/s,^#LoadModule,LoadModule," ${mpmconf} + echo "---> Set MPM to ${HTTPD_MPM} in ${mpmconf}" + fi +} + # get_matched_files finds file for image extending function get_matched_files() { local custom_dir default_dir @@ -114,8 +125,11 @@ process_config_files() { process_ssl_certs() { local dir=${1:-.} if [ -d ${dir}/httpd-ssl/private ] && [ -d ${dir}/httpd-ssl/certs ]; then + echo "---> Moving the httpd-ssl directory included in the source to a directory that isn't exposed by httpd..." + mv ${dir}/httpd-ssl ${HTTPD_APP_ROOT} + fi + if [ -d ${HTTPD_APP_ROOT}/httpd-ssl/private ] && [ -d ${HTTPD_APP_ROOT}/httpd-ssl/certs ]; then echo "---> Looking for SSL certs for httpd..." - cp -r ${dir}/httpd-ssl ${HTTPD_APP_ROOT} local ssl_cert="$(ls -A ${HTTPD_APP_ROOT}/httpd-ssl/certs/*.pem | head -n 1)" local ssl_private="$(ls -A ${HTTPD_APP_ROOT}/httpd-ssl/private/*.pem | head -n 1)" if [ -f "${ssl_cert}" ] ; then @@ -130,7 +144,6 @@ process_ssl_certs() { sed -i '/^SSLCertificateKeyFile .*/d' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf fi fi - rm -rf ${dir}/httpd-ssl fi } diff --git a/root/usr/share/container-scripts/httpd/pre-init/10-set-mpm.sh b/root/usr/share/container-scripts/httpd/pre-init/10-set-mpm.sh new file mode 100644 index 0000000..f7de495 --- /dev/null +++ b/root/usr/share/container-scripts/httpd/pre-init/10-set-mpm.sh @@ -0,0 +1,3 @@ +source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh + +config_mpm diff --git a/sources b/sources deleted file mode 100644 index e69de29..0000000 diff --git a/test/run b/test/run index 13ac012..d73bc3b 100755 --- a/test/run +++ b/test/run @@ -7,8 +7,10 @@ THISDIR=$(dirname ${BASH_SOURCE[0]}) . ${THISDIR}/utils.sh test_dir="$(readlink -zf $(dirname "${BASH_SOURCE[0]}"))" +. "$test_dir/test-lib.sh" + function _container_is_scl() { - docker inspect --format='{{.Config.Env}}' "${1-$IMAGE_NAME}" | grep -q HTTPD_SCL + docker inspect --format='{{.ContainerConfig.Env}}' "${1-$IMAGE_NAME}" | grep -q HTTPD_SCL return $? } @@ -80,7 +82,7 @@ function run_default_page_test() { function run_as_root_test() { # Try running as root - DOCKER_ARGS="-u 0" + DOCKER_ARGS="--user 0" run "create_container test_run_as_root" DOCKER_ARGS= sleep 2 @@ -106,7 +108,7 @@ function _run_log_to_volume_test() { run "ls -d ${logs_dir} || mkdir ${logs_dir}" 0 'Create log directory' run "chown -R 1001:1001 ${logs_dir}" run "chcon -Rvt svirt_sandbox_file_t ${logs_dir}" 0 'Change SELinux context on the log dir' - DOCKER_ARGS="-e HTTPD_LOG_TO_VOLUME=1 -u 0 -v ${logs_dir}:${volume_dir}" + DOCKER_ARGS="-e HTTPD_LOG_TO_VOLUME=1 --user 0 -v ${logs_dir}:${volume_dir}" run "create_container test_log_dir_${variant}" DOCKER_ARGS= sleep 2 @@ -122,7 +124,7 @@ function _run_log_to_volume_test() { function _run_invalid_log_volume_test() { # Check wrong usage of the HTTP_LOG_TO_VOLUME env variable - DOCKER_ARGS="-e HTTPD_LOG_TO_VOLUME=1 -u 1001" + DOCKER_ARGS="-e HTTPD_LOG_TO_VOLUME=1 --user 1001" run "create_container test_log_dir_fail" DOCKER_ARGS= sleep 2 @@ -157,15 +159,31 @@ function _run_data_volume_test() { run "grep -e '^hello$' output" } +function _run_mpm_config_test() { + local mpm=$1 + # Check worker MPM can be configured + DOCKER_ARGS="-e HTTPD_MPM=$mpm --user 1001" + run "create_container test_mpm_${mpm}" + DOCKER_ARGS= + sleep 2 + cid=$(get_cid "test_mpm_$mpm") + run "docker logs $cid | grep -s mpm_${mpm}':notice.*resuming normal operations'" +} + +function run_mpm_config_test() { + for m in worker event prefork; do + _run_mpm_config_test $m + done +} function run_s2i_test() { # Test s2i use case # Since we built the candidate image locally, we don't want S2I attempt to pull # it from Docker hub s2i_args="--pull-policy=never" - run "s2i usage ${s2i_args} ${IMAGE_NAME}" 0 "Testing 's2i usage'" - run "s2i build ${s2i_args} file://${test_dir}/sample-test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp" 0 "Testing 's2i build'" - DOCKER_ARGS='-u 1000' + run "ct_s2i_usage ${IMAGE_NAME} ${s2i_args}" 0 "Testing 's2i usage'" + run "ct_s2i_build_as_df file://${test_dir}/sample-test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp ${s2i_args}" 0 "Testing 's2i build'" + DOCKER_ARGS='--user 1000' create_container testing-app-s2i ${IMAGE_NAME}-testapp DOCKER_ARGS= sleep 5 @@ -181,8 +199,8 @@ function run_pre_init_test() { # Since we built the candidate image locally, we don't want S2I attempt to pull # it from Docker hub s2i_args="--pull-policy=never" - run "s2i build ${s2i_args} file://${test_dir}/pre-init-test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp2" 0 "Testing 's2i build' with pre-init script" - DOCKER_ARGS='-u 1000' + run "ct_s2i_build_as_df file://${test_dir}/pre-init-test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp2 ${s2i_args}" 0 "Testing 's2i build' with pre-init script" + DOCKER_ARGS='--user 1000' create_container testing-app-pre-init ${IMAGE_NAME}-testapp2 DOCKER_ARGS= sleep 5 @@ -198,8 +216,8 @@ function run_self_cert_test() { # Since we built the candidate image locally, we don't want S2I attempt to pull # it from Docker hub s2i_args="--pull-policy=never" - run "s2i build ${s2i_args} file://${test_dir}/self-signed-ssl ${IMAGE_NAME} ${IMAGE_NAME}-self-signed" 0 "Testing 's2i build' with self-signed cert" - DOCKER_ARGS='-u 1000' + run "ct_s2i_build_as_df file://${test_dir}/self-signed-ssl ${IMAGE_NAME} ${IMAGE_NAME}-self-signed ${s2i_args}" 0 "Testing 's2i build' with self-signed cert" + DOCKER_ARGS='--user 1000' create_container testing-self-signed ${IMAGE_NAME}-self-signed DOCKER_ARGS= sleep 5 @@ -266,7 +284,9 @@ run_as_root_test run_log_to_volume_test run_data_volume_test run_s2i_test -run_pre_init_test" +run_pre_init_test +run_mpm_config_test +" test $# -eq 1 -a "${1-}" == --list && echo "$TEST_LIST" && exit 0 diff --git a/test/run-openshift b/test/run-openshift index a9e9eec..c72bc64 100755 --- a/test/run-openshift +++ b/test/run-openshift @@ -24,12 +24,12 @@ ct_os_cluster_up ct_os_test_s2i_app "${IMAGE_NAME}" "${THISDIR}/sample-test-app" . 'This is a sample s2i application with static content' # test remote example app -ct_os_test_s2i_app "${IMAGE_NAME}" "https://github.com/openshift/httpd-ex#${BRANCH_TO_TEST}" . 'Welcome to your static httpd application on OpenShift' +ct_os_test_s2i_app "${IMAGE_NAME}" "https://github.com/sclorg/httpd-ex#${BRANCH_TO_TEST}" . 'Welcome to your static httpd application on OpenShift' # test template from the example app ct_os_test_template_app "${IMAGE_NAME}" \ "https://raw.githubusercontent.com/openshift/httpd-ex/${BRANCH_TO_TEST}/openshift/templates/httpd.json" \ httpd \ 'Welcome to your static httpd application on OpenShift' \ - 8080 http 200 "-p SOURCE_REPOSITORY_REF=${BRANCH_TO_TEST}" + 8080 http 200 "-p SOURCE_REPOSITORY_REF=${BRANCH_TO_TEST} -p NAME=httpd-testing" diff --git a/test/test-lib-openshift.sh b/test/test-lib-openshift.sh index 53bb9d3..f988ac5 100644 --- a/test/test-lib-openshift.sh +++ b/test/test-lib-openshift.sh @@ -223,7 +223,7 @@ function _ct_os_get_uniq_project_name() { local r while true ; do r=${RANDOM} - mkdir /var/tmp/os-test-${r} &>/dev/null && echo test-${r} && break + mkdir /var/tmp/sclorg-test-${r} &>/dev/null && echo sclorg-test-${r} && break done } @@ -234,6 +234,10 @@ function _ct_os_get_uniq_project_name() { # Expects 'os' command that is properly logged in to the OpenShift cluster. # Not using mktemp, because we cannot use uppercase characters. function ct_os_new_project() { + if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then + echo "Creating project skipped." + return + fi local project_name="${1:-$(_ct_os_get_uniq_project_name)}" ; shift || : oc new-project ${project_name} # let openshift cluster to sync to avoid some race condition errors @@ -245,17 +249,38 @@ function ct_os_new_project() { # Deletes the specified project in the openshfit # Arguments: project - project name, uses the current project if omitted function ct_os_delete_project() { + if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then + echo "Deleting project skipped, cleaning objects only." + ct_delete_all_objects + return + fi local project_name="${1:-$(oc project -q)}" ; shift || : oc delete project "${project_name}" } +# ct_delete_all_objects +# ----------------- +# Deletes all objects within the project. +# Handy when we have one project and want to run more tests. +function ct_delete_all_objects() { + for x in bc builds dc is isimage istag po pv pvc rc routes secrets svc ; do + oc delete $x --all + done + # for some objects it takes longer to be really deleted, so a dummy sleep + # to avoid some races when other test can see not-yet-deleted objects and can fail + sleep 10 +} + # ct_os_docker_login # -------------------- # Logs in into docker daemon +# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address. +# Does not do anything if REGISTRY_ADDRESS is set. function ct_os_docker_login() { + [ -n "${REGISTRY_ADDRESS:-}" ] && "REGISTRY_ADDRESS set, not trying to docker login." && return 0 # docker login fails with "404 page not found" error sometimes, just try it more times for i in `seq 12` ; do - docker login -u developer -p $(oc whoami -t) 172.30.1.1:5000 && return 0 || : + docker login -u developer -p $(oc whoami -t) ${REGISRTY_ADDRESS:-172.30.1.1:5000} && return 0 || : sleep 5 done return 1 @@ -267,11 +292,12 @@ function ct_os_docker_login() { # Arguments: image - image name to upload # Arguments: imagestream - name and tag to use for the internal registry. # In the format of name:tag ($image_name:latest by default) +# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address. function ct_os_upload_image() { local input_name="${1}" ; shift local image_name=${input_name##*/} local imagestream=${1:-$image_name:latest} - local output_name="172.30.1.1:5000/$(oc project -q)/$imagestream" + local output_name="${REGISRTY_ADDRESS:-172.30.1.1:5000}/$(oc project -q)/$imagestream" ct_os_docker_login docker tag ${input_name} ${output_name} @@ -295,10 +321,12 @@ function ct_os_install_in_centos() { # use "true" for allow remote access to the web-UI, # "false" is default # Arguments: cluster_version - version of the OpenShift cluster to use, empty -# means default version of `oc`; example value: v3.7.0; +# means default version of `oc`; example value: 3.7; # also can be specified outside by OC_CLUSTER_VERSION function ct_os_cluster_up() { ct_os_cluster_running && echo "Cluster already running. Nothing is done." && return 0 + ct_os_logged_in && echo "Already logged in to a cluster. Nothing is done." && return 0 + mkdir -p /var/tmp/openshift local dir="${1:-$(mktemp -d /var/tmp/openshift/os-data-XXXXXX)}" ; shift || : local is_public="${1:-'false'}" ; shift || : @@ -308,7 +336,7 @@ function ct_os_cluster_up() { sed -i "s|OPTIONS='|OPTIONS='--insecure-registry 172.30.0.0/16 |" /etc/sysconfig/docker fi - systemctl stop firewalld + systemctl stop firewalld || : setenforce 0 iptables -F @@ -316,10 +344,25 @@ function ct_os_cluster_up() { local cluster_ip="127.0.0.1" [ "${is_public}" == "true" ] && cluster_ip=$(ct_get_public_ip) + if [ -n "${cluster_version}" ] ; then + # if $cluster_version is not set, we simply use oc that is available + ct_os_set_path_oc "${cluster_version}" + fi + mkdir -p ${dir}/{config,data,pv} - oc cluster up --host-data-dir=${dir}/data --host-config-dir=${dir}/config \ - --host-pv-dir=${dir}/pv --use-existing-config --public-hostname=${cluster_ip} \ - ${cluster_version:+--version=$cluster_version } + case $(oc version| head -n 1) in + "oc v3.1"?.*) + oc cluster up --base-dir="${dir}/data" --public-hostname="${cluster_ip}" + ;; + "oc v3."*) + oc cluster up --host-data-dir="${dir}/data" --host-config-dir="${dir}/config" \ + --host-pv-dir="${dir}/pv" --use-existing-config --public-hostname="${cluster_ip}" + ;; + *) + echo "ERROR: Unexpected oc version." >&2 + return 1 + ;; + esac oc version oc login -u system:admin oc project default @@ -344,6 +387,96 @@ function ct_os_cluster_running() { oc cluster status &>/dev/null } +# ct_os_logged_in +# --------------- +# Returns 0 if logged in to a cluster (remote or local) +function ct_os_logged_in() { + oc whoami >/dev/null +} + +# ct_os_set_path_oc OC_VERSION +# -------------------- +# This is a trick that helps using correct version of the `oc`: +# The input is version of the openshift in format v3.6.0 etc. +# If the currently available version of oc is not of this version, +# it first takes a look into /usr/local/oc-/bin directory, +# and if not found there it downloads the community release from github. +# In the end the PATH variable is changed, so the other tests can still use just 'oc'. +# Arguments: oc_version - X.Y part of the version of OSE (e.g. 3.9) +function ct_os_set_path_oc() { + local oc_version=$(ct_os_get_latest_ver $1) + local oc_path + + if oc version | grep -q "oc ${oc_version%.*}." ; then + echo "Binary oc found already available in version ${oc_version}: `which oc` Doing noting." + return 0 + fi + + # first check whether we already have oc available in /usr/local + local installed_oc_path="/usr/local/oc-${oc_version%.*}/bin" + + if [ -x "${installed_oc_path}/oc" ] ; then + oc_path="${installed_oc_path}" + echo "Binary oc found in ${installed_oc_path}" >&2 + else + # oc not available in /usr/local, try to download it from github (community release) + oc_path="/tmp/oc-${oc_version}-bin" + ct_os_download_upstream_oc "${oc_version}" "${oc_path}" + fi + if [ -z "${oc_path}/oc" ] ; then + echo "ERROR: oc not found installed, nor downloaded" >&1 + return 1 + fi + export PATH="${oc_path}:${PATH}" + if ! oc version | grep -q "oc ${oc_version%.*}." ; then + echo "ERROR: something went wrong, oc located at ${oc_path}, but oc of version ${oc_version} not found in PATH ($PATH)" >&1 + return 1 + else + echo "PATH set correctly, binary oc found in version ${oc_version}: `which oc`" + fi +} + +# ct_os_get_latest_ver VERSION_PART_X +# -------------------- +# Returns full version (vX.Y.Z) from part of the version (X.Y) +# Arguments: vxy - X.Y part of the version +# Returns vX.Y.Z variant of the version +function ct_os_get_latest_ver(){ + local vxy="v$1" + for vz in {3..0} ; do + curl -sif "https://github.com/openshift/origin/releases/tag/${vxy}.${vz}" >/dev/null && echo "${vxy}.${vz}" && return 0 + done + echo "ERROR: version ${vxy} not found in https://github.com/openshift/origin/tags" >&2 + return 1 +} + +# ct_os_download_upstream_oc OC_VERSION OUTPUT_DIR +# -------------------- +# Downloads a particular version of openshift-origin-client-tools from +# github into specified output directory +# Arguments: oc_version - version of OSE (e.g. v3.7.2) +# Arguments: output_dir - output directory +function ct_os_download_upstream_oc() { + local oc_version=$1 + local output_dir=$2 + + # check whether we already have the binary in place + [ -x "${output_dir}/oc" ] && return 0 + + mkdir -p "${output_dir}" + # using html output instead of https://api.github.com/repos/openshift/origin/releases/tags/${oc_version}, + # because API is limited for number of queries if not authenticated + tarball=$(curl -si "https://github.com/openshift/origin/releases/tag/${oc_version}" | grep -o -e "openshift-origin-client-tools-${oc_version}-[a-f0-9]*-linux-64bit.tar.gz" | head -n 1) + + # download, unpack the binaries and then put them into output directory + echo "Downloading https://github.com/openshift/origin/releases/download/${oc_version}/${tarball} into ${output_dir}/" >&2 + curl -sL https://github.com/openshift/origin/releases/download/${oc_version}/"${tarball}" | tar -C "${output_dir}" -xz + mv -f "${output_dir}"/"${tarball%.tar.gz}"/* "${output_dir}/" + + rmdir "${output_dir}"/"${tarball%.tar.gz}" +} + + # ct_os_test_s2i_app_func IMAGE APP CONTEXT_DIR CHECK_CMD [OC_ARGS] # -------------------- # Runs [image] and [app] in the openshift and optionally specifies env_params @@ -362,9 +495,10 @@ function ct_os_test_s2i_app_func() { local context_dir=${3} local check_command=${4} local oc_args=${5:-} + local import_image=${6:-} local image_name_no_namespace=${image_name##*/} local service_name="${image_name_no_namespace}-testing" - local image_tagged="${image_name_no_namespace}:testing" + local image_tagged="${image_name_no_namespace}:${VERSION}" if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then echo "ERROR: ct_os_test_s2i_app_func() requires at least 4 arguments that cannot be emtpy." >&2 @@ -373,7 +507,19 @@ function ct_os_test_s2i_app_func() { ct_os_new_project # Create a specific imagestream tag for the image so that oc cannot use anything else - ct_os_upload_image "${image_name}" "${image_tagged}" + if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then + if [ -n "${import_image}" ] ; then + echo "Importing image ${import_image} as ${image_name}:${VERSION}" + oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm + else + echo "Uploading and importing image skipped." + fi + else + if [ -n "${import_image}" ] ; then + echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead." + fi + ct_os_upload_image "${image_name}" "${image_tagged}" + fi local app_param="${app}" if [ -d "${app}" ] ; then @@ -435,6 +581,7 @@ function ct_os_test_s2i_app() { local protocol=${6:-http} local response_code=${7:-200} local oc_args=${8:-} + local import_image=${9:-} if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then echo "ERROR: ct_os_test_s2i_app() requires at least 4 arguments that cannot be emtpy." >&2 @@ -444,8 +591,8 @@ function ct_os_test_s2i_app() { ct_os_test_s2i_app_func "${image_name}" \ "${app}" \ "${context_dir}" \ - "ct_test_response '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ - "${oc_args}" + "ct_os_test_response_internal '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ + "${oc_args}" "${import_image}" } # ct_os_test_template_app_func IMAGE APP IMAGE_IN_TEMPLATE CHECK_CMD [OC_ARGS] @@ -471,6 +618,7 @@ function ct_os_test_template_app_func() { local check_command=${4} local oc_args=${5:-} local other_images=${6:-} + local import_image=${7:-} if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then echo "ERROR: ct_os_test_template_app_func() requires at least 4 arguments that cannot be emtpy." >&2 @@ -481,27 +629,39 @@ function ct_os_test_template_app_func() { local image_tagged="${name_in_template}:${VERSION}" ct_os_new_project - # Create a specific imagestream tag for the image so that oc cannot use anything else - ct_os_upload_image "${image_name}" "${image_tagged}" - # upload also other images, that template might need (list of pairs in the format | - local images_tags_a - local i_t - for i_t in ${other_images} ; do - echo "${i_t}" - IFS='|' read -ra image_tag_a <<< "${i_t}" - docker pull "${image_tag_a[0]}" - ct_os_upload_image "${image_tag_a[0]}" "${image_tag_a[1]}" - done + # Create a specific imagestream tag for the image so that oc cannot use anything else + if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then + if [ -n "${import_image}" ] ; then + echo "Importing image ${import_image} as ${image_name}:${VERSION}" + oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm + else + echo "Uploading and importing image skipped." + fi + else + if [ -n "${import_image}" ] ; then + echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead." + fi + ct_os_upload_image "${image_name}" "${image_tagged}" + + # upload also other images, that template might need (list of pairs in the format | + local images_tags_a + local i_t + for i_t in ${other_images} ; do + echo "${i_t}" + IFS='|' read -ra image_tag_a <<< "${i_t}" + docker pull "${image_tag_a[0]}" + ct_os_upload_image "${image_tag_a[0]}" "${image_tag_a[1]}" + done + fi local local_template=$(ct_obtain_input "${template}") + local namespace=${CT_NAMESPACE:-$(oc project -q)} oc new-app ${local_template} \ - -p NAME="${service_name}" \ - -p NAMESPACE="$(oc project -q)" \ + --name "${name_in_template}" \ + -p NAMESPACE="${namespace}" \ ${oc_args} - oc start-build "${service_name}" - ct_os_wait_pod_ready "${service_name}" 300 local ip=$(ct_os_get_service_ip "${service_name}") @@ -549,6 +709,7 @@ function ct_os_test_template_app() { local response_code=${7:-200} local oc_args=${8:-} local other_images=${9:-} + local import_image=${10:-} if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then echo "ERROR: ct_os_test_template_app() requires at least 4 arguments that cannot be emtpy." >&2 @@ -558,27 +719,28 @@ function ct_os_test_template_app() { ct_os_test_template_app_func "${image_name}" \ "${template}" \ "${name_in_template}" \ - "ct_test_response '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ + "ct_os_test_response_internal '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ "${oc_args}" \ - "${other_images}" + "${other_images}" \ + "${import_image}" } -# ct_os_test_image_update IMAGE IS CHECK_CMD OC_ARGS +# ct_os_test_image_update IMAGE_NAME OLD_IMAGE ISTAG CHECK_FUNCTION OC_ARGS # -------------------- # Runs an image update test with [image] uploaded to [is] imagestream -# and checks the services using an arbitrary function provided in [check_cmd]. -# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) -# Arguments: is - imagestream to upload the images into (compulsory) -# Arguments: check_cmd - command to be run to check functionality of created services (compulsory) +# and checks the services using an arbitrary function provided in [check_function]. +# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: old_image - valid name of the image from the registry +# Arguments: istag - imagestream to upload the images into (compulsory) +# Arguments: check_function - command to be run to check functionality of created services (compulsory) # Arguments: oc_args - arguments to use during oc new-app (compulsory) ct_os_test_image_update() { local image_name=$1; shift + local old_image=$1; shift local istag=$1; shift local check_function=$1; shift local service_name=${image_name##*/} - local old_image="" ip="" check_command_exp="" registry="" - registry=$(ct_registry_from_os "$OS") - old_image="$registry/$image_name" + local ip="" check_command_exp="" echo "Running image update test for: $image_name" ct_os_new_project @@ -607,3 +769,157 @@ ct_os_test_image_update() { ct_os_delete_project } + +# ct_os_deploy_cmd_image IMAGE_NAME +# -------------------- +# Runs a special command pod, a pod that does nothing, but includes utilities for testing. +# A typical usage is a mysql pod that includes mysql commandline, that we need for testing. +# Running commands inside this command pod is done via ct_os_cmd_image_run function. +# The pod is not run again if already running. +# Arguments: image_name - image to be used as a command pod +function ct_os_deploy_cmd_image() { + local image_name=${1} + oc get pod command-app &>/dev/null && echo "command POD already running" && return 0 + echo "command POD not running yet, will start one called command-app" + oc create -f - <" + local sleep_time=3 + local attempt=1 + local result=1 + local status + local response_code + local response_file=$(mktemp /tmp/ct_test_response_XXXXXX) + local util_image_name='python:3.6' + + ct_os_deploy_cmd_image "${util_image_name}" + + while [ ${attempt} -le ${max_attempts} ]; do + ct_os_cmd_image_run "curl --connect-timeout 10 -s -w '%{http_code}' '${url}'" >${response_file} && status=0 || status=1 + if [ ${status} -eq 0 ]; then + response_code=$(cat ${response_file} | tail -c 3) + if [ "${response_code}" -eq "${expected_code}" ]; then + result=0 + fi + cat ${response_file} | grep -qP -e "${body_regexp}" || result=1; + # Some services return 40x code until they are ready, so let's give them + # some chance and not end with failure right away + # Do not wait if we already have expected outcome though + if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then + break + fi + fi + attempt=$(( ${attempt} + 1 )) + sleep ${sleep_time} + done + rm -f ${response_file} + return ${result} +} + +# ct_os_get_image_from_pod +# ------------------------ +# Print image identifier from an existing pod to stdout +# Argument: pod_prefix - prefix or full name of the pod to get image from +ct_os_get_image_from_pod() { + local pod_prefix=$1 ; shift + local pod_name=$(ct_os_get_pod_name $pod_prefix) + oc get "po/${pod_name}" -o yaml | sed -ne 's/^\s*image:\s*\(.*\)\s*$/\1/ p' | head -1 +} + +# ct_os_check_cmd_internal +# ---------------- +# Runs a specified command, checks exit code and compares the output with expected regexp. +# That all is done inside an image in the cluster, so the function is used +# typically in clusters that are not accessible outside. +# The check is repeated until timeout. +# Argument: util_image_name - name of the image in the cluster that is used for running the cmd +# Argument: service_name - kubernetes' service name to work with (IP address is taken from this one) +# Argument: check_command - command that is run within the util_image_name container +# Argument: expected_content_match - regexp that must be in the output (use .* to ignore check) +# Argument: timeout - number of seconds to wait till the check succeeds +function ct_os_check_cmd_internal() { + local util_image_name=$1 ; shift + local service_name=$1 ; shift + local check_command=$1 ; shift + local expected_content_match=${1:-.*} ; shift + local timeout=${1:-60} ; shift || : + + : " Service ${service_name} check ..." + + local output + local ret + local ip=$(ct_os_get_service_ip "${service_name}") + local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") + + ct_os_deploy_cmd_image $(ct_os_get_image_from_pod "${util_image_name}" | head -n 1) + SECONDS=0 + + echo -n "Waiting for ${service_name} service becoming ready ..." + while true ; do + output=$(ct_os_cmd_image_run "$check_command_exp") + ret=$? + echo "${output}" | grep -qe "${expected_content_match}" || ret=1 + if [ ${ret} -eq 0 ] ; then + echo " PASS" + return 0 + fi + echo -n "." + [ ${SECONDS} -gt ${timeout} ] && break + sleep 3 + done + echo " FAIL" + return 1 +} + diff --git a/test/test-lib.sh b/test/test-lib.sh index dfc63d9..e372870 100644 --- a/test/test-lib.sh +++ b/test/test-lib.sh @@ -208,6 +208,29 @@ function ct_doc_content_old() { } +# ct_npm_works +# -------------------- +# Checks existance of the npm tool and runs it. +function ct_npm_works() { + local tmpdir=$(mktemp -d) + : " Testing npm in the container image" + docker run --rm ${IMAGE_NAME} /bin/bash -c "npm --version" >${tmpdir}/version + + if [ $? -ne 0 ] ; then + echo "ERROR: 'npm --version' does not work inside the image ${IMAGE_NAME}." >&2 + return 1 + fi + + docker run --rm ${IMAGE_NAME} /bin/bash -c "npm install jquery && test -f node_modules/jquery/src/jquery.js" + if [ $? -ne 0 ] ; then + echo "ERROR: npm could not install jquery inside the image ${IMAGE_NAME}." >&2 + return 1 + fi + + : " Success!" +} + + # ct_path_append PATH_VARNAME DIRECTORY # ------------------------------------- # Append DIRECTORY to VARIABLE of name PATH_VARNAME, the VARIABLE must consist @@ -284,7 +307,7 @@ function ct_obtain_input() { local output=$(mktemp "/var/tmp/test-input-XXXXXX$extension") if [ -f "${input}" ] ; then - cp "${input}" "${output}" + cp -f "${input}" "${output}" elif [ -d "${input}" ] ; then rm -f "${output}" cp -r -LH "${input}" "${output}" @@ -400,3 +423,85 @@ ct_random_string() | fold -w "${1-10}" \ | head -n 1 ) + +# ct_s2i_usage IMG_NAME [S2I_ARGS] +# ---------------------------- +# Create a container and run the usage script inside +# Argument: IMG_NAME - name of the image to be used for the container run +# Argument: S2I_ARGS - Additional list of source-to-image arguments, currently unused. +ct_s2i_usage() +{ + local img_name=$1; shift + local s2i_args="$*"; + local usage_command="/usr/libexec/s2i/usage" + docker run --rm "$img_name" bash -c "$usage_command" +} + +# ct_s2i_build_as_df APP_PATH SRC_IMAGE DST_IMAGE [S2I_ARGS] +# ---------------------------- +# Create a new s2i app image from local sources in a similar way as source-to-image would have used. +# Argument: APP_PATH - local path to the app sources to be used in the test +# Argument: SRC_IMAGE - image to be used as a base for the s2i build +# Argument: DST_IMAGE - image name to be used during the tagging of the s2i build result +# Argument: S2I_ARGS - Additional list of source-to-image arguments. +# Only used to check for pull-policy=never and environment variable definitions. +ct_s2i_build_as_df() +{ + local app_path=$1; shift + local src_image=$1; shift + local dst_image=$1; shift + local s2i_args="$*"; + local local_app=upload/src/ + local local_scripts=upload/scripts/ + local user_id= + local df_name= + local tmpdir= + # Use /tmp to not pollute cwd + tmpdir=$(mktemp -d) + df_name=$(mktemp -p "$tmpdir" Dockerfile.XXXX) + pushd "$tmpdir" + # Check if the image is available locally and try to pull it if it is not + docker images "$src_image" &>/dev/null || echo "$s2i_args" | grep -q "pull-policy=never" || docker pull "$src_image" + user_id=$(docker inspect -f "{{.ContainerConfig.User}}" "$src_image") + # Strip file:// from APP_PATH and copy its contents into current context + mkdir -p "$local_app" + cp -r "${app_path/file:\/\//}/." "$local_app" + [ -d "$local_app/.s2i/bin/" ] && mv "$local_app/.s2i/bin" "$local_scripts" + # Create a Dockerfile named df_name and fill it with proper content + #FIXME: Some commands could be combined into a single layer but not sure if worth the trouble for testing purposes + cat <"$df_name" +FROM $src_image +LABEL "io.openshift.s2i.build.image"="$src_image" \\ + "io.openshift.s2i.build.source-location"="$app_path" +USER root +COPY $local_app /tmp/src +EOF + [ -d "$local_scripts" ] && echo "COPY $local_scripts /tmp/scripts" >> "$df_name" && + echo "RUN chown -R $user_id:0 /tmp/scripts" >>"$df_name" + echo "RUN chown -R $user_id:0 /tmp/src" >>"$df_name" + # Check for custom environment variables inside .s2i/ folder + if [ -e "$local_app/.s2i/environment" ]; then + # Remove any comments and add the contents as ENV commands to the Dockerfile + sed '/^\s*#.*$/d' "$local_app/.s2i/environment" | while read -r line; do + echo "ENV $line" >>"$df_name" + done + fi + # Filter out env var definitions from $s2i_args and create Dockerfile ENV commands out of them + echo "$s2i_args" | grep -o -e '\(-e\|--env\)[[:space:]=]\S*=\S*' | sed -e 's/-e /ENV /' -e 's/--env[ =]/ENV /' >>"$df_name" + echo "USER $user_id" >>"$df_name" + # If exists, run the custom assemble script, else default to /usr/libexec/s2i/assemble + if [ -x "$local_scripts/assemble" ]; then + echo "RUN /tmp/scripts/assemble" >>"$df_name" + else + echo "RUN /usr/libexec/s2i/assemble" >>"$df_name" + fi + # If exists, set the custom run script as CMD, else default to /usr/libexec/s2i/run + if [ -x "$local_scripts/run" ]; then + echo "CMD /tmp/scripts/run" >>"$df_name" + else + echo "CMD /usr/libexec/s2i/run" >>"$df_name" + fi + # Run the build and tag the result + docker build -f "$df_name" -t "$dst_image" . + popd +} From c24d0a19bd5116f0b465d425f3d18bbea68d6385 Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Wed, 12 Mar 2025 10:05:12 +0100 Subject: [PATCH 15/15] This container component is no longer used for anything, retiring to make it explicit. --- .gitignore | 0 2.4 | 1 - Dockerfile | 69 -- Dockerfile.fedora | 1 - README.md | 1 - bot-cfg.yml | 20 - dead.package | 1 + help.md | 1 - root/help.1 | 217 ---- root/opt/app-root/scl_enable | 3 - root/usr/bin/run-httpd | 18 - root/usr/libexec/httpd-prepare | 39 - .../share/container-scripts/httpd/README.md | 150 --- .../share/container-scripts/httpd/common.sh | 149 --- .../container-scripts/httpd/passwd.template | 15 - .../httpd/post-assemble/20-copy-config.sh | 4 - .../httpd/post-assemble/40-ssl-certs.sh | 4 - .../httpd/pre-init/10-set-mpm.sh | 3 - .../httpd/pre-init/20-copy-config.sh | 4 - .../httpd/pre-init/40-ssl-certs.sh | 4 - s2i/bin/assemble | 17 - s2i/bin/run | 7 - s2i/bin/usage | 17 - .../httpd-pre-init/modify_index.sh | 1 - test/pre-init-test-app/index.html | 1 - test/run | 297 ------ test/run-openshift | 35 - test/sample-test-app/index.html | 1 - .../certs/server-cert-selfsigned.pem | 20 - .../httpd-ssl/private/server-key.pem | 28 - test/self-signed-ssl/index.html | 1 - test/test-lib-openshift.sh | 925 ------------------ test/test-lib.sh | 507 ---------- test/utils.sh | 46 - 34 files changed, 1 insertion(+), 2606 deletions(-) delete mode 100644 .gitignore delete mode 120000 2.4 delete mode 100644 Dockerfile delete mode 120000 Dockerfile.fedora delete mode 120000 README.md delete mode 100644 bot-cfg.yml create mode 100644 dead.package delete mode 120000 help.md delete mode 100644 root/help.1 delete mode 100644 root/opt/app-root/scl_enable delete mode 100755 root/usr/bin/run-httpd delete mode 100755 root/usr/libexec/httpd-prepare delete mode 100644 root/usr/share/container-scripts/httpd/README.md delete mode 100644 root/usr/share/container-scripts/httpd/common.sh delete mode 100644 root/usr/share/container-scripts/httpd/passwd.template delete mode 100644 root/usr/share/container-scripts/httpd/post-assemble/20-copy-config.sh delete mode 100644 root/usr/share/container-scripts/httpd/post-assemble/40-ssl-certs.sh delete mode 100644 root/usr/share/container-scripts/httpd/pre-init/10-set-mpm.sh delete mode 100644 root/usr/share/container-scripts/httpd/pre-init/20-copy-config.sh delete mode 100644 root/usr/share/container-scripts/httpd/pre-init/40-ssl-certs.sh delete mode 100755 s2i/bin/assemble delete mode 100755 s2i/bin/run delete mode 100755 s2i/bin/usage delete mode 100644 test/pre-init-test-app/httpd-pre-init/modify_index.sh delete mode 100644 test/pre-init-test-app/index.html delete mode 100755 test/run delete mode 100755 test/run-openshift delete mode 100644 test/sample-test-app/index.html delete mode 100644 test/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem delete mode 100644 test/self-signed-ssl/httpd-ssl/private/server-key.pem delete mode 100644 test/self-signed-ssl/index.html delete mode 100644 test/test-lib-openshift.sh delete mode 100644 test/test-lib.sh delete mode 100755 test/utils.sh diff --git a/.gitignore b/.gitignore deleted file mode 100644 index e69de29..0000000 diff --git a/2.4 b/2.4 deleted file mode 120000 index 945c9b4..0000000 --- a/2.4 +++ /dev/null @@ -1 +0,0 @@ -. \ No newline at end of file diff --git a/Dockerfile b/Dockerfile deleted file mode 100644 index 1f47576..0000000 --- a/Dockerfile +++ /dev/null @@ -1,69 +0,0 @@ -FROM registry.fedoraproject.org/f30/s2i-core:latest - -# Apache HTTP Server image. -# -# Volumes: -# * /var/www - Datastore for httpd -# * /var/log/httpd - Storage for logs when $HTTPD_LOG_TO_VOLUME is set -# Environment: -# * $HTTPD_LOG_TO_VOLUME (optional) - When set, httpd will log into /var/log/httpd - -ENV HTTPD_VERSION=2.4 \ - NAME=httpd \ - ARCH=x86_64 - -ENV SUMMARY="Platform for running Apache httpd $HTTPD_VERSION or building httpd-based application" \ - DESCRIPTION="Apache httpd $HTTPD_VERSION available as container, is a powerful, efficient, \ -and extensible web server. Apache supports a variety of features, many implemented as compiled modules \ -which extend the core functionality. \ -These can range from server-side programming language support to authentication schemes. \ -Virtual hosting allows one Apache installation to serve many different Web sites." - -LABEL summary="$SUMMARY" \ - description="$DESCRIPTION" \ - io.k8s.description="$SUMMARY" \ - io.k8s.display-name="Apache httpd $HTTPD_VERSION" \ - io.openshift.expose-services="8080:http,8443:https" \ - io.openshift.tags="builder,httpd,httpd24" \ - com.redhat.component="$NAME" \ - name="$FGC/$NAME" \ - version="$HTTPD_VERSION" \ - usage="s2i build https://github.com/sclorg/httpd-container.git --context-dir=examples/sample-test-app/ $FGC/$NAME sample-server" \ - maintainer="SoftwareCollections.org " - -EXPOSE 8080 -EXPOSE 8443 - -RUN dnf install -y yum-utils gettext hostname && \ - INSTALL_PKGS="nss_wrapper bind-utils httpd mod_ssl" && \ - dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \ - rpm -V $INSTALL_PKGS && \ - dnf clean all - -ENV HTTPD_CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/httpd/ \ - HTTPD_APP_ROOT=${APP_ROOT} \ - HTTPD_CONFIGURATION_PATH=${APP_ROOT}/etc/httpd.d \ - HTTPD_MAIN_CONF_PATH=/etc/httpd/conf \ - HTTPD_MAIN_CONF_MODULES_D_PATH=/etc/httpd/conf.modules.d \ - HTTPD_MAIN_CONF_D_PATH=/etc/httpd/conf.d \ - HTTPD_VAR_RUN=/var/run/httpd \ - HTTPD_DATA_PATH=/var/www \ - HTTPD_DATA_ORIG_PATH=/var/www \ - HTTPD_LOG_PATH=/var/log/httpd - -COPY ./s2i/bin/ $STI_SCRIPTS_PATH -COPY ./root / - -# Generate SSL certs and reset permissions of filesystem to default values -# Reset permissions of filesystem to default values -RUN /usr/libexec/httpd-ssl-gencerts && \ - /usr/libexec/httpd-prepare && rpm-file-permissions - -USER 1001 - -# Not using VOLUME statement since it's not working in OpenShift Online: -# https://github.com/sclorg/httpd-container/issues/30 -# VOLUME ["${HTTPD_DATA_PATH}"] -# VOLUME ["${HTTPD_LOG_PATH}"] - -CMD ["/usr/bin/run-httpd"] diff --git a/Dockerfile.fedora b/Dockerfile.fedora deleted file mode 120000 index 1d1fe94..0000000 --- a/Dockerfile.fedora +++ /dev/null @@ -1 +0,0 @@ -Dockerfile \ No newline at end of file diff --git a/README.md b/README.md deleted file mode 120000 index 299cf2b..0000000 --- a/README.md +++ /dev/null @@ -1 +0,0 @@ -root/usr/share/container-scripts/httpd/README.md \ No newline at end of file diff --git a/bot-cfg.yml b/bot-cfg.yml deleted file mode 100644 index 0a03762..0000000 --- a/bot-cfg.yml +++ /dev/null @@ -1,20 +0,0 @@ ---- -version: "1" - -betka: - # is betka enabled for this repository - # optional - defaults to true - enabled: true - notifications: - email_addresses: ["pkubat@redhat.com", "phracek@redhat.com", "hhorak@redhat.com"] - - # Specify if master branch in upstream repository is synced - master_checker: true - # Should pull requests be synced? - pr_checker: false - # Path to directory with dockerfile withing upstream repository - upstream_git_path: "2.4" - # Github comment message to enforce sync of a pull request - pr_comment_message: "[test]" - # Specify URL to an image used for dist-git source generation. Like - image_url: "quay.io/rhscl/cwt-generator" diff --git a/dead.package b/dead.package new file mode 100644 index 0000000..2e10e65 --- /dev/null +++ b/dead.package @@ -0,0 +1 @@ +This container component is no longer used for anything, retiring to make it explicit. diff --git a/help.md b/help.md deleted file mode 120000 index 42061c0..0000000 --- a/help.md +++ /dev/null @@ -1 +0,0 @@ -README.md \ No newline at end of file diff --git a/root/help.1 b/root/help.1 deleted file mode 100644 index ddf8343..0000000 --- a/root/help.1 +++ /dev/null @@ -1,217 +0,0 @@ -.TH Apache HTTP Server 2.4 Container Image -.PP -This container image includes Apache HTTP Server 2.4 for OpenShift and general usage. -Users can choose between RHEL, CentOS and Fedora based images. -The RHEL image is available in the Red Hat Container Catalog -\[la]https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/httpd-24-rhel7\[ra] -as registry.access.redhat.com/rhscl/httpd\-24\-rhel7. -The CentOS image is then available on Docker Hub -\[la]https://hub.docker.com/r/centos/httpd-24-centos7/\[ra] -as centos/httpd\-24\-centos7. - -.SH Description -.PP -Apache HTTP Server 2.4 available as container, is a powerful, efficient, -and extensible web server. Apache supports a variety of features, many implemented as compiled modules -which extend the core functionality. -These can range from server\-side programming language support to authentication schemes. -Virtual hosting allows one Apache installation to serve many different Web sites." - -.SH Usage -.PP -For this, we will assume that you are using the Apache HTTP Server 2.4 container image from the -Red Hat Container Catalog called \fB\fCrhscl/httpd\-24\-rhel7\fR\&. -The image can be used as a base image for other applications based on Apache HTTP web server. - -.PP -An example of the data on the host for both the examples above, that will be served by -Apache HTTP web server: - -.PP -.RS - -.nf -$ ls \-lZ /wwwdata/html -\-rw\-r\-\-r\-\-. 1 1001 1001 54321 Jan 01 12:34 index.html -\-rw\-r\-\-r\-\-. 1 1001 1001 5678 Jan 01 12:34 page.html - -.fi -.RE - -.PP -If you want to run the image and mount the static pages available in \fB\fC/wwwdata\fR on the host -as a container volume, execute the following command: - -.PP -.RS - -.nf -$ docker run \-d \-\-name httpd \-p 8080:8080 \-v /wwwdata:/var/www:Z rhscl/httpd\-24\-rhel7 - -.fi -.RE - -.PP -This will create a container named \fB\fChttpd\fR running Apache HTTP Server, serving data from -\fB\fC/wwwdata\fR directory. Port 8080 will be exposed and mapped to the host. - -.PP -If you want to create a new container layered image, use Source\-to\-Image -\[la]https://github.com/openshift/source-to-image\[ra], a tool for building/building artifacts from source and injecting into container images. To create a new container image named \fB\fChttpd\-app\fR using Source\-to\-Image, while using data available in \fB\fC/wwwdata\fR on the host, execute the following command: - -.PP -.RS - -.nf -$ s2i build file:///wwwdata/html rhscl/httpd\-24\-rhel7 httpd\-app - -.fi -.RE - -.PP -To run such a new image, execute the following command: - -.PP -.RS - -.nf -$ docker run \-d \-\-name httpd \-p 8080:8080 httpd\-app - -.fi -.RE - -.PP -The structure of httpd\-app can look like this: - -.PP -\fB\fB\fC\&./httpd\-\&cfg\fR\fP -.br - Can contain additional Apache configuration files (\fB\fC*.conf\fR) - -.PP -\fB\fB\fC\&./httpd\-\&pre\-\&init\fR\fP -.br - Can contain shell scripts (\fB\fC*.sh\fR) that are sourced before \fB\fChttpd\fR is started - -.PP -\fB\fB\fC\&./httpd\-\&ssl\fR\fP -.br - Can contain own SSL certificate (in \fB\fCcerts/\fR subdirectory) and key (in \fB\fCprivate/\fR subdirectory) - -.PP -\fB\fB\fC\&./\fR\fP -.br - Application source code - -.SH Environment variables and volumes -.PP -The Apache HTTP Server container image supports the following configuration variable, which can be set by using the \fB\fC\-e\fR option with the docker run command: - -.PP -\fB\fB\fCHTTPD\_LOG\_TO\_VOLUME\fR\fP -.br - By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When \fB\fCHTTPD\_LOG\_TO\_VOLUME\fR is set, httpd logs into \fB\fC/var/log/httpd24\fR, which can be mounted to host system using the container volumes. This option is only allowed when container is run as UID 0. - -.PP -\fB\fB\fCHTTPD\_MPM\fR\fP - The variable \fB\fCHTTPD\_MPM\fR can be set to change the default Multi\-Processing Module (MPM) from the package default MPM. - -.PP -If you want to run the image and mount the log files into \fB\fC/wwwlogs\fR on the host -as a container volume, execute the following command: - -.PP -.RS - -.nf -$ docker run \-d \-u 0 \-e HTTPD\_LOG\_TO\_VOLUME=1 \-\-name httpd \-v /wwwlogs:/var/log/httpd24:Z rhscl/httpd\-24\-rhel7 - -.fi -.RE - -.PP -To run an image using the \fB\fCevent\fR MPM (rather than the default \fB\fCprefork\fR), execute the following command: - -.PP -.RS - -.nf -$ docker run \-d \-e HTTPD\_MPM=event \-\-name httpd rhscl/httpd\-24\-rhel7 - -.fi -.RE - -.PP -You can also set the following mount points by passing the \fB\fC\-v /host:/container\fR flag to Docker. - -.PP -\fB\fB\fC/var/www\fR\fP -.br - Apache HTTP Server data directory - -.PP -\fB\fB\fC/var/log/httpd24\fR\fP -.br - Apache HTTP Server log directory (available only when running as root, path \fB\fC/var/log/httpd\fR is used in case of Fedora based image) - -.PP -\fBNotice: When mouting a directory from the host into the container, ensure that the mounted -directory has the appropriate permissions and that the owner and group of the directory -matches the user UID or name which is running inside the container.\fP - -.SH Using own SSL certificates -.PP -In order to provide own SSL certificates for securing the connection with SSL, use the extending feature described above. In particular, put the SSL certificates into a separate directory inside your application: - -.PP -.RS - -.nf -\&./httpd\-\&ssl/certs/server\-\&cert\-\&selfsigned.pem -./httpd\-\&ssl/private/server\-\&key.pem - -.fi -.RE - -.PP -The default behaviour is to look for the certificate and the private key in subdirectories certs/ and private/; those files will be used for the ssl settings in the httpd. - -.SH Default user -.PP -By default, Apache HTTP Server container runs as UID 1001. That means the volume mounted directories for the files (if mounted using \fB\fC\-v\fR option) need to be prepared properly, so the UID 1001 can read them. - -.PP -To run the container as a different UID, use \fB\fC\-u\fR option. For example if you want to run the container as UID 1234, execute the following command: - -.PP -.RS - -.nf -docker run \-d \-u 1234 rhscl/httpd\-24\-rhel7 - -.fi -.RE - -.PP -To log into a volume mounted directory, the container needs to be run as UID 0 (see above). - -.SH Troubleshooting -.PP -The httpd deamon in the container logs to the standard output by default, so the log is available in the container log. The log can be examined by running: - -.PP -.RS - -.nf -docker logs - -.fi -.RE - -.SH See also -.PP -Dockerfile and other sources for this container image are available on - -\[la]https://github.com/sclorg/httpd-container\[ra]\&. -In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile -for RHEL is called Dockerfile.rhel7 and Dockerfile for Fedora is called Dockerfile.fedora. diff --git a/root/opt/app-root/scl_enable b/root/opt/app-root/scl_enable deleted file mode 100644 index 373330d..0000000 --- a/root/opt/app-root/scl_enable +++ /dev/null @@ -1,3 +0,0 @@ -# This will make scl collection binaries work out of box. -unset BASH_ENV PROMPT_COMMAND ENV -source scl_source enable httpd24 diff --git a/root/usr/bin/run-httpd b/root/usr/bin/run-httpd deleted file mode 100755 index e03578f..0000000 --- a/root/usr/bin/run-httpd +++ /dev/null @@ -1,18 +0,0 @@ -#!/bin/bash - -set -eu - -source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh - -# Check whether we run as s2i -if ! [ -v HTTPD_RUN_BY_S2I ] && runs_privileged ; then - config_privileged -else - # We run as non-root or as s2i - config_non_privileged - generate_container_user -fi - -process_extending_files ${HTTPD_APP_ROOT}/src/httpd-pre-init/ ${HTTPD_CONTAINER_SCRIPTS_PATH}/pre-init/ - -exec httpd -D FOREGROUND $@ diff --git a/root/usr/libexec/httpd-prepare b/root/usr/libexec/httpd-prepare deleted file mode 100755 index e2857da..0000000 --- a/root/usr/libexec/httpd-prepare +++ /dev/null @@ -1,39 +0,0 @@ -#!/bin/bash - -set -e - -source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh - -# compatibility symlinks so we hide SCL paths -if [ -v HTTPD_SCL ] ; then - # /opt/rh/httpd24/root/etc/httpd will be symlink to /etc/httpd - mv /opt/rh/httpd24/root/etc/httpd /etc/httpd - ln -s /etc/httpd /opt/rh/httpd24/root/etc/httpd - - # /opt/rh/httpd24/root/var/run/httpd will be symlink to /var/run/httpd - mv /opt/rh/httpd24/root/var/run/httpd /var/run/httpd - ln -s /var/run/httpd /opt/rh/httpd24/root/var/run/httpd - - # /opt/rh/httpd24/root/var/www will be symlink to /var/www - rm -rf /var/www - mv /opt/rh/httpd24/root/var/www /var/www - ln -s /var/www /opt/rh/httpd24/root/var/www -fi - -mkdir -p ${HTTPD_CONFIGURATION_PATH} -chmod -R a+rwx ${HTTPD_MAIN_CONF_PATH} -chmod -R a+rwx ${HTTPD_MAIN_CONF_D_PATH} -chmod -R a+rwx ${HTTPD_MAIN_CONF_MODULES_D_PATH} -chmod -R a+r /etc/pki/tls/certs/localhost.crt -chmod -R a+r /etc/pki/tls/private/localhost.key -mkdir -p ${HTTPD_APP_ROOT}/etc -chmod -R a+rwx ${HTTPD_APP_ROOT}/etc -chmod -R a+rwx ${HTTPD_VAR_RUN} -chown -R 1001:0 ${HTTPD_APP_ROOT} -chown -R 1001:0 ${HTTPD_DATA_PATH} -chown -R 1001:0 ${HTTPD_LOG_PATH} - -mkdir -p ${HTTPD_CONTAINER_SCRIPTS_PATH}/pre-init - -config_general - diff --git a/root/usr/share/container-scripts/httpd/README.md b/root/usr/share/container-scripts/httpd/README.md deleted file mode 100644 index 99eceed..0000000 --- a/root/usr/share/container-scripts/httpd/README.md +++ /dev/null @@ -1,150 +0,0 @@ -Apache HTTP Server 2.4 Container Image -====================== - -This container image includes Apache HTTP Server 2.4 for OpenShift and general usage. -Users can choose between RHEL, CentOS and Fedora based images. -The RHEL image is available in the [Red Hat Container Catalog](https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/httpd-24-rhel7) -as registry.access.redhat.com/rhscl/httpd-24-rhel7. -The CentOS image is then available on [Docker Hub](https://hub.docker.com/r/centos/httpd-24-centos7/) -as centos/httpd-24-centos7. - - -Description ------------ - -Apache HTTP Server 2.4 available as container, is a powerful, efficient, -and extensible web server. Apache supports a variety of features, many implemented as compiled modules -which extend the core functionality. -These can range from server-side programming language support to authentication schemes. -Virtual hosting allows one Apache installation to serve many different Web sites." - - -Usage ------ - -For this, we will assume that you are using the Apache HTTP Server 2.4 container image from the -Red Hat Container Catalog called `rhscl/httpd-24-rhel7`. -The image can be used as a base image for other applications based on Apache HTTP web server. - -An example of the data on the host for both the examples above, that will be served by -Apache HTTP web server: - -``` -$ ls -lZ /wwwdata/html --rw-r--r--. 1 1001 1001 54321 Jan 01 12:34 index.html --rw-r--r--. 1 1001 1001 5678 Jan 01 12:34 page.html -``` - -If you want to run the image and mount the static pages available in `/wwwdata` on the host -as a container volume, execute the following command: - -``` -$ docker run -d --name httpd -p 8080:8080 -v /wwwdata:/var/www:Z rhscl/httpd-24-rhel7 -``` - -This will create a container named `httpd` running Apache HTTP Server, serving data from -`/wwwdata` directory. Port 8080 will be exposed and mapped to the host. - -If you want to create a new container layered image, use [Source-to-Image](https://github.com/openshift/source-to-image), a tool for building/building artifacts from source and injecting into container images. To create a new container image named `httpd-app` using Source-to-Image, while using data available in `/wwwdata` on the host, execute the following command: - -``` -$ s2i build file:///wwwdata/html rhscl/httpd-24-rhel7 httpd-app -``` - -To run such a new image, execute the following command: - -``` -$ docker run -d --name httpd -p 8080:8080 httpd-app -``` - -The structure of httpd-app can look like this: - -**`./httpd-cfg`** - Can contain additional Apache configuration files (`*.conf`) - -**`./httpd-pre-init`** - Can contain shell scripts (`*.sh`) that are sourced before `httpd` is started - -**`./httpd-ssl`** - Can contain own SSL certificate (in `certs/` subdirectory) and key (in `private/` subdirectory) - -**`./`** - Application source code - - -Environment variables and volumes ---------------------------------- - -The Apache HTTP Server container image supports the following configuration variable, which can be set by using the `-e` option with the docker run command: - -**`HTTPD_LOG_TO_VOLUME`** - By default, httpd logs into standard output, so the logs are accessible by using the docker logs command. When `HTTPD_LOG_TO_VOLUME` is set, httpd logs into `/var/log/httpd24`, which can be mounted to host system using the container volumes. This option is only allowed when container is run as UID 0. - -**`HTTPD_MPM`** - The variable `HTTPD_MPM` can be set to change the default Multi-Processing Module (MPM) from the package default MPM. - - -If you want to run the image and mount the log files into `/wwwlogs` on the host -as a container volume, execute the following command: - -``` -$ docker run -d -u 0 -e HTTPD_LOG_TO_VOLUME=1 --name httpd -v /wwwlogs:/var/log/httpd24:Z rhscl/httpd-24-rhel7 -``` - -To run an image using the `event` MPM (rather than the default `prefork`), execute the following command: - -``` -$ docker run -d -e HTTPD_MPM=event --name httpd rhscl/httpd-24-rhel7 -``` - -You can also set the following mount points by passing the `-v /host:/container` flag to Docker. - -**`/var/www`** - Apache HTTP Server data directory - -**`/var/log/httpd24`** - Apache HTTP Server log directory (available only when running as root, path `/var/log/httpd` is used in case of Fedora based image) - - -**Notice: When mouting a directory from the host into the container, ensure that the mounted -directory has the appropriate permissions and that the owner and group of the directory -matches the user UID or name which is running inside the container.** - - -Using own SSL certificates --------------------------- -In order to provide own SSL certificates for securing the connection with SSL, use the extending feature described above. In particular, put the SSL certificates into a separate directory inside your application: - - ./httpd-ssl/certs/server-cert-selfsigned.pem - ./httpd-ssl/private/server-key.pem - -The default behaviour is to look for the certificate and the private key in subdirectories certs/ and private/; those files will be used for the ssl settings in the httpd. - - -Default user ------------- - -By default, Apache HTTP Server container runs as UID 1001. That means the volume mounted directories for the files (if mounted using `-v` option) need to be prepared properly, so the UID 1001 can read them. - -To run the container as a different UID, use `-u` option. For example if you want to run the container as UID 1234, execute the following command: - -``` -docker run -d -u 1234 rhscl/httpd-24-rhel7 -``` - -To log into a volume mounted directory, the container needs to be run as UID 0 (see above). - - -Troubleshooting ---------------- -The httpd deamon in the container logs to the standard output by default, so the log is available in the container log. The log can be examined by running: - - docker logs - - -See also --------- -Dockerfile and other sources for this container image are available on -https://github.com/sclorg/httpd-container. -In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile -for RHEL is called Dockerfile.rhel7 and Dockerfile for Fedora is called Dockerfile.fedora. diff --git a/root/usr/share/container-scripts/httpd/common.sh b/root/usr/share/container-scripts/httpd/common.sh deleted file mode 100644 index 1cdeee9..0000000 --- a/root/usr/share/container-scripts/httpd/common.sh +++ /dev/null @@ -1,149 +0,0 @@ -# Set of functions used in other scripts - -config_general() { - sed -i -e 's/^Listen 80/Listen 0.0.0.0:8080/' ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \ - sed -i -e '151s%AllowOverride None%AllowOverride All%' ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \ - sed -i -e 's/^Listen 443/Listen 0.0.0.0:8443/' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf - sed -i -e 's/_default_:443/_default_:8443/' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf -} - -config_log_to_stdout() { - sed -ri " s!^(\s*CustomLog)\s+\S+!\1 |/usr/bin/cat!g; s!^(\s*ErrorLog)\s+\S+!\1 |/usr/bin/cat!g;" ${HTTPD_MAIN_CONF_PATH}/httpd.conf - sed -ri " s!^(\s*CustomLog)\s+\S+!\1 |/usr/bin/cat!g; s!^(\s*TransferLog)\s+\S+!\1 |/usr/bin/cat!g; s!^(\s*ErrorLog)\s+\S+!\1 |/usr/bin/cat!g;" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf -} - -runs_privileged() { - test "$(id -u)" == "0" - return $? -} - -config_privileged() { - # Change the s2i permissions back to the normal ones - chmod 644 ${HTTPD_MAIN_CONF_PATH}/* && \ - chmod 755 ${HTTPD_MAIN_CONF_PATH} && \ - chmod 644 ${HTTPD_MAIN_CONF_D_PATH}/* && \ - chmod 755 ${HTTPD_MAIN_CONF_D_PATH} && \ - chmod 644 ${HTTPD_MAIN_CONF_MODULES_D_PATH}/* && \ - chmod 755 ${HTTPD_MAIN_CONF_MODULES_D_PATH} && \ - chmod 600 /etc/pki/tls/certs/localhost.crt && \ - chmod 600 /etc/pki/tls/private/localhost.key && \ - chmod 710 ${HTTPD_VAR_RUN} - - if ! [ -v HTTPD_LOG_TO_VOLUME ] ; then - config_log_to_stdout - fi -} - -config_s2i() { - sed -i -e "s%^DocumentRoot \"${HTTPD_DATA_ORIG_PATH}/html\"%DocumentRoot \"${HTTPD_APP_ROOT}/src\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf - sed -i -e "s%^> ${HTTPD_MAIN_CONF_PATH}/httpd.conf && \ - head -n151 ${HTTPD_MAIN_CONF_PATH}/httpd.conf | tail -n1 | grep "AllowOverride All" || exit -} - -config_non_privileged() { - sed -i -e "s/^User apache/User default/" ${HTTPD_MAIN_CONF_PATH}/httpd.conf - sed -i -e "s/^Group apache/Group root/" ${HTTPD_MAIN_CONF_PATH}/httpd.conf - config_log_to_stdout - if [ -v HTTPD_LOG_TO_VOLUME ] ; then - echo "Error: Option HTTPD_LOG_TO_VOLUME is only valid for privileged runs (as UID 0)." - return 1 - fi -} - -config_mpm() { - if [ -v HTTPD_MPM -a -f ${HTTPD_MAIN_CONF_MODULES_D_PATH}/00-mpm.conf ]; then - local mpmconf=${HTTPD_MAIN_CONF_MODULES_D_PATH}/00-mpm.conf - sed -i -e 's,^LoadModule,#LoadModule,' ${mpmconf} - sed -i -e "/LoadModule mpm_${HTTPD_MPM}/s,^#LoadModule,LoadModule," ${mpmconf} - echo "---> Set MPM to ${HTTPD_MPM} in ${mpmconf}" - fi -} - -# get_matched_files finds file for image extending -function get_matched_files() { - local custom_dir default_dir - custom_dir="$1" - default_dir="$2" - files_matched="$3" - find "$default_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n" - [ -d "$custom_dir" ] && find "$custom_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n" -} - -# process_extending_files process extending files in $1 and $2 directories -# - source all *.sh files -# (if there are files with same name source only file from $1) -function process_extending_files() { - local custom_dir default_dir - custom_dir=$1 - default_dir=$2 - while read filename ; do - echo "=> sourcing $filename ..." - # Custom file is prefered - if [ -f $custom_dir/$filename ]; then - source $custom_dir/$filename - elif [ -f $default_dir/$filename ]; then - source $default_dir/$filename - fi - done <<<"$(get_matched_files "$custom_dir" "$default_dir" '*.sh' | sort -u)" -} - -# Set current user in nss_wrapper -generate_container_user() { - local passwd_output_dir="${HTTPD_APP_ROOT}/etc" - - export USER_ID=$(id -u) - export GROUP_ID=$(id -g) - envsubst < ${HTTPD_CONTAINER_SCRIPTS_PATH}/passwd.template > ${passwd_output_dir}/passwd - export LD_PRELOAD=libnss_wrapper.so - export NSS_WRAPPER_PASSWD=${passwd_output_dir}/passwd - export NSS_WRAPPER_GROUP=/etc/group -} - -# Copy config files from application to the location where httd expects them -# Param sets the directory where to look for files -process_config_files() { - local dir=${1:-.} - if [ -d ${dir}/httpd-cfg ]; then - echo "---> Copying httpd configuration files..." - if [ "$(ls -A ${dir}/httpd-cfg/*.conf)" ]; then - cp -v ${dir}/httpd-cfg/*.conf "${HTTPD_CONFIGURATION_PATH}" - rm -rf ${dir}/httpd-cfg - fi - else - if [ -d ${dir}/cfg ]; then - echo "---> Copying httpd configuration files from deprecated './cfg' directory, use './httpd-cfg' instead..." - if [ "$(ls -A ${dir}/cfg/*.conf)" ]; then - cp -v ${dir}/cfg/*.conf "${HTTPD_CONFIGURATION_PATH}" - rm -rf ${dir}/cfg - fi - fi - fi -} - -# Copy SSL files provided in application source -process_ssl_certs() { - local dir=${1:-.} - if [ -d ${dir}/httpd-ssl/private ] && [ -d ${dir}/httpd-ssl/certs ]; then - echo "---> Moving the httpd-ssl directory included in the source to a directory that isn't exposed by httpd..." - mv ${dir}/httpd-ssl ${HTTPD_APP_ROOT} - fi - if [ -d ${HTTPD_APP_ROOT}/httpd-ssl/private ] && [ -d ${HTTPD_APP_ROOT}/httpd-ssl/certs ]; then - echo "---> Looking for SSL certs for httpd..." - local ssl_cert="$(ls -A ${HTTPD_APP_ROOT}/httpd-ssl/certs/*.pem | head -n 1)" - local ssl_private="$(ls -A ${HTTPD_APP_ROOT}/httpd-ssl/private/*.pem | head -n 1)" - if [ -f "${ssl_cert}" ] ; then - # do sed for SSLCertificateFile and SSLCertificateKeyFile - echo "---> Setting SSL cert file for httpd..." - sed -i -e "s|^SSLCertificateFile .*$|SSLCertificateFile ${ssl_cert}|" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf - if [ -f "${ssl_private}" ]; then - echo "---> Setting SSL key file for httpd..." - sed -i -e "s|^SSLCertificateKeyFile .*$|SSLCertificateKeyFile ${ssl_private}|" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf - else - echo "---> Removing SSL key file settings for httpd..." - sed -i '/^SSLCertificateKeyFile .*/d' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf - fi - fi - fi -} - diff --git a/root/usr/share/container-scripts/httpd/passwd.template b/root/usr/share/container-scripts/httpd/passwd.template deleted file mode 100644 index 7ad0b78..0000000 --- a/root/usr/share/container-scripts/httpd/passwd.template +++ /dev/null @@ -1,15 +0,0 @@ -root:x:0:0:root:/root:/bin/bash -bin:x:1:1:bin:/bin:/sbin/nologin -daemon:x:2:2:daemon:/sbin:/sbin/nologin -adm:x:3:4:adm:/var/adm:/sbin/nologin -lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin -sync:x:5:0:sync:/sbin:/bin/sync -shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown -halt:x:7:0:halt:/sbin:/sbin/halt -mail:x:8:12:mail:/var/spool/mail:/sbin/nologin -operator:x:11:0:operator:/root:/sbin/nologin -games:x:12:100:games:/usr/games:/sbin/nologin -ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin -nobody:x:99:99:Nobody:/:/sbin/nologin -default:x:${USER_ID}:${GROUP_ID}:Default Application User:${HOME}:/sbin/nologin -apache:x:48:48:Apache:/usr/share/httpd:/sbin/nologin diff --git a/root/usr/share/container-scripts/httpd/post-assemble/20-copy-config.sh b/root/usr/share/container-scripts/httpd/post-assemble/20-copy-config.sh deleted file mode 100644 index 2fd03c7..0000000 --- a/root/usr/share/container-scripts/httpd/post-assemble/20-copy-config.sh +++ /dev/null @@ -1,4 +0,0 @@ -source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh - -# Copy config files from application to the location where httpd expects them -process_config_files diff --git a/root/usr/share/container-scripts/httpd/post-assemble/40-ssl-certs.sh b/root/usr/share/container-scripts/httpd/post-assemble/40-ssl-certs.sh deleted file mode 100644 index cbad2c3..0000000 --- a/root/usr/share/container-scripts/httpd/post-assemble/40-ssl-certs.sh +++ /dev/null @@ -1,4 +0,0 @@ -source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh - -# Copy SSL files provided in application source -process_ssl_certs diff --git a/root/usr/share/container-scripts/httpd/pre-init/10-set-mpm.sh b/root/usr/share/container-scripts/httpd/pre-init/10-set-mpm.sh deleted file mode 100644 index f7de495..0000000 --- a/root/usr/share/container-scripts/httpd/pre-init/10-set-mpm.sh +++ /dev/null @@ -1,3 +0,0 @@ -source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh - -config_mpm diff --git a/root/usr/share/container-scripts/httpd/pre-init/20-copy-config.sh b/root/usr/share/container-scripts/httpd/pre-init/20-copy-config.sh deleted file mode 100644 index f7ce08b..0000000 --- a/root/usr/share/container-scripts/httpd/pre-init/20-copy-config.sh +++ /dev/null @@ -1,4 +0,0 @@ -source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh - -# Copy config files from application to the location where httd expects them -process_config_files ${HTTPD_APP_ROOT}/src diff --git a/root/usr/share/container-scripts/httpd/pre-init/40-ssl-certs.sh b/root/usr/share/container-scripts/httpd/pre-init/40-ssl-certs.sh deleted file mode 100644 index 38bc8cf..0000000 --- a/root/usr/share/container-scripts/httpd/pre-init/40-ssl-certs.sh +++ /dev/null @@ -1,4 +0,0 @@ -source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh - -# Copy SSL files provided in application source -process_ssl_certs ${HTTPD_APP_ROOT}/src diff --git a/s2i/bin/assemble b/s2i/bin/assemble deleted file mode 100755 index d8b61ee..0000000 --- a/s2i/bin/assemble +++ /dev/null @@ -1,17 +0,0 @@ -#!/bin/bash - -set -e - -source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh - -echo "---> Enabling s2i support in httpd24 image" - -config_s2i - -echo "---> Installing application source" -cp -Rf /tmp/src/. ./ - -process_extending_files ${HTTPD_APP_ROOT}/src/httpd-post-assemble/ ${HTTPD_CONTAINER_SCRIPTS_PATH}/post-assemble/ - -# Fix source directory permissions -fix-permissions ./ diff --git a/s2i/bin/run b/s2i/bin/run deleted file mode 100755 index f8f8aa3..0000000 --- a/s2i/bin/run +++ /dev/null @@ -1,7 +0,0 @@ -#!/bin/bash - -source ${HTTPD_CONTAINER_SCRIPTS_PATH}/common.sh - -export HTTPD_RUN_BY_S2I=1 - -exec run-httpd $@ diff --git a/s2i/bin/usage b/s2i/bin/usage deleted file mode 100755 index 69ed8de..0000000 --- a/s2i/bin/usage +++ /dev/null @@ -1,17 +0,0 @@ -#!/bin/sh - -DISTRO=`cat /etc/*-release | grep ^ID= | grep -Po '".*?"' | tr -d '"'` -NAMESPACE=centos -[[ $DISTRO =~ rhel* ]] && NAMESPACE=rhscl - -cat < ${HTTPD_APP_ROOT}/src/index.html diff --git a/test/pre-init-test-app/index.html b/test/pre-init-test-app/index.html deleted file mode 100644 index 38f417d..0000000 --- a/test/pre-init-test-app/index.html +++ /dev/null @@ -1 +0,0 @@ -This is a sample s2i application with static content. diff --git a/test/run b/test/run deleted file mode 100755 index d73bc3b..0000000 --- a/test/run +++ /dev/null @@ -1,297 +0,0 @@ -#!/usr/bin/env bash - -set -e -IMAGE_NAME="${IMAGE_NAME:-rhscl/httpd-24-rhel7}" - -THISDIR=$(dirname ${BASH_SOURCE[0]}) -. ${THISDIR}/utils.sh -test_dir="$(readlink -zf $(dirname "${BASH_SOURCE[0]}"))" - -. "$test_dir/test-lib.sh" - -function _container_is_scl() { - docker inspect --format='{{.ContainerConfig.Env}}' "${1-$IMAGE_NAME}" | grep -q HTTPD_SCL - return $? -} - -function create_container() { - local name="$1" ; shift - local image="${1-$IMAGE_NAME}" - [ -n "$1" ] && shift - cidfile="$CIDFILE_DIR/$name" - # create container with a cidfile in a directory for cleanup - docker run ${DOCKER_ARGS:-} --cidfile $cidfile -d $image || return 1 - echo docker run ${DOCKER_ARGS:-} --cidfile $cidfile -d $image - echo "Created container $(cat $cidfile)" -} - -function update_overall() { - res="$1" - if [ "$res" != 0 ]; then - overall="$res" - fi -} - -function get_cid() { - local id="$1" ; shift || return 1 - echo $(cat "$CIDFILE_DIR/$id") -} - -function get_container_ip() { - local id="$1" ; shift - docker inspect --format='{{.NetworkSettings.IPAddress}}' $(get_cid "$id") -} - -function rm_container() { - local name="$1" - local cid="`get_cid $name`" - docker kill "$cid" || : - docker rm "$cid" - rm -f "$CIDFILE_DIR/$name" -} - -function run() { - cmd="$1" - expected_res="${2:-0}" - msg="${3:-Running command '$cmd'}" - set +e - run_command "$cmd" "$expected_res" "$msg" - res=$? - set -e - test "$res" -eq "$expected_res" && res=0 || res=1 - update_overall $res - return $res -} - - -function _check_test_page() { - run "curl ${1}:8080 > output" - if ! run "fgrep -e 'Test Page for the Apache HTTP Server on' output" ; then - cat output - return 1 - fi -} - -function run_default_page_test() { - # Check default page - run "create_container test_default_page" - sleep 2 - cip=$(get_container_ip 'test_default_page') - _check_test_page ${cip} -} - -function run_as_root_test() { - # Try running as root - DOCKER_ARGS="--user 0" - run "create_container test_run_as_root" - DOCKER_ARGS= - sleep 2 - cip=$(get_container_ip 'test_run_as_root') - _check_test_page ${cip} -} - - -function run_log_to_volume_test() { - _run_invalid_log_volume_test - if _container_is_scl ; then - _run_log_to_volume_test old /var/log/httpd24 - else - _run_log_to_volume_test new /var/log/httpd - fi -} - -function _run_log_to_volume_test() { - # Check the HTTP_LOG_TO_VOLUME env variable - local variant=${1} - local volume_dir=${2} - local logs_dir=$(mktemp -d /tmp/httpd-test-volume-XXXXXX) - run "ls -d ${logs_dir} || mkdir ${logs_dir}" 0 'Create log directory' - run "chown -R 1001:1001 ${logs_dir}" - run "chcon -Rvt svirt_sandbox_file_t ${logs_dir}" 0 'Change SELinux context on the log dir' - DOCKER_ARGS="-e HTTPD_LOG_TO_VOLUME=1 --user 0 -v ${logs_dir}:${volume_dir}" - run "create_container test_log_dir_${variant}" - DOCKER_ARGS= - sleep 2 - cip=$(get_container_ip "test_log_dir_${variant}") - run "curl ${cip}:8080 > /dev/null" - ls ${logs_dir} > output - run "grep -e '^access_log$' output" 0 "Checking that file access_log exists" - run "grep -e '^error_log$' output" 0 "Checking that file error_log exists" - run "grep -e '^ssl_access_log$' output" 0 "Checking that file ssl_access_log exists" - run "grep -e '^ssl_error_log$' output" 0 "Checking that file ssl_error_log exists" - run "grep -e '^ssl_request_log$' output" 0 "Checking that file ssl_request_log exists" -} - -function _run_invalid_log_volume_test() { - # Check wrong usage of the HTTP_LOG_TO_VOLUME env variable - DOCKER_ARGS="-e HTTPD_LOG_TO_VOLUME=1 --user 1001" - run "create_container test_log_dir_fail" - DOCKER_ARGS= - sleep 2 - cid=$(get_cid "test_log_dir_fail") - exit_status=$(docker inspect -f '{{.State.ExitCode}}' ${cid}) - run "test $exit_status == 1" 0 "Checking that setting HTTPD_LOG_TO_VOLUME is not allowed if UID is not 0" -} - - -function run_data_volume_test() { - if _container_is_scl ; then - _run_data_volume_test old /opt/rh/httpd24/root/var/www - fi - _run_data_volume_test new /var/www -} - -function _run_data_volume_test() { - local variant=${1} - local volume_dir=${2} - # Test that docker volume for DocumentRoot works - datadir=$(mktemp -d /tmp/httpd-test-data-XXXXXX) - run "mkdir -p ${datadir}/html" 0 'Create document root' - run "echo hello > ${datadir}/html/index.html" - run "chown -R 1001:1001 ${datadir}" - run "chcon -Rvt svirt_sandbox_file_t ${datadir}/" 0 'Change SELinux context on the document root' - DOCKER_ARGS="-v ${datadir}:${volume_dir}" - run "create_container test_doc_root_${variant}" - DOCKER_ARGS= - sleep 2 - cip=$(get_container_ip "test_doc_root_${variant}") - run "curl ${cip}:8080 > output" - run "grep -e '^hello$' output" -} - -function _run_mpm_config_test() { - local mpm=$1 - # Check worker MPM can be configured - DOCKER_ARGS="-e HTTPD_MPM=$mpm --user 1001" - run "create_container test_mpm_${mpm}" - DOCKER_ARGS= - sleep 2 - cid=$(get_cid "test_mpm_$mpm") - run "docker logs $cid | grep -s mpm_${mpm}':notice.*resuming normal operations'" -} - -function run_mpm_config_test() { - for m in worker event prefork; do - _run_mpm_config_test $m - done -} - -function run_s2i_test() { - # Test s2i use case - # Since we built the candidate image locally, we don't want S2I attempt to pull - # it from Docker hub - s2i_args="--pull-policy=never" - run "ct_s2i_usage ${IMAGE_NAME} ${s2i_args}" 0 "Testing 's2i usage'" - run "ct_s2i_build_as_df file://${test_dir}/sample-test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp ${s2i_args}" 0 "Testing 's2i build'" - DOCKER_ARGS='--user 1000' - create_container testing-app-s2i ${IMAGE_NAME}-testapp - DOCKER_ARGS= - sleep 5 - cip=$(get_container_ip 'testing-app-s2i') - run "curl ${cip}:8080 > output_s2i" - run "fgrep -e 'This is a sample s2i application with static content.' output_s2i" - # 0 "Checking page served by s2i feature" - sleep 2 -} - -function run_pre_init_test() { - # Test s2i use case #2 - testing pre-init script - # Since we built the candidate image locally, we don't want S2I attempt to pull - # it from Docker hub - s2i_args="--pull-policy=never" - run "ct_s2i_build_as_df file://${test_dir}/pre-init-test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp2 ${s2i_args}" 0 "Testing 's2i build' with pre-init script" - DOCKER_ARGS='--user 1000' - create_container testing-app-pre-init ${IMAGE_NAME}-testapp2 - DOCKER_ARGS= - sleep 5 - cip=$(get_container_ip 'testing-app-pre-init') - run "curl ${cip}:8080 > output_pre_init" - run "fgrep -e 'This content was replaced by pre-init script.' output_pre_init" - # 0 "Checking page served by s2i feature and edited by pre-init script" - sleep 2 -} - -function run_self_cert_test() { - # Test s2i use case #3 - using own ssl certs - # Since we built the candidate image locally, we don't want S2I attempt to pull - # it from Docker hub - s2i_args="--pull-policy=never" - run "ct_s2i_build_as_df file://${test_dir}/self-signed-ssl ${IMAGE_NAME} ${IMAGE_NAME}-self-signed ${s2i_args}" 0 "Testing 's2i build' with self-signed cert" - DOCKER_ARGS='--user 1000' - create_container testing-self-signed ${IMAGE_NAME}-self-signed - DOCKER_ARGS= - sleep 5 - cip=$(get_container_ip 'testing-self-signed') - run "curl -k https://${cip}:8443 > output_ssl_cert" - run "fgrep -e 'SSL test works' output_ssl_cert" - echo | openssl s_client -showcerts -servername ${cip} -connect ${cip}:8443 2>/dev/null | openssl x509 -inform pem -noout -text >./servercert - openssl x509 -in ${test_dir}/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem -inform pem -noout -text >./configcert - run "diff ./configcert ./servercert" - run "diff ./configcert ./servercert >cert.diff" - sleep 2 -} - -function run_all_tests() { - for test_case in $TEST_LIST; do - : "Running test $test_case" - $test_case - done; -} - - -function cleanup() { - for cidfile in $CIDFILE_DIR/* ; do - CONTAINER=$(cat $cidfile) - - echo "Stopping and removing container $CONTAINER..." - docker stop $CONTAINER - exit_status=$(docker inspect -f '{{.State.ExitCode}}' $CONTAINER) - if [ "$exit_status" != "0" ]; then - echo "Dumping logs for $CONTAINER" - docker logs $CONTAINER - fi - docker rm $CONTAINER - rm $cidfile - echo "Done." - done - if [ "$overall" -eq 0 ] ; then - print_result "pass" "All tests passed." - else - print_result "fail" "Tests failed." - fi - rmdir $CIDFILE_DIR - rm -Rf "$working_dir" - return "$overall" -} -trap cleanup EXIT - - -working_dir=`mktemp -d` -pushd $working_dir > /dev/null || exit 1 - -CIDFILE_DIR=`pwd`/cid_files -mkdir "$CIDFILE_DIR" - -overall=0 - -run "docker inspect $IMAGE_NAME >/dev/null || docker pull $IMAGE_NAME" 0 - - -TEST_LIST="\ -run_self_cert_test -run_default_page_test -run_as_root_test -run_log_to_volume_test -run_data_volume_test -run_s2i_test -run_pre_init_test -run_mpm_config_test -" - -test $# -eq 1 -a "${1-}" == --list && echo "$TEST_LIST" && exit 0 - -TEST_LIST=${@:-$TEST_LIST} run_all_tests - -popd > /dev/null - -exit "$overall" diff --git a/test/run-openshift b/test/run-openshift deleted file mode 100755 index c72bc64..0000000 --- a/test/run-openshift +++ /dev/null @@ -1,35 +0,0 @@ -#!/bin/bash -# -# Test the httpd image in OpenShift. -# -# IMAGE_NAME specifies a name of the candidate image used for testing. -# VERSION specifies a version of the python in the candidate image. -# The image has to be available before this script is executed. - -THISDIR=$(dirname ${BASH_SOURCE[0]}) - -source "${THISDIR}/test-lib.sh" -source "${THISDIR}/test-lib-openshift.sh" - -BRANCH_TO_TEST=master - -set -eo nounset - -test -n "${IMAGE_NAME-}" || false 'make sure $IMAGE_NAME is defined' -test -n "${VERSION-}" || false 'make sure $VERSION is defined' - -ct_os_cluster_up - -# test local app -ct_os_test_s2i_app "${IMAGE_NAME}" "${THISDIR}/sample-test-app" . 'This is a sample s2i application with static content' - -# test remote example app -ct_os_test_s2i_app "${IMAGE_NAME}" "https://github.com/sclorg/httpd-ex#${BRANCH_TO_TEST}" . 'Welcome to your static httpd application on OpenShift' - -# test template from the example app -ct_os_test_template_app "${IMAGE_NAME}" \ - "https://raw.githubusercontent.com/openshift/httpd-ex/${BRANCH_TO_TEST}/openshift/templates/httpd.json" \ - httpd \ - 'Welcome to your static httpd application on OpenShift' \ - 8080 http 200 "-p SOURCE_REPOSITORY_REF=${BRANCH_TO_TEST} -p NAME=httpd-testing" - diff --git a/test/sample-test-app/index.html b/test/sample-test-app/index.html deleted file mode 100644 index 38f417d..0000000 --- a/test/sample-test-app/index.html +++ /dev/null @@ -1 +0,0 @@ -This is a sample s2i application with static content. diff --git a/test/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem b/test/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem deleted file mode 100644 index 8495b88..0000000 --- a/test/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem +++ /dev/null @@ -1,20 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDWjCCAkKgAwIBAgIJAI4x7HuBG49oMA0GCSqGSIb3DQEBCwUAMEIxCzAJBgNV -BAYTAlhYMRUwEwYDVQQHDAxEZWZhdWx0IENpdHkxHDAaBgNVBAoME0RlZmF1bHQg -Q29tcGFueSBMdGQwHhcNMTcxMjAzMjMzMzU3WhcNMTgwMTAyMjMzMzU3WjBCMQsw -CQYDVQQGEwJYWDEVMBMGA1UEBwwMRGVmYXVsdCBDaXR5MRwwGgYDVQQKDBNEZWZh -dWx0IENvbXBhbnkgTHRkMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA -vH4Vdq0a3UWUQd8Z6s2csxhxjAOyUx0rszGL0m3uTjQido6JRBdjN2dXiZc3LFoq -YeOKR3CeHsn7UdrlzaboHFDfjAaextse0740mB1g14H1bAS0POuTPeKa+3wGfzCb -sTSXnfSrICl3n2D/3KSO93WwmS90kBD6HmKt5nfkLpJnROM/4bHmuoV0Ry8CDjzj -mka7pQU4yzyMKLU3sHpncZU6g7o4Vezic9ksVzIAbdPCSbF7ktVz/hisyCuzyKN6 -s2327jq593vBgGOsNU5PDPDjKW74Q0Bv/FxPK4nx+o4IkcRW1QEb+yAx8XOM7CDZ -ViKvI/A0b+Y4Y3rIQ465+wIDAQABo1MwUTAdBgNVHQ4EFgQUAY1i6ZNbqO1+46aw -pldCyPaWoYswHwYDVR0jBBgwFoAUAY1i6ZNbqO1+46awpldCyPaWoYswDwYDVR0T -AQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEADhGjnYGq9JvQcygMYEQiIdyS -t06Nu7NUkWz52GJp7WFognWyG+0jAomBR0GSUchfubvVZ7cHIaVKLhiGOqg+HIol -7tNRfvE6x/Idk674g6OTRAWxO/wOlgnRMpRy6XhHOtb4HcPcpWFZJS8MC8+HRWIs -kzMErXe0/obnKn9O04kcEREfmB7kfcD4ooqk5gwbdQk1W6a44LcN6AB5qYPjOzgF -Qnb2aLQW9XhgNhiMsYqDzCZsy0az0rz7NgkVOnKrGJ8x3kVX13GR2joVVHOazms9 -Gd90z+mLMDTbqCRGIPMLvEp4HtAmBxbgsj/zHyinajIqV96B3Cr3zTdW29lHJg== ------END CERTIFICATE----- diff --git a/test/self-signed-ssl/httpd-ssl/private/server-key.pem b/test/self-signed-ssl/httpd-ssl/private/server-key.pem deleted file mode 100644 index ff2ac89..0000000 --- a/test/self-signed-ssl/httpd-ssl/private/server-key.pem +++ /dev/null @@ -1,28 +0,0 @@ ------BEGIN PRIVATE KEY----- -MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQC8fhV2rRrdRZRB -3xnqzZyzGHGMA7JTHSuzMYvSbe5ONCJ2jolEF2M3Z1eJlzcsWiph44pHcJ4eyftR -2uXNpugcUN+MBp7G2x7TvjSYHWDXgfVsBLQ865M94pr7fAZ/MJuxNJed9KsgKXef -YP/cpI73dbCZL3SQEPoeYq3md+QukmdE4z/hsea6hXRHLwIOPOOaRrulBTjLPIwo -tTewemdxlTqDujhV7OJz2SxXMgBt08JJsXuS1XP+GKzIK7PIo3qzbfbuOrn3e8GA -Y6w1Tk8M8OMpbvhDQG/8XE8rifH6jgiRxFbVARv7IDHxc4zsINlWIq8j8DRv5jhj -eshDjrn7AgMBAAECggEARZxeutxE/pCypv0IqkFS7IVLccTvt2gfemcC1yzIBFOW -oqgTI3Vrq8tbdbHFq3iFDG+m4qlBi+dWDC3GDoPkVoi7dg//1TqZEOO+sqqu2Afj -pge6tIDfeMxWJifwkkpWRURB9hCknhUSW2bMNyUCs3rgREJVTtsmM9CHnoSKXXQL -aOeYXalFVpx3ceK+xdp0VGfpsqEabBKs0yy3EDiQy2huoWce3EVFLVrwx/IkhcsZ -JlI5LPpoiTglSs1g9i88JHS2slBtKtb1lWl/yXHhK1g7s34c6f9jP8snuFE5ddMn -0L4GDA9teaPGvB533eb2RIFy2kUYgpr5c03G6rpoOQKBgQDpY6BFJkPGENnC5Bdb -fJCuN2nyRdC1qvv6ESFaQYb0s6QjKDqpb0dUSYN3+zNgtiAysbQLeU/d9mmt4UR8 -ohjRkOySU0eQ/YNFokjw6g6GPoiMHJJ9cP75NA94uIMIUTY7uHEWWZwXI5UphdPC -p5/3MaF1VlYQys9a5wtiEaDSfQKBgQDOwPV0zQjUabkVQ4yV0amP8xybvHH8ghG0 -RMStHg96RfDmg35JQaw22A2xiVROCoZgLqiE1DFSl/3gBF/vfqBh/uzdxwNerJC6 -ROdCxyS4rys5d/02P4aNOa73sD+ZKyEZRTF1v3bmOGKidRFF5oxIpuHjFWlJFKx1 -O/b3AI0v1wKBgQC/L4N84emm+OrKAfs4UIRckrxRYOulxhmAMkQ2IXOiRP5yZmQX -pDa0TzxJLxhZYxhhLr0koQ3R8CeF7wEhb9AQ7D0/aMU5etLsWhKSd8nKIrPMwyMl -a0kTb5g09kEwsQZSSbcp7eI1+koYp65eyN37q0ZuTnlWbC0MdDQY9APgKQKBgQCb -HqaKNXLUe2XDkGSf2ygOumXSanZS7vt9dsLg59bQ9DyjljBfogglNcBAXTqFOtxK -uXbyAYnn3+U399BKjYSjQXJRioj6tRn4xs2DiooAjlwtx9qQouS+fHLLns54iqVQ -oltTbo00eUV3gcGt4iWKNLrxdxUBIaOqaY0HEMDdDQKBgQCRvcHDF7JSPuBiO3Tw -PSOUD4q6dD/dhI+X2ZKg83w94SZXXms6eMSbedUkLoJ8TDunmdRUUWb6rgP/pJwr -zKRTskItF15i9IWCwC6jBrSfx5n2JcSoBALyc0aR9heF0GQjWwqURd+PC/msomrW -z9SCl8mpQVFtBlui7PcnDLTFAg== ------END PRIVATE KEY----- diff --git a/test/self-signed-ssl/index.html b/test/self-signed-ssl/index.html deleted file mode 100644 index 82ff698..0000000 --- a/test/self-signed-ssl/index.html +++ /dev/null @@ -1 +0,0 @@ -SSL test works diff --git a/test/test-lib-openshift.sh b/test/test-lib-openshift.sh deleted file mode 100644 index f988ac5..0000000 --- a/test/test-lib-openshift.sh +++ /dev/null @@ -1,925 +0,0 @@ -# Set of functions for testing docker images in OpenShift using 'oc' command - -# ct_os_get_status -# -------------------- -# Returns status of all objects to make debugging easier. -function ct_os_get_status() { - oc get all - oc status -} - -# ct_os_print_logs -# -------------------- -# Returns status of all objects and logs from all pods. -function ct_os_print_logs() { - ct_os_get_status - while read pod_name; do - echo "INFO: printing logs for pod ${pod_name}" - oc logs ${pod_name} - done < <(oc get pods --no-headers=true -o custom-columns=NAME:.metadata.name) -} - -# ct_os_enable_print_logs -# -------------------- -# Enables automatic printing of pod logs on ERR. -function ct_os_enable_print_logs() { - set -E - trap ct_os_print_logs ERR -} - -# ct_get_public_ip -# -------------------- -# Returns best guess for the IP that the node is accessible from other computers. -# This is a bit funny heuristic, simply goes through all IPv4 addresses that -# hostname -I returns and de-prioritizes IP addresses commonly used for local -# addressing. The rest of addresses are taken as public with higher probability. -function ct_get_public_ip() { - local hostnames=$(hostname -I) - local public_ip='' - local found_ip - for guess_exp in '127\.0\.0\.1' '192\.168\.[0-9\.]*' '172\.[0-9\.]*' \ - '10\.[0-9\.]*' '[0-9\.]*' ; do - found_ip=$(echo "${hostnames}" | grep -oe "${guess_exp}") - if [ -n "${found_ip}" ] ; then - hostnames=$(echo "${hostnames}" | sed -e "s/${found_ip}//") - public_ip="${found_ip}" - fi - done - if [ -z "${public_ip}" ] ; then - echo "ERROR: public IP could not be guessed." >&2 - return 1 - fi - echo "${public_ip}" -} - -# ct_os_run_in_pod POD_NAME CMD -# -------------------- -# Runs [cmd] in the pod specified by prefix [pod_prefix]. -# Arguments: pod_name - full name of the pod -# Arguments: cmd - command to be run in the pod -function ct_os_run_in_pod() { - local pod_name="$1" ; shift - - oc exec "$pod_name" -- "$@" -} - -# ct_os_get_service_ip SERVICE_NAME -# -------------------- -# Returns IP of the service specified by [service_name]. -# Arguments: service_name - name of the service -function ct_os_get_service_ip() { - local service_name="${1}" ; shift - oc get "svc/${service_name}" -o yaml | grep clusterIP | \ - cut -d':' -f2 | grep -oe '172\.30\.[0-9\.]*' -} - - -# ct_os_get_all_pods_status -# -------------------- -# Returns status of all pods. -function ct_os_get_all_pods_status() { - oc get pods -o custom-columns=Ready:status.containerStatuses[0].ready,NAME:.metadata.name -} - -# ct_os_get_all_pods_name -# -------------------- -# Returns the full name of all pods. -function ct_os_get_all_pods_name() { - oc get pods --no-headers -o custom-columns=NAME:.metadata.name -} - -# ct_os_get_pod_status POD_PREFIX -# -------------------- -# Returns status of the pod specified by prefix [pod_prefix]. -# Note: Ignores -build and -deploy pods -# Arguments: pod_prefix - prefix or whole ID of the pod -function ct_os_get_pod_status() { - local pod_prefix="${1}" ; shift - ct_os_get_all_pods_status | grep -e "${pod_prefix}" | grep -Ev "(build|deploy)$" \ - | awk '{print $1}' | head -n 1 -} - -# ct_os_get_pod_name POD_PREFIX -# -------------------- -# Returns the full name of pods specified by prefix [pod_prefix]. -# Note: Ignores -build and -deploy pods -# Arguments: pod_prefix - prefix or whole ID of the pod -function ct_os_get_pod_name() { - local pod_prefix="${1}" ; shift - ct_os_get_all_pods_name | grep -e "^${pod_prefix}" | grep -Ev "(build|deploy)$" -} - -# ct_os_get_pod_ip POD_NAME -# -------------------- -# Returns the ip of the pod specified by [pod_name]. -# Arguments: pod_name - full name of the pod -function ct_os_get_pod_ip() { - local pod_name="${1}" - oc get pod "$pod_name" --no-headers -o custom-columns=IP:status.podIP -} - -# ct_os_check_pod_readiness POD_PREFIX STATUS -# -------------------- -# Checks whether the pod is ready. -# Arguments: pod_prefix - prefix or whole ID of the pod -# Arguments: status - expected status (true, false) -function ct_os_check_pod_readiness() { - local pod_prefix="${1}" ; shift - local status="${1}" ; shift - test "$(ct_os_get_pod_status ${pod_prefix})" == "${status}" -} - -# ct_os_wait_pod_ready POD_PREFIX TIMEOUT -# -------------------- -# Wait maximum [timeout] for the pod becomming ready. -# Arguments: pod_prefix - prefix or whole ID of the pod -# Arguments: timeout - how many seconds to wait seconds -function ct_os_wait_pod_ready() { - local pod_prefix="${1}" ; shift - local timeout="${1}" ; shift - SECONDS=0 - echo -n "Waiting for ${pod_prefix} pod becoming ready ..." - while ! ct_os_check_pod_readiness "${pod_prefix}" "true" ; do - echo -n "." - [ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1 - sleep 3 - done - echo " DONE" -} - -# ct_os_wait_rc_ready POD_PREFIX TIMEOUT -# -------------------- -# Wait maximum [timeout] for the rc having desired number of replicas ready. -# Arguments: pod_prefix - prefix of the replication controller -# Arguments: timeout - how many seconds to wait seconds -function ct_os_wait_rc_ready() { - local pod_prefix="${1}" ; shift - local timeout="${1}" ; shift - SECONDS=0 - echo -n "Waiting for ${pod_prefix} pod becoming ready ..." - while ! test "$((oc get --no-headers statefulsets; oc get --no-headers rc) 2>/dev/null \ - | grep "^${pod_prefix}" | awk '$2==$3 {print "ready"}')" == "ready" ; do - echo -n "." - [ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1 - sleep 3 - done - echo " DONE" -} - -# ct_os_deploy_pure_image IMAGE [ENV_PARAMS, ...] -# -------------------- -# Runs [image] in the openshift and optionally specifies env_params -# as environment variables to the image. -# Arguments: image - prefix or whole ID of the pod to run the cmd in -# Arguments: env_params - environment variables parameters for the images. -function ct_os_deploy_pure_image() { - local image="${1}" ; shift - # ignore error exit code, because oc new-app returns error when image exists - oc new-app ${image} "$@" || : - # let openshift cluster to sync to avoid some race condition errors - sleep 3 -} - -# ct_os_deploy_s2i_image IMAGE APP [ENV_PARAMS, ... ] -# -------------------- -# Runs [image] and [app] in the openshift and optionally specifies env_params -# as environment variables to the image. -# Arguments: image - prefix or whole ID of the pod to run the cmd in -# Arguments: app - url or local path to git repo with the application sources. -# Arguments: env_params - environment variables parameters for the images. -function ct_os_deploy_s2i_image() { - local image="${1}" ; shift - local app="${1}" ; shift - # ignore error exit code, because oc new-app returns error when image exists - oc new-app "${image}~${app}" "$@" || : - - # let openshift cluster to sync to avoid some race condition errors - sleep 3 -} - -# ct_os_deploy_template_image TEMPLATE [ENV_PARAMS, ...] -# -------------------- -# Runs template in the openshift and optionally gives env_params to use -# specific values in the template. -# Arguments: template - prefix or whole ID of the pod to run the cmd in -# Arguments: env_params - environment variables parameters for the template. -# Example usage: ct_os_deploy_template_image mariadb-ephemeral-template.yaml \ -# DATABASE_SERVICE_NAME=mysql-57-centos7 \ -# DATABASE_IMAGE=mysql-57-centos7 \ -# MYSQL_USER=testu \ -# MYSQL_PASSWORD=testp \ -# MYSQL_DATABASE=testdb -function ct_os_deploy_template_image() { - local template="${1}" ; shift - oc process -f "${template}" "$@" | oc create -f - - # let openshift cluster to sync to avoid some race condition errors - sleep 3 -} - -# _ct_os_get_uniq_project_name -# -------------------- -# Returns a uniq name of the OpenShift project. -function _ct_os_get_uniq_project_name() { - local r - while true ; do - r=${RANDOM} - mkdir /var/tmp/sclorg-test-${r} &>/dev/null && echo sclorg-test-${r} && break - done -} - -# ct_os_new_project [PROJECT] -# -------------------- -# Creates a new project in the openshfit using 'os' command. -# Arguments: project - project name, uses a new random name if omitted -# Expects 'os' command that is properly logged in to the OpenShift cluster. -# Not using mktemp, because we cannot use uppercase characters. -function ct_os_new_project() { - if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then - echo "Creating project skipped." - return - fi - local project_name="${1:-$(_ct_os_get_uniq_project_name)}" ; shift || : - oc new-project ${project_name} - # let openshift cluster to sync to avoid some race condition errors - sleep 3 -} - -# ct_os_delete_project [PROJECT] -# -------------------- -# Deletes the specified project in the openshfit -# Arguments: project - project name, uses the current project if omitted -function ct_os_delete_project() { - if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then - echo "Deleting project skipped, cleaning objects only." - ct_delete_all_objects - return - fi - local project_name="${1:-$(oc project -q)}" ; shift || : - oc delete project "${project_name}" -} - -# ct_delete_all_objects -# ----------------- -# Deletes all objects within the project. -# Handy when we have one project and want to run more tests. -function ct_delete_all_objects() { - for x in bc builds dc is isimage istag po pv pvc rc routes secrets svc ; do - oc delete $x --all - done - # for some objects it takes longer to be really deleted, so a dummy sleep - # to avoid some races when other test can see not-yet-deleted objects and can fail - sleep 10 -} - -# ct_os_docker_login -# -------------------- -# Logs in into docker daemon -# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address. -# Does not do anything if REGISTRY_ADDRESS is set. -function ct_os_docker_login() { - [ -n "${REGISTRY_ADDRESS:-}" ] && "REGISTRY_ADDRESS set, not trying to docker login." && return 0 - # docker login fails with "404 page not found" error sometimes, just try it more times - for i in `seq 12` ; do - docker login -u developer -p $(oc whoami -t) ${REGISRTY_ADDRESS:-172.30.1.1:5000} && return 0 || : - sleep 5 - done - return 1 -} - -# ct_os_upload_image IMAGE [IMAGESTREAM] -# -------------------- -# Uploads image from local registry to the OpenShift internal registry. -# Arguments: image - image name to upload -# Arguments: imagestream - name and tag to use for the internal registry. -# In the format of name:tag ($image_name:latest by default) -# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address. -function ct_os_upload_image() { - local input_name="${1}" ; shift - local image_name=${input_name##*/} - local imagestream=${1:-$image_name:latest} - local output_name="${REGISRTY_ADDRESS:-172.30.1.1:5000}/$(oc project -q)/$imagestream" - - ct_os_docker_login - docker tag ${input_name} ${output_name} - docker push ${output_name} -} - -# ct_os_install_in_centos -# -------------------- -# Installs os cluster in CentOS -function ct_os_install_in_centos() { - yum install -y centos-release-openshift-origin - yum install -y wget git net-tools bind-utils iptables-services bridge-utils\ - bash-completion origin-clients docker origin-clients -} - -# ct_os_cluster_up [DIR, IS_PUBLIC, CLUSTER_VERSION] -# -------------------- -# Runs the local OpenShift cluster using 'oc cluster up' and logs in as developer. -# Arguments: dir - directory to keep configuration data in, random if omitted -# Arguments: is_public - sets either private or public hostname for web-UI, -# use "true" for allow remote access to the web-UI, -# "false" is default -# Arguments: cluster_version - version of the OpenShift cluster to use, empty -# means default version of `oc`; example value: 3.7; -# also can be specified outside by OC_CLUSTER_VERSION -function ct_os_cluster_up() { - ct_os_cluster_running && echo "Cluster already running. Nothing is done." && return 0 - ct_os_logged_in && echo "Already logged in to a cluster. Nothing is done." && return 0 - - mkdir -p /var/tmp/openshift - local dir="${1:-$(mktemp -d /var/tmp/openshift/os-data-XXXXXX)}" ; shift || : - local is_public="${1:-'false'}" ; shift || : - local default_cluster_version=${OC_CLUSTER_VERSION:-} - local cluster_version=${1:-${default_cluster_version}} ; shift || : - if ! grep -qe '--insecure-registry.*172\.30\.0\.0' /etc/sysconfig/docker ; then - sed -i "s|OPTIONS='|OPTIONS='--insecure-registry 172.30.0.0/16 |" /etc/sysconfig/docker - fi - - systemctl stop firewalld || : - setenforce 0 - iptables -F - - systemctl restart docker - local cluster_ip="127.0.0.1" - [ "${is_public}" == "true" ] && cluster_ip=$(ct_get_public_ip) - - if [ -n "${cluster_version}" ] ; then - # if $cluster_version is not set, we simply use oc that is available - ct_os_set_path_oc "${cluster_version}" - fi - - mkdir -p ${dir}/{config,data,pv} - case $(oc version| head -n 1) in - "oc v3.1"?.*) - oc cluster up --base-dir="${dir}/data" --public-hostname="${cluster_ip}" - ;; - "oc v3."*) - oc cluster up --host-data-dir="${dir}/data" --host-config-dir="${dir}/config" \ - --host-pv-dir="${dir}/pv" --use-existing-config --public-hostname="${cluster_ip}" - ;; - *) - echo "ERROR: Unexpected oc version." >&2 - return 1 - ;; - esac - oc version - oc login -u system:admin - oc project default - ct_os_wait_rc_ready docker-registry 180 - ct_os_wait_rc_ready router 30 - oc login -u developer -p developer - # let openshift cluster to sync to avoid some race condition errors - sleep 3 -} - -# ct_os_cluster_down -# -------------------- -# Shuts down the local OpenShift cluster using 'oc cluster down' -function ct_os_cluster_down() { - oc cluster down -} - -# ct_os_cluster_running -# -------------------- -# Returns 0 if oc cluster is running -function ct_os_cluster_running() { - oc cluster status &>/dev/null -} - -# ct_os_logged_in -# --------------- -# Returns 0 if logged in to a cluster (remote or local) -function ct_os_logged_in() { - oc whoami >/dev/null -} - -# ct_os_set_path_oc OC_VERSION -# -------------------- -# This is a trick that helps using correct version of the `oc`: -# The input is version of the openshift in format v3.6.0 etc. -# If the currently available version of oc is not of this version, -# it first takes a look into /usr/local/oc-/bin directory, -# and if not found there it downloads the community release from github. -# In the end the PATH variable is changed, so the other tests can still use just 'oc'. -# Arguments: oc_version - X.Y part of the version of OSE (e.g. 3.9) -function ct_os_set_path_oc() { - local oc_version=$(ct_os_get_latest_ver $1) - local oc_path - - if oc version | grep -q "oc ${oc_version%.*}." ; then - echo "Binary oc found already available in version ${oc_version}: `which oc` Doing noting." - return 0 - fi - - # first check whether we already have oc available in /usr/local - local installed_oc_path="/usr/local/oc-${oc_version%.*}/bin" - - if [ -x "${installed_oc_path}/oc" ] ; then - oc_path="${installed_oc_path}" - echo "Binary oc found in ${installed_oc_path}" >&2 - else - # oc not available in /usr/local, try to download it from github (community release) - oc_path="/tmp/oc-${oc_version}-bin" - ct_os_download_upstream_oc "${oc_version}" "${oc_path}" - fi - if [ -z "${oc_path}/oc" ] ; then - echo "ERROR: oc not found installed, nor downloaded" >&1 - return 1 - fi - export PATH="${oc_path}:${PATH}" - if ! oc version | grep -q "oc ${oc_version%.*}." ; then - echo "ERROR: something went wrong, oc located at ${oc_path}, but oc of version ${oc_version} not found in PATH ($PATH)" >&1 - return 1 - else - echo "PATH set correctly, binary oc found in version ${oc_version}: `which oc`" - fi -} - -# ct_os_get_latest_ver VERSION_PART_X -# -------------------- -# Returns full version (vX.Y.Z) from part of the version (X.Y) -# Arguments: vxy - X.Y part of the version -# Returns vX.Y.Z variant of the version -function ct_os_get_latest_ver(){ - local vxy="v$1" - for vz in {3..0} ; do - curl -sif "https://github.com/openshift/origin/releases/tag/${vxy}.${vz}" >/dev/null && echo "${vxy}.${vz}" && return 0 - done - echo "ERROR: version ${vxy} not found in https://github.com/openshift/origin/tags" >&2 - return 1 -} - -# ct_os_download_upstream_oc OC_VERSION OUTPUT_DIR -# -------------------- -# Downloads a particular version of openshift-origin-client-tools from -# github into specified output directory -# Arguments: oc_version - version of OSE (e.g. v3.7.2) -# Arguments: output_dir - output directory -function ct_os_download_upstream_oc() { - local oc_version=$1 - local output_dir=$2 - - # check whether we already have the binary in place - [ -x "${output_dir}/oc" ] && return 0 - - mkdir -p "${output_dir}" - # using html output instead of https://api.github.com/repos/openshift/origin/releases/tags/${oc_version}, - # because API is limited for number of queries if not authenticated - tarball=$(curl -si "https://github.com/openshift/origin/releases/tag/${oc_version}" | grep -o -e "openshift-origin-client-tools-${oc_version}-[a-f0-9]*-linux-64bit.tar.gz" | head -n 1) - - # download, unpack the binaries and then put them into output directory - echo "Downloading https://github.com/openshift/origin/releases/download/${oc_version}/${tarball} into ${output_dir}/" >&2 - curl -sL https://github.com/openshift/origin/releases/download/${oc_version}/"${tarball}" | tar -C "${output_dir}" -xz - mv -f "${output_dir}"/"${tarball%.tar.gz}"/* "${output_dir}/" - - rmdir "${output_dir}"/"${tarball%.tar.gz}" -} - - -# ct_os_test_s2i_app_func IMAGE APP CONTEXT_DIR CHECK_CMD [OC_ARGS] -# -------------------- -# Runs [image] and [app] in the openshift and optionally specifies env_params -# as environment variables to the image. Then check the container by arbitrary -# function given as argument (such an argument may include string, -# that will be replaced with actual IP). -# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) -# Arguments: app - url or local path to git repo with the application sources (compulsory) -# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory) -# Arguments: check_command - CMD line that checks whether the container works (compulsory; '' will be replaced with actual IP) -# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` -# command, typically environment variables (optional) -function ct_os_test_s2i_app_func() { - local image_name=${1} - local app=${2} - local context_dir=${3} - local check_command=${4} - local oc_args=${5:-} - local import_image=${6:-} - local image_name_no_namespace=${image_name##*/} - local service_name="${image_name_no_namespace}-testing" - local image_tagged="${image_name_no_namespace}:${VERSION}" - - if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then - echo "ERROR: ct_os_test_s2i_app_func() requires at least 4 arguments that cannot be emtpy." >&2 - return 1 - fi - - ct_os_new_project - # Create a specific imagestream tag for the image so that oc cannot use anything else - if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then - if [ -n "${import_image}" ] ; then - echo "Importing image ${import_image} as ${image_name}:${VERSION}" - oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm - else - echo "Uploading and importing image skipped." - fi - else - if [ -n "${import_image}" ] ; then - echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead." - fi - ct_os_upload_image "${image_name}" "${image_tagged}" - fi - - local app_param="${app}" - if [ -d "${app}" ] ; then - # for local directory, we need to copy the content, otherwise too smart os command - # pulls the git remote repository instead - app_param=$(ct_obtain_input "${app}") - fi - - ct_os_deploy_s2i_image "${image_tagged}" "${app_param}" \ - --context-dir="${context_dir}" \ - --name "${service_name}" \ - ${oc_args} - - if [ -d "${app}" ] ; then - # in order to avoid weird race seen sometimes, let's wait shortly - # before starting the build explicitly - sleep 5 - oc start-build "${service_name}" --from-dir="${app_param}" - fi - - ct_os_wait_pod_ready "${service_name}" 300 - - local ip=$(ct_os_get_service_ip "${service_name}") - local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") - - echo " Checking APP using $check_command_exp ..." - local result=0 - eval "$check_command_exp" || result=1 - - if [ $result -eq 0 ] ; then - echo " Check passed." - else - echo " Check failed." - fi - - ct_os_delete_project - return $result -} - -# ct_os_test_s2i_app IMAGE APP CONTEXT_DIR EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ] -# -------------------- -# Runs [image] and [app] in the openshift and optionally specifies env_params -# as environment variables to the image. Then check the http response. -# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) -# Arguments: app - url or local path to git repo with the application sources (compulsory) -# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory) -# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory) -# Arguments: port - which port to use (optional; default: 8080) -# Arguments: protocol - which protocol to use (optional; default: http) -# Arguments: response_code - what http response code to expect (optional; default: 200) -# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` -# command, typically environment variables (optional) -function ct_os_test_s2i_app() { - local image_name=${1} - local app=${2} - local context_dir=${3} - local expected_output=${4} - local port=${5:-8080} - local protocol=${6:-http} - local response_code=${7:-200} - local oc_args=${8:-} - local import_image=${9:-} - - if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then - echo "ERROR: ct_os_test_s2i_app() requires at least 4 arguments that cannot be emtpy." >&2 - return 1 - fi - - ct_os_test_s2i_app_func "${image_name}" \ - "${app}" \ - "${context_dir}" \ - "ct_os_test_response_internal '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ - "${oc_args}" "${import_image}" -} - -# ct_os_test_template_app_func IMAGE APP IMAGE_IN_TEMPLATE CHECK_CMD [OC_ARGS] -# -------------------- -# Runs [image] and [app] in the openshift and optionally specifies env_params -# as environment variables to the image. Then check the container by arbitrary -# function given as argument (such an argument may include string, -# that will be replaced with actual IP). -# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) -# Arguments: template - url or local path to a template to use (compulsory) -# Arguments: name_in_template - image name used in the template -# Arguments: check_command - CMD line that checks whether the container works (compulsory; '' will be replaced with actual IP) -# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` -# command, typically environment variables (optional) -# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry, -# specify them in this parameter as "|", where "" is a full image name -# (including registry if needed) and "" is a tag under which the image should be available -# in the OpenShift registry. -function ct_os_test_template_app_func() { - local image_name=${1} - local template=${2} - local name_in_template=${3} - local check_command=${4} - local oc_args=${5:-} - local other_images=${6:-} - local import_image=${7:-} - - if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then - echo "ERROR: ct_os_test_template_app_func() requires at least 4 arguments that cannot be emtpy." >&2 - return 1 - fi - - local service_name="${name_in_template}-testing" - local image_tagged="${name_in_template}:${VERSION}" - - ct_os_new_project - - # Create a specific imagestream tag for the image so that oc cannot use anything else - if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then - if [ -n "${import_image}" ] ; then - echo "Importing image ${import_image} as ${image_name}:${VERSION}" - oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm - else - echo "Uploading and importing image skipped." - fi - else - if [ -n "${import_image}" ] ; then - echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead." - fi - ct_os_upload_image "${image_name}" "${image_tagged}" - - # upload also other images, that template might need (list of pairs in the format | - local images_tags_a - local i_t - for i_t in ${other_images} ; do - echo "${i_t}" - IFS='|' read -ra image_tag_a <<< "${i_t}" - docker pull "${image_tag_a[0]}" - ct_os_upload_image "${image_tag_a[0]}" "${image_tag_a[1]}" - done - fi - - local local_template=$(ct_obtain_input "${template}") - local namespace=${CT_NAMESPACE:-$(oc project -q)} - oc new-app ${local_template} \ - --name "${name_in_template}" \ - -p NAMESPACE="${namespace}" \ - ${oc_args} - - ct_os_wait_pod_ready "${service_name}" 300 - - local ip=$(ct_os_get_service_ip "${service_name}") - local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") - - echo " Checking APP using $check_command_exp ..." - local result=0 - eval "$check_command_exp" || result=1 - - if [ $result -eq 0 ] ; then - echo " Check passed." - else - echo " Check failed." - fi - - ct_os_delete_project - return $result -} - -# params: -# ct_os_test_template_app IMAGE APP IMAGE_IN_TEMPLATE EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ] -# -------------------- -# Runs [image] and [app] in the openshift and optionally specifies env_params -# as environment variables to the image. Then check the http response. -# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) -# Arguments: template - url or local path to a template to use (compulsory) -# Arguments: name_in_template - image name used in the template -# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory) -# Arguments: port - which port to use (optional; default: 8080) -# Arguments: protocol - which protocol to use (optional; default: http) -# Arguments: response_code - what http response code to expect (optional; default: 200) -# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` -# command, typically environment variables (optional) -# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry, -# specify them in this parameter as "|", where "" is a full image name -# (including registry if needed) and "" is a tag under which the image should be available -# in the OpenShift registry. -function ct_os_test_template_app() { - local image_name=${1} - local template=${2} - local name_in_template=${3} - local expected_output=${4} - local port=${5:-8080} - local protocol=${6:-http} - local response_code=${7:-200} - local oc_args=${8:-} - local other_images=${9:-} - local import_image=${10:-} - - if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then - echo "ERROR: ct_os_test_template_app() requires at least 4 arguments that cannot be emtpy." >&2 - return 1 - fi - - ct_os_test_template_app_func "${image_name}" \ - "${template}" \ - "${name_in_template}" \ - "ct_os_test_response_internal '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ - "${oc_args}" \ - "${other_images}" \ - "${import_image}" -} - -# ct_os_test_image_update IMAGE_NAME OLD_IMAGE ISTAG CHECK_FUNCTION OC_ARGS -# -------------------- -# Runs an image update test with [image] uploaded to [is] imagestream -# and checks the services using an arbitrary function provided in [check_function]. -# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) -# Arguments: old_image - valid name of the image from the registry -# Arguments: istag - imagestream to upload the images into (compulsory) -# Arguments: check_function - command to be run to check functionality of created services (compulsory) -# Arguments: oc_args - arguments to use during oc new-app (compulsory) -ct_os_test_image_update() { - local image_name=$1; shift - local old_image=$1; shift - local istag=$1; shift - local check_function=$1; shift - local service_name=${image_name##*/} - local ip="" check_command_exp="" - - echo "Running image update test for: $image_name" - ct_os_new_project - - # Get current image from repository and create an imagestream - docker pull "$old_image:latest" 2>/dev/null - ct_os_upload_image "$old_image" "$istag" - - # Setup example application with curent image - oc new-app "$@" --name "$service_name" - ct_os_wait_pod_ready "$service_name" 60 - - # Check application output - ip=$(ct_os_get_service_ip "$service_name") - check_command_exp=${check_function///$ip} - ct_assert_cmd_success "$check_command_exp" - - # Tag built image into the imagestream and wait for rebuild - ct_os_upload_image "$image_name" "$istag" - ct_os_wait_pod_ready "${service_name}-2" 60 - - # Check application output - ip=$(ct_os_get_service_ip "$service_name") - check_command_exp=${check_function///$ip} - ct_assert_cmd_success "$check_command_exp" - - ct_os_delete_project -} - -# ct_os_deploy_cmd_image IMAGE_NAME -# -------------------- -# Runs a special command pod, a pod that does nothing, but includes utilities for testing. -# A typical usage is a mysql pod that includes mysql commandline, that we need for testing. -# Running commands inside this command pod is done via ct_os_cmd_image_run function. -# The pod is not run again if already running. -# Arguments: image_name - image to be used as a command pod -function ct_os_deploy_cmd_image() { - local image_name=${1} - oc get pod command-app &>/dev/null && echo "command POD already running" && return 0 - echo "command POD not running yet, will start one called command-app" - oc create -f - <" - local sleep_time=3 - local attempt=1 - local result=1 - local status - local response_code - local response_file=$(mktemp /tmp/ct_test_response_XXXXXX) - local util_image_name='python:3.6' - - ct_os_deploy_cmd_image "${util_image_name}" - - while [ ${attempt} -le ${max_attempts} ]; do - ct_os_cmd_image_run "curl --connect-timeout 10 -s -w '%{http_code}' '${url}'" >${response_file} && status=0 || status=1 - if [ ${status} -eq 0 ]; then - response_code=$(cat ${response_file} | tail -c 3) - if [ "${response_code}" -eq "${expected_code}" ]; then - result=0 - fi - cat ${response_file} | grep -qP -e "${body_regexp}" || result=1; - # Some services return 40x code until they are ready, so let's give them - # some chance and not end with failure right away - # Do not wait if we already have expected outcome though - if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then - break - fi - fi - attempt=$(( ${attempt} + 1 )) - sleep ${sleep_time} - done - rm -f ${response_file} - return ${result} -} - -# ct_os_get_image_from_pod -# ------------------------ -# Print image identifier from an existing pod to stdout -# Argument: pod_prefix - prefix or full name of the pod to get image from -ct_os_get_image_from_pod() { - local pod_prefix=$1 ; shift - local pod_name=$(ct_os_get_pod_name $pod_prefix) - oc get "po/${pod_name}" -o yaml | sed -ne 's/^\s*image:\s*\(.*\)\s*$/\1/ p' | head -1 -} - -# ct_os_check_cmd_internal -# ---------------- -# Runs a specified command, checks exit code and compares the output with expected regexp. -# That all is done inside an image in the cluster, so the function is used -# typically in clusters that are not accessible outside. -# The check is repeated until timeout. -# Argument: util_image_name - name of the image in the cluster that is used for running the cmd -# Argument: service_name - kubernetes' service name to work with (IP address is taken from this one) -# Argument: check_command - command that is run within the util_image_name container -# Argument: expected_content_match - regexp that must be in the output (use .* to ignore check) -# Argument: timeout - number of seconds to wait till the check succeeds -function ct_os_check_cmd_internal() { - local util_image_name=$1 ; shift - local service_name=$1 ; shift - local check_command=$1 ; shift - local expected_content_match=${1:-.*} ; shift - local timeout=${1:-60} ; shift || : - - : " Service ${service_name} check ..." - - local output - local ret - local ip=$(ct_os_get_service_ip "${service_name}") - local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") - - ct_os_deploy_cmd_image $(ct_os_get_image_from_pod "${util_image_name}" | head -n 1) - SECONDS=0 - - echo -n "Waiting for ${service_name} service becoming ready ..." - while true ; do - output=$(ct_os_cmd_image_run "$check_command_exp") - ret=$? - echo "${output}" | grep -qe "${expected_content_match}" || ret=1 - if [ ${ret} -eq 0 ] ; then - echo " PASS" - return 0 - fi - echo -n "." - [ ${SECONDS} -gt ${timeout} ] && break - sleep 3 - done - echo " FAIL" - return 1 -} - diff --git a/test/test-lib.sh b/test/test-lib.sh deleted file mode 100644 index e372870..0000000 --- a/test/test-lib.sh +++ /dev/null @@ -1,507 +0,0 @@ -# -# Test a container image. -# -# Always use sourced from a specific container testfile -# -# reguires definition of CID_FILE_DIR -# CID_FILE_DIR=$(mktemp --suffix=_test_cidfiles -d) -# reguires definition of TEST_LIST -# TEST_LIST="\ -# ctest_container_creation -# ctest_doc_content" - -# Container CI tests -# abbreviated as "ct" - -# may be redefined in the specific container testfile -EXPECTED_EXIT_CODE=0 - -# ct_cleanup -# -------------------- -# Cleans up containers used during tests. Stops and removes all containers -# referenced by cid_files in CID_FILE_DIR. Dumps logs if a container exited -# unexpectedly. Removes the cid_files and CID_FILE_DIR as well. -# Uses: $CID_FILE_DIR - path to directory containing cid_files -# Uses: $EXPECTED_EXIT_CODE - expected container exit code -function ct_cleanup() { - for cid_file in $CID_FILE_DIR/* ; do - local container=$(cat $cid_file) - - : "Stopping and removing container $container..." - docker stop $container - exit_status=$(docker inspect -f '{{.State.ExitCode}}' $container) - if [ "$exit_status" != "$EXPECTED_EXIT_CODE" ]; then - : "Dumping logs for $container" - docker logs $container - fi - docker rm -v $container - rm $cid_file - done - rmdir $CID_FILE_DIR - : "Done." -} - -# ct_enable_cleanup -# -------------------- -# Enables automatic container cleanup after tests. -function ct_enable_cleanup() { - trap ct_cleanup EXIT SIGINT -} - -# ct_get_cid [name] -# -------------------- -# Prints container id from cid_file based on the name of the file. -# Argument: name - name of cid_file where the container id will be stored -# Uses: $CID_FILE_DIR - path to directory containing cid_files -function ct_get_cid() { - local name="$1" ; shift || return 1 - echo $(cat "$CID_FILE_DIR/$name") -} - -# ct_get_cip [id] -# -------------------- -# Prints container ip address based on the container id. -# Argument: id - container id -function ct_get_cip() { - local id="$1" ; shift - docker inspect --format='{{.NetworkSettings.IPAddress}}' $(ct_get_cid "$id") -} - -# ct_wait_for_cid [cid_file] -# -------------------- -# Holds the execution until the cid_file is created. Usually run after container -# creation. -# Argument: cid_file - name of the cid_file that should be created -function ct_wait_for_cid() { - local cid_file=$1 - local max_attempts=10 - local sleep_time=1 - local attempt=1 - local result=1 - while [ $attempt -le $max_attempts ]; do - [ -f $cid_file ] && [ -s $cid_file ] && return 0 - : "Waiting for container start..." - attempt=$(( $attempt + 1 )) - sleep $sleep_time - done - return 1 -} - -# ct_assert_container_creation_fails [container_args] -# -------------------- -# The invocation of docker run should fail based on invalid container_args -# passed to the function. Returns 0 when container fails to start properly. -# Argument: container_args - all arguments are passed directly to dokcer run -# Uses: $CID_FILE_DIR - path to directory containing cid_files -function ct_assert_container_creation_fails() { - local ret=0 - local max_attempts=10 - local attempt=1 - local cid_file=assert - set +e - local old_container_args="${CONTAINER_ARGS-}" - CONTAINER_ARGS="$@" - ct_create_container $cid_file - if [ $? -eq 0 ]; then - local cid=$(ct_get_cid $cid_file) - - while [ "$(docker inspect -f '{{.State.Running}}' $cid)" == "true" ] ; do - sleep 2 - attempt=$(( $attempt + 1 )) - if [ $attempt -gt $max_attempts ]; then - docker stop $cid - ret=1 - break - fi - done - exit_status=$(docker inspect -f '{{.State.ExitCode}}' $cid) - if [ "$exit_status" == "0" ]; then - ret=1 - fi - docker rm -v $cid - rm $CID_FILE_DIR/$cid_file - fi - [ ! -z $old_container_args ] && CONTAINER_ARGS="$old_container_args" - set -e - return $ret -} - -# ct_create_container [name, command] -# -------------------- -# Creates a container using the IMAGE_NAME and CONTAINER_ARGS variables. Also -# stores the container id to a cid_file located in the CID_FILE_DIR, and waits -# for the creation of the file. -# Argument: name - name of cid_file where the container id will be stored -# Argument: command - optional command to be executed in the container -# Uses: $CID_FILE_DIR - path to directory containing cid_files -# Uses: $CONTAINER_ARGS - optional arguments passed directly to docker run -# Uses: $IMAGE_NAME - name of the image being tested -function ct_create_container() { - local cid_file="$CID_FILE_DIR/$1" ; shift - # create container with a cidfile in a directory for cleanup - docker run --cidfile="$cid_file" -d ${CONTAINER_ARGS:-} $IMAGE_NAME "$@" - ct_wait_for_cid $cid_file || return 1 - : "Created container $(cat $cid_file)" -} - -# ct_scl_usage_old [name, command, expected] -# -------------------- -# Tests three ways of running the SCL, by looking for an expected string -# in the output of the command -# Argument: name - name of cid_file where the container id will be stored -# Argument: command - executed inside the container -# Argument: expected - string that is expected to be in the command output -# Uses: $CID_FILE_DIR - path to directory containing cid_files -# Uses: $IMAGE_NAME - name of the image being tested -function ct_scl_usage_old() { - local name="$1" - local command="$2" - local expected="$3" - local out="" - : " Testing the image SCL enable" - out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${command}") - if ! echo "${out}" | grep -q "${expected}"; then - echo "ERROR[/bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2 - return 1 - fi - out=$(docker exec $(ct_get_cid $name) /bin/bash -c "${command}" 2>&1) - if ! echo "${out}" | grep -q "${expected}"; then - echo "ERROR[exec /bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2 - return 1 - fi - out=$(docker exec $(ct_get_cid $name) /bin/sh -ic "${command}" 2>&1) - if ! echo "${out}" | grep -q "${expected}"; then - echo "ERROR[exec /bin/sh -ic "${command}"] Expected '${expected}', got '${out}'" >&2 - return 1 - fi -} - -# ct_doc_content_old [strings] -# -------------------- -# Looks for occurence of stirngs in the documentation files and checks -# the format of the files. Files examined: help.1 -# Argument: strings - strings expected to appear in the documentation -# Uses: $IMAGE_NAME - name of the image being tested -function ct_doc_content_old() { - local tmpdir=$(mktemp -d) - local f - : " Testing documentation in the container image" - # Extract the help files from the container - for f in help.1 ; do - docker run --rm ${IMAGE_NAME} /bin/bash -c "cat /${f}" >${tmpdir}/$(basename ${f}) - # Check whether the files contain some important information - for term in $@ ; do - if ! cat ${tmpdir}/$(basename ${f}) | grep -F -q -e "${term}" ; then - echo "ERROR: File /${f} does not include '${term}'." >&2 - return 1 - fi - done - # Check whether the files use the correct format - for term in TH PP SH ; do - if ! grep -q "^\.${term}" ${tmpdir}/help.1 ; then - echo "ERROR: /help.1 is probably not in troff or groff format, since '${term}' is missing." >&2 - return 1 - fi - done - done - : " Success!" -} - - -# ct_npm_works -# -------------------- -# Checks existance of the npm tool and runs it. -function ct_npm_works() { - local tmpdir=$(mktemp -d) - : " Testing npm in the container image" - docker run --rm ${IMAGE_NAME} /bin/bash -c "npm --version" >${tmpdir}/version - - if [ $? -ne 0 ] ; then - echo "ERROR: 'npm --version' does not work inside the image ${IMAGE_NAME}." >&2 - return 1 - fi - - docker run --rm ${IMAGE_NAME} /bin/bash -c "npm install jquery && test -f node_modules/jquery/src/jquery.js" - if [ $? -ne 0 ] ; then - echo "ERROR: npm could not install jquery inside the image ${IMAGE_NAME}." >&2 - return 1 - fi - - : " Success!" -} - - -# ct_path_append PATH_VARNAME DIRECTORY -# ------------------------------------- -# Append DIRECTORY to VARIABLE of name PATH_VARNAME, the VARIABLE must consist -# of colon-separated list of directories. -ct_path_append () -{ - if eval "test -n \"\${$1-}\""; then - eval "$1=\$2:\$$1" - else - eval "$1=\$2" - fi -} - - -# ct_path_foreach PATH ACTION [ARGS ...] -# -------------------------------------- -# For each DIR in PATH execute ACTION (path is colon separated list of -# directories). The particular calls to ACTION will look like -# '$ ACTION directory [ARGS ...]' -ct_path_foreach () -{ - local dir dirlist action save_IFS - save_IFS=$IFS - IFS=: - dirlist=$1 - action=$2 - shift 2 - for dir in $dirlist; do "$action" "$dir" "$@" ; done - IFS=$save_IFS -} - - -# ct_run_test_list -# -------------------- -# Execute the tests specified by TEST_LIST -# Uses: $TEST_LIST - list of test names -function ct_run_test_list() { - for test_case in $TEST_LIST; do - : "Running test $test_case" - [ -f test/$test_case ] && source test/$test_case - [ -f ../test/$test_case ] && source ../test/$test_case - $test_case - done; -} - -# ct_gen_self_signed_cert_pem -# --------------------------- -# Generates a self-signed PEM certificate pair into specified directory. -# Argument: output_dir - output directory path -# Argument: base_name - base name of the certificate files -# Resulted files will be those: -# /-cert-selfsigned.pem -- public PEM cert -# /-key.pem -- PEM private key -ct_gen_self_signed_cert_pem() { - local output_dir=$1 ; shift - local base_name=$1 ; shift - mkdir -p ${output_dir} - openssl req -newkey rsa:2048 -nodes -keyout ${output_dir}/${base_name}-key.pem -subj '/C=GB/ST=Berkshire/L=Newbury/O=My Server Company' > ${base_name}-req.pem - openssl req -new -x509 -nodes -key ${output_dir}/${base_name}-key.pem -batch > ${output_dir}/${base_name}-cert-selfsigned.pem -} - -# ct_obtain_input FILE|DIR|URL -# -------------------- -# Either copies a file or a directory to a tmp location for local copies, or -# downloads the file from remote location. -# Resulted file path is printed, so it can be later used by calling function. -# Arguments: input - local file, directory or remote URL -function ct_obtain_input() { - local input=$1 - local extension="${input##*.}" - - # Try to use same extension for the temporary file if possible - [[ "${extension}" =~ ^[a-z0-9]*$ ]] && extension=".${extension}" || extension="" - - local output=$(mktemp "/var/tmp/test-input-XXXXXX$extension") - if [ -f "${input}" ] ; then - cp -f "${input}" "${output}" - elif [ -d "${input}" ] ; then - rm -f "${output}" - cp -r -LH "${input}" "${output}" - elif echo "${input}" | grep -qe '^http\(s\)\?://' ; then - curl "${input}" > "${output}" - else - echo "ERROR: file type not known: ${input}" >&2 - return 1 - fi - echo "${output}" -} - -# ct_test_response -# ---------------- -# Perform GET request to the application container, checks output with -# a reg-exp and HTTP response code. -# Argument: url - request URL path -# Argument: expected_code - expected HTTP response code -# Argument: body_regexp - PCRE regular expression that must match the response body -# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between -# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10) -ct_test_response() { - local url="$1" - local expected_code="$2" - local body_regexp="$3" - local max_attempts=${4:-20} - local ignore_error_attempts=${5:-10} - - : " Testing the HTTP(S) response for <${url}>" - local sleep_time=3 - local attempt=1 - local result=1 - local status - local response_code - local response_file=$(mktemp /tmp/ct_test_response_XXXXXX) - while [ ${attempt} -le ${max_attempts} ]; do - curl --connect-timeout 10 -s -w '%{http_code}' "${url}" >${response_file} && status=0 || status=1 - if [ ${status} -eq 0 ]; then - response_code=$(cat ${response_file} | tail -c 3) - if [ "${response_code}" -eq "${expected_code}" ]; then - result=0 - fi - cat ${response_file} | grep -qP -e "${body_regexp}" || result=1; - # Some services return 40x code until they are ready, so let's give them - # some chance and not end with failure right away - # Do not wait if we already have expected outcome though - if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then - break - fi - fi - attempt=$(( ${attempt} + 1 )) - sleep ${sleep_time} - done - rm -f ${response_file} - return ${result} -} - -# ct_registry_from_os OS -# ---------------- -# Transform operating system string [os] into registry url -# Argument: OS - string containing the os version -ct_registry_from_os() { - local registry="" - case $1 in - rhel7) - registry=registry.access.redhat.com - ;; - *) - registry=docker.io - ;; - esac - echo "$registry" -} - -# ct_assert_cmd_success CMD -# ---------------- -# Evaluates [cmd] and fails if it does not succeed. -# Argument: CMD - Command to be run -function ct_assert_cmd_success() { - echo "Checking '$*' for success ..." - if ! eval "$@" &>/dev/null; then - echo " FAIL" - return 1 - fi - echo " PASS" - return 0 -} - -# ct_assert_cmd_failure CMD -# ---------------- -# Evaluates [cmd] and fails if it succeeds. -# Argument: CMD - Command to be run -function ct_assert_cmd_failure() { - echo "Checking '$*' for failure ..." - if eval "$@" &>/dev/null; then - echo " FAIL" - return 1 - fi - echo " PASS" - return 0 -} - - -# ct_random_string [LENGTH=10] -# ---------------------------- -# Generate pseudorandom alphanumeric string of LENGTH bytes, the -# default length is 10. The string is printed on stdout. -ct_random_string() -( - export LC_ALL=C - dd if=/dev/urandom count=1 bs=10k 2>/dev/null \ - | tr -dc 'a-z0-9' \ - | fold -w "${1-10}" \ - | head -n 1 -) - -# ct_s2i_usage IMG_NAME [S2I_ARGS] -# ---------------------------- -# Create a container and run the usage script inside -# Argument: IMG_NAME - name of the image to be used for the container run -# Argument: S2I_ARGS - Additional list of source-to-image arguments, currently unused. -ct_s2i_usage() -{ - local img_name=$1; shift - local s2i_args="$*"; - local usage_command="/usr/libexec/s2i/usage" - docker run --rm "$img_name" bash -c "$usage_command" -} - -# ct_s2i_build_as_df APP_PATH SRC_IMAGE DST_IMAGE [S2I_ARGS] -# ---------------------------- -# Create a new s2i app image from local sources in a similar way as source-to-image would have used. -# Argument: APP_PATH - local path to the app sources to be used in the test -# Argument: SRC_IMAGE - image to be used as a base for the s2i build -# Argument: DST_IMAGE - image name to be used during the tagging of the s2i build result -# Argument: S2I_ARGS - Additional list of source-to-image arguments. -# Only used to check for pull-policy=never and environment variable definitions. -ct_s2i_build_as_df() -{ - local app_path=$1; shift - local src_image=$1; shift - local dst_image=$1; shift - local s2i_args="$*"; - local local_app=upload/src/ - local local_scripts=upload/scripts/ - local user_id= - local df_name= - local tmpdir= - # Use /tmp to not pollute cwd - tmpdir=$(mktemp -d) - df_name=$(mktemp -p "$tmpdir" Dockerfile.XXXX) - pushd "$tmpdir" - # Check if the image is available locally and try to pull it if it is not - docker images "$src_image" &>/dev/null || echo "$s2i_args" | grep -q "pull-policy=never" || docker pull "$src_image" - user_id=$(docker inspect -f "{{.ContainerConfig.User}}" "$src_image") - # Strip file:// from APP_PATH and copy its contents into current context - mkdir -p "$local_app" - cp -r "${app_path/file:\/\//}/." "$local_app" - [ -d "$local_app/.s2i/bin/" ] && mv "$local_app/.s2i/bin" "$local_scripts" - # Create a Dockerfile named df_name and fill it with proper content - #FIXME: Some commands could be combined into a single layer but not sure if worth the trouble for testing purposes - cat <"$df_name" -FROM $src_image -LABEL "io.openshift.s2i.build.image"="$src_image" \\ - "io.openshift.s2i.build.source-location"="$app_path" -USER root -COPY $local_app /tmp/src -EOF - [ -d "$local_scripts" ] && echo "COPY $local_scripts /tmp/scripts" >> "$df_name" && - echo "RUN chown -R $user_id:0 /tmp/scripts" >>"$df_name" - echo "RUN chown -R $user_id:0 /tmp/src" >>"$df_name" - # Check for custom environment variables inside .s2i/ folder - if [ -e "$local_app/.s2i/environment" ]; then - # Remove any comments and add the contents as ENV commands to the Dockerfile - sed '/^\s*#.*$/d' "$local_app/.s2i/environment" | while read -r line; do - echo "ENV $line" >>"$df_name" - done - fi - # Filter out env var definitions from $s2i_args and create Dockerfile ENV commands out of them - echo "$s2i_args" | grep -o -e '\(-e\|--env\)[[:space:]=]\S*=\S*' | sed -e 's/-e /ENV /' -e 's/--env[ =]/ENV /' >>"$df_name" - echo "USER $user_id" >>"$df_name" - # If exists, run the custom assemble script, else default to /usr/libexec/s2i/assemble - if [ -x "$local_scripts/assemble" ]; then - echo "RUN /tmp/scripts/assemble" >>"$df_name" - else - echo "RUN /usr/libexec/s2i/assemble" >>"$df_name" - fi - # If exists, set the custom run script as CMD, else default to /usr/libexec/s2i/run - if [ -x "$local_scripts/run" ]; then - echo "CMD /tmp/scripts/run" >>"$df_name" - else - echo "CMD /usr/libexec/s2i/run" >>"$df_name" - fi - # Run the build and tag the result - docker build -f "$df_name" -t "$dst_image" . - popd -} diff --git a/test/utils.sh b/test/utils.sh deleted file mode 100755 index 525c3e2..0000000 --- a/test/utils.sh +++ /dev/null @@ -1,46 +0,0 @@ -#!/usr/bin/env bash - -function print_result { - local RESET='\e[0m' - local RED='\e[0;31m' - local GREEN='\e[0;32m' - local YELLOW='\e[1;33m' - local PASS="${RESET}${GREEN}[PASS]" - local FAIL="${RESET}${RED}[FAIL]" - local WORKING="${RESET}${YELLOW}[....]" - local STATUS="$1" - shift - - if [ "${STATUS}" = pass ]; then - echo -en "${PASS}" - elif [ "${STATUS}" = fail ]; then - echo -en "${FAIL}" - elif [ "${STATUS}" = working ]; then - echo -en "${WORKING}" - else - return - fi - - echo -en " ${@}${RESET}" - echo -} - -function get_status { - if [ "$1" = "$2" ]; then - echo pass - else - echo fail - fi -} - -function run_command { - local cmd="$1" - local expected="${2:-0}" - local msg="${3:-Running command '$cmd'}" - print_result working "$msg" - eval $cmd - local res="$?" - status=`get_status "$res" "$expected"` - print_result "$status" "$msg" - return "$res" -}