Compare commits

...
Sign in to create a new pull request.

8 commits

Author SHA1 Message Date
Marek Skalický
31ef4c5607
Pull changes from upstream and rebase for: latest Fedora base image 2018-11-13 17:24:34 +00:00
Marek Skalický
38ad119200
Add missing version symlink 2018-11-06 14:00:34 +00:00
Marek Skalický
06f217d131
Pull changes from upstream repository. 2018-10-26 13:00:19 +01:00
Mohan Boddu
d31e93c1f2 "Bump RELEASE for automatic rebuild" 2018-07-17 19:55:40 +00:00
Mohan Boddu
e22a0dda0e "Bump RELEASE for automatic rebuild" 2018-05-21 16:37:24 +00:00
Honza Horak
19d921920f Update fedora version 2018-04-25 08:40:25 +02:00
Honza Horak
64049cca16 Pull changes from upstream and rebase for: rebuild for latest fedora:28 2018-04-25 08:30:15 +02:00
Mohan Boddu
060586310c "Bump RELEASE for automatic rebuild" 2018-04-20 14:10:41 +00:00
57 changed files with 3649 additions and 821 deletions

1
10.2 Symbolic link
View file

@ -0,0 +1 @@
.

View file

@ -1,6 +1,4 @@
FROM fedora:27
LABEL MAINTAINER "Honza Horak" <hhorak@redhat.com>
FROM registry.fedoraproject.org/f27/s2i-core:latest
# MariaDB image for OpenShift.
#
@ -13,48 +11,56 @@ LABEL MAINTAINER "Honza Horak" <hhorak@redhat.com>
# * $MYSQL_ROOT_PASSWORD (Optional) - Password for the 'root' MySQL account
ENV MYSQL_VERSION=10.2 \
HOME=/var/lib/mysql
APP_DATA=/opt/app-root/src \
HOME=/var/lib/mysql \
NAME=mariadb \
VERSION=10.2 \
ARCH=x86_64 \
SUMMARY="MariaDB 10.2 SQL database server" \
DESCRIPTION="MariaDB is a multi-user, multi-threaded SQL database server. The container \
image provides a containerized packaging of the MariaDB mysqld daemon and client application. \
The mysqld server daemon accepts connections from clients and provides access to content from \
MariaDB databases on behalf of the clients."
LABEL summary="MariaDB is a multi-user, multi-threaded SQL database server" \
LABEL summary="$SUMMARY" \
description="$DESCRIPTION" \
io.k8s.description="MariaDB is a multi-user, multi-threaded SQL database server" \
io.k8s.display-name="MariaDB 10.2" \
io.openshift.expose-services="3306:mysql" \
io.openshift.tags="database,mysql,mariadb,mariadb101,galera"
ENV NAME=mariadb VERSION=10.2 RELEASE=14 ARCH=x86_64
LABEL BZComponent="$NAME" \
Name="$FGC/$NAME" \
Version="$VERSION" \
Release="$RELEASE.$DISTTAG" \
Architecture="$ARCH"
io.openshift.tags="database,mysql,mariadb,mariadb102,galera" \
com.redhat.component="$NAME" \
name="$FGC/$NAME" \
version="$VERSION" \
usage="docker run -d -e MYSQL_USER=user -e MYSQL_PASSWORD=pass -e MYSQL_DATABASE=db -p 3306:3306 $FGC/$NAME" \
maintainer="SoftwareCollections.org <sclorg@redhat.com>"
EXPOSE 3306
# This image must forever use UID 27 for mysql user so our volumes are
# safe in the future. This should *never* change, the last test is there
# to make sure of that.
RUN INSTALL_PKGS="rsync tar gettext hostname bind-utils mariadb-server policycoreutils" && \
RUN INSTALL_PKGS="rsync tar gettext hostname bind-utils groff-base shadow-utils mariadb mariadb-server policycoreutils" && \
dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \
rpm -V --noghost $INSTALL_PKGS && \
rpm -V $INSTALL_PKGS && \
dnf clean all && \
mkdir -p /var/lib/mysql/data && chown -R mysql.0 /var/lib/mysql && \
test "$(id mysql)" = "uid=27(mysql) gid=27(mysql) groups=27(mysql)"
# On Fedora, we fake missing python binary. In case user installs the python2
# in the container, this hack will be removed by installing /usr/bin/python from RPM.
RUN ln -s /usr/bin/python3 /usr/bin/python
# Get prefix path and path to scripts rather than hard-code them in scripts
ENV CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/mysql \
MYSQL_PREFIX=/usr
ADD root /
COPY 10.2/root-common /
COPY 10.2/s2i-common/bin/ $STI_SCRIPTS_PATH
COPY 10.2/root /
# this is needed due to issues with squash
# when this directory gets rm'd by the container-setup
# script.
RUN rm -rf /etc/my.cnf.d/*
RUN /usr/libexec/container-setup
# Also reset permissions of filesystem to default values
RUN rm -rf /etc/my.cnf.d/* && \
/usr/libexec/container-setup && \
rpm-file-permissions
VOLUME ["/var/lib/mysql/data"]

1
Dockerfile.fedora Symbolic link
View file

@ -0,0 +1 @@
Dockerfile

1
cccp.yml Normal file
View file

@ -0,0 +1 @@
job-id: mariadb-102-centos7

10
content_sets.yml Normal file
View file

@ -0,0 +1,10 @@
# This is a file defining which content sets are needed to update content in
# this image. Data provided here helps determine which images are vulnerable to
# specific CVEs. Generally you should only need to update this file when:
# 1. You start depending on new product
# 2. You are preparing new product release and your content sets will change
---
x86_64:
- rhel-7-server-rpms
- rhel-7-server-optional-rpms
- rhel-server-rhscl-7-rpms

1
help.md Symbolic link
View file

@ -0,0 +1 @@
README.md

View file

@ -9,4 +9,7 @@ skip_name_resolve
# http://www.chriscalender.com/ignoring-the-lostfound-directory-in-your-datadir/
ignore-db-dir=lost+found
# GlusterFS equivalent of 'lost+found'
ignore-db-dir=.trashcan
!includedir /etc/my.cnf.d

31
root-common/usr/bin/run-mysqld Executable file
View file

@ -0,0 +1,31 @@
#!/bin/bash
export_vars=$(cgroup-limits); export $export_vars
source ${CONTAINER_SCRIPTS_PATH}/common.sh
set -eu
if [[ -v DEBUG_IGNORE_SCRIPT_FAILURES ]]; then
set +e
fi
export_setting_variables
log_volume_info $MYSQL_DATADIR
# pre-init files
process_extending_files ${APP_DATA}/mysql-pre-init/ ${CONTAINER_SCRIPTS_PATH}/pre-init/
if [ ! -d "$MYSQL_DATADIR/mysql" ]; then
initialize_database "$@"
else
start_local_mysql "$@"
fi
# init files
process_extending_files ${APP_DATA}/mysql-init/ ${CONTAINER_SCRIPTS_PATH}/init/
# Restart the MySQL server with public IP bindings
shutdown_local_mysql
unset_env_vars
log_volume_info $MYSQL_DATADIR
log_info 'Running final exec -- Only MySQL server logs after this point'
exec ${MYSQL_PREFIX}/libexec/mysqld --defaults-file=$MYSQL_DEFAULTS_FILE "$@" 2>&1

View file

@ -2,26 +2,26 @@
#
# This is an entrypoint that runs the MySQL server in the 'master' mode.
#
export_vars=$(cgroup-limits); export $export_vars
source ${CONTAINER_SCRIPTS_PATH}/common.sh
set -eu
if [[ -v DEBUG_IGNORE_SCRIPT_FAILURES ]]; then
set +e
fi
export_setting_variables
log_volume_info $MYSQL_DATADIR
export MYSQL_RUNNING_AS_MASTER=1
[ -f ${CONTAINER_SCRIPTS_PATH}/validate_replication_variables.sh ] && source ${CONTAINER_SCRIPTS_PATH}/validate_replication_variables.sh
[ -f ${CONTAINER_SCRIPTS_PATH}/validate_variables.sh ] && source ${CONTAINER_SCRIPTS_PATH}/validate_variables.sh
# The 'server-id' for master needs to be constant
export MYSQL_SERVER_ID=1
log_info "The 'master' server-id is ${MYSQL_SERVER_ID}"
# Process the MySQL configuration files
log_info 'Processing MySQL configuration files ...'
envsubst < ${CONTAINER_SCRIPTS_PATH}/my-base.cnf.template > /etc/my.cnf.d/base.cnf
envsubst < ${CONTAINER_SCRIPTS_PATH}/my-paas.cnf.template > /etc/my.cnf.d/paas.cnf
envsubst < ${CONTAINER_SCRIPTS_PATH}/my-master.cnf.template > /etc/my.cnf.d/master.cnf
envsubst < ${CONTAINER_SCRIPTS_PATH}/my-repl-gtid.cnf.template > /etc/my.cnf.d/repl-gtid.cnf
envsubst < ${CONTAINER_SCRIPTS_PATH}/my-tuning.cnf.template > /etc/my.cnf.d/tuning.cnf
# pre-init files
process_extending_files ${APP_DATA}/mysql-pre-init/ ${CONTAINER_SCRIPTS_PATH}/pre-init/
if [ ! -d "$MYSQL_DATADIR/mysql" ]; then
initialize_database "$@"
@ -39,8 +39,8 @@ mysql $mysql_flags <<EOSQL
FLUSH PRIVILEGES;
EOSQL
log_info 'Sourcing post-init.sh ...'
[ -f ${CONTAINER_SCRIPTS_PATH}/post-init.sh ] && source ${CONTAINER_SCRIPTS_PATH}/post-init.sh
# init files
process_extending_files ${APP_DATA}/mysql-init/ ${CONTAINER_SCRIPTS_PATH}/init/
# Restart the MySQL server with public IP bindings
shutdown_local_mysql

View file

@ -0,0 +1,60 @@
#!/bin/bash
#
# This is an entrypoint that runs the MySQL server in the 'slave' mode.
#
export_vars=$(cgroup-limits); export $export_vars
source ${CONTAINER_SCRIPTS_PATH}/common.sh
set -eu
if [[ -v DEBUG_IGNORE_SCRIPT_FAILURES ]]; then
set +e
fi
export_setting_variables
log_volume_info $MYSQL_DATADIR
export MYSQL_RUNNING_AS_SLAVE=1
# Generate the unique 'server-id' for this master
export MYSQL_SERVER_ID=$(server_id)
log_info "The 'slave' server-id is ${MYSQL_SERVER_ID}"
# pre-init files
process_extending_files ${APP_DATA}/mysql-pre-init/ ${CONTAINER_SCRIPTS_PATH}/pre-init/
if [ ! -e "${MYSQL_DATADIR}/mysql" ]; then
# Initialize MySQL database and wait for the MySQL master to accept
# connections.
initialize_database "$@"
wait_for_mysql_master
# Get binlog file and position from master
STATUS_INFO=$(mysql --host "$MYSQL_MASTER_SERVICE_NAME" "-u${MYSQL_MASTER_USER}" "-p${MYSQL_MASTER_PASSWORD}" replication -e 'SELECT gtid from replication limit 1\G')
GTID_VALUE=$(echo "$STATUS_INFO" | grep 'gtid:' | head -n 1 | sed -e 's/^\s*gtid: //')
# checking STATUS_INFO here because empty GTID_VALUE is valid value
if [ -z "${STATUS_INFO}" ] ; then
echo "Could not read GTID value from master"
exit 1
fi
mysql $mysql_flags <<EOSQL
STOP SLAVE;
SET GLOBAL gtid_slave_pos = "${GTID_VALUE}";
CHANGE MASTER TO MASTER_HOST='${MYSQL_MASTER_SERVICE_NAME}',MASTER_USER='${MYSQL_MASTER_USER}', MASTER_PASSWORD='${MYSQL_MASTER_PASSWORD}', MASTER_USE_GTID=slave_pos;
START SLAVE;
EOSQL
# init files
process_extending_files ${APP_DATA}/mysql-init/ ${CONTAINER_SCRIPTS_PATH}/init/
# Restart the MySQL server with public IP bindings
shutdown_local_mysql
fi
unset_env_vars
log_volume_info $MYSQL_DATADIR
log_info 'Running final exec -- Only MySQL server logs after this point'
exec ${MYSQL_PREFIX}/libexec/mysqld --defaults-file=$MYSQL_DEFAULTS_FILE \
--report-host=$(hostname -I) "$@" 2>&1

4
root-common/usr/bin/usage Executable file
View file

@ -0,0 +1,4 @@
#!/bin/bash
cat /usr/share/container-scripts/mysql/README.md

View file

@ -54,5 +54,6 @@ restorecon -R /var/lib/mysql
# arbitrary UID
# When only specifying user, group is 0, that's why /var/lib/mysql must have
# owner mysql.0; that allows to avoid a+rwx for this dir
chmod g+w -R /var/lib/mysql ${MYSQL_CONFIG_FILE}.d
/usr/libexec/fix-permissions /var/lib/mysql ${MYSQL_CONFIG_FILE}.d ${APP_DATA}/..
usermod -a -G root mysql

View file

@ -0,0 +1,6 @@
#!/bin/sh
# Fix permissions on the given directory to allow group read/write of
# regular files and execute of directories.
find $@ -exec chown mysql:0 {} \;
find $@ -exec chmod g+rw {} \;
find $@ -type d -exec chmod g+x {} +

View file

@ -6,6 +6,10 @@
# Sets how the table names are stored and compared. Default: 0
lower_case_table_names = ${MYSQL_LOWER_CASE_TABLE_NAMES}
# Sets whether queries should be logged
general_log = ${MYSQL_LOG_QUERIES_ENABLED}
general_log_file = ${MYSQL_DATADIR}/mysql-query.log
# The maximum permitted number of simultaneous client connections. Default: 151
max_connections = ${MYSQL_MAX_CONNECTIONS}

View file

@ -11,7 +11,6 @@ myisam_sort_buffer_size = 2M
# It is recommended that innodb_buffer_pool_size is configured to 50 to 75 percent of system memory.
innodb_buffer_pool_size = ${MYSQL_INNODB_BUFFER_POOL_SIZE}
innodb_additional_mem_pool_size = 2M
# Set .._log_file_size to 25 % of buffer pool size
innodb_log_file_size = ${MYSQL_INNODB_LOG_FILE_SIZE}
innodb_log_buffer_size = ${MYSQL_INNODB_LOG_BUFFER_SIZE}

View file

@ -0,0 +1,285 @@
#!/bin/bash
source ${CONTAINER_SCRIPTS_PATH}/helpers.sh
# Data directory where MySQL database files live. The data subdirectory is here
# because .bashrc and my.cnf both live in /var/lib/mysql/ and we don't want a
# volume to override it.
export MYSQL_DATADIR=/var/lib/mysql/data
# Configuration settings.
export MYSQL_DEFAULTS_FILE=${MYSQL_DEFAULTS_FILE:-/etc/my.cnf}
function export_setting_variables() {
export MYSQL_BINLOG_FORMAT=${MYSQL_BINLOG_FORMAT:-STATEMENT}
export MYSQL_LOWER_CASE_TABLE_NAMES=${MYSQL_LOWER_CASE_TABLE_NAMES:-0}
export MYSQL_LOG_QUERIES_ENABLED=${MYSQL_LOG_QUERIES_ENABLED:-0}
export MYSQL_MAX_CONNECTIONS=${MYSQL_MAX_CONNECTIONS:-151}
export MYSQL_FT_MIN_WORD_LEN=${MYSQL_FT_MIN_WORD_LEN:-4}
export MYSQL_FT_MAX_WORD_LEN=${MYSQL_FT_MAX_WORD_LEN:-20}
export MYSQL_AIO=${MYSQL_AIO:-1}
export MYSQL_MAX_ALLOWED_PACKET=${MYSQL_MAX_ALLOWED_PACKET:-200M}
export MYSQL_TABLE_OPEN_CACHE=${MYSQL_TABLE_OPEN_CACHE:-400}
export MYSQL_SORT_BUFFER_SIZE=${MYSQL_SORT_BUFFER_SIZE:-256K}
# Export memory limit variables and calculate limits
local export_vars=$(cgroup-limits) && export $export_vars || exit 1
if [ -n "${NO_MEMORY_LIMIT:-}" -o -z "${MEMORY_LIMIT_IN_BYTES:-}" ]; then
export MYSQL_KEY_BUFFER_SIZE=${MYSQL_KEY_BUFFER_SIZE:-32M}
export MYSQL_READ_BUFFER_SIZE=${MYSQL_READ_BUFFER_SIZE:-8M}
export MYSQL_INNODB_BUFFER_POOL_SIZE=${MYSQL_INNODB_BUFFER_POOL_SIZE:-32M}
export MYSQL_INNODB_LOG_FILE_SIZE=${MYSQL_INNODB_LOG_FILE_SIZE:-8M}
export MYSQL_INNODB_LOG_BUFFER_SIZE=${MYSQL_INNODB_LOG_BUFFER_SIZE:-8M}
else
export MYSQL_KEY_BUFFER_SIZE=${MYSQL_KEY_BUFFER_SIZE:-$((MEMORY_LIMIT_IN_BYTES/1024/1024/10))M}
export MYSQL_READ_BUFFER_SIZE=${MYSQL_READ_BUFFER_SIZE:-$((MEMORY_LIMIT_IN_BYTES/1024/1024/20))M}
export MYSQL_INNODB_BUFFER_POOL_SIZE=${MYSQL_INNODB_BUFFER_POOL_SIZE:-$((MEMORY_LIMIT_IN_BYTES/1024/1024/2))M}
# We are multiplying by 15 first and dividing by 100 later so we get as much
# precision as possible with whole numbers. Result is 15% of memory.
export MYSQL_INNODB_LOG_FILE_SIZE=${MYSQL_INNODB_LOG_FILE_SIZE:-$((MEMORY_LIMIT_IN_BYTES*15/1024/1024/100))M}
export MYSQL_INNODB_LOG_BUFFER_SIZE=${MYSQL_INNODB_LOG_BUFFER_SIZE:-$((MEMORY_LIMIT_IN_BYTES*15/1024/1024/100))M}
fi
export MYSQL_DATADIR_ACTION=${MYSQL_DATADIR_ACTION:-upgrade-warn}
}
# this stores whether the database was initialized from empty datadir
export MYSQL_DATADIR_FIRST_INIT=false
# Be paranoid and stricter than we should be.
# https://dev.mysql.com/doc/refman/en/identifiers.html
mysql_identifier_regex='^[a-zA-Z0-9_]+$'
mysql_password_regex='^[a-zA-Z0-9_~!@#$%^&*()-=<>,.?;:|]+$'
# Variables that are used to connect to local mysql during initialization
mysql_flags="-u root --socket=/tmp/mysql.sock"
admin_flags="--defaults-file=$MYSQL_DEFAULTS_FILE $mysql_flags"
# Make sure env variables don't propagate to mysqld process.
function unset_env_vars() {
log_info 'Cleaning up environment variables MYSQL_USER, MYSQL_PASSWORD, MYSQL_DATABASE and MYSQL_ROOT_PASSWORD ...'
unset MYSQL_USER MYSQL_PASSWORD MYSQL_DATABASE MYSQL_ROOT_PASSWORD
}
# Poll until MySQL responds to our ping.
function wait_for_mysql() {
pid=$1 ; shift
while true; do
if [ -d "/proc/$pid" ]; then
mysqladmin $admin_flags ping &>/dev/null && log_info "MySQL started successfully" && return 0
else
return 1
fi
log_info "Waiting for MySQL to start ..."
sleep 1
done
}
# Start local MySQL server with a defaults file
function start_local_mysql() {
log_info 'Starting MySQL server with disabled networking ...'
${MYSQL_PREFIX}/libexec/mysqld \
--defaults-file=$MYSQL_DEFAULTS_FILE \
--skip-networking --socket=/tmp/mysql.sock "$@" &
mysql_pid=$!
wait_for_mysql $mysql_pid
}
# Shutdown mysql flushing privileges
function shutdown_local_mysql() {
log_info 'Shutting down MySQL ...'
mysqladmin $admin_flags flush-privileges shutdown
}
# Initialize the MySQL database (create user accounts and the initial database)
function initialize_database() {
log_info 'Initializing database ...'
log_info 'Running mysql_install_db ...'
# Using --rpm since we need mysql_install_db behaves as in RPM
mysql_install_db --rpm --datadir=$MYSQL_DATADIR
start_local_mysql "$@"
# Running mysql_upgrade creates the mysql_upgrade_info file in the data dir,
# which is necessary to detect which version of the mysqld daemon created the data.
# Checking empty file should not take longer than a second and one extra check should not harm.
mysql_upgrade ${admin_flags}
if [ -v MYSQL_RUNNING_AS_SLAVE ]; then
log_info 'Initialization finished'
return 0
fi
if [ -v MYSQL_RUNNING_AS_MASTER ]; then
# Save master status into a separate database.
STATUS_INFO=$(mysql $admin_flags -e 'SHOW MASTER STATUS\G')
BINLOG_POSITION=$(echo "$STATUS_INFO" | grep 'Position:' | head -n 1 | sed -e 's/^\s*Position: //')
BINLOG_FILE=$(echo "$STATUS_INFO" | grep 'File:' | head -n 1 | sed -e 's/^\s*File: //')
GTID_INFO=$(mysql $admin_flags -e "SELECT BINLOG_GTID_POS('$BINLOG_FILE', '$BINLOG_POSITION') AS gtid_value \G")
GTID_VALUE=$(echo "$GTID_INFO" | grep 'gtid_value:' | head -n 1 | sed -e 's/^\s*gtid_value: //')
mysqladmin $admin_flags create replication
mysql $admin_flags <<EOSQL
use replication
CREATE TABLE replication (gtid VARCHAR(256));
INSERT INTO replication (gtid) VALUES ('$GTID_VALUE');
EOSQL
fi
# Do not care what option is compulsory here, just create what is specified
if [ -v MYSQL_USER ]; then
log_info "Creating user specified by MYSQL_USER (${MYSQL_USER}) ..."
mysql $mysql_flags <<EOSQL
CREATE USER '${MYSQL_USER}'@'%' IDENTIFIED BY '${MYSQL_PASSWORD}';
EOSQL
fi
if [ -v MYSQL_DATABASE ]; then
log_info "Creating database ${MYSQL_DATABASE} ..."
mysqladmin $admin_flags create "${MYSQL_DATABASE}"
if [ -v MYSQL_USER ]; then
log_info "Granting privileges to user ${MYSQL_USER} for ${MYSQL_DATABASE} ..."
mysql $mysql_flags <<EOSQL
GRANT ALL ON \`${MYSQL_DATABASE}\`.* TO '${MYSQL_USER}'@'%' ;
FLUSH PRIVILEGES ;
EOSQL
fi
fi
if [ -v MYSQL_ROOT_PASSWORD ]; then
log_info "Setting password for MySQL root user ..."
if [ "$MYSQL_VERSION" \> "10.0" ] ; then
mysql $mysql_flags <<EOSQL
CREATE USER IF NOT EXISTS 'root'@'%';
EOSQL
fi
mysql $mysql_flags <<EOSQL
GRANT ALL PRIVILEGES ON *.* TO 'root'@'%' IDENTIFIED BY '${MYSQL_ROOT_PASSWORD}' WITH GRANT OPTION;
EOSQL
fi
log_info 'Initialization finished'
# remember that the database was just initialized, it may be needed on other places
export MYSQL_DATADIR_FIRST_INIT=true
}
# The 'server_id' number for slave needs to be within 1-4294967295 range.
# This function will take the 'hostname' if the container, hash it and turn it
# into the number.
# See: https://dev.mysql.com/doc/refman/en/replication-options.html#option_mysqld_server-id
function server_id() {
checksum=$(sha256sum <<< $(hostname -I))
checksum=${checksum:0:14}
echo -n $((0x${checksum}%4294967295))
}
function wait_for_mysql_master() {
while true; do
log_info "Waiting for MySQL master (${MYSQL_MASTER_SERVICE_NAME}) to accept connections ..."
mysqladmin --host=${MYSQL_MASTER_SERVICE_NAME} --user="${MYSQL_MASTER_USER}" \
--password="${MYSQL_MASTER_PASSWORD}" ping &>/dev/null && log_info "MySQL master is ready" && return 0
sleep 1
done
}
# get_matched_files finds file for image extending
function get_matched_files() {
local custom_dir default_dir
custom_dir="$1"
default_dir="$2"
files_matched="$3"
find "$default_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n"
[ -d "$custom_dir" ] && find "$custom_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n"
}
# process_extending_files process extending files in $1 and $2 directories
# - source all *.sh files
# (if there are files with same name source only file from $1)
function process_extending_files() {
local custom_dir default_dir
custom_dir=$1
default_dir=$2
while read filename ; do
echo "=> sourcing $filename ..."
# Custom file is prefered
if [ -f $custom_dir/$filename ]; then
source $custom_dir/$filename
else
source $default_dir/$filename
fi
done <<<"$(get_matched_files "$custom_dir" "$default_dir" '*.sh' | sort -u)"
}
# process extending config files in $1 and $2 directories
# - expand variables in *.cnf and copy the files into /etc/my.cnf.d directory
# (if there are files with same name source only file from $1)
function process_extending_config_files() {
local custom_dir default_dir
custom_dir=$1
default_dir=$2
while read filename ; do
echo "=> sourcing $filename ..."
# Custom file is prefered
if [ -f $custom_dir/$filename ]; then
envsubst < $custom_dir/$filename > /etc/my.cnf.d/$filename
else
envsubst < $default_dir/$filename > /etc/my.cnf.d/$filename
fi
done <<<"$(get_matched_files "$custom_dir" "$default_dir" '*.cnf' | sort -u)"
}
# Converts string version to the integer format (5.5.33 is converted to 505,
# 10.1.23-MariaDB is converted into 1001, etc.
function version2number() {
local version_major=$(echo "$1" | grep -o -e '^[0-9]*\.[0-9]*')
printf %d%02d ${version_major%%.*} ${version_major##*.}
}
# Converts the version in format of an integer into major.minor
function number2version() {
local numver=${1}
echo $((numver / 100)).$((numver % 100))
}
# Prints version of the mysqld that is currently available (string)
function mysqld_version() {
${MYSQL_PREFIX}/libexec/mysqld -V | awk '{print $3}'
}
# Returns version from the daemon in integer format
function mysqld_compat_version() {
version2number $(mysqld_version)
}
# Returns version from the datadir in the integer format
function get_datadir_version() {
local datadir="$1"
local upgrade_info_file=$(get_mysql_upgrade_info_file "$datadir")
[ -r "$upgrade_info_file" ] || return
local version_text=$(cat "$upgrade_info_file" | head -n 1)
version2number "${version_text}"
}
# Returns name of the file in the datadir that holds version information about the data
function get_mysql_upgrade_info_file() {
local datadir="$1"
echo "$datadir/mysql_upgrade_info"
}
# Writes version string of the daemon into mysql_upgrade_info file
# (should be only used when the file is missing and only during limited time;
# once most deployments include this version file, we should leave it on
# scripts to generate the file right after initialization or when upgrading)
function write_mysql_upgrade_info_file() {
local datadir="$1"
local version=$(mysqld_version)
local upgrade_info_file=$(get_mysql_upgrade_info_file "$datadir")
if [ -f "$datadir/mysql_upgrade_info" ] ; then
echo "File ${upgrade_info_file} exists, nothing is done."
else
log_info "Storing version '${version}' information into the data dir '${upgrade_info_file}'"
echo "${version}" > "${upgrade_info_file}"
mysqld_version >"$datadir/mysql_upgrade_info"
fi
}

View file

@ -2,6 +2,10 @@ function log_info {
echo "---> `date +%T` $@"
}
function log_warn {
echo "---> `date +%T` Warning: $@"
}
function log_and_run {
log_info "Running $@"
"$@"
@ -21,4 +25,7 @@ function log_volume_info {
shift
done
set -e
if [[ -v DEBUG_IGNORE_SCRIPT_FAILURES ]]; then
set +e
fi
}

View file

@ -0,0 +1,111 @@
upstream_upgrade_info() {
echo -n "For upstream documentation about upgrading, see: "
case ${MYSQL_VERSION} in
10.0) echo "https://mariadb.com/kb/en/library/upgrading-from-mariadb-55-to-mariadb-100/" ;;
10.1) echo "https://mariadb.com/kb/en/library/upgrading-from-mariadb-100-to-mariadb-101/" ;;
10.2) echo "https://mariadb.com/kb/en/library/upgrading-from-mariadb-101-to-mariadb-102/" ;;
5.6) echo "https://dev.mysql.com/doc/refman/5.6/en/upgrading-from-previous-series.html" ;;
5.7) echo "https://dev.mysql.com/doc/refman/5.7/en/upgrading-from-previous-series.html" ;;
*) echo "Non expected version '${MYSQL_VERSION}'" ; return 1 ;;
esac
}
check_datadir_version() {
local datadir="$1"
local datadir_version=$(get_datadir_version "$datadir")
local mysqld_version=$(mysqld_compat_version)
local datadir_version_dot=$(number2version "${datadir_version}")
local mysqld_version_dot=$(number2version "${mysqld_version}")
for datadir_action in ${MYSQL_DATADIR_ACTION//,/ } ; do
log_info "Running datadir action: ${datadir_action}"
case ${datadir_action} in
upgrade-auto|upgrade-warn)
if [ -z "${datadir_version}" ] || [ "${datadir_version}" -eq 0 ] ; then
# Writing the info file, since historically it was not written
log_warn "Version of the data could not be determined."\
"It is because the file mysql_upgrade_info is missing in the data directory, which"\
"is most probably because it was not created when initialization of data directory."\
"In order to allow seamless updates to the next higher version in the future,"\
"the file mysql_upgrade_info will be created."\
"If the data directory was created with a different version than ${mysqld_version_dot},"\
"it is required to run this container with the MYSQL_DATADIR_ACTION environment variable"\
"set to 'force', or run 'mysql_upgrade' utility manually; the mysql_upgrade tool"\
"checks the tables and creates such a file as well. $(upstream_upgrade_info)"
write_mysql_upgrade_info_file "${MYSQL_DATADIR}"
continue
# This is currently a dead-code, but should be enabled after the mysql_upgrade_info
# file gets to the deployments (after few months most of the deployments should already have the file)
log_warn "Version of the data could not be determined."\
"Running such a container is risky."\
"The current daemon version is ${mysqld_version_dot}."\
"If you are not sure whether the data directory is compatible with the current"\
"version ${mysqld_version_dot}, restore the data from a back-up."\
"If restoring from a back-up is not possible, create a file 'mysql_upgrade_info'"\
"that includes version information (${mysqld_version_dot} in this case) in the root"\
"of the data directory."\
"In order to create the 'mysql_upgrade_info' file, either run this container with"\
"the MYSQL_DATADIR_ACTION environment variable set to 'force', or run 'mysql_upgrade' utility"\
"manually; the mysql_upgrade tool checks the tables and creates such a file as well."\
"That will enable correct upgrade check in the future. $(upstream_upgrade_info)"
fi
if [ "${datadir_version}" -eq "${mysqld_version}" ] ; then
log_info "MySQL server version check passed, both server and data directory"\
"are version ${mysqld_version_dot}."
continue
fi
if [ $(( ${datadir_version} + 1 )) -eq "${mysqld_version}" -o "${datadir_version}" -eq 505 -a "${mysqld_version}" -eq 1000 ] ; then
log_warn "MySQL server is version ${mysqld_version_dot} and datadir is version"\
"${datadir_version_dot}, which is a compatible combination."
if [ "${MYSQL_DATADIR_ACTION}" == 'upgrade-auto' ] ; then
log_info "The data directory will be upgraded automatically from ${datadir_version_dot}"\
"to version ${mysqld_version_dot}. $(upstream_upgrade_info)"
log_and_run mysql_upgrade ${mysql_flags}
else
log_warn "Automatic upgrade is not turned on, proceed with the upgrade."\
"In order to upgrade the data directory, run this container with the MYSQL_DATADIR_ACTION"\
"environment variable set to 'upgrade-auto' or run mysql_upgrade manually. $(upstream_upgrade_info)"
fi
else
log_warn "MySQL server is version ${mysqld_version_dot} and datadir is version"\
"${datadir_version_dot}, which are incompatible. Remember, that upgrade is only supported"\
"by upstream from previous version and it is not allowed to skip versions. $(upstream_upgrade_info)"
if [ "${datadir_version}" -gt "${mysqld_version}" ] ; then
log_warn "Downgrading to the lower version is not supported. Consider"\
"dumping data and load them again into a fresh instance. $(upstream_upgrade_info)"
fi
log_warn "Consider restoring the database from a back-up. To ignore this"\
"warning, set 'MYSQL_DATADIR_ACTION' variable to 'upgrade-force', but this may result in data corruption. $(upstream_upgrade_info)"
return 1
fi
;;
upgrade-force)
log_and_run mysql_upgrade ${mysql_flags} --force
;;
optimize)
log_and_run mysqlcheck ${mysql_flags} --optimize --all-databases --force
;;
analyze)
log_and_run mysqlcheck ${mysql_flags} --analyze --all-databases --force
;;
disable)
log_info "Nothing is done about the data directory."
;;
*)
log_warn "Unknown value of MYSQL_DATADIR_ACTION variable: '${MYSQL_DATADIR_ACTION}', ignoring."
;;
esac
done
}
check_datadir_version "${MYSQL_DATADIR}"
unset -f check_datadir_version upstream_upgrade_info

View file

@ -0,0 +1,49 @@
password_change() {
log_info 'Setting passwords ...'
# Set the password for MySQL user and root everytime this container is started.
# This allows to change the password by editing the deployment configuration.
if [[ -v MYSQL_USER && -v MYSQL_PASSWORD ]]; then
mysql $mysql_flags <<EOSQL
SET PASSWORD FOR '${MYSQL_USER}'@'%' = PASSWORD('${MYSQL_PASSWORD}');
EOSQL
fi
# The MYSQL_ROOT_PASSWORD is optional, therefore we need to either enable remote
# access with a password if the variable is set or disable remote access otherwise.
if [ -v MYSQL_ROOT_PASSWORD ]; then
# GRANT will create a user if it doesn't exist on 10.0 and lower, but we
# need to explicitly call CREATE USER in 10.1 and higher
# then set its password
if [ "$MYSQL_VERSION" \> "10.0" ] ; then
mysql $mysql_flags <<EOSQL
CREATE USER IF NOT EXISTS 'root'@'%';
EOSQL
fi
mysql $mysql_flags <<EOSQL
GRANT ALL PRIVILEGES ON *.* TO 'root'@'%' IDENTIFIED BY '${MYSQL_ROOT_PASSWORD}' WITH GRANT OPTION;
EOSQL
else
if [ "$MYSQL_VERSION" \> "10.0" ] ; then
mysql $mysql_flags <<EOSQL
DROP USER IF EXISTS 'root'@'%';
FLUSH PRIVILEGES;
EOSQL
else
# In 10.0 and lower, We do GRANT and DROP USER to emulate a DROP USER IF EXISTS statement
# http://bugs.mysql.com/bug.php?id=19166
mysql $mysql_flags <<EOSQL
GRANT USAGE ON *.* TO 'root'@'%';
DROP USER 'root'@'%';
FLUSH PRIVILEGES;
EOSQL
fi
fi
}
if ! [ -v MYSQL_RUNNING_AS_SLAVE ] ; then
password_change
fi
unset -f password_change

View file

@ -9,6 +9,7 @@ function usage() {
echo "Or both."
echo "Optional Settings:"
echo " MYSQL_LOWER_CASE_TABLE_NAMES (default: 0)"
echo " MYSQL_LOG_QUERIES_ENABLED (default: 0)"
echo " MYSQL_MAX_CONNECTIONS (default: 151)"
echo " MYSQL_FT_MIN_WORD_LEN (default: 4)"
echo " MYSQL_FT_MAX_WORD_LEN (default: 20)"
@ -30,7 +31,7 @@ function validate_variables() {
# Check basic sanity of specified variables
if [[ -v MYSQL_USER && -v MYSQL_PASSWORD ]]; then
[[ "$MYSQL_USER" =~ $mysql_identifier_regex ]] || usage "Invalid MySQL username"
[ ${#MYSQL_USER} -le 16 ] || usage "MySQL username too long (maximum 16 characters)"
[ ${#MYSQL_USER} -le 80 ] || usage "MySQL username too long (maximum 80 characters)"
[[ "$MYSQL_PASSWORD" =~ $mysql_password_regex ]] || usage "Invalid password"
user_specified=1
fi
@ -75,4 +76,6 @@ function validate_variables() {
fi
}
validate_variables
if ! [ -v MYSQL_RUNNING_AS_SLAVE ] ; then
validate_variables
fi

View file

@ -8,6 +8,7 @@ function validate_replication_variables() {
echo " MYSQL_MASTER_USER"
echo " MYSQL_MASTER_PASSWORD"
echo
return 1
fi
[[ "$MYSQL_DATABASE" =~ $mysql_identifier_regex ]] || usage "Invalid database name"
[[ "$MYSQL_MASTER_USER" =~ $mysql_identifier_regex ]] || usage "Invalid MySQL master username"
@ -15,4 +16,6 @@ function validate_replication_variables() {
[[ "$MYSQL_MASTER_PASSWORD" =~ $mysql_password_regex ]] || usage "Invalid MySQL master password"
}
validate_replication_variables
if [ -v MYSQL_RUNNING_AS_MASTER ] || [ -v MYSQL_RUNNING_AS_SLAVE ] ; then
validate_replication_variables
fi

View file

@ -0,0 +1,3 @@
log_info 'Processing basic MySQL configuration files ...'
envsubst < ${CONTAINER_SCRIPTS_PATH}/pre-init/my-base.cnf.template > /etc/my.cnf.d/base.cnf

View file

@ -0,0 +1,17 @@
# mysqld configuration for replication scenarios
if [ -v MYSQL_RUNNING_AS_MASTER ] || [ -v MYSQL_RUNNING_AS_SLAVE ] ; then
log_info 'Processing basic MySQL configuration for replication (master and slave) files ...'
envsubst < ${CONTAINER_SCRIPTS_PATH}/pre-init/my-repl-gtid.cnf.template > /etc/my.cnf.d/repl-gtid.cnf
fi
if [ -v MYSQL_RUNNING_AS_MASTER ] ; then
log_info 'Processing basic MySQL configuration for replication (master only) files ...'
envsubst < ${CONTAINER_SCRIPTS_PATH}/pre-init/my-master.cnf.template > /etc/my.cnf.d/master.cnf
fi
if [ -v MYSQL_RUNNING_AS_SLAVE ] ; then
log_info 'Processing basic MySQL configuration for replication (slave only) files ...'
envsubst < ${CONTAINER_SCRIPTS_PATH}/pre-init/my-slave.cnf.template > /etc/my.cnf.d/slave.cnf
fi

View file

@ -0,0 +1,6 @@
# additional arbitrary mysqld configuration provided by user using s2i
log_info 'Processing additional arbitrary MySQL configuration provided by s2i ...'
process_extending_config_files ${APP_DATA}/mysql-cfg/ ${CONTAINER_SCRIPTS_PATH}/cnf/

View file

@ -1,332 +1,439 @@
.\"t
.\" WARNING: Do not edit this file manually, it is generated from README.md automatically.
.\"
.\"t
.\" Automatically generated by Pandoc 1.16.0.2
.\"
.TH "MARIADB\-101\-RHEL7" "1" "February 22, 2017" "Container Image Pages" ""
.hy
.SH MariaDB Docker image
.TH MariaDB 10.2 SQL Database Server Docker image
.PP
This container image includes MariaDB server 10.1 for OpenShift and
general usage.
This container image includes MariaDB 10.2 SQL database server for OpenShift and general usage.
Users can choose between RHEL and CentOS based images.
The RHEL image is available in the Red Hat Container Catalog
\[la]https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/mariadb-102-rhel7\[ra]
as registry.access.redhat.com/rhscl/mariadb\-102\-rhel7.
The CentOS image is then available on Docker Hub
\[la]https://hub.docker.com/r/centos/mariadb-102-centos7/\[ra]
as centos/mariadb\-102\-centos7.
.SH Description
.PP
Dockerfile for CentOS is called Dockerfile, Dockerfile for RHEL is
called Dockerfile.rhel7.
.SS Environment variables and volumes
This container image provides a containerized packaging of the MariaDB mysqld daemon
and client application. The mysqld server daemon accepts connections from clients
and provides access to content from MySQL databases on behalf of the clients.
You can find more information on the MariaDB project from the project Web site
(
\[la]https://mariadb.org/\[ra]).
.SH Usage
.PP
The image recognizes the following environment variables that you can
set during initialization by passing \f[C]\-e\ VAR=VALUE\f[] to the
Docker run command.
For this, we will assume that you are using the MariaDB 10.2 container image from the
Red Hat Container Catalog called \fB\fCrhscl/mariadb\-102\-rhel7\fR\&.
If you want to set only the mandatory environment variables and not store
the database in a host directory, execute the following command:
.PP
.TS
tab(@);
l l.
T{
Variable name
T}@T{
Description
T}
_
T{
\f[C]MYSQL_USER\f[]
T}@T{
User name for MySQL account to be created
T}
T{
\f[C]MYSQL_PASSWORD\f[]
T}@T{
Password for the user account
T}
T{
\f[C]MYSQL_DATABASE\f[]
T}@T{
Database name
T}
T{
\f[C]MYSQL_ROOT_PASSWORD\f[]
T}@T{
Password for the root user (optional)
T}
.TE
.PP
The following environment variables influence the MySQL configuration
file.
They are all optional.
.PP
.TS
tab(@);
lw(17.2n) lw(35.5n) lw(17.2n).
T{
Variable name
T}@T{
Description
T}@T{
Default
T}
_
T{
\f[C]MYSQL_LOWER_CASE_TABLE_NAMES\f[]
T}@T{
Sets how the table names are stored and compared
T}@T{
0
T}
T{
\f[C]MYSQL_MAX_CONNECTIONS\f[]
T}@T{
The maximum permitted number of simultaneous client connections
T}@T{
151
T}
T{
\f[C]MYSQL_MAX_ALLOWED_PACKET\f[]
T}@T{
The maximum size of one packet or any generated/intermediate string
T}@T{
200M
T}
T{
\f[C]MYSQL_FT_MIN_WORD_LEN\f[]
T}@T{
The minimum length of the word to be included in a FULLTEXT index
T}@T{
4
T}
T{
\f[C]MYSQL_FT_MAX_WORD_LEN\f[]
T}@T{
The maximum length of the word to be included in a FULLTEXT index
T}@T{
20
T}
T{
\f[C]MYSQL_AIO\f[]
T}@T{
Controls the \f[C]innodb_use_native_aio\f[] setting value in case the
native AIO is broken.
See http://help.directadmin.com/item.php?id=529
T}@T{
1
T}
T{
\f[C]MYSQL_TABLE_OPEN_CACHE\f[]
T}@T{
The number of open tables for all threads
T}@T{
400
T}
T{
\f[C]MYSQL_KEY_BUFFER_SIZE\f[]
T}@T{
The size of the buffer used for index blocks
T}@T{
32M (or 10% of available memory)
T}
T{
\f[C]MYSQL_SORT_BUFFER_SIZE\f[]
T}@T{
The size of the buffer used for sorting
T}@T{
256K
T}
T{
\f[C]MYSQL_READ_BUFFER_SIZE\f[]
T}@T{
The size of the buffer used for a sequential scan
T}@T{
8M (or 5% of available memory)
T}
T{
\f[C]MYSQL_INNODB_BUFFER_POOL_SIZE\f[]
T}@T{
The size of the buffer pool where InnoDB caches table and index data
T}@T{
32M (or 50% of available memory)
T}
T{
\f[C]MYSQL_INNODB_LOG_FILE_SIZE\f[]
T}@T{
The size of each log file in a log group
T}@T{
8M (or 15% of available available)
T}
T{
\f[C]MYSQL_INNODB_LOG_BUFFER_SIZE\f[]
T}@T{
The size of the buffer that InnoDB uses to write to the log files on
disk
T}@T{
8M (or 15% of available memory)
T}
T{
\f[C]MYSQL_DEFAULTS_FILE\f[]
T}@T{
Point to an alternative configuration file
T}@T{
/etc/my.cnf
T}
T{
\f[C]MYSQL_BINLOG_FORMAT\f[]
T}@T{
Set sets the binlog format, supported values are \f[C]row\f[] and
\f[C]statement\f[]
T}@T{
statement
T}
.TE
.PP
You can also set the following mount points by passing the
\f[C]\-v\ /host:/container\f[] flag to Docker.
.PP
.TS
tab(@);
l l.
T{
Volume mount point
T}@T{
Description
T}
_
T{
\f[C]/var/lib/mysql/data\f[]
T}@T{
MySQL data directory
T}
.TE
.PP
\f[B]Notice: When mouting a directory from the host into the container,
ensure that the mounted directory has the appropriate permissions and
that the owner and group of the directory matches the user UID or name
which is running inside the container.\f[]
.SS Usage
.PP
For this, we will assume that you are using the
\f[C]rhscl/mariadb\-100\-rhel7\f[] image.
If you want to set only the mandatory environment variables and not
store the database in a host directory, execute the following command:
.IP
.RS
.nf
\f[C]
$\ docker\ run\ \-d\ \-\-name\ mariadb_database\ \-e\ MYSQL_USER=user\ \-e\ MYSQL_PASSWORD=pass\ \-e\ MYSQL_DATABASE=db\ \-p\ 3306:3306\ rhscl/mariadb\-100\-rhel7
\f[]
$ docker run \-d \-\-name mariadb\_database \-e MYSQL\_USER=user \-e MYSQL\_PASSWORD=pass \-e MYSQL\_DATABASE=db \-p 3306:3306 rhscl/mariadb\-102\-rhel7
.fi
.RE
.PP
This will create a container named \f[C]mariadb_database\f[] running
MySQL with database \f[C]db\f[] and user with credentials
\f[C]user:pass\f[].
Port 3306 will be exposed and mapped to the host.
If you want your database to be persistent across container executions,
also add a \f[C]\-v\ /host/db/path:/var/lib/mysql/data\f[] argument.
This will be the MySQL data directory.
This will create a container named \fB\fCmariadb\_database\fR running MySQL with database
\fB\fCdb\fR and user with credentials \fB\fCuser:pass\fR\&. Port 3306 will be exposed and mapped
to the host. If you want your database to be persistent across container executions,
also add a \fB\fC\-v /host/db/path:/var/lib/mysql/data\fR argument. This will be the MySQL
data directory.
.PP
If the database directory is not initialized, the entrypoint script will
first run
\f[C]mysql_install_db\f[] (https://dev.mysql.com/doc/refman/5.6/en/mysql-install-db.html)
and setup necessary database users and passwords.
After the database is initialized, or if it was already present,
\f[C]mysqld\f[] is executed and will run as PID 1.
You can stop the detached container by running
\f[C]docker\ stop\ mariadb_database\f[].
.SS MariaDB auto\-tuning
If the database directory is not initialized, the entrypoint script will first
run \fB\fCmysql\_install\_db\fR
\[la]https://dev.mysql.com/doc/refman/5.6/en/mysql-install-db.html\[ra]
and setup necessary database users and passwords. After the database is initialized,
or if it was already present, \fB\fCmysqld\fR is executed and will run as PID 1. You can
stop the detached container by running \fB\fCdocker stop mariadb\_database\fR\&.
.SH Environment variables and volumes
.PP
When the MySQL image is run with the \f[C]\-\-memory\f[] parameter set
and you didn\[aq]t specify value for some parameters, their values will
be automatically calculated based on the available memory.
The image recognizes the following environment variables that you can set during
initialization by passing \fB\fC\-e VAR=VALUE\fR to the Docker run command.
.PP
.TS
tab(@);
l l l.
T{
Variable name
T}@T{
Configuration parameter
T}@T{
Relative value
T}
_
T{
\f[C]MYSQL_KEY_BUFFER_SIZE\f[]
T}@T{
\f[C]key_buffer_size\f[]
T}@T{
10%
T}
T{
\f[C]MYSQL_READ_BUFFER_SIZE\f[]
T}@T{
\f[C]read_buffer_size\f[]
T}@T{
5%
T}
T{
\f[C]MYSQL_INNODB_BUFFER_POOL_SIZE\f[]
T}@T{
\f[C]innodb_buffer_pool_size\f[]
T}@T{
50%
T}
T{
\f[C]MYSQL_INNODB_LOG_FILE_SIZE\f[]
T}@T{
\f[C]innodb_log_file_size\f[]
T}@T{
15%
T}
T{
\f[C]MYSQL_INNODB_LOG_BUFFER_SIZE\f[]
T}@T{
\f[C]innodb_log_buffer_size\f[]
T}@T{
15%
T}
.TE
.SS MySQL root user
\fB\fB\fCMYSQL\_USER\fR\fP
.br
User name for MySQL account to be created
.PP
The root user has no password set by default, only allowing local
connections.
You can set it by setting the \f[C]MYSQL_ROOT_PASSWORD\f[] environment
variable.
This will allow you to login to the root account remotely.
Local connections will still not require a password.
\fB\fB\fCMYSQL\_PASSWORD\fR\fP
.br
Password for the user account
.PP
To disable remote root access, simply unset \f[C]MYSQL_ROOT_PASSWORD\f[]
and restart the container.
.SS Changing passwords
\fB\fB\fCMYSQL\_DATABASE\fR\fP
.br
Database name
.PP
Since passwords are part of the image configuration, the only supported
method to change passwords for the database user (\f[C]MYSQL_USER\f[])
and root user is by changing the environment variables
\f[C]MYSQL_PASSWORD\f[] and \f[C]MYSQL_ROOT_PASSWORD\f[], respectively.
\fB\fB\fCMYSQL\_ROOT\_PASSWORD\fR\fP
.br
Password for the root user (optional)
.PP
Changing database passwords through SQL statements or any way other than
through the environment variables aforementioned will cause a mismatch
between the values stored in the variables and the actual passwords.
Whenever a database container starts it will reset the passwords to the
values stored in the environment variables.
.SS Default my.cnf file
The following environment variables influence the MySQL configuration file. They are all optional.
.PP
With environment variables we are able to customize a lot of different
parameters or configurations for the mysql bootstrap configurations.
If you\[aq]d prefer to use your own configuration file, you can override
the \f[C]MYSQL_DEFAULTS_FILE\f[] env variable with the full path of the
file you wish to use.
For example, the default location is \f[C]/etc/my.cnf\f[] but you can
change it to \f[C]/etc/mysql/my.cnf\f[] by setting
\f[C]MYSQL_DEFAULTS_FILE=/etc/mysql/my.cnf\f[]
.SS Changing the replication binlog_format
\fB\fB\fCMYSQL\_LOWER\_CASE\_TABLE\_NAMES (default: 0)\fR\fP
.br
Sets how the table names are stored and compared
.PP
Some applications may wish to use \f[C]row\f[] binlog_formats (for
example, those built with change\-data\-capture in mind).
The default replication/binlog format is \f[C]statement\f[] but to
change it you can set the \f[C]MYSQL_BINLOG_FORMAT\f[] environment
variable.
For example \f[C]MYSQL_BINLOG_FORMAT=row\f[].
Now when you run the database with \f[C]master\f[] replication turned on
(ie, set the Docker/container \f[C]cmd\f[] to be
\f[C]run\-mysqld\-master\f[]) the binlog will emit the actual data for
the rows that change as opposed to the statements (ie, DML like
insert...) that caused the change.
.SH AUTHORS
Red Hat.
\fB\fB\fCMYSQL\_MAX\_CONNECTIONS (default: 151)\fR\fP
.br
The maximum permitted number of simultaneous client connections
.PP
\fB\fB\fCMYSQL\_MAX\_ALLOWED\_PACKET (default: 200M)\fR\fP
.br
The maximum size of one packet or any generated/intermediate string
.PP
\fB\fB\fCMYSQL\_FT\_MIN\_WORD\_LEN (default: 4)\fR\fP
.br
The minimum length of the word to be included in a FULLTEXT index
.PP
\fB\fB\fCMYSQL\_FT\_MAX\_WORD\_LEN (default: 20)\fR\fP
.br
The maximum length of the word to be included in a FULLTEXT index
.PP
\fB\fB\fCMYSQL\_AIO (default: 1)\fR\fP
.br
Controls the \fB\fCinnodb\_use\_native\_aio\fR setting value in case the native AIO is broken. See
\[la]http://help.directadmin.com/item.php?id=529\[ra]
.PP
\fB\fB\fCMYSQL\_TABLE\_OPEN\_CACHE (default: 400)\fR\fP
.br
The number of open tables for all threads
.PP
\fB\fB\fCMYSQL\_KEY\_BUFFER\_SIZE (default: 32M or 10% of available memory)\fR\fP
.br
The size of the buffer used for index blocks
.PP
\fB\fB\fCMYSQL\_SORT\_BUFFER\_SIZE (default: 256K)\fR\fP
.br
The size of the buffer used for sorting
.PP
\fB\fB\fCMYSQL\_READ\_BUFFER\_SIZE (default: 8M or 5% of available memory)\fR\fP
.br
The size of the buffer used for a sequential scan
.PP
\fB\fB\fCMYSQL\_INNODB\_BUFFER\_POOL\_SIZE (default: 32M or 50% of available memory)\fR\fP
.br
The size of the buffer pool where InnoDB caches table and index data
.PP
\fB\fB\fCMYSQL\_INNODB\_LOG\_FILE\_SIZE (default: 8M or 15% of available available)\fR\fP
.br
The size of each log file in a log group
.PP
\fB\fB\fCMYSQL\_INNODB\_LOG\_BUFFER\_SIZE (default: 8M or 15% of available memory)\fR\fP
.br
The size of the buffer that InnoDB uses to write to the log files on disk
.PP
\fB\fB\fCMYSQL\_DEFAULTS\_FILE (default: /etc/my.cnf)\fR\fP
.br
Point to an alternative configuration file
.PP
\fB\fB\fCMYSQL\_BINLOG\_FORMAT (default: statement)\fR\fP
.br
Set sets the binlog format, supported values are \fB\fCrow\fR and \fB\fCstatement\fR
.PP
\fB\fB\fCMYSQL\_LOG\_QUERIES\_ENABLED (default: 0)\fR\fP
.br
To enable query logging set this to \fB\fC1\fR
.PP
You can also set the following mount points by passing the \fB\fC\-v /host:/container\fR flag to Docker.
.PP
\fB\fB\fC/var/lib/mysql/data\fR\fP
.br
MySQL data directory
.PP
\fBNotice: When mouting a directory from the host into the container, ensure that the mounted
directory has the appropriate permissions and that the owner and group of the directory
matches the user UID or name which is running inside the container.\fP
.SH MariaDB auto\-tuning
.PP
When the MySQL image is run with the \fB\fC\-\-memory\fR parameter set and you didn't
specify value for some parameters, their values will be automatically
calculated based on the available memory.
.PP
\fB\fB\fCMYSQL\_KEY\_BUFFER\_SIZE (default: 10%)\fR\fP
.br
\fB\fCkey\_buffer\_size\fR
.PP
\fB\fB\fCMYSQL\_READ\_BUFFER\_SIZE (default: 5%)\fR\fP
.br
\fB\fCread\_buffer\_size\fR
.PP
\fB\fB\fCMYSQL\_INNODB\_BUFFER\_POOL\_SIZE (default: 50%)\fR\fP
.br
\fB\fCinnodb\_buffer\_pool\_size\fR
.PP
\fB\fB\fCMYSQL\_INNODB\_LOG\_FILE\_SIZE (default: 15%)\fR\fP
.br
\fB\fCinnodb\_log\_file\_size\fR
.PP
\fB\fB\fCMYSQL\_INNODB\_LOG\_BUFFER\_SIZE (default: 15%)\fR\fP
.br
\fB\fCinnodb\_log\_buffer\_size\fR
.SH MySQL root user
.PP
The root user has no password set by default, only allowing local connections.
You can set it by setting the \fB\fCMYSQL\_ROOT\_PASSWORD\fR environment variable. This
will allow you to login to the root account remotely. Local connections will
still not require a password.
.PP
To disable remote root access, simply unset \fB\fCMYSQL\_ROOT\_PASSWORD\fR and restart
the container.
.SH Changing passwords
.PP
Since passwords are part of the image configuration, the only supported method
to change passwords for the database user (\fB\fCMYSQL\_USER\fR) and root user is by
changing the environment variables \fB\fCMYSQL\_PASSWORD\fR and \fB\fCMYSQL\_ROOT\_PASSWORD\fR,
respectively.
.PP
Changing database passwords through SQL statements or any way other than through
the environment variables aforementioned will cause a mismatch between the
values stored in the variables and the actual passwords. Whenever a database
container starts it will reset the passwords to the values stored in the
environment variables.
.SH Default my.cnf file
.PP
With environment variables we are able to customize a lot of different parameters
or configurations for the mysql bootstrap configurations. If you'd prefer to use
your own configuration file, you can override the \fB\fCMYSQL\_DEFAULTS\_FILE\fR env
variable with the full path of the file you wish to use. For example, the default
location is \fB\fC/etc/my.cnf\fR but you can change it to \fB\fC/etc/mysql/my.cnf\fR by setting
\fB\fCMYSQL\_DEFAULTS\_FILE=/etc/mysql/my.cnf\fR
.SH Extending image
.PP
This image can be extended using source\-to\-image
\[la]https://github.com/openshift/source-to-image\[ra]\&.
.PP
For example, to build a customized MariaDB database image \fB\fCmy\-mariadb\-rhel7\fR
with a configuration in \fB\fC\~/image\-configuration/\fR run:
.PP
.RS
.nf
$ s2i build \~/image\-configuration/ rhscl/mariadb\-102\-rhel7 my\-mariadb\-rhel7
.fi
.RE
.PP
The directory passed to \fB\fCs2i build\fR can contain these directories:
.PP
\fB\fCmysql\-cfg/\fR
When starting the container, files from this directory will be used as
a configuration for the \fB\fCmysqld\fR daemon.
\fB\fCenvsubst\fR command is run on this file to still allow customization of
the image using environmental variables
.PP
\fB\fCmysql\-pre\-init/\fR
Shell scripts (\fB\fC*.sh\fR) available in this directory are sourced before
\fB\fCmysqld\fR daemon is started.
.PP
\fB\fCmysql\-init/\fR
Shell scripts (\fB\fC*.sh\fR) available in this directory are sourced when
\fB\fCmysqld\fR daemon is started locally. In this phase, use \fB\fC${mysql\_flags}\fR
to connect to the locally running daemon, for example \fB\fCmysql $mysql\_flags < dump.sql\fR
.PP
Variables that can be used in the scripts provided to s2i:
.PP
\fB\fC$mysql\_flags\fR
arguments for the \fB\fCmysql\fR tool that will connect to the locally running \fB\fCmysqld\fR during initialization
.PP
\fB\fC$MYSQL\_RUNNING\_AS\_MASTER\fR
variable defined when the container is run with \fB\fCrun\-mysqld\-master\fR command
.PP
\fB\fC$MYSQL\_RUNNING\_AS\_SLAVE\fR
variable defined when the container is run with \fB\fCrun\-mysqld\-slave\fR command
.PP
\fB\fC$MYSQL\_DATADIR\_FIRST\_INIT\fR
variable defined when the container was initialized from the empty data dir
.PP
During \fB\fCs2i build\fR all provided files are copied into \fB\fC/opt/app\-root/src\fR
directory into the resulting image. If some configuration files are present
in the destination directory, files with the same name are overwritten.
Also only one file with the same name can be used for customization and user
provided files are preferred over default files in
\fB\fC/usr/share/container\-scripts/mysql/\fR\- so it is possible to overwrite them.
.PP
Same configuration directory structure can be used to customize the image
every time the image is started using \fB\fCdocker run\fR\&. The directory has to be
mounted into \fB\fC/opt/app\-root/src/\fR in the image
(\fB\fC\-v ./image\-configuration/:/opt/app\-root/src/\fR).
This overwrites customization built into the image.
.SH Securing the connection with SSL
.PP
In order to secure the connection with SSL, use the extending feature described
above. In particular, put the SSL certificates into a separate directory:
.PP
.RS
.nf
sslapp/mysql\-certs/server\-cert\-selfsigned.pem
sslapp/mysql\-certs/server\-key.pem
.fi
.RE
.PP
And then put a separate configuration file into mysql\-cfg:
.PP
.RS
.nf
$> cat sslapp/mysql\-cfg/ssl.cnf
[mysqld]
ssl\-key=${APP\_DATA}/mysql\-certs/server\-key.pem
ssl\-cert=${APP\_DATA}/mysql\-certs/server\-cert\-selfsigned.pem
.fi
.RE
.PP
Such a directory \fB\fCsslapp\fR can then be mounted into the container with \-v,
or a new container image can be built using s2i.
.SH Upgrading and data directory version checking
.PP
MySQL and MariaDB use versions that consist of three numbers X.Y.Z (e.g. 5.6.23).
For version changes in Z part, the server's binary data format stays compatible and thus no
special upgrade procedure is needed. For upgrades from X.Y to X.Y+1, consider doing manual
steps as described at
\[la]https://mariadb.com/kb/en/library/upgrading-from-mariadb-101-to-mariadb-102/\[ra]
.PP
Skipping versions like from X.Y to X.Y+2 or downgrading to lower version is not supported;
the only exception is ugrading from MariaDB 5.5 to MariaDB 10.0.
.PP
\fBImportant\fP: Upgrading to a new version is always risky and users are expected to make a full
back\-up of all data before.
.PP
A safer solution to upgrade is to dump all data using \fB\fCmysqldump\fR or \fB\fCmysqldbexport\fR and then
load the data using \fB\fCmysql\fR or \fB\fCmysqldbimport\fR into an empty (freshly initialized) database.
.PP
Another way of proceeding with the upgrade is starting the new version of the \fB\fCmysqld\fR daemon
and run \fB\fCmysql\_upgrade\fR right after the start. This so called in\-place upgrade is generally
faster for large data directory, but only possible if upgrading from the very previous version,
so skipping versions is not supported.
.PP
This container detects whether the data needs to be upgraded using \fB\fCmysql\_upgrade\fR and
we can control it by setting \fB\fCMYSQL\_DATADIR\_ACTION\fR variable, which can have one or more of the following values:
.IP \(bu 2
\fB\fCupgrade\-warn\fR \-\- If the data version can be determined and the data come from a different version
of the daemon, a warning is printed but the container starts. This is the default value.
Since historically the version file \fB\fCmysql\_upgrade\_info\fR was not created, when using this option,
the version file is created if not exist, but no \fB\fCmysql\_upgrade\fR will be called.
However, this automatic creation will be removed after few months, since the version should be
created on most deployments at that point.
.IP \(bu 2
\fB\fCupgrade\-auto\fR \-\- \fB\fCmysql\_upgrade\fR is run at the beginning of the container start, when the local
daemon is running, but only if the data version can be determined and the data come
with the very previous version. A warning is printed if the data come from even older
or newer version. This value effectively enables automatic upgrades,
but it is always risky and users should still back\-up all the data before starting the newer container.
Set this option only if you have very good back\-ups at any moment and you are fine to fail\-over
from the back\-up.
.IP \(bu 2
\fB\fCupgrade\-force\fR \-\- \fB\fCmysql\_upgrade \-\-force\fR is run at the beginning of the container start, when the local
daemon is running, no matter what version of the daemon the data come from.
This is also the way to create the missing version file \fB\fCmysql\_upgrade\_info\fR if not present
in the root of the data directory; this file holds information about the version of the data.
.PP
There are also some other actions that you may want to run at the beginning of the container start,
when the local daemon is running, no matter what version of the data is detected:
.IP \(bu 2
\fB\fCoptimize\fR \-\- runs \fB\fCmysqlcheck \-\-optimize\fR\&. It optimizes all the tables.
.IP \(bu 2
\fB\fCanalyze\fR \-\- runs \fB\fCmysqlcheck \-\-analyze\fR\&. It analyzes all the tables.
.IP \(bu 2
\fB\fCdisable\fR \-\- nothing is done regarding data directory version.
.PP
Multiple values are separated by comma and run in\-order, e.g. \fB\fCMYSQL\_DATADIR\_ACTION="optimize,analyze"\fR\&.
.SH Changing the replication binlog\_format
.PP
Some applications may wish to use \fB\fCrow\fR binlog\_formats (for example, those built
with change\-data\-capture in mind). The default replication/binlog format is
\fB\fCstatement\fR but to change it you can set the \fB\fCMYSQL\_BINLOG\_FORMAT\fR environment
variable. For example \fB\fCMYSQL\_BINLOG\_FORMAT=row\fR\&. Now when you run the database
with \fB\fCmaster\fR replication turned on (ie, set the Docker/container \fB\fCcmd\fR to be
\fB\fCrun\-mysqld\-master\fR) the binlog will emit the actual data for the rows that change
as opposed to the statements (ie, DML like insert...) that caused the change.
.SH Troubleshooting
.PP
The mysqld deamon in the container logs to the standard output, so the log is available in the container log. The log can be examined by running:
.PP
.RS
.nf
docker logs <container>
.fi
.RE
.SH See also
.PP
Dockerfile and other sources for this container image are available on
\[la]https://github.com/sclorg/mariadb-container\[ra]\&.
In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile
for RHEL is called Dockerfile.rhel7.

View file

@ -1,35 +0,0 @@
#!/bin/bash
export_vars=$(cgroup-limits); export $export_vars
source ${CONTAINER_SCRIPTS_PATH}/common.sh
set -eu
[ -f ${CONTAINER_SCRIPTS_PATH}/validate-variables.sh ] && source ${CONTAINER_SCRIPTS_PATH}/validate-variables.sh
# Process the MySQL configuration files
log_info 'Processing MySQL configuration files ...'
envsubst < ${CONTAINER_SCRIPTS_PATH}/my-base.cnf.template > /etc/my.cnf.d/base.cnf
envsubst < ${CONTAINER_SCRIPTS_PATH}/my-paas.cnf.template > /etc/my.cnf.d/paas.cnf
envsubst < ${CONTAINER_SCRIPTS_PATH}/my-tuning.cnf.template > /etc/my.cnf.d/tuning.cnf
if [ ! -d "$MYSQL_DATADIR/mysql" ]; then
initialize_database "$@"
else
start_local_mysql "$@"
fi
if [ -f ${CONTAINER_SCRIPTS_PATH}/passwd-change.sh ]; then
log_info 'Setting passwords ...'
source ${CONTAINER_SCRIPTS_PATH}/passwd-change.sh
fi
if [ -f ${CONTAINER_SCRIPTS_PATH}/post-init.sh ]; then
log_info 'Sourcing post-init.sh ...'
source ${CONTAINER_SCRIPTS_PATH}/post-init.sh
fi
# Restart the MySQL server with public IP bindings
shutdown_local_mysql
unset_env_vars
log_volume_info $MYSQL_DATADIR
log_info 'Running final exec -- Only MySQL server logs after this point'
exec ${MYSQL_PREFIX}/libexec/mysqld --defaults-file=$MYSQL_DEFAULTS_FILE "$@" 2>&1

View file

@ -1,60 +0,0 @@
#!/bin/bash
#
# This is an entrypoint that runs the MySQL server in the 'slave' mode.
#
export_vars=$(cgroup-limits); export $export_vars
source ${CONTAINER_SCRIPTS_PATH}/common.sh
set -eu
# Just run normal server if the data directory is already initialized
if [ -d "${MYSQL_DATADIR}/mysql" ]; then
exec /usr/bin/run-mysqld "$@"
fi
export MYSQL_RUNNING_AS_SLAVE=1
[ -f ${CONTAINER_SCRIPTS_PATH}/validate_replication_variables.sh ] && source ${CONTAINER_SCRIPTS_PATH}/validate_replication_variables.sh
# Generate the unique 'server-id' for this master
export MYSQL_SERVER_ID=$(server_id)
log_info "The 'slave' server-id is ${MYSQL_SERVER_ID}"
# Process the MySQL configuration files
envsubst < ${CONTAINER_SCRIPTS_PATH}/my-base.cnf.template > /etc/my.cnf.d/base.cnf
envsubst < ${CONTAINER_SCRIPTS_PATH}/my-paas.cnf.template > /etc/my.cnf.d/paas.cnf
envsubst < ${CONTAINER_SCRIPTS_PATH}/my-slave.cnf.template > /etc/my.cnf.d/slave.cnf
envsubst < ${CONTAINER_SCRIPTS_PATH}/my-repl-gtid.cnf.template > /etc/my.cnf.d/repl-gtid.cnf
envsubst < ${CONTAINER_SCRIPTS_PATH}/my-tuning.cnf.template > /etc/my.cnf.d/tuning.cnf
# Initialize MySQL database and wait for the MySQL master to accept
# connections.
initialize_database "$@"
wait_for_mysql_master
# Get binlog file and position from master
STATUS_INFO=$(mysql --host "$MYSQL_MASTER_SERVICE_NAME" "-u${MYSQL_MASTER_USER}" "-p${MYSQL_MASTER_PASSWORD}" replication -e 'SELECT gtid from replication limit 1\G')
GTID_VALUE=$(echo "$STATUS_INFO" | grep 'gtid:' | head -n 1 | sed -e 's/^\s*gtid: //')
# checking STATUS_INFO here because empty GTID_VALUE is valid value
if [ -z "${STATUS_INFO}" ] ; then
echo "Could not read GTID value from master"
exit 1
fi
mysql $mysql_flags <<EOSQL
STOP SLAVE;
SET GLOBAL gtid_slave_pos = "${GTID_VALUE}";
CHANGE MASTER TO MASTER_HOST='${MYSQL_MASTER_SERVICE_NAME}',MASTER_USER='${MYSQL_MASTER_USER}', MASTER_PASSWORD='${MYSQL_MASTER_PASSWORD}', MASTER_USE_GTID=slave_pos;
START SLAVE;
EOSQL
log_info 'Sourcing post-init.sh ...'
[ -f ${CONTAINER_SCRIPTS_PATH}/post-init.sh ] && source ${CONTAINER_SCRIPTS_PATH}/post-init.sh
# Restart the MySQL server with public IP bindings
shutdown_local_mysql
unset_env_vars
log_volume_info $MYSQL_DATADIR
log_info 'Running final exec -- Only MySQL server logs after this point'
exec ${MYSQL_PREFIX}/libexec/mysqld --defaults-file=$MYSQL_DEFAULTS_FILE \
--report-host=$(hostname -i) "$@" 2>&1

View file

@ -1,64 +1,34 @@
MariaDB Docker image
====================
MariaDB 10.2 SQL Database Server Docker image
=============================================
This container image includes MariaDB server 10.1 for OpenShift and general usage.
This container image includes MariaDB 10.2 SQL database server for OpenShift and general usage.
Users can choose between RHEL and CentOS based images.
The RHEL image is available in the [Red Hat Container Catalog](https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/mariadb-102-rhel7)
as registry.access.redhat.com/rhscl/mariadb-102-rhel7.
The CentOS image is then available on [Docker Hub](https://hub.docker.com/r/centos/mariadb-102-centos7/)
as centos/mariadb-102-centos7.
Dockerfile for CentOS is called Dockerfile, Dockerfile for RHEL is called
Dockerfile.rhel7.
Environment variables and volumes
----------------------------------
Description
-----------
The image recognizes the following environment variables that you can set during
initialization by passing `-e VAR=VALUE` to the Docker run command.
This container image provides a containerized packaging of the MariaDB mysqld daemon
and client application. The mysqld server daemon accepts connections from clients
and provides access to content from MySQL databases on behalf of the clients.
You can find more information on the MariaDB project from the project Web site
(https://mariadb.org/).
| Variable name | Description |
| :--------------------- | ----------------------------------------- |
| `MYSQL_USER` | User name for MySQL account to be created |
| `MYSQL_PASSWORD` | Password for the user account |
| `MYSQL_DATABASE` | Database name |
| `MYSQL_ROOT_PASSWORD` | Password for the root user (optional) |
The following environment variables influence the MySQL configuration file. They are all optional.
| Variable name | Description | Default
| :------------------------------ | ----------------------------------------------------------------- | -------------------------------
| `MYSQL_LOWER_CASE_TABLE_NAMES` | Sets how the table names are stored and compared | 0
| `MYSQL_MAX_CONNECTIONS` | The maximum permitted number of simultaneous client connections | 151
| `MYSQL_MAX_ALLOWED_PACKET` | The maximum size of one packet or any generated/intermediate string | 200M
| `MYSQL_FT_MIN_WORD_LEN` | The minimum length of the word to be included in a FULLTEXT index | 4
| `MYSQL_FT_MAX_WORD_LEN` | The maximum length of the word to be included in a FULLTEXT index | 20
| `MYSQL_AIO` | Controls the `innodb_use_native_aio` setting value in case the native AIO is broken. See http://help.directadmin.com/item.php?id=529 | 1
| `MYSQL_TABLE_OPEN_CACHE` | The number of open tables for all threads | 400
| `MYSQL_KEY_BUFFER_SIZE` | The size of the buffer used for index blocks | 32M (or 10% of available memory)
| `MYSQL_SORT_BUFFER_SIZE` | The size of the buffer used for sorting | 256K
| `MYSQL_READ_BUFFER_SIZE` | The size of the buffer used for a sequential scan | 8M (or 5% of available memory)
| `MYSQL_INNODB_BUFFER_POOL_SIZE`| The size of the buffer pool where InnoDB caches table and index data | 32M (or 50% of available memory)
| `MYSQL_INNODB_LOG_FILE_SIZE` | The size of each log file in a log group | 8M (or 15% of available available)
| `MYSQL_INNODB_LOG_BUFFER_SIZE` | The size of the buffer that InnoDB uses to write to the log files on disk | 8M (or 15% of available memory)
| `MYSQL_DEFAULTS_FILE` | Point to an alternative configuration file | /etc/my.cnf
| `MYSQL_BINLOG_FORMAT` | Set sets the binlog format, supported values are `row` and `statement` | statement
You can also set the following mount points by passing the `-v /host:/container` flag to Docker.
| Volume mount point | Description |
| :----------------------- | -------------------- |
| `/var/lib/mysql/data` | MySQL data directory |
**Notice: When mouting a directory from the host into the container, ensure that the mounted
directory has the appropriate permissions and that the owner and group of the directory
matches the user UID or name which is running inside the container.**
Usage
---------------------------------
-----
For this, we will assume that you are using the `rhscl/mariadb-100-rhel7` image.
For this, we will assume that you are using the MariaDB 10.2 container image from the
Red Hat Container Catalog called `rhscl/mariadb-102-rhel7`.
If you want to set only the mandatory environment variables and not store
the database in a host directory, execute the following command:
```
$ docker run -d --name mariadb_database -e MYSQL_USER=user -e MYSQL_PASSWORD=pass -e MYSQL_DATABASE=db -p 3306:3306 rhscl/mariadb-100-rhel7
$ docker run -d --name mariadb_database -e MYSQL_USER=user -e MYSQL_PASSWORD=pass -e MYSQL_DATABASE=db -p 3306:3306 rhscl/mariadb-102-rhel7
```
This will create a container named `mariadb_database` running MySQL with database
@ -74,6 +44,87 @@ or if it was already present, `mysqld` is executed and will run as PID 1. You ca
stop the detached container by running `docker stop mariadb_database`.
Environment variables and volumes
---------------------------------
The image recognizes the following environment variables that you can set during
initialization by passing `-e VAR=VALUE` to the Docker run command.
**`MYSQL_USER`**
User name for MySQL account to be created
**`MYSQL_PASSWORD`**
Password for the user account
**`MYSQL_DATABASE`**
Database name
**`MYSQL_ROOT_PASSWORD`**
Password for the root user (optional)
The following environment variables influence the MySQL configuration file. They are all optional.
**`MYSQL_LOWER_CASE_TABLE_NAMES (default: 0)`**
Sets how the table names are stored and compared
**`MYSQL_MAX_CONNECTIONS (default: 151)`**
The maximum permitted number of simultaneous client connections
**`MYSQL_MAX_ALLOWED_PACKET (default: 200M)`**
The maximum size of one packet or any generated/intermediate string
**`MYSQL_FT_MIN_WORD_LEN (default: 4)`**
The minimum length of the word to be included in a FULLTEXT index
**`MYSQL_FT_MAX_WORD_LEN (default: 20)`**
The maximum length of the word to be included in a FULLTEXT index
**`MYSQL_AIO (default: 1)`**
Controls the `innodb_use_native_aio` setting value in case the native AIO is broken. See http://help.directadmin.com/item.php?id=529
**`MYSQL_TABLE_OPEN_CACHE (default: 400)`**
The number of open tables for all threads
**`MYSQL_KEY_BUFFER_SIZE (default: 32M or 10% of available memory)`**
The size of the buffer used for index blocks
**`MYSQL_SORT_BUFFER_SIZE (default: 256K)`**
The size of the buffer used for sorting
**`MYSQL_READ_BUFFER_SIZE (default: 8M or 5% of available memory)`**
The size of the buffer used for a sequential scan
**`MYSQL_INNODB_BUFFER_POOL_SIZE (default: 32M or 50% of available memory)`**
The size of the buffer pool where InnoDB caches table and index data
**`MYSQL_INNODB_LOG_FILE_SIZE (default: 8M or 15% of available available)`**
The size of each log file in a log group
**`MYSQL_INNODB_LOG_BUFFER_SIZE (default: 8M or 15% of available memory)`**
The size of the buffer that InnoDB uses to write to the log files on disk
**`MYSQL_DEFAULTS_FILE (default: /etc/my.cnf)`**
Point to an alternative configuration file
**`MYSQL_BINLOG_FORMAT (default: statement)`**
Set sets the binlog format, supported values are `row` and `statement`
**`MYSQL_LOG_QUERIES_ENABLED (default: 0)`**
To enable query logging set this to `1`
You can also set the following mount points by passing the `-v /host:/container` flag to Docker.
**`/var/lib/mysql/data`**
MySQL data directory
**Notice: When mouting a directory from the host into the container, ensure that the mounted
directory has the appropriate permissions and that the owner and group of the directory
matches the user UID or name which is running inside the container.**
MariaDB auto-tuning
-------------------
@ -81,13 +132,21 @@ When the MySQL image is run with the `--memory` parameter set and you didn't
specify value for some parameters, their values will be automatically
calculated based on the available memory.
| Variable name | Configuration parameter | Relative value
| :-------------------------------| ------------------------- | --------------
| `MYSQL_KEY_BUFFER_SIZE` | `key_buffer_size` | 10%
| `MYSQL_READ_BUFFER_SIZE` | `read_buffer_size` | 5%
| `MYSQL_INNODB_BUFFER_POOL_SIZE` | `innodb_buffer_pool_size` | 50%
| `MYSQL_INNODB_LOG_FILE_SIZE` | `innodb_log_file_size` | 15%
| `MYSQL_INNODB_LOG_BUFFER_SIZE` | `innodb_log_buffer_size` | 15%
**`MYSQL_KEY_BUFFER_SIZE (default: 10%)`**
`key_buffer_size`
**`MYSQL_READ_BUFFER_SIZE (default: 5%)`**
`read_buffer_size`
**`MYSQL_INNODB_BUFFER_POOL_SIZE (default: 50%)`**
`innodb_buffer_pool_size`
**`MYSQL_INNODB_LOG_FILE_SIZE (default: 15%)`**
`innodb_log_file_size`
**`MYSQL_INNODB_LOG_BUFFER_SIZE (default: 15%)`**
`innodb_log_buffer_size`
MySQL root user
@ -115,6 +174,7 @@ values stored in the variables and the actual passwords. Whenever a database
container starts it will reset the passwords to the values stored in the
environment variables.
Default my.cnf file
-------------------
With environment variables we are able to customize a lot of different parameters
@ -124,6 +184,136 @@ variable with the full path of the file you wish to use. For example, the defaul
location is `/etc/my.cnf` but you can change it to `/etc/mysql/my.cnf` by setting
`MYSQL_DEFAULTS_FILE=/etc/mysql/my.cnf`
Extending image
---------------
This image can be extended using [source-to-image](https://github.com/openshift/source-to-image).
For example, to build a customized MariaDB database image `my-mariadb-rhel7`
with a configuration in `~/image-configuration/` run:
```
$ s2i build ~/image-configuration/ rhscl/mariadb-102-rhel7 my-mariadb-rhel7
```
The directory passed to `s2i build` can contain these directories:
`mysql-cfg/`
When starting the container, files from this directory will be used as
a configuration for the `mysqld` daemon.
`envsubst` command is run on this file to still allow customization of
the image using environmental variables
`mysql-pre-init/`
Shell scripts (`*.sh`) available in this directory are sourced before
`mysqld` daemon is started.
`mysql-init/`
Shell scripts (`*.sh`) available in this directory are sourced when
`mysqld` daemon is started locally. In this phase, use `${mysql_flags}`
to connect to the locally running daemon, for example `mysql $mysql_flags < dump.sql`
Variables that can be used in the scripts provided to s2i:
`$mysql_flags`
arguments for the `mysql` tool that will connect to the locally running `mysqld` during initialization
`$MYSQL_RUNNING_AS_MASTER`
variable defined when the container is run with `run-mysqld-master` command
`$MYSQL_RUNNING_AS_SLAVE`
variable defined when the container is run with `run-mysqld-slave` command
`$MYSQL_DATADIR_FIRST_INIT`
variable defined when the container was initialized from the empty data dir
During `s2i build` all provided files are copied into `/opt/app-root/src`
directory into the resulting image. If some configuration files are present
in the destination directory, files with the same name are overwritten.
Also only one file with the same name can be used for customization and user
provided files are preferred over default files in
`/usr/share/container-scripts/mysql/`- so it is possible to overwrite them.
Same configuration directory structure can be used to customize the image
every time the image is started using `docker run`. The directory has to be
mounted into `/opt/app-root/src/` in the image
(`-v ./image-configuration/:/opt/app-root/src/`).
This overwrites customization built into the image.
Securing the connection with SSL
--------------------------------
In order to secure the connection with SSL, use the extending feature described
above. In particular, put the SSL certificates into a separate directory:
sslapp/mysql-certs/server-cert-selfsigned.pem
sslapp/mysql-certs/server-key.pem
And then put a separate configuration file into mysql-cfg:
$> cat sslapp/mysql-cfg/ssl.cnf
[mysqld]
ssl-key=${APP_DATA}/mysql-certs/server-key.pem
ssl-cert=${APP_DATA}/mysql-certs/server-cert-selfsigned.pem
Such a directory `sslapp` can then be mounted into the container with -v,
or a new container image can be built using s2i.
Upgrading and data directory version checking
---------------------------------------------
MySQL and MariaDB use versions that consist of three numbers X.Y.Z (e.g. 5.6.23).
For version changes in Z part, the server's binary data format stays compatible and thus no
special upgrade procedure is needed. For upgrades from X.Y to X.Y+1, consider doing manual
steps as described at
https://mariadb.com/kb/en/library/upgrading-from-mariadb-101-to-mariadb-102/
Skipping versions like from X.Y to X.Y+2 or downgrading to lower version is not supported;
the only exception is ugrading from MariaDB 5.5 to MariaDB 10.0.
**Important**: Upgrading to a new version is always risky and users are expected to make a full
back-up of all data before.
A safer solution to upgrade is to dump all data using `mysqldump` or `mysqldbexport` and then
load the data using `mysql` or `mysqldbimport` into an empty (freshly initialized) database.
Another way of proceeding with the upgrade is starting the new version of the `mysqld` daemon
and run `mysql_upgrade` right after the start. This so called in-place upgrade is generally
faster for large data directory, but only possible if upgrading from the very previous version,
so skipping versions is not supported.
This container detects whether the data needs to be upgraded using `mysql_upgrade` and
we can control it by setting `MYSQL_DATADIR_ACTION` variable, which can have one or more of the following values:
* `upgrade-warn` -- If the data version can be determined and the data come from a different version
of the daemon, a warning is printed but the container starts. This is the default value.
Since historically the version file `mysql_upgrade_info` was not created, when using this option,
the version file is created if not exist, but no `mysql_upgrade` will be called.
However, this automatic creation will be removed after few months, since the version should be
created on most deployments at that point.
* `upgrade-auto` -- `mysql_upgrade` is run at the beginning of the container start, when the local
daemon is running, but only if the data version can be determined and the data come
with the very previous version. A warning is printed if the data come from even older
or newer version. This value effectively enables automatic upgrades,
but it is always risky and users should still back-up all the data before starting the newer container.
Set this option only if you have very good back-ups at any moment and you are fine to fail-over
from the back-up.
* `upgrade-force` -- `mysql_upgrade --force` is run at the beginning of the container start, when the local
daemon is running, no matter what version of the daemon the data come from.
This is also the way to create the missing version file `mysql_upgrade_info` if not present
in the root of the data directory; this file holds information about the version of the data.
There are also some other actions that you may want to run at the beginning of the container start,
when the local daemon is running, no matter what version of the data is detected:
* `optimize` -- runs `mysqlcheck --optimize`. It optimizes all the tables.
* `analyze` -- runs `mysqlcheck --analyze`. It analyzes all the tables.
* `disable` -- nothing is done regarding data directory version.
Multiple values are separated by comma and run in-order, e.g. `MYSQL_DATADIR_ACTION="optimize,analyze"`.
Changing the replication binlog_format
--------------------------------------
Some applications may wish to use `row` binlog_formats (for example, those built
@ -133,3 +323,18 @@ Some applications may wish to use `row` binlog_formats (for example, those built
with `master` replication turned on (ie, set the Docker/container `cmd` to be
`run-mysqld-master`) the binlog will emit the actual data for the rows that change
as opposed to the statements (ie, DML like insert...) that caused the change.
Troubleshooting
---------------
The mysqld deamon in the container logs to the standard output, so the log is available in the container log. The log can be examined by running:
docker logs <container>
See also
--------
Dockerfile and other sources for this container image are available on
https://github.com/sclorg/mariadb-container.
In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile
for RHEL is called Dockerfile.rhel7.

View file

@ -1,164 +0,0 @@
#!/bin/bash
source ${CONTAINER_SCRIPTS_PATH}/helpers.sh
# Data directory where MySQL database files live. The data subdirectory is here
# because .bashrc and my.cnf both live in /var/lib/mysql/ and we don't want a
# volume to override it.
export MYSQL_DATADIR=/var/lib/mysql/data
# Configuration settings.
export MYSQL_DEFAULTS_FILE=${MYSQL_DEFAULTS_FILE:-/etc/my.cnf}
export MYSQL_BINLOG_FORMAT=${MYSQL_BINLOG_FORMAT:-STATEMENT}
export MYSQL_LOWER_CASE_TABLE_NAMES=${MYSQL_LOWER_CASE_TABLE_NAMES:-0}
export MYSQL_MAX_CONNECTIONS=${MYSQL_MAX_CONNECTIONS:-151}
export MYSQL_FT_MIN_WORD_LEN=${MYSQL_FT_MIN_WORD_LEN:-4}
export MYSQL_FT_MAX_WORD_LEN=${MYSQL_FT_MAX_WORD_LEN:-20}
export MYSQL_AIO=${MYSQL_AIO:-1}
export MYSQL_MAX_ALLOWED_PACKET=${MYSQL_MAX_ALLOWED_PACKET:-200M}
export MYSQL_TABLE_OPEN_CACHE=${MYSQL_TABLE_OPEN_CACHE:-400}
export MYSQL_SORT_BUFFER_SIZE=${MYSQL_SORT_BUFFER_SIZE:-256K}
if [ -n "${NO_MEMORY_LIMIT:-}" -o -z "${MEMORY_LIMIT_IN_BYTES:-}" ]; then
key_buffer_size='32M'
read_buffer_size='8M'
innodb_buffer_pool_size='32M'
innodb_log_file_size='8M'
innodb_log_buffer_size='8M'
else
key_buffer_size="$(python -c "print(int((${MEMORY_LIMIT_IN_BYTES}/(1024*1024))*0.1))")M"
read_buffer_size="$(python -c "print(int((${MEMORY_LIMIT_IN_BYTES}/(1024*1024))*0.05))")M"
innodb_buffer_pool_size="$(python -c "print(int((${MEMORY_LIMIT_IN_BYTES}/(1024*1024))*0.5))")M"
innodb_log_file_size="$(python -c "print(int((${MEMORY_LIMIT_IN_BYTES}/(1024*1024))*0.15))")M"
innodb_log_buffer_size="$(python -c "print(int((${MEMORY_LIMIT_IN_BYTES}/(1024*1024))*0.15))")M"
fi
export MYSQL_KEY_BUFFER_SIZE=${MYSQL_KEY_BUFFER_SIZE:-$key_buffer_size}
export MYSQL_READ_BUFFER_SIZE=${MYSQL_READ_BUFFER_SIZE:-$read_buffer_size}
export MYSQL_INNODB_BUFFER_POOL_SIZE=${MYSQL_INNODB_BUFFER_POOL_SIZE:-$innodb_buffer_pool_size}
export MYSQL_INNODB_LOG_FILE_SIZE=${MYSQL_INNODB_LOG_FILE_SIZE:-$innodb_log_file_size}
export MYSQL_INNODB_LOG_BUFFER_SIZE=${MYSQL_INNODB_LOG_BUFFER_SIZE:-$innodb_log_buffer_size}
# Be paranoid and stricter than we should be.
# https://dev.mysql.com/doc/refman/en/identifiers.html
mysql_identifier_regex='^[a-zA-Z0-9_]+$'
mysql_password_regex='^[a-zA-Z0-9_~!@#$%^&*()-=<>,.?;:|]+$'
# Variables that are used to connect to local mysql during initialization
mysql_flags="-u root --socket=/tmp/mysql.sock"
admin_flags="--defaults-file=$MYSQL_DEFAULTS_FILE $mysql_flags"
# Make sure env variables don't propagate to mysqld process.
function unset_env_vars() {
log_info 'Cleaning up environment variables MYSQL_USER, MYSQL_PASSWORD, MYSQL_DATABASE and MYSQL_ROOT_PASSWORD ...'
unset MYSQL_USER MYSQL_PASSWORD MYSQL_DATABASE MYSQL_ROOT_PASSWORD
}
# Poll until MySQL responds to our ping.
function wait_for_mysql() {
pid=$1 ; shift
while [ true ]; do
if [ -d "/proc/$pid" ]; then
mysqladmin --socket=/tmp/mysql.sock ping &>/dev/null && log_info "MySQL started successfully" && return 0
else
return 1
fi
log_info "Waiting for MySQL to start ..."
sleep 1
done
}
# Start local MySQL server with a defaults file
function start_local_mysql() {
log_info 'Starting MySQL server with disabled networking ...'
${MYSQL_PREFIX}/libexec/mysqld \
--defaults-file=$MYSQL_DEFAULTS_FILE \
--skip-networking --socket=/tmp/mysql.sock "$@" &
mysql_pid=$!
wait_for_mysql $mysql_pid
}
# Shutdown mysql flushing privileges
function shutdown_local_mysql() {
log_info 'Shutting down MySQL ...'
mysqladmin $admin_flags flush-privileges shutdown
}
# Initialize the MySQL database (create user accounts and the initial database)
function initialize_database() {
log_info 'Initializing database ...'
log_info 'Running mysql_install_db ...'
# Using --rpm since we need mysql_install_db behaves as in RPM
# Using empty --basedir to work-around https://bugzilla.redhat.com/show_bug.cgi?id=1406391
mysql_install_db --rpm --datadir=$MYSQL_DATADIR --basedir=''
start_local_mysql "$@"
if [ -v MYSQL_RUNNING_AS_SLAVE ]; then
log_info 'Initialization finished'
return 0
fi
if [ -v MYSQL_RUNNING_AS_MASTER ]; then
# Save master status into a separate database.
STATUS_INFO=$(mysql $admin_flags -e 'SHOW MASTER STATUS\G')
BINLOG_POSITION=$(echo "$STATUS_INFO" | grep 'Position:' | head -n 1 | sed -e 's/^\s*Position: //')
BINLOG_FILE=$(echo "$STATUS_INFO" | grep 'File:' | head -n 1 | sed -e 's/^\s*File: //')
GTID_INFO=$(mysql $admin_flags -e "SELECT BINLOG_GTID_POS('$BINLOG_FILE', '$BINLOG_POSITION') AS gtid_value \G")
GTID_VALUE=$(echo "$GTID_INFO" | grep 'gtid_value:' | head -n 1 | sed -e 's/^\s*gtid_value: //')
mysqladmin $admin_flags create replication
mysql $admin_flags <<EOSQL
use replication
CREATE TABLE replication (gtid VARCHAR(256));
INSERT INTO replication (gtid) VALUES ('$GTID_VALUE');
EOSQL
fi
# Do not care what option is compulsory here, just create what is specified
if [ -v MYSQL_USER ]; then
log_info "Creating user specified by MYSQL_USER (${MYSQL_USER}) ..."
mysql $mysql_flags <<EOSQL
CREATE USER '${MYSQL_USER}'@'%' IDENTIFIED BY '${MYSQL_PASSWORD}';
EOSQL
fi
if [ -v MYSQL_DATABASE ]; then
log_info "Creating database ${MYSQL_DATABASE} ..."
mysqladmin $admin_flags create "${MYSQL_DATABASE}"
if [ -v MYSQL_USER ]; then
log_info "Granting privileges to user ${MYSQL_USER} for ${MYSQL_DATABASE} ..."
mysql $mysql_flags <<EOSQL
GRANT ALL ON \`${MYSQL_DATABASE}\`.* TO '${MYSQL_USER}'@'%' ;
FLUSH PRIVILEGES ;
EOSQL
fi
fi
if [ -v MYSQL_ROOT_PASSWORD ]; then
log_info "Setting password for MySQL root user ..."
mysql $mysql_flags <<EOSQL
CREATE USER IF NOT EXISTS 'root'@'%';
GRANT ALL PRIVILEGES ON *.* TO 'root'@'%' IDENTIFIED BY '${MYSQL_ROOT_PASSWORD}' WITH GRANT OPTION;
EOSQL
fi
log_info 'Initialization finished'
}
# The 'server_id' number for slave needs to be within 1-4294967295 range.
# This function will take the 'hostname' if the container, hash it and turn it
# into the number.
# See: https://dev.mysql.com/doc/refman/en/replication-options.html#option_mysqld_server-id
function server_id() {
checksum=$(sha256sum <<< $(hostname -i))
checksum=${checksum:0:14}
echo -n $((0x${checksum}%4294967295))
}
function wait_for_mysql_master() {
while true; do
log_info "Waiting for MySQL master (${MYSQL_MASTER_SERVICE_NAME}) to accept connections ..."
mysqladmin --host=${MYSQL_MASTER_SERVICE_NAME} --user="${MYSQL_MASTER_USER}" \
--password="${MYSQL_MASTER_PASSWORD}" ping &>/dev/null && log_info "MySQL master is ready" && return 0
sleep 1
done
}

View file

@ -1,23 +0,0 @@
# Set the password for MySQL user and root everytime this container is started.
# This allows to change the password by editing the deployment configuration.
if [[ -v MYSQL_USER && -v MYSQL_PASSWORD ]]; then
mysql $mysql_flags <<EOSQL
SET PASSWORD FOR '${MYSQL_USER}'@'%' = PASSWORD('${MYSQL_PASSWORD}');
EOSQL
fi
# The MYSQL_ROOT_PASSWORD is optional, therefore we need to either enable remote
# access with a password if the variable is set or disable remote access otherwise.
if [ -v MYSQL_ROOT_PASSWORD ]; then
# create a user if it doesn't exist and set its password
mysql $mysql_flags <<EOSQL
CREATE USER IF NOT EXISTS 'root'@'%';
GRANT ALL PRIVILEGES ON *.* TO 'root'@'%' IDENTIFIED BY '${MYSQL_ROOT_PASSWORD}' WITH GRANT OPTION;
EOSQL
else
mysql $mysql_flags <<EOSQL
DROP USER IF EXISTS 'root'@'%';
FLUSH PRIVILEGES;
EOSQL
fi

13
s2i-common/bin/assemble Executable file
View file

@ -0,0 +1,13 @@
#!/bin/bash
set -o errexit
set -o nounset
set -o pipefail
shopt -s dotglob
echo "---> Installing application source ..."
mv /tmp/src/* ./ 2>/dev/null || true
# Fix source directory permissions
/usr/libexec/fix-permissions ./

1
s2i-common/bin/run Symbolic link
View file

@ -0,0 +1 @@
/bin/run-mysqld

8
s2i-common/bin/usage Executable file
View file

@ -0,0 +1,8 @@
#!/bin/sh
set -o errexit
set -o nounset
set -o pipefail
groff -t -man -ETascii /help.1

View file

View file

@ -0,0 +1,254 @@
{
"kind": "Template",
"apiVersion": "v1",
"metadata": {
"name": "mariadb-ephemeral",
"annotations": {
"openshift.io/display-name": "MariaDB (Ephemeral)",
"description": "MariaDB database service, without persistent storage. For more information about using this template, including OpenShift considerations, see https://github.com/sclorg/mariadb-container/blob/master/10.2/root/usr/share/container-scripts/mysql/README.md.\n\nWARNING: Any data stored will be lost upon pod destruction. Only use this template for testing",
"iconClass": "icon-mariadb",
"tags": "database,mariadb",
"openshift.io/long-description": "This template provides a standalone MariaDB server with a database created. The database is not stored on persistent storage, so any restart of the service will result in all data being lost. The database name, username, and password are chosen via parameters when provisioning this service.",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"openshift.io/documentation-url": "https://github.com/sclorg/mariadb-container/blob/master/10.2/root/usr/share/container-scripts/mysql/README.md",
"openshift.io/support-url": "https://access.redhat.com"
}
},
"message": "The following service(s) have been created in your project: ${DATABASE_SERVICE_NAME}.\n\n Username: ${MYSQL_USER}\n Password: ${MYSQL_PASSWORD}\n Database Name: ${MYSQL_DATABASE}\n Connection URL: mysql://${DATABASE_SERVICE_NAME}:3306/\n\nFor more information about using this template, including OpenShift considerations, see https://github.com/sclorg/mariadb-container/blob/master/10.2/root/usr/share/container-scripts/mysql/README.md.",
"labels": {
"template": "mariadb-ephemeral-template"
},
"objects": [
{
"kind": "Secret",
"apiVersion": "v1",
"metadata": {
"name": "${DATABASE_SERVICE_NAME}",
"annotations": {
"template.openshift.io/expose-username": "{.data['database-user']}",
"template.openshift.io/expose-password": "{.data['database-password']}",
"template.openshift.io/expose-root_password": "{.data['database-root-password']}",
"template.openshift.io/expose-database_name": "{.data['database-name']}"
}
},
"stringData" : {
"database-user" : "${MYSQL_USER}",
"database-password" : "${MYSQL_PASSWORD}",
"database-root-password" : "${MYSQL_ROOT_PASSWORD}",
"database-name" : "${MYSQL_DATABASE}"
}
},
{
"kind": "Service",
"apiVersion": "v1",
"metadata": {
"name": "${DATABASE_SERVICE_NAME}",
"annotations": {
"template.openshift.io/expose-uri": "mysql://{.spec.clusterIP}:{.spec.ports[?(.name==\"mariadb\")].port}"
}
},
"spec": {
"ports": [
{
"name": "mariadb",
"port": 3306
}
],
"selector": {
"name": "${DATABASE_SERVICE_NAME}"
}
}
},
{
"kind": "DeploymentConfig",
"apiVersion": "v1",
"metadata": {
"name": "${DATABASE_SERVICE_NAME}",
"annotations": {
"template.alpha.openshift.io/wait-for-ready": "true"
}
},
"spec": {
"strategy": {
"type": "Recreate"
},
"triggers": [
{
"type": "ImageChange",
"imageChangeParams": {
"automatic": true,
"containerNames": [
"mariadb"
],
"from": {
"kind": "ImageStreamTag",
"name": "mariadb:${MARIADB_VERSION}",
"namespace": "${NAMESPACE}"
}
}
},
{
"type": "ConfigChange"
}
],
"replicas": 1,
"selector": {
"name": "${DATABASE_SERVICE_NAME}"
},
"template": {
"metadata": {
"labels": {
"name": "${DATABASE_SERVICE_NAME}"
}
},
"spec": {
"containers": [
{
"name": "mariadb",
"image": " ",
"ports": [
{
"containerPort": 3306
}
],
"readinessProbe": {
"timeoutSeconds": 1,
"initialDelaySeconds": 5,
"exec": {
"command": [ "/bin/sh", "-i", "-c",
"MYSQL_PWD=\"$MYSQL_PASSWORD\" mysql -h 127.0.0.1 -u $MYSQL_USER -D $MYSQL_DATABASE -e 'SELECT 1'"]
}
},
"livenessProbe": {
"timeoutSeconds": 1,
"initialDelaySeconds": 30,
"tcpSocket": {
"port": 3306
}
},
"env": [
{
"name": "MYSQL_USER",
"valueFrom": {
"secretKeyRef" : {
"name" : "${DATABASE_SERVICE_NAME}",
"key" : "database-user"
}
}
},
{
"name": "MYSQL_PASSWORD",
"valueFrom": {
"secretKeyRef" : {
"name" : "${DATABASE_SERVICE_NAME}",
"key" : "database-password"
}
}
},
{
"name": "MYSQL_ROOT_PASSWORD",
"valueFrom": {
"secretKeyRef" : {
"name" : "${DATABASE_SERVICE_NAME}",
"key" : "database-root-password"
}
}
},
{
"name": "MYSQL_DATABASE",
"valueFrom": {
"secretKeyRef" : {
"name" : "${DATABASE_SERVICE_NAME}",
"key" : "database-name"
}
}
}
],
"resources": {
"limits": {
"memory": "${MEMORY_LIMIT}"
}
},
"volumeMounts": [
{
"name": "${DATABASE_SERVICE_NAME}-data",
"mountPath": "/var/lib/mysql/data"
}
],
"imagePullPolicy": "IfNotPresent"
}
],
"volumes": [
{
"name": "${DATABASE_SERVICE_NAME}-data",
"emptyDir": {
"medium": ""
}
}
]
}
}
}
}
],
"parameters": [
{
"name": "MEMORY_LIMIT",
"displayName": "Memory Limit",
"description": "Maximum amount of memory the container can use.",
"value": "512Mi",
"required": true
},
{
"name": "NAMESPACE",
"displayName": "Namespace",
"description": "The OpenShift Namespace where the ImageStream resides.",
"value": "openshift"
},
{
"name": "DATABASE_SERVICE_NAME",
"displayName": "Database Service Name",
"description": "The name of the OpenShift Service exposed for the database.",
"value": "mariadb",
"required": true
},
{
"name": "MYSQL_USER",
"displayName": "MariaDB Connection Username",
"description": "Username for MariaDB user that will be used for accessing the database.",
"generate": "expression",
"from": "user[A-Z0-9]{3}",
"required": true
},
{
"name": "MYSQL_PASSWORD",
"displayName": "MariaDB Connection Password",
"description": "Password for the MariaDB connection user.",
"generate": "expression",
"from": "[a-zA-Z0-9]{16}",
"required": true
},
{
"name": "MYSQL_ROOT_PASSWORD",
"displayName": "MariaDB root Password",
"description": "Password for the MariaDB root user.",
"generate": "expression",
"from": "[a-zA-Z0-9]{16}",
"required": true
},
{
"name": "MYSQL_DATABASE",
"displayName": "MariaDB Database Name",
"description": "Name of the MariaDB database accessed.",
"value": "sampledb",
"required": true
},
{
"name": "MARIADB_VERSION",
"displayName": "Version of MariaDB Image",
"description": "Version of MariaDB image to be used (10.2 or latest).",
"value": "10.2",
"required": true
}
]
}

428
test/run
View file

@ -10,49 +10,48 @@ set -o errexit
set -o nounset
shopt -s nullglob
IMAGE_NAME=${IMAGE_NAME-centos/mariadb-101-centos7-candidate}
THISDIR=$(dirname ${BASH_SOURCE[0]})
source ${THISDIR}/test-lib.sh
CIDFILE_DIR=$(mktemp --suffix=mysql_test_cidfiles -d)
TEST_LIST="\
run_container_creation_tests
run_configuration_tests
run_general_tests
run_change_password_test
run_replication_test
run_doc_test
run_s2i_test
run_ssl_test
run_upgrade_test
"
if [ -e "${IMAGE_NAME:-}" ] ; then
echo "Error: IMAGE_NAME must be specified"
exit 1
fi
CID_FILE_DIR=$(mktemp --suffix=mysql_test_cidfiles -d)
TESTSUITE_RESULT=1
test_dir="$(readlink -f $(dirname "${BASH_SOURCE[0]}"))"
s2i_args="--pull-policy=never "
function cleanup() {
local cidfile
for cidfile in $CIDFILE_DIR/* ; do
local CONTAINER
CONTAINER=$(cat $cidfile)
ct_cleanup
echo "Stopping and removing container $CONTAINER..."
docker stop $CONTAINER >/dev/null
local exit_status
exit_status=$(docker inspect -f '{{.State.ExitCode}}' $CONTAINER)
if [ "$exit_status" != "0" ]; then
echo "Inspecting container $CONTAINER"
docker inspect $CONTAINER
echo "Dumping logs for $CONTAINER"
docker logs $CONTAINER
fi
docker rm -v $CONTAINER >/dev/null
rm $cidfile
echo "Done."
done
rmdir $CIDFILE_DIR
if [ $TESTSUITE_RESULT -eq 0 ] ; then
echo "Tests for ${IMAGE_NAME} succeeded."
else
echo "Tests for ${IMAGE_NAME} failed."
fi
}
trap cleanup EXIT SIGINT
function get_cid() {
local id="$1" ; shift || return 1
echo $(cat "$CIDFILE_DIR/$id")
}
function get_container_ip() {
local id="$1" ; shift
docker inspect --format='{{.NetworkSettings.IPAddress}}' $(get_cid "$id")
}
function mysql_cmd() {
local container_ip="$1"; shift
local login="$1"; shift
local password="$1"; shift
docker run --rm "$IMAGE_NAME" mysql --host "$container_ip" -u"$login" -p"$password" "$@" db
docker run --rm ${CONTAINER_EXTRA_ARGS:-} "$IMAGE_NAME" mysql --host "$container_ip" -u"$login" -p"$password" "$@" db
}
function test_connection() {
@ -60,21 +59,36 @@ function test_connection() {
local login=$1 ; shift
local password=$1 ; shift
local ip
ip=$(get_container_ip $name)
ip=$(ct_get_cip $name)
echo " Testing MySQL connection to $ip..."
local max_attempts=20
local sleep_time=2
local i
local status=''
echo -n " Trying to connect..."
for i in $(seq $max_attempts); do
echo " Trying to connect..."
if mysql_cmd "$ip" "$login" "$password" <<< 'SELECT 1;'; then
local status=$(docker inspect -f '{{.State.Status}}' $(ct_get_cid "${name}"))
if [ "${status}" != 'running' ] ; then
break;
fi
echo -n "."
if mysql_cmd "$ip" "$login" "$password" &>/dev/null <<< 'SELECT 1;'; then
echo " OK"
echo " Success!"
return 0
fi
sleep $sleep_time
done
echo " Giving up: Failed to connect. Logs:"
docker logs $(get_cid $name)
echo " FAIL"
echo " Giving up: Failed to connect."
if [ "${status}" == 'running' ] ; then
echo " Container is still running."
else
local exit_status=$(docker inspect -f '{{.State.ExitCode}}' ${name})
echo " Container finised with exit code ${exit_status}."
fi
echo "Logs:"
docker logs $(ct_get_cid $name)
return 1
}
@ -95,22 +109,22 @@ function test_mysql() {
function create_container() {
local name=$1 ; shift
cidfile="$CIDFILE_DIR/$name"
cidfile="$CID_FILE_DIR/$name"
# create container with a cidfile in a directory for cleanup
local container_id
container_id="$(docker run ${DOCKER_ARGS:-} --cidfile $cidfile -d "$@" $IMAGE_NAME ${CONTAINER_ARGS:-})"
echo "Created container $container_id"
echo " Created container $container_id"
}
function run_change_password_test() {
local tmpdir=$(mktemp -d)
mkdir "${tmpdir}/data" && chmod -R a+rwx "${tmpdir}"
chmod -R a+rwx "${tmpdir}"
# Create MySQL container with persistent volume and set the initial password
create_container "testpass1" -e MYSQL_USER=user -e MYSQL_PASSWORD=foo \
-e MYSQL_DATABASE=db -v ${tmpdir}:/var/lib/mysql/data:Z
test_connection testpass1 user foo
docker stop $(get_cid testpass1) >/dev/null
docker stop $(ct_get_cid testpass1) >/dev/null
# Create second container with changed password
create_container "testpass2" -e MYSQL_USER=user -e MYSQL_PASSWORD=bar \
@ -118,7 +132,7 @@ function run_change_password_test() {
test_connection testpass2 user bar
# The old password should not work anymore
if mysql_cmd "$(get_container_ip testpass2)" user foo -e 'SELECT 1;'; then
if mysql_cmd "$(ct_get_cip testpass2)" user foo -e 'SELECT 1;'; then
return 1
fi
}
@ -131,16 +145,16 @@ function run_replication_test() {
docker run $cluster_args -e MYSQL_USER=user -e MYSQL_PASSWORD=foo \
-e MYSQL_ROOT_PASSWORD=root \
-e MYSQL_INNODB_BUFFER_POOL_SIZE=5M \
-d --cidfile ${CIDFILE_DIR}/master.cid $IMAGE_NAME mysqld-master >/dev/null
-d --cidfile ${CID_FILE_DIR}/master.cid $IMAGE_NAME mysqld-master >/dev/null
local master_ip
master_ip=$(get_container_ip master.cid)
master_ip=$(ct_get_cip master.cid)
# Run the MySQL slave
docker run $cluster_args -e MYSQL_MASTER_SERVICE_NAME=${master_ip} \
-e MYSQL_INNODB_BUFFER_POOL_SIZE=5M \
-d --cidfile ${CIDFILE_DIR}/slave.cid $IMAGE_NAME mysqld-slave >/dev/null
-d --cidfile ${CID_FILE_DIR}/slave.cid $IMAGE_NAME mysqld-slave >/dev/null
local slave_ip
slave_ip=$(get_container_ip slave.cid)
slave_ip=$(ct_get_cip slave.cid)
# Now wait till the MASTER will see the SLAVE
local i
@ -152,8 +166,8 @@ function run_replication_test() {
fi
if [[ "${i}" == "${max_attempts}" ]]; then
echo "The ${slave_ip} failed to register in MASTER"
echo "Dumping logs for $(get_cid slave.cid)"
docker logs $(get_cid slave.cid)
echo "Dumping logs for $(ct_get_cid slave.cid)"
docker logs $(ct_get_cid slave.cid)
return 1
fi
sleep 1
@ -173,8 +187,8 @@ function run_replication_test() {
fi
if [[ "${i}" == "${max_attempts}" ]]; then
echo "The ${slave_ip} failed to see value added on MASTER"
echo "Dumping logs for $(get_cid slave.cid)"
docker logs $(get_cid slave.cid)
echo "Dumping logs for $(ct_get_cid slave.cid)"
docker logs $(ct_get_cid slave.cid)
return 1
fi
sleep 1
@ -204,7 +218,12 @@ function assert_login_access() {
function assert_local_access() {
local id="$1" ; shift
docker exec $(get_cid "$id") bash -c 'mysql <<< "SELECT 1;"'
if docker exec $(ct_get_cid "$id") bash -c 'mysql -uroot <<< "SELECT 1;"' ; then
echo " local access granted as expected"
return
fi
echo " local access assertion failed"
return 1
}
# Make sure the invocation of docker run fails.
@ -220,6 +239,7 @@ function assert_container_creation_fails() {
if [ $ret -gt 30 ]; then
return 1
fi
echo " Success!"
}
function try_image_invalid_combinations() {
@ -234,9 +254,10 @@ function run_container_creation_tests() {
try_image_invalid_combinations -e MYSQL_ROOT_PASSWORD=root_pass
local VERY_LONG_DB_NAME="very_long_database_name_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
local VERY_LONG_USER_NAME="very_long_user_name_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
assert_container_creation_fails -e MYSQL_USER=user -e MYSQL_PASSWORD=pass
assert_container_creation_fails -e MYSQL_USER=\$invalid -e MYSQL_PASSWORD=pass -e MYSQL_DATABASE=db -e MYSQL_ROOT_PASSWORD=root_pass
assert_container_creation_fails -e MYSQL_USER=very_long_username -e MYSQL_PASSWORD=pass -e MYSQL_DATABASE=db -e MYSQL_ROOT_PASSWORD=root_pass
assert_container_creation_fails -e MYSQL_USER=$VERY_LONG_USER_NAME -e MYSQL_PASSWORD=pass -e MYSQL_DATABASE=db -e MYSQL_ROOT_PASSWORD=root_pass
assert_container_creation_fails -e MYSQL_USER=user -e MYSQL_PASSWORD="\"" -e MYSQL_DATABASE=db -e MYSQL_ROOT_PASSWORD=root_pass
assert_container_creation_fails -e MYSQL_USER=user -e MYSQL_PASSWORD=pass -e MYSQL_DATABASE=\$invalid -e MYSQL_ROOT_PASSWORD=root_pass
assert_container_creation_fails -e MYSQL_USER=user -e MYSQL_PASSWORD=pass -e MYSQL_DATABASE=$VERY_LONG_DB_NAME -e MYSQL_ROOT_PASSWORD=root_pass
@ -252,7 +273,7 @@ function test_config_option() {
local option_value="$4"
if ! echo "$configuration" | grep -qx "$option_name[[:space:]]*=[[:space:]]*$option_value"; then
local configs="$(docker exec -t "$(get_cid $container_name)" bash -c 'set +f; shopt -s nullglob; echo /etc/my.cnf /etc/my.cnf.d/* /opt/rh/mysql*/root/etc/my.cnf /opt/rh/mysql*/root/etc/my.cnf.d/* | paste -s')"
local configs="$(docker exec -t "$(ct_get_cid $container_name)" bash -c 'set +f; shopt -s nullglob; echo /etc/my.cnf /etc/my.cnf.d/* /opt/rh/mysql*/root/etc/my.cnf /opt/rh/mysql*/root/etc/my.cnf.d/* | paste -s')"
echo >&2 "FAIL: option '$option_name' should have value '$option_value', but it wasn't found in any of the configuration files ($configs):"
echo >&2
echo >&2 "$configuration"
@ -274,6 +295,7 @@ function run_configuration_tests() {
--env MYSQL_PASSWORD=config_test \
--env MYSQL_DATABASE=db \
--env MYSQL_LOWER_CASE_TABLE_NAMES=1 \
--env MYSQL_LOG_QUERIES_ENABLED=1 \
--env MYSQL_MAX_CONNECTIONS=1337 \
--env MYSQL_FT_MIN_WORD_LEN=8 \
--env MYSQL_FT_MAX_WORD_LEN=15 \
@ -294,9 +316,10 @@ function run_configuration_tests() {
# - we should look for an option in the desired config, not in all of them
# - we should respect section of the config (now we have duplicated options from a different sections)
local configuration
configuration="$(docker exec -t "$(get_cid $container_name)" bash -c 'set +f; shopt -s nullglob; egrep -hv "^(#|\!|\[|$)" /etc/my.cnf /etc/my.cnf.d/* /opt/rh/mysql*/root/etc/my.cnf /opt/rh/mysql*/root/etc/my.cnf.d/*' | sed 's,\(^[[:space:]]\+\|[[:space:]]\+$\),,' | sort -u)"
configuration="$(docker exec -t "$(ct_get_cid $container_name)" bash -c 'set +f; shopt -s nullglob; egrep -hv "^(#|\!|\[|$)" /etc/my.cnf /etc/my.cnf.d/* /opt/rh/mysql*/root/etc/my.cnf /opt/rh/mysql*/root/etc/my.cnf.d/*' | sed 's,\(^[[:space:]]\+\|[[:space:]]\+$\),,' | sort -u)"
test_config_option "$container_name" "$configuration" lower_case_table_names 1
test_config_option "$container_name" "$configuration" general_log 1
test_config_option "$container_name" "$configuration" max_connections 1337
test_config_option "$container_name" "$configuration" ft_min_word_len 8
test_config_option "$container_name" "$configuration" ft_max_word_len 15
@ -309,7 +332,7 @@ function run_configuration_tests() {
test_config_option "$container_name" "$configuration" innodb_log_file_size 4M
test_config_option "$container_name" "$configuration" innodb_log_buffer_size 4M
docker stop "$(get_cid $container_name)" >/dev/null
docker stop "$(ct_get_cid $container_name)" >/dev/null
echo " Success!"
echo " Testing image auto-calculated configuration settings"
@ -324,7 +347,7 @@ function run_configuration_tests() {
test_connection "$container_name" config_test_user config_test
configuration="$(docker exec -t "$(get_cid $container_name)" bash -c 'set +f; shopt -s nullglob; egrep -hv "^(#|\!|\[|$)" /etc/my.cnf /etc/my.cnf.d/* /opt/rh/mysql*/root/etc/my.cnf /opt/rh/mysql*/root/etc/my.cnf.d/*' | sed 's,\(^[[:space:]]\+\|[[:space:]]\+$\),,' | sort -u)"
configuration="$(docker exec -t "$(ct_get_cid $container_name)" bash -c 'set +f; shopt -s nullglob; egrep -hv "^(#|\!|\[|$)" /etc/my.cnf /etc/my.cnf.d/* /opt/rh/mysql*/root/etc/my.cnf /opt/rh/mysql*/root/etc/my.cnf.d/*' | sed 's,\(^[[:space:]]\+\|[[:space:]]\+$\),,' | sort -u)"
test_config_option "$container_name" "$configuration" key_buffer_size 25M
test_config_option "$container_name" "$configuration" read_buffer_size 12M
@ -332,35 +355,11 @@ function run_configuration_tests() {
test_config_option "$container_name" "$configuration" innodb_log_file_size 38M
test_config_option "$container_name" "$configuration" innodb_log_buffer_size 38M
docker stop "$(get_cid $container_name)" >/dev/null
docker stop "$(ct_get_cid $container_name)" >/dev/null
echo " Success!"
}
test_scl_usage() {
local name="$1"
local run_cmd="$2"
local expected="$3"
echo " Testing the image SCL enable"
local out
out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${run_cmd}")
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[/bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'"
return 1
fi
out=$(docker exec $(get_cid $name) /bin/bash -c "${run_cmd}" 2>&1)
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[exec /bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'"
return 1
fi
out=$(docker exec $(get_cid $name) /bin/sh -ic "${run_cmd}" 2>&1)
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[exec /bin/sh -ic "${run_cmd}"] Expected '${expected}', got '${out}'"
return 1
fi
}
function run_tests() {
local name=$1 ; shift
envs="-e MYSQL_USER=$USER -e MYSQL_PASSWORD=$PASS -e MYSQL_DATABASE=db"
@ -370,10 +369,10 @@ function run_tests() {
create_container $name $envs
test_connection "$name" "$USER" "$PASS"
echo " Testing scl usage"
test_scl_usage $name 'mysql --version' '10.1'
ct_scl_usage_old $name 'mysql --version' "$VERSION"
echo " Testing login accesses"
local container_ip
container_ip=$(get_container_ip $name)
container_ip=$(ct_get_cip $name)
assert_login_access "$container_ip" "$USER" "$PASS" true
assert_login_access "$container_ip" "$USER" "${PASS}_foo" false
if [ -v ROOT_PASS ]; then
@ -389,49 +388,244 @@ function run_tests() {
}
run_doc_test() {
local tmpdir=$(mktemp -d)
local f
echo " Testing documentation in the container image"
# Extract the help files from the container
for f in /usr/share/container-scripts/mysql/README.md help.1 ; do
docker run --rm ${IMAGE_NAME} /bin/bash -c "cat /${f}" >${tmpdir}/$(basename ${f})
# Check whether the files include some important information
for term in MYSQL_ROOT_PASSWORD volume 3306 ; do
if ! cat ${tmpdir}/$(basename ${f}) | grep -q -e "${term}" ; then
echo "ERROR: File /${f} does not include '${term}'."
return 1
fi
done
done
# Check whether the files use the correct format
if ! file ${tmpdir}/help.1 | grep -q roff ; then
echo "ERROR: /help.1 is not in troff or groff format"
return 1
fi
ct_doc_content_old "MYSQL\_ROOT\_PASSWORD" volume 3306
echo " Success!"
echo
}
# Tests.
_s2i_test_image() {
local container_name="$1"
local mount_opts="$2"
echo " Testing s2i app image with invalid configuration"
assert_container_creation_fails -e MYSQL_USER=root -e MYSQL_PASSWORD=pass -e MYSQL_DATABASE=db -e MYSQL_ROOT_PASSWORD=pass
echo " Testing s2i app image with correct configuration"
create_container \
"$container_name" \
--env MYSQL_USER=config_test_user \
--env MYSQL_PASSWORD=config_test \
--env MYSQL_DATABASE=db \
--env MYSQL_OPERATIONS_USER=operations_user \
--env MYSQL_OPERATIONS_PASSWORD=operations_pass \
${mount_opts}
run_container_creation_tests
test_connection "$container_name" operations_user operations_pass
run_configuration_tests
configuration="$(docker exec -t "$(ct_get_cid $container_name)" bash -c 'set +f; shopt -s nullglob; egrep -hv "^(#|\!|\[|$)" /etc/my.cnf /etc/my.cnf.d/* /opt/rh/mysql*/root/etc/my.cnf /opt/rh/mysql*/root/etc/my.cnf.d/*' | sed 's,\(^[[:space:]]\+\|[[:space:]]\+$\),,' | sort -u)"
# Set lower buffer pool size to avoid running out of memory.
export CONTAINER_ARGS="run-mysqld --innodb_buffer_pool_size=5242880"
docker stop "$(ct_get_cid $container_name)" >/dev/null
}
# Normal tests
USER=user PASS=pass run_tests no_root
USER=user1 PASS=pass1 ROOT_PASS=r00t run_tests root
# Test with arbitrary uid for the container
DOCKER_ARGS="-u 12345" USER=user PASS=pass run_tests no_root_altuid
DOCKER_ARGS="-u 12345" USER=user1 PASS=pass1 ROOT_PASS=r00t run_tests root_altuid
run_s2i_test() {
echo " Testing s2i usage"
ct_s2i_usage ${IMAGE_NAME} ${s2i_args} &>/dev/null
# Test the password change
run_change_password_test
echo " Testing s2i build"
ct_s2i_build_as_df file://${test_dir}/test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp
local image_name_backup=${IMAGE_NAME}
export IMAGE_NAME=${IMAGE_NAME}-testapp
# Replication tests
run_replication_test
local container_name=s2i_config_build
_s2i_test_image "s2i_config_build" ""
# return back original value for IMAGE_NAME
export IMAGE_NAME=${image_name_backup}
echo " Testing s2i mount"
test_app_dir=$(mktemp -d)
cp -Lr ${test_dir}/test-app ${test_app_dir}/
chown -R 27:27 ${test_app_dir}
_s2i_test_image "_s2i_test_mount" "-v ${test_app_dir}/test-app:/opt/app-root/src/:z"
rm -rf ${test_app_dir}
echo " Success!"
}
gen_self_signed_cert() {
local output_dir=$1 ; shift
local base_name=$1 ; shift
mkdir -p ${output_dir}
openssl req -newkey rsa:2048 -nodes -keyout ${output_dir}/${base_name}-key.pem -subj '/C=GB/ST=Berkshire/L=Newbury/O=My Server Company' > ${base_name}-req.pem
openssl req -new -x509 -nodes -key ${output_dir}/${base_name}-key.pem -batch > ${output_dir}/${base_name}-cert-selfsigned.pem
}
run_ssl_test() {
echo " Testing ssl usage"
test_app_dir=$(mktemp -d)
mkdir -p ${test_app_dir}/{mysql-certs,mysql-cfg}
gen_self_signed_cert ${test_app_dir}/mysql-certs server
echo "[mysqld]
ssl-key=\${APP_DATA}/mysql-certs/server-key.pem
ssl-cert=\${APP_DATA}/mysql-certs/server-cert-selfsigned.pem
" >${test_app_dir}/mysql-cfg/ssl.cnf
chown -R 27:27 ${test_app_dir}
local ca_cert_path="/opt/app-root/src/mysql-certs/server-cert-selfsigned.pem"
create_container \
"_s2i_test_ssl" \
--env MYSQL_USER=ssl_test_user \
--env MYSQL_PASSWORD=ssl_test \
--env MYSQL_DATABASE=db \
-v ${test_app_dir}:/opt/app-root/src/:z
test_connection "_s2i_test_ssl" ssl_test_user ssl_test
ip=$(ct_get_cip _s2i_test_ssl)
# At least MySQL 5.6 requires ssl-ca option on client side, otherwise the ssl is not used
CONTAINER_EXTRA_ARGS="-v ${test_app_dir}:/opt/app-root/src/:z"
# MySQL requires --ssl-mode to be set in order to require SSL
case ${VERSION} in
5*) ssl_mode_opt='--ssl-mode=REQUIRED'
esac
if mysql_cmd "$ip" "ssl_test_user" "ssl_test" ${ssl_mode_opt:-} --ssl-ca=${ca_cert_path} -e 'show status like "Ssl_cipher" \G' | grep 'Value: [A-Z][A-Z0-9-]*' ; then
echo " Success!"
rm -rf ${test_app_dir}
else
echo " FAIL!"
mysql_cmd "$ip" "ssl_test_user" "ssl_test" --ssl-ca=${ca_cert_path} -e 'show status like "%ssl%" \G'
return 1
fi
# Clear the global variable content after we are done using it
CONTAINER_EXTRA_ARGS=""
}
function run_general_tests() {
# Set lower buffer pool size to avoid running out of memory.
export CONTAINER_ARGS="run-mysqld --innodb_buffer_pool_size=5242880"
# Normal tests
USER=user PASS=pass run_tests no_root
USER=user1 PASS=pass1 ROOT_PASS=r00t run_tests root
# Test with arbitrary uid for the container
DOCKER_ARGS="--user 12345" USER=user PASS=pass run_tests no_root_altuid
DOCKER_ARGS="--user 12345" USER=user1 PASS=pass1 ROOT_PASS=r00t run_tests root_altuid
}
function get_previous_major_version() {
case "${1}" in
5.5) echo "5.1" ;;
5.6) echo "5.5" ;;
5.7) echo "5.6" ;;
8.0) echo "5.7" ;;
10.0) echo "5.5" ;;
10.1) echo "10.0" ;;
10.2) echo "10.1" ;;
10.3) echo "10.2" ;;
*) echo "Non expected version '${1}'" ; return 1 ;;
esac
}
function run_upgrade_test() {
local tmpdir=$(mktemp -d)
echo " Testing upgrade of the container image"
mkdir "${tmpdir}/data" && chmod -R a+rwx "${tmpdir}"
# Create MySQL container with persistent volume and set the version from too old version
local datadir=${tmpdir}/data
create_container "testupg1" -e MYSQL_USER=user -e MYSQL_PASSWORD=foo \
-e MYSQL_DATABASE=db -v ${datadir}:/var/lib/mysql/data:Z
test_connection testupg1 user foo
docker stop $(ct_get_cid testupg1) >/dev/null
# Simulate datadir without version information
rm -f ${datadir}/mysql_upgrade_info
echo " Testing upgrade from data without version"
# This should work, but warning should be printed
create_container "testupg2" -e MYSQL_USER=user -e MYSQL_PASSWORD=foo \
-e MYSQL_DATABASE=db -v ${datadir}:/var/lib/mysql/data:Z
test_connection testupg2 user foo
docker stop $(ct_get_cid testupg2) >/dev/null
# Check whether some information is provided
if ! docker logs $(ct_get_cid testupg2) 2>&1 | grep -e 'Version of the data could not be determined' &>/dev/null ; then
echo "Information about missing version file is not available in the logs"
return 1
fi
# Check whether upgrade did not happen
if docker logs $(ct_get_cid testupg2) 2>&1 | grep -e 'Running mysql_upgrade' &>/dev/null ; then
echo "Upgrade should not be run when information about version is missing"
return 1
fi
# Create version file that is too old
echo " Testing upgrade from too old data"
echo "5.0.12" >${datadir}/mysql_upgrade_info
# Create another container with same data and upgrade set to 'upgrade-auto'
assert_container_creation_fails -e MYSQL_USER=user -e MYSQL_PASSWORD=foo \
-e MYSQL_DATABASE=db -v ${datadir}:/var/lib/mysql/data:Z -e MYSQL_DATADIR_ACTION=upgrade-auto 2>/dev/null
# Create version file that we can upgrade from
echo " Testing upgrade from previous version"
echo "$(get_previous_major_version ${VERSION}).12" >${datadir}/mysql_upgrade_info
# Create another container with same data and upgrade set to 'upgrade-aauto'
create_container "testupg3" -e MYSQL_USER=user -e MYSQL_PASSWORD=foo \
-e MYSQL_DATABASE=db -v ${datadir}:/var/lib/mysql/data:Z -e MYSQL_DATADIR_ACTION=upgrade-auto
test_connection testupg3 user foo
docker stop $(ct_get_cid testupg3) >/dev/null
# Check whether some upgrade happened
if ! docker logs $(ct_get_cid testupg3) 2>&1 | grep -qe 'Running mysql_upgrade' ; then
echo "Upgrade did not happen but it should when upgrading from previous version"
docker logs $(ct_get_cid testupg3)
return 1
fi
# Create version file that we don't need to upgrade from
echo " Testing upgrade from the same version"
echo "${VERSION}.12" >${datadir}/mysql_upgrade_info
# Create another container with same data and upgrade set to 'upgrade-aauto'
create_container "testupg4" -e MYSQL_USER=user -e MYSQL_PASSWORD=foo \
-e MYSQL_DATABASE=db -v ${datadir}:/var/lib/mysql/data:Z -e MYSQL_DATADIR_ACTION=upgrade-auto
test_connection testupg4 user foo
docker stop $(ct_get_cid testupg4) >/dev/null
# Check whether some upgrade happened
if docker logs $(ct_get_cid testupg4) 2>&1 | grep -e 'Running mysql_upgrade' &>/dev/null ; then
echo "Upgrade happened but it should not when upgrading from current version"
return 1
fi
# Create second container with same data and upgrade set to 'analyze'
echo " Testing running --analyze"
create_container "testupg5" -e MYSQL_USER=user -e MYSQL_PASSWORD=foo \
-e MYSQL_DATABASE=db -v ${datadir}:/var/lib/mysql/data:Z -e MYSQL_DATADIR_ACTION=analyze
test_connection testupg5 user foo
docker stop $(ct_get_cid testupg5) >/dev/null
# Check whether analyze happened
if ! docker logs $(ct_get_cid testupg5) 2>&1 | grep -e '--analyze --all-databases' &>/dev/null ; then
echo "Analyze did not happen but it should"
return 1
fi
# Create another container with same data and upgrade set to 'optimize'
echo " Testing running --optimize"
create_container "testupg6" -e MYSQL_USER=user -e MYSQL_PASSWORD=foo \
-e MYSQL_DATABASE=db -v ${datadir}:/var/lib/mysql/data:Z -e MYSQL_DATADIR_ACTION=optimize
test_connection testupg6 user foo
docker stop $(ct_get_cid testupg6) >/dev/null
# Check whether optimize happened
if ! docker logs $(ct_get_cid testupg6) 2>&1 | grep -e '--optimize --all-databases' &>/dev/null ; then
echo "Optimize did not happen but it should"
return 1
fi
# Create version file that we cannot upgrade from
echo " Testing upgrade from the future version"
echo "20.1.12" >${datadir}/mysql_upgrade_info
assert_container_creation_fails -e MYSQL_USER=user -e MYSQL_PASSWORD=foo \
-e MYSQL_DATABASE=db -v ${datadir}:/var/lib/mysql/data:Z -e MYSQL_DATADIR_ACTION=upgrade-auto 2>/dev/null
echo " Upgrade tests succeeded!"
echo
}
function run_all_tests() {
for test_case in $TEST_LIST; do
echo "Running test $test_case for ${IMAGE_NAME}"
$test_case
done;
}
# Run the chosen tests
TEST_LIST=${@:-$TEST_LIST} run_all_tests
TESTSUITE_RESULT=0
run_doc_test

1
test/run-openshift Symbolic link
View file

@ -0,0 +1 @@
run-openshift-local-cluster

View file

@ -0,0 +1,43 @@
#!/bin/bash
#
# Test the MariaDB image in OpenShift (local cluster)
#
# IMAGE_NAME specifies a name of the candidate image used for testing.
# The image has to be available before this script is executed.
# VERSION specifies the major version of the MariaDB in format of X.Y
# OS specifies RHEL version (e.g. OS=rhel7)
#
THISDIR=$(dirname ${BASH_SOURCE[0]})
source ${THISDIR}/test-lib-mysql.sh
set -eo nounset
trap ct_os_cleanup EXIT SIGINT
ct_os_check_compulsory_vars
ct_os_cluster_up
test_mysql_pure_image "${IMAGE_NAME}"
test_mysql_template "${IMAGE_NAME}"
# TODO: Can we make the build against examples inside the same PR?
test_mysql_s2i "${IMAGE_NAME}" "https://github.com/sclorg/mariadb-container.git" test/test-app
# test with a current image and integrated template
export CT_NAMESPACE=openshift
test_mariadb_integration "${IMAGE_NAME}" "${VERSION}"
# test with a released image and integrated template
export CT_SKIP_UPLOAD_IMAGE=true
case ${OS} in
rhel7) IMAGE_NAME=rhscl/mariadb-${VERSION//./}-rhel7 ;;
*) ;;
esac
test_mariadb_integration mariadb "${VERSION}" "registry.access.redhat.com/${IMAGE_NAME}"
OS_TESTSUITE_RESULT=0

View file

@ -0,0 +1,30 @@
#!/bin/bash
#
# Test the MariaDB image in OpenShift (remote cluster)
#
# IMAGE_NAME specifies a name of the candidate image used for testing.
# The image has to be available before this script is executed.
# VERSION specifies the major version of the MariaDB in format of X.Y
# OS specifies RHEL version (e.g. OS=rhel7)
#
THISDIR=$(dirname ${BASH_SOURCE[0]})
source ${THISDIR}/test-lib-mysql.sh
set -eo nounset
trap ct_os_cleanup EXIT SIGINT
ct_os_check_compulsory_vars
oc status || false "It looks like oc is not properly logged in."
export CT_SKIP_NEW_PROJECT=true
export CT_SKIP_UPLOAD_IMAGE=true
export CT_NAMESPACE=openshift
test_mariadb_integration mariadb ${VERSION} "registry.access.redhat.com/${IMAGE_NAME}"
OS_TESTSUITE_RESULT=0

View file

@ -0,0 +1,3 @@
[mysqld]
query-cache-limit=262144

View file

@ -0,0 +1,4 @@
CREATE TABLE products (id INTEGER, name VARCHAR(256), price FLOAT, variant INTEGER);
CREATE TABLE products_variant (id INTEGER, name VARCHAR(256));
INSERT INTO products_variant (id, name) VALUES ('1', 'blue'), ('2', 'green');

View file

@ -0,0 +1,17 @@
create_arbitrary_users() {
# Do not care what option is compulsory here, just create what is specified
log_info "Creating user specified by MYSQL_OPERATIONS_USER (${MYSQL_OPERATIONS_USER}) ..."
mysql $mysql_flags <<EOSQL
CREATE USER '${MYSQL_OPERATIONS_USER}'@'%' IDENTIFIED BY '${MYSQL_OPERATIONS_PASSWORD}';
EOSQL
log_info "Granting privileges to user ${MYSQL_OPERATIONS_USER} for ${MYSQL_DATABASE} ..."
mysql $mysql_flags <<EOSQL
GRANT ALL ON \`${MYSQL_DATABASE}\`.* TO '${MYSQL_OPERATIONS_USER}'@'%' ;
FLUSH PRIVILEGES ;
EOSQL
}
if ! [ -v MYSQL_RUNNING_AS_SLAVE ]; then
create_arbitrary_users
fi

View file

@ -0,0 +1,12 @@
init_arbitrary_database() {
local thisdir
local init_data_file
thisdir=$(dirname ${BASH_SOURCE[0]})
init_data_file=$(readlink -f ${thisdir}/../mysql-data/init.sql)
log_info "Initializing the arbitrary database from file ${init_data_file}..."
mysql $mysql_flags ${MYSQL_DATABASE} < ${init_data_file}
}
if ! [ -v MYSQL_RUNNING_AS_SLAVE ] && $MYSQL_DATADIR_FIRST_INIT ; then
init_arbitrary_database
fi

View file

@ -0,0 +1,10 @@
check_arbitrary_users() {
if ! [[ -v MYSQL_OPERATIONS_USER && -v MYSQL_OPERATIONS_PASSWORD && -v MYSQL_DATABASE ]]; then
echo "You need to specify all these variables: MYSQL_OPERATIONS_USER, MYSQL_OPERATIONS_PASSWORD, and MYSQL_DATABASE"
return 1
fi
}
if ! [ -v MYSQL_RUNNING_AS_SLAVE ]; then
check_arbitrary_users
fi

129
test/test-lib-mysql.sh Executable file
View file

@ -0,0 +1,129 @@
#!/bin/bash
#
# Functions for tests for the MariaDB image in OpenShift.
#
# IMAGE_NAME specifies a name of the candidate image used for testing.
# The image has to be available before this script is executed.
#
THISDIR=$(dirname ${BASH_SOURCE[0]})
source ${THISDIR}/test-lib.sh
source ${THISDIR}/test-lib-openshift.sh
function check_mysql_os_service_connection() {
local util_image_name="${1}" ; shift
local service_name="${1}" ; shift
local user="${1}" ; shift
local pass="${1}" ; shift
local timeout="${1:-60}" ; shift || :
local pod_ip=$(ct_os_get_service_ip ${service_name})
: " Service ${service_name} check ..."
local cmd="echo 'SELECT 42 as testval\g' | mysql --connect-timeout=15 -h ${pod_ip} -u${user} -p${pass}"
local expected_value='^42'
local output
local ret
SECONDS=0
echo -n "Waiting for ${service_name} service becoming ready ..."
while true ; do
output=$(docker run --rm ${util_image_name} bash -c "${cmd}" || :)
echo "${output}" | grep -qe "${expected_value}" && ret=0 || ret=1
if [ ${ret} -eq 0 ] ; then
echo " PASS"
return 0
fi
echo -n "."
[ ${SECONDS} -gt ${timeout} ] && break
sleep 3
done
echo " FAIL"
return 1
}
function test_mysql_pure_image() {
local image_name=${1:-centos/mariadb-101-centos7}
local image_name_no_namespace=${image_name##*/}
local service_name=${image_name_no_namespace}
ct_os_new_project
# Create a specific imagestream tag for the image so that oc cannot use anything else
ct_os_upload_image "${image_name}" "$image_name_no_namespace:testing"
ct_os_deploy_pure_image "$image_name_no_namespace:testing" \
--name "${service_name}" \
--env MYSQL_ROOT_PASSWORD=test
ct_os_wait_pod_ready "${service_name}" 60
check_mysql_os_service_connection "${image_name}" "${service_name}" root test
ct_os_delete_project
}
function test_mysql_template() {
local image_name=${1:-centos/mariadb-101-centos7}
local image_name_no_namespace=${image_name##*/}
local service_name=${image_name_no_namespace}
ct_os_new_project
ct_os_upload_image "${image_name}" "mariadb:$VERSION"
ct_os_deploy_template_image ${THISDIR}/mariadb-ephemeral-template.json \
NAMESPACE="$(oc project -q)" \
MARIADB_VERSION="$VERSION" \
DATABASE_SERVICE_NAME="${service_name}" \
MYSQL_USER=testu \
MYSQL_PASSWORD=testp \
MYSQL_DATABASE=testdb
ct_os_wait_pod_ready "${service_name}" 60
check_mysql_os_service_connection "${image_name}" "${service_name}" testu testp
ct_os_delete_project
}
function test_mysql_s2i() {
local image_name=${1:-centos/mariadb-101-centos7}
local app=${2:-https://github.com/sclorg/mariadb-container.git}
local context_dir=${3:-test/test-app}
local image_name_no_namespace=${image_name##*/}
local service_name="${image_name_no_namespace}-testing"
ct_os_new_project
# Create a specific imagestream tag for the image so that oc cannot use anything else
ct_os_upload_image "${image_name}" "$image_name_no_namespace:testing"
ct_os_deploy_s2i_image "$image_name_no_namespace:testing" "${app}" \
--context-dir="${context_dir}" \
--name "${service_name}" \
--env MYSQL_ROOT_PASSWORD=test \
--env MYSQL_OPERATIONS_USER=testo \
--env MYSQL_OPERATIONS_PASSWORD=testo \
--env MYSQL_DATABASE=testopdb \
--env MYSQL_USER=testnormal \
--env MYSQL_PASSWORD=testnormal
ct_os_wait_pod_ready "${service_name}" 60
check_mysql_os_service_connection "${image_name}" "${service_name}" testo testo 120
ct_os_delete_project
}
function test_mariadb_integration() {
local image_name=$1
local VERSION=$2
local import_image=${3:-}
local service_name=${image_name##*/}
ct_os_test_template_app_func "${image_name}" \
"mariadb-persistent" \
"${service_name}" \
"ct_os_check_cmd_internal '${image_name}' '${service_name}' \"echo 'SELECT 42 as testval\g' | mysql --connect-timeout=15 -h <IP> testdb -utestu -ptestp\" '^42' 120" \
"-p MARIADB_VERSION=${VERSION} \
-p DATABASE_SERVICE_NAME="${service_name}-testing" \
-p MYSQL_USER=testu \
-p MYSQL_PASSWORD=testp \
-p MYSQL_DATABASE=testdb" "" "${import_image}"
}

960
test/test-lib-openshift.sh Normal file
View file

@ -0,0 +1,960 @@
# some functions are used from test-lib.sh, that is usually in the same dir
source $(dirname ${BASH_SOURCE[0]})/test-lib.sh
# Set of functions for testing docker images in OpenShift using 'oc' command
# A variable containing the overall test result; must be changed to 0 in the end
# of the testing script:
# OS_TESTSUITE_RESULT=0
# And the following trap must be set, in the beginning of the test script:
# trap ct_os_cleanup EXIT SIGINT
OS_TESTSUITE_RESULT=1
function ct_os_cleanup() {
if [ $OS_TESTSUITE_RESULT -eq 0 ] ; then
echo "OpenShift tests for ${IMAGE_NAME} succeeded."
else
echo "OpenShift tests for ${IMAGE_NAME} failed."
fi
}
# ct_os_check_compulsory_vars
# ---------------------------
# Check the compulsory variables:
# * IMAGE_NAME specifies a name of the candidate image used for testing.
# * VERSION specifies the major version of the MariaDB in format of X.Y
# * OS specifies RHEL version (e.g. OS=rhel7)
function ct_os_check_compulsory_vars() {
test -n "${IMAGE_NAME-}" || ( echo 'make sure $IMAGE_NAME is defined' >&2 ; exit 1)
test -n "${VERSION-}" || ( echo 'make sure $VERSION is defined' >&2 ; exit 1)
test -n "${OS-}" || ( echo 'make sure $OS is defined' >&2 ; exit 1)
}
# ct_os_get_status
# --------------------
# Returns status of all objects to make debugging easier.
function ct_os_get_status() {
oc get all
oc status
}
# ct_os_print_logs
# --------------------
# Returns status of all objects and logs from all pods.
function ct_os_print_logs() {
ct_os_get_status
while read pod_name; do
echo "INFO: printing logs for pod ${pod_name}"
oc logs ${pod_name}
done < <(oc get pods --no-headers=true -o custom-columns=NAME:.metadata.name)
}
# ct_os_enable_print_logs
# --------------------
# Enables automatic printing of pod logs on ERR.
function ct_os_enable_print_logs() {
set -E
trap ct_os_print_logs ERR
}
# ct_get_public_ip
# --------------------
# Returns best guess for the IP that the node is accessible from other computers.
# This is a bit funny heuristic, simply goes through all IPv4 addresses that
# hostname -I returns and de-prioritizes IP addresses commonly used for local
# addressing. The rest of addresses are taken as public with higher probability.
function ct_get_public_ip() {
local hostnames=$(hostname -I)
local public_ip=''
local found_ip
for guess_exp in '127\.0\.0\.1' '192\.168\.[0-9\.]*' '172\.[0-9\.]*' \
'10\.[0-9\.]*' '[0-9\.]*' ; do
found_ip=$(echo "${hostnames}" | grep -oe "${guess_exp}")
if [ -n "${found_ip}" ] ; then
hostnames=$(echo "${hostnames}" | sed -e "s/${found_ip}//")
public_ip="${found_ip}"
fi
done
if [ -z "${public_ip}" ] ; then
echo "ERROR: public IP could not be guessed." >&2
return 1
fi
echo "${public_ip}"
}
# ct_os_run_in_pod POD_NAME CMD
# --------------------
# Runs [cmd] in the pod specified by prefix [pod_prefix].
# Arguments: pod_name - full name of the pod
# Arguments: cmd - command to be run in the pod
function ct_os_run_in_pod() {
local pod_name="$1" ; shift
oc exec "$pod_name" -- "$@"
}
# ct_os_get_service_ip SERVICE_NAME
# --------------------
# Returns IP of the service specified by [service_name].
# Arguments: service_name - name of the service
function ct_os_get_service_ip() {
local service_name="${1}" ; shift
oc get "svc/${service_name}" -o yaml | grep clusterIP | \
cut -d':' -f2 | grep -oe '172\.30\.[0-9\.]*'
}
# ct_os_get_all_pods_status
# --------------------
# Returns status of all pods.
function ct_os_get_all_pods_status() {
oc get pods -o custom-columns=Ready:status.containerStatuses[0].ready,NAME:.metadata.name
}
# ct_os_get_all_pods_name
# --------------------
# Returns the full name of all pods.
function ct_os_get_all_pods_name() {
oc get pods --no-headers -o custom-columns=NAME:.metadata.name
}
# ct_os_get_pod_status POD_PREFIX
# --------------------
# Returns status of the pod specified by prefix [pod_prefix].
# Note: Ignores -build and -deploy pods
# Arguments: pod_prefix - prefix or whole ID of the pod
function ct_os_get_pod_status() {
local pod_prefix="${1}" ; shift
ct_os_get_all_pods_status | grep -e "${pod_prefix}" | grep -Ev "(build|deploy)$" \
| awk '{print $1}' | head -n 1
}
# ct_os_get_pod_name POD_PREFIX
# --------------------
# Returns the full name of pods specified by prefix [pod_prefix].
# Note: Ignores -build and -deploy pods
# Arguments: pod_prefix - prefix or whole ID of the pod
function ct_os_get_pod_name() {
local pod_prefix="${1}" ; shift
ct_os_get_all_pods_name | grep -e "^${pod_prefix}" | grep -Ev "(build|deploy)$"
}
# ct_os_get_pod_ip POD_NAME
# --------------------
# Returns the ip of the pod specified by [pod_name].
# Arguments: pod_name - full name of the pod
function ct_os_get_pod_ip() {
local pod_name="${1}"
oc get pod "$pod_name" --no-headers -o custom-columns=IP:status.podIP
}
# ct_os_check_pod_readiness POD_PREFIX STATUS
# --------------------
# Checks whether the pod is ready.
# Arguments: pod_prefix - prefix or whole ID of the pod
# Arguments: status - expected status (true, false)
function ct_os_check_pod_readiness() {
local pod_prefix="${1}" ; shift
local status="${1}" ; shift
test "$(ct_os_get_pod_status ${pod_prefix})" == "${status}"
}
# ct_os_wait_pod_ready POD_PREFIX TIMEOUT
# --------------------
# Wait maximum [timeout] for the pod becomming ready.
# Arguments: pod_prefix - prefix or whole ID of the pod
# Arguments: timeout - how many seconds to wait seconds
function ct_os_wait_pod_ready() {
local pod_prefix="${1}" ; shift
local timeout="${1}" ; shift
SECONDS=0
echo -n "Waiting for ${pod_prefix} pod becoming ready ..."
while ! ct_os_check_pod_readiness "${pod_prefix}" "true" ; do
echo -n "."
[ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1
sleep 3
done
echo " DONE"
}
# ct_os_wait_rc_ready POD_PREFIX TIMEOUT
# --------------------
# Wait maximum [timeout] for the rc having desired number of replicas ready.
# Arguments: pod_prefix - prefix of the replication controller
# Arguments: timeout - how many seconds to wait seconds
function ct_os_wait_rc_ready() {
local pod_prefix="${1}" ; shift
local timeout="${1}" ; shift
SECONDS=0
echo -n "Waiting for ${pod_prefix} pod becoming ready ..."
while ! test "$((oc get --no-headers statefulsets; oc get --no-headers rc) 2>/dev/null \
| grep "^${pod_prefix}" | awk '$2==$3 {print "ready"}')" == "ready" ; do
echo -n "."
[ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1
sleep 3
done
echo " DONE"
}
# ct_os_deploy_pure_image IMAGE [ENV_PARAMS, ...]
# --------------------
# Runs [image] in the openshift and optionally specifies env_params
# as environment variables to the image.
# Arguments: image - prefix or whole ID of the pod to run the cmd in
# Arguments: env_params - environment variables parameters for the images.
function ct_os_deploy_pure_image() {
local image="${1}" ; shift
# ignore error exit code, because oc new-app returns error when image exists
oc new-app ${image} "$@" || :
# let openshift cluster to sync to avoid some race condition errors
sleep 3
}
# ct_os_deploy_s2i_image IMAGE APP [ENV_PARAMS, ... ]
# --------------------
# Runs [image] and [app] in the openshift and optionally specifies env_params
# as environment variables to the image.
# Arguments: image - prefix or whole ID of the pod to run the cmd in
# Arguments: app - url or local path to git repo with the application sources.
# Arguments: env_params - environment variables parameters for the images.
function ct_os_deploy_s2i_image() {
local image="${1}" ; shift
local app="${1}" ; shift
# ignore error exit code, because oc new-app returns error when image exists
oc new-app "${image}~${app}" "$@" || :
# let openshift cluster to sync to avoid some race condition errors
sleep 3
}
# ct_os_deploy_template_image TEMPLATE [ENV_PARAMS, ...]
# --------------------
# Runs template in the openshift and optionally gives env_params to use
# specific values in the template.
# Arguments: template - prefix or whole ID of the pod to run the cmd in
# Arguments: env_params - environment variables parameters for the template.
# Example usage: ct_os_deploy_template_image mariadb-ephemeral-template.yaml \
# DATABASE_SERVICE_NAME=mysql-57-centos7 \
# DATABASE_IMAGE=mysql-57-centos7 \
# MYSQL_USER=testu \
# MYSQL_PASSWORD=testp \
# MYSQL_DATABASE=testdb
function ct_os_deploy_template_image() {
local template="${1}" ; shift
oc process -f "${template}" "$@" | oc create -f -
# let openshift cluster to sync to avoid some race condition errors
sleep 3
}
# _ct_os_get_uniq_project_name
# --------------------
# Returns a uniq name of the OpenShift project.
function _ct_os_get_uniq_project_name() {
local r
while true ; do
r=${RANDOM}
mkdir /var/tmp/sclorg-test-${r} &>/dev/null && echo sclorg-test-${r} && break
done
}
# ct_os_new_project [PROJECT]
# --------------------
# Creates a new project in the openshfit using 'os' command.
# Arguments: project - project name, uses a new random name if omitted
# Expects 'os' command that is properly logged in to the OpenShift cluster.
# Not using mktemp, because we cannot use uppercase characters.
function ct_os_new_project() {
if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then
echo "Creating project skipped."
return
fi
local project_name="${1:-$(_ct_os_get_uniq_project_name)}" ; shift || :
oc new-project ${project_name}
# let openshift cluster to sync to avoid some race condition errors
sleep 3
}
# ct_os_delete_project [PROJECT]
# --------------------
# Deletes the specified project in the openshfit
# Arguments: project - project name, uses the current project if omitted
function ct_os_delete_project() {
if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then
echo "Deleting project skipped, cleaning objects only."
# when not having enough privileges (remote cluster), it might fail and
# it is not a big problem, so ignore failure in this case
ct_delete_all_objects || :
return
fi
local project_name="${1:-$(oc project -q)}" ; shift || :
oc delete project "${project_name}"
}
# ct_delete_all_objects
# -----------------
# Deletes all objects within the project.
# Handy when we have one project and want to run more tests.
function ct_delete_all_objects() {
for x in bc builds dc is isimage istag po pv pvc rc routes secrets svc ; do
oc delete $x --all
done
# for some objects it takes longer to be really deleted, so a dummy sleep
# to avoid some races when other test can see not-yet-deleted objects and can fail
sleep 10
}
# ct_os_docker_login
# --------------------
# Logs in into docker daemon
# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address.
# Does not do anything if REGISTRY_ADDRESS is set.
function ct_os_docker_login() {
[ -n "${REGISTRY_ADDRESS:-}" ] && "REGISTRY_ADDRESS set, not trying to docker login." && return 0
# docker login fails with "404 page not found" error sometimes, just try it more times
for i in `seq 12` ; do
docker login -u developer -p $(oc whoami -t) ${REGISRTY_ADDRESS:-172.30.1.1:5000} && return 0 || :
sleep 5
done
return 1
}
# ct_os_upload_image IMAGE [IMAGESTREAM]
# --------------------
# Uploads image from local registry to the OpenShift internal registry.
# Arguments: image - image name to upload
# Arguments: imagestream - name and tag to use for the internal registry.
# In the format of name:tag ($image_name:latest by default)
# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address.
function ct_os_upload_image() {
local input_name="${1}" ; shift
local image_name=${input_name##*/}
local imagestream=${1:-$image_name:latest}
local output_name="${REGISRTY_ADDRESS:-172.30.1.1:5000}/$(oc project -q)/$imagestream"
ct_os_docker_login
docker tag ${input_name} ${output_name}
docker push ${output_name}
}
# ct_os_install_in_centos
# --------------------
# Installs os cluster in CentOS
function ct_os_install_in_centos() {
yum install -y centos-release-openshift-origin
yum install -y wget git net-tools bind-utils iptables-services bridge-utils\
bash-completion origin-clients docker origin-clients
}
# ct_os_cluster_up [DIR, IS_PUBLIC, CLUSTER_VERSION]
# --------------------
# Runs the local OpenShift cluster using 'oc cluster up' and logs in as developer.
# Arguments: dir - directory to keep configuration data in, random if omitted
# Arguments: is_public - sets either private or public hostname for web-UI,
# use "true" for allow remote access to the web-UI,
# "false" is default
# Arguments: cluster_version - version of the OpenShift cluster to use, empty
# means default version of `oc`; example value: 3.7;
# also can be specified outside by OC_CLUSTER_VERSION
function ct_os_cluster_up() {
ct_os_cluster_running && echo "Cluster already running. Nothing is done." && return 0
ct_os_logged_in && echo "Already logged in to a cluster. Nothing is done." && return 0
mkdir -p /var/tmp/openshift
local dir="${1:-$(mktemp -d /var/tmp/openshift/os-data-XXXXXX)}" ; shift || :
local is_public="${1:-'false'}" ; shift || :
local default_cluster_version=${OC_CLUSTER_VERSION:-}
local cluster_version=${1:-${default_cluster_version}} ; shift || :
if ! grep -qe '--insecure-registry.*172\.30\.0\.0' /etc/sysconfig/docker ; then
sed -i "s|OPTIONS='|OPTIONS='--insecure-registry 172.30.0.0/16 |" /etc/sysconfig/docker
fi
systemctl stop firewalld || :
setenforce 0
iptables -F
systemctl restart docker
local cluster_ip="127.0.0.1"
[ "${is_public}" == "true" ] && cluster_ip=$(ct_get_public_ip)
if [ -n "${cluster_version}" ] ; then
# if $cluster_version is not set, we simply use oc that is available
ct_os_set_path_oc "${cluster_version}"
fi
mkdir -p ${dir}/{config,data,pv}
case $(oc version| head -n 1) in
"oc v3.1"?.*)
oc cluster up --base-dir="${dir}/data" --public-hostname="${cluster_ip}"
;;
"oc v3."*)
oc cluster up --host-data-dir="${dir}/data" --host-config-dir="${dir}/config" \
--host-pv-dir="${dir}/pv" --use-existing-config --public-hostname="${cluster_ip}"
;;
*)
echo "ERROR: Unexpected oc version." >&2
return 1
;;
esac
oc version
oc login -u system:admin
oc project default
ct_os_wait_rc_ready docker-registry 180
ct_os_wait_rc_ready router 30
oc login -u developer -p developer
# let openshift cluster to sync to avoid some race condition errors
sleep 3
}
# ct_os_cluster_down
# --------------------
# Shuts down the local OpenShift cluster using 'oc cluster down'
function ct_os_cluster_down() {
oc cluster down
}
# ct_os_cluster_running
# --------------------
# Returns 0 if oc cluster is running
function ct_os_cluster_running() {
oc cluster status &>/dev/null
}
# ct_os_logged_in
# ---------------
# Returns 0 if logged in to a cluster (remote or local)
function ct_os_logged_in() {
oc whoami >/dev/null
}
# ct_os_set_path_oc OC_VERSION
# --------------------
# This is a trick that helps using correct version of the `oc`:
# The input is version of the openshift in format v3.6.0 etc.
# If the currently available version of oc is not of this version,
# it first takes a look into /usr/local/oc-<ver>/bin directory,
# and if not found there it downloads the community release from github.
# In the end the PATH variable is changed, so the other tests can still use just 'oc'.
# Arguments: oc_version - X.Y part of the version of OSE (e.g. 3.9)
function ct_os_set_path_oc() {
local oc_version=$(ct_os_get_latest_ver $1)
local oc_path
if oc version | grep -q "oc ${oc_version%.*}." ; then
echo "Binary oc found already available in version ${oc_version}: `which oc` Doing noting."
return 0
fi
# first check whether we already have oc available in /usr/local
local installed_oc_path="/usr/local/oc-${oc_version%.*}/bin"
if [ -x "${installed_oc_path}/oc" ] ; then
oc_path="${installed_oc_path}"
echo "Binary oc found in ${installed_oc_path}" >&2
else
# oc not available in /usr/local, try to download it from github (community release)
oc_path="/tmp/oc-${oc_version}-bin"
ct_os_download_upstream_oc "${oc_version}" "${oc_path}"
fi
if [ -z "${oc_path}/oc" ] ; then
echo "ERROR: oc not found installed, nor downloaded" >&1
return 1
fi
export PATH="${oc_path}:${PATH}"
if ! oc version | grep -q "oc ${oc_version%.*}." ; then
echo "ERROR: something went wrong, oc located at ${oc_path}, but oc of version ${oc_version} not found in PATH ($PATH)" >&1
return 1
else
echo "PATH set correctly, binary oc found in version ${oc_version}: `which oc`"
fi
}
# ct_os_get_latest_ver VERSION_PART_X
# --------------------
# Returns full version (vX.Y.Z) from part of the version (X.Y)
# Arguments: vxy - X.Y part of the version
# Returns vX.Y.Z variant of the version
function ct_os_get_latest_ver(){
local vxy="v$1"
for vz in {3..0} ; do
curl -sif "https://github.com/openshift/origin/releases/tag/${vxy}.${vz}" >/dev/null && echo "${vxy}.${vz}" && return 0
done
echo "ERROR: version ${vxy} not found in https://github.com/openshift/origin/tags" >&2
return 1
}
# ct_os_download_upstream_oc OC_VERSION OUTPUT_DIR
# --------------------
# Downloads a particular version of openshift-origin-client-tools from
# github into specified output directory
# Arguments: oc_version - version of OSE (e.g. v3.7.2)
# Arguments: output_dir - output directory
function ct_os_download_upstream_oc() {
local oc_version=$1
local output_dir=$2
# check whether we already have the binary in place
[ -x "${output_dir}/oc" ] && return 0
mkdir -p "${output_dir}"
# using html output instead of https://api.github.com/repos/openshift/origin/releases/tags/${oc_version},
# because API is limited for number of queries if not authenticated
tarball=$(curl -si "https://github.com/openshift/origin/releases/tag/${oc_version}" | grep -o -e "openshift-origin-client-tools-${oc_version}-[a-f0-9]*-linux-64bit.tar.gz" | head -n 1)
# download, unpack the binaries and then put them into output directory
echo "Downloading https://github.com/openshift/origin/releases/download/${oc_version}/${tarball} into ${output_dir}/" >&2
curl -sL https://github.com/openshift/origin/releases/download/${oc_version}/"${tarball}" | tar -C "${output_dir}" -xz
mv -f "${output_dir}"/"${tarball%.tar.gz}"/* "${output_dir}/"
rmdir "${output_dir}"/"${tarball%.tar.gz}"
}
# ct_os_test_s2i_app_func IMAGE APP CONTEXT_DIR CHECK_CMD [OC_ARGS]
# --------------------
# Runs [image] and [app] in the openshift and optionally specifies env_params
# as environment variables to the image. Then check the container by arbitrary
# function given as argument (such an argument may include <IP> string,
# that will be replaced with actual IP).
# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory)
# Arguments: app - url or local path to git repo with the application sources (compulsory)
# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory)
# Arguments: check_command - CMD line that checks whether the container works (compulsory; '<IP>' will be replaced with actual IP)
# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app`
# command, typically environment variables (optional)
function ct_os_test_s2i_app_func() {
local image_name=${1}
local app=${2}
local context_dir=${3}
local check_command=${4}
local oc_args=${5:-}
local import_image=${6:-}
local image_name_no_namespace=${image_name##*/}
local service_name="${image_name_no_namespace}-testing"
local image_tagged="${image_name_no_namespace}:${VERSION}"
if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then
echo "ERROR: ct_os_test_s2i_app_func() requires at least 4 arguments that cannot be emtpy." >&2
return 1
fi
ct_os_new_project
# Create a specific imagestream tag for the image so that oc cannot use anything else
if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then
if [ -n "${import_image}" ] ; then
echo "Importing image ${import_image} as ${image_name}:${VERSION}"
oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm
else
echo "Uploading and importing image skipped."
fi
else
if [ -n "${import_image}" ] ; then
echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead."
fi
ct_os_upload_image "${image_name}" "${image_tagged}"
fi
local app_param="${app}"
if [ -d "${app}" ] ; then
# for local directory, we need to copy the content, otherwise too smart os command
# pulls the git remote repository instead
app_param=$(ct_obtain_input "${app}")
fi
ct_os_deploy_s2i_image "${image_tagged}" "${app_param}" \
--context-dir="${context_dir}" \
--name "${service_name}" \
${oc_args}
if [ -d "${app}" ] ; then
# in order to avoid weird race seen sometimes, let's wait shortly
# before starting the build explicitly
sleep 5
oc start-build "${service_name}" --from-dir="${app_param}"
fi
ct_os_wait_pod_ready "${service_name}" 300
local ip=$(ct_os_get_service_ip "${service_name}")
local check_command_exp=$(echo "$check_command" | sed -e "s/<IP>/$ip/g")
echo " Checking APP using $check_command_exp ..."
local result=0
eval "$check_command_exp" || result=1
if [ $result -eq 0 ] ; then
echo " Check passed."
else
echo " Check failed."
fi
ct_os_delete_project
return $result
}
# ct_os_test_s2i_app IMAGE APP CONTEXT_DIR EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ]
# --------------------
# Runs [image] and [app] in the openshift and optionally specifies env_params
# as environment variables to the image. Then check the http response.
# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory)
# Arguments: app - url or local path to git repo with the application sources (compulsory)
# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory)
# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory)
# Arguments: port - which port to use (optional; default: 8080)
# Arguments: protocol - which protocol to use (optional; default: http)
# Arguments: response_code - what http response code to expect (optional; default: 200)
# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app`
# command, typically environment variables (optional)
function ct_os_test_s2i_app() {
local image_name=${1}
local app=${2}
local context_dir=${3}
local expected_output=${4}
local port=${5:-8080}
local protocol=${6:-http}
local response_code=${7:-200}
local oc_args=${8:-}
local import_image=${9:-}
if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then
echo "ERROR: ct_os_test_s2i_app() requires at least 4 arguments that cannot be emtpy." >&2
return 1
fi
ct_os_test_s2i_app_func "${image_name}" \
"${app}" \
"${context_dir}" \
"ct_os_test_response_internal '${protocol}://<IP>:${port}' '${response_code}' '${expected_output}'" \
"${oc_args}" "${import_image}"
}
# ct_os_test_template_app_func IMAGE APP IMAGE_IN_TEMPLATE CHECK_CMD [OC_ARGS]
# --------------------
# Runs [image] and [app] in the openshift and optionally specifies env_params
# as environment variables to the image. Then check the container by arbitrary
# function given as argument (such an argument may include <IP> string,
# that will be replaced with actual IP).
# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory)
# Arguments: template - url or local path to a template to use (compulsory)
# Arguments: name_in_template - image name used in the template
# Arguments: check_command - CMD line that checks whether the container works (compulsory; '<IP>' will be replaced with actual IP)
# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app`
# command, typically environment variables (optional)
# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry,
# specify them in this parameter as "<image>|<tag>", where "<image>" is a full image name
# (including registry if needed) and "<tag>" is a tag under which the image should be available
# in the OpenShift registry.
function ct_os_test_template_app_func() {
local image_name=${1}
local template=${2}
local name_in_template=${3}
local check_command=${4}
local oc_args=${5:-}
local other_images=${6:-}
local import_image=${7:-}
if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then
echo "ERROR: ct_os_test_template_app_func() requires at least 4 arguments that cannot be emtpy." >&2
return 1
fi
local service_name="${name_in_template}-testing"
local image_tagged="${name_in_template}:${VERSION}"
ct_os_new_project
# Create a specific imagestream tag for the image so that oc cannot use anything else
if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then
if [ -n "${import_image}" ] ; then
echo "Importing image ${import_image} as ${image_name}:${VERSION}"
oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm
else
echo "Uploading and importing image skipped."
fi
else
if [ -n "${import_image}" ] ; then
echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead."
fi
ct_os_upload_image "${image_name}" "${image_tagged}"
# upload also other images, that template might need (list of pairs in the format <image>|<tag>
local images_tags_a
local i_t
for i_t in ${other_images} ; do
echo "${i_t}"
IFS='|' read -ra image_tag_a <<< "${i_t}"
docker pull "${image_tag_a[0]}"
ct_os_upload_image "${image_tag_a[0]}" "${image_tag_a[1]}"
done
fi
# get the template file from remote or local location; if not found, it is
# considered an internal template name, like 'mysql', so use the name
# explicitly
local local_template=$(ct_obtain_input "${template}" || echo "${template}")
local namespace=${CT_NAMESPACE:-$(oc project -q)}
oc new-app ${local_template} \
--name "${name_in_template}" \
-p NAMESPACE="${namespace}" \
${oc_args}
ct_os_wait_pod_ready "${service_name}" 300
local ip=$(ct_os_get_service_ip "${service_name}")
local check_command_exp=$(echo "$check_command" | sed -e "s/<IP>/$ip/g")
echo " Checking APP using $check_command_exp ..."
local result=0
eval "$check_command_exp" || result=1
if [ $result -eq 0 ] ; then
echo " Check passed."
else
echo " Check failed."
fi
ct_os_delete_project
return $result
}
# params:
# ct_os_test_template_app IMAGE APP IMAGE_IN_TEMPLATE EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ]
# --------------------
# Runs [image] and [app] in the openshift and optionally specifies env_params
# as environment variables to the image. Then check the http response.
# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory)
# Arguments: template - url or local path to a template to use (compulsory)
# Arguments: name_in_template - image name used in the template
# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory)
# Arguments: port - which port to use (optional; default: 8080)
# Arguments: protocol - which protocol to use (optional; default: http)
# Arguments: response_code - what http response code to expect (optional; default: 200)
# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app`
# command, typically environment variables (optional)
# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry,
# specify them in this parameter as "<image>|<tag>", where "<image>" is a full image name
# (including registry if needed) and "<tag>" is a tag under which the image should be available
# in the OpenShift registry.
function ct_os_test_template_app() {
local image_name=${1}
local template=${2}
local name_in_template=${3}
local expected_output=${4}
local port=${5:-8080}
local protocol=${6:-http}
local response_code=${7:-200}
local oc_args=${8:-}
local other_images=${9:-}
local import_image=${10:-}
if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then
echo "ERROR: ct_os_test_template_app() requires at least 4 arguments that cannot be emtpy." >&2
return 1
fi
ct_os_test_template_app_func "${image_name}" \
"${template}" \
"${name_in_template}" \
"ct_os_test_response_internal '${protocol}://<IP>:${port}' '${response_code}' '${expected_output}'" \
"${oc_args}" \
"${other_images}" \
"${import_image}"
}
# ct_os_test_image_update IMAGE_NAME OLD_IMAGE ISTAG CHECK_FUNCTION OC_ARGS
# --------------------
# Runs an image update test with [image] uploaded to [is] imagestream
# and checks the services using an arbitrary function provided in [check_function].
# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory)
# Arguments: old_image - valid name of the image from the registry
# Arguments: istag - imagestream to upload the images into (compulsory)
# Arguments: check_function - command to be run to check functionality of created services (compulsory)
# Arguments: oc_args - arguments to use during oc new-app (compulsory)
ct_os_test_image_update() {
local image_name=$1; shift
local old_image=$1; shift
local istag=$1; shift
local check_function=$1; shift
local service_name=${image_name##*/}
local ip="" check_command_exp=""
echo "Running image update test for: $image_name"
ct_os_new_project
# Get current image from repository and create an imagestream
docker pull "$old_image:latest" 2>/dev/null
ct_os_upload_image "$old_image" "$istag"
# Setup example application with curent image
oc new-app "$@" --name "$service_name"
ct_os_wait_pod_ready "$service_name" 60
# Check application output
ip=$(ct_os_get_service_ip "$service_name")
check_command_exp=${check_function//<IP>/$ip}
ct_assert_cmd_success "$check_command_exp"
# Tag built image into the imagestream and wait for rebuild
ct_os_upload_image "$image_name" "$istag"
ct_os_wait_pod_ready "${service_name}-2" 60
# Check application output
ip=$(ct_os_get_service_ip "$service_name")
check_command_exp=${check_function//<IP>/$ip}
ct_assert_cmd_success "$check_command_exp"
ct_os_delete_project
}
# ct_os_deploy_cmd_image IMAGE_NAME
# --------------------
# Runs a special command pod, a pod that does nothing, but includes utilities for testing.
# A typical usage is a mysql pod that includes mysql commandline, that we need for testing.
# Running commands inside this command pod is done via ct_os_cmd_image_run function.
# The pod is not run again if already running.
# Arguments: image_name - image to be used as a command pod
function ct_os_deploy_cmd_image() {
local image_name=${1}
oc get pod command-app &>/dev/null && echo "command POD already running" && return 0
echo "command POD not running yet, will start one called command-app"
oc create -f - <<EOF
apiVersion: v1
kind: Pod
metadata:
name: command-app
spec:
containers:
- name: command-container
image: "${image_name}"
command: ["sleep"]
args: ["3h"]
restartPolicy: OnFailure
EOF
SECONDS=0
echo -n "Waiting for command POD ."
while [ $SECONDS -lt 180 ] ; do
sout="$(ct_os_cmd_image_run 'echo $((11*11))' 2>/dev/null)"
grep -q '^121$' <<< "$sout" && echo "DONE" && return 0 || :
sleep 3
echo -n "."
done
echo "FAIL"
return 1
}
# ct_os_cmd_image_run CMD [ ARG ... ]
# --------------------
# Runs a command CMD inside a special command pod
# Arguments: cmd - shell command with args to run in a pod
function ct_os_cmd_image_run() {
oc exec command-app -- bash -c "$@"
}
# ct_os_test_response_internal
# ----------------
# Perform GET request to the application container, checks output with
# a reg-exp and HTTP response code.
# That all is done inside an image in the cluster, so the function is used
# typically in clusters that are not accessible outside.
# The interanal image is a python image that should include the most of the useful commands.
# The check is repeated until timeout.
# Argument: url - request URL path
# Argument: expected_code - expected HTTP response code
# Argument: body_regexp - PCRE regular expression that must match the response body
# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between
# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10)
ct_os_test_response_internal() {
local url="$1"
local expected_code="$2"
local body_regexp="$3"
local max_attempts=${4:-20}
local ignore_error_attempts=${5:-10}
: " Testing the HTTP(S) response for <${url}>"
local sleep_time=3
local attempt=1
local result=1
local status
local response_code
local response_file=$(mktemp /tmp/ct_test_response_XXXXXX)
local util_image_name='python:3.6'
ct_os_deploy_cmd_image "${util_image_name}"
while [ ${attempt} -le ${max_attempts} ]; do
ct_os_cmd_image_run "curl --connect-timeout 10 -s -w '%{http_code}' '${url}'" >${response_file} && status=0 || status=1
if [ ${status} -eq 0 ]; then
response_code=$(cat ${response_file} | tail -c 3)
if [ "${response_code}" -eq "${expected_code}" ]; then
result=0
fi
cat ${response_file} | grep -qP -e "${body_regexp}" || result=1;
# Some services return 40x code until they are ready, so let's give them
# some chance and not end with failure right away
# Do not wait if we already have expected outcome though
if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then
break
fi
fi
attempt=$(( ${attempt} + 1 ))
sleep ${sleep_time}
done
rm -f ${response_file}
return ${result}
}
# ct_os_get_image_from_pod
# ------------------------
# Print image identifier from an existing pod to stdout
# Argument: pod_prefix - prefix or full name of the pod to get image from
ct_os_get_image_from_pod() {
local pod_prefix=$1 ; shift
local pod_name=$(ct_os_get_pod_name $pod_prefix)
oc get "po/${pod_name}" -o yaml | sed -ne 's/^\s*image:\s*\(.*\)\s*$/\1/ p' | head -1
}
# ct_os_check_cmd_internal
# ----------------
# Runs a specified command, checks exit code and compares the output with expected regexp.
# That all is done inside an image in the cluster, so the function is used
# typically in clusters that are not accessible outside.
# The check is repeated until timeout.
# Argument: util_image_name - name of the image in the cluster that is used for running the cmd
# Argument: service_name - kubernetes' service name to work with (IP address is taken from this one)
# Argument: check_command - command that is run within the util_image_name container
# Argument: expected_content_match - regexp that must be in the output (use .* to ignore check)
# Argument: timeout - number of seconds to wait till the check succeeds
function ct_os_check_cmd_internal() {
local util_image_name=$1 ; shift
local service_name=$1 ; shift
local check_command=$1 ; shift
local expected_content_match=${1:-.*} ; shift
local timeout=${1:-60} ; shift || :
: " Service ${service_name} check ..."
local output
local ret
local ip=$(ct_os_get_service_ip "${service_name}")
local check_command_exp=$(echo "$check_command" | sed -e "s/<IP>/$ip/g")
ct_os_deploy_cmd_image $(ct_os_get_image_from_pod "${util_image_name##*/}" | head -n 1)
SECONDS=0
echo -n "Waiting for ${service_name} service becoming ready ..."
while true ; do
output=$(ct_os_cmd_image_run "$check_command_exp")
ret=$?
echo "${output}" | grep -qe "${expected_content_match}" || ret=1
if [ ${ret} -eq 0 ] ; then
echo " PASS"
return 0
fi
echo -n "."
[ ${SECONDS} -gt ${timeout} ] && break
sleep 3
done
echo " FAIL"
return 1
}

507
test/test-lib.sh Normal file
View file

@ -0,0 +1,507 @@
#
# Test a container image.
#
# Always use sourced from a specific container testfile
#
# reguires definition of CID_FILE_DIR
# CID_FILE_DIR=$(mktemp --suffix=<container>_test_cidfiles -d)
# reguires definition of TEST_LIST
# TEST_LIST="\
# ctest_container_creation
# ctest_doc_content"
# Container CI tests
# abbreviated as "ct"
# may be redefined in the specific container testfile
EXPECTED_EXIT_CODE=0
# ct_cleanup
# --------------------
# Cleans up containers used during tests. Stops and removes all containers
# referenced by cid_files in CID_FILE_DIR. Dumps logs if a container exited
# unexpectedly. Removes the cid_files and CID_FILE_DIR as well.
# Uses: $CID_FILE_DIR - path to directory containing cid_files
# Uses: $EXPECTED_EXIT_CODE - expected container exit code
function ct_cleanup() {
for cid_file in $CID_FILE_DIR/* ; do
local container=$(cat $cid_file)
: "Stopping and removing container $container..."
docker stop $container
exit_status=$(docker inspect -f '{{.State.ExitCode}}' $container)
if [ "$exit_status" != "$EXPECTED_EXIT_CODE" ]; then
: "Dumping logs for $container"
docker logs $container
fi
docker rm -v $container
rm $cid_file
done
rmdir $CID_FILE_DIR
: "Done."
}
# ct_enable_cleanup
# --------------------
# Enables automatic container cleanup after tests.
function ct_enable_cleanup() {
trap ct_cleanup EXIT SIGINT
}
# ct_get_cid [name]
# --------------------
# Prints container id from cid_file based on the name of the file.
# Argument: name - name of cid_file where the container id will be stored
# Uses: $CID_FILE_DIR - path to directory containing cid_files
function ct_get_cid() {
local name="$1" ; shift || return 1
echo $(cat "$CID_FILE_DIR/$name")
}
# ct_get_cip [id]
# --------------------
# Prints container ip address based on the container id.
# Argument: id - container id
function ct_get_cip() {
local id="$1" ; shift
docker inspect --format='{{.NetworkSettings.IPAddress}}' $(ct_get_cid "$id")
}
# ct_wait_for_cid [cid_file]
# --------------------
# Holds the execution until the cid_file is created. Usually run after container
# creation.
# Argument: cid_file - name of the cid_file that should be created
function ct_wait_for_cid() {
local cid_file=$1
local max_attempts=10
local sleep_time=1
local attempt=1
local result=1
while [ $attempt -le $max_attempts ]; do
[ -f $cid_file ] && [ -s $cid_file ] && return 0
: "Waiting for container start..."
attempt=$(( $attempt + 1 ))
sleep $sleep_time
done
return 1
}
# ct_assert_container_creation_fails [container_args]
# --------------------
# The invocation of docker run should fail based on invalid container_args
# passed to the function. Returns 0 when container fails to start properly.
# Argument: container_args - all arguments are passed directly to dokcer run
# Uses: $CID_FILE_DIR - path to directory containing cid_files
function ct_assert_container_creation_fails() {
local ret=0
local max_attempts=10
local attempt=1
local cid_file=assert
set +e
local old_container_args="${CONTAINER_ARGS-}"
CONTAINER_ARGS="$@"
ct_create_container $cid_file
if [ $? -eq 0 ]; then
local cid=$(ct_get_cid $cid_file)
while [ "$(docker inspect -f '{{.State.Running}}' $cid)" == "true" ] ; do
sleep 2
attempt=$(( $attempt + 1 ))
if [ $attempt -gt $max_attempts ]; then
docker stop $cid
ret=1
break
fi
done
exit_status=$(docker inspect -f '{{.State.ExitCode}}' $cid)
if [ "$exit_status" == "0" ]; then
ret=1
fi
docker rm -v $cid
rm $CID_FILE_DIR/$cid_file
fi
[ ! -z $old_container_args ] && CONTAINER_ARGS="$old_container_args"
set -e
return $ret
}
# ct_create_container [name, command]
# --------------------
# Creates a container using the IMAGE_NAME and CONTAINER_ARGS variables. Also
# stores the container id to a cid_file located in the CID_FILE_DIR, and waits
# for the creation of the file.
# Argument: name - name of cid_file where the container id will be stored
# Argument: command - optional command to be executed in the container
# Uses: $CID_FILE_DIR - path to directory containing cid_files
# Uses: $CONTAINER_ARGS - optional arguments passed directly to docker run
# Uses: $IMAGE_NAME - name of the image being tested
function ct_create_container() {
local cid_file="$CID_FILE_DIR/$1" ; shift
# create container with a cidfile in a directory for cleanup
docker run --cidfile="$cid_file" -d ${CONTAINER_ARGS:-} $IMAGE_NAME "$@"
ct_wait_for_cid $cid_file || return 1
: "Created container $(cat $cid_file)"
}
# ct_scl_usage_old [name, command, expected]
# --------------------
# Tests three ways of running the SCL, by looking for an expected string
# in the output of the command
# Argument: name - name of cid_file where the container id will be stored
# Argument: command - executed inside the container
# Argument: expected - string that is expected to be in the command output
# Uses: $CID_FILE_DIR - path to directory containing cid_files
# Uses: $IMAGE_NAME - name of the image being tested
function ct_scl_usage_old() {
local name="$1"
local command="$2"
local expected="$3"
local out=""
: " Testing the image SCL enable"
out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${command}")
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[/bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2
return 1
fi
out=$(docker exec $(ct_get_cid $name) /bin/bash -c "${command}" 2>&1)
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[exec /bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2
return 1
fi
out=$(docker exec $(ct_get_cid $name) /bin/sh -ic "${command}" 2>&1)
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[exec /bin/sh -ic "${command}"] Expected '${expected}', got '${out}'" >&2
return 1
fi
}
# ct_doc_content_old [strings]
# --------------------
# Looks for occurence of stirngs in the documentation files and checks
# the format of the files. Files examined: help.1
# Argument: strings - strings expected to appear in the documentation
# Uses: $IMAGE_NAME - name of the image being tested
function ct_doc_content_old() {
local tmpdir=$(mktemp -d)
local f
: " Testing documentation in the container image"
# Extract the help files from the container
for f in help.1 ; do
docker run --rm ${IMAGE_NAME} /bin/bash -c "cat /${f}" >${tmpdir}/$(basename ${f})
# Check whether the files contain some important information
for term in $@ ; do
if ! cat ${tmpdir}/$(basename ${f}) | grep -F -q -e "${term}" ; then
echo "ERROR: File /${f} does not include '${term}'." >&2
return 1
fi
done
# Check whether the files use the correct format
for term in TH PP SH ; do
if ! grep -q "^\.${term}" ${tmpdir}/help.1 ; then
echo "ERROR: /help.1 is probably not in troff or groff format, since '${term}' is missing." >&2
return 1
fi
done
done
: " Success!"
}
# ct_npm_works
# --------------------
# Checks existance of the npm tool and runs it.
function ct_npm_works() {
local tmpdir=$(mktemp -d)
: " Testing npm in the container image"
docker run --rm ${IMAGE_NAME} /bin/bash -c "npm --version" >${tmpdir}/version
if [ $? -ne 0 ] ; then
echo "ERROR: 'npm --version' does not work inside the image ${IMAGE_NAME}." >&2
return 1
fi
docker run --rm ${IMAGE_NAME} /bin/bash -c "npm install jquery && test -f node_modules/jquery/src/jquery.js"
if [ $? -ne 0 ] ; then
echo "ERROR: npm could not install jquery inside the image ${IMAGE_NAME}." >&2
return 1
fi
: " Success!"
}
# ct_path_append PATH_VARNAME DIRECTORY
# -------------------------------------
# Append DIRECTORY to VARIABLE of name PATH_VARNAME, the VARIABLE must consist
# of colon-separated list of directories.
ct_path_append ()
{
if eval "test -n \"\${$1-}\""; then
eval "$1=\$2:\$$1"
else
eval "$1=\$2"
fi
}
# ct_path_foreach PATH ACTION [ARGS ...]
# --------------------------------------
# For each DIR in PATH execute ACTION (path is colon separated list of
# directories). The particular calls to ACTION will look like
# '$ ACTION directory [ARGS ...]'
ct_path_foreach ()
{
local dir dirlist action save_IFS
save_IFS=$IFS
IFS=:
dirlist=$1
action=$2
shift 2
for dir in $dirlist; do "$action" "$dir" "$@" ; done
IFS=$save_IFS
}
# ct_run_test_list
# --------------------
# Execute the tests specified by TEST_LIST
# Uses: $TEST_LIST - list of test names
function ct_run_test_list() {
for test_case in $TEST_LIST; do
: "Running test $test_case"
[ -f test/$test_case ] && source test/$test_case
[ -f ../test/$test_case ] && source ../test/$test_case
$test_case
done;
}
# ct_gen_self_signed_cert_pem
# ---------------------------
# Generates a self-signed PEM certificate pair into specified directory.
# Argument: output_dir - output directory path
# Argument: base_name - base name of the certificate files
# Resulted files will be those:
# <output_dir>/<base_name>-cert-selfsigned.pem -- public PEM cert
# <output_dir>/<base_name>-key.pem -- PEM private key
ct_gen_self_signed_cert_pem() {
local output_dir=$1 ; shift
local base_name=$1 ; shift
mkdir -p ${output_dir}
openssl req -newkey rsa:2048 -nodes -keyout ${output_dir}/${base_name}-key.pem -subj '/C=GB/ST=Berkshire/L=Newbury/O=My Server Company' > ${base_name}-req.pem
openssl req -new -x509 -nodes -key ${output_dir}/${base_name}-key.pem -batch > ${output_dir}/${base_name}-cert-selfsigned.pem
}
# ct_obtain_input FILE|DIR|URL
# --------------------
# Either copies a file or a directory to a tmp location for local copies, or
# downloads the file from remote location.
# Resulted file path is printed, so it can be later used by calling function.
# Arguments: input - local file, directory or remote URL
function ct_obtain_input() {
local input=$1
local extension="${input##*.}"
# Try to use same extension for the temporary file if possible
[[ "${extension}" =~ ^[a-z0-9]*$ ]] && extension=".${extension}" || extension=""
local output=$(mktemp "/var/tmp/test-input-XXXXXX$extension")
if [ -f "${input}" ] ; then
cp -f "${input}" "${output}"
elif [ -d "${input}" ] ; then
rm -f "${output}"
cp -r -LH "${input}" "${output}"
elif echo "${input}" | grep -qe '^http\(s\)\?://' ; then
curl "${input}" > "${output}"
else
echo "ERROR: file type not known: ${input}" >&2
return 1
fi
echo "${output}"
}
# ct_test_response
# ----------------
# Perform GET request to the application container, checks output with
# a reg-exp and HTTP response code.
# Argument: url - request URL path
# Argument: expected_code - expected HTTP response code
# Argument: body_regexp - PCRE regular expression that must match the response body
# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between
# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10)
ct_test_response() {
local url="$1"
local expected_code="$2"
local body_regexp="$3"
local max_attempts=${4:-20}
local ignore_error_attempts=${5:-10}
: " Testing the HTTP(S) response for <${url}>"
local sleep_time=3
local attempt=1
local result=1
local status
local response_code
local response_file=$(mktemp /tmp/ct_test_response_XXXXXX)
while [ ${attempt} -le ${max_attempts} ]; do
curl --connect-timeout 10 -s -w '%{http_code}' "${url}" >${response_file} && status=0 || status=1
if [ ${status} -eq 0 ]; then
response_code=$(cat ${response_file} | tail -c 3)
if [ "${response_code}" -eq "${expected_code}" ]; then
result=0
fi
cat ${response_file} | grep -qP -e "${body_regexp}" || result=1;
# Some services return 40x code until they are ready, so let's give them
# some chance and not end with failure right away
# Do not wait if we already have expected outcome though
if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then
break
fi
fi
attempt=$(( ${attempt} + 1 ))
sleep ${sleep_time}
done
rm -f ${response_file}
return ${result}
}
# ct_registry_from_os OS
# ----------------
# Transform operating system string [os] into registry url
# Argument: OS - string containing the os version
ct_registry_from_os() {
local registry=""
case $1 in
rhel7)
registry=registry.access.redhat.com
;;
*)
registry=docker.io
;;
esac
echo "$registry"
}
# ct_assert_cmd_success CMD
# ----------------
# Evaluates [cmd] and fails if it does not succeed.
# Argument: CMD - Command to be run
function ct_assert_cmd_success() {
echo "Checking '$*' for success ..."
if ! eval "$@" &>/dev/null; then
echo " FAIL"
return 1
fi
echo " PASS"
return 0
}
# ct_assert_cmd_failure CMD
# ----------------
# Evaluates [cmd] and fails if it succeeds.
# Argument: CMD - Command to be run
function ct_assert_cmd_failure() {
echo "Checking '$*' for failure ..."
if eval "$@" &>/dev/null; then
echo " FAIL"
return 1
fi
echo " PASS"
return 0
}
# ct_random_string [LENGTH=10]
# ----------------------------
# Generate pseudorandom alphanumeric string of LENGTH bytes, the
# default length is 10. The string is printed on stdout.
ct_random_string()
(
export LC_ALL=C
dd if=/dev/urandom count=1 bs=10k 2>/dev/null \
| tr -dc 'a-z0-9' \
| fold -w "${1-10}" \
| head -n 1
)
# ct_s2i_usage IMG_NAME [S2I_ARGS]
# ----------------------------
# Create a container and run the usage script inside
# Argument: IMG_NAME - name of the image to be used for the container run
# Argument: S2I_ARGS - Additional list of source-to-image arguments, currently unused.
ct_s2i_usage()
{
local img_name=$1; shift
local s2i_args="$*";
local usage_command="/usr/libexec/s2i/usage"
docker run --rm "$img_name" bash -c "$usage_command"
}
# ct_s2i_build_as_df APP_PATH SRC_IMAGE DST_IMAGE [S2I_ARGS]
# ----------------------------
# Create a new s2i app image from local sources in a similar way as source-to-image would have used.
# Argument: APP_PATH - local path to the app sources to be used in the test
# Argument: SRC_IMAGE - image to be used as a base for the s2i build
# Argument: DST_IMAGE - image name to be used during the tagging of the s2i build result
# Argument: S2I_ARGS - Additional list of source-to-image arguments.
# Only used to check for pull-policy=never and environment variable definitions.
ct_s2i_build_as_df()
{
local app_path=$1; shift
local src_image=$1; shift
local dst_image=$1; shift
local s2i_args="$*";
local local_app=upload/src/
local local_scripts=upload/scripts/
local user_id=
local df_name=
local tmpdir=
# Use /tmp to not pollute cwd
tmpdir=$(mktemp -d)
df_name=$(mktemp -p "$tmpdir" Dockerfile.XXXX)
pushd "$tmpdir"
# Check if the image is available locally and try to pull it if it is not
docker images "$src_image" &>/dev/null || echo "$s2i_args" | grep -q "pull-policy=never" || docker pull "$src_image"
user_id=$(docker inspect -f "{{.ContainerConfig.User}}" "$src_image")
# Strip file:// from APP_PATH and copy its contents into current context
mkdir -p "$local_app"
cp -r "${app_path/file:\/\//}/." "$local_app"
[ -d "$local_app/.s2i/bin/" ] && mv "$local_app/.s2i/bin" "$local_scripts"
# Create a Dockerfile named df_name and fill it with proper content
#FIXME: Some commands could be combined into a single layer but not sure if worth the trouble for testing purposes
cat <<EOF >"$df_name"
FROM $src_image
LABEL "io.openshift.s2i.build.image"="$src_image" \\
"io.openshift.s2i.build.source-location"="$app_path"
USER root
COPY $local_app /tmp/src
EOF
[ -d "$local_scripts" ] && echo "COPY $local_scripts /tmp/scripts" >> "$df_name" &&
echo "RUN chown -R $user_id:0 /tmp/scripts" >>"$df_name"
echo "RUN chown -R $user_id:0 /tmp/src" >>"$df_name"
# Check for custom environment variables inside .s2i/ folder
if [ -e "$local_app/.s2i/environment" ]; then
# Remove any comments and add the contents as ENV commands to the Dockerfile
sed '/^\s*#.*$/d' "$local_app/.s2i/environment" | while read -r line; do
echo "ENV $line" >>"$df_name"
done
fi
# Filter out env var definitions from $s2i_args and create Dockerfile ENV commands out of them
echo "$s2i_args" | grep -o -e '\(-e\|--env\)[[:space:]=]\S*=\S*' | sed -e 's/-e /ENV /' -e 's/--env[ =]/ENV /' >>"$df_name"
echo "USER $user_id" >>"$df_name"
# If exists, run the custom assemble script, else default to /usr/libexec/s2i/assemble
if [ -x "$local_scripts/assemble" ]; then
echo "RUN /tmp/scripts/assemble" >>"$df_name"
else
echo "RUN /usr/libexec/s2i/assemble" >>"$df_name"
fi
# If exists, set the custom run script as CMD, else default to /usr/libexec/s2i/run
if [ -x "$local_scripts/run" ]; then
echo "CMD /tmp/scripts/run" >>"$df_name"
else
echo "CMD /usr/libexec/s2i/run" >>"$df_name"
fi
# Run the build and tag the result
docker build -f "$df_name" -t "$dst_image" .
popd
}