Compare commits
1 commit
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8d712db213 |
38 changed files with 2350 additions and 1476 deletions
|
|
@ -1,29 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
shopt -s dotglob
|
|
||||||
echo "---> Installing application source..."
|
|
||||||
mv /tmp/src/* ./
|
|
||||||
|
|
||||||
if [ -f composer.json ]; then
|
|
||||||
echo "Found 'composer.json', installing dependencies using composer.phar... "
|
|
||||||
|
|
||||||
# Install Composer
|
|
||||||
curl https://getcomposer.org/installer | php
|
|
||||||
|
|
||||||
# Change the repo mirror if provided
|
|
||||||
if [ -n "$COMPOSER_MIRROR" ]; then
|
|
||||||
./composer.phar config -g repositories.packagist composer $COMPOSER_MIRROR
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Install App dependencies using Composer
|
|
||||||
./composer.phar install --no-interaction --no-ansi --optimize-autoloader
|
|
||||||
|
|
||||||
if [ ! -f composer.lock ]; then
|
|
||||||
echo -e "\nConsider adding a 'composer.lock' file into your source repository.\n"
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Fix source directory permissions
|
|
||||||
fix-permissions ./
|
|
||||||
|
|
@ -1,12 +0,0 @@
|
||||||
#!/bin/bash -e
|
|
||||||
cat <<EOF
|
|
||||||
This is the php S2I image:
|
|
||||||
To use it, install S2I: https://github.com/openshift/source-to-image
|
|
||||||
|
|
||||||
Sample invocation:
|
|
||||||
|
|
||||||
s2i build <source code path/URL> php <application image>
|
|
||||||
|
|
||||||
You can then run the resulting image via:
|
|
||||||
docker run <application image>
|
|
||||||
EOF
|
|
||||||
1
7.1
Symbolic link
1
7.1
Symbolic link
|
|
@ -0,0 +1 @@
|
||||||
|
.
|
||||||
131
Dockerfile
131
Dockerfile
|
|
@ -1,84 +1,87 @@
|
||||||
FROM registry.fedoraproject.org/fedora:26
|
FROM registry.fedoraproject.org/f27/s2i-base:latest
|
||||||
|
|
||||||
# Description
|
# This image provides an Apache+PHP environment for running PHP
|
||||||
# This image provides an Apache 2.4 + PHP 7.0 environment for running PHP applications.
|
# applications.
|
||||||
# Exposed ports:
|
|
||||||
# * 8080 - alternative port for http
|
|
||||||
# Additional packages
|
|
||||||
# * git, zip, unzip are needed for composer
|
|
||||||
# * gettext is needed for `envsubst` command used by scripts
|
|
||||||
# * findutils for fixing permissions
|
|
||||||
# * python for cgroup limits helper script
|
|
||||||
|
|
||||||
LABEL MAINTAINER Rado Pitonak <rpitonak@redhat.com>
|
EXPOSE 8080
|
||||||
|
EXPOSE 8443
|
||||||
|
|
||||||
RUN dnf install -y --setopt=tsflags=nodocs php php-opcache && \
|
ENV PHP_VERSION=7.1 \
|
||||||
dnf install -y --setopt=tsflags=nodocs httpd && \
|
PATH=$PATH:/usr/bin
|
||||||
dnf install -y --setopt=tsflags=nodocs git gettext zip unzip findutils python && \
|
|
||||||
dnf -y clean all
|
|
||||||
|
|
||||||
ENV PHP_VERSION=7.0 \
|
ENV SUMMARY="Platform for building and running PHP $PHP_VERSION applications" \
|
||||||
NAME=php\
|
DESCRIPTION="PHP $PHP_VERSION available as container is a base platform for \
|
||||||
|
building and running various PHP $PHP_VERSION applications and frameworks. \
|
||||||
|
PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers \
|
||||||
|
to write dynamically generated web pages. PHP also offers built-in database integration \
|
||||||
|
for several commercial and non-commercial database management systems, so writing \
|
||||||
|
a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding \
|
||||||
|
is probably as a replacement for CGI scripts."
|
||||||
|
|
||||||
|
ENV NAME=php \
|
||||||
VERSION=0 \
|
VERSION=0 \
|
||||||
RELEASE=1 \
|
RELEASE=1 \
|
||||||
ARCH=x86_64
|
ARCH=x86_64
|
||||||
|
|
||||||
ENV HOME=/opt/app-root
|
LABEL summary="$SUMMARY" \
|
||||||
|
description="$DESCRIPTION" \
|
||||||
LABEL summary="php runtime" \
|
io.k8s.description="$DESCRIPTION" \
|
||||||
|
io.k8s.display-name="Apache 2.4 with PHP 7.1" \
|
||||||
|
io.openshift.expose-services="8080:http" \
|
||||||
|
io.openshift.tags="builder,php,php71,rh-php71" \
|
||||||
name="$FGC/$NAME" \
|
name="$FGC/$NAME" \
|
||||||
version="$VERSION" \
|
|
||||||
release="$RELEASE.$DISTTAG" \
|
|
||||||
architecture="$ARCH" \
|
|
||||||
description="Platform for building and running PHP 7.0 applications." \
|
|
||||||
vendor="Fedora Project" \
|
|
||||||
com.redhat.component="$NAME" \
|
com.redhat.component="$NAME" \
|
||||||
usage="s2i build <SOURCE-REPOSITORY> php <APP-NAME>" \
|
version="$VERSION" \
|
||||||
org.fedoraproject.component="php" \
|
usage="s2i build https://github.com/sclorg/s2i-php-container.git --context-dir=/7.1/test/test-app $FGC/$NAME sample-server" \
|
||||||
authoritative-source-url="registry.fedoraproject.org" \
|
maintainer="SoftwareCollections.org <sclorg@redhat.com>"
|
||||||
io.k8s.description="Platform for building and running PHP 7.0 applications." \
|
|
||||||
io.k8s.display-name="Apache 2.4 with PHP 7.0" \
|
|
||||||
io.openshift.tags="builder,php,php70" \
|
|
||||||
io.openshift.expose-services="8080:https" \
|
|
||||||
io.openshift.s2i.scripts-url="image:///usr/local/s2i"
|
|
||||||
|
|
||||||
# S2I scripts
|
# Install Apache httpd and PHP
|
||||||
COPY ./.s2i/bin/ /usr/local/s2i
|
RUN INSTALL_PKGS="php php-mysqlnd php-bcmath \
|
||||||
|
php-gd php-intl php-ldap php-mbstring php-pdo \
|
||||||
|
php-process php-soap php-opcache php-xml \
|
||||||
|
php-gmp php-pecl-apcu mod_ssl hostname" && \
|
||||||
|
yum install -y --setopt=tsflags=nodocs $INSTALL_PKGS --nogpgcheck && \
|
||||||
|
rpm -V $INSTALL_PKGS && \
|
||||||
|
yum clean all -y
|
||||||
|
|
||||||
# Copy executable utilities.
|
ENV PHP_CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/php/ \
|
||||||
COPY bin/ /usr/bin/
|
APP_DATA=${APP_ROOT}/src \
|
||||||
|
PHP_DEFAULT_INCLUDE_PATH=/usr/share/pear \
|
||||||
|
PHP_SYSCONF_PATH=/etc/ \
|
||||||
|
PHP_HTTPD_CONF_FILE=php.conf \
|
||||||
|
HTTPD_CONFIGURATION_PATH=${APP_ROOT}/etc/conf.d \
|
||||||
|
HTTPD_MAIN_CONF_PATH=/etc/httpd/conf \
|
||||||
|
HTTPD_MAIN_CONF_D_PATH=/etc/httpd/conf.d \
|
||||||
|
HTTPD_VAR_RUN=/var/run/httpd \
|
||||||
|
HTTPD_DATA_PATH=/var/www \
|
||||||
|
HTTPD_DATA_ORIG_PATH=/var/www \
|
||||||
|
HTTPD_VAR_PATH=/var
|
||||||
|
|
||||||
# Each language image can have 'contrib' a directory with extra files needed to
|
# Copy the S2I scripts from the specific language image to $STI_SCRIPTS_PATH
|
||||||
# run and build the applications.
|
COPY ./s2i/bin/ $STI_SCRIPTS_PATH
|
||||||
COPY ./contrib/ /opt/app-root
|
|
||||||
|
|
||||||
# Add help file
|
# Copy extra files to the image.
|
||||||
COPY root /
|
COPY ./root/ /
|
||||||
|
|
||||||
EXPOSE 8080
|
# Reset permissions of filesystem to default values
|
||||||
|
# Generate SSL certs and reset permissions of filesystem to default values
|
||||||
|
RUN /usr/libexec/httpd-ssl-gencerts && \
|
||||||
|
/usr/libexec/container-setup && rpm-file-permissions
|
||||||
|
|
||||||
RUN mkdir -p ${HOME} && \
|
# Fedora uses by default 'event' MPM module
|
||||||
useradd -u 1001 -r -g 0 -d ${HOME} -s /sbin/nologin \
|
# switch to 'prefork' to provide same user experience as with RHEL image
|
||||||
-c "Default user" default
|
# Code taken from 'config_mpm()' function in sclorg/httpd-container repo
|
||||||
|
ENV HTTPD_MPM=prefork \
|
||||||
|
HTTPD_MAIN_CONF_MODULES_D_PATH=/etc/httpd/conf.modules.d
|
||||||
|
|
||||||
# In order to drop the root user, we have to make some directories world
|
RUN if [ -v HTTPD_MPM -a -f ${HTTPD_MAIN_CONF_MODULES_D_PATH}/00-mpm.conf ]; then \
|
||||||
# writeable as OpenShift default security model is to run the container under
|
mpmconf=${HTTPD_MAIN_CONF_MODULES_D_PATH}/00-mpm.conf; \
|
||||||
# random UID.
|
sed -i -e 's,^LoadModule,#LoadModule,' ${mpmconf}; \
|
||||||
RUN mkdir -p ${HOME}/src && \
|
sed -i -e "/LoadModule mpm_${HTTPD_MPM}/s,^#LoadModule,LoadModule," ${mpmconf}; \
|
||||||
sed -i -f /opt/app-root/etc/httpdconf.sed /etc/httpd/conf/httpd.conf && \
|
echo "---> Set MPM to ${HTTPD_MPM} in ${mpmconf}"; \
|
||||||
head -n151 /etc/httpd/conf/httpd.conf | tail -n1 | grep "AllowOverride All" || exit && \
|
fi
|
||||||
echo "IncludeOptional /opt/app-root/etc/conf.d/*.conf" >> /etc/httpd/conf/httpd.conf && \
|
|
||||||
mkdir /tmp/sessions && \
|
|
||||||
chown -R 1001:0 /opt/app-root /tmp/sessions && \
|
|
||||||
chmod -R a+rwx /tmp/sessions && \
|
|
||||||
chmod -R ug+rwx /opt/app-root && \
|
|
||||||
chmod -R a+rwx /etc/php.d && \
|
|
||||||
chmod -R a+rwx /etc/php.ini && \
|
|
||||||
chmod -R a+rwx /run/httpd
|
|
||||||
|
|
||||||
USER 1001
|
USER 1001
|
||||||
|
|
||||||
WORKDIR ${HOME}/src
|
# Set the default CMD to print the usage of the language image
|
||||||
|
CMD $STI_SCRIPTS_PATH/usage
|
||||||
# Command which will start service during command `docker run`
|
|
||||||
CMD /usr/local/s2i/usage
|
|
||||||
|
|
|
||||||
1
Dockerfile.fedora
Symbolic link
1
Dockerfile.fedora
Symbolic link
|
|
@ -0,0 +1 @@
|
||||||
|
Dockerfile
|
||||||
674
LICENSE
674
LICENSE
|
|
@ -1,674 +0,0 @@
|
||||||
GNU GENERAL PUBLIC LICENSE
|
|
||||||
Version 3, 29 June 2007
|
|
||||||
|
|
||||||
Copyright (C) 2007 Free Software Foundation, Inc. <http://fsf.org/>
|
|
||||||
Everyone is permitted to copy and distribute verbatim copies
|
|
||||||
of this license document, but changing it is not allowed.
|
|
||||||
|
|
||||||
Preamble
|
|
||||||
|
|
||||||
The GNU General Public License is a free, copyleft license for
|
|
||||||
software and other kinds of works.
|
|
||||||
|
|
||||||
The licenses for most software and other practical works are designed
|
|
||||||
to take away your freedom to share and change the works. By contrast,
|
|
||||||
the GNU General Public License is intended to guarantee your freedom to
|
|
||||||
share and change all versions of a program--to make sure it remains free
|
|
||||||
software for all its users. We, the Free Software Foundation, use the
|
|
||||||
GNU General Public License for most of our software; it applies also to
|
|
||||||
any other work released this way by its authors. You can apply it to
|
|
||||||
your programs, too.
|
|
||||||
|
|
||||||
When we speak of free software, we are referring to freedom, not
|
|
||||||
price. Our General Public Licenses are designed to make sure that you
|
|
||||||
have the freedom to distribute copies of free software (and charge for
|
|
||||||
them if you wish), that you receive source code or can get it if you
|
|
||||||
want it, that you can change the software or use pieces of it in new
|
|
||||||
free programs, and that you know you can do these things.
|
|
||||||
|
|
||||||
To protect your rights, we need to prevent others from denying you
|
|
||||||
these rights or asking you to surrender the rights. Therefore, you have
|
|
||||||
certain responsibilities if you distribute copies of the software, or if
|
|
||||||
you modify it: responsibilities to respect the freedom of others.
|
|
||||||
|
|
||||||
For example, if you distribute copies of such a program, whether
|
|
||||||
gratis or for a fee, you must pass on to the recipients the same
|
|
||||||
freedoms that you received. You must make sure that they, too, receive
|
|
||||||
or can get the source code. And you must show them these terms so they
|
|
||||||
know their rights.
|
|
||||||
|
|
||||||
Developers that use the GNU GPL protect your rights with two steps:
|
|
||||||
(1) assert copyright on the software, and (2) offer you this License
|
|
||||||
giving you legal permission to copy, distribute and/or modify it.
|
|
||||||
|
|
||||||
For the developers' and authors' protection, the GPL clearly explains
|
|
||||||
that there is no warranty for this free software. For both users' and
|
|
||||||
authors' sake, the GPL requires that modified versions be marked as
|
|
||||||
changed, so that their problems will not be attributed erroneously to
|
|
||||||
authors of previous versions.
|
|
||||||
|
|
||||||
Some devices are designed to deny users access to install or run
|
|
||||||
modified versions of the software inside them, although the manufacturer
|
|
||||||
can do so. This is fundamentally incompatible with the aim of
|
|
||||||
protecting users' freedom to change the software. The systematic
|
|
||||||
pattern of such abuse occurs in the area of products for individuals to
|
|
||||||
use, which is precisely where it is most unacceptable. Therefore, we
|
|
||||||
have designed this version of the GPL to prohibit the practice for those
|
|
||||||
products. If such problems arise substantially in other domains, we
|
|
||||||
stand ready to extend this provision to those domains in future versions
|
|
||||||
of the GPL, as needed to protect the freedom of users.
|
|
||||||
|
|
||||||
Finally, every program is threatened constantly by software patents.
|
|
||||||
States should not allow patents to restrict development and use of
|
|
||||||
software on general-purpose computers, but in those that do, we wish to
|
|
||||||
avoid the special danger that patents applied to a free program could
|
|
||||||
make it effectively proprietary. To prevent this, the GPL assures that
|
|
||||||
patents cannot be used to render the program non-free.
|
|
||||||
|
|
||||||
The precise terms and conditions for copying, distribution and
|
|
||||||
modification follow.
|
|
||||||
|
|
||||||
TERMS AND CONDITIONS
|
|
||||||
|
|
||||||
0. Definitions.
|
|
||||||
|
|
||||||
"This License" refers to version 3 of the GNU General Public License.
|
|
||||||
|
|
||||||
"Copyright" also means copyright-like laws that apply to other kinds of
|
|
||||||
works, such as semiconductor masks.
|
|
||||||
|
|
||||||
"The Program" refers to any copyrightable work licensed under this
|
|
||||||
License. Each licensee is addressed as "you". "Licensees" and
|
|
||||||
"recipients" may be individuals or organizations.
|
|
||||||
|
|
||||||
To "modify" a work means to copy from or adapt all or part of the work
|
|
||||||
in a fashion requiring copyright permission, other than the making of an
|
|
||||||
exact copy. The resulting work is called a "modified version" of the
|
|
||||||
earlier work or a work "based on" the earlier work.
|
|
||||||
|
|
||||||
A "covered work" means either the unmodified Program or a work based
|
|
||||||
on the Program.
|
|
||||||
|
|
||||||
To "propagate" a work means to do anything with it that, without
|
|
||||||
permission, would make you directly or secondarily liable for
|
|
||||||
infringement under applicable copyright law, except executing it on a
|
|
||||||
computer or modifying a private copy. Propagation includes copying,
|
|
||||||
distribution (with or without modification), making available to the
|
|
||||||
public, and in some countries other activities as well.
|
|
||||||
|
|
||||||
To "convey" a work means any kind of propagation that enables other
|
|
||||||
parties to make or receive copies. Mere interaction with a user through
|
|
||||||
a computer network, with no transfer of a copy, is not conveying.
|
|
||||||
|
|
||||||
An interactive user interface displays "Appropriate Legal Notices"
|
|
||||||
to the extent that it includes a convenient and prominently visible
|
|
||||||
feature that (1) displays an appropriate copyright notice, and (2)
|
|
||||||
tells the user that there is no warranty for the work (except to the
|
|
||||||
extent that warranties are provided), that licensees may convey the
|
|
||||||
work under this License, and how to view a copy of this License. If
|
|
||||||
the interface presents a list of user commands or options, such as a
|
|
||||||
menu, a prominent item in the list meets this criterion.
|
|
||||||
|
|
||||||
1. Source Code.
|
|
||||||
|
|
||||||
The "source code" for a work means the preferred form of the work
|
|
||||||
for making modifications to it. "Object code" means any non-source
|
|
||||||
form of a work.
|
|
||||||
|
|
||||||
A "Standard Interface" means an interface that either is an official
|
|
||||||
standard defined by a recognized standards body, or, in the case of
|
|
||||||
interfaces specified for a particular programming language, one that
|
|
||||||
is widely used among developers working in that language.
|
|
||||||
|
|
||||||
The "System Libraries" of an executable work include anything, other
|
|
||||||
than the work as a whole, that (a) is included in the normal form of
|
|
||||||
packaging a Major Component, but which is not part of that Major
|
|
||||||
Component, and (b) serves only to enable use of the work with that
|
|
||||||
Major Component, or to implement a Standard Interface for which an
|
|
||||||
implementation is available to the public in source code form. A
|
|
||||||
"Major Component", in this context, means a major essential component
|
|
||||||
(kernel, window system, and so on) of the specific operating system
|
|
||||||
(if any) on which the executable work runs, or a compiler used to
|
|
||||||
produce the work, or an object code interpreter used to run it.
|
|
||||||
|
|
||||||
The "Corresponding Source" for a work in object code form means all
|
|
||||||
the source code needed to generate, install, and (for an executable
|
|
||||||
work) run the object code and to modify the work, including scripts to
|
|
||||||
control those activities. However, it does not include the work's
|
|
||||||
System Libraries, or general-purpose tools or generally available free
|
|
||||||
programs which are used unmodified in performing those activities but
|
|
||||||
which are not part of the work. For example, Corresponding Source
|
|
||||||
includes interface definition files associated with source files for
|
|
||||||
the work, and the source code for shared libraries and dynamically
|
|
||||||
linked subprograms that the work is specifically designed to require,
|
|
||||||
such as by intimate data communication or control flow between those
|
|
||||||
subprograms and other parts of the work.
|
|
||||||
|
|
||||||
The Corresponding Source need not include anything that users
|
|
||||||
can regenerate automatically from other parts of the Corresponding
|
|
||||||
Source.
|
|
||||||
|
|
||||||
The Corresponding Source for a work in source code form is that
|
|
||||||
same work.
|
|
||||||
|
|
||||||
2. Basic Permissions.
|
|
||||||
|
|
||||||
All rights granted under this License are granted for the term of
|
|
||||||
copyright on the Program, and are irrevocable provided the stated
|
|
||||||
conditions are met. This License explicitly affirms your unlimited
|
|
||||||
permission to run the unmodified Program. The output from running a
|
|
||||||
covered work is covered by this License only if the output, given its
|
|
||||||
content, constitutes a covered work. This License acknowledges your
|
|
||||||
rights of fair use or other equivalent, as provided by copyright law.
|
|
||||||
|
|
||||||
You may make, run and propagate covered works that you do not
|
|
||||||
convey, without conditions so long as your license otherwise remains
|
|
||||||
in force. You may convey covered works to others for the sole purpose
|
|
||||||
of having them make modifications exclusively for you, or provide you
|
|
||||||
with facilities for running those works, provided that you comply with
|
|
||||||
the terms of this License in conveying all material for which you do
|
|
||||||
not control copyright. Those thus making or running the covered works
|
|
||||||
for you must do so exclusively on your behalf, under your direction
|
|
||||||
and control, on terms that prohibit them from making any copies of
|
|
||||||
your copyrighted material outside their relationship with you.
|
|
||||||
|
|
||||||
Conveying under any other circumstances is permitted solely under
|
|
||||||
the conditions stated below. Sublicensing is not allowed; section 10
|
|
||||||
makes it unnecessary.
|
|
||||||
|
|
||||||
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
|
|
||||||
|
|
||||||
No covered work shall be deemed part of an effective technological
|
|
||||||
measure under any applicable law fulfilling obligations under article
|
|
||||||
11 of the WIPO copyright treaty adopted on 20 December 1996, or
|
|
||||||
similar laws prohibiting or restricting circumvention of such
|
|
||||||
measures.
|
|
||||||
|
|
||||||
When you convey a covered work, you waive any legal power to forbid
|
|
||||||
circumvention of technological measures to the extent such circumvention
|
|
||||||
is effected by exercising rights under this License with respect to
|
|
||||||
the covered work, and you disclaim any intention to limit operation or
|
|
||||||
modification of the work as a means of enforcing, against the work's
|
|
||||||
users, your or third parties' legal rights to forbid circumvention of
|
|
||||||
technological measures.
|
|
||||||
|
|
||||||
4. Conveying Verbatim Copies.
|
|
||||||
|
|
||||||
You may convey verbatim copies of the Program's source code as you
|
|
||||||
receive it, in any medium, provided that you conspicuously and
|
|
||||||
appropriately publish on each copy an appropriate copyright notice;
|
|
||||||
keep intact all notices stating that this License and any
|
|
||||||
non-permissive terms added in accord with section 7 apply to the code;
|
|
||||||
keep intact all notices of the absence of any warranty; and give all
|
|
||||||
recipients a copy of this License along with the Program.
|
|
||||||
|
|
||||||
You may charge any price or no price for each copy that you convey,
|
|
||||||
and you may offer support or warranty protection for a fee.
|
|
||||||
|
|
||||||
5. Conveying Modified Source Versions.
|
|
||||||
|
|
||||||
You may convey a work based on the Program, or the modifications to
|
|
||||||
produce it from the Program, in the form of source code under the
|
|
||||||
terms of section 4, provided that you also meet all of these conditions:
|
|
||||||
|
|
||||||
a) The work must carry prominent notices stating that you modified
|
|
||||||
it, and giving a relevant date.
|
|
||||||
|
|
||||||
b) The work must carry prominent notices stating that it is
|
|
||||||
released under this License and any conditions added under section
|
|
||||||
7. This requirement modifies the requirement in section 4 to
|
|
||||||
"keep intact all notices".
|
|
||||||
|
|
||||||
c) You must license the entire work, as a whole, under this
|
|
||||||
License to anyone who comes into possession of a copy. This
|
|
||||||
License will therefore apply, along with any applicable section 7
|
|
||||||
additional terms, to the whole of the work, and all its parts,
|
|
||||||
regardless of how they are packaged. This License gives no
|
|
||||||
permission to license the work in any other way, but it does not
|
|
||||||
invalidate such permission if you have separately received it.
|
|
||||||
|
|
||||||
d) If the work has interactive user interfaces, each must display
|
|
||||||
Appropriate Legal Notices; however, if the Program has interactive
|
|
||||||
interfaces that do not display Appropriate Legal Notices, your
|
|
||||||
work need not make them do so.
|
|
||||||
|
|
||||||
A compilation of a covered work with other separate and independent
|
|
||||||
works, which are not by their nature extensions of the covered work,
|
|
||||||
and which are not combined with it such as to form a larger program,
|
|
||||||
in or on a volume of a storage or distribution medium, is called an
|
|
||||||
"aggregate" if the compilation and its resulting copyright are not
|
|
||||||
used to limit the access or legal rights of the compilation's users
|
|
||||||
beyond what the individual works permit. Inclusion of a covered work
|
|
||||||
in an aggregate does not cause this License to apply to the other
|
|
||||||
parts of the aggregate.
|
|
||||||
|
|
||||||
6. Conveying Non-Source Forms.
|
|
||||||
|
|
||||||
You may convey a covered work in object code form under the terms
|
|
||||||
of sections 4 and 5, provided that you also convey the
|
|
||||||
machine-readable Corresponding Source under the terms of this License,
|
|
||||||
in one of these ways:
|
|
||||||
|
|
||||||
a) Convey the object code in, or embodied in, a physical product
|
|
||||||
(including a physical distribution medium), accompanied by the
|
|
||||||
Corresponding Source fixed on a durable physical medium
|
|
||||||
customarily used for software interchange.
|
|
||||||
|
|
||||||
b) Convey the object code in, or embodied in, a physical product
|
|
||||||
(including a physical distribution medium), accompanied by a
|
|
||||||
written offer, valid for at least three years and valid for as
|
|
||||||
long as you offer spare parts or customer support for that product
|
|
||||||
model, to give anyone who possesses the object code either (1) a
|
|
||||||
copy of the Corresponding Source for all the software in the
|
|
||||||
product that is covered by this License, on a durable physical
|
|
||||||
medium customarily used for software interchange, for a price no
|
|
||||||
more than your reasonable cost of physically performing this
|
|
||||||
conveying of source, or (2) access to copy the
|
|
||||||
Corresponding Source from a network server at no charge.
|
|
||||||
|
|
||||||
c) Convey individual copies of the object code with a copy of the
|
|
||||||
written offer to provide the Corresponding Source. This
|
|
||||||
alternative is allowed only occasionally and noncommercially, and
|
|
||||||
only if you received the object code with such an offer, in accord
|
|
||||||
with subsection 6b.
|
|
||||||
|
|
||||||
d) Convey the object code by offering access from a designated
|
|
||||||
place (gratis or for a charge), and offer equivalent access to the
|
|
||||||
Corresponding Source in the same way through the same place at no
|
|
||||||
further charge. You need not require recipients to copy the
|
|
||||||
Corresponding Source along with the object code. If the place to
|
|
||||||
copy the object code is a network server, the Corresponding Source
|
|
||||||
may be on a different server (operated by you or a third party)
|
|
||||||
that supports equivalent copying facilities, provided you maintain
|
|
||||||
clear directions next to the object code saying where to find the
|
|
||||||
Corresponding Source. Regardless of what server hosts the
|
|
||||||
Corresponding Source, you remain obligated to ensure that it is
|
|
||||||
available for as long as needed to satisfy these requirements.
|
|
||||||
|
|
||||||
e) Convey the object code using peer-to-peer transmission, provided
|
|
||||||
you inform other peers where the object code and Corresponding
|
|
||||||
Source of the work are being offered to the general public at no
|
|
||||||
charge under subsection 6d.
|
|
||||||
|
|
||||||
A separable portion of the object code, whose source code is excluded
|
|
||||||
from the Corresponding Source as a System Library, need not be
|
|
||||||
included in conveying the object code work.
|
|
||||||
|
|
||||||
A "User Product" is either (1) a "consumer product", which means any
|
|
||||||
tangible personal property which is normally used for personal, family,
|
|
||||||
or household purposes, or (2) anything designed or sold for incorporation
|
|
||||||
into a dwelling. In determining whether a product is a consumer product,
|
|
||||||
doubtful cases shall be resolved in favor of coverage. For a particular
|
|
||||||
product received by a particular user, "normally used" refers to a
|
|
||||||
typical or common use of that class of product, regardless of the status
|
|
||||||
of the particular user or of the way in which the particular user
|
|
||||||
actually uses, or expects or is expected to use, the product. A product
|
|
||||||
is a consumer product regardless of whether the product has substantial
|
|
||||||
commercial, industrial or non-consumer uses, unless such uses represent
|
|
||||||
the only significant mode of use of the product.
|
|
||||||
|
|
||||||
"Installation Information" for a User Product means any methods,
|
|
||||||
procedures, authorization keys, or other information required to install
|
|
||||||
and execute modified versions of a covered work in that User Product from
|
|
||||||
a modified version of its Corresponding Source. The information must
|
|
||||||
suffice to ensure that the continued functioning of the modified object
|
|
||||||
code is in no case prevented or interfered with solely because
|
|
||||||
modification has been made.
|
|
||||||
|
|
||||||
If you convey an object code work under this section in, or with, or
|
|
||||||
specifically for use in, a User Product, and the conveying occurs as
|
|
||||||
part of a transaction in which the right of possession and use of the
|
|
||||||
User Product is transferred to the recipient in perpetuity or for a
|
|
||||||
fixed term (regardless of how the transaction is characterized), the
|
|
||||||
Corresponding Source conveyed under this section must be accompanied
|
|
||||||
by the Installation Information. But this requirement does not apply
|
|
||||||
if neither you nor any third party retains the ability to install
|
|
||||||
modified object code on the User Product (for example, the work has
|
|
||||||
been installed in ROM).
|
|
||||||
|
|
||||||
The requirement to provide Installation Information does not include a
|
|
||||||
requirement to continue to provide support service, warranty, or updates
|
|
||||||
for a work that has been modified or installed by the recipient, or for
|
|
||||||
the User Product in which it has been modified or installed. Access to a
|
|
||||||
network may be denied when the modification itself materially and
|
|
||||||
adversely affects the operation of the network or violates the rules and
|
|
||||||
protocols for communication across the network.
|
|
||||||
|
|
||||||
Corresponding Source conveyed, and Installation Information provided,
|
|
||||||
in accord with this section must be in a format that is publicly
|
|
||||||
documented (and with an implementation available to the public in
|
|
||||||
source code form), and must require no special password or key for
|
|
||||||
unpacking, reading or copying.
|
|
||||||
|
|
||||||
7. Additional Terms.
|
|
||||||
|
|
||||||
"Additional permissions" are terms that supplement the terms of this
|
|
||||||
License by making exceptions from one or more of its conditions.
|
|
||||||
Additional permissions that are applicable to the entire Program shall
|
|
||||||
be treated as though they were included in this License, to the extent
|
|
||||||
that they are valid under applicable law. If additional permissions
|
|
||||||
apply only to part of the Program, that part may be used separately
|
|
||||||
under those permissions, but the entire Program remains governed by
|
|
||||||
this License without regard to the additional permissions.
|
|
||||||
|
|
||||||
When you convey a copy of a covered work, you may at your option
|
|
||||||
remove any additional permissions from that copy, or from any part of
|
|
||||||
it. (Additional permissions may be written to require their own
|
|
||||||
removal in certain cases when you modify the work.) You may place
|
|
||||||
additional permissions on material, added by you to a covered work,
|
|
||||||
for which you have or can give appropriate copyright permission.
|
|
||||||
|
|
||||||
Notwithstanding any other provision of this License, for material you
|
|
||||||
add to a covered work, you may (if authorized by the copyright holders of
|
|
||||||
that material) supplement the terms of this License with terms:
|
|
||||||
|
|
||||||
a) Disclaiming warranty or limiting liability differently from the
|
|
||||||
terms of sections 15 and 16 of this License; or
|
|
||||||
|
|
||||||
b) Requiring preservation of specified reasonable legal notices or
|
|
||||||
author attributions in that material or in the Appropriate Legal
|
|
||||||
Notices displayed by works containing it; or
|
|
||||||
|
|
||||||
c) Prohibiting misrepresentation of the origin of that material, or
|
|
||||||
requiring that modified versions of such material be marked in
|
|
||||||
reasonable ways as different from the original version; or
|
|
||||||
|
|
||||||
d) Limiting the use for publicity purposes of names of licensors or
|
|
||||||
authors of the material; or
|
|
||||||
|
|
||||||
e) Declining to grant rights under trademark law for use of some
|
|
||||||
trade names, trademarks, or service marks; or
|
|
||||||
|
|
||||||
f) Requiring indemnification of licensors and authors of that
|
|
||||||
material by anyone who conveys the material (or modified versions of
|
|
||||||
it) with contractual assumptions of liability to the recipient, for
|
|
||||||
any liability that these contractual assumptions directly impose on
|
|
||||||
those licensors and authors.
|
|
||||||
|
|
||||||
All other non-permissive additional terms are considered "further
|
|
||||||
restrictions" within the meaning of section 10. If the Program as you
|
|
||||||
received it, or any part of it, contains a notice stating that it is
|
|
||||||
governed by this License along with a term that is a further
|
|
||||||
restriction, you may remove that term. If a license document contains
|
|
||||||
a further restriction but permits relicensing or conveying under this
|
|
||||||
License, you may add to a covered work material governed by the terms
|
|
||||||
of that license document, provided that the further restriction does
|
|
||||||
not survive such relicensing or conveying.
|
|
||||||
|
|
||||||
If you add terms to a covered work in accord with this section, you
|
|
||||||
must place, in the relevant source files, a statement of the
|
|
||||||
additional terms that apply to those files, or a notice indicating
|
|
||||||
where to find the applicable terms.
|
|
||||||
|
|
||||||
Additional terms, permissive or non-permissive, may be stated in the
|
|
||||||
form of a separately written license, or stated as exceptions;
|
|
||||||
the above requirements apply either way.
|
|
||||||
|
|
||||||
8. Termination.
|
|
||||||
|
|
||||||
You may not propagate or modify a covered work except as expressly
|
|
||||||
provided under this License. Any attempt otherwise to propagate or
|
|
||||||
modify it is void, and will automatically terminate your rights under
|
|
||||||
this License (including any patent licenses granted under the third
|
|
||||||
paragraph of section 11).
|
|
||||||
|
|
||||||
However, if you cease all violation of this License, then your
|
|
||||||
license from a particular copyright holder is reinstated (a)
|
|
||||||
provisionally, unless and until the copyright holder explicitly and
|
|
||||||
finally terminates your license, and (b) permanently, if the copyright
|
|
||||||
holder fails to notify you of the violation by some reasonable means
|
|
||||||
prior to 60 days after the cessation.
|
|
||||||
|
|
||||||
Moreover, your license from a particular copyright holder is
|
|
||||||
reinstated permanently if the copyright holder notifies you of the
|
|
||||||
violation by some reasonable means, this is the first time you have
|
|
||||||
received notice of violation of this License (for any work) from that
|
|
||||||
copyright holder, and you cure the violation prior to 30 days after
|
|
||||||
your receipt of the notice.
|
|
||||||
|
|
||||||
Termination of your rights under this section does not terminate the
|
|
||||||
licenses of parties who have received copies or rights from you under
|
|
||||||
this License. If your rights have been terminated and not permanently
|
|
||||||
reinstated, you do not qualify to receive new licenses for the same
|
|
||||||
material under section 10.
|
|
||||||
|
|
||||||
9. Acceptance Not Required for Having Copies.
|
|
||||||
|
|
||||||
You are not required to accept this License in order to receive or
|
|
||||||
run a copy of the Program. Ancillary propagation of a covered work
|
|
||||||
occurring solely as a consequence of using peer-to-peer transmission
|
|
||||||
to receive a copy likewise does not require acceptance. However,
|
|
||||||
nothing other than this License grants you permission to propagate or
|
|
||||||
modify any covered work. These actions infringe copyright if you do
|
|
||||||
not accept this License. Therefore, by modifying or propagating a
|
|
||||||
covered work, you indicate your acceptance of this License to do so.
|
|
||||||
|
|
||||||
10. Automatic Licensing of Downstream Recipients.
|
|
||||||
|
|
||||||
Each time you convey a covered work, the recipient automatically
|
|
||||||
receives a license from the original licensors, to run, modify and
|
|
||||||
propagate that work, subject to this License. You are not responsible
|
|
||||||
for enforcing compliance by third parties with this License.
|
|
||||||
|
|
||||||
An "entity transaction" is a transaction transferring control of an
|
|
||||||
organization, or substantially all assets of one, or subdividing an
|
|
||||||
organization, or merging organizations. If propagation of a covered
|
|
||||||
work results from an entity transaction, each party to that
|
|
||||||
transaction who receives a copy of the work also receives whatever
|
|
||||||
licenses to the work the party's predecessor in interest had or could
|
|
||||||
give under the previous paragraph, plus a right to possession of the
|
|
||||||
Corresponding Source of the work from the predecessor in interest, if
|
|
||||||
the predecessor has it or can get it with reasonable efforts.
|
|
||||||
|
|
||||||
You may not impose any further restrictions on the exercise of the
|
|
||||||
rights granted or affirmed under this License. For example, you may
|
|
||||||
not impose a license fee, royalty, or other charge for exercise of
|
|
||||||
rights granted under this License, and you may not initiate litigation
|
|
||||||
(including a cross-claim or counterclaim in a lawsuit) alleging that
|
|
||||||
any patent claim is infringed by making, using, selling, offering for
|
|
||||||
sale, or importing the Program or any portion of it.
|
|
||||||
|
|
||||||
11. Patents.
|
|
||||||
|
|
||||||
A "contributor" is a copyright holder who authorizes use under this
|
|
||||||
License of the Program or a work on which the Program is based. The
|
|
||||||
work thus licensed is called the contributor's "contributor version".
|
|
||||||
|
|
||||||
A contributor's "essential patent claims" are all patent claims
|
|
||||||
owned or controlled by the contributor, whether already acquired or
|
|
||||||
hereafter acquired, that would be infringed by some manner, permitted
|
|
||||||
by this License, of making, using, or selling its contributor version,
|
|
||||||
but do not include claims that would be infringed only as a
|
|
||||||
consequence of further modification of the contributor version. For
|
|
||||||
purposes of this definition, "control" includes the right to grant
|
|
||||||
patent sublicenses in a manner consistent with the requirements of
|
|
||||||
this License.
|
|
||||||
|
|
||||||
Each contributor grants you a non-exclusive, worldwide, royalty-free
|
|
||||||
patent license under the contributor's essential patent claims, to
|
|
||||||
make, use, sell, offer for sale, import and otherwise run, modify and
|
|
||||||
propagate the contents of its contributor version.
|
|
||||||
|
|
||||||
In the following three paragraphs, a "patent license" is any express
|
|
||||||
agreement or commitment, however denominated, not to enforce a patent
|
|
||||||
(such as an express permission to practice a patent or covenant not to
|
|
||||||
sue for patent infringement). To "grant" such a patent license to a
|
|
||||||
party means to make such an agreement or commitment not to enforce a
|
|
||||||
patent against the party.
|
|
||||||
|
|
||||||
If you convey a covered work, knowingly relying on a patent license,
|
|
||||||
and the Corresponding Source of the work is not available for anyone
|
|
||||||
to copy, free of charge and under the terms of this License, through a
|
|
||||||
publicly available network server or other readily accessible means,
|
|
||||||
then you must either (1) cause the Corresponding Source to be so
|
|
||||||
available, or (2) arrange to deprive yourself of the benefit of the
|
|
||||||
patent license for this particular work, or (3) arrange, in a manner
|
|
||||||
consistent with the requirements of this License, to extend the patent
|
|
||||||
license to downstream recipients. "Knowingly relying" means you have
|
|
||||||
actual knowledge that, but for the patent license, your conveying the
|
|
||||||
covered work in a country, or your recipient's use of the covered work
|
|
||||||
in a country, would infringe one or more identifiable patents in that
|
|
||||||
country that you have reason to believe are valid.
|
|
||||||
|
|
||||||
If, pursuant to or in connection with a single transaction or
|
|
||||||
arrangement, you convey, or propagate by procuring conveyance of, a
|
|
||||||
covered work, and grant a patent license to some of the parties
|
|
||||||
receiving the covered work authorizing them to use, propagate, modify
|
|
||||||
or convey a specific copy of the covered work, then the patent license
|
|
||||||
you grant is automatically extended to all recipients of the covered
|
|
||||||
work and works based on it.
|
|
||||||
|
|
||||||
A patent license is "discriminatory" if it does not include within
|
|
||||||
the scope of its coverage, prohibits the exercise of, or is
|
|
||||||
conditioned on the non-exercise of one or more of the rights that are
|
|
||||||
specifically granted under this License. You may not convey a covered
|
|
||||||
work if you are a party to an arrangement with a third party that is
|
|
||||||
in the business of distributing software, under which you make payment
|
|
||||||
to the third party based on the extent of your activity of conveying
|
|
||||||
the work, and under which the third party grants, to any of the
|
|
||||||
parties who would receive the covered work from you, a discriminatory
|
|
||||||
patent license (a) in connection with copies of the covered work
|
|
||||||
conveyed by you (or copies made from those copies), or (b) primarily
|
|
||||||
for and in connection with specific products or compilations that
|
|
||||||
contain the covered work, unless you entered into that arrangement,
|
|
||||||
or that patent license was granted, prior to 28 March 2007.
|
|
||||||
|
|
||||||
Nothing in this License shall be construed as excluding or limiting
|
|
||||||
any implied license or other defenses to infringement that may
|
|
||||||
otherwise be available to you under applicable patent law.
|
|
||||||
|
|
||||||
12. No Surrender of Others' Freedom.
|
|
||||||
|
|
||||||
If conditions are imposed on you (whether by court order, agreement or
|
|
||||||
otherwise) that contradict the conditions of this License, they do not
|
|
||||||
excuse you from the conditions of this License. If you cannot convey a
|
|
||||||
covered work so as to satisfy simultaneously your obligations under this
|
|
||||||
License and any other pertinent obligations, then as a consequence you may
|
|
||||||
not convey it at all. For example, if you agree to terms that obligate you
|
|
||||||
to collect a royalty for further conveying from those to whom you convey
|
|
||||||
the Program, the only way you could satisfy both those terms and this
|
|
||||||
License would be to refrain entirely from conveying the Program.
|
|
||||||
|
|
||||||
13. Use with the GNU Affero General Public License.
|
|
||||||
|
|
||||||
Notwithstanding any other provision of this License, you have
|
|
||||||
permission to link or combine any covered work with a work licensed
|
|
||||||
under version 3 of the GNU Affero General Public License into a single
|
|
||||||
combined work, and to convey the resulting work. The terms of this
|
|
||||||
License will continue to apply to the part which is the covered work,
|
|
||||||
but the special requirements of the GNU Affero General Public License,
|
|
||||||
section 13, concerning interaction through a network will apply to the
|
|
||||||
combination as such.
|
|
||||||
|
|
||||||
14. Revised Versions of this License.
|
|
||||||
|
|
||||||
The Free Software Foundation may publish revised and/or new versions of
|
|
||||||
the GNU General Public License from time to time. Such new versions will
|
|
||||||
be similar in spirit to the present version, but may differ in detail to
|
|
||||||
address new problems or concerns.
|
|
||||||
|
|
||||||
Each version is given a distinguishing version number. If the
|
|
||||||
Program specifies that a certain numbered version of the GNU General
|
|
||||||
Public License "or any later version" applies to it, you have the
|
|
||||||
option of following the terms and conditions either of that numbered
|
|
||||||
version or of any later version published by the Free Software
|
|
||||||
Foundation. If the Program does not specify a version number of the
|
|
||||||
GNU General Public License, you may choose any version ever published
|
|
||||||
by the Free Software Foundation.
|
|
||||||
|
|
||||||
If the Program specifies that a proxy can decide which future
|
|
||||||
versions of the GNU General Public License can be used, that proxy's
|
|
||||||
public statement of acceptance of a version permanently authorizes you
|
|
||||||
to choose that version for the Program.
|
|
||||||
|
|
||||||
Later license versions may give you additional or different
|
|
||||||
permissions. However, no additional obligations are imposed on any
|
|
||||||
author or copyright holder as a result of your choosing to follow a
|
|
||||||
later version.
|
|
||||||
|
|
||||||
15. Disclaimer of Warranty.
|
|
||||||
|
|
||||||
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
|
|
||||||
APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
|
|
||||||
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
|
|
||||||
OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
|
|
||||||
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
|
||||||
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
|
|
||||||
IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
|
|
||||||
ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
|
|
||||||
|
|
||||||
16. Limitation of Liability.
|
|
||||||
|
|
||||||
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
|
|
||||||
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS
|
|
||||||
THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY
|
|
||||||
GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE
|
|
||||||
USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
|
|
||||||
DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD
|
|
||||||
PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS),
|
|
||||||
EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
|
|
||||||
SUCH DAMAGES.
|
|
||||||
|
|
||||||
17. Interpretation of Sections 15 and 16.
|
|
||||||
|
|
||||||
If the disclaimer of warranty and limitation of liability provided
|
|
||||||
above cannot be given local legal effect according to their terms,
|
|
||||||
reviewing courts shall apply local law that most closely approximates
|
|
||||||
an absolute waiver of all civil liability in connection with the
|
|
||||||
Program, unless a warranty or assumption of liability accompanies a
|
|
||||||
copy of the Program in return for a fee.
|
|
||||||
|
|
||||||
END OF TERMS AND CONDITIONS
|
|
||||||
|
|
||||||
How to Apply These Terms to Your New Programs
|
|
||||||
|
|
||||||
If you develop a new program, and you want it to be of the greatest
|
|
||||||
possible use to the public, the best way to achieve this is to make it
|
|
||||||
free software which everyone can redistribute and change under these terms.
|
|
||||||
|
|
||||||
To do so, attach the following notices to the program. It is safest
|
|
||||||
to attach them to the start of each source file to most effectively
|
|
||||||
state the exclusion of warranty; and each file should have at least
|
|
||||||
the "copyright" line and a pointer to where the full notice is found.
|
|
||||||
|
|
||||||
{one line to give the program's name and a brief idea of what it does.}
|
|
||||||
Copyright (C) {year} {name of author}
|
|
||||||
|
|
||||||
This program is free software: you can redistribute it and/or modify
|
|
||||||
it under the terms of the GNU General Public License as published by
|
|
||||||
the Free Software Foundation, either version 3 of the License, or
|
|
||||||
(at your option) any later version.
|
|
||||||
|
|
||||||
This program is distributed in the hope that it will be useful,
|
|
||||||
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
||||||
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
||||||
GNU General Public License for more details.
|
|
||||||
|
|
||||||
You should have received a copy of the GNU General Public License
|
|
||||||
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
||||||
|
|
||||||
Also add information on how to contact you by electronic and paper mail.
|
|
||||||
|
|
||||||
If the program does terminal interaction, make it output a short
|
|
||||||
notice like this when it starts in an interactive mode:
|
|
||||||
|
|
||||||
{project} Copyright (C) {year} {fullname}
|
|
||||||
This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
|
|
||||||
This is free software, and you are welcome to redistribute it
|
|
||||||
under certain conditions; type `show c' for details.
|
|
||||||
|
|
||||||
The hypothetical commands `show w' and `show c' should show the appropriate
|
|
||||||
parts of the General Public License. Of course, your program's commands
|
|
||||||
might be different; for a GUI interface, you would use an "about box".
|
|
||||||
|
|
||||||
You should also get your employer (if you work as a programmer) or school,
|
|
||||||
if any, to sign a "copyright disclaimer" for the program, if necessary.
|
|
||||||
For more information on this, and how to apply and follow the GNU GPL, see
|
|
||||||
<http://www.gnu.org/licenses/>.
|
|
||||||
|
|
||||||
The GNU General Public License does not permit incorporating your program
|
|
||||||
into proprietary programs. If your program is a subroutine library, you
|
|
||||||
may consider it more useful to permit linking proprietary applications with
|
|
||||||
the library. If this is what you want to do, use the GNU Lesser General
|
|
||||||
Public License instead of this License. But first, please read
|
|
||||||
<http://www.gnu.org/philosophy/why-not-lgpl.html>.
|
|
||||||
15
Makefile
15
Makefile
|
|
@ -1,15 +0,0 @@
|
||||||
.PHONY: build run test build-test
|
|
||||||
|
|
||||||
IMAGE_NAME=php
|
|
||||||
|
|
||||||
build:
|
|
||||||
docker build --tag=$(IMAGE_NAME) .
|
|
||||||
|
|
||||||
run: build
|
|
||||||
docker run -d -p 8080:8080 $(IMAGE_NAME)
|
|
||||||
|
|
||||||
build-test:
|
|
||||||
docker build --tag=$(IMAGE_NAME)-candidate .
|
|
||||||
|
|
||||||
test: build-test
|
|
||||||
./test/run
|
|
||||||
216
README.md
216
README.md
|
|
@ -1,112 +1,52 @@
|
||||||
PHP Source to image builder
|
PHP 7.1 Docker image
|
||||||
============================
|
================
|
||||||
|
|
||||||
This repository contains the source for building various versions of
|
This container image includes PHP 7.1 as a [S2I](https://github.com/openshift/source-to-image) base image for your PHP 7.1 applications.
|
||||||
the PHP application as a reproducible Docker image using
|
Users can choose between RHEL and CentOS based builder images.
|
||||||
[source-to-image](https://github.com/openshift/source-to-image).
|
The RHEL image is available in the [Red Hat Container Catalog](https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/php-71-rhel7)
|
||||||
This image is port to **fedora** of Software collections [php7.0 s2i](https://github.com/sclorg/s2i-php-container/tree/master/7.0).
|
as registry.access.redhat.com/rhscl/php-71-rhel7.
|
||||||
|
The CentOS image is then available on [Docker Hub](https://hub.docker.com/r/centos/php-71-centos7/)
|
||||||
|
as centos/php-71-centos7.
|
||||||
The resulting image can be run using [Docker](http://docker.io).
|
The resulting image can be run using [Docker](http://docker.io).
|
||||||
|
|
||||||
Build
|
Description
|
||||||
------------------------
|
-----------
|
||||||
|
|
||||||
Most simple way to build image is using **Makefile**.
|
PHP 7.1 available as container is a base platform for
|
||||||
```
|
building and running various PHP 7.1 applications and frameworks.
|
||||||
$ make build
|
PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers
|
||||||
```
|
to write dynamically generated web pages. PHP also offers built-in database integration
|
||||||
|
for several commercial and non-commercial database management systems, so writing
|
||||||
|
a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding
|
||||||
|
is probably as a replacement for CGI scripts.
|
||||||
|
|
||||||
This build php image and tag it with name and version specified in **Makefile**:
|
This container image includes an npm utility, so users can use it to install JavaScript
|
||||||
```
|
modules for their web applications. There is no guarantee for any specific npm or nodejs
|
||||||
IMAGE_NAME=php
|
version, that is included in the image; those versions can be changed anytime and
|
||||||
VERSION=7
|
the nodejs itself is included just to make the npm work.
|
||||||
```
|
|
||||||
|
|
||||||
Usage
|
Usage
|
||||||
------------------------
|
---------------------
|
||||||
|
To build a simple [php-test-app](https://github.com/sclorg/s2i-php-container/tree/master/7.1/test/test-app) application
|
||||||
|
using standalone [S2I](https://github.com/openshift/source-to-image) and then run the
|
||||||
|
resulting image with [Docker](http://docker.io) execute:
|
||||||
|
|
||||||
Build your PHP application
|
* **For RHEL based image**
|
||||||
```
|
```
|
||||||
s2i build <SOURCE-REPOSITORY> php <NAME-OF-APP>
|
$ s2i build https://github.com/sclorg/s2i-php-container.git --context-dir=7.1/test/test-app rhscl/php-71-rhel7 php-test-app
|
||||||
```
|
$ docker run -p 8080:8080 php-test-app
|
||||||
Substitute <SOURCE-REPOSITORY> with path to your application or link to GitHub repository.
|
```
|
||||||
For example:
|
|
||||||
```
|
|
||||||
s2i build https://github.com/fermayo/hello-world-php php hello-world
|
|
||||||
```
|
|
||||||
|
|
||||||
Then run application in docker container:
|
* **For CentOS based image**
|
||||||
```
|
```
|
||||||
docker run -p 8080:8080 <NAME-OF-APP>
|
$ s2i build https://github.com/sclorg/s2i-php-container.git --context-dir=7.1/test/test-app centos/php-71-centos7 php-test-app
|
||||||
```
|
$ docker run -p 8080:8080 php-test-app
|
||||||
|
```
|
||||||
So for our example it would be:
|
|
||||||
```
|
|
||||||
docker run -p 8080:8080 hello-world
|
|
||||||
```
|
|
||||||
|
|
||||||
**Accessing the application:**
|
**Accessing the application:**
|
||||||
```
|
```
|
||||||
curl 127.0.0.1:8080
|
$ curl 127.0.0.1:8080
|
||||||
```
|
```
|
||||||
Repository organization
|
|
||||||
------------------------
|
|
||||||
* **php**
|
|
||||||
|
|
||||||
* **Dockerfile**
|
|
||||||
|
|
||||||
Fedora based Dockerfile.
|
|
||||||
|
|
||||||
* **Makefile**
|
|
||||||
|
|
||||||
Used to build and run docker image.
|
|
||||||
|
|
||||||
* **openshift-template.yaml**
|
|
||||||
|
|
||||||
Template to build and run PHP applications easily in OpenShift.
|
|
||||||
|
|
||||||
* **`.s2i/bin/`**
|
|
||||||
|
|
||||||
This folder contains scripts that are run by [S2I](https://github.com/openshift/source-to-image):
|
|
||||||
|
|
||||||
* **assemble**
|
|
||||||
|
|
||||||
Used to install the sources into the location where the application
|
|
||||||
will be run and prepare the application for deployment (eg. installing
|
|
||||||
modules using npm, etc..)
|
|
||||||
|
|
||||||
* **run**
|
|
||||||
|
|
||||||
This script is responsible for running the application, by using the
|
|
||||||
application web server.
|
|
||||||
* **usage**
|
|
||||||
|
|
||||||
This script is called when someone try to run image using docker.
|
|
||||||
|
|
||||||
* **`bin/`**
|
|
||||||
|
|
||||||
Helper scripts for fixing permissions and reading limits from cgroup system.
|
|
||||||
|
|
||||||
* **`contrib/`**
|
|
||||||
|
|
||||||
This folder contains a file with commonly used modules.
|
|
||||||
|
|
||||||
* **`root/`**
|
|
||||||
|
|
||||||
Manual pages.
|
|
||||||
|
|
||||||
* **`test/`**
|
|
||||||
|
|
||||||
This folder contains the [S2I](https://github.com/openshift/source-to-image)
|
|
||||||
test framework with a sample PHP app.
|
|
||||||
|
|
||||||
* **`test-app/`**
|
|
||||||
|
|
||||||
A simple PHP app used for testing purposes by the [S2I](https://github.com/openshift/source-to-image) test framework.
|
|
||||||
|
|
||||||
* **run**
|
|
||||||
|
|
||||||
Script that runs the [S2I](https://github.com/openshift/source-to-image) test framework.
|
|
||||||
|
|
||||||
|
|
||||||
Environment variables
|
Environment variables
|
||||||
---------------------
|
---------------------
|
||||||
|
|
@ -132,10 +72,28 @@ The following environment variables set their equivalent property value in the p
|
||||||
* Default: ON
|
* Default: ON
|
||||||
* **INCLUDE_PATH**
|
* **INCLUDE_PATH**
|
||||||
* Path for PHP source files
|
* Path for PHP source files
|
||||||
* Default: .:/opt/app-root/src:/usr/share/pear
|
* Default: .:/opt/app-root/src:/opt/rh/rh-php71/root/usr/share/pear
|
||||||
|
* **PHP_MEMORY_LIMIT**
|
||||||
|
* Memory Limit
|
||||||
|
* Default: 128M
|
||||||
|
* **SESSION_NAME**
|
||||||
|
* Name of the session
|
||||||
|
* Default: PHPSESSID
|
||||||
|
* **SESSION_HANDLER**
|
||||||
|
* Method for saving sessions
|
||||||
|
* Default: files
|
||||||
* **SESSION_PATH**
|
* **SESSION_PATH**
|
||||||
* Location for session data files
|
* Location for session data files
|
||||||
* Default: /tmp/sessions
|
* Default: /tmp/sessions
|
||||||
|
* **SESSION_COOKIE_DOMAIN**
|
||||||
|
* The domain for which the cookie is valid.
|
||||||
|
* Default:
|
||||||
|
* **SESSION_COOKIE_HTTPONLY**
|
||||||
|
* Whether or not to add the httpOnly flag to the cookie
|
||||||
|
* Default: 0
|
||||||
|
* **SESSION_COOKIE_SECURE**
|
||||||
|
* Specifies whether cookies should only be sent over secure connections.
|
||||||
|
* Default: Off
|
||||||
* **SHORT_OPEN_TAG**
|
* **SHORT_OPEN_TAG**
|
||||||
* Determines whether or not PHP will recognize code between <? and ?> tags
|
* Determines whether or not PHP will recognize code between <? and ?> tags
|
||||||
* Default: OFF
|
* Default: OFF
|
||||||
|
|
@ -178,6 +136,11 @@ yourself:
|
||||||
|
|
||||||
* **COMPOSER_MIRROR**
|
* **COMPOSER_MIRROR**
|
||||||
* Adds a custom composer repository mirror URL to composer configuration. Note: This only affects packages listed in composer.json.
|
* Adds a custom composer repository mirror URL to composer configuration. Note: This only affects packages listed in composer.json.
|
||||||
|
* **COMPOSER_INSTALLER**
|
||||||
|
* Overrides the default URL for downloading Composer of https://getcomposer.org/installer. Useful in disconnected environments.
|
||||||
|
* **COMPOSER_ARGS**
|
||||||
|
* Adds extra arguments to the `composer install` command line (for example `--no-dev`).
|
||||||
|
|
||||||
|
|
||||||
Source repository layout
|
Source repository layout
|
||||||
------------------------
|
------------------------
|
||||||
|
|
@ -215,39 +178,32 @@ docker exec -it <CONTAINER_ID> /bin/bash
|
||||||
After you [Docker exec](http://docker.io) into the running container, your current directory is set
|
After you [Docker exec](http://docker.io) into the running container, your current directory is set
|
||||||
to `/opt/app-root/src`, where the source code is located.
|
to `/opt/app-root/src`, where the source code is located.
|
||||||
|
|
||||||
Test
|
|
||||||
|
Extending image
|
||||||
|
---------------
|
||||||
|
Not only content, but also startup scripts and configuration of the image can
|
||||||
|
be extended using [source-to-image](https://github.com/openshift/source-to-image).
|
||||||
|
|
||||||
|
The structure of the application can look like this:
|
||||||
|
|
||||||
|
| Folder name | Description |
|
||||||
|
|-------------------|----------------------------|
|
||||||
|
| `./httpd-cfg` | Can contain additional Apache configuration files (`*.conf`)|
|
||||||
|
| `./httpd-ssl` | Can contain own SSL certificate (in `certs/` subdirectory) and key (in `private/` subdirectory)|
|
||||||
|
| `./php-pre-start`| Can contain shell scripts (`*.sh`) that are sourced before `httpd` is started|
|
||||||
|
| `./php-post-assemble`| Can contain shell scripts (`*.sh`) that are sourced at the end of `assemble` script|
|
||||||
|
| `./` | Application source code |
|
||||||
|
|
||||||
|
|
||||||
|
See also
|
||||||
|
--------
|
||||||
|
Dockerfile and other sources are available on https://github.com/sclorg/s2i-php-container.
|
||||||
|
In that repository you also can find another versions of PHP environment Dockerfiles.
|
||||||
|
Dockerfile for CentOS is called Dockerfile, Dockerfile for RHEL is called Dockerfile.rhel7.
|
||||||
|
|
||||||
|
Security Implications
|
||||||
---------------------
|
---------------------
|
||||||
Run:
|
|
||||||
```
|
|
||||||
$ make test
|
|
||||||
```
|
|
||||||
This will build candidate image and check the basic functionality of s2i image.
|
|
||||||
|
|
||||||
Running in OpenShift
|
-p 8080:8080
|
||||||
---------------------
|
|
||||||
Login
|
|
||||||
```
|
|
||||||
$ oc login -u developer
|
|
||||||
```
|
|
||||||
|
|
||||||
Create new project
|
Opens container port 8080 and maps it to the same port on the Host.
|
||||||
```
|
|
||||||
$ oc new-project sample-project
|
|
||||||
```
|
|
||||||
|
|
||||||
Create template from YAML file
|
|
||||||
```
|
|
||||||
$ oc create -f openshift-template.yaml
|
|
||||||
```
|
|
||||||
|
|
||||||
Create new application (php-fedora is template created in previous step)
|
|
||||||
```
|
|
||||||
$ oc new-app php-fedora -p APP_NAME=<name> -p SOURCE_REPOSITORY=<your-github-repository>
|
|
||||||
```
|
|
||||||
For example:
|
|
||||||
```
|
|
||||||
$ oc new-app php-fedora -p APP_NAME=my-app -p SOURCE_REPOSITORY=https://github.com/fermayo/hello-world-php
|
|
||||||
```
|
|
||||||
Check if everything is ok
|
|
||||||
```
|
|
||||||
$ oc logs -f bc/my-app
|
|
||||||
|
|
|
||||||
|
|
@ -1,92 +0,0 @@
|
||||||
#!/usr/bin/python
|
|
||||||
|
|
||||||
"""
|
|
||||||
Script for parsing cgroup information
|
|
||||||
|
|
||||||
This script will read some limits from the cgroup system and parse
|
|
||||||
them, printing out "VARIABLE=VALUE" on each line for every limit that is
|
|
||||||
successfully read. Output of this script can be directly fed into
|
|
||||||
bash's export command. Recommended usage from a bash script:
|
|
||||||
|
|
||||||
set -o errexit
|
|
||||||
export_vars=$(cgroup-limits) ; export $export_vars
|
|
||||||
|
|
||||||
Variables currently supported:
|
|
||||||
MAX_MEMORY_LIMIT_IN_BYTES
|
|
||||||
Maximum possible limit MEMORY_LIMIT_IN_BYTES can have. This is
|
|
||||||
currently constant value of 9223372036854775807.
|
|
||||||
MEMORY_LIMIT_IN_BYTES
|
|
||||||
Maximum amount of user memory in bytes. If this value is set
|
|
||||||
to the same value as MAX_MEMORY_LIMIT_IN_BYTES, it means that
|
|
||||||
there is no limit set. The value is taken from
|
|
||||||
/sys/fs/cgroup/memory/memory.limit_in_bytes
|
|
||||||
NUMBER_OF_CORES
|
|
||||||
Number of detected CPU cores that can be used. This value is
|
|
||||||
calculated from /sys/fs/cgroup/cpuset/cpuset.cpus
|
|
||||||
NO_MEMORY_LIMIT
|
|
||||||
Set to "true" if MEMORY_LIMIT_IN_BYTES is so high that the caller
|
|
||||||
can act as if no memory limit was set. Undefined otherwise.
|
|
||||||
"""
|
|
||||||
|
|
||||||
from __future__ import print_function
|
|
||||||
import sys
|
|
||||||
|
|
||||||
|
|
||||||
def _read_file(path):
|
|
||||||
try:
|
|
||||||
with open(path, 'r') as f:
|
|
||||||
return f.read().strip()
|
|
||||||
except IOError:
|
|
||||||
return None
|
|
||||||
|
|
||||||
|
|
||||||
def get_memory_limit():
|
|
||||||
"""
|
|
||||||
Read memory limit, in bytes.
|
|
||||||
"""
|
|
||||||
|
|
||||||
limit = _read_file('/sys/fs/cgroup/memory/memory.limit_in_bytes')
|
|
||||||
if limit is None or not limit.isdigit():
|
|
||||||
print("Warning: Can't detect memory limit from cgroups",
|
|
||||||
file=sys.stderr)
|
|
||||||
return None
|
|
||||||
return int(limit)
|
|
||||||
|
|
||||||
|
|
||||||
def get_number_of_cores():
|
|
||||||
"""
|
|
||||||
Read number of CPU cores.
|
|
||||||
"""
|
|
||||||
|
|
||||||
core_count = 0
|
|
||||||
|
|
||||||
line = _read_file('/sys/fs/cgroup/cpuset/cpuset.cpus')
|
|
||||||
if line is None:
|
|
||||||
print("Warning: Can't detect number of CPU cores from cgroups",
|
|
||||||
file=sys.stderr)
|
|
||||||
return None
|
|
||||||
|
|
||||||
for group in line.split(','):
|
|
||||||
core_ids = list(map(int, group.split('-')))
|
|
||||||
if len(core_ids) == 2:
|
|
||||||
core_count += core_ids[1] - core_ids[0] + 1
|
|
||||||
else:
|
|
||||||
core_count += 1
|
|
||||||
|
|
||||||
return core_count
|
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
env_vars = {
|
|
||||||
"MAX_MEMORY_LIMIT_IN_BYTES": 9223372036854775807,
|
|
||||||
"MEMORY_LIMIT_IN_BYTES": get_memory_limit(),
|
|
||||||
"NUMBER_OF_CORES": get_number_of_cores()
|
|
||||||
}
|
|
||||||
|
|
||||||
env_vars = {k: v for k, v in env_vars.items() if v is not None}
|
|
||||||
|
|
||||||
if env_vars.get("MEMORY_LIMIT_IN_BYTES", 0) >= 92233720368547:
|
|
||||||
env_vars["NO_MEMORY_LIMIT"] = "true"
|
|
||||||
|
|
||||||
for key, value in env_vars.items():
|
|
||||||
print("{0}={1}".format(key, value))
|
|
||||||
|
|
@ -1,6 +0,0 @@
|
||||||
#!/bin/sh
|
|
||||||
# Fix permissions on the given directory to allow group read/write of
|
|
||||||
# regular files and execute of directories.
|
|
||||||
find $1 -exec chgrp 0 {} \;
|
|
||||||
find $1 -exec chmod g+rw {} \;
|
|
||||||
find $1 -type d -exec chmod g+x {} +
|
|
||||||
|
|
@ -1,9 +0,0 @@
|
||||||
s/^Listen 80/Listen 0.0.0.0:8080/
|
|
||||||
s/^User apache/User default/
|
|
||||||
s/^Group apache/Group root/
|
|
||||||
s%^DocumentRoot "/var/www/html"%#DocumentRoot "/opt/app-root/src"%
|
|
||||||
s%^<Directory "/var/www/html"%<Directory "/opt/app-root/src"%
|
|
||||||
s%^<Directory "/var/html"%<Directory "/opt/app-root/src"%
|
|
||||||
s%^ErrorLog "logs/error_log"%ErrorLog "|/usr/bin/cat"%
|
|
||||||
s%CustomLog "logs/access_log"%CustomLog "|/usr/bin/cat"%
|
|
||||||
151s%AllowOverride None%AllowOverride All%
|
|
||||||
1
help.md
Symbolic link
1
help.md
Symbolic link
|
|
@ -0,0 +1 @@
|
||||||
|
README.md
|
||||||
|
|
@ -1,141 +0,0 @@
|
||||||
---
|
|
||||||
kind: Template
|
|
||||||
apiVersion: v1
|
|
||||||
metadata:
|
|
||||||
name: php-fedora
|
|
||||||
annotations:
|
|
||||||
description: Php source to image builder
|
|
||||||
tags: php s2i
|
|
||||||
iconClass: icon-php
|
|
||||||
labels:
|
|
||||||
template: php
|
|
||||||
role: php_application_builder
|
|
||||||
objects:
|
|
||||||
- kind : ImageStream
|
|
||||||
apiVersion : v1
|
|
||||||
metadata :
|
|
||||||
name : ${APP_NAME}
|
|
||||||
labels :
|
|
||||||
appid : php-${APP_NAME}
|
|
||||||
- kind : ImageStream
|
|
||||||
apiVersion : v1
|
|
||||||
metadata :
|
|
||||||
name : ${APP_NAME}-s2i
|
|
||||||
labels :
|
|
||||||
appid : php-${APP_NAME}
|
|
||||||
spec :
|
|
||||||
tags :
|
|
||||||
- name : latest
|
|
||||||
from :
|
|
||||||
kind : DockerImage
|
|
||||||
name : modularitycontainers/php
|
|
||||||
- kind : BuildConfig
|
|
||||||
apiVersion : v1
|
|
||||||
metadata :
|
|
||||||
name : ${APP_NAME}
|
|
||||||
labels :
|
|
||||||
appid : php-${APP_NAME}
|
|
||||||
spec :
|
|
||||||
triggers :
|
|
||||||
- type : ConfigChange
|
|
||||||
- type : ImageChange
|
|
||||||
- type : GitHub
|
|
||||||
github:
|
|
||||||
secret: secret101
|
|
||||||
source :
|
|
||||||
type : Git
|
|
||||||
git :
|
|
||||||
uri : ${SOURCE_REPOSITORY}
|
|
||||||
contextDir : ${SOURCE_REPOSITORY}
|
|
||||||
strategy :
|
|
||||||
type : Source
|
|
||||||
sourceStrategy :
|
|
||||||
from :
|
|
||||||
kind : ImageStreamTag
|
|
||||||
name : ${APP_NAME}-s2i:latest
|
|
||||||
output :
|
|
||||||
to :
|
|
||||||
kind : ImageStreamTag
|
|
||||||
name : ${APP_NAME}:latest
|
|
||||||
- kind : DeploymentConfig
|
|
||||||
apiVersion : v1
|
|
||||||
metadata :
|
|
||||||
name: ${APP_NAME}
|
|
||||||
labels :
|
|
||||||
appid : php-${APP_NAME}
|
|
||||||
spec :
|
|
||||||
strategy :
|
|
||||||
type : Rolling
|
|
||||||
triggers :
|
|
||||||
- type : ConfigChange
|
|
||||||
- type : ImageChange
|
|
||||||
imageChangeParams :
|
|
||||||
automatic : true
|
|
||||||
containerNames :
|
|
||||||
- ${APP_NAME}
|
|
||||||
from :
|
|
||||||
kind : ImageStreamTag
|
|
||||||
name : ${APP_NAME}:latest
|
|
||||||
replicas : 1
|
|
||||||
selector :
|
|
||||||
deploymentconfig : ${APP_NAME}
|
|
||||||
template :
|
|
||||||
metadata :
|
|
||||||
labels :
|
|
||||||
appid: php-${APP_NAME}
|
|
||||||
deploymentconfig : ${APP_NAME}
|
|
||||||
spec :
|
|
||||||
containers :
|
|
||||||
- name : ${APP_NAME}
|
|
||||||
image : ${APP_NAME}:latest
|
|
||||||
ports :
|
|
||||||
- containerPort : 8080
|
|
||||||
protocol : TCP
|
|
||||||
livenessProbe:
|
|
||||||
tcpSocket:
|
|
||||||
port: 8080
|
|
||||||
initialDelaySeconds: 15
|
|
||||||
timeoutSeconds: 1
|
|
||||||
readinessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: /
|
|
||||||
port: 8080
|
|
||||||
initialDelaySeconds: 15
|
|
||||||
timeoutSeconds: 1
|
|
||||||
- kind : Service
|
|
||||||
apiVersion : v1
|
|
||||||
metadata :
|
|
||||||
name : ${APP_NAME}
|
|
||||||
labels :
|
|
||||||
appid : php-${APP_NAME}
|
|
||||||
spec :
|
|
||||||
ports :
|
|
||||||
- name: 8080-tcp
|
|
||||||
protocol : TCP
|
|
||||||
port : 8080
|
|
||||||
targetPort : 8080
|
|
||||||
selector :
|
|
||||||
deploymentconfig : ${APP_NAME}
|
|
||||||
- kind : Route
|
|
||||||
apiVersion : v1
|
|
||||||
metadata :
|
|
||||||
name : ${APP_NAME}
|
|
||||||
labels :
|
|
||||||
appid : php-${APP_NAME}
|
|
||||||
spec :
|
|
||||||
host :
|
|
||||||
to :
|
|
||||||
kind : Service
|
|
||||||
name : ${APP_NAME}
|
|
||||||
weight : 100
|
|
||||||
port :
|
|
||||||
targetPort : 8080-tcp
|
|
||||||
parameters :
|
|
||||||
- name : APP_NAME
|
|
||||||
description : Name of application
|
|
||||||
value :
|
|
||||||
required : true
|
|
||||||
- name : SOURCE_REPOSITORY
|
|
||||||
description : Git source repository
|
|
||||||
value :
|
|
||||||
required : true
|
|
||||||
327
root/help.1
327
root/help.1
|
|
@ -1,183 +1,286 @@
|
||||||
.TH "php" "1" "" "Rado Pitonak \<rpitonak@redhat.com\>" "DATE 07.04.2017" ""
|
.TH PHP 7.1 Docker image
|
||||||
|
|
||||||
|
|
||||||
.SH NAME
|
|
||||||
.PP
|
.PP
|
||||||
php \- source to image builder of php applications.
|
This container image includes PHP 7.1 as a S2I
|
||||||
|
\[la]https://github.com/openshift/source-to-image\[ra] base image for your PHP 7.1 applications.
|
||||||
|
Users can choose between RHEL and CentOS based builder images.
|
||||||
|
The RHEL image is available in the Red Hat Container Catalog
|
||||||
|
\[la]https://access.redhat.com/containers/#/registry.access.redhat.com/rhscl/php-71-rhel7\[ra]
|
||||||
|
as registry.access.redhat.com/rhscl/php\-71\-rhel7.
|
||||||
|
The CentOS image is then available on Docker Hub
|
||||||
|
\[la]https://hub.docker.com/r/centos/php-71-centos7/\[ra]
|
||||||
|
as centos/php\-71\-centos7.
|
||||||
|
The resulting image can be run using Docker
|
||||||
|
\[la]http://docker.io\[ra]\&.
|
||||||
|
|
||||||
|
.SH Description
|
||||||
.SH DESCRIPTION
|
|
||||||
.PP
|
.PP
|
||||||
Image for building php application as reproducible Docker image using source to image. Image is based on fedora.
|
PHP 7.1 available as container is a base platform for
|
||||||
|
building and running various PHP 7.1 applications and frameworks.
|
||||||
|
PHP is an HTML\-embedded scripting language. PHP attempts to make it easy for developers
|
||||||
|
to write dynamically generated web pages. PHP also offers built\-in database integration
|
||||||
|
for several commercial and non\-commercial database management systems, so writing
|
||||||
|
a database\-enabled webpage with PHP is fairly simple. The most common use of PHP coding
|
||||||
|
is probably as a replacement for CGI scripts.
|
||||||
|
|
||||||
.SH USAGE
|
|
||||||
.PP
|
.PP
|
||||||
To pull the php container run:
|
This container image includes an npm utility, so users can use it to install JavaScript
|
||||||
|
modules for their web applications. There is no guarantee for any specific npm or nodejs
|
||||||
|
version, that is included in the image; those versions can be changed anytime and
|
||||||
|
the nodejs itself is included just to make the npm work.
|
||||||
|
|
||||||
|
.SH Usage
|
||||||
|
.PP
|
||||||
|
To build a simple php\-test\-app
|
||||||
|
\[la]https://github.com/sclorg/s2i-php-container/tree/master/7.1/test/test-app\[ra] application
|
||||||
|
using standalone S2I
|
||||||
|
\[la]https://github.com/openshift/source-to-image\[ra] and then run the
|
||||||
|
resulting image with Docker
|
||||||
|
\[la]http://docker.io\[ra] execute:
|
||||||
|
.IP \(bu 2
|
||||||
|
|
||||||
|
.PP
|
||||||
|
\fBFor RHEL based image\fP
|
||||||
.PP
|
.PP
|
||||||
.RS
|
.RS
|
||||||
|
|
||||||
.nf
|
.nf
|
||||||
# docker pull modularitycontainers/php
|
$ s2i build https://github.com/sclorg/s2i\-php\-container.git \-\-context\-dir=7.1/test/test\-app rhscl/php\-71\-rhel7 php\-test\-app
|
||||||
|
$ docker run \-p 8080:8080 php\-test\-app
|
||||||
|
|
||||||
|
.fi
|
||||||
|
.RE
|
||||||
|
.IP \(bu 2
|
||||||
|
|
||||||
|
.PP
|
||||||
|
\fBFor CentOS based image\fP
|
||||||
|
.PP
|
||||||
|
.RS
|
||||||
|
|
||||||
|
.nf
|
||||||
|
$ s2i build https://github.com/sclorg/s2i\-php\-container.git \-\-context\-dir=7.1/test/test\-app centos/php\-71\-centos7 php\-test\-app
|
||||||
|
$ docker run \-p 8080:8080 php\-test\-app
|
||||||
|
|
||||||
.fi
|
.fi
|
||||||
.RE
|
.RE
|
||||||
|
|
||||||
.PP
|
.PP
|
||||||
To build your php application run:
|
\fBAccessing the application:\fP
|
||||||
|
|
||||||
.PP
|
.PP
|
||||||
.RS
|
.RS
|
||||||
|
|
||||||
.nf
|
.nf
|
||||||
# s2i build <SOURCE\-REPOSITORY> modularitycontainers/php <NAME\-OF\-APP>
|
$ curl 127.0.0.1:8080
|
||||||
|
|
||||||
.fi
|
.fi
|
||||||
.RE
|
.RE
|
||||||
|
|
||||||
|
.SH Environment variables
|
||||||
.PP
|
.PP
|
||||||
To run your application in docker container:
|
To set these environment variables, you can place them as a key value pair into a \fB\fC\&.sti/environment\fR
|
||||||
|
|
||||||
.PP
|
|
||||||
.RS
|
|
||||||
|
|
||||||
.nf
|
|
||||||
# docker run \-p 8080:8080 <NAME\-OF\-APP>
|
|
||||||
|
|
||||||
.fi
|
|
||||||
.RE
|
|
||||||
|
|
||||||
.SH ENVIROMENT VARIABLES
|
|
||||||
.PP
|
|
||||||
To set environment variables, you can place them as a key value pair into a \fB\fC.sti/environment\fR
|
|
||||||
file inside your source code repository.
|
file inside your source code repository.
|
||||||
|
|
||||||
.PP
|
.PP
|
||||||
The following environment variables set their equivalent property value in the php.ini file:
|
The following environment variables set their equivalent property value in the php.ini file:
|
||||||
|
* \fBERROR\_REPORTING\fP
|
||||||
.PP
|
* Informs PHP of which errors, warnings and notices you would like it to take action for
|
||||||
ERROR\_REPORTING
|
* Default: E\_ALL \& \~E\_NOTICE
|
||||||
Informs PHP of which errors, warnings and notices you would like it to take action for.
|
* \fBDISPLAY\_ERRORS\fP
|
||||||
Default: E\_ALL \& \~E\_NOTICE
|
* Controls whether or not and where PHP will output errors, notices and warnings
|
||||||
|
* Default: ON
|
||||||
.PP
|
* \fBDISPLAY\_STARTUP\_ERRORS\fP
|
||||||
DISPLAY\_ERRORS
|
* Cause display errors which occur during PHP's startup sequence to be handled separately from display errors
|
||||||
Controls whether or not and where PHP will output errors, notices and warnings.
|
* Default: OFF
|
||||||
Default: ON
|
* \fBTRACK\_ERRORS\fP
|
||||||
|
* Store the last error/warning message in $php\_errormsg (boolean)
|
||||||
.PP
|
* Default: OFF
|
||||||
DISPLAY\_STARTUP\_ERRORS
|
* \fBHTML\_ERRORS\fP
|
||||||
Cause display errors which occur during PHP's startup sequence to be handled separately from display errors.
|
* Link errors to documentation related to the error
|
||||||
Default: OFF
|
* Default: ON
|
||||||
|
* \fBINCLUDE\_PATH\fP
|
||||||
.PP
|
* Path for PHP source files
|
||||||
TRACK\_ERRORS
|
* Default: .:/opt/app\-root/src:/opt/rh/rh\-php71/root/usr/share/pear
|
||||||
Store the last error/warning message in $php\_errormsg (boolean)
|
* \fBPHP\_MEMORY\_LIMIT\fP
|
||||||
Default: OFF
|
* Memory Limit
|
||||||
|
* Default: 128M
|
||||||
.PP
|
* \fBSESSION\_NAME\fP
|
||||||
HTML\_ERRORS
|
* Name of the session
|
||||||
Link errors to documentation related to the error
|
* Default: PHPSESSID
|
||||||
Default: ON
|
* \fBSESSION\_HANDLER\fP
|
||||||
|
* Method for saving sessions
|
||||||
.PP
|
* Default: files
|
||||||
INCLUDE\_PATH
|
* \fBSESSION\_PATH\fP
|
||||||
Path for PHP source files
|
* Location for session data files
|
||||||
Default: .:/opt/app\-root/src:/usr/share/pear
|
* Default: /tmp/sessions
|
||||||
|
* \fBSESSION\_COOKIE\_DOMAIN\fP
|
||||||
.PP
|
* The domain for which the cookie is valid.
|
||||||
SESSION\_PATH
|
* Default:
|
||||||
Location for session data files
|
* \fBSESSION\_COOKIE\_HTTPONLY\fP
|
||||||
Default: /tmp/sessions
|
* Whether or not to add the httpOnly flag to the cookie
|
||||||
|
* Default: 0
|
||||||
.PP
|
* \fBSESSION\_COOKIE\_SECURE\fP
|
||||||
SHORT\_OPEN\_TAG
|
* Specifies whether cookies should only be sent over secure connections.
|
||||||
Determines whether or not PHP will recognize code between <? and ?> tags
|
* Default: Off
|
||||||
Default: OFF
|
* \fBSHORT\_OPEN\_TAG\fP
|
||||||
|
* Determines whether or not PHP will recognize code between <? and ?> tags
|
||||||
.PP
|
* Default: OFF
|
||||||
DOCUMENTROOT
|
* \fBDOCUMENTROOT\fP
|
||||||
Path that defines the DocumentRoot for your application (ie. /public)
|
* Path that defines the DocumentRoot for your application (ie. /public)
|
||||||
Default: /
|
* Default: /
|
||||||
|
|
||||||
.PP
|
.PP
|
||||||
The following environment variables set their equivalent property value in the opcache.ini file:
|
The following environment variables set their equivalent property value in the opcache.ini file:
|
||||||
|
* \fBOPCACHE\_MEMORY\_CONSUMPTION\fP
|
||||||
.PP
|
* The OPcache shared memory storage size in megabytes
|
||||||
OPCACHE\_MEMORY\_CONSUMPTION
|
* Default: 128
|
||||||
The OPcache shared memory storage size in megabytes
|
* \fBOPCACHE\_REVALIDATE\_FREQ\fP
|
||||||
Default: 128
|
* How often to check script timestamps for updates, in seconds. 0 will result in OPcache checking for updates on every request.
|
||||||
|
* Default: 2
|
||||||
.PP
|
|
||||||
OPCACHE\_REVALIDATE\_FREQ
|
|
||||||
How often to check script timestamps for updates, in seconds. 0 will result in OPcache checking for updates on every request.
|
|
||||||
Default: 2
|
|
||||||
|
|
||||||
.PP
|
.PP
|
||||||
You can also override the entire directory used to load the PHP configuration by setting:
|
You can also override the entire directory used to load the PHP configuration by setting:
|
||||||
|
* \fBPHPRC\fP
|
||||||
|
* Sets the path to the php.ini file
|
||||||
|
* \fBPHP\_INI\_SCAN\_DIR\fP
|
||||||
|
* Path to scan for additional ini configuration files
|
||||||
|
|
||||||
.PP
|
.PP
|
||||||
PHPRC
|
You can override the Apache MPM prefork
|
||||||
Sets the path to the php.ini file
|
\[la]https://httpd.apache.org/docs/2.4/mod/mpm_common.html\[ra]
|
||||||
|
settings to increase the performance for of the PHP application. In case you set
|
||||||
.PP
|
|
||||||
PHP\_INI\_SCAN\_DIR
|
|
||||||
Path to scan for additional ini configuration files
|
|
||||||
|
|
||||||
.PP
|
|
||||||
You can override the Apache MPM prefork settings to increase the performance for of the PHP application. In case you set
|
|
||||||
the Cgroup limits in Docker, the image will attempt to automatically set the
|
the Cgroup limits in Docker, the image will attempt to automatically set the
|
||||||
optimal values. You can override this at any time by specifying the values
|
optimal values. You can override this at any time by specifying the values
|
||||||
yourself:
|
yourself:
|
||||||
|
.IP \(bu 2
|
||||||
.PP
|
\fBHTTPD\_START\_SERVERS\fP
|
||||||
HTTPD\_START\_SERVERS
|
.IP \(bu 2
|
||||||
The StartServers directive sets the number of child server processes created on startup.
|
The StartServers
|
||||||
Default: 8
|
\[la]https://httpd.apache.org/docs/2.4/mod/mpm_common.html#startservers\[ra]
|
||||||
|
directive sets the number of child server processes created on startup.
|
||||||
.PP
|
.IP \(bu 2
|
||||||
HTTPD\_MAX\_REQUEST\_WORKERS
|
Default: 8
|
||||||
The MaxRequestWorkers directive sets the limit on the number of simultaneous requests that will be served.
|
.IP \(bu 2
|
||||||
\fB\fCMaxRequestWorkers\fR was called \fB\fCMaxClients\fR before version httpd 2.3.13.
|
\fBHTTPD\_MAX\_REQUEST\_WORKERS\fP
|
||||||
Default: 256 (this is automatically tuned by setting Cgroup limits for the container using this formula:
|
.IP \(bu 2
|
||||||
\fB\fCTOTAL\_MEMORY / 15MB\fR. The 15MB is average size of a single httpd process.
|
The MaxRequestWorkers
|
||||||
|
\[la]https://httpd.apache.org/docs/2.4/mod/mpm_common.html#maxrequestworkers\[ra]
|
||||||
|
directive sets the limit on the number of simultaneous requests that will be served.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fB\fCMaxRequestWorkers\fR was called \fB\fCMaxClients\fR before version httpd 2.3.13.
|
||||||
|
.IP \(bu 2
|
||||||
|
Default: 256 (this is automatically tuned by setting Cgroup limits for the container using this formula:
|
||||||
|
\fB\fCTOTAL\_MEMORY / 15MB\fR\&. The 15MB is average size of a single httpd process.
|
||||||
|
|
||||||
.PP
|
.PP
|
||||||
You can use a custom composer repository mirror URL to download packages instead of the default 'packagist.org':
|
You can use a custom composer repository mirror URL to download packages instead of the default 'packagist.org':
|
||||||
|
|
||||||
.PP
|
.PP
|
||||||
COMPOSER\_MIRROR
|
.RS
|
||||||
Adds a custom composer repository mirror URL to composer configuration. Note: This only affects packages listed in composer.json.
|
|
||||||
|
|
||||||
.SH HOT DEPLOY
|
.nf
|
||||||
|
* **COMPOSER\_MIRROR**
|
||||||
|
* Adds a custom composer repository mirror URL to composer configuration. Note: This only affects packages listed in composer.json.
|
||||||
|
* **COMPOSER\_INSTALLER**
|
||||||
|
* Overrides the default URL for downloading Composer of https://getcomposer.org/installer. Useful in disconnected environments.
|
||||||
|
* **COMPOSER\_ARGS**
|
||||||
|
* Adds extra arguments to the `composer install` command line (for example `\-\-no\-dev`).
|
||||||
|
|
||||||
|
.fi
|
||||||
|
.RE
|
||||||
|
|
||||||
|
.SH Source repository layout
|
||||||
.PP
|
.PP
|
||||||
In order to immediately pick up changes made in your application source code, you need to run your built image with the \fB\fCOPCACHE\_REVALIDATE\_FREQ=0\fR environment variable passed to the Docker \fB\fC\-e\fR run flag:
|
You do not need to change anything in your existing PHP project's repository.
|
||||||
|
However, if these files exist they will affect the behavior of the build process:
|
||||||
|
.IP \(bu 2
|
||||||
|
\fBcomposer.json\fP
|
||||||
|
|
||||||
|
.PP
|
||||||
|
List of dependencies to be installed with \fB\fCcomposer\fR\&. The format is documented
|
||||||
|
here
|
||||||
|
\[la]https://getcomposer.org/doc/04-schema.md\[ra]\&.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fB\&.htaccess\fP
|
||||||
|
|
||||||
|
.PP
|
||||||
|
In case the \fBDocumentRoot\fP of the application is nested within the source directory \fB\fC/opt/app\-root/src\fR,
|
||||||
|
users can provide their own Apache \fB\&.htaccess\fP file. This allows the overriding of Apache's behavior and
|
||||||
|
specifies how application requests should be handled. The \fB\&.htaccess\fP file needs to be located at the root
|
||||||
|
of the application source.
|
||||||
|
|
||||||
|
.SH Hot deploy
|
||||||
|
.PP
|
||||||
|
In order to immediately pick up changes made in your application source code, you need to run your built image with the \fB\fCOPCACHE\_REVALIDATE\_FREQ=0\fR environment variable passed to the Docker
|
||||||
|
\[la]http://docker.io\[ra] \fB\fC\-e\fR run flag:
|
||||||
|
|
||||||
.PP
|
.PP
|
||||||
.RS
|
.RS
|
||||||
|
|
||||||
.nf
|
.nf
|
||||||
# docker run \-e OPCACHE\_REVALIDATE\_FREQ=0 \-p 8080:8080 php\-app
|
$ docker run \-e OPCACHE\_REVALIDATE\_FREQ=0 \-p 8080:8080 php\-app
|
||||||
|
|
||||||
.fi
|
.fi
|
||||||
.RE
|
.RE
|
||||||
|
|
||||||
.PP
|
.PP
|
||||||
To change your source code in running container, use Docker's exec command:
|
To change your source code in running container, use Docker's exec
|
||||||
|
\[la]http://docker.io\[ra] command:
|
||||||
|
|
||||||
.PP
|
.PP
|
||||||
.RS
|
.RS
|
||||||
|
|
||||||
.nf
|
.nf
|
||||||
# docker exec \-it <CONTAINER\_ID> /bin/bash
|
docker exec \-it <CONTAINER\_ID> /bin/bash
|
||||||
|
|
||||||
.fi
|
.fi
|
||||||
.RE
|
.RE
|
||||||
|
|
||||||
.PP
|
.PP
|
||||||
After you Docker exec into the running container, your current directory is set to \fB\fC/opt/app\-root/src\fR, where the source code is located.
|
After you Docker exec
|
||||||
|
\[la]http://docker.io\[ra] into the running container, your current directory is set
|
||||||
|
to \fB\fC/opt/app\-root/src\fR, where the source code is located.
|
||||||
|
|
||||||
.SH SECURITY IMPLICATIONS
|
.SH Extending image
|
||||||
|
.PP
|
||||||
|
Not only content, but also startup scripts and configuration of the image can
|
||||||
|
be extended using source\-to\-image
|
||||||
|
\[la]https://github.com/openshift/source-to-image\[ra]\&.
|
||||||
|
|
||||||
|
.PP
|
||||||
|
The structure of the application can look like this:
|
||||||
|
|
||||||
|
.TS
|
||||||
|
allbox;
|
||||||
|
l l
|
||||||
|
l l .
|
||||||
|
\fB\fCFolder name\fR \fB\fCDescription\fR
|
||||||
|
\fB\fC\&./httpd\-\&cfg\fR T{
|
||||||
|
Can contain additional Apache configuration files (\fB\fC*.conf\fR)
|
||||||
|
T}
|
||||||
|
\fB\fC\&./httpd\-\&ssl\fR T{
|
||||||
|
Can contain own SSL certificate (in \fB\fCcerts/\fR subdirectory) and key (in \fB\fCprivate/\fR subdirectory)
|
||||||
|
T}
|
||||||
|
T{
|
||||||
|
\fB\fC\&./php\-\&pre\-\&start\fR
|
||||||
|
T} T{
|
||||||
|
Can contain shell scripts (\fB\fC*.sh\fR) that are sourced before \fB\fChttpd\fR is started
|
||||||
|
T}
|
||||||
|
T{
|
||||||
|
\fB\fC\&./php\-\&post\-\&assemble\fR
|
||||||
|
T} T{
|
||||||
|
Can contain shell scripts (\fB\fC*.sh\fR) that are sourced at the end of \fB\fCassemble\fR script
|
||||||
|
T}
|
||||||
|
\fB\fC\&./\fR Application source code
|
||||||
|
.TE
|
||||||
|
|
||||||
|
.SH See also
|
||||||
|
.PP
|
||||||
|
Dockerfile and other sources are available on
|
||||||
|
\[la]https://github.com/sclorg/s2i-php-container\[ra]\&.
|
||||||
|
In that repository you also can find another versions of PHP environment Dockerfiles.
|
||||||
|
Dockerfile for CentOS is called Dockerfile, Dockerfile for RHEL is called Dockerfile.rhel7.
|
||||||
|
|
||||||
|
.SH Security Implications
|
||||||
.PP
|
.PP
|
||||||
\-p 8080:8080
|
\-p 8080:8080
|
||||||
|
|
||||||
|
|
|
||||||
121
root/help.md
121
root/help.md
|
|
@ -1,121 +0,0 @@
|
||||||
% php(1)
|
|
||||||
% Rado Pitonak \<rpitonak@redhat.com\>
|
|
||||||
% DATE 07.04.2017
|
|
||||||
|
|
||||||
# NAME
|
|
||||||
php - source to image builder of php applications.
|
|
||||||
|
|
||||||
# DESCRIPTION
|
|
||||||
Image for building php application as reproducible Docker image using source to image. Image is based on fedora.
|
|
||||||
## USAGE
|
|
||||||
|
|
||||||
To pull the php container run:
|
|
||||||
|
|
||||||
# docker pull modularitycontainers/php
|
|
||||||
|
|
||||||
To build your php application run:
|
|
||||||
|
|
||||||
# s2i build <SOURCE-REPOSITORY> modularitycontainers/php <NAME-OF-APP>
|
|
||||||
|
|
||||||
To run your application in docker container:
|
|
||||||
|
|
||||||
# docker run -p 8080:8080 <NAME-OF-APP>
|
|
||||||
|
|
||||||
## ENVIROMENT VARIABLES
|
|
||||||
|
|
||||||
To set environment variables, you can place them as a key value pair into a `.sti/environment`
|
|
||||||
file inside your source code repository.
|
|
||||||
|
|
||||||
The following environment variables set their equivalent property value in the php.ini file:
|
|
||||||
|
|
||||||
ERROR_REPORTING
|
|
||||||
Informs PHP of which errors, warnings and notices you would like it to take action for.
|
|
||||||
Default: E_ALL & ~E_NOTICE
|
|
||||||
|
|
||||||
DISPLAY_ERRORS
|
|
||||||
Controls whether or not and where PHP will output errors, notices and warnings.
|
|
||||||
Default: ON
|
|
||||||
|
|
||||||
DISPLAY_STARTUP_ERRORS
|
|
||||||
Cause display errors which occur during PHP's startup sequence to be handled separately from display errors.
|
|
||||||
Default: OFF
|
|
||||||
|
|
||||||
TRACK_ERRORS
|
|
||||||
Store the last error/warning message in $php_errormsg (boolean)
|
|
||||||
Default: OFF
|
|
||||||
|
|
||||||
HTML_ERRORS
|
|
||||||
Link errors to documentation related to the error
|
|
||||||
Default: ON
|
|
||||||
|
|
||||||
INCLUDE_PATH
|
|
||||||
Path for PHP source files
|
|
||||||
Default: .:/opt/app-root/src:/usr/share/pear
|
|
||||||
|
|
||||||
SESSION_PATH
|
|
||||||
Location for session data files
|
|
||||||
Default: /tmp/sessions
|
|
||||||
|
|
||||||
SHORT_OPEN_TAG
|
|
||||||
Determines whether or not PHP will recognize code between <? and ?> tags
|
|
||||||
Default: OFF
|
|
||||||
|
|
||||||
DOCUMENTROOT
|
|
||||||
Path that defines the DocumentRoot for your application (ie. /public)
|
|
||||||
Default: /
|
|
||||||
|
|
||||||
The following environment variables set their equivalent property value in the opcache.ini file:
|
|
||||||
|
|
||||||
OPCACHE_MEMORY_CONSUMPTION
|
|
||||||
The OPcache shared memory storage size in megabytes
|
|
||||||
Default: 128
|
|
||||||
|
|
||||||
OPCACHE_REVALIDATE_FREQ
|
|
||||||
How often to check script timestamps for updates, in seconds. 0 will result in OPcache checking for updates on every request.
|
|
||||||
Default: 2
|
|
||||||
|
|
||||||
You can also override the entire directory used to load the PHP configuration by setting:
|
|
||||||
|
|
||||||
PHPRC
|
|
||||||
Sets the path to the php.ini file
|
|
||||||
|
|
||||||
PHP_INI_SCAN_DIR
|
|
||||||
Path to scan for additional ini configuration files
|
|
||||||
|
|
||||||
You can override the Apache MPM prefork settings to increase the performance for of the PHP application. In case you set
|
|
||||||
the Cgroup limits in Docker, the image will attempt to automatically set the
|
|
||||||
optimal values. You can override this at any time by specifying the values
|
|
||||||
yourself:
|
|
||||||
|
|
||||||
HTTPD_START_SERVERS
|
|
||||||
The StartServers directive sets the number of child server processes created on startup.
|
|
||||||
Default: 8
|
|
||||||
|
|
||||||
HTTPD_MAX_REQUEST_WORKERS
|
|
||||||
The MaxRequestWorkers directive sets the limit on the number of simultaneous requests that will be served.
|
|
||||||
`MaxRequestWorkers` was called `MaxClients` before version httpd 2.3.13.
|
|
||||||
Default: 256 (this is automatically tuned by setting Cgroup limits for the container using this formula:
|
|
||||||
`TOTAL_MEMORY / 15MB`. The 15MB is average size of a single httpd process.
|
|
||||||
|
|
||||||
You can use a custom composer repository mirror URL to download packages instead of the default 'packagist.org':
|
|
||||||
|
|
||||||
COMPOSER_MIRROR
|
|
||||||
Adds a custom composer repository mirror URL to composer configuration. Note: This only affects packages listed in composer.json.
|
|
||||||
|
|
||||||
## HOT DEPLOY
|
|
||||||
|
|
||||||
In order to immediately pick up changes made in your application source code, you need to run your built image with the `OPCACHE_REVALIDATE_FREQ=0` environment variable passed to the Docker `-e` run flag:
|
|
||||||
|
|
||||||
# docker run -e OPCACHE_REVALIDATE_FREQ=0 -p 8080:8080 php-app
|
|
||||||
|
|
||||||
To change your source code in running container, use Docker's exec command:
|
|
||||||
|
|
||||||
# docker exec -it <CONTAINER_ID> /bin/bash
|
|
||||||
|
|
||||||
After you Docker exec into the running container, your current directory is set to `/opt/app-root/src`, where the source code is located.
|
|
||||||
|
|
||||||
## SECURITY IMPLICATIONS
|
|
||||||
|
|
||||||
-p 8080:8080
|
|
||||||
|
|
||||||
Opens container port 8080 and maps it to the same port on the Host.
|
|
||||||
|
|
@ -58,7 +58,7 @@ opcache.revalidate_freq=${OPCACHE_REVALIDATE_FREQ}
|
||||||
; The location of the OPcache blacklist file (wildcards allowed).
|
; The location of the OPcache blacklist file (wildcards allowed).
|
||||||
; Each OPcache blacklist file is a text file that holds the names of files
|
; Each OPcache blacklist file is a text file that holds the names of files
|
||||||
; that should not be accelerated.
|
; that should not be accelerated.
|
||||||
opcache.blacklist_filename=/etc/opt/rh/rh-php70/php.d/opcache*.blacklist
|
opcache.blacklist_filename=${PHP_SYSCONF_PATH}/php.d/opcache*.blacklist
|
||||||
|
|
||||||
; Allows exclusion of large files from being cached. By default all files
|
; Allows exclusion of large files from being cached. By default all files
|
||||||
; are cached.
|
; are cached.
|
||||||
|
|
@ -386,7 +386,7 @@ max_input_time = 60
|
||||||
|
|
||||||
; Maximum amount of memory a script may consume (128MB)
|
; Maximum amount of memory a script may consume (128MB)
|
||||||
; http://php.net/memory-limit
|
; http://php.net/memory-limit
|
||||||
memory_limit = 128M
|
memory_limit = ${PHP_MEMORY_LIMIT}
|
||||||
|
|
||||||
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
|
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
|
||||||
; Error handling and logging ;
|
; Error handling and logging ;
|
||||||
|
|
@ -1180,7 +1180,7 @@ bcmath.scale = 0
|
||||||
[Session]
|
[Session]
|
||||||
; Handler used to store/retrieve data.
|
; Handler used to store/retrieve data.
|
||||||
; http://php.net/session.save-handler
|
; http://php.net/session.save-handler
|
||||||
session.save_handler = files
|
session.save_handler = ${SESSION_HANDLER}
|
||||||
|
|
||||||
; Argument passed to save_handler. In the case of files, this is the path
|
; Argument passed to save_handler. In the case of files, this is the path
|
||||||
; where data files are stored. Note: Windows users have to change this
|
; where data files are stored. Note: Windows users have to change this
|
||||||
|
|
@ -1228,7 +1228,7 @@ session.use_strict_mode = 0
|
||||||
session.use_cookies = 1
|
session.use_cookies = 1
|
||||||
|
|
||||||
; http://php.net/session.cookie-secure
|
; http://php.net/session.cookie-secure
|
||||||
;session.cookie_secure =
|
session.cookie_secure = ${SESSION_COOKIE_SECURE}
|
||||||
|
|
||||||
; This option forces PHP to fetch and use a cookie for storing and maintaining
|
; This option forces PHP to fetch and use a cookie for storing and maintaining
|
||||||
; the session id. We encourage this operation as it's very helpful in combating
|
; the session id. We encourage this operation as it's very helpful in combating
|
||||||
|
|
@ -1239,7 +1239,7 @@ session.use_only_cookies = 1
|
||||||
|
|
||||||
; Name of the session (used as cookie name).
|
; Name of the session (used as cookie name).
|
||||||
; http://php.net/session.name
|
; http://php.net/session.name
|
||||||
session.name = PHPSESSID
|
session.name = ${SESSION_NAME}
|
||||||
|
|
||||||
; Initialize session on request startup.
|
; Initialize session on request startup.
|
||||||
; http://php.net/session.auto-start
|
; http://php.net/session.auto-start
|
||||||
|
|
@ -1255,11 +1255,11 @@ session.cookie_path = /
|
||||||
|
|
||||||
; The domain for which the cookie is valid.
|
; The domain for which the cookie is valid.
|
||||||
; http://php.net/session.cookie-domain
|
; http://php.net/session.cookie-domain
|
||||||
session.cookie_domain =
|
session.cookie_domain = ${SESSION_COOKIE_DOMAIN}
|
||||||
|
|
||||||
; Whether or not to add the httpOnly flag to the cookie, which makes it inaccessible to browser scripting languages such as JavaScript.
|
; Whether or not to add the httpOnly flag to the cookie, which makes it inaccessible to browser scripting languages such as JavaScript.
|
||||||
; http://php.net/session.cookie-httponly
|
; http://php.net/session.cookie-httponly
|
||||||
session.cookie_httponly =
|
session.cookie_httponly = ${SESSION_COOKIE_HTTPONLY}
|
||||||
|
|
||||||
; Handler used to serialize data. php is the standard serializer of PHP.
|
; Handler used to serialize data. php is the standard serializer of PHP.
|
||||||
; http://php.net/session.serialize-handler
|
; http://php.net/session.serialize-handler
|
||||||
6
root/opt/app-root/etc/scl_enable
Normal file
6
root/opt/app-root/etc/scl_enable
Normal file
|
|
@ -0,0 +1,6 @@
|
||||||
|
# IMPORTANT: Do not add more content to this file unless you know what you are
|
||||||
|
# doing. This file is sourced everytime the shell session is opened.
|
||||||
|
#
|
||||||
|
# This will make scl collection binaries work out of box.
|
||||||
|
unset BASH_ENV PROMPT_COMMAND ENV
|
||||||
|
source scl_source enable ${SCL_ENABLED} httpd24 $NODEJS_SCL
|
||||||
49
root/usr/libexec/container-setup
Executable file
49
root/usr/libexec/container-setup
Executable file
|
|
@ -0,0 +1,49 @@
|
||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
set -e
|
||||||
|
|
||||||
|
# In order to drop the root user, we have to make some directories world
|
||||||
|
# writeable as OpenShift default security model is to run the container under
|
||||||
|
# random UID.
|
||||||
|
|
||||||
|
source ${PHP_CONTAINER_SCRIPTS_PATH}/common.sh
|
||||||
|
|
||||||
|
# compatibility symlinks so we hide SCL paths
|
||||||
|
if [ -v SCL_ENABLED ] ; then
|
||||||
|
# /opt/rh/httpd24/root/etc/httpd will be symlink to /etc/httpd
|
||||||
|
mv /opt/rh/httpd24/root/etc/httpd /etc/httpd
|
||||||
|
ln -s /etc/httpd /opt/rh/httpd24/root/etc/httpd
|
||||||
|
|
||||||
|
# /opt/rh/httpd24/root/var/run/httpd will be symlink to /var/run/httpd
|
||||||
|
mv /opt/rh/httpd24/root/var/run/httpd /var/run/httpd
|
||||||
|
ln -s /var/run/httpd /opt/rh/httpd24/root/var/run/httpd
|
||||||
|
|
||||||
|
# /opt/rh/httpd24/root/var/www will be symlink to /var/www
|
||||||
|
rm -rf /var/www
|
||||||
|
mv ${HTTPD_DATA_ORIG_PATH} /var/www
|
||||||
|
ln -s /var/www ${HTTPD_DATA_ORIG_PATH}
|
||||||
|
else
|
||||||
|
rm -f /opt/app-root/etc/scl_enable
|
||||||
|
fi
|
||||||
|
|
||||||
|
mkdir -p ${HTTPD_CONFIGURATION_PATH}
|
||||||
|
chmod -R a+rwx ${HTTPD_MAIN_CONF_PATH}
|
||||||
|
chmod -R a+rwx ${HTTPD_MAIN_CONF_D_PATH}
|
||||||
|
chmod -R ug+r /etc/pki/tls/certs/localhost.crt
|
||||||
|
chmod -R ug+r /etc/pki/tls/private/localhost.key
|
||||||
|
chown -R 1001:0 /etc/pki/tls/certs/localhost.crt
|
||||||
|
chown -R 1001:0 /etc/pki/tls/private/localhost.key
|
||||||
|
mkdir -p ${APP_ROOT}/etc
|
||||||
|
chmod -R a+rwx ${APP_ROOT}/etc
|
||||||
|
chmod -R a+rwx ${HTTPD_VAR_RUN}
|
||||||
|
chown -R 1001:0 ${APP_ROOT}
|
||||||
|
mkdir /tmp/sessions
|
||||||
|
chmod -R a+rwx /tmp/sessions
|
||||||
|
chown -R 1001:0 /tmp/sessions
|
||||||
|
chown -R 1001:0 ${HTTPD_DATA_PATH}
|
||||||
|
chmod -R a+rwx ${PHP_SYSCONF_PATH}
|
||||||
|
|
||||||
|
mkdir -p ${PHP_CONTAINER_SCRIPTS_PATH}/pre-init
|
||||||
|
|
||||||
|
config_general
|
||||||
|
|
||||||
140
root/usr/share/container-scripts/php/common.sh
Normal file
140
root/usr/share/container-scripts/php/common.sh
Normal file
|
|
@ -0,0 +1,140 @@
|
||||||
|
config_httpd_conf() {
|
||||||
|
sed -i "s/^Listen 80/Listen 0.0.0.0:8080/" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
|
||||||
|
sed -i "s/^User apache/User default/" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
|
||||||
|
sed -i "s/^Group apache/Group root/" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
|
||||||
|
sed -i "s%^DocumentRoot \"${HTTPD_DATA_ORIG_PATH}/html\"%#DocumentRoot \"${APP_DATA}\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
|
||||||
|
sed -i "s%^<Directory \"${HTTPD_DATA_ORIG_PATH}/html\"%<Directory \"${APP_DATA}\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
|
||||||
|
sed -i "s%^<Directory \"${HTTPD_VAR_PATH}/html\"%<Directory \"${APP_DATA}\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
|
||||||
|
sed -i "s%^ErrorLog \"logs/error_log\"%ErrorLog \"|/usr/bin/cat\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
|
||||||
|
sed -i "s%CustomLog \"logs/access_log\"%CustomLog \"|/usr/bin/cat\"%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
|
||||||
|
sed -i "151s%AllowOverride None%AllowOverride All%" ${HTTPD_MAIN_CONF_PATH}/httpd.conf
|
||||||
|
}
|
||||||
|
|
||||||
|
config_ssl_conf() {
|
||||||
|
sed -i -E "s/^Listen 443/Listen 0.0.0.0:8443/" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
|
||||||
|
sed -i -E "s/_default_:443/_default_:8443/" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
|
||||||
|
sed -i -E "s!^(\s*CustomLog)\s+\S+!\1 |/usr/bin/cat!" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
|
||||||
|
sed -i -E "s!^(\s*TransferLog)\s+\S+!\1 |/usr/bin/cat!" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
|
||||||
|
sed -i -E "s!^(\s*ErrorLog)\s+\S+!\1 |/usr/bin/cat!" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
|
||||||
|
}
|
||||||
|
|
||||||
|
config_general() {
|
||||||
|
config_httpd_conf
|
||||||
|
config_ssl_conf
|
||||||
|
sed -i '/php_value session.save_/d' ${HTTPD_MAIN_CONF_D_PATH}/${PHP_HTTPD_CONF_FILE}
|
||||||
|
head -n151 ${HTTPD_MAIN_CONF_PATH}/httpd.conf | tail -n1 | grep "AllowOverride All" || exit 1
|
||||||
|
echo "IncludeOptional ${APP_ROOT}/etc/conf.d/*.conf" >> ${HTTPD_MAIN_CONF_PATH}/httpd.conf
|
||||||
|
}
|
||||||
|
|
||||||
|
function log_info {
|
||||||
|
echo "---> `date +%T` $@"
|
||||||
|
}
|
||||||
|
|
||||||
|
function log_and_run {
|
||||||
|
log_info "Running $@"
|
||||||
|
"$@"
|
||||||
|
}
|
||||||
|
|
||||||
|
function log_volume_info {
|
||||||
|
CONTAINER_DEBUG=${CONTAINER_DEBUG:-}
|
||||||
|
if [[ "${CONTAINER_DEBUG,,}" != "true" ]]; then
|
||||||
|
return
|
||||||
|
fi
|
||||||
|
|
||||||
|
log_info "Volume info for $@:"
|
||||||
|
set +e
|
||||||
|
log_and_run mount
|
||||||
|
while [ $# -gt 0 ]; do
|
||||||
|
log_and_run ls -alZ $1
|
||||||
|
shift
|
||||||
|
done
|
||||||
|
set -e
|
||||||
|
}
|
||||||
|
|
||||||
|
# get_matched_files finds file for image extending
|
||||||
|
function get_matched_files() {
|
||||||
|
local custom_dir default_dir
|
||||||
|
custom_dir="$1"
|
||||||
|
default_dir="$2"
|
||||||
|
files_matched="$3"
|
||||||
|
find "$default_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n"
|
||||||
|
[ -d "$custom_dir" ] && find "$custom_dir" -maxdepth 1 -type f -name "$files_matched" -printf "%f\n"
|
||||||
|
}
|
||||||
|
|
||||||
|
# process_extending_files process extending files in $1 and $2 directories
|
||||||
|
# - source all *.sh files
|
||||||
|
# (if there are files with same name source only file from $1)
|
||||||
|
function process_extending_files() {
|
||||||
|
local custom_dir default_dir
|
||||||
|
custom_dir=$1
|
||||||
|
default_dir=$2
|
||||||
|
|
||||||
|
while read filename ; do
|
||||||
|
echo "=> sourcing $filename ..."
|
||||||
|
# Custom file is prefered
|
||||||
|
if [ -f $custom_dir/$filename ]; then
|
||||||
|
source $custom_dir/$filename
|
||||||
|
elif [ -f $default_dir/$filename ]; then
|
||||||
|
source $default_dir/$filename
|
||||||
|
fi
|
||||||
|
done <<<"$(get_matched_files "$custom_dir" "$default_dir" '*.sh' | sort -u)"
|
||||||
|
}
|
||||||
|
|
||||||
|
# process extending config files in $1 and $2 directories
|
||||||
|
# - expand variables in *.conf and copy the files into /opt/app-root/etc/httpd.d directory
|
||||||
|
# (if there are files with same name source only file from $1)
|
||||||
|
function process_extending_config_files() {
|
||||||
|
local custom_dir default_dir
|
||||||
|
custom_dir=$1
|
||||||
|
default_dir=$2
|
||||||
|
|
||||||
|
while read filename ; do
|
||||||
|
echo "=> sourcing $filename ..."
|
||||||
|
# Custom file is prefered
|
||||||
|
if [ -f $custom_dir/$filename ]; then
|
||||||
|
envsubst < $custom_dir/$filename > ${HTTPD_CONFIGURATION_PATH}/$filename
|
||||||
|
elif [ -f $default_dir/$filename ]; then
|
||||||
|
envsubst < $default_dir/$filename > ${HTTPD_CONFIGURATION_PATH}/$filename
|
||||||
|
fi
|
||||||
|
done <<<"$(get_matched_files "$custom_dir" "$default_dir" '*.conf' | sort -u)"
|
||||||
|
}
|
||||||
|
|
||||||
|
# Copy config files from application to the location where httpd expects them
|
||||||
|
# Param sets the directory where to look for files
|
||||||
|
# This function was taken from httpd container
|
||||||
|
process_config_files() {
|
||||||
|
local dir=${1:-.}
|
||||||
|
if [ -d ${dir}/httpd-cfg ]; then
|
||||||
|
echo "---> Copying httpd configuration files..."
|
||||||
|
if [ "$(ls -A ${dir}/httpd-cfg/*.conf)" ]; then
|
||||||
|
cp -v ${dir}/httpd-cfg/*.conf "${HTTPD_CONFIGURATION_PATH}"/
|
||||||
|
rm -rf ${dir}/httpd-cfg
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# Copy SSL files provided in application source
|
||||||
|
# This function was taken from httpd container
|
||||||
|
process_ssl_certs() {
|
||||||
|
local dir=${1:-.}
|
||||||
|
if [ -d ${dir}/httpd-ssl/private ] && [ -d ${dir}/httpd-ssl/certs ]; then
|
||||||
|
echo "---> Looking for SSL certs for httpd..."
|
||||||
|
cp -r ${dir}/httpd-ssl ${APP_ROOT}
|
||||||
|
local ssl_cert="$(ls -A ${APP_ROOT}/httpd-ssl/certs/*.pem | head -n 1)"
|
||||||
|
local ssl_private="$(ls -A ${APP_ROOT}/httpd-ssl/private/*.pem | head -n 1)"
|
||||||
|
if [ -f "${ssl_cert}" ] ; then
|
||||||
|
# do sed for SSLCertificateFile and SSLCertificateKeyFile
|
||||||
|
echo "---> Setting SSL cert file for httpd..."
|
||||||
|
sed -i -e "s|^SSLCertificateFile .*$|SSLCertificateFile ${ssl_cert}|" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
|
||||||
|
if [ -f "${ssl_private}" ]; then
|
||||||
|
echo "---> Setting SSL key file for httpd..."
|
||||||
|
sed -i -e "s|^SSLCertificateKeyFile .*$|SSLCertificateKeyFile ${ssl_private}|" ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
|
||||||
|
else
|
||||||
|
echo "---> Removing SSL key file settings for httpd..."
|
||||||
|
sed -i '/^SSLCertificateKeyFile .*/d' ${HTTPD_MAIN_CONF_D_PATH}/ssl.conf
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
rm -rf ${dir}/httpd-ssl
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
|
@ -0,0 +1,6 @@
|
||||||
|
# additional arbitrary httpd configuration provided by user using s2i
|
||||||
|
|
||||||
|
log_info 'Processing additional arbitrary httpd configuration provided by s2i ...'
|
||||||
|
|
||||||
|
process_extending_config_files ${APP_DATA}/httpd-cfg/ ${PHP_CONTAINER_SCRIPTS_PATH}/httpd-cnf/
|
||||||
|
|
||||||
|
|
@ -0,0 +1,4 @@
|
||||||
|
source ${PHP_CONTAINER_SCRIPTS_PATH}/common.sh
|
||||||
|
|
||||||
|
# Copy SSL files provided in application source
|
||||||
|
process_ssl_certs
|
||||||
|
|
@ -0,0 +1,6 @@
|
||||||
|
# additional arbitrary httpd configuration provided by user using s2i
|
||||||
|
|
||||||
|
log_info 'Processing additional arbitrary httpd configuration provided by s2i ...'
|
||||||
|
|
||||||
|
process_extending_config_files ${APP_DATA}/httpd-cfg/ ${PHP_CONTAINER_SCRIPTS_PATH}/httpd-cnf/
|
||||||
|
|
||||||
|
|
@ -0,0 +1,4 @@
|
||||||
|
source ${PHP_CONTAINER_SCRIPTS_PATH}/common.sh
|
||||||
|
|
||||||
|
# Copy SSL files provided in application source
|
||||||
|
process_ssl_certs ${APP_ROOT}/src
|
||||||
56
s2i/bin/assemble
Executable file
56
s2i/bin/assemble
Executable file
|
|
@ -0,0 +1,56 @@
|
||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
set -e
|
||||||
|
|
||||||
|
source ${PHP_CONTAINER_SCRIPTS_PATH}/common.sh
|
||||||
|
|
||||||
|
shopt -s dotglob
|
||||||
|
echo "---> Installing application source..."
|
||||||
|
mv /tmp/src/* ./
|
||||||
|
|
||||||
|
if [ -f composer.json ]; then
|
||||||
|
echo "Found 'composer.json', installing dependencies using composer.phar... "
|
||||||
|
|
||||||
|
# Install Composer
|
||||||
|
TEMPFILE=$(mktemp)
|
||||||
|
RETRIES=6
|
||||||
|
for ((i=0; i<$RETRIES; i++)); do
|
||||||
|
|
||||||
|
if [ -z "$COMPOSER_INSTALLER" ]; then
|
||||||
|
export COMPOSER_INSTALLER="https://getcomposer.org/installer"
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "Downloading $COMPOSER_INSTALLER, attempt $((i+1))/$RETRIES"
|
||||||
|
curl -o $TEMPFILE $COMPOSER_INSTALLER && break
|
||||||
|
sleep 10
|
||||||
|
done
|
||||||
|
if [[ $i == $RETRIES ]]; then
|
||||||
|
echo "Download failed, giving up."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
php <$TEMPFILE
|
||||||
|
|
||||||
|
if [ "$(ls -a /tmp/artifacts/ 2>/dev/null)" ]; then
|
||||||
|
echo "Restoring build artifacts"
|
||||||
|
mv /tmp/artifacts/* $HOME/
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Change the repo mirror if provided
|
||||||
|
if [ -n "$COMPOSER_MIRROR" ]; then
|
||||||
|
./composer.phar config -g repositories.packagist composer $COMPOSER_MIRROR
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Install App dependencies using Composer
|
||||||
|
./composer.phar install --no-interaction --no-ansi --optimize-autoloader $COMPOSER_ARGS
|
||||||
|
|
||||||
|
if [ ! -f composer.lock ]; then
|
||||||
|
echo -e "\nConsider adding a 'composer.lock' file into your source repository.\n"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
# post-assemble files
|
||||||
|
process_extending_files ./php-post-assemble/ ${PHP_CONTAINER_SCRIPTS_PATH}/post-assemble/
|
||||||
|
|
||||||
|
# Fix source directory permissions
|
||||||
|
fix-permissions ./
|
||||||
|
fix-permissions ${HTTPD_CONFIGURATION_PATH}
|
||||||
|
|
@ -1,5 +1,7 @@
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
|
source ${PHP_CONTAINER_SCRIPTS_PATH}/common.sh
|
||||||
|
|
||||||
export_vars=$(cgroup-limits); export $export_vars
|
export_vars=$(cgroup-limits); export $export_vars
|
||||||
export DOCUMENTROOT=${DOCUMENTROOT:-/}
|
export DOCUMENTROOT=${DOCUMENTROOT:-/}
|
||||||
|
|
||||||
|
|
@ -10,19 +12,26 @@ export DISPLAY_ERRORS=${DISPLAY_ERRORS:-ON}
|
||||||
export DISPLAY_STARTUP_ERRORS=${DISPLAY_STARTUP_ERRORS:-OFF}
|
export DISPLAY_STARTUP_ERRORS=${DISPLAY_STARTUP_ERRORS:-OFF}
|
||||||
export TRACK_ERRORS=${TRACK_ERRORS:-OFF}
|
export TRACK_ERRORS=${TRACK_ERRORS:-OFF}
|
||||||
export HTML_ERRORS=${HTML_ERRORS:-ON}
|
export HTML_ERRORS=${HTML_ERRORS:-ON}
|
||||||
export INCLUDE_PATH=${INCLUDE_PATH:-.:/opt/app-root/src:/usr/share/pear}
|
export INCLUDE_PATH=${INCLUDE_PATH:-.:/opt/app-root/src:${PHP_DEFAULT_INCLUDE_PATH}}
|
||||||
|
export PHP_MEMORY_LIMIT=${PHP_MEMORY_LIMIT:-128M}
|
||||||
|
export SESSION_NAME=${SESSION_NAME:-PHPSESSID}
|
||||||
|
export SESSION_HANDLER=${SESSION_HANDLER:-files}
|
||||||
export SESSION_PATH=${SESSION_PATH:-/tmp/sessions}
|
export SESSION_PATH=${SESSION_PATH:-/tmp/sessions}
|
||||||
|
export SESSION_COOKIE_DOMAIN=${SESSION_COOKIE_DOMAIN:-}
|
||||||
|
export SESSION_COOKIE_HTTPONLY=${SESSION_COOKIE_HTTPONLY:-}
|
||||||
|
export SESSION_COOKIE_SECURE=${SESSION_COOKIE_SECURE:-0}
|
||||||
export SHORT_OPEN_TAG=${SHORT_OPEN_TAG:-OFF}
|
export SHORT_OPEN_TAG=${SHORT_OPEN_TAG:-OFF}
|
||||||
|
|
||||||
# TODO should be dynamically calculated based on container memory limit/16
|
# TODO should be dynamically calculated based on container memory limit/16
|
||||||
export OPCACHE_MEMORY_CONSUMPTION=${OPCACHE_MEMORY_CONSUMPTION:-128}
|
export OPCACHE_MEMORY_CONSUMPTION=${OPCACHE_MEMORY_CONSUMPTION:-128}
|
||||||
|
|
||||||
export OPCACHE_REVALIDATE_FREQ=${OPCACHE_REVALIDATE_FREQ:-2}
|
export OPCACHE_REVALIDATE_FREQ=${OPCACHE_REVALIDATE_FREQ:-2}
|
||||||
|
|
||||||
export PHPRC=${PHPRC:-/etc/php.ini}
|
export PHPRC=${PHPRC:-${PHP_SYSCONF_PATH}/php.ini}
|
||||||
export PHP_INI_SCAN_DIR=${PHP_INI_SCAN_DIR:-/etc/php.d}
|
export PHP_INI_SCAN_DIR=${PHP_INI_SCAN_DIR:-${PHP_SYSCONF_PATH}/php.d}
|
||||||
|
|
||||||
envsubst < /opt/app-root/etc/php.ini.template > /etc/php.ini
|
envsubst < /opt/app-root/etc/php.ini.template > ${PHP_SYSCONF_PATH}/php.ini
|
||||||
envsubst < /opt/app-root/etc/php.d/10-opcache.ini.template > /etc/php.d/10-opcache.ini
|
envsubst < /opt/app-root/etc/php.d/10-opcache.ini.template > ${PHP_SYSCONF_PATH}/php.d/10-opcache.ini
|
||||||
|
|
||||||
export HTTPD_START_SERVERS=${HTTPD_START_SERVERS:-8}
|
export HTTPD_START_SERVERS=${HTTPD_START_SERVERS:-8}
|
||||||
export HTTPD_MAX_SPARE_SERVERS=$((HTTPD_START_SERVERS+10))
|
export HTTPD_MAX_SPARE_SERVERS=$((HTTPD_START_SERVERS+10))
|
||||||
|
|
@ -42,7 +51,7 @@ else
|
||||||
echo "-> Cgroups memory limit is set, using HTTPD_MAX_REQUEST_WORKERS=${HTTPD_MAX_REQUEST_WORKERS}"
|
echo "-> Cgroups memory limit is set, using HTTPD_MAX_REQUEST_WORKERS=${HTTPD_MAX_REQUEST_WORKERS}"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
envsubst < /opt/app-root/etc/conf.d/50-mpm-tuning.conf.template > /opt/app-root/etc/conf.d/50-mpm-tuning.conf
|
# pre-start files
|
||||||
envsubst < /opt/app-root/etc/conf.d/00-documentroot.conf.template > /opt/app-root/etc/conf.d/00-documentroot.conf
|
process_extending_files ${APP_DATA}/php-pre-start/ ${PHP_CONTAINER_SCRIPTS_PATH}/pre-start/
|
||||||
|
|
||||||
exec httpd -D FOREGROUND
|
exec httpd -D FOREGROUND
|
||||||
4
s2i/bin/save-artifacts
Executable file
4
s2i/bin/save-artifacts
Executable file
|
|
@ -0,0 +1,4 @@
|
||||||
|
#!/bin/sh
|
||||||
|
pushd ${HOME} >/dev/null
|
||||||
|
tar cf - vendor
|
||||||
|
popd >/dev/null
|
||||||
17
s2i/bin/usage
Executable file
17
s2i/bin/usage
Executable file
|
|
@ -0,0 +1,17 @@
|
||||||
|
#!/bin/sh
|
||||||
|
|
||||||
|
DISTRO=`cat /etc/*-release | grep ^ID= | grep -Po '".*?"' | tr -d '"'`
|
||||||
|
NAMESPACE=centos
|
||||||
|
[[ $DISTRO =~ rhel* ]] && NAMESPACE=rhscl
|
||||||
|
|
||||||
|
cat <<EOF
|
||||||
|
This is a S2I PHP-7.1 ${DISTRO} base image:
|
||||||
|
To use it, install S2I: https://github.com/openshift/source-to-image
|
||||||
|
|
||||||
|
Sample invocation:
|
||||||
|
|
||||||
|
s2i build https://github.com/sclorg/s2i-php-container.git --context-dir=/7.1/test/test-app/ ${NAMESPACE}/php-71-${DISTRO}7 php-test-app
|
||||||
|
|
||||||
|
You can then run the resulting image via:
|
||||||
|
docker run -p 8080:8080 php-test-app
|
||||||
|
EOF
|
||||||
1
test/.gitignore
vendored
1
test/.gitignore
vendored
|
|
@ -1 +0,0 @@
|
||||||
.git/
|
|
||||||
164
test/run
164
test/run
|
|
@ -1,35 +1,22 @@
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
#
|
#
|
||||||
# The 'run' performs a simple test that verifies the S2I image.
|
# The 'run' performs a simple test that verifies that S2I image.
|
||||||
# The main focus here is to exercise the S2I scripts.
|
# The main focus here is to excersise the S2I scripts.
|
||||||
#
|
|
||||||
# For more information see the documentation:
|
|
||||||
# https://github.com/openshift/source-to-image/blob/master/docs/builder_image.md
|
|
||||||
#
|
#
|
||||||
# IMAGE_NAME specifies a name of the candidate image used for testing.
|
# IMAGE_NAME specifies a name of the candidate image used for testing.
|
||||||
# The image has to be available before this script is executed.
|
# The image has to be available before this script is executed.
|
||||||
#
|
#
|
||||||
IMAGE_NAME=${IMAGE_NAME-php-candidate}
|
IMAGE_NAME=${IMAGE_NAME-centos/php-71-centos-candidate}
|
||||||
|
|
||||||
# Determining system utility executables (darwin compatibility check)
|
# TODO: Make command compatible for Mac users
|
||||||
READLINK_EXEC="readlink"
|
test_dir="$(readlink -zf $(dirname "${BASH_SOURCE[0]}"))"
|
||||||
MKTEMP_EXEC="mktemp"
|
image_dir=$(readlink -zf ${test_dir}/..)
|
||||||
if [[ "$OSTYPE" =~ 'darwin' ]]; then
|
|
||||||
! type -a "greadlink" &>"/dev/null" || READLINK_EXEC="greadlink"
|
|
||||||
! type -a "gmktemp" &>"/dev/null" || MKTEMP_EXEC="gmktemp"
|
|
||||||
fi
|
|
||||||
|
|
||||||
test_dir="$($READLINK_EXEC -zf $(dirname "${BASH_SOURCE[0]}"))"
|
source "${test_dir}/test-lib.sh"
|
||||||
image_dir=$($READLINK_EXEC -zf ${test_dir}/..)
|
|
||||||
scripts_url="file://${image_dir}/.s2i/bin"
|
|
||||||
cid_file=$($MKTEMP_EXEC -u --suffix=.cid)
|
|
||||||
|
|
||||||
# Since we built the candidate image locally, we don't want S2I to attempt to pull
|
# TODO: This should be part of the image metadata
|
||||||
# it from Docker hub
|
|
||||||
s2i_args="--force-pull=false"
|
|
||||||
|
|
||||||
# Port the image exposes service to be tested
|
|
||||||
test_port=8080
|
test_port=8080
|
||||||
|
test_port_ssl=8443
|
||||||
|
|
||||||
info() {
|
info() {
|
||||||
echo -e "\n\e[1m[INFO] $@...\e[0m\n"
|
echo -e "\n\e[1m[INFO] $@...\e[0m\n"
|
||||||
|
|
@ -44,23 +31,11 @@ container_exists() {
|
||||||
}
|
}
|
||||||
|
|
||||||
container_ip() {
|
container_ip() {
|
||||||
if [ ! -z "$DOCKER_HOST" ] && [[ "$OSTYPE" =~ 'darwin' ]]; then
|
docker inspect --format="{{ .NetworkSettings.IPAddress }}" $(cat $cid_file)
|
||||||
docker-machine ip
|
|
||||||
else
|
|
||||||
docker inspect --format="{{ .NetworkSettings.IPAddress }}" $(cat $cid_file)
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
container_port() {
|
|
||||||
if [ ! -z "$DOCKER_HOST" ] && [[ "$OSTYPE" =~ 'darwin' ]]; then
|
|
||||||
docker inspect --format="{{(index .NetworkSettings.Ports \"$test_port/tcp\" 0).HostPort}}" "$(cat "${cid_file}")"
|
|
||||||
else
|
|
||||||
echo $test_port
|
|
||||||
fi
|
|
||||||
}
|
}
|
||||||
|
|
||||||
run_s2i_build() {
|
run_s2i_build() {
|
||||||
s2i build --incremental=true ${s2i_args} file://${test_dir}/test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp
|
ct_s2i_build_as_df file://${test_dir}/test-app ${IMAGE_NAME} ${IMAGE_NAME}-testapp ${s2i_args}
|
||||||
}
|
}
|
||||||
|
|
||||||
prepare() {
|
prepare() {
|
||||||
|
|
@ -68,7 +43,9 @@ prepare() {
|
||||||
echo "ERROR: The image ${IMAGE_NAME} must exist before this script is executed."
|
echo "ERROR: The image ${IMAGE_NAME} must exist before this script is executed."
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
# s2i build requires the application is a valid 'Git' repository
|
# TODO: S2I build require the application is a valid 'GIT' repository, we
|
||||||
|
# should remove this restriction in the future when a file:// is used.
|
||||||
|
info "Build the test application image"
|
||||||
pushd ${test_dir}/test-app >/dev/null
|
pushd ${test_dir}/test-app >/dev/null
|
||||||
git init
|
git init
|
||||||
git config user.email "build@localhost" && git config user.name "builder"
|
git config user.email "build@localhost" && git config user.name "builder"
|
||||||
|
|
@ -77,7 +54,8 @@ prepare() {
|
||||||
}
|
}
|
||||||
|
|
||||||
run_test_application() {
|
run_test_application() {
|
||||||
docker run --user=100001 --rm --cidfile=${cid_file} -p ${test_port} ${IMAGE_NAME}-testapp
|
run_args=${CONTAINER_ARGS:-}
|
||||||
|
docker run --user=100001 ${run_args} --cidfile=${cid_file} ${IMAGE_NAME}-testapp
|
||||||
}
|
}
|
||||||
|
|
||||||
cleanup_test_app() {
|
cleanup_test_app() {
|
||||||
|
|
@ -92,20 +70,17 @@ cleanup_test_app() {
|
||||||
}
|
}
|
||||||
|
|
||||||
cleanup() {
|
cleanup() {
|
||||||
if [ -f $cid_file ]; then
|
info "Cleaning up the test application image"
|
||||||
if container_exists; then
|
|
||||||
docker stop $(cat $cid_file)
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
if image_exists ${IMAGE_NAME}-testapp; then
|
if image_exists ${IMAGE_NAME}-testapp; then
|
||||||
docker rmi -f ${IMAGE_NAME}-testapp
|
docker rmi -f ${IMAGE_NAME}-testapp
|
||||||
fi
|
fi
|
||||||
|
rm -rf ${test_dir}/test-app/.git
|
||||||
}
|
}
|
||||||
|
|
||||||
check_result() {
|
check_result() {
|
||||||
local result="$1"
|
local result="$1"
|
||||||
if [[ "$result" != "0" ]]; then
|
if [[ "$result" != "0" ]]; then
|
||||||
echo "S2I image '${IMAGE_NAME}' test FAILED (exit code: ${result})"
|
info "TEST FAILED (${result})"
|
||||||
cleanup
|
cleanup
|
||||||
exit $result
|
exit $result
|
||||||
fi
|
fi
|
||||||
|
|
@ -116,17 +91,17 @@ wait_for_cid() {
|
||||||
local sleep_time=1
|
local sleep_time=1
|
||||||
local attempt=1
|
local attempt=1
|
||||||
local result=1
|
local result=1
|
||||||
|
info "Waiting for application container to start"
|
||||||
while [ $attempt -le $max_attempts ]; do
|
while [ $attempt -le $max_attempts ]; do
|
||||||
[ -f $cid_file ] && break
|
[ -f $cid_file ] && [ -s $cid_file ] && break
|
||||||
echo "Waiting for container to start..."
|
|
||||||
attempt=$(( $attempt + 1 ))
|
attempt=$(( $attempt + 1 ))
|
||||||
sleep $sleep_time
|
sleep $sleep_time
|
||||||
done
|
done
|
||||||
}
|
}
|
||||||
|
|
||||||
test_s2i_usage() {
|
test_s2i_usage() {
|
||||||
echo "Testing 's2i usage'..."
|
info "Testing 's2i usage'"
|
||||||
s2i usage ${s2i_args} ${IMAGE_NAME} &>/dev/null
|
ct_s2i_usage ${IMAGE_NAME} ${s2i_args} &>/dev/null
|
||||||
}
|
}
|
||||||
|
|
||||||
test_docker_run_usage() {
|
test_docker_run_usage() {
|
||||||
|
|
@ -134,21 +109,57 @@ test_docker_run_usage() {
|
||||||
docker run ${IMAGE_NAME} &>/dev/null
|
docker run ${IMAGE_NAME} &>/dev/null
|
||||||
}
|
}
|
||||||
|
|
||||||
|
test_scl_usage() {
|
||||||
|
local run_cmd="$1"
|
||||||
|
local expected="$2"
|
||||||
|
|
||||||
|
info "Testing the image SCL enable"
|
||||||
|
out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${run_cmd}")
|
||||||
|
if ! echo "${out}" | grep -q "${expected}"; then
|
||||||
|
echo "ERROR[/bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
out=$(docker exec $(cat ${cid_file}) /bin/bash -c "${run_cmd}" 2>&1)
|
||||||
|
if ! echo "${out}" | grep -q "${expected}"; then
|
||||||
|
echo "ERROR[exec /bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
out=$(docker exec $(cat ${cid_file}) /bin/sh -ic "${run_cmd}" 2>&1)
|
||||||
|
if ! echo "${out}" | grep -q "${expected}"; then
|
||||||
|
echo "ERROR[exec /bin/sh -ic "${run_cmd}"] Expected '${expected}', got '${out}'"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
test_session() {
|
||||||
|
local check_port=$1 ; shift
|
||||||
|
local check_protocol=${1:-http}
|
||||||
|
cat $cid_file
|
||||||
|
info "Testing PHP session"
|
||||||
|
response=$(curl -s -k ${check_protocol}://$(container_ip):${check_port}/session_test.php)
|
||||||
|
if [ "${response}" != "Passed" ]; then
|
||||||
|
echo "ERROR starting PHP session. Test app returned: '${response}'"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
test_connection() {
|
test_connection() {
|
||||||
echo "Testing HTTP connection (http://$(container_ip):$(container_port))"
|
local check_port=$1 ; shift
|
||||||
|
local check_protocol=${1:-http}
|
||||||
|
cat $cid_file
|
||||||
|
info "Testing the HTTP connection (${check_protocol}://$(container_ip):${check_port})"
|
||||||
local max_attempts=10
|
local max_attempts=10
|
||||||
local sleep_time=1
|
local sleep_time=1
|
||||||
local attempt=1
|
local attempt=1
|
||||||
local result=1
|
local result=1
|
||||||
while [ $attempt -le $max_attempts ]; do
|
while [ $attempt -le $max_attempts ]; do
|
||||||
echo "Sending GET request to http://$(container_ip):$(container_port)/"
|
response_code=$(curl -s -w %{http_code} -o /dev/null -k ${check_protocol}://$(container_ip):${check_port}/)
|
||||||
response_code=$(curl -s -w %{http_code} -o /dev/null http://$(container_ip):$(container_port)/)
|
|
||||||
status=$?
|
status=$?
|
||||||
if [ $status -eq 0 ]; then
|
if [ $status -eq 0 ]; then
|
||||||
if [ $response_code -eq 200 ]; then
|
if [ $response_code -eq 200 ]; then
|
||||||
result=0
|
result=0
|
||||||
|
break
|
||||||
fi
|
fi
|
||||||
break
|
|
||||||
fi
|
fi
|
||||||
attempt=$(( $attempt + 1 ))
|
attempt=$(( $attempt + 1 ))
|
||||||
sleep $sleep_time
|
sleep $sleep_time
|
||||||
|
|
@ -163,18 +174,49 @@ test_application() {
|
||||||
# Wait for the container to write it's CID file
|
# Wait for the container to write it's CID file
|
||||||
wait_for_cid
|
wait_for_cid
|
||||||
|
|
||||||
test_connection
|
test_scl_usage "php --version" "7.1"
|
||||||
|
check_result $?
|
||||||
|
|
||||||
|
test_session ${test_port}
|
||||||
|
check_result $?
|
||||||
|
|
||||||
|
test_connection ${test_port}
|
||||||
|
check_result $?
|
||||||
|
test_connection ${test_port_ssl} https
|
||||||
check_result $?
|
check_result $?
|
||||||
cleanup_test_app
|
cleanup_test_app
|
||||||
}
|
}
|
||||||
|
|
||||||
# Build the application image twice to ensure the 'save-artifacts' and
|
test_ssl() {
|
||||||
# 'restore-artifacts' scripts are working properly
|
local cert_dir=/tmp
|
||||||
|
local cert_base=mycert
|
||||||
|
ct_gen_self_signed_cert_pem ${cert_dir} ${cert_base}
|
||||||
|
local private_key=${cert_dir}/${cert_base}-cert-selfsigned.pem
|
||||||
|
local cert_file=${cert_dir}/${cert_base}-key.pem
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
test_ssl_own_cert() {
|
||||||
|
ct_s2i_build_as_df file://${test_dir}/self-signed-ssl ${IMAGE_NAME} ${IMAGE_NAME}-test-self-signed-ssl ${s2i_args}
|
||||||
|
docker run -d --user=100001 ${run_args} --cidfile=${cid_file} ${IMAGE_NAME}-test-self-signed-ssl
|
||||||
|
test_connection ${test_port_ssl} https
|
||||||
|
check_result $?
|
||||||
|
echo | openssl s_client -showcerts -servername $(container_ip) -connect $(container_ip):${test_port_ssl} 2>/dev/null | openssl x509 -inform pem -noout -text >./servercert
|
||||||
|
openssl x509 -in ${test_dir}/self-signed-ssl/httpd-ssl/certs/server-cert-selfsigned.pem -inform pem -noout -text >./configcert
|
||||||
|
diff ./configcert ./servercert >cert.diff
|
||||||
|
}
|
||||||
|
|
||||||
|
cid_file=$(mktemp -u --suffix=.cid)
|
||||||
|
|
||||||
|
# Since we built the candidate image locally, we don't want S2I attempt to pull
|
||||||
|
# it from Docker hub
|
||||||
|
s2i_args="--pull-policy=never"
|
||||||
|
|
||||||
prepare
|
prepare
|
||||||
run_s2i_build
|
run_s2i_build
|
||||||
check_result $?
|
check_result $?
|
||||||
|
|
||||||
# Verify the 'usage' script is working properly
|
# Verify the 'usage' script is working properly when running the base image with 's2i usage ...'
|
||||||
test_s2i_usage
|
test_s2i_usage
|
||||||
check_result $?
|
check_result $?
|
||||||
|
|
||||||
|
|
@ -186,8 +228,16 @@ check_result $?
|
||||||
test_application
|
test_application
|
||||||
|
|
||||||
# Test application with random uid
|
# Test application with random uid
|
||||||
CONTAINER_ARGS="-u 12345" test_application
|
CONTAINER_ARGS="--user 12345" test_application
|
||||||
|
|
||||||
|
echo "Testing npm availibility"
|
||||||
|
ct_npm_works
|
||||||
|
check_result $?
|
||||||
|
|
||||||
cleanup
|
cleanup
|
||||||
|
|
||||||
|
test_ssl_own_cert
|
||||||
|
check_result $?
|
||||||
|
cleanup
|
||||||
|
|
||||||
info "All tests finished successfully."
|
info "All tests finished successfully."
|
||||||
|
|
|
||||||
77
test/run-openshift
Executable file
77
test/run-openshift
Executable file
|
|
@ -0,0 +1,77 @@
|
||||||
|
#!/bin/bash
|
||||||
|
#
|
||||||
|
# Test the PHP image in OpenShift.
|
||||||
|
#
|
||||||
|
# IMAGE_NAME specifies a name of the candidate image used for testing.
|
||||||
|
# The image has to be available before this script is executed.
|
||||||
|
#
|
||||||
|
|
||||||
|
THISDIR=$(dirname ${BASH_SOURCE[0]})
|
||||||
|
|
||||||
|
source ${THISDIR}/test-lib.sh
|
||||||
|
source ${THISDIR}/test-lib-openshift.sh
|
||||||
|
|
||||||
|
# change the branch to a different value if a new change in the example
|
||||||
|
# app needs to be tested
|
||||||
|
BRANCH_TO_TEST=master
|
||||||
|
|
||||||
|
set -eo nounset
|
||||||
|
|
||||||
|
test -n "${IMAGE_NAME-}" || false 'make sure $IMAGE_NAME is defined'
|
||||||
|
test -n "${VERSION-}" || false 'make sure $VERSION is defined'
|
||||||
|
test -n "${OS-}" || false 'make sure $OS is defined'
|
||||||
|
istag="php:$VERSION"
|
||||||
|
|
||||||
|
function test_file_upload() {
|
||||||
|
local image_name=$1
|
||||||
|
local service_name=${image_name##*/}
|
||||||
|
local app="https://github.com/openshift-qe/openshift-php-upload-demo"
|
||||||
|
local ip=""
|
||||||
|
|
||||||
|
echo "Running file upload test for: $image_name"
|
||||||
|
ct_os_new_project
|
||||||
|
ct_os_upload_image "$image_name" "$istag"
|
||||||
|
|
||||||
|
ct_os_deploy_s2i_image "$istag" "$app" --name "${service_name}"
|
||||||
|
ct_os_wait_pod_ready "$service_name" 60
|
||||||
|
|
||||||
|
# Wait until the app is prepared to receive files
|
||||||
|
ip=$(ct_os_get_service_ip "$service_name")
|
||||||
|
curl "$ip:8080" 2>/dev/null | grep -q "OpenShift File Upload Demonstration"
|
||||||
|
|
||||||
|
# Upload a file into the pod using the php app
|
||||||
|
curl -F fto=@README.md "$ip:8080/upload.php" &>/dev/null
|
||||||
|
ct_os_run_in_pod "$(ct_os_get_pod_name "$service_name")" ls uploaded/README.md >/dev/null
|
||||||
|
|
||||||
|
ct_os_delete_project
|
||||||
|
}
|
||||||
|
|
||||||
|
ct_os_cluster_up
|
||||||
|
|
||||||
|
# test local app
|
||||||
|
ct_os_test_s2i_app ${IMAGE_NAME} "https://github.com/sclorg/s2i-php-container.git" ${VERSION}/test/test-app "Test PHP passed"
|
||||||
|
|
||||||
|
ct_os_test_s2i_app ${IMAGE_NAME} "https://github.com/sclorg/cakephp-ex.git#${BRANCH_TO_TEST}" . 'Welcome to your CakePHP application on OpenShift'
|
||||||
|
|
||||||
|
# cakephp template does not work with version 5.6
|
||||||
|
if [[ "${VERSION}" > "5.6" ]] ; then
|
||||||
|
ct_os_test_template_app ${IMAGE_NAME} \
|
||||||
|
https://raw.githubusercontent.com/sclorg/cakephp-ex/${BRANCH_TO_TEST}/openshift/templates/cakephp.json \
|
||||||
|
php \
|
||||||
|
'Welcome to your CakePHP application on OpenShift' \
|
||||||
|
8080 http 200 "-p SOURCE_REPOSITORY_REF=${BRANCH_TO_TEST} -p SOURCE_REPOSITORY_URL=https://github.com/sclorg/cakephp-ex.git -p PHP_VERSION=${VERSION} -p NAME=php-testing"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# test image update with s2i
|
||||||
|
case "$OS" in
|
||||||
|
rhel7) old_image=rhscl/php-${VERSION/./}-rhel7 ;;
|
||||||
|
# Fedora image isn't in registry yet
|
||||||
|
# fedora) old_image=${IMAGE_NAME/localhost\//}
|
||||||
|
*) old_image=centos/php-${VERSION/./}-centos7 ;;
|
||||||
|
esac
|
||||||
|
ct_os_test_image_update "$IMAGE_NAME" "${old_image}" "$istag" \
|
||||||
|
'ct_test_response "http://<IP>:8080" "200" "Test PHP passed"' \
|
||||||
|
"$istag~https://github.com/sclorg/s2i-php-container.git" \
|
||||||
|
--context-dir="$VERSION/test/test-app"
|
||||||
|
|
||||||
|
test_file_upload "$IMAGE_NAME"
|
||||||
|
|
@ -0,0 +1,20 @@
|
||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIIDWjCCAkKgAwIBAgIJAI4x7HuBG49oMA0GCSqGSIb3DQEBCwUAMEIxCzAJBgNV
|
||||||
|
BAYTAlhYMRUwEwYDVQQHDAxEZWZhdWx0IENpdHkxHDAaBgNVBAoME0RlZmF1bHQg
|
||||||
|
Q29tcGFueSBMdGQwHhcNMTcxMjAzMjMzMzU3WhcNMTgwMTAyMjMzMzU3WjBCMQsw
|
||||||
|
CQYDVQQGEwJYWDEVMBMGA1UEBwwMRGVmYXVsdCBDaXR5MRwwGgYDVQQKDBNEZWZh
|
||||||
|
dWx0IENvbXBhbnkgTHRkMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA
|
||||||
|
vH4Vdq0a3UWUQd8Z6s2csxhxjAOyUx0rszGL0m3uTjQido6JRBdjN2dXiZc3LFoq
|
||||||
|
YeOKR3CeHsn7UdrlzaboHFDfjAaextse0740mB1g14H1bAS0POuTPeKa+3wGfzCb
|
||||||
|
sTSXnfSrICl3n2D/3KSO93WwmS90kBD6HmKt5nfkLpJnROM/4bHmuoV0Ry8CDjzj
|
||||||
|
mka7pQU4yzyMKLU3sHpncZU6g7o4Vezic9ksVzIAbdPCSbF7ktVz/hisyCuzyKN6
|
||||||
|
s2327jq593vBgGOsNU5PDPDjKW74Q0Bv/FxPK4nx+o4IkcRW1QEb+yAx8XOM7CDZ
|
||||||
|
ViKvI/A0b+Y4Y3rIQ465+wIDAQABo1MwUTAdBgNVHQ4EFgQUAY1i6ZNbqO1+46aw
|
||||||
|
pldCyPaWoYswHwYDVR0jBBgwFoAUAY1i6ZNbqO1+46awpldCyPaWoYswDwYDVR0T
|
||||||
|
AQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEADhGjnYGq9JvQcygMYEQiIdyS
|
||||||
|
t06Nu7NUkWz52GJp7WFognWyG+0jAomBR0GSUchfubvVZ7cHIaVKLhiGOqg+HIol
|
||||||
|
7tNRfvE6x/Idk674g6OTRAWxO/wOlgnRMpRy6XhHOtb4HcPcpWFZJS8MC8+HRWIs
|
||||||
|
kzMErXe0/obnKn9O04kcEREfmB7kfcD4ooqk5gwbdQk1W6a44LcN6AB5qYPjOzgF
|
||||||
|
Qnb2aLQW9XhgNhiMsYqDzCZsy0az0rz7NgkVOnKrGJ8x3kVX13GR2joVVHOazms9
|
||||||
|
Gd90z+mLMDTbqCRGIPMLvEp4HtAmBxbgsj/zHyinajIqV96B3Cr3zTdW29lHJg==
|
||||||
|
-----END CERTIFICATE-----
|
||||||
28
test/self-signed-ssl/httpd-ssl/private/server-key.pem
Normal file
28
test/self-signed-ssl/httpd-ssl/private/server-key.pem
Normal file
|
|
@ -0,0 +1,28 @@
|
||||||
|
-----BEGIN PRIVATE KEY-----
|
||||||
|
MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQC8fhV2rRrdRZRB
|
||||||
|
3xnqzZyzGHGMA7JTHSuzMYvSbe5ONCJ2jolEF2M3Z1eJlzcsWiph44pHcJ4eyftR
|
||||||
|
2uXNpugcUN+MBp7G2x7TvjSYHWDXgfVsBLQ865M94pr7fAZ/MJuxNJed9KsgKXef
|
||||||
|
YP/cpI73dbCZL3SQEPoeYq3md+QukmdE4z/hsea6hXRHLwIOPOOaRrulBTjLPIwo
|
||||||
|
tTewemdxlTqDujhV7OJz2SxXMgBt08JJsXuS1XP+GKzIK7PIo3qzbfbuOrn3e8GA
|
||||||
|
Y6w1Tk8M8OMpbvhDQG/8XE8rifH6jgiRxFbVARv7IDHxc4zsINlWIq8j8DRv5jhj
|
||||||
|
eshDjrn7AgMBAAECggEARZxeutxE/pCypv0IqkFS7IVLccTvt2gfemcC1yzIBFOW
|
||||||
|
oqgTI3Vrq8tbdbHFq3iFDG+m4qlBi+dWDC3GDoPkVoi7dg//1TqZEOO+sqqu2Afj
|
||||||
|
pge6tIDfeMxWJifwkkpWRURB9hCknhUSW2bMNyUCs3rgREJVTtsmM9CHnoSKXXQL
|
||||||
|
aOeYXalFVpx3ceK+xdp0VGfpsqEabBKs0yy3EDiQy2huoWce3EVFLVrwx/IkhcsZ
|
||||||
|
JlI5LPpoiTglSs1g9i88JHS2slBtKtb1lWl/yXHhK1g7s34c6f9jP8snuFE5ddMn
|
||||||
|
0L4GDA9teaPGvB533eb2RIFy2kUYgpr5c03G6rpoOQKBgQDpY6BFJkPGENnC5Bdb
|
||||||
|
fJCuN2nyRdC1qvv6ESFaQYb0s6QjKDqpb0dUSYN3+zNgtiAysbQLeU/d9mmt4UR8
|
||||||
|
ohjRkOySU0eQ/YNFokjw6g6GPoiMHJJ9cP75NA94uIMIUTY7uHEWWZwXI5UphdPC
|
||||||
|
p5/3MaF1VlYQys9a5wtiEaDSfQKBgQDOwPV0zQjUabkVQ4yV0amP8xybvHH8ghG0
|
||||||
|
RMStHg96RfDmg35JQaw22A2xiVROCoZgLqiE1DFSl/3gBF/vfqBh/uzdxwNerJC6
|
||||||
|
ROdCxyS4rys5d/02P4aNOa73sD+ZKyEZRTF1v3bmOGKidRFF5oxIpuHjFWlJFKx1
|
||||||
|
O/b3AI0v1wKBgQC/L4N84emm+OrKAfs4UIRckrxRYOulxhmAMkQ2IXOiRP5yZmQX
|
||||||
|
pDa0TzxJLxhZYxhhLr0koQ3R8CeF7wEhb9AQ7D0/aMU5etLsWhKSd8nKIrPMwyMl
|
||||||
|
a0kTb5g09kEwsQZSSbcp7eI1+koYp65eyN37q0ZuTnlWbC0MdDQY9APgKQKBgQCb
|
||||||
|
HqaKNXLUe2XDkGSf2ygOumXSanZS7vt9dsLg59bQ9DyjljBfogglNcBAXTqFOtxK
|
||||||
|
uXbyAYnn3+U399BKjYSjQXJRioj6tRn4xs2DiooAjlwtx9qQouS+fHLLns54iqVQ
|
||||||
|
oltTbo00eUV3gcGt4iWKNLrxdxUBIaOqaY0HEMDdDQKBgQCRvcHDF7JSPuBiO3Tw
|
||||||
|
PSOUD4q6dD/dhI+X2ZKg83w94SZXXms6eMSbedUkLoJ8TDunmdRUUWb6rgP/pJwr
|
||||||
|
zKRTskItF15i9IWCwC6jBrSfx5n2JcSoBALyc0aR9heF0GQjWwqURd+PC/msomrW
|
||||||
|
z9SCl8mpQVFtBlui7PcnDLTFAg==
|
||||||
|
-----END PRIVATE KEY-----
|
||||||
1
test/self-signed-ssl/index.html
Normal file
1
test/self-signed-ssl/index.html
Normal file
|
|
@ -0,0 +1 @@
|
||||||
|
SSL test works
|
||||||
925
test/test-lib-openshift.sh
Normal file
925
test/test-lib-openshift.sh
Normal file
|
|
@ -0,0 +1,925 @@
|
||||||
|
# Set of functions for testing docker images in OpenShift using 'oc' command
|
||||||
|
|
||||||
|
# ct_os_get_status
|
||||||
|
# --------------------
|
||||||
|
# Returns status of all objects to make debugging easier.
|
||||||
|
function ct_os_get_status() {
|
||||||
|
oc get all
|
||||||
|
oc status
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_print_logs
|
||||||
|
# --------------------
|
||||||
|
# Returns status of all objects and logs from all pods.
|
||||||
|
function ct_os_print_logs() {
|
||||||
|
ct_os_get_status
|
||||||
|
while read pod_name; do
|
||||||
|
echo "INFO: printing logs for pod ${pod_name}"
|
||||||
|
oc logs ${pod_name}
|
||||||
|
done < <(oc get pods --no-headers=true -o custom-columns=NAME:.metadata.name)
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_enable_print_logs
|
||||||
|
# --------------------
|
||||||
|
# Enables automatic printing of pod logs on ERR.
|
||||||
|
function ct_os_enable_print_logs() {
|
||||||
|
set -E
|
||||||
|
trap ct_os_print_logs ERR
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_get_public_ip
|
||||||
|
# --------------------
|
||||||
|
# Returns best guess for the IP that the node is accessible from other computers.
|
||||||
|
# This is a bit funny heuristic, simply goes through all IPv4 addresses that
|
||||||
|
# hostname -I returns and de-prioritizes IP addresses commonly used for local
|
||||||
|
# addressing. The rest of addresses are taken as public with higher probability.
|
||||||
|
function ct_get_public_ip() {
|
||||||
|
local hostnames=$(hostname -I)
|
||||||
|
local public_ip=''
|
||||||
|
local found_ip
|
||||||
|
for guess_exp in '127\.0\.0\.1' '192\.168\.[0-9\.]*' '172\.[0-9\.]*' \
|
||||||
|
'10\.[0-9\.]*' '[0-9\.]*' ; do
|
||||||
|
found_ip=$(echo "${hostnames}" | grep -oe "${guess_exp}")
|
||||||
|
if [ -n "${found_ip}" ] ; then
|
||||||
|
hostnames=$(echo "${hostnames}" | sed -e "s/${found_ip}//")
|
||||||
|
public_ip="${found_ip}"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
if [ -z "${public_ip}" ] ; then
|
||||||
|
echo "ERROR: public IP could not be guessed." >&2
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
echo "${public_ip}"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_run_in_pod POD_NAME CMD
|
||||||
|
# --------------------
|
||||||
|
# Runs [cmd] in the pod specified by prefix [pod_prefix].
|
||||||
|
# Arguments: pod_name - full name of the pod
|
||||||
|
# Arguments: cmd - command to be run in the pod
|
||||||
|
function ct_os_run_in_pod() {
|
||||||
|
local pod_name="$1" ; shift
|
||||||
|
|
||||||
|
oc exec "$pod_name" -- "$@"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_get_service_ip SERVICE_NAME
|
||||||
|
# --------------------
|
||||||
|
# Returns IP of the service specified by [service_name].
|
||||||
|
# Arguments: service_name - name of the service
|
||||||
|
function ct_os_get_service_ip() {
|
||||||
|
local service_name="${1}" ; shift
|
||||||
|
oc get "svc/${service_name}" -o yaml | grep clusterIP | \
|
||||||
|
cut -d':' -f2 | grep -oe '172\.30\.[0-9\.]*'
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
# ct_os_get_all_pods_status
|
||||||
|
# --------------------
|
||||||
|
# Returns status of all pods.
|
||||||
|
function ct_os_get_all_pods_status() {
|
||||||
|
oc get pods -o custom-columns=Ready:status.containerStatuses[0].ready,NAME:.metadata.name
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_get_all_pods_name
|
||||||
|
# --------------------
|
||||||
|
# Returns the full name of all pods.
|
||||||
|
function ct_os_get_all_pods_name() {
|
||||||
|
oc get pods --no-headers -o custom-columns=NAME:.metadata.name
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_get_pod_status POD_PREFIX
|
||||||
|
# --------------------
|
||||||
|
# Returns status of the pod specified by prefix [pod_prefix].
|
||||||
|
# Note: Ignores -build and -deploy pods
|
||||||
|
# Arguments: pod_prefix - prefix or whole ID of the pod
|
||||||
|
function ct_os_get_pod_status() {
|
||||||
|
local pod_prefix="${1}" ; shift
|
||||||
|
ct_os_get_all_pods_status | grep -e "${pod_prefix}" | grep -Ev "(build|deploy)$" \
|
||||||
|
| awk '{print $1}' | head -n 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_get_pod_name POD_PREFIX
|
||||||
|
# --------------------
|
||||||
|
# Returns the full name of pods specified by prefix [pod_prefix].
|
||||||
|
# Note: Ignores -build and -deploy pods
|
||||||
|
# Arguments: pod_prefix - prefix or whole ID of the pod
|
||||||
|
function ct_os_get_pod_name() {
|
||||||
|
local pod_prefix="${1}" ; shift
|
||||||
|
ct_os_get_all_pods_name | grep -e "^${pod_prefix}" | grep -Ev "(build|deploy)$"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_get_pod_ip POD_NAME
|
||||||
|
# --------------------
|
||||||
|
# Returns the ip of the pod specified by [pod_name].
|
||||||
|
# Arguments: pod_name - full name of the pod
|
||||||
|
function ct_os_get_pod_ip() {
|
||||||
|
local pod_name="${1}"
|
||||||
|
oc get pod "$pod_name" --no-headers -o custom-columns=IP:status.podIP
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_check_pod_readiness POD_PREFIX STATUS
|
||||||
|
# --------------------
|
||||||
|
# Checks whether the pod is ready.
|
||||||
|
# Arguments: pod_prefix - prefix or whole ID of the pod
|
||||||
|
# Arguments: status - expected status (true, false)
|
||||||
|
function ct_os_check_pod_readiness() {
|
||||||
|
local pod_prefix="${1}" ; shift
|
||||||
|
local status="${1}" ; shift
|
||||||
|
test "$(ct_os_get_pod_status ${pod_prefix})" == "${status}"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_wait_pod_ready POD_PREFIX TIMEOUT
|
||||||
|
# --------------------
|
||||||
|
# Wait maximum [timeout] for the pod becomming ready.
|
||||||
|
# Arguments: pod_prefix - prefix or whole ID of the pod
|
||||||
|
# Arguments: timeout - how many seconds to wait seconds
|
||||||
|
function ct_os_wait_pod_ready() {
|
||||||
|
local pod_prefix="${1}" ; shift
|
||||||
|
local timeout="${1}" ; shift
|
||||||
|
SECONDS=0
|
||||||
|
echo -n "Waiting for ${pod_prefix} pod becoming ready ..."
|
||||||
|
while ! ct_os_check_pod_readiness "${pod_prefix}" "true" ; do
|
||||||
|
echo -n "."
|
||||||
|
[ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1
|
||||||
|
sleep 3
|
||||||
|
done
|
||||||
|
echo " DONE"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_wait_rc_ready POD_PREFIX TIMEOUT
|
||||||
|
# --------------------
|
||||||
|
# Wait maximum [timeout] for the rc having desired number of replicas ready.
|
||||||
|
# Arguments: pod_prefix - prefix of the replication controller
|
||||||
|
# Arguments: timeout - how many seconds to wait seconds
|
||||||
|
function ct_os_wait_rc_ready() {
|
||||||
|
local pod_prefix="${1}" ; shift
|
||||||
|
local timeout="${1}" ; shift
|
||||||
|
SECONDS=0
|
||||||
|
echo -n "Waiting for ${pod_prefix} pod becoming ready ..."
|
||||||
|
while ! test "$((oc get --no-headers statefulsets; oc get --no-headers rc) 2>/dev/null \
|
||||||
|
| grep "^${pod_prefix}" | awk '$2==$3 {print "ready"}')" == "ready" ; do
|
||||||
|
echo -n "."
|
||||||
|
[ ${SECONDS} -gt ${timeout} ] && echo " FAIL" && return 1
|
||||||
|
sleep 3
|
||||||
|
done
|
||||||
|
echo " DONE"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_deploy_pure_image IMAGE [ENV_PARAMS, ...]
|
||||||
|
# --------------------
|
||||||
|
# Runs [image] in the openshift and optionally specifies env_params
|
||||||
|
# as environment variables to the image.
|
||||||
|
# Arguments: image - prefix or whole ID of the pod to run the cmd in
|
||||||
|
# Arguments: env_params - environment variables parameters for the images.
|
||||||
|
function ct_os_deploy_pure_image() {
|
||||||
|
local image="${1}" ; shift
|
||||||
|
# ignore error exit code, because oc new-app returns error when image exists
|
||||||
|
oc new-app ${image} "$@" || :
|
||||||
|
# let openshift cluster to sync to avoid some race condition errors
|
||||||
|
sleep 3
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_deploy_s2i_image IMAGE APP [ENV_PARAMS, ... ]
|
||||||
|
# --------------------
|
||||||
|
# Runs [image] and [app] in the openshift and optionally specifies env_params
|
||||||
|
# as environment variables to the image.
|
||||||
|
# Arguments: image - prefix or whole ID of the pod to run the cmd in
|
||||||
|
# Arguments: app - url or local path to git repo with the application sources.
|
||||||
|
# Arguments: env_params - environment variables parameters for the images.
|
||||||
|
function ct_os_deploy_s2i_image() {
|
||||||
|
local image="${1}" ; shift
|
||||||
|
local app="${1}" ; shift
|
||||||
|
# ignore error exit code, because oc new-app returns error when image exists
|
||||||
|
oc new-app "${image}~${app}" "$@" || :
|
||||||
|
|
||||||
|
# let openshift cluster to sync to avoid some race condition errors
|
||||||
|
sleep 3
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_deploy_template_image TEMPLATE [ENV_PARAMS, ...]
|
||||||
|
# --------------------
|
||||||
|
# Runs template in the openshift and optionally gives env_params to use
|
||||||
|
# specific values in the template.
|
||||||
|
# Arguments: template - prefix or whole ID of the pod to run the cmd in
|
||||||
|
# Arguments: env_params - environment variables parameters for the template.
|
||||||
|
# Example usage: ct_os_deploy_template_image mariadb-ephemeral-template.yaml \
|
||||||
|
# DATABASE_SERVICE_NAME=mysql-57-centos7 \
|
||||||
|
# DATABASE_IMAGE=mysql-57-centos7 \
|
||||||
|
# MYSQL_USER=testu \
|
||||||
|
# MYSQL_PASSWORD=testp \
|
||||||
|
# MYSQL_DATABASE=testdb
|
||||||
|
function ct_os_deploy_template_image() {
|
||||||
|
local template="${1}" ; shift
|
||||||
|
oc process -f "${template}" "$@" | oc create -f -
|
||||||
|
# let openshift cluster to sync to avoid some race condition errors
|
||||||
|
sleep 3
|
||||||
|
}
|
||||||
|
|
||||||
|
# _ct_os_get_uniq_project_name
|
||||||
|
# --------------------
|
||||||
|
# Returns a uniq name of the OpenShift project.
|
||||||
|
function _ct_os_get_uniq_project_name() {
|
||||||
|
local r
|
||||||
|
while true ; do
|
||||||
|
r=${RANDOM}
|
||||||
|
mkdir /var/tmp/sclorg-test-${r} &>/dev/null && echo sclorg-test-${r} && break
|
||||||
|
done
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_new_project [PROJECT]
|
||||||
|
# --------------------
|
||||||
|
# Creates a new project in the openshfit using 'os' command.
|
||||||
|
# Arguments: project - project name, uses a new random name if omitted
|
||||||
|
# Expects 'os' command that is properly logged in to the OpenShift cluster.
|
||||||
|
# Not using mktemp, because we cannot use uppercase characters.
|
||||||
|
function ct_os_new_project() {
|
||||||
|
if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then
|
||||||
|
echo "Creating project skipped."
|
||||||
|
return
|
||||||
|
fi
|
||||||
|
local project_name="${1:-$(_ct_os_get_uniq_project_name)}" ; shift || :
|
||||||
|
oc new-project ${project_name}
|
||||||
|
# let openshift cluster to sync to avoid some race condition errors
|
||||||
|
sleep 3
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_delete_project [PROJECT]
|
||||||
|
# --------------------
|
||||||
|
# Deletes the specified project in the openshfit
|
||||||
|
# Arguments: project - project name, uses the current project if omitted
|
||||||
|
function ct_os_delete_project() {
|
||||||
|
if [ "${CT_SKIP_NEW_PROJECT:-false}" == 'true' ] ; then
|
||||||
|
echo "Deleting project skipped, cleaning objects only."
|
||||||
|
ct_delete_all_objects
|
||||||
|
return
|
||||||
|
fi
|
||||||
|
local project_name="${1:-$(oc project -q)}" ; shift || :
|
||||||
|
oc delete project "${project_name}"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_delete_all_objects
|
||||||
|
# -----------------
|
||||||
|
# Deletes all objects within the project.
|
||||||
|
# Handy when we have one project and want to run more tests.
|
||||||
|
function ct_delete_all_objects() {
|
||||||
|
for x in bc builds dc is isimage istag po pv pvc rc routes secrets svc ; do
|
||||||
|
oc delete $x --all
|
||||||
|
done
|
||||||
|
# for some objects it takes longer to be really deleted, so a dummy sleep
|
||||||
|
# to avoid some races when other test can see not-yet-deleted objects and can fail
|
||||||
|
sleep 10
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_docker_login
|
||||||
|
# --------------------
|
||||||
|
# Logs in into docker daemon
|
||||||
|
# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address.
|
||||||
|
# Does not do anything if REGISTRY_ADDRESS is set.
|
||||||
|
function ct_os_docker_login() {
|
||||||
|
[ -n "${REGISTRY_ADDRESS:-}" ] && "REGISTRY_ADDRESS set, not trying to docker login." && return 0
|
||||||
|
# docker login fails with "404 page not found" error sometimes, just try it more times
|
||||||
|
for i in `seq 12` ; do
|
||||||
|
docker login -u developer -p $(oc whoami -t) ${REGISRTY_ADDRESS:-172.30.1.1:5000} && return 0 || :
|
||||||
|
sleep 5
|
||||||
|
done
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_upload_image IMAGE [IMAGESTREAM]
|
||||||
|
# --------------------
|
||||||
|
# Uploads image from local registry to the OpenShift internal registry.
|
||||||
|
# Arguments: image - image name to upload
|
||||||
|
# Arguments: imagestream - name and tag to use for the internal registry.
|
||||||
|
# In the format of name:tag ($image_name:latest by default)
|
||||||
|
# Uses global REGISRTY_ADDRESS environment variable for arbitrary registry address.
|
||||||
|
function ct_os_upload_image() {
|
||||||
|
local input_name="${1}" ; shift
|
||||||
|
local image_name=${input_name##*/}
|
||||||
|
local imagestream=${1:-$image_name:latest}
|
||||||
|
local output_name="${REGISRTY_ADDRESS:-172.30.1.1:5000}/$(oc project -q)/$imagestream"
|
||||||
|
|
||||||
|
ct_os_docker_login
|
||||||
|
docker tag ${input_name} ${output_name}
|
||||||
|
docker push ${output_name}
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_install_in_centos
|
||||||
|
# --------------------
|
||||||
|
# Installs os cluster in CentOS
|
||||||
|
function ct_os_install_in_centos() {
|
||||||
|
yum install -y centos-release-openshift-origin
|
||||||
|
yum install -y wget git net-tools bind-utils iptables-services bridge-utils\
|
||||||
|
bash-completion origin-clients docker origin-clients
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_cluster_up [DIR, IS_PUBLIC, CLUSTER_VERSION]
|
||||||
|
# --------------------
|
||||||
|
# Runs the local OpenShift cluster using 'oc cluster up' and logs in as developer.
|
||||||
|
# Arguments: dir - directory to keep configuration data in, random if omitted
|
||||||
|
# Arguments: is_public - sets either private or public hostname for web-UI,
|
||||||
|
# use "true" for allow remote access to the web-UI,
|
||||||
|
# "false" is default
|
||||||
|
# Arguments: cluster_version - version of the OpenShift cluster to use, empty
|
||||||
|
# means default version of `oc`; example value: 3.7;
|
||||||
|
# also can be specified outside by OC_CLUSTER_VERSION
|
||||||
|
function ct_os_cluster_up() {
|
||||||
|
ct_os_cluster_running && echo "Cluster already running. Nothing is done." && return 0
|
||||||
|
ct_os_logged_in && echo "Already logged in to a cluster. Nothing is done." && return 0
|
||||||
|
|
||||||
|
mkdir -p /var/tmp/openshift
|
||||||
|
local dir="${1:-$(mktemp -d /var/tmp/openshift/os-data-XXXXXX)}" ; shift || :
|
||||||
|
local is_public="${1:-'false'}" ; shift || :
|
||||||
|
local default_cluster_version=${OC_CLUSTER_VERSION:-}
|
||||||
|
local cluster_version=${1:-${default_cluster_version}} ; shift || :
|
||||||
|
if ! grep -qe '--insecure-registry.*172\.30\.0\.0' /etc/sysconfig/docker ; then
|
||||||
|
sed -i "s|OPTIONS='|OPTIONS='--insecure-registry 172.30.0.0/16 |" /etc/sysconfig/docker
|
||||||
|
fi
|
||||||
|
|
||||||
|
systemctl stop firewalld || :
|
||||||
|
setenforce 0
|
||||||
|
iptables -F
|
||||||
|
|
||||||
|
systemctl restart docker
|
||||||
|
local cluster_ip="127.0.0.1"
|
||||||
|
[ "${is_public}" == "true" ] && cluster_ip=$(ct_get_public_ip)
|
||||||
|
|
||||||
|
if [ -n "${cluster_version}" ] ; then
|
||||||
|
# if $cluster_version is not set, we simply use oc that is available
|
||||||
|
ct_os_set_path_oc "${cluster_version}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
mkdir -p ${dir}/{config,data,pv}
|
||||||
|
case $(oc version| head -n 1) in
|
||||||
|
"oc v3.1"?.*)
|
||||||
|
oc cluster up --base-dir="${dir}/data" --public-hostname="${cluster_ip}"
|
||||||
|
;;
|
||||||
|
"oc v3."*)
|
||||||
|
oc cluster up --host-data-dir="${dir}/data" --host-config-dir="${dir}/config" \
|
||||||
|
--host-pv-dir="${dir}/pv" --use-existing-config --public-hostname="${cluster_ip}"
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
echo "ERROR: Unexpected oc version." >&2
|
||||||
|
return 1
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
oc version
|
||||||
|
oc login -u system:admin
|
||||||
|
oc project default
|
||||||
|
ct_os_wait_rc_ready docker-registry 180
|
||||||
|
ct_os_wait_rc_ready router 30
|
||||||
|
oc login -u developer -p developer
|
||||||
|
# let openshift cluster to sync to avoid some race condition errors
|
||||||
|
sleep 3
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_cluster_down
|
||||||
|
# --------------------
|
||||||
|
# Shuts down the local OpenShift cluster using 'oc cluster down'
|
||||||
|
function ct_os_cluster_down() {
|
||||||
|
oc cluster down
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_cluster_running
|
||||||
|
# --------------------
|
||||||
|
# Returns 0 if oc cluster is running
|
||||||
|
function ct_os_cluster_running() {
|
||||||
|
oc cluster status &>/dev/null
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_logged_in
|
||||||
|
# ---------------
|
||||||
|
# Returns 0 if logged in to a cluster (remote or local)
|
||||||
|
function ct_os_logged_in() {
|
||||||
|
oc whoami >/dev/null
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_set_path_oc OC_VERSION
|
||||||
|
# --------------------
|
||||||
|
# This is a trick that helps using correct version of the `oc`:
|
||||||
|
# The input is version of the openshift in format v3.6.0 etc.
|
||||||
|
# If the currently available version of oc is not of this version,
|
||||||
|
# it first takes a look into /usr/local/oc-<ver>/bin directory,
|
||||||
|
# and if not found there it downloads the community release from github.
|
||||||
|
# In the end the PATH variable is changed, so the other tests can still use just 'oc'.
|
||||||
|
# Arguments: oc_version - X.Y part of the version of OSE (e.g. 3.9)
|
||||||
|
function ct_os_set_path_oc() {
|
||||||
|
local oc_version=$(ct_os_get_latest_ver $1)
|
||||||
|
local oc_path
|
||||||
|
|
||||||
|
if oc version | grep -q "oc ${oc_version%.*}." ; then
|
||||||
|
echo "Binary oc found already available in version ${oc_version}: `which oc` Doing noting."
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# first check whether we already have oc available in /usr/local
|
||||||
|
local installed_oc_path="/usr/local/oc-${oc_version%.*}/bin"
|
||||||
|
|
||||||
|
if [ -x "${installed_oc_path}/oc" ] ; then
|
||||||
|
oc_path="${installed_oc_path}"
|
||||||
|
echo "Binary oc found in ${installed_oc_path}" >&2
|
||||||
|
else
|
||||||
|
# oc not available in /usr/local, try to download it from github (community release)
|
||||||
|
oc_path="/tmp/oc-${oc_version}-bin"
|
||||||
|
ct_os_download_upstream_oc "${oc_version}" "${oc_path}"
|
||||||
|
fi
|
||||||
|
if [ -z "${oc_path}/oc" ] ; then
|
||||||
|
echo "ERROR: oc not found installed, nor downloaded" >&1
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
export PATH="${oc_path}:${PATH}"
|
||||||
|
if ! oc version | grep -q "oc ${oc_version%.*}." ; then
|
||||||
|
echo "ERROR: something went wrong, oc located at ${oc_path}, but oc of version ${oc_version} not found in PATH ($PATH)" >&1
|
||||||
|
return 1
|
||||||
|
else
|
||||||
|
echo "PATH set correctly, binary oc found in version ${oc_version}: `which oc`"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_get_latest_ver VERSION_PART_X
|
||||||
|
# --------------------
|
||||||
|
# Returns full version (vX.Y.Z) from part of the version (X.Y)
|
||||||
|
# Arguments: vxy - X.Y part of the version
|
||||||
|
# Returns vX.Y.Z variant of the version
|
||||||
|
function ct_os_get_latest_ver(){
|
||||||
|
local vxy="v$1"
|
||||||
|
for vz in {3..0} ; do
|
||||||
|
curl -sif "https://github.com/openshift/origin/releases/tag/${vxy}.${vz}" >/dev/null && echo "${vxy}.${vz}" && return 0
|
||||||
|
done
|
||||||
|
echo "ERROR: version ${vxy} not found in https://github.com/openshift/origin/tags" >&2
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_download_upstream_oc OC_VERSION OUTPUT_DIR
|
||||||
|
# --------------------
|
||||||
|
# Downloads a particular version of openshift-origin-client-tools from
|
||||||
|
# github into specified output directory
|
||||||
|
# Arguments: oc_version - version of OSE (e.g. v3.7.2)
|
||||||
|
# Arguments: output_dir - output directory
|
||||||
|
function ct_os_download_upstream_oc() {
|
||||||
|
local oc_version=$1
|
||||||
|
local output_dir=$2
|
||||||
|
|
||||||
|
# check whether we already have the binary in place
|
||||||
|
[ -x "${output_dir}/oc" ] && return 0
|
||||||
|
|
||||||
|
mkdir -p "${output_dir}"
|
||||||
|
# using html output instead of https://api.github.com/repos/openshift/origin/releases/tags/${oc_version},
|
||||||
|
# because API is limited for number of queries if not authenticated
|
||||||
|
tarball=$(curl -si "https://github.com/openshift/origin/releases/tag/${oc_version}" | grep -o -e "openshift-origin-client-tools-${oc_version}-[a-f0-9]*-linux-64bit.tar.gz" | head -n 1)
|
||||||
|
|
||||||
|
# download, unpack the binaries and then put them into output directory
|
||||||
|
echo "Downloading https://github.com/openshift/origin/releases/download/${oc_version}/${tarball} into ${output_dir}/" >&2
|
||||||
|
curl -sL https://github.com/openshift/origin/releases/download/${oc_version}/"${tarball}" | tar -C "${output_dir}" -xz
|
||||||
|
mv -f "${output_dir}"/"${tarball%.tar.gz}"/* "${output_dir}/"
|
||||||
|
|
||||||
|
rmdir "${output_dir}"/"${tarball%.tar.gz}"
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
# ct_os_test_s2i_app_func IMAGE APP CONTEXT_DIR CHECK_CMD [OC_ARGS]
|
||||||
|
# --------------------
|
||||||
|
# Runs [image] and [app] in the openshift and optionally specifies env_params
|
||||||
|
# as environment variables to the image. Then check the container by arbitrary
|
||||||
|
# function given as argument (such an argument may include <IP> string,
|
||||||
|
# that will be replaced with actual IP).
|
||||||
|
# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory)
|
||||||
|
# Arguments: app - url or local path to git repo with the application sources (compulsory)
|
||||||
|
# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory)
|
||||||
|
# Arguments: check_command - CMD line that checks whether the container works (compulsory; '<IP>' will be replaced with actual IP)
|
||||||
|
# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app`
|
||||||
|
# command, typically environment variables (optional)
|
||||||
|
function ct_os_test_s2i_app_func() {
|
||||||
|
local image_name=${1}
|
||||||
|
local app=${2}
|
||||||
|
local context_dir=${3}
|
||||||
|
local check_command=${4}
|
||||||
|
local oc_args=${5:-}
|
||||||
|
local import_image=${6:-}
|
||||||
|
local image_name_no_namespace=${image_name##*/}
|
||||||
|
local service_name="${image_name_no_namespace}-testing"
|
||||||
|
local image_tagged="${image_name_no_namespace}:${VERSION}"
|
||||||
|
|
||||||
|
if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then
|
||||||
|
echo "ERROR: ct_os_test_s2i_app_func() requires at least 4 arguments that cannot be emtpy." >&2
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
ct_os_new_project
|
||||||
|
# Create a specific imagestream tag for the image so that oc cannot use anything else
|
||||||
|
if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then
|
||||||
|
if [ -n "${import_image}" ] ; then
|
||||||
|
echo "Importing image ${import_image} as ${image_name}:${VERSION}"
|
||||||
|
oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm
|
||||||
|
else
|
||||||
|
echo "Uploading and importing image skipped."
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
if [ -n "${import_image}" ] ; then
|
||||||
|
echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead."
|
||||||
|
fi
|
||||||
|
ct_os_upload_image "${image_name}" "${image_tagged}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
local app_param="${app}"
|
||||||
|
if [ -d "${app}" ] ; then
|
||||||
|
# for local directory, we need to copy the content, otherwise too smart os command
|
||||||
|
# pulls the git remote repository instead
|
||||||
|
app_param=$(ct_obtain_input "${app}")
|
||||||
|
fi
|
||||||
|
|
||||||
|
ct_os_deploy_s2i_image "${image_tagged}" "${app_param}" \
|
||||||
|
--context-dir="${context_dir}" \
|
||||||
|
--name "${service_name}" \
|
||||||
|
${oc_args}
|
||||||
|
|
||||||
|
if [ -d "${app}" ] ; then
|
||||||
|
# in order to avoid weird race seen sometimes, let's wait shortly
|
||||||
|
# before starting the build explicitly
|
||||||
|
sleep 5
|
||||||
|
oc start-build "${service_name}" --from-dir="${app_param}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
ct_os_wait_pod_ready "${service_name}" 300
|
||||||
|
|
||||||
|
local ip=$(ct_os_get_service_ip "${service_name}")
|
||||||
|
local check_command_exp=$(echo "$check_command" | sed -e "s/<IP>/$ip/g")
|
||||||
|
|
||||||
|
echo " Checking APP using $check_command_exp ..."
|
||||||
|
local result=0
|
||||||
|
eval "$check_command_exp" || result=1
|
||||||
|
|
||||||
|
if [ $result -eq 0 ] ; then
|
||||||
|
echo " Check passed."
|
||||||
|
else
|
||||||
|
echo " Check failed."
|
||||||
|
fi
|
||||||
|
|
||||||
|
ct_os_delete_project
|
||||||
|
return $result
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_test_s2i_app IMAGE APP CONTEXT_DIR EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ]
|
||||||
|
# --------------------
|
||||||
|
# Runs [image] and [app] in the openshift and optionally specifies env_params
|
||||||
|
# as environment variables to the image. Then check the http response.
|
||||||
|
# Arguments: image - prefix or whole ID of the pod to run the cmd in (compulsory)
|
||||||
|
# Arguments: app - url or local path to git repo with the application sources (compulsory)
|
||||||
|
# Arguments: context_dir - sub-directory inside the repository with the application sources (compulsory)
|
||||||
|
# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory)
|
||||||
|
# Arguments: port - which port to use (optional; default: 8080)
|
||||||
|
# Arguments: protocol - which protocol to use (optional; default: http)
|
||||||
|
# Arguments: response_code - what http response code to expect (optional; default: 200)
|
||||||
|
# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app`
|
||||||
|
# command, typically environment variables (optional)
|
||||||
|
function ct_os_test_s2i_app() {
|
||||||
|
local image_name=${1}
|
||||||
|
local app=${2}
|
||||||
|
local context_dir=${3}
|
||||||
|
local expected_output=${4}
|
||||||
|
local port=${5:-8080}
|
||||||
|
local protocol=${6:-http}
|
||||||
|
local response_code=${7:-200}
|
||||||
|
local oc_args=${8:-}
|
||||||
|
local import_image=${9:-}
|
||||||
|
|
||||||
|
if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then
|
||||||
|
echo "ERROR: ct_os_test_s2i_app() requires at least 4 arguments that cannot be emtpy." >&2
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
ct_os_test_s2i_app_func "${image_name}" \
|
||||||
|
"${app}" \
|
||||||
|
"${context_dir}" \
|
||||||
|
"ct_os_test_response_internal '${protocol}://<IP>:${port}' '${response_code}' '${expected_output}'" \
|
||||||
|
"${oc_args}" "${import_image}"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_test_template_app_func IMAGE APP IMAGE_IN_TEMPLATE CHECK_CMD [OC_ARGS]
|
||||||
|
# --------------------
|
||||||
|
# Runs [image] and [app] in the openshift and optionally specifies env_params
|
||||||
|
# as environment variables to the image. Then check the container by arbitrary
|
||||||
|
# function given as argument (such an argument may include <IP> string,
|
||||||
|
# that will be replaced with actual IP).
|
||||||
|
# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory)
|
||||||
|
# Arguments: template - url or local path to a template to use (compulsory)
|
||||||
|
# Arguments: name_in_template - image name used in the template
|
||||||
|
# Arguments: check_command - CMD line that checks whether the container works (compulsory; '<IP>' will be replaced with actual IP)
|
||||||
|
# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app`
|
||||||
|
# command, typically environment variables (optional)
|
||||||
|
# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry,
|
||||||
|
# specify them in this parameter as "<image>|<tag>", where "<image>" is a full image name
|
||||||
|
# (including registry if needed) and "<tag>" is a tag under which the image should be available
|
||||||
|
# in the OpenShift registry.
|
||||||
|
function ct_os_test_template_app_func() {
|
||||||
|
local image_name=${1}
|
||||||
|
local template=${2}
|
||||||
|
local name_in_template=${3}
|
||||||
|
local check_command=${4}
|
||||||
|
local oc_args=${5:-}
|
||||||
|
local other_images=${6:-}
|
||||||
|
local import_image=${7:-}
|
||||||
|
|
||||||
|
if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then
|
||||||
|
echo "ERROR: ct_os_test_template_app_func() requires at least 4 arguments that cannot be emtpy." >&2
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
local service_name="${name_in_template}-testing"
|
||||||
|
local image_tagged="${name_in_template}:${VERSION}"
|
||||||
|
|
||||||
|
ct_os_new_project
|
||||||
|
|
||||||
|
# Create a specific imagestream tag for the image so that oc cannot use anything else
|
||||||
|
if [ "${CT_SKIP_UPLOAD_IMAGE:-false}" == 'true' ] ; then
|
||||||
|
if [ -n "${import_image}" ] ; then
|
||||||
|
echo "Importing image ${import_image} as ${image_name}:${VERSION}"
|
||||||
|
oc import-image ${image_name}:${VERSION} --from ${import_image} --confirm
|
||||||
|
else
|
||||||
|
echo "Uploading and importing image skipped."
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
if [ -n "${import_image}" ] ; then
|
||||||
|
echo "Warning: Import image ${import_image} requested, but uploading image ${image_name} instead."
|
||||||
|
fi
|
||||||
|
ct_os_upload_image "${image_name}" "${image_tagged}"
|
||||||
|
|
||||||
|
# upload also other images, that template might need (list of pairs in the format <image>|<tag>
|
||||||
|
local images_tags_a
|
||||||
|
local i_t
|
||||||
|
for i_t in ${other_images} ; do
|
||||||
|
echo "${i_t}"
|
||||||
|
IFS='|' read -ra image_tag_a <<< "${i_t}"
|
||||||
|
docker pull "${image_tag_a[0]}"
|
||||||
|
ct_os_upload_image "${image_tag_a[0]}" "${image_tag_a[1]}"
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
|
||||||
|
local local_template=$(ct_obtain_input "${template}")
|
||||||
|
local namespace=${CT_NAMESPACE:-$(oc project -q)}
|
||||||
|
oc new-app ${local_template} \
|
||||||
|
--name "${name_in_template}" \
|
||||||
|
-p NAMESPACE="${namespace}" \
|
||||||
|
${oc_args}
|
||||||
|
|
||||||
|
ct_os_wait_pod_ready "${service_name}" 300
|
||||||
|
|
||||||
|
local ip=$(ct_os_get_service_ip "${service_name}")
|
||||||
|
local check_command_exp=$(echo "$check_command" | sed -e "s/<IP>/$ip/g")
|
||||||
|
|
||||||
|
echo " Checking APP using $check_command_exp ..."
|
||||||
|
local result=0
|
||||||
|
eval "$check_command_exp" || result=1
|
||||||
|
|
||||||
|
if [ $result -eq 0 ] ; then
|
||||||
|
echo " Check passed."
|
||||||
|
else
|
||||||
|
echo " Check failed."
|
||||||
|
fi
|
||||||
|
|
||||||
|
ct_os_delete_project
|
||||||
|
return $result
|
||||||
|
}
|
||||||
|
|
||||||
|
# params:
|
||||||
|
# ct_os_test_template_app IMAGE APP IMAGE_IN_TEMPLATE EXPECTED_OUTPUT [PORT, PROTOCOL, RESPONSE_CODE, OC_ARGS, ... ]
|
||||||
|
# --------------------
|
||||||
|
# Runs [image] and [app] in the openshift and optionally specifies env_params
|
||||||
|
# as environment variables to the image. Then check the http response.
|
||||||
|
# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory)
|
||||||
|
# Arguments: template - url or local path to a template to use (compulsory)
|
||||||
|
# Arguments: name_in_template - image name used in the template
|
||||||
|
# Arguments: expected_output - PCRE regular expression that must match the response body (compulsory)
|
||||||
|
# Arguments: port - which port to use (optional; default: 8080)
|
||||||
|
# Arguments: protocol - which protocol to use (optional; default: http)
|
||||||
|
# Arguments: response_code - what http response code to expect (optional; default: 200)
|
||||||
|
# Arguments: oc_args - all other arguments are used as additional parameters for the `oc new-app`
|
||||||
|
# command, typically environment variables (optional)
|
||||||
|
# Arguments: other_images - some templates need other image to be pushed into the OpenShift registry,
|
||||||
|
# specify them in this parameter as "<image>|<tag>", where "<image>" is a full image name
|
||||||
|
# (including registry if needed) and "<tag>" is a tag under which the image should be available
|
||||||
|
# in the OpenShift registry.
|
||||||
|
function ct_os_test_template_app() {
|
||||||
|
local image_name=${1}
|
||||||
|
local template=${2}
|
||||||
|
local name_in_template=${3}
|
||||||
|
local expected_output=${4}
|
||||||
|
local port=${5:-8080}
|
||||||
|
local protocol=${6:-http}
|
||||||
|
local response_code=${7:-200}
|
||||||
|
local oc_args=${8:-}
|
||||||
|
local other_images=${9:-}
|
||||||
|
local import_image=${10:-}
|
||||||
|
|
||||||
|
if [ $# -lt 4 ] || [ -z "${1}" -o -z "${2}" -o -z "${3}" -o -z "${4}" ]; then
|
||||||
|
echo "ERROR: ct_os_test_template_app() requires at least 4 arguments that cannot be emtpy." >&2
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
ct_os_test_template_app_func "${image_name}" \
|
||||||
|
"${template}" \
|
||||||
|
"${name_in_template}" \
|
||||||
|
"ct_os_test_response_internal '${protocol}://<IP>:${port}' '${response_code}' '${expected_output}'" \
|
||||||
|
"${oc_args}" \
|
||||||
|
"${other_images}" \
|
||||||
|
"${import_image}"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_test_image_update IMAGE_NAME OLD_IMAGE ISTAG CHECK_FUNCTION OC_ARGS
|
||||||
|
# --------------------
|
||||||
|
# Runs an image update test with [image] uploaded to [is] imagestream
|
||||||
|
# and checks the services using an arbitrary function provided in [check_function].
|
||||||
|
# Arguments: image_name - prefix or whole ID of the pod to run the cmd in (compulsory)
|
||||||
|
# Arguments: old_image - valid name of the image from the registry
|
||||||
|
# Arguments: istag - imagestream to upload the images into (compulsory)
|
||||||
|
# Arguments: check_function - command to be run to check functionality of created services (compulsory)
|
||||||
|
# Arguments: oc_args - arguments to use during oc new-app (compulsory)
|
||||||
|
ct_os_test_image_update() {
|
||||||
|
local image_name=$1; shift
|
||||||
|
local old_image=$1; shift
|
||||||
|
local istag=$1; shift
|
||||||
|
local check_function=$1; shift
|
||||||
|
local service_name=${image_name##*/}
|
||||||
|
local ip="" check_command_exp=""
|
||||||
|
|
||||||
|
echo "Running image update test for: $image_name"
|
||||||
|
ct_os_new_project
|
||||||
|
|
||||||
|
# Get current image from repository and create an imagestream
|
||||||
|
docker pull "$old_image:latest" 2>/dev/null
|
||||||
|
ct_os_upload_image "$old_image" "$istag"
|
||||||
|
|
||||||
|
# Setup example application with curent image
|
||||||
|
oc new-app "$@" --name "$service_name"
|
||||||
|
ct_os_wait_pod_ready "$service_name" 60
|
||||||
|
|
||||||
|
# Check application output
|
||||||
|
ip=$(ct_os_get_service_ip "$service_name")
|
||||||
|
check_command_exp=${check_function//<IP>/$ip}
|
||||||
|
ct_assert_cmd_success "$check_command_exp"
|
||||||
|
|
||||||
|
# Tag built image into the imagestream and wait for rebuild
|
||||||
|
ct_os_upload_image "$image_name" "$istag"
|
||||||
|
ct_os_wait_pod_ready "${service_name}-2" 60
|
||||||
|
|
||||||
|
# Check application output
|
||||||
|
ip=$(ct_os_get_service_ip "$service_name")
|
||||||
|
check_command_exp=${check_function//<IP>/$ip}
|
||||||
|
ct_assert_cmd_success "$check_command_exp"
|
||||||
|
|
||||||
|
ct_os_delete_project
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_deploy_cmd_image IMAGE_NAME
|
||||||
|
# --------------------
|
||||||
|
# Runs a special command pod, a pod that does nothing, but includes utilities for testing.
|
||||||
|
# A typical usage is a mysql pod that includes mysql commandline, that we need for testing.
|
||||||
|
# Running commands inside this command pod is done via ct_os_cmd_image_run function.
|
||||||
|
# The pod is not run again if already running.
|
||||||
|
# Arguments: image_name - image to be used as a command pod
|
||||||
|
function ct_os_deploy_cmd_image() {
|
||||||
|
local image_name=${1}
|
||||||
|
oc get pod command-app &>/dev/null && echo "command POD already running" && return 0
|
||||||
|
echo "command POD not running yet, will start one called command-app"
|
||||||
|
oc create -f - <<EOF
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: command-app
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: command-container
|
||||||
|
image: "${image_name}"
|
||||||
|
command: ["sleep"]
|
||||||
|
args: ["3h"]
|
||||||
|
restartPolicy: OnFailure
|
||||||
|
EOF
|
||||||
|
|
||||||
|
SECONDS=0
|
||||||
|
echo -n "Waiting for command POD ."
|
||||||
|
while [ $SECONDS -lt 180 ] ; do
|
||||||
|
sout="$(ct_os_cmd_image_run 'echo $((11*11))')"
|
||||||
|
grep -q '^121$' <<< "$sout" && echo "DONE" && return 0 || :
|
||||||
|
sleep 3
|
||||||
|
echo -n "."
|
||||||
|
done
|
||||||
|
echo "FAIL"
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_cmd_image_run CMD [ ARG ... ]
|
||||||
|
# --------------------
|
||||||
|
# Runs a command CMD inside a special command pod
|
||||||
|
# Arguments: cmd - shell command with args to run in a pod
|
||||||
|
function ct_os_cmd_image_run() {
|
||||||
|
oc exec command-app -- bash -c "$@"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_test_response_internal
|
||||||
|
# ----------------
|
||||||
|
# Perform GET request to the application container, checks output with
|
||||||
|
# a reg-exp and HTTP response code.
|
||||||
|
# That all is done inside an image in the cluster, so the function is used
|
||||||
|
# typically in clusters that are not accessible outside.
|
||||||
|
# The interanal image is a python image that should include the most of the useful commands.
|
||||||
|
# The check is repeated until timeout.
|
||||||
|
# Argument: url - request URL path
|
||||||
|
# Argument: expected_code - expected HTTP response code
|
||||||
|
# Argument: body_regexp - PCRE regular expression that must match the response body
|
||||||
|
# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between
|
||||||
|
# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10)
|
||||||
|
ct_os_test_response_internal() {
|
||||||
|
local url="$1"
|
||||||
|
local expected_code="$2"
|
||||||
|
local body_regexp="$3"
|
||||||
|
local max_attempts=${4:-20}
|
||||||
|
local ignore_error_attempts=${5:-10}
|
||||||
|
|
||||||
|
: " Testing the HTTP(S) response for <${url}>"
|
||||||
|
local sleep_time=3
|
||||||
|
local attempt=1
|
||||||
|
local result=1
|
||||||
|
local status
|
||||||
|
local response_code
|
||||||
|
local response_file=$(mktemp /tmp/ct_test_response_XXXXXX)
|
||||||
|
local util_image_name='python:3.6'
|
||||||
|
|
||||||
|
ct_os_deploy_cmd_image "${util_image_name}"
|
||||||
|
|
||||||
|
while [ ${attempt} -le ${max_attempts} ]; do
|
||||||
|
ct_os_cmd_image_run "curl --connect-timeout 10 -s -w '%{http_code}' '${url}'" >${response_file} && status=0 || status=1
|
||||||
|
if [ ${status} -eq 0 ]; then
|
||||||
|
response_code=$(cat ${response_file} | tail -c 3)
|
||||||
|
if [ "${response_code}" -eq "${expected_code}" ]; then
|
||||||
|
result=0
|
||||||
|
fi
|
||||||
|
cat ${response_file} | grep -qP -e "${body_regexp}" || result=1;
|
||||||
|
# Some services return 40x code until they are ready, so let's give them
|
||||||
|
# some chance and not end with failure right away
|
||||||
|
# Do not wait if we already have expected outcome though
|
||||||
|
if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
attempt=$(( ${attempt} + 1 ))
|
||||||
|
sleep ${sleep_time}
|
||||||
|
done
|
||||||
|
rm -f ${response_file}
|
||||||
|
return ${result}
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_get_image_from_pod
|
||||||
|
# ------------------------
|
||||||
|
# Print image identifier from an existing pod to stdout
|
||||||
|
# Argument: pod_prefix - prefix or full name of the pod to get image from
|
||||||
|
ct_os_get_image_from_pod() {
|
||||||
|
local pod_prefix=$1 ; shift
|
||||||
|
local pod_name=$(ct_os_get_pod_name $pod_prefix)
|
||||||
|
oc get "po/${pod_name}" -o yaml | sed -ne 's/^\s*image:\s*\(.*\)\s*$/\1/ p' | head -1
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_os_check_cmd_internal
|
||||||
|
# ----------------
|
||||||
|
# Runs a specified command, checks exit code and compares the output with expected regexp.
|
||||||
|
# That all is done inside an image in the cluster, so the function is used
|
||||||
|
# typically in clusters that are not accessible outside.
|
||||||
|
# The check is repeated until timeout.
|
||||||
|
# Argument: util_image_name - name of the image in the cluster that is used for running the cmd
|
||||||
|
# Argument: service_name - kubernetes' service name to work with (IP address is taken from this one)
|
||||||
|
# Argument: check_command - command that is run within the util_image_name container
|
||||||
|
# Argument: expected_content_match - regexp that must be in the output (use .* to ignore check)
|
||||||
|
# Argument: timeout - number of seconds to wait till the check succeeds
|
||||||
|
function ct_os_check_cmd_internal() {
|
||||||
|
local util_image_name=$1 ; shift
|
||||||
|
local service_name=$1 ; shift
|
||||||
|
local check_command=$1 ; shift
|
||||||
|
local expected_content_match=${1:-.*} ; shift
|
||||||
|
local timeout=${1:-60} ; shift || :
|
||||||
|
|
||||||
|
: " Service ${service_name} check ..."
|
||||||
|
|
||||||
|
local output
|
||||||
|
local ret
|
||||||
|
local ip=$(ct_os_get_service_ip "${service_name}")
|
||||||
|
local check_command_exp=$(echo "$check_command" | sed -e "s/<IP>/$ip/g")
|
||||||
|
|
||||||
|
ct_os_deploy_cmd_image $(ct_os_get_image_from_pod "${util_image_name}" | head -n 1)
|
||||||
|
SECONDS=0
|
||||||
|
|
||||||
|
echo -n "Waiting for ${service_name} service becoming ready ..."
|
||||||
|
while true ; do
|
||||||
|
output=$(ct_os_cmd_image_run "$check_command_exp")
|
||||||
|
ret=$?
|
||||||
|
echo "${output}" | grep -qe "${expected_content_match}" || ret=1
|
||||||
|
if [ ${ret} -eq 0 ] ; then
|
||||||
|
echo " PASS"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
echo -n "."
|
||||||
|
[ ${SECONDS} -gt ${timeout} ] && break
|
||||||
|
sleep 3
|
||||||
|
done
|
||||||
|
echo " FAIL"
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
507
test/test-lib.sh
Normal file
507
test/test-lib.sh
Normal file
|
|
@ -0,0 +1,507 @@
|
||||||
|
#
|
||||||
|
# Test a container image.
|
||||||
|
#
|
||||||
|
# Always use sourced from a specific container testfile
|
||||||
|
#
|
||||||
|
# reguires definition of CID_FILE_DIR
|
||||||
|
# CID_FILE_DIR=$(mktemp --suffix=<container>_test_cidfiles -d)
|
||||||
|
# reguires definition of TEST_LIST
|
||||||
|
# TEST_LIST="\
|
||||||
|
# ctest_container_creation
|
||||||
|
# ctest_doc_content"
|
||||||
|
|
||||||
|
# Container CI tests
|
||||||
|
# abbreviated as "ct"
|
||||||
|
|
||||||
|
# may be redefined in the specific container testfile
|
||||||
|
EXPECTED_EXIT_CODE=0
|
||||||
|
|
||||||
|
# ct_cleanup
|
||||||
|
# --------------------
|
||||||
|
# Cleans up containers used during tests. Stops and removes all containers
|
||||||
|
# referenced by cid_files in CID_FILE_DIR. Dumps logs if a container exited
|
||||||
|
# unexpectedly. Removes the cid_files and CID_FILE_DIR as well.
|
||||||
|
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
||||||
|
# Uses: $EXPECTED_EXIT_CODE - expected container exit code
|
||||||
|
function ct_cleanup() {
|
||||||
|
for cid_file in $CID_FILE_DIR/* ; do
|
||||||
|
local container=$(cat $cid_file)
|
||||||
|
|
||||||
|
: "Stopping and removing container $container..."
|
||||||
|
docker stop $container
|
||||||
|
exit_status=$(docker inspect -f '{{.State.ExitCode}}' $container)
|
||||||
|
if [ "$exit_status" != "$EXPECTED_EXIT_CODE" ]; then
|
||||||
|
: "Dumping logs for $container"
|
||||||
|
docker logs $container
|
||||||
|
fi
|
||||||
|
docker rm -v $container
|
||||||
|
rm $cid_file
|
||||||
|
done
|
||||||
|
rmdir $CID_FILE_DIR
|
||||||
|
: "Done."
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_enable_cleanup
|
||||||
|
# --------------------
|
||||||
|
# Enables automatic container cleanup after tests.
|
||||||
|
function ct_enable_cleanup() {
|
||||||
|
trap ct_cleanup EXIT SIGINT
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_get_cid [name]
|
||||||
|
# --------------------
|
||||||
|
# Prints container id from cid_file based on the name of the file.
|
||||||
|
# Argument: name - name of cid_file where the container id will be stored
|
||||||
|
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
||||||
|
function ct_get_cid() {
|
||||||
|
local name="$1" ; shift || return 1
|
||||||
|
echo $(cat "$CID_FILE_DIR/$name")
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_get_cip [id]
|
||||||
|
# --------------------
|
||||||
|
# Prints container ip address based on the container id.
|
||||||
|
# Argument: id - container id
|
||||||
|
function ct_get_cip() {
|
||||||
|
local id="$1" ; shift
|
||||||
|
docker inspect --format='{{.NetworkSettings.IPAddress}}' $(ct_get_cid "$id")
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_wait_for_cid [cid_file]
|
||||||
|
# --------------------
|
||||||
|
# Holds the execution until the cid_file is created. Usually run after container
|
||||||
|
# creation.
|
||||||
|
# Argument: cid_file - name of the cid_file that should be created
|
||||||
|
function ct_wait_for_cid() {
|
||||||
|
local cid_file=$1
|
||||||
|
local max_attempts=10
|
||||||
|
local sleep_time=1
|
||||||
|
local attempt=1
|
||||||
|
local result=1
|
||||||
|
while [ $attempt -le $max_attempts ]; do
|
||||||
|
[ -f $cid_file ] && [ -s $cid_file ] && return 0
|
||||||
|
: "Waiting for container start..."
|
||||||
|
attempt=$(( $attempt + 1 ))
|
||||||
|
sleep $sleep_time
|
||||||
|
done
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_assert_container_creation_fails [container_args]
|
||||||
|
# --------------------
|
||||||
|
# The invocation of docker run should fail based on invalid container_args
|
||||||
|
# passed to the function. Returns 0 when container fails to start properly.
|
||||||
|
# Argument: container_args - all arguments are passed directly to dokcer run
|
||||||
|
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
||||||
|
function ct_assert_container_creation_fails() {
|
||||||
|
local ret=0
|
||||||
|
local max_attempts=10
|
||||||
|
local attempt=1
|
||||||
|
local cid_file=assert
|
||||||
|
set +e
|
||||||
|
local old_container_args="${CONTAINER_ARGS-}"
|
||||||
|
CONTAINER_ARGS="$@"
|
||||||
|
ct_create_container $cid_file
|
||||||
|
if [ $? -eq 0 ]; then
|
||||||
|
local cid=$(ct_get_cid $cid_file)
|
||||||
|
|
||||||
|
while [ "$(docker inspect -f '{{.State.Running}}' $cid)" == "true" ] ; do
|
||||||
|
sleep 2
|
||||||
|
attempt=$(( $attempt + 1 ))
|
||||||
|
if [ $attempt -gt $max_attempts ]; then
|
||||||
|
docker stop $cid
|
||||||
|
ret=1
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
exit_status=$(docker inspect -f '{{.State.ExitCode}}' $cid)
|
||||||
|
if [ "$exit_status" == "0" ]; then
|
||||||
|
ret=1
|
||||||
|
fi
|
||||||
|
docker rm -v $cid
|
||||||
|
rm $CID_FILE_DIR/$cid_file
|
||||||
|
fi
|
||||||
|
[ ! -z $old_container_args ] && CONTAINER_ARGS="$old_container_args"
|
||||||
|
set -e
|
||||||
|
return $ret
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_create_container [name, command]
|
||||||
|
# --------------------
|
||||||
|
# Creates a container using the IMAGE_NAME and CONTAINER_ARGS variables. Also
|
||||||
|
# stores the container id to a cid_file located in the CID_FILE_DIR, and waits
|
||||||
|
# for the creation of the file.
|
||||||
|
# Argument: name - name of cid_file where the container id will be stored
|
||||||
|
# Argument: command - optional command to be executed in the container
|
||||||
|
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
||||||
|
# Uses: $CONTAINER_ARGS - optional arguments passed directly to docker run
|
||||||
|
# Uses: $IMAGE_NAME - name of the image being tested
|
||||||
|
function ct_create_container() {
|
||||||
|
local cid_file="$CID_FILE_DIR/$1" ; shift
|
||||||
|
# create container with a cidfile in a directory for cleanup
|
||||||
|
docker run --cidfile="$cid_file" -d ${CONTAINER_ARGS:-} $IMAGE_NAME "$@"
|
||||||
|
ct_wait_for_cid $cid_file || return 1
|
||||||
|
: "Created container $(cat $cid_file)"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_scl_usage_old [name, command, expected]
|
||||||
|
# --------------------
|
||||||
|
# Tests three ways of running the SCL, by looking for an expected string
|
||||||
|
# in the output of the command
|
||||||
|
# Argument: name - name of cid_file where the container id will be stored
|
||||||
|
# Argument: command - executed inside the container
|
||||||
|
# Argument: expected - string that is expected to be in the command output
|
||||||
|
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
||||||
|
# Uses: $IMAGE_NAME - name of the image being tested
|
||||||
|
function ct_scl_usage_old() {
|
||||||
|
local name="$1"
|
||||||
|
local command="$2"
|
||||||
|
local expected="$3"
|
||||||
|
local out=""
|
||||||
|
: " Testing the image SCL enable"
|
||||||
|
out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${command}")
|
||||||
|
if ! echo "${out}" | grep -q "${expected}"; then
|
||||||
|
echo "ERROR[/bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
out=$(docker exec $(ct_get_cid $name) /bin/bash -c "${command}" 2>&1)
|
||||||
|
if ! echo "${out}" | grep -q "${expected}"; then
|
||||||
|
echo "ERROR[exec /bin/bash -c "${command}"] Expected '${expected}', got '${out}'" >&2
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
out=$(docker exec $(ct_get_cid $name) /bin/sh -ic "${command}" 2>&1)
|
||||||
|
if ! echo "${out}" | grep -q "${expected}"; then
|
||||||
|
echo "ERROR[exec /bin/sh -ic "${command}"] Expected '${expected}', got '${out}'" >&2
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_doc_content_old [strings]
|
||||||
|
# --------------------
|
||||||
|
# Looks for occurence of stirngs in the documentation files and checks
|
||||||
|
# the format of the files. Files examined: help.1
|
||||||
|
# Argument: strings - strings expected to appear in the documentation
|
||||||
|
# Uses: $IMAGE_NAME - name of the image being tested
|
||||||
|
function ct_doc_content_old() {
|
||||||
|
local tmpdir=$(mktemp -d)
|
||||||
|
local f
|
||||||
|
: " Testing documentation in the container image"
|
||||||
|
# Extract the help files from the container
|
||||||
|
for f in help.1 ; do
|
||||||
|
docker run --rm ${IMAGE_NAME} /bin/bash -c "cat /${f}" >${tmpdir}/$(basename ${f})
|
||||||
|
# Check whether the files contain some important information
|
||||||
|
for term in $@ ; do
|
||||||
|
if ! cat ${tmpdir}/$(basename ${f}) | grep -F -q -e "${term}" ; then
|
||||||
|
echo "ERROR: File /${f} does not include '${term}'." >&2
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
# Check whether the files use the correct format
|
||||||
|
for term in TH PP SH ; do
|
||||||
|
if ! grep -q "^\.${term}" ${tmpdir}/help.1 ; then
|
||||||
|
echo "ERROR: /help.1 is probably not in troff or groff format, since '${term}' is missing." >&2
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
done
|
||||||
|
: " Success!"
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
# ct_npm_works
|
||||||
|
# --------------------
|
||||||
|
# Checks existance of the npm tool and runs it.
|
||||||
|
function ct_npm_works() {
|
||||||
|
local tmpdir=$(mktemp -d)
|
||||||
|
: " Testing npm in the container image"
|
||||||
|
docker run --rm ${IMAGE_NAME} /bin/bash -c "npm --version" >${tmpdir}/version
|
||||||
|
|
||||||
|
if [ $? -ne 0 ] ; then
|
||||||
|
echo "ERROR: 'npm --version' does not work inside the image ${IMAGE_NAME}." >&2
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
docker run --rm ${IMAGE_NAME} /bin/bash -c "npm install jquery && test -f node_modules/jquery/src/jquery.js"
|
||||||
|
if [ $? -ne 0 ] ; then
|
||||||
|
echo "ERROR: npm could not install jquery inside the image ${IMAGE_NAME}." >&2
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
: " Success!"
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
# ct_path_append PATH_VARNAME DIRECTORY
|
||||||
|
# -------------------------------------
|
||||||
|
# Append DIRECTORY to VARIABLE of name PATH_VARNAME, the VARIABLE must consist
|
||||||
|
# of colon-separated list of directories.
|
||||||
|
ct_path_append ()
|
||||||
|
{
|
||||||
|
if eval "test -n \"\${$1-}\""; then
|
||||||
|
eval "$1=\$2:\$$1"
|
||||||
|
else
|
||||||
|
eval "$1=\$2"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
# ct_path_foreach PATH ACTION [ARGS ...]
|
||||||
|
# --------------------------------------
|
||||||
|
# For each DIR in PATH execute ACTION (path is colon separated list of
|
||||||
|
# directories). The particular calls to ACTION will look like
|
||||||
|
# '$ ACTION directory [ARGS ...]'
|
||||||
|
ct_path_foreach ()
|
||||||
|
{
|
||||||
|
local dir dirlist action save_IFS
|
||||||
|
save_IFS=$IFS
|
||||||
|
IFS=:
|
||||||
|
dirlist=$1
|
||||||
|
action=$2
|
||||||
|
shift 2
|
||||||
|
for dir in $dirlist; do "$action" "$dir" "$@" ; done
|
||||||
|
IFS=$save_IFS
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
# ct_run_test_list
|
||||||
|
# --------------------
|
||||||
|
# Execute the tests specified by TEST_LIST
|
||||||
|
# Uses: $TEST_LIST - list of test names
|
||||||
|
function ct_run_test_list() {
|
||||||
|
for test_case in $TEST_LIST; do
|
||||||
|
: "Running test $test_case"
|
||||||
|
[ -f test/$test_case ] && source test/$test_case
|
||||||
|
[ -f ../test/$test_case ] && source ../test/$test_case
|
||||||
|
$test_case
|
||||||
|
done;
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_gen_self_signed_cert_pem
|
||||||
|
# ---------------------------
|
||||||
|
# Generates a self-signed PEM certificate pair into specified directory.
|
||||||
|
# Argument: output_dir - output directory path
|
||||||
|
# Argument: base_name - base name of the certificate files
|
||||||
|
# Resulted files will be those:
|
||||||
|
# <output_dir>/<base_name>-cert-selfsigned.pem -- public PEM cert
|
||||||
|
# <output_dir>/<base_name>-key.pem -- PEM private key
|
||||||
|
ct_gen_self_signed_cert_pem() {
|
||||||
|
local output_dir=$1 ; shift
|
||||||
|
local base_name=$1 ; shift
|
||||||
|
mkdir -p ${output_dir}
|
||||||
|
openssl req -newkey rsa:2048 -nodes -keyout ${output_dir}/${base_name}-key.pem -subj '/C=GB/ST=Berkshire/L=Newbury/O=My Server Company' > ${base_name}-req.pem
|
||||||
|
openssl req -new -x509 -nodes -key ${output_dir}/${base_name}-key.pem -batch > ${output_dir}/${base_name}-cert-selfsigned.pem
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_obtain_input FILE|DIR|URL
|
||||||
|
# --------------------
|
||||||
|
# Either copies a file or a directory to a tmp location for local copies, or
|
||||||
|
# downloads the file from remote location.
|
||||||
|
# Resulted file path is printed, so it can be later used by calling function.
|
||||||
|
# Arguments: input - local file, directory or remote URL
|
||||||
|
function ct_obtain_input() {
|
||||||
|
local input=$1
|
||||||
|
local extension="${input##*.}"
|
||||||
|
|
||||||
|
# Try to use same extension for the temporary file if possible
|
||||||
|
[[ "${extension}" =~ ^[a-z0-9]*$ ]] && extension=".${extension}" || extension=""
|
||||||
|
|
||||||
|
local output=$(mktemp "/var/tmp/test-input-XXXXXX$extension")
|
||||||
|
if [ -f "${input}" ] ; then
|
||||||
|
cp -f "${input}" "${output}"
|
||||||
|
elif [ -d "${input}" ] ; then
|
||||||
|
rm -f "${output}"
|
||||||
|
cp -r -LH "${input}" "${output}"
|
||||||
|
elif echo "${input}" | grep -qe '^http\(s\)\?://' ; then
|
||||||
|
curl "${input}" > "${output}"
|
||||||
|
else
|
||||||
|
echo "ERROR: file type not known: ${input}" >&2
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
echo "${output}"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_test_response
|
||||||
|
# ----------------
|
||||||
|
# Perform GET request to the application container, checks output with
|
||||||
|
# a reg-exp and HTTP response code.
|
||||||
|
# Argument: url - request URL path
|
||||||
|
# Argument: expected_code - expected HTTP response code
|
||||||
|
# Argument: body_regexp - PCRE regular expression that must match the response body
|
||||||
|
# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between
|
||||||
|
# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10)
|
||||||
|
ct_test_response() {
|
||||||
|
local url="$1"
|
||||||
|
local expected_code="$2"
|
||||||
|
local body_regexp="$3"
|
||||||
|
local max_attempts=${4:-20}
|
||||||
|
local ignore_error_attempts=${5:-10}
|
||||||
|
|
||||||
|
: " Testing the HTTP(S) response for <${url}>"
|
||||||
|
local sleep_time=3
|
||||||
|
local attempt=1
|
||||||
|
local result=1
|
||||||
|
local status
|
||||||
|
local response_code
|
||||||
|
local response_file=$(mktemp /tmp/ct_test_response_XXXXXX)
|
||||||
|
while [ ${attempt} -le ${max_attempts} ]; do
|
||||||
|
curl --connect-timeout 10 -s -w '%{http_code}' "${url}" >${response_file} && status=0 || status=1
|
||||||
|
if [ ${status} -eq 0 ]; then
|
||||||
|
response_code=$(cat ${response_file} | tail -c 3)
|
||||||
|
if [ "${response_code}" -eq "${expected_code}" ]; then
|
||||||
|
result=0
|
||||||
|
fi
|
||||||
|
cat ${response_file} | grep -qP -e "${body_regexp}" || result=1;
|
||||||
|
# Some services return 40x code until they are ready, so let's give them
|
||||||
|
# some chance and not end with failure right away
|
||||||
|
# Do not wait if we already have expected outcome though
|
||||||
|
if [ ${result} -eq 0 -o ${attempt} -gt ${ignore_error_attempts} -o ${attempt} -eq ${max_attempts} ] ; then
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
attempt=$(( ${attempt} + 1 ))
|
||||||
|
sleep ${sleep_time}
|
||||||
|
done
|
||||||
|
rm -f ${response_file}
|
||||||
|
return ${result}
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_registry_from_os OS
|
||||||
|
# ----------------
|
||||||
|
# Transform operating system string [os] into registry url
|
||||||
|
# Argument: OS - string containing the os version
|
||||||
|
ct_registry_from_os() {
|
||||||
|
local registry=""
|
||||||
|
case $1 in
|
||||||
|
rhel7)
|
||||||
|
registry=registry.access.redhat.com
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
registry=docker.io
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
echo "$registry"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_assert_cmd_success CMD
|
||||||
|
# ----------------
|
||||||
|
# Evaluates [cmd] and fails if it does not succeed.
|
||||||
|
# Argument: CMD - Command to be run
|
||||||
|
function ct_assert_cmd_success() {
|
||||||
|
echo "Checking '$*' for success ..."
|
||||||
|
if ! eval "$@" &>/dev/null; then
|
||||||
|
echo " FAIL"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
echo " PASS"
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_assert_cmd_failure CMD
|
||||||
|
# ----------------
|
||||||
|
# Evaluates [cmd] and fails if it succeeds.
|
||||||
|
# Argument: CMD - Command to be run
|
||||||
|
function ct_assert_cmd_failure() {
|
||||||
|
echo "Checking '$*' for failure ..."
|
||||||
|
if eval "$@" &>/dev/null; then
|
||||||
|
echo " FAIL"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
echo " PASS"
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
# ct_random_string [LENGTH=10]
|
||||||
|
# ----------------------------
|
||||||
|
# Generate pseudorandom alphanumeric string of LENGTH bytes, the
|
||||||
|
# default length is 10. The string is printed on stdout.
|
||||||
|
ct_random_string()
|
||||||
|
(
|
||||||
|
export LC_ALL=C
|
||||||
|
dd if=/dev/urandom count=1 bs=10k 2>/dev/null \
|
||||||
|
| tr -dc 'a-z0-9' \
|
||||||
|
| fold -w "${1-10}" \
|
||||||
|
| head -n 1
|
||||||
|
)
|
||||||
|
|
||||||
|
# ct_s2i_usage IMG_NAME [S2I_ARGS]
|
||||||
|
# ----------------------------
|
||||||
|
# Create a container and run the usage script inside
|
||||||
|
# Argument: IMG_NAME - name of the image to be used for the container run
|
||||||
|
# Argument: S2I_ARGS - Additional list of source-to-image arguments, currently unused.
|
||||||
|
ct_s2i_usage()
|
||||||
|
{
|
||||||
|
local img_name=$1; shift
|
||||||
|
local s2i_args="$*";
|
||||||
|
local usage_command="/usr/libexec/s2i/usage"
|
||||||
|
docker run --rm "$img_name" bash -c "$usage_command"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ct_s2i_build_as_df APP_PATH SRC_IMAGE DST_IMAGE [S2I_ARGS]
|
||||||
|
# ----------------------------
|
||||||
|
# Create a new s2i app image from local sources in a similar way as source-to-image would have used.
|
||||||
|
# Argument: APP_PATH - local path to the app sources to be used in the test
|
||||||
|
# Argument: SRC_IMAGE - image to be used as a base for the s2i build
|
||||||
|
# Argument: DST_IMAGE - image name to be used during the tagging of the s2i build result
|
||||||
|
# Argument: S2I_ARGS - Additional list of source-to-image arguments.
|
||||||
|
# Only used to check for pull-policy=never and environment variable definitions.
|
||||||
|
ct_s2i_build_as_df()
|
||||||
|
{
|
||||||
|
local app_path=$1; shift
|
||||||
|
local src_image=$1; shift
|
||||||
|
local dst_image=$1; shift
|
||||||
|
local s2i_args="$*";
|
||||||
|
local local_app=upload/src/
|
||||||
|
local local_scripts=upload/scripts/
|
||||||
|
local user_id=
|
||||||
|
local df_name=
|
||||||
|
local tmpdir=
|
||||||
|
# Use /tmp to not pollute cwd
|
||||||
|
tmpdir=$(mktemp -d)
|
||||||
|
df_name=$(mktemp -p "$tmpdir" Dockerfile.XXXX)
|
||||||
|
pushd "$tmpdir"
|
||||||
|
# Check if the image is available locally and try to pull it if it is not
|
||||||
|
docker images "$src_image" &>/dev/null || echo "$s2i_args" | grep -q "pull-policy=never" || docker pull "$src_image"
|
||||||
|
user_id=$(docker inspect -f "{{.ContainerConfig.User}}" "$src_image")
|
||||||
|
# Strip file:// from APP_PATH and copy its contents into current context
|
||||||
|
mkdir -p "$local_app"
|
||||||
|
cp -r "${app_path/file:\/\//}/." "$local_app"
|
||||||
|
[ -d "$local_app/.s2i/bin/" ] && mv "$local_app/.s2i/bin" "$local_scripts"
|
||||||
|
# Create a Dockerfile named df_name and fill it with proper content
|
||||||
|
#FIXME: Some commands could be combined into a single layer but not sure if worth the trouble for testing purposes
|
||||||
|
cat <<EOF >"$df_name"
|
||||||
|
FROM $src_image
|
||||||
|
LABEL "io.openshift.s2i.build.image"="$src_image" \\
|
||||||
|
"io.openshift.s2i.build.source-location"="$app_path"
|
||||||
|
USER root
|
||||||
|
COPY $local_app /tmp/src
|
||||||
|
EOF
|
||||||
|
[ -d "$local_scripts" ] && echo "COPY $local_scripts /tmp/scripts" >> "$df_name" &&
|
||||||
|
echo "RUN chown -R $user_id:0 /tmp/scripts" >>"$df_name"
|
||||||
|
echo "RUN chown -R $user_id:0 /tmp/src" >>"$df_name"
|
||||||
|
# Check for custom environment variables inside .s2i/ folder
|
||||||
|
if [ -e "$local_app/.s2i/environment" ]; then
|
||||||
|
# Remove any comments and add the contents as ENV commands to the Dockerfile
|
||||||
|
sed '/^\s*#.*$/d' "$local_app/.s2i/environment" | while read -r line; do
|
||||||
|
echo "ENV $line" >>"$df_name"
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
# Filter out env var definitions from $s2i_args and create Dockerfile ENV commands out of them
|
||||||
|
echo "$s2i_args" | grep -o -e '\(-e\|--env\)[[:space:]=]\S*=\S*' | sed -e 's/-e /ENV /' -e 's/--env[ =]/ENV /' >>"$df_name"
|
||||||
|
echo "USER $user_id" >>"$df_name"
|
||||||
|
# If exists, run the custom assemble script, else default to /usr/libexec/s2i/assemble
|
||||||
|
if [ -x "$local_scripts/assemble" ]; then
|
||||||
|
echo "RUN /tmp/scripts/assemble" >>"$df_name"
|
||||||
|
else
|
||||||
|
echo "RUN /usr/libexec/s2i/assemble" >>"$df_name"
|
||||||
|
fi
|
||||||
|
# If exists, set the custom run script as CMD, else default to /usr/libexec/s2i/run
|
||||||
|
if [ -x "$local_scripts/run" ]; then
|
||||||
|
echo "CMD /tmp/scripts/run" >>"$df_name"
|
||||||
|
else
|
||||||
|
echo "CMD /usr/libexec/s2i/run" >>"$df_name"
|
||||||
|
fi
|
||||||
|
# Run the build and tag the result
|
||||||
|
docker build -f "$df_name" -t "$dst_image" .
|
||||||
|
popd
|
||||||
|
}
|
||||||
Loading…
Add table
Add a link
Reference in a new issue