Update to the v12

This commit is contained in:
Honza Horak 2020-11-02 16:10:10 +01:00
commit 7142c18265
69 changed files with 5289 additions and 1759 deletions

View file

View file

@ -1,4 +1,4 @@
FROM registry.fedoraproject.org/f31/s2i-core:latest
FROM registry.fedoraproject.org/f32/s2i-core:latest
# PostgreSQL image for OpenShift.
# Volumes:
@ -14,7 +14,7 @@ ENV NAME=postgresql \
VERSION=0 \
ARCH=x86_64 \
\
POSTGRESQL_VERSION=11 \
POSTGRESQL_VERSION=12 \
POSTGRESQL_PREV_VERSION=10 \
HOME=/var/lib/pgsql \
PGUSER=postgres \
@ -28,9 +28,9 @@ create, run, maintain and access a PostgreSQL DBMS server."
LABEL summary="$SUMMARY" \
description="$DESCRIPTION" \
io.k8s.description="$DESCRIPTION" \
io.k8s.display-name="PostgreSQL 11" \
io.k8s.display-name="PostgreSQL 12" \
io.openshift.expose-services="5432:postgresql" \
io.openshift.tags="database,postgresql,postgresql11" \
io.openshift.tags="database,postgresql,postgresql12" \
com.redhat.component="$NAME" \
maintainer="SoftwareCollections.org <sclorg@redhat.com>" \
name="$FGC/$NAME" \
@ -46,7 +46,8 @@ COPY root/usr/libexec/fix-permissions /usr/libexec/fix-permissions
# to make sure of that.
RUN INSTALL_PKGS="rsync tar gettext bind-utils postgresql-server postgresql-contrib nss_wrapper " && \
INSTALL_PKGS+="findutils xz" && \
dnf -y module enable postgresql:11 && \
INSTALL_PKGS+=" pgaudit" && \
dnf -y module enable postgresql:12 && \
dnf -y --setopt=tsflags=nodocs install $INSTALL_PKGS && \
rpm -V $INSTALL_PKGS && \
dnf clean all && \

4
common/.travis.yml Normal file
View file

@ -0,0 +1,4 @@
language: shell
os: linux
script:
- make shellcheck

202
common/LICENSE Normal file
View file

@ -0,0 +1,202 @@
Apache License
Version 2.0, January 2004
http://www.apache.org/licenses/
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
1. Definitions.
"License" shall mean the terms and conditions for use, reproduction,
and distribution as defined by Sections 1 through 9 of this document.
"Licensor" shall mean the copyright owner or entity authorized by
the copyright owner that is granting the License.
"Legal Entity" shall mean the union of the acting entity and all
other entities that control, are controlled by, or are under common
control with that entity. For the purposes of this definition,
"control" means (i) the power, direct or indirect, to cause the
direction or management of such entity, whether by contract or
otherwise, or (ii) ownership of fifty percent (50%) or more of the
outstanding shares, or (iii) beneficial ownership of such entity.
"You" (or "Your") shall mean an individual or Legal Entity
exercising permissions granted by this License.
"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation
source, and configuration files.
"Object" form shall mean any form resulting from mechanical
transformation or translation of a Source form, including but
not limited to compiled object code, generated documentation,
and conversions to other media types.
"Work" shall mean the work of authorship, whether in Source or
Object form, made available under the License, as indicated by a
copyright notice that is included in or attached to the work
(an example is provided in the Appendix below).
"Derivative Works" shall mean any work, whether in Source or Object
form, that is based on (or derived from) the Work and for which the
editorial revisions, annotations, elaborations, or other modifications
represent, as a whole, an original work of authorship. For the purposes
of this License, Derivative Works shall not include works that remain
separable from, or merely link (or bind by name) to the interfaces of,
the Work and Derivative Works thereof.
"Contribution" shall mean any work of authorship, including
the original version of the Work and any modifications or additions
to that Work or Derivative Works thereof, that is intentionally
submitted to Licensor for inclusion in the Work by the copyright owner
or by an individual or Legal Entity authorized to submit on behalf of
the copyright owner. For the purposes of this definition, "submitted"
means any form of electronic, verbal, or written communication sent
to the Licensor or its representatives, including but not limited to
communication on electronic mailing lists, source code control systems,
and issue tracking systems that are managed by, or on behalf of, the
Licensor for the purpose of discussing and improving the Work, but
excluding communication that is conspicuously marked or otherwise
designated in writing by the copyright owner as "Not a Contribution."
"Contributor" shall mean Licensor and any individual or Legal Entity
on behalf of whom a Contribution has been received by Licensor and
subsequently incorporated within the Work.
2. Grant of Copyright License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
copyright license to reproduce, prepare Derivative Works of,
publicly display, publicly perform, sublicense, and distribute the
Work and such Derivative Works in Source or Object form.
3. Grant of Patent License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
(except as stated in this section) patent license to make, have made,
use, offer to sell, sell, import, and otherwise transfer the Work,
where such license applies only to those patent claims licensable
by such Contributor that are necessarily infringed by their
Contribution(s) alone or by combination of their Contribution(s)
with the Work to which such Contribution(s) was submitted. If You
institute patent litigation against any entity (including a
cross-claim or counterclaim in a lawsuit) alleging that the Work
or a Contribution incorporated within the Work constitutes direct
or contributory patent infringement, then any patent licenses
granted to You under this License for that Work shall terminate
as of the date such litigation is filed.
4. Redistribution. You may reproduce and distribute copies of the
Work or Derivative Works thereof in any medium, with or without
modifications, and in Source or Object form, provided that You
meet the following conditions:
(a) You must give any other recipients of the Work or
Derivative Works a copy of this License; and
(b) You must cause any modified files to carry prominent notices
stating that You changed the files; and
(c) You must retain, in the Source form of any Derivative Works
that You distribute, all copyright, patent, trademark, and
attribution notices from the Source form of the Work,
excluding those notices that do not pertain to any part of
the Derivative Works; and
(d) If the Work includes a "NOTICE" text file as part of its
distribution, then any Derivative Works that You distribute must
include a readable copy of the attribution notices contained
within such NOTICE file, excluding those notices that do not
pertain to any part of the Derivative Works, in at least one
of the following places: within a NOTICE text file distributed
as part of the Derivative Works; within the Source form or
documentation, if provided along with the Derivative Works; or,
within a display generated by the Derivative Works, if and
wherever such third-party notices normally appear. The contents
of the NOTICE file are for informational purposes only and
do not modify the License. You may add Your own attribution
notices within Derivative Works that You distribute, alongside
or as an addendum to the NOTICE text from the Work, provided
that such additional attribution notices cannot be construed
as modifying the License.
You may add Your own copyright statement to Your modifications and
may provide additional or different license terms and conditions
for use, reproduction, or distribution of Your modifications, or
for any such Derivative Works as a whole, provided Your use,
reproduction, and distribution of the Work otherwise complies with
the conditions stated in this License.
5. Submission of Contributions. Unless You explicitly state otherwise,
any Contribution intentionally submitted for inclusion in the Work
by You to the Licensor shall be under the terms and conditions of
this License, without any additional terms or conditions.
Notwithstanding the above, nothing herein shall supersede or modify
the terms of any separate license agreement you may have executed
with Licensor regarding such Contributions.
6. Trademarks. This License does not grant permission to use the trade
names, trademarks, service marks, or product names of the Licensor,
except as required for reasonable and customary use in describing the
origin of the Work and reproducing the content of the NOTICE file.
7. Disclaimer of Warranty. Unless required by applicable law or
agreed to in writing, Licensor provides the Work (and each
Contributor provides its Contributions) on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
implied, including, without limitation, any warranties or conditions
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
PARTICULAR PURPOSE. You are solely responsible for determining the
appropriateness of using or redistributing the Work and assume any
risks associated with Your exercise of permissions under this License.
8. Limitation of Liability. In no event and under no legal theory,
whether in tort (including negligence), contract, or otherwise,
unless required by applicable law (such as deliberate and grossly
negligent acts) or agreed to in writing, shall any Contributor be
liable to You for damages, including any direct, indirect, special,
incidental, or consequential damages of any character arising as a
result of this License or out of the use or inability to use the
Work (including but not limited to damages for loss of goodwill,
work stoppage, computer failure or malfunction, or any and all
other commercial damages or losses), even if such Contributor
has been advised of the possibility of such damages.
9. Accepting Warranty or Additional Liability. While redistributing
the Work or Derivative Works thereof, You may choose to offer,
and charge a fee for, acceptance of support, warranty, indemnity,
or other liability obligations and/or rights consistent with this
License. However, in accepting such obligations, You may act only
on Your own behalf and on Your sole responsibility, not on behalf
of any other Contributor, and only if You agree to indemnify,
defend, and hold each Contributor harmless for any liability
incurred by, or claims asserted against, such Contributor by reason
of your accepting any such warranty or additional liability.
END OF TERMS AND CONDITIONS
APPENDIX: How to apply the Apache License to your work.
To apply the Apache License to your work, attach the following
boilerplate notice, with the fields enclosed by brackets "[]"
replaced with your own identifying information. (Don't include
the brackets!) The text should be enclosed in the appropriate
comment syntax for the file format. We also recommend that a
file or class name and description of purpose be included on the
same "printed page" as the copyright notice for easier
identification within third-party archives.
Copyright [yyyy] [name of copyright owner]
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.

46
common/Makefile Normal file
View file

@ -0,0 +1,46 @@
SHELL := /usr/bin/env bash
all:
@echo >&2 "Only 'make check' allowed"
TESTED_IMAGES = \
postgresql-container \
s2i-python-container \
s2i-nodejs-container
.PHONY: check test all check-failures
TEST_LIB_TESTS = \
path_foreach \
random_string \
test_npm \
image_availability \
public_image_name
$(TEST_LIB_TESTS):
@echo " RUN TEST '$@'" ; \
$(SHELL) tests/test-lib/$@ || $(SHELL) -x tests/lib/$@
test-lib-foreach:
check-test-lib: $(TEST_LIB_TESTS)
test: check
shellcheck:
./run-shellcheck.sh `git ls-files *.sh`
check-failures: check-test-lib
cd tests/failures/check && make tag && ! make check && make clean
grep -q "Red Hat Enterprise Linux release 8" /etc/system-release || cd tests/failures/check && make tag SKIP_SQUASH=0
check-squash:
./tests/squash/squash.sh
check-latest-imagestream:
cd tests && ./check_imagestreams.sh
check: check-failures check-squash check-latest-imagestream
TESTED_IMAGES="$(TESTED_IMAGES)" tests/remote-containers.sh

126
common/README.md Normal file
View file

@ -0,0 +1,126 @@
Common build helpers for sclorg containers
==========================================
This repository is aimed to be added as git submodule into particular
containers' source repositories. By default, the path to submodule should be
named 'common'.
Usage
-----
This section explains the usage of the shared scripts in this repository when
it is used as a submodule in a container source repository.
Once you have the repository set as a submodule include `common.mk` into your
root Makefile in order to access the default rules used to call shared scripts.
**Default rules:**
`make` or `make build`
This rule will build an image without tagging it with any tags after it is built.
After the image finishes building the scripts will squash the image using `docker-squash`.
`make build` will also expect a `README.md` so that it can transfrom it into
a man page that gets added to the image so make sure it is available and that
you have the `go-md2man` tool installed on your host.
`make tag`
Use this rule if you want to tag an image after it is built. It will be tagged with
two tags - name:latest and name:version.
Depends on `build`
`make test` or `make check`
This rule will run the testsuite scripts contained in the container source repositories.
It expects the test to be available at `$gitroot/$version/test/run`
Depends on `tag` as some tests might need to have the images tagged (s2i).
`make test-openshift`
Similar to `make test` but runs testsuite for Openshift 3, expected to be found at
`$gitroot/$version/test/run-openshift`
`make test-openshift-4`
Similar to `make test` but runs testsuite for Openshift 4, expected to be found at
`$gitroot/$version/test/run-openshift-remote-cluster`
`make test-with-conu`
The rule is similar to `make test`. It runs a test suite written using [conu
library](https://github.com/user-cont/conu). The path to the test script is
meant to be at `$gitroot/$version/test/run-conu`. By default the test suite is
being run in the current environment. You can also run the tests in a container
by defining variable `CONU_IMAGE`. Container images with conu are available in
[this docker hub repository](docker.io/usercont/conu:0.6.2), a good value for
the variable is `docker.io/usercont/conu:0.6.2`.
`make clean`
Runs scripts that clean-up the working dir. Depends on the `clean-images` rule by default
and additional clean rules can be provided through the `clean-hook` variable.
`make clean-images`
Best-effort to remove the last set of images that have been built using the scripts.
`make shellcheck`
Check the shell syntax of the files specified by `$SHELLCHECK_FILES` variable.
See `SHELLCHECK_FILES` variable description below for more info (default is `.`).
The files matching this specification are then filtered, to not show results twice
for symlinks. Only files with a suffix `.sh` or shell shebang are scanned with
the `shellcheck` utility. See [run-shellcheck.sh](./run-shellcheck.sh) in this repo for more detailed info.
Once the shell syntax issues are fixed, CI that runs `make shellcheck` for each PR can be
turned on by putting [.travis.yml](.travis.yml) file into the root of the image's repository.
[.travis.yml](https://github.com/sclorg/container-common-scripts/blob/master/.travis.yml)
for its content.
**There are additional variables that you can use that the default rules are prepared to
work with:**
`VERSIONS`
Names of the directories in which the Dockerfiles are contained. Needs to be defined in your
Dockerfile for the scripts to know which versions to build.
`OS`
OS version you want to build the images for. Currently the scripts are able to build for
centos (default), centos6, centos8, rhel7, rhel8 and fedora.
`SKIP_SQUASH`
When set to 1 the build script will skip the squash phase of the build.
`CUSTOM_REPO`
Set this variable to the path to your local .repo files you want to have available inside
the image while building. Useful for building rhel-based images on an unsubscribed box.
Be aware that you cannot write to any .repo files used this way inside the image as they
will be mounted into the image as read-only.
`UPDATE_BASE`
Set to 1 if you want the build script to always pull the base image when available.
`DOCKER_BUILD_CONTEXT`
Use this variable in case you want to have a different context for your builds. By default
the context of the build is the versioned directory the Dockerfiles are contained in.
`SHELLCHECK_FILES`
One or more files or directories to be scanned by the shellcheck, default is `.`, which
means a whole repository directory. If a directory is provided then all of its content
is scanned as well.
`clean-hook`
Append Makefile rules to this variable to make sure additional cleaning actions are run
when `make clean` is called.
Regression tests
----------------
`make check`
Runs the tests of few images that use this set of scripts. If the tests of those
images pass, this repo is considered to be working.
`make shellcheck`
Check the shell syntax of all `*.sh` files tracked by the git in this repository.
Dependencies for testsuite:
- /usr/bin/docker (either `docker` or `podman` + `podman-docker`)
- docker-squash (if `docker` is used, otherwise set `SKIP_SQUASH`, which is done automatically on non-EL-7)
- git
- go-md2man
- make
- source-to-image
- shellcheck

226
common/build.sh Executable file
View file

@ -0,0 +1,226 @@
#!/bin/bash
# This script is used to build the OpenShift Docker images.
#
# OS - Specifies distribution - "rhel7", "rhel8", "centos7", "centos8" or "fedora"
# VERSION - Specifies the image version - (must match with subdirectory in repo)
# VERSIONS - Must be set to a list with possible versions (subdirectories)
set -e
script_name=$(readlink -f "$0")
script_dir=$(dirname "$script_name")
OS=${1-$OS}
VERSION=${2-$VERSION}
error() { echo "ERROR: $*" ; false ; }
# _parse_output_inner
# -------------------
# Helper function for 'parse_output'.
# We need to avoid case statements in $() for older Bash versions (per issue
# postgresql-container#35, mac ships with 3.2).
# Example of problematic statement: echo $(case i in i) echo i;; esac)
_parse_output_inner ()
{
set -o pipefail
{
case $stream in
stdout|1|"")
eval "$command" | tee >(cat - >&"$stdout_fd")
;;
stderr|2)
set +x # avoid stderr pollution
eval "$command" {free_fd}>&1 1>&"$stdout_fd" 2>&"$free_fd" | tee >(cat - >&"$stderr_fd")
;;
esac
# Inherit correct exit status.
(exit "${PIPESTATUS[0]}")
} | eval "$filter"
}
# parse_output COMMAND FILTER_COMMAND OUTVAR [STREAM={stderr|stdout}]
# -------------------------------------------------------------------
# Parse standard (error) output of COMMAND with FILTER_COMMAND and store the
# output into variable named OUTVAR. STREAM might be 'stdout' or 'stderr',
# defaults to 'stdout'. The filtered output stays (live) printed to terminal.
# This method doesn't create any explicit temporary files.
# Defines:
# ${$OUTVAR}: Set to FILTER_COMMAND output.
parse_output ()
{
local command=$1 filter=$2 var=$3 stream=$4
local raw_output='' rc=0
{
# shellcheck disable=SC2034
raw_output=$(_parse_output_inner)
} {stdout_fd}>&1 {stderr_fd}>&2
rc=$?
eval "$var=\$raw_output"
(exit $rc)
}
# "best-effort" cleanup of previous image
function clean_image {
if test -f .image-id.raw; then
local previous_id
previous_id=$(cat .image-id.raw)
if test "$IMAGE_ID" != "$previous_id"; then
# Also remove squashed image since it will change anyway
docker rmi "$previous_id" "$(cat .image-id)" || :
rm -f ".image-id.raw" ".image-id" || :
fi
fi
}
# Pull image based on FROM, before we build our own.
function pull_image {
local dockerfile="$1"
local loops=10
local loop=0
# Get image_name from Dockerfile before pulling.
while read -r line; do
if ! grep -q "^FROM" <<< "$line"; then
continue
fi
image_name=$(echo "$line" | cut -d ' ' -f2)
# In case FROM scratch is defined, skip it
if [[ x"$image_name" == "xscratch" ]]; then
continue
fi
echo "-> Pulling image $image_name before building image from $dockerfile."
# Sometimes in Fedora case it fails with HTTP 50X
# Check if the image is available locally and try to pull it if it is not
if [[ "$(docker images -q "$image_name" 2>/dev/null)" != "" ]]; then
echo "The image $image_name is already pulled."
continue
fi
# Try pulling the image to see if it is accessible
# WORKAROUND: Since Fedora registry sometimes fails randomly, let's try it more times
while ! docker pull "$image_name"; do
((loop++)) || :
echo "Pulling image $image_name failed."
[ "$loop" -gt "$loops" ] && { echo "It happened $loops times. Giving up." ; return 1; }
echo "Let's wait $((loop*5)) seconds and try again."
sleep "$((loop*5))"
done
done < "$dockerfile"
}
# Perform docker build but append the LABEL with GIT commit id at the end
function docker_build_with_version {
local dockerfile="$1"
local exclude=.exclude-${OS}
if [ -e "$exclude" ]; then
echo "-> $exclude file exists for version $dir, skipping build."
clean_image
return
fi
if [ ! -e "$dockerfile" ]; then
echo "-> $dockerfile for version $dir does not exist, skipping build."
clean_image
return
fi
echo "-> Version ${dir}: building image from '${dockerfile}' ..."
git_version=$(git rev-parse --short HEAD)
BUILD_OPTIONS+=" --label io.openshift.builder-version=\"${git_version}\""
if [[ "${UPDATE_BASE}" == "1" ]]; then
BUILD_OPTIONS+=" --pull=true"
fi
if [ -n "$CUSTOM_REPO" ]; then
if [ -f "$CUSTOM_REPO" ]; then
BUILD_OPTIONS+=" -v $CUSTOM_REPO:/etc/yum.repos.d/sclorg_custom.repo:Z"
elif [ -d "$CUSTOM_REPO" ]; then
BUILD_OPTIONS+=" -v $CUSTOM_REPO:/etc/yum.repos.d/:Z"
else
echo "ERROR: file type not known: $CUSTOM_REPO" >&2
fi
fi
pull_image "$dockerfile"
# shellcheck disable=SC2016
parse_output 'docker build '"$BUILD_OPTIONS"' -f "$dockerfile" "${DOCKER_BUILD_CONTEXT}"' \
"tail -n 1 | awk '/Successfully built|(^--> )?(Using cache )?[a-fA-F0-9]+$/{print \$NF}'" \
IMAGE_ID
clean_image
echo "$IMAGE_ID" > .image-id.raw
squash "${dockerfile}"
echo "$IMAGE_ID" > .image-id
}
# squash DOCKERFILE
# -----------------
# Use python library docker_squash[1] and squash the result image
# when necessary.
# [1] https://github.com/goldmann/docker-squash
# Reads:
# $IMAGE_ID
# Sets:
# $IMAGE_ID
squash ()
{
local base squashed_from squashed='' unsquashed=$IMAGE_ID
test "$SKIP_SQUASH" = 1 && return 0
if test -f .image-id.squashed; then
squashed=$(cat .image-id.squashed)
# We (maybe) already have squashed file.
if test -f .image-id.squashed_from; then
squashed_from=$(cat .image-id.squashed_from)
if test "$squashed_from" = "$IMAGE_ID"; then
# $squashed is up2date
IMAGE_ID=$squashed
echo "Image '$unsquashed' already squashed as '$squashed'"
return 0
fi
fi
# We are going to squash now, so if there's existing squashed image, try
# to do the best-effort 'rmi' to not waste memory unnecessarily.
docker rmi "$squashed" || :
fi
base=$(awk '/^FROM/{print $2}' "$1")
echo "Squashing the image '$unsquashed' from '$base' layer."
IMAGE_ID=$("${PYTHON-python3}" "$script_dir"/squash.py "$unsquashed" "$base")
echo "Squashed as '$IMAGE_ID'."
echo "$unsquashed" > .image-id.squashed_from
echo "$IMAGE_ID" > .image-id.squashed
}
# Versions are stored in subdirectories. You can specify VERSION variable
# to build just one single version. By default we build all versions
dirs=${VERSION:-$VERSIONS}
for dir in ${dirs}; do
pushd "${dir}" > /dev/null
if [ "$OS" == "rhel8" ] || [ "$OS" == "rhel8-candidate" ]; then
docker_build_with_version Dockerfile.rhel8
elif [ "$OS" == "rhel7" ] || [ "$OS" == "rhel7-candidate" ]; then
docker_build_with_version Dockerfile.rhel7
elif [ "$OS" == "fedora" ] || [ "$OS" == "fedora-candidate" ]; then
docker_build_with_version Dockerfile.fedora
elif [ "$OS" == "centos6" ] || [ "$OS" == "centos6-candidate" ]; then
docker_build_with_version Dockerfile.centos6
elif [ "$OS" == "centos8" ] || [ "$OS" == "centos8-candidate" ]; then
docker_build_with_version Dockerfile.centos8
else
docker_build_with_version Dockerfile
fi
popd > /dev/null
done

73
common/check_imagestreams.py Executable file
View file

@ -0,0 +1,73 @@
#!/bin/env python3
import sys
import json
import logging
import os
from pathlib import Path
from typing import Dict
IMAGESTREAMS_DIR: str = "imagestreams"
class ImageStreamChecker(object):
version: str = ""
results: Dict = {}
def __init__(self, version: str):
self.version = version
def load_json_file(self, filename: Path):
with open(str(filename)) as f:
return json.load(f)
def check_version(self, json_dict: Dict):
res = []
for tags in json_dict["spec"]["tags"]:
# The name can be"<stream>" or "<stream>-elX" or "<stream>-ubiX"
if (tags["name"] == self.version or
tags["name"].startswith(self.version + '-')):
res.append(tags)
return res
def check_latest_tag(self, json_dict: Dict):
latest_tag_correct: bool = False
for tags in json_dict["spec"]["tags"]:
if tags["name"] != "latest":
continue
# The latest can link to either "<stream>" or "<stream>-elX" or "<stream>-ubiX"
if tags["from"]["name"] == self.version or tags["from"]["name"].startswith(self.version + '-'):
latest_tag_correct = True
return latest_tag_correct
def check_imagestreams(self):
p = Path(".")
json_files = p.glob(f"{IMAGESTREAMS_DIR}/*.json")
if not json_files:
print(f"No json files present in {IMAGESTREAMS_DIR}.")
return 0
for f in json_files:
if os.environ.get("TARGET") in ("rhel7", "centos7") and "aarch64" in str(f):
print("Imagestream aarch64 is not supported on rhel7")
continue
print(f"Checking file {str(f)}.")
json_dict = self.load_json_file(f)
if not (self.check_version(json_dict) and self.check_latest_tag(json_dict)):
print(f"The latest version is not present in {str(f)} or in latest tag.")
self.results[f] = False
if self.results:
return 1
print("Imagestreams contains the latest version.")
return 0
if __name__ == "__main__":
if len(sys.argv) != 2:
logging.fatal("%s: %s", sys.argv[0], "VERSION as an argument was not provided")
sys.exit(1)
print(f"Version to check is {sys.argv[1]}.")
isc = ImageStreamChecker(version=sys.argv[1])
sys.exit(isc.check_imagestreams())

21
common/clean.sh Executable file
View file

@ -0,0 +1,21 @@
#! /bin/sh
set -e
test -f auto_targets.mk && rm auto_targets.mk
for version
do
remove_images=
for idfile in .image-id.raw .image-id.squashed; do
# shellcheck disable=SC2039
test ! -f "$version/$idfile" || remove_images+=" $(cat "$version/$idfile")"
done
for image in $remove_images; do
# shellcheck disable=SC2046
docker rm -f $(docker ps -q -a -f "ancestor=$image") 2>/dev/null || :
docker rmi -f "$image" || :
done
rm -rf "$version"/.image-id*
done

150
common/common.mk Normal file
View file

@ -0,0 +1,150 @@
# SKIP_SQUASH = 0/1
# =================
# If set to '0', images are automatically squashed. '1' disables
# squashing. By default only RHEL containers are squashed.
SHELL := /usr/bin/env bash
ifndef common_dir
common_dir = common
endif
build = $(SHELL) $(common_dir)/build.sh
test = $(SHELL) $(common_dir)/test.sh
testr = $(SHELL) $(common_dir)/test-remote-cluster.sh
shellcheck = $(SHELL) $(common_dir)/run-shellcheck.sh
tag = $(SHELL) $(common_dir)/tag.sh
clean = $(SHELL) $(common_dir)/clean.sh
DG ?= /bin/dg
generator = DG="$(DG)" $(SHELL) $(common_dir)/generate.sh
# pretty printers
# ---------------
__PROLOG = $(if $(VERBOSE),,@echo " $(1) " $@;)
V_LN = $(call __PROLOG,LN )
V_DG = $(call __PROLOG,DG )
V_DGM = $(call __PROLOG,DGM)
V_CP = $(call __PROLOG,CP )
CDIR = mkdir -p "$$(dirname "$@")" || exit 1 ;
ifeq ($(TARGET),rhel8)
SKIP_SQUASH ?= 1
OS := rhel8
DOCKERFILE ?= Dockerfile.rhel8
else ifeq ($(TARGET),rhel7)
SKIP_SQUASH ?= 0
OS := rhel7
DOCKERFILE ?= Dockerfile.rhel7
else ifeq ($(TARGET),fedora)
OS := fedora
DOCKERFILE ?= Dockerfile.fedora
else ifeq ($(TARGET),centos6)
OS := centos6
DOCKERFILE ?= Dockerfile.centos6
else ifeq ($(TARGET),centos8)
OS := centos8
DOCKERFILE ?= Dockerfile.centos8
else
OS := centos7
DOCKERFILE ?= Dockerfile
endif
SKIP_SQUASH ?= 1
DOCKER_BUILD_CONTEXT ?= .
SHELLCHECK_FILES ?= .
script_env = \
SKIP_SQUASH=$(SKIP_SQUASH) \
UPDATE_BASE=$(UPDATE_BASE) \
OS=$(OS) \
CLEAN_AFTER=$(CLEAN_AFTER) \
DOCKER_BUILD_CONTEXT=$(DOCKER_BUILD_CONTEXT) \
OPENSHIFT_NAMESPACES="$(OPENSHIFT_NAMESPACES)" \
CUSTOM_REPO="$(CUSTOM_REPO)"
# TODO: switch to 'build: build-all' once parallel builds are relatively safe
.PHONY: build build-serial build-all
build: build-serial
build-serial:
@$(MAKE) -j1 build-all
build-all: $(VERSIONS)
@for i in $(VERSIONS); do \
test -f $$i/.image-id || continue ; \
echo -n "$(BASE_IMAGE_NAME) $$i => " ; \
cat $$i/.image-id ; \
done
.PHONY: $(VERSIONS)
$(VERSIONS): % : %/root/help.1
VERSION="$@" $(script_env) $(build)
.PHONY: test check
check: test
test: script_env += TEST_MODE=true
# The tests should ideally depend on $IMAGE_ID only, but see PR#19 for more info
# while we need to depend on 'tag' instead of 'build'.
test: tag
VERSIONS="$(VERSIONS)" $(script_env) $(test)
.PHONY: test-with-conu
test-with-conu: script_env += TEST_CONU_MODE=true
test-with-conu: tag
VERSIONS="$(VERSIONS)" $(script_env) $(test)
.PHONY: test-openshift-4
test-openshift-4: script_env += TEST_OPENSHIFT_4=true
test-openshift-4: tag
VERSIONS="$(VERSIONS)" BASE_IMAGE_NAME="$(BASE_IMAGE_NAME)" $(script_env) $(test)
.PHONY: test-openshift
test-openshift: script_env += TEST_OPENSHIFT_MODE=true
test-openshift: tag
VERSIONS="$(VERSIONS)" BASE_IMAGE_NAME="$(BASE_IMAGE_NAME)" $(script_env) $(test)
.PHONY: shellcheck
shellcheck:
$(shellcheck) $(SHELLCHECK_FILES)
.PHONY: tag
tag: build
VERSIONS="$(VERSIONS)" $(script_env) $(tag)
.PHONY: clean clean-hook clean-images clean-versions
clean: clean-images
@$(MAKE) --no-print-directory clean-hook
clean-images:
$(clean) $(VERSIONS)
clean-versions:
rm -rf $(VERSIONS)
%root/help.1: %README.md
mkdir -p $(@D)
go-md2man -in "$^" -out "$@"
chmod a+r "$@"
generate-all: generate
MANIFEST_FILE ?= manifest.sh
auto_targets.mk: $(MANIFEST_FILE)
MANIFEST_FILE="$(MANIFEST_FILE)" \
VERSIONS="$(VERSIONS)" \
$(generator)
# triggers build of auto_targets.mk automatically
-include auto_targets.mk
# We have to remove auto_targets.mk here, otherwise subsequent make calls
# with different VERSIONS=* option keeps the auto_targets.mk unchanged.
.PHONY: generate
generate: $(DISTGEN_TARGETS) $(DISTGEN_MULTI_TARGETS) $(COPY_TARGETS) $(SYMLINK_TARGETS)
rm auto_targets.mk

184
common/generate.sh Executable file
View file

@ -0,0 +1,184 @@
#!/bin/bash
# This script is used to create image directories using distgen, cp or ln
# It requires "$MANIFEST_FILE" (defaults to manifest.sh) file to be present in
# image repository.
# The manifest file should contain set of rules in form:
# <rules_type>="
# src=<path to source>
# dest=<path to destination>
# mode=<destination file mode (optional)>;
# ...;
# "
#
# Supported type rules are now COPY_RULES, DISTGEN_RULES and SYMLINKS_RULES
# for real example see https://github.com/sclorg/postgresql-container/blob/master/manifest.sh
# shellcheck disable=SC1090
source "$MANIFEST_FILE"
die () { echo "FATAL: $*" ; exit 1 ; }
nl='
'
test -f auto_targets.mk && rm auto_targets.mk
DG="${DG-/bin/dg}"
[ ! -x "$DG" ] && echo " Error: distgen binary not found or not executable in $DG" && \
echo " Make sure distgen is properly installed on your host in $DG, or provide a path to your distgen binary via \$DG" && exit 1
DISTGEN_COMBINATIONS=$("$DG" --multispec specs/multispec.yml --multispec-combinations)
clean_rule_variables(){
src=""
dest=""
mode=""
link_target=""
link_name=""
}
parse_rules() {
targets=""
OLD_IFS=$IFS
IFS=";"
for rule in $rules; do
if [ -z "$(echo "$rule"| tr -d '[:space:]')" ]; then
continue
fi
clean_rule_variables
eval "$rule"
# shellcheck disable=SC2016
cdir='$(CDIR)'
case "$creator" in
copy)
[[ -z "$src" ]] && echo "src has to be specified in copy rule" && exit 1
[[ -z "$dest" ]] && echo "dest has to be specified in copy rule" && exit 1
core_subst=$core
prolog="\$(V_CP)$cdir"
;;
distgen)
[[ -z "$src" ]] && echo "src has to be specified in distgen rule" && exit 1
[[ -z "$dest" ]] && echo "dest has to be specified in distgen rule" && exit 1
core_subst=$core
prolog="\$(V_DG)$cdir"
;;
distgen_multi)
[[ -z "$src" ]] && echo "src has to be specified in distgen rule" && exit 1
[[ -z "$dest" ]] && echo "dest has to be specified in distgen rule" && exit 1
if [[ "$dest" == "Dockerfile.rhel7" ]]; then
if ! [[ "$DG_CONF" =~ rhel-7-x86_64.yaml ]]; then
continue
fi
elif [[ "$dest" == "Dockerfile.rhel8" ]]; then
if ! [[ "$DG_CONF" =~ rhel-8-x86_64.yaml ]]; then
continue
fi
elif [[ "$dest" == "Dockerfile.centos8" ]]; then
if ! [[ "$DG_CONF" =~ centos-8-x86_64.yaml ]]; then
continue
fi
elif [[ "$dest" == *"Dockerfile.fedora" ]]; then
if ! [[ "$DG_CONF" =~ fedora-[0-9]{,2}-x86_64.yaml ]]; then
continue
fi
elif [[ "$dest" == *"Dockerfile" ]]; then
if ! [[ "$DG_CONF" =~ centos-[0-9]{,2}-x86_64.yaml ]]; then
continue
fi
fi
prolog="\$(V_DGM)$cdir"
core_subst=$core
;;
link)
[[ -z "$link_name" ]] && echo "link_name has to be specified in link rule" && exit 1
[[ -z "$link_target" ]] && echo "link_target has to be specified in link rule" && exit 1
dest="$link_name"
# shellcheck disable=SC2001
core_subst=$(echo "$core" | sed -e "s~__link_target__~${link_target}~g")
prolog="\$(V_LN)$cdir"
;;
esac
case $version$dest$src in
*' '*) die "space not allowed in version, dest, src" ;;
esac
target=$version/$dest
targets+="\\$nl $target"
cat >> auto_targets.mk << EOF
$nl$target: $src \$(MANIFEST_FILE)
$prolog \\
$core_subst${mode:+"; \\
chmod $mode '\$@'"}
EOF
done
IFS=$OLD_IFS
}
for version in ${VERSIONS}; do
# Get a working combination of distgen options for this version
while read -r combination; do
# line looks like: --distro rhel-7-x86_64.yaml --multispec-selector version=9.4
echo "$combination" | grep "version=$version" &>/dev/null && break
done <<< "$DISTGEN_COMBINATIONS"
[ -z "$combination" ] && die "Could not find a working distgen options combination for version $version"
# copy targets
rules="$COPY_RULES"
core="cp \$< \$@"
creator="copy"
parse_rules
COPY_TARGETS+="$targets"
# distgen targets
rules="$DISTGEN_RULES"
core="\$(DG) --multispec specs/multispec.yml \\
--template \"\$<\" $combination --output \"\$@\""
creator="distgen"
parse_rules
DISTGEN_TARGETS+="$targets"
rules=$SYMLINK_RULES
core="ln -nfs __link_target__ \$@"
creator="link"
parse_rules
SYMLINK_TARGETS+="$targets"
done
while read -r combination; do
# line looks like: --distro rhel-7-x86_64.yaml --multispec-selector version=9.4
eval 'set -- $combination'
case $4 in
version=*) version=${4##*=} ;;
*) die "version not found"
esac
case $2 in
*x86_64*) DG_CONF=$2 ;;
*) die "invalid --distro option"
esac
# distgen multi targets
rules="$DISTGEN_MULTI_RULES"
core="\$(DG) --multispec specs/multispec.yml \\
--template \"\$<\" \\
--output \"\$@\" \\
$combination"
creator="distgen_multi"
parse_rules
DISTGEN_MULTI_TARGETS+="$targets"
done <<< "$DISTGEN_COMBINATIONS"
cat -v >> auto_targets.mk <<EOF
COPY_TARGETS = $COPY_TARGETS
DISTGEN_TARGETS = $DISTGEN_TARGETS
DISTGEN_MULTI_TARGETS = $DISTGEN_MULTI_TARGETS
SYMLINK_TARGETS = $SYMLINK_TARGETS
EOF

44
common/run-shellcheck.sh Executable file
View file

@ -0,0 +1,44 @@
#!/bin/bash
VERBOSE_OUTPUT=0
usage() {
echo "Usage: $(basename "$0") [ -v|--verbose ] <dir|file> [ <dir|file> ... ]"
}
verbose() {
if [ "${VERBOSE_OUTPUT}" -eq 1 ] ; then
echo "$@" >&2
fi
}
if [ $# -eq 0 ] ; then
echo "ERROR: No arguments given."
usage
exit 1
fi
case $1 in
-v|--verbose) VERBOSE_OUTPUT=1; shift ;;
esac
filter_files() {
while read -r file ; do
if [ -L "$file" ] ; then
verbose "Ignoring symlink $file."
continue
fi
verbose "Will scan $file"
echo "$file"
done
}
detect_shell_files() {
find -H "$@" -type f -not -path '*/\.git/*' -exec grep -l '^#!/bin/\(bash\|sh\)' {} +
find -H "$@" -name '*.sh' -not -path '*/\.git/*'
}
# Run shellcheck on all files (we should also ignore symlinks)
detect_shell_files "$@" | filter_files | sort -u | xargs shellcheck
# vim: set tabstop=2:shiftwidth=2:expandtab:

23
common/squash.py Executable file
View file

@ -0,0 +1,23 @@
#! /bin/python
import sys
import logging
from platform import python_version
try:
from docker_squash import squash
except ImportError:
logging.fatal("please install 'docker_squash' for Python {0}".format(python_version()))
sys.exit(1)
if __name__ == "__main__":
if len(sys.argv) != 3:
logging.fatal("%s: %s", sys.argv[0], msg)
sys.exit(1)
print(squash.Squash(
log=logging.getLogger(),
image=sys.argv[1],
from_layer=sys.argv[2]).run()
)

34
common/tag.sh Executable file
View file

@ -0,0 +1,34 @@
#!/bin/bash
# This script is used to tag the OpenShift Docker images.
#
# Resulting image will be tagged: 'name:version' and 'name:latest'. Name and version
# are values of labels from resulted image
#
# VERSIONS - Must be set to a list with possible versions (subdirectories)
set -e
for dir in ${VERSIONS}; do
[ ! -e "${dir}/.image-id" ] && echo "-> Image for version $dir not built, skipping tag." && continue
pushd "${dir}" > /dev/null
IMAGE_ID=$(cat .image-id)
name=$(docker inspect -f "{{.Config.Labels.name}}" "$IMAGE_ID")
version=$(docker inspect -f "{{.Config.Labels.version}}" "$IMAGE_ID")
commit_date=$(git show -s HEAD --format=%cd --date=short | sed 's/-//g')
date_and_hash="${commit_date}-$(git rev-parse --short HEAD)"
echo "-> Tagging image '$IMAGE_ID' as '$name:$version' and '$name:latest' and '$name:$date_and_hash'"
docker tag "$IMAGE_ID" "$name:$version"
docker tag "$IMAGE_ID" "$name:latest"
docker tag "$IMAGE_ID" "$name:$date_and_hash"
for suffix in squashed raw; do
id_file=.image-id.$suffix
if test -f "$id_file"; then
docker tag "$(cat "$id_file")" "$name:$suffix" || rm .image-id."$suffix"
fi
done
popd > /dev/null
done

1278
common/test-lib-openshift.sh Normal file

File diff suppressed because it is too large Load diff

View file

@ -0,0 +1,107 @@
# shellcheck shell=bash
# some functions are used from test-lib.sh, that is usually in the same dir
# shellcheck source=/dev/null
source "$(dirname "${BASH_SOURCE[0]}")"/test-lib.sh
# Set of functions for testing docker images in OpenShift using 'oc' command
# A variable containing the overall test result; must be changed to 0 in the end
# of the testing script:
# OS_TESTSUITE_RESULT=0
# And the following trap must be set, in the beginning of the test script:
# trap ct_os_cleanup EXIT SIGINT
# ct_os_set_path_oc_4 OC_VERSION
# --------------------
# This is a trick that helps using correct version 4 of the `oc`:
# The input is version of the openshift in format 4.4 etc.
# If the currently available version of oc is not of this version,
# it first takes a look into /usr/local/oc-<ver>/bin directory,
# Arguments: oc_version - X.Y part of the version of OSE (e.g. 3.9)
function ct_os_set_path_oc_4() {
echo "Setting OCP4 client"
local oc_version=$1
local installed_oc_path="/usr/local/oc-v${oc_version}/bin"
echo "PATH ${installed_oc_path}"
if [ -x "${installed_oc_path}/oc" ] ; then
oc_path="${installed_oc_path}"
echo "Binary oc found in ${installed_oc_path}" >&2
else
echo "OCP4 not found"
return 1
fi
export PATH="${oc_path}:${PATH}"
oc version
if ! oc version | grep -q "Client Version: ${oc_version}." ; then
echo "ERROR: something went wrong, oc located at ${oc_path}, but oc of version ${oc_version} not found in PATH ($PATH)" >&1
return 1
else
echo "PATH set correctly, binary oc found in version ${oc_version}: $(command -v oc)"
fi
}
# ct_os_prepare_ocp4
# ------------------
# Prepares environment for testing images in OpenShift 4 environment
#
#
function ct_os_set_ocp4() {
local login
OS_OC_CLIENT_VERSION=${OS_OC_CLIENT_VERSION:-4.4}
ct_os_set_path_oc_4 "${OS_OC_CLIENT_VERSION}"
oc version
login=$(cat "$KUBEPASSWORD")
oc login -u kubeadmin -p "$login"
echo "Login to OpenShift ${OS_OC_CLIENT_VERSION} is DONE"
# let openshift cluster to sync to avoid some race condition errors
sleep 3
}
function ct_os_upload_image_external_registry() {
local input_name="${1}" ; shift
local image_name=${input_name##*/}
local imagestream=${1:-$image_name:latest}
local output_name
ct_os_login_external_registry
output_name="${INTERNAL_DOCKER_REGISTRY}/rhscl-ci-testing/$imagestream"
docker images
docker tag "${input_name}" "${output_name}"
docker push "${output_name}"
}
function ct_os_login_external_registry() {
local docker_token
# docker login fails with "404 page not found" error sometimes, just try it more times
# shellcheck disable=SC2034
echo "loging"
[ -z "${INTERNAL_DOCKER_REGISTRY:-}" ] && "INTERNAL_DOCKER_REGISTRY has to be set for working with Internal registry" && return 1
# shellcheck disable=SC2034
for i in $(seq 12) ; do
# shellcheck disable=SC2015
docker_token=$(cat "$DOCKER_UPSHIFT_TOKEN")
# shellcheck disable=SC2015
docker login -u rhscl-ci-testing -p "$docker_token" "${INTERNAL_DOCKER_REGISTRY}" && return 0 || :
sleep 5
done
return 1
}
function ct_os_import_image_ocp4() {
local image_name="${1}"; shift
local imagestream=${1:-$image_name:latest}
local namespace
namespace=${CT_NAMESPACE:-"$(oc project -q)"}
deploy_image_name="${INTERNAL_DOCKER_REGISTRY}/rhscl-ci-testing/${imagestream}"
echo "Uploading image ${image_name} as ${deploy_image_name} , ${imagestream} into external registry."
ct_os_upload_image_external_registry "${image_name}" "${imagestream}"
echo "Import image into OpenShift 4 environment "
oc import-image "${namespace}/${imagestream}" --from="${deploy_image_name}" --confirm --reference-policy=local
}

901
common/test-lib.sh Normal file
View file

@ -0,0 +1,901 @@
# shellcheck shell=bash
#
# Test a container image.
#
# Always use sourced from a specific container testfile
#
# reguires definition of CID_FILE_DIR
# CID_FILE_DIR=$(mktemp --suffix=<container>_test_cidfiles -d)
# reguires definition of TEST_LIST
# TEST_LIST="\
# ctest_container_creation
# ctest_doc_content"
# Container CI tests
# abbreviated as "ct"
# may be redefined in the specific container testfile
EXPECTED_EXIT_CODE=0
# ct_cleanup
# --------------------
# Cleans up containers used during tests. Stops and removes all containers
# referenced by cid_files in CID_FILE_DIR. Dumps logs if a container exited
# unexpectedly. Removes the cid_files and CID_FILE_DIR as well.
# Uses: $CID_FILE_DIR - path to directory containing cid_files
# Uses: $EXPECTED_EXIT_CODE - expected container exit code
function ct_cleanup() {
ct_show_resources
for cid_file in "$CID_FILE_DIR"/* ; do
local container
container=$(cat "$cid_file")
: "Stopping and removing container $container..."
docker stop "$container"
exit_status=$(docker inspect -f '{{.State.ExitCode}}' "$container")
if [ "$exit_status" != "$EXPECTED_EXIT_CODE" ]; then
: "Dumping logs for $container"
docker logs "$container"
fi
docker rm -v "$container"
rm "$cid_file"
done
rmdir "$CID_FILE_DIR"
: "Done."
}
# ct_enable_cleanup
# --------------------
# Enables automatic container cleanup after tests.
function ct_enable_cleanup() {
trap ct_cleanup EXIT SIGINT
}
# ct_check_envs_set env_filter check_envs loop_envs [env_format]
# --------------------
# Compares values from one list of environment variable definitions against such list,
# checking if the values are present and have a specific format.
# Argument: env_filter - optional string passed to grep used for
# choosing which variables to filter out in env var lists.
# Argument: check_envs - list of env var definitions to check values against
# Argument: loop_envs - list of env var definitions to check values for
# Argument: env_format (optional) - format string for bash substring deletion used
# for checking whether the value is contained in check_envs.
# Defaults to: "*VALUE*", VALUE string gets replaced by actual value from loop_envs
function ct_check_envs_set {
local env_filter check_envs env_format
env_filter=$1; shift
check_envs=$1; shift
loop_envs=$1; shift
env_format=${1:-"*VALUE*"}
while read -r variable; do
[ -z "$variable" ] && continue
var_name=$(echo "$variable" | awk -F= '{ print $1 }')
stripped=$(echo "$variable" | awk -F= '{ print $2 }')
filtered_envs=$(echo "$check_envs" | grep "^$var_name=")
[ -z "$filtered_envs" ] && { echo "$var_name not found during \` docker exec\`"; return 1; }
old_IFS=$IFS
# For each such variable compare its content with the `docker exec` result, use `:` as delimiter
IFS=:
for value in $stripped; do
# If the falue checked does not go through env_filter we do not care about it
echo "$value" | grep -q "$env_filter" || continue
if [ -n "${filtered_envs##${env_format//VALUE/$value}}" ]; then
echo " Value $value is missing from variable $var_name"
echo "$filtered_envs"
return 1
fi
done
done <<< "$(echo "$loop_envs" | grep "$env_filter" | grep -v "^PWD=")"
IFS=$old_IFS
}
# ct_get_cid [name]
# --------------------
# Prints container id from cid_file based on the name of the file.
# Argument: name - name of cid_file where the container id will be stored
# Uses: $CID_FILE_DIR - path to directory containing cid_files
function ct_get_cid() {
local name="$1" ; shift || return 1
cat "$CID_FILE_DIR/$name"
}
# ct_get_cip [id]
# --------------------
# Prints container ip address based on the container id.
# Argument: id - container id
function ct_get_cip() {
local id="$1" ; shift
docker inspect --format='{{.NetworkSettings.IPAddress}}' "$(ct_get_cid "$id")"
}
# ct_wait_for_cid [cid_file]
# --------------------
# Holds the execution until the cid_file is created. Usually run after container
# creation.
# Argument: cid_file - name of the cid_file that should be created
function ct_wait_for_cid() {
local cid_file=$1
local max_attempts=10
local sleep_time=1
local attempt=1
local result=1
while [ $attempt -le $max_attempts ]; do
[ -f "$cid_file" ] && [ -s "$cid_file" ] && return 0
: "Waiting for container start..."
attempt=$(( attempt + 1 ))
sleep $sleep_time
done
return 1
}
# ct_assert_container_creation_fails [container_args]
# --------------------
# The invocation of docker run should fail based on invalid container_args
# passed to the function. Returns 0 when container fails to start properly.
# Argument: container_args - all arguments are passed directly to dokcer run
# Uses: $CID_FILE_DIR - path to directory containing cid_files
function ct_assert_container_creation_fails() {
local ret=0
local max_attempts=10
local attempt=1
local cid_file=assert
set +e
local old_container_args="${CONTAINER_ARGS-}"
# we really work with CONTAINER_ARGS as with a string
# shellcheck disable=SC2124
CONTAINER_ARGS="$@"
if ct_create_container "$cid_file" ; then
local cid
cid=$(ct_get_cid "$cid_file")
while [ "$(docker inspect -f '{{.State.Running}}' "$cid")" == "true" ] ; do
sleep 2
attempt=$(( attempt + 1 ))
if [ "$attempt" -gt "$max_attempts" ]; then
docker stop "$cid"
ret=1
break
fi
done
exit_status=$(docker inspect -f '{{.State.ExitCode}}' "$cid")
if [ "$exit_status" == "0" ]; then
ret=1
fi
docker rm -v "$cid"
rm "$CID_FILE_DIR/$cid_file"
fi
[ -n "$old_container_args" ] && CONTAINER_ARGS="$old_container_args"
set -e
return "$ret"
}
# ct_create_container [name, command]
# --------------------
# Creates a container using the IMAGE_NAME and CONTAINER_ARGS variables. Also
# stores the container id to a cid_file located in the CID_FILE_DIR, and waits
# for the creation of the file.
# Argument: name - name of cid_file where the container id will be stored
# Argument: command - optional command to be executed in the container
# Uses: $CID_FILE_DIR - path to directory containing cid_files
# Uses: $CONTAINER_ARGS - optional arguments passed directly to docker run
# Uses: $IMAGE_NAME - name of the image being tested
function ct_create_container() {
local cid_file="$CID_FILE_DIR/$1" ; shift
# create container with a cidfile in a directory for cleanup
# shellcheck disable=SC2086
docker run --cidfile="$cid_file" -d ${CONTAINER_ARGS:-} "$IMAGE_NAME" "$@"
ct_wait_for_cid "$cid_file" || return 1
: "Created container $(cat "$cid_file")"
}
# ct_scl_usage_old [name, command, expected]
# --------------------
# Tests three ways of running the SCL, by looking for an expected string
# in the output of the command
# Argument: name - name of cid_file where the container id will be stored
# Argument: command - executed inside the container
# Argument: expected - string that is expected to be in the command output
# Uses: $CID_FILE_DIR - path to directory containing cid_files
# Uses: $IMAGE_NAME - name of the image being tested
function ct_scl_usage_old() {
local name="$1"
local command="$2"
local expected="$3"
local out=""
: " Testing the image SCL enable"
out=$(docker run --rm "${IMAGE_NAME}" /bin/bash -c "${command}")
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[/bin/bash -c \"${command}\"] Expected '${expected}', got '${out}'" >&2
return 1
fi
out=$(docker exec "$(ct_get_cid "$name")" /bin/bash -c "${command}" 2>&1)
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[exec /bin/bash -c \"${command}\"] Expected '${expected}', got '${out}'" >&2
return 1
fi
out=$(docker exec "$(ct_get_cid "$name")" /bin/sh -ic "${command}" 2>&1)
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[exec /bin/sh -ic \"${command}\"] Expected '${expected}', got '${out}'" >&2
return 1
fi
}
# ct_doc_content_old [strings]
# --------------------
# Looks for occurence of stirngs in the documentation files and checks
# the format of the files. Files examined: help.1
# Argument: strings - strings expected to appear in the documentation
# Uses: $IMAGE_NAME - name of the image being tested
function ct_doc_content_old() {
local tmpdir
tmpdir=$(mktemp -d)
local f
: " Testing documentation in the container image"
# Extract the help files from the container
# shellcheck disable=SC2043
for f in help.1 ; do
docker run --rm "${IMAGE_NAME}" /bin/bash -c "cat /${f}" >"${tmpdir}/$(basename "${f}")"
# Check whether the files contain some important information
for term in "$@" ; do
if ! grep -F -q -e "${term}" "${tmpdir}/$(basename "${f}")" ; then
echo "ERROR: File /${f} does not include '${term}'." >&2
return 1
fi
done
# Check whether the files use the correct format
for term in TH PP SH ; do
if ! grep -q "^\.${term}" "${tmpdir}/help.1" ; then
echo "ERROR: /help.1 is probably not in troff or groff format, since '${term}' is missing." >&2
return 1
fi
done
done
: " Success!"
}
# full_ca_file_path
# Return string for full path to CA file
function full_ca_file_path()
{
echo "/etc/pki/ca-trust/source/anchors/RH-IT-Root-CA.crt"
}
# ct_mount_ca_file
# ------------------
# Check if /etc/pki/certs/RH-IT-Root-CA.crt file exists
# return mount string for containers or empty string
function ct_mount_ca_file()
{
# mount CA file only if NPM_REGISTRY variable is present.
local mount_parameter=""
if [ -n "$NPM_REGISTRY" ] && [ -f "$(full_ca_file_path)" ]; then
mount_parameter="-v $(full_ca_file_path):$(full_ca_file_path):Z"
fi
echo "$mount_parameter"
}
# ct_build_s2i_npm_variables URL_TO_NPM_JS_SERVER
# ------------------------------------------
# Function returns -e NPM_MIRROR and -v MOUNT_POINT_FOR_CAFILE
# or empty string
function ct_build_s2i_npm_variables()
{
npm_variables=""
if [ -n "$NPM_REGISTRY" ] && [ -f "$(full_ca_file_path)" ]; then
npm_variables="-e NPM_MIRROR=$NPM_REGISTRY $(ct_mount_ca_file)"
fi
echo "$npm_variables"
}
# ct_npm_works
# --------------------
# Checks existance of the npm tool and runs it.
function ct_npm_works() {
local tmpdir
tmpdir=$(mktemp -d)
: " Testing npm in the container image"
local cid_file="${tmpdir}/cid"
if ! docker run --rm "${IMAGE_NAME}" /bin/bash -c "npm --version" >"${tmpdir}/version" ; then
echo "ERROR: 'npm --version' does not work inside the image ${IMAGE_NAME}." >&2
return 1
fi
# shellcheck disable=SC2046
docker run -d $(ct_mount_ca_file) --rm --cidfile="$cid_file" "${IMAGE_NAME}-testapp"
# Wait for the container to write it's CID file
ct_wait_for_cid "$cid_file" || return 1
if ! docker exec "$(cat "$cid_file")" /bin/bash -c "npm --verbose install jquery && test -f node_modules/jquery/src/jquery.js" >"${tmpdir}/jquery" 2>&1 ; then
echo "ERROR: npm could not install jquery inside the image ${IMAGE_NAME}." >&2
return 1
fi
if [ -n "$NPM_REGISTRY" ] && [ -f "$(full_ca_file_path)" ]; then
if ! grep -qo "$NPM_REGISTRY" "${tmpdir}/jquery"; then
echo "ERROR: Internal repository is NOT set. Even it is requested."
return 1
fi
fi
if [ -f "$cid_file" ]; then
docker stop "$(cat "$cid_file")"
rm "$cid_file"
fi
: " Success!"
}
# ct_binary_found_from_df binary [path]
# --------------------
# Checks if a binary can be found in PATH during Dockerfile build
# Argument: binary - name of the binary to test accessibility for
# Argument: path - optional path in which the binary should reside in
# /opt/rh by default
function ct_binary_found_from_df() {
local tmpdir
local binary=$1; shift
local binary_path=${1:-"^/opt/rh"}
tmpdir=$(mktemp -d)
: " Testing $binary in build from Dockerfile"
# Create Dockerfile that looks for the binary
cat <<EOF >"$tmpdir/Dockerfile"
FROM $IMAGE_NAME
RUN which $binary | grep "$binary_path"
EOF
# Build an image, looking for expected path in the output
if ! docker build -f "$tmpdir/Dockerfile" --no-cache "$tmpdir"; then
echo " ERROR: Failed to find $binary in Dockerfile!" >&2
return 1
fi
: " Success!"
}
# ct_check_exec_env_vars [env_filter]
# --------------------
# Checks if all relevant environment variables from `docker run`
# can be found in `docker exec` as well.
# Argument: env_filter - optional string passed to grep used for
# choosing which variables to check in the test case.
# Defaults to X_SCLS and variables containing /opt/app-root, /opt/rh
# Uses: $CID_FILE_DIR - path to directory containing cid_files
# Uses: $IMAGE_NAME - name of the image being tested
function ct_check_exec_env_vars() {
local tmpdir exec_envs cid old_IFS env_filter
local var_name stripped filtered_envs run_envs
env_filter=${1:-"^X_SCLS=\|/opt/rh\|/opt/app-root"}
tmpdir=$(mktemp -d)
CID_FILE_DIR=${CID_FILE_DIR:-$(mktemp -d)}
# Get environment variables from `docker run`
run_envs=$(docker run --rm "$IMAGE_NAME" /bin/bash -c "env")
# Get environment variables from `docker exec`
ct_create_container "test_exec_envs" bash -c "sleep 1000" >/dev/null
cid=$(ct_get_cid "test_exec_envs")
exec_envs=$(docker exec "$cid" env)
# Filter out variables we are not interested in
# Always check X_SCLS, ignore PWD
# Check variables from `docker run` that have alternative paths inside (/opt/rh, /opt/app-root)
ct_check_envs_set "$env_filter" "$exec_envs" "$run_envs" "*VALUE*" || return 1
echo " All values present in \`docker exec\`"
return 0
}
# ct_check_scl_enable_vars [env_filter]
# --------------------
# Checks if all relevant environment variables from `docker run`
# are set twice after a second call of `scl enable $SCLS`.
# Argument: env_filter - optional string passed to grep used for
# choosing which variables to check in the test case.
# Defaults to paths containing enabled SCLS in the image
# Uses: $IMAGE_NAME - name of the image being tested
function ct_check_scl_enable_vars() {
local tmpdir exec_envs cid old_IFS env_filter enabled_scls
local var_name stripped filtered_envs loop_envs
env_filter=$1
tmpdir=$(mktemp -d)
enabled_scls=$(docker run --rm "$IMAGE_NAME" /bin/bash -c "echo \$X_SCLS")
if [ -z "$env_filter" ]; then
for scl in $enabled_scls; do
[ -z "$env_filter" ] && env_filter="/$scl" && continue
# env_filter not empty, append to the existing list
env_filter="$env_filter|/$scl"
done
fi
# Get environment variables from `docker run`
loop_envs=$(docker run --rm "$IMAGE_NAME" /bin/bash -c "env")
run_envs=$(docker run --rm "$IMAGE_NAME" /bin/bash -c "X_SCLS= scl enable $enabled_scls env")
# Check if the values are set twice in the second set of envs
ct_check_envs_set "$env_filter" "$run_envs" "$loop_envs" "*VALUE*VALUE*" || return 1
echo " All scl_enable values present"
return 0
}
# ct_path_append PATH_VARNAME DIRECTORY
# -------------------------------------
# Append DIRECTORY to VARIABLE of name PATH_VARNAME, the VARIABLE must consist
# of colon-separated list of directories.
ct_path_append ()
{
if eval "test -n \"\${$1-}\""; then
eval "$1=\$2:\$$1"
else
eval "$1=\$2"
fi
}
# ct_path_foreach PATH ACTION [ARGS ...]
# --------------------------------------
# For each DIR in PATH execute ACTION (path is colon separated list of
# directories). The particular calls to ACTION will look like
# '$ ACTION directory [ARGS ...]'
ct_path_foreach ()
{
local dir dirlist action save_IFS
save_IFS=$IFS
IFS=:
dirlist=$1
action=$2
shift 2
for dir in $dirlist; do "$action" "$dir" "$@" ; done
IFS=$save_IFS
}
# ct_run_test_list
# --------------------
# Execute the tests specified by TEST_LIST
# Uses: $TEST_LIST - list of test names
function ct_run_test_list() {
for test_case in $TEST_LIST; do
: "Running test $test_case"
# shellcheck source=/dev/null
[ -f "test/$test_case" ] && source "test/$test_case"
# shellcheck source=/dev/null
[ -f "../test/$test_case" ] && source "../test/$test_case"
$test_case
done;
}
# ct_gen_self_signed_cert_pem
# ---------------------------
# Generates a self-signed PEM certificate pair into specified directory.
# Argument: output_dir - output directory path
# Argument: base_name - base name of the certificate files
# Resulted files will be those:
# <output_dir>/<base_name>-cert-selfsigned.pem -- public PEM cert
# <output_dir>/<base_name>-key.pem -- PEM private key
ct_gen_self_signed_cert_pem() {
local output_dir=$1 ; shift
local base_name=$1 ; shift
mkdir -p "${output_dir}"
openssl req -newkey rsa:2048 -nodes -keyout "${output_dir}"/"${base_name}"-key.pem -subj '/C=GB/ST=Berkshire/L=Newbury/O=My Server Company' > "${base_name}"-req.pem
openssl req -new -x509 -nodes -key "${output_dir}"/"${base_name}"-key.pem -batch > "${output_dir}"/"${base_name}"-cert-selfsigned.pem
}
# ct_obtain_input FILE|DIR|URL
# --------------------
# Either copies a file or a directory to a tmp location for local copies, or
# downloads the file from remote location.
# Resulted file path is printed, so it can be later used by calling function.
# Arguments: input - local file, directory or remote URL
function ct_obtain_input() {
local input=$1
local extension="${input##*.}"
# Try to use same extension for the temporary file if possible
[[ "${extension}" =~ ^[a-z0-9]*$ ]] && extension=".${extension}" || extension=""
local output
output=$(mktemp "/var/tmp/test-input-XXXXXX$extension")
if [ -f "${input}" ] ; then
cp -f "${input}" "${output}"
elif [ -d "${input}" ] ; then
rm -f "${output}"
cp -r -LH "${input}" "${output}"
elif echo "${input}" | grep -qe '^http\(s\)\?://' ; then
curl "${input}" > "${output}"
else
echo "ERROR: file type not known: ${input}" >&2
return 1
fi
echo "${output}"
}
# ct_test_response
# ----------------
# Perform GET request to the application container, checks output with
# a reg-exp and HTTP response code.
# Argument: url - request URL path
# Argument: expected_code - expected HTTP response code
# Argument: body_regexp - PCRE regular expression that must match the response body
# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between
# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10)
ct_test_response() {
local url="$1"
local expected_code="$2"
local body_regexp="$3"
local max_attempts=${4:-20}
local ignore_error_attempts=${5:-10}
: " Testing the HTTP(S) response for <${url}>"
local sleep_time=3
local attempt=1
local result=1
local status
local response_code
local response_file
response_file=$(mktemp /tmp/ct_test_response_XXXXXX)
while [ "${attempt}" -le "${max_attempts}" ]; do
curl --connect-timeout 10 -s -w '%{http_code}' "${url}" >"${response_file}" && status=0 || status=1
if [ "${status}" -eq 0 ]; then
response_code=$(tail -c 3 "${response_file}")
if [ "${response_code}" -eq "${expected_code}" ]; then
result=0
fi
grep -qP -e "${body_regexp}" "${response_file}" || result=1;
# Some services return 40x code until they are ready, so let's give them
# some chance and not end with failure right away
# Do not wait if we already have expected outcome though
if [ "${result}" -eq 0 ] || [ "${attempt}" -gt "${ignore_error_attempts}" ] || [ "${attempt}" -eq "${max_attempts}" ] ; then
break
fi
fi
attempt=$(( attempt + 1 ))
sleep "${sleep_time}"
done
rm -f "${response_file}"
return "${result}"
}
# ct_registry_from_os OS
# ----------------
# Transform operating system string [os] into registry url
# Argument: OS - string containing the os version
ct_registry_from_os() {
local registry=""
case $1 in
rhel*)
registry=registry.redhat.io
;;
*)
registry=docker.io
;;
esac
echo "$registry"
}
# ct_get_public_image_name OS BASE_IMAGE_NAME VERSION
# ----------------
# Transform the arguments into public image name
# Argument: OS - string containing the os version
# Argument: BASE_IMAGE_NAME - string containing the base name of the image as defined in the Makefile
# Argument: VERSION - string containing the version of the image as defined in the Makefile
ct_get_public_image_name() {
local os=$1; shift
local base_image_name=$1; shift
local version=$1; shift
local public_image_name
local registry
registry=$(ct_registry_from_os "$os")
if [ "x$os" == "xrhel7" ]; then
public_image_name=$registry/rhscl/$base_image_name-${version//./}-rhel7
elif [ "x$os" == "xrhel8" ]; then
public_image_name=$registry/rhel8/$base_image_name-${version//./}
elif [ "x$os" == "xcentos7" ]; then
public_image_name=$registry/centos/$base_image_name-${version//./}-centos7
elif [ "x$os" == "xcentos8" ]; then
public_image_name=$registry/centos/$base_image_name-${version//./}-centos8
fi
echo "$public_image_name"
}
# ct_assert_cmd_success CMD
# ----------------
# Evaluates [cmd] and fails if it does not succeed.
# Argument: CMD - Command to be run
function ct_assert_cmd_success() {
echo "Checking '$*' for success ..."
if ! eval "$@" &>/dev/null; then
echo " FAIL"
return 1
fi
echo " PASS"
return 0
}
# ct_assert_cmd_failure CMD
# ----------------
# Evaluates [cmd] and fails if it succeeds.
# Argument: CMD - Command to be run
function ct_assert_cmd_failure() {
echo "Checking '$*' for failure ..."
if eval "$@" &>/dev/null; then
echo " FAIL"
return 1
fi
echo " PASS"
return 0
}
# ct_random_string [LENGTH=10]
# ----------------------------
# Generate pseudorandom alphanumeric string of LENGTH bytes, the
# default length is 10. The string is printed on stdout.
ct_random_string()
(
export LC_ALL=C
dd if=/dev/urandom count=1 bs=10k 2>/dev/null \
| tr -dc 'a-z0-9' \
| fold -w "${1-10}" \
| head -n 1
)
# ct_s2i_usage IMG_NAME [S2I_ARGS]
# ----------------------------
# Create a container and run the usage script inside
# Argument: IMG_NAME - name of the image to be used for the container run
# Argument: S2I_ARGS - Additional list of source-to-image arguments, currently unused.
ct_s2i_usage()
{
local img_name=$1; shift
local s2i_args="$*";
local usage_command="/usr/libexec/s2i/usage"
docker run --rm "$img_name" bash -c "$usage_command"
}
# ct_s2i_build_as_df APP_PATH SRC_IMAGE DST_IMAGE [S2I_ARGS]
# ----------------------------
# Create a new s2i app image from local sources in a similar way as source-to-image would have used.
# Argument: APP_PATH - local path to the app sources to be used in the test
# Argument: SRC_IMAGE - image to be used as a base for the s2i build
# Argument: DST_IMAGE - image name to be used during the tagging of the s2i build result
# Argument: S2I_ARGS - Additional list of source-to-image arguments.
# Only used to check for pull-policy=never and environment variable definitions.
ct_s2i_build_as_df()
{
local app_path=$1; shift
local src_image=$1; shift
local dst_image=$1; shift
local s2i_args="$*";
local local_app=upload/src/
local local_scripts=upload/scripts/
local user_id=
local df_name=
local tmpdir=
local incremental=false
local mount_options=""
# Run the entire thing inside a subshell so that we do not leak shell options outside of the function
(
# Error out if any part of the build fails
set -e
# Use /tmp to not pollute cwd
tmpdir=$(mktemp -d)
df_name=$(mktemp -p "$tmpdir" Dockerfile.XXXX)
cd "$tmpdir"
# Check if the image is available locally and try to pull it if it is not
docker images "$src_image" &>/dev/null || echo "$s2i_args" | grep -q "pull-policy=never" || docker pull "$src_image"
user=$(docker inspect -f "{{.Config.User}}" "$src_image")
# Default to root if no user is set by the image
user=${user:-0}
# run the user through the image in case it is non-numeric or does not exist
# NOTE: The '-eq' test is used to check if $user is numeric as it will fail if $user is not an integer
if ! [ "$user" -eq "$user" ] 2>/dev/null && ! user_id=$(docker run --rm "$src_image" bash -c "id -u $user 2>/dev/null"); then
echo "ERROR: id of user $user not found inside image $src_image."
echo "Terminating s2i build."
return 1
else
user_id=${user_id:-$user}
fi
echo "$s2i_args" | grep -q "\-\-incremental" && incremental=true
if $incremental; then
inc_tmp=$(mktemp -d --tmpdir incremental.XXXX)
setfacl -m "u:$user_id:rwx" "$inc_tmp"
# Check if the image exists, build should fail (for testing use case) if it does not
docker images "$dst_image" &>/dev/null || (echo "Image $dst_image not found."; false)
# Run the original image with a mounted in volume and get the artifacts out of it
cmd="if [ -s /usr/libexec/s2i/save-artifacts ]; then /usr/libexec/s2i/save-artifacts > \"$inc_tmp/artifacts.tar\"; else touch \"$inc_tmp/artifacts.tar\"; fi"
docker run --rm -v "$inc_tmp:$inc_tmp:Z" "$dst_image" bash -c "$cmd"
# Move the created content into the $tmpdir for the build to pick it up
mv "$inc_tmp/artifacts.tar" "$tmpdir/"
fi
# Strip file:// from APP_PATH and copy its contents into current context
mkdir -p "$local_app"
cp -r "${app_path/file:\/\//}/." "$local_app"
[ -d "$local_app/.s2i/bin/" ] && mv "$local_app/.s2i/bin" "$local_scripts"
# Create a Dockerfile named df_name and fill it with proper content
#FIXME: Some commands could be combined into a single layer but not sure if worth the trouble for testing purposes
cat <<EOF >"$df_name"
FROM $src_image
LABEL "io.openshift.s2i.build.image"="$src_image" \\
"io.openshift.s2i.build.source-location"="$app_path"
USER root
COPY $local_app /tmp/src
EOF
[ -d "$local_scripts" ] && echo "COPY $local_scripts /tmp/scripts" >> "$df_name" &&
echo "RUN chown -R $user_id:0 /tmp/scripts" >>"$df_name"
echo "RUN chown -R $user_id:0 /tmp/src" >>"$df_name"
# Check for custom environment variables inside .s2i/ folder
if [ -e "$local_app/.s2i/environment" ]; then
# Remove any comments and add the contents as ENV commands to the Dockerfile
sed '/^\s*#.*$/d' "$local_app/.s2i/environment" | while read -r line; do
echo "ENV $line" >>"$df_name"
done
fi
# Filter out env var definitions from $s2i_args and create Dockerfile ENV commands out of them
echo "$s2i_args" | grep -o -e '\(-e\|--env\)[[:space:]=]\S*=\S*' | sed -e 's/-e /ENV /' -e 's/--env[ =]/ENV /' >>"$df_name"
# Check if CA autority is present on host and add it into Dockerfile
[ -f "$(full_ca_file_path)" ] && echo "RUN cd /etc/pki/ca-trust/source/anchors && update-ca-trust extract" >>"$df_name"
# Add in artifacts if doing an incremental build
if $incremental; then
{ echo "RUN mkdir /tmp/artifacts"
echo "ADD artifacts.tar /tmp/artifacts"
echo "RUN chown -R $user_id:0 /tmp/artifacts" ; } >>"$df_name"
fi
echo "USER $user_id" >>"$df_name"
# If exists, run the custom assemble script, else default to /usr/libexec/s2i/assemble
if [ -x "$local_scripts/assemble" ]; then
echo "RUN /tmp/scripts/assemble" >>"$df_name"
else
echo "RUN /usr/libexec/s2i/assemble" >>"$df_name"
fi
# If exists, set the custom run script as CMD, else default to /usr/libexec/s2i/run
if [ -x "$local_scripts/run" ]; then
echo "CMD /tmp/scripts/run" >>"$df_name"
else
echo "CMD /usr/libexec/s2i/run" >>"$df_name"
fi
# Check if -v parameter is present in s2i_args and add it into docker build command
mount_options=$(echo "$s2i_args" | grep -o -e '\(-v\)[[:space:]]\.*\S*' || true)
# Run the build and tag the result
# shellcheck disable=SC2086
docker build $mount_options -f "$df_name" --no-cache=true -t "$dst_image" .
)
}
# ct_check_image_availability PUBLIC_IMAGE_NAME
# ----------------------------
# Pull an image from the public repositories to see if the image is already available.
# Argument: PUBLIC_IMAGE_NAME - string containing the public name of the image to pull
ct_check_image_availability() {
local public_image_name=$1;
# Try pulling the image to see if it is accessible
if ! docker pull "$public_image_name" &>/dev/null; then
echo "$public_image_name could not be downloaded via 'docker'"
return 1
fi
}
# ct_check_latest_imagestreams
# -----------------------------
# Check if the latest version present in Makefile in the variable VERSIONS
# is present in all imagestreams.
# Also the latest tag in the imagestreams has to contain the latest version
ct_check_latest_imagestreams() {
local latest_version=
local test_lib_dir=
# We only maintain imagestreams for RHEL and CentOS (Community)
if [[ "$OS" =~ ^fedora.* ]] ; then
echo "Imagestreams for Fedora are not maintained, skipping ct_check_latest_imagestreams"
return 0
fi
# Check only lines which starts with VERSIONS
latest_version=$(grep '^VERSIONS' Makefile | rev | cut -d ' ' -f 1 | rev )
# Fall back to previous version if the latest is excluded for this OS
[ -f "$latest_version/.exclude-$OS" ] && latest_version=$(grep '^VERSIONS' Makefile | rev | cut -d ' ' -f 2 | rev )
# Only test the imagestream once, when the version matches
# ignore the SC warning, $VERSION is always available
# shellcheck disable=SC2153
if [ "$latest_version" == "$VERSION" ]; then
test_lib_dir=$(dirname "$(readlink -f "$0")")
python3 "${test_lib_dir}/check_imagestreams.py" "$latest_version"
else
echo "Image version $VERSION is not latest, skipping ct_check_latest_imagestreams"
fi
}
# ct_show_resources
# ----------------
# Prints the available resources
ct_show_resources()
{
echo "Resources info:"
echo "Memory:"
free -h
echo "Storage:"
df -h
echo "CPU"
lscpu
}
# ct_test_app_dockerfile
# -----------------------------
# Argument: dockerfile - path to a Dockerfile that will be used for building an image
# (must work with an application directory called 'app-src')
# Argument: app_url - git URI with a testing application
# Argument: body_regexp - PCRE regular expression that must match the response body
# Argument: app_dir - name of the application directory that is used in the Dockerfile
# Argument: port - Optional port number (default: 8080)
ct_test_app_dockerfile() {
local dockerfile=$1
local app_url=$2
local expected_text=$3
local app_dir=$4 # this is a directory that must match with the name in the Dockerfile
local port=${5:-8080}
local app_image_name=myapp
local ret
local cname=app_dockerfile
if [ -z "$app_dir" ] ; then
echo "ERROR: Option app_dir not set. Terminating the Dockerfile build."
return 1
fi
if ! [ -r "${dockerfile}" ] || ! [ -s "${dockerfile}" ] ; then
echo "ERROR: Dockerfile ${dockerfile} does not exist or is empty."
echo "Terminating the Dockerfile build."
return 1
fi
CID_FILE_DIR=${CID_FILE_DIR:-$(mktemp -d)}
local dockerfile_abs
dockerfile_abs=$(readlink -f "${dockerfile}")
tmpdir=$(mktemp -d)
pushd "$tmpdir" >/dev/null
cp "${dockerfile_abs}" Dockerfile
# Rewrite the source image to what we test
sed -i -e "s|^FROM.*$|FROM $IMAGE_NAME|" Dockerfile
# a bit more verbose, but should help debugging failures
echo "Using this Dockerfile:"
cat Dockerfile
if ! git clone "${app_url}" "${app_dir}" ; then
echo "ERROR: Git repository ${app_url} cannot be cloned into ${app_dir}."
echo "Terminating the Dockerfile build."
return 1
fi
echo "Building '${app_image_name}' image using docker build"
if ! docker build --no-cache=true -t "${app_image_name}" . ; then
echo "ERROR: The image cannot be built from ${dockerfile} and application ${app_url}."
echo "Terminating the Dockerfile build."
return 1
fi
if ! docker run -d --cidfile="${CID_FILE_DIR}/app_dockerfile" --rm "${app_image_name}" ; then
echo "ERROR: The image ${app_image_name} cannot be run for ${dockerfile} and application ${app_url}."
echo "Terminating the Dockerfile build."
return 1
fi
echo "Waiting for ${app_image_name} to start"
ct_wait_for_cid "${CID_FILE_DIR}/app_dockerfile"
ip="$(ct_get_cip "${cname}")"
ct_test_response "http://$ip:${port}" 200 "${expected_text}"
ret=$?
# cleanup
docker kill "$(ct_get_cid "${cname}")"
sleep 2
docker rmi "${app_image_name}"
popd >/dev/null
rm -rf "${tmpdir}"
rm -f "${CID_FILE_DIR}/${cname}"
return $ret
}
# vim: set tabstop=2:shiftwidth=2:expandtab:

38
common/test-remote-cluster.sh Executable file
View file

@ -0,0 +1,38 @@
#!/bin/bash
# This script is used to test container images integrated in the OpenShift.
#
# VERSIONS - Must be set to a list with possible versions (subdirectories)
#
# This script expects oc command to exist and logged in to a working cluster.
set -e
export OS=${OS:-rhel7}
if [ "${OS}" == "rhel7" ] ; then
NAMESPACE=${NAMESPACE:-rhscl/}
REGISTRY=${REGISTRY:-registry.access.redhat.com/}
else
NAMESPACE=${NAMESPACE:-centos/}
fi
export NAMESPACE
export REGISTRY
for dir in ${VERSIONS}; do
[ ! -e "${dir}/.image-id" ] && echo "-> Image for version $dir not built, skipping OpenShift 4 tests." && continue
pushd "${dir}" > /dev/null
export IMAGE_NAME="${NAMESPACE}${BASE_IMAGE_NAME}-${dir//./}-${OS}"
if [[ -x test/run-openshift-remote-cluster ]]; then
VERSION="${dir}" test/run-openshift-remote-cluster
else
echo "-> Tests for OpenShift 4 are not present. Add run-openshift-remote-cluster script, skipping"
fi
popd > /dev/null
done
# vim: set tabstop=2:shiftwidth=2:expandtab:

67
common/test.sh Executable file
View file

@ -0,0 +1,67 @@
#!/bin/bash
# This script is used to test the OpenShift Docker images.
#
# TEST_MODE - If set, run regular test suite
# TEST_OPENSHIFT_MODE - If set, run OpenShift tests (if present)
# VERSIONS - Must be set to a list with possible versions (subdirectories)
set -e
for dir in ${VERSIONS}; do
[ ! -e "${dir}/.image-id" ] && echo "-> Image for version $dir not built, skipping tests." && continue
pushd "${dir}" > /dev/null
IMAGE_ID=$(cat .image-id)
export IMAGE_ID
IMAGE_VERSION=$(docker inspect -f "{{.Config.Labels.version}}" "$IMAGE_ID")
# Kept also IMAGE_NAME as some tests might still use that.
IMAGE_NAME="$(docker inspect -f "{{.Config.Labels.name}}" "$IMAGE_ID"):$IMAGE_VERSION"
export IMAGE_NAME
if [ -n "${TEST_MODE}" ]; then
VERSION=$dir test/run
fi
if [ -n "${TEST_CONU_MODE}" ]; then
if [[ -x test/run-conu ]]; then
if [ -n "${CONU_IMAGE}" ]; then
echo "-> Running conu tests in a container"
docker run \
--net=host \
-e VERSION="${dir}" \
-e IMAGE_NAME \
--rm \
--security-opt label=disable \
-ti \
-v /var/run/docker.sock:/var/run/docker.sock \
-v "${PWD}"/../:/src \
-w "/src/${dir}/" \
-ti \
"${CONU_IMAGE}" \
./test/run-conu
else
VERSION="${dir}" ./test/run-conu
fi
else
echo "-> conu tests are not present, skipping"
fi
fi
if [ -n "${TEST_OPENSHIFT_4}" ]; then
if [[ -x test/run-openshift-remote-cluster ]]; then
VERSION=$dir test/run-openshift-remote-cluster
else
echo "-> Tests for OpenShift 4 are not present. Add run-openshift-remote-cluster script, skipping"
fi
fi
if [ -n "${TEST_OPENSHIFT_MODE}" ]; then
if [[ -x test/run-openshift ]]; then
VERSION=$dir test/run-openshift
else
echo "-> OpenShift 3 tests are not present, skipping"
fi
fi
popd > /dev/null
done

3
common/tests/.gitignore vendored Normal file
View file

@ -0,0 +1,3 @@
.image-id*
help.1
check_imagestreams.py

View file

@ -0,0 +1,9 @@
#!/bin/sh
set -x
check_imagestreams=$(dirname "$(readlink -f "$0")")/../check_imagestreams.py
"${PYTHON-python3}" "$check_imagestreams" "2.5"
test $? -eq 1
"${PYTHON-python3}" "$check_imagestreams" "2.4"
test $? -eq 0

View file

@ -0,0 +1,4 @@
# Variables are documented in common/build.sh.
BASE_IMAGE_NAME = test-container
VERSIONS = v0
include common/common.mk

View file

@ -0,0 +1 @@
../../..

View file

@ -0,0 +1,2 @@
FROM centos/s2i-core-centos7
LABEL name=test-image

View file

@ -0,0 +1 @@
This is just no-op-build container.

View file

@ -0,0 +1,3 @@
#! /bin/sh -x
false this must fail the whole testsuite

View file

@ -0,0 +1,53 @@
{
"apiVersion": "v1",
"kind": "ImageStream",
"metadata": {
"annotations": {
"openshift.io/display-name": "Apache HTTP Server (httpd)"
},
"name": "httpd"
},
"spec": {
"tags": [
{
"annotations": {
"description": "Build and serve static content via Apache HTTP Server (httpd) on RHEL 7. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/httpd-container/blob/master/2.4/README.md.\n\nWARNING: By selecting this tag, your application will automatically update to use the latest version of Httpd available on OpenShift, including major version updates.",
"iconClass": "icon-apache",
"openshift.io/display-name": "Apache HTTP Server (Latest)",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"sampleRepo": "https://github.com/sclorg/httpd-ex.git",
"supports": "httpd",
"tags": "builder,httpd"
},
"from": {
"kind": "ImageStreamTag",
"name": "2.4"
},
"referencePolicy": {
"type": "Local"
},
"name": "latest"
},
{
"annotations": {
"description": "Build and serve static content via Apache HTTP Server (httpd) 2.4 on RHEL 7. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/httpd-container/blob/master/2.4/README.md.",
"iconClass": "icon-apache",
"openshift.io/display-name": "Apache HTTP Server 2.4",
"openshift.io/provider-display-name": "Red Hat, Inc.",
"sampleRepo": "https://github.com/sclorg/httpd-ex.git",
"supports": "httpd",
"tags": "builder,httpd",
"version": "2.4"
},
"from": {
"kind": "DockerImage",
"name": "registry.redhat.io/rhscl/httpd-24-rhel7"
},
"referencePolicy": {
"type": "Local"
},
"name": "2.4"
}
]
}
}

103
common/tests/remote-containers.sh Executable file
View file

@ -0,0 +1,103 @@
#! /bin/bash
set -e
declare -A IMAGES
for image in ${TESTED_IMAGES}; do
IMAGES[$image]=master
done
OS=centos7
MERGE_INTO=origin/master
# This is the Fedora default, some users' boxes have more strict
# defaults (e.g. 0077).
umask 0022
die () { echo >&2 " # FATAL: $*"; exit 1; }
info () { echo " * $*"; }
error () { echo >&2 " # ERROR: $*"; }
test -f common.mk -a -f build.sh -a -d .git \
|| die "Doesn't seem to be run from common's git directory"
analyse_commits ()
{
# TODO: If we wanted to test "after PR merge", this needs to take some
# argument specifying how long we should look in the commit history.
git merge-base --is-ancestor "$MERGE_INTO" HEAD \
|| die "Please rebase the commit '$(git rev-parse --short HEAD)'" \
"to allow --ff merge into '$MERGE_INTO' branch"
while read line; do
case $line in
Required-by:\ *)
set -- $line
old_IFS=$IFS
IFS=\#
set -- $2
IFS=$old_IFS
set -- $1 $2
info "PR commits ask for testing $1 from PR $2"
IMAGES[$1]=$2
;;
esac
done < <(git log --format=%B --reverse "$MERGE_INTO"..HEAD)
}
analyse_commits
for image in "${!IMAGES[@]}"; do
# We don't want to remove user's WIP stuff.
test -e "$image" && die "directory '$image' exists"
( set -e
testdir=$PWD
cleanup () {
set -x
# Ensure the cleanup finishes!
trap '' INT
# Go back, wherever we are.
cd "$testdir"
# Try to cleanup, if available (and if needed).
make clean -C "$image" || :
# Drop the image sources.
test ! -d "$image" || rm -rf "$image"
}
trap cleanup EXIT
info "Testing $image image"
# Use --recursive even if we remove 'common', because there might be
# other git submodules which need to be tested.
git clone --recursive -q https://github.com/sclorg/"$image".git
cd "$image"
revision=${IMAGES[$image]}
if ! test "$revision" = master; then
info "Fetching $image PR $revision"
git fetch origin "pull/$revision/head":PR_BRANCH
git checkout PR_BRANCH
git submodule update
fi
# We fail if the 'common' directory doesn't exist.
test -d common
rm -rf common
info "Replacing common with PR's version"
ln -s ../ common
# TODO: Do we have to test all $(VERSION)s?
# TODO: The PS4 hack doesn't work if we run the testsuite as UID=0.
PS4="+ [$image] " make TARGET="$OS" test
# Cleanup.
make clean
)
if test $? -ne 0; then
die "Tests for $image failed"
fi
done

1
common/tests/squash/.gitignore vendored Normal file
View file

@ -0,0 +1 @@
Dockerfile

24
common/tests/squash/squash.sh Executable file
View file

@ -0,0 +1,24 @@
#! /bin/sh
set -e
if grep -q "Red Hat Enterprise Linux release 8" /etc/system-release; then
# No use testing squash.py on rhel8 for now as it does not work at all
echo " ! test case ignored on RHEL8 host"
exit 0
fi
origin=busybox
squash=$(dirname "$(readlink -f "$0")")/../../squash.py
cd "$(dirname "$0")"
cat > Dockerfile <<EOF
FROM $origin
ENV test=test
CMD /bin/echo test
EOF
out=`docker build . | awk '/Successfully built/{print $NF}'`
echo "$out"
squashed=$("${PYTHON-python3}" "$squash" "$out" "$origin")
output=$(docker run --rm $squashed)
test "$output" = "test"

View file

@ -0,0 +1,17 @@
#!/bin/bash
set -e
. test-lib.sh
# This should succeed
if ! ct_check_image_availability docker.io/centos/postgresql-10-centos7; then
echo "image_availability test failed"
fi
# This should fail
if ct_check_image_availability docker.io/centos/postgresql-98-centos7; then
echo "image_availability test failed"
fi
echo "image_availability test completed successfully."

View file

@ -0,0 +1,24 @@
#! /bin/bash
set -e
. test-lib.sh
path='a b c:d x:y'
exp_output="==a b c==
==.==
==d x==
==.==
==y==
==.=="
wrap() { for arg; do echo "==$arg=="; done; }
test "$(ct_path_foreach "$path" wrap .)" == "$exp_output"
ct_path_append path '/a'
exp_output="==/a==
==.==
$exp_output"
test "$(ct_path_foreach "$path" wrap .)" == "$exp_output"

View file

@ -0,0 +1,17 @@
#!/bin/bash
set -e
. test-lib.sh
combinations="rhel7:registry.redhat.io/rhscl/postgresql-10-rhel7
centos7:docker.io/centos/postgresql-10-centos7
rhel8:registry.redhat.io/rhel8/postgresql-10
"
for c in $combinations; do
public_name=$(ct_get_public_image_name "${c%%:*}" postgresql 10)
[ "$public_name" == "${c#*:}" ]
done
echo "public_image_name test completed successfully."

View file

@ -0,0 +1,17 @@
#! /bin/bash
set -e
. test-lib.sh
x=$(ct_random_string)
test ${#x} -eq 10
for i in 5 9 11 13; do
x=$(ct_random_string $i)
test ${#x} -eq $i
done
# Even with ignored sigpipe we have to succeed promptly (#70).
trap '' SIGPIPE
x=$(ct_random_string 20)
test ${#x} -eq 20

16
common/tests/test-lib/test_npm Executable file
View file

@ -0,0 +1,16 @@
#! /bin/bash
set -ex
. test-lib.sh
NPM_REGISTRY=""
output=$(ct_build_s2i_npm_variables)
test x"$output" == "x"
ca_file="/etc/pki/ca-trust/source/anchors/RH-IT-Root-CA.crt"
NPM_REGISTRY="https://foobar.registry.org"
if [ -f "$ca_file" ]; then
output=$(ct_build_s2i_npm_variables)
test x"$output" == "x-e NPM_MIRROR=$NPM_REGISTRY -v $ca_file:$ca_file:Z"
fi

72
common/update-generated.sh Executable file
View file

@ -0,0 +1,72 @@
#!/bin/bash
set -ex
shopt -s extglob
COMMIT=$(git rev-parse HEAD)
# import generated content from this git reference ..
SOURCE_BRANCH=${1:-$COMMIT}
# into this git branch
GENERATED_BRANCH=${2:-generated}
git clean -f -d
# switch to generated branch for working env; and switch back later
git checkout "$GENERATED_BRANCH"
git submodule update
# Clean everything in generated branch.
rm -rf -- *
srcdir=srcdir
cleanup ()
{
exit_status=$?
rm -rf "$srcdir"
# switch back to initial ranch
git checkout "$SOURCE_BRANCH"
git submodule update
return $exit_status
}
trap cleanup EXIT
(
# Copy the actual repo into $srcdir, and generate there
mkdir "$srcdir"
cd "$srcdir"
git clone .. .
git checkout "$SOURCE_BRANCH"
git submodule update --init
make generate-all
)
# copy the relevant (generated) content from $srcdir
versions=$(sed -n 's/^VERSIONS[[:space:]]*=//p' "$srcdir"/Makefile)
for i in $versions; do
cp -r "$srcdir/$i" .
done
# source directory is not needed anymore
rm -rf "$srcdir"
# shellcheck disable=SC2086
git add $versions
# Add deleted files to the index as well
(
IFS=$'\n'
for i in $(git ls-files --deleted) ;do
git add --all "$i"
done
)
if ! git diff --cached --exit-code --quiet ; then
git commit -m "auto-sync: master commit $COMMIT"
else
echo "Nothing changed"
fi

View file

@ -245,8 +245,8 @@
{
"name": "POSTGRESQL_VERSION",
"displayName": "Version of PostgreSQL Image",
"description": "Version of PostgreSQL image to be used (10 or latest).",
"value": "10",
"description": "Version of PostgreSQL image to be used (10-el7, 10-el8, or latest).",
"value": "10-el8",
"required": true
}
]

View file

@ -269,8 +269,8 @@
{
"name": "POSTGRESQL_VERSION",
"displayName": "Version of PostgreSQL Image",
"description": "Version of PostgreSQL image to be used (10 or latest).",
"value": "10",
"description": "Version of PostgreSQL image to be used (10-el7, 10-el8, or latest).",
"value": "10-el8",
"required": true
}
]

404
root/help.1 Normal file
View file

@ -0,0 +1,404 @@
.nh
.TH PostgreSQL 12 SQL Database Server container image
.PP
This container image includes PostgreSQL 12 SQL database server for OpenShift and general usage.
Users can choose between RHEL, CentOS and Fedora based images.
The RHEL images are available in the Red Hat Container Catalog
\[la]https://access.redhat.com/containers/\[ra],
the CentOS images are available on Docker Hub
\[la]https://hub.docker.com/r/centos/\[ra],
and the Fedora images are available in Fedora Registry
\[la]https://registry.fedoraproject.org/\[ra]\&.
The resulting image can be run using podman
\[la]https://github.com/containers/libpod\[ra]\&.
.PP
Note: while the examples in this README are calling \fB\fCpodman\fR, you can replace any such calls by \fB\fCdocker\fR with the same arguments
.SH Description
.PP
This container image provides a containerized packaging of the PostgreSQL postgres daemon
and client application. The postgres server daemon accepts connections from clients
and provides access to content from PostgreSQL databases on behalf of the clients.
You can find more information on the PostgreSQL project from the project Web site
(https://www.postgresql.org/).
.SH Usage
.PP
For this, we will assume that you are using the \fB\fCrhscl/postgresql\-12\-rhel7\fR image, available via \fB\fCpostgresql:12\fR imagestream tag in Openshift.
If you want to set only the mandatory environment variables and not store the database
in a host directory, execute the following command:
.PP
.RS
.nf
$ podman run \-d \-\-name postgresql\_database \-e POSTGRESQL\_USER=user \-e POSTGRESQL\_PASSWORD=pass \-e POSTGRESQL\_DATABASE=db \-p 5432:5432 rhscl/postgresql\-12\-rhel7
.fi
.RE
.PP
This will create a container named \fB\fCpostgresql\_database\fR running PostgreSQL with
database \fB\fCdb\fR and user with credentials \fB\fCuser:pass\fR\&.
> Note: user \fB\fCpostgres\fR is reserved for internal usage
.PP
Port 5432 will be exposed
and mapped to the host. If you want your database to be persistent across container
executions, also add a \fB\fC\-v /host/db/path:/var/lib/pgsql/data\fR argument (see
below). This will be the PostgreSQL database cluster directory.
.PP
The same can be achieved in an Openshift instance using templates provided by Openshift or available in examples
\[la]https://github.com/sclorg/postgresql-container/tree/master/examples\[ra]:
.PP
.RS
.nf
$ oc process \-f examples/postgresql\-ephemeral\-template.json \-p POSTGRESQL\_VERSION=12 \-p POSTGRESQL\_USER=user \-p POSTGRESQL\_PASSWORD=pass \-p POSTGRESQL\_DATABASE=db | oc create \-f \-
.fi
.RE
.PP
If the database cluster directory is not initialized, the entrypoint script will
first run \fB\fCinitdb\fR
\[la]http://www.postgresql.org/docs/12/static/app-initdb.html\[ra]
and setup necessary database users and passwords. After the database is initialized,
or if it was already present, \fB\fCpostgres\fR
\[la]http://www.postgresql.org/docs/12/static/app-postgres.html\[ra]
is executed and will run as PID 1. You can stop the detached container by running
\fB\fCpodman stop postgresql\_database\fR\&.
.SH Environment variables and volumes
.PP
The image recognizes the following environment variables that you can set during
initialization by passing \fB\fC\-e VAR=VALUE\fR to the Docker run command.
.PP
\fB\fB\fCPOSTGRESQL\_USER\fR\fP
.br
User name for PostgreSQL account to be created
.PP
\fB\fB\fCPOSTGRESQL\_PASSWORD\fR\fP
.br
Password for the user account
.PP
\fB\fB\fCPOSTGRESQL\_DATABASE\fR\fP
.br
Database name
.PP
\fB\fB\fCPOSTGRESQL\_ADMIN\_PASSWORD\fR\fP
.br
Password for the \fB\fCpostgres\fR admin account (optional)
.PP
Alternatively, the following options are related to migration scenario:
.PP
\fB\fB\fCPOSTGRESQL\_MIGRATION\_REMOTE\_HOST\fR\fP
.br
Hostname/IP to migrate from
.PP
\fB\fB\fCPOSTGRESQL\_MIGRATION\_ADMIN\_PASSWORD\fR\fP
.br
Password for the remote 'postgres' admin user
.PP
\fB\fB\fCPOSTGRESQL\_MIGRATION\_IGNORE\_ERRORS (optional, default 'no')\fR\fP
.br
Set to 'yes' to ignore sql import errors
.PP
The following environment variables influence the PostgreSQL configuration file. They are all optional.
.PP
\fB\fB\fCPOSTGRESQL\_MAX\_CONNECTIONS (default: 100)\fR\fP
.br
The maximum number of client connections allowed
.PP
\fB\fB\fCPOSTGRESQL\_MAX\_PREPARED\_TRANSACTIONS (default: 0)\fR\fP
.br
Sets the maximum number of transactions that can be in the "prepared" state. If you are using prepared transactions, you will probably want this to be at least as large as max\_connections
.PP
\fB\fB\fCPOSTGRESQL\_SHARED\_BUFFERS (default: 32M)\fR\fP
.br
Sets how much memory is dedicated to PostgreSQL to use for caching data
.PP
\fB\fB\fCPOSTGRESQL\_EFFECTIVE\_CACHE\_SIZE (default: 128M)\fR\fP
.br
Set to an estimate of how much memory is available for disk caching by the operating system and within the database itself
.PP
You can also set the following mount points by passing the \fB\fC\-v /host/dir:/container/dir:Z\fR flag to Docker.
.PP
\fB\fB\fC/var/lib/pgsql/data\fR\fP
.br
PostgreSQL database cluster directory
.PP
\fBNotice: When mouting a directory from the host into the container, ensure that the mounted
directory has the appropriate permissions and that the owner and group of the directory
matches the user UID or name which is running inside the container.\fP
.PP
Typically (unless you use \fB\fCpodman run \-u\fR option) processes in container
run under UID 26, so \-\- on GNU/Linux \-\- you can fix the datadir permissions
for example by:
.PP
.RS
.nf
$ setfacl \-m u:26:\-wx /your/data/dir
$ podman run <...> \-v /your/data/dir:/var/lib/pgsql/data:Z <...>
.fi
.RE
.SH Data migration
.PP
PostgreSQL container supports migration of data from remote PostgreSQL server.
You can run it like:
.PP
.RS
.nf
$ podman run \-d \-\-name postgresql\_database \\
\-e POSTGRESQL\_MIGRATION\_REMOTE\_HOST=172.17.0.2 \\
\-e POSTGRESQL\_MIGRATION\_ADMIN\_PASSWORD=remoteAdminP@ssword \\
[ OPTIONAL\_CONFIGURATION\_VARIABLES ]
openshift/postgresql\-92\-centos7
.fi
.RE
.PP
The migration is done the \fBdump and restore\fP way (running \fB\fCpg\_dumpall\fR against
remote cluster and importing the dump locally by \fB\fCpsql\fR). Because the process
is streamed (unix pipeline), there are no intermediate dump files created during
this process to not waste additional storage space.
.PP
If some SQL commands fail during applying, the default behavior
of the migration script is to fail as well to ensure the \fBall\fP or \fBnothing\fP
result of scripted, unattended migration. In most common cases, successful
migration is expected (but not guaranteed!), given you migrate from
a previous version of PostgreSQL server container, that is created using
the same principles as this one (e.g. migration from
\fB\fCopenshift/postgresql\-92\-centos7\fR to \fB\fCcentos/postgresql\-95\-centos7\fR).
Migration from a different kind of PostgreSQL container can likely fail.
.PP
If this \fBall\fP or \fBnothing\fP principle is inadequate for you, and you know
what you are doing, there's optional \fB\fCPOSTGRESQL\_MIGRATION\_IGNORE\_ERRORS\fR option
which does \fBbest effort\fP migration (some data might be lost, it is up to user
to review the standard error output and fix the issues manually in
post\-migration time).
.PP
Please keep in mind that the container image provides help for users'
convenience, but fully automatic migration is not guaranteed. Thus, before you
start proceeding with the database migration, get prepared to perform manual
steps in order to get all your data migrated.
.PP
Note that you might not use variables like \fB\fCPOSTGRESQL\_USER\fR in migration
scenario, all the data (including info about databases, roles or passwords are
copied from old cluster). Ensure that you use the same
\fB\fCOPTIONAL\_CONFIGURATION\_VARIABLES\fR as you used for initialization of the old
PostgreSQL container. If some non\-default configuration is done on remote
cluster, you might need to copy the configuration files manually, too.
.PP
Security warning: Note that the IP communication between old and new PostgreSQL
clusters is not encrypted by default, it is up to user to configure SSL on
remote cluster or ensure security via different means.
.SH PostgreSQL auto\-tuning
.PP
When the PostgreSQL image is run with the \fB\fC\-\-memory\fR parameter set and if there
are no values provided for \fB\fCPOSTGRESQL\_SHARED\_BUFFERS\fR and
\fB\fCPOSTGRESQL\_EFFECTIVE\_CACHE\_SIZE\fR those values are automatically calculated
based on the value provided in the \fB\fC\-\-memory\fR parameter.
.PP
The values are calculated based on the
upstream
\[la]https://wiki.postgresql.org/wiki/Tuning_Your_PostgreSQL_Server\[ra]
formulas. For the \fB\fCshared\_buffers\fR we use 1/4 of given memory and for the
\fB\fCeffective\_cache\_size\fR we set the value to 1/2 of the given memory.
.SH PostgreSQL admin account
.PP
The admin account \fB\fCpostgres\fR has no password set by default, only allowing local
connections. You can set it by setting the \fB\fCPOSTGRESQL\_ADMIN\_PASSWORD\fR environment
variable when initializing your container. This will allow you to login to the
\fB\fCpostgres\fR account remotely. Local connections will still not require a password.
.SH Changing passwords
.PP
Since passwords are part of the image configuration, the only supported method
to change passwords for the database user (\fB\fCPOSTGRESQL\_USER\fR) and \fB\fCpostgres\fR
admin user is by changing the environment variables \fB\fCPOSTGRESQL\_PASSWORD\fR and
\fB\fCPOSTGRESQL\_ADMIN\_PASSWORD\fR, respectively.
.PP
Changing database passwords through SQL statements or any way other than through
the environment variables aforementioned will cause a mismatch between the
values stored in the variables and the actual passwords. Whenever a database
container starts it will reset the passwords to the values stored in the
environment variables.
.SH Upgrading database (by switching to newer PostgreSQL image version)
.PP
** Warning! Please, before you decide to do the data directory upgrade, always
ensure that you've carefully backed up all your data and that you are OK with
potential manual rollback! **
.PP
This image supports automatic upgrade of data directory created by
the PostgreSQL server version 10 (and \fIonly\fP this version) \- provided by sclorg
image. The upgrade process is designed so that you should be able to just
switch from \fIimage A\fP to \fIimage B\fP, and set the \fB\fC$POSTGRESQL\_UPGRADE\fR variable
appropriately to explicitly request the database data transformation.
.PP
The upgrade process is internally implemented via \fB\fCpg\_upgrade\fR binary, and for
that purpose the container needs to contain two versions of PostgreSQL server
(have a look at \fB\fCman pg\_upgrade\fR for more info).
.PP
For the \fB\fCpg\_upgrade\fR process \- and the new server version, we need to initialize
a brand new data directory. That's data directory is created automatically by
container tooling under /var/lib/pgsql/data, which is usually external
bind\-mountpoint. The \fB\fCpg\_upgrade\fR execution is then similar to dump\&restore
approach \-\- it starts both old and new PostgreSQL servers (within container) and
"dumps" the old datadir while and at the same time it "restores" it into new
datadir. This operation requires a lot of data files copying, so you can decide
what type of upgrade you'll do by setting \fB\fC$POSTGRESQL\_UPGRADE\fR appropriately:
.PP
\fB\fB\fCcopy\fR\fP
.br
The data files are copied from old datadir to new datadir. This option has low risk of data loss in case of some upgrade failure.
.PP
\fB\fB\fChardlink\fR\fP
.br
Data files are hard\-linked from old to the new data directory, which brings performance optimization \- but the old directory becomes unusable, even in case of failure.
.PP
Note that because we copy data directory, you need to make sure that you have
enough space for the copy; upgrade failure because of not enough space might
lead to data loss.
.SH Extending image
.PP
This image can be extended in Openshift using the \fB\fCSource\fR build strategy or via the standalone
source\-to\-image
\[la]https://github.com/openshift/source-to-image\[ra] application (where available).
For this, we will assume that you are using the \fB\fCrhscl/postgresql\-12\-rhel7\fR image,
available via \fB\fCpostgresql:12\fR imagestream tag in Openshift.
.PP
For example to build customized image \fB\fCnew\-postgresql\fR
with configuration from \fB\fChttps://github.com/sclorg/postgresql\-container/tree/master/examples/extending\-image\fR run:
.PP
.RS
.nf
$ oc new\-app postgresql:12\~https://github.com/sclorg/postgresql\-container.git \\
\-\-name new\-postgresql \\
\-\-context\-dir examples/extending\-image/ \\
\-e POSTGRESQL\_USER=user \\
\-e POSTGRESQL\_DATABASE=db \\
\-e POSTGRESQL\_PASSWORD=password
.fi
.RE
.PP
or via \fB\fCs2i\fR:
.PP
.RS
.nf
$ s2i build \-\-context\-dir examples/extending\-image/ https://github.com/sclorg/postgresql\-container.git rhscl/postgresql\-12\-rhel7 new\-postgresql
.fi
.RE
.PP
The directory passed to Openshift should contain one or more of the
following directories:
.SS \fB\fCpostgresql\-pre\-start/\fR
.PP
Source all \fB\fC*.sh\fR files from this directory during early start of the
container. There's no PostgreSQL daemon running on background.
.SS \fB\fCpostgresql\-cfg/\fR
.PP
Contained configuration files (\fB\fC*.conf\fR) will be included at the end of image
postgresql.conf file.
.SS \fB\fCpostgresql\-init/\fR
.PP
Contained shell scripts (\fB\fC*.sh\fR) are sourced when the database is freshly
initialized (after successful initdb run which made the data directory
non\-empty). At the time of sourcing these scripts, the local PostgreSQL
server is running. For re\-deployments scenarios with persistent data
directory, the scripts are not sourced (no\-op).
.SS \fB\fCpostgresql\-start/\fR
.PP
Same sematics as \fB\fCpostgresql\-init/\fR, except that these scripts are
always sourced (after \fB\fCpostgresql\-init/\fR scripts, if they exist).
.ti 0
\l'\n(.lu'
.PP
During the s2i build all provided files are copied into \fB\fC/opt/app\-root/src\fR
directory in the new image. Only one
file with the same name can be used for customization and user provided files
are preferred over default files in \fB\fC/usr/share/container\-scripts/\fR\-
so it is possible to overwrite them.
.SH Troubleshooting
.PP
At first the postgres daemon writes its logs to the standard output, so these are available in the container log. The log can be examined by running:
.PP
.RS
.nf
podman logs <container>
.fi
.RE
.PP
Then log output is redirected to logging collector process and will appear in directory "pg\_log".
.SH See also
.PP
Dockerfile and other sources for this container image are available on
https://github.com/sclorg/postgresql\-container.
In that repository, the Dockerfile for CentOS is called Dockerfile, the Dockerfile
for RHEL7 is called Dockerfile.rhel7, the Dockerfile for RHEL8 is called Dockerfile.rhel8,
and the Dockerfile for Fedora is called Dockerfile.fedora.

View file

@ -17,11 +17,13 @@ function initialize_replica() {
# PostgreSQL recovery configuration.
generate_postgresql_recovery_config
cat >> "$PGDATA/recovery.conf" <<EOF
cat >> "$PGDATA/postgresql.auto.conf" <<EOF
# Custom OpenShift recovery configuration:
include '${POSTGRESQL_RECOVERY_FILE}'
EOF
# activate standby mode
touch "$PGDATA/standby.signal"
}
check_env_vars

View file

@ -1,7 +1,7 @@
PostgreSQL 11 SQL Database Server container image
PostgreSQL 12 SQL Database Server container image
===============================================
This container image includes PostgreSQL 11 SQL database server for OpenShift and general usage.
This container image includes PostgreSQL 12 SQL database server for OpenShift and general usage.
Users can choose between RHEL, CentOS and Fedora based images.
The RHEL images are available in the [Red Hat Container Catalog](https://access.redhat.com/containers/),
the CentOS images are available on [Docker Hub](https://hub.docker.com/r/centos/),
@ -24,16 +24,19 @@ You can find more information on the PostgreSQL project from the project Web sit
Usage
-----
For this, we will assume that you are using the `` image, available via `postgresql:11` imagestream tag in Openshift.
For this, we will assume that you are using the `rhscl/postgresql-12-rhel7` image, available via `postgresql:12` imagestream tag in Openshift.
If you want to set only the mandatory environment variables and not store the database
in a host directory, execute the following command:
```
$ podman run -d --name postgresql_database -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db -p 5432:5432
$ podman run -d --name postgresql_database -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db -p 5432:5432 rhscl/postgresql-12-rhel7
```
This will create a container named `postgresql_database` running PostgreSQL with
database `db` and user with credentials `user:pass`. Port 5432 will be exposed
database `db` and user with credentials `user:pass`.
> Note: user `postgres` is reserved for internal usage
Port 5432 will be exposed
and mapped to the host. If you want your database to be persistent across container
executions, also add a `-v /host/db/path:/var/lib/pgsql/data` argument (see
below). This will be the PostgreSQL database cluster directory.
@ -41,13 +44,13 @@ below). This will be the PostgreSQL database cluster directory.
The same can be achieved in an Openshift instance using templates provided by Openshift or available in [examples](https://github.com/sclorg/postgresql-container/tree/master/examples):
```
$ oc process -f examples/postgresql-ephemeral-template.json -p POSTGRESQL_VERSION=11 -p POSTGRESQL_USER=user -p POSTGRESQL_PASSWORD=pass -p POSTGRESQL_DATABASE=db | oc create -f -
$ oc process -f examples/postgresql-ephemeral-template.json -p POSTGRESQL_VERSION=12 -p POSTGRESQL_USER=user -p POSTGRESQL_PASSWORD=pass -p POSTGRESQL_DATABASE=db | oc create -f -
```
If the database cluster directory is not initialized, the entrypoint script will
first run [`initdb`](http://www.postgresql.org/docs/11/static/app-initdb.html)
first run [`initdb`](http://www.postgresql.org/docs/12/static/app-initdb.html)
and setup necessary database users and passwords. After the database is initialized,
or if it was already present, [`postgres`](http://www.postgresql.org/docs/11/static/app-postgres.html)
or if it was already present, [`postgres`](http://www.postgresql.org/docs/12/static/app-postgres.html)
is executed and will run as PID 1. You can stop the detached container by running
`podman stop postgresql_database`.
@ -248,14 +251,14 @@ Extending image
This image can be extended in Openshift using the `Source` build strategy or via the standalone
[source-to-image](https://github.com/openshift/source-to-image) application (where available).
For this, we will assume that you are using the `` image,
available via `postgresql:11` imagestream tag in Openshift.
For this, we will assume that you are using the `rhscl/postgresql-12-rhel7` image,
available via `postgresql:12` imagestream tag in Openshift.
For example to build customized image `new-postgresql`
with configuration from `https://github.com/sclorg/postgresql-container/tree/master/examples/extending-image` run:
```
$ oc new-app postgresql:11~https://github.com/sclorg/postgresql-container.git \
$ oc new-app postgresql:12~https://github.com/sclorg/postgresql-container.git \
--name new-postgresql \
--context-dir examples/extending-image/ \
-e POSTGRESQL_USER=user \
@ -266,7 +269,7 @@ $ oc new-app postgresql:11~https://github.com/sclorg/postgresql-container.git \
or via `s2i`:
```
$ s2i build --context-dir examples/extending-image/ https://github.com/sclorg/postgresql-container.git new-postgresql
$ s2i build --context-dir examples/extending-image/ https://github.com/sclorg/postgresql-container.git rhscl/postgresql-12-rhel7 new-postgresql
```
The directory passed to Openshift should contain one or more of the

View file

@ -105,6 +105,43 @@ function postgresql_master_addr() {
echo -n "$(echo $endpoints | cut -d ' ' -f 1)"
}
# Converts the version in format x.y or x.y.z to a number.
version2number ()
{
local old_IFS=$IFS
local to_print= depth=${2-3} width=${3-2} sum=0 one_part
IFS='.'
set -- $1
while test $depth -ge 1; do
depth=$(( depth - 1 ))
part=${1-0} ; shift || :
printf "%0${width}d" "$part"
done
IFS=$old_IFS
}
# On non-intel arches, data_sync_retry = off does not work
# Upstream discussion: https://www.postgresql.org/message-id/CA+mCpegfOUph2U4ZADtQT16dfbkjjYNJL1bSTWErsazaFjQW9A@mail.gmail.com
# Upstream changes that caused this issue:
# https://github.com/postgres/postgres/commit/483520eca426fb1b428e8416d1d014ac5ad80ef4
# https://github.com/postgres/postgres/commit/9ccdd7f66e3324d2b6d3dec282cfa9ff084083f1
# RHBZ: https://bugzilla.redhat.com/show_bug.cgi?id=1779150
# Special handle of data_sync_retry should handle only in some cases.
# These cases are: non-intel architectures, and version higher or equal 12.0, 10.7, 9.6.12
# Return value 0 means the hack is needed.
function should_hack_data_sync_retry() {
[ "$(uname -p)" == 'x86_64' ] && return 1
local version_number=$(version2number "$(pg_ctl -V | sed -e 's/^pg_ctl (PostgreSQL) //')")
# this matches all 12.x and versions of 10.x where we need the hack
[ "$version_number" -ge 100700 ] && return 0
# this matches all 10.x that were not matched above
[ "$version_number" -ge 100000 ] && return 1
# this matches all 9.x where need the hack
[ "$version_number" -ge 090612 ] && return 0
# all rest should be older 9.x releases
return 1
}
# New config is generated every time a container is created. It only contains
# additional custom settings and is included from $PGDATA/postgresql.conf.
function generate_postgresql_config() {
@ -118,13 +155,7 @@ function generate_postgresql_config() {
>> "${POSTGRESQL_CONFIG_FILE}"
fi
if [ "$POSTGRESQL_VERSION" -ge 12 ] && [ "$(uname -p)" != 'x86_64' ] && [[ "$(. /etc/os-release ; echo $VERSION_ID)" =~ 7.* ]] ; then
# On non-intel arches, data_sync_retry = off does not work
# Upstream discussion: https://www.postgresql.org/message-id/CA+mCpegfOUph2U4ZADtQT16dfbkjjYNJL1bSTWErsazaFjQW9A@mail.gmail.com
# Upstream changes that caused this issue:
# https://github.com/postgres/postgres/commit/483520eca426fb1b428e8416d1d014ac5ad80ef4
# https://github.com/postgres/postgres/commit/9ccdd7f66e3324d2b6d3dec282cfa9ff084083f1
# RHBZ: https://bugzilla.redhat.com/show_bug.cgi?id=1779150
if should_hack_data_sync_retry ; then
echo "data_sync_retry = on" >>"${POSTGRESQL_CONFIG_FILE}"
fi
@ -157,7 +188,7 @@ initdb_wrapper ()
{
# Initialize the database cluster with utf8 support enabled by default.
# This might affect performance, see:
# http://www.postgresql.org/docs/11/static/locale.html
# http://www.postgresql.org/docs/12/static/locale.html
LANG=${LANG:-en_US.utf8} "$@"
}

View file

@ -5,5 +5,4 @@
# Changes to this file will be overwritten.
#
standby_mode = on
primary_conninfo = 'host=${MASTER_FQDN} port=5432 user=${POSTGRESQL_MASTER_USER} password=${POSTGRESQL_MASTER_PASSWORD}'

1
test/check_imagestreams.py Symbolic link
View file

@ -0,0 +1 @@
../common/check_imagestreams.py

1
test/examples Symbolic link
View file

@ -0,0 +1 @@
../examples/

View file

@ -34,4 +34,9 @@ case $(sha256sum "$pagila_file") in
*) false ;;
esac
docker exec -i "$CID" container-entrypoint psql -tA < "$pagila_file" &>/dev/null
# Deliberately using a separate container, otherwise the docker exec with redirection
# does not work in podman 1.6.x due to https://bugzilla.redhat.com/show_bug.cgi?id=1827324
# This change can be reverted to the previous variant, once this BZ is fixed.
server_ip=$(docker inspect --format='{{.NetworkSettings.IPAddress}}' "$CID")
admin_pass=$(docker exec "$CID" bash -c 'echo $POSTGRESQL_ADMIN_PASSWORD')
docker run --rm -i "$IMAGE_NAME" bash -c "PGPASSWORD=$admin_pass psql -h $server_ip" <"$pagila_file" &>/dev/null

View file

@ -58,11 +58,13 @@ data_pagila_check ()
local exp_output='28
16
2'
local output=$(docker exec -i "$CID" container-entrypoint psql -tA <<EOF
# Deliberately moving heredoc into the container, otherwise it does not work
# in podman 1.6.x due to https://bugzilla.redhat.com/show_bug.cgi?id=1827324
local output=$(docker exec -i "$CID" bash -c "psql -tA <<EOF
select count(*) from information_schema.tables where table_schema = 'public';
select count(*) from information_schema.triggers;
select count(*) from staff;
EOF
EOF"
)
test "$exp_output" = "$output" \
|| error "Unexpected output: '$output', expected: '$exp_output'"
@ -70,10 +72,12 @@ EOF
data_empty_create ()
{
docker exec -i "$CID" container-entrypoint psql &>/dev/null <<EOF
# Deliberately moving heredoc into the container, otherwise it does not work
# in podman 1.6.x due to https://bugzilla.redhat.com/show_bug.cgi?id=1827324
docker exec -i "$CID" bash -c "psql &>/dev/null <<EOF
create table blah (id int);
insert into blah values (1), (2), (3);
EOF
EOF"
}
data_empty_check ()
@ -82,9 +86,11 @@ data_empty_check ()
local exp_output='1
2
3'
local output=$(docker exec -i "$CID" container-entrypoint psql -tA <<EOF
# Deliberately moving heredoc into the container, otherwise it does not work
# in podman 1.6.x due to https://bugzilla.redhat.com/show_bug.cgi?id=1827324
local output=$(docker exec -i "$CID" bash -c "psql -tA <<EOF
select * from blah order by id;
EOF
EOF"
)
test "$exp_output" = "$output" || error "Unexpected output '$output'"
}

View file

@ -16,9 +16,9 @@ source "$THISDIR"/test-lib-postgresql.sh
set -exo nounset
test -n "${IMAGE_NAME-}" || false 'make sure $IMAGE_NAME is defined'
test -n "${VERSION-}" || false 'make sure $VERSION is defined'
test -n "${OS-}" || false 'make sure $OS is defined'
trap ct_os_cleanup EXIT SIGINT
ct_os_check_compulsory_vars
# Populate template variables if not set already
if [ -z "${EPHEMERAL_TEMPLATES:-}" ]; then
@ -428,27 +428,29 @@ run_persistent_tests "$IMAGE_NAME"
test_postgresql_configmap_start "$IMAGE_NAME"
# test with the just built image and an integrated template
test_postgresql_integration "${IMAGE_NAME}" "${VERSION}" postgresql
echo "Running test_postgresql_integration with ${IMAGE_NAME}"
test_postgresql_integration "${IMAGE_NAME}"
# test with a released image and an integrated template
# ignore possible failure of this test for centos images
fail_not_released=true
if [ "${OS}" == "rhel7" ] ; then
PUBLIC_IMAGE_NAME=${PUBLIC_IMAGE_NAME:-${REGISTRY:-registry.redhat.io/}rhscl/${BASE_IMAGE_NAME}-${VERSION//./}-rhel7}
else
PUBLIC_IMAGE_NAME=${PUBLIC_IMAGE_NAME:-${REGISTRY:-}centos/${BASE_IMAGE_NAME}-${VERSION//./}-centos7}
fail_not_released=false
fi
PUBLIC_IMAGE_NAME=${PUBLIC_IMAGE_NAME:-$(ct_get_public_image_name "${OS}" "${BASE_IMAGE_NAME}" "${VERSION}")}
export CT_SKIP_UPLOAD_IMAGE=true
# Try pulling the image first to see if it is accessible
if docker pull "${PUBLIC_IMAGE_NAME}"; then
test_postgresql_integration postgresql "${VERSION}" "${PUBLIC_IMAGE_NAME}"
echo "Running test_postgresql_integration with ${PUBLIC_IMAGE_NAME}"
test_postgresql_integration "${PUBLIC_IMAGE_NAME}"
else
echo "Warning: ${PUBLIC_IMAGE_NAME} could not be downloaded via 'docker'"
! $fail_not_released || false "ERROR: Failed to pull image"
# ignore possible failure of this test for centos images
[ "${OS}" == "rhel7" ] && false "ERROR: Failed to pull image"
fi
# Check the imagestream
echo "Running test_mariadb_imagestream"
test_postgresql_imagestream
OS_TESTSUITE_RESULT=0
ct_os_cluster_down
# vim: set tabstop=2:shiftwidth=2:expandtab:

View file

@ -24,7 +24,13 @@ export CT_SKIP_NEW_PROJECT=true
export CT_SKIP_UPLOAD_IMAGE=true
export CT_NAMESPACE=openshift
test_postgresql_integration postgresql ${VERSION} "${IMAGE_NAME}"
# Check the template
test_postgresql_integration "${IMAGE_NAME}"
# Check the imagestream
test_postgresql_imagestream
OS_TESTSUITE_RESULT=0
# vim: set tabstop=2:shiftwidth=2:expandtab:

View file

@ -29,6 +29,7 @@ run_s2i_enable_ssl_test
run_upgrade_test
run_migration_test
run_pgaudit_test
run_latest_imagestreams_test
"
test $# -eq 1 -a "${1-}" == --list && echo "$TEST_LIST" && exit 0
@ -60,6 +61,9 @@ add_cleanup_command ()
'
}
function cleanup() {
# Print a big fat separator to find the error easier
echo "=================================== Cleanup begins here ============================="
for cidfile in $CIDFILE_DIR/* ; do
CONTAINER=$(cat $cidfile)
@ -872,19 +876,21 @@ run_pgaudit_test()
wait_ready "$name"
# enable the pgaudit extension
docker exec -i $(get_cid "$name") bash -c psql <<EOSQL
# Deliberately moving heredoc into the container, otherwise it does not work
# in podman 1.6.x due to https://bugzilla.redhat.com/show_bug.cgi?id=1827324
docker exec -i $(get_cid "$name") bash -c "psql <<EOSQL
CREATE EXTENSION pgaudit;
SET pgaudit.log = 'read, ddl';
CREATE DATABASE pgaudittest;
EOSQL
EOSQL"
# simulate some trafic that should be audited
docker exec -i $(get_cid "$name") bash -c psql pgaudittest <<EOSQL
docker exec -i $(get_cid "$name") bash -c "psql pgaudittest <<EOSQL
SET pgaudit.log = 'read, ddl';
CREATE TABLE account (id int, name text, password text, description text);
INSERT INTO account (id, name, password, description) VALUES (1, 'user1', 'HASH1', 'blah, blah');
SELECT * FROM account;
EOSQL
EOSQL"
# give server some time for write all audit messages
sleep 1
@ -893,6 +899,17 @@ EOSQL
grep -E 'AUDIT: SESSION,.*,.*,READ,SELECT,,,SELECT' "${data_dir}"/userdata/log/postgresql-*.log
}
function run_latest_imagestreams_test() {
local result=1
# Switch to root directory of a container
echo "Testing the latest version in imagestreams"
pushd "${test_dir}/.." >/dev/null || return 1
ct_check_latest_imagestreams
result=$?
popd >/dev/null || return 1
return $result
}
function run_all_tests() {
for test_case in $TEST_LIST; do
: "Running test $test_case"

847
test/run_test.orig Executable file
View file

@ -0,0 +1,847 @@
#!/bin/bash
#
# Test the PostgreSQL image.
#
# IMAGE_NAME specifies the name of the candidate image used for testing.
# The image has to be available before this script is executed.
#
set -exo nounset
shopt -s nullglob
# library from container-common-scripts
. test/test-lib.sh
# local library
. test/pg-test-lib.sh
TEST_LIST="\
run_container_creation_tests
run_general_tests
run_change_password_test
run_replication_test
run_master_restart_test
run_doc_test
run_s2i_test
run_test_cfg_hook
run_s2i_bake_data_test
run_s2i_enable_ssl_test
run_upgrade_test
run_migration_test
"
test $# -eq 1 -a "${1-}" == --list && echo "$TEST_LIST" && exit 0
test -n "${IMAGE_NAME-}" || false 'make sure $IMAGE_NAME is defined'
test -n "${VERSION-}" || false 'make sure $VERSION is defined'
test -n "${OS-}" || false 'make sure $OS is defined'
CIDFILE_DIR=$(mktemp --suffix=postgresql_test_cidfiles -d)
volumes_to_clean=
images_to_clean=()
files_to_clean=
test_dir="$(readlink -f "$(dirname "$0")")"
_cleanup_commands_space=
_cleanup_commands=
add_cleanup_command ()
{
local cmd= space=
for arg; do
cmd+="$space$(printf "%q" "$arg")"
space=' '
done
_cleanup_commands+="$_cleanup_commands_space$cmd"
_cleanup_commands_space='
'
}
function cleanup() {
for cidfile in $CIDFILE_DIR/* ; do
CONTAINER=$(cat $cidfile)
echo "Stopping and removing container $CONTAINER..."
docker stop $CONTAINER
exit_status=$(docker inspect -f '{{.State.ExitCode}}' $CONTAINER)
if [ "$exit_status" != "0" ]; then
echo "Dumping logs for $CONTAINER"
docker logs $CONTAINER
fi
docker rm $CONTAINER
rm $cidfile
echo "Done."
done
rmdir $CIDFILE_DIR
ct_path_foreach "$volumes_to_clean" cleanup_volume_dir
if test -n "${images_to_clean-}"; then
# Workaround for RHEL 7 bash bug:
# https://bugzilla.redhat.com/show_bug.cgi?id=1636393
for image in "${images_to_clean[@]}"; do
docker rmi -f "$image"
done
fi
ct_path_foreach "$files_to_clean" rm
echo "$_cleanup_commands" | while read -r line; do
eval "$line"
done
}
trap cleanup EXIT
cleanup_volume_dir ()
{
test ! -d "$1" && : "WARN: cleaned $1 for some reason" && return 0
# When we run this test script as non-root (we should?), the PostgreSQL server
# within container is still run under 'postgres' user. It means that, taking
# into account 0077 umask of PostgreSQL server, we are unable to remove files
# created by server. That's why we need to let docker escalate the privileges
# again.
local datadir=/var/lib/pgsql/data
docker run -v "$1:$datadir:Z" --rm "$IMAGE_NAME" /bin/sh -c "/bin/rm -rf $datadir/userdata"
rmdir "$1"
}
function get_cid() {
local id="$1" ; shift || return 1
echo $(cat "$CIDFILE_DIR/$id")
}
function get_container_ip() {
local id="$1" ; shift
docker inspect --format='{{.NetworkSettings.IPAddress}}' $(get_cid "$id")
}
function get_ip_from_cid() {
local cid="$1"; shift
docker inspect --format='{{.NetworkSettings.IPAddress}}' $cid
}
function postgresql_cmd() {
docker run --rm -e PGPASSWORD="$PASS" "$IMAGE_NAME" psql "postgresql://$PGUSER@$CONTAINER_IP:5432/${DB-db}" "$@"
}
function test_connection() {
local name=$1 ; shift
ip=$(get_container_ip $name)
echo " Testing PostgreSQL connection to $ip..."
local max_attempts=20
local sleep_time=2
for i in $(seq $max_attempts); do
echo " Trying to connect..."
set +e
# Don't let the code come here if neither user nor admin is able to
# connect.
if [ -v PGUSER ] && [ -v PASS ]; then
CONTAINER_IP=$ip postgresql_cmd <<< "SELECT 1;"
else
PGUSER=postgres PASS=$ADMIN_PASS CONTAINER_IP=$ip DB=postgres postgresql_cmd <<< "SELECT 1;"
fi
status=$?
set -e
if [ $status -eq 0 ]; then
echo " Success!"
return 0
fi
sleep $sleep_time
done
return 1
}
function test_postgresql() {
echo " Testing PostgreSQL"
postgresql_cmd <<< "CREATE EXTENSION 'uuid-ossp';" # to test contrib package
postgresql_cmd <<< "CREATE TABLE tbl (col1 VARCHAR(20), col2 VARCHAR(20));"
postgresql_cmd <<< "INSERT INTO tbl VALUES ('foo1', 'bar1');"
postgresql_cmd <<< "INSERT INTO tbl VALUES ('foo2', 'bar2');"
postgresql_cmd <<< "INSERT INTO tbl VALUES ('foo3', 'bar3');"
postgresql_cmd <<< "SELECT * FROM tbl;"
#postgresql_cmd <<< "DROP TABLE tbl;"
echo " Success!"
}
function create_container() {
local name=$1 ; shift
local cargs=${DOCKER_ARGS:-}
# TODO: fix all create_container() invocations so that we don't need this,
# e.g. multiline DOCKER_ARGS var should end by trailing backslashes
cargs=$(echo "$cargs" | tr '\n' ' ')
cidfile="$CIDFILE_DIR/$name"
# create container with a cidfile in a directory for cleanup
eval "docker run $cargs --cidfile \$cidfile -d \$IMAGE_NAME \"\$@\""
echo "Created container $(cat $cidfile)"
}
create_volume_dir ()
{
volume_dir=`mktemp -d --tmpdir pg-testdata.XXXXX`
setfacl -m u:26:-wx "$volume_dir"
ct_path_append volumes_to_clean "$volume_dir"
}
create_temp_file ()
{
temp_file=`mktemp --tmpdir pg-testfile.XXXXX`
setfacl -m u:26:rw- "$temp_file"
ct_path_append files_to_clean "$temp_file"
}
function assert_login_access() {
local PGUSER=$1 ; shift
local PASS=$1 ; shift
local success=$1 ; shift
echo "testing login as $PGUSER:$PASS; should_success=$success"
if postgresql_cmd <<<'SELECT 1;' ; then
if $success ; then
echo " $PGUSER($PASS) access granted as expected"
return
fi
else
if ! $success ; then
echo " $PGUSER($PASS) access denied as expected"
return
fi
fi
echo " $PGUSER($PASS) login assertion failed"
exit 1
}
function assert_local_access() {
local id="$1" ; shift
docker exec -i $(get_cid "$id") bash -c psql <<< "SELECT 1;"
}
# Make sure the invocation of docker run fails.
function assert_container_creation_fails() {
# Time the docker run command. It should fail. If it doesn't fail,
# postgresql will keep running so we kill it with SIGKILL to make sure
# timeout returns a non-zero value.
set +e
timeout -s 9 --preserve-status 60s docker run --rm "$@" $IMAGE_NAME
ret=$?
set -e
# Timeout will exit with a high number.
if [ $ret -gt 30 ]; then
return 1
fi
}
# assert_container_creation_succeeds NAME [ARGS]
# ----------------------------------------------
# Chcek that 'docker run' with IMAGE_NAME succeeds with docker arguments
# specified as ARGS.
assert_container_creation_succeeds ()
{
local check_env=false
local name=pg-success-"$(ct_random_string)"
local PGUSER='' PGPASS='' DB='' ADMIN_PASS=
local docker_args=
for arg; do
docker_args+=" $(printf "%q" "$arg")"
if $check_env; then
local env=${arg//=*/}
local val=${arg//$env=/}
case $env in
POSTGRESQL_ADMIN_PASSWORD) ADMIN_PASS=$val ;;
POSTGRESQL_USER) PGUSER=$val ;;
POSTGRESQL_PASSWORD) PGPASS=$val ;;
POSTGRESQL_DATABASE) DB=$val ;;
esac
check_env=false
elif test "$arg" = -e; then
check_env=:
fi
done
DOCKER_ARGS=$docker_args create_container "$name"
if test -n "$PGUSER" && test -n "$PGPASS"; then
PGUSER=$PGUSER PASS=$PGPASS DB=$DB test_connection "$name"
fi
if test -n "$ADMIN_PASS"; then
PGUSER=postgres PASS=$ADMIN_PASS DB=$DB test_connection "$name"
fi
docker stop "$(get_cid "$name")"
}
function try_image_invalid_combinations() {
assert_container_creation_fails -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass "$@"
assert_container_creation_fails -e POSTGRESQL_USER=user -e POSTGRESQL_DATABASE=db "$@"
assert_container_creation_fails -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db "$@"
}
function run_container_creation_tests() {
echo " Testing image entrypoint usage"
try_image_invalid_combinations
try_image_invalid_combinations -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
VERY_LONG_IDENTIFIER="very_long_identifier_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
assert_container_creation_fails -e POSTGRESQL_USER= -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
assert_container_creation_fails -e POSTGRESQL_USER=$VERY_LONG_IDENTIFIER -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
assert_container_creation_succeeds -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD="\"" -e POSTGRESQL_DATABASE=db -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
assert_container_creation_succeeds -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=9invalid -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
assert_container_creation_fails -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=$VERY_LONG_IDENTIFIER -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
assert_container_creation_succeeds -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db -e POSTGRESQL_ADMIN_PASSWORD="\""
echo " Success!"
assert_container_creation_succeeds -e POSTGRESQL_ADMIN_PASSWORD="the @password"
assert_container_creation_succeeds -e POSTGRESQL_PASSWORD="the pass" -e POSTGRESQL_USER="the user" -e POSTGRESQL_DATABASE="the db"
}
function test_config_option() {
local name=$1 ; shift
local setting=$1 ; shift
local value=$1 ; shift
docker exec $(get_cid ${name}) grep -q "${setting} = ${value}" /var/lib/pgsql/openshift-custom-postgresql.conf
}
# wait_ready
# ----------
# Wait until the PG container becomes ready
wait_ready ()
{
while ! docker exec "$(get_cid "$1")" /usr/libexec/check-container ; do
sleep 1
done
}
# assert_runtime_option option value
# ----------------------------------
assert_runtime_option ()
{
local name=$1 option=$2 value=$3
wait_ready "$name"
set -- $(docker exec "$(get_cid "$name")" bash -c "psql -tA -c 'SHOW $option;'")
test "$value" = "$1"
}
function run_configuration_tests() {
local name=$1 ; shift
echo " Testing image configuration settings"
test_config_option ${name} max_connections ${POSTGRESQL_MAX_CONNECTIONS}
test_config_option ${name} max_prepared_transactions ${POSTGRESQL_MAX_PREPARED_TRANSACTIONS}
test_config_option ${name} shared_buffers ${POSTGRESQL_SHARED_BUFFERS}
echo " Success!"
}
test_scl_usage() {
local name="$1"
local run_cmd="$2"
local expected="$3"
echo " Testing the image SCL enable"
out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${run_cmd}")
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[/bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'"
return 1
fi
out=$(docker exec $(get_cid $name) /bin/bash -c "${run_cmd}" 2>&1)
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[exec /bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'"
return 1
fi
out=$(docker exec $(get_cid $name) /bin/sh -ic "${run_cmd}" 2>&1)
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[exec /bin/sh -ic "${run_cmd}"] Expected '${expected}', got '${out}'"
return 1
fi
}
function run_tests() {
echo " Testing general usage (run_tests) with '$1' as argument"
local name=$1 ; shift
user_login=false
admin_login=false
envs=
# NOTE: We work wrongly with variables so please don't try to pass spaces
# within PGUSER/PASS/ADMIN_PASS variables.
[ -v PGUSER ] && envs+=" -e POSTGRESQL_USER=$PGUSER"
[ -v PASS ] && envs+=" -e POSTGRESQL_PASSWORD=$PASS"
if [ -v PGUSER ] && [ -v PASS ]; then
envs+=" -e POSTGRESQL_DATABASE=db"
user_login=:
fi
if [ -v ADMIN_PASS ]; then
envs="$envs -e POSTGRESQL_ADMIN_PASSWORD=$ADMIN_PASS"
admin_login=:
fi
if [ -v POSTGRESQL_MAX_CONNECTIONS ]; then
envs="$envs -e POSTGRESQL_MAX_CONNECTIONS=$POSTGRESQL_MAX_CONNECTIONS"
fi
if [ -v POSTGRESQL_MAX_PREPARED_TRANSACTIONS ]; then
envs="$envs -e POSTGRESQL_MAX_PREPARED_TRANSACTIONS=$POSTGRESQL_MAX_PREPARED_TRANSACTIONS"
fi
if [ -v POSTGRESQL_SHARED_BUFFERS ]; then
envs="$envs -e POSTGRESQL_SHARED_BUFFERS=$POSTGRESQL_SHARED_BUFFERS"
fi
DOCKER_ARGS="${DOCKER_ARGS:-} $envs" create_container $name
CONTAINER_IP=$(get_container_ip $name)
test_connection $name
echo " Testing scl usage"
test_scl_usage $name 'psql --version' "$VERSION"
echo " Testing login accesses"
assert_login_access "${PGUSER:-}" "${PASS-}" "$user_login"
assert_login_access "${PGUSER:-}" "${PASS-}_foo" false
assert_login_access postgres "${ADMIN_PASS-}" "$admin_login"
assert_login_access postgres "${ADMIN_PASS-}_foo" false
assert_local_access $name
run_configuration_tests $name
echo " Success!"
if $user_login; then
test_postgresql $name
fi
if $admin_login; then
DB=postgres PGUSER=postgres PASS=$ADMIN_PASS test_postgresql $name
fi
}
function run_slave() {
local suffix="$1"; shift
docker run $cluster_args -e POSTGRESQL_MASTER_IP=${master_hostname} \
-d --cidfile ${CIDFILE_DIR}/slave-${suffix}.cid $IMAGE_NAME run-postgresql-slave
}
function run_master() {
local suffix="$1"; shift
master_args=${master_args-}
docker run $cluster_args $master_args \
-d --cidfile ${CIDFILE_DIR}/master-${suffix}.cid $IMAGE_NAME run-postgresql-master >/dev/null
}
function test_slave_visibility() {
local max_attempts=30
for slave in $slave_cids; do
slave_ip=$(get_ip_from_cid $slave)
if [ -z "$slave_ip" ]; then
echo "Failed to get IP for slave $slave."
echo "Dumping logs for $slave"
docker logs "$slave"
return 1
fi
for i in $(seq $max_attempts); do
result="$(postgresql_cmd -c "select client_addr from pg_stat_replication;" | grep "$slave_ip" || true)"
if [[ -n "${result}" ]]; then
echo "${slave_ip} successfully registered as SLAVE for ${master_ip}"
break
fi
if [[ "${i}" == "${max_attempts}" ]]; then
echo "The ${slave_ip} failed to register in MASTER"
echo "Dumping logs for $slave"
docker logs $slave
return 1
fi
sleep 1
done
done
}
function test_value_replication() {
local max_attempts=30
# Setup the replication data
local value
value=24
postgresql_cmd -c "CREATE TABLE $table_name (a integer); INSERT INTO $table_name VALUES ($value);"
# Read value from slaves and check whether it is expected
for slave in $slave_cids; do
slave_ip=$(get_ip_from_cid $slave)
CONTAINER_IP=$slave_ip
for i in $(seq $max_attempts); do
result="$(postgresql_cmd -At -c "select * from $table_name" || :)"
if [[ "$result" == "$value" ]]; then
echo "${slave_ip} successfully got value from MASTER ${master_ip}"
break
fi
if [[ "${i}" == "${max_attempts}" ]]; then
echo "The ${slave_ip} failed to see value added on MASTER"
echo "Dumping logs for $slave"
docker logs $slave
return 1
fi
sleep 1
done
done
}
function setup_replication_cluster() {
# Run the PostgreSQL master
run_master "$cid_suffix"
# Run the PostgreSQL slaves
local i
master_ip=$(get_container_ip "master-$cid_suffix.cid")
local cluster_args="$cluster_args --add-host postgresql-master:$master_ip"
local master_hostname="postgresql-master"
for i in $(seq ${slave_num:-1}); do
slave_cids="$slave_cids $(run_slave $cid_suffix-$i)"
done
}
function run_master_restart_test() {
local DB=postgres
local PGUSER=master
local PASS=master
echo "Testing failed master restart"
local cluster_args="-e POSTGRESQL_ADMIN_PASSWORD=pass -e POSTGRESQL_MASTER_USER=$PGUSER -e POSTGRESQL_MASTER_PASSWORD=$PASS"
local cid_suffix="mrestart"
local table_name="t1"
local master_ip=
local slave_cids=
create_volume_dir
local master_args="-v ${volume_dir}:/var/lib/pgsql/data:Z"
# Setup the cluster
slave_num=2 setup_replication_cluster
# Check if the master knows about the slaves
CONTAINER_IP=$master_ip
test_slave_visibility
echo "Kill the master and create a new one"
local cidfile=$CIDFILE_DIR/master-$cid_suffix.cid
docker kill $(cat $cidfile)
# Don't forget to remove its .cid file
rm $cidfile
run_master $cid_suffix
CONTAINER_IP=$(get_container_ip master-$cid_suffix.cid)
# Update master_ip in slaves
for slave in $slave_cids; do
docker exec -u 0 $slave bash -c "sed \"s/$master_ip/$CONTAINER_IP/g\" /etc/hosts >/tmp/hosts && cp /tmp/hosts /etc/hosts"
done
master_ip=$CONTAINER_IP
# Check if the new master sees existing slaves
test_slave_visibility
# Check if the replication works
table_name="t1" test_value_replication
}
function run_replication_test() {
local DB=postgres
local PGUSER=master
local PASS=master
echo "Testing master-slave replication"
local cluster_args="-e POSTGRESQL_ADMIN_PASSWORD=pass -e POSTGRESQL_MASTER_USER=$PGUSER -e POSTGRESQL_MASTER_PASSWORD=$PASS"
local cid_suffix="basic"
local master_ip=
local slave_cids=
# Setup the cluster
setup_replication_cluster
# Check if the master knows about the slaves
CONTAINER_IP=$master_ip
test_slave_visibility
# Do some real work to test replication in practice
table_name="t1" test_value_replication
}
function run_change_password_test() {
echo " Testing password change"
local name="change_password"
local database='db'
local user='user'
local password='password'
local admin_password='adminPassword'
create_volume_dir
local volume_options="-v ${volume_dir}:/var/lib/pgsql/data:Z"
DOCKER_ARGS="
-e POSTGRESQL_DATABASE=${database}
-e POSTGRESQL_USER=${user}
-e POSTGRESQL_PASSWORD=${password}
-e POSTGRESQL_ADMIN_PASSWORD=${admin_password}
$volume_options
" create_container ${name}
# need to set these because `postgresql_cmd` relies on global variables
PGUSER=${user}
PASS=${password}
# need this to wait for the container to start up
CONTAINER_IP=$(get_container_ip ${name})
test_connection ${name}
echo " Testing login"
assert_login_access ${user} ${password} true
assert_login_access 'postgres' ${admin_password} true
echo " Changing passwords"
docker stop $(get_cid ${name})
DOCKER_ARGS="
-e POSTGRESQL_DATABASE=${database}
-e POSTGRESQL_USER=${user}
-e POSTGRESQL_PASSWORD=NEW_${password}
-e POSTGRESQL_ADMIN_PASSWORD=NEW_${admin_password}
$volume_options
" create_container "${name}_NEW"
# need to set this because `postgresql_cmd` relies on global variables
PASS="NEW_${password}"
# need this to wait for the container to start up
CONTAINER_IP=$(get_container_ip "${name}_NEW")
test_connection "${name}_NEW"
echo " Testing login with new passwords"
assert_login_access ${user} "NEW_${password}" true
assert_login_access ${user} ${password} false
assert_login_access 'postgres' "NEW_${admin_password}" true
assert_login_access 'postgres' ${admin_password} false
echo " Success!"
}
run_upgrade_test ()
{
# Do not run on Fedora or RHEL8 until the upgrade script
# is fixed for non-SCL use cases
{ [ "${OS}" == "fedora" ] || [ "${OS}" == "rhel8" ]; } && return 0
local upgrade_path="none 9.2 9.4 9.5 9.6 10 none" prev= act=
for act in $upgrade_path; do
if test "$act" = $VERSION; then
break
fi
prev=$act
done
test "$prev" != none
# Check if the previous image is available in the registry
docker pull "$(get_image_id "$prev:remote")" || return 0
# TODO: We run this script from $VERSION directory, through test/run symlink.
test/run_upgrade_test "$prev:remote" "$VERSION:local"
}
run_migration_test ()
{
[ "${OS}" == "fedora" ] && return 0
local from_version
# Only test a subset of the migration path on non-intel hosts
if [ "$(uname -i)" == "x86_64" ]; then
local upgrade_path="9.2 9.4 9.5 9.6 10"
else
local upgrade_path="10"
fi
for from_version in $upgrade_path; do
# Do not test migration from $VERSION:remote to $VERSION:local
test $(version2number $from_version) -lt $(version2number "$VERSION") \
|| break
# Skip if the previous image is not available in the registry
docker pull "$(get_image_id "$from_version:remote")" || continue
test/run_migration_test $from_version:remote $VERSION:local
done
}
run_doc_test() {
local tmpdir=$(mktemp -d)
local f
echo " Testing documentation in the container image"
# Extract the help files from the container
for f in help.1 ; do
docker run --rm ${IMAGE_NAME} /bin/bash -c "cat /${f}" >${tmpdir}/$(basename ${f})
# Check whether the files include some important information
for term in "POSTGRESQL\_ADMIN\_PASSWORD" volume 5432 ; do
if ! cat ${tmpdir}/$(basename ${f}) | grep -F -q -e "${term}" ; then
echo "ERROR: File /${f} does not include '${term}'."
return 1
fi
done
done
# Check whether the files use the correct format
if ! file ${tmpdir}/help.1 | grep -q roff ; then
echo "ERROR: /help.1 is not in troff or groff format"
return 1
fi
echo " Success!"
echo
}
test_the_app_image () {
local container_name=$1
local mount_opts=$2
echo " Testing s2i app image with invalid configuration"
assert_container_creation_fails -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db
echo " Testing s2i app image with correct configuration"
DOCKER_ARGS="
-e POSTGRESQL_DATABASE=db
-e POSTGRESQL_USER=user
-e POSTGRESQL_PASSWORD=password
-e POSTGRESQL_ADMIN_PASSWORD=password
-e POSTGRESQL_BACKUP_USER=backuser
-e POSTGRESQL_BACKUP_PASSWORD=pass
${mount_opts}
" create_container "$container_name"
# need this to wait for the container to start up
PGUSER=user PASS=password test_connection "$container_name"
PGUSER=backuser PASS=pass DB=backup test_connection "$container_name"
docker stop "$(get_cid $container_name)" >/dev/null
}
run_s2i_test() {
local temp_file
echo " Testing s2i usage"
ct_s2i_usage "${IMAGE_NAME}" --pull-policy=never 1>/dev/null
echo " Testing s2i build"
local s2i_image_name=$IMAGE_NAME-testapp_$(ct_random_string)
images_to_clean+=( "$s2i_image_name" )
ct_s2i_build_as_df "file://${test_dir}/test-app" "${IMAGE_NAME}" "$s2i_image_name" 1>/dev/null
IMAGE_NAME=$s2i_image_name test_the_app_image s2i_config_build ""
echo " Testing s2i mount"
create_temp_file
cat "$test_dir"/test-app/postgresql-init/backup_user.sh >> "$temp_file"
# Test against original image, not the s2i one. But even if so, we expect
# user mouns the directory under "s2i" direcetory $APP_DATA/src.
local mount_point=/opt/app-root/src/postgresql-init/add_backup_user.sh
test_the_app_image _s2i_test_mount "-v ${temp_file}:$mount_point:z,ro"
echo " Success!"
}
function run_general_tests() {
PGUSER=user PASS=pass POSTGRESQL_MAX_CONNECTIONS=42 POSTGRESQL_MAX_PREPARED_TRANSACTIONS=42 POSTGRESQL_SHARED_BUFFERS=64MB run_tests no_admin
PGUSER=user1 PASS=pass1 ADMIN_PASS=r00t run_tests admin
DB=postgres ADMIN_PASS=r00t run_tests only_admin
# Test with arbitrary uid for the container
DOCKER_ARGS="-u 12345" PGUSER=user2 PASS=pass run_tests no_admin_altuid
DOCKER_ARGS="-u 12345" PGUSER=user3 PASS=pass1 ADMIN_PASS=r00t run_tests admin_altuid
DB=postgres DOCKER_ARGS="-u 12345" ADMIN_PASS=rOOt run_tests only_admin_altuid
}
run_test_cfg_hook()
{
local volume_dir name=pg-test-cfg-dir
volume_dir=$(mktemp -d --tmpdir pg-hook-volume.XXXXX)
add_cleanup_command /bin/rm -rf "$volume_dir"
setfacl -R -m u:26:rwx "$volume_dir"
cp -r "$test_dir"/examples/custom-config/* "$volume_dir"
setfacl -R -m u:26:rwx "$volume_dir"
DOCKER_ARGS="
-e POSTGRESQL_ADMIN_PASSWORD=password
-v $volume_dir:/opt/app-root/src:Z
" create_container "$name"
assert_runtime_option "$name" shared_buffers 111MB
# Check that POSTGRESQL_SHARED_BUFFERS has effect.
DOCKER_ARGS="
-e POSTGRESQL_ADMIN_PASSWORD=password
-e POSTGRESQL_SHARED_BUFFERS=113MB
" create_container "$name-2"
assert_runtime_option "$name-2" shared_buffers 113MB
# Check that volume has priority over POSTGRESQL_SHARED_BUFFERS.
DOCKER_ARGS="
-e POSTGRESQL_ADMIN_PASSWORD=password
-e POSTGRESQL_SHARED_BUFFERS=113MB
-v $volume_dir:/opt/app-root/src:Z
" create_container "$name-3"
assert_runtime_option "$name-3" shared_buffers 111MB
}
run_s2i_enable_ssl_test()
{
local s2i_image_name="$IMAGE_NAME-ssl_$(ct_random_string)"
ct_s2i_build_as_df "file://$test_dir/examples/enable-ssl" "${IMAGE_NAME}" "$s2i_image_name" 1>/dev/null
images_to_clean+=( "$s2i_image_name" )
local container_name=enable-ssl-test
DOCKER_ARGS="-e POSTGRESQL_ADMIN_PASSWORD=password" \
IMAGE_NAME="$s2i_image_name" create_container "$container_name"
wait_ready "$container_name"
CONTAINER_IP=$(get_container_ip $container_name)
DB=postgres assert_login_access postgres password true
docker run --rm -e PGPASSWORD="password" "$IMAGE_NAME" psql "postgresql://postgres@$CONTAINER_IP:5432/postgres?sslmode=require" || \
false "FAIL: Did not manage to connect using SSL only."
docker stop "$(get_cid "$container_name")"
}
run_s2i_bake_data_test ()
{
local s2i_image_name="$IMAGE_NAME-bake_$(ct_random_string)"
ct_s2i_build_as_df "file://$test_dir/examples/s2i-dump-data" "${IMAGE_NAME}" "$s2i_image_name" 1>/dev/null
images_to_clean+=( "$s2i_image_name" )
local container_name=bake-data-test
DOCKER_ARGS="-e POSTGRESQL_ADMIN_PASSWORD=password" \
IMAGE_NAME="$s2i_image_name" create_container "$container_name"
wait_ready "$container_name"
test "hello world" == "$(docker exec "$(get_cid "$container_name")" \
bash -c "psql -tA -c 'SELECT * FROM test;'")"
docker stop "$(get_cid "$container_name")"
}
function run_all_tests() {
for test_case in $TEST_LIST; do
: "Running test $test_case"
$test_case
done;
}
# configuration defaults
POSTGRESQL_MAX_CONNECTIONS=100
POSTGRESQL_MAX_PREPARED_TRANSACTIONS=0
POSTGRESQL_SHARED_BUFFERS=32MB
# Run the chosen tests
TEST_LIST=${TESTS:-$TEST_LIST} run_all_tests

File diff suppressed because it is too large Load diff

1
test/test-lib-openshift.sh Symbolic link
View file

@ -0,0 +1 @@
../common/test-lib-openshift.sh

View file

@ -13,19 +13,27 @@ source ${THISDIR}/test-lib-openshift.sh
function test_postgresql_integration() {
local image_name=$1
local VERSION=$2
local import_image=$3
local service_name=${import_image##*/}
local service_name=postgresql
ct_os_template_exists postgresql-ephemeral && t=postgresql-ephemeral || t=postgresql-persistent
ct_os_test_template_app_func "${image_name}" \
"${t}" \
"${service_name}" \
"ct_os_check_cmd_internal '${import_image}' '${service_name}' 'PGPASSWORD=testp pg_isready -t 15 -h <IP> -U testu -d testdb' 'accepting connections' 120" \
"ct_os_check_cmd_internal '<SAME_IMAGE>' '${service_name}-testing' 'PGPASSWORD=testp pg_isready -t 15 -h <IP> -U testu -d testdb' 'accepting connections' 120" \
"-p POSTGRESQL_VERSION=${VERSION} \
-p DATABASE_SERVICE_NAME="${service_name}-testing" \
-p POSTGRESQL_USER=testu \
-p POSTGRESQL_PASSWORD=testp \
-p POSTGRESQL_DATABASE=testdb" "" "${import_image}"
-p POSTGRESQL_DATABASE=testdb"
}
# Check the imagestream
function test_postgresql_imagestream() {
case ${OS} in
rhel7|centos7) ;;
*) echo "Imagestream testing not supported for $OS environment." ; return 0 ;;
esac
ct_os_test_image_stream_template "${THISDIR}/../imagestreams/postgresql-${OS%[0-9]*}.json" "${THISDIR}/../examples/postgresql-ephemeral-template.json" postgresql "-p POSTGRESQL_VERSION=${VERSION}"
}
# vim: set tabstop=2:shiftwidth=2:expandtab:

View file

@ -1,653 +0,0 @@
# shellcheck shell=bash
#
# Test a container image.
#
# Always use sourced from a specific container testfile
#
# reguires definition of CID_FILE_DIR
# CID_FILE_DIR=$(mktemp --suffix=<container>_test_cidfiles -d)
# reguires definition of TEST_LIST
# TEST_LIST="\
# ctest_container_creation
# ctest_doc_content"
# Container CI tests
# abbreviated as "ct"
# may be redefined in the specific container testfile
EXPECTED_EXIT_CODE=0
# ct_cleanup
# --------------------
# Cleans up containers used during tests. Stops and removes all containers
# referenced by cid_files in CID_FILE_DIR. Dumps logs if a container exited
# unexpectedly. Removes the cid_files and CID_FILE_DIR as well.
# Uses: $CID_FILE_DIR - path to directory containing cid_files
# Uses: $EXPECTED_EXIT_CODE - expected container exit code
function ct_cleanup() {
for cid_file in "$CID_FILE_DIR"/* ; do
local container
container=$(cat "$cid_file")
: "Stopping and removing container $container..."
docker stop "$container"
exit_status=$(docker inspect -f '{{.State.ExitCode}}' "$container")
if [ "$exit_status" != "$EXPECTED_EXIT_CODE" ]; then
: "Dumping logs for $container"
docker logs "$container"
fi
docker rm -v "$container"
rm "$cid_file"
done
rmdir "$CID_FILE_DIR"
: "Done."
}
# ct_enable_cleanup
# --------------------
# Enables automatic container cleanup after tests.
function ct_enable_cleanup() {
trap ct_cleanup EXIT SIGINT
}
# ct_get_cid [name]
# --------------------
# Prints container id from cid_file based on the name of the file.
# Argument: name - name of cid_file where the container id will be stored
# Uses: $CID_FILE_DIR - path to directory containing cid_files
function ct_get_cid() {
local name="$1" ; shift || return 1
cat "$CID_FILE_DIR/$name"
}
# ct_get_cip [id]
# --------------------
# Prints container ip address based on the container id.
# Argument: id - container id
function ct_get_cip() {
local id="$1" ; shift
docker inspect --format='{{.NetworkSettings.IPAddress}}' "$(ct_get_cid "$id")"
}
# ct_wait_for_cid [cid_file]
# --------------------
# Holds the execution until the cid_file is created. Usually run after container
# creation.
# Argument: cid_file - name of the cid_file that should be created
function ct_wait_for_cid() {
local cid_file=$1
local max_attempts=10
local sleep_time=1
local attempt=1
local result=1
while [ $attempt -le $max_attempts ]; do
[ -f "$cid_file" ] && [ -s "$cid_file" ] && return 0
: "Waiting for container start..."
attempt=$(( attempt + 1 ))
sleep $sleep_time
done
return 1
}
# ct_assert_container_creation_fails [container_args]
# --------------------
# The invocation of docker run should fail based on invalid container_args
# passed to the function. Returns 0 when container fails to start properly.
# Argument: container_args - all arguments are passed directly to dokcer run
# Uses: $CID_FILE_DIR - path to directory containing cid_files
function ct_assert_container_creation_fails() {
local ret=0
local max_attempts=10
local attempt=1
local cid_file=assert
set +e
local old_container_args="${CONTAINER_ARGS-}"
# we really work with CONTAINER_ARGS as with a string
# shellcheck disable=SC2124
CONTAINER_ARGS="$@"
if ct_create_container "$cid_file" ; then
local cid
cid=$(ct_get_cid "$cid_file")
while [ "$(docker inspect -f '{{.State.Running}}' "$cid")" == "true" ] ; do
sleep 2
attempt=$(( attempt + 1 ))
if [ "$attempt" -gt "$max_attempts" ]; then
docker stop "$cid"
ret=1
break
fi
done
exit_status=$(docker inspect -f '{{.State.ExitCode}}' "$cid")
if [ "$exit_status" == "0" ]; then
ret=1
fi
docker rm -v "$cid"
rm "$CID_FILE_DIR/$cid_file"
fi
[ -n "$old_container_args" ] && CONTAINER_ARGS="$old_container_args"
set -e
return "$ret"
}
# ct_create_container [name, command]
# --------------------
# Creates a container using the IMAGE_NAME and CONTAINER_ARGS variables. Also
# stores the container id to a cid_file located in the CID_FILE_DIR, and waits
# for the creation of the file.
# Argument: name - name of cid_file where the container id will be stored
# Argument: command - optional command to be executed in the container
# Uses: $CID_FILE_DIR - path to directory containing cid_files
# Uses: $CONTAINER_ARGS - optional arguments passed directly to docker run
# Uses: $IMAGE_NAME - name of the image being tested
function ct_create_container() {
local cid_file="$CID_FILE_DIR/$1" ; shift
# create container with a cidfile in a directory for cleanup
# shellcheck disable=SC2086
docker run --cidfile="$cid_file" -d ${CONTAINER_ARGS:-} "$IMAGE_NAME" "$@"
ct_wait_for_cid "$cid_file" || return 1
: "Created container $(cat "$cid_file")"
}
# ct_scl_usage_old [name, command, expected]
# --------------------
# Tests three ways of running the SCL, by looking for an expected string
# in the output of the command
# Argument: name - name of cid_file where the container id will be stored
# Argument: command - executed inside the container
# Argument: expected - string that is expected to be in the command output
# Uses: $CID_FILE_DIR - path to directory containing cid_files
# Uses: $IMAGE_NAME - name of the image being tested
function ct_scl_usage_old() {
local name="$1"
local command="$2"
local expected="$3"
local out=""
: " Testing the image SCL enable"
out=$(docker run --rm "${IMAGE_NAME}" /bin/bash -c "${command}")
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[/bin/bash -c \"${command}\"] Expected '${expected}', got '${out}'" >&2
return 1
fi
out=$(docker exec "$(ct_get_cid "$name")" /bin/bash -c "${command}" 2>&1)
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[exec /bin/bash -c \"${command}\"] Expected '${expected}', got '${out}'" >&2
return 1
fi
out=$(docker exec "$(ct_get_cid "$name")" /bin/sh -ic "${command}" 2>&1)
if ! echo "${out}" | grep -q "${expected}"; then
echo "ERROR[exec /bin/sh -ic \"${command}\"] Expected '${expected}', got '${out}'" >&2
return 1
fi
}
# ct_doc_content_old [strings]
# --------------------
# Looks for occurence of stirngs in the documentation files and checks
# the format of the files. Files examined: help.1
# Argument: strings - strings expected to appear in the documentation
# Uses: $IMAGE_NAME - name of the image being tested
function ct_doc_content_old() {
local tmpdir
tmpdir=$(mktemp -d)
local f
: " Testing documentation in the container image"
# Extract the help files from the container
# shellcheck disable=SC2043
for f in help.1 ; do
docker run --rm "${IMAGE_NAME}" /bin/bash -c "cat /${f}" >"${tmpdir}/$(basename "${f}")"
# Check whether the files contain some important information
for term in "$@" ; do
if ! grep -F -q -e "${term}" "${tmpdir}/$(basename "${f}")" ; then
echo "ERROR: File /${f} does not include '${term}'." >&2
return 1
fi
done
# Check whether the files use the correct format
for term in TH PP SH ; do
if ! grep -q "^\.${term}" "${tmpdir}/help.1" ; then
echo "ERROR: /help.1 is probably not in troff or groff format, since '${term}' is missing." >&2
return 1
fi
done
done
: " Success!"
}
# full_ca_file_path
# Return string for full path to CA file
function full_ca_file_path()
{
echo "/etc/pki/ca-trust/source/anchors/RH-IT-Root-CA.crt"
}
# ct_mount_ca_file
# ------------------
# Check if /etc/pki/certs/RH-IT-Root-CA.crt file exists
# return mount string for containers or empty string
function ct_mount_ca_file()
{
# mount CA file only if NPM_REGISTRY variable is present.
local mount_parameter=""
if [ -n "$NPM_REGISTRY" ] && [ -f "$(full_ca_file_path)" ]; then
mount_parameter="-v $(full_ca_file_path):$(full_ca_file_path):Z"
fi
echo "$mount_parameter"
}
# ct_build_s2i_npm_variables URL_TO_NPM_JS_SERVER
# ------------------------------------------
# Function returns -e NPM_MIRROR and -v MOUNT_POINT_FOR_CAFILE
# or empty string
function ct_build_s2i_npm_variables()
{
npm_variables=""
if [ -n "$NPM_REGISTRY" ] && [ -f "$(full_ca_file_path)" ]; then
npm_variables="-e NPM_MIRROR=$NPM_REGISTRY $(ct_mount_ca_file)"
fi
echo "$npm_variables"
}
# ct_npm_works
# --------------------
# Checks existance of the npm tool and runs it.
function ct_npm_works() {
local tmpdir
tmpdir=$(mktemp -d)
: " Testing npm in the container image"
local cid_file="${tmpdir}/cid"
if ! docker run --rm "${IMAGE_NAME}" /bin/bash -c "npm --version" >"${tmpdir}/version" ; then
echo "ERROR: 'npm --version' does not work inside the image ${IMAGE_NAME}." >&2
return 1
fi
# shellcheck disable=SC2046
docker run -d $(ct_mount_ca_file) --rm --cidfile="$cid_file" "${IMAGE_NAME}-testapp"
# Wait for the container to write it's CID file
ct_wait_for_cid "$cid_file" || return 1
if ! docker exec "$(cat "$cid_file")" /bin/bash -c "npm --verbose install jquery && test -f node_modules/jquery/src/jquery.js" >"${tmpdir}/jquery" 2>&1 ; then
echo "ERROR: npm could not install jquery inside the image ${IMAGE_NAME}." >&2
return 1
fi
if [ -n "$NPM_REGISTRY" ] && [ -f "$(full_ca_file_path)" ]; then
if ! grep -qo "$NPM_REGISTRY" "${tmpdir}/jquery"; then
echo "ERROR: Internal repository is NOT set. Even it is requested."
return 1
fi
fi
if [ -f "$cid_file" ]; then
docker stop "$(cat "$cid_file")"
rm "$cid_file"
fi
: " Success!"
}
# ct_path_append PATH_VARNAME DIRECTORY
# -------------------------------------
# Append DIRECTORY to VARIABLE of name PATH_VARNAME, the VARIABLE must consist
# of colon-separated list of directories.
ct_path_append ()
{
if eval "test -n \"\${$1-}\""; then
eval "$1=\$2:\$$1"
else
eval "$1=\$2"
fi
}
# ct_path_foreach PATH ACTION [ARGS ...]
# --------------------------------------
# For each DIR in PATH execute ACTION (path is colon separated list of
# directories). The particular calls to ACTION will look like
# '$ ACTION directory [ARGS ...]'
ct_path_foreach ()
{
local dir dirlist action save_IFS
save_IFS=$IFS
IFS=:
dirlist=$1
action=$2
shift 2
for dir in $dirlist; do "$action" "$dir" "$@" ; done
IFS=$save_IFS
}
# ct_run_test_list
# --------------------
# Execute the tests specified by TEST_LIST
# Uses: $TEST_LIST - list of test names
function ct_run_test_list() {
for test_case in $TEST_LIST; do
: "Running test $test_case"
# shellcheck source=/dev/null
[ -f "test/$test_case" ] && source "test/$test_case"
# shellcheck source=/dev/null
[ -f "../test/$test_case" ] && source "../test/$test_case"
$test_case
done;
}
# ct_gen_self_signed_cert_pem
# ---------------------------
# Generates a self-signed PEM certificate pair into specified directory.
# Argument: output_dir - output directory path
# Argument: base_name - base name of the certificate files
# Resulted files will be those:
# <output_dir>/<base_name>-cert-selfsigned.pem -- public PEM cert
# <output_dir>/<base_name>-key.pem -- PEM private key
ct_gen_self_signed_cert_pem() {
local output_dir=$1 ; shift
local base_name=$1 ; shift
mkdir -p "${output_dir}"
openssl req -newkey rsa:2048 -nodes -keyout "${output_dir}"/"${base_name}"-key.pem -subj '/C=GB/ST=Berkshire/L=Newbury/O=My Server Company' > "${base_name}"-req.pem
openssl req -new -x509 -nodes -key "${output_dir}"/"${base_name}"-key.pem -batch > "${output_dir}"/"${base_name}"-cert-selfsigned.pem
}
# ct_obtain_input FILE|DIR|URL
# --------------------
# Either copies a file or a directory to a tmp location for local copies, or
# downloads the file from remote location.
# Resulted file path is printed, so it can be later used by calling function.
# Arguments: input - local file, directory or remote URL
function ct_obtain_input() {
local input=$1
local extension="${input##*.}"
# Try to use same extension for the temporary file if possible
[[ "${extension}" =~ ^[a-z0-9]*$ ]] && extension=".${extension}" || extension=""
local output
output=$(mktemp "/var/tmp/test-input-XXXXXX$extension")
if [ -f "${input}" ] ; then
cp -f "${input}" "${output}"
elif [ -d "${input}" ] ; then
rm -f "${output}"
cp -r -LH "${input}" "${output}"
elif echo "${input}" | grep -qe '^http\(s\)\?://' ; then
curl "${input}" > "${output}"
else
echo "ERROR: file type not known: ${input}" >&2
return 1
fi
echo "${output}"
}
# ct_test_response
# ----------------
# Perform GET request to the application container, checks output with
# a reg-exp and HTTP response code.
# Argument: url - request URL path
# Argument: expected_code - expected HTTP response code
# Argument: body_regexp - PCRE regular expression that must match the response body
# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between
# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10)
ct_test_response() {
local url="$1"
local expected_code="$2"
local body_regexp="$3"
local max_attempts=${4:-20}
local ignore_error_attempts=${5:-10}
: " Testing the HTTP(S) response for <${url}>"
local sleep_time=3
local attempt=1
local result=1
local status
local response_code
local response_file
response_file=$(mktemp /tmp/ct_test_response_XXXXXX)
while [ "${attempt}" -le "${max_attempts}" ]; do
curl --connect-timeout 10 -s -w '%{http_code}' "${url}" >"${response_file}" && status=0 || status=1
if [ "${status}" -eq 0 ]; then
response_code=$(tail -c 3 "${response_file}")
if [ "${response_code}" -eq "${expected_code}" ]; then
result=0
fi
grep -qP -e "${body_regexp}" "${response_file}" || result=1;
# Some services return 40x code until they are ready, so let's give them
# some chance and not end with failure right away
# Do not wait if we already have expected outcome though
if [ "${result}" -eq 0 ] || [ "${attempt}" -gt "${ignore_error_attempts}" ] || [ "${attempt}" -eq "${max_attempts}" ] ; then
break
fi
fi
attempt=$(( attempt + 1 ))
sleep "${sleep_time}"
done
rm -f "${response_file}"
return "${result}"
}
# ct_registry_from_os OS
# ----------------
# Transform operating system string [os] into registry url
# Argument: OS - string containing the os version
ct_registry_from_os() {
local registry=""
case $1 in
rhel*)
registry=registry.redhat.io
;;
*)
registry=docker.io
;;
esac
echo "$registry"
}
# ct_get_public_image_name OS BASE_IMAGE_NAME VERSION
# ----------------
# Transform the arguments into public image name
# Argument: OS - string containing the os version
# Argument: BASE_IMAGE_NAME - string containing the base name of the image as defined in the Makefile
# Argument: VERSION - string containing the version of the image as defined in the Makefile
ct_get_public_image_name() {
local os=$1; shift
local base_image_name=$1; shift
local version=$1; shift
local public_image_name
local registry
registry=$(ct_registry_from_os "$os")
if [ "x$os" == "xrhel7" ]; then
public_image_name=$registry/rhscl/$base_image_name-${version//./}-rhel7
elif [ "x$os" == "xrhel8" ]; then
public_image_name=$registry/rhel8/$base_image_name-${version//./}
elif [ "x$os" == "xcentos7" ]; then
public_image_name=$registry/centos/$base_image_name-${version//./}-centos7
fi
echo "$public_image_name"
}
# ct_assert_cmd_success CMD
# ----------------
# Evaluates [cmd] and fails if it does not succeed.
# Argument: CMD - Command to be run
function ct_assert_cmd_success() {
echo "Checking '$*' for success ..."
if ! eval "$@" &>/dev/null; then
echo " FAIL"
return 1
fi
echo " PASS"
return 0
}
# ct_assert_cmd_failure CMD
# ----------------
# Evaluates [cmd] and fails if it succeeds.
# Argument: CMD - Command to be run
function ct_assert_cmd_failure() {
echo "Checking '$*' for failure ..."
if eval "$@" &>/dev/null; then
echo " FAIL"
return 1
fi
echo " PASS"
return 0
}
# ct_random_string [LENGTH=10]
# ----------------------------
# Generate pseudorandom alphanumeric string of LENGTH bytes, the
# default length is 10. The string is printed on stdout.
ct_random_string()
(
export LC_ALL=C
dd if=/dev/urandom count=1 bs=10k 2>/dev/null \
| tr -dc 'a-z0-9' \
| fold -w "${1-10}" \
| head -n 1
)
# ct_s2i_usage IMG_NAME [S2I_ARGS]
# ----------------------------
# Create a container and run the usage script inside
# Argument: IMG_NAME - name of the image to be used for the container run
# Argument: S2I_ARGS - Additional list of source-to-image arguments, currently unused.
ct_s2i_usage()
{
local img_name=$1; shift
local s2i_args="$*";
local usage_command="/usr/libexec/s2i/usage"
docker run --rm "$img_name" bash -c "$usage_command"
}
# ct_s2i_build_as_df APP_PATH SRC_IMAGE DST_IMAGE [S2I_ARGS]
# ----------------------------
# Create a new s2i app image from local sources in a similar way as source-to-image would have used.
# Argument: APP_PATH - local path to the app sources to be used in the test
# Argument: SRC_IMAGE - image to be used as a base for the s2i build
# Argument: DST_IMAGE - image name to be used during the tagging of the s2i build result
# Argument: S2I_ARGS - Additional list of source-to-image arguments.
# Only used to check for pull-policy=never and environment variable definitions.
ct_s2i_build_as_df()
{
local app_path=$1; shift
local src_image=$1; shift
local dst_image=$1; shift
local s2i_args="$*";
local local_app=upload/src/
local local_scripts=upload/scripts/
local user_id=
local df_name=
local tmpdir=
local incremental=false
local mount_options=""
# Run the entire thing inside a subshell so that we do not leak shell options outside of the function
(
# Error out if any part of the build fails
set -e
# Use /tmp to not pollute cwd
tmpdir=$(mktemp -d)
df_name=$(mktemp -p "$tmpdir" Dockerfile.XXXX)
cd "$tmpdir"
# Check if the image is available locally and try to pull it if it is not
docker images "$src_image" &>/dev/null || echo "$s2i_args" | grep -q "pull-policy=never" || docker pull "$src_image"
user=$(docker inspect -f "{{.Config.User}}" "$src_image")
# Default to root if no user is set by the image
user=${user:-0}
# run the user through the image in case it is non-numeric or does not exist
# NOTE: The '-eq' test is used to check if $user is numeric as it will fail if $user is not an integer
if ! [ "$user" -eq "$user" ] 2>/dev/null && ! user_id=$(docker run --rm "$src_image" bash -c "id -u $user 2>/dev/null"); then
echo "ERROR: id of user $user not found inside image $src_image."
echo "Terminating s2i build."
return 1
else
user_id=${user_id:-$user}
fi
echo "$s2i_args" | grep -q "\-\-incremental" && incremental=true
if $incremental; then
inc_tmp=$(mktemp -d --tmpdir incremental.XXXX)
setfacl -m "u:$user_id:rwx" "$inc_tmp"
# Check if the image exists, build should fail (for testing use case) if it does not
docker images "$dst_image" &>/dev/null || (echo "Image $dst_image not found."; false)
# Run the original image with a mounted in volume and get the artifacts out of it
cmd="if [ -s /usr/libexec/s2i/save-artifacts ]; then /usr/libexec/s2i/save-artifacts > \"$inc_tmp/artifacts.tar\"; else touch \"$inc_tmp/artifacts.tar\"; fi"
docker run --rm -v "$inc_tmp:$inc_tmp:Z" "$dst_image" bash -c "$cmd"
# Move the created content into the $tmpdir for the build to pick it up
mv "$inc_tmp/artifacts.tar" "$tmpdir/"
fi
# Strip file:// from APP_PATH and copy its contents into current context
mkdir -p "$local_app"
cp -r "${app_path/file:\/\//}/." "$local_app"
[ -d "$local_app/.s2i/bin/" ] && mv "$local_app/.s2i/bin" "$local_scripts"
# Create a Dockerfile named df_name and fill it with proper content
#FIXME: Some commands could be combined into a single layer but not sure if worth the trouble for testing purposes
cat <<EOF >"$df_name"
FROM $src_image
LABEL "io.openshift.s2i.build.image"="$src_image" \\
"io.openshift.s2i.build.source-location"="$app_path"
USER root
COPY $local_app /tmp/src
EOF
[ -d "$local_scripts" ] && echo "COPY $local_scripts /tmp/scripts" >> "$df_name" &&
echo "RUN chown -R $user_id:0 /tmp/scripts" >>"$df_name"
echo "RUN chown -R $user_id:0 /tmp/src" >>"$df_name"
# Check for custom environment variables inside .s2i/ folder
if [ -e "$local_app/.s2i/environment" ]; then
# Remove any comments and add the contents as ENV commands to the Dockerfile
sed '/^\s*#.*$/d' "$local_app/.s2i/environment" | while read -r line; do
echo "ENV $line" >>"$df_name"
done
fi
# Filter out env var definitions from $s2i_args and create Dockerfile ENV commands out of them
echo "$s2i_args" | grep -o -e '\(-e\|--env\)[[:space:]=]\S*=\S*' | sed -e 's/-e /ENV /' -e 's/--env[ =]/ENV /' >>"$df_name"
# Check if CA autority is present on host and add it into Dockerfile
[ -f "$(full_ca_file_path)" ] && echo "RUN cd /etc/pki/ca-trust/source/anchors && update-ca-trust extract" >>"$df_name"
# Add in artifacts if doing an incremental build
if $incremental; then
{ echo "RUN mkdir /tmp/artifacts"
echo "ADD artifacts.tar /tmp/artifacts"
echo "RUN chown -R $user_id:0 /tmp/artifacts" ; } >>"$df_name"
fi
echo "USER $user_id" >>"$df_name"
# If exists, run the custom assemble script, else default to /usr/libexec/s2i/assemble
if [ -x "$local_scripts/assemble" ]; then
echo "RUN /tmp/scripts/assemble" >>"$df_name"
else
echo "RUN /usr/libexec/s2i/assemble" >>"$df_name"
fi
# If exists, set the custom run script as CMD, else default to /usr/libexec/s2i/run
if [ -x "$local_scripts/run" ]; then
echo "CMD /tmp/scripts/run" >>"$df_name"
else
echo "CMD /usr/libexec/s2i/run" >>"$df_name"
fi
# Check if -v parameter is present in s2i_args and add it into docker build command
mount_options=$(echo "$s2i_args" | grep -o -e '\(-v\)[[:space:]]\.*\S*' || true)
# Run the build and tag the result
# shellcheck disable=SC2086
docker build $mount_options -f "$df_name" --no-cache=true -t "$dst_image" .
)
}
# ct_check_image_availability PUBLIC_IMAGE_NAME
# ----------------------------
# Pull an image from the public repositories to see if the image is already available.
# Argument: PUBLIC_IMAGE_NAME - string containing the public name of the image to pull
ct_check_image_availability() {
local public_image_name=$1;
# Try pulling the image to see if it is accessible
if ! docker pull "$public_image_name" &>/dev/null; then
echo "$public_image_name could not be downloaded via 'docker'"
return 1
fi
}
# vim: set tabstop=2:shiftwidth=2:expandtab:

1
test/test-lib.sh Symbolic link
View file

@ -0,0 +1 @@
../common/test-lib.sh