From d32edfb53d832e395aef7c7a2ba313acf117b7a5 Mon Sep 17 00:00:00 2001 From: Clement Verna Date: Mon, 27 Aug 2018 09:50:31 +0200 Subject: [PATCH 1/9] Drop Release label in favor of OSBS release_bump plugin. OSBS can automatically bump the release number, for that we just need to drop the label from the Dockerfile See https://pagure.io/ContainerSIG/container-sig/issue/1 Signed-off-by: Clement Verna --- Dockerfile | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/Dockerfile b/Dockerfile index 684b8dc..6d1874c 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM registry.fedoraproject.org/f26/s2i-base:latest +FROM registry.fedoraproject.org/f30/s2i-base:latest # nginx 1.12 image. # @@ -11,7 +11,6 @@ EXPOSE 8443 ENV NAME=nginx \ NGINX_VERSION=1.12 \ VERSION=0 \ - RELEASE=1 \ ARCH=x86_64 ENV SUMMARY="Platform for running nginx $NGINX_VERSION or building nginx-based application" \ @@ -31,7 +30,6 @@ LABEL summary="$SUMMARY" \ com.redhat.component="$NAME" \ name="$FGC/$NAME" \ version="$VERSION" \ - release="$RELEASE.$DISTTAG" \ architecture="$ARCH" \ usage="s2i build file:///your/app $FGC/nginx your-app" From a6ce591931333de3b414d2c28ae51c5654d77f98 Mon Sep 17 00:00:00 2001 From: Clement Verna Date: Mon, 27 Aug 2018 09:49:05 +0200 Subject: [PATCH 2/9] Drop Release label in favor of OSBS release_bump plugin. OSBS can automatically bump the release number, for that we just need to drop the label from the Dockerfile See https://pagure.io/ContainerSIG/container-sig/issue/1 Signed-off-by: Clement Verna --- Dockerfile | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/Dockerfile b/Dockerfile index 684b8dc..c15998f 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM registry.fedoraproject.org/f26/s2i-base:latest +FROM registry.fedoraproject.org/f28/s2i-base:latest # nginx 1.12 image. # @@ -11,7 +11,6 @@ EXPOSE 8443 ENV NAME=nginx \ NGINX_VERSION=1.12 \ VERSION=0 \ - RELEASE=1 \ ARCH=x86_64 ENV SUMMARY="Platform for running nginx $NGINX_VERSION or building nginx-based application" \ @@ -31,7 +30,6 @@ LABEL summary="$SUMMARY" \ com.redhat.component="$NAME" \ name="$FGC/$NAME" \ version="$VERSION" \ - release="$RELEASE.$DISTTAG" \ architecture="$ARCH" \ usage="s2i build file:///your/app $FGC/nginx your-app" From 075b20187a7859e0b0bea3c3c7304abb220fde12 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marek=20Skalick=C3=BD?= Date: Mon, 29 Oct 2018 09:35:55 +0000 Subject: [PATCH 3/9] Pull changes from upstream repository. --- Dockerfile | 59 +- Dockerfile.fedora | 1 + README.md | 36 +- help.md | 1 + root/help.1 | 139 +++ root/opt/app-root/nginxconf.sed | 2 - .../share/container-scripts/nginx/common.sh | 31 + s2i/bin/assemble | 16 + s2i/bin/run | 4 + test/run | 102 +- test/run-openshift | 37 + test/start-hook-test-app/index.html | 8 + test/start-hook-test-app/index2.html | 8 + .../nginx-cfg/default.conf | 8 + test/start-hook-test-app/nginx-start/init.sh | 19 + test/test-app | 1 - test/test-app/index.html | 8 + test/test-app/index2.html | 8 + test/test-app/nginx-cfg/default.conf | 6 + test/test-app/nginx-default-cfg/alias.conf | 3 + test/test-app/nginx.conf | 117 +++ test/test-app/nginx.conf.fedora | 90 ++ test/test-lib-openshift.sh | 925 ++++++++++++++++++ test/test-lib.sh | 507 ++++++++++ 24 files changed, 2082 insertions(+), 54 deletions(-) create mode 120000 Dockerfile.fedora create mode 120000 help.md create mode 100644 root/help.1 create mode 100644 root/usr/share/container-scripts/nginx/common.sh create mode 100755 test/run-openshift create mode 100644 test/start-hook-test-app/index.html create mode 100644 test/start-hook-test-app/index2.html create mode 100644 test/start-hook-test-app/nginx-cfg/default.conf create mode 100644 test/start-hook-test-app/nginx-start/init.sh delete mode 120000 test/test-app create mode 100644 test/test-app/index.html create mode 100644 test/test-app/index2.html create mode 100644 test/test-app/nginx-cfg/default.conf create mode 100644 test/test-app/nginx-default-cfg/alias.conf create mode 100644 test/test-app/nginx.conf create mode 100644 test/test-app/nginx.conf.fedora create mode 100644 test/test-lib-openshift.sh create mode 100644 test/test-lib.sh diff --git a/Dockerfile b/Dockerfile index c15998f..023bff7 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM registry.fedoraproject.org/f28/s2i-base:latest +FROM registry.fedoraproject.org/f28/s2i-core:latest # nginx 1.12 image. # @@ -10,6 +10,7 @@ EXPOSE 8443 ENV NAME=nginx \ NGINX_VERSION=1.12 \ + NGINX_SHORT_VER=112 \ VERSION=0 \ ARCH=x86_64 @@ -20,21 +21,25 @@ image provides a containerized packaging of the nginx $NGINX_VERSION daemon. The as a base image for other applications based on nginx $NGINX_VERSION web server. \ Nginx server image can be extended using source-to-image tool." -LABEL summary="$SUMMARY" \ - description="$DESCRIPTION" \ - io.k8s.description="$SUMMARY" \ - io.k8s.display-name="Nginx $NGINX_VERSION" \ +LABEL summary="${SUMMARY}" \ + description="${DESCRIPTION}" \ + io.k8s.description="${DESCRIPTION}" \ + io.k8s.display-name="Nginx ${NGINX_VERSION}" \ io.openshift.expose-services="8080:http" \ io.openshift.expose-services="8443:https" \ - io.openshift.tags="builder,nginx,nginx112" \ - com.redhat.component="$NAME" \ - name="$FGC/$NAME" \ - version="$VERSION" \ - architecture="$ARCH" \ - usage="s2i build file:///your/app $FGC/nginx your-app" + io.openshift.tags="builder,${NAME},${NAME}${NGINX_SHORT_VER}" \ + com.redhat.component="${NAME}" \ + name="${FGC}/${NAME}" \ + version="${VERSION}" \ + maintainer="SoftwareCollections.org " \ + help="For more information visit https://github.com/sclorg/${NAME}-container" \ + usage="s2i build ${FGC}/nginx " -ENV NGINX_CONFIGURATION_PATH=/opt/app-root/etc/nginx.d -ENV NGINX_DEFAULT_CONF_PATH=/opt/app-root/etc/nginx.default.d +ENV NGINX_CONFIGURATION_PATH=${APP_ROOT}/etc/nginx.d \ + NGINX_CONF_PATH=/etc/nginx/nginx.conf \ + NGINX_DEFAULT_CONF_PATH=${APP_ROOT}/etc/nginx.default.d \ + NGINX_CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/nginx \ + NGINX_APP_ROOT=${APP_ROOT} RUN dnf install -y gettext hostname && \ INSTALL_PKGS="nss_wrapper bind-utils nginx" && \ @@ -51,17 +56,29 @@ COPY ./root/ / # In order to drop the root user, we have to make some directories world # writeable as OpenShift default security model is to run the container under # random UID. -RUN sed -i -f /opt/app-root/nginxconf-fed.sed /etc/nginx/nginx.conf && \ - mkdir -p /opt/app-root/etc/nginx.d/ && \ - mkdir -p /opt/app-root/etc/nginx.default.d/ && \ - chmod -R a+rwx /opt/app-root/etc && \ +RUN sed -i -f ${NGINX_APP_ROOT}/nginxconf-fed.sed ${NGINX_CONF_PATH} && \ + chmod a+rwx ${NGINX_CONF_PATH} && \ + mkdir -p ${NGINX_APP_ROOT}/etc/nginx.d/ && \ + mkdir -p ${NGINX_APP_ROOT}/etc/nginx.default.d/ && \ + mkdir -p ${NGINX_APP_ROOT}/src/nginx-start/ && \ + mkdir -p ${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start && \ + mkdir -p /var/log/nginx && \ + ln -sf /dev/stdout /var/log/nginx/access.log && \ + ln -sf /dev/stderr /var/log/nginx/error.log && \ + chmod -R a+rwx ${NGINX_APP_ROOT}/etc && \ chmod -R a+rwx /var /run && \ - chown -R 1001:0 /opt/app-root && \ - chown -R 1001:0 /var + chmod -R a+rwx ${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start && \ + chown -R 1001:0 ${NGINX_APP_ROOT} && \ + chown -R 1001:0 /var && \ + chown -R 1001:0 ${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start && \ + rpm-file-permissions + USER 1001 -VOLUME ["/usr/share/nginx/html"] -VOLUME ["/var/log/nginx/"] +# Not using VOLUME statement since it's not working in OpenShift Online: +# https://github.com/sclorg/httpd-container/issues/30 +# VOLUME ["/usr/share/nginx/html"] +# VOLUME ["/var/log/nginx/"] CMD $STI_SCRIPTS_PATH/usage diff --git a/Dockerfile.fedora b/Dockerfile.fedora new file mode 120000 index 0000000..1d1fe94 --- /dev/null +++ b/Dockerfile.fedora @@ -0,0 +1 @@ +Dockerfile \ No newline at end of file diff --git a/README.md b/README.md index a3501b1..077002f 100644 --- a/README.md +++ b/README.md @@ -1,4 +1,4 @@ -Nginx 1.12 server and a reverse proxy server Docker image +Nginx 1.12 server and a reverse proxy server container image ========================================================= This container image includes Nginx 1.12 server and a reverse server for OpenShift and general usage. @@ -47,20 +47,36 @@ S2I build support Nginx server image can be extended using S2I tool (see Usage section). S2I build folder structure: -| Folder name | Description | -| :-------------------------- | ----------------------------------------- | -| ./nginx-cfg/*.conf | Should contain all nginx configuration we want to include into image | -| ./nginx-default-cfg/*.conf | Contains any nginx config snippets to include in the default server block | -| ./ | Should contain nginx application source code | +**`./nginx.conf`**-- + The main nginx configuration file + +**`./nginx-cfg/*.conf`** + Should contain all nginx configuration we want to include into image + +**`./nginx-default-cfg/*.conf`** + Contains any nginx config snippets to include in the default server block + +**`./nginx-start/*.sh`** + Contains shell scripts that are sourced right before nginx is launched + +**`./`** + Should contain nginx application source code + Environment variables and volumes ------------- The nginx container image supports the following configuration variable, which can be set by using the `-e` option with the docker run command: -| Variable name | Description | -| :--------------------- | ----------------------------------------- | -| `NGINX_LOG_TO_VOLUME` | When `NGINX_LOG_TO_VOLUME` is set, nginx logs into `/var/opt/rh/rh-nginx112/log/nginx/` | +**`NGINX_LOG_TO_VOLUME`** + When `NGINX_LOG_TO_VOLUME` is set, nginx logs into `/var/opt/rh/rh-nginx112/log/nginx/` + + +You can mount your own web root like this: +``` +$ docker run -v :/var/www/html/ +``` +You can replace \ with location of your web root. Please note that this has to be an **absolute** path, due to Docker requirements. Troubleshooting @@ -69,7 +85,7 @@ By default, nginx logs into standard output, so the log is available in the cont docker logs -**If `NGINX_LOG_TO_VOLUME` variable is set, nginx logs into `/var/opt/rh/rh-nginx112/log/nginx/`, which can be mounted to host system using the Docker volumes.** +**If `NGINX_LOG_TO_VOLUME` variable is set, nginx logs into `/var/opt/rh/rh-nginx112/log/nginx/`, which can be mounted to host system using the container volumes.** See also diff --git a/help.md b/help.md new file mode 120000 index 0000000..42061c0 --- /dev/null +++ b/help.md @@ -0,0 +1 @@ +README.md \ No newline at end of file diff --git a/root/help.1 b/root/help.1 new file mode 100644 index 0000000..d8ce31c --- /dev/null +++ b/root/help.1 @@ -0,0 +1,139 @@ +.TH Nginx 1.12 server and a reverse proxy server container image +.PP +This container image includes Nginx 1.12 server and a reverse server for OpenShift and general usage. +Users can choose RHEL based image. +The RHEL image is available in the Red Hat Container Catalog +\[la]https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/nginx-112-rhel7\[ra] +as registry.access.redhat.com/rhscl/nginx\-112\-rhel7. + +.SH Description +.PP +Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 and IMAP +protocols, with a strong focus on high concurrency, performance and low memory usage. The container +image provides a containerized packaging of the nginx 1.12 daemon. The image can be used +as a base image for other applications based on nginx 1.12 web server. +Nginx server image can be extended using source\-to\-image tool. + +.SH Usage +.PP +To build a simple sample\-app +\[la]https://github.com/sclorg/nginx-container/tree/master/1.12/test/test-app\[ra] application +using standalone S2I +\[la]https://github.com/openshift/source-to-image\[ra] and then run the +resulting image with Docker +\[la]http://docker.io\[ra] execute: +.IP \(bu 2 + +.PP +\fBFor RHEL based image\fP +.PP +.RS + +.nf +$ s2i build https://github.com/sclorg/nginx\-container.git \-\-context\-dir=1.12/test/test\-app/ rhscl/nginx\-112\-rhel7 nginx\-sample\-app +$ docker run \-p 8080:8080 nginx\-sample\-app + +.fi +.RE +.IP \(bu 2 + +.PP +\fBFor CentOS based image\fP +.PP +.RS + +.nf +$ s2i build https://github.com/sclorg/nginx\-container.git \-\-context\-dir=1.12/test/test\-app/ centos/nginx\-112\-centos7 nginx\-sample\-app +$ docker run \-p 8080:8080 nginx\-sample\-app + +.fi +.RE + +.PP +\fBAccessing the application:\fP + +.PP +.RS + +.nf +$ curl 127.0.0.1:8080 + +.fi +.RE + +.SH S2I build support +.PP +Nginx server image can be extended using S2I tool (see Usage section). +S2I build folder structure: + +.PP +\fB\fB\fC\&./nginx.conf\fR\fP\-\- + The main nginx configuration file + +.PP +\fB\fB\fC\&./nginx\-\&cfg/*.conf\fR\fP +.br + Should contain all nginx configuration we want to include into image + +.PP +\fB\fB\fC\&./nginx\-\&default\-\&cfg/*.conf\fR\fP +.br + Contains any nginx config snippets to include in the default server block + +.PP +\fB\fB\fC\&./nginx\-\&start/*.sh\fR\fP +.br + Contains shell scripts that are sourced right before nginx is launched + +.PP +\fB\fB\fC\&./\fR\fP +.br + Should contain nginx application source code + +.SH Environment variables and volumes +.PP +The nginx container image supports the following configuration variable, which can be set by using the \fB\fC\-e\fR option with the docker run command: + +.PP +\fB\fB\fCNGINX\_LOG\_TO\_VOLUME\fR\fP +.br + When \fB\fCNGINX\_LOG\_TO\_VOLUME\fR is set, nginx logs into \fB\fC/var/opt/rh/rh\-nginx112/log/nginx/\fR + +.PP +You can mount your own web root like this: + +.PP +.RS + +.nf +$ docker run \-v :/var/www/html/ + +.fi +.RE + +.PP +You can replace with location of your web root. Please note that this has to be an \fBabsolute\fP path, due to Docker requirements. + +.SH Troubleshooting +.PP +By default, nginx logs into standard output, so the log is available in the container log. The log can be examined by running: + +.PP +.RS + +.nf +docker logs + +.fi +.RE + +.PP +\fBIf \fB\fCNGINX\_LOG\_TO\_VOLUME\fR variable is set, nginx logs into \fB\fC/var/opt/rh/rh\-nginx112/log/nginx/\fR, which can be mounted to host system using the container volumes.\fP + +.SH See also +.PP +Dockerfile and other sources for this container image are available on + +\[la]https://github.com/sclorg/nginx-container\[ra]\&. +In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile +for RHEL is called Dockerfile.rhel7. diff --git a/root/opt/app-root/nginxconf.sed b/root/opt/app-root/nginxconf.sed index 36faf3a..007448d 100644 --- a/root/opt/app-root/nginxconf.sed +++ b/root/opt/app-root/nginxconf.sed @@ -3,5 +3,3 @@ s/^user *nginx;// s%/etc/opt/rh/rh-nginx112/nginx/conf.d/%/opt/app-root/etc/nginx.d/% s%/etc/opt/rh/rh-nginx112/nginx/default.d/%/opt/app-root/etc/nginx.default.d/% s%/opt/rh/rh-nginx112/root/usr/share/nginx/html%/opt/app-root/src% -s%/var/opt/rh/rh-nginx112/log/nginx/error.log%stderr% -s%access_log /var/opt/rh/rh-nginx112/log/nginx/access.log main;%% diff --git a/root/usr/share/container-scripts/nginx/common.sh b/root/usr/share/container-scripts/nginx/common.sh new file mode 100644 index 0000000..319219c --- /dev/null +++ b/root/usr/share/container-scripts/nginx/common.sh @@ -0,0 +1,31 @@ +#!/bin/sh + +# get_matched_files finds file for image extending +function get_matched_files() { + local custom_dir default_dir + custom_dir="$1" + default_dir="$2" + files_matched="$3" + find "$default_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n" + [ -d "$custom_dir" ] && find "$custom_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n" +} + +# process_extending_files process extending files in $1 and $2 directories +# - source all *.sh files +# (if there are files with same name source only file from $1) +function process_extending_files() { + local custom_dir default_dir + custom_dir=$1 + default_dir=$2 + while read filename ; do + if [ $filename ]; then + echo "=> sourcing $filename ..." + # Custom file is prefered + if [ -f $custom_dir/$filename ]; then + source $custom_dir/$filename + elif [ -f $default_dir/$filename ]; then + source $default_dir/$filename + fi + fi + done <<<"$(get_matched_files "$custom_dir" "$default_dir" '*.sh' | sort -u)" +} \ No newline at end of file diff --git a/s2i/bin/assemble b/s2i/bin/assemble index 65ba990..ef27877 100755 --- a/s2i/bin/assemble +++ b/s2i/bin/assemble @@ -5,12 +5,19 @@ set -e echo "---> Installing application source" cp -Rf /tmp/src/. ./ +if [ -f ./nginx.conf ]; then + echo "---> Copying nginx.conf configuration file..." + cp -v ./nginx.conf "${NGINX_CONF_PATH}" + rm -f ./nginx.conf +fi + if [ -d ./nginx-cfg ]; then echo "---> Copying nginx configuration files..." if [ "$(ls -A ./nginx-cfg/*.conf)" ]; then cp -v ./nginx-cfg/*.conf "${NGINX_CONFIGURATION_PATH}" rm -rf ./nginx-cfg fi + chmod -Rf g+rw ${NGINX_CONFIGURATION_PATH} fi if [ -d ./nginx-default-cfg ]; then @@ -19,6 +26,15 @@ if [ -d ./nginx-default-cfg ]; then cp -v ./nginx-default-cfg/*.conf "${NGINX_DEFAULT_CONF_PATH}" rm -rf ./nginx-default-cfg fi + chmod -Rf g+rw ${NGINX_DEFAULT_CONF_PATH} +fi + +if [ -d ./nginx-start ]; then + echo "---> Copying nginx start-hook scripts..." + if [ "$(ls -A ./nginx-start/* 2>/dev/null)" ]; then + cp -v ./nginx-start/* "${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start/" + rm -rf ./nginx-start + fi fi # Fix source directory permissions diff --git a/s2i/bin/run b/s2i/bin/run index 084463a..ca8d55b 100755 --- a/s2i/bin/run +++ b/s2i/bin/run @@ -4,4 +4,8 @@ source /opt/app-root/etc/generate_container_user set -e +source ${NGINX_CONTAINER_SCRIPTS_PATH}/common.sh + +process_extending_files ${NGINX_APP_ROOT}/src/nginx-start ${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start + exec nginx -g "daemon off;" diff --git a/test/run b/test/run index a2d2783..3c1545c 100755 --- a/test/run +++ b/test/run @@ -12,6 +12,8 @@ IMAGE_NAME=${IMAGE_NAME:-rhscl/nginx-112-rhel7} test_dir="$(readlink -zf $(dirname "${BASH_SOURCE[0]}"))" image_dir=$(readlink -zf ${test_dir}/..) +. $test_dir/test-lib.sh + # TODO: This should be part of the image metadata test_port=8080 @@ -32,7 +34,7 @@ container_ip() { } run_s2i_build() { - s2i build ${s2i_args} file://${test_dir}/test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp + ct_s2i_build_as_df file://${test_dir}/${1} ${IMAGE_NAME} ${IMAGE_NAME}-${1} ${s2i_args} } prepare() { @@ -43,7 +45,7 @@ prepare() { # TODO: S2I build require the application is a valid 'GIT' repository, we # should remove this restriction in the future when a file:// is used. info "Build the test application image" - pushd ${test_dir}/test-app >/dev/null + pushd ${test_dir}/${1} >/dev/null git init git config user.email "build@localhost" && git config user.name "builder" git add -A && git commit -m "Sample commit" @@ -52,7 +54,7 @@ prepare() { run_test_application() { run_args=${CONTAINER_ARGS:-} - docker run --user=100001 ${run_args} --cidfile=${cid_file} ${IMAGE_NAME}-testapp + docker run --user=100001 ${run_args} --cidfile=${cid_file} ${IMAGE_NAME}-${1} } cleanup_test_app() { @@ -68,17 +70,17 @@ cleanup_test_app() { cleanup() { info "Cleaning up the test application image" - if image_exists ${IMAGE_NAME}-testapp; then - docker rmi -f ${IMAGE_NAME}-testapp + if image_exists ${IMAGE_NAME}-${1}; then + docker rmi -f ${IMAGE_NAME}-${1} fi - rm -rf ${test_dir}/test-app/.git + rm -rf ${test_dir}/${1}/.git } check_result() { local result="$1" if [[ "$result" != "0" ]]; then info "TEST FAILED (${result})" - cleanup + cleanup $2 exit $result fi } @@ -98,7 +100,7 @@ wait_for_cid() { test_s2i_usage() { info "Testing 's2i usage'" - s2i usage ${s2i_args} ${IMAGE_NAME} &>/dev/null + ct_s2i_usage ${IMAGE_NAME} ${s2i_args} &>/dev/null } test_docker_run_usage() { @@ -116,6 +118,18 @@ test_scl_usage() { echo "ERROR[/bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'" return 1 fi + test_command "$run_cmd" "$expected" + return $? +} + +test_command() { + local run_cmd="$1" + local expected="$2" + local message="$3" + + if [ $message ]; then + info ${3} + fi out=$(docker exec $(cat ${cid_file}) /bin/bash -c "${run_cmd}" 2>&1) if ! echo "${out}" | grep -q "${expected}"; then echo "ERROR[exec /bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'" @@ -125,7 +139,9 @@ test_scl_usage() { if ! echo "${out}" | grep -q "${expected}"; then echo "ERROR[exec /bin/sh -ic "${run_cmd}"] Expected '${expected}', got '${out}'" return 1 - fi + fi + + return 0 } test_for_output() @@ -174,44 +190,90 @@ test_connection() { return 1 } +test_connection_s2i() { + cat $cid_file + info "Testing the HTTP connection (http://$(container_ip):${test_port})" + + if test_for_output "http://$(container_ip):${test_port}/" "NGINX is working" && + test_for_output "http://$(container_ip):${test_port}/" "NGINX2 is working" localhost2 && + test_for_output "http://$(container_ip):${test_port}/nginx-cfg/default.conf" "404"; then + return 0 + fi + + return 1 +} + test_application() { # Verify that the HTTP connection can be established to test application container - run_test_application & + run_test_application "test-app" & # Wait for the container to write it's CID file wait_for_cid test_scl_usage "nginx -v" "nginx version: nginx/1.12." - check_result $? + check_result $? "test-app" test_connection - check_result $? + check_result $? "test-app" cleanup_test_app } +test_pre_init_script() { + # Verify that the HTTP connection can be established to test application container + run_test_application "start-hook-test-app" & + + # Wait for the container to write it's CID file + wait_for_cid + + test_command "cat /opt/app-root/etc/nginx.d/default.conf | grep 'resolver' | sed -e 's/resolver\(.*\);/\1/' | grep 'DNS_SERVER'" "" + check_result $? "start-hook-test-app" + + test_connection_s2i + check_result $? "start-hook-test-app" + cleanup_test_app + +} + cid_file=$(mktemp -u --suffix=.cid) # Since we built the candidate image locally, we don't want S2I attempt to pull # it from Docker hub s2i_args="--pull-policy=never" -prepare -run_s2i_build -check_result $? +if [ "$TARGET" == "fedora" ]; then + mv ${test_dir}/test-app/nginx.conf{,.bkp} + cp ${test_dir}/test-app/nginx.conf{.fedora,} +fi +prepare "test-app" +run_s2i_build "test-app" +if [ "$TARGET" == "fedora" ]; then + mv ${test_dir}/test-app/nginx.conf{.bkp,} +fi +check_result $? "test-app" # Verify the 'usage' script is working properly when running the base image with 's2i usage ...' test_s2i_usage -check_result $? +check_result $? "test-app" # Verify the 'usage' script is working properly when running the base image with 'docker run ...' test_docker_run_usage -check_result $? +check_result $? "test-app" # Test application with default uid -test_application +test_application # Test application with random uid -CONTAINER_ARGS="-u 12345" test_application -cleanup +CONTAINER_ARGS="--user 12345" test_application +cleanup "test-app" + +# Test start-hook script functionality +cid_file=$(mktemp -u --suffix=.cid) + +prepare "start-hook-test-app" +run_s2i_build "start-hook-test-app" +check_result $? "start-hook-test-app" + +test_pre_init_script +cleanup "start-hook-test-app" info "All tests finished successfully." diff --git a/test/run-openshift b/test/run-openshift new file mode 100755 index 0000000..fd2a22f --- /dev/null +++ b/test/run-openshift @@ -0,0 +1,37 @@ +#!/bin/bash +# +# Test the Nginx image in OpenShift. +# +# IMAGE_NAME specifies a name of the candidate image used for testing. +# The image has to be available before this script is executed. +# + +THISDIR=$(dirname ${BASH_SOURCE[0]}) + +source ${THISDIR}/test-lib.sh +source ${THISDIR}/test-lib-openshift.sh + +# TODO: branch should be changed to master, once code in example app +# stabilizes on with referencing latest version +BRANCH_TO_TEST=master + +set -eo nounset + +test -n "${IMAGE_NAME-}" || false 'make sure $IMAGE_NAME is defined' +test -n "${VERSION-}" || false 'make sure $VERSION is defined' + +ct_os_cluster_up + +# test local app +ct_os_test_s2i_app ${IMAGE_NAME} "${THISDIR}/test-app" . 'Test NGINX passed' + +# test remote example app +ct_os_test_s2i_app ${IMAGE_NAME} "https://github.com/sclorg/nginx-ex.git#${BRANCH_TO_TEST}" . 'Welcome to your static nginx application on OpenShift' + +# test template from the example app +ct_os_test_template_app ${IMAGE_NAME} \ + https://raw.githubusercontent.com/sclorg/nginx-ex/${BRANCH_TO_TEST}/openshift/templates/nginx.json \ + nginx \ + 'Welcome to your static nginx application on OpenShift' \ + 8080 http 200 "-p SOURCE_REPOSITORY_REF=${BRANCH_TO_TEST} -p NGINX_VERSION=${VERSION} -p NAME=nginx-testing" + diff --git a/test/start-hook-test-app/index.html b/test/start-hook-test-app/index.html new file mode 100644 index 0000000..d147627 --- /dev/null +++ b/test/start-hook-test-app/index.html @@ -0,0 +1,8 @@ + + + Test NGINX passed + + +

NGINX is working

+ + diff --git a/test/start-hook-test-app/index2.html b/test/start-hook-test-app/index2.html new file mode 100644 index 0000000..e73a98c --- /dev/null +++ b/test/start-hook-test-app/index2.html @@ -0,0 +1,8 @@ + + + Test NGINX passed + + +

NGINX2 is working

+ + diff --git a/test/start-hook-test-app/nginx-cfg/default.conf b/test/start-hook-test-app/nginx-cfg/default.conf new file mode 100644 index 0000000..e947c98 --- /dev/null +++ b/test/start-hook-test-app/nginx-cfg/default.conf @@ -0,0 +1,8 @@ +server { + listen 8080; + server_name localhost2; + root /opt/app-root/src; + index ${INDEX_FILE}; + resolver ${DNS_SERVER}; + +} \ No newline at end of file diff --git a/test/start-hook-test-app/nginx-start/init.sh b/test/start-hook-test-app/nginx-start/init.sh new file mode 100644 index 0000000..450dfe4 --- /dev/null +++ b/test/start-hook-test-app/nginx-start/init.sh @@ -0,0 +1,19 @@ +setup_dns_env_var() { + if [ -z "$DNS_SERVER" ]; then + export DNS_SERVER=`cat /etc/resolv.conf | grep "nameserver " | awk '{print $2}' | tr '\n' ' '` + echo "Using system dns server ${DNS_SERVER}" + else + echo "Using user defined dns server: ${DNS_SERVER}" + fi +} + +inject_env_vars() { + ## Replace only specified environment variables in specified file. + envsubst '${DNS_SERVER},${INDEX_FILE}' < ${NGINX_CONFIGURATION_PATH}/$1 > output.conf + cp output.conf ${NGINX_CONFIGURATION_PATH}/$1 + echo "This is $1: " && cat ${NGINX_CONFIGURATION_PATH}/$1 +} + +export INDEX_FILE=index2.html +setup_dns_env_var +inject_env_vars "default.conf" diff --git a/test/test-app b/test/test-app deleted file mode 120000 index 5f73990..0000000 --- a/test/test-app +++ /dev/null @@ -1 +0,0 @@ -../../examples/1.12/test-app \ No newline at end of file diff --git a/test/test-app/index.html b/test/test-app/index.html new file mode 100644 index 0000000..d147627 --- /dev/null +++ b/test/test-app/index.html @@ -0,0 +1,8 @@ + + + Test NGINX passed + + +

NGINX is working

+ + diff --git a/test/test-app/index2.html b/test/test-app/index2.html new file mode 100644 index 0000000..e73a98c --- /dev/null +++ b/test/test-app/index2.html @@ -0,0 +1,8 @@ + + + Test NGINX passed + + +

NGINX2 is working

+ + diff --git a/test/test-app/nginx-cfg/default.conf b/test/test-app/nginx-cfg/default.conf new file mode 100644 index 0000000..d5a49f6 --- /dev/null +++ b/test/test-app/nginx-cfg/default.conf @@ -0,0 +1,6 @@ +server { + listen 8080; + server_name localhost2; + root /opt/app-root/src; + index index2.html; +} diff --git a/test/test-app/nginx-default-cfg/alias.conf b/test/test-app/nginx-default-cfg/alias.conf new file mode 100644 index 0000000..649ca52 --- /dev/null +++ b/test/test-app/nginx-default-cfg/alias.conf @@ -0,0 +1,3 @@ +location /aliased/ { + alias /opt/app-root/src/; +} diff --git a/test/test-app/nginx.conf b/test/test-app/nginx.conf new file mode 100644 index 0000000..76ce0eb --- /dev/null +++ b/test/test-app/nginx.conf @@ -0,0 +1,117 @@ +# For more information on configuration, see: +# * Official English Documentation: http://nginx.org/en/docs/ +# * Official Russian Documentation: http://nginx.org/ru/docs/ + + +worker_processes auto; +error_log stderr; +pid /var/opt/rh/rh-nginx112/run/nginx/nginx.pid; + +# Load dynamic modules. See /opt/rh/rh-nginx112/root/usr/share/doc/README.dynamic. +include /opt/rh/rh-nginx112/root/usr/share/nginx/modules/*.conf; + +events { + worker_connections 1024; +} + +http { + log_format main '$remote_addr - $remote_user [$time_local] "$request" ' + '$status $body_bytes_sent "$http_referer" ' + '"$http_user_agent" "$http_x_forwarded_for"'; + + sendfile on; + tcp_nopush on; + tcp_nodelay on; + keepalive_timeout 65; + types_hash_max_size 2048; + + include /etc/opt/rh/rh-nginx112/nginx/mime.types; + default_type application/octet-stream; + + # Load modular configuration files from the /etc/nginx/conf.d directory. + # See http://nginx.org/en/docs/ngx_core_module.html#include + # for more information. + include /opt/app-root/etc/nginx.d/*.conf; + + server { + listen 8080 default_server; + listen [::]:8080 default_server; + server_name _; + root /opt/app-root/src; + + # Load configuration files for the default server block. + include /opt/app-root/etc/nginx.default.d/*.conf; + + location / { + } + + error_page 404 /404.html; + location = /40x.html { + } + + error_page 500 502 503 504 /50x.html; + location = /50x.html { + } + + # proxy the PHP scripts to Apache listening on 127.0.0.1:8080 + # + #location ~ \.php$ { + # proxy_pass http://127.0.0.1; + #} + + # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000 + # + #location ~ \.php$ { + # root html; + # fastcgi_pass 127.0.0.1:9000; + # fastcgi_index index.php; + # fastcgi_param SCRIPT_FILENAME /scripts$fastcgi_script_name; + # include fastcgi_params; + #} + + # deny access to .htaccess files, if Apache's document root + # concurs with nginx's one + # + #location ~ /\.ht { + # deny all; + #} + } + + + # another virtual host using mix of IP-, name-, and port-based configuration + # + #server { + # listen 808000; + # listen somename:808080; + # server_name somename alias another.alias; + + # location / { + # root html; + # index index.html index.htm; + # } + #} + + + # HTTPS server + # + #server { + # listen 443; + # server_name localhost; + + # ssl on; + # ssl_certificate cert.pem; + # ssl_certificate_key cert.key; + + # ssl_session_timeout 5m; + + # ssl_protocols SSLv2 SSLv3 TLSv1; + # ssl_ciphers HIGH:!aNULL:!MD5; + # ssl_prefer_server_ciphers on; + + # location / { + # root html; + # index index.html index.htm; + # } + #} + +} diff --git a/test/test-app/nginx.conf.fedora b/test/test-app/nginx.conf.fedora new file mode 100644 index 0000000..e395483 --- /dev/null +++ b/test/test-app/nginx.conf.fedora @@ -0,0 +1,90 @@ +# For more information on configuration, see: +# * Official English Documentation: http://nginx.org/en/docs/ +# * Official Russian Documentation: http://nginx.org/ru/docs/ + + +worker_processes auto; +error_log stderr; +pid /run/nginx.pid; + +# Load dynamic modules. See /usr/share/doc/nginx/README.dynamic. +include /usr/share/nginx/modules/*.conf; + +events { + worker_connections 1024; +} + +http { + log_format main '$remote_addr - $remote_user [$time_local] "$request" ' + '$status $body_bytes_sent "$http_referer" ' + '"$http_user_agent" "$http_x_forwarded_for"'; + + + + sendfile on; + tcp_nopush on; + tcp_nodelay on; + keepalive_timeout 65; + types_hash_max_size 2048; + + include /etc/nginx/mime.types; + default_type application/octet-stream; + + # Load modular configuration files from the /etc/nginx/conf.d directory. + # See http://nginx.org/en/docs/ngx_core_module.html#include + # for more information. + include /opt/app-root/etc/nginx.d/*.conf; + + server { + listen 8080 default_server; + listen [::]:8080 default_server; + server_name _; + root /opt/app-root/src; + + # Load configuration files for the default server block. + include /opt/app-root/etc/nginx.default.d/*.conf; + + location / { + } + + error_page 404 /404.html; + location = /40x.html { + } + + error_page 500 502 503 504 /50x.html; + location = /50x.html { + } + } + +# Settings for a TLS enabled server. +# +# server { +# listen 443 ssl http2 default_server; +# listen [::]:443 ssl http2 default_server; +# server_name _; +# root /opt/app-root/src; +# +# ssl_certificate "/etc/pki/nginx/server.crt"; +# ssl_certificate_key "/etc/pki/nginx/private/server.key"; +# ssl_session_cache shared:SSL:1m; +# ssl_session_timeout 10m; +# ssl_ciphers PROFILE=SYSTEM; +# ssl_prefer_server_ciphers on; +# +# # Load configuration files for the default server block. +# include /opt/app-root/etc/nginx.default.d/*.conf; +# +# location / { +# } +# +# error_page 404 /404.html; +# location = /40x.html { +# } +# +# error_page 500 502 503 504 /50x.html; +# location = /50x.html { +# } +# } + +} + diff --git a/test/test-lib-openshift.sh b/test/test-lib-openshift.sh new file mode 100644 index 0000000..f988ac5 --- /dev/null +++ b/test/test-lib-openshift.sh @@ -0,0 +1,925 @@ +# Set of functions for testing docker images in OpenShift using 'oc' command + +# ct_os_get_status +# -------------------- +# Returns status of all objects to make debugging easier. +function ct_os_get_status() { + oc get all + oc status +} + +# ct_os_print_logs +# -------------------- +# Returns status of all objects and logs from all pods. +function ct_os_print_logs() { + ct_os_get_status + while read pod_name; do + echo "INFO: printing logs for pod ${pod_name}" + oc logs ${pod_name} + done < <(oc get pods --no-headers=true -o custom-columns=NAME:.metadata.name) +} + +# ct_os_enable_print_logs +# -------------------- +# Enables automatic printing of pod logs on ERR. +function ct_os_enable_print_logs() { + set -E + trap ct_os_print_logs ERR +} + +# ct_get_public_ip +# -------------------- +# Returns best guess for the IP that the node is accessible from other computers. +# This is a bit funny heuristic, simply goes through all IPv4 addresses that +# hostname -I returns and de-prioritizes IP addresses commonly used for local +# addressing. The rest of addresses are taken as public with higher probability. +function ct_get_public_ip() { + local hostnames=$(hostname -I) + local public_ip='' + local found_ip + for guess_exp in '127\.0\.0\.1' '192\.168\.[0-9\.]*' '172\.[0-9\.]*' \ + '10\.[0-9\.]*' '[0-9\.]*' ; do + found_ip=$(echo "${hostnames}" | grep -oe "${guess_exp}") + if [ -n "${found_ip}" ] ; then + hostnames=$(echo "${hostnames}" | sed -e "s/${found_ip}//") + public_ip="${found_ip}" + fi + done + if [ -z "${public_ip}" ] ; then + echo "ERROR: public IP could not be guessed." >&2 + return 1 + fi + echo "${public_ip}" +} + +# ct_os_run_in_pod POD_NAME CMD +# -------------------- +# Runs [cmd] in the pod specified by prefix [pod_prefix]. +# Arguments: pod_name - full name of the pod +# Arguments: cmd - command to be run in the pod +function ct_os_run_in_pod() { + local pod_name="$1" ; shift + + oc exec "$pod_name" -- "$@" +} + +# ct_os_get_service_ip SERVICE_NAME +# -------------------- +# Returns IP of the service specified by [service_name]. +# Arguments: service_name - name of the service +function ct_os_get_service_ip() { + local service_name="${1}" ; shift + oc get "svc/${service_name}" -o yaml | grep clusterIP | \ + cut -d':' -f2 | grep -oe '172\.30\.[0-9\.]*' +} + + +# ct_os_get_all_pods_status +# -------------------- +# Returns status of all pods. +function ct_os_get_all_pods_status() { + oc get pods -o custom-columns=Ready:status.containerStatuses[0].ready,NAME:.metadata.name +} + +# ct_os_get_all_pods_name +# -------------------- +# Returns the full name of all pods. +function ct_os_get_all_pods_name() { + oc get pods --no-headers -o custom-columns=NAME:.metadata.name +} + +# ct_os_get_pod_status POD_PREFIX +# -------------------- +# Returns status of the pod specified by prefix [pod_prefix]. +# Note: Ignores -build and -deploy pods +# Arguments: pod_prefix - prefix or whole ID of the pod +function ct_os_get_pod_status() { + local pod_prefix="${1}" ; shift + ct_os_get_all_pods_status | grep -e "${pod_prefix}" | grep -Ev "(build|deploy)$" \ + | awk '{print $1}' | head -n 1 +} + +# ct_os_get_pod_name POD_PREFIX +# -------------------- +# Returns the full name of pods specified by prefix [pod_prefix]. +# Note: Ignores -build and -deploy pods +# Arguments: pod_prefix - prefix or whole ID of the pod +function ct_os_get_pod_name() { + local pod_prefix="${1}" ; shift + ct_os_get_all_pods_name | grep -e "^${pod_prefix}" | grep -Ev "(build|deploy)$" +} + +# ct_os_get_pod_ip POD_NAME +# -------------------- +# Returns the ip of the pod specified by [pod_name]. +# Arguments: pod_name - full name of the pod +function ct_os_get_pod_ip() { + local pod_name="${1}" + oc get pod "$pod_name" --no-headers -o custom-columns=IP:status.podIP +} + +# ct_os_check_pod_readiness POD_PREFIX STATUS +# -------------------- +# Checks whether the pod is ready. +# Arguments: pod_prefix - prefix or whole ID of the pod +# Arguments: status - expected status (true, false) +function ct_os_check_pod_readiness() { + local pod_prefix="${1}" ; shift + local status="${1}" ; shift + test "$(ct_os_get_pod_status ${pod_prefix})" == "${status}" +} + +# ct_os_wait_pod_ready POD_PREFIX TIMEOUT +# -------------------- +# Wait maximum [timeout] for the pod becomming ready. +# Arguments: pod_prefix - prefix or whole ID of the pod +# Arguments: timeout - how many seconds to wait seconds +function ct_os_wait_pod_ready() { + local pod_prefix="${1}" ; shift + local timeout="${1}" ; shift + SECONDS=0 + echo -n "Waiting for ${pod_prefix} pod becoming ready ..." + while ! ct_os_check_pod_readiness "${pod_prefix}" "true" ; do + echo -n "." + [ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1 + sleep 3 + done + echo " DONE" +} + +# ct_os_wait_rc_ready POD_PREFIX TIMEOUT +# -------------------- +# Wait maximum [timeout] for the rc having desired number of replicas ready. +# Arguments: pod_prefix - prefix of the replication controller +# Arguments: timeout - how many seconds to wait seconds +function ct_os_wait_rc_ready() { + local pod_prefix="${1}" ; shift + local timeout="${1}" ; shift + SECONDS=0 + echo -n "Waiting for ${pod_prefix} pod becoming ready ..." + while ! test "$((oc get --no-headers statefulsets; oc get --no-headers rc) 2>/dev/null \ + | grep "^${pod_prefix}" | awk '$2==$3 {print "ready"}')" == "ready" ; do + echo -n "." + [ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1 + sleep 3 + done + echo " DONE" +} + +# ct_os_deploy_pure_image IMAGE [ENV_PARAMS, ...] +# -------------------- +# Runs [image] in the openshift and optionally specifies env_params +# as environment variables to the image. +# Arguments: image - prefix or whole ID of the pod to run the cmd in +# Arguments: env_params - environment variables parameters for the images. +function ct_os_deploy_pure_image() { + local image="${1}" ; shift + # ignore error exit code, because oc new-app returns error when image exists + oc new-app ${image} "$@" || : + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_deploy_s2i_image IMAGE APP [ENV_PARAMS, ... ] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. +# Arguments: image - prefix or whole ID of the pod to run the cmd in +# Arguments: app - url or local path to git repo with the application sources. +# Arguments: env_params - environment variables parameters for the images. +function ct_os_deploy_s2i_image() { + local image="${1}" ; shift + local app="${1}" ; shift + # ignore error exit code, because oc new-app returns error when image exists + oc new-app "${image}~${app}" "$@" || : + + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_deploy_template_image TEMPLATE [ENV_PARAMS, ...] +# -------------------- +# Runs template in the openshift and optionally gives env_params to use +# specific values in the template. +# Arguments: template - prefix or whole ID of the pod to run the cmd in +# Arguments: env_params - environment variables parameters for the template. +# Example usage: ct_os_deploy_template_image mariadb-ephemeral-template.yaml \ +# DATABASE_SERVICE_NAME=mysql-57-centos7 \ +# DATABASE_IMAGE=mysql-57-centos7 \ +# MYSQL_USER=testu \ +# MYSQL_PASSWORD=testp \ +# MYSQL_DATABASE=testdb +function ct_os_deploy_template_image() { + local template="${1}" ; shift + oc process -f "${template}" "$@" | oc create -f - + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# _ct_os_get_uniq_project_name +# -------------------- +# Returns a uniq name of the OpenShift project. +function _ct_os_get_uniq_project_name() { + local r + while true ; do + r=${RANDOM} + mkdir /var/tmp/sclorg-test-${r} &>/dev/null && echo sclorg-test-${r} && break + done +} + +# ct_os_new_project [PROJECT] +# -------------------- +# Creates a new project in the openshfit using 'os' command. +# Arguments: project - project name, uses a new random name if omitted +# Expects 'os' command that is properly logged in to the OpenShift cluster. +# Not using mktemp, because we cannot use uppercase characters. +function ct_os_new_project() { + if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then + echo "Creating project skipped." + return + fi + local project_name="${1:-$(_ct_os_get_uniq_project_name)}" ; shift || : + oc new-project ${project_name} + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_delete_project [PROJECT] +# -------------------- +# Deletes the specified project in the openshfit +# Arguments: project - project name, uses the current project if omitted +function ct_os_delete_project() { + if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then + echo "Deleting project skipped, cleaning objects only." + ct_delete_all_objects + return + fi + local project_name="${1:-$(oc project -q)}" ; shift || : + oc delete project "${project_name}" +} + +# ct_delete_all_objects +# ----------------- +# Deletes all objects within the project. +# Handy when we have one project and want to run more tests. +function ct_delete_all_objects() { + for x in bc builds dc is isimage istag po pv pvc rc routes secrets svc ; do + oc delete $x --all + done + # for some objects it takes longer to be really deleted, so a dummy sleep + # to avoid some races when other test can see not-yet-deleted objects and can fail + sleep 10 +} + +# ct_os_docker_login +# -------------------- +# Logs in into docker daemon +# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address. +# Does not do anything if REGISTRY_ADDRESS is set. +function ct_os_docker_login() { + [ -n "${REGISTRY_ADDRESS:-}" ] && "REGISTRY_ADDRESS set, not trying to docker login." && return 0 + # docker login fails with "404 page not found" error sometimes, just try it more times + for i in `seq 12` ; do + docker login -u developer -p $(oc whoami -t) ${REGISRTY_ADDRESS:-172.30.1.1:5000} && return 0 || : + sleep 5 + done + return 1 +} + +# ct_os_upload_image IMAGE [IMAGESTREAM] +# -------------------- +# Uploads image from local registry to the OpenShift internal registry. +# Arguments: image - image name to upload +# Arguments: imagestream - name and tag to use for the internal registry. +# In the format of name:tag ($image_name:latest by default) +# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address. +function ct_os_upload_image() { + local input_name="${1}" ; shift + local image_name=${input_name##*/} + local imagestream=${1:-$image_name:latest} + local output_name="${REGISRTY_ADDRESS:-172.30.1.1:5000}/$(oc project -q)/$imagestream" + + ct_os_docker_login + docker tag ${input_name} ${output_name} + docker push ${output_name} +} + +# ct_os_install_in_centos +# -------------------- +# Installs os cluster in CentOS +function ct_os_install_in_centos() { + yum install -y centos-release-openshift-origin + yum install -y wget git net-tools bind-utils iptables-services bridge-utils\ + bash-completion origin-clients docker origin-clients +} + +# ct_os_cluster_up [DIR, IS_PUBLIC, CLUSTER_VERSION] +# -------------------- +# Runs the local OpenShift cluster using 'oc cluster up' and logs in as developer. +# Arguments: dir - directory to keep configuration data in, random if omitted +# Arguments: is_public - sets either private or public hostname for web-UI, +# use "true" for allow remote access to the web-UI, +# "false" is default +# Arguments: cluster_version - version of the OpenShift cluster to use, empty +# means default version of `oc`; example value: 3.7; +# also can be specified outside by OC_CLUSTER_VERSION +function ct_os_cluster_up() { + ct_os_cluster_running && echo "Cluster already running. Nothing is done." && return 0 + ct_os_logged_in && echo "Already logged in to a cluster. Nothing is done." && return 0 + + mkdir -p /var/tmp/openshift + local dir="${1:-$(mktemp -d /var/tmp/openshift/os-data-XXXXXX)}" ; shift || : + local is_public="${1:-'false'}" ; shift || : + local default_cluster_version=${OC_CLUSTER_VERSION:-} + local cluster_version=${1:-${default_cluster_version}} ; shift || : + if ! grep -qe '--insecure-registry.*172\.30\.0\.0' /etc/sysconfig/docker ; then + sed -i "s|OPTIONS='|OPTIONS='--insecure-registry 172.30.0.0/16 |" /etc/sysconfig/docker + fi + + systemctl stop firewalld || : + setenforce 0 + iptables -F + + systemctl restart docker + local cluster_ip="127.0.0.1" + [ "${is_public}" == "true" ] && cluster_ip=$(ct_get_public_ip) + + if [ -n "${cluster_version}" ] ; then + # if $cluster_version is not set, we simply use oc that is available + ct_os_set_path_oc "${cluster_version}" + fi + + mkdir -p ${dir}/{config,data,pv} + case $(oc version| head -n 1) in + "oc v3.1"?.*) + oc cluster up --base-dir="${dir}/data" --public-hostname="${cluster_ip}" + ;; + "oc v3."*) + oc cluster up --host-data-dir="${dir}/data" --host-config-dir="${dir}/config" \ + --host-pv-dir="${dir}/pv" --use-existing-config --public-hostname="${cluster_ip}" + ;; + *) + echo "ERROR: Unexpected oc version." >&2 + return 1 + ;; + esac + oc version + oc login -u system:admin + oc project default + ct_os_wait_rc_ready docker-registry 180 + ct_os_wait_rc_ready router 30 + oc login -u developer -p developer + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_cluster_down +# -------------------- +# Shuts down the local OpenShift cluster using 'oc cluster down' +function ct_os_cluster_down() { + oc cluster down +} + +# ct_os_cluster_running +# -------------------- +# Returns 0 if oc cluster is running +function ct_os_cluster_running() { + oc cluster status &>/dev/null +} + +# ct_os_logged_in +# --------------- +# Returns 0 if logged in to a cluster (remote or local) +function ct_os_logged_in() { + oc whoami >/dev/null +} + +# ct_os_set_path_oc OC_VERSION +# -------------------- +# This is a trick that helps using correct version of the `oc`: +# The input is version of the openshift in format v3.6.0 etc. +# If the currently available version of oc is not of this version, +# it first takes a look into /usr/local/oc-/bin directory, +# and if not found there it downloads the community release from github. +# In the end the PATH variable is changed, so the other tests can still use just 'oc'. +# Arguments: oc_version - X.Y part of the version of OSE (e.g. 3.9) +function ct_os_set_path_oc() { + local oc_version=$(ct_os_get_latest_ver $1) + local oc_path + + if oc version | grep -q "oc ${oc_version%.*}." ; then + echo "Binary oc found already available in version ${oc_version}: `which oc` Doing noting." + return 0 + fi + + # first check whether we already have oc available in /usr/local + local installed_oc_path="/usr/local/oc-${oc_version%.*}/bin" + + if [ -x "${installed_oc_path}/oc" ] ; then + oc_path="${installed_oc_path}" + echo "Binary oc found in ${installed_oc_path}" >&2 + else + # oc not available in /usr/local, try to download it from github (community release) + oc_path="/tmp/oc-${oc_version}-bin" + ct_os_download_upstream_oc "${oc_version}" "${oc_path}" + fi + if [ -z "${oc_path}/oc" ] ; then + echo "ERROR: oc not found installed, nor downloaded" >&1 + return 1 + fi + export PATH="${oc_path}:${PATH}" + if ! oc version | grep -q "oc ${oc_version%.*}." ; then + echo "ERROR: something went wrong, oc located at ${oc_path}, but oc of version ${oc_version} not found in PATH ($PATH)" >&1 + return 1 + else + echo "PATH set correctly, binary oc found in version ${oc_version}: `which oc`" + fi +} + +# ct_os_get_latest_ver VERSION_PART_X +# -------------------- +# Returns full version (vX.Y.Z) from part of the version (X.Y) +# Arguments: vxy - X.Y part of the version +# Returns vX.Y.Z variant of the version +function ct_os_get_latest_ver(){ + local vxy="v$1" + for vz in {3..0} ; do + curl -sif "https://github.com/openshift/origin/releases/tag/${vxy}.${vz}" >/dev/null && echo "${vxy}.${vz}" && return 0 + done + echo "ERROR: version ${vxy} not found in https://github.com/openshift/origin/tags" >&2 + return 1 +} + +# ct_os_download_upstream_oc OC_VERSION OUTPUT_DIR +# -------------------- +# Downloads a particular version of openshift-origin-client-tools from +# github into specified output directory +# Arguments: oc_version - version of OSE (e.g. v3.7.2) +# Arguments: output_dir - output directory +function ct_os_download_upstream_oc() { + local oc_version=$1 + local output_dir=$2 + + # check whether we already have the binary in place + [ -x "${output_dir}/oc" ] && return 0 + + mkdir -p "${output_dir}" + # using html output instead of https://api.github.com/repos/openshift/origin/releases/tags/${oc_version}, + # because API is limited for number of queries if not authenticated + tarball=$(curl -si "https://github.com/openshift/origin/releases/tag/${oc_version}" | grep -o -e "openshift-origin-client-tools-${oc_version}-[a-f0-9]*-linux-64bit.tar.gz" | head -n 1) + + # download, unpack the binaries and then put them into output directory + echo "Downloading https://github.com/openshift/origin/releases/download/${oc_version}/${tarball} into ${output_dir}/" >&2 + curl -sL https://github.com/openshift/origin/releases/download/${oc_version}/"${tarball}" | tar -C "${output_dir}" -xz + mv -f "${output_dir}"/"${tarball%.tar.gz}"/* "${output_dir}/" + + rmdir "${output_dir}"/"${tarball%.tar.gz}" +} + + +# ct_os_test_s2i_app_func IMAGE APP CONTEXT_DIR CHECK_CMD [OC_ARGS] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the container by arbitrary +# function given as argument (such an argument may include string, +# that will be replaced with actual IP). +# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: app - url or local path to git repo with the application sources (compulsory) +# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory) +# Arguments: check_command - CMD line that checks whether the container works (compulsory; '' will be replaced with actual IP) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +function ct_os_test_s2i_app_func() { + local image_name=${1} + local app=${2} + local context_dir=${3} + local check_command=${4} + local oc_args=${5:-} + local import_image=${6:-} + local image_name_no_namespace=${image_name##*/} + local service_name="${image_name_no_namespace}-testing" + local image_tagged="${image_name_no_namespace}:${VERSION}" + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_s2i_app_func() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + ct_os_new_project + # Create a specific imagestream tag for the image so that oc cannot use anything else + if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then + if [ -n "${import_image}" ] ; then + echo "Importing image ${import_image} as ${image_name}:${VERSION}" + oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm + else + echo "Uploading and importing image skipped." + fi + else + if [ -n "${import_image}" ] ; then + echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead." + fi + ct_os_upload_image "${image_name}" "${image_tagged}" + fi + + local app_param="${app}" + if [ -d "${app}" ] ; then + # for local directory, we need to copy the content, otherwise too smart os command + # pulls the git remote repository instead + app_param=$(ct_obtain_input "${app}") + fi + + ct_os_deploy_s2i_image "${image_tagged}" "${app_param}" \ + --context-dir="${context_dir}" \ + --name "${service_name}" \ + ${oc_args} + + if [ -d "${app}" ] ; then + # in order to avoid weird race seen sometimes, let's wait shortly + # before starting the build explicitly + sleep 5 + oc start-build "${service_name}" --from-dir="${app_param}" + fi + + ct_os_wait_pod_ready "${service_name}" 300 + + local ip=$(ct_os_get_service_ip "${service_name}") + local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") + + echo " Checking APP using $check_command_exp ..." + local result=0 + eval "$check_command_exp" || result=1 + + if [ $result -eq 0 ] ; then + echo " Check passed." + else + echo " Check failed." + fi + + ct_os_delete_project + return $result +} + +# ct_os_test_s2i_app IMAGE APP CONTEXT_DIR EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the http response. +# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: app - url or local path to git repo with the application sources (compulsory) +# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory) +# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory) +# Arguments: port - which port to use (optional; default: 8080) +# Arguments: protocol - which protocol to use (optional; default: http) +# Arguments: response_code - what http response code to expect (optional; default: 200) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +function ct_os_test_s2i_app() { + local image_name=${1} + local app=${2} + local context_dir=${3} + local expected_output=${4} + local port=${5:-8080} + local protocol=${6:-http} + local response_code=${7:-200} + local oc_args=${8:-} + local import_image=${9:-} + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_s2i_app() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + ct_os_test_s2i_app_func "${image_name}" \ + "${app}" \ + "${context_dir}" \ + "ct_os_test_response_internal '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ + "${oc_args}" "${import_image}" +} + +# ct_os_test_template_app_func IMAGE APP IMAGE_IN_TEMPLATE CHECK_CMD [OC_ARGS] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the container by arbitrary +# function given as argument (such an argument may include string, +# that will be replaced with actual IP). +# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: template - url or local path to a template to use (compulsory) +# Arguments: name_in_template - image name used in the template +# Arguments: check_command - CMD line that checks whether the container works (compulsory; '' will be replaced with actual IP) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry, +# specify them in this parameter as "|", where "" is a full image name +# (including registry if needed) and "" is a tag under which the image should be available +# in the OpenShift registry. +function ct_os_test_template_app_func() { + local image_name=${1} + local template=${2} + local name_in_template=${3} + local check_command=${4} + local oc_args=${5:-} + local other_images=${6:-} + local import_image=${7:-} + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_template_app_func() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + local service_name="${name_in_template}-testing" + local image_tagged="${name_in_template}:${VERSION}" + + ct_os_new_project + + # Create a specific imagestream tag for the image so that oc cannot use anything else + if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then + if [ -n "${import_image}" ] ; then + echo "Importing image ${import_image} as ${image_name}:${VERSION}" + oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm + else + echo "Uploading and importing image skipped." + fi + else + if [ -n "${import_image}" ] ; then + echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead." + fi + ct_os_upload_image "${image_name}" "${image_tagged}" + + # upload also other images, that template might need (list of pairs in the format | + local images_tags_a + local i_t + for i_t in ${other_images} ; do + echo "${i_t}" + IFS='|' read -ra image_tag_a <<< "${i_t}" + docker pull "${image_tag_a[0]}" + ct_os_upload_image "${image_tag_a[0]}" "${image_tag_a[1]}" + done + fi + + local local_template=$(ct_obtain_input "${template}") + local namespace=${CT_NAMESPACE:-$(oc project -q)} + oc new-app ${local_template} \ + --name "${name_in_template}" \ + -p NAMESPACE="${namespace}" \ + ${oc_args} + + ct_os_wait_pod_ready "${service_name}" 300 + + local ip=$(ct_os_get_service_ip "${service_name}") + local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") + + echo " Checking APP using $check_command_exp ..." + local result=0 + eval "$check_command_exp" || result=1 + + if [ $result -eq 0 ] ; then + echo " Check passed." + else + echo " Check failed." + fi + + ct_os_delete_project + return $result +} + +# params: +# ct_os_test_template_app IMAGE APP IMAGE_IN_TEMPLATE EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the http response. +# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: template - url or local path to a template to use (compulsory) +# Arguments: name_in_template - image name used in the template +# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory) +# Arguments: port - which port to use (optional; default: 8080) +# Arguments: protocol - which protocol to use (optional; default: http) +# Arguments: response_code - what http response code to expect (optional; default: 200) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry, +# specify them in this parameter as "|", where "" is a full image name +# (including registry if needed) and "" is a tag under which the image should be available +# in the OpenShift registry. +function ct_os_test_template_app() { + local image_name=${1} + local template=${2} + local name_in_template=${3} + local expected_output=${4} + local port=${5:-8080} + local protocol=${6:-http} + local response_code=${7:-200} + local oc_args=${8:-} + local other_images=${9:-} + local import_image=${10:-} + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_template_app() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + ct_os_test_template_app_func "${image_name}" \ + "${template}" \ + "${name_in_template}" \ + "ct_os_test_response_internal '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ + "${oc_args}" \ + "${other_images}" \ + "${import_image}" +} + +# ct_os_test_image_update IMAGE_NAME OLD_IMAGE ISTAG CHECK_FUNCTION OC_ARGS +# -------------------- +# Runs an image update test with [image] uploaded to [is] imagestream +# and checks the services using an arbitrary function provided in [check_function]. +# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: old_image - valid name of the image from the registry +# Arguments: istag - imagestream to upload the images into (compulsory) +# Arguments: check_function - command to be run to check functionality of created services (compulsory) +# Arguments: oc_args - arguments to use during oc new-app (compulsory) +ct_os_test_image_update() { + local image_name=$1; shift + local old_image=$1; shift + local istag=$1; shift + local check_function=$1; shift + local service_name=${image_name##*/} + local ip="" check_command_exp="" + + echo "Running image update test for: $image_name" + ct_os_new_project + + # Get current image from repository and create an imagestream + docker pull "$old_image:latest" 2>/dev/null + ct_os_upload_image "$old_image" "$istag" + + # Setup example application with curent image + oc new-app "$@" --name "$service_name" + ct_os_wait_pod_ready "$service_name" 60 + + # Check application output + ip=$(ct_os_get_service_ip "$service_name") + check_command_exp=${check_function///$ip} + ct_assert_cmd_success "$check_command_exp" + + # Tag built image into the imagestream and wait for rebuild + ct_os_upload_image "$image_name" "$istag" + ct_os_wait_pod_ready "${service_name}-2" 60 + + # Check application output + ip=$(ct_os_get_service_ip "$service_name") + check_command_exp=${check_function///$ip} + ct_assert_cmd_success "$check_command_exp" + + ct_os_delete_project +} + +# ct_os_deploy_cmd_image IMAGE_NAME +# -------------------- +# Runs a special command pod, a pod that does nothing, but includes utilities for testing. +# A typical usage is a mysql pod that includes mysql commandline, that we need for testing. +# Running commands inside this command pod is done via ct_os_cmd_image_run function. +# The pod is not run again if already running. +# Arguments: image_name - image to be used as a command pod +function ct_os_deploy_cmd_image() { + local image_name=${1} + oc get pod command-app &>/dev/null && echo "command POD already running" && return 0 + echo "command POD not running yet, will start one called command-app" + oc create -f - <" + local sleep_time=3 + local attempt=1 + local result=1 + local status + local response_code + local response_file=$(mktemp /tmp/ct_test_response_XXXXXX) + local util_image_name='python:3.6' + + ct_os_deploy_cmd_image "${util_image_name}" + + while [ ${attempt} -le ${max_attempts} ]; do + ct_os_cmd_image_run "curl --connect-timeout 10 -s -w '%{http_code}' '${url}'" >${response_file} && status=0 || status=1 + if [ ${status} -eq 0 ]; then + response_code=$(cat ${response_file} | tail -c 3) + if [ "${response_code}" -eq "${expected_code}" ]; then + result=0 + fi + cat ${response_file} | grep -qP -e "${body_regexp}" || result=1; + # Some services return 40x code until they are ready, so let's give them + # some chance and not end with failure right away + # Do not wait if we already have expected outcome though + if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then + break + fi + fi + attempt=$(( ${attempt} + 1 )) + sleep ${sleep_time} + done + rm -f ${response_file} + return ${result} +} + +# ct_os_get_image_from_pod +# ------------------------ +# Print image identifier from an existing pod to stdout +# Argument: pod_prefix - prefix or full name of the pod to get image from +ct_os_get_image_from_pod() { + local pod_prefix=$1 ; shift + local pod_name=$(ct_os_get_pod_name $pod_prefix) + oc get "po/${pod_name}" -o yaml | sed -ne 's/^\s*image:\s*\(.*\)\s*$/\1/ p' | head -1 +} + +# ct_os_check_cmd_internal +# ---------------- +# Runs a specified command, checks exit code and compares the output with expected regexp. +# That all is done inside an image in the cluster, so the function is used +# typically in clusters that are not accessible outside. +# The check is repeated until timeout. +# Argument: util_image_name - name of the image in the cluster that is used for running the cmd +# Argument: service_name - kubernetes' service name to work with (IP address is taken from this one) +# Argument: check_command - command that is run within the util_image_name container +# Argument: expected_content_match - regexp that must be in the output (use .* to ignore check) +# Argument: timeout - number of seconds to wait till the check succeeds +function ct_os_check_cmd_internal() { + local util_image_name=$1 ; shift + local service_name=$1 ; shift + local check_command=$1 ; shift + local expected_content_match=${1:-.*} ; shift + local timeout=${1:-60} ; shift || : + + : " Service ${service_name} check ..." + + local output + local ret + local ip=$(ct_os_get_service_ip "${service_name}") + local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") + + ct_os_deploy_cmd_image $(ct_os_get_image_from_pod "${util_image_name}" | head -n 1) + SECONDS=0 + + echo -n "Waiting for ${service_name} service becoming ready ..." + while true ; do + output=$(ct_os_cmd_image_run "$check_command_exp") + ret=$? + echo "${output}" | grep -qe "${expected_content_match}" || ret=1 + if [ ${ret} -eq 0 ] ; then + echo " PASS" + return 0 + fi + echo -n "." + [ ${SECONDS} -gt ${timeout} ] && break + sleep 3 + done + echo " FAIL" + return 1 +} + diff --git a/test/test-lib.sh b/test/test-lib.sh new file mode 100644 index 0000000..e372870 --- /dev/null +++ b/test/test-lib.sh @@ -0,0 +1,507 @@ +# +# Test a container image. +# +# Always use sourced from a specific container testfile +# +# reguires definition of CID_FILE_DIR +# CID_FILE_DIR=$(mktemp --suffix=_test_cidfiles -d) +# reguires definition of TEST_LIST +# TEST_LIST="\ +# ctest_container_creation +# ctest_doc_content" + +# Container CI tests +# abbreviated as "ct" + +# may be redefined in the specific container testfile +EXPECTED_EXIT_CODE=0 + +# ct_cleanup +# -------------------- +# Cleans up containers used during tests. Stops and removes all containers +# referenced by cid_files in CID_FILE_DIR. Dumps logs if a container exited +# unexpectedly. Removes the cid_files and CID_FILE_DIR as well. +# Uses: $CID_FILE_DIR - path to directory containing cid_files +# Uses: $EXPECTED_EXIT_CODE - expected container exit code +function ct_cleanup() { + for cid_file in $CID_FILE_DIR/* ; do + local container=$(cat $cid_file) + + : "Stopping and removing container $container..." + docker stop $container + exit_status=$(docker inspect -f '{{.State.ExitCode}}' $container) + if [ "$exit_status" != "$EXPECTED_EXIT_CODE" ]; then + : "Dumping logs for $container" + docker logs $container + fi + docker rm -v $container + rm $cid_file + done + rmdir $CID_FILE_DIR + : "Done." +} + +# ct_enable_cleanup +# -------------------- +# Enables automatic container cleanup after tests. +function ct_enable_cleanup() { + trap ct_cleanup EXIT SIGINT +} + +# ct_get_cid [name] +# -------------------- +# Prints container id from cid_file based on the name of the file. +# Argument: name - name of cid_file where the container id will be stored +# Uses: $CID_FILE_DIR - path to directory containing cid_files +function ct_get_cid() { + local name="$1" ; shift || return 1 + echo $(cat "$CID_FILE_DIR/$name") +} + +# ct_get_cip [id] +# -------------------- +# Prints container ip address based on the container id. +# Argument: id - container id +function ct_get_cip() { + local id="$1" ; shift + docker inspect --format='{{.NetworkSettings.IPAddress}}' $(ct_get_cid "$id") +} + +# ct_wait_for_cid [cid_file] +# -------------------- +# Holds the execution until the cid_file is created. Usually run after container +# creation. +# Argument: cid_file - name of the cid_file that should be created +function ct_wait_for_cid() { + local cid_file=$1 + local max_attempts=10 + local sleep_time=1 + local attempt=1 + local result=1 + while [ $attempt -le $max_attempts ]; do + [ -f $cid_file ] && [ -s $cid_file ] && return 0 + : "Waiting for container start..." + attempt=$(( $attempt + 1 )) + sleep $sleep_time + done + return 1 +} + +# ct_assert_container_creation_fails [container_args] +# -------------------- +# The invocation of docker run should fail based on invalid container_args +# passed to the function. Returns 0 when container fails to start properly. +# Argument: container_args - all arguments are passed directly to dokcer run +# Uses: $CID_FILE_DIR - path to directory containing cid_files +function ct_assert_container_creation_fails() { + local ret=0 + local max_attempts=10 + local attempt=1 + local cid_file=assert + set +e + local old_container_args="${CONTAINER_ARGS-}" + CONTAINER_ARGS="$@" + ct_create_container $cid_file + if [ $? -eq 0 ]; then + local cid=$(ct_get_cid $cid_file) + + while [ "$(docker inspect -f '{{.State.Running}}' $cid)" == "true" ] ; do + sleep 2 + attempt=$(( $attempt + 1 )) + if [ $attempt -gt $max_attempts ]; then + docker stop $cid + ret=1 + break + fi + done + exit_status=$(docker inspect -f '{{.State.ExitCode}}' $cid) + if [ "$exit_status" == "0" ]; then + ret=1 + fi + docker rm -v $cid + rm $CID_FILE_DIR/$cid_file + fi + [ ! -z $old_container_args ] && CONTAINER_ARGS="$old_container_args" + set -e + return $ret +} + +# ct_create_container [name, command] +# -------------------- +# Creates a container using the IMAGE_NAME and CONTAINER_ARGS variables. Also +# stores the container id to a cid_file located in the CID_FILE_DIR, and waits +# for the creation of the file. +# Argument: name - name of cid_file where the container id will be stored +# Argument: command - optional command to be executed in the container +# Uses: $CID_FILE_DIR - path to directory containing cid_files +# Uses: $CONTAINER_ARGS - optional arguments passed directly to docker run +# Uses: $IMAGE_NAME - name of the image being tested +function ct_create_container() { + local cid_file="$CID_FILE_DIR/$1" ; shift + # create container with a cidfile in a directory for cleanup + docker run --cidfile="$cid_file" -d ${CONTAINER_ARGS:-} $IMAGE_NAME "$@" + ct_wait_for_cid $cid_file || return 1 + : "Created container $(cat $cid_file)" +} + +# ct_scl_usage_old [name, command, expected] +# -------------------- +# Tests three ways of running the SCL, by looking for an expected string +# in the output of the command +# Argument: name - name of cid_file where the container id will be stored +# Argument: command - executed inside the container +# Argument: expected - string that is expected to be in the command output +# Uses: $CID_FILE_DIR - path to directory containing cid_files +# Uses: $IMAGE_NAME - name of the image being tested +function ct_scl_usage_old() { + local name="$1" + local command="$2" + local expected="$3" + local out="" + : " Testing the image SCL enable" + out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${command}") + if ! echo "${out}" | grep -q "${expected}"; then + echo "ERROR[/bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2 + return 1 + fi + out=$(docker exec $(ct_get_cid $name) /bin/bash -c "${command}" 2>&1) + if ! echo "${out}" | grep -q "${expected}"; then + echo "ERROR[exec /bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2 + return 1 + fi + out=$(docker exec $(ct_get_cid $name) /bin/sh -ic "${command}" 2>&1) + if ! echo "${out}" | grep -q "${expected}"; then + echo "ERROR[exec /bin/sh -ic "${command}"] Expected '${expected}', got '${out}'" >&2 + return 1 + fi +} + +# ct_doc_content_old [strings] +# -------------------- +# Looks for occurence of stirngs in the documentation files and checks +# the format of the files. Files examined: help.1 +# Argument: strings - strings expected to appear in the documentation +# Uses: $IMAGE_NAME - name of the image being tested +function ct_doc_content_old() { + local tmpdir=$(mktemp -d) + local f + : " Testing documentation in the container image" + # Extract the help files from the container + for f in help.1 ; do + docker run --rm ${IMAGE_NAME} /bin/bash -c "cat /${f}" >${tmpdir}/$(basename ${f}) + # Check whether the files contain some important information + for term in $@ ; do + if ! cat ${tmpdir}/$(basename ${f}) | grep -F -q -e "${term}" ; then + echo "ERROR: File /${f} does not include '${term}'." >&2 + return 1 + fi + done + # Check whether the files use the correct format + for term in TH PP SH ; do + if ! grep -q "^\.${term}" ${tmpdir}/help.1 ; then + echo "ERROR: /help.1 is probably not in troff or groff format, since '${term}' is missing." >&2 + return 1 + fi + done + done + : " Success!" +} + + +# ct_npm_works +# -------------------- +# Checks existance of the npm tool and runs it. +function ct_npm_works() { + local tmpdir=$(mktemp -d) + : " Testing npm in the container image" + docker run --rm ${IMAGE_NAME} /bin/bash -c "npm --version" >${tmpdir}/version + + if [ $? -ne 0 ] ; then + echo "ERROR: 'npm --version' does not work inside the image ${IMAGE_NAME}." >&2 + return 1 + fi + + docker run --rm ${IMAGE_NAME} /bin/bash -c "npm install jquery && test -f node_modules/jquery/src/jquery.js" + if [ $? -ne 0 ] ; then + echo "ERROR: npm could not install jquery inside the image ${IMAGE_NAME}." >&2 + return 1 + fi + + : " Success!" +} + + +# ct_path_append PATH_VARNAME DIRECTORY +# ------------------------------------- +# Append DIRECTORY to VARIABLE of name PATH_VARNAME, the VARIABLE must consist +# of colon-separated list of directories. +ct_path_append () +{ + if eval "test -n \"\${$1-}\""; then + eval "$1=\$2:\$$1" + else + eval "$1=\$2" + fi +} + + +# ct_path_foreach PATH ACTION [ARGS ...] +# -------------------------------------- +# For each DIR in PATH execute ACTION (path is colon separated list of +# directories). The particular calls to ACTION will look like +# '$ ACTION directory [ARGS ...]' +ct_path_foreach () +{ + local dir dirlist action save_IFS + save_IFS=$IFS + IFS=: + dirlist=$1 + action=$2 + shift 2 + for dir in $dirlist; do "$action" "$dir" "$@" ; done + IFS=$save_IFS +} + + +# ct_run_test_list +# -------------------- +# Execute the tests specified by TEST_LIST +# Uses: $TEST_LIST - list of test names +function ct_run_test_list() { + for test_case in $TEST_LIST; do + : "Running test $test_case" + [ -f test/$test_case ] && source test/$test_case + [ -f ../test/$test_case ] && source ../test/$test_case + $test_case + done; +} + +# ct_gen_self_signed_cert_pem +# --------------------------- +# Generates a self-signed PEM certificate pair into specified directory. +# Argument: output_dir - output directory path +# Argument: base_name - base name of the certificate files +# Resulted files will be those: +# /-cert-selfsigned.pem -- public PEM cert +# /-key.pem -- PEM private key +ct_gen_self_signed_cert_pem() { + local output_dir=$1 ; shift + local base_name=$1 ; shift + mkdir -p ${output_dir} + openssl req -newkey rsa:2048 -nodes -keyout ${output_dir}/${base_name}-key.pem -subj '/C=GB/ST=Berkshire/L=Newbury/O=My Server Company' > ${base_name}-req.pem + openssl req -new -x509 -nodes -key ${output_dir}/${base_name}-key.pem -batch > ${output_dir}/${base_name}-cert-selfsigned.pem +} + +# ct_obtain_input FILE|DIR|URL +# -------------------- +# Either copies a file or a directory to a tmp location for local copies, or +# downloads the file from remote location. +# Resulted file path is printed, so it can be later used by calling function. +# Arguments: input - local file, directory or remote URL +function ct_obtain_input() { + local input=$1 + local extension="${input##*.}" + + # Try to use same extension for the temporary file if possible + [[ "${extension}" =~ ^[a-z0-9]*$ ]] && extension=".${extension}" || extension="" + + local output=$(mktemp "/var/tmp/test-input-XXXXXX$extension") + if [ -f "${input}" ] ; then + cp -f "${input}" "${output}" + elif [ -d "${input}" ] ; then + rm -f "${output}" + cp -r -LH "${input}" "${output}" + elif echo "${input}" | grep -qe '^http\(s\)\?://' ; then + curl "${input}" > "${output}" + else + echo "ERROR: file type not known: ${input}" >&2 + return 1 + fi + echo "${output}" +} + +# ct_test_response +# ---------------- +# Perform GET request to the application container, checks output with +# a reg-exp and HTTP response code. +# Argument: url - request URL path +# Argument: expected_code - expected HTTP response code +# Argument: body_regexp - PCRE regular expression that must match the response body +# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between +# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10) +ct_test_response() { + local url="$1" + local expected_code="$2" + local body_regexp="$3" + local max_attempts=${4:-20} + local ignore_error_attempts=${5:-10} + + : " Testing the HTTP(S) response for <${url}>" + local sleep_time=3 + local attempt=1 + local result=1 + local status + local response_code + local response_file=$(mktemp /tmp/ct_test_response_XXXXXX) + while [ ${attempt} -le ${max_attempts} ]; do + curl --connect-timeout 10 -s -w '%{http_code}' "${url}" >${response_file} && status=0 || status=1 + if [ ${status} -eq 0 ]; then + response_code=$(cat ${response_file} | tail -c 3) + if [ "${response_code}" -eq "${expected_code}" ]; then + result=0 + fi + cat ${response_file} | grep -qP -e "${body_regexp}" || result=1; + # Some services return 40x code until they are ready, so let's give them + # some chance and not end with failure right away + # Do not wait if we already have expected outcome though + if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then + break + fi + fi + attempt=$(( ${attempt} + 1 )) + sleep ${sleep_time} + done + rm -f ${response_file} + return ${result} +} + +# ct_registry_from_os OS +# ---------------- +# Transform operating system string [os] into registry url +# Argument: OS - string containing the os version +ct_registry_from_os() { + local registry="" + case $1 in + rhel7) + registry=registry.access.redhat.com + ;; + *) + registry=docker.io + ;; + esac + echo "$registry" +} + +# ct_assert_cmd_success CMD +# ---------------- +# Evaluates [cmd] and fails if it does not succeed. +# Argument: CMD - Command to be run +function ct_assert_cmd_success() { + echo "Checking '$*' for success ..." + if ! eval "$@" &>/dev/null; then + echo " FAIL" + return 1 + fi + echo " PASS" + return 0 +} + +# ct_assert_cmd_failure CMD +# ---------------- +# Evaluates [cmd] and fails if it succeeds. +# Argument: CMD - Command to be run +function ct_assert_cmd_failure() { + echo "Checking '$*' for failure ..." + if eval "$@" &>/dev/null; then + echo " FAIL" + return 1 + fi + echo " PASS" + return 0 +} + + +# ct_random_string [LENGTH=10] +# ---------------------------- +# Generate pseudorandom alphanumeric string of LENGTH bytes, the +# default length is 10. The string is printed on stdout. +ct_random_string() +( + export LC_ALL=C + dd if=/dev/urandom count=1 bs=10k 2>/dev/null \ + | tr -dc 'a-z0-9' \ + | fold -w "${1-10}" \ + | head -n 1 +) + +# ct_s2i_usage IMG_NAME [S2I_ARGS] +# ---------------------------- +# Create a container and run the usage script inside +# Argument: IMG_NAME - name of the image to be used for the container run +# Argument: S2I_ARGS - Additional list of source-to-image arguments, currently unused. +ct_s2i_usage() +{ + local img_name=$1; shift + local s2i_args="$*"; + local usage_command="/usr/libexec/s2i/usage" + docker run --rm "$img_name" bash -c "$usage_command" +} + +# ct_s2i_build_as_df APP_PATH SRC_IMAGE DST_IMAGE [S2I_ARGS] +# ---------------------------- +# Create a new s2i app image from local sources in a similar way as source-to-image would have used. +# Argument: APP_PATH - local path to the app sources to be used in the test +# Argument: SRC_IMAGE - image to be used as a base for the s2i build +# Argument: DST_IMAGE - image name to be used during the tagging of the s2i build result +# Argument: S2I_ARGS - Additional list of source-to-image arguments. +# Only used to check for pull-policy=never and environment variable definitions. +ct_s2i_build_as_df() +{ + local app_path=$1; shift + local src_image=$1; shift + local dst_image=$1; shift + local s2i_args="$*"; + local local_app=upload/src/ + local local_scripts=upload/scripts/ + local user_id= + local df_name= + local tmpdir= + # Use /tmp to not pollute cwd + tmpdir=$(mktemp -d) + df_name=$(mktemp -p "$tmpdir" Dockerfile.XXXX) + pushd "$tmpdir" + # Check if the image is available locally and try to pull it if it is not + docker images "$src_image" &>/dev/null || echo "$s2i_args" | grep -q "pull-policy=never" || docker pull "$src_image" + user_id=$(docker inspect -f "{{.ContainerConfig.User}}" "$src_image") + # Strip file:// from APP_PATH and copy its contents into current context + mkdir -p "$local_app" + cp -r "${app_path/file:\/\//}/." "$local_app" + [ -d "$local_app/.s2i/bin/" ] && mv "$local_app/.s2i/bin" "$local_scripts" + # Create a Dockerfile named df_name and fill it with proper content + #FIXME: Some commands could be combined into a single layer but not sure if worth the trouble for testing purposes + cat <"$df_name" +FROM $src_image +LABEL "io.openshift.s2i.build.image"="$src_image" \\ + "io.openshift.s2i.build.source-location"="$app_path" +USER root +COPY $local_app /tmp/src +EOF + [ -d "$local_scripts" ] && echo "COPY $local_scripts /tmp/scripts" >> "$df_name" && + echo "RUN chown -R $user_id:0 /tmp/scripts" >>"$df_name" + echo "RUN chown -R $user_id:0 /tmp/src" >>"$df_name" + # Check for custom environment variables inside .s2i/ folder + if [ -e "$local_app/.s2i/environment" ]; then + # Remove any comments and add the contents as ENV commands to the Dockerfile + sed '/^\s*#.*$/d' "$local_app/.s2i/environment" | while read -r line; do + echo "ENV $line" >>"$df_name" + done + fi + # Filter out env var definitions from $s2i_args and create Dockerfile ENV commands out of them + echo "$s2i_args" | grep -o -e '\(-e\|--env\)[[:space:]=]\S*=\S*' | sed -e 's/-e /ENV /' -e 's/--env[ =]/ENV /' >>"$df_name" + echo "USER $user_id" >>"$df_name" + # If exists, run the custom assemble script, else default to /usr/libexec/s2i/assemble + if [ -x "$local_scripts/assemble" ]; then + echo "RUN /tmp/scripts/assemble" >>"$df_name" + else + echo "RUN /usr/libexec/s2i/assemble" >>"$df_name" + fi + # If exists, set the custom run script as CMD, else default to /usr/libexec/s2i/run + if [ -x "$local_scripts/run" ]; then + echo "CMD /tmp/scripts/run" >>"$df_name" + else + echo "CMD /usr/libexec/s2i/run" >>"$df_name" + fi + # Run the build and tag the result + docker build -f "$df_name" -t "$dst_image" . + popd +} From 12fc654899b105da032797ec71947b86cc99d330 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marek=20Skalick=C3=BD?= Date: Mon, 29 Oct 2018 14:11:37 +0000 Subject: [PATCH 4/9] Add versioned symlink - needed by some images. --- 1.12 | 1 + 1 file changed, 1 insertion(+) create mode 120000 1.12 diff --git a/1.12 b/1.12 new file mode 120000 index 0000000..945c9b4 --- /dev/null +++ b/1.12 @@ -0,0 +1 @@ +. \ No newline at end of file From 6928218b3551c8393838fa33842dffa403076cb9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marek=20Skalick=C3=BD?= Date: Fri, 30 Nov 2018 17:46:20 +0000 Subject: [PATCH 5/9] Pull changes from upstream and rebase for: rebuild for latest f30 --- 1.12 | 1 + Dockerfile | 59 +- Dockerfile.fedora | 1 + README.md | 36 +- help.md | 1 + root/help.1 | 139 +++ root/opt/app-root/nginxconf.sed | 2 - .../share/container-scripts/nginx/common.sh | 31 + s2i/bin/assemble | 16 + s2i/bin/run | 4 + test/run | 102 +- test/run-openshift | 37 + test/start-hook-test-app/index.html | 8 + test/start-hook-test-app/index2.html | 8 + .../nginx-cfg/default.conf | 8 + test/start-hook-test-app/nginx-start/init.sh | 19 + test/test-app | 1 - test/test-app/index.html | 8 + test/test-app/index2.html | 8 + test/test-app/nginx-cfg/default.conf | 6 + test/test-app/nginx-default-cfg/alias.conf | 3 + test/test-app/nginx.conf | 117 +++ test/test-app/nginx.conf.fedora | 90 ++ test/test-lib-openshift.sh | 925 ++++++++++++++++++ test/test-lib.sh | 507 ++++++++++ 25 files changed, 2083 insertions(+), 54 deletions(-) create mode 120000 1.12 create mode 120000 Dockerfile.fedora create mode 120000 help.md create mode 100644 root/help.1 create mode 100644 root/usr/share/container-scripts/nginx/common.sh create mode 100755 test/run-openshift create mode 100644 test/start-hook-test-app/index.html create mode 100644 test/start-hook-test-app/index2.html create mode 100644 test/start-hook-test-app/nginx-cfg/default.conf create mode 100644 test/start-hook-test-app/nginx-start/init.sh delete mode 120000 test/test-app create mode 100644 test/test-app/index.html create mode 100644 test/test-app/index2.html create mode 100644 test/test-app/nginx-cfg/default.conf create mode 100644 test/test-app/nginx-default-cfg/alias.conf create mode 100644 test/test-app/nginx.conf create mode 100644 test/test-app/nginx.conf.fedora create mode 100644 test/test-lib-openshift.sh create mode 100644 test/test-lib.sh diff --git a/1.12 b/1.12 new file mode 120000 index 0000000..945c9b4 --- /dev/null +++ b/1.12 @@ -0,0 +1 @@ +. \ No newline at end of file diff --git a/Dockerfile b/Dockerfile index 6d1874c..214b9d6 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM registry.fedoraproject.org/f30/s2i-base:latest +FROM registry.fedoraproject.org/f30/s2i-core:latest # nginx 1.12 image. # @@ -10,6 +10,7 @@ EXPOSE 8443 ENV NAME=nginx \ NGINX_VERSION=1.12 \ + NGINX_SHORT_VER=112 \ VERSION=0 \ ARCH=x86_64 @@ -20,21 +21,25 @@ image provides a containerized packaging of the nginx $NGINX_VERSION daemon. The as a base image for other applications based on nginx $NGINX_VERSION web server. \ Nginx server image can be extended using source-to-image tool." -LABEL summary="$SUMMARY" \ - description="$DESCRIPTION" \ - io.k8s.description="$SUMMARY" \ - io.k8s.display-name="Nginx $NGINX_VERSION" \ +LABEL summary="${SUMMARY}" \ + description="${DESCRIPTION}" \ + io.k8s.description="${DESCRIPTION}" \ + io.k8s.display-name="Nginx ${NGINX_VERSION}" \ io.openshift.expose-services="8080:http" \ io.openshift.expose-services="8443:https" \ - io.openshift.tags="builder,nginx,nginx112" \ - com.redhat.component="$NAME" \ - name="$FGC/$NAME" \ - version="$VERSION" \ - architecture="$ARCH" \ - usage="s2i build file:///your/app $FGC/nginx your-app" + io.openshift.tags="builder,${NAME},${NAME}${NGINX_SHORT_VER}" \ + com.redhat.component="${NAME}" \ + name="${FGC}/${NAME}" \ + version="${VERSION}" \ + maintainer="SoftwareCollections.org " \ + help="For more information visit https://github.com/sclorg/${NAME}-container" \ + usage="s2i build ${FGC}/nginx " -ENV NGINX_CONFIGURATION_PATH=/opt/app-root/etc/nginx.d -ENV NGINX_DEFAULT_CONF_PATH=/opt/app-root/etc/nginx.default.d +ENV NGINX_CONFIGURATION_PATH=${APP_ROOT}/etc/nginx.d \ + NGINX_CONF_PATH=/etc/nginx/nginx.conf \ + NGINX_DEFAULT_CONF_PATH=${APP_ROOT}/etc/nginx.default.d \ + NGINX_CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/nginx \ + NGINX_APP_ROOT=${APP_ROOT} RUN dnf install -y gettext hostname && \ INSTALL_PKGS="nss_wrapper bind-utils nginx" && \ @@ -51,17 +56,29 @@ COPY ./root/ / # In order to drop the root user, we have to make some directories world # writeable as OpenShift default security model is to run the container under # random UID. -RUN sed -i -f /opt/app-root/nginxconf-fed.sed /etc/nginx/nginx.conf && \ - mkdir -p /opt/app-root/etc/nginx.d/ && \ - mkdir -p /opt/app-root/etc/nginx.default.d/ && \ - chmod -R a+rwx /opt/app-root/etc && \ +RUN sed -i -f ${NGINX_APP_ROOT}/nginxconf-fed.sed ${NGINX_CONF_PATH} && \ + chmod a+rwx ${NGINX_CONF_PATH} && \ + mkdir -p ${NGINX_APP_ROOT}/etc/nginx.d/ && \ + mkdir -p ${NGINX_APP_ROOT}/etc/nginx.default.d/ && \ + mkdir -p ${NGINX_APP_ROOT}/src/nginx-start/ && \ + mkdir -p ${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start && \ + mkdir -p /var/log/nginx && \ + ln -sf /dev/stdout /var/log/nginx/access.log && \ + ln -sf /dev/stderr /var/log/nginx/error.log && \ + chmod -R a+rwx ${NGINX_APP_ROOT}/etc && \ chmod -R a+rwx /var /run && \ - chown -R 1001:0 /opt/app-root && \ - chown -R 1001:0 /var + chmod -R a+rwx ${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start && \ + chown -R 1001:0 ${NGINX_APP_ROOT} && \ + chown -R 1001:0 /var && \ + chown -R 1001:0 ${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start && \ + rpm-file-permissions + USER 1001 -VOLUME ["/usr/share/nginx/html"] -VOLUME ["/var/log/nginx/"] +# Not using VOLUME statement since it's not working in OpenShift Online: +# https://github.com/sclorg/httpd-container/issues/30 +# VOLUME ["/usr/share/nginx/html"] +# VOLUME ["/var/log/nginx/"] CMD $STI_SCRIPTS_PATH/usage diff --git a/Dockerfile.fedora b/Dockerfile.fedora new file mode 120000 index 0000000..1d1fe94 --- /dev/null +++ b/Dockerfile.fedora @@ -0,0 +1 @@ +Dockerfile \ No newline at end of file diff --git a/README.md b/README.md index a3501b1..077002f 100644 --- a/README.md +++ b/README.md @@ -1,4 +1,4 @@ -Nginx 1.12 server and a reverse proxy server Docker image +Nginx 1.12 server and a reverse proxy server container image ========================================================= This container image includes Nginx 1.12 server and a reverse server for OpenShift and general usage. @@ -47,20 +47,36 @@ S2I build support Nginx server image can be extended using S2I tool (see Usage section). S2I build folder structure: -| Folder name | Description | -| :-------------------------- | ----------------------------------------- | -| ./nginx-cfg/*.conf | Should contain all nginx configuration we want to include into image | -| ./nginx-default-cfg/*.conf | Contains any nginx config snippets to include in the default server block | -| ./ | Should contain nginx application source code | +**`./nginx.conf`**-- + The main nginx configuration file + +**`./nginx-cfg/*.conf`** + Should contain all nginx configuration we want to include into image + +**`./nginx-default-cfg/*.conf`** + Contains any nginx config snippets to include in the default server block + +**`./nginx-start/*.sh`** + Contains shell scripts that are sourced right before nginx is launched + +**`./`** + Should contain nginx application source code + Environment variables and volumes ------------- The nginx container image supports the following configuration variable, which can be set by using the `-e` option with the docker run command: -| Variable name | Description | -| :--------------------- | ----------------------------------------- | -| `NGINX_LOG_TO_VOLUME` | When `NGINX_LOG_TO_VOLUME` is set, nginx logs into `/var/opt/rh/rh-nginx112/log/nginx/` | +**`NGINX_LOG_TO_VOLUME`** + When `NGINX_LOG_TO_VOLUME` is set, nginx logs into `/var/opt/rh/rh-nginx112/log/nginx/` + + +You can mount your own web root like this: +``` +$ docker run -v :/var/www/html/ +``` +You can replace \ with location of your web root. Please note that this has to be an **absolute** path, due to Docker requirements. Troubleshooting @@ -69,7 +85,7 @@ By default, nginx logs into standard output, so the log is available in the cont docker logs -**If `NGINX_LOG_TO_VOLUME` variable is set, nginx logs into `/var/opt/rh/rh-nginx112/log/nginx/`, which can be mounted to host system using the Docker volumes.** +**If `NGINX_LOG_TO_VOLUME` variable is set, nginx logs into `/var/opt/rh/rh-nginx112/log/nginx/`, which can be mounted to host system using the container volumes.** See also diff --git a/help.md b/help.md new file mode 120000 index 0000000..42061c0 --- /dev/null +++ b/help.md @@ -0,0 +1 @@ +README.md \ No newline at end of file diff --git a/root/help.1 b/root/help.1 new file mode 100644 index 0000000..d8ce31c --- /dev/null +++ b/root/help.1 @@ -0,0 +1,139 @@ +.TH Nginx 1.12 server and a reverse proxy server container image +.PP +This container image includes Nginx 1.12 server and a reverse server for OpenShift and general usage. +Users can choose RHEL based image. +The RHEL image is available in the Red Hat Container Catalog +\[la]https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/nginx-112-rhel7\[ra] +as registry.access.redhat.com/rhscl/nginx\-112\-rhel7. + +.SH Description +.PP +Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 and IMAP +protocols, with a strong focus on high concurrency, performance and low memory usage. The container +image provides a containerized packaging of the nginx 1.12 daemon. The image can be used +as a base image for other applications based on nginx 1.12 web server. +Nginx server image can be extended using source\-to\-image tool. + +.SH Usage +.PP +To build a simple sample\-app +\[la]https://github.com/sclorg/nginx-container/tree/master/1.12/test/test-app\[ra] application +using standalone S2I +\[la]https://github.com/openshift/source-to-image\[ra] and then run the +resulting image with Docker +\[la]http://docker.io\[ra] execute: +.IP \(bu 2 + +.PP +\fBFor RHEL based image\fP +.PP +.RS + +.nf +$ s2i build https://github.com/sclorg/nginx\-container.git \-\-context\-dir=1.12/test/test\-app/ rhscl/nginx\-112\-rhel7 nginx\-sample\-app +$ docker run \-p 8080:8080 nginx\-sample\-app + +.fi +.RE +.IP \(bu 2 + +.PP +\fBFor CentOS based image\fP +.PP +.RS + +.nf +$ s2i build https://github.com/sclorg/nginx\-container.git \-\-context\-dir=1.12/test/test\-app/ centos/nginx\-112\-centos7 nginx\-sample\-app +$ docker run \-p 8080:8080 nginx\-sample\-app + +.fi +.RE + +.PP +\fBAccessing the application:\fP + +.PP +.RS + +.nf +$ curl 127.0.0.1:8080 + +.fi +.RE + +.SH S2I build support +.PP +Nginx server image can be extended using S2I tool (see Usage section). +S2I build folder structure: + +.PP +\fB\fB\fC\&./nginx.conf\fR\fP\-\- + The main nginx configuration file + +.PP +\fB\fB\fC\&./nginx\-\&cfg/*.conf\fR\fP +.br + Should contain all nginx configuration we want to include into image + +.PP +\fB\fB\fC\&./nginx\-\&default\-\&cfg/*.conf\fR\fP +.br + Contains any nginx config snippets to include in the default server block + +.PP +\fB\fB\fC\&./nginx\-\&start/*.sh\fR\fP +.br + Contains shell scripts that are sourced right before nginx is launched + +.PP +\fB\fB\fC\&./\fR\fP +.br + Should contain nginx application source code + +.SH Environment variables and volumes +.PP +The nginx container image supports the following configuration variable, which can be set by using the \fB\fC\-e\fR option with the docker run command: + +.PP +\fB\fB\fCNGINX\_LOG\_TO\_VOLUME\fR\fP +.br + When \fB\fCNGINX\_LOG\_TO\_VOLUME\fR is set, nginx logs into \fB\fC/var/opt/rh/rh\-nginx112/log/nginx/\fR + +.PP +You can mount your own web root like this: + +.PP +.RS + +.nf +$ docker run \-v :/var/www/html/ + +.fi +.RE + +.PP +You can replace with location of your web root. Please note that this has to be an \fBabsolute\fP path, due to Docker requirements. + +.SH Troubleshooting +.PP +By default, nginx logs into standard output, so the log is available in the container log. The log can be examined by running: + +.PP +.RS + +.nf +docker logs + +.fi +.RE + +.PP +\fBIf \fB\fCNGINX\_LOG\_TO\_VOLUME\fR variable is set, nginx logs into \fB\fC/var/opt/rh/rh\-nginx112/log/nginx/\fR, which can be mounted to host system using the container volumes.\fP + +.SH See also +.PP +Dockerfile and other sources for this container image are available on + +\[la]https://github.com/sclorg/nginx-container\[ra]\&. +In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile +for RHEL is called Dockerfile.rhel7. diff --git a/root/opt/app-root/nginxconf.sed b/root/opt/app-root/nginxconf.sed index 36faf3a..007448d 100644 --- a/root/opt/app-root/nginxconf.sed +++ b/root/opt/app-root/nginxconf.sed @@ -3,5 +3,3 @@ s/^user *nginx;// s%/etc/opt/rh/rh-nginx112/nginx/conf.d/%/opt/app-root/etc/nginx.d/% s%/etc/opt/rh/rh-nginx112/nginx/default.d/%/opt/app-root/etc/nginx.default.d/% s%/opt/rh/rh-nginx112/root/usr/share/nginx/html%/opt/app-root/src% -s%/var/opt/rh/rh-nginx112/log/nginx/error.log%stderr% -s%access_log /var/opt/rh/rh-nginx112/log/nginx/access.log main;%% diff --git a/root/usr/share/container-scripts/nginx/common.sh b/root/usr/share/container-scripts/nginx/common.sh new file mode 100644 index 0000000..319219c --- /dev/null +++ b/root/usr/share/container-scripts/nginx/common.sh @@ -0,0 +1,31 @@ +#!/bin/sh + +# get_matched_files finds file for image extending +function get_matched_files() { + local custom_dir default_dir + custom_dir="$1" + default_dir="$2" + files_matched="$3" + find "$default_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n" + [ -d "$custom_dir" ] && find "$custom_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n" +} + +# process_extending_files process extending files in $1 and $2 directories +# - source all *.sh files +# (if there are files with same name source only file from $1) +function process_extending_files() { + local custom_dir default_dir + custom_dir=$1 + default_dir=$2 + while read filename ; do + if [ $filename ]; then + echo "=> sourcing $filename ..." + # Custom file is prefered + if [ -f $custom_dir/$filename ]; then + source $custom_dir/$filename + elif [ -f $default_dir/$filename ]; then + source $default_dir/$filename + fi + fi + done <<<"$(get_matched_files "$custom_dir" "$default_dir" '*.sh' | sort -u)" +} \ No newline at end of file diff --git a/s2i/bin/assemble b/s2i/bin/assemble index 65ba990..ef27877 100755 --- a/s2i/bin/assemble +++ b/s2i/bin/assemble @@ -5,12 +5,19 @@ set -e echo "---> Installing application source" cp -Rf /tmp/src/. ./ +if [ -f ./nginx.conf ]; then + echo "---> Copying nginx.conf configuration file..." + cp -v ./nginx.conf "${NGINX_CONF_PATH}" + rm -f ./nginx.conf +fi + if [ -d ./nginx-cfg ]; then echo "---> Copying nginx configuration files..." if [ "$(ls -A ./nginx-cfg/*.conf)" ]; then cp -v ./nginx-cfg/*.conf "${NGINX_CONFIGURATION_PATH}" rm -rf ./nginx-cfg fi + chmod -Rf g+rw ${NGINX_CONFIGURATION_PATH} fi if [ -d ./nginx-default-cfg ]; then @@ -19,6 +26,15 @@ if [ -d ./nginx-default-cfg ]; then cp -v ./nginx-default-cfg/*.conf "${NGINX_DEFAULT_CONF_PATH}" rm -rf ./nginx-default-cfg fi + chmod -Rf g+rw ${NGINX_DEFAULT_CONF_PATH} +fi + +if [ -d ./nginx-start ]; then + echo "---> Copying nginx start-hook scripts..." + if [ "$(ls -A ./nginx-start/* 2>/dev/null)" ]; then + cp -v ./nginx-start/* "${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start/" + rm -rf ./nginx-start + fi fi # Fix source directory permissions diff --git a/s2i/bin/run b/s2i/bin/run index 084463a..ca8d55b 100755 --- a/s2i/bin/run +++ b/s2i/bin/run @@ -4,4 +4,8 @@ source /opt/app-root/etc/generate_container_user set -e +source ${NGINX_CONTAINER_SCRIPTS_PATH}/common.sh + +process_extending_files ${NGINX_APP_ROOT}/src/nginx-start ${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start + exec nginx -g "daemon off;" diff --git a/test/run b/test/run index a2d2783..3c1545c 100755 --- a/test/run +++ b/test/run @@ -12,6 +12,8 @@ IMAGE_NAME=${IMAGE_NAME:-rhscl/nginx-112-rhel7} test_dir="$(readlink -zf $(dirname "${BASH_SOURCE[0]}"))" image_dir=$(readlink -zf ${test_dir}/..) +. $test_dir/test-lib.sh + # TODO: This should be part of the image metadata test_port=8080 @@ -32,7 +34,7 @@ container_ip() { } run_s2i_build() { - s2i build ${s2i_args} file://${test_dir}/test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp + ct_s2i_build_as_df file://${test_dir}/${1} ${IMAGE_NAME} ${IMAGE_NAME}-${1} ${s2i_args} } prepare() { @@ -43,7 +45,7 @@ prepare() { # TODO: S2I build require the application is a valid 'GIT' repository, we # should remove this restriction in the future when a file:// is used. info "Build the test application image" - pushd ${test_dir}/test-app >/dev/null + pushd ${test_dir}/${1} >/dev/null git init git config user.email "build@localhost" && git config user.name "builder" git add -A && git commit -m "Sample commit" @@ -52,7 +54,7 @@ prepare() { run_test_application() { run_args=${CONTAINER_ARGS:-} - docker run --user=100001 ${run_args} --cidfile=${cid_file} ${IMAGE_NAME}-testapp + docker run --user=100001 ${run_args} --cidfile=${cid_file} ${IMAGE_NAME}-${1} } cleanup_test_app() { @@ -68,17 +70,17 @@ cleanup_test_app() { cleanup() { info "Cleaning up the test application image" - if image_exists ${IMAGE_NAME}-testapp; then - docker rmi -f ${IMAGE_NAME}-testapp + if image_exists ${IMAGE_NAME}-${1}; then + docker rmi -f ${IMAGE_NAME}-${1} fi - rm -rf ${test_dir}/test-app/.git + rm -rf ${test_dir}/${1}/.git } check_result() { local result="$1" if [[ "$result" != "0" ]]; then info "TEST FAILED (${result})" - cleanup + cleanup $2 exit $result fi } @@ -98,7 +100,7 @@ wait_for_cid() { test_s2i_usage() { info "Testing 's2i usage'" - s2i usage ${s2i_args} ${IMAGE_NAME} &>/dev/null + ct_s2i_usage ${IMAGE_NAME} ${s2i_args} &>/dev/null } test_docker_run_usage() { @@ -116,6 +118,18 @@ test_scl_usage() { echo "ERROR[/bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'" return 1 fi + test_command "$run_cmd" "$expected" + return $? +} + +test_command() { + local run_cmd="$1" + local expected="$2" + local message="$3" + + if [ $message ]; then + info ${3} + fi out=$(docker exec $(cat ${cid_file}) /bin/bash -c "${run_cmd}" 2>&1) if ! echo "${out}" | grep -q "${expected}"; then echo "ERROR[exec /bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'" @@ -125,7 +139,9 @@ test_scl_usage() { if ! echo "${out}" | grep -q "${expected}"; then echo "ERROR[exec /bin/sh -ic "${run_cmd}"] Expected '${expected}', got '${out}'" return 1 - fi + fi + + return 0 } test_for_output() @@ -174,44 +190,90 @@ test_connection() { return 1 } +test_connection_s2i() { + cat $cid_file + info "Testing the HTTP connection (http://$(container_ip):${test_port})" + + if test_for_output "http://$(container_ip):${test_port}/" "NGINX is working" && + test_for_output "http://$(container_ip):${test_port}/" "NGINX2 is working" localhost2 && + test_for_output "http://$(container_ip):${test_port}/nginx-cfg/default.conf" "404"; then + return 0 + fi + + return 1 +} + test_application() { # Verify that the HTTP connection can be established to test application container - run_test_application & + run_test_application "test-app" & # Wait for the container to write it's CID file wait_for_cid test_scl_usage "nginx -v" "nginx version: nginx/1.12." - check_result $? + check_result $? "test-app" test_connection - check_result $? + check_result $? "test-app" cleanup_test_app } +test_pre_init_script() { + # Verify that the HTTP connection can be established to test application container + run_test_application "start-hook-test-app" & + + # Wait for the container to write it's CID file + wait_for_cid + + test_command "cat /opt/app-root/etc/nginx.d/default.conf | grep 'resolver' | sed -e 's/resolver\(.*\);/\1/' | grep 'DNS_SERVER'" "" + check_result $? "start-hook-test-app" + + test_connection_s2i + check_result $? "start-hook-test-app" + cleanup_test_app + +} + cid_file=$(mktemp -u --suffix=.cid) # Since we built the candidate image locally, we don't want S2I attempt to pull # it from Docker hub s2i_args="--pull-policy=never" -prepare -run_s2i_build -check_result $? +if [ "$TARGET" == "fedora" ]; then + mv ${test_dir}/test-app/nginx.conf{,.bkp} + cp ${test_dir}/test-app/nginx.conf{.fedora,} +fi +prepare "test-app" +run_s2i_build "test-app" +if [ "$TARGET" == "fedora" ]; then + mv ${test_dir}/test-app/nginx.conf{.bkp,} +fi +check_result $? "test-app" # Verify the 'usage' script is working properly when running the base image with 's2i usage ...' test_s2i_usage -check_result $? +check_result $? "test-app" # Verify the 'usage' script is working properly when running the base image with 'docker run ...' test_docker_run_usage -check_result $? +check_result $? "test-app" # Test application with default uid -test_application +test_application # Test application with random uid -CONTAINER_ARGS="-u 12345" test_application -cleanup +CONTAINER_ARGS="--user 12345" test_application +cleanup "test-app" + +# Test start-hook script functionality +cid_file=$(mktemp -u --suffix=.cid) + +prepare "start-hook-test-app" +run_s2i_build "start-hook-test-app" +check_result $? "start-hook-test-app" + +test_pre_init_script +cleanup "start-hook-test-app" info "All tests finished successfully." diff --git a/test/run-openshift b/test/run-openshift new file mode 100755 index 0000000..fd2a22f --- /dev/null +++ b/test/run-openshift @@ -0,0 +1,37 @@ +#!/bin/bash +# +# Test the Nginx image in OpenShift. +# +# IMAGE_NAME specifies a name of the candidate image used for testing. +# The image has to be available before this script is executed. +# + +THISDIR=$(dirname ${BASH_SOURCE[0]}) + +source ${THISDIR}/test-lib.sh +source ${THISDIR}/test-lib-openshift.sh + +# TODO: branch should be changed to master, once code in example app +# stabilizes on with referencing latest version +BRANCH_TO_TEST=master + +set -eo nounset + +test -n "${IMAGE_NAME-}" || false 'make sure $IMAGE_NAME is defined' +test -n "${VERSION-}" || false 'make sure $VERSION is defined' + +ct_os_cluster_up + +# test local app +ct_os_test_s2i_app ${IMAGE_NAME} "${THISDIR}/test-app" . 'Test NGINX passed' + +# test remote example app +ct_os_test_s2i_app ${IMAGE_NAME} "https://github.com/sclorg/nginx-ex.git#${BRANCH_TO_TEST}" . 'Welcome to your static nginx application on OpenShift' + +# test template from the example app +ct_os_test_template_app ${IMAGE_NAME} \ + https://raw.githubusercontent.com/sclorg/nginx-ex/${BRANCH_TO_TEST}/openshift/templates/nginx.json \ + nginx \ + 'Welcome to your static nginx application on OpenShift' \ + 8080 http 200 "-p SOURCE_REPOSITORY_REF=${BRANCH_TO_TEST} -p NGINX_VERSION=${VERSION} -p NAME=nginx-testing" + diff --git a/test/start-hook-test-app/index.html b/test/start-hook-test-app/index.html new file mode 100644 index 0000000..d147627 --- /dev/null +++ b/test/start-hook-test-app/index.html @@ -0,0 +1,8 @@ + + + Test NGINX passed + + +

NGINX is working

+ + diff --git a/test/start-hook-test-app/index2.html b/test/start-hook-test-app/index2.html new file mode 100644 index 0000000..e73a98c --- /dev/null +++ b/test/start-hook-test-app/index2.html @@ -0,0 +1,8 @@ + + + Test NGINX passed + + +

NGINX2 is working

+ + diff --git a/test/start-hook-test-app/nginx-cfg/default.conf b/test/start-hook-test-app/nginx-cfg/default.conf new file mode 100644 index 0000000..e947c98 --- /dev/null +++ b/test/start-hook-test-app/nginx-cfg/default.conf @@ -0,0 +1,8 @@ +server { + listen 8080; + server_name localhost2; + root /opt/app-root/src; + index ${INDEX_FILE}; + resolver ${DNS_SERVER}; + +} \ No newline at end of file diff --git a/test/start-hook-test-app/nginx-start/init.sh b/test/start-hook-test-app/nginx-start/init.sh new file mode 100644 index 0000000..450dfe4 --- /dev/null +++ b/test/start-hook-test-app/nginx-start/init.sh @@ -0,0 +1,19 @@ +setup_dns_env_var() { + if [ -z "$DNS_SERVER" ]; then + export DNS_SERVER=`cat /etc/resolv.conf | grep "nameserver " | awk '{print $2}' | tr '\n' ' '` + echo "Using system dns server ${DNS_SERVER}" + else + echo "Using user defined dns server: ${DNS_SERVER}" + fi +} + +inject_env_vars() { + ## Replace only specified environment variables in specified file. + envsubst '${DNS_SERVER},${INDEX_FILE}' < ${NGINX_CONFIGURATION_PATH}/$1 > output.conf + cp output.conf ${NGINX_CONFIGURATION_PATH}/$1 + echo "This is $1: " && cat ${NGINX_CONFIGURATION_PATH}/$1 +} + +export INDEX_FILE=index2.html +setup_dns_env_var +inject_env_vars "default.conf" diff --git a/test/test-app b/test/test-app deleted file mode 120000 index 5f73990..0000000 --- a/test/test-app +++ /dev/null @@ -1 +0,0 @@ -../../examples/1.12/test-app \ No newline at end of file diff --git a/test/test-app/index.html b/test/test-app/index.html new file mode 100644 index 0000000..d147627 --- /dev/null +++ b/test/test-app/index.html @@ -0,0 +1,8 @@ + + + Test NGINX passed + + +

NGINX is working

+ + diff --git a/test/test-app/index2.html b/test/test-app/index2.html new file mode 100644 index 0000000..e73a98c --- /dev/null +++ b/test/test-app/index2.html @@ -0,0 +1,8 @@ + + + Test NGINX passed + + +

NGINX2 is working

+ + diff --git a/test/test-app/nginx-cfg/default.conf b/test/test-app/nginx-cfg/default.conf new file mode 100644 index 0000000..d5a49f6 --- /dev/null +++ b/test/test-app/nginx-cfg/default.conf @@ -0,0 +1,6 @@ +server { + listen 8080; + server_name localhost2; + root /opt/app-root/src; + index index2.html; +} diff --git a/test/test-app/nginx-default-cfg/alias.conf b/test/test-app/nginx-default-cfg/alias.conf new file mode 100644 index 0000000..649ca52 --- /dev/null +++ b/test/test-app/nginx-default-cfg/alias.conf @@ -0,0 +1,3 @@ +location /aliased/ { + alias /opt/app-root/src/; +} diff --git a/test/test-app/nginx.conf b/test/test-app/nginx.conf new file mode 100644 index 0000000..76ce0eb --- /dev/null +++ b/test/test-app/nginx.conf @@ -0,0 +1,117 @@ +# For more information on configuration, see: +# * Official English Documentation: http://nginx.org/en/docs/ +# * Official Russian Documentation: http://nginx.org/ru/docs/ + + +worker_processes auto; +error_log stderr; +pid /var/opt/rh/rh-nginx112/run/nginx/nginx.pid; + +# Load dynamic modules. See /opt/rh/rh-nginx112/root/usr/share/doc/README.dynamic. +include /opt/rh/rh-nginx112/root/usr/share/nginx/modules/*.conf; + +events { + worker_connections 1024; +} + +http { + log_format main '$remote_addr - $remote_user [$time_local] "$request" ' + '$status $body_bytes_sent "$http_referer" ' + '"$http_user_agent" "$http_x_forwarded_for"'; + + sendfile on; + tcp_nopush on; + tcp_nodelay on; + keepalive_timeout 65; + types_hash_max_size 2048; + + include /etc/opt/rh/rh-nginx112/nginx/mime.types; + default_type application/octet-stream; + + # Load modular configuration files from the /etc/nginx/conf.d directory. + # See http://nginx.org/en/docs/ngx_core_module.html#include + # for more information. + include /opt/app-root/etc/nginx.d/*.conf; + + server { + listen 8080 default_server; + listen [::]:8080 default_server; + server_name _; + root /opt/app-root/src; + + # Load configuration files for the default server block. + include /opt/app-root/etc/nginx.default.d/*.conf; + + location / { + } + + error_page 404 /404.html; + location = /40x.html { + } + + error_page 500 502 503 504 /50x.html; + location = /50x.html { + } + + # proxy the PHP scripts to Apache listening on 127.0.0.1:8080 + # + #location ~ \.php$ { + # proxy_pass http://127.0.0.1; + #} + + # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000 + # + #location ~ \.php$ { + # root html; + # fastcgi_pass 127.0.0.1:9000; + # fastcgi_index index.php; + # fastcgi_param SCRIPT_FILENAME /scripts$fastcgi_script_name; + # include fastcgi_params; + #} + + # deny access to .htaccess files, if Apache's document root + # concurs with nginx's one + # + #location ~ /\.ht { + # deny all; + #} + } + + + # another virtual host using mix of IP-, name-, and port-based configuration + # + #server { + # listen 808000; + # listen somename:808080; + # server_name somename alias another.alias; + + # location / { + # root html; + # index index.html index.htm; + # } + #} + + + # HTTPS server + # + #server { + # listen 443; + # server_name localhost; + + # ssl on; + # ssl_certificate cert.pem; + # ssl_certificate_key cert.key; + + # ssl_session_timeout 5m; + + # ssl_protocols SSLv2 SSLv3 TLSv1; + # ssl_ciphers HIGH:!aNULL:!MD5; + # ssl_prefer_server_ciphers on; + + # location / { + # root html; + # index index.html index.htm; + # } + #} + +} diff --git a/test/test-app/nginx.conf.fedora b/test/test-app/nginx.conf.fedora new file mode 100644 index 0000000..e395483 --- /dev/null +++ b/test/test-app/nginx.conf.fedora @@ -0,0 +1,90 @@ +# For more information on configuration, see: +# * Official English Documentation: http://nginx.org/en/docs/ +# * Official Russian Documentation: http://nginx.org/ru/docs/ + + +worker_processes auto; +error_log stderr; +pid /run/nginx.pid; + +# Load dynamic modules. See /usr/share/doc/nginx/README.dynamic. +include /usr/share/nginx/modules/*.conf; + +events { + worker_connections 1024; +} + +http { + log_format main '$remote_addr - $remote_user [$time_local] "$request" ' + '$status $body_bytes_sent "$http_referer" ' + '"$http_user_agent" "$http_x_forwarded_for"'; + + + + sendfile on; + tcp_nopush on; + tcp_nodelay on; + keepalive_timeout 65; + types_hash_max_size 2048; + + include /etc/nginx/mime.types; + default_type application/octet-stream; + + # Load modular configuration files from the /etc/nginx/conf.d directory. + # See http://nginx.org/en/docs/ngx_core_module.html#include + # for more information. + include /opt/app-root/etc/nginx.d/*.conf; + + server { + listen 8080 default_server; + listen [::]:8080 default_server; + server_name _; + root /opt/app-root/src; + + # Load configuration files for the default server block. + include /opt/app-root/etc/nginx.default.d/*.conf; + + location / { + } + + error_page 404 /404.html; + location = /40x.html { + } + + error_page 500 502 503 504 /50x.html; + location = /50x.html { + } + } + +# Settings for a TLS enabled server. +# +# server { +# listen 443 ssl http2 default_server; +# listen [::]:443 ssl http2 default_server; +# server_name _; +# root /opt/app-root/src; +# +# ssl_certificate "/etc/pki/nginx/server.crt"; +# ssl_certificate_key "/etc/pki/nginx/private/server.key"; +# ssl_session_cache shared:SSL:1m; +# ssl_session_timeout 10m; +# ssl_ciphers PROFILE=SYSTEM; +# ssl_prefer_server_ciphers on; +# +# # Load configuration files for the default server block. +# include /opt/app-root/etc/nginx.default.d/*.conf; +# +# location / { +# } +# +# error_page 404 /404.html; +# location = /40x.html { +# } +# +# error_page 500 502 503 504 /50x.html; +# location = /50x.html { +# } +# } + +} + diff --git a/test/test-lib-openshift.sh b/test/test-lib-openshift.sh new file mode 100644 index 0000000..f988ac5 --- /dev/null +++ b/test/test-lib-openshift.sh @@ -0,0 +1,925 @@ +# Set of functions for testing docker images in OpenShift using 'oc' command + +# ct_os_get_status +# -------------------- +# Returns status of all objects to make debugging easier. +function ct_os_get_status() { + oc get all + oc status +} + +# ct_os_print_logs +# -------------------- +# Returns status of all objects and logs from all pods. +function ct_os_print_logs() { + ct_os_get_status + while read pod_name; do + echo "INFO: printing logs for pod ${pod_name}" + oc logs ${pod_name} + done < <(oc get pods --no-headers=true -o custom-columns=NAME:.metadata.name) +} + +# ct_os_enable_print_logs +# -------------------- +# Enables automatic printing of pod logs on ERR. +function ct_os_enable_print_logs() { + set -E + trap ct_os_print_logs ERR +} + +# ct_get_public_ip +# -------------------- +# Returns best guess for the IP that the node is accessible from other computers. +# This is a bit funny heuristic, simply goes through all IPv4 addresses that +# hostname -I returns and de-prioritizes IP addresses commonly used for local +# addressing. The rest of addresses are taken as public with higher probability. +function ct_get_public_ip() { + local hostnames=$(hostname -I) + local public_ip='' + local found_ip + for guess_exp in '127\.0\.0\.1' '192\.168\.[0-9\.]*' '172\.[0-9\.]*' \ + '10\.[0-9\.]*' '[0-9\.]*' ; do + found_ip=$(echo "${hostnames}" | grep -oe "${guess_exp}") + if [ -n "${found_ip}" ] ; then + hostnames=$(echo "${hostnames}" | sed -e "s/${found_ip}//") + public_ip="${found_ip}" + fi + done + if [ -z "${public_ip}" ] ; then + echo "ERROR: public IP could not be guessed." >&2 + return 1 + fi + echo "${public_ip}" +} + +# ct_os_run_in_pod POD_NAME CMD +# -------------------- +# Runs [cmd] in the pod specified by prefix [pod_prefix]. +# Arguments: pod_name - full name of the pod +# Arguments: cmd - command to be run in the pod +function ct_os_run_in_pod() { + local pod_name="$1" ; shift + + oc exec "$pod_name" -- "$@" +} + +# ct_os_get_service_ip SERVICE_NAME +# -------------------- +# Returns IP of the service specified by [service_name]. +# Arguments: service_name - name of the service +function ct_os_get_service_ip() { + local service_name="${1}" ; shift + oc get "svc/${service_name}" -o yaml | grep clusterIP | \ + cut -d':' -f2 | grep -oe '172\.30\.[0-9\.]*' +} + + +# ct_os_get_all_pods_status +# -------------------- +# Returns status of all pods. +function ct_os_get_all_pods_status() { + oc get pods -o custom-columns=Ready:status.containerStatuses[0].ready,NAME:.metadata.name +} + +# ct_os_get_all_pods_name +# -------------------- +# Returns the full name of all pods. +function ct_os_get_all_pods_name() { + oc get pods --no-headers -o custom-columns=NAME:.metadata.name +} + +# ct_os_get_pod_status POD_PREFIX +# -------------------- +# Returns status of the pod specified by prefix [pod_prefix]. +# Note: Ignores -build and -deploy pods +# Arguments: pod_prefix - prefix or whole ID of the pod +function ct_os_get_pod_status() { + local pod_prefix="${1}" ; shift + ct_os_get_all_pods_status | grep -e "${pod_prefix}" | grep -Ev "(build|deploy)$" \ + | awk '{print $1}' | head -n 1 +} + +# ct_os_get_pod_name POD_PREFIX +# -------------------- +# Returns the full name of pods specified by prefix [pod_prefix]. +# Note: Ignores -build and -deploy pods +# Arguments: pod_prefix - prefix or whole ID of the pod +function ct_os_get_pod_name() { + local pod_prefix="${1}" ; shift + ct_os_get_all_pods_name | grep -e "^${pod_prefix}" | grep -Ev "(build|deploy)$" +} + +# ct_os_get_pod_ip POD_NAME +# -------------------- +# Returns the ip of the pod specified by [pod_name]. +# Arguments: pod_name - full name of the pod +function ct_os_get_pod_ip() { + local pod_name="${1}" + oc get pod "$pod_name" --no-headers -o custom-columns=IP:status.podIP +} + +# ct_os_check_pod_readiness POD_PREFIX STATUS +# -------------------- +# Checks whether the pod is ready. +# Arguments: pod_prefix - prefix or whole ID of the pod +# Arguments: status - expected status (true, false) +function ct_os_check_pod_readiness() { + local pod_prefix="${1}" ; shift + local status="${1}" ; shift + test "$(ct_os_get_pod_status ${pod_prefix})" == "${status}" +} + +# ct_os_wait_pod_ready POD_PREFIX TIMEOUT +# -------------------- +# Wait maximum [timeout] for the pod becomming ready. +# Arguments: pod_prefix - prefix or whole ID of the pod +# Arguments: timeout - how many seconds to wait seconds +function ct_os_wait_pod_ready() { + local pod_prefix="${1}" ; shift + local timeout="${1}" ; shift + SECONDS=0 + echo -n "Waiting for ${pod_prefix} pod becoming ready ..." + while ! ct_os_check_pod_readiness "${pod_prefix}" "true" ; do + echo -n "." + [ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1 + sleep 3 + done + echo " DONE" +} + +# ct_os_wait_rc_ready POD_PREFIX TIMEOUT +# -------------------- +# Wait maximum [timeout] for the rc having desired number of replicas ready. +# Arguments: pod_prefix - prefix of the replication controller +# Arguments: timeout - how many seconds to wait seconds +function ct_os_wait_rc_ready() { + local pod_prefix="${1}" ; shift + local timeout="${1}" ; shift + SECONDS=0 + echo -n "Waiting for ${pod_prefix} pod becoming ready ..." + while ! test "$((oc get --no-headers statefulsets; oc get --no-headers rc) 2>/dev/null \ + | grep "^${pod_prefix}" | awk '$2==$3 {print "ready"}')" == "ready" ; do + echo -n "." + [ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1 + sleep 3 + done + echo " DONE" +} + +# ct_os_deploy_pure_image IMAGE [ENV_PARAMS, ...] +# -------------------- +# Runs [image] in the openshift and optionally specifies env_params +# as environment variables to the image. +# Arguments: image - prefix or whole ID of the pod to run the cmd in +# Arguments: env_params - environment variables parameters for the images. +function ct_os_deploy_pure_image() { + local image="${1}" ; shift + # ignore error exit code, because oc new-app returns error when image exists + oc new-app ${image} "$@" || : + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_deploy_s2i_image IMAGE APP [ENV_PARAMS, ... ] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. +# Arguments: image - prefix or whole ID of the pod to run the cmd in +# Arguments: app - url or local path to git repo with the application sources. +# Arguments: env_params - environment variables parameters for the images. +function ct_os_deploy_s2i_image() { + local image="${1}" ; shift + local app="${1}" ; shift + # ignore error exit code, because oc new-app returns error when image exists + oc new-app "${image}~${app}" "$@" || : + + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_deploy_template_image TEMPLATE [ENV_PARAMS, ...] +# -------------------- +# Runs template in the openshift and optionally gives env_params to use +# specific values in the template. +# Arguments: template - prefix or whole ID of the pod to run the cmd in +# Arguments: env_params - environment variables parameters for the template. +# Example usage: ct_os_deploy_template_image mariadb-ephemeral-template.yaml \ +# DATABASE_SERVICE_NAME=mysql-57-centos7 \ +# DATABASE_IMAGE=mysql-57-centos7 \ +# MYSQL_USER=testu \ +# MYSQL_PASSWORD=testp \ +# MYSQL_DATABASE=testdb +function ct_os_deploy_template_image() { + local template="${1}" ; shift + oc process -f "${template}" "$@" | oc create -f - + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# _ct_os_get_uniq_project_name +# -------------------- +# Returns a uniq name of the OpenShift project. +function _ct_os_get_uniq_project_name() { + local r + while true ; do + r=${RANDOM} + mkdir /var/tmp/sclorg-test-${r} &>/dev/null && echo sclorg-test-${r} && break + done +} + +# ct_os_new_project [PROJECT] +# -------------------- +# Creates a new project in the openshfit using 'os' command. +# Arguments: project - project name, uses a new random name if omitted +# Expects 'os' command that is properly logged in to the OpenShift cluster. +# Not using mktemp, because we cannot use uppercase characters. +function ct_os_new_project() { + if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then + echo "Creating project skipped." + return + fi + local project_name="${1:-$(_ct_os_get_uniq_project_name)}" ; shift || : + oc new-project ${project_name} + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_delete_project [PROJECT] +# -------------------- +# Deletes the specified project in the openshfit +# Arguments: project - project name, uses the current project if omitted +function ct_os_delete_project() { + if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then + echo "Deleting project skipped, cleaning objects only." + ct_delete_all_objects + return + fi + local project_name="${1:-$(oc project -q)}" ; shift || : + oc delete project "${project_name}" +} + +# ct_delete_all_objects +# ----------------- +# Deletes all objects within the project. +# Handy when we have one project and want to run more tests. +function ct_delete_all_objects() { + for x in bc builds dc is isimage istag po pv pvc rc routes secrets svc ; do + oc delete $x --all + done + # for some objects it takes longer to be really deleted, so a dummy sleep + # to avoid some races when other test can see not-yet-deleted objects and can fail + sleep 10 +} + +# ct_os_docker_login +# -------------------- +# Logs in into docker daemon +# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address. +# Does not do anything if REGISTRY_ADDRESS is set. +function ct_os_docker_login() { + [ -n "${REGISTRY_ADDRESS:-}" ] && "REGISTRY_ADDRESS set, not trying to docker login." && return 0 + # docker login fails with "404 page not found" error sometimes, just try it more times + for i in `seq 12` ; do + docker login -u developer -p $(oc whoami -t) ${REGISRTY_ADDRESS:-172.30.1.1:5000} && return 0 || : + sleep 5 + done + return 1 +} + +# ct_os_upload_image IMAGE [IMAGESTREAM] +# -------------------- +# Uploads image from local registry to the OpenShift internal registry. +# Arguments: image - image name to upload +# Arguments: imagestream - name and tag to use for the internal registry. +# In the format of name:tag ($image_name:latest by default) +# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address. +function ct_os_upload_image() { + local input_name="${1}" ; shift + local image_name=${input_name##*/} + local imagestream=${1:-$image_name:latest} + local output_name="${REGISRTY_ADDRESS:-172.30.1.1:5000}/$(oc project -q)/$imagestream" + + ct_os_docker_login + docker tag ${input_name} ${output_name} + docker push ${output_name} +} + +# ct_os_install_in_centos +# -------------------- +# Installs os cluster in CentOS +function ct_os_install_in_centos() { + yum install -y centos-release-openshift-origin + yum install -y wget git net-tools bind-utils iptables-services bridge-utils\ + bash-completion origin-clients docker origin-clients +} + +# ct_os_cluster_up [DIR, IS_PUBLIC, CLUSTER_VERSION] +# -------------------- +# Runs the local OpenShift cluster using 'oc cluster up' and logs in as developer. +# Arguments: dir - directory to keep configuration data in, random if omitted +# Arguments: is_public - sets either private or public hostname for web-UI, +# use "true" for allow remote access to the web-UI, +# "false" is default +# Arguments: cluster_version - version of the OpenShift cluster to use, empty +# means default version of `oc`; example value: 3.7; +# also can be specified outside by OC_CLUSTER_VERSION +function ct_os_cluster_up() { + ct_os_cluster_running && echo "Cluster already running. Nothing is done." && return 0 + ct_os_logged_in && echo "Already logged in to a cluster. Nothing is done." && return 0 + + mkdir -p /var/tmp/openshift + local dir="${1:-$(mktemp -d /var/tmp/openshift/os-data-XXXXXX)}" ; shift || : + local is_public="${1:-'false'}" ; shift || : + local default_cluster_version=${OC_CLUSTER_VERSION:-} + local cluster_version=${1:-${default_cluster_version}} ; shift || : + if ! grep -qe '--insecure-registry.*172\.30\.0\.0' /etc/sysconfig/docker ; then + sed -i "s|OPTIONS='|OPTIONS='--insecure-registry 172.30.0.0/16 |" /etc/sysconfig/docker + fi + + systemctl stop firewalld || : + setenforce 0 + iptables -F + + systemctl restart docker + local cluster_ip="127.0.0.1" + [ "${is_public}" == "true" ] && cluster_ip=$(ct_get_public_ip) + + if [ -n "${cluster_version}" ] ; then + # if $cluster_version is not set, we simply use oc that is available + ct_os_set_path_oc "${cluster_version}" + fi + + mkdir -p ${dir}/{config,data,pv} + case $(oc version| head -n 1) in + "oc v3.1"?.*) + oc cluster up --base-dir="${dir}/data" --public-hostname="${cluster_ip}" + ;; + "oc v3."*) + oc cluster up --host-data-dir="${dir}/data" --host-config-dir="${dir}/config" \ + --host-pv-dir="${dir}/pv" --use-existing-config --public-hostname="${cluster_ip}" + ;; + *) + echo "ERROR: Unexpected oc version." >&2 + return 1 + ;; + esac + oc version + oc login -u system:admin + oc project default + ct_os_wait_rc_ready docker-registry 180 + ct_os_wait_rc_ready router 30 + oc login -u developer -p developer + # let openshift cluster to sync to avoid some race condition errors + sleep 3 +} + +# ct_os_cluster_down +# -------------------- +# Shuts down the local OpenShift cluster using 'oc cluster down' +function ct_os_cluster_down() { + oc cluster down +} + +# ct_os_cluster_running +# -------------------- +# Returns 0 if oc cluster is running +function ct_os_cluster_running() { + oc cluster status &>/dev/null +} + +# ct_os_logged_in +# --------------- +# Returns 0 if logged in to a cluster (remote or local) +function ct_os_logged_in() { + oc whoami >/dev/null +} + +# ct_os_set_path_oc OC_VERSION +# -------------------- +# This is a trick that helps using correct version of the `oc`: +# The input is version of the openshift in format v3.6.0 etc. +# If the currently available version of oc is not of this version, +# it first takes a look into /usr/local/oc-/bin directory, +# and if not found there it downloads the community release from github. +# In the end the PATH variable is changed, so the other tests can still use just 'oc'. +# Arguments: oc_version - X.Y part of the version of OSE (e.g. 3.9) +function ct_os_set_path_oc() { + local oc_version=$(ct_os_get_latest_ver $1) + local oc_path + + if oc version | grep -q "oc ${oc_version%.*}." ; then + echo "Binary oc found already available in version ${oc_version}: `which oc` Doing noting." + return 0 + fi + + # first check whether we already have oc available in /usr/local + local installed_oc_path="/usr/local/oc-${oc_version%.*}/bin" + + if [ -x "${installed_oc_path}/oc" ] ; then + oc_path="${installed_oc_path}" + echo "Binary oc found in ${installed_oc_path}" >&2 + else + # oc not available in /usr/local, try to download it from github (community release) + oc_path="/tmp/oc-${oc_version}-bin" + ct_os_download_upstream_oc "${oc_version}" "${oc_path}" + fi + if [ -z "${oc_path}/oc" ] ; then + echo "ERROR: oc not found installed, nor downloaded" >&1 + return 1 + fi + export PATH="${oc_path}:${PATH}" + if ! oc version | grep -q "oc ${oc_version%.*}." ; then + echo "ERROR: something went wrong, oc located at ${oc_path}, but oc of version ${oc_version} not found in PATH ($PATH)" >&1 + return 1 + else + echo "PATH set correctly, binary oc found in version ${oc_version}: `which oc`" + fi +} + +# ct_os_get_latest_ver VERSION_PART_X +# -------------------- +# Returns full version (vX.Y.Z) from part of the version (X.Y) +# Arguments: vxy - X.Y part of the version +# Returns vX.Y.Z variant of the version +function ct_os_get_latest_ver(){ + local vxy="v$1" + for vz in {3..0} ; do + curl -sif "https://github.com/openshift/origin/releases/tag/${vxy}.${vz}" >/dev/null && echo "${vxy}.${vz}" && return 0 + done + echo "ERROR: version ${vxy} not found in https://github.com/openshift/origin/tags" >&2 + return 1 +} + +# ct_os_download_upstream_oc OC_VERSION OUTPUT_DIR +# -------------------- +# Downloads a particular version of openshift-origin-client-tools from +# github into specified output directory +# Arguments: oc_version - version of OSE (e.g. v3.7.2) +# Arguments: output_dir - output directory +function ct_os_download_upstream_oc() { + local oc_version=$1 + local output_dir=$2 + + # check whether we already have the binary in place + [ -x "${output_dir}/oc" ] && return 0 + + mkdir -p "${output_dir}" + # using html output instead of https://api.github.com/repos/openshift/origin/releases/tags/${oc_version}, + # because API is limited for number of queries if not authenticated + tarball=$(curl -si "https://github.com/openshift/origin/releases/tag/${oc_version}" | grep -o -e "openshift-origin-client-tools-${oc_version}-[a-f0-9]*-linux-64bit.tar.gz" | head -n 1) + + # download, unpack the binaries and then put them into output directory + echo "Downloading https://github.com/openshift/origin/releases/download/${oc_version}/${tarball} into ${output_dir}/" >&2 + curl -sL https://github.com/openshift/origin/releases/download/${oc_version}/"${tarball}" | tar -C "${output_dir}" -xz + mv -f "${output_dir}"/"${tarball%.tar.gz}"/* "${output_dir}/" + + rmdir "${output_dir}"/"${tarball%.tar.gz}" +} + + +# ct_os_test_s2i_app_func IMAGE APP CONTEXT_DIR CHECK_CMD [OC_ARGS] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the container by arbitrary +# function given as argument (such an argument may include string, +# that will be replaced with actual IP). +# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: app - url or local path to git repo with the application sources (compulsory) +# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory) +# Arguments: check_command - CMD line that checks whether the container works (compulsory; '' will be replaced with actual IP) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +function ct_os_test_s2i_app_func() { + local image_name=${1} + local app=${2} + local context_dir=${3} + local check_command=${4} + local oc_args=${5:-} + local import_image=${6:-} + local image_name_no_namespace=${image_name##*/} + local service_name="${image_name_no_namespace}-testing" + local image_tagged="${image_name_no_namespace}:${VERSION}" + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_s2i_app_func() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + ct_os_new_project + # Create a specific imagestream tag for the image so that oc cannot use anything else + if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then + if [ -n "${import_image}" ] ; then + echo "Importing image ${import_image} as ${image_name}:${VERSION}" + oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm + else + echo "Uploading and importing image skipped." + fi + else + if [ -n "${import_image}" ] ; then + echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead." + fi + ct_os_upload_image "${image_name}" "${image_tagged}" + fi + + local app_param="${app}" + if [ -d "${app}" ] ; then + # for local directory, we need to copy the content, otherwise too smart os command + # pulls the git remote repository instead + app_param=$(ct_obtain_input "${app}") + fi + + ct_os_deploy_s2i_image "${image_tagged}" "${app_param}" \ + --context-dir="${context_dir}" \ + --name "${service_name}" \ + ${oc_args} + + if [ -d "${app}" ] ; then + # in order to avoid weird race seen sometimes, let's wait shortly + # before starting the build explicitly + sleep 5 + oc start-build "${service_name}" --from-dir="${app_param}" + fi + + ct_os_wait_pod_ready "${service_name}" 300 + + local ip=$(ct_os_get_service_ip "${service_name}") + local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") + + echo " Checking APP using $check_command_exp ..." + local result=0 + eval "$check_command_exp" || result=1 + + if [ $result -eq 0 ] ; then + echo " Check passed." + else + echo " Check failed." + fi + + ct_os_delete_project + return $result +} + +# ct_os_test_s2i_app IMAGE APP CONTEXT_DIR EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the http response. +# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: app - url or local path to git repo with the application sources (compulsory) +# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory) +# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory) +# Arguments: port - which port to use (optional; default: 8080) +# Arguments: protocol - which protocol to use (optional; default: http) +# Arguments: response_code - what http response code to expect (optional; default: 200) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +function ct_os_test_s2i_app() { + local image_name=${1} + local app=${2} + local context_dir=${3} + local expected_output=${4} + local port=${5:-8080} + local protocol=${6:-http} + local response_code=${7:-200} + local oc_args=${8:-} + local import_image=${9:-} + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_s2i_app() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + ct_os_test_s2i_app_func "${image_name}" \ + "${app}" \ + "${context_dir}" \ + "ct_os_test_response_internal '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ + "${oc_args}" "${import_image}" +} + +# ct_os_test_template_app_func IMAGE APP IMAGE_IN_TEMPLATE CHECK_CMD [OC_ARGS] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the container by arbitrary +# function given as argument (such an argument may include string, +# that will be replaced with actual IP). +# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: template - url or local path to a template to use (compulsory) +# Arguments: name_in_template - image name used in the template +# Arguments: check_command - CMD line that checks whether the container works (compulsory; '' will be replaced with actual IP) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry, +# specify them in this parameter as "|", where "" is a full image name +# (including registry if needed) and "" is a tag under which the image should be available +# in the OpenShift registry. +function ct_os_test_template_app_func() { + local image_name=${1} + local template=${2} + local name_in_template=${3} + local check_command=${4} + local oc_args=${5:-} + local other_images=${6:-} + local import_image=${7:-} + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_template_app_func() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + local service_name="${name_in_template}-testing" + local image_tagged="${name_in_template}:${VERSION}" + + ct_os_new_project + + # Create a specific imagestream tag for the image so that oc cannot use anything else + if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then + if [ -n "${import_image}" ] ; then + echo "Importing image ${import_image} as ${image_name}:${VERSION}" + oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm + else + echo "Uploading and importing image skipped." + fi + else + if [ -n "${import_image}" ] ; then + echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead." + fi + ct_os_upload_image "${image_name}" "${image_tagged}" + + # upload also other images, that template might need (list of pairs in the format | + local images_tags_a + local i_t + for i_t in ${other_images} ; do + echo "${i_t}" + IFS='|' read -ra image_tag_a <<< "${i_t}" + docker pull "${image_tag_a[0]}" + ct_os_upload_image "${image_tag_a[0]}" "${image_tag_a[1]}" + done + fi + + local local_template=$(ct_obtain_input "${template}") + local namespace=${CT_NAMESPACE:-$(oc project -q)} + oc new-app ${local_template} \ + --name "${name_in_template}" \ + -p NAMESPACE="${namespace}" \ + ${oc_args} + + ct_os_wait_pod_ready "${service_name}" 300 + + local ip=$(ct_os_get_service_ip "${service_name}") + local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") + + echo " Checking APP using $check_command_exp ..." + local result=0 + eval "$check_command_exp" || result=1 + + if [ $result -eq 0 ] ; then + echo " Check passed." + else + echo " Check failed." + fi + + ct_os_delete_project + return $result +} + +# params: +# ct_os_test_template_app IMAGE APP IMAGE_IN_TEMPLATE EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ] +# -------------------- +# Runs [image] and [app] in the openshift and optionally specifies env_params +# as environment variables to the image. Then check the http response. +# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: template - url or local path to a template to use (compulsory) +# Arguments: name_in_template - image name used in the template +# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory) +# Arguments: port - which port to use (optional; default: 8080) +# Arguments: protocol - which protocol to use (optional; default: http) +# Arguments: response_code - what http response code to expect (optional; default: 200) +# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` +# command, typically environment variables (optional) +# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry, +# specify them in this parameter as "|", where "" is a full image name +# (including registry if needed) and "" is a tag under which the image should be available +# in the OpenShift registry. +function ct_os_test_template_app() { + local image_name=${1} + local template=${2} + local name_in_template=${3} + local expected_output=${4} + local port=${5:-8080} + local protocol=${6:-http} + local response_code=${7:-200} + local oc_args=${8:-} + local other_images=${9:-} + local import_image=${10:-} + + if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then + echo "ERROR: ct_os_test_template_app() requires at least 4 arguments that cannot be emtpy." >&2 + return 1 + fi + + ct_os_test_template_app_func "${image_name}" \ + "${template}" \ + "${name_in_template}" \ + "ct_os_test_response_internal '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ + "${oc_args}" \ + "${other_images}" \ + "${import_image}" +} + +# ct_os_test_image_update IMAGE_NAME OLD_IMAGE ISTAG CHECK_FUNCTION OC_ARGS +# -------------------- +# Runs an image update test with [image] uploaded to [is] imagestream +# and checks the services using an arbitrary function provided in [check_function]. +# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) +# Arguments: old_image - valid name of the image from the registry +# Arguments: istag - imagestream to upload the images into (compulsory) +# Arguments: check_function - command to be run to check functionality of created services (compulsory) +# Arguments: oc_args - arguments to use during oc new-app (compulsory) +ct_os_test_image_update() { + local image_name=$1; shift + local old_image=$1; shift + local istag=$1; shift + local check_function=$1; shift + local service_name=${image_name##*/} + local ip="" check_command_exp="" + + echo "Running image update test for: $image_name" + ct_os_new_project + + # Get current image from repository and create an imagestream + docker pull "$old_image:latest" 2>/dev/null + ct_os_upload_image "$old_image" "$istag" + + # Setup example application with curent image + oc new-app "$@" --name "$service_name" + ct_os_wait_pod_ready "$service_name" 60 + + # Check application output + ip=$(ct_os_get_service_ip "$service_name") + check_command_exp=${check_function///$ip} + ct_assert_cmd_success "$check_command_exp" + + # Tag built image into the imagestream and wait for rebuild + ct_os_upload_image "$image_name" "$istag" + ct_os_wait_pod_ready "${service_name}-2" 60 + + # Check application output + ip=$(ct_os_get_service_ip "$service_name") + check_command_exp=${check_function///$ip} + ct_assert_cmd_success "$check_command_exp" + + ct_os_delete_project +} + +# ct_os_deploy_cmd_image IMAGE_NAME +# -------------------- +# Runs a special command pod, a pod that does nothing, but includes utilities for testing. +# A typical usage is a mysql pod that includes mysql commandline, that we need for testing. +# Running commands inside this command pod is done via ct_os_cmd_image_run function. +# The pod is not run again if already running. +# Arguments: image_name - image to be used as a command pod +function ct_os_deploy_cmd_image() { + local image_name=${1} + oc get pod command-app &>/dev/null && echo "command POD already running" && return 0 + echo "command POD not running yet, will start one called command-app" + oc create -f - <" + local sleep_time=3 + local attempt=1 + local result=1 + local status + local response_code + local response_file=$(mktemp /tmp/ct_test_response_XXXXXX) + local util_image_name='python:3.6' + + ct_os_deploy_cmd_image "${util_image_name}" + + while [ ${attempt} -le ${max_attempts} ]; do + ct_os_cmd_image_run "curl --connect-timeout 10 -s -w '%{http_code}' '${url}'" >${response_file} && status=0 || status=1 + if [ ${status} -eq 0 ]; then + response_code=$(cat ${response_file} | tail -c 3) + if [ "${response_code}" -eq "${expected_code}" ]; then + result=0 + fi + cat ${response_file} | grep -qP -e "${body_regexp}" || result=1; + # Some services return 40x code until they are ready, so let's give them + # some chance and not end with failure right away + # Do not wait if we already have expected outcome though + if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then + break + fi + fi + attempt=$(( ${attempt} + 1 )) + sleep ${sleep_time} + done + rm -f ${response_file} + return ${result} +} + +# ct_os_get_image_from_pod +# ------------------------ +# Print image identifier from an existing pod to stdout +# Argument: pod_prefix - prefix or full name of the pod to get image from +ct_os_get_image_from_pod() { + local pod_prefix=$1 ; shift + local pod_name=$(ct_os_get_pod_name $pod_prefix) + oc get "po/${pod_name}" -o yaml | sed -ne 's/^\s*image:\s*\(.*\)\s*$/\1/ p' | head -1 +} + +# ct_os_check_cmd_internal +# ---------------- +# Runs a specified command, checks exit code and compares the output with expected regexp. +# That all is done inside an image in the cluster, so the function is used +# typically in clusters that are not accessible outside. +# The check is repeated until timeout. +# Argument: util_image_name - name of the image in the cluster that is used for running the cmd +# Argument: service_name - kubernetes' service name to work with (IP address is taken from this one) +# Argument: check_command - command that is run within the util_image_name container +# Argument: expected_content_match - regexp that must be in the output (use .* to ignore check) +# Argument: timeout - number of seconds to wait till the check succeeds +function ct_os_check_cmd_internal() { + local util_image_name=$1 ; shift + local service_name=$1 ; shift + local check_command=$1 ; shift + local expected_content_match=${1:-.*} ; shift + local timeout=${1:-60} ; shift || : + + : " Service ${service_name} check ..." + + local output + local ret + local ip=$(ct_os_get_service_ip "${service_name}") + local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") + + ct_os_deploy_cmd_image $(ct_os_get_image_from_pod "${util_image_name}" | head -n 1) + SECONDS=0 + + echo -n "Waiting for ${service_name} service becoming ready ..." + while true ; do + output=$(ct_os_cmd_image_run "$check_command_exp") + ret=$? + echo "${output}" | grep -qe "${expected_content_match}" || ret=1 + if [ ${ret} -eq 0 ] ; then + echo " PASS" + return 0 + fi + echo -n "." + [ ${SECONDS} -gt ${timeout} ] && break + sleep 3 + done + echo " FAIL" + return 1 +} + diff --git a/test/test-lib.sh b/test/test-lib.sh new file mode 100644 index 0000000..e372870 --- /dev/null +++ b/test/test-lib.sh @@ -0,0 +1,507 @@ +# +# Test a container image. +# +# Always use sourced from a specific container testfile +# +# reguires definition of CID_FILE_DIR +# CID_FILE_DIR=$(mktemp --suffix=_test_cidfiles -d) +# reguires definition of TEST_LIST +# TEST_LIST="\ +# ctest_container_creation +# ctest_doc_content" + +# Container CI tests +# abbreviated as "ct" + +# may be redefined in the specific container testfile +EXPECTED_EXIT_CODE=0 + +# ct_cleanup +# -------------------- +# Cleans up containers used during tests. Stops and removes all containers +# referenced by cid_files in CID_FILE_DIR. Dumps logs if a container exited +# unexpectedly. Removes the cid_files and CID_FILE_DIR as well. +# Uses: $CID_FILE_DIR - path to directory containing cid_files +# Uses: $EXPECTED_EXIT_CODE - expected container exit code +function ct_cleanup() { + for cid_file in $CID_FILE_DIR/* ; do + local container=$(cat $cid_file) + + : "Stopping and removing container $container..." + docker stop $container + exit_status=$(docker inspect -f '{{.State.ExitCode}}' $container) + if [ "$exit_status" != "$EXPECTED_EXIT_CODE" ]; then + : "Dumping logs for $container" + docker logs $container + fi + docker rm -v $container + rm $cid_file + done + rmdir $CID_FILE_DIR + : "Done." +} + +# ct_enable_cleanup +# -------------------- +# Enables automatic container cleanup after tests. +function ct_enable_cleanup() { + trap ct_cleanup EXIT SIGINT +} + +# ct_get_cid [name] +# -------------------- +# Prints container id from cid_file based on the name of the file. +# Argument: name - name of cid_file where the container id will be stored +# Uses: $CID_FILE_DIR - path to directory containing cid_files +function ct_get_cid() { + local name="$1" ; shift || return 1 + echo $(cat "$CID_FILE_DIR/$name") +} + +# ct_get_cip [id] +# -------------------- +# Prints container ip address based on the container id. +# Argument: id - container id +function ct_get_cip() { + local id="$1" ; shift + docker inspect --format='{{.NetworkSettings.IPAddress}}' $(ct_get_cid "$id") +} + +# ct_wait_for_cid [cid_file] +# -------------------- +# Holds the execution until the cid_file is created. Usually run after container +# creation. +# Argument: cid_file - name of the cid_file that should be created +function ct_wait_for_cid() { + local cid_file=$1 + local max_attempts=10 + local sleep_time=1 + local attempt=1 + local result=1 + while [ $attempt -le $max_attempts ]; do + [ -f $cid_file ] && [ -s $cid_file ] && return 0 + : "Waiting for container start..." + attempt=$(( $attempt + 1 )) + sleep $sleep_time + done + return 1 +} + +# ct_assert_container_creation_fails [container_args] +# -------------------- +# The invocation of docker run should fail based on invalid container_args +# passed to the function. Returns 0 when container fails to start properly. +# Argument: container_args - all arguments are passed directly to dokcer run +# Uses: $CID_FILE_DIR - path to directory containing cid_files +function ct_assert_container_creation_fails() { + local ret=0 + local max_attempts=10 + local attempt=1 + local cid_file=assert + set +e + local old_container_args="${CONTAINER_ARGS-}" + CONTAINER_ARGS="$@" + ct_create_container $cid_file + if [ $? -eq 0 ]; then + local cid=$(ct_get_cid $cid_file) + + while [ "$(docker inspect -f '{{.State.Running}}' $cid)" == "true" ] ; do + sleep 2 + attempt=$(( $attempt + 1 )) + if [ $attempt -gt $max_attempts ]; then + docker stop $cid + ret=1 + break + fi + done + exit_status=$(docker inspect -f '{{.State.ExitCode}}' $cid) + if [ "$exit_status" == "0" ]; then + ret=1 + fi + docker rm -v $cid + rm $CID_FILE_DIR/$cid_file + fi + [ ! -z $old_container_args ] && CONTAINER_ARGS="$old_container_args" + set -e + return $ret +} + +# ct_create_container [name, command] +# -------------------- +# Creates a container using the IMAGE_NAME and CONTAINER_ARGS variables. Also +# stores the container id to a cid_file located in the CID_FILE_DIR, and waits +# for the creation of the file. +# Argument: name - name of cid_file where the container id will be stored +# Argument: command - optional command to be executed in the container +# Uses: $CID_FILE_DIR - path to directory containing cid_files +# Uses: $CONTAINER_ARGS - optional arguments passed directly to docker run +# Uses: $IMAGE_NAME - name of the image being tested +function ct_create_container() { + local cid_file="$CID_FILE_DIR/$1" ; shift + # create container with a cidfile in a directory for cleanup + docker run --cidfile="$cid_file" -d ${CONTAINER_ARGS:-} $IMAGE_NAME "$@" + ct_wait_for_cid $cid_file || return 1 + : "Created container $(cat $cid_file)" +} + +# ct_scl_usage_old [name, command, expected] +# -------------------- +# Tests three ways of running the SCL, by looking for an expected string +# in the output of the command +# Argument: name - name of cid_file where the container id will be stored +# Argument: command - executed inside the container +# Argument: expected - string that is expected to be in the command output +# Uses: $CID_FILE_DIR - path to directory containing cid_files +# Uses: $IMAGE_NAME - name of the image being tested +function ct_scl_usage_old() { + local name="$1" + local command="$2" + local expected="$3" + local out="" + : " Testing the image SCL enable" + out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${command}") + if ! echo "${out}" | grep -q "${expected}"; then + echo "ERROR[/bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2 + return 1 + fi + out=$(docker exec $(ct_get_cid $name) /bin/bash -c "${command}" 2>&1) + if ! echo "${out}" | grep -q "${expected}"; then + echo "ERROR[exec /bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2 + return 1 + fi + out=$(docker exec $(ct_get_cid $name) /bin/sh -ic "${command}" 2>&1) + if ! echo "${out}" | grep -q "${expected}"; then + echo "ERROR[exec /bin/sh -ic "${command}"] Expected '${expected}', got '${out}'" >&2 + return 1 + fi +} + +# ct_doc_content_old [strings] +# -------------------- +# Looks for occurence of stirngs in the documentation files and checks +# the format of the files. Files examined: help.1 +# Argument: strings - strings expected to appear in the documentation +# Uses: $IMAGE_NAME - name of the image being tested +function ct_doc_content_old() { + local tmpdir=$(mktemp -d) + local f + : " Testing documentation in the container image" + # Extract the help files from the container + for f in help.1 ; do + docker run --rm ${IMAGE_NAME} /bin/bash -c "cat /${f}" >${tmpdir}/$(basename ${f}) + # Check whether the files contain some important information + for term in $@ ; do + if ! cat ${tmpdir}/$(basename ${f}) | grep -F -q -e "${term}" ; then + echo "ERROR: File /${f} does not include '${term}'." >&2 + return 1 + fi + done + # Check whether the files use the correct format + for term in TH PP SH ; do + if ! grep -q "^\.${term}" ${tmpdir}/help.1 ; then + echo "ERROR: /help.1 is probably not in troff or groff format, since '${term}' is missing." >&2 + return 1 + fi + done + done + : " Success!" +} + + +# ct_npm_works +# -------------------- +# Checks existance of the npm tool and runs it. +function ct_npm_works() { + local tmpdir=$(mktemp -d) + : " Testing npm in the container image" + docker run --rm ${IMAGE_NAME} /bin/bash -c "npm --version" >${tmpdir}/version + + if [ $? -ne 0 ] ; then + echo "ERROR: 'npm --version' does not work inside the image ${IMAGE_NAME}." >&2 + return 1 + fi + + docker run --rm ${IMAGE_NAME} /bin/bash -c "npm install jquery && test -f node_modules/jquery/src/jquery.js" + if [ $? -ne 0 ] ; then + echo "ERROR: npm could not install jquery inside the image ${IMAGE_NAME}." >&2 + return 1 + fi + + : " Success!" +} + + +# ct_path_append PATH_VARNAME DIRECTORY +# ------------------------------------- +# Append DIRECTORY to VARIABLE of name PATH_VARNAME, the VARIABLE must consist +# of colon-separated list of directories. +ct_path_append () +{ + if eval "test -n \"\${$1-}\""; then + eval "$1=\$2:\$$1" + else + eval "$1=\$2" + fi +} + + +# ct_path_foreach PATH ACTION [ARGS ...] +# -------------------------------------- +# For each DIR in PATH execute ACTION (path is colon separated list of +# directories). The particular calls to ACTION will look like +# '$ ACTION directory [ARGS ...]' +ct_path_foreach () +{ + local dir dirlist action save_IFS + save_IFS=$IFS + IFS=: + dirlist=$1 + action=$2 + shift 2 + for dir in $dirlist; do "$action" "$dir" "$@" ; done + IFS=$save_IFS +} + + +# ct_run_test_list +# -------------------- +# Execute the tests specified by TEST_LIST +# Uses: $TEST_LIST - list of test names +function ct_run_test_list() { + for test_case in $TEST_LIST; do + : "Running test $test_case" + [ -f test/$test_case ] && source test/$test_case + [ -f ../test/$test_case ] && source ../test/$test_case + $test_case + done; +} + +# ct_gen_self_signed_cert_pem +# --------------------------- +# Generates a self-signed PEM certificate pair into specified directory. +# Argument: output_dir - output directory path +# Argument: base_name - base name of the certificate files +# Resulted files will be those: +# /-cert-selfsigned.pem -- public PEM cert +# /-key.pem -- PEM private key +ct_gen_self_signed_cert_pem() { + local output_dir=$1 ; shift + local base_name=$1 ; shift + mkdir -p ${output_dir} + openssl req -newkey rsa:2048 -nodes -keyout ${output_dir}/${base_name}-key.pem -subj '/C=GB/ST=Berkshire/L=Newbury/O=My Server Company' > ${base_name}-req.pem + openssl req -new -x509 -nodes -key ${output_dir}/${base_name}-key.pem -batch > ${output_dir}/${base_name}-cert-selfsigned.pem +} + +# ct_obtain_input FILE|DIR|URL +# -------------------- +# Either copies a file or a directory to a tmp location for local copies, or +# downloads the file from remote location. +# Resulted file path is printed, so it can be later used by calling function. +# Arguments: input - local file, directory or remote URL +function ct_obtain_input() { + local input=$1 + local extension="${input##*.}" + + # Try to use same extension for the temporary file if possible + [[ "${extension}" =~ ^[a-z0-9]*$ ]] && extension=".${extension}" || extension="" + + local output=$(mktemp "/var/tmp/test-input-XXXXXX$extension") + if [ -f "${input}" ] ; then + cp -f "${input}" "${output}" + elif [ -d "${input}" ] ; then + rm -f "${output}" + cp -r -LH "${input}" "${output}" + elif echo "${input}" | grep -qe '^http\(s\)\?://' ; then + curl "${input}" > "${output}" + else + echo "ERROR: file type not known: ${input}" >&2 + return 1 + fi + echo "${output}" +} + +# ct_test_response +# ---------------- +# Perform GET request to the application container, checks output with +# a reg-exp and HTTP response code. +# Argument: url - request URL path +# Argument: expected_code - expected HTTP response code +# Argument: body_regexp - PCRE regular expression that must match the response body +# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between +# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10) +ct_test_response() { + local url="$1" + local expected_code="$2" + local body_regexp="$3" + local max_attempts=${4:-20} + local ignore_error_attempts=${5:-10} + + : " Testing the HTTP(S) response for <${url}>" + local sleep_time=3 + local attempt=1 + local result=1 + local status + local response_code + local response_file=$(mktemp /tmp/ct_test_response_XXXXXX) + while [ ${attempt} -le ${max_attempts} ]; do + curl --connect-timeout 10 -s -w '%{http_code}' "${url}" >${response_file} && status=0 || status=1 + if [ ${status} -eq 0 ]; then + response_code=$(cat ${response_file} | tail -c 3) + if [ "${response_code}" -eq "${expected_code}" ]; then + result=0 + fi + cat ${response_file} | grep -qP -e "${body_regexp}" || result=1; + # Some services return 40x code until they are ready, so let's give them + # some chance and not end with failure right away + # Do not wait if we already have expected outcome though + if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then + break + fi + fi + attempt=$(( ${attempt} + 1 )) + sleep ${sleep_time} + done + rm -f ${response_file} + return ${result} +} + +# ct_registry_from_os OS +# ---------------- +# Transform operating system string [os] into registry url +# Argument: OS - string containing the os version +ct_registry_from_os() { + local registry="" + case $1 in + rhel7) + registry=registry.access.redhat.com + ;; + *) + registry=docker.io + ;; + esac + echo "$registry" +} + +# ct_assert_cmd_success CMD +# ---------------- +# Evaluates [cmd] and fails if it does not succeed. +# Argument: CMD - Command to be run +function ct_assert_cmd_success() { + echo "Checking '$*' for success ..." + if ! eval "$@" &>/dev/null; then + echo " FAIL" + return 1 + fi + echo " PASS" + return 0 +} + +# ct_assert_cmd_failure CMD +# ---------------- +# Evaluates [cmd] and fails if it succeeds. +# Argument: CMD - Command to be run +function ct_assert_cmd_failure() { + echo "Checking '$*' for failure ..." + if eval "$@" &>/dev/null; then + echo " FAIL" + return 1 + fi + echo " PASS" + return 0 +} + + +# ct_random_string [LENGTH=10] +# ---------------------------- +# Generate pseudorandom alphanumeric string of LENGTH bytes, the +# default length is 10. The string is printed on stdout. +ct_random_string() +( + export LC_ALL=C + dd if=/dev/urandom count=1 bs=10k 2>/dev/null \ + | tr -dc 'a-z0-9' \ + | fold -w "${1-10}" \ + | head -n 1 +) + +# ct_s2i_usage IMG_NAME [S2I_ARGS] +# ---------------------------- +# Create a container and run the usage script inside +# Argument: IMG_NAME - name of the image to be used for the container run +# Argument: S2I_ARGS - Additional list of source-to-image arguments, currently unused. +ct_s2i_usage() +{ + local img_name=$1; shift + local s2i_args="$*"; + local usage_command="/usr/libexec/s2i/usage" + docker run --rm "$img_name" bash -c "$usage_command" +} + +# ct_s2i_build_as_df APP_PATH SRC_IMAGE DST_IMAGE [S2I_ARGS] +# ---------------------------- +# Create a new s2i app image from local sources in a similar way as source-to-image would have used. +# Argument: APP_PATH - local path to the app sources to be used in the test +# Argument: SRC_IMAGE - image to be used as a base for the s2i build +# Argument: DST_IMAGE - image name to be used during the tagging of the s2i build result +# Argument: S2I_ARGS - Additional list of source-to-image arguments. +# Only used to check for pull-policy=never and environment variable definitions. +ct_s2i_build_as_df() +{ + local app_path=$1; shift + local src_image=$1; shift + local dst_image=$1; shift + local s2i_args="$*"; + local local_app=upload/src/ + local local_scripts=upload/scripts/ + local user_id= + local df_name= + local tmpdir= + # Use /tmp to not pollute cwd + tmpdir=$(mktemp -d) + df_name=$(mktemp -p "$tmpdir" Dockerfile.XXXX) + pushd "$tmpdir" + # Check if the image is available locally and try to pull it if it is not + docker images "$src_image" &>/dev/null || echo "$s2i_args" | grep -q "pull-policy=never" || docker pull "$src_image" + user_id=$(docker inspect -f "{{.ContainerConfig.User}}" "$src_image") + # Strip file:// from APP_PATH and copy its contents into current context + mkdir -p "$local_app" + cp -r "${app_path/file:\/\//}/." "$local_app" + [ -d "$local_app/.s2i/bin/" ] && mv "$local_app/.s2i/bin" "$local_scripts" + # Create a Dockerfile named df_name and fill it with proper content + #FIXME: Some commands could be combined into a single layer but not sure if worth the trouble for testing purposes + cat <"$df_name" +FROM $src_image +LABEL "io.openshift.s2i.build.image"="$src_image" \\ + "io.openshift.s2i.build.source-location"="$app_path" +USER root +COPY $local_app /tmp/src +EOF + [ -d "$local_scripts" ] && echo "COPY $local_scripts /tmp/scripts" >> "$df_name" && + echo "RUN chown -R $user_id:0 /tmp/scripts" >>"$df_name" + echo "RUN chown -R $user_id:0 /tmp/src" >>"$df_name" + # Check for custom environment variables inside .s2i/ folder + if [ -e "$local_app/.s2i/environment" ]; then + # Remove any comments and add the contents as ENV commands to the Dockerfile + sed '/^\s*#.*$/d' "$local_app/.s2i/environment" | while read -r line; do + echo "ENV $line" >>"$df_name" + done + fi + # Filter out env var definitions from $s2i_args and create Dockerfile ENV commands out of them + echo "$s2i_args" | grep -o -e '\(-e\|--env\)[[:space:]=]\S*=\S*' | sed -e 's/-e /ENV /' -e 's/--env[ =]/ENV /' >>"$df_name" + echo "USER $user_id" >>"$df_name" + # If exists, run the custom assemble script, else default to /usr/libexec/s2i/assemble + if [ -x "$local_scripts/assemble" ]; then + echo "RUN /tmp/scripts/assemble" >>"$df_name" + else + echo "RUN /usr/libexec/s2i/assemble" >>"$df_name" + fi + # If exists, set the custom run script as CMD, else default to /usr/libexec/s2i/run + if [ -x "$local_scripts/run" ]; then + echo "CMD /tmp/scripts/run" >>"$df_name" + else + echo "CMD /usr/libexec/s2i/run" >>"$df_name" + fi + # Run the build and tag the result + docker build -f "$df_name" -t "$dst_image" . + popd +} From 72b927fcdb261a66909241e76e2997bd7f0fd61e Mon Sep 17 00:00:00 2001 From: "Petr \"Stone\" Hracek" Date: Wed, 3 Jun 2020 10:39:34 +0200 Subject: [PATCH 6/9] This commit adds support for syncing upstream repository to Fedora land Signed-off-by: Petr "Stone" Hracek --- bot-cfg.yml | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 bot-cfg.yml diff --git a/bot-cfg.yml b/bot-cfg.yml new file mode 100644 index 0000000..a289462 --- /dev/null +++ b/bot-cfg.yml @@ -0,0 +1,23 @@ +version: "1" +betka: + # is betka enabled for this repository + # optional - defaults to false + enabled: true + # optional + notifications: + email_addresses: [phracek@redhat.com] + # Specify if master branch in upstream repository is synced + master_checker: true + # Should pull requests be synced? + # optional + pr_checker: false + # Either 'upstream_branch_name' or 'upstream_git_path' has to be specified + # Branch name which is used for sync + upstream_branch_name: master + # Path to directory with dockerfile withing upstream repository + upstream_git_path: "1.18" + # Github comment message to enforce sync of a pull request + # required if pr_checker is true otherwise optional + pr_comment_message: "[test]" + # optional + image_url: quay.io/rhscl/cwt-generator From 739625db969a079f0a67235c26cea1b8df539e3c Mon Sep 17 00:00:00 2001 From: "Petr \"Stone\" Hracek" Date: Tue, 9 Jun 2020 15:15:44 +0200 Subject: [PATCH 7/9] This commit adds support for syncing upstream repository to Fedora land Signed-off-by: Petr "Stone" Hracek --- bot-cfg.yml | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 bot-cfg.yml diff --git a/bot-cfg.yml b/bot-cfg.yml new file mode 100644 index 0000000..a289462 --- /dev/null +++ b/bot-cfg.yml @@ -0,0 +1,23 @@ +version: "1" +betka: + # is betka enabled for this repository + # optional - defaults to false + enabled: true + # optional + notifications: + email_addresses: [phracek@redhat.com] + # Specify if master branch in upstream repository is synced + master_checker: true + # Should pull requests be synced? + # optional + pr_checker: false + # Either 'upstream_branch_name' or 'upstream_git_path' has to be specified + # Branch name which is used for sync + upstream_branch_name: master + # Path to directory with dockerfile withing upstream repository + upstream_git_path: "1.18" + # Github comment message to enforce sync of a pull request + # required if pr_checker is true otherwise optional + pr_comment_message: "[test]" + # optional + image_url: quay.io/rhscl/cwt-generator From 66e413c1a6df47228c86e8ee9dae84c7cf93e355 Mon Sep 17 00:00:00 2001 From: Petr Hracek Date: Tue, 9 Mar 2021 11:01:43 +0000 Subject: [PATCH 8/9] Update bot-cfg.yml with email addresses --- bot-cfg.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/bot-cfg.yml b/bot-cfg.yml index a289462..0618e2d 100644 --- a/bot-cfg.yml +++ b/bot-cfg.yml @@ -5,7 +5,7 @@ betka: enabled: true # optional notifications: - email_addresses: [phracek@redhat.com] + email_addresses: ["phracek@redhat.com", "pkubat@redhat.com", "hhorak@redhat.com"] # Specify if master branch in upstream repository is synced master_checker: true # Should pull requests be synced? From 09fc059ddfa0ef9f11911a7783b69f3343b66f03 Mon Sep 17 00:00:00 2001 From: Honza Horak Date: Tue, 8 Jul 2025 17:39:27 +0200 Subject: [PATCH 9/9] container sources not used for building fedora containers anymore --- 1.12 | 1 - Dockerfile | 84 -- Dockerfile.fedora | 1 - README.md | 96 -- bot-cfg.yml | 23 - dead.package | 1 + help.md | 1 - root/help.1 | 139 --- root/opt/app-root/etc/generate_container_user | 9 - root/opt/app-root/etc/passwd.template | 15 - root/opt/app-root/etc/scl_enable | 3 - root/opt/app-root/nginxconf-fed.sed | 7 - root/opt/app-root/nginxconf.sed | 5 - .../share/container-scripts/nginx/common.sh | 31 - s2i/bin/assemble | 41 - s2i/bin/run | 11 - s2i/bin/usage | 17 - test/run | 279 ------ test/run-openshift | 37 - test/start-hook-test-app/index.html | 8 - test/start-hook-test-app/index2.html | 8 - .../nginx-cfg/default.conf | 8 - test/start-hook-test-app/nginx-start/init.sh | 19 - test/test-app/index.html | 8 - test/test-app/index2.html | 8 - test/test-app/nginx-cfg/default.conf | 6 - test/test-app/nginx-default-cfg/alias.conf | 3 - test/test-app/nginx.conf | 117 --- test/test-app/nginx.conf.fedora | 90 -- test/test-lib-openshift.sh | 925 ------------------ test/test-lib.sh | 507 ---------- 31 files changed, 1 insertion(+), 2507 deletions(-) delete mode 120000 1.12 delete mode 100644 Dockerfile delete mode 120000 Dockerfile.fedora delete mode 100644 README.md delete mode 100644 bot-cfg.yml create mode 100644 dead.package delete mode 120000 help.md delete mode 100644 root/help.1 delete mode 100644 root/opt/app-root/etc/generate_container_user delete mode 100644 root/opt/app-root/etc/passwd.template delete mode 100644 root/opt/app-root/etc/scl_enable delete mode 100644 root/opt/app-root/nginxconf-fed.sed delete mode 100644 root/opt/app-root/nginxconf.sed delete mode 100644 root/usr/share/container-scripts/nginx/common.sh delete mode 100755 s2i/bin/assemble delete mode 100755 s2i/bin/run delete mode 100755 s2i/bin/usage delete mode 100755 test/run delete mode 100755 test/run-openshift delete mode 100644 test/start-hook-test-app/index.html delete mode 100644 test/start-hook-test-app/index2.html delete mode 100644 test/start-hook-test-app/nginx-cfg/default.conf delete mode 100644 test/start-hook-test-app/nginx-start/init.sh delete mode 100644 test/test-app/index.html delete mode 100644 test/test-app/index2.html delete mode 100644 test/test-app/nginx-cfg/default.conf delete mode 100644 test/test-app/nginx-default-cfg/alias.conf delete mode 100644 test/test-app/nginx.conf delete mode 100644 test/test-app/nginx.conf.fedora delete mode 100644 test/test-lib-openshift.sh delete mode 100644 test/test-lib.sh diff --git a/1.12 b/1.12 deleted file mode 120000 index 945c9b4..0000000 --- a/1.12 +++ /dev/null @@ -1 +0,0 @@ -. \ No newline at end of file diff --git a/Dockerfile b/Dockerfile deleted file mode 100644 index 214b9d6..0000000 --- a/Dockerfile +++ /dev/null @@ -1,84 +0,0 @@ -FROM registry.fedoraproject.org/f30/s2i-core:latest - -# nginx 1.12 image. -# -# Volumes: -# * /var/log/nginx/ - Storage for logs - -EXPOSE 8080 -EXPOSE 8443 - -ENV NAME=nginx \ - NGINX_VERSION=1.12 \ - NGINX_SHORT_VER=112 \ - VERSION=0 \ - ARCH=x86_64 - -ENV SUMMARY="Platform for running nginx $NGINX_VERSION or building nginx-based application" \ - DESCRIPTION="Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 and IMAP \ -protocols, with a strong focus on high concurrency, performance and low memory usage. The container \ -image provides a containerized packaging of the nginx $NGINX_VERSION daemon. The image can be used \ -as a base image for other applications based on nginx $NGINX_VERSION web server. \ -Nginx server image can be extended using source-to-image tool." - -LABEL summary="${SUMMARY}" \ - description="${DESCRIPTION}" \ - io.k8s.description="${DESCRIPTION}" \ - io.k8s.display-name="Nginx ${NGINX_VERSION}" \ - io.openshift.expose-services="8080:http" \ - io.openshift.expose-services="8443:https" \ - io.openshift.tags="builder,${NAME},${NAME}${NGINX_SHORT_VER}" \ - com.redhat.component="${NAME}" \ - name="${FGC}/${NAME}" \ - version="${VERSION}" \ - maintainer="SoftwareCollections.org " \ - help="For more information visit https://github.com/sclorg/${NAME}-container" \ - usage="s2i build ${FGC}/nginx " - -ENV NGINX_CONFIGURATION_PATH=${APP_ROOT}/etc/nginx.d \ - NGINX_CONF_PATH=/etc/nginx/nginx.conf \ - NGINX_DEFAULT_CONF_PATH=${APP_ROOT}/etc/nginx.default.d \ - NGINX_CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/nginx \ - NGINX_APP_ROOT=${APP_ROOT} - -RUN dnf install -y gettext hostname && \ - INSTALL_PKGS="nss_wrapper bind-utils nginx" && \ - dnf install -y --setopt=tsflags=nodocs $INSTALL_PKGS && \ - rpm -V $INSTALL_PKGS && \ - dnf clean all - -# Copy the S2I scripts from the specific language image to $STI_SCRIPTS_PATH -COPY ./s2i/bin/ $STI_SCRIPTS_PATH - -# Copy extra files to the image. -COPY ./root/ / - -# In order to drop the root user, we have to make some directories world -# writeable as OpenShift default security model is to run the container under -# random UID. -RUN sed -i -f ${NGINX_APP_ROOT}/nginxconf-fed.sed ${NGINX_CONF_PATH} && \ - chmod a+rwx ${NGINX_CONF_PATH} && \ - mkdir -p ${NGINX_APP_ROOT}/etc/nginx.d/ && \ - mkdir -p ${NGINX_APP_ROOT}/etc/nginx.default.d/ && \ - mkdir -p ${NGINX_APP_ROOT}/src/nginx-start/ && \ - mkdir -p ${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start && \ - mkdir -p /var/log/nginx && \ - ln -sf /dev/stdout /var/log/nginx/access.log && \ - ln -sf /dev/stderr /var/log/nginx/error.log && \ - chmod -R a+rwx ${NGINX_APP_ROOT}/etc && \ - chmod -R a+rwx /var /run && \ - chmod -R a+rwx ${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start && \ - chown -R 1001:0 ${NGINX_APP_ROOT} && \ - chown -R 1001:0 /var && \ - chown -R 1001:0 ${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start && \ - rpm-file-permissions - - -USER 1001 - -# Not using VOLUME statement since it's not working in OpenShift Online: -# https://github.com/sclorg/httpd-container/issues/30 -# VOLUME ["/usr/share/nginx/html"] -# VOLUME ["/var/log/nginx/"] - -CMD $STI_SCRIPTS_PATH/usage diff --git a/Dockerfile.fedora b/Dockerfile.fedora deleted file mode 120000 index 1d1fe94..0000000 --- a/Dockerfile.fedora +++ /dev/null @@ -1 +0,0 @@ -Dockerfile \ No newline at end of file diff --git a/README.md b/README.md deleted file mode 100644 index 077002f..0000000 --- a/README.md +++ /dev/null @@ -1,96 +0,0 @@ -Nginx 1.12 server and a reverse proxy server container image -========================================================= - -This container image includes Nginx 1.12 server and a reverse server for OpenShift and general usage. -Users can choose RHEL based image. -The RHEL image is available in the [Red Hat Container Catalog](https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/nginx-112-rhel7) -as registry.access.redhat.com/rhscl/nginx-112-rhel7. - - -Description ------------ - -Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 and IMAP -protocols, with a strong focus on high concurrency, performance and low memory usage. The container -image provides a containerized packaging of the nginx 1.12 daemon. The image can be used -as a base image for other applications based on nginx 1.12 web server. -Nginx server image can be extended using source-to-image tool. - - -Usage ------ - -To build a simple [sample-app](https://github.com/sclorg/nginx-container/tree/master/1.12/test/test-app) application -using standalone [S2I](https://github.com/openshift/source-to-image) and then run the -resulting image with [Docker](http://docker.io) execute: - -* **For RHEL based image** - ``` - $ s2i build https://github.com/sclorg/nginx-container.git --context-dir=1.12/test/test-app/ rhscl/nginx-112-rhel7 nginx-sample-app - $ docker run -p 8080:8080 nginx-sample-app - ``` - -* **For CentOS based image** - ``` - $ s2i build https://github.com/sclorg/nginx-container.git --context-dir=1.12/test/test-app/ centos/nginx-112-centos7 nginx-sample-app - $ docker run -p 8080:8080 nginx-sample-app - ``` - -**Accessing the application:** -``` -$ curl 127.0.0.1:8080 -``` - - -S2I build support -------------- -Nginx server image can be extended using S2I tool (see Usage section). -S2I build folder structure: - -**`./nginx.conf`**-- - The main nginx configuration file - -**`./nginx-cfg/*.conf`** - Should contain all nginx configuration we want to include into image - -**`./nginx-default-cfg/*.conf`** - Contains any nginx config snippets to include in the default server block - -**`./nginx-start/*.sh`** - Contains shell scripts that are sourced right before nginx is launched - -**`./`** - Should contain nginx application source code - - -Environment variables and volumes -------------- -The nginx container image supports the following configuration variable, which can be set by using the `-e` option with the docker run command: - - -**`NGINX_LOG_TO_VOLUME`** - When `NGINX_LOG_TO_VOLUME` is set, nginx logs into `/var/opt/rh/rh-nginx112/log/nginx/` - - -You can mount your own web root like this: -``` -$ docker run -v :/var/www/html/ -``` -You can replace \ with location of your web root. Please note that this has to be an **absolute** path, due to Docker requirements. - - -Troubleshooting ---------------- -By default, nginx logs into standard output, so the log is available in the container log. The log can be examined by running: - - docker logs - -**If `NGINX_LOG_TO_VOLUME` variable is set, nginx logs into `/var/opt/rh/rh-nginx112/log/nginx/`, which can be mounted to host system using the container volumes.** - - -See also --------- -Dockerfile and other sources for this container image are available on -https://github.com/sclorg/nginx-container. -In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile -for RHEL is called Dockerfile.rhel7. diff --git a/bot-cfg.yml b/bot-cfg.yml deleted file mode 100644 index 0618e2d..0000000 --- a/bot-cfg.yml +++ /dev/null @@ -1,23 +0,0 @@ -version: "1" -betka: - # is betka enabled for this repository - # optional - defaults to false - enabled: true - # optional - notifications: - email_addresses: ["phracek@redhat.com", "pkubat@redhat.com", "hhorak@redhat.com"] - # Specify if master branch in upstream repository is synced - master_checker: true - # Should pull requests be synced? - # optional - pr_checker: false - # Either 'upstream_branch_name' or 'upstream_git_path' has to be specified - # Branch name which is used for sync - upstream_branch_name: master - # Path to directory with dockerfile withing upstream repository - upstream_git_path: "1.18" - # Github comment message to enforce sync of a pull request - # required if pr_checker is true otherwise optional - pr_comment_message: "[test]" - # optional - image_url: quay.io/rhscl/cwt-generator diff --git a/dead.package b/dead.package new file mode 100644 index 0000000..7290702 --- /dev/null +++ b/dead.package @@ -0,0 +1 @@ +container sources not used for building fedora containers anymore diff --git a/help.md b/help.md deleted file mode 120000 index 42061c0..0000000 --- a/help.md +++ /dev/null @@ -1 +0,0 @@ -README.md \ No newline at end of file diff --git a/root/help.1 b/root/help.1 deleted file mode 100644 index d8ce31c..0000000 --- a/root/help.1 +++ /dev/null @@ -1,139 +0,0 @@ -.TH Nginx 1.12 server and a reverse proxy server container image -.PP -This container image includes Nginx 1.12 server and a reverse server for OpenShift and general usage. -Users can choose RHEL based image. -The RHEL image is available in the Red Hat Container Catalog -\[la]https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/nginx-112-rhel7\[ra] -as registry.access.redhat.com/rhscl/nginx\-112\-rhel7. - -.SH Description -.PP -Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 and IMAP -protocols, with a strong focus on high concurrency, performance and low memory usage. The container -image provides a containerized packaging of the nginx 1.12 daemon. The image can be used -as a base image for other applications based on nginx 1.12 web server. -Nginx server image can be extended using source\-to\-image tool. - -.SH Usage -.PP -To build a simple sample\-app -\[la]https://github.com/sclorg/nginx-container/tree/master/1.12/test/test-app\[ra] application -using standalone S2I -\[la]https://github.com/openshift/source-to-image\[ra] and then run the -resulting image with Docker -\[la]http://docker.io\[ra] execute: -.IP \(bu 2 - -.PP -\fBFor RHEL based image\fP -.PP -.RS - -.nf -$ s2i build https://github.com/sclorg/nginx\-container.git \-\-context\-dir=1.12/test/test\-app/ rhscl/nginx\-112\-rhel7 nginx\-sample\-app -$ docker run \-p 8080:8080 nginx\-sample\-app - -.fi -.RE -.IP \(bu 2 - -.PP -\fBFor CentOS based image\fP -.PP -.RS - -.nf -$ s2i build https://github.com/sclorg/nginx\-container.git \-\-context\-dir=1.12/test/test\-app/ centos/nginx\-112\-centos7 nginx\-sample\-app -$ docker run \-p 8080:8080 nginx\-sample\-app - -.fi -.RE - -.PP -\fBAccessing the application:\fP - -.PP -.RS - -.nf -$ curl 127.0.0.1:8080 - -.fi -.RE - -.SH S2I build support -.PP -Nginx server image can be extended using S2I tool (see Usage section). -S2I build folder structure: - -.PP -\fB\fB\fC\&./nginx.conf\fR\fP\-\- - The main nginx configuration file - -.PP -\fB\fB\fC\&./nginx\-\&cfg/*.conf\fR\fP -.br - Should contain all nginx configuration we want to include into image - -.PP -\fB\fB\fC\&./nginx\-\&default\-\&cfg/*.conf\fR\fP -.br - Contains any nginx config snippets to include in the default server block - -.PP -\fB\fB\fC\&./nginx\-\&start/*.sh\fR\fP -.br - Contains shell scripts that are sourced right before nginx is launched - -.PP -\fB\fB\fC\&./\fR\fP -.br - Should contain nginx application source code - -.SH Environment variables and volumes -.PP -The nginx container image supports the following configuration variable, which can be set by using the \fB\fC\-e\fR option with the docker run command: - -.PP -\fB\fB\fCNGINX\_LOG\_TO\_VOLUME\fR\fP -.br - When \fB\fCNGINX\_LOG\_TO\_VOLUME\fR is set, nginx logs into \fB\fC/var/opt/rh/rh\-nginx112/log/nginx/\fR - -.PP -You can mount your own web root like this: - -.PP -.RS - -.nf -$ docker run \-v :/var/www/html/ - -.fi -.RE - -.PP -You can replace with location of your web root. Please note that this has to be an \fBabsolute\fP path, due to Docker requirements. - -.SH Troubleshooting -.PP -By default, nginx logs into standard output, so the log is available in the container log. The log can be examined by running: - -.PP -.RS - -.nf -docker logs - -.fi -.RE - -.PP -\fBIf \fB\fCNGINX\_LOG\_TO\_VOLUME\fR variable is set, nginx logs into \fB\fC/var/opt/rh/rh\-nginx112/log/nginx/\fR, which can be mounted to host system using the container volumes.\fP - -.SH See also -.PP -Dockerfile and other sources for this container image are available on - -\[la]https://github.com/sclorg/nginx-container\[ra]\&. -In that repository, Dockerfile for CentOS is called Dockerfile, Dockerfile -for RHEL is called Dockerfile.rhel7. diff --git a/root/opt/app-root/etc/generate_container_user b/root/opt/app-root/etc/generate_container_user deleted file mode 100644 index 229b986..0000000 --- a/root/opt/app-root/etc/generate_container_user +++ /dev/null @@ -1,9 +0,0 @@ -# Set current user in nss_wrapper -PASSWD_DIR="/opt/app-root/etc" - -export USER_ID=$(id -u) -export GROUP_ID=$(id -g) -envsubst < ${PASSWD_DIR}/passwd.template > ${PASSWD_DIR}/passwd -export LD_PRELOAD=libnss_wrapper.so -export NSS_WRAPPER_PASSWD=${PASSWD_DIR}/passwd -export NSS_WRAPPER_GROUP=/etc/group diff --git a/root/opt/app-root/etc/passwd.template b/root/opt/app-root/etc/passwd.template deleted file mode 100644 index 7ad0b78..0000000 --- a/root/opt/app-root/etc/passwd.template +++ /dev/null @@ -1,15 +0,0 @@ -root:x:0:0:root:/root:/bin/bash -bin:x:1:1:bin:/bin:/sbin/nologin -daemon:x:2:2:daemon:/sbin:/sbin/nologin -adm:x:3:4:adm:/var/adm:/sbin/nologin -lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin -sync:x:5:0:sync:/sbin:/bin/sync -shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown -halt:x:7:0:halt:/sbin:/sbin/halt -mail:x:8:12:mail:/var/spool/mail:/sbin/nologin -operator:x:11:0:operator:/root:/sbin/nologin -games:x:12:100:games:/usr/games:/sbin/nologin -ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin -nobody:x:99:99:Nobody:/:/sbin/nologin -default:x:${USER_ID}:${GROUP_ID}:Default Application User:${HOME}:/sbin/nologin -apache:x:48:48:Apache:/usr/share/httpd:/sbin/nologin diff --git a/root/opt/app-root/etc/scl_enable b/root/opt/app-root/etc/scl_enable deleted file mode 100644 index 9079c61..0000000 --- a/root/opt/app-root/etc/scl_enable +++ /dev/null @@ -1,3 +0,0 @@ -# This will make scl collection binaries work out of box. -unset BASH_ENV PROMPT_COMMAND ENV -source scl_source enable rh-nginx112 diff --git a/root/opt/app-root/nginxconf-fed.sed b/root/opt/app-root/nginxconf-fed.sed deleted file mode 100644 index 4755966..0000000 --- a/root/opt/app-root/nginxconf-fed.sed +++ /dev/null @@ -1,7 +0,0 @@ -/listen/s%80%8080% -s/^user *nginx;// -s%/etc/nginx/conf.d/%/opt/app-root/etc/nginx.d/% -s%/etc/nginx/default.d/%/opt/app-root/etc/nginx.default.d/% -s%/usr/share/nginx/html%/opt/app-root/src% -s%/var/log/nginx/error.log%stderr% -s%access_log /var/log/nginx/access.log main;%% diff --git a/root/opt/app-root/nginxconf.sed b/root/opt/app-root/nginxconf.sed deleted file mode 100644 index 007448d..0000000 --- a/root/opt/app-root/nginxconf.sed +++ /dev/null @@ -1,5 +0,0 @@ -/listen/s%80%8080% -s/^user *nginx;// -s%/etc/opt/rh/rh-nginx112/nginx/conf.d/%/opt/app-root/etc/nginx.d/% -s%/etc/opt/rh/rh-nginx112/nginx/default.d/%/opt/app-root/etc/nginx.default.d/% -s%/opt/rh/rh-nginx112/root/usr/share/nginx/html%/opt/app-root/src% diff --git a/root/usr/share/container-scripts/nginx/common.sh b/root/usr/share/container-scripts/nginx/common.sh deleted file mode 100644 index 319219c..0000000 --- a/root/usr/share/container-scripts/nginx/common.sh +++ /dev/null @@ -1,31 +0,0 @@ -#!/bin/sh - -# get_matched_files finds file for image extending -function get_matched_files() { - local custom_dir default_dir - custom_dir="$1" - default_dir="$2" - files_matched="$3" - find "$default_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n" - [ -d "$custom_dir" ] && find "$custom_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n" -} - -# process_extending_files process extending files in $1 and $2 directories -# - source all *.sh files -# (if there are files with same name source only file from $1) -function process_extending_files() { - local custom_dir default_dir - custom_dir=$1 - default_dir=$2 - while read filename ; do - if [ $filename ]; then - echo "=> sourcing $filename ..." - # Custom file is prefered - if [ -f $custom_dir/$filename ]; then - source $custom_dir/$filename - elif [ -f $default_dir/$filename ]; then - source $default_dir/$filename - fi - fi - done <<<"$(get_matched_files "$custom_dir" "$default_dir" '*.sh' | sort -u)" -} \ No newline at end of file diff --git a/s2i/bin/assemble b/s2i/bin/assemble deleted file mode 100755 index ef27877..0000000 --- a/s2i/bin/assemble +++ /dev/null @@ -1,41 +0,0 @@ -#!/bin/bash - -set -e - -echo "---> Installing application source" -cp -Rf /tmp/src/. ./ - -if [ -f ./nginx.conf ]; then - echo "---> Copying nginx.conf configuration file..." - cp -v ./nginx.conf "${NGINX_CONF_PATH}" - rm -f ./nginx.conf -fi - -if [ -d ./nginx-cfg ]; then - echo "---> Copying nginx configuration files..." - if [ "$(ls -A ./nginx-cfg/*.conf)" ]; then - cp -v ./nginx-cfg/*.conf "${NGINX_CONFIGURATION_PATH}" - rm -rf ./nginx-cfg - fi - chmod -Rf g+rw ${NGINX_CONFIGURATION_PATH} -fi - -if [ -d ./nginx-default-cfg ]; then - echo "---> Copying nginx default server configuration files..." - if [ "$(ls -A ./nginx-default-cfg/*.conf)" ]; then - cp -v ./nginx-default-cfg/*.conf "${NGINX_DEFAULT_CONF_PATH}" - rm -rf ./nginx-default-cfg - fi - chmod -Rf g+rw ${NGINX_DEFAULT_CONF_PATH} -fi - -if [ -d ./nginx-start ]; then - echo "---> Copying nginx start-hook scripts..." - if [ "$(ls -A ./nginx-start/* 2>/dev/null)" ]; then - cp -v ./nginx-start/* "${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start/" - rm -rf ./nginx-start - fi -fi - -# Fix source directory permissions -fix-permissions ./ diff --git a/s2i/bin/run b/s2i/bin/run deleted file mode 100755 index ca8d55b..0000000 --- a/s2i/bin/run +++ /dev/null @@ -1,11 +0,0 @@ -#!/bin/bash - -source /opt/app-root/etc/generate_container_user - -set -e - -source ${NGINX_CONTAINER_SCRIPTS_PATH}/common.sh - -process_extending_files ${NGINX_APP_ROOT}/src/nginx-start ${NGINX_CONTAINER_SCRIPTS_PATH}/nginx-start - -exec nginx -g "daemon off;" diff --git a/s2i/bin/usage b/s2i/bin/usage deleted file mode 100755 index 1bc9219..0000000 --- a/s2i/bin/usage +++ /dev/null @@ -1,17 +0,0 @@ -#!/bin/sh - -DISTRO=`cat /etc/*-release | grep ^ID= | grep -Po '".*?"' | tr -d '"'` -NAMESPACE=centos -[[ $DISTRO =~ rhel* ]] && NAMESPACE=rhscl - -cat </dev/null -} - -container_exists() { - image_exists $(cat $cid_file) -} - -container_ip() { - docker inspect --format="{{ .NetworkSettings.IPAddress }}" $(cat $cid_file) -} - -run_s2i_build() { - ct_s2i_build_as_df file://${test_dir}/${1} ${IMAGE_NAME} ${IMAGE_NAME}-${1} ${s2i_args} -} - -prepare() { - if ! image_exists ${IMAGE_NAME}; then - echo "ERROR: The image ${IMAGE_NAME} must exist before this script is executed." - exit 1 - fi - # TODO: S2I build require the application is a valid 'GIT' repository, we - # should remove this restriction in the future when a file:// is used. - info "Build the test application image" - pushd ${test_dir}/${1} >/dev/null - git init - git config user.email "build@localhost" && git config user.name "builder" - git add -A && git commit -m "Sample commit" - popd >/dev/null -} - -run_test_application() { - run_args=${CONTAINER_ARGS:-} - docker run --user=100001 ${run_args} --cidfile=${cid_file} ${IMAGE_NAME}-${1} -} - -cleanup_test_app() { - info "Cleaning up the test application" - if [ -f $cid_file ]; then - if container_exists; then - docker stop $(cat $cid_file) - docker rm $(cat $cid_file) - fi - rm $cid_file - fi -} - -cleanup() { - info "Cleaning up the test application image" - if image_exists ${IMAGE_NAME}-${1}; then - docker rmi -f ${IMAGE_NAME}-${1} - fi - rm -rf ${test_dir}/${1}/.git -} - -check_result() { - local result="$1" - if [[ "$result" != "0" ]]; then - info "TEST FAILED (${result})" - cleanup $2 - exit $result - fi -} - -wait_for_cid() { - local max_attempts=10 - local sleep_time=1 - local attempt=1 - local result=1 - info "Waiting for application container to start" - while [ $attempt -le $max_attempts ]; do - [ -f $cid_file ] && [ -s $cid_file ] && break - attempt=$(( $attempt + 1 )) - sleep $sleep_time - done -} - -test_s2i_usage() { - info "Testing 's2i usage'" - ct_s2i_usage ${IMAGE_NAME} ${s2i_args} &>/dev/null -} - -test_docker_run_usage() { - info "Testing 'docker run' usage" - docker run ${IMAGE_NAME} &>/dev/null -} - -test_scl_usage() { - local run_cmd="$1" - local expected="$2" - - info "Testing the image SCL enable" - out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${run_cmd} 2>&1") - if ! echo "${out}" | grep -q "${expected}"; then - echo "ERROR[/bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'" - return 1 - fi - test_command "$run_cmd" "$expected" - return $? -} - -test_command() { - local run_cmd="$1" - local expected="$2" - local message="$3" - - if [ $message ]; then - info ${3} - fi - out=$(docker exec $(cat ${cid_file}) /bin/bash -c "${run_cmd}" 2>&1) - if ! echo "${out}" | grep -q "${expected}"; then - echo "ERROR[exec /bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'" - return 1 - fi - out=$(docker exec $(cat ${cid_file}) /bin/sh -ic "${run_cmd}" 2>&1) - if ! echo "${out}" | grep -q "${expected}"; then - echo "ERROR[exec /bin/sh -ic "${run_cmd}"] Expected '${expected}', got '${out}'" - return 1 - fi - - return 0 -} - -test_for_output() -{ - local url="$1" - local expect="$2" - local host="${3-localhost}" - local max_attempts=5 - local sleep_time=1 - local attempt=1 - local result=1 - - info "Testing URL $url with HTTP hostname ${host} produces output $expect" - - while [ $attempt -le $max_attempts ]; do - response=$(curl -s -H "Host: ${host}" ${url}) - echo "${response}" - status=$? - if [ $status -eq 0 ]; then - if echo "${response}" | grep -q "${expect}"; then - info "Success!" - result=0 - break - else - echo "Response: ${response}" - fi - fi - attempt=$(( $attempt + 1 )) - sleep $sleep_time - done - - return $result -} - -test_connection() { - cat $cid_file - info "Testing the HTTP connection (http://$(container_ip):${test_port})" - - if test_for_output "http://$(container_ip):${test_port}/" "NGINX is working" && - test_for_output "http://$(container_ip):${test_port}/" "NGINX2 is working" localhost2 && - test_for_output "http://$(container_ip):${test_port}/aliased/index2.html" "NGINX2 is working" && - test_for_output "http://$(container_ip):${test_port}/nginx-cfg/default.conf" "404"; then - return 0 - fi - - return 1 -} - -test_connection_s2i() { - cat $cid_file - info "Testing the HTTP connection (http://$(container_ip):${test_port})" - - if test_for_output "http://$(container_ip):${test_port}/" "NGINX is working" && - test_for_output "http://$(container_ip):${test_port}/" "NGINX2 is working" localhost2 && - test_for_output "http://$(container_ip):${test_port}/nginx-cfg/default.conf" "404"; then - return 0 - fi - - return 1 -} - -test_application() { - # Verify that the HTTP connection can be established to test application container - run_test_application "test-app" & - - # Wait for the container to write it's CID file - wait_for_cid - - test_scl_usage "nginx -v" "nginx version: nginx/1.12." - check_result $? "test-app" - - test_connection - check_result $? "test-app" - cleanup_test_app -} - -test_pre_init_script() { - # Verify that the HTTP connection can be established to test application container - run_test_application "start-hook-test-app" & - - # Wait for the container to write it's CID file - wait_for_cid - - test_command "cat /opt/app-root/etc/nginx.d/default.conf | grep 'resolver' | sed -e 's/resolver\(.*\);/\1/' | grep 'DNS_SERVER'" "" - check_result $? "start-hook-test-app" - - test_connection_s2i - check_result $? "start-hook-test-app" - cleanup_test_app - -} - -cid_file=$(mktemp -u --suffix=.cid) - -# Since we built the candidate image locally, we don't want S2I attempt to pull -# it from Docker hub -s2i_args="--pull-policy=never" - -if [ "$TARGET" == "fedora" ]; then - mv ${test_dir}/test-app/nginx.conf{,.bkp} - cp ${test_dir}/test-app/nginx.conf{.fedora,} -fi -prepare "test-app" -run_s2i_build "test-app" -if [ "$TARGET" == "fedora" ]; then - mv ${test_dir}/test-app/nginx.conf{.bkp,} -fi -check_result $? "test-app" - -# Verify the 'usage' script is working properly when running the base image with 's2i usage ...' -test_s2i_usage -check_result $? "test-app" - -# Verify the 'usage' script is working properly when running the base image with 'docker run ...' -test_docker_run_usage -check_result $? "test-app" - -# Test application with default uid -test_application - -# Test application with random uid -CONTAINER_ARGS="--user 12345" test_application -cleanup "test-app" - -# Test start-hook script functionality -cid_file=$(mktemp -u --suffix=.cid) - -prepare "start-hook-test-app" -run_s2i_build "start-hook-test-app" -check_result $? "start-hook-test-app" - -test_pre_init_script -cleanup "start-hook-test-app" - -info "All tests finished successfully." diff --git a/test/run-openshift b/test/run-openshift deleted file mode 100755 index fd2a22f..0000000 --- a/test/run-openshift +++ /dev/null @@ -1,37 +0,0 @@ -#!/bin/bash -# -# Test the Nginx image in OpenShift. -# -# IMAGE_NAME specifies a name of the candidate image used for testing. -# The image has to be available before this script is executed. -# - -THISDIR=$(dirname ${BASH_SOURCE[0]}) - -source ${THISDIR}/test-lib.sh -source ${THISDIR}/test-lib-openshift.sh - -# TODO: branch should be changed to master, once code in example app -# stabilizes on with referencing latest version -BRANCH_TO_TEST=master - -set -eo nounset - -test -n "${IMAGE_NAME-}" || false 'make sure $IMAGE_NAME is defined' -test -n "${VERSION-}" || false 'make sure $VERSION is defined' - -ct_os_cluster_up - -# test local app -ct_os_test_s2i_app ${IMAGE_NAME} "${THISDIR}/test-app" . 'Test NGINX passed' - -# test remote example app -ct_os_test_s2i_app ${IMAGE_NAME} "https://github.com/sclorg/nginx-ex.git#${BRANCH_TO_TEST}" . 'Welcome to your static nginx application on OpenShift' - -# test template from the example app -ct_os_test_template_app ${IMAGE_NAME} \ - https://raw.githubusercontent.com/sclorg/nginx-ex/${BRANCH_TO_TEST}/openshift/templates/nginx.json \ - nginx \ - 'Welcome to your static nginx application on OpenShift' \ - 8080 http 200 "-p SOURCE_REPOSITORY_REF=${BRANCH_TO_TEST} -p NGINX_VERSION=${VERSION} -p NAME=nginx-testing" - diff --git a/test/start-hook-test-app/index.html b/test/start-hook-test-app/index.html deleted file mode 100644 index d147627..0000000 --- a/test/start-hook-test-app/index.html +++ /dev/null @@ -1,8 +0,0 @@ - - - Test NGINX passed - - -

NGINX is working

- - diff --git a/test/start-hook-test-app/index2.html b/test/start-hook-test-app/index2.html deleted file mode 100644 index e73a98c..0000000 --- a/test/start-hook-test-app/index2.html +++ /dev/null @@ -1,8 +0,0 @@ - - - Test NGINX passed - - -

NGINX2 is working

- - diff --git a/test/start-hook-test-app/nginx-cfg/default.conf b/test/start-hook-test-app/nginx-cfg/default.conf deleted file mode 100644 index e947c98..0000000 --- a/test/start-hook-test-app/nginx-cfg/default.conf +++ /dev/null @@ -1,8 +0,0 @@ -server { - listen 8080; - server_name localhost2; - root /opt/app-root/src; - index ${INDEX_FILE}; - resolver ${DNS_SERVER}; - -} \ No newline at end of file diff --git a/test/start-hook-test-app/nginx-start/init.sh b/test/start-hook-test-app/nginx-start/init.sh deleted file mode 100644 index 450dfe4..0000000 --- a/test/start-hook-test-app/nginx-start/init.sh +++ /dev/null @@ -1,19 +0,0 @@ -setup_dns_env_var() { - if [ -z "$DNS_SERVER" ]; then - export DNS_SERVER=`cat /etc/resolv.conf | grep "nameserver " | awk '{print $2}' | tr '\n' ' '` - echo "Using system dns server ${DNS_SERVER}" - else - echo "Using user defined dns server: ${DNS_SERVER}" - fi -} - -inject_env_vars() { - ## Replace only specified environment variables in specified file. - envsubst '${DNS_SERVER},${INDEX_FILE}' < ${NGINX_CONFIGURATION_PATH}/$1 > output.conf - cp output.conf ${NGINX_CONFIGURATION_PATH}/$1 - echo "This is $1: " && cat ${NGINX_CONFIGURATION_PATH}/$1 -} - -export INDEX_FILE=index2.html -setup_dns_env_var -inject_env_vars "default.conf" diff --git a/test/test-app/index.html b/test/test-app/index.html deleted file mode 100644 index d147627..0000000 --- a/test/test-app/index.html +++ /dev/null @@ -1,8 +0,0 @@ - - - Test NGINX passed - - -

NGINX is working

- - diff --git a/test/test-app/index2.html b/test/test-app/index2.html deleted file mode 100644 index e73a98c..0000000 --- a/test/test-app/index2.html +++ /dev/null @@ -1,8 +0,0 @@ - - - Test NGINX passed - - -

NGINX2 is working

- - diff --git a/test/test-app/nginx-cfg/default.conf b/test/test-app/nginx-cfg/default.conf deleted file mode 100644 index d5a49f6..0000000 --- a/test/test-app/nginx-cfg/default.conf +++ /dev/null @@ -1,6 +0,0 @@ -server { - listen 8080; - server_name localhost2; - root /opt/app-root/src; - index index2.html; -} diff --git a/test/test-app/nginx-default-cfg/alias.conf b/test/test-app/nginx-default-cfg/alias.conf deleted file mode 100644 index 649ca52..0000000 --- a/test/test-app/nginx-default-cfg/alias.conf +++ /dev/null @@ -1,3 +0,0 @@ -location /aliased/ { - alias /opt/app-root/src/; -} diff --git a/test/test-app/nginx.conf b/test/test-app/nginx.conf deleted file mode 100644 index 76ce0eb..0000000 --- a/test/test-app/nginx.conf +++ /dev/null @@ -1,117 +0,0 @@ -# For more information on configuration, see: -# * Official English Documentation: http://nginx.org/en/docs/ -# * Official Russian Documentation: http://nginx.org/ru/docs/ - - -worker_processes auto; -error_log stderr; -pid /var/opt/rh/rh-nginx112/run/nginx/nginx.pid; - -# Load dynamic modules. See /opt/rh/rh-nginx112/root/usr/share/doc/README.dynamic. -include /opt/rh/rh-nginx112/root/usr/share/nginx/modules/*.conf; - -events { - worker_connections 1024; -} - -http { - log_format main '$remote_addr - $remote_user [$time_local] "$request" ' - '$status $body_bytes_sent "$http_referer" ' - '"$http_user_agent" "$http_x_forwarded_for"'; - - sendfile on; - tcp_nopush on; - tcp_nodelay on; - keepalive_timeout 65; - types_hash_max_size 2048; - - include /etc/opt/rh/rh-nginx112/nginx/mime.types; - default_type application/octet-stream; - - # Load modular configuration files from the /etc/nginx/conf.d directory. - # See http://nginx.org/en/docs/ngx_core_module.html#include - # for more information. - include /opt/app-root/etc/nginx.d/*.conf; - - server { - listen 8080 default_server; - listen [::]:8080 default_server; - server_name _; - root /opt/app-root/src; - - # Load configuration files for the default server block. - include /opt/app-root/etc/nginx.default.d/*.conf; - - location / { - } - - error_page 404 /404.html; - location = /40x.html { - } - - error_page 500 502 503 504 /50x.html; - location = /50x.html { - } - - # proxy the PHP scripts to Apache listening on 127.0.0.1:8080 - # - #location ~ \.php$ { - # proxy_pass http://127.0.0.1; - #} - - # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000 - # - #location ~ \.php$ { - # root html; - # fastcgi_pass 127.0.0.1:9000; - # fastcgi_index index.php; - # fastcgi_param SCRIPT_FILENAME /scripts$fastcgi_script_name; - # include fastcgi_params; - #} - - # deny access to .htaccess files, if Apache's document root - # concurs with nginx's one - # - #location ~ /\.ht { - # deny all; - #} - } - - - # another virtual host using mix of IP-, name-, and port-based configuration - # - #server { - # listen 808000; - # listen somename:808080; - # server_name somename alias another.alias; - - # location / { - # root html; - # index index.html index.htm; - # } - #} - - - # HTTPS server - # - #server { - # listen 443; - # server_name localhost; - - # ssl on; - # ssl_certificate cert.pem; - # ssl_certificate_key cert.key; - - # ssl_session_timeout 5m; - - # ssl_protocols SSLv2 SSLv3 TLSv1; - # ssl_ciphers HIGH:!aNULL:!MD5; - # ssl_prefer_server_ciphers on; - - # location / { - # root html; - # index index.html index.htm; - # } - #} - -} diff --git a/test/test-app/nginx.conf.fedora b/test/test-app/nginx.conf.fedora deleted file mode 100644 index e395483..0000000 --- a/test/test-app/nginx.conf.fedora +++ /dev/null @@ -1,90 +0,0 @@ -# For more information on configuration, see: -# * Official English Documentation: http://nginx.org/en/docs/ -# * Official Russian Documentation: http://nginx.org/ru/docs/ - - -worker_processes auto; -error_log stderr; -pid /run/nginx.pid; - -# Load dynamic modules. See /usr/share/doc/nginx/README.dynamic. -include /usr/share/nginx/modules/*.conf; - -events { - worker_connections 1024; -} - -http { - log_format main '$remote_addr - $remote_user [$time_local] "$request" ' - '$status $body_bytes_sent "$http_referer" ' - '"$http_user_agent" "$http_x_forwarded_for"'; - - - - sendfile on; - tcp_nopush on; - tcp_nodelay on; - keepalive_timeout 65; - types_hash_max_size 2048; - - include /etc/nginx/mime.types; - default_type application/octet-stream; - - # Load modular configuration files from the /etc/nginx/conf.d directory. - # See http://nginx.org/en/docs/ngx_core_module.html#include - # for more information. - include /opt/app-root/etc/nginx.d/*.conf; - - server { - listen 8080 default_server; - listen [::]:8080 default_server; - server_name _; - root /opt/app-root/src; - - # Load configuration files for the default server block. - include /opt/app-root/etc/nginx.default.d/*.conf; - - location / { - } - - error_page 404 /404.html; - location = /40x.html { - } - - error_page 500 502 503 504 /50x.html; - location = /50x.html { - } - } - -# Settings for a TLS enabled server. -# -# server { -# listen 443 ssl http2 default_server; -# listen [::]:443 ssl http2 default_server; -# server_name _; -# root /opt/app-root/src; -# -# ssl_certificate "/etc/pki/nginx/server.crt"; -# ssl_certificate_key "/etc/pki/nginx/private/server.key"; -# ssl_session_cache shared:SSL:1m; -# ssl_session_timeout 10m; -# ssl_ciphers PROFILE=SYSTEM; -# ssl_prefer_server_ciphers on; -# -# # Load configuration files for the default server block. -# include /opt/app-root/etc/nginx.default.d/*.conf; -# -# location / { -# } -# -# error_page 404 /404.html; -# location = /40x.html { -# } -# -# error_page 500 502 503 504 /50x.html; -# location = /50x.html { -# } -# } - -} - diff --git a/test/test-lib-openshift.sh b/test/test-lib-openshift.sh deleted file mode 100644 index f988ac5..0000000 --- a/test/test-lib-openshift.sh +++ /dev/null @@ -1,925 +0,0 @@ -# Set of functions for testing docker images in OpenShift using 'oc' command - -# ct_os_get_status -# -------------------- -# Returns status of all objects to make debugging easier. -function ct_os_get_status() { - oc get all - oc status -} - -# ct_os_print_logs -# -------------------- -# Returns status of all objects and logs from all pods. -function ct_os_print_logs() { - ct_os_get_status - while read pod_name; do - echo "INFO: printing logs for pod ${pod_name}" - oc logs ${pod_name} - done < <(oc get pods --no-headers=true -o custom-columns=NAME:.metadata.name) -} - -# ct_os_enable_print_logs -# -------------------- -# Enables automatic printing of pod logs on ERR. -function ct_os_enable_print_logs() { - set -E - trap ct_os_print_logs ERR -} - -# ct_get_public_ip -# -------------------- -# Returns best guess for the IP that the node is accessible from other computers. -# This is a bit funny heuristic, simply goes through all IPv4 addresses that -# hostname -I returns and de-prioritizes IP addresses commonly used for local -# addressing. The rest of addresses are taken as public with higher probability. -function ct_get_public_ip() { - local hostnames=$(hostname -I) - local public_ip='' - local found_ip - for guess_exp in '127\.0\.0\.1' '192\.168\.[0-9\.]*' '172\.[0-9\.]*' \ - '10\.[0-9\.]*' '[0-9\.]*' ; do - found_ip=$(echo "${hostnames}" | grep -oe "${guess_exp}") - if [ -n "${found_ip}" ] ; then - hostnames=$(echo "${hostnames}" | sed -e "s/${found_ip}//") - public_ip="${found_ip}" - fi - done - if [ -z "${public_ip}" ] ; then - echo "ERROR: public IP could not be guessed." >&2 - return 1 - fi - echo "${public_ip}" -} - -# ct_os_run_in_pod POD_NAME CMD -# -------------------- -# Runs [cmd] in the pod specified by prefix [pod_prefix]. -# Arguments: pod_name - full name of the pod -# Arguments: cmd - command to be run in the pod -function ct_os_run_in_pod() { - local pod_name="$1" ; shift - - oc exec "$pod_name" -- "$@" -} - -# ct_os_get_service_ip SERVICE_NAME -# -------------------- -# Returns IP of the service specified by [service_name]. -# Arguments: service_name - name of the service -function ct_os_get_service_ip() { - local service_name="${1}" ; shift - oc get "svc/${service_name}" -o yaml | grep clusterIP | \ - cut -d':' -f2 | grep -oe '172\.30\.[0-9\.]*' -} - - -# ct_os_get_all_pods_status -# -------------------- -# Returns status of all pods. -function ct_os_get_all_pods_status() { - oc get pods -o custom-columns=Ready:status.containerStatuses[0].ready,NAME:.metadata.name -} - -# ct_os_get_all_pods_name -# -------------------- -# Returns the full name of all pods. -function ct_os_get_all_pods_name() { - oc get pods --no-headers -o custom-columns=NAME:.metadata.name -} - -# ct_os_get_pod_status POD_PREFIX -# -------------------- -# Returns status of the pod specified by prefix [pod_prefix]. -# Note: Ignores -build and -deploy pods -# Arguments: pod_prefix - prefix or whole ID of the pod -function ct_os_get_pod_status() { - local pod_prefix="${1}" ; shift - ct_os_get_all_pods_status | grep -e "${pod_prefix}" | grep -Ev "(build|deploy)$" \ - | awk '{print $1}' | head -n 1 -} - -# ct_os_get_pod_name POD_PREFIX -# -------------------- -# Returns the full name of pods specified by prefix [pod_prefix]. -# Note: Ignores -build and -deploy pods -# Arguments: pod_prefix - prefix or whole ID of the pod -function ct_os_get_pod_name() { - local pod_prefix="${1}" ; shift - ct_os_get_all_pods_name | grep -e "^${pod_prefix}" | grep -Ev "(build|deploy)$" -} - -# ct_os_get_pod_ip POD_NAME -# -------------------- -# Returns the ip of the pod specified by [pod_name]. -# Arguments: pod_name - full name of the pod -function ct_os_get_pod_ip() { - local pod_name="${1}" - oc get pod "$pod_name" --no-headers -o custom-columns=IP:status.podIP -} - -# ct_os_check_pod_readiness POD_PREFIX STATUS -# -------------------- -# Checks whether the pod is ready. -# Arguments: pod_prefix - prefix or whole ID of the pod -# Arguments: status - expected status (true, false) -function ct_os_check_pod_readiness() { - local pod_prefix="${1}" ; shift - local status="${1}" ; shift - test "$(ct_os_get_pod_status ${pod_prefix})" == "${status}" -} - -# ct_os_wait_pod_ready POD_PREFIX TIMEOUT -# -------------------- -# Wait maximum [timeout] for the pod becomming ready. -# Arguments: pod_prefix - prefix or whole ID of the pod -# Arguments: timeout - how many seconds to wait seconds -function ct_os_wait_pod_ready() { - local pod_prefix="${1}" ; shift - local timeout="${1}" ; shift - SECONDS=0 - echo -n "Waiting for ${pod_prefix} pod becoming ready ..." - while ! ct_os_check_pod_readiness "${pod_prefix}" "true" ; do - echo -n "." - [ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1 - sleep 3 - done - echo " DONE" -} - -# ct_os_wait_rc_ready POD_PREFIX TIMEOUT -# -------------------- -# Wait maximum [timeout] for the rc having desired number of replicas ready. -# Arguments: pod_prefix - prefix of the replication controller -# Arguments: timeout - how many seconds to wait seconds -function ct_os_wait_rc_ready() { - local pod_prefix="${1}" ; shift - local timeout="${1}" ; shift - SECONDS=0 - echo -n "Waiting for ${pod_prefix} pod becoming ready ..." - while ! test "$((oc get --no-headers statefulsets; oc get --no-headers rc) 2>/dev/null \ - | grep "^${pod_prefix}" | awk '$2==$3 {print "ready"}')" == "ready" ; do - echo -n "." - [ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1 - sleep 3 - done - echo " DONE" -} - -# ct_os_deploy_pure_image IMAGE [ENV_PARAMS, ...] -# -------------------- -# Runs [image] in the openshift and optionally specifies env_params -# as environment variables to the image. -# Arguments: image - prefix or whole ID of the pod to run the cmd in -# Arguments: env_params - environment variables parameters for the images. -function ct_os_deploy_pure_image() { - local image="${1}" ; shift - # ignore error exit code, because oc new-app returns error when image exists - oc new-app ${image} "$@" || : - # let openshift cluster to sync to avoid some race condition errors - sleep 3 -} - -# ct_os_deploy_s2i_image IMAGE APP [ENV_PARAMS, ... ] -# -------------------- -# Runs [image] and [app] in the openshift and optionally specifies env_params -# as environment variables to the image. -# Arguments: image - prefix or whole ID of the pod to run the cmd in -# Arguments: app - url or local path to git repo with the application sources. -# Arguments: env_params - environment variables parameters for the images. -function ct_os_deploy_s2i_image() { - local image="${1}" ; shift - local app="${1}" ; shift - # ignore error exit code, because oc new-app returns error when image exists - oc new-app "${image}~${app}" "$@" || : - - # let openshift cluster to sync to avoid some race condition errors - sleep 3 -} - -# ct_os_deploy_template_image TEMPLATE [ENV_PARAMS, ...] -# -------------------- -# Runs template in the openshift and optionally gives env_params to use -# specific values in the template. -# Arguments: template - prefix or whole ID of the pod to run the cmd in -# Arguments: env_params - environment variables parameters for the template. -# Example usage: ct_os_deploy_template_image mariadb-ephemeral-template.yaml \ -# DATABASE_SERVICE_NAME=mysql-57-centos7 \ -# DATABASE_IMAGE=mysql-57-centos7 \ -# MYSQL_USER=testu \ -# MYSQL_PASSWORD=testp \ -# MYSQL_DATABASE=testdb -function ct_os_deploy_template_image() { - local template="${1}" ; shift - oc process -f "${template}" "$@" | oc create -f - - # let openshift cluster to sync to avoid some race condition errors - sleep 3 -} - -# _ct_os_get_uniq_project_name -# -------------------- -# Returns a uniq name of the OpenShift project. -function _ct_os_get_uniq_project_name() { - local r - while true ; do - r=${RANDOM} - mkdir /var/tmp/sclorg-test-${r} &>/dev/null && echo sclorg-test-${r} && break - done -} - -# ct_os_new_project [PROJECT] -# -------------------- -# Creates a new project in the openshfit using 'os' command. -# Arguments: project - project name, uses a new random name if omitted -# Expects 'os' command that is properly logged in to the OpenShift cluster. -# Not using mktemp, because we cannot use uppercase characters. -function ct_os_new_project() { - if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then - echo "Creating project skipped." - return - fi - local project_name="${1:-$(_ct_os_get_uniq_project_name)}" ; shift || : - oc new-project ${project_name} - # let openshift cluster to sync to avoid some race condition errors - sleep 3 -} - -# ct_os_delete_project [PROJECT] -# -------------------- -# Deletes the specified project in the openshfit -# Arguments: project - project name, uses the current project if omitted -function ct_os_delete_project() { - if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then - echo "Deleting project skipped, cleaning objects only." - ct_delete_all_objects - return - fi - local project_name="${1:-$(oc project -q)}" ; shift || : - oc delete project "${project_name}" -} - -# ct_delete_all_objects -# ----------------- -# Deletes all objects within the project. -# Handy when we have one project and want to run more tests. -function ct_delete_all_objects() { - for x in bc builds dc is isimage istag po pv pvc rc routes secrets svc ; do - oc delete $x --all - done - # for some objects it takes longer to be really deleted, so a dummy sleep - # to avoid some races when other test can see not-yet-deleted objects and can fail - sleep 10 -} - -# ct_os_docker_login -# -------------------- -# Logs in into docker daemon -# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address. -# Does not do anything if REGISTRY_ADDRESS is set. -function ct_os_docker_login() { - [ -n "${REGISTRY_ADDRESS:-}" ] && "REGISTRY_ADDRESS set, not trying to docker login." && return 0 - # docker login fails with "404 page not found" error sometimes, just try it more times - for i in `seq 12` ; do - docker login -u developer -p $(oc whoami -t) ${REGISRTY_ADDRESS:-172.30.1.1:5000} && return 0 || : - sleep 5 - done - return 1 -} - -# ct_os_upload_image IMAGE [IMAGESTREAM] -# -------------------- -# Uploads image from local registry to the OpenShift internal registry. -# Arguments: image - image name to upload -# Arguments: imagestream - name and tag to use for the internal registry. -# In the format of name:tag ($image_name:latest by default) -# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address. -function ct_os_upload_image() { - local input_name="${1}" ; shift - local image_name=${input_name##*/} - local imagestream=${1:-$image_name:latest} - local output_name="${REGISRTY_ADDRESS:-172.30.1.1:5000}/$(oc project -q)/$imagestream" - - ct_os_docker_login - docker tag ${input_name} ${output_name} - docker push ${output_name} -} - -# ct_os_install_in_centos -# -------------------- -# Installs os cluster in CentOS -function ct_os_install_in_centos() { - yum install -y centos-release-openshift-origin - yum install -y wget git net-tools bind-utils iptables-services bridge-utils\ - bash-completion origin-clients docker origin-clients -} - -# ct_os_cluster_up [DIR, IS_PUBLIC, CLUSTER_VERSION] -# -------------------- -# Runs the local OpenShift cluster using 'oc cluster up' and logs in as developer. -# Arguments: dir - directory to keep configuration data in, random if omitted -# Arguments: is_public - sets either private or public hostname for web-UI, -# use "true" for allow remote access to the web-UI, -# "false" is default -# Arguments: cluster_version - version of the OpenShift cluster to use, empty -# means default version of `oc`; example value: 3.7; -# also can be specified outside by OC_CLUSTER_VERSION -function ct_os_cluster_up() { - ct_os_cluster_running && echo "Cluster already running. Nothing is done." && return 0 - ct_os_logged_in && echo "Already logged in to a cluster. Nothing is done." && return 0 - - mkdir -p /var/tmp/openshift - local dir="${1:-$(mktemp -d /var/tmp/openshift/os-data-XXXXXX)}" ; shift || : - local is_public="${1:-'false'}" ; shift || : - local default_cluster_version=${OC_CLUSTER_VERSION:-} - local cluster_version=${1:-${default_cluster_version}} ; shift || : - if ! grep -qe '--insecure-registry.*172\.30\.0\.0' /etc/sysconfig/docker ; then - sed -i "s|OPTIONS='|OPTIONS='--insecure-registry 172.30.0.0/16 |" /etc/sysconfig/docker - fi - - systemctl stop firewalld || : - setenforce 0 - iptables -F - - systemctl restart docker - local cluster_ip="127.0.0.1" - [ "${is_public}" == "true" ] && cluster_ip=$(ct_get_public_ip) - - if [ -n "${cluster_version}" ] ; then - # if $cluster_version is not set, we simply use oc that is available - ct_os_set_path_oc "${cluster_version}" - fi - - mkdir -p ${dir}/{config,data,pv} - case $(oc version| head -n 1) in - "oc v3.1"?.*) - oc cluster up --base-dir="${dir}/data" --public-hostname="${cluster_ip}" - ;; - "oc v3."*) - oc cluster up --host-data-dir="${dir}/data" --host-config-dir="${dir}/config" \ - --host-pv-dir="${dir}/pv" --use-existing-config --public-hostname="${cluster_ip}" - ;; - *) - echo "ERROR: Unexpected oc version." >&2 - return 1 - ;; - esac - oc version - oc login -u system:admin - oc project default - ct_os_wait_rc_ready docker-registry 180 - ct_os_wait_rc_ready router 30 - oc login -u developer -p developer - # let openshift cluster to sync to avoid some race condition errors - sleep 3 -} - -# ct_os_cluster_down -# -------------------- -# Shuts down the local OpenShift cluster using 'oc cluster down' -function ct_os_cluster_down() { - oc cluster down -} - -# ct_os_cluster_running -# -------------------- -# Returns 0 if oc cluster is running -function ct_os_cluster_running() { - oc cluster status &>/dev/null -} - -# ct_os_logged_in -# --------------- -# Returns 0 if logged in to a cluster (remote or local) -function ct_os_logged_in() { - oc whoami >/dev/null -} - -# ct_os_set_path_oc OC_VERSION -# -------------------- -# This is a trick that helps using correct version of the `oc`: -# The input is version of the openshift in format v3.6.0 etc. -# If the currently available version of oc is not of this version, -# it first takes a look into /usr/local/oc-/bin directory, -# and if not found there it downloads the community release from github. -# In the end the PATH variable is changed, so the other tests can still use just 'oc'. -# Arguments: oc_version - X.Y part of the version of OSE (e.g. 3.9) -function ct_os_set_path_oc() { - local oc_version=$(ct_os_get_latest_ver $1) - local oc_path - - if oc version | grep -q "oc ${oc_version%.*}." ; then - echo "Binary oc found already available in version ${oc_version}: `which oc` Doing noting." - return 0 - fi - - # first check whether we already have oc available in /usr/local - local installed_oc_path="/usr/local/oc-${oc_version%.*}/bin" - - if [ -x "${installed_oc_path}/oc" ] ; then - oc_path="${installed_oc_path}" - echo "Binary oc found in ${installed_oc_path}" >&2 - else - # oc not available in /usr/local, try to download it from github (community release) - oc_path="/tmp/oc-${oc_version}-bin" - ct_os_download_upstream_oc "${oc_version}" "${oc_path}" - fi - if [ -z "${oc_path}/oc" ] ; then - echo "ERROR: oc not found installed, nor downloaded" >&1 - return 1 - fi - export PATH="${oc_path}:${PATH}" - if ! oc version | grep -q "oc ${oc_version%.*}." ; then - echo "ERROR: something went wrong, oc located at ${oc_path}, but oc of version ${oc_version} not found in PATH ($PATH)" >&1 - return 1 - else - echo "PATH set correctly, binary oc found in version ${oc_version}: `which oc`" - fi -} - -# ct_os_get_latest_ver VERSION_PART_X -# -------------------- -# Returns full version (vX.Y.Z) from part of the version (X.Y) -# Arguments: vxy - X.Y part of the version -# Returns vX.Y.Z variant of the version -function ct_os_get_latest_ver(){ - local vxy="v$1" - for vz in {3..0} ; do - curl -sif "https://github.com/openshift/origin/releases/tag/${vxy}.${vz}" >/dev/null && echo "${vxy}.${vz}" && return 0 - done - echo "ERROR: version ${vxy} not found in https://github.com/openshift/origin/tags" >&2 - return 1 -} - -# ct_os_download_upstream_oc OC_VERSION OUTPUT_DIR -# -------------------- -# Downloads a particular version of openshift-origin-client-tools from -# github into specified output directory -# Arguments: oc_version - version of OSE (e.g. v3.7.2) -# Arguments: output_dir - output directory -function ct_os_download_upstream_oc() { - local oc_version=$1 - local output_dir=$2 - - # check whether we already have the binary in place - [ -x "${output_dir}/oc" ] && return 0 - - mkdir -p "${output_dir}" - # using html output instead of https://api.github.com/repos/openshift/origin/releases/tags/${oc_version}, - # because API is limited for number of queries if not authenticated - tarball=$(curl -si "https://github.com/openshift/origin/releases/tag/${oc_version}" | grep -o -e "openshift-origin-client-tools-${oc_version}-[a-f0-9]*-linux-64bit.tar.gz" | head -n 1) - - # download, unpack the binaries and then put them into output directory - echo "Downloading https://github.com/openshift/origin/releases/download/${oc_version}/${tarball} into ${output_dir}/" >&2 - curl -sL https://github.com/openshift/origin/releases/download/${oc_version}/"${tarball}" | tar -C "${output_dir}" -xz - mv -f "${output_dir}"/"${tarball%.tar.gz}"/* "${output_dir}/" - - rmdir "${output_dir}"/"${tarball%.tar.gz}" -} - - -# ct_os_test_s2i_app_func IMAGE APP CONTEXT_DIR CHECK_CMD [OC_ARGS] -# -------------------- -# Runs [image] and [app] in the openshift and optionally specifies env_params -# as environment variables to the image. Then check the container by arbitrary -# function given as argument (such an argument may include string, -# that will be replaced with actual IP). -# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) -# Arguments: app - url or local path to git repo with the application sources (compulsory) -# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory) -# Arguments: check_command - CMD line that checks whether the container works (compulsory; '' will be replaced with actual IP) -# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` -# command, typically environment variables (optional) -function ct_os_test_s2i_app_func() { - local image_name=${1} - local app=${2} - local context_dir=${3} - local check_command=${4} - local oc_args=${5:-} - local import_image=${6:-} - local image_name_no_namespace=${image_name##*/} - local service_name="${image_name_no_namespace}-testing" - local image_tagged="${image_name_no_namespace}:${VERSION}" - - if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then - echo "ERROR: ct_os_test_s2i_app_func() requires at least 4 arguments that cannot be emtpy." >&2 - return 1 - fi - - ct_os_new_project - # Create a specific imagestream tag for the image so that oc cannot use anything else - if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then - if [ -n "${import_image}" ] ; then - echo "Importing image ${import_image} as ${image_name}:${VERSION}" - oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm - else - echo "Uploading and importing image skipped." - fi - else - if [ -n "${import_image}" ] ; then - echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead." - fi - ct_os_upload_image "${image_name}" "${image_tagged}" - fi - - local app_param="${app}" - if [ -d "${app}" ] ; then - # for local directory, we need to copy the content, otherwise too smart os command - # pulls the git remote repository instead - app_param=$(ct_obtain_input "${app}") - fi - - ct_os_deploy_s2i_image "${image_tagged}" "${app_param}" \ - --context-dir="${context_dir}" \ - --name "${service_name}" \ - ${oc_args} - - if [ -d "${app}" ] ; then - # in order to avoid weird race seen sometimes, let's wait shortly - # before starting the build explicitly - sleep 5 - oc start-build "${service_name}" --from-dir="${app_param}" - fi - - ct_os_wait_pod_ready "${service_name}" 300 - - local ip=$(ct_os_get_service_ip "${service_name}") - local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") - - echo " Checking APP using $check_command_exp ..." - local result=0 - eval "$check_command_exp" || result=1 - - if [ $result -eq 0 ] ; then - echo " Check passed." - else - echo " Check failed." - fi - - ct_os_delete_project - return $result -} - -# ct_os_test_s2i_app IMAGE APP CONTEXT_DIR EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ] -# -------------------- -# Runs [image] and [app] in the openshift and optionally specifies env_params -# as environment variables to the image. Then check the http response. -# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory) -# Arguments: app - url or local path to git repo with the application sources (compulsory) -# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory) -# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory) -# Arguments: port - which port to use (optional; default: 8080) -# Arguments: protocol - which protocol to use (optional; default: http) -# Arguments: response_code - what http response code to expect (optional; default: 200) -# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` -# command, typically environment variables (optional) -function ct_os_test_s2i_app() { - local image_name=${1} - local app=${2} - local context_dir=${3} - local expected_output=${4} - local port=${5:-8080} - local protocol=${6:-http} - local response_code=${7:-200} - local oc_args=${8:-} - local import_image=${9:-} - - if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then - echo "ERROR: ct_os_test_s2i_app() requires at least 4 arguments that cannot be emtpy." >&2 - return 1 - fi - - ct_os_test_s2i_app_func "${image_name}" \ - "${app}" \ - "${context_dir}" \ - "ct_os_test_response_internal '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ - "${oc_args}" "${import_image}" -} - -# ct_os_test_template_app_func IMAGE APP IMAGE_IN_TEMPLATE CHECK_CMD [OC_ARGS] -# -------------------- -# Runs [image] and [app] in the openshift and optionally specifies env_params -# as environment variables to the image. Then check the container by arbitrary -# function given as argument (such an argument may include string, -# that will be replaced with actual IP). -# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) -# Arguments: template - url or local path to a template to use (compulsory) -# Arguments: name_in_template - image name used in the template -# Arguments: check_command - CMD line that checks whether the container works (compulsory; '' will be replaced with actual IP) -# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` -# command, typically environment variables (optional) -# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry, -# specify them in this parameter as "|", where "" is a full image name -# (including registry if needed) and "" is a tag under which the image should be available -# in the OpenShift registry. -function ct_os_test_template_app_func() { - local image_name=${1} - local template=${2} - local name_in_template=${3} - local check_command=${4} - local oc_args=${5:-} - local other_images=${6:-} - local import_image=${7:-} - - if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then - echo "ERROR: ct_os_test_template_app_func() requires at least 4 arguments that cannot be emtpy." >&2 - return 1 - fi - - local service_name="${name_in_template}-testing" - local image_tagged="${name_in_template}:${VERSION}" - - ct_os_new_project - - # Create a specific imagestream tag for the image so that oc cannot use anything else - if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then - if [ -n "${import_image}" ] ; then - echo "Importing image ${import_image} as ${image_name}:${VERSION}" - oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm - else - echo "Uploading and importing image skipped." - fi - else - if [ -n "${import_image}" ] ; then - echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead." - fi - ct_os_upload_image "${image_name}" "${image_tagged}" - - # upload also other images, that template might need (list of pairs in the format | - local images_tags_a - local i_t - for i_t in ${other_images} ; do - echo "${i_t}" - IFS='|' read -ra image_tag_a <<< "${i_t}" - docker pull "${image_tag_a[0]}" - ct_os_upload_image "${image_tag_a[0]}" "${image_tag_a[1]}" - done - fi - - local local_template=$(ct_obtain_input "${template}") - local namespace=${CT_NAMESPACE:-$(oc project -q)} - oc new-app ${local_template} \ - --name "${name_in_template}" \ - -p NAMESPACE="${namespace}" \ - ${oc_args} - - ct_os_wait_pod_ready "${service_name}" 300 - - local ip=$(ct_os_get_service_ip "${service_name}") - local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") - - echo " Checking APP using $check_command_exp ..." - local result=0 - eval "$check_command_exp" || result=1 - - if [ $result -eq 0 ] ; then - echo " Check passed." - else - echo " Check failed." - fi - - ct_os_delete_project - return $result -} - -# params: -# ct_os_test_template_app IMAGE APP IMAGE_IN_TEMPLATE EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ] -# -------------------- -# Runs [image] and [app] in the openshift and optionally specifies env_params -# as environment variables to the image. Then check the http response. -# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) -# Arguments: template - url or local path to a template to use (compulsory) -# Arguments: name_in_template - image name used in the template -# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory) -# Arguments: port - which port to use (optional; default: 8080) -# Arguments: protocol - which protocol to use (optional; default: http) -# Arguments: response_code - what http response code to expect (optional; default: 200) -# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app` -# command, typically environment variables (optional) -# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry, -# specify them in this parameter as "|", where "" is a full image name -# (including registry if needed) and "" is a tag under which the image should be available -# in the OpenShift registry. -function ct_os_test_template_app() { - local image_name=${1} - local template=${2} - local name_in_template=${3} - local expected_output=${4} - local port=${5:-8080} - local protocol=${6:-http} - local response_code=${7:-200} - local oc_args=${8:-} - local other_images=${9:-} - local import_image=${10:-} - - if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then - echo "ERROR: ct_os_test_template_app() requires at least 4 arguments that cannot be emtpy." >&2 - return 1 - fi - - ct_os_test_template_app_func "${image_name}" \ - "${template}" \ - "${name_in_template}" \ - "ct_os_test_response_internal '${protocol}://:${port}' '${response_code}' '${expected_output}'" \ - "${oc_args}" \ - "${other_images}" \ - "${import_image}" -} - -# ct_os_test_image_update IMAGE_NAME OLD_IMAGE ISTAG CHECK_FUNCTION OC_ARGS -# -------------------- -# Runs an image update test with [image] uploaded to [is] imagestream -# and checks the services using an arbitrary function provided in [check_function]. -# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory) -# Arguments: old_image - valid name of the image from the registry -# Arguments: istag - imagestream to upload the images into (compulsory) -# Arguments: check_function - command to be run to check functionality of created services (compulsory) -# Arguments: oc_args - arguments to use during oc new-app (compulsory) -ct_os_test_image_update() { - local image_name=$1; shift - local old_image=$1; shift - local istag=$1; shift - local check_function=$1; shift - local service_name=${image_name##*/} - local ip="" check_command_exp="" - - echo "Running image update test for: $image_name" - ct_os_new_project - - # Get current image from repository and create an imagestream - docker pull "$old_image:latest" 2>/dev/null - ct_os_upload_image "$old_image" "$istag" - - # Setup example application with curent image - oc new-app "$@" --name "$service_name" - ct_os_wait_pod_ready "$service_name" 60 - - # Check application output - ip=$(ct_os_get_service_ip "$service_name") - check_command_exp=${check_function///$ip} - ct_assert_cmd_success "$check_command_exp" - - # Tag built image into the imagestream and wait for rebuild - ct_os_upload_image "$image_name" "$istag" - ct_os_wait_pod_ready "${service_name}-2" 60 - - # Check application output - ip=$(ct_os_get_service_ip "$service_name") - check_command_exp=${check_function///$ip} - ct_assert_cmd_success "$check_command_exp" - - ct_os_delete_project -} - -# ct_os_deploy_cmd_image IMAGE_NAME -# -------------------- -# Runs a special command pod, a pod that does nothing, but includes utilities for testing. -# A typical usage is a mysql pod that includes mysql commandline, that we need for testing. -# Running commands inside this command pod is done via ct_os_cmd_image_run function. -# The pod is not run again if already running. -# Arguments: image_name - image to be used as a command pod -function ct_os_deploy_cmd_image() { - local image_name=${1} - oc get pod command-app &>/dev/null && echo "command POD already running" && return 0 - echo "command POD not running yet, will start one called command-app" - oc create -f - <" - local sleep_time=3 - local attempt=1 - local result=1 - local status - local response_code - local response_file=$(mktemp /tmp/ct_test_response_XXXXXX) - local util_image_name='python:3.6' - - ct_os_deploy_cmd_image "${util_image_name}" - - while [ ${attempt} -le ${max_attempts} ]; do - ct_os_cmd_image_run "curl --connect-timeout 10 -s -w '%{http_code}' '${url}'" >${response_file} && status=0 || status=1 - if [ ${status} -eq 0 ]; then - response_code=$(cat ${response_file} | tail -c 3) - if [ "${response_code}" -eq "${expected_code}" ]; then - result=0 - fi - cat ${response_file} | grep -qP -e "${body_regexp}" || result=1; - # Some services return 40x code until they are ready, so let's give them - # some chance and not end with failure right away - # Do not wait if we already have expected outcome though - if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then - break - fi - fi - attempt=$(( ${attempt} + 1 )) - sleep ${sleep_time} - done - rm -f ${response_file} - return ${result} -} - -# ct_os_get_image_from_pod -# ------------------------ -# Print image identifier from an existing pod to stdout -# Argument: pod_prefix - prefix or full name of the pod to get image from -ct_os_get_image_from_pod() { - local pod_prefix=$1 ; shift - local pod_name=$(ct_os_get_pod_name $pod_prefix) - oc get "po/${pod_name}" -o yaml | sed -ne 's/^\s*image:\s*\(.*\)\s*$/\1/ p' | head -1 -} - -# ct_os_check_cmd_internal -# ---------------- -# Runs a specified command, checks exit code and compares the output with expected regexp. -# That all is done inside an image in the cluster, so the function is used -# typically in clusters that are not accessible outside. -# The check is repeated until timeout. -# Argument: util_image_name - name of the image in the cluster that is used for running the cmd -# Argument: service_name - kubernetes' service name to work with (IP address is taken from this one) -# Argument: check_command - command that is run within the util_image_name container -# Argument: expected_content_match - regexp that must be in the output (use .* to ignore check) -# Argument: timeout - number of seconds to wait till the check succeeds -function ct_os_check_cmd_internal() { - local util_image_name=$1 ; shift - local service_name=$1 ; shift - local check_command=$1 ; shift - local expected_content_match=${1:-.*} ; shift - local timeout=${1:-60} ; shift || : - - : " Service ${service_name} check ..." - - local output - local ret - local ip=$(ct_os_get_service_ip "${service_name}") - local check_command_exp=$(echo "$check_command" | sed -e "s//$ip/g") - - ct_os_deploy_cmd_image $(ct_os_get_image_from_pod "${util_image_name}" | head -n 1) - SECONDS=0 - - echo -n "Waiting for ${service_name} service becoming ready ..." - while true ; do - output=$(ct_os_cmd_image_run "$check_command_exp") - ret=$? - echo "${output}" | grep -qe "${expected_content_match}" || ret=1 - if [ ${ret} -eq 0 ] ; then - echo " PASS" - return 0 - fi - echo -n "." - [ ${SECONDS} -gt ${timeout} ] && break - sleep 3 - done - echo " FAIL" - return 1 -} - diff --git a/test/test-lib.sh b/test/test-lib.sh deleted file mode 100644 index e372870..0000000 --- a/test/test-lib.sh +++ /dev/null @@ -1,507 +0,0 @@ -# -# Test a container image. -# -# Always use sourced from a specific container testfile -# -# reguires definition of CID_FILE_DIR -# CID_FILE_DIR=$(mktemp --suffix=_test_cidfiles -d) -# reguires definition of TEST_LIST -# TEST_LIST="\ -# ctest_container_creation -# ctest_doc_content" - -# Container CI tests -# abbreviated as "ct" - -# may be redefined in the specific container testfile -EXPECTED_EXIT_CODE=0 - -# ct_cleanup -# -------------------- -# Cleans up containers used during tests. Stops and removes all containers -# referenced by cid_files in CID_FILE_DIR. Dumps logs if a container exited -# unexpectedly. Removes the cid_files and CID_FILE_DIR as well. -# Uses: $CID_FILE_DIR - path to directory containing cid_files -# Uses: $EXPECTED_EXIT_CODE - expected container exit code -function ct_cleanup() { - for cid_file in $CID_FILE_DIR/* ; do - local container=$(cat $cid_file) - - : "Stopping and removing container $container..." - docker stop $container - exit_status=$(docker inspect -f '{{.State.ExitCode}}' $container) - if [ "$exit_status" != "$EXPECTED_EXIT_CODE" ]; then - : "Dumping logs for $container" - docker logs $container - fi - docker rm -v $container - rm $cid_file - done - rmdir $CID_FILE_DIR - : "Done." -} - -# ct_enable_cleanup -# -------------------- -# Enables automatic container cleanup after tests. -function ct_enable_cleanup() { - trap ct_cleanup EXIT SIGINT -} - -# ct_get_cid [name] -# -------------------- -# Prints container id from cid_file based on the name of the file. -# Argument: name - name of cid_file where the container id will be stored -# Uses: $CID_FILE_DIR - path to directory containing cid_files -function ct_get_cid() { - local name="$1" ; shift || return 1 - echo $(cat "$CID_FILE_DIR/$name") -} - -# ct_get_cip [id] -# -------------------- -# Prints container ip address based on the container id. -# Argument: id - container id -function ct_get_cip() { - local id="$1" ; shift - docker inspect --format='{{.NetworkSettings.IPAddress}}' $(ct_get_cid "$id") -} - -# ct_wait_for_cid [cid_file] -# -------------------- -# Holds the execution until the cid_file is created. Usually run after container -# creation. -# Argument: cid_file - name of the cid_file that should be created -function ct_wait_for_cid() { - local cid_file=$1 - local max_attempts=10 - local sleep_time=1 - local attempt=1 - local result=1 - while [ $attempt -le $max_attempts ]; do - [ -f $cid_file ] && [ -s $cid_file ] && return 0 - : "Waiting for container start..." - attempt=$(( $attempt + 1 )) - sleep $sleep_time - done - return 1 -} - -# ct_assert_container_creation_fails [container_args] -# -------------------- -# The invocation of docker run should fail based on invalid container_args -# passed to the function. Returns 0 when container fails to start properly. -# Argument: container_args - all arguments are passed directly to dokcer run -# Uses: $CID_FILE_DIR - path to directory containing cid_files -function ct_assert_container_creation_fails() { - local ret=0 - local max_attempts=10 - local attempt=1 - local cid_file=assert - set +e - local old_container_args="${CONTAINER_ARGS-}" - CONTAINER_ARGS="$@" - ct_create_container $cid_file - if [ $? -eq 0 ]; then - local cid=$(ct_get_cid $cid_file) - - while [ "$(docker inspect -f '{{.State.Running}}' $cid)" == "true" ] ; do - sleep 2 - attempt=$(( $attempt + 1 )) - if [ $attempt -gt $max_attempts ]; then - docker stop $cid - ret=1 - break - fi - done - exit_status=$(docker inspect -f '{{.State.ExitCode}}' $cid) - if [ "$exit_status" == "0" ]; then - ret=1 - fi - docker rm -v $cid - rm $CID_FILE_DIR/$cid_file - fi - [ ! -z $old_container_args ] && CONTAINER_ARGS="$old_container_args" - set -e - return $ret -} - -# ct_create_container [name, command] -# -------------------- -# Creates a container using the IMAGE_NAME and CONTAINER_ARGS variables. Also -# stores the container id to a cid_file located in the CID_FILE_DIR, and waits -# for the creation of the file. -# Argument: name - name of cid_file where the container id will be stored -# Argument: command - optional command to be executed in the container -# Uses: $CID_FILE_DIR - path to directory containing cid_files -# Uses: $CONTAINER_ARGS - optional arguments passed directly to docker run -# Uses: $IMAGE_NAME - name of the image being tested -function ct_create_container() { - local cid_file="$CID_FILE_DIR/$1" ; shift - # create container with a cidfile in a directory for cleanup - docker run --cidfile="$cid_file" -d ${CONTAINER_ARGS:-} $IMAGE_NAME "$@" - ct_wait_for_cid $cid_file || return 1 - : "Created container $(cat $cid_file)" -} - -# ct_scl_usage_old [name, command, expected] -# -------------------- -# Tests three ways of running the SCL, by looking for an expected string -# in the output of the command -# Argument: name - name of cid_file where the container id will be stored -# Argument: command - executed inside the container -# Argument: expected - string that is expected to be in the command output -# Uses: $CID_FILE_DIR - path to directory containing cid_files -# Uses: $IMAGE_NAME - name of the image being tested -function ct_scl_usage_old() { - local name="$1" - local command="$2" - local expected="$3" - local out="" - : " Testing the image SCL enable" - out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${command}") - if ! echo "${out}" | grep -q "${expected}"; then - echo "ERROR[/bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2 - return 1 - fi - out=$(docker exec $(ct_get_cid $name) /bin/bash -c "${command}" 2>&1) - if ! echo "${out}" | grep -q "${expected}"; then - echo "ERROR[exec /bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2 - return 1 - fi - out=$(docker exec $(ct_get_cid $name) /bin/sh -ic "${command}" 2>&1) - if ! echo "${out}" | grep -q "${expected}"; then - echo "ERROR[exec /bin/sh -ic "${command}"] Expected '${expected}', got '${out}'" >&2 - return 1 - fi -} - -# ct_doc_content_old [strings] -# -------------------- -# Looks for occurence of stirngs in the documentation files and checks -# the format of the files. Files examined: help.1 -# Argument: strings - strings expected to appear in the documentation -# Uses: $IMAGE_NAME - name of the image being tested -function ct_doc_content_old() { - local tmpdir=$(mktemp -d) - local f - : " Testing documentation in the container image" - # Extract the help files from the container - for f in help.1 ; do - docker run --rm ${IMAGE_NAME} /bin/bash -c "cat /${f}" >${tmpdir}/$(basename ${f}) - # Check whether the files contain some important information - for term in $@ ; do - if ! cat ${tmpdir}/$(basename ${f}) | grep -F -q -e "${term}" ; then - echo "ERROR: File /${f} does not include '${term}'." >&2 - return 1 - fi - done - # Check whether the files use the correct format - for term in TH PP SH ; do - if ! grep -q "^\.${term}" ${tmpdir}/help.1 ; then - echo "ERROR: /help.1 is probably not in troff or groff format, since '${term}' is missing." >&2 - return 1 - fi - done - done - : " Success!" -} - - -# ct_npm_works -# -------------------- -# Checks existance of the npm tool and runs it. -function ct_npm_works() { - local tmpdir=$(mktemp -d) - : " Testing npm in the container image" - docker run --rm ${IMAGE_NAME} /bin/bash -c "npm --version" >${tmpdir}/version - - if [ $? -ne 0 ] ; then - echo "ERROR: 'npm --version' does not work inside the image ${IMAGE_NAME}." >&2 - return 1 - fi - - docker run --rm ${IMAGE_NAME} /bin/bash -c "npm install jquery && test -f node_modules/jquery/src/jquery.js" - if [ $? -ne 0 ] ; then - echo "ERROR: npm could not install jquery inside the image ${IMAGE_NAME}." >&2 - return 1 - fi - - : " Success!" -} - - -# ct_path_append PATH_VARNAME DIRECTORY -# ------------------------------------- -# Append DIRECTORY to VARIABLE of name PATH_VARNAME, the VARIABLE must consist -# of colon-separated list of directories. -ct_path_append () -{ - if eval "test -n \"\${$1-}\""; then - eval "$1=\$2:\$$1" - else - eval "$1=\$2" - fi -} - - -# ct_path_foreach PATH ACTION [ARGS ...] -# -------------------------------------- -# For each DIR in PATH execute ACTION (path is colon separated list of -# directories). The particular calls to ACTION will look like -# '$ ACTION directory [ARGS ...]' -ct_path_foreach () -{ - local dir dirlist action save_IFS - save_IFS=$IFS - IFS=: - dirlist=$1 - action=$2 - shift 2 - for dir in $dirlist; do "$action" "$dir" "$@" ; done - IFS=$save_IFS -} - - -# ct_run_test_list -# -------------------- -# Execute the tests specified by TEST_LIST -# Uses: $TEST_LIST - list of test names -function ct_run_test_list() { - for test_case in $TEST_LIST; do - : "Running test $test_case" - [ -f test/$test_case ] && source test/$test_case - [ -f ../test/$test_case ] && source ../test/$test_case - $test_case - done; -} - -# ct_gen_self_signed_cert_pem -# --------------------------- -# Generates a self-signed PEM certificate pair into specified directory. -# Argument: output_dir - output directory path -# Argument: base_name - base name of the certificate files -# Resulted files will be those: -# /-cert-selfsigned.pem -- public PEM cert -# /-key.pem -- PEM private key -ct_gen_self_signed_cert_pem() { - local output_dir=$1 ; shift - local base_name=$1 ; shift - mkdir -p ${output_dir} - openssl req -newkey rsa:2048 -nodes -keyout ${output_dir}/${base_name}-key.pem -subj '/C=GB/ST=Berkshire/L=Newbury/O=My Server Company' > ${base_name}-req.pem - openssl req -new -x509 -nodes -key ${output_dir}/${base_name}-key.pem -batch > ${output_dir}/${base_name}-cert-selfsigned.pem -} - -# ct_obtain_input FILE|DIR|URL -# -------------------- -# Either copies a file or a directory to a tmp location for local copies, or -# downloads the file from remote location. -# Resulted file path is printed, so it can be later used by calling function. -# Arguments: input - local file, directory or remote URL -function ct_obtain_input() { - local input=$1 - local extension="${input##*.}" - - # Try to use same extension for the temporary file if possible - [[ "${extension}" =~ ^[a-z0-9]*$ ]] && extension=".${extension}" || extension="" - - local output=$(mktemp "/var/tmp/test-input-XXXXXX$extension") - if [ -f "${input}" ] ; then - cp -f "${input}" "${output}" - elif [ -d "${input}" ] ; then - rm -f "${output}" - cp -r -LH "${input}" "${output}" - elif echo "${input}" | grep -qe '^http\(s\)\?://' ; then - curl "${input}" > "${output}" - else - echo "ERROR: file type not known: ${input}" >&2 - return 1 - fi - echo "${output}" -} - -# ct_test_response -# ---------------- -# Perform GET request to the application container, checks output with -# a reg-exp and HTTP response code. -# Argument: url - request URL path -# Argument: expected_code - expected HTTP response code -# Argument: body_regexp - PCRE regular expression that must match the response body -# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between -# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10) -ct_test_response() { - local url="$1" - local expected_code="$2" - local body_regexp="$3" - local max_attempts=${4:-20} - local ignore_error_attempts=${5:-10} - - : " Testing the HTTP(S) response for <${url}>" - local sleep_time=3 - local attempt=1 - local result=1 - local status - local response_code - local response_file=$(mktemp /tmp/ct_test_response_XXXXXX) - while [ ${attempt} -le ${max_attempts} ]; do - curl --connect-timeout 10 -s -w '%{http_code}' "${url}" >${response_file} && status=0 || status=1 - if [ ${status} -eq 0 ]; then - response_code=$(cat ${response_file} | tail -c 3) - if [ "${response_code}" -eq "${expected_code}" ]; then - result=0 - fi - cat ${response_file} | grep -qP -e "${body_regexp}" || result=1; - # Some services return 40x code until they are ready, so let's give them - # some chance and not end with failure right away - # Do not wait if we already have expected outcome though - if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then - break - fi - fi - attempt=$(( ${attempt} + 1 )) - sleep ${sleep_time} - done - rm -f ${response_file} - return ${result} -} - -# ct_registry_from_os OS -# ---------------- -# Transform operating system string [os] into registry url -# Argument: OS - string containing the os version -ct_registry_from_os() { - local registry="" - case $1 in - rhel7) - registry=registry.access.redhat.com - ;; - *) - registry=docker.io - ;; - esac - echo "$registry" -} - -# ct_assert_cmd_success CMD -# ---------------- -# Evaluates [cmd] and fails if it does not succeed. -# Argument: CMD - Command to be run -function ct_assert_cmd_success() { - echo "Checking '$*' for success ..." - if ! eval "$@" &>/dev/null; then - echo " FAIL" - return 1 - fi - echo " PASS" - return 0 -} - -# ct_assert_cmd_failure CMD -# ---------------- -# Evaluates [cmd] and fails if it succeeds. -# Argument: CMD - Command to be run -function ct_assert_cmd_failure() { - echo "Checking '$*' for failure ..." - if eval "$@" &>/dev/null; then - echo " FAIL" - return 1 - fi - echo " PASS" - return 0 -} - - -# ct_random_string [LENGTH=10] -# ---------------------------- -# Generate pseudorandom alphanumeric string of LENGTH bytes, the -# default length is 10. The string is printed on stdout. -ct_random_string() -( - export LC_ALL=C - dd if=/dev/urandom count=1 bs=10k 2>/dev/null \ - | tr -dc 'a-z0-9' \ - | fold -w "${1-10}" \ - | head -n 1 -) - -# ct_s2i_usage IMG_NAME [S2I_ARGS] -# ---------------------------- -# Create a container and run the usage script inside -# Argument: IMG_NAME - name of the image to be used for the container run -# Argument: S2I_ARGS - Additional list of source-to-image arguments, currently unused. -ct_s2i_usage() -{ - local img_name=$1; shift - local s2i_args="$*"; - local usage_command="/usr/libexec/s2i/usage" - docker run --rm "$img_name" bash -c "$usage_command" -} - -# ct_s2i_build_as_df APP_PATH SRC_IMAGE DST_IMAGE [S2I_ARGS] -# ---------------------------- -# Create a new s2i app image from local sources in a similar way as source-to-image would have used. -# Argument: APP_PATH - local path to the app sources to be used in the test -# Argument: SRC_IMAGE - image to be used as a base for the s2i build -# Argument: DST_IMAGE - image name to be used during the tagging of the s2i build result -# Argument: S2I_ARGS - Additional list of source-to-image arguments. -# Only used to check for pull-policy=never and environment variable definitions. -ct_s2i_build_as_df() -{ - local app_path=$1; shift - local src_image=$1; shift - local dst_image=$1; shift - local s2i_args="$*"; - local local_app=upload/src/ - local local_scripts=upload/scripts/ - local user_id= - local df_name= - local tmpdir= - # Use /tmp to not pollute cwd - tmpdir=$(mktemp -d) - df_name=$(mktemp -p "$tmpdir" Dockerfile.XXXX) - pushd "$tmpdir" - # Check if the image is available locally and try to pull it if it is not - docker images "$src_image" &>/dev/null || echo "$s2i_args" | grep -q "pull-policy=never" || docker pull "$src_image" - user_id=$(docker inspect -f "{{.ContainerConfig.User}}" "$src_image") - # Strip file:// from APP_PATH and copy its contents into current context - mkdir -p "$local_app" - cp -r "${app_path/file:\/\//}/." "$local_app" - [ -d "$local_app/.s2i/bin/" ] && mv "$local_app/.s2i/bin" "$local_scripts" - # Create a Dockerfile named df_name and fill it with proper content - #FIXME: Some commands could be combined into a single layer but not sure if worth the trouble for testing purposes - cat <"$df_name" -FROM $src_image -LABEL "io.openshift.s2i.build.image"="$src_image" \\ - "io.openshift.s2i.build.source-location"="$app_path" -USER root -COPY $local_app /tmp/src -EOF - [ -d "$local_scripts" ] && echo "COPY $local_scripts /tmp/scripts" >> "$df_name" && - echo "RUN chown -R $user_id:0 /tmp/scripts" >>"$df_name" - echo "RUN chown -R $user_id:0 /tmp/src" >>"$df_name" - # Check for custom environment variables inside .s2i/ folder - if [ -e "$local_app/.s2i/environment" ]; then - # Remove any comments and add the contents as ENV commands to the Dockerfile - sed '/^\s*#.*$/d' "$local_app/.s2i/environment" | while read -r line; do - echo "ENV $line" >>"$df_name" - done - fi - # Filter out env var definitions from $s2i_args and create Dockerfile ENV commands out of them - echo "$s2i_args" | grep -o -e '\(-e\|--env\)[[:space:]=]\S*=\S*' | sed -e 's/-e /ENV /' -e 's/--env[ =]/ENV /' >>"$df_name" - echo "USER $user_id" >>"$df_name" - # If exists, run the custom assemble script, else default to /usr/libexec/s2i/assemble - if [ -x "$local_scripts/assemble" ]; then - echo "RUN /tmp/scripts/assemble" >>"$df_name" - else - echo "RUN /usr/libexec/s2i/assemble" >>"$df_name" - fi - # If exists, set the custom run script as CMD, else default to /usr/libexec/s2i/run - if [ -x "$local_scripts/run" ]; then - echo "CMD /tmp/scripts/run" >>"$df_name" - else - echo "CMD /usr/libexec/s2i/run" >>"$df_name" - fi - # Run the build and tag the result - docker build -f "$df_name" -t "$dst_image" . - popd -}