RPM uses a wrong file in the config, fix it in the container

Related: https://bugzilla.redhat.com/show_bug.cgi?id=2092356
This commit is contained in:
phracek 2022-06-09 08:34:45 +00:00
commit 55915bde9d
43 changed files with 6161 additions and 0 deletions

1
7.4 Symbolic link
View file

@ -0,0 +1 @@
.

73
Dockerfile Normal file
View file

@ -0,0 +1,73 @@
FROM registry.fedoraproject.org/f34/s2i-base:latest
# This image provides an Apache+PHP environment for running PHP
# applications.
EXPOSE 8080
EXPOSE 8443
ENV PHP_VERSION=7.4 \
PATH=$PATH:/usr/bin
ENV SUMMARY="Platform for building and running PHP $PHP_VERSION applications" \
DESCRIPTION="PHP $PHP_VERSION available as container is a base platform for \
building and running various PHP $PHP_VERSION applications and frameworks. \
PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers \
to write dynamically generated web pages. PHP also offers built-in database integration \
for several commercial and non-commercial database management systems, so writing \
a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding \
is probably as a replacement for CGI scripts."
ENV NAME=php \
VERSION=0 \
RELEASE=1 \
ARCH=x86_64
LABEL summary="$SUMMARY" \
description="$DESCRIPTION" \
io.k8s.description="$DESCRIPTION" \
io.k8s.display-name="Apache 2.4 with PHP $PHP_VERSION" \
io.openshift.expose-services="8080:http" \
io.openshift.tags="builder,php" \
name="$FGC/$NAME" \
com.redhat.component="$NAME" \
version="$VERSION" \
usage="s2i build https://github.com/sclorg/s2i-php-container.git --context-dir=/$PHP_VERSION/test/test-app $FGC/$NAME sample-server" \
maintainer="SoftwareCollections.org <sclorg@redhat.com>"
# Install Apache httpd and PHP
RUN INSTALL_PKGS="php php-mysqlnd php-bcmath php-json \
php-gd php-intl php-ldap php-mbstring php-pdo \
php-process php-soap php-opcache php-xml \
php-gmp php-pecl-apcu mod_ssl hostname" && \
yum install -y --setopt=tsflags=nodocs $INSTALL_PKGS --nogpgcheck && \
rpm -V $INSTALL_PKGS && \
yum -y clean all --enablerepo='*'
ENV PHP_CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/php/ \
APP_DATA=${APP_ROOT}/src \
PHP_DEFAULT_INCLUDE_PATH=/usr/share/pear \
PHP_SYSCONF_PATH=/etc/ \
PHP_HTTPD_CONF_FILE=php.conf \
HTTPD_CONFIGURATION_PATH=${APP_ROOT}/etc/conf.d \
HTTPD_MAIN_CONF_PATH=/etc/httpd/conf \
HTTPD_MAIN_CONF_D_PATH=/etc/httpd/conf.d \
HTTPD_MODULES_CONF_D_PATH=/etc/httpd/conf.modules.d \
HTTPD_VAR_RUN=/var/run/httpd \
HTTPD_DATA_PATH=/var/www \
HTTPD_DATA_ORIG_PATH=/var/www \
HTTPD_VAR_PATH=/var
# Copy the S2I scripts from the specific language image to $STI_SCRIPTS_PATH
COPY ./s2i/bin/ $STI_SCRIPTS_PATH
# Copy extra files to the image.
COPY ./root/ /
# Reset permissions of filesystem to default values
RUN /usr/libexec/container-setup && rpm-file-permissions
USER 1001
# Set the default CMD to print the usage of the language image
CMD $STI_SCRIPTS_PATH/usage

1
Dockerfile.fedora Symbolic link
View file

@ -0,0 +1 @@
Dockerfile

330
README.md Normal file
View file

@ -0,0 +1,330 @@
PHP 7.4 container image
=======================
This container image includes PHP 7.4 as a [S2I](https://github.com/openshift/source-to-image) base image for your PHP 7.4 applications.
Users can choose between RHEL and CentOS based builder images.
The RHEL UBI images are available in the [Red Hat Container Catalog](https://access.redhat.com/containers/),
the CentOS images are available on [Quay.io](https://quay.io/organization/centos7),
and the Fedora images are available in [Fedora Registry](https://registry.fedoraproject.org/).
The resulting image can be run using [podman](https://github.com/containers/libpod).
Note: while the examples in this README are calling `podman`, you can replace any such calls by `docker` with the same arguments
Description
-----------
PHP 7.4 available as container is a base platform for
building and running various PHP 7.4 applications and frameworks.
PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers
to write dynamically generated web pages. PHP also offers built-in database integration
for several commercial and non-commercial database management systems, so writing
a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding
is probably as a replacement for CGI scripts.
This container image includes an npm utility, so users can use it to install JavaScript
modules for their web applications. There is no guarantee for any specific npm or nodejs
version, that is included in the image; those versions can be changed anytime and
the nodejs itself is included just to make the npm work.
Usage in OpenShift
------------------
In this example, we will assume that you are using the `ubi8/php-74` image, available via `php:74` imagestream tag in Openshift.
To build a simple [cakephp-sample-app](https://github.com/sclorg/cakephp-ex.git) application in Openshift:
```
oc new-app php:7.4~https://github.com/sclorg/cakephp-ex.git
```
To access the application:
```
$ oc get pods
$ oc exec <pod> -- curl 127.0.0.1:8080
```
**Accessing the application:**
```
$ curl 127.0.0.1:8080
```
Source-to-Image framework and scripts
-------------------------------------
This image supports the [Source-to-Image](https://docs.openshift.com/container-platform/3.11/creating_images/s2i.html)
(S2I) strategy in OpenShift. The Source-to-Image is an OpenShift framework
which makes it easy to write images that take application source code as
an input, use a builder image like this PHP container image, and produce
a new image that runs the assembled application as an output.
To support the Source-to-Image framework, important scripts are included in the builder image:
* The `/usr/libexec/s2i/assemble` script inside the image is run to produce a new image with the application artifacts. The script takes sources of a given application and places them into appropriate directories inside the image. It utilizes some common patterns in PHP application development (see the **Environment variables** section below).
* The `/usr/libexec/s2i/run` script is set as the default command in the resulting container image (the new image with the application artifacts). It runs `httpd` with PHP support enabled.
Building an application using a Dockerfile
------------------------------------------
Compared to the Source-to-Image strategy, using a Dockerfile is a more
flexible way to build a PHP container image with an application.
Use a Dockerfile when Source-to-Image is not sufficiently flexible for you or
when you build the image outside of the OpenShift environment.
To use the PHP image in a Dockerfile, follow these steps:
#### 1. Pull a base builder image to build on
```
podman pull ubi8/php-74
```
An UBI image `ubi8/php-74` is used in this example. This image is usable and freely redistributable under the terms of the UBI End User License Agreement (EULA). See more about UBI at [UBI FAQ](https://developers.redhat.com/articles/ubi-faq).
#### 2. Pull an application code
An example application available at https://github.com/sclorg/cakephp-ex.git is used here. Feel free to clone the repository for further experiments.
```
git clone https://github.com/sclorg/cakephp-ex.git app-src
```
#### 3. Prepare an application inside a container
This step usually consists of at least these parts:
* putting the application source into the container
* installing the dependencies
* setting the default command in the resulting image
For all these three parts, users can either setup all manually and use commands `./composer.phar` or other commands explicitly in the Dockerfile ([3.1.](#31-to-use-your-own-setup-create-a-dockerfile-with-this-content)), or users can use the Source-to-Image scripts inside the image ([3.2.](#32-to-use-the-source-to-image-scripts-and-build-an-image-using-a-dockerfile-create-a-dockerfile-with-this-content); see more about these scripts in the section "Source-to-Image framework and scripts" above), that already know how to set-up and run some common PHP applications.
##### 3.1. To use your own setup, create a Dockerfile with this content:
```
FROM ubi8/php-74
# Add application sources
ADD app-src .
# Install the dependencies
RUN TEMPFILE=$(mktemp) && \
curl -o "$TEMPFILE" "https://getcomposer.org/installer" && \
php <"$TEMPFILE" && \
./composer.phar install --no-interaction --no-ansi --optimize-autoloader
# Run script uses standard ways to configure the PHP application
# and execs httpd -D FOREGROUND at the end
# See more in <version>/s2i/bin/run in this repository.
# Shortly what the run script does: The httpd daemon and php needs to be
# configured, so this script prepares the configuration based on the container
# parameters (e.g. available memory) and puts the configuration files into
# the approriate places.
# This can obviously be done differently, and in that case, the final CMD
# should be set to "CMD httpd -D FOREGROUND" instead.
CMD /usr/libexec/s2i/run
```
##### 3.2. To use the Source-to-Image scripts and build an image using a Dockerfile, create a Dockerfile with this content:
```
FROM ubi8/php-74
# Add application sources to a directory that the assemble script expects them
# and set permissions so that the container runs without root access
USER 0
ADD app-src /tmp/src
RUN chown -R 1001:0 /tmp/src
USER 1001
# Install the dependencies
RUN /usr/libexec/s2i/assemble
# Set the default command for the resulting image
CMD /usr/libexec/s2i/run
```
#### 4. Build a new image from a Dockerfile prepared in the previous step
```
podman build -t cakephp-app .
```
#### 5. Run the resulting image with the final application
```
podman run -d cakephp-app
```
Environment variables for Source-to-Image
-----------------------------------------
To set these environment variables, you can place them as a key value pair into a `.s2i/environment`
file inside your source code repository.
The following environment variables set their equivalent property value in the php.ini file:
* **ERROR_REPORTING**
* Informs PHP of which errors, warnings and notices you would like it to take action for
* Default: E_ALL & ~E_NOTICE
* **DISPLAY_ERRORS**
* Controls whether or not and where PHP will output errors, notices and warnings
* Default: ON
* **DISPLAY_STARTUP_ERRORS**
* Cause display errors which occur during PHP's startup sequence to be handled separately from display errors
* Default: OFF
* **TRACK_ERRORS**
* Store the last error/warning message in $php_errormsg (boolean)
* Default: OFF
* **HTML_ERRORS**
* Link errors to documentation related to the error
* Default: ON
* **INCLUDE_PATH**
* Path for PHP source files
* Default: .:/opt/app-root/src:/opt/rh/rh-php74/root/usr/share/pear (EL7)
* Default: .:/opt/app-root/src:/usr/share/pear (EL8, Fedora)
* **PHP_MEMORY_LIMIT**
* Memory Limit
* Default: 128M
* **SESSION_NAME**
* Name of the session
* Default: PHPSESSID
* **SESSION_HANDLER**
* Method for saving sessions
* Default: files
* **SESSION_PATH**
* Location for session data files
* Default: /tmp/sessions
* **SESSION_COOKIE_DOMAIN**
* The domain for which the cookie is valid.
* Default:
* **SESSION_COOKIE_HTTPONLY**
* Whether or not to add the httpOnly flag to the cookie
* Default: 0
* **SESSION_COOKIE_SECURE**
* Specifies whether cookies should only be sent over secure connections.
* Default: Off
* **SHORT_OPEN_TAG**
* Determines whether or not PHP will recognize code between <? and ?> tags
* Default: OFF
* **DOCUMENTROOT**
* Path that defines the DocumentRoot for your application (ie. /public)
* Default: /
The following environment variables set their equivalent property value in the opcache.ini file:
* **OPCACHE_MEMORY_CONSUMPTION**
* The OPcache shared memory storage size in megabytes
* Default: 128
* **OPCACHE_REVALIDATE_FREQ**
* How often to check script timestamps for updates, in seconds. 0 will result in OPcache checking for updates on every request.
* Default: 2
* **OPCACHE_MAX_FILES**
* The maximum number of keys (scripts) in the OPcache hash table. Only numbers between 200 and 1000000 are allowed.
* Default: 4000
You can also override the entire directory used to load the PHP configuration by setting:
* **PHPRC**
* Sets the path to the php.ini file
* **PHP_INI_SCAN_DIR**
* Path to scan for additional ini configuration files
You can override the Apache [MPM prefork](https://httpd.apache.org/docs/2.4/mod/mpm_common.html)
settings to increase the performance for of the PHP application. In case you set
some Cgroup limits, the image will attempt to automatically set the
optimal values. You can override this at any time by specifying the values
yourself:
* **HTTPD_START_SERVERS**
* The [StartServers](https://httpd.apache.org/docs/2.4/mod/mpm_common.html#startservers)
directive sets the number of child server processes created on startup.
* Default: 8
* **HTTPD_MAX_REQUEST_WORKERS**
* The [MaxRequestWorkers](https://httpd.apache.org/docs/2.4/mod/mpm_common.html#maxrequestworkers)
directive sets the limit on the number of simultaneous requests that will be served.
* `MaxRequestWorkers` was called `MaxClients` before version httpd 2.3.13.
* Default: 256 (this is automatically tuned by setting Cgroup limits for the container using this formula:
`TOTAL_MEMORY / 15MB`. The 15MB is average size of a single httpd process.
* **HTTPD_MAX_REQUESTS_PER_CHILD**
* The [MaxRequestsPerChild](http://httpd.apache.org/docs/current/mod/mpm_common.html#maxconnectionsperchild)
directive sets the limit on the number of connections that an individual child server process will handle.
After `MaxRequestsPerChild` connections, the child process will die. If `MaxRequestsPerChild` is 0, then the process will never expire.
* Setting `MaxRequestsPerChild` to a non-zero value limits the amount of memory that a process can consume by (accidental) memory leakage.
* `MaxRequestsPerChild` is called `MaxConnectionsPerChild` in Apache HTTP 2.3.9 and later.
* Default: 4000
* **HTTPD_MAX_KEEPALIVE_REQUESTS**
* The [MaxKeepAliveRequests](http://httpd.apache.org/docs/current/mod/core.html#maxkeepaliverequests)
directive limits the number of requests allowed per connection when `KeepAlive` is on. If it is set to 0, unlimited requests will be allowed.
* Default: 100
You can use a custom composer repository mirror URL to download packages instead of the default 'packagist.org':
* **COMPOSER_MIRROR**
* Adds a custom composer repository mirror URL to composer configuration. Note: This only affects packages listed in composer.json.
* **COMPOSER_INSTALLER**
* Overrides the default URL for downloading Composer of https://getcomposer.org/installer. Useful in disconnected environments.
* **COMPOSER_VERSION**
* Overrides the default composer version to install (1, 2, preview, snapshot or version="x.y.z")
* **COMPOSER_ARGS**
* Adds extra arguments to the `composer install` command line (for example `--no-dev`).
Source repository layout
------------------------
You do not need to change anything in your existing PHP project's repository.
However, if these files exist they will affect the behavior of the build process:
* **composer.json**
List of dependencies to be installed with `composer`. The format is documented
[here](https://getcomposer.org/doc/04-schema.md).
* **.htaccess**
In case the **DocumentRoot** of the application is nested within the source directory `/opt/app-root/src`,
users can provide their own Apache **.htaccess** file. This allows the overriding of Apache's behavior and
specifies how application requests should be handled. The **.htaccess** file needs to be located at the root
of the application source.
Hot deploy
----------
In order to immediately pick up changes made in your application source code, you need to run your built image with the `OPCACHE_REVALIDATE_FREQ=0` environment variable passed to [Podman](https://github.com/containers/libpod) `-e` run flag:
```
$ podman run -e OPCACHE_REVALIDATE_FREQ=0 -p 8080:8080 php-app
```
To change your source code in running container, use Podman's [exec](https://github.com/containers/libpod)) command:
```
podman exec -it <CONTAINER_ID> /bin/bash
```
After you [Podman exec](https://github.com/containers/libpod) into the running container, your current directory is set
to `/opt/app-root/src`, where the source code is located.
Extending image
---------------
Not only content, but also startup scripts and configuration of the image can
be extended using [source-to-image](https://github.com/openshift/source-to-image).
The structure of the application can look like this:
| Folder name | Description |
|-------------------|----------------------------|
| `./httpd-cfg` | Can contain additional Apache configuration files (`*.conf`)|
| `./httpd-ssl` | Can contain own SSL certificate (in `certs/` subdirectory) and key (in `private/` subdirectory)|
| `./php-pre-start`| Can contain shell scripts (`*.sh`) that are sourced before `httpd` is started|
| `./php-post-assemble`| Can contain shell scripts (`*.sh`) that are sourced at the end of `assemble` script|
| `./` | Application source code |
See also
--------
Dockerfile and other sources are available on https://github.com/sclorg/s2i-php-container.
In that repository you also can find another versions of Python environment Dockerfiles.
Dockerfile for CentOS is called `Dockerfile`, Dockerfile for RHEL7 is called `Dockerfile.rhel7`,
for RHEL8 it's `Dockerfile.rhel8` and the Fedora Dockerfile is called Dockerfile.fedora.
Security Implications
---------------------
-p 8080:8080
Opens container port 8080 and maps it to the same port on the Host.

1
help.md Symbolic link
View file

@ -0,0 +1 @@
README.md

View file

@ -0,0 +1,114 @@
; Enable Zend OPcache extension module
zend_extension=opcache.so
; Determines if Zend OPCache is enabled
opcache.enable=1
; Determines if Zend OPCache is enabled for the CLI version of PHP
;opcache.enable_cli=0
; The OPcache shared memory storage size.
opcache.memory_consumption=${OPCACHE_MEMORY_CONSUMPTION}
; The amount of memory for interned strings in Mbytes.
opcache.interned_strings_buffer=8
; The maximum number of keys (scripts) in the OPcache hash table.
; Only numbers between 200 and 1000000 are allowed.
opcache.max_accelerated_files=${OPCACHE_MAX_FILES}
; The maximum percentage of "wasted" memory until a restart is scheduled.
;opcache.max_wasted_percentage=5
; When this directive is enabled, the OPcache appends the current working
; directory to the script key, thus eliminating possible collisions between
; files with the same name (basename). Disabling the directive improves
; performance, but may break existing applications.
;opcache.use_cwd=1
; When disabled, you must reset the OPcache manually or restart the
; webserver for changes to the filesystem to take effect.
;opcache.validate_timestamps=1
; How often (in seconds) to check file timestamps for changes to the shared
; memory storage allocation. ("1" means validate once per second, but only
; once per request. "0" means always validate)
opcache.revalidate_freq=${OPCACHE_REVALIDATE_FREQ}
; Enables or disables file search in include_path optimization
;opcache.revalidate_path=0
; If disabled, all PHPDoc comments are dropped from the code to reduce the
; size of the optimized code.
;opcache.save_comments=1
; If enabled, a fast shutdown sequence is used for the accelerated code
; Depending on the used Memory Manager this may cause some incompatibilities.
;opcache.fast_shutdown=0
; Allow file existence override (file_exists, etc.) performance feature.
;opcache.enable_file_override=0
; A bitmask, where each bit enables or disables the appropriate OPcache
; passes
;opcache.optimization_level=0xffffffff
;opcache.inherited_hack=1
;opcache.dups_fix=0
; The location of the OPcache blacklist file (wildcards allowed).
; Each OPcache blacklist file is a text file that holds the names of files
; that should not be accelerated.
opcache.blacklist_filename=${PHP_SYSCONF_PATH}/php.d/opcache*.blacklist
; Allows exclusion of large files from being cached. By default all files
; are cached.
opcache.max_file_size=1M
; Check the cache checksum each N requests.
; The default value of "0" means that the checks are disabled.
;opcache.consistency_checks=0
; How long to wait (in seconds) for a scheduled restart to begin if the cache
; is not being accessed.
;opcache.force_restart_timeout=180
; OPcache error_log file name. Empty string assumes "stderr".
;opcache.error_log=
; All OPcache errors go to the Web server log.
; By default, only fatal errors (level 0) or errors (level 1) are logged.
; You can also enable warnings (level 2), info messages (level 3) or
; debug messages (level 4).
;opcache.log_verbosity_level=1
; Preferred Shared Memory back-end. Leave empty and let the system decide.
;opcache.preferred_memory_model=
; Protect the shared memory from unexpected writing during script execution.
; Useful for internal debugging only.
;opcache.protect_memory=0
; Allows calling OPcache API functions only from PHP scripts which path is
; started from specified string. The default "" means no restriction
;opcache.restrict_api=
; Enables and sets the second level cache directory.
; It should improve performance when SHM memory is full, at server restart or
; SHM reset. The default "" disables file based caching.
; RPM note : file cache directory must be owned by process owner
; for mod_php, see /etc/httpd/conf.d/php.conf
; for php-fpm, see /etc/php-fpm.d/*conf
;opcache.file_cache=
; Enables or disables opcode caching in shared memory.
;opcache.file_cache_only=0
; Enables or disables checksum validation when script loaded from file cache.
;opcache.file_cache_consistency_checks=1
; Enables or disables copying of PHP code (text segment) into HUGE PAGES.
; This should improve performance, but requires appropriate OS configuration.
;opcache.huge_code_pages=0

File diff suppressed because it is too large Load diff

View file

@ -0,0 +1,6 @@
# IMPORTANT: Do not add more content to this file unless you know what you are
# doing. This file is sourced everytime the shell session is opened.
#
# This will make scl collection binaries work out of box.
unset BASH_ENV PROMPT_COMMAND ENV
source scl_source enable ${SCL_ENABLED} httpd24 $NODEJS_SCL

View file

@ -0,0 +1,53 @@
#!/bin/bash
set -e
# In order to drop the root user, we have to make some directories world
# writeable as OpenShift default security model is to run the container under
# random UID.
source ${PHP_CONTAINER_SCRIPTS_PATH}/common.sh
# compatibility symlinks so we hide SCL paths
if [ -v SCL_ENABLED ] ; then
# /opt/rh/httpd24/root/etc/httpd will be symlink to /etc/httpd
mv /opt/rh/httpd24/root/etc/httpd /etc/httpd
ln -s /etc/httpd /opt/rh/httpd24/root/etc/httpd
# /opt/rh/httpd24/root/var/run/httpd will be symlink to /var/run/httpd
mv /opt/rh/httpd24/root/var/run/httpd /var/run/httpd
ln -s /var/run/httpd /opt/rh/httpd24/root/var/run/httpd
# /opt/rh/httpd24/root/var/www will be symlink to /var/www
rm -rf /var/www
mv ${HTTPD_DATA_ORIG_PATH} /var/www
ln -s /var/www ${HTTPD_DATA_ORIG_PATH}
else
rm -f /opt/app-root/etc/scl_enable
fi
if head "/etc/redhat-release" | grep -q -e "^Red Hat Enterprise Linux release 8" -e "Fedora"; then
/usr/libexec/httpd-ssl-gencerts
fi
mkdir -p ${HTTPD_CONFIGURATION_PATH}
chmod -R a+rwx ${HTTPD_MAIN_CONF_PATH}
chmod -R a+rwx ${HTTPD_MAIN_CONF_D_PATH}
chmod -R ug+r /etc/pki/tls/certs/localhost.crt
chmod -R ug+r /etc/pki/tls/private/localhost.key
chown -R 1001:0 /etc/pki/tls/certs/localhost.crt
chown -R 1001:0 /etc/pki/tls/private/localhost.key
mkdir -p ${APP_ROOT}/etc
chmod -R a+rwx ${APP_ROOT}/etc
chmod -R a+rwx ${HTTPD_VAR_RUN}
chown -R 1001:0 ${APP_ROOT}
mkdir /tmp/sessions
chmod -R a+rwx /tmp/sessions
chown -R 1001:0 /tmp/sessions
chown -R 1001:0 ${HTTPD_DATA_PATH}
chmod -R a+rwx ${PHP_SYSCONF_PATH}
mkdir -p ${PHP_CONTAINER_SCRIPTS_PATH}/pre-init
config_general

View file

@ -0,0 +1,152 @@
if [ "x$PLATFORM" == "xel7" ]; then
HTTPCONF_LINENO=151
else
HTTPCONF_LINENO=154
fi
config_httpd_conf() {
sed -i "s/^Listen 80/Listen 0.0.0.0:8080/" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
sed -i "s/^User apache/User default/" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
sed -i "s/^Group apache/Group root/" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
sed -i "s%^DocumentRoot \"${HTTPD_DATA_ORIG_PATH}/html\"%#DocumentRoot \"${APP_DATA}\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
sed -i "s%^<Directory \"${HTTPD_DATA_ORIG_PATH}/html\"%<Directory \"${APP_DATA}\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
sed -i "s%^<Directory \"${HTTPD_VAR_PATH}/html\"%<Directory \"${APP_DATA}\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
sed -i "s%^ErrorLog \"logs/error_log\"%ErrorLog \"|/usr/bin/cat\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
sed -i "s%CustomLog \"logs/access_log\"%CustomLog \"|/usr/bin/cat\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
sed -i "${HTTPCONF_LINENO}s%AllowOverride None%AllowOverride All%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
}
config_ssl_conf() {
sed -i -E "s/^Listen 443/Listen 0.0.0.0:8443/" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
sed -i -E "s/_default_:443/_default_:8443/" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
sed -i -E "s!^(\s*CustomLog)\s+\S+!\1 |/usr/bin/cat!" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
sed -i -E "s!^(\s*TransferLog)\s+\S+!\1 |/usr/bin/cat!" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
sed -i -E "s!^(\s*ErrorLog)\s+\S+!\1 |/usr/bin/cat!" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
}
config_modules_conf() {
# overwrite default rhel-8 mpm mode
echo "LoadModule mpm_prefork_module modules/mod_mpm_prefork.so" > "${HTTPD_MODULES_CONF_D_PATH}/00-mpm.conf"
}
config_general() {
config_httpd_conf
config_ssl_conf
config_modules_conf
sed -i '/php_value session.save_/d' ${HTTPD_MAIN_CONF_D_PATH}/${PHP_HTTPD_CONF_FILE}
head -n${HTTPCONF_LINENO} ${HTTPD_MAIN_CONF_PATH}/httpd.conf | tail -n1 | grep "AllowOverride All" || exit 1
echo "IncludeOptional ${APP_ROOT}/etc/conf.d/*.conf" >> ${HTTPD_MAIN_CONF_PATH}/httpd.conf
}
function log_info {
echo "---> `date +%T` $@"
}
function log_and_run {
log_info "Running $@"
"$@"
}
function log_volume_info {
CONTAINER_DEBUG=${CONTAINER_DEBUG:-}
if [[ "${CONTAINER_DEBUG,,}" != "true" ]]; then
return
fi
log_info "Volume info for $@:"
set +e
log_and_run mount
while [ $# -gt 0 ]; do
log_and_run ls -alZ $1
shift
done
set -e
}
# get_matched_files finds file for image extending
function get_matched_files() {
local custom_dir default_dir
custom_dir="$1"
default_dir="$2"
files_matched="$3"
find "$default_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n"
[ -d "$custom_dir" ] && find "$custom_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n"
}
# process_extending_files process extending files in $1 and $2 directories
# - source all *.sh files
# (if there are files with same name source only file from $1)
function process_extending_files() {
local custom_dir default_dir
custom_dir=$1
default_dir=$2
while read filename ; do
echo "=> sourcing $filename ..."
# Custom file is prefered
if [ -f $custom_dir/$filename ]; then
source $custom_dir/$filename
elif [ -f $default_dir/$filename ]; then
source $default_dir/$filename
fi
done <<<"$(get_matched_files "$custom_dir" "$default_dir" '*.sh' | sort -u)"
}
# process extending config files in $1 and $2 directories
# - expand variables in *.conf and copy the files into /opt/app-root/etc/httpd.d directory
# (if there are files with same name source only file from $1)
function process_extending_config_files() {
local custom_dir default_dir
custom_dir=$1
default_dir=$2
while read filename ; do
echo "=> sourcing $filename ..."
# Custom file is prefered
if [ -f $custom_dir/$filename ]; then
envsubst < $custom_dir/$filename > ${HTTPD_CONFIGURATION_PATH}/$filename
elif [ -f $default_dir/$filename ]; then
envsubst < $default_dir/$filename > ${HTTPD_CONFIGURATION_PATH}/$filename
fi
done <<<"$(get_matched_files "$custom_dir" "$default_dir" '*.conf' | sort -u)"
}
# Copy config files from application to the location where httpd expects them
# Param sets the directory where to look for files
# This function was taken from httpd container
process_config_files() {
local dir=${1:-.}
if [ -d ${dir}/httpd-cfg ]; then
echo "---> Copying httpd configuration files..."
if [ "$(ls -A ${dir}/httpd-cfg/*.conf)" ]; then
cp -v ${dir}/httpd-cfg/*.conf "${HTTPD_CONFIGURATION_PATH}"/
rm -rf ${dir}/httpd-cfg
fi
fi
}
# Copy SSL files provided in application source
# This function was taken from httpd container
process_ssl_certs() {
local dir=${1:-.}
if [ -d ${dir}/httpd-ssl/private ] && [ -d ${dir}/httpd-ssl/certs ]; then
echo "---> Looking for SSL certs for httpd..."
cp -r ${dir}/httpd-ssl ${APP_ROOT}
local ssl_cert="$(ls -A ${APP_ROOT}/httpd-ssl/certs/*.pem | head -n 1)"
local ssl_private="$(ls -A ${APP_ROOT}/httpd-ssl/private/*.pem | head -n 1)"
if [ -f "${ssl_cert}" ] ; then
# do sed for SSLCertificateFile and SSLCertificateKeyFile
echo "---> Setting SSL cert file for httpd..."
sed -i -e "s|^SSLCertificateFile .*$|SSLCertificateFile ${ssl_cert}|" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
if [ -f "${ssl_private}" ]; then
echo "---> Setting SSL key file for httpd..."
sed -i -e "s|^SSLCertificateKeyFile .*$|SSLCertificateKeyFile ${ssl_private}|" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
else
echo "---> Removing SSL key file settings for httpd..."
sed -i '/^SSLCertificateKeyFile .*/d' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
fi
fi
rm -rf ${dir}/httpd-ssl
fi
}

View file

@ -0,0 +1 @@
DocumentRoot "/opt/app-root/src${DOCUMENTROOT}"

View file

@ -0,0 +1,12 @@
<IfModule mpm_prefork_module>
# This value should mirror what is set in MinSpareServers.
StartServers ${HTTPD_START_SERVERS}
MinSpareServers ${HTTPD_START_SERVERS}
MaxSpareServers ${HTTPD_MAX_SPARE_SERVERS}
# The MaxRequestWorkers directive sets the limit on the number of simultaneous requests that will be served.
# The default value, when no Cgroup limits are set is 256.
MaxRequestWorkers ${HTTPD_MAX_REQUEST_WORKERS}
ServerLimit ${HTTPD_MAX_REQUEST_WORKERS}
MaxRequestsPerChild ${HTTPD_MAX_REQUESTS_PER_CHILD}
MaxKeepAliveRequests ${HTTPD_MAX_KEEPALIVE_REQUESTS}
</IfModule>

View file

@ -0,0 +1,6 @@
# additional arbitrary httpd configuration provided by user using s2i
log_info 'Processing additional arbitrary httpd configuration provided by s2i ...'
process_extending_config_files ${APP_DATA}/httpd-cfg/ ${PHP_CONTAINER_SCRIPTS_PATH}/httpd-cnf/

View file

@ -0,0 +1,4 @@
source ${PHP_CONTAINER_SCRIPTS_PATH}/common.sh
# Copy SSL files provided in application source
process_ssl_certs

View file

@ -0,0 +1,6 @@
# additional arbitrary httpd configuration provided by user using s2i
log_info 'Processing additional arbitrary httpd configuration provided by s2i ...'
process_extending_config_files ${APP_DATA}/httpd-cfg/ ${PHP_CONTAINER_SCRIPTS_PATH}/httpd-cnf/

View file

@ -0,0 +1,4 @@
source ${PHP_CONTAINER_SCRIPTS_PATH}/common.sh
# Copy SSL files provided in application source
process_ssl_certs ${APP_ROOT}/src

73
s2i/bin/assemble Executable file
View file

@ -0,0 +1,73 @@
#!/bin/bash
set -e
source ${PHP_CONTAINER_SCRIPTS_PATH}/common.sh
shopt -s dotglob
echo "---> Installing application source..."
rm -fR /tmp/src/.git
mv /tmp/src/* ./
# Fix source directory permissions
fix-permissions ./
fix-permissions ${HTTPD_CONFIGURATION_PATH}
# Change the npm registry mirror if provided
if [ -n "$NPM_MIRROR" ]; then
npm config set registry $NPM_MIRROR
fi
if [ -f composer.json ]; then
echo "Found 'composer.json', installing dependencies using composer.phar... "
# Install Composer
TEMPFILE=$(mktemp)
RETRIES=6
for ((i=0; i<$RETRIES; i++)); do
if [ -z "$COMPOSER_INSTALLER" ]; then
export COMPOSER_INSTALLER="https://getcomposer.org/installer"
fi
echo "Downloading $COMPOSER_INSTALLER, attempt $((i+1))/$RETRIES"
curl -o $TEMPFILE $COMPOSER_INSTALLER && break
sleep 10
done
if [[ $i == $RETRIES ]]; then
echo "Download failed, giving up."
exit 1
fi
if [ -z $COMPOSER_VERSION ]; then
echo "By default, latest composer will be used. If you want to use v1 please use the environment variable COMPOSER_VERSION=1"
php <$TEMPFILE
else
echo "You set the COMPOSER_VERSION"
php <$TEMPFILE -- --$COMPOSER_VERSION
fi
if [ "$(ls -a /tmp/artifacts/ 2>/dev/null)" ]; then
echo "Restoring build artifacts"
mv /tmp/artifacts/* $HOME/
fi
# Change the repo mirror if provided
if [ -n "$COMPOSER_MIRROR" ]; then
./composer.phar config -g repositories.packagist composer $COMPOSER_MIRROR
fi
# Install App dependencies using Composer
./composer.phar install --no-interaction --no-ansi --optimize-autoloader $COMPOSER_ARGS
if [ ! -f composer.lock ]; then
echo -e "\nConsider adding a 'composer.lock' file into your source repository.\n"
fi
fi
# post-assemble files
process_extending_files ./php-post-assemble/ ${PHP_CONTAINER_SCRIPTS_PATH}/post-assemble/
# Fix source directory permissions
fix-permissions ./
fix-permissions ${HTTPD_CONFIGURATION_PATH}

60
s2i/bin/run Executable file
View file

@ -0,0 +1,60 @@
#!/bin/bash
source ${PHP_CONTAINER_SCRIPTS_PATH}/common.sh
export_vars=$(cgroup-limits); export $export_vars
export DOCUMENTROOT=${DOCUMENTROOT:-/}
# Default php.ini configuration values, all taken
# from php defaults.
export ERROR_REPORTING=${ERROR_REPORTING:-E_ALL & ~E_NOTICE}
export DISPLAY_ERRORS=${DISPLAY_ERRORS:-ON}
export DISPLAY_STARTUP_ERRORS=${DISPLAY_STARTUP_ERRORS:-OFF}
export TRACK_ERRORS=${TRACK_ERRORS:-OFF}
export HTML_ERRORS=${HTML_ERRORS:-ON}
export INCLUDE_PATH=${INCLUDE_PATH:-.:/opt/app-root/src:${PHP_DEFAULT_INCLUDE_PATH}}
export PHP_MEMORY_LIMIT=${PHP_MEMORY_LIMIT:-128M}
export SESSION_NAME=${SESSION_NAME:-PHPSESSID}
export SESSION_HANDLER=${SESSION_HANDLER:-files}
export SESSION_PATH=${SESSION_PATH:-/tmp/sessions}
export SESSION_COOKIE_DOMAIN=${SESSION_COOKIE_DOMAIN:-}
export SESSION_COOKIE_HTTPONLY=${SESSION_COOKIE_HTTPONLY:-}
export SESSION_COOKIE_SECURE=${SESSION_COOKIE_SECURE:-0}
export SHORT_OPEN_TAG=${SHORT_OPEN_TAG:-OFF}
# TODO should be dynamically calculated based on container memory limit/16
export OPCACHE_MEMORY_CONSUMPTION=${OPCACHE_MEMORY_CONSUMPTION:-128}
export OPCACHE_REVALIDATE_FREQ=${OPCACHE_REVALIDATE_FREQ:-2}
export OPCACHE_MAX_FILES=${OPCACHE_MAX_FILES:-4000}
export PHPRC=${PHPRC:-${PHP_SYSCONF_PATH}/php.ini}
export PHP_INI_SCAN_DIR=${PHP_INI_SCAN_DIR:-${PHP_SYSCONF_PATH}/php.d}
envsubst < /opt/app-root/etc/php.ini.template > ${PHP_SYSCONF_PATH}/php.ini
envsubst < /opt/app-root/etc/php.d/10-opcache.ini.template > ${PHP_SYSCONF_PATH}/php.d/10-opcache.ini
export HTTPD_START_SERVERS=${HTTPD_START_SERVERS:-8}
export HTTPD_MAX_SPARE_SERVERS=$((HTTPD_START_SERVERS+10))
export HTTPD_MAX_REQUESTS_PER_CHILD=${HTTPD_MAX_REQUESTS_PER_CHILD:-4000}
export HTTPD_MAX_KEEPALIVE_REQUESTS=${HTTPD_MAX_KEEPALIVE_REQUESTS:-100}
if [ -n "${NO_MEMORY_LIMIT:-}" -o -z "${MEMORY_LIMIT_IN_BYTES:-}" ]; then
#
export HTTPD_MAX_REQUEST_WORKERS=${HTTPD_MAX_REQUEST_WORKERS:-256}
else
# A simple calculation for MaxRequestWorkers would be: Total Memory / Size Per Apache process.
# The total memory is determined from the Cgroups and the average size for the
# Apache process is estimated to 15MB.
max_clients_computed=$((MEMORY_LIMIT_IN_BYTES/1024/1024/15))
# The MaxClients should never be lower than StartServers, which is set to 5.
# In case the container has memory limit set to <64M we pin the MaxClients to 4.
[[ $max_clients_computed -le 4 ]] && max_clients_computed=4
export HTTPD_MAX_REQUEST_WORKERS=${HTTPD_MAX_REQUEST_WORKERS:-$max_clients_computed}
echo "-> Cgroups memory limit is set, using HTTPD_MAX_REQUEST_WORKERS=${HTTPD_MAX_REQUEST_WORKERS}"
fi
# pre-start files
process_extending_files ${APP_DATA}/php-pre-start/ ${PHP_CONTAINER_SCRIPTS_PATH}/pre-start/
exec httpd -D FOREGROUND

4
s2i/bin/save-artifacts Executable file
View file

@ -0,0 +1,4 @@
#!/bin/sh
pushd ${HOME} >/dev/null
tar cf - vendor
popd >/dev/null

21
s2i/bin/usage Executable file
View file

@ -0,0 +1,21 @@
#!/bin/sh
DISTRO=`cat /etc/*-release | grep ^ID= | grep -Po '".*?"' | tr -d '"'`
NAMESPACE=centos
[[ $DISTRO =~ rhel* ]] && NAMESPACE=rhscl
cat <<EOF
This is a S2I PHP-${PHP_VERSION} ${DISTRO} base image:
To use it in Openshift, run:
oc new-app php:${PHP_VERSION}~https://github.com/sclorg/cakephp-ex.git
To access the application:
oc get pods
oc exec <pod> -- curl 127.0.0.1:8080
Alternatively, to run the image directly using podman or docker, or how to use it as a parent image in a Dockerfile, see documentation at
https://github.com/sclorg/s2i-php-container/blob/master/${PHP_VERSION}/README.md
EOF

View file

@ -0,0 +1 @@
app-src

View file

@ -0,0 +1,24 @@
FROM ubi8/php-73
USER 0
# Add application sources
ADD app-src .
RUN chown -R 1001:0 .
USER 1001
# Install the dependencies
RUN TEMPFILE=$(mktemp) && \
curl -o "$TEMPFILE" "https://getcomposer.org/installer" && \
php <"$TEMPFILE" && \
./composer.phar install --no-interaction --no-ansi --optimize-autoloader
# Run script uses standard ways to configure the PHP application
# and execs httpd -D FOREGROUND at the end
# See more in <version>/s2i/bin/run in this repository.
# Shortly what the run script does: The httpd daemon and php needs to be
# configured, so this script prepares the configuration based on the container
# parameters (e.g. available memory) and puts the configuration files into
# the approriate places.
# This can obviously be done differently, and in that case, the final CMD
# should be set to "CMD httpd -D FOREGROUND" instead.
CMD /usr/libexec/s2i/run

View file

@ -0,0 +1,25 @@
FROM registry.access.redhat.com/ubi8/php-73
# This image supports the Source-to-Image
# (see more at https://docs.openshift.com/container-platform/3.11/creating_images/s2i.html).
# In order to support the Source-to-Image framework, there are some interesting
# scripts inside the builder image, that can be run in a Dockerfile directly as well:
# * The `/usr/libexec/s2i/assemble` script inside the image is run in order
# to produce a new image with the application artifacts.
# The script takes sources of a given application and places them into
# appropriate directories inside the image.
# * The `/usr/libexec/s2i/run` script executes the application and is set as
# a default command in the resulting container image.
# Add application sources to a directory that the assemble script expects them
# and set permissions so that the container runs without root access
USER 0
ADD app-src /tmp/src
RUN chown -R 1001:0 /tmp/src
USER 1001
# Let the assemble script to install the dependencies
RUN /usr/libexec/s2i/assemble
# Run script uses standard ways to run the application
CMD /usr/libexec/s2i/run

View file

@ -0,0 +1,22 @@
Dockerfile examples
===================
This directory contains example Dockerfiles that demonstrate how to use the image with a Dockerfile and `podman build`.
For demonstration, we use an application code available at https://github.com/sclorg/cakephp-ex.git.
Pull the source to the local machine first:
```
git clone https://github.com/sclorg/cakephp-ex.git app-src
```
Then, build a new image from a Dockerfile in this directory:
```
podman build -f Dockerfile -t cakephp-app .
```
And run the resulting image with the final application:
```
podman run -ti --rm cakephp-app
```

View file

@ -0,0 +1,20 @@
-----BEGIN CERTIFICATE-----
MIIDWjCCAkKgAwIBAgIJAI4x7HuBG49oMA0GCSqGSIb3DQEBCwUAMEIxCzAJBgNV
BAYTAlhYMRUwEwYDVQQHDAxEZWZhdWx0IENpdHkxHDAaBgNVBAoME0RlZmF1bHQg
Q29tcGFueSBMdGQwHhcNMTcxMjAzMjMzMzU3WhcNMTgwMTAyMjMzMzU3WjBCMQsw
CQYDVQQGEwJYWDEVMBMGA1UEBwwMRGVmYXVsdCBDaXR5MRwwGgYDVQQKDBNEZWZh
dWx0IENvbXBhbnkgTHRkMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA
vH4Vdq0a3UWUQd8Z6s2csxhxjAOyUx0rszGL0m3uTjQido6JRBdjN2dXiZc3LFoq
YeOKR3CeHsn7UdrlzaboHFDfjAaextse0740mB1g14H1bAS0POuTPeKa+3wGfzCb
sTSXnfSrICl3n2D/3KSO93WwmS90kBD6HmKt5nfkLpJnROM/4bHmuoV0Ry8CDjzj
mka7pQU4yzyMKLU3sHpncZU6g7o4Vezic9ksVzIAbdPCSbF7ktVz/hisyCuzyKN6
s2327jq593vBgGOsNU5PDPDjKW74Q0Bv/FxPK4nx+o4IkcRW1QEb+yAx8XOM7CDZ
ViKvI/A0b+Y4Y3rIQ465+wIDAQABo1MwUTAdBgNVHQ4EFgQUAY1i6ZNbqO1+46aw
pldCyPaWoYswHwYDVR0jBBgwFoAUAY1i6ZNbqO1+46awpldCyPaWoYswDwYDVR0T
AQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEADhGjnYGq9JvQcygMYEQiIdyS
t06Nu7NUkWz52GJp7WFognWyG+0jAomBR0GSUchfubvVZ7cHIaVKLhiGOqg+HIol
7tNRfvE6x/Idk674g6OTRAWxO/wOlgnRMpRy6XhHOtb4HcPcpWFZJS8MC8+HRWIs
kzMErXe0/obnKn9O04kcEREfmB7kfcD4ooqk5gwbdQk1W6a44LcN6AB5qYPjOzgF
Qnb2aLQW9XhgNhiMsYqDzCZsy0az0rz7NgkVOnKrGJ8x3kVX13GR2joVVHOazms9
Gd90z+mLMDTbqCRGIPMLvEp4HtAmBxbgsj/zHyinajIqV96B3Cr3zTdW29lHJg==
-----END CERTIFICATE-----

View file

@ -0,0 +1,28 @@
-----BEGIN PRIVATE KEY-----
MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQC8fhV2rRrdRZRB
3xnqzZyzGHGMA7JTHSuzMYvSbe5ONCJ2jolEF2M3Z1eJlzcsWiph44pHcJ4eyftR
2uXNpugcUN+MBp7G2x7TvjSYHWDXgfVsBLQ865M94pr7fAZ/MJuxNJed9KsgKXef
YP/cpI73dbCZL3SQEPoeYq3md+QukmdE4z/hsea6hXRHLwIOPOOaRrulBTjLPIwo
tTewemdxlTqDujhV7OJz2SxXMgBt08JJsXuS1XP+GKzIK7PIo3qzbfbuOrn3e8GA
Y6w1Tk8M8OMpbvhDQG/8XE8rifH6jgiRxFbVARv7IDHxc4zsINlWIq8j8DRv5jhj
eshDjrn7AgMBAAECggEARZxeutxE/pCypv0IqkFS7IVLccTvt2gfemcC1yzIBFOW
oqgTI3Vrq8tbdbHFq3iFDG+m4qlBi+dWDC3GDoPkVoi7dg//1TqZEOO+sqqu2Afj
pge6tIDfeMxWJifwkkpWRURB9hCknhUSW2bMNyUCs3rgREJVTtsmM9CHnoSKXXQL
aOeYXalFVpx3ceK+xdp0VGfpsqEabBKs0yy3EDiQy2huoWce3EVFLVrwx/IkhcsZ
JlI5LPpoiTglSs1g9i88JHS2slBtKtb1lWl/yXHhK1g7s34c6f9jP8snuFE5ddMn
0L4GDA9teaPGvB533eb2RIFy2kUYgpr5c03G6rpoOQKBgQDpY6BFJkPGENnC5Bdb
fJCuN2nyRdC1qvv6ESFaQYb0s6QjKDqpb0dUSYN3+zNgtiAysbQLeU/d9mmt4UR8
ohjRkOySU0eQ/YNFokjw6g6GPoiMHJJ9cP75NA94uIMIUTY7uHEWWZwXI5UphdPC
p5/3MaF1VlYQys9a5wtiEaDSfQKBgQDOwPV0zQjUabkVQ4yV0amP8xybvHH8ghG0
RMStHg96RfDmg35JQaw22A2xiVROCoZgLqiE1DFSl/3gBF/vfqBh/uzdxwNerJC6
ROdCxyS4rys5d/02P4aNOa73sD+ZKyEZRTF1v3bmOGKidRFF5oxIpuHjFWlJFKx1
O/b3AI0v1wKBgQC/L4N84emm+OrKAfs4UIRckrxRYOulxhmAMkQ2IXOiRP5yZmQX
pDa0TzxJLxhZYxhhLr0koQ3R8CeF7wEhb9AQ7D0/aMU5etLsWhKSd8nKIrPMwyMl
a0kTb5g09kEwsQZSSbcp7eI1+koYp65eyN37q0ZuTnlWbC0MdDQY9APgKQKBgQCb
HqaKNXLUe2XDkGSf2ygOumXSanZS7vt9dsLg59bQ9DyjljBfogglNcBAXTqFOtxK
uXbyAYnn3+U399BKjYSjQXJRioj6tRn4xs2DiooAjlwtx9qQouS+fHLLns54iqVQ
oltTbo00eUV3gcGt4iWKNLrxdxUBIaOqaY0HEMDdDQKBgQCRvcHDF7JSPuBiO3Tw
PSOUD4q6dD/dhI+X2ZKg83w94SZXXms6eMSbedUkLoJ8TDunmdRUUWb6rgP/pJwr
zKRTskItF15i9IWCwC6jBrSfx5n2JcSoBALyc0aR9heF0GQjWwqURd+PC/msomrW
z9SCl8mpQVFtBlui7PcnDLTFAg==
-----END PRIVATE KEY-----

View file

@ -0,0 +1 @@
SSL test works

View file

@ -0,0 +1,133 @@
{
"kind": "ImageStream",
"apiVersion": "image.openshift.io/v1",
"metadata": {
"name": "php",
"annotations": {
"openshift.io/display-name": "PHP"
}
},
"spec": {
"tags": [
{
"name": "latest",
"annotations": {
"openshift.io/display-name": "PHP (Latest)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP applications on UBI. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/8.0/README.md.\n\nWARNING: By selecting this tag, your application will automatically update to use the latest version of PHP available on OpenShift, including major version updates.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "ImageStreamTag",
"name": "8.0-ubi8"
},
"referencePolicy": {
"type": "Local"
}
},
{
"name": "8.0-ubi9",
"annotations": {
"openshift.io/display-name": "PHP 8.0 (UBI 9)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP 8.0 applications on UBI 9. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/8.0/README.md.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php:8.0,php",
"version": "8.0",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "DockerImage",
"name": "registry.access.redhat.com/ubi9/php-80:latest"
},
"referencePolicy": {
"type": "Local"
}
},
{
"name": "8.0-ubi8",
"annotations": {
"openshift.io/display-name": "PHP 8.0 (UBI 8)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP 8.0 applications on UBI 8. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/8.0/README.md.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php:8.0,php",
"version": "8.0",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "DockerImage",
"name": "registry.access.redhat.com/ubi8/php-80:latest"
},
"referencePolicy": {
"type": "Local"
}
},
{
"name": "7.4-ubi8",
"annotations": {
"openshift.io/display-name": "PHP 7.4 (UBI 8)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP 7.4 applications on UBI 8. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/7.4/README.md.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php:7.4,php",
"version": "7.4",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "DockerImage",
"name": "registry.access.redhat.com/ubi8/php-74:latest"
},
"referencePolicy": {
"type": "Local"
}
},
{
"name": "7.3-ubi7",
"annotations": {
"openshift.io/display-name": "PHP 7.3 (UBI 7)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP 7.3 applications on UBI 7. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/7.3/README.md.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php:7.3,php",
"version": "7.3",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "DockerImage",
"name": "registry.access.redhat.com/ubi7/php-73:latest"
},
"referencePolicy": {
"type": "Local"
}
},
{
"name": "7.3",
"annotations": {
"openshift.io/display-name": "PHP 7.3",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP 7.3 applications on CentOS 7. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/7.3/README.md.",
"iconClass": "icon-php",
"tags": "builder,php,hidden",
"supports":"php:7.3,php",
"version": "7.3",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "DockerImage",
"name": "quay.io/centos7/php-73-centos7:latest"
},
"referencePolicy": {
"type": "Local"
}
}
]
}
}

View file

@ -0,0 +1,93 @@
{
"kind": "ImageStream",
"apiVersion": "image.openshift.io/v1",
"metadata": {
"name": "php",
"annotations": {
"openshift.io/display-name": "PHP"
}
},
"spec": {
"tags": [
{
"name": "latest",
"annotations": {
"openshift.io/display-name": "PHP (Latest)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP applications on UBI. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/8.0/README.md.\n\nWARNING: By selecting this tag, your application will automatically update to use the latest version of PHP available on OpenShift, including major version updates.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "ImageStreamTag",
"name": "8.0-ubi8"
},
"referencePolicy": {
"type": "Local"
}
},
{
"name": "8.0-ubi9",
"annotations": {
"openshift.io/display-name": "PHP 8.0 (UBI 9)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP 8.0 applications on UBI 9. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/8.0/README.md.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php:8.0,php",
"version": "8.0",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "DockerImage",
"name": "registry.redhat.io/ubi9/php-80:latest"
},
"referencePolicy": {
"type": "Local"
}
},
{
"name": "8.0-ubi8",
"annotations": {
"openshift.io/display-name": "PHP 8.0 (UBI 8)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP 8.0 applications on UBI 8. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/8.0/README.md.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php:8.0,php",
"version": "8.0",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "DockerImage",
"name": "registry.redhat.io/ubi8/php-80:latest"
},
"referencePolicy": {
"type": "Local"
}
},
{
"name": "7.4-ubi8",
"annotations": {
"openshift.io/display-name": "PHP 7.4 (UBI 8)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP 7.4 applications on UBI 8. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/7.4/README.md.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php:7.4,php",
"version": "7.4",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "DockerImage",
"name": "registry.redhat.io/ubi8/php-74:latest"
},
"referencePolicy": {
"type": "Local"
}
}
]
}
}

View file

@ -0,0 +1,133 @@
{
"kind": "ImageStream",
"apiVersion": "image.openshift.io/v1",
"metadata": {
"name": "php",
"annotations": {
"openshift.io/display-name": "PHP"
}
},
"spec": {
"tags": [
{
"name": "latest",
"annotations": {
"openshift.io/display-name": "PHP (Latest)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP applications on UBI. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/8.0/README.md.\n\nWARNING: By selecting this tag, your application will automatically update to use the latest version of PHP available on OpenShift, including major version updates.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "ImageStreamTag",
"name": "8.0-ubi8"
},
"referencePolicy": {
"type": "Local"
}
},
{
"name": "8.0-ubi9",
"annotations": {
"openshift.io/display-name": "PHP 8.0 (UBI 9)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP 8.0 applications on UBI 9. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/8.0/README.md.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php:8.0,php",
"version": "8.0",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "DockerImage",
"name": "registry.redhat.io/ubi9/php-80:latest"
},
"referencePolicy": {
"type": "Local"
}
},
{
"name": "8.0-ubi8",
"annotations": {
"openshift.io/display-name": "PHP 8.0 (UBI 8)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP 8.0 applications on UBI 8. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/8.0/README.md.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php:8.0,php",
"version": "8.0",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "DockerImage",
"name": "registry.redhat.io/ubi8/php-80:latest"
},
"referencePolicy": {
"type": "Local"
}
},
{
"name": "7.4-ubi8",
"annotations": {
"openshift.io/display-name": "PHP 7.4 (UBI 8)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP 7.4 applications on UBI 8. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/7.4/README.md.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php:7.4,php",
"version": "7.4",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "DockerImage",
"name": "registry.redhat.io/ubi8/php-74:latest"
},
"referencePolicy": {
"type": "Local"
}
},
{
"name": "7.3-ubi7",
"annotations": {
"openshift.io/display-name": "PHP 7.3 (UBI 7)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP 7.3 applications on UBI 7. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/7.3/README.md.",
"iconClass": "icon-php",
"tags": "builder,php",
"supports":"php:7.3,php",
"version": "7.3",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "DockerImage",
"name": "registry.redhat.io/ubi7/php-73:latest"
},
"referencePolicy": {
"type": "Local"
}
},
{
"name": "7.3",
"annotations": {
"openshift.io/display-name": "PHP 7.3",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"description": "Build and run PHP 7.3 applications on RHEL 7. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/s2i-php-container/blob/master/7.3/README.md.",
"iconClass": "icon-php",
"tags": "builder,php,hidden",
"supports":"php:7.3,php",
"version": "7.3",
"sampleRepo": "https://github.com/sclorg/cakephp-ex.git"
},
"from": {
"kind": "DockerImage",
"name": "registry.redhat.io/rhscl/php-73-rhel7:latest"
},
"referencePolicy": {
"type": "Local"
}
}
]
}
}

290
test/run Executable file
View file

@ -0,0 +1,290 @@
#!/bin/bash
#
# The 'run' performs a simple test that verifies that S2I image.
# The main focus here is to excersise the S2I scripts.
#
# IMAGE_NAME specifies a name of the candidate image used for testing.
# The image has to be available before this script is executed.
#
test -n "${IMAGE_NAME-}" || false 'make sure $IMAGE_NAME is defined'
test -n "${VERSION-}" || false 'make sure $VERSION is defined'
TEST_LIST="\
test_s2i_usage
test_docker_run_usage
test_scl_usage
test_application
test_application_user
test_ssl
test_ssl_own_cert
ct_npm_works
test_build_from_dockerfile
"
# TODO: Make command compatible for Mac users
test_dir="$(readlink -f $(dirname "${BASH_SOURCE[0]}"))"
image_dir=$(readlink -f ${test_dir}/..)
test_short_summary=''
TESTSUITE_RESULT=0
source "${test_dir}/test-lib.sh"
# TODO: This should be part of the image metadata
test_port=8080
test_port_ssl=8443
ct_enable_cleanup
info() {
echo -e "\n\e[1m[INFO] $@...\e[0m\n"
}
image_exists() {
docker inspect $1 &>/dev/null
}
container_exists() {
image_exists $(cat $cid_file)
}
container_ip() {
docker inspect --format="{{ .NetworkSettings.IPAddress }}" $(cat $cid_file)
}
run_s2i_build() {
ct_s2i_build_as_df file://${test_dir}/test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp ${s2i_args} $(ct_build_s2i_npm_variables)
}
prepare() {
if ! image_exists ${IMAGE_NAME}; then
echo "ERROR: The image ${IMAGE_NAME} must exist before this script is executed."
exit 1
fi
# TODO: S2I build require the application is a valid 'GIT' repository, we
# should remove this restriction in the future when a file:// is used.
info "Build the test application image"
pushd ${test_dir}/test-app >/dev/null
git init
git config user.email "build@localhost" && git config user.name "builder"
git add -A && git commit -m "Sample commit"
popd >/dev/null
}
run_test_application() {
run_args=${CONTAINER_ARGS:-}
docker run -d --user=100001 ${run_args} --cidfile=${cid_file} ${IMAGE_NAME}-testapp
}
cleanup_test_app() {
info "Cleaning up the test application"
if [ -f $cid_file ]; then
if container_exists; then
docker stop $(cat $cid_file)
docker rm $(cat $cid_file)
fi
rm $cid_file
fi
}
cleanup() {
info "Cleaning up the test application image"
if image_exists ${IMAGE_NAME}-testapp; then
docker rmi -f ${IMAGE_NAME}-testapp
fi
rm -rf ${test_dir}/test-app/.git
echo "$test_short_summary"
if [ $TESTSUITE_RESULT -eq 0 ] ; then
echo "Tests for ${IMAGE_NAME} succeeded."
else
echo "Tests for ${IMAGE_NAME} failed."
fi
exit $TESTSUITE_RESULT
}
check_result() {
local result="$1"
if [[ "$result" != "0" ]]; then
TESTCASE_RESULT=1
fi
return $result
}
wait_for_cid() {
local max_attempts=10
local sleep_time=1
local attempt=1
local result=1
info "Waiting for application container to start"
while [ $attempt -le $max_attempts ]; do
[ -f $cid_file ] && [ -s $cid_file ] && result=0 && break
attempt=$(( $attempt + 1 ))
sleep $sleep_time
done
return $result
}
test_s2i_usage() {
info "Testing 's2i usage'"
ct_s2i_usage ${IMAGE_NAME} ${s2i_args} &>/dev/null
}
test_docker_run_usage() {
info "Testing 'docker run' usage"
docker run ${IMAGE_NAME} &>/dev/null
}
test_scl_usage() {
local run_cmd="$1"
local expected="$2"
info "Testing the image SCL enable"
out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${run_cmd}")
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[/bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'"
return 1
fi
out=$(docker exec $(cat ${cid_file}) /bin/bash -c "${run_cmd}" 2>&1)
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[exec /bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'"
return 1
fi
out=$(docker exec $(cat ${cid_file}) /bin/sh -ic "${run_cmd}" 2>&1)
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[exec /bin/sh -ic "${run_cmd}"] Expected '${expected}', got '${out}'"
return 1
fi
}
test_session() {
local check_port=$1 ; shift
local check_protocol=${1:-http}
cat $cid_file
info "Testing PHP session"
response=$(curl -s -k ${check_protocol}://$(container_ip):${check_port}/session_test.php)
if [ "${response}" != "Passed" ]; then
echo "ERROR starting PHP session. Test app returned: '${response}'"
return 1
fi
}
test_connection() {
local check_port=$1 ; shift
local check_protocol=${1:-http}
cat $cid_file
info "Testing the HTTP connection (${check_protocol}://$(container_ip):${check_port})"
local max_attempts=10
local sleep_time=1
local attempt=1
local result=1
while [ $attempt -le $max_attempts ]; do
response_code=$(curl -s -w %{http_code} -o /dev/null -k ${check_protocol}://$(container_ip):${check_port}/)
status=$?
if [ $status -eq 0 ]; then
if [ $response_code -eq 200 ]; then
result=0
break
fi
fi
attempt=$(( $attempt + 1 ))
sleep $sleep_time
done
return $result
}
test_application() {
# Verify that the HTTP connection can be established to test application container
run_test_application &
# Wait for the container to write it's CID file
wait_for_cid
check_result $?
test_scl_usage "php --version" "$VERSION"
check_result $?
test_session ${test_port}
check_result $?
test_connection ${test_port}
check_result $?
test_connection ${test_port_ssl} https
check_result $?
cleanup_test_app
}
test_application_user() {
# Test application with random uid
CONTAINER_ARGS="--user 12345" test_application
}
test_ssl() {
local cert_dir=/tmp
local cert_base=mycert
ct_gen_self_signed_cert_pem ${cert_dir} ${cert_base}
local private_key=${cert_dir}/${cert_base}-cert-selfsigned.pem
local cert_file=${cert_dir}/${cert_base}-key.pem
}
test_ssl_own_cert() {
cleanup_test_app
ct_s2i_build_as_df file://${test_dir}/self-signed-ssl ${IMAGE_NAME} ${IMAGE_NAME}-test-self-signed-ssl ${s2i_args} $(ct_build_s2i_npm_variables)
docker run -d --user=100001 ${run_args} --cidfile=${cid_file} ${IMAGE_NAME}-test-self-signed-ssl
test_connection ${test_port_ssl} https
check_result $?
echo | openssl s_client -showcerts -servername $(container_ip) -connect $(container_ip):${test_port_ssl} 2>/dev/null | openssl x509 -inform pem -noout -text >./servercert
openssl x509 -in ${test_dir}/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem -inform pem -noout -text >./configcert
diff ./configcert ./servercert >cert.diff
check_result $?
}
test_build_from_dockerfile() {
info "Check building using a Dockerfile"
ct_test_app_dockerfile ${test_dir}/examples/from-dockerfile/Dockerfile \
'https://github.com/sclorg/cakephp-ex.git' \
'Welcome to your CakePHP application on OpenShift' \
app-src
check_result $?
ct_test_app_dockerfile ${test_dir}/examples/from-dockerfile/Dockerfile.s2i \
'https://github.com/sclorg/cakephp-ex.git' \
'Welcome to your CakePHP application on OpenShift' \
app-src
check_result $?
}
cid_file=$(mktemp -u --suffix=.cid)
# Since we built the candidate image locally, we don't want S2I attempt to pull
# it from Docker hub
s2i_args="--pull-policy=never"
prepare
run_s2i_build
check_result $?
function run_all_tests() {
for test_case in $TEST_LIST; do
echo "Running test $test_case ...."
TESTCASE_RESULT=0
$test_case
check_result $?
if [ $TESTCASE_RESULT -eq 0 ]; then
printf -v test_short_summary "${test_short_summary}[PASSED] $test_case\n"
else
printf -v test_short_summary "${test_short_summary}[FAILED] $test_case\n"
TESTSUITE_RESULT=1
[ -n "${FAIL_QUICKLY:-}" ] && return 1
fi
cleanup_test_app
done;
}
# Run the chosen tests
TEST_LIST=${TESTS:-$TEST_LIST} run_all_tests
cleanup

1
test/run-openshift Symbolic link
View file

@ -0,0 +1 @@
run-openshift-local-cluster

View file

@ -0,0 +1,40 @@
#!/bin/bash
#
# Test the PHP S2I image in OpenShift (remote cluster)
#
# IMAGE_NAME specifies a name of the candidate image used for testing.
# The image has to be available before this script is executed.
# VERSION specifies the major version of the PHP runtime in format of X.Y
# OS specifies RHEL version (e.g. OS=rhel7)
#
THISDIR=$(dirname ${BASH_SOURCE[0]})
source ${THISDIR}/test-lib-php.sh
source ${THISDIR}/test-lib-openshift.sh
source ${THISDIR}/test-lib-remote-openshift.sh
set -eo nounset
trap ct_os_cleanup EXIT SIGINT
ct_os_check_compulsory_vars
ct_os_set_ocp4
oc version
oc status || false "It looks like oc is not properly logged in."
# For testing on OpenShift 4 we use OpenShift internal registry
export CT_OCP4_TEST=true
test_php_integration "${IMAGE_NAME}"
# Check the imagestream
test_php_imagestream
OS_TESTSUITE_RESULT=0
# vim: set tabstop=2:shiftwidth=2:expandtab:

View file

@ -0,0 +1,20 @@
-----BEGIN CERTIFICATE-----
MIIDWjCCAkKgAwIBAgIJAI4x7HuBG49oMA0GCSqGSIb3DQEBCwUAMEIxCzAJBgNV
BAYTAlhYMRUwEwYDVQQHDAxEZWZhdWx0IENpdHkxHDAaBgNVBAoME0RlZmF1bHQg
Q29tcGFueSBMdGQwHhcNMTcxMjAzMjMzMzU3WhcNMTgwMTAyMjMzMzU3WjBCMQsw
CQYDVQQGEwJYWDEVMBMGA1UEBwwMRGVmYXVsdCBDaXR5MRwwGgYDVQQKDBNEZWZh
dWx0IENvbXBhbnkgTHRkMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA
vH4Vdq0a3UWUQd8Z6s2csxhxjAOyUx0rszGL0m3uTjQido6JRBdjN2dXiZc3LFoq
YeOKR3CeHsn7UdrlzaboHFDfjAaextse0740mB1g14H1bAS0POuTPeKa+3wGfzCb
sTSXnfSrICl3n2D/3KSO93WwmS90kBD6HmKt5nfkLpJnROM/4bHmuoV0Ry8CDjzj
mka7pQU4yzyMKLU3sHpncZU6g7o4Vezic9ksVzIAbdPCSbF7ktVz/hisyCuzyKN6
s2327jq593vBgGOsNU5PDPDjKW74Q0Bv/FxPK4nx+o4IkcRW1QEb+yAx8XOM7CDZ
ViKvI/A0b+Y4Y3rIQ465+wIDAQABo1MwUTAdBgNVHQ4EFgQUAY1i6ZNbqO1+46aw
pldCyPaWoYswHwYDVR0jBBgwFoAUAY1i6ZNbqO1+46awpldCyPaWoYswDwYDVR0T
AQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEADhGjnYGq9JvQcygMYEQiIdyS
t06Nu7NUkWz52GJp7WFognWyG+0jAomBR0GSUchfubvVZ7cHIaVKLhiGOqg+HIol
7tNRfvE6x/Idk674g6OTRAWxO/wOlgnRMpRy6XhHOtb4HcPcpWFZJS8MC8+HRWIs
kzMErXe0/obnKn9O04kcEREfmB7kfcD4ooqk5gwbdQk1W6a44LcN6AB5qYPjOzgF
Qnb2aLQW9XhgNhiMsYqDzCZsy0az0rz7NgkVOnKrGJ8x3kVX13GR2joVVHOazms9
Gd90z+mLMDTbqCRGIPMLvEp4HtAmBxbgsj/zHyinajIqV96B3Cr3zTdW29lHJg==
-----END CERTIFICATE-----

View file

@ -0,0 +1,28 @@
-----BEGIN PRIVATE KEY-----
MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQC8fhV2rRrdRZRB
3xnqzZyzGHGMA7JTHSuzMYvSbe5ONCJ2jolEF2M3Z1eJlzcsWiph44pHcJ4eyftR
2uXNpugcUN+MBp7G2x7TvjSYHWDXgfVsBLQ865M94pr7fAZ/MJuxNJed9KsgKXef
YP/cpI73dbCZL3SQEPoeYq3md+QukmdE4z/hsea6hXRHLwIOPOOaRrulBTjLPIwo
tTewemdxlTqDujhV7OJz2SxXMgBt08JJsXuS1XP+GKzIK7PIo3qzbfbuOrn3e8GA
Y6w1Tk8M8OMpbvhDQG/8XE8rifH6jgiRxFbVARv7IDHxc4zsINlWIq8j8DRv5jhj
eshDjrn7AgMBAAECggEARZxeutxE/pCypv0IqkFS7IVLccTvt2gfemcC1yzIBFOW
oqgTI3Vrq8tbdbHFq3iFDG+m4qlBi+dWDC3GDoPkVoi7dg//1TqZEOO+sqqu2Afj
pge6tIDfeMxWJifwkkpWRURB9hCknhUSW2bMNyUCs3rgREJVTtsmM9CHnoSKXXQL
aOeYXalFVpx3ceK+xdp0VGfpsqEabBKs0yy3EDiQy2huoWce3EVFLVrwx/IkhcsZ
JlI5LPpoiTglSs1g9i88JHS2slBtKtb1lWl/yXHhK1g7s34c6f9jP8snuFE5ddMn
0L4GDA9teaPGvB533eb2RIFy2kUYgpr5c03G6rpoOQKBgQDpY6BFJkPGENnC5Bdb
fJCuN2nyRdC1qvv6ESFaQYb0s6QjKDqpb0dUSYN3+zNgtiAysbQLeU/d9mmt4UR8
ohjRkOySU0eQ/YNFokjw6g6GPoiMHJJ9cP75NA94uIMIUTY7uHEWWZwXI5UphdPC
p5/3MaF1VlYQys9a5wtiEaDSfQKBgQDOwPV0zQjUabkVQ4yV0amP8xybvHH8ghG0
RMStHg96RfDmg35JQaw22A2xiVROCoZgLqiE1DFSl/3gBF/vfqBh/uzdxwNerJC6
ROdCxyS4rys5d/02P4aNOa73sD+ZKyEZRTF1v3bmOGKidRFF5oxIpuHjFWlJFKx1
O/b3AI0v1wKBgQC/L4N84emm+OrKAfs4UIRckrxRYOulxhmAMkQ2IXOiRP5yZmQX
pDa0TzxJLxhZYxhhLr0koQ3R8CeF7wEhb9AQ7D0/aMU5etLsWhKSd8nKIrPMwyMl
a0kTb5g09kEwsQZSSbcp7eI1+koYp65eyN37q0ZuTnlWbC0MdDQY9APgKQKBgQCb
HqaKNXLUe2XDkGSf2ygOumXSanZS7vt9dsLg59bQ9DyjljBfogglNcBAXTqFOtxK
uXbyAYnn3+U399BKjYSjQXJRioj6tRn4xs2DiooAjlwtx9qQouS+fHLLns54iqVQ
oltTbo00eUV3gcGt4iWKNLrxdxUBIaOqaY0HEMDdDQKBgQCRvcHDF7JSPuBiO3Tw
PSOUD4q6dD/dhI+X2ZKg83w94SZXXms6eMSbedUkLoJ8TDunmdRUUWb6rgP/pJwr
zKRTskItF15i9IWCwC6jBrSfx5n2JcSoBALyc0aR9heF0GQjWwqURd+PC/msomrW
z9SCl8mpQVFtBlui7PcnDLTFAg==
-----END PRIVATE KEY-----

View file

@ -0,0 +1 @@
SSL test works

View file

@ -0,0 +1,6 @@
{
"require": {
"monolog/monolog": "1.0.*"
}
}

13
test/test-app/index.php Normal file
View file

@ -0,0 +1,13 @@
<html>
<head>
<title>Test PHP passed</title>
</head>
<body>
<h1>PHP is working</h1>
<p>
<?php
phpinfo();
?>
</p>
</body>
</html>

View file

@ -0,0 +1,4 @@
<?php
session_start();
echo "Passed";
?>

1418
test/test-lib-openshift.sh Normal file

File diff suppressed because it is too large Load diff

35
test/test-lib-php.sh Normal file
View file

@ -0,0 +1,35 @@
#!/bin/bash
#
# Functions for tests for the PHP image in OpenShift.
#
# IMAGE_NAME specifies a name of the candidate image used for testing.
# The image has to be available before this script is executed.
#
THISDIR=$(dirname ${BASH_SOURCE[0]})
source ${THISDIR}/test-lib.sh
source ${THISDIR}/test-lib-openshift.sh
function test_php_integration() {
local image_name=$1
ct_os_test_s2i_app "${image_name}" \
"https://github.com/sclorg/s2i-php-container.git" \
"test/test-app" \
"Test PHP passed"
}
# Check the imagestream
function test_php_imagestream() {
case ${OS} in
rhel7|centos7) ;;
*) echo "Imagestream testing not supported for $OS environment." ; return 0 ;;
esac
ct_os_test_image_stream_s2i "${THISDIR}/imagestreams/php-${OS%[0-9]*}.json" "${IMAGE_NAME}" \
"https://github.com/sclorg/s2i-php-container.git" \
test/test-app \
"Test PHP passed"
}
# vim: set tabstop=2:shiftwidth=2:expandtab:

View file

@ -0,0 +1,87 @@
# shellcheck shell=bash
# some functions are used from test-lib.sh, that is usually in the same dir
# shellcheck source=/dev/null
source "$(dirname "${BASH_SOURCE[0]}")"/test-lib.sh
# Set of functions for testing docker images in OpenShift using 'oc' command
# A variable containing the overall test result
# TESTSUITE_RESULT=0
# And the following trap must be set, in the beginning of the test script:
# trap ct_os_cleanup EXIT SIGINT
# ct_os_set_path_oc_4 OC_VERSION
# --------------------
# This is a trick that helps using correct version 4 of the `oc`:
# The input is version of the openshift in format 4.4 etc.
# If the currently available version of oc is not of this version,
# it first takes a look into /usr/local/oc-<ver>/bin directory,
# Arguments: oc_version - X.Y part of the version of OSE (e.g. 3.9)
function ct_os_set_path_oc_4() {
echo "Setting OCP4 client"
local oc_version=$1
local installed_oc_path="/usr/local/oc-v${oc_version}/bin"
echo "PATH ${installed_oc_path}"
if [ -x "${installed_oc_path}/oc" ] ; then
oc_path="${installed_oc_path}"
echo "Binary oc found in ${installed_oc_path}" >&2
else
echo "OCP4 not found"
return 1
fi
export PATH="${oc_path}:${PATH}"
}
# ct_os_prepare_ocp4
# ------------------
# Prepares environment for testing images in OpenShift 4 environment
#
#
function ct_os_set_ocp4() {
if [ "${CVP:-0}" -eq "1" ]; then
echo "Testing in CVP environment. No need to login to OpenShift cluster. This is already done by CVP pipeline."
return
fi
local login
OS_OC_CLIENT_VERSION=${OS_OC_CLIENT_VERSION:-4.4}
ct_os_set_path_oc_4 "${OS_OC_CLIENT_VERSION}"
login=$(cat "$KUBEPASSWORD")
oc login -u kubeadmin -p "$login"
oc version
if ! oc version | grep -q "Client Version: ${OS_OC_CLIENT_VERSION}." ; then
echo "ERROR: something went wrong, oc located at ${oc_path}, but oc of version ${OS_OC_CLIENT_VERSION} not found in PATH ($PATH)" >&1
return 1
else
echo "PATH set correctly, binary oc found in version ${OS_OC_CLIENT_VERSION}: $(command -v oc)"
fi
echo "Login to OpenShift ${OS_OC_CLIENT_VERSION} is DONE"
# let openshift cluster to sync to avoid some race condition errors
sleep 3
}
function ct_os_upload_image_external_registry() {
local input_name="${1}" ; shift
local image_name=${input_name##*/}
local imagestream=${1:-$image_name:latest}
local output_name
ct_os_login_external_registry
output_name="${INTERNAL_DOCKER_REGISTRY}/rhscl-ci-testing/$imagestream"
docker images
docker tag "${input_name}" "${output_name}"
docker push "${output_name}"
}
function ct_os_import_image_ocp4() {
local image_name="${1}"; shift
local imagestream=${1:-$image_name:latest}
echo "Uploading image ${image_name} as ${imagestream} into OpenShift internal registry."
ct_os_upload_image_v4 "${image_name}" "${imagestream}"
}

1190
test/test-lib.sh Normal file

File diff suppressed because it is too large Load diff