Compare commits
2 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
82b9c3b753 | ||
|
|
9b9facaf28 |
92 changed files with 1 additions and 9428 deletions
0
.gitignore
vendored
0
.gitignore
vendored
1
12
1
12
|
|
@ -1 +0,0 @@
|
||||||
.
|
|
||||||
83
Dockerfile
83
Dockerfile
|
|
@ -1,83 +0,0 @@
|
||||||
FROM registry.fedoraproject.org/f33/s2i-core:latest
|
|
||||||
|
|
||||||
# PostgreSQL image for OpenShift.
|
|
||||||
# Volumes:
|
|
||||||
# * /var/lib/psql/data - Database cluster for PostgreSQL
|
|
||||||
# Environment:
|
|
||||||
# * $POSTGRESQL_USER - Database user name
|
|
||||||
# * $POSTGRESQL_PASSWORD - User's password
|
|
||||||
# * $POSTGRESQL_DATABASE - Name of the database to create
|
|
||||||
# * $POSTGRESQL_ADMIN_PASSWORD (Optional) - Password for the 'postgres'
|
|
||||||
# PostgreSQL administrative account
|
|
||||||
|
|
||||||
ENV NAME=postgresql \
|
|
||||||
VERSION=0 \
|
|
||||||
ARCH=x86_64 \
|
|
||||||
\
|
|
||||||
POSTGRESQL_VERSION=12 \
|
|
||||||
POSTGRESQL_PREV_VERSION=11 \
|
|
||||||
HOME=/var/lib/pgsql \
|
|
||||||
PGUSER=postgres \
|
|
||||||
APP_DATA=/opt/app-root
|
|
||||||
|
|
||||||
ENV SUMMARY="PostgreSQL is an advanced Object-Relational database management system" \
|
|
||||||
DESCRIPTION="PostgreSQL is an advanced Object-Relational database management system (DBMS). \
|
|
||||||
The image contains the client and server programs that you'll need to \
|
|
||||||
create, run, maintain and access a PostgreSQL DBMS server."
|
|
||||||
|
|
||||||
LABEL summary="$SUMMARY" \
|
|
||||||
description="$DESCRIPTION" \
|
|
||||||
io.k8s.description="$DESCRIPTION" \
|
|
||||||
io.k8s.display-name="PostgreSQL 12" \
|
|
||||||
io.openshift.expose-services="5432:postgresql" \
|
|
||||||
io.openshift.tags="database,postgresql,postgresql12" \
|
|
||||||
com.redhat.component="$NAME" \
|
|
||||||
maintainer="SoftwareCollections.org <sclorg@redhat.com>" \
|
|
||||||
name="$FGC/$NAME" \
|
|
||||||
version="0" \
|
|
||||||
usage="docker run -d --name postgresql_database -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db -p 5432:5432 $FGC/$NAME"
|
|
||||||
|
|
||||||
EXPOSE 5432
|
|
||||||
|
|
||||||
COPY root/usr/libexec/fix-permissions /usr/libexec/fix-permissions
|
|
||||||
|
|
||||||
# This image must forever use UID 26 for postgres user so our volumes are
|
|
||||||
# safe in the future. This should *never* change, the last test is there
|
|
||||||
# to make sure of that.
|
|
||||||
RUN INSTALL_PKGS="rsync tar gettext bind-utils postgresql-server postgresql-contrib nss_wrapper " && \
|
|
||||||
INSTALL_PKGS+="findutils xz" && \
|
|
||||||
INSTALL_PKGS+=" pgaudit" && \
|
|
||||||
dnf -y module enable postgresql:12 && \
|
|
||||||
dnf -y --setopt=tsflags=nodocs install $INSTALL_PKGS && \
|
|
||||||
rpm -V $INSTALL_PKGS && \
|
|
||||||
dnf clean all && \
|
|
||||||
test "$(id postgres)" = "uid=26(postgres) gid=26(postgres) groups=26(postgres)" && \
|
|
||||||
mkdir -p /var/lib/pgsql/data && \
|
|
||||||
/usr/libexec/fix-permissions /var/lib/pgsql /var/run/postgresql
|
|
||||||
|
|
||||||
# Get prefix path and path to scripts rather than hard-code them in scripts
|
|
||||||
ENV CONTAINER_SCRIPTS_PATH=/usr/share/container-scripts/postgresql
|
|
||||||
|
|
||||||
COPY root /
|
|
||||||
COPY ./s2i/bin/ $STI_SCRIPTS_PATH
|
|
||||||
|
|
||||||
VOLUME ["/var/lib/pgsql/data"]
|
|
||||||
|
|
||||||
# S2I permission fixes
|
|
||||||
# --------------------
|
|
||||||
# 1. unless specified otherwise (or - equivalently - we are in OpenShift), s2i
|
|
||||||
# build process would be executed as 'uid=26(postgres) gid=26(postgres)'.
|
|
||||||
# Such process wouldn't be able to execute the default 'assemble' script
|
|
||||||
# correctly (it transitively executes 'fix-permissions' script). So let's
|
|
||||||
# add the 'postgres' user into 'root' group here
|
|
||||||
#
|
|
||||||
# 2. we call fix-permissions on $APP_DATA here directly (UID=0 during build
|
|
||||||
# anyways) to assure that s2i process is actually able to _read_ the
|
|
||||||
# user-specified scripting.
|
|
||||||
RUN usermod -a -G root postgres && \
|
|
||||||
/usr/libexec/fix-permissions --read-only "$APP_DATA"
|
|
||||||
|
|
||||||
USER 26
|
|
||||||
|
|
||||||
ENTRYPOINT ["container-entrypoint"]
|
|
||||||
CMD ["run-postgresql"]
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
Dockerfile
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
root/usr/share/container-scripts/postgresql/README.md
|
|
||||||
|
|
@ -1,4 +0,0 @@
|
||||||
language: shell
|
|
||||||
os: linux
|
|
||||||
script:
|
|
||||||
- make shellcheck
|
|
||||||
202
common/LICENSE
202
common/LICENSE
|
|
@ -1,202 +0,0 @@
|
||||||
|
|
||||||
Apache License
|
|
||||||
Version 2.0, January 2004
|
|
||||||
http://www.apache.org/licenses/
|
|
||||||
|
|
||||||
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
|
||||||
|
|
||||||
1. Definitions.
|
|
||||||
|
|
||||||
"License" shall mean the terms and conditions for use, reproduction,
|
|
||||||
and distribution as defined by Sections 1 through 9 of this document.
|
|
||||||
|
|
||||||
"Licensor" shall mean the copyright owner or entity authorized by
|
|
||||||
the copyright owner that is granting the License.
|
|
||||||
|
|
||||||
"Legal Entity" shall mean the union of the acting entity and all
|
|
||||||
other entities that control, are controlled by, or are under common
|
|
||||||
control with that entity. For the purposes of this definition,
|
|
||||||
"control" means (i) the power, direct or indirect, to cause the
|
|
||||||
direction or management of such entity, whether by contract or
|
|
||||||
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
|
||||||
outstanding shares, or (iii) beneficial ownership of such entity.
|
|
||||||
|
|
||||||
"You" (or "Your") shall mean an individual or Legal Entity
|
|
||||||
exercising permissions granted by this License.
|
|
||||||
|
|
||||||
"Source" form shall mean the preferred form for making modifications,
|
|
||||||
including but not limited to software source code, documentation
|
|
||||||
source, and configuration files.
|
|
||||||
|
|
||||||
"Object" form shall mean any form resulting from mechanical
|
|
||||||
transformation or translation of a Source form, including but
|
|
||||||
not limited to compiled object code, generated documentation,
|
|
||||||
and conversions to other media types.
|
|
||||||
|
|
||||||
"Work" shall mean the work of authorship, whether in Source or
|
|
||||||
Object form, made available under the License, as indicated by a
|
|
||||||
copyright notice that is included in or attached to the work
|
|
||||||
(an example is provided in the Appendix below).
|
|
||||||
|
|
||||||
"Derivative Works" shall mean any work, whether in Source or Object
|
|
||||||
form, that is based on (or derived from) the Work and for which the
|
|
||||||
editorial revisions, annotations, elaborations, or other modifications
|
|
||||||
represent, as a whole, an original work of authorship. For the purposes
|
|
||||||
of this License, Derivative Works shall not include works that remain
|
|
||||||
separable from, or merely link (or bind by name) to the interfaces of,
|
|
||||||
the Work and Derivative Works thereof.
|
|
||||||
|
|
||||||
"Contribution" shall mean any work of authorship, including
|
|
||||||
the original version of the Work and any modifications or additions
|
|
||||||
to that Work or Derivative Works thereof, that is intentionally
|
|
||||||
submitted to Licensor for inclusion in the Work by the copyright owner
|
|
||||||
or by an individual or Legal Entity authorized to submit on behalf of
|
|
||||||
the copyright owner. For the purposes of this definition, "submitted"
|
|
||||||
means any form of electronic, verbal, or written communication sent
|
|
||||||
to the Licensor or its representatives, including but not limited to
|
|
||||||
communication on electronic mailing lists, source code control systems,
|
|
||||||
and issue tracking systems that are managed by, or on behalf of, the
|
|
||||||
Licensor for the purpose of discussing and improving the Work, but
|
|
||||||
excluding communication that is conspicuously marked or otherwise
|
|
||||||
designated in writing by the copyright owner as "Not a Contribution."
|
|
||||||
|
|
||||||
"Contributor" shall mean Licensor and any individual or Legal Entity
|
|
||||||
on behalf of whom a Contribution has been received by Licensor and
|
|
||||||
subsequently incorporated within the Work.
|
|
||||||
|
|
||||||
2. Grant of Copyright License. Subject to the terms and conditions of
|
|
||||||
this License, each Contributor hereby grants to You a perpetual,
|
|
||||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
|
||||||
copyright license to reproduce, prepare Derivative Works of,
|
|
||||||
publicly display, publicly perform, sublicense, and distribute the
|
|
||||||
Work and such Derivative Works in Source or Object form.
|
|
||||||
|
|
||||||
3. Grant of Patent License. Subject to the terms and conditions of
|
|
||||||
this License, each Contributor hereby grants to You a perpetual,
|
|
||||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
|
||||||
(except as stated in this section) patent license to make, have made,
|
|
||||||
use, offer to sell, sell, import, and otherwise transfer the Work,
|
|
||||||
where such license applies only to those patent claims licensable
|
|
||||||
by such Contributor that are necessarily infringed by their
|
|
||||||
Contribution(s) alone or by combination of their Contribution(s)
|
|
||||||
with the Work to which such Contribution(s) was submitted. If You
|
|
||||||
institute patent litigation against any entity (including a
|
|
||||||
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
|
||||||
or a Contribution incorporated within the Work constitutes direct
|
|
||||||
or contributory patent infringement, then any patent licenses
|
|
||||||
granted to You under this License for that Work shall terminate
|
|
||||||
as of the date such litigation is filed.
|
|
||||||
|
|
||||||
4. Redistribution. You may reproduce and distribute copies of the
|
|
||||||
Work or Derivative Works thereof in any medium, with or without
|
|
||||||
modifications, and in Source or Object form, provided that You
|
|
||||||
meet the following conditions:
|
|
||||||
|
|
||||||
(a) You must give any other recipients of the Work or
|
|
||||||
Derivative Works a copy of this License; and
|
|
||||||
|
|
||||||
(b) You must cause any modified files to carry prominent notices
|
|
||||||
stating that You changed the files; and
|
|
||||||
|
|
||||||
(c) You must retain, in the Source form of any Derivative Works
|
|
||||||
that You distribute, all copyright, patent, trademark, and
|
|
||||||
attribution notices from the Source form of the Work,
|
|
||||||
excluding those notices that do not pertain to any part of
|
|
||||||
the Derivative Works; and
|
|
||||||
|
|
||||||
(d) If the Work includes a "NOTICE" text file as part of its
|
|
||||||
distribution, then any Derivative Works that You distribute must
|
|
||||||
include a readable copy of the attribution notices contained
|
|
||||||
within such NOTICE file, excluding those notices that do not
|
|
||||||
pertain to any part of the Derivative Works, in at least one
|
|
||||||
of the following places: within a NOTICE text file distributed
|
|
||||||
as part of the Derivative Works; within the Source form or
|
|
||||||
documentation, if provided along with the Derivative Works; or,
|
|
||||||
within a display generated by the Derivative Works, if and
|
|
||||||
wherever such third-party notices normally appear. The contents
|
|
||||||
of the NOTICE file are for informational purposes only and
|
|
||||||
do not modify the License. You may add Your own attribution
|
|
||||||
notices within Derivative Works that You distribute, alongside
|
|
||||||
or as an addendum to the NOTICE text from the Work, provided
|
|
||||||
that such additional attribution notices cannot be construed
|
|
||||||
as modifying the License.
|
|
||||||
|
|
||||||
You may add Your own copyright statement to Your modifications and
|
|
||||||
may provide additional or different license terms and conditions
|
|
||||||
for use, reproduction, or distribution of Your modifications, or
|
|
||||||
for any such Derivative Works as a whole, provided Your use,
|
|
||||||
reproduction, and distribution of the Work otherwise complies with
|
|
||||||
the conditions stated in this License.
|
|
||||||
|
|
||||||
5. Submission of Contributions. Unless You explicitly state otherwise,
|
|
||||||
any Contribution intentionally submitted for inclusion in the Work
|
|
||||||
by You to the Licensor shall be under the terms and conditions of
|
|
||||||
this License, without any additional terms or conditions.
|
|
||||||
Notwithstanding the above, nothing herein shall supersede or modify
|
|
||||||
the terms of any separate license agreement you may have executed
|
|
||||||
with Licensor regarding such Contributions.
|
|
||||||
|
|
||||||
6. Trademarks. This License does not grant permission to use the trade
|
|
||||||
names, trademarks, service marks, or product names of the Licensor,
|
|
||||||
except as required for reasonable and customary use in describing the
|
|
||||||
origin of the Work and reproducing the content of the NOTICE file.
|
|
||||||
|
|
||||||
7. Disclaimer of Warranty. Unless required by applicable law or
|
|
||||||
agreed to in writing, Licensor provides the Work (and each
|
|
||||||
Contributor provides its Contributions) on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
|
||||||
implied, including, without limitation, any warranties or conditions
|
|
||||||
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
|
||||||
PARTICULAR PURPOSE. You are solely responsible for determining the
|
|
||||||
appropriateness of using or redistributing the Work and assume any
|
|
||||||
risks associated with Your exercise of permissions under this License.
|
|
||||||
|
|
||||||
8. Limitation of Liability. In no event and under no legal theory,
|
|
||||||
whether in tort (including negligence), contract, or otherwise,
|
|
||||||
unless required by applicable law (such as deliberate and grossly
|
|
||||||
negligent acts) or agreed to in writing, shall any Contributor be
|
|
||||||
liable to You for damages, including any direct, indirect, special,
|
|
||||||
incidental, or consequential damages of any character arising as a
|
|
||||||
result of this License or out of the use or inability to use the
|
|
||||||
Work (including but not limited to damages for loss of goodwill,
|
|
||||||
work stoppage, computer failure or malfunction, or any and all
|
|
||||||
other commercial damages or losses), even if such Contributor
|
|
||||||
has been advised of the possibility of such damages.
|
|
||||||
|
|
||||||
9. Accepting Warranty or Additional Liability. While redistributing
|
|
||||||
the Work or Derivative Works thereof, You may choose to offer,
|
|
||||||
and charge a fee for, acceptance of support, warranty, indemnity,
|
|
||||||
or other liability obligations and/or rights consistent with this
|
|
||||||
License. However, in accepting such obligations, You may act only
|
|
||||||
on Your own behalf and on Your sole responsibility, not on behalf
|
|
||||||
of any other Contributor, and only if You agree to indemnify,
|
|
||||||
defend, and hold each Contributor harmless for any liability
|
|
||||||
incurred by, or claims asserted against, such Contributor by reason
|
|
||||||
of your accepting any such warranty or additional liability.
|
|
||||||
|
|
||||||
END OF TERMS AND CONDITIONS
|
|
||||||
|
|
||||||
APPENDIX: How to apply the Apache License to your work.
|
|
||||||
|
|
||||||
To apply the Apache License to your work, attach the following
|
|
||||||
boilerplate notice, with the fields enclosed by brackets "[]"
|
|
||||||
replaced with your own identifying information. (Don't include
|
|
||||||
the brackets!) The text should be enclosed in the appropriate
|
|
||||||
comment syntax for the file format. We also recommend that a
|
|
||||||
file or class name and description of purpose be included on the
|
|
||||||
same "printed page" as the copyright notice for easier
|
|
||||||
identification within third-party archives.
|
|
||||||
|
|
||||||
Copyright [yyyy] [name of copyright owner]
|
|
||||||
|
|
||||||
Licensed under the Apache License, Version 2.0 (the "License");
|
|
||||||
you may not use this file except in compliance with the License.
|
|
||||||
You may obtain a copy of the License at
|
|
||||||
|
|
||||||
http://www.apache.org/licenses/LICENSE-2.0
|
|
||||||
|
|
||||||
Unless required by applicable law or agreed to in writing, software
|
|
||||||
distributed under the License is distributed on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
||||||
See the License for the specific language governing permissions and
|
|
||||||
limitations under the License.
|
|
||||||
|
|
@ -1,46 +0,0 @@
|
||||||
SHELL := /usr/bin/env bash
|
|
||||||
|
|
||||||
all:
|
|
||||||
@echo >&2 "Only 'make check' allowed"
|
|
||||||
|
|
||||||
|
|
||||||
TESTED_IMAGES = \
|
|
||||||
postgresql-container \
|
|
||||||
s2i-python-container \
|
|
||||||
s2i-nodejs-container
|
|
||||||
|
|
||||||
.PHONY: check test all check-failures
|
|
||||||
|
|
||||||
|
|
||||||
TEST_LIB_TESTS = \
|
|
||||||
path_foreach \
|
|
||||||
random_string \
|
|
||||||
test_npm \
|
|
||||||
image_availability \
|
|
||||||
public_image_name
|
|
||||||
|
|
||||||
$(TEST_LIB_TESTS):
|
|
||||||
@echo " RUN TEST '$@'" ; \
|
|
||||||
$(SHELL) tests/test-lib/$@ || $(SHELL) -x tests/lib/$@
|
|
||||||
|
|
||||||
test-lib-foreach:
|
|
||||||
|
|
||||||
check-test-lib: $(TEST_LIB_TESTS)
|
|
||||||
|
|
||||||
test: check
|
|
||||||
|
|
||||||
shellcheck:
|
|
||||||
./run-shellcheck.sh `git ls-files *.sh`
|
|
||||||
|
|
||||||
check-failures: check-test-lib
|
|
||||||
cd tests/failures/check && make tag && ! make check && make clean
|
|
||||||
grep -q "Red Hat Enterprise Linux release 8" /etc/system-release || cd tests/failures/check && make tag SKIP_SQUASH=0
|
|
||||||
|
|
||||||
check-squash:
|
|
||||||
./tests/squash/squash.sh
|
|
||||||
|
|
||||||
check-latest-imagestream:
|
|
||||||
cd tests && ./check_imagestreams.sh
|
|
||||||
|
|
||||||
check: check-failures check-squash check-latest-imagestream
|
|
||||||
TESTED_IMAGES="$(TESTED_IMAGES)" tests/remote-containers.sh
|
|
||||||
126
common/README.md
126
common/README.md
|
|
@ -1,126 +0,0 @@
|
||||||
Common build helpers for sclorg containers
|
|
||||||
==========================================
|
|
||||||
|
|
||||||
This repository is aimed to be added as git submodule into particular
|
|
||||||
containers' source repositories. By default, the path to submodule should be
|
|
||||||
named 'common'.
|
|
||||||
|
|
||||||
Usage
|
|
||||||
-----
|
|
||||||
|
|
||||||
This section explains the usage of the shared scripts in this repository when
|
|
||||||
it is used as a submodule in a container source repository.
|
|
||||||
|
|
||||||
Once you have the repository set as a submodule include `common.mk` into your
|
|
||||||
root Makefile in order to access the default rules used to call shared scripts.
|
|
||||||
|
|
||||||
**Default rules:**
|
|
||||||
|
|
||||||
`make` or `make build`
|
|
||||||
This rule will build an image without tagging it with any tags after it is built.
|
|
||||||
After the image finishes building the scripts will squash the image using `docker-squash`.
|
|
||||||
`make build` will also expect a `README.md` so that it can transfrom it into
|
|
||||||
a man page that gets added to the image so make sure it is available and that
|
|
||||||
you have the `go-md2man` tool installed on your host.
|
|
||||||
|
|
||||||
|
|
||||||
`make tag`
|
|
||||||
Use this rule if you want to tag an image after it is built. It will be tagged with
|
|
||||||
two tags - name:latest and name:version.
|
|
||||||
Depends on `build`
|
|
||||||
|
|
||||||
`make test` or `make check`
|
|
||||||
This rule will run the testsuite scripts contained in the container source repositories.
|
|
||||||
It expects the test to be available at `$gitroot/$version/test/run`
|
|
||||||
Depends on `tag` as some tests might need to have the images tagged (s2i).
|
|
||||||
|
|
||||||
`make test-openshift`
|
|
||||||
Similar to `make test` but runs testsuite for Openshift 3, expected to be found at
|
|
||||||
`$gitroot/$version/test/run-openshift`
|
|
||||||
|
|
||||||
`make test-openshift-4`
|
|
||||||
Similar to `make test` but runs testsuite for Openshift 4, expected to be found at
|
|
||||||
`$gitroot/$version/test/run-openshift-remote-cluster`
|
|
||||||
|
|
||||||
`make test-with-conu`
|
|
||||||
The rule is similar to `make test`. It runs a test suite written using [conu
|
|
||||||
library](https://github.com/user-cont/conu). The path to the test script is
|
|
||||||
meant to be at `$gitroot/$version/test/run-conu`. By default the test suite is
|
|
||||||
being run in the current environment. You can also run the tests in a container
|
|
||||||
by defining variable `CONU_IMAGE`. Container images with conu are available in
|
|
||||||
[this docker hub repository](docker.io/usercont/conu:0.6.2), a good value for
|
|
||||||
the variable is `docker.io/usercont/conu:0.6.2`.
|
|
||||||
|
|
||||||
`make clean`
|
|
||||||
Runs scripts that clean-up the working dir. Depends on the `clean-images` rule by default
|
|
||||||
and additional clean rules can be provided through the `clean-hook` variable.
|
|
||||||
|
|
||||||
`make clean-images`
|
|
||||||
Best-effort to remove the last set of images that have been built using the scripts.
|
|
||||||
|
|
||||||
`make shellcheck`
|
|
||||||
Check the shell syntax of the files specified by `$SHELLCHECK_FILES` variable.
|
|
||||||
See `SHELLCHECK_FILES` variable description below for more info (default is `.`).
|
|
||||||
The files matching this specification are then filtered, to not show results twice
|
|
||||||
for symlinks. Only files with a suffix `.sh` or shell shebang are scanned with
|
|
||||||
the `shellcheck` utility. See [run-shellcheck.sh](./run-shellcheck.sh) in this repo for more detailed info.
|
|
||||||
Once the shell syntax issues are fixed, CI that runs `make shellcheck` for each PR can be
|
|
||||||
turned on by putting [.travis.yml](.travis.yml) file into the root of the image's repository.
|
|
||||||
[.travis.yml](https://github.com/sclorg/container-common-scripts/blob/master/.travis.yml)
|
|
||||||
for its content.
|
|
||||||
|
|
||||||
**There are additional variables that you can use that the default rules are prepared to
|
|
||||||
work with:**
|
|
||||||
|
|
||||||
`VERSIONS`
|
|
||||||
Names of the directories in which the Dockerfiles are contained. Needs to be defined in your
|
|
||||||
Dockerfile for the scripts to know which versions to build.
|
|
||||||
|
|
||||||
`OS`
|
|
||||||
OS version you want to build the images for. Currently the scripts are able to build for
|
|
||||||
centos (default), centos6, centos8, rhel7, rhel8 and fedora.
|
|
||||||
|
|
||||||
`SKIP_SQUASH`
|
|
||||||
When set to 1 the build script will skip the squash phase of the build.
|
|
||||||
|
|
||||||
`CUSTOM_REPO`
|
|
||||||
Set this variable to the path to your local .repo files you want to have available inside
|
|
||||||
the image while building. Useful for building rhel-based images on an unsubscribed box.
|
|
||||||
Be aware that you cannot write to any .repo files used this way inside the image as they
|
|
||||||
will be mounted into the image as read-only.
|
|
||||||
|
|
||||||
`UPDATE_BASE`
|
|
||||||
Set to 1 if you want the build script to always pull the base image when available.
|
|
||||||
|
|
||||||
`DOCKER_BUILD_CONTEXT`
|
|
||||||
Use this variable in case you want to have a different context for your builds. By default
|
|
||||||
the context of the build is the versioned directory the Dockerfiles are contained in.
|
|
||||||
|
|
||||||
`SHELLCHECK_FILES`
|
|
||||||
One or more files or directories to be scanned by the shellcheck, default is `.`, which
|
|
||||||
means a whole repository directory. If a directory is provided then all of its content
|
|
||||||
is scanned as well.
|
|
||||||
|
|
||||||
`clean-hook`
|
|
||||||
Append Makefile rules to this variable to make sure additional cleaning actions are run
|
|
||||||
when `make clean` is called.
|
|
||||||
|
|
||||||
Regression tests
|
|
||||||
----------------
|
|
||||||
|
|
||||||
`make check`
|
|
||||||
Runs the tests of few images that use this set of scripts. If the tests of those
|
|
||||||
images pass, this repo is considered to be working.
|
|
||||||
|
|
||||||
`make shellcheck`
|
|
||||||
Check the shell syntax of all `*.sh` files tracked by the git in this repository.
|
|
||||||
|
|
||||||
Dependencies for testsuite:
|
|
||||||
|
|
||||||
- /usr/bin/docker (either `docker` or `podman` + `podman-docker`)
|
|
||||||
- docker-squash (if `docker` is used, otherwise set `SKIP_SQUASH`, which is done automatically on non-EL-7)
|
|
||||||
- git
|
|
||||||
- go-md2man
|
|
||||||
- make
|
|
||||||
- source-to-image
|
|
||||||
- shellcheck
|
|
||||||
226
common/build.sh
226
common/build.sh
|
|
@ -1,226 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
# This script is used to build the OpenShift Docker images.
|
|
||||||
#
|
|
||||||
# OS - Specifies distribution - "rhel7", "rhel8", "centos7", "centos8" or "fedora"
|
|
||||||
# VERSION - Specifies the image version - (must match with subdirectory in repo)
|
|
||||||
# VERSIONS - Must be set to a list with possible versions (subdirectories)
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
script_name=$(readlink -f "$0")
|
|
||||||
script_dir=$(dirname "$script_name")
|
|
||||||
|
|
||||||
OS=${1-$OS}
|
|
||||||
VERSION=${2-$VERSION}
|
|
||||||
|
|
||||||
error() { echo "ERROR: $*" ; false ; }
|
|
||||||
|
|
||||||
|
|
||||||
# _parse_output_inner
|
|
||||||
# -------------------
|
|
||||||
# Helper function for 'parse_output'.
|
|
||||||
# We need to avoid case statements in $() for older Bash versions (per issue
|
|
||||||
# postgresql-container#35, mac ships with 3.2).
|
|
||||||
# Example of problematic statement: echo $(case i in i) echo i;; esac)
|
|
||||||
_parse_output_inner ()
|
|
||||||
{
|
|
||||||
set -o pipefail
|
|
||||||
{
|
|
||||||
case $stream in
|
|
||||||
stdout|1|"")
|
|
||||||
eval "$command" | tee >(cat - >&"$stdout_fd")
|
|
||||||
;;
|
|
||||||
stderr|2)
|
|
||||||
set +x # avoid stderr pollution
|
|
||||||
eval "$command" {free_fd}>&1 1>&"$stdout_fd" 2>&"$free_fd" | tee >(cat - >&"$stderr_fd")
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
# Inherit correct exit status.
|
|
||||||
(exit "${PIPESTATUS[0]}")
|
|
||||||
} | eval "$filter"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# parse_output COMMAND FILTER_COMMAND OUTVAR [STREAM={stderr|stdout}]
|
|
||||||
# -------------------------------------------------------------------
|
|
||||||
# Parse standard (error) output of COMMAND with FILTER_COMMAND and store the
|
|
||||||
# output into variable named OUTVAR. STREAM might be 'stdout' or 'stderr',
|
|
||||||
# defaults to 'stdout'. The filtered output stays (live) printed to terminal.
|
|
||||||
# This method doesn't create any explicit temporary files.
|
|
||||||
# Defines:
|
|
||||||
# ${$OUTVAR}: Set to FILTER_COMMAND output.
|
|
||||||
parse_output ()
|
|
||||||
{
|
|
||||||
local command=$1 filter=$2 var=$3 stream=$4
|
|
||||||
local raw_output='' rc=0
|
|
||||||
{
|
|
||||||
# shellcheck disable=SC2034
|
|
||||||
raw_output=$(_parse_output_inner)
|
|
||||||
} {stdout_fd}>&1 {stderr_fd}>&2
|
|
||||||
rc=$?
|
|
||||||
eval "$var=\$raw_output"
|
|
||||||
(exit $rc)
|
|
||||||
}
|
|
||||||
|
|
||||||
# "best-effort" cleanup of previous image
|
|
||||||
function clean_image {
|
|
||||||
if test -f .image-id.raw; then
|
|
||||||
local previous_id
|
|
||||||
previous_id=$(cat .image-id.raw)
|
|
||||||
if test "$IMAGE_ID" != "$previous_id"; then
|
|
||||||
# Also remove squashed image since it will change anyway
|
|
||||||
docker rmi "$previous_id" "$(cat .image-id)" || :
|
|
||||||
rm -f ".image-id.raw" ".image-id" || :
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
# Pull image based on FROM, before we build our own.
|
|
||||||
function pull_image {
|
|
||||||
local dockerfile="$1"
|
|
||||||
local loops=10
|
|
||||||
local loop=0
|
|
||||||
|
|
||||||
# Get image_name from Dockerfile before pulling.
|
|
||||||
while read -r line; do
|
|
||||||
if ! grep -q "^FROM" <<< "$line"; then
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
|
|
||||||
image_name=$(echo "$line" | cut -d ' ' -f2)
|
|
||||||
|
|
||||||
# In case FROM scratch is defined, skip it
|
|
||||||
if [[ x"$image_name" == "xscratch" ]]; then
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
echo "-> Pulling image $image_name before building image from $dockerfile."
|
|
||||||
# Sometimes in Fedora case it fails with HTTP 50X
|
|
||||||
# Check if the image is available locally and try to pull it if it is not
|
|
||||||
if [[ "$(docker images -q "$image_name" 2>/dev/null)" != "" ]]; then
|
|
||||||
echo "The image $image_name is already pulled."
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Try pulling the image to see if it is accessible
|
|
||||||
# WORKAROUND: Since Fedora registry sometimes fails randomly, let's try it more times
|
|
||||||
while ! docker pull "$image_name"; do
|
|
||||||
((loop++)) || :
|
|
||||||
echo "Pulling image $image_name failed."
|
|
||||||
[ "$loop" -gt "$loops" ] && { echo "It happened $loops times. Giving up." ; return 1; }
|
|
||||||
echo "Let's wait $((loop*5)) seconds and try again."
|
|
||||||
sleep "$((loop*5))"
|
|
||||||
done
|
|
||||||
|
|
||||||
done < "$dockerfile"
|
|
||||||
}
|
|
||||||
|
|
||||||
# Perform docker build but append the LABEL with GIT commit id at the end
|
|
||||||
function docker_build_with_version {
|
|
||||||
local dockerfile="$1"
|
|
||||||
local exclude=.exclude-${OS}
|
|
||||||
if [ -e "$exclude" ]; then
|
|
||||||
echo "-> $exclude file exists for version $dir, skipping build."
|
|
||||||
clean_image
|
|
||||||
return
|
|
||||||
fi
|
|
||||||
if [ ! -e "$dockerfile" ]; then
|
|
||||||
echo "-> $dockerfile for version $dir does not exist, skipping build."
|
|
||||||
clean_image
|
|
||||||
return
|
|
||||||
fi
|
|
||||||
echo "-> Version ${dir}: building image from '${dockerfile}' ..."
|
|
||||||
|
|
||||||
git_version=$(git rev-parse --short HEAD)
|
|
||||||
BUILD_OPTIONS+=" --label io.openshift.builder-version=\"${git_version}\""
|
|
||||||
if [[ "${UPDATE_BASE}" == "1" ]]; then
|
|
||||||
BUILD_OPTIONS+=" --pull=true"
|
|
||||||
fi
|
|
||||||
if [ -n "$CUSTOM_REPO" ]; then
|
|
||||||
if [ -f "$CUSTOM_REPO" ]; then
|
|
||||||
BUILD_OPTIONS+=" -v $CUSTOM_REPO:/etc/yum.repos.d/sclorg_custom.repo:Z"
|
|
||||||
elif [ -d "$CUSTOM_REPO" ]; then
|
|
||||||
BUILD_OPTIONS+=" -v $CUSTOM_REPO:/etc/yum.repos.d/:Z"
|
|
||||||
else
|
|
||||||
echo "ERROR: file type not known: $CUSTOM_REPO" >&2
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
|
|
||||||
pull_image "$dockerfile"
|
|
||||||
|
|
||||||
# shellcheck disable=SC2016
|
|
||||||
parse_output 'docker build '"$BUILD_OPTIONS"' -f "$dockerfile" "${DOCKER_BUILD_CONTEXT}"' \
|
|
||||||
"tail -n 1 | awk '/Successfully built|(^--> )?(Using cache )?[a-fA-F0-9]+$/{print \$NF}'" \
|
|
||||||
IMAGE_ID
|
|
||||||
clean_image
|
|
||||||
echo "$IMAGE_ID" > .image-id.raw
|
|
||||||
|
|
||||||
squash "${dockerfile}"
|
|
||||||
echo "$IMAGE_ID" > .image-id
|
|
||||||
}
|
|
||||||
|
|
||||||
# squash DOCKERFILE
|
|
||||||
# -----------------
|
|
||||||
# Use python library docker_squash[1] and squash the result image
|
|
||||||
# when necessary.
|
|
||||||
# [1] https://github.com/goldmann/docker-squash
|
|
||||||
# Reads:
|
|
||||||
# $IMAGE_ID
|
|
||||||
# Sets:
|
|
||||||
# $IMAGE_ID
|
|
||||||
squash ()
|
|
||||||
{
|
|
||||||
local base squashed_from squashed='' unsquashed=$IMAGE_ID
|
|
||||||
test "$SKIP_SQUASH" = 1 && return 0
|
|
||||||
|
|
||||||
if test -f .image-id.squashed; then
|
|
||||||
squashed=$(cat .image-id.squashed)
|
|
||||||
# We (maybe) already have squashed file.
|
|
||||||
if test -f .image-id.squashed_from; then
|
|
||||||
squashed_from=$(cat .image-id.squashed_from)
|
|
||||||
if test "$squashed_from" = "$IMAGE_ID"; then
|
|
||||||
# $squashed is up2date
|
|
||||||
IMAGE_ID=$squashed
|
|
||||||
echo "Image '$unsquashed' already squashed as '$squashed'"
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
|
|
||||||
# We are going to squash now, so if there's existing squashed image, try
|
|
||||||
# to do the best-effort 'rmi' to not waste memory unnecessarily.
|
|
||||||
docker rmi "$squashed" || :
|
|
||||||
fi
|
|
||||||
|
|
||||||
base=$(awk '/^FROM/{print $2}' "$1")
|
|
||||||
|
|
||||||
echo "Squashing the image '$unsquashed' from '$base' layer."
|
|
||||||
IMAGE_ID=$("${PYTHON-python3}" "$script_dir"/squash.py "$unsquashed" "$base")
|
|
||||||
|
|
||||||
echo "Squashed as '$IMAGE_ID'."
|
|
||||||
|
|
||||||
echo "$unsquashed" > .image-id.squashed_from
|
|
||||||
echo "$IMAGE_ID" > .image-id.squashed
|
|
||||||
}
|
|
||||||
|
|
||||||
# Versions are stored in subdirectories. You can specify VERSION variable
|
|
||||||
# to build just one single version. By default we build all versions
|
|
||||||
dirs=${VERSION:-$VERSIONS}
|
|
||||||
|
|
||||||
for dir in ${dirs}; do
|
|
||||||
pushd "${dir}" > /dev/null
|
|
||||||
if [ "$OS" == "rhel8" ] || [ "$OS" == "rhel8-candidate" ]; then
|
|
||||||
docker_build_with_version Dockerfile.rhel8
|
|
||||||
elif [ "$OS" == "rhel7" ] || [ "$OS" == "rhel7-candidate" ]; then
|
|
||||||
docker_build_with_version Dockerfile.rhel7
|
|
||||||
elif [ "$OS" == "fedora" ] || [ "$OS" == "fedora-candidate" ]; then
|
|
||||||
docker_build_with_version Dockerfile.fedora
|
|
||||||
elif [ "$OS" == "centos6" ] || [ "$OS" == "centos6-candidate" ]; then
|
|
||||||
docker_build_with_version Dockerfile.centos6
|
|
||||||
elif [ "$OS" == "centos8" ] || [ "$OS" == "centos8-candidate" ]; then
|
|
||||||
docker_build_with_version Dockerfile.centos8
|
|
||||||
else
|
|
||||||
docker_build_with_version Dockerfile
|
|
||||||
fi
|
|
||||||
|
|
||||||
popd > /dev/null
|
|
||||||
done
|
|
||||||
|
|
@ -1,73 +0,0 @@
|
||||||
#!/bin/env python3
|
|
||||||
|
|
||||||
import sys
|
|
||||||
import json
|
|
||||||
import logging
|
|
||||||
import os
|
|
||||||
|
|
||||||
from pathlib import Path
|
|
||||||
from typing import Dict
|
|
||||||
|
|
||||||
IMAGESTREAMS_DIR: str = "imagestreams"
|
|
||||||
|
|
||||||
|
|
||||||
class ImageStreamChecker(object):
|
|
||||||
version: str = ""
|
|
||||||
results: Dict = {}
|
|
||||||
|
|
||||||
def __init__(self, version: str):
|
|
||||||
self.version = version
|
|
||||||
|
|
||||||
def load_json_file(self, filename: Path):
|
|
||||||
with open(str(filename)) as f:
|
|
||||||
return json.load(f)
|
|
||||||
|
|
||||||
def check_version(self, json_dict: Dict):
|
|
||||||
res = []
|
|
||||||
for tags in json_dict["spec"]["tags"]:
|
|
||||||
# The name can be"<stream>" or "<stream>-elX" or "<stream>-ubiX"
|
|
||||||
if (tags["name"] == self.version or
|
|
||||||
tags["name"].startswith(self.version + '-')):
|
|
||||||
res.append(tags)
|
|
||||||
return res
|
|
||||||
|
|
||||||
def check_latest_tag(self, json_dict: Dict):
|
|
||||||
latest_tag_correct: bool = False
|
|
||||||
for tags in json_dict["spec"]["tags"]:
|
|
||||||
if tags["name"] != "latest":
|
|
||||||
continue
|
|
||||||
# The latest can link to either "<stream>" or "<stream>-elX" or "<stream>-ubiX"
|
|
||||||
if tags["from"]["name"] == self.version or tags["from"]["name"].startswith(self.version + '-'):
|
|
||||||
latest_tag_correct = True
|
|
||||||
return latest_tag_correct
|
|
||||||
|
|
||||||
def check_imagestreams(self):
|
|
||||||
p = Path(".")
|
|
||||||
json_files = p.glob(f"{IMAGESTREAMS_DIR}/*.json")
|
|
||||||
if not json_files:
|
|
||||||
print(f"No json files present in {IMAGESTREAMS_DIR}.")
|
|
||||||
return 0
|
|
||||||
for f in json_files:
|
|
||||||
if os.environ.get("TARGET") in ("rhel7", "centos7") and "aarch64" in str(f):
|
|
||||||
print("Imagestream aarch64 is not supported on rhel7")
|
|
||||||
continue
|
|
||||||
print(f"Checking file {str(f)}.")
|
|
||||||
json_dict = self.load_json_file(f)
|
|
||||||
if not (self.check_version(json_dict) and self.check_latest_tag(json_dict)):
|
|
||||||
print(f"The latest version is not present in {str(f)} or in latest tag.")
|
|
||||||
self.results[f] = False
|
|
||||||
if self.results:
|
|
||||||
return 1
|
|
||||||
print("Imagestreams contains the latest version.")
|
|
||||||
return 0
|
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
if len(sys.argv) != 2:
|
|
||||||
logging.fatal("%s: %s", sys.argv[0], "VERSION as an argument was not provided")
|
|
||||||
sys.exit(1)
|
|
||||||
|
|
||||||
print(f"Version to check is {sys.argv[1]}.")
|
|
||||||
isc = ImageStreamChecker(version=sys.argv[1])
|
|
||||||
sys.exit(isc.check_imagestreams())
|
|
||||||
|
|
||||||
|
|
@ -1,21 +0,0 @@
|
||||||
#! /bin/sh
|
|
||||||
|
|
||||||
set -e
|
|
||||||
test -f auto_targets.mk && rm auto_targets.mk
|
|
||||||
|
|
||||||
for version
|
|
||||||
do
|
|
||||||
remove_images=
|
|
||||||
for idfile in .image-id.raw .image-id.squashed; do
|
|
||||||
# shellcheck disable=SC2039
|
|
||||||
test ! -f "$version/$idfile" || remove_images+=" $(cat "$version/$idfile")"
|
|
||||||
done
|
|
||||||
|
|
||||||
for image in $remove_images; do
|
|
||||||
# shellcheck disable=SC2046
|
|
||||||
docker rm -f $(docker ps -q -a -f "ancestor=$image") 2>/dev/null || :
|
|
||||||
docker rmi -f "$image" || :
|
|
||||||
done
|
|
||||||
|
|
||||||
rm -rf "$version"/.image-id*
|
|
||||||
done
|
|
||||||
150
common/common.mk
150
common/common.mk
|
|
@ -1,150 +0,0 @@
|
||||||
# SKIP_SQUASH = 0/1
|
|
||||||
# =================
|
|
||||||
# If set to '0', images are automatically squashed. '1' disables
|
|
||||||
# squashing. By default only RHEL containers are squashed.
|
|
||||||
|
|
||||||
SHELL := /usr/bin/env bash
|
|
||||||
|
|
||||||
ifndef common_dir
|
|
||||||
common_dir = common
|
|
||||||
endif
|
|
||||||
|
|
||||||
build = $(SHELL) $(common_dir)/build.sh
|
|
||||||
test = $(SHELL) $(common_dir)/test.sh
|
|
||||||
testr = $(SHELL) $(common_dir)/test-remote-cluster.sh
|
|
||||||
shellcheck = $(SHELL) $(common_dir)/run-shellcheck.sh
|
|
||||||
tag = $(SHELL) $(common_dir)/tag.sh
|
|
||||||
clean = $(SHELL) $(common_dir)/clean.sh
|
|
||||||
|
|
||||||
DG ?= /bin/dg
|
|
||||||
|
|
||||||
generator = DG="$(DG)" $(SHELL) $(common_dir)/generate.sh
|
|
||||||
|
|
||||||
|
|
||||||
# pretty printers
|
|
||||||
# ---------------
|
|
||||||
__PROLOG = $(if $(VERBOSE),,@echo " $(1) " $@;)
|
|
||||||
V_LN = $(call __PROLOG,LN )
|
|
||||||
V_DG = $(call __PROLOG,DG )
|
|
||||||
V_DGM = $(call __PROLOG,DGM)
|
|
||||||
V_CP = $(call __PROLOG,CP )
|
|
||||||
|
|
||||||
CDIR = mkdir -p "$$(dirname "$@")" || exit 1 ;
|
|
||||||
|
|
||||||
ifeq ($(TARGET),rhel8)
|
|
||||||
SKIP_SQUASH ?= 1
|
|
||||||
OS := rhel8
|
|
||||||
DOCKERFILE ?= Dockerfile.rhel8
|
|
||||||
else ifeq ($(TARGET),rhel7)
|
|
||||||
SKIP_SQUASH ?= 0
|
|
||||||
OS := rhel7
|
|
||||||
DOCKERFILE ?= Dockerfile.rhel7
|
|
||||||
else ifeq ($(TARGET),fedora)
|
|
||||||
OS := fedora
|
|
||||||
DOCKERFILE ?= Dockerfile.fedora
|
|
||||||
else ifeq ($(TARGET),centos6)
|
|
||||||
OS := centos6
|
|
||||||
DOCKERFILE ?= Dockerfile.centos6
|
|
||||||
else ifeq ($(TARGET),centos8)
|
|
||||||
OS := centos8
|
|
||||||
DOCKERFILE ?= Dockerfile.centos8
|
|
||||||
else
|
|
||||||
OS := centos7
|
|
||||||
DOCKERFILE ?= Dockerfile
|
|
||||||
endif
|
|
||||||
|
|
||||||
SKIP_SQUASH ?= 1
|
|
||||||
DOCKER_BUILD_CONTEXT ?= .
|
|
||||||
SHELLCHECK_FILES ?= .
|
|
||||||
|
|
||||||
script_env = \
|
|
||||||
SKIP_SQUASH=$(SKIP_SQUASH) \
|
|
||||||
UPDATE_BASE=$(UPDATE_BASE) \
|
|
||||||
OS=$(OS) \
|
|
||||||
CLEAN_AFTER=$(CLEAN_AFTER) \
|
|
||||||
DOCKER_BUILD_CONTEXT=$(DOCKER_BUILD_CONTEXT) \
|
|
||||||
OPENSHIFT_NAMESPACES="$(OPENSHIFT_NAMESPACES)" \
|
|
||||||
CUSTOM_REPO="$(CUSTOM_REPO)"
|
|
||||||
|
|
||||||
# TODO: switch to 'build: build-all' once parallel builds are relatively safe
|
|
||||||
.PHONY: build build-serial build-all
|
|
||||||
build: build-serial
|
|
||||||
build-serial:
|
|
||||||
@$(MAKE) -j1 build-all
|
|
||||||
|
|
||||||
build-all: $(VERSIONS)
|
|
||||||
@for i in $(VERSIONS); do \
|
|
||||||
test -f $$i/.image-id || continue ; \
|
|
||||||
echo -n "$(BASE_IMAGE_NAME) $$i => " ; \
|
|
||||||
cat $$i/.image-id ; \
|
|
||||||
done
|
|
||||||
|
|
||||||
.PHONY: $(VERSIONS)
|
|
||||||
$(VERSIONS): % : %/root/help.1
|
|
||||||
VERSION="$@" $(script_env) $(build)
|
|
||||||
|
|
||||||
.PHONY: test check
|
|
||||||
check: test
|
|
||||||
|
|
||||||
test: script_env += TEST_MODE=true
|
|
||||||
|
|
||||||
# The tests should ideally depend on $IMAGE_ID only, but see PR#19 for more info
|
|
||||||
# while we need to depend on 'tag' instead of 'build'.
|
|
||||||
test: tag
|
|
||||||
VERSIONS="$(VERSIONS)" $(script_env) $(test)
|
|
||||||
|
|
||||||
.PHONY: test-with-conu
|
|
||||||
test-with-conu: script_env += TEST_CONU_MODE=true
|
|
||||||
test-with-conu: tag
|
|
||||||
VERSIONS="$(VERSIONS)" $(script_env) $(test)
|
|
||||||
|
|
||||||
.PHONY: test-openshift-4
|
|
||||||
test-openshift-4: script_env += TEST_OPENSHIFT_4=true
|
|
||||||
test-openshift-4: tag
|
|
||||||
VERSIONS="$(VERSIONS)" BASE_IMAGE_NAME="$(BASE_IMAGE_NAME)" $(script_env) $(test)
|
|
||||||
|
|
||||||
.PHONY: test-openshift
|
|
||||||
test-openshift: script_env += TEST_OPENSHIFT_MODE=true
|
|
||||||
test-openshift: tag
|
|
||||||
VERSIONS="$(VERSIONS)" BASE_IMAGE_NAME="$(BASE_IMAGE_NAME)" $(script_env) $(test)
|
|
||||||
|
|
||||||
.PHONY: shellcheck
|
|
||||||
shellcheck:
|
|
||||||
$(shellcheck) $(SHELLCHECK_FILES)
|
|
||||||
|
|
||||||
.PHONY: tag
|
|
||||||
tag: build
|
|
||||||
VERSIONS="$(VERSIONS)" $(script_env) $(tag)
|
|
||||||
|
|
||||||
.PHONY: clean clean-hook clean-images clean-versions
|
|
||||||
clean: clean-images
|
|
||||||
@$(MAKE) --no-print-directory clean-hook
|
|
||||||
|
|
||||||
clean-images:
|
|
||||||
$(clean) $(VERSIONS)
|
|
||||||
|
|
||||||
clean-versions:
|
|
||||||
rm -rf $(VERSIONS)
|
|
||||||
|
|
||||||
%root/help.1: %README.md
|
|
||||||
mkdir -p $(@D)
|
|
||||||
go-md2man -in "$^" -out "$@"
|
|
||||||
chmod a+r "$@"
|
|
||||||
|
|
||||||
generate-all: generate
|
|
||||||
|
|
||||||
MANIFEST_FILE ?= manifest.sh
|
|
||||||
|
|
||||||
auto_targets.mk: $(MANIFEST_FILE)
|
|
||||||
MANIFEST_FILE="$(MANIFEST_FILE)" \
|
|
||||||
VERSIONS="$(VERSIONS)" \
|
|
||||||
$(generator)
|
|
||||||
|
|
||||||
# triggers build of auto_targets.mk automatically
|
|
||||||
-include auto_targets.mk
|
|
||||||
|
|
||||||
# We have to remove auto_targets.mk here, otherwise subsequent make calls
|
|
||||||
# with different VERSIONS=* option keeps the auto_targets.mk unchanged.
|
|
||||||
.PHONY: generate
|
|
||||||
generate: $(DISTGEN_TARGETS) $(DISTGEN_MULTI_TARGETS) $(COPY_TARGETS) $(SYMLINK_TARGETS)
|
|
||||||
rm auto_targets.mk
|
|
||||||
|
|
@ -1,184 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
# This script is used to create image directories using distgen, cp or ln
|
|
||||||
# It requires "$MANIFEST_FILE" (defaults to manifest.sh) file to be present in
|
|
||||||
# image repository.
|
|
||||||
# The manifest file should contain set of rules in form:
|
|
||||||
# <rules_type>="
|
|
||||||
# src=<path to source>
|
|
||||||
# dest=<path to destination>
|
|
||||||
# mode=<destination file mode (optional)>;
|
|
||||||
# ...;
|
|
||||||
# "
|
|
||||||
#
|
|
||||||
# Supported type rules are now COPY_RULES, DISTGEN_RULES and SYMLINKS_RULES
|
|
||||||
# for real example see https://github.com/sclorg/postgresql-container/blob/master/manifest.sh
|
|
||||||
|
|
||||||
# shellcheck disable=SC1090
|
|
||||||
source "$MANIFEST_FILE"
|
|
||||||
|
|
||||||
die () { echo "FATAL: $*" ; exit 1 ; }
|
|
||||||
|
|
||||||
nl='
|
|
||||||
'
|
|
||||||
|
|
||||||
test -f auto_targets.mk && rm auto_targets.mk
|
|
||||||
DG="${DG-/bin/dg}"
|
|
||||||
[ ! -x "$DG" ] && echo " Error: distgen binary not found or not executable in $DG" && \
|
|
||||||
echo " Make sure distgen is properly installed on your host in $DG, or provide a path to your distgen binary via \$DG" && exit 1
|
|
||||||
|
|
||||||
DISTGEN_COMBINATIONS=$("$DG" --multispec specs/multispec.yml --multispec-combinations)
|
|
||||||
|
|
||||||
|
|
||||||
clean_rule_variables(){
|
|
||||||
src=""
|
|
||||||
dest=""
|
|
||||||
mode=""
|
|
||||||
link_target=""
|
|
||||||
link_name=""
|
|
||||||
}
|
|
||||||
|
|
||||||
parse_rules() {
|
|
||||||
targets=""
|
|
||||||
OLD_IFS=$IFS
|
|
||||||
IFS=";"
|
|
||||||
for rule in $rules; do
|
|
||||||
if [ -z "$(echo "$rule"| tr -d '[:space:]')" ]; then
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
clean_rule_variables
|
|
||||||
eval "$rule"
|
|
||||||
|
|
||||||
# shellcheck disable=SC2016
|
|
||||||
cdir='$(CDIR)'
|
|
||||||
case "$creator" in
|
|
||||||
copy)
|
|
||||||
[[ -z "$src" ]] && echo "src has to be specified in copy rule" && exit 1
|
|
||||||
[[ -z "$dest" ]] && echo "dest has to be specified in copy rule" && exit 1
|
|
||||||
core_subst=$core
|
|
||||||
prolog="\$(V_CP)$cdir"
|
|
||||||
;;
|
|
||||||
distgen)
|
|
||||||
[[ -z "$src" ]] && echo "src has to be specified in distgen rule" && exit 1
|
|
||||||
[[ -z "$dest" ]] && echo "dest has to be specified in distgen rule" && exit 1
|
|
||||||
core_subst=$core
|
|
||||||
prolog="\$(V_DG)$cdir"
|
|
||||||
;;
|
|
||||||
distgen_multi)
|
|
||||||
[[ -z "$src" ]] && echo "src has to be specified in distgen rule" && exit 1
|
|
||||||
[[ -z "$dest" ]] && echo "dest has to be specified in distgen rule" && exit 1
|
|
||||||
|
|
||||||
if [[ "$dest" == "Dockerfile.rhel7" ]]; then
|
|
||||||
if ! [[ "$DG_CONF" =~ rhel-7-x86_64.yaml ]]; then
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
elif [[ "$dest" == "Dockerfile.rhel8" ]]; then
|
|
||||||
if ! [[ "$DG_CONF" =~ rhel-8-x86_64.yaml ]]; then
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
elif [[ "$dest" == "Dockerfile.centos8" ]]; then
|
|
||||||
if ! [[ "$DG_CONF" =~ centos-8-x86_64.yaml ]]; then
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
elif [[ "$dest" == *"Dockerfile.fedora" ]]; then
|
|
||||||
if ! [[ "$DG_CONF" =~ fedora-[0-9]{,2}-x86_64.yaml ]]; then
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
elif [[ "$dest" == *"Dockerfile" ]]; then
|
|
||||||
if ! [[ "$DG_CONF" =~ centos-[0-9]{,2}-x86_64.yaml ]]; then
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
prolog="\$(V_DGM)$cdir"
|
|
||||||
core_subst=$core
|
|
||||||
;;
|
|
||||||
link)
|
|
||||||
[[ -z "$link_name" ]] && echo "link_name has to be specified in link rule" && exit 1
|
|
||||||
[[ -z "$link_target" ]] && echo "link_target has to be specified in link rule" && exit 1
|
|
||||||
dest="$link_name"
|
|
||||||
# shellcheck disable=SC2001
|
|
||||||
core_subst=$(echo "$core" | sed -e "s~__link_target__~${link_target}~g")
|
|
||||||
prolog="\$(V_LN)$cdir"
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
case $version$dest$src in
|
|
||||||
*' '*) die "space not allowed in version, dest, src" ;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
target=$version/$dest
|
|
||||||
targets+="\\$nl $target"
|
|
||||||
|
|
||||||
cat >> auto_targets.mk << EOF
|
|
||||||
$nl$target: $src \$(MANIFEST_FILE)
|
|
||||||
$prolog \\
|
|
||||||
$core_subst${mode:+"; \\
|
|
||||||
chmod $mode '\$@'"}
|
|
||||||
EOF
|
|
||||||
done
|
|
||||||
IFS=$OLD_IFS
|
|
||||||
}
|
|
||||||
|
|
||||||
for version in ${VERSIONS}; do
|
|
||||||
# Get a working combination of distgen options for this version
|
|
||||||
while read -r combination; do
|
|
||||||
# line looks like: --distro rhel-7-x86_64.yaml --multispec-selector version=9.4
|
|
||||||
echo "$combination" | grep "version=$version" &>/dev/null && break
|
|
||||||
done <<< "$DISTGEN_COMBINATIONS"
|
|
||||||
[ -z "$combination" ] && die "Could not find a working distgen options combination for version $version"
|
|
||||||
|
|
||||||
# copy targets
|
|
||||||
rules="$COPY_RULES"
|
|
||||||
core="cp \$< \$@"
|
|
||||||
creator="copy"
|
|
||||||
parse_rules
|
|
||||||
COPY_TARGETS+="$targets"
|
|
||||||
|
|
||||||
|
|
||||||
# distgen targets
|
|
||||||
rules="$DISTGEN_RULES"
|
|
||||||
core="\$(DG) --multispec specs/multispec.yml \\
|
|
||||||
--template \"\$<\" $combination --output \"\$@\""
|
|
||||||
creator="distgen"
|
|
||||||
parse_rules
|
|
||||||
DISTGEN_TARGETS+="$targets"
|
|
||||||
|
|
||||||
|
|
||||||
rules=$SYMLINK_RULES
|
|
||||||
core="ln -nfs __link_target__ \$@"
|
|
||||||
creator="link"
|
|
||||||
parse_rules
|
|
||||||
SYMLINK_TARGETS+="$targets"
|
|
||||||
done
|
|
||||||
|
|
||||||
while read -r combination; do
|
|
||||||
# line looks like: --distro rhel-7-x86_64.yaml --multispec-selector version=9.4
|
|
||||||
eval 'set -- $combination'
|
|
||||||
case $4 in
|
|
||||||
version=*) version=${4##*=} ;;
|
|
||||||
*) die "version not found"
|
|
||||||
esac
|
|
||||||
case $2 in
|
|
||||||
*x86_64*) DG_CONF=$2 ;;
|
|
||||||
*) die "invalid --distro option"
|
|
||||||
esac
|
|
||||||
# distgen multi targets
|
|
||||||
rules="$DISTGEN_MULTI_RULES"
|
|
||||||
core="\$(DG) --multispec specs/multispec.yml \\
|
|
||||||
--template \"\$<\" \\
|
|
||||||
--output \"\$@\" \\
|
|
||||||
$combination"
|
|
||||||
creator="distgen_multi"
|
|
||||||
parse_rules
|
|
||||||
DISTGEN_MULTI_TARGETS+="$targets"
|
|
||||||
done <<< "$DISTGEN_COMBINATIONS"
|
|
||||||
|
|
||||||
cat -v >> auto_targets.mk <<EOF
|
|
||||||
COPY_TARGETS = $COPY_TARGETS
|
|
||||||
|
|
||||||
DISTGEN_TARGETS = $DISTGEN_TARGETS
|
|
||||||
|
|
||||||
DISTGEN_MULTI_TARGETS = $DISTGEN_MULTI_TARGETS
|
|
||||||
|
|
||||||
SYMLINK_TARGETS = $SYMLINK_TARGETS
|
|
||||||
EOF
|
|
||||||
|
|
@ -1,44 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
VERBOSE_OUTPUT=0
|
|
||||||
|
|
||||||
usage() {
|
|
||||||
echo "Usage: $(basename "$0") [ -v|--verbose ] <dir|file> [ <dir|file> ... ]"
|
|
||||||
}
|
|
||||||
|
|
||||||
verbose() {
|
|
||||||
if [ "${VERBOSE_OUTPUT}" -eq 1 ] ; then
|
|
||||||
echo "$@" >&2
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
if [ $# -eq 0 ] ; then
|
|
||||||
echo "ERROR: No arguments given."
|
|
||||||
usage
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
case $1 in
|
|
||||||
-v|--verbose) VERBOSE_OUTPUT=1; shift ;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
filter_files() {
|
|
||||||
while read -r file ; do
|
|
||||||
if [ -L "$file" ] ; then
|
|
||||||
verbose "Ignoring symlink $file."
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
verbose "Will scan $file"
|
|
||||||
echo "$file"
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
detect_shell_files() {
|
|
||||||
find -H "$@" -type f -not -path '*/\.git/*' -exec grep -l '^#!/bin/\(bash\|sh\)' {} +
|
|
||||||
find -H "$@" -name '*.sh' -not -path '*/\.git/*'
|
|
||||||
}
|
|
||||||
|
|
||||||
# Run shellcheck on all files (we should also ignore symlinks)
|
|
||||||
detect_shell_files "$@" | filter_files | sort -u | xargs shellcheck
|
|
||||||
|
|
||||||
# vim: set tabstop=2:shiftwidth=2:expandtab:
|
|
||||||
|
|
@ -1,23 +0,0 @@
|
||||||
#! /bin/python
|
|
||||||
|
|
||||||
import sys
|
|
||||||
import logging
|
|
||||||
from platform import python_version
|
|
||||||
|
|
||||||
try:
|
|
||||||
from docker_squash import squash
|
|
||||||
except ImportError:
|
|
||||||
logging.fatal("please install 'docker_squash' for Python {0}".format(python_version()))
|
|
||||||
sys.exit(1)
|
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
if len(sys.argv) != 3:
|
|
||||||
logging.fatal("%s: %s", sys.argv[0], msg)
|
|
||||||
sys.exit(1)
|
|
||||||
|
|
||||||
print(squash.Squash(
|
|
||||||
log=logging.getLogger(),
|
|
||||||
image=sys.argv[1],
|
|
||||||
from_layer=sys.argv[2]).run()
|
|
||||||
)
|
|
||||||
|
|
@ -1,34 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
# This script is used to tag the OpenShift Docker images.
|
|
||||||
#
|
|
||||||
# Resulting image will be tagged: 'name:version' and 'name:latest'. Name and version
|
|
||||||
# are values of labels from resulted image
|
|
||||||
#
|
|
||||||
# VERSIONS - Must be set to a list with possible versions (subdirectories)
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
for dir in ${VERSIONS}; do
|
|
||||||
[ ! -e "${dir}/.image-id" ] && echo "-> Image for version $dir not built, skipping tag." && continue
|
|
||||||
pushd "${dir}" > /dev/null
|
|
||||||
IMAGE_ID=$(cat .image-id)
|
|
||||||
name=$(docker inspect -f "{{.Config.Labels.name}}" "$IMAGE_ID")
|
|
||||||
version=$(docker inspect -f "{{.Config.Labels.version}}" "$IMAGE_ID")
|
|
||||||
commit_date=$(git show -s HEAD --format=%cd --date=short | sed 's/-//g')
|
|
||||||
date_and_hash="${commit_date}-$(git rev-parse --short HEAD)"
|
|
||||||
|
|
||||||
echo "-> Tagging image '$IMAGE_ID' as '$name:$version' and '$name:latest' and '$name:$date_and_hash'"
|
|
||||||
docker tag "$IMAGE_ID" "$name:$version"
|
|
||||||
docker tag "$IMAGE_ID" "$name:latest"
|
|
||||||
docker tag "$IMAGE_ID" "$name:$date_and_hash"
|
|
||||||
|
|
||||||
for suffix in squashed raw; do
|
|
||||||
id_file=.image-id.$suffix
|
|
||||||
if test -f "$id_file"; then
|
|
||||||
docker tag "$(cat "$id_file")" "$name:$suffix" || rm .image-id."$suffix"
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
|
|
||||||
popd > /dev/null
|
|
||||||
done
|
|
||||||
File diff suppressed because it is too large
Load diff
|
|
@ -1,107 +0,0 @@
|
||||||
# shellcheck shell=bash
|
|
||||||
# some functions are used from test-lib.sh, that is usually in the same dir
|
|
||||||
# shellcheck source=/dev/null
|
|
||||||
source "$(dirname "${BASH_SOURCE[0]}")"/test-lib.sh
|
|
||||||
|
|
||||||
# Set of functions for testing docker images in OpenShift using 'oc' command
|
|
||||||
|
|
||||||
# A variable containing the overall test result; must be changed to 0 in the end
|
|
||||||
# of the testing script:
|
|
||||||
# OS_TESTSUITE_RESULT=0
|
|
||||||
# And the following trap must be set, in the beginning of the test script:
|
|
||||||
# trap ct_os_cleanup EXIT SIGINT
|
|
||||||
|
|
||||||
# ct_os_set_path_oc_4 OC_VERSION
|
|
||||||
# --------------------
|
|
||||||
# This is a trick that helps using correct version 4 of the `oc`:
|
|
||||||
# The input is version of the openshift in format 4.4 etc.
|
|
||||||
# If the currently available version of oc is not of this version,
|
|
||||||
# it first takes a look into /usr/local/oc-<ver>/bin directory,
|
|
||||||
|
|
||||||
# Arguments: oc_version - X.Y part of the version of OSE (e.g. 3.9)
|
|
||||||
function ct_os_set_path_oc_4() {
|
|
||||||
echo "Setting OCP4 client"
|
|
||||||
local oc_version=$1
|
|
||||||
local installed_oc_path="/usr/local/oc-v${oc_version}/bin"
|
|
||||||
echo "PATH ${installed_oc_path}"
|
|
||||||
if [ -x "${installed_oc_path}/oc" ] ; then
|
|
||||||
oc_path="${installed_oc_path}"
|
|
||||||
echo "Binary oc found in ${installed_oc_path}" >&2
|
|
||||||
else
|
|
||||||
echo "OCP4 not found"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
export PATH="${oc_path}:${PATH}"
|
|
||||||
oc version
|
|
||||||
if ! oc version | grep -q "Client Version: ${oc_version}." ; then
|
|
||||||
echo "ERROR: something went wrong, oc located at ${oc_path}, but oc of version ${oc_version} not found in PATH ($PATH)" >&1
|
|
||||||
return 1
|
|
||||||
else
|
|
||||||
echo "PATH set correctly, binary oc found in version ${oc_version}: $(command -v oc)"
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_os_prepare_ocp4
|
|
||||||
# ------------------
|
|
||||||
# Prepares environment for testing images in OpenShift 4 environment
|
|
||||||
#
|
|
||||||
#
|
|
||||||
function ct_os_set_ocp4() {
|
|
||||||
local login
|
|
||||||
OS_OC_CLIENT_VERSION=${OS_OC_CLIENT_VERSION:-4.4}
|
|
||||||
ct_os_set_path_oc_4 "${OS_OC_CLIENT_VERSION}"
|
|
||||||
|
|
||||||
oc version
|
|
||||||
|
|
||||||
login=$(cat "$KUBEPASSWORD")
|
|
||||||
oc login -u kubeadmin -p "$login"
|
|
||||||
echo "Login to OpenShift ${OS_OC_CLIENT_VERSION} is DONE"
|
|
||||||
# let openshift cluster to sync to avoid some race condition errors
|
|
||||||
sleep 3
|
|
||||||
}
|
|
||||||
|
|
||||||
function ct_os_upload_image_external_registry() {
|
|
||||||
local input_name="${1}" ; shift
|
|
||||||
local image_name=${input_name##*/}
|
|
||||||
local imagestream=${1:-$image_name:latest}
|
|
||||||
local output_name
|
|
||||||
|
|
||||||
ct_os_login_external_registry
|
|
||||||
|
|
||||||
output_name="${INTERNAL_DOCKER_REGISTRY}/rhscl-ci-testing/$imagestream"
|
|
||||||
|
|
||||||
docker images
|
|
||||||
docker tag "${input_name}" "${output_name}"
|
|
||||||
docker push "${output_name}"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
function ct_os_login_external_registry() {
|
|
||||||
local docker_token
|
|
||||||
# docker login fails with "404 page not found" error sometimes, just try it more times
|
|
||||||
# shellcheck disable=SC2034
|
|
||||||
echo "loging"
|
|
||||||
[ -z "${INTERNAL_DOCKER_REGISTRY:-}" ] && "INTERNAL_DOCKER_REGISTRY has to be set for working with Internal registry" && return 1
|
|
||||||
# shellcheck disable=SC2034
|
|
||||||
for i in $(seq 12) ; do
|
|
||||||
# shellcheck disable=SC2015
|
|
||||||
docker_token=$(cat "$DOCKER_UPSHIFT_TOKEN")
|
|
||||||
# shellcheck disable=SC2015
|
|
||||||
docker login -u rhscl-ci-testing -p "$docker_token" "${INTERNAL_DOCKER_REGISTRY}" && return 0 || :
|
|
||||||
sleep 5
|
|
||||||
done
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
|
|
||||||
function ct_os_import_image_ocp4() {
|
|
||||||
local image_name="${1}"; shift
|
|
||||||
local imagestream=${1:-$image_name:latest}
|
|
||||||
local namespace
|
|
||||||
|
|
||||||
namespace=${CT_NAMESPACE:-"$(oc project -q)"}
|
|
||||||
deploy_image_name="${INTERNAL_DOCKER_REGISTRY}/rhscl-ci-testing/${imagestream}"
|
|
||||||
echo "Uploading image ${image_name} as ${deploy_image_name} , ${imagestream} into external registry."
|
|
||||||
ct_os_upload_image_external_registry "${image_name}" "${imagestream}"
|
|
||||||
echo "Import image into OpenShift 4 environment "
|
|
||||||
oc import-image "${namespace}/${imagestream}" --from="${deploy_image_name}" --confirm --reference-policy=local
|
|
||||||
}
|
|
||||||
|
|
@ -1,901 +0,0 @@
|
||||||
# shellcheck shell=bash
|
|
||||||
#
|
|
||||||
# Test a container image.
|
|
||||||
#
|
|
||||||
# Always use sourced from a specific container testfile
|
|
||||||
#
|
|
||||||
# reguires definition of CID_FILE_DIR
|
|
||||||
# CID_FILE_DIR=$(mktemp --suffix=<container>_test_cidfiles -d)
|
|
||||||
# reguires definition of TEST_LIST
|
|
||||||
# TEST_LIST="\
|
|
||||||
# ctest_container_creation
|
|
||||||
# ctest_doc_content"
|
|
||||||
|
|
||||||
# Container CI tests
|
|
||||||
# abbreviated as "ct"
|
|
||||||
|
|
||||||
# may be redefined in the specific container testfile
|
|
||||||
EXPECTED_EXIT_CODE=0
|
|
||||||
|
|
||||||
# ct_cleanup
|
|
||||||
# --------------------
|
|
||||||
# Cleans up containers used during tests. Stops and removes all containers
|
|
||||||
# referenced by cid_files in CID_FILE_DIR. Dumps logs if a container exited
|
|
||||||
# unexpectedly. Removes the cid_files and CID_FILE_DIR as well.
|
|
||||||
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
|
||||||
# Uses: $EXPECTED_EXIT_CODE - expected container exit code
|
|
||||||
function ct_cleanup() {
|
|
||||||
ct_show_resources
|
|
||||||
for cid_file in "$CID_FILE_DIR"/* ; do
|
|
||||||
local container
|
|
||||||
container=$(cat "$cid_file")
|
|
||||||
|
|
||||||
: "Stopping and removing container $container..."
|
|
||||||
docker stop "$container"
|
|
||||||
exit_status=$(docker inspect -f '{{.State.ExitCode}}' "$container")
|
|
||||||
if [ "$exit_status" != "$EXPECTED_EXIT_CODE" ]; then
|
|
||||||
: "Dumping logs for $container"
|
|
||||||
docker logs "$container"
|
|
||||||
fi
|
|
||||||
docker rm -v "$container"
|
|
||||||
rm "$cid_file"
|
|
||||||
done
|
|
||||||
rmdir "$CID_FILE_DIR"
|
|
||||||
: "Done."
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_enable_cleanup
|
|
||||||
# --------------------
|
|
||||||
# Enables automatic container cleanup after tests.
|
|
||||||
function ct_enable_cleanup() {
|
|
||||||
trap ct_cleanup EXIT SIGINT
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_check_envs_set env_filter check_envs loop_envs [env_format]
|
|
||||||
# --------------------
|
|
||||||
# Compares values from one list of environment variable definitions against such list,
|
|
||||||
# checking if the values are present and have a specific format.
|
|
||||||
# Argument: env_filter - optional string passed to grep used for
|
|
||||||
# choosing which variables to filter out in env var lists.
|
|
||||||
# Argument: check_envs - list of env var definitions to check values against
|
|
||||||
# Argument: loop_envs - list of env var definitions to check values for
|
|
||||||
# Argument: env_format (optional) - format string for bash substring deletion used
|
|
||||||
# for checking whether the value is contained in check_envs.
|
|
||||||
# Defaults to: "*VALUE*", VALUE string gets replaced by actual value from loop_envs
|
|
||||||
function ct_check_envs_set {
|
|
||||||
local env_filter check_envs env_format
|
|
||||||
env_filter=$1; shift
|
|
||||||
check_envs=$1; shift
|
|
||||||
loop_envs=$1; shift
|
|
||||||
env_format=${1:-"*VALUE*"}
|
|
||||||
while read -r variable; do
|
|
||||||
[ -z "$variable" ] && continue
|
|
||||||
var_name=$(echo "$variable" | awk -F= '{ print $1 }')
|
|
||||||
stripped=$(echo "$variable" | awk -F= '{ print $2 }')
|
|
||||||
filtered_envs=$(echo "$check_envs" | grep "^$var_name=")
|
|
||||||
[ -z "$filtered_envs" ] && { echo "$var_name not found during \` docker exec\`"; return 1; }
|
|
||||||
old_IFS=$IFS
|
|
||||||
# For each such variable compare its content with the `docker exec` result, use `:` as delimiter
|
|
||||||
IFS=:
|
|
||||||
for value in $stripped; do
|
|
||||||
# If the falue checked does not go through env_filter we do not care about it
|
|
||||||
echo "$value" | grep -q "$env_filter" || continue
|
|
||||||
if [ -n "${filtered_envs##${env_format//VALUE/$value}}" ]; then
|
|
||||||
echo " Value $value is missing from variable $var_name"
|
|
||||||
echo "$filtered_envs"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
done <<< "$(echo "$loop_envs" | grep "$env_filter" | grep -v "^PWD=")"
|
|
||||||
IFS=$old_IFS
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_get_cid [name]
|
|
||||||
# --------------------
|
|
||||||
# Prints container id from cid_file based on the name of the file.
|
|
||||||
# Argument: name - name of cid_file where the container id will be stored
|
|
||||||
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
|
||||||
function ct_get_cid() {
|
|
||||||
local name="$1" ; shift || return 1
|
|
||||||
cat "$CID_FILE_DIR/$name"
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_get_cip [id]
|
|
||||||
# --------------------
|
|
||||||
# Prints container ip address based on the container id.
|
|
||||||
# Argument: id - container id
|
|
||||||
function ct_get_cip() {
|
|
||||||
local id="$1" ; shift
|
|
||||||
docker inspect --format='{{.NetworkSettings.IPAddress}}' "$(ct_get_cid "$id")"
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_wait_for_cid [cid_file]
|
|
||||||
# --------------------
|
|
||||||
# Holds the execution until the cid_file is created. Usually run after container
|
|
||||||
# creation.
|
|
||||||
# Argument: cid_file - name of the cid_file that should be created
|
|
||||||
function ct_wait_for_cid() {
|
|
||||||
local cid_file=$1
|
|
||||||
local max_attempts=10
|
|
||||||
local sleep_time=1
|
|
||||||
local attempt=1
|
|
||||||
local result=1
|
|
||||||
while [ $attempt -le $max_attempts ]; do
|
|
||||||
[ -f "$cid_file" ] && [ -s "$cid_file" ] && return 0
|
|
||||||
: "Waiting for container start..."
|
|
||||||
attempt=$(( attempt + 1 ))
|
|
||||||
sleep $sleep_time
|
|
||||||
done
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_assert_container_creation_fails [container_args]
|
|
||||||
# --------------------
|
|
||||||
# The invocation of docker run should fail based on invalid container_args
|
|
||||||
# passed to the function. Returns 0 when container fails to start properly.
|
|
||||||
# Argument: container_args - all arguments are passed directly to dokcer run
|
|
||||||
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
|
||||||
function ct_assert_container_creation_fails() {
|
|
||||||
local ret=0
|
|
||||||
local max_attempts=10
|
|
||||||
local attempt=1
|
|
||||||
local cid_file=assert
|
|
||||||
set +e
|
|
||||||
local old_container_args="${CONTAINER_ARGS-}"
|
|
||||||
# we really work with CONTAINER_ARGS as with a string
|
|
||||||
# shellcheck disable=SC2124
|
|
||||||
CONTAINER_ARGS="$@"
|
|
||||||
if ct_create_container "$cid_file" ; then
|
|
||||||
local cid
|
|
||||||
cid=$(ct_get_cid "$cid_file")
|
|
||||||
|
|
||||||
while [ "$(docker inspect -f '{{.State.Running}}' "$cid")" == "true" ] ; do
|
|
||||||
sleep 2
|
|
||||||
attempt=$(( attempt + 1 ))
|
|
||||||
if [ "$attempt" -gt "$max_attempts" ]; then
|
|
||||||
docker stop "$cid"
|
|
||||||
ret=1
|
|
||||||
break
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
exit_status=$(docker inspect -f '{{.State.ExitCode}}' "$cid")
|
|
||||||
if [ "$exit_status" == "0" ]; then
|
|
||||||
ret=1
|
|
||||||
fi
|
|
||||||
docker rm -v "$cid"
|
|
||||||
rm "$CID_FILE_DIR/$cid_file"
|
|
||||||
fi
|
|
||||||
[ -n "$old_container_args" ] && CONTAINER_ARGS="$old_container_args"
|
|
||||||
set -e
|
|
||||||
return "$ret"
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_create_container [name, command]
|
|
||||||
# --------------------
|
|
||||||
# Creates a container using the IMAGE_NAME and CONTAINER_ARGS variables. Also
|
|
||||||
# stores the container id to a cid_file located in the CID_FILE_DIR, and waits
|
|
||||||
# for the creation of the file.
|
|
||||||
# Argument: name - name of cid_file where the container id will be stored
|
|
||||||
# Argument: command - optional command to be executed in the container
|
|
||||||
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
|
||||||
# Uses: $CONTAINER_ARGS - optional arguments passed directly to docker run
|
|
||||||
# Uses: $IMAGE_NAME - name of the image being tested
|
|
||||||
function ct_create_container() {
|
|
||||||
local cid_file="$CID_FILE_DIR/$1" ; shift
|
|
||||||
# create container with a cidfile in a directory for cleanup
|
|
||||||
# shellcheck disable=SC2086
|
|
||||||
docker run --cidfile="$cid_file" -d ${CONTAINER_ARGS:-} "$IMAGE_NAME" "$@"
|
|
||||||
ct_wait_for_cid "$cid_file" || return 1
|
|
||||||
: "Created container $(cat "$cid_file")"
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_scl_usage_old [name, command, expected]
|
|
||||||
# --------------------
|
|
||||||
# Tests three ways of running the SCL, by looking for an expected string
|
|
||||||
# in the output of the command
|
|
||||||
# Argument: name - name of cid_file where the container id will be stored
|
|
||||||
# Argument: command - executed inside the container
|
|
||||||
# Argument: expected - string that is expected to be in the command output
|
|
||||||
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
|
||||||
# Uses: $IMAGE_NAME - name of the image being tested
|
|
||||||
function ct_scl_usage_old() {
|
|
||||||
local name="$1"
|
|
||||||
local command="$2"
|
|
||||||
local expected="$3"
|
|
||||||
local out=""
|
|
||||||
: " Testing the image SCL enable"
|
|
||||||
out=$(docker run --rm "${IMAGE_NAME}" /bin/bash -c "${command}")
|
|
||||||
if ! echo "${out}" | grep -q "${expected}"; then
|
|
||||||
echo "ERROR[/bin/bash -c \"${command}\"] Expected '${expected}', got '${out}'" >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
out=$(docker exec "$(ct_get_cid "$name")" /bin/bash -c "${command}" 2>&1)
|
|
||||||
if ! echo "${out}" | grep -q "${expected}"; then
|
|
||||||
echo "ERROR[exec /bin/bash -c \"${command}\"] Expected '${expected}', got '${out}'" >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
out=$(docker exec "$(ct_get_cid "$name")" /bin/sh -ic "${command}" 2>&1)
|
|
||||||
if ! echo "${out}" | grep -q "${expected}"; then
|
|
||||||
echo "ERROR[exec /bin/sh -ic \"${command}\"] Expected '${expected}', got '${out}'" >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_doc_content_old [strings]
|
|
||||||
# --------------------
|
|
||||||
# Looks for occurence of stirngs in the documentation files and checks
|
|
||||||
# the format of the files. Files examined: help.1
|
|
||||||
# Argument: strings - strings expected to appear in the documentation
|
|
||||||
# Uses: $IMAGE_NAME - name of the image being tested
|
|
||||||
function ct_doc_content_old() {
|
|
||||||
local tmpdir
|
|
||||||
tmpdir=$(mktemp -d)
|
|
||||||
local f
|
|
||||||
: " Testing documentation in the container image"
|
|
||||||
# Extract the help files from the container
|
|
||||||
# shellcheck disable=SC2043
|
|
||||||
for f in help.1 ; do
|
|
||||||
docker run --rm "${IMAGE_NAME}" /bin/bash -c "cat /${f}" >"${tmpdir}/$(basename "${f}")"
|
|
||||||
# Check whether the files contain some important information
|
|
||||||
for term in "$@" ; do
|
|
||||||
if ! grep -F -q -e "${term}" "${tmpdir}/$(basename "${f}")" ; then
|
|
||||||
echo "ERROR: File /${f} does not include '${term}'." >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
# Check whether the files use the correct format
|
|
||||||
for term in TH PP SH ; do
|
|
||||||
if ! grep -q "^\.${term}" "${tmpdir}/help.1" ; then
|
|
||||||
echo "ERROR: /help.1 is probably not in troff or groff format, since '${term}' is missing." >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
done
|
|
||||||
: " Success!"
|
|
||||||
}
|
|
||||||
|
|
||||||
# full_ca_file_path
|
|
||||||
# Return string for full path to CA file
|
|
||||||
function full_ca_file_path()
|
|
||||||
{
|
|
||||||
echo "/etc/pki/ca-trust/source/anchors/RH-IT-Root-CA.crt"
|
|
||||||
}
|
|
||||||
# ct_mount_ca_file
|
|
||||||
# ------------------
|
|
||||||
# Check if /etc/pki/certs/RH-IT-Root-CA.crt file exists
|
|
||||||
# return mount string for containers or empty string
|
|
||||||
function ct_mount_ca_file()
|
|
||||||
{
|
|
||||||
# mount CA file only if NPM_REGISTRY variable is present.
|
|
||||||
local mount_parameter=""
|
|
||||||
if [ -n "$NPM_REGISTRY" ] && [ -f "$(full_ca_file_path)" ]; then
|
|
||||||
mount_parameter="-v $(full_ca_file_path):$(full_ca_file_path):Z"
|
|
||||||
fi
|
|
||||||
echo "$mount_parameter"
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_build_s2i_npm_variables URL_TO_NPM_JS_SERVER
|
|
||||||
# ------------------------------------------
|
|
||||||
# Function returns -e NPM_MIRROR and -v MOUNT_POINT_FOR_CAFILE
|
|
||||||
# or empty string
|
|
||||||
function ct_build_s2i_npm_variables()
|
|
||||||
{
|
|
||||||
npm_variables=""
|
|
||||||
if [ -n "$NPM_REGISTRY" ] && [ -f "$(full_ca_file_path)" ]; then
|
|
||||||
npm_variables="-e NPM_MIRROR=$NPM_REGISTRY $(ct_mount_ca_file)"
|
|
||||||
fi
|
|
||||||
echo "$npm_variables"
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_npm_works
|
|
||||||
# --------------------
|
|
||||||
# Checks existance of the npm tool and runs it.
|
|
||||||
function ct_npm_works() {
|
|
||||||
local tmpdir
|
|
||||||
tmpdir=$(mktemp -d)
|
|
||||||
: " Testing npm in the container image"
|
|
||||||
local cid_file="${tmpdir}/cid"
|
|
||||||
if ! docker run --rm "${IMAGE_NAME}" /bin/bash -c "npm --version" >"${tmpdir}/version" ; then
|
|
||||||
echo "ERROR: 'npm --version' does not work inside the image ${IMAGE_NAME}." >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# shellcheck disable=SC2046
|
|
||||||
docker run -d $(ct_mount_ca_file) --rm --cidfile="$cid_file" "${IMAGE_NAME}-testapp"
|
|
||||||
|
|
||||||
# Wait for the container to write it's CID file
|
|
||||||
ct_wait_for_cid "$cid_file" || return 1
|
|
||||||
|
|
||||||
if ! docker exec "$(cat "$cid_file")" /bin/bash -c "npm --verbose install jquery && test -f node_modules/jquery/src/jquery.js" >"${tmpdir}/jquery" 2>&1 ; then
|
|
||||||
echo "ERROR: npm could not install jquery inside the image ${IMAGE_NAME}." >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -n "$NPM_REGISTRY" ] && [ -f "$(full_ca_file_path)" ]; then
|
|
||||||
if ! grep -qo "$NPM_REGISTRY" "${tmpdir}/jquery"; then
|
|
||||||
echo "ERROR: Internal repository is NOT set. Even it is requested."
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -f "$cid_file" ]; then
|
|
||||||
docker stop "$(cat "$cid_file")"
|
|
||||||
rm "$cid_file"
|
|
||||||
fi
|
|
||||||
: " Success!"
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_binary_found_from_df binary [path]
|
|
||||||
# --------------------
|
|
||||||
# Checks if a binary can be found in PATH during Dockerfile build
|
|
||||||
# Argument: binary - name of the binary to test accessibility for
|
|
||||||
# Argument: path - optional path in which the binary should reside in
|
|
||||||
# /opt/rh by default
|
|
||||||
function ct_binary_found_from_df() {
|
|
||||||
local tmpdir
|
|
||||||
local binary=$1; shift
|
|
||||||
local binary_path=${1:-"^/opt/rh"}
|
|
||||||
tmpdir=$(mktemp -d)
|
|
||||||
: " Testing $binary in build from Dockerfile"
|
|
||||||
|
|
||||||
# Create Dockerfile that looks for the binary
|
|
||||||
cat <<EOF >"$tmpdir/Dockerfile"
|
|
||||||
FROM $IMAGE_NAME
|
|
||||||
RUN which $binary | grep "$binary_path"
|
|
||||||
EOF
|
|
||||||
# Build an image, looking for expected path in the output
|
|
||||||
if ! docker build -f "$tmpdir/Dockerfile" --no-cache "$tmpdir"; then
|
|
||||||
echo " ERROR: Failed to find $binary in Dockerfile!" >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
: " Success!"
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_check_exec_env_vars [env_filter]
|
|
||||||
# --------------------
|
|
||||||
# Checks if all relevant environment variables from `docker run`
|
|
||||||
# can be found in `docker exec` as well.
|
|
||||||
# Argument: env_filter - optional string passed to grep used for
|
|
||||||
# choosing which variables to check in the test case.
|
|
||||||
# Defaults to X_SCLS and variables containing /opt/app-root, /opt/rh
|
|
||||||
# Uses: $CID_FILE_DIR - path to directory containing cid_files
|
|
||||||
# Uses: $IMAGE_NAME - name of the image being tested
|
|
||||||
function ct_check_exec_env_vars() {
|
|
||||||
local tmpdir exec_envs cid old_IFS env_filter
|
|
||||||
local var_name stripped filtered_envs run_envs
|
|
||||||
env_filter=${1:-"^X_SCLS=\|/opt/rh\|/opt/app-root"}
|
|
||||||
tmpdir=$(mktemp -d)
|
|
||||||
CID_FILE_DIR=${CID_FILE_DIR:-$(mktemp -d)}
|
|
||||||
# Get environment variables from `docker run`
|
|
||||||
run_envs=$(docker run --rm "$IMAGE_NAME" /bin/bash -c "env")
|
|
||||||
# Get environment variables from `docker exec`
|
|
||||||
ct_create_container "test_exec_envs" bash -c "sleep 1000" >/dev/null
|
|
||||||
cid=$(ct_get_cid "test_exec_envs")
|
|
||||||
exec_envs=$(docker exec "$cid" env)
|
|
||||||
# Filter out variables we are not interested in
|
|
||||||
# Always check X_SCLS, ignore PWD
|
|
||||||
# Check variables from `docker run` that have alternative paths inside (/opt/rh, /opt/app-root)
|
|
||||||
ct_check_envs_set "$env_filter" "$exec_envs" "$run_envs" "*VALUE*" || return 1
|
|
||||||
echo " All values present in \`docker exec\`"
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_check_scl_enable_vars [env_filter]
|
|
||||||
# --------------------
|
|
||||||
# Checks if all relevant environment variables from `docker run`
|
|
||||||
# are set twice after a second call of `scl enable $SCLS`.
|
|
||||||
# Argument: env_filter - optional string passed to grep used for
|
|
||||||
# choosing which variables to check in the test case.
|
|
||||||
# Defaults to paths containing enabled SCLS in the image
|
|
||||||
# Uses: $IMAGE_NAME - name of the image being tested
|
|
||||||
function ct_check_scl_enable_vars() {
|
|
||||||
local tmpdir exec_envs cid old_IFS env_filter enabled_scls
|
|
||||||
local var_name stripped filtered_envs loop_envs
|
|
||||||
env_filter=$1
|
|
||||||
tmpdir=$(mktemp -d)
|
|
||||||
enabled_scls=$(docker run --rm "$IMAGE_NAME" /bin/bash -c "echo \$X_SCLS")
|
|
||||||
if [ -z "$env_filter" ]; then
|
|
||||||
for scl in $enabled_scls; do
|
|
||||||
[ -z "$env_filter" ] && env_filter="/$scl" && continue
|
|
||||||
# env_filter not empty, append to the existing list
|
|
||||||
env_filter="$env_filter|/$scl"
|
|
||||||
done
|
|
||||||
fi
|
|
||||||
# Get environment variables from `docker run`
|
|
||||||
loop_envs=$(docker run --rm "$IMAGE_NAME" /bin/bash -c "env")
|
|
||||||
run_envs=$(docker run --rm "$IMAGE_NAME" /bin/bash -c "X_SCLS= scl enable $enabled_scls env")
|
|
||||||
# Check if the values are set twice in the second set of envs
|
|
||||||
ct_check_envs_set "$env_filter" "$run_envs" "$loop_envs" "*VALUE*VALUE*" || return 1
|
|
||||||
echo " All scl_enable values present"
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_path_append PATH_VARNAME DIRECTORY
|
|
||||||
# -------------------------------------
|
|
||||||
# Append DIRECTORY to VARIABLE of name PATH_VARNAME, the VARIABLE must consist
|
|
||||||
# of colon-separated list of directories.
|
|
||||||
ct_path_append ()
|
|
||||||
{
|
|
||||||
if eval "test -n \"\${$1-}\""; then
|
|
||||||
eval "$1=\$2:\$$1"
|
|
||||||
else
|
|
||||||
eval "$1=\$2"
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# ct_path_foreach PATH ACTION [ARGS ...]
|
|
||||||
# --------------------------------------
|
|
||||||
# For each DIR in PATH execute ACTION (path is colon separated list of
|
|
||||||
# directories). The particular calls to ACTION will look like
|
|
||||||
# '$ ACTION directory [ARGS ...]'
|
|
||||||
ct_path_foreach ()
|
|
||||||
{
|
|
||||||
local dir dirlist action save_IFS
|
|
||||||
save_IFS=$IFS
|
|
||||||
IFS=:
|
|
||||||
dirlist=$1
|
|
||||||
action=$2
|
|
||||||
shift 2
|
|
||||||
for dir in $dirlist; do "$action" "$dir" "$@" ; done
|
|
||||||
IFS=$save_IFS
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# ct_run_test_list
|
|
||||||
# --------------------
|
|
||||||
# Execute the tests specified by TEST_LIST
|
|
||||||
# Uses: $TEST_LIST - list of test names
|
|
||||||
function ct_run_test_list() {
|
|
||||||
for test_case in $TEST_LIST; do
|
|
||||||
: "Running test $test_case"
|
|
||||||
# shellcheck source=/dev/null
|
|
||||||
[ -f "test/$test_case" ] && source "test/$test_case"
|
|
||||||
# shellcheck source=/dev/null
|
|
||||||
[ -f "../test/$test_case" ] && source "../test/$test_case"
|
|
||||||
$test_case
|
|
||||||
done;
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_gen_self_signed_cert_pem
|
|
||||||
# ---------------------------
|
|
||||||
# Generates a self-signed PEM certificate pair into specified directory.
|
|
||||||
# Argument: output_dir - output directory path
|
|
||||||
# Argument: base_name - base name of the certificate files
|
|
||||||
# Resulted files will be those:
|
|
||||||
# <output_dir>/<base_name>-cert-selfsigned.pem -- public PEM cert
|
|
||||||
# <output_dir>/<base_name>-key.pem -- PEM private key
|
|
||||||
ct_gen_self_signed_cert_pem() {
|
|
||||||
local output_dir=$1 ; shift
|
|
||||||
local base_name=$1 ; shift
|
|
||||||
mkdir -p "${output_dir}"
|
|
||||||
openssl req -newkey rsa:2048 -nodes -keyout "${output_dir}"/"${base_name}"-key.pem -subj '/C=GB/ST=Berkshire/L=Newbury/O=My Server Company' > "${base_name}"-req.pem
|
|
||||||
openssl req -new -x509 -nodes -key "${output_dir}"/"${base_name}"-key.pem -batch > "${output_dir}"/"${base_name}"-cert-selfsigned.pem
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_obtain_input FILE|DIR|URL
|
|
||||||
# --------------------
|
|
||||||
# Either copies a file or a directory to a tmp location for local copies, or
|
|
||||||
# downloads the file from remote location.
|
|
||||||
# Resulted file path is printed, so it can be later used by calling function.
|
|
||||||
# Arguments: input - local file, directory or remote URL
|
|
||||||
function ct_obtain_input() {
|
|
||||||
local input=$1
|
|
||||||
local extension="${input##*.}"
|
|
||||||
|
|
||||||
# Try to use same extension for the temporary file if possible
|
|
||||||
[[ "${extension}" =~ ^[a-z0-9]*$ ]] && extension=".${extension}" || extension=""
|
|
||||||
|
|
||||||
local output
|
|
||||||
output=$(mktemp "/var/tmp/test-input-XXXXXX$extension")
|
|
||||||
if [ -f "${input}" ] ; then
|
|
||||||
cp -f "${input}" "${output}"
|
|
||||||
elif [ -d "${input}" ] ; then
|
|
||||||
rm -f "${output}"
|
|
||||||
cp -r -LH "${input}" "${output}"
|
|
||||||
elif echo "${input}" | grep -qe '^http\(s\)\?://' ; then
|
|
||||||
curl "${input}" > "${output}"
|
|
||||||
else
|
|
||||||
echo "ERROR: file type not known: ${input}" >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
echo "${output}"
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_test_response
|
|
||||||
# ----------------
|
|
||||||
# Perform GET request to the application container, checks output with
|
|
||||||
# a reg-exp and HTTP response code.
|
|
||||||
# Argument: url - request URL path
|
|
||||||
# Argument: expected_code - expected HTTP response code
|
|
||||||
# Argument: body_regexp - PCRE regular expression that must match the response body
|
|
||||||
# Argument: max_attempts - Optional number of attempts (default: 20), three seconds sleep between
|
|
||||||
# Argument: ignore_error_attempts - Optional number of attempts when we ignore error output (default: 10)
|
|
||||||
ct_test_response() {
|
|
||||||
local url="$1"
|
|
||||||
local expected_code="$2"
|
|
||||||
local body_regexp="$3"
|
|
||||||
local max_attempts=${4:-20}
|
|
||||||
local ignore_error_attempts=${5:-10}
|
|
||||||
|
|
||||||
: " Testing the HTTP(S) response for <${url}>"
|
|
||||||
local sleep_time=3
|
|
||||||
local attempt=1
|
|
||||||
local result=1
|
|
||||||
local status
|
|
||||||
local response_code
|
|
||||||
local response_file
|
|
||||||
response_file=$(mktemp /tmp/ct_test_response_XXXXXX)
|
|
||||||
while [ "${attempt}" -le "${max_attempts}" ]; do
|
|
||||||
curl --connect-timeout 10 -s -w '%{http_code}' "${url}" >"${response_file}" && status=0 || status=1
|
|
||||||
if [ "${status}" -eq 0 ]; then
|
|
||||||
response_code=$(tail -c 3 "${response_file}")
|
|
||||||
if [ "${response_code}" -eq "${expected_code}" ]; then
|
|
||||||
result=0
|
|
||||||
fi
|
|
||||||
grep -qP -e "${body_regexp}" "${response_file}" || result=1;
|
|
||||||
# Some services return 40x code until they are ready, so let's give them
|
|
||||||
# some chance and not end with failure right away
|
|
||||||
# Do not wait if we already have expected outcome though
|
|
||||||
if [ "${result}" -eq 0 ] || [ "${attempt}" -gt "${ignore_error_attempts}" ] || [ "${attempt}" -eq "${max_attempts}" ] ; then
|
|
||||||
break
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
attempt=$(( attempt + 1 ))
|
|
||||||
sleep "${sleep_time}"
|
|
||||||
done
|
|
||||||
rm -f "${response_file}"
|
|
||||||
return "${result}"
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_registry_from_os OS
|
|
||||||
# ----------------
|
|
||||||
# Transform operating system string [os] into registry url
|
|
||||||
# Argument: OS - string containing the os version
|
|
||||||
ct_registry_from_os() {
|
|
||||||
local registry=""
|
|
||||||
case $1 in
|
|
||||||
rhel*)
|
|
||||||
registry=registry.redhat.io
|
|
||||||
;;
|
|
||||||
*)
|
|
||||||
registry=docker.io
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
echo "$registry"
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_get_public_image_name OS BASE_IMAGE_NAME VERSION
|
|
||||||
# ----------------
|
|
||||||
# Transform the arguments into public image name
|
|
||||||
# Argument: OS - string containing the os version
|
|
||||||
# Argument: BASE_IMAGE_NAME - string containing the base name of the image as defined in the Makefile
|
|
||||||
# Argument: VERSION - string containing the version of the image as defined in the Makefile
|
|
||||||
ct_get_public_image_name() {
|
|
||||||
local os=$1; shift
|
|
||||||
local base_image_name=$1; shift
|
|
||||||
local version=$1; shift
|
|
||||||
|
|
||||||
local public_image_name
|
|
||||||
local registry
|
|
||||||
|
|
||||||
registry=$(ct_registry_from_os "$os")
|
|
||||||
if [ "x$os" == "xrhel7" ]; then
|
|
||||||
public_image_name=$registry/rhscl/$base_image_name-${version//./}-rhel7
|
|
||||||
elif [ "x$os" == "xrhel8" ]; then
|
|
||||||
public_image_name=$registry/rhel8/$base_image_name-${version//./}
|
|
||||||
elif [ "x$os" == "xcentos7" ]; then
|
|
||||||
public_image_name=$registry/centos/$base_image_name-${version//./}-centos7
|
|
||||||
elif [ "x$os" == "xcentos8" ]; then
|
|
||||||
public_image_name=$registry/centos/$base_image_name-${version//./}-centos8
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "$public_image_name"
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_assert_cmd_success CMD
|
|
||||||
# ----------------
|
|
||||||
# Evaluates [cmd] and fails if it does not succeed.
|
|
||||||
# Argument: CMD - Command to be run
|
|
||||||
function ct_assert_cmd_success() {
|
|
||||||
echo "Checking '$*' for success ..."
|
|
||||||
if ! eval "$@" &>/dev/null; then
|
|
||||||
echo " FAIL"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
echo " PASS"
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_assert_cmd_failure CMD
|
|
||||||
# ----------------
|
|
||||||
# Evaluates [cmd] and fails if it succeeds.
|
|
||||||
# Argument: CMD - Command to be run
|
|
||||||
function ct_assert_cmd_failure() {
|
|
||||||
echo "Checking '$*' for failure ..."
|
|
||||||
if eval "$@" &>/dev/null; then
|
|
||||||
echo " FAIL"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
echo " PASS"
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# ct_random_string [LENGTH=10]
|
|
||||||
# ----------------------------
|
|
||||||
# Generate pseudorandom alphanumeric string of LENGTH bytes, the
|
|
||||||
# default length is 10. The string is printed on stdout.
|
|
||||||
ct_random_string()
|
|
||||||
(
|
|
||||||
export LC_ALL=C
|
|
||||||
dd if=/dev/urandom count=1 bs=10k 2>/dev/null \
|
|
||||||
| tr -dc 'a-z0-9' \
|
|
||||||
| fold -w "${1-10}" \
|
|
||||||
| head -n 1
|
|
||||||
)
|
|
||||||
|
|
||||||
# ct_s2i_usage IMG_NAME [S2I_ARGS]
|
|
||||||
# ----------------------------
|
|
||||||
# Create a container and run the usage script inside
|
|
||||||
# Argument: IMG_NAME - name of the image to be used for the container run
|
|
||||||
# Argument: S2I_ARGS - Additional list of source-to-image arguments, currently unused.
|
|
||||||
ct_s2i_usage()
|
|
||||||
{
|
|
||||||
local img_name=$1; shift
|
|
||||||
local s2i_args="$*";
|
|
||||||
local usage_command="/usr/libexec/s2i/usage"
|
|
||||||
docker run --rm "$img_name" bash -c "$usage_command"
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_s2i_build_as_df APP_PATH SRC_IMAGE DST_IMAGE [S2I_ARGS]
|
|
||||||
# ----------------------------
|
|
||||||
# Create a new s2i app image from local sources in a similar way as source-to-image would have used.
|
|
||||||
# Argument: APP_PATH - local path to the app sources to be used in the test
|
|
||||||
# Argument: SRC_IMAGE - image to be used as a base for the s2i build
|
|
||||||
# Argument: DST_IMAGE - image name to be used during the tagging of the s2i build result
|
|
||||||
# Argument: S2I_ARGS - Additional list of source-to-image arguments.
|
|
||||||
# Only used to check for pull-policy=never and environment variable definitions.
|
|
||||||
ct_s2i_build_as_df()
|
|
||||||
{
|
|
||||||
local app_path=$1; shift
|
|
||||||
local src_image=$1; shift
|
|
||||||
local dst_image=$1; shift
|
|
||||||
local s2i_args="$*";
|
|
||||||
local local_app=upload/src/
|
|
||||||
local local_scripts=upload/scripts/
|
|
||||||
local user_id=
|
|
||||||
local df_name=
|
|
||||||
local tmpdir=
|
|
||||||
local incremental=false
|
|
||||||
local mount_options=""
|
|
||||||
|
|
||||||
# Run the entire thing inside a subshell so that we do not leak shell options outside of the function
|
|
||||||
(
|
|
||||||
# Error out if any part of the build fails
|
|
||||||
set -e
|
|
||||||
|
|
||||||
# Use /tmp to not pollute cwd
|
|
||||||
tmpdir=$(mktemp -d)
|
|
||||||
df_name=$(mktemp -p "$tmpdir" Dockerfile.XXXX)
|
|
||||||
cd "$tmpdir"
|
|
||||||
# Check if the image is available locally and try to pull it if it is not
|
|
||||||
docker images "$src_image" &>/dev/null || echo "$s2i_args" | grep -q "pull-policy=never" || docker pull "$src_image"
|
|
||||||
user=$(docker inspect -f "{{.Config.User}}" "$src_image")
|
|
||||||
# Default to root if no user is set by the image
|
|
||||||
user=${user:-0}
|
|
||||||
# run the user through the image in case it is non-numeric or does not exist
|
|
||||||
# NOTE: The '-eq' test is used to check if $user is numeric as it will fail if $user is not an integer
|
|
||||||
if ! [ "$user" -eq "$user" ] 2>/dev/null && ! user_id=$(docker run --rm "$src_image" bash -c "id -u $user 2>/dev/null"); then
|
|
||||||
echo "ERROR: id of user $user not found inside image $src_image."
|
|
||||||
echo "Terminating s2i build."
|
|
||||||
return 1
|
|
||||||
else
|
|
||||||
user_id=${user_id:-$user}
|
|
||||||
fi
|
|
||||||
echo "$s2i_args" | grep -q "\-\-incremental" && incremental=true
|
|
||||||
if $incremental; then
|
|
||||||
inc_tmp=$(mktemp -d --tmpdir incremental.XXXX)
|
|
||||||
setfacl -m "u:$user_id:rwx" "$inc_tmp"
|
|
||||||
# Check if the image exists, build should fail (for testing use case) if it does not
|
|
||||||
docker images "$dst_image" &>/dev/null || (echo "Image $dst_image not found."; false)
|
|
||||||
# Run the original image with a mounted in volume and get the artifacts out of it
|
|
||||||
cmd="if [ -s /usr/libexec/s2i/save-artifacts ]; then /usr/libexec/s2i/save-artifacts > \"$inc_tmp/artifacts.tar\"; else touch \"$inc_tmp/artifacts.tar\"; fi"
|
|
||||||
docker run --rm -v "$inc_tmp:$inc_tmp:Z" "$dst_image" bash -c "$cmd"
|
|
||||||
# Move the created content into the $tmpdir for the build to pick it up
|
|
||||||
mv "$inc_tmp/artifacts.tar" "$tmpdir/"
|
|
||||||
fi
|
|
||||||
# Strip file:// from APP_PATH and copy its contents into current context
|
|
||||||
mkdir -p "$local_app"
|
|
||||||
cp -r "${app_path/file:\/\//}/." "$local_app"
|
|
||||||
[ -d "$local_app/.s2i/bin/" ] && mv "$local_app/.s2i/bin" "$local_scripts"
|
|
||||||
# Create a Dockerfile named df_name and fill it with proper content
|
|
||||||
#FIXME: Some commands could be combined into a single layer but not sure if worth the trouble for testing purposes
|
|
||||||
cat <<EOF >"$df_name"
|
|
||||||
FROM $src_image
|
|
||||||
LABEL "io.openshift.s2i.build.image"="$src_image" \\
|
|
||||||
"io.openshift.s2i.build.source-location"="$app_path"
|
|
||||||
USER root
|
|
||||||
COPY $local_app /tmp/src
|
|
||||||
EOF
|
|
||||||
[ -d "$local_scripts" ] && echo "COPY $local_scripts /tmp/scripts" >> "$df_name" &&
|
|
||||||
echo "RUN chown -R $user_id:0 /tmp/scripts" >>"$df_name"
|
|
||||||
echo "RUN chown -R $user_id:0 /tmp/src" >>"$df_name"
|
|
||||||
# Check for custom environment variables inside .s2i/ folder
|
|
||||||
if [ -e "$local_app/.s2i/environment" ]; then
|
|
||||||
# Remove any comments and add the contents as ENV commands to the Dockerfile
|
|
||||||
sed '/^\s*#.*$/d' "$local_app/.s2i/environment" | while read -r line; do
|
|
||||||
echo "ENV $line" >>"$df_name"
|
|
||||||
done
|
|
||||||
fi
|
|
||||||
# Filter out env var definitions from $s2i_args and create Dockerfile ENV commands out of them
|
|
||||||
echo "$s2i_args" | grep -o -e '\(-e\|--env\)[[:space:]=]\S*=\S*' | sed -e 's/-e /ENV /' -e 's/--env[ =]/ENV /' >>"$df_name"
|
|
||||||
# Check if CA autority is present on host and add it into Dockerfile
|
|
||||||
[ -f "$(full_ca_file_path)" ] && echo "RUN cd /etc/pki/ca-trust/source/anchors && update-ca-trust extract" >>"$df_name"
|
|
||||||
|
|
||||||
# Add in artifacts if doing an incremental build
|
|
||||||
if $incremental; then
|
|
||||||
{ echo "RUN mkdir /tmp/artifacts"
|
|
||||||
echo "ADD artifacts.tar /tmp/artifacts"
|
|
||||||
echo "RUN chown -R $user_id:0 /tmp/artifacts" ; } >>"$df_name"
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "USER $user_id" >>"$df_name"
|
|
||||||
# If exists, run the custom assemble script, else default to /usr/libexec/s2i/assemble
|
|
||||||
if [ -x "$local_scripts/assemble" ]; then
|
|
||||||
echo "RUN /tmp/scripts/assemble" >>"$df_name"
|
|
||||||
else
|
|
||||||
echo "RUN /usr/libexec/s2i/assemble" >>"$df_name"
|
|
||||||
fi
|
|
||||||
# If exists, set the custom run script as CMD, else default to /usr/libexec/s2i/run
|
|
||||||
if [ -x "$local_scripts/run" ]; then
|
|
||||||
echo "CMD /tmp/scripts/run" >>"$df_name"
|
|
||||||
else
|
|
||||||
echo "CMD /usr/libexec/s2i/run" >>"$df_name"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Check if -v parameter is present in s2i_args and add it into docker build command
|
|
||||||
mount_options=$(echo "$s2i_args" | grep -o -e '\(-v\)[[:space:]]\.*\S*' || true)
|
|
||||||
|
|
||||||
# Run the build and tag the result
|
|
||||||
# shellcheck disable=SC2086
|
|
||||||
docker build $mount_options -f "$df_name" --no-cache=true -t "$dst_image" .
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_check_image_availability PUBLIC_IMAGE_NAME
|
|
||||||
# ----------------------------
|
|
||||||
# Pull an image from the public repositories to see if the image is already available.
|
|
||||||
# Argument: PUBLIC_IMAGE_NAME - string containing the public name of the image to pull
|
|
||||||
ct_check_image_availability() {
|
|
||||||
local public_image_name=$1;
|
|
||||||
|
|
||||||
# Try pulling the image to see if it is accessible
|
|
||||||
if ! docker pull "$public_image_name" &>/dev/null; then
|
|
||||||
echo "$public_image_name could not be downloaded via 'docker'"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_check_latest_imagestreams
|
|
||||||
# -----------------------------
|
|
||||||
# Check if the latest version present in Makefile in the variable VERSIONS
|
|
||||||
# is present in all imagestreams.
|
|
||||||
# Also the latest tag in the imagestreams has to contain the latest version
|
|
||||||
ct_check_latest_imagestreams() {
|
|
||||||
local latest_version=
|
|
||||||
local test_lib_dir=
|
|
||||||
|
|
||||||
# We only maintain imagestreams for RHEL and CentOS (Community)
|
|
||||||
if [[ "$OS" =~ ^fedora.* ]] ; then
|
|
||||||
echo "Imagestreams for Fedora are not maintained, skipping ct_check_latest_imagestreams"
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Check only lines which starts with VERSIONS
|
|
||||||
latest_version=$(grep '^VERSIONS' Makefile | rev | cut -d ' ' -f 1 | rev )
|
|
||||||
# Fall back to previous version if the latest is excluded for this OS
|
|
||||||
[ -f "$latest_version/.exclude-$OS" ] && latest_version=$(grep '^VERSIONS' Makefile | rev | cut -d ' ' -f 2 | rev )
|
|
||||||
# Only test the imagestream once, when the version matches
|
|
||||||
# ignore the SC warning, $VERSION is always available
|
|
||||||
# shellcheck disable=SC2153
|
|
||||||
if [ "$latest_version" == "$VERSION" ]; then
|
|
||||||
test_lib_dir=$(dirname "$(readlink -f "$0")")
|
|
||||||
python3 "${test_lib_dir}/check_imagestreams.py" "$latest_version"
|
|
||||||
else
|
|
||||||
echo "Image version $VERSION is not latest, skipping ct_check_latest_imagestreams"
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_show_resources
|
|
||||||
# ----------------
|
|
||||||
# Prints the available resources
|
|
||||||
ct_show_resources()
|
|
||||||
{
|
|
||||||
echo "Resources info:"
|
|
||||||
echo "Memory:"
|
|
||||||
free -h
|
|
||||||
echo "Storage:"
|
|
||||||
df -h
|
|
||||||
echo "CPU"
|
|
||||||
lscpu
|
|
||||||
}
|
|
||||||
|
|
||||||
# ct_test_app_dockerfile
|
|
||||||
# -----------------------------
|
|
||||||
# Argument: dockerfile - path to a Dockerfile that will be used for building an image
|
|
||||||
# (must work with an application directory called 'app-src')
|
|
||||||
# Argument: app_url - git URI with a testing application
|
|
||||||
# Argument: body_regexp - PCRE regular expression that must match the response body
|
|
||||||
# Argument: app_dir - name of the application directory that is used in the Dockerfile
|
|
||||||
# Argument: port - Optional port number (default: 8080)
|
|
||||||
ct_test_app_dockerfile() {
|
|
||||||
local dockerfile=$1
|
|
||||||
local app_url=$2
|
|
||||||
local expected_text=$3
|
|
||||||
local app_dir=$4 # this is a directory that must match with the name in the Dockerfile
|
|
||||||
local port=${5:-8080}
|
|
||||||
local app_image_name=myapp
|
|
||||||
local ret
|
|
||||||
local cname=app_dockerfile
|
|
||||||
|
|
||||||
if [ -z "$app_dir" ] ; then
|
|
||||||
echo "ERROR: Option app_dir not set. Terminating the Dockerfile build."
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
if ! [ -r "${dockerfile}" ] || ! [ -s "${dockerfile}" ] ; then
|
|
||||||
echo "ERROR: Dockerfile ${dockerfile} does not exist or is empty."
|
|
||||||
echo "Terminating the Dockerfile build."
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
CID_FILE_DIR=${CID_FILE_DIR:-$(mktemp -d)}
|
|
||||||
local dockerfile_abs
|
|
||||||
dockerfile_abs=$(readlink -f "${dockerfile}")
|
|
||||||
tmpdir=$(mktemp -d)
|
|
||||||
pushd "$tmpdir" >/dev/null
|
|
||||||
cp "${dockerfile_abs}" Dockerfile
|
|
||||||
|
|
||||||
# Rewrite the source image to what we test
|
|
||||||
sed -i -e "s|^FROM.*$|FROM $IMAGE_NAME|" Dockerfile
|
|
||||||
# a bit more verbose, but should help debugging failures
|
|
||||||
echo "Using this Dockerfile:"
|
|
||||||
cat Dockerfile
|
|
||||||
|
|
||||||
if ! git clone "${app_url}" "${app_dir}" ; then
|
|
||||||
echo "ERROR: Git repository ${app_url} cannot be cloned into ${app_dir}."
|
|
||||||
echo "Terminating the Dockerfile build."
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "Building '${app_image_name}' image using docker build"
|
|
||||||
if ! docker build --no-cache=true -t "${app_image_name}" . ; then
|
|
||||||
echo "ERROR: The image cannot be built from ${dockerfile} and application ${app_url}."
|
|
||||||
echo "Terminating the Dockerfile build."
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
if ! docker run -d --cidfile="${CID_FILE_DIR}/app_dockerfile" --rm "${app_image_name}" ; then
|
|
||||||
echo "ERROR: The image ${app_image_name} cannot be run for ${dockerfile} and application ${app_url}."
|
|
||||||
echo "Terminating the Dockerfile build."
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
echo "Waiting for ${app_image_name} to start"
|
|
||||||
ct_wait_for_cid "${CID_FILE_DIR}/app_dockerfile"
|
|
||||||
|
|
||||||
ip="$(ct_get_cip "${cname}")"
|
|
||||||
ct_test_response "http://$ip:${port}" 200 "${expected_text}"
|
|
||||||
ret=$?
|
|
||||||
|
|
||||||
# cleanup
|
|
||||||
docker kill "$(ct_get_cid "${cname}")"
|
|
||||||
sleep 2
|
|
||||||
docker rmi "${app_image_name}"
|
|
||||||
popd >/dev/null
|
|
||||||
rm -rf "${tmpdir}"
|
|
||||||
rm -f "${CID_FILE_DIR}/${cname}"
|
|
||||||
return $ret
|
|
||||||
}
|
|
||||||
|
|
||||||
# vim: set tabstop=2:shiftwidth=2:expandtab:
|
|
||||||
|
|
@ -1,38 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
# This script is used to test container images integrated in the OpenShift.
|
|
||||||
#
|
|
||||||
# VERSIONS - Must be set to a list with possible versions (subdirectories)
|
|
||||||
#
|
|
||||||
# This script expects oc command to exist and logged in to a working cluster.
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
export OS=${OS:-rhel7}
|
|
||||||
|
|
||||||
if [ "${OS}" == "rhel7" ] ; then
|
|
||||||
NAMESPACE=${NAMESPACE:-rhscl/}
|
|
||||||
REGISTRY=${REGISTRY:-registry.access.redhat.com/}
|
|
||||||
else
|
|
||||||
NAMESPACE=${NAMESPACE:-centos/}
|
|
||||||
fi
|
|
||||||
|
|
||||||
export NAMESPACE
|
|
||||||
export REGISTRY
|
|
||||||
|
|
||||||
for dir in ${VERSIONS}; do
|
|
||||||
[ ! -e "${dir}/.image-id" ] && echo "-> Image for version $dir not built, skipping OpenShift 4 tests." && continue
|
|
||||||
pushd "${dir}" > /dev/null
|
|
||||||
|
|
||||||
export IMAGE_NAME="${NAMESPACE}${BASE_IMAGE_NAME}-${dir//./}-${OS}"
|
|
||||||
|
|
||||||
if [[ -x test/run-openshift-remote-cluster ]]; then
|
|
||||||
VERSION="${dir}" test/run-openshift-remote-cluster
|
|
||||||
else
|
|
||||||
echo "-> Tests for OpenShift 4 are not present. Add run-openshift-remote-cluster script, skipping"
|
|
||||||
fi
|
|
||||||
|
|
||||||
popd > /dev/null
|
|
||||||
done
|
|
||||||
|
|
||||||
# vim: set tabstop=2:shiftwidth=2:expandtab:
|
|
||||||
|
|
@ -1,67 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
# This script is used to test the OpenShift Docker images.
|
|
||||||
#
|
|
||||||
# TEST_MODE - If set, run regular test suite
|
|
||||||
# TEST_OPENSHIFT_MODE - If set, run OpenShift tests (if present)
|
|
||||||
# VERSIONS - Must be set to a list with possible versions (subdirectories)
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
for dir in ${VERSIONS}; do
|
|
||||||
[ ! -e "${dir}/.image-id" ] && echo "-> Image for version $dir not built, skipping tests." && continue
|
|
||||||
pushd "${dir}" > /dev/null
|
|
||||||
IMAGE_ID=$(cat .image-id)
|
|
||||||
export IMAGE_ID
|
|
||||||
IMAGE_VERSION=$(docker inspect -f "{{.Config.Labels.version}}" "$IMAGE_ID")
|
|
||||||
# Kept also IMAGE_NAME as some tests might still use that.
|
|
||||||
IMAGE_NAME="$(docker inspect -f "{{.Config.Labels.name}}" "$IMAGE_ID"):$IMAGE_VERSION"
|
|
||||||
export IMAGE_NAME
|
|
||||||
|
|
||||||
if [ -n "${TEST_MODE}" ]; then
|
|
||||||
VERSION=$dir test/run
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -n "${TEST_CONU_MODE}" ]; then
|
|
||||||
if [[ -x test/run-conu ]]; then
|
|
||||||
if [ -n "${CONU_IMAGE}" ]; then
|
|
||||||
echo "-> Running conu tests in a container"
|
|
||||||
docker run \
|
|
||||||
--net=host \
|
|
||||||
-e VERSION="${dir}" \
|
|
||||||
-e IMAGE_NAME \
|
|
||||||
--rm \
|
|
||||||
--security-opt label=disable \
|
|
||||||
-ti \
|
|
||||||
-v /var/run/docker.sock:/var/run/docker.sock \
|
|
||||||
-v "${PWD}"/../:/src \
|
|
||||||
-w "/src/${dir}/" \
|
|
||||||
-ti \
|
|
||||||
"${CONU_IMAGE}" \
|
|
||||||
./test/run-conu
|
|
||||||
else
|
|
||||||
VERSION="${dir}" ./test/run-conu
|
|
||||||
fi
|
|
||||||
else
|
|
||||||
echo "-> conu tests are not present, skipping"
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -n "${TEST_OPENSHIFT_4}" ]; then
|
|
||||||
if [[ -x test/run-openshift-remote-cluster ]]; then
|
|
||||||
VERSION=$dir test/run-openshift-remote-cluster
|
|
||||||
else
|
|
||||||
echo "-> Tests for OpenShift 4 are not present. Add run-openshift-remote-cluster script, skipping"
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -n "${TEST_OPENSHIFT_MODE}" ]; then
|
|
||||||
if [[ -x test/run-openshift ]]; then
|
|
||||||
VERSION=$dir test/run-openshift
|
|
||||||
else
|
|
||||||
echo "-> OpenShift 3 tests are not present, skipping"
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
|
|
||||||
popd > /dev/null
|
|
||||||
done
|
|
||||||
3
common/tests/.gitignore
vendored
3
common/tests/.gitignore
vendored
|
|
@ -1,3 +0,0 @@
|
||||||
.image-id*
|
|
||||||
help.1
|
|
||||||
check_imagestreams.py
|
|
||||||
|
|
@ -1,9 +0,0 @@
|
||||||
#!/bin/sh
|
|
||||||
|
|
||||||
set -x
|
|
||||||
|
|
||||||
check_imagestreams=$(dirname "$(readlink -f "$0")")/../check_imagestreams.py
|
|
||||||
"${PYTHON-python3}" "$check_imagestreams" "2.5"
|
|
||||||
test $? -eq 1
|
|
||||||
"${PYTHON-python3}" "$check_imagestreams" "2.4"
|
|
||||||
test $? -eq 0
|
|
||||||
|
|
@ -1,4 +0,0 @@
|
||||||
# Variables are documented in common/build.sh.
|
|
||||||
BASE_IMAGE_NAME = test-container
|
|
||||||
VERSIONS = v0
|
|
||||||
include common/common.mk
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
../../..
|
|
||||||
|
|
@ -1,2 +0,0 @@
|
||||||
FROM centos/s2i-core-centos7
|
|
||||||
LABEL name=test-image
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
This is just no-op-build container.
|
|
||||||
|
|
@ -1,3 +0,0 @@
|
||||||
#! /bin/sh -x
|
|
||||||
|
|
||||||
false this must fail the whole testsuite
|
|
||||||
|
|
@ -1,53 +0,0 @@
|
||||||
{
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"kind": "ImageStream",
|
|
||||||
"metadata": {
|
|
||||||
"annotations": {
|
|
||||||
"openshift.io/display-name": "Apache HTTP Server (httpd)"
|
|
||||||
},
|
|
||||||
"name": "httpd"
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"tags": [
|
|
||||||
{
|
|
||||||
"annotations": {
|
|
||||||
"description": "Build and serve static content via Apache HTTP Server (httpd) on RHEL 7. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/httpd-container/blob/master/2.4/README.md.\n\nWARNING: By selecting this tag, your application will automatically update to use the latest version of Httpd available on OpenShift, including major version updates.",
|
|
||||||
"iconClass": "icon-apache",
|
|
||||||
"openshift.io/display-name": "Apache HTTP Server (Latest)",
|
|
||||||
"openshift.io/provider-display-name": "Red Hat, Inc.",
|
|
||||||
"sampleRepo": "https://github.com/sclorg/httpd-ex.git",
|
|
||||||
"supports": "httpd",
|
|
||||||
"tags": "builder,httpd"
|
|
||||||
},
|
|
||||||
"from": {
|
|
||||||
"kind": "ImageStreamTag",
|
|
||||||
"name": "2.4"
|
|
||||||
},
|
|
||||||
"referencePolicy": {
|
|
||||||
"type": "Local"
|
|
||||||
},
|
|
||||||
"name": "latest"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"annotations": {
|
|
||||||
"description": "Build and serve static content via Apache HTTP Server (httpd) 2.4 on RHEL 7. For more information about using this builder image, including OpenShift considerations, see https://github.com/sclorg/httpd-container/blob/master/2.4/README.md.",
|
|
||||||
"iconClass": "icon-apache",
|
|
||||||
"openshift.io/display-name": "Apache HTTP Server 2.4",
|
|
||||||
"openshift.io/provider-display-name": "Red Hat, Inc.",
|
|
||||||
"sampleRepo": "https://github.com/sclorg/httpd-ex.git",
|
|
||||||
"supports": "httpd",
|
|
||||||
"tags": "builder,httpd",
|
|
||||||
"version": "2.4"
|
|
||||||
},
|
|
||||||
"from": {
|
|
||||||
"kind": "DockerImage",
|
|
||||||
"name": "registry.redhat.io/rhscl/httpd-24-rhel7"
|
|
||||||
},
|
|
||||||
"referencePolicy": {
|
|
||||||
"type": "Local"
|
|
||||||
},
|
|
||||||
"name": "2.4"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -1,103 +0,0 @@
|
||||||
#! /bin/bash
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
declare -A IMAGES
|
|
||||||
|
|
||||||
for image in ${TESTED_IMAGES}; do
|
|
||||||
IMAGES[$image]=master
|
|
||||||
done
|
|
||||||
|
|
||||||
OS=centos7
|
|
||||||
|
|
||||||
MERGE_INTO=origin/master
|
|
||||||
|
|
||||||
# This is the Fedora default, some users' boxes have more strict
|
|
||||||
# defaults (e.g. 0077).
|
|
||||||
umask 0022
|
|
||||||
|
|
||||||
die () { echo >&2 " # FATAL: $*"; exit 1; }
|
|
||||||
info () { echo " * $*"; }
|
|
||||||
error () { echo >&2 " # ERROR: $*"; }
|
|
||||||
|
|
||||||
test -f common.mk -a -f build.sh -a -d .git \
|
|
||||||
|| die "Doesn't seem to be run from common's git directory"
|
|
||||||
|
|
||||||
analyse_commits ()
|
|
||||||
{
|
|
||||||
# TODO: If we wanted to test "after PR merge", this needs to take some
|
|
||||||
# argument specifying how long we should look in the commit history.
|
|
||||||
git merge-base --is-ancestor "$MERGE_INTO" HEAD \
|
|
||||||
|| die "Please rebase the commit '$(git rev-parse --short HEAD)'" \
|
|
||||||
"to allow --ff merge into '$MERGE_INTO' branch"
|
|
||||||
|
|
||||||
while read line; do
|
|
||||||
case $line in
|
|
||||||
Required-by:\ *)
|
|
||||||
set -- $line
|
|
||||||
old_IFS=$IFS
|
|
||||||
IFS=\#
|
|
||||||
set -- $2
|
|
||||||
IFS=$old_IFS
|
|
||||||
set -- $1 $2
|
|
||||||
info "PR commits ask for testing $1 from PR $2"
|
|
||||||
IMAGES[$1]=$2
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
done < <(git log --format=%B --reverse "$MERGE_INTO"..HEAD)
|
|
||||||
}
|
|
||||||
|
|
||||||
analyse_commits
|
|
||||||
|
|
||||||
for image in "${!IMAGES[@]}"; do
|
|
||||||
# We don't want to remove user's WIP stuff.
|
|
||||||
test -e "$image" && die "directory '$image' exists"
|
|
||||||
|
|
||||||
( set -e
|
|
||||||
testdir=$PWD
|
|
||||||
cleanup () {
|
|
||||||
set -x
|
|
||||||
# Ensure the cleanup finishes!
|
|
||||||
trap '' INT
|
|
||||||
# Go back, wherever we are.
|
|
||||||
cd "$testdir"
|
|
||||||
# Try to cleanup, if available (and if needed).
|
|
||||||
make clean -C "$image" || :
|
|
||||||
# Drop the image sources.
|
|
||||||
test ! -d "$image" || rm -rf "$image"
|
|
||||||
}
|
|
||||||
trap cleanup EXIT
|
|
||||||
|
|
||||||
info "Testing $image image"
|
|
||||||
|
|
||||||
# Use --recursive even if we remove 'common', because there might be
|
|
||||||
# other git submodules which need to be tested.
|
|
||||||
git clone --recursive -q https://github.com/sclorg/"$image".git
|
|
||||||
cd "$image"
|
|
||||||
|
|
||||||
revision=${IMAGES[$image]}
|
|
||||||
if ! test "$revision" = master; then
|
|
||||||
info "Fetching $image PR $revision"
|
|
||||||
git fetch origin "pull/$revision/head":PR_BRANCH
|
|
||||||
git checkout PR_BRANCH
|
|
||||||
git submodule update
|
|
||||||
fi
|
|
||||||
|
|
||||||
# We fail if the 'common' directory doesn't exist.
|
|
||||||
test -d common
|
|
||||||
rm -rf common
|
|
||||||
info "Replacing common with PR's version"
|
|
||||||
ln -s ../ common
|
|
||||||
|
|
||||||
# TODO: Do we have to test all $(VERSION)s?
|
|
||||||
# TODO: The PS4 hack doesn't work if we run the testsuite as UID=0.
|
|
||||||
PS4="+ [$image] " make TARGET="$OS" test
|
|
||||||
|
|
||||||
# Cleanup.
|
|
||||||
make clean
|
|
||||||
)
|
|
||||||
|
|
||||||
if test $? -ne 0; then
|
|
||||||
die "Tests for $image failed"
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
1
common/tests/squash/.gitignore
vendored
1
common/tests/squash/.gitignore
vendored
|
|
@ -1 +0,0 @@
|
||||||
Dockerfile
|
|
||||||
|
|
@ -1,24 +0,0 @@
|
||||||
#! /bin/sh
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
if grep -q "Red Hat Enterprise Linux release 8" /etc/system-release; then
|
|
||||||
# No use testing squash.py on rhel8 for now as it does not work at all
|
|
||||||
echo " ! test case ignored on RHEL8 host"
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
origin=busybox
|
|
||||||
squash=$(dirname "$(readlink -f "$0")")/../../squash.py
|
|
||||||
cd "$(dirname "$0")"
|
|
||||||
|
|
||||||
cat > Dockerfile <<EOF
|
|
||||||
FROM $origin
|
|
||||||
ENV test=test
|
|
||||||
CMD /bin/echo test
|
|
||||||
EOF
|
|
||||||
out=`docker build . | awk '/Successfully built/{print $NF}'`
|
|
||||||
echo "$out"
|
|
||||||
squashed=$("${PYTHON-python3}" "$squash" "$out" "$origin")
|
|
||||||
output=$(docker run --rm $squashed)
|
|
||||||
test "$output" = "test"
|
|
||||||
|
|
@ -1,17 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
. test-lib.sh
|
|
||||||
|
|
||||||
# This should succeed
|
|
||||||
if ! ct_check_image_availability docker.io/centos/postgresql-10-centos7; then
|
|
||||||
echo "image_availability test failed"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# This should fail
|
|
||||||
if ct_check_image_availability docker.io/centos/postgresql-98-centos7; then
|
|
||||||
echo "image_availability test failed"
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "image_availability test completed successfully."
|
|
||||||
|
|
@ -1,24 +0,0 @@
|
||||||
#! /bin/bash
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
. test-lib.sh
|
|
||||||
|
|
||||||
path='a b c:d x:y'
|
|
||||||
exp_output="==a b c==
|
|
||||||
==.==
|
|
||||||
==d x==
|
|
||||||
==.==
|
|
||||||
==y==
|
|
||||||
==.=="
|
|
||||||
|
|
||||||
wrap() { for arg; do echo "==$arg=="; done; }
|
|
||||||
|
|
||||||
test "$(ct_path_foreach "$path" wrap .)" == "$exp_output"
|
|
||||||
|
|
||||||
ct_path_append path '/a'
|
|
||||||
exp_output="==/a==
|
|
||||||
==.==
|
|
||||||
$exp_output"
|
|
||||||
|
|
||||||
test "$(ct_path_foreach "$path" wrap .)" == "$exp_output"
|
|
||||||
|
|
@ -1,17 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
. test-lib.sh
|
|
||||||
|
|
||||||
combinations="rhel7:registry.redhat.io/rhscl/postgresql-10-rhel7
|
|
||||||
centos7:docker.io/centos/postgresql-10-centos7
|
|
||||||
rhel8:registry.redhat.io/rhel8/postgresql-10
|
|
||||||
"
|
|
||||||
|
|
||||||
for c in $combinations; do
|
|
||||||
public_name=$(ct_get_public_image_name "${c%%:*}" postgresql 10)
|
|
||||||
[ "$public_name" == "${c#*:}" ]
|
|
||||||
done
|
|
||||||
|
|
||||||
echo "public_image_name test completed successfully."
|
|
||||||
|
|
@ -1,17 +0,0 @@
|
||||||
#! /bin/bash
|
|
||||||
|
|
||||||
set -e
|
|
||||||
. test-lib.sh
|
|
||||||
|
|
||||||
x=$(ct_random_string)
|
|
||||||
test ${#x} -eq 10
|
|
||||||
|
|
||||||
for i in 5 9 11 13; do
|
|
||||||
x=$(ct_random_string $i)
|
|
||||||
test ${#x} -eq $i
|
|
||||||
done
|
|
||||||
|
|
||||||
# Even with ignored sigpipe we have to succeed promptly (#70).
|
|
||||||
trap '' SIGPIPE
|
|
||||||
x=$(ct_random_string 20)
|
|
||||||
test ${#x} -eq 20
|
|
||||||
|
|
@ -1,16 +0,0 @@
|
||||||
#! /bin/bash
|
|
||||||
|
|
||||||
set -ex
|
|
||||||
|
|
||||||
. test-lib.sh
|
|
||||||
|
|
||||||
NPM_REGISTRY=""
|
|
||||||
output=$(ct_build_s2i_npm_variables)
|
|
||||||
test x"$output" == "x"
|
|
||||||
|
|
||||||
ca_file="/etc/pki/ca-trust/source/anchors/RH-IT-Root-CA.crt"
|
|
||||||
NPM_REGISTRY="https://foobar.registry.org"
|
|
||||||
if [ -f "$ca_file" ]; then
|
|
||||||
output=$(ct_build_s2i_npm_variables)
|
|
||||||
test x"$output" == "x-e NPM_MIRROR=$NPM_REGISTRY -v $ca_file:$ca_file:Z"
|
|
||||||
fi
|
|
||||||
|
|
@ -1,72 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
set -ex
|
|
||||||
shopt -s extglob
|
|
||||||
|
|
||||||
COMMIT=$(git rev-parse HEAD)
|
|
||||||
|
|
||||||
# import generated content from this git reference ..
|
|
||||||
SOURCE_BRANCH=${1:-$COMMIT}
|
|
||||||
|
|
||||||
# into this git branch
|
|
||||||
GENERATED_BRANCH=${2:-generated}
|
|
||||||
|
|
||||||
git clean -f -d
|
|
||||||
|
|
||||||
# switch to generated branch for working env; and switch back later
|
|
||||||
git checkout "$GENERATED_BRANCH"
|
|
||||||
git submodule update
|
|
||||||
|
|
||||||
# Clean everything in generated branch.
|
|
||||||
rm -rf -- *
|
|
||||||
|
|
||||||
srcdir=srcdir
|
|
||||||
|
|
||||||
cleanup ()
|
|
||||||
{
|
|
||||||
exit_status=$?
|
|
||||||
rm -rf "$srcdir"
|
|
||||||
|
|
||||||
# switch back to initial ranch
|
|
||||||
git checkout "$SOURCE_BRANCH"
|
|
||||||
git submodule update
|
|
||||||
|
|
||||||
return $exit_status
|
|
||||||
}
|
|
||||||
trap cleanup EXIT
|
|
||||||
|
|
||||||
(
|
|
||||||
# Copy the actual repo into $srcdir, and generate there
|
|
||||||
mkdir "$srcdir"
|
|
||||||
cd "$srcdir"
|
|
||||||
git clone .. .
|
|
||||||
git checkout "$SOURCE_BRANCH"
|
|
||||||
git submodule update --init
|
|
||||||
make generate-all
|
|
||||||
)
|
|
||||||
|
|
||||||
# copy the relevant (generated) content from $srcdir
|
|
||||||
versions=$(sed -n 's/^VERSIONS[[:space:]]*=//p' "$srcdir"/Makefile)
|
|
||||||
for i in $versions; do
|
|
||||||
cp -r "$srcdir/$i" .
|
|
||||||
done
|
|
||||||
|
|
||||||
# source directory is not needed anymore
|
|
||||||
rm -rf "$srcdir"
|
|
||||||
|
|
||||||
# shellcheck disable=SC2086
|
|
||||||
git add $versions
|
|
||||||
|
|
||||||
# Add deleted files to the index as well
|
|
||||||
(
|
|
||||||
IFS=$'\n'
|
|
||||||
for i in $(git ls-files --deleted) ;do
|
|
||||||
git add --all "$i"
|
|
||||||
done
|
|
||||||
)
|
|
||||||
|
|
||||||
if ! git diff --cached --exit-code --quiet ; then
|
|
||||||
git commit -m "auto-sync: master commit $COMMIT"
|
|
||||||
else
|
|
||||||
echo "Nothing changed"
|
|
||||||
fi
|
|
||||||
1
dead.package
Normal file
1
dead.package
Normal file
|
|
@ -0,0 +1 @@
|
||||||
|
The repository is available in https://github.com/sclorg organization. Images are pushed to quay.io/fedora organization from the upstream repo.
|
||||||
|
|
@ -1,2 +0,0 @@
|
||||||
Bind-mount this directory under /opt/app-root/src in container, and all the
|
|
||||||
*.conf files from postgresql-cfg/ files will be included to postgresql.conf.
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
shared_buffers = 111MB
|
|
||||||
|
|
@ -1,5 +0,0 @@
|
||||||
ssl = on
|
|
||||||
ssl_cert_file = '/opt/app-root/src/server.crt' # server certificate
|
|
||||||
ssl_key_file = '/opt/app-root/src/server.key' # server private key
|
|
||||||
#ssl_ca_file # trusted certificate authorities
|
|
||||||
#ssl_crl_file # certificates revoked by certificate authorities
|
|
||||||
|
|
@ -1,4 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
# Postgresql server will reject key files with liberal permissions
|
|
||||||
chmod og-rwx server.key
|
|
||||||
|
|
@ -1,77 +0,0 @@
|
||||||
Certificate:
|
|
||||||
Data:
|
|
||||||
Version: 3 (0x2)
|
|
||||||
Serial Number:
|
|
||||||
2c:86:f9:22:0f:0c:ed:2b:e8:a3:f1:cf:9e:2b:09:82:22:76:ec:2b
|
|
||||||
Signature Algorithm: sha256WithRSAEncryption
|
|
||||||
Issuer: CN = testing
|
|
||||||
Validity
|
|
||||||
Not Before: Sep 16 11:39:01 2019 GMT
|
|
||||||
Not After : Sep 13 11:39:01 2029 GMT
|
|
||||||
Subject: CN = testing
|
|
||||||
Subject Public Key Info:
|
|
||||||
Public Key Algorithm: rsaEncryption
|
|
||||||
RSA Public-Key: (2048 bit)
|
|
||||||
Modulus:
|
|
||||||
00:d9:0f:25:ca:d9:32:4d:db:95:f5:5f:09:5a:2b:
|
|
||||||
e2:f7:ae:6a:b3:43:ce:1c:35:60:bd:cc:01:3f:f2:
|
|
||||||
0f:eb:20:da:55:8b:42:95:da:a5:0a:c8:c5:43:54:
|
|
||||||
64:85:e7:5b:2c:77:6a:1f:db:9f:56:39:35:e4:0f:
|
|
||||||
b0:1c:2b:a6:73:46:e8:27:2b:9f:62:5c:bf:7f:48:
|
|
||||||
5a:99:e1:8d:73:fe:d6:3a:ec:25:35:07:ad:69:f3:
|
|
||||||
95:81:ea:8a:20:50:fd:fc:e9:c0:b5:ac:f7:21:af:
|
|
||||||
37:2c:8e:23:51:74:fa:75:b2:48:c4:6e:95:f1:2d:
|
|
||||||
bc:af:ff:f4:eb:da:a3:78:fe:e9:c9:c0:ef:21:b5:
|
|
||||||
46:f5:e9:8c:9a:f9:94:84:a7:63:be:d6:fe:eb:31:
|
|
||||||
fb:ca:87:2e:e6:43:53:bd:3c:09:7f:cc:7b:9d:e2:
|
|
||||||
b9:0a:49:a5:5c:61:6e:94:f9:75:85:e3:41:e7:92:
|
|
||||||
24:84:9f:61:c7:d4:cc:b5:26:8a:c1:db:bf:a5:ce:
|
|
||||||
43:72:61:04:2f:bf:21:c4:d1:73:dd:b4:f8:37:bf:
|
|
||||||
85:0d:0e:92:8d:22:33:4b:ed:6d:55:2d:0b:42:c4:
|
|
||||||
23:e8:30:f3:86:2b:99:ba:e5:ba:ef:54:b4:40:29:
|
|
||||||
2d:53:7c:d4:59:72:20:65:88:9d:68:5a:fc:25:a8:
|
|
||||||
13:0d
|
|
||||||
Exponent: 65537 (0x10001)
|
|
||||||
X509v3 extensions:
|
|
||||||
X509v3 Subject Key Identifier:
|
|
||||||
17:77:65:09:AD:ED:EE:02:01:AB:09:FE:1E:FD:AB:4E:F2:4D:0A:23
|
|
||||||
X509v3 Authority Key Identifier:
|
|
||||||
keyid:17:77:65:09:AD:ED:EE:02:01:AB:09:FE:1E:FD:AB:4E:F2:4D:0A:23
|
|
||||||
|
|
||||||
X509v3 Basic Constraints: critical
|
|
||||||
CA:TRUE
|
|
||||||
Signature Algorithm: sha256WithRSAEncryption
|
|
||||||
14:67:98:15:fa:57:88:75:89:9a:0b:f0:e1:94:dd:dc:12:ab:
|
|
||||||
a0:2a:20:6d:38:64:39:39:58:4f:4d:2d:16:1d:e2:e2:d3:56:
|
|
||||||
35:2e:3c:f5:be:7e:16:fb:87:a1:b9:27:e6:d4:52:e8:1e:c5:
|
|
||||||
c7:b7:74:b5:15:53:6d:b0:90:34:8c:ce:20:82:62:60:1e:f2:
|
|
||||||
21:f9:22:a5:cb:17:a7:a9:55:71:cb:66:f5:dd:c2:85:6a:e1:
|
|
||||||
a7:35:d0:b9:09:6a:ae:4d:a5:32:34:fa:2a:cc:10:85:6c:95:
|
|
||||||
50:50:2c:e9:59:d1:40:78:16:d3:87:c3:31:cb:33:7b:0f:3a:
|
|
||||||
ef:51:c1:2e:0c:eb:38:61:de:01:42:0e:1d:cc:7d:b1:24:4b:
|
|
||||||
ef:ce:9d:c6:b0:97:51:c9:cc:23:d6:5d:4e:cf:68:06:c2:47:
|
|
||||||
94:c5:80:df:07:bc:72:cc:79:3d:94:be:6d:c8:b3:17:e6:5e:
|
|
||||||
52:38:c4:6b:a9:ee:ad:94:f9:74:bf:8a:95:12:06:b4:4d:17:
|
|
||||||
ca:72:a5:61:90:b7:c0:0f:d0:04:e1:39:3c:75:d5:8a:5c:11:
|
|
||||||
96:f7:fe:82:5a:e6:30:2c:2f:94:4e:bb:1e:8e:d8:0b:6e:1e:
|
|
||||||
e4:5f:f6:c9:a3:4d:2f:58:ee:ad:b7:cd:53:3f:f1:dc:1e:d2:
|
|
||||||
06:a0:03:58
|
|
||||||
-----BEGIN CERTIFICATE-----
|
|
||||||
MIIDBTCCAe2gAwIBAgIULIb5Ig8M7Svoo/HPnisJgiJ27CswDQYJKoZIhvcNAQEL
|
|
||||||
BQAwEjEQMA4GA1UEAwwHdGVzdGluZzAeFw0xOTA5MTYxMTM5MDFaFw0yOTA5MTMx
|
|
||||||
MTM5MDFaMBIxEDAOBgNVBAMMB3Rlc3RpbmcwggEiMA0GCSqGSIb3DQEBAQUAA4IB
|
|
||||||
DwAwggEKAoIBAQDZDyXK2TJN25X1XwlaK+L3rmqzQ84cNWC9zAE/8g/rINpVi0KV
|
|
||||||
2qUKyMVDVGSF51ssd2of259WOTXkD7AcK6ZzRugnK59iXL9/SFqZ4Y1z/tY67CU1
|
|
||||||
B61p85WB6oogUP386cC1rPchrzcsjiNRdPp1skjEbpXxLbyv//Tr2qN4/unJwO8h
|
|
||||||
tUb16Yya+ZSEp2O+1v7rMfvKhy7mQ1O9PAl/zHud4rkKSaVcYW6U+XWF40HnkiSE
|
|
||||||
n2HH1My1JorB27+lzkNyYQQvvyHE0XPdtPg3v4UNDpKNIjNL7W1VLQtCxCPoMPOG
|
|
||||||
K5m65brvVLRAKS1TfNRZciBliJ1oWvwlqBMNAgMBAAGjUzBRMB0GA1UdDgQWBBQX
|
|
||||||
d2UJre3uAgGrCf4e/atO8k0KIzAfBgNVHSMEGDAWgBQXd2UJre3uAgGrCf4e/atO
|
|
||||||
8k0KIzAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAUZ5gV+leI
|
|
||||||
dYmaC/DhlN3cEqugKiBtOGQ5OVhPTS0WHeLi01Y1Ljz1vn4W+4ehuSfm1FLoHsXH
|
|
||||||
t3S1FVNtsJA0jM4ggmJgHvIh+SKlyxenqVVxy2b13cKFauGnNdC5CWquTaUyNPoq
|
|
||||||
zBCFbJVQUCzpWdFAeBbTh8MxyzN7DzrvUcEuDOs4Yd4BQg4dzH2xJEvvzp3GsJdR
|
|
||||||
ycwj1l1Oz2gGwkeUxYDfB7xyzHk9lL5tyLMX5l5SOMRrqe6tlPl0v4qVEga0TRfK
|
|
||||||
cqVhkLfAD9AE4Tk8ddWKXBGW9/6CWuYwLC+UTrsejtgLbh7kX/bJo00vWO6tt81T
|
|
||||||
P/HcHtIGoANY
|
|
||||||
-----END CERTIFICATE-----
|
|
||||||
|
|
@ -1,28 +0,0 @@
|
||||||
-----BEGIN PRIVATE KEY-----
|
|
||||||
MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDZDyXK2TJN25X1
|
|
||||||
XwlaK+L3rmqzQ84cNWC9zAE/8g/rINpVi0KV2qUKyMVDVGSF51ssd2of259WOTXk
|
|
||||||
D7AcK6ZzRugnK59iXL9/SFqZ4Y1z/tY67CU1B61p85WB6oogUP386cC1rPchrzcs
|
|
||||||
jiNRdPp1skjEbpXxLbyv//Tr2qN4/unJwO8htUb16Yya+ZSEp2O+1v7rMfvKhy7m
|
|
||||||
Q1O9PAl/zHud4rkKSaVcYW6U+XWF40HnkiSEn2HH1My1JorB27+lzkNyYQQvvyHE
|
|
||||||
0XPdtPg3v4UNDpKNIjNL7W1VLQtCxCPoMPOGK5m65brvVLRAKS1TfNRZciBliJ1o
|
|
||||||
WvwlqBMNAgMBAAECggEAKvM8Xy8rLQzOV4c+qoEUoD37Dw3TsvE8+1FqzeRwEe6m
|
|
||||||
RVcRDeX90mx33CLO4VAuUlYuwa8LkFwxtbcE+g4JGbZmKZoQJ76ChgUjKF/hRZqf
|
|
||||||
eXlQw3WJcvWoF9T5D/v2xhza7RgUrq2lFUPq6Stkg/WLQJNBSD/snkbfh+vzfPVW
|
|
||||||
slg2zo1o9dMe53AOzjMkQ8RljbOfd+KZE340ZzftPxcTyrE9VaQqGLNtRiehhXPJ
|
|
||||||
dB7Kmc+/Pm1OkmpblnSAIJudsMNelUYsadYFgjtEgYYXFcuqNrCWeNRmMl5I/vEp
|
|
||||||
xnVf+gQfldJ+zAbkB4+nxMCOn1tqS2nOJRGW6xu4YQKBgQDt97CAAceXnRYoraqy
|
|
||||||
1ff5K8WxxCmcD0TcX/EfYXj1Qaex979x2SpftsrBTclkOxoTPv+OfrKZ1/Eq4a8z
|
|
||||||
0onP/lRGRxQ95gPvwFzQldKzmQVsoW6odZqMPO6hYJ0SsiZTwzc82IEXPA1QJJ6E
|
|
||||||
n3OggTLs0iCW3uLyXFL8npaL4wKBgQDpgdvSU82ipiEntMpqUuQdhw1TvnYwcSaC
|
|
||||||
GTUl4Uhwfdxmb424cqHiDoBKitd6DjHo20MshA/6WhWYq/dMz7ueEBu9cCKe85En
|
|
||||||
RzX0InCV26K1zBBbwMXGJGquIaQeha1GmOkpgORHjNwdwKZkZ/DJOHYOsjwGyQ22
|
|
||||||
H8cC6MX4TwKBgQCpqQ+ApEQuN0QmKnNqX50VXHztmeLkrgo1aH3cFr2LdozeGLm4
|
|
||||||
rNFGPmfeW9w7Btw3XpILgQ9LGieKoC8urmutDDH/jQvEeerSk35ZBIidnXq9kXb4
|
|
||||||
yigu1f54tg4m1zb2P1dxnRakfx8qxYDzI0/n3lV1fPbZOf3qN6K/Ez5YawKBgHQi
|
|
||||||
rQTvvz+c5rKL3XyCG4iACeXTvY6cSC2+gcuEP3YLcxnTc6YABXmcAryQT1kaREJv
|
|
||||||
AvrZ9+Ro94LGTKn8S3DyzAktA1sRAumJJlF064/s/AD1LFGmD/dbV1+hxbGUhLiv
|
|
||||||
BpAo1eCsMzHtBhS8CWra1QS8KtSpHFOvfFh7EzNLAoGBANyGrLj6qzywdSV7ccnd
|
|
||||||
sWg5U7Jgzuonb3K8LAc9NTnGn9C093RGY5HhsS1kTew01QRfxR7IdtSI9Q0vO/6I
|
|
||||||
stLGSa9fpn4leu2P6iF8r640xx02UFhKyf8wpM2RF38hHjAWRW/BaUEfnECeDi5A
|
|
||||||
yWuW6DFMAuJ80LdwyMPGkkt2
|
|
||||||
-----END PRIVATE KEY-----
|
|
||||||
|
|
@ -1,4 +0,0 @@
|
||||||
log_destination = 'stderr'
|
|
||||||
logging_collector = on
|
|
||||||
log_directory = 'pg_log'
|
|
||||||
log_filename = 'postgresql.log'
|
|
||||||
|
|
@ -1,4 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
# postgresql image encrypts user passwords at service start
|
|
||||||
# the functionality can be disabled by providing this file (postgresql-start-hook/set_passwords.sh) in s2i build
|
|
||||||
|
|
@ -1,10 +0,0 @@
|
||||||
The PostgreSQL Audit Extension (or pgaudit) provides detailed session and/or object
|
|
||||||
audit logging via the standard logging facility provided by PostgreSQL.
|
|
||||||
|
|
||||||
Bind-mount this directory under /opt/app-root/src in the container, and all the
|
|
||||||
*.conf files from postgresql-cfg/ files will be included to postgresql.conf.
|
|
||||||
|
|
||||||
This config file enables the pgaudit extensions that is available in the container
|
|
||||||
image, but needs to be enabled.
|
|
||||||
|
|
||||||
More about pgaudit extension at https://www.pgaudit.org.
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
shared_preload_libraries = 'pgaudit'
|
|
||||||
|
|
@ -1,253 +0,0 @@
|
||||||
{
|
|
||||||
"kind": "Template",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "postgresql-ephemeral",
|
|
||||||
"annotations": {
|
|
||||||
"openshift.io/display-name": "PostgreSQL (Ephemeral)",
|
|
||||||
"description": "PostgreSQL database service, without persistent storage. For more information about using this template, including OpenShift considerations, see https://github.com/sclorg/postgresql-container/.\n\nWARNING: Any data stored will be lost upon pod destruction. Only use this template for testing",
|
|
||||||
"iconClass": "icon-postgresql",
|
|
||||||
"tags": "database,postgresql",
|
|
||||||
"openshift.io/long-description": "This template provides a standalone PostgreSQL server with a database created. The database is not stored on persistent storage, so any restart of the service will result in all data being lost. The database name, username, and password are chosen via parameters when provisioning this service.",
|
|
||||||
"openshift.io/provider-display-name": "Red Hat, Inc.",
|
|
||||||
"openshift.io/documentation-url": "https://docs.okd.io/latest/using_images/db_images/postgresql.html",
|
|
||||||
"openshift.io/support-url": "https://access.redhat.com"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"message": "The following service(s) have been created in your project: ${DATABASE_SERVICE_NAME}.\n\n Username: ${POSTGRESQL_USER}\n Password: ${POSTGRESQL_PASSWORD}\n Database Name: ${POSTGRESQL_DATABASE}\n Connection URL: postgresql://${DATABASE_SERVICE_NAME}:5432/\n\nFor more information about using this template, including OpenShift considerations, see https://github.com/sclorg/postgresql-container/.",
|
|
||||||
"labels": {
|
|
||||||
"template": "postgresql-ephemeral-template"
|
|
||||||
},
|
|
||||||
"objects": [
|
|
||||||
{
|
|
||||||
"kind": "Secret",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}",
|
|
||||||
"annotations": {
|
|
||||||
"template.openshift.io/expose-username": "{.data['database-user']}",
|
|
||||||
"template.openshift.io/expose-password": "{.data['database-password']}",
|
|
||||||
"template.openshift.io/expose-database_name": "{.data['database-name']}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"stringData" : {
|
|
||||||
"database-user" : "${POSTGRESQL_USER}",
|
|
||||||
"database-password" : "${POSTGRESQL_PASSWORD}",
|
|
||||||
"database-name" : "${POSTGRESQL_DATABASE}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"kind": "Service",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}",
|
|
||||||
"annotations": {
|
|
||||||
"template.openshift.io/expose-uri": "postgres://{.spec.clusterIP}:{.spec.ports[?(.name==\"postgresql\")].port}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"ports": [
|
|
||||||
{
|
|
||||||
"name": "postgresql",
|
|
||||||
"protocol": "TCP",
|
|
||||||
"port": 5432,
|
|
||||||
"targetPort": 5432,
|
|
||||||
"nodePort": 0
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"selector": {
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}"
|
|
||||||
},
|
|
||||||
"type": "ClusterIP",
|
|
||||||
"sessionAffinity": "None"
|
|
||||||
},
|
|
||||||
"status": {
|
|
||||||
"loadBalancer": {}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"kind": "DeploymentConfig",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}",
|
|
||||||
"annotations": {
|
|
||||||
"template.alpha.openshift.io/wait-for-ready": "true"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"strategy": {
|
|
||||||
"type": "Recreate"
|
|
||||||
},
|
|
||||||
"triggers": [
|
|
||||||
{
|
|
||||||
"type": "ImageChange",
|
|
||||||
"imageChangeParams": {
|
|
||||||
"automatic": true,
|
|
||||||
"containerNames": [
|
|
||||||
"postgresql"
|
|
||||||
],
|
|
||||||
"from": {
|
|
||||||
"kind": "ImageStreamTag",
|
|
||||||
"name": "postgresql:${POSTGRESQL_VERSION}",
|
|
||||||
"namespace": "${NAMESPACE}"
|
|
||||||
},
|
|
||||||
"lastTriggeredImage": ""
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "ConfigChange"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"replicas": 1,
|
|
||||||
"selector": {
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}"
|
|
||||||
},
|
|
||||||
"template": {
|
|
||||||
"metadata": {
|
|
||||||
"labels": {
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"containers": [
|
|
||||||
{
|
|
||||||
"name": "postgresql",
|
|
||||||
"image": " ",
|
|
||||||
"ports": [
|
|
||||||
{
|
|
||||||
"containerPort": 5432,
|
|
||||||
"protocol": "TCP"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"readinessProbe": {
|
|
||||||
"timeoutSeconds": 1,
|
|
||||||
"initialDelaySeconds": 5,
|
|
||||||
"exec": {
|
|
||||||
"command": [ "/usr/libexec/check-container" ]
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"livenessProbe": {
|
|
||||||
"timeoutSeconds": 10,
|
|
||||||
"initialDelaySeconds": 120,
|
|
||||||
"exec": {
|
|
||||||
"command": [ "/usr/libexec/check-container", "--live" ]
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"env": [
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_USER",
|
|
||||||
"valueFrom": {
|
|
||||||
"secretKeyRef" : {
|
|
||||||
"name" : "${DATABASE_SERVICE_NAME}",
|
|
||||||
"key" : "database-user"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_PASSWORD",
|
|
||||||
"valueFrom": {
|
|
||||||
"secretKeyRef" : {
|
|
||||||
"name" : "${DATABASE_SERVICE_NAME}",
|
|
||||||
"key" : "database-password"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_DATABASE",
|
|
||||||
"valueFrom": {
|
|
||||||
"secretKeyRef" : {
|
|
||||||
"name" : "${DATABASE_SERVICE_NAME}",
|
|
||||||
"key" : "database-name"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"resources": {
|
|
||||||
"limits": {
|
|
||||||
"memory": "${MEMORY_LIMIT}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"volumeMounts": [
|
|
||||||
{
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}-data",
|
|
||||||
"mountPath": "/var/lib/pgsql/data"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"terminationMessagePath": "/dev/termination-log",
|
|
||||||
"imagePullPolicy": "IfNotPresent",
|
|
||||||
"capabilities": {},
|
|
||||||
"securityContext": {
|
|
||||||
"capabilities": {},
|
|
||||||
"privileged": false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"volumes": [
|
|
||||||
{
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}-data",
|
|
||||||
"emptyDir": {
|
|
||||||
"medium": ""
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"restartPolicy": "Always",
|
|
||||||
"dnsPolicy": "ClusterFirst"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"status": {}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"name": "MEMORY_LIMIT",
|
|
||||||
"displayName": "Memory Limit",
|
|
||||||
"description": "Maximum amount of memory the container can use.",
|
|
||||||
"value": "512Mi",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "NAMESPACE",
|
|
||||||
"displayName": "Namespace",
|
|
||||||
"description": "The OpenShift Namespace where the ImageStream resides.",
|
|
||||||
"value": "openshift"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "DATABASE_SERVICE_NAME",
|
|
||||||
"displayName": "Database Service Name",
|
|
||||||
"description": "The name of the OpenShift Service exposed for the database.",
|
|
||||||
"value": "postgresql",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_USER",
|
|
||||||
"displayName": "PostgreSQL Connection Username",
|
|
||||||
"description": "Username for PostgreSQL user that will be used for accessing the database.",
|
|
||||||
"generate": "expression",
|
|
||||||
"from": "user[A-Z0-9]{3}",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_PASSWORD",
|
|
||||||
"displayName": "PostgreSQL Connection Password",
|
|
||||||
"description": "Password for the PostgreSQL connection user.",
|
|
||||||
"generate": "expression",
|
|
||||||
"from": "[a-zA-Z0-9]{16}",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_DATABASE",
|
|
||||||
"displayName": "PostgreSQL Database Name",
|
|
||||||
"description": "Name of the PostgreSQL database accessed.",
|
|
||||||
"value": "sampledb",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_VERSION",
|
|
||||||
"displayName": "Version of PostgreSQL Image",
|
|
||||||
"description": "Version of PostgreSQL image to be used (10-el7, 10-el8, or latest).",
|
|
||||||
"value": "10-el8",
|
|
||||||
"required": true
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
|
|
@ -1,277 +0,0 @@
|
||||||
{
|
|
||||||
"kind": "Template",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "postgresql-persistent",
|
|
||||||
"annotations": {
|
|
||||||
"openshift.io/display-name": "PostgreSQL",
|
|
||||||
"description": "PostgreSQL database service, with persistent storage. For more information about using this template, including OpenShift considerations, see https://github.com/sclorg/postgresql-container/.\n\nNOTE: Scaling to more than one replica is not supported. You must have persistent volumes available in your cluster to use this template.",
|
|
||||||
"iconClass": "icon-postgresql",
|
|
||||||
"tags": "database,postgresql",
|
|
||||||
"openshift.io/long-description": "This template provides a standalone PostgreSQL server with a database created. The database is stored on persistent storage. The database name, username, and password are chosen via parameters when provisioning this service.",
|
|
||||||
"openshift.io/provider-display-name": "Red Hat, Inc.",
|
|
||||||
"openshift.io/documentation-url": "https://docs.okd.io/latest/using_images/db_images/postgresql.html",
|
|
||||||
"openshift.io/support-url": "https://access.redhat.com"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"message": "The following service(s) have been created in your project: ${DATABASE_SERVICE_NAME}.\n\n Username: ${POSTGRESQL_USER}\n Password: ${POSTGRESQL_PASSWORD}\n Database Name: ${POSTGRESQL_DATABASE}\n Connection URL: postgresql://${DATABASE_SERVICE_NAME}:5432/\n\nFor more information about using this template, including OpenShift considerations, see https://github.com/sclorg/postgresql-container/.",
|
|
||||||
"labels": {
|
|
||||||
"template": "postgresql-persistent-template"
|
|
||||||
},
|
|
||||||
"objects": [
|
|
||||||
{
|
|
||||||
"kind": "Secret",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}",
|
|
||||||
"annotations": {
|
|
||||||
"template.openshift.io/expose-username": "{.data['database-user']}",
|
|
||||||
"template.openshift.io/expose-password": "{.data['database-password']}",
|
|
||||||
"template.openshift.io/expose-database_name": "{.data['database-name']}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"stringData" : {
|
|
||||||
"database-user" : "${POSTGRESQL_USER}",
|
|
||||||
"database-password" : "${POSTGRESQL_PASSWORD}",
|
|
||||||
"database-name" : "${POSTGRESQL_DATABASE}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"kind": "Service",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}",
|
|
||||||
"annotations": {
|
|
||||||
"template.openshift.io/expose-uri": "postgres://{.spec.clusterIP}:{.spec.ports[?(.name==\"postgresql\")].port}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"ports": [
|
|
||||||
{
|
|
||||||
"name": "postgresql",
|
|
||||||
"protocol": "TCP",
|
|
||||||
"port": 5432,
|
|
||||||
"targetPort": 5432,
|
|
||||||
"nodePort": 0
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"selector": {
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}"
|
|
||||||
},
|
|
||||||
"type": "ClusterIP",
|
|
||||||
"sessionAffinity": "None"
|
|
||||||
},
|
|
||||||
"status": {
|
|
||||||
"loadBalancer": {}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"kind": "PersistentVolumeClaim",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}"
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"accessModes": [
|
|
||||||
"ReadWriteOnce"
|
|
||||||
],
|
|
||||||
"resources": {
|
|
||||||
"requests": {
|
|
||||||
"storage": "${VOLUME_CAPACITY}"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"kind": "DeploymentConfig",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}",
|
|
||||||
"annotations": {
|
|
||||||
"template.alpha.openshift.io/wait-for-ready": "true"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"strategy": {
|
|
||||||
"type": "Recreate"
|
|
||||||
},
|
|
||||||
"triggers": [
|
|
||||||
{
|
|
||||||
"type": "ImageChange",
|
|
||||||
"imageChangeParams": {
|
|
||||||
"automatic": true,
|
|
||||||
"containerNames": [
|
|
||||||
"postgresql"
|
|
||||||
],
|
|
||||||
"from": {
|
|
||||||
"kind": "ImageStreamTag",
|
|
||||||
"name": "postgresql:${POSTGRESQL_VERSION}",
|
|
||||||
"namespace": "${NAMESPACE}"
|
|
||||||
},
|
|
||||||
"lastTriggeredImage": ""
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "ConfigChange"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"replicas": 1,
|
|
||||||
"selector": {
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}"
|
|
||||||
},
|
|
||||||
"template": {
|
|
||||||
"metadata": {
|
|
||||||
"labels": {
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"containers": [
|
|
||||||
{
|
|
||||||
"name": "postgresql",
|
|
||||||
"image": " ",
|
|
||||||
"ports": [
|
|
||||||
{
|
|
||||||
"containerPort": 5432,
|
|
||||||
"protocol": "TCP"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"readinessProbe": {
|
|
||||||
"timeoutSeconds": 1,
|
|
||||||
"initialDelaySeconds": 5,
|
|
||||||
"exec": {
|
|
||||||
"command": [ "/usr/libexec/check-container" ]
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"livenessProbe": {
|
|
||||||
"timeoutSeconds": 10,
|
|
||||||
"initialDelaySeconds": 120,
|
|
||||||
"exec": {
|
|
||||||
"command": [ "/usr/libexec/check-container", "--live" ]
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"env": [
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_USER",
|
|
||||||
"valueFrom": {
|
|
||||||
"secretKeyRef" : {
|
|
||||||
"name" : "${DATABASE_SERVICE_NAME}",
|
|
||||||
"key" : "database-user"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_PASSWORD",
|
|
||||||
"valueFrom": {
|
|
||||||
"secretKeyRef" : {
|
|
||||||
"name" : "${DATABASE_SERVICE_NAME}",
|
|
||||||
"key" : "database-password"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_DATABASE",
|
|
||||||
"valueFrom": {
|
|
||||||
"secretKeyRef" : {
|
|
||||||
"name" : "${DATABASE_SERVICE_NAME}",
|
|
||||||
"key" : "database-name"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"resources": {
|
|
||||||
"limits": {
|
|
||||||
"memory": "${MEMORY_LIMIT}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"volumeMounts": [
|
|
||||||
{
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}-data",
|
|
||||||
"mountPath": "/var/lib/pgsql/data"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"terminationMessagePath": "/dev/termination-log",
|
|
||||||
"imagePullPolicy": "IfNotPresent",
|
|
||||||
"capabilities": {},
|
|
||||||
"securityContext": {
|
|
||||||
"capabilities": {},
|
|
||||||
"privileged": false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"volumes": [
|
|
||||||
{
|
|
||||||
"name": "${DATABASE_SERVICE_NAME}-data",
|
|
||||||
"persistentVolumeClaim": {
|
|
||||||
"claimName": "${DATABASE_SERVICE_NAME}"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"restartPolicy": "Always",
|
|
||||||
"dnsPolicy": "ClusterFirst"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"status": {}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"name": "MEMORY_LIMIT",
|
|
||||||
"displayName": "Memory Limit",
|
|
||||||
"description": "Maximum amount of memory the container can use.",
|
|
||||||
"value": "512Mi",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "NAMESPACE",
|
|
||||||
"displayName": "Namespace",
|
|
||||||
"description": "The OpenShift Namespace where the ImageStream resides.",
|
|
||||||
"value": "openshift"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "DATABASE_SERVICE_NAME",
|
|
||||||
"displayName": "Database Service Name",
|
|
||||||
"description": "The name of the OpenShift Service exposed for the database.",
|
|
||||||
"value": "postgresql",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_USER",
|
|
||||||
"displayName": "PostgreSQL Connection Username",
|
|
||||||
"description": "Username for PostgreSQL user that will be used for accessing the database.",
|
|
||||||
"generate": "expression",
|
|
||||||
"from": "user[A-Z0-9]{3}",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_PASSWORD",
|
|
||||||
"displayName": "PostgreSQL Connection Password",
|
|
||||||
"description": "Password for the PostgreSQL connection user.",
|
|
||||||
"generate": "expression",
|
|
||||||
"from": "[a-zA-Z0-9]{16}",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_DATABASE",
|
|
||||||
"displayName": "PostgreSQL Database Name",
|
|
||||||
"description": "Name of the PostgreSQL database accessed.",
|
|
||||||
"value": "sampledb",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "VOLUME_CAPACITY",
|
|
||||||
"displayName": "Volume Capacity",
|
|
||||||
"description": "Volume space available for data, e.g. 512Mi, 2Gi.",
|
|
||||||
"value": "1Gi",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_VERSION",
|
|
||||||
"displayName": "Version of PostgreSQL Image",
|
|
||||||
"description": "Version of PostgreSQL image to be used (10-el7, 10-el8, or latest).",
|
|
||||||
"value": "10-el8",
|
|
||||||
"required": true
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
|
|
@ -1,240 +0,0 @@
|
||||||
# PostgreSQL Replication Example
|
|
||||||
|
|
||||||
**WARNING: This is only a Proof-Of-Concept example and it is not meant to be used in
|
|
||||||
production. Use at your own risk.**
|
|
||||||
|
|
||||||
## What is PostgreSQL replication?
|
|
||||||
|
|
||||||
Replication enables data from one database server (master, or primary) to be
|
|
||||||
replicated to one or more servers (slaves, or standby servers).
|
|
||||||
|
|
||||||
PostgreSQL has [different replication solutions](http://www.postgresql.org/docs/9.2/static/different-replication-solutions.html),
|
|
||||||
each with its own pros and cons.
|
|
||||||
This example uses PostgreSQL's native support for [streaming replication](http://www.postgresql.org/docs/9.2/static/warm-standby.html).
|
|
||||||
In this configuration, the primary server operates in continuous archiving mode,
|
|
||||||
while each standby server operates in continuous recovery mode, streaming over
|
|
||||||
the network the write-ahead log (WAL) records from the primary as they're
|
|
||||||
generated.
|
|
||||||
|
|
||||||
This configuration can be used to create a high availability (HA) cluster
|
|
||||||
configuration and has relatively low performance impact on the primary server.
|
|
||||||
|
|
||||||
A standby server can also be used for read-only queries.
|
|
||||||
|
|
||||||
## Deployment
|
|
||||||
|
|
||||||
This example uses a [PersistentVolumeClaim](https://docs.okd.io/latest/architecture/additional_concepts/storage.html#persistent-volume-claims)
|
|
||||||
to request persistent storage for the primary PostgreSQL server.
|
|
||||||
|
|
||||||
You need to have persistent volumes configured and available in your project in
|
|
||||||
order to continue. For trying out this example in a single node testing
|
|
||||||
environment, you can create a temporary volume with:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ oc create -f - <<EOF
|
|
||||||
{
|
|
||||||
"kind": "PersistentVolume",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "postgres-data-volume"
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"capacity": {
|
|
||||||
"storage": "512Mi"
|
|
||||||
},
|
|
||||||
"hostPath": {
|
|
||||||
"path": "`mktemp -d --tmpdir pg-data.XXXXX | tee >(xargs chmod a+rwx)`"
|
|
||||||
},
|
|
||||||
"accessModes": [
|
|
||||||
"ReadWriteOnce"
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
EOF
|
|
||||||
```
|
|
||||||
|
|
||||||
It is recommended, however, that you use other [type of PersistentVolume](https://docs.okd.io/latest/architecture/additional_concepts/storage.html#types-of-persistent-volumes)
|
|
||||||
such as NFS.
|
|
||||||
|
|
||||||
Now you can create a new database deployment:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ oc new-app examples/replica/postgresql_replica.json
|
|
||||||
```
|
|
||||||
|
|
||||||
## How does this example work?
|
|
||||||
|
|
||||||
### Services 'postgresql-master' and 'postgresql-slave'
|
|
||||||
|
|
||||||
These services are the entry point for connecting to, respectively, the primary
|
|
||||||
database server and any of the standby servers.
|
|
||||||
|
|
||||||
In your application, connect to the `postgresql-master` service for write operations, and to `postgresql-master` or `postgresql-slave` for reads.
|
|
||||||
Keep in mind that reading from a slave might return slightly outdated data.
|
|
||||||
|
|
||||||
To get a list of endpoints for the read-only standby servers, you can do a DNS
|
|
||||||
query. From a container in the same OpenShift project:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ dig postgresql-slave A +search +short
|
|
||||||
```
|
|
||||||
|
|
||||||
### DeploymentConfig 'postgresql-master'
|
|
||||||
|
|
||||||
This resource defines a [deployment configuration](https://docs.okd.io/latest/architecture/core_concepts/deployments.html#deployments-and-deployment-configurations)
|
|
||||||
to spawn the PostgreSQL primary database server, or master.
|
|
||||||
|
|
||||||
Once the master is started, it works as a standalone database server, fully
|
|
||||||
independent of the slaves.
|
|
||||||
|
|
||||||
### DeploymentConfig 'postgresql-slave'
|
|
||||||
|
|
||||||
This resource defines a [deployment configuration](https://docs.okd.io/latest/architecture/core_concepts/deployments.html#deployments-and-deployment-configurations)
|
|
||||||
to spawn PostgreSQL standby servers, the slaves.
|
|
||||||
|
|
||||||
Upon startup, each slave waits for the master server to become available (via
|
|
||||||
DNS lookup). Once that happens, the slave connects to the master and starts
|
|
||||||
streaming the WAL.
|
|
||||||
|
|
||||||
To check that the slave is connected and streaming changes from the master,
|
|
||||||
you can issue the following commands:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ master_name=`oc get pods -l name=postgresql-master -t '{{ (index .items 0).metadata.name }}'`
|
|
||||||
$ oc exec $master_name -- bash -c 'psql -c "select client_addr, state from pg_stat_replication;"'
|
|
||||||
```
|
|
||||||
|
|
||||||
After a successful deployment, you should get an output similar to:
|
|
||||||
|
|
||||||
```
|
|
||||||
client_addr | state
|
|
||||||
--------------+-----------
|
|
||||||
172.17.0.227 | streaming
|
|
||||||
(1 row)
|
|
||||||
```
|
|
||||||
|
|
||||||
## Scaling
|
|
||||||
|
|
||||||
By default, the provided template creates one primary and one standby server.
|
|
||||||
Scaling in this setup means increasing the number of standby servers,
|
|
||||||
consequently increasing data redundancy and concurrent read throughput (if
|
|
||||||
reading from slaves).
|
|
||||||
|
|
||||||
You can add more slaves using `oc scale`:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ oc scale dc postgresql-slave --replicas=2
|
|
||||||
```
|
|
||||||
|
|
||||||
Using `oc scale` with `postgresql-master` is not supported.
|
|
||||||
|
|
||||||
After scaling, you can verify that all slaves are streaming changes from the
|
|
||||||
master with:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ oc exec $master_name -- bash -c 'psql -c "select client_addr, state from pg_stat_replication;"'
|
|
||||||
client_addr | state
|
|
||||||
--------------+-----------
|
|
||||||
172.17.0.227 | streaming
|
|
||||||
172.17.0.229 | streaming
|
|
||||||
(2 rows)
|
|
||||||
```
|
|
||||||
|
|
||||||
There should be one row per slave (number of replicas defined via `oc scale`).
|
|
||||||
|
|
||||||
## Changing passwords
|
|
||||||
|
|
||||||
You can change the passwords for the database user and admin, as well as the
|
|
||||||
password used for replication, by changing the appropriate environment variables
|
|
||||||
in the deployment configurations described earlier.
|
|
||||||
No other method is supported.
|
|
||||||
|
|
||||||
On every deploy, passwords are reset to match the values in the environment
|
|
||||||
variables of the DeploymentConfig 'postgresql-master'.
|
|
||||||
|
|
||||||
### POSTGRESQL_PASSWORD and POSTGRESQL_ADMIN_PASSWORD
|
|
||||||
|
|
||||||
These are, respectively, the passwords for the regular database user defined
|
|
||||||
by `POSTGRESQL_USER` and the admin user 'postgres'.
|
|
||||||
|
|
||||||
You can change these passwords with:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ oc env dc postgresql-master POSTGRESQL_PASSWORD=NewPassword POSTGRESQL_ADMIN_PASSWORD=NewAdminPassword
|
|
||||||
deploymentconfigs/postgresql-master
|
|
||||||
```
|
|
||||||
|
|
||||||
This will trigger the redeployment of the primary server.
|
|
||||||
Note that you can change one password but not the other by simply omitting one
|
|
||||||
of the arguments to `oc env` above.
|
|
||||||
|
|
||||||
You can verify that the new password is in effect with:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ oc exec $master_name -- bash -c 'PGPASSWORD=NewPassword psql -h postgresql-master $POSTGRESQL_DATABASE $POSTGRESQL_USER -c "select * from (select inet_server_addr()) ra cross join (select current_database()) cdb cross join (select current_user) cu"'
|
|
||||||
inet_server_addr | current_database | current_user
|
|
||||||
------------------+------------------+--------------
|
|
||||||
172.17.1.38 | userdb | user
|
|
||||||
(1 row)
|
|
||||||
```
|
|
||||||
|
|
||||||
You should also be able to connect to a slave using the new password:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ oc exec $master_name -- bash -c 'PGPASSWORD=NewPassword psql -h postgresql-slave $POSTGRESQL_DATABASE $POSTGRESQL_USER -c "select * from (select inet_server_addr()) ra cross join (select current_database()) cdb cross join (select current_user) cu"'
|
|
||||||
inet_server_addr | current_database | current_user
|
|
||||||
------------------+------------------+--------------
|
|
||||||
172.17.1.35 | userdb | user
|
|
||||||
(1 row)
|
|
||||||
```
|
|
||||||
|
|
||||||
For completeness, here's how to verify the new admin password:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ oc exec $master_name -- bash -c 'PGPASSWORD=NewAdminPassword psql -h postgresql-master $POSTGRESQL_DATABASE -c "select * from (select inet_server_addr()) ra cross join (select current_database()) cdb cross join (select current_user) cu"'
|
|
||||||
inet_server_addr | current_database | current_user
|
|
||||||
------------------+------------------+--------------
|
|
||||||
172.17.1.38 | userdb | postgres
|
|
||||||
(1 row)
|
|
||||||
```
|
|
||||||
|
|
||||||
```
|
|
||||||
$ oc exec $master_name -- bash -c 'PGPASSWORD=NewAdminPassword psql -h postgresql-slave $POSTGRESQL_DATABASE -c "select * from (select inet_server_addr()) ra cross join (select current_database()) cdb cross join (select current_user) cu"'
|
|
||||||
inet_server_addr | current_database | current_user
|
|
||||||
------------------+------------------+--------------
|
|
||||||
172.17.1.35 | userdb | postgres
|
|
||||||
(1 row)
|
|
||||||
```
|
|
||||||
|
|
||||||
### POSTGRESQL_MASTER_PASSWORD
|
|
||||||
|
|
||||||
This password is used by standby servers to connect to the primary. Both
|
|
||||||
deployment configurations in this example setup need to agree on the value of
|
|
||||||
this password to have replication working correctly.
|
|
||||||
|
|
||||||
You can change the environment variable with the password on both deployment
|
|
||||||
configurations at once:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ oc env dc postgresql-master postgresql-slave POSTGRESQL_MASTER_PASSWORD=NewReplicationPassword
|
|
||||||
deploymentconfigs/postgresql-master
|
|
||||||
deploymentconfigs/postgresql-slave
|
|
||||||
```
|
|
||||||
|
|
||||||
This will trigger the redeployment of both primary and standby servers.
|
|
||||||
|
|
||||||
Note that, as a current limitation in this example, the standby servers store
|
|
||||||
replicated data in an an ephemeral [emptyDir](https://docs.okd.io/latest/dev_guide/volumes.html).
|
|
||||||
This means that redeploying a standby server will cause it to start replicating
|
|
||||||
again from scratch.
|
|
||||||
|
|
||||||
After the primary and standby servers are ready, you can verify that the standby
|
|
||||||
servers are successfully connected to the primary:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ oc exec $master_name -- bash -c 'psql -c "select client_addr, state from pg_stat_replication;"'
|
|
||||||
client_addr | state
|
|
||||||
-------------+-----------
|
|
||||||
172.17.1.35 | streaming
|
|
||||||
(1 row)
|
|
||||||
```
|
|
||||||
|
|
@ -1,370 +0,0 @@
|
||||||
{
|
|
||||||
"kind": "Template",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "pg-replica-example",
|
|
||||||
"annotations": {
|
|
||||||
"description": "PostgreSQL Replication Example",
|
|
||||||
"iconClass": "icon-database",
|
|
||||||
"tags": "database,postgresql,replication"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"parameters": [
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_MASTER_USER",
|
|
||||||
"description": "The username used for master-slave replication",
|
|
||||||
"value": "master",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_MASTER_PASSWORD",
|
|
||||||
"description": "The password for the PostgreSQL replication user",
|
|
||||||
"generate": "expression",
|
|
||||||
"from": "[a-zA-Z0-9]{12}",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_USER",
|
|
||||||
"description": "The username that clients will use to connect to PostgreSQL server",
|
|
||||||
"value": "user",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_PASSWORD",
|
|
||||||
"description": "The password for the PostgreSQL master user",
|
|
||||||
"generate": "expression",
|
|
||||||
"from": "[a-zA-Z0-9]{12}",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_DATABASE",
|
|
||||||
"description": "The name of the database that will be created",
|
|
||||||
"value": "userdb",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_ADMIN_PASSWORD",
|
|
||||||
"description": "The password for the PostgreSQL administrator",
|
|
||||||
"generate": "expression",
|
|
||||||
"from": "[a-zA-Z0-9]{12}",
|
|
||||||
"required": false
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_MASTER_SERVICE_NAME",
|
|
||||||
"description": "The name of the PostgreSQL Service (used to DNS lookup, default: 'postgresql-master')",
|
|
||||||
"value": "postgresql-master",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_SLAVE_SERVICE_NAME",
|
|
||||||
"description": "The name of the PostgreSQL Service (used to DNS lookup, default: 'postgresql-slave')",
|
|
||||||
"value": "postgresql-slave",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "VOLUME_CAPACITY",
|
|
||||||
"description": "Volume space available for data, e.g. 512Mi, 2Gi",
|
|
||||||
"value": "512Mi",
|
|
||||||
"required": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "IMAGESTREAMTAG",
|
|
||||||
"displayName": "ImageStreamTag",
|
|
||||||
"description": "The OpenShift ImageStreamTag to use for PostgreSQL.",
|
|
||||||
"value": "postgresql:9.6"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "NAMESPACE",
|
|
||||||
"displayName": "Namespace",
|
|
||||||
"description": "The OpenShift Namespace where the ImageStream resides.",
|
|
||||||
"value": "openshift"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"objects": [
|
|
||||||
{
|
|
||||||
"kind": "PersistentVolumeClaim",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "postgresql-data-claim"
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"accessModes": [
|
|
||||||
"ReadWriteOnce"
|
|
||||||
],
|
|
||||||
"resources": {
|
|
||||||
"requests": {
|
|
||||||
"storage": "${VOLUME_CAPACITY}"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"kind": "Service",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "${POSTGRESQL_MASTER_SERVICE_NAME}",
|
|
||||||
"labels": {
|
|
||||||
"name": "${POSTGRESQL_MASTER_SERVICE_NAME}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"ports": [
|
|
||||||
{
|
|
||||||
"port": 5432,
|
|
||||||
"targetPort": 5432
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"selector": {
|
|
||||||
"name": "${POSTGRESQL_MASTER_SERVICE_NAME}"
|
|
||||||
},
|
|
||||||
"clusterIP": "None"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"kind": "Service",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "${POSTGRESQL_SLAVE_SERVICE_NAME}",
|
|
||||||
"labels": {
|
|
||||||
"name": "${POSTGRESQL_SLAVE_SERVICE_NAME}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"ports": [
|
|
||||||
{
|
|
||||||
"port": 5432,
|
|
||||||
"targetPort": 5432
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"selector": {
|
|
||||||
"name": "${POSTGRESQL_SLAVE_SERVICE_NAME}"
|
|
||||||
},
|
|
||||||
"clusterIP": "None"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"kind": "DeploymentConfig",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "${POSTGRESQL_MASTER_SERVICE_NAME}"
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"strategy": {
|
|
||||||
"type": "Recreate"
|
|
||||||
},
|
|
||||||
"triggers": [
|
|
||||||
{
|
|
||||||
"type": "ImageChange",
|
|
||||||
"imageChangeParams": {
|
|
||||||
"automatic": true,
|
|
||||||
"containerNames": [
|
|
||||||
"postgresql-master"
|
|
||||||
],
|
|
||||||
"from": {
|
|
||||||
"kind": "ImageStreamTag",
|
|
||||||
"name": "${IMAGESTREAMTAG}",
|
|
||||||
"namespace": "${NAMESPACE}"
|
|
||||||
},
|
|
||||||
"lastTriggeredImage": ""
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "ConfigChange"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"replicas": 1,
|
|
||||||
"selector": {
|
|
||||||
"name": "${POSTGRESQL_MASTER_SERVICE_NAME}"
|
|
||||||
},
|
|
||||||
"template": {
|
|
||||||
"metadata": {
|
|
||||||
"labels": {
|
|
||||||
"name": "${POSTGRESQL_MASTER_SERVICE_NAME}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"volumes": [
|
|
||||||
{
|
|
||||||
"name": "postgresql-data",
|
|
||||||
"persistentVolumeClaim": {
|
|
||||||
"claimName": "postgresql-data-claim"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"containers": [
|
|
||||||
{
|
|
||||||
"name": "postgresql-master",
|
|
||||||
"image": " ",
|
|
||||||
"args": [
|
|
||||||
"run-postgresql-master"
|
|
||||||
],
|
|
||||||
"ports": [
|
|
||||||
{
|
|
||||||
"containerPort": 5432
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"readinessProbe": {
|
|
||||||
"timeoutSeconds": 1,
|
|
||||||
"initialDelaySeconds": 5,
|
|
||||||
"exec": {
|
|
||||||
"command": [ "/usr/libexec/check-container" ]
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"livenessProbe": {
|
|
||||||
"timeoutSeconds": 10,
|
|
||||||
"initialDelaySeconds": 120,
|
|
||||||
"exec": {
|
|
||||||
"command": [ "/usr/libexec/check-container", "--live" ]
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"env": [
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_MASTER_USER",
|
|
||||||
"value": "${POSTGRESQL_MASTER_USER}"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_MASTER_PASSWORD",
|
|
||||||
"value": "${POSTGRESQL_MASTER_PASSWORD}"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_USER",
|
|
||||||
"value": "${POSTGRESQL_USER}"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_PASSWORD",
|
|
||||||
"value": "${POSTGRESQL_PASSWORD}"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_DATABASE",
|
|
||||||
"value": "${POSTGRESQL_DATABASE}"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_ADMIN_PASSWORD",
|
|
||||||
"value": "${POSTGRESQL_ADMIN_PASSWORD}"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"volumeMounts": [
|
|
||||||
{
|
|
||||||
"name": "postgresql-data",
|
|
||||||
"mountPath": "/var/lib/pgsql/data"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"kind": "DeploymentConfig",
|
|
||||||
"apiVersion": "v1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "${POSTGRESQL_SLAVE_SERVICE_NAME}"
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"strategy": {
|
|
||||||
"type": "Recreate"
|
|
||||||
},
|
|
||||||
"triggers": [
|
|
||||||
{
|
|
||||||
"type": "ImageChange",
|
|
||||||
"imageChangeParams": {
|
|
||||||
"automatic": true,
|
|
||||||
"containerNames": [
|
|
||||||
"postgresql-slave"
|
|
||||||
],
|
|
||||||
"from": {
|
|
||||||
"kind": "ImageStreamTag",
|
|
||||||
"name": "${IMAGESTREAMTAG}",
|
|
||||||
"namespace": "${NAMESPACE}"
|
|
||||||
},
|
|
||||||
"lastTriggeredImage": ""
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"type": "ConfigChange"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"replicas": 1,
|
|
||||||
"selector": {
|
|
||||||
"name": "${POSTGRESQL_SLAVE_SERVICE_NAME}"
|
|
||||||
},
|
|
||||||
"template": {
|
|
||||||
"metadata": {
|
|
||||||
"labels": {
|
|
||||||
"name": "${POSTGRESQL_SLAVE_SERVICE_NAME}"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"volumes": [
|
|
||||||
{
|
|
||||||
"name": "postgresql-data",
|
|
||||||
"emptyDir": {}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"containers": [
|
|
||||||
{
|
|
||||||
"name": "postgresql-slave",
|
|
||||||
"image": " ",
|
|
||||||
"args": [
|
|
||||||
"run-postgresql-slave"
|
|
||||||
],
|
|
||||||
"ports": [
|
|
||||||
{
|
|
||||||
"containerPort": 5432
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"readinessProbe": {
|
|
||||||
"timeoutSeconds": 1,
|
|
||||||
"initialDelaySeconds": 5,
|
|
||||||
"exec": {
|
|
||||||
"command": [ "/usr/libexec/check-container" ]
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"livenessProbe": {
|
|
||||||
"timeoutSeconds": 10,
|
|
||||||
"initialDelaySeconds": 120,
|
|
||||||
"exec": {
|
|
||||||
"command": [ "/usr/libexec/check-container", "--live" ]
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"env": [
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_MASTER_SERVICE_NAME",
|
|
||||||
"value": "${POSTGRESQL_MASTER_SERVICE_NAME}"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_MASTER_USER",
|
|
||||||
"value": "${POSTGRESQL_MASTER_USER}"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_MASTER_PASSWORD",
|
|
||||||
"value": "${POSTGRESQL_MASTER_PASSWORD}"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_USER",
|
|
||||||
"value": "${POSTGRESQL_USER}"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_PASSWORD",
|
|
||||||
"value": "${POSTGRESQL_PASSWORD}"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "POSTGRESQL_DATABASE",
|
|
||||||
"value": "${POSTGRESQL_DATABASE}"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"volumeMounts": [
|
|
||||||
{
|
|
||||||
"name": "postgresql-data",
|
|
||||||
"mountPath": "/var/lib/pgsql/data"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
|
|
@ -1,36 +0,0 @@
|
||||||
#! /usr/bin/bash -x
|
|
||||||
|
|
||||||
# fail early
|
|
||||||
set -e
|
|
||||||
|
|
||||||
# source the convenience tooling
|
|
||||||
source "${CONTAINER_SCRIPTS_PATH}/common.sh"
|
|
||||||
|
|
||||||
# set $PGDATA variable
|
|
||||||
set_pgdata
|
|
||||||
|
|
||||||
# assert uninitialized data
|
|
||||||
test ! -f "$PGDATA/postgresql.conf"
|
|
||||||
|
|
||||||
# empty config file is needed after 'initialize_database' call
|
|
||||||
touch "$POSTGRESQL_CONFIG_FILE"
|
|
||||||
|
|
||||||
initialize_database
|
|
||||||
|
|
||||||
# start local PostgreSQL server (wait with '-w')
|
|
||||||
pg_ctl -w start -o "-h ''"
|
|
||||||
|
|
||||||
# load all sql files
|
|
||||||
shopt -s nullglob
|
|
||||||
for file in /tmp/src/init/*.sql; do
|
|
||||||
psql -f "$file"
|
|
||||||
done
|
|
||||||
|
|
||||||
pg_ctl stop
|
|
||||||
|
|
||||||
# dump the data into $PWD (in-image storage)
|
|
||||||
tar caf data.tar.xz -C "$PGDATA" .
|
|
||||||
rm -rf "$PGDATA"
|
|
||||||
|
|
||||||
# install pre-start hook
|
|
||||||
cp -r /tmp/src/postgresql-pre-start .
|
|
||||||
|
|
@ -1,2 +0,0 @@
|
||||||
CREATE TABLE test (sth TEXT);
|
|
||||||
INSERT INTO test VALUES ('hello world');
|
|
||||||
|
|
@ -1,3 +0,0 @@
|
||||||
if test ! -f "$PGDATA/postgresql.conf"; then
|
|
||||||
tar xf "$APP_DATA"/src/data.tar.xz -C "$PGDATA"
|
|
||||||
fi
|
|
||||||
1
help.md
1
help.md
|
|
@ -1 +0,0 @@
|
||||||
README.md
|
|
||||||
404
root/help.1
404
root/help.1
|
|
@ -1,404 +0,0 @@
|
||||||
.nh
|
|
||||||
.TH PostgreSQL 12 SQL Database Server container image
|
|
||||||
.PP
|
|
||||||
This container image includes PostgreSQL 12 SQL database server for OpenShift and general usage.
|
|
||||||
Users can choose between RHEL, CentOS and Fedora based images.
|
|
||||||
The RHEL images are available in the Red Hat Container Catalog
|
|
||||||
\[la]https://access.redhat.com/containers/\[ra],
|
|
||||||
the CentOS images are available on Docker Hub
|
|
||||||
\[la]https://hub.docker.com/r/centos/\[ra],
|
|
||||||
and the Fedora images are available in Fedora Registry
|
|
||||||
\[la]https://registry.fedoraproject.org/\[ra]\&.
|
|
||||||
The resulting image can be run using podman
|
|
||||||
\[la]https://github.com/containers/libpod\[ra]\&.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
Note: while the examples in this README are calling \fB\fCpodman\fR, you can replace any such calls by \fB\fCdocker\fR with the same arguments
|
|
||||||
|
|
||||||
.SH Description
|
|
||||||
.PP
|
|
||||||
This container image provides a containerized packaging of the PostgreSQL postgres daemon
|
|
||||||
and client application. The postgres server daemon accepts connections from clients
|
|
||||||
and provides access to content from PostgreSQL databases on behalf of the clients.
|
|
||||||
You can find more information on the PostgreSQL project from the project Web site
|
|
||||||
(https://www.postgresql.org/).
|
|
||||||
|
|
||||||
.SH Usage
|
|
||||||
.PP
|
|
||||||
For this, we will assume that you are using the \fB\fCrhscl/postgresql\-12\-rhel7\fR image, available via \fB\fCpostgresql:12\fR imagestream tag in Openshift.
|
|
||||||
If you want to set only the mandatory environment variables and not store the database
|
|
||||||
in a host directory, execute the following command:
|
|
||||||
|
|
||||||
.PP
|
|
||||||
.RS
|
|
||||||
|
|
||||||
.nf
|
|
||||||
$ podman run \-d \-\-name postgresql\_database \-e POSTGRESQL\_USER=user \-e POSTGRESQL\_PASSWORD=pass \-e POSTGRESQL\_DATABASE=db \-p 5432:5432 rhscl/postgresql\-12\-rhel7
|
|
||||||
|
|
||||||
.fi
|
|
||||||
.RE
|
|
||||||
|
|
||||||
.PP
|
|
||||||
This will create a container named \fB\fCpostgresql\_database\fR running PostgreSQL with
|
|
||||||
database \fB\fCdb\fR and user with credentials \fB\fCuser:pass\fR\&.
|
|
||||||
> Note: user \fB\fCpostgres\fR is reserved for internal usage
|
|
||||||
|
|
||||||
.PP
|
|
||||||
Port 5432 will be exposed
|
|
||||||
and mapped to the host. If you want your database to be persistent across container
|
|
||||||
executions, also add a \fB\fC\-v /host/db/path:/var/lib/pgsql/data\fR argument (see
|
|
||||||
below). This will be the PostgreSQL database cluster directory.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
The same can be achieved in an Openshift instance using templates provided by Openshift or available in examples
|
|
||||||
\[la]https://github.com/sclorg/postgresql-container/tree/master/examples\[ra]:
|
|
||||||
|
|
||||||
.PP
|
|
||||||
.RS
|
|
||||||
|
|
||||||
.nf
|
|
||||||
$ oc process \-f examples/postgresql\-ephemeral\-template.json \-p POSTGRESQL\_VERSION=12 \-p POSTGRESQL\_USER=user \-p POSTGRESQL\_PASSWORD=pass \-p POSTGRESQL\_DATABASE=db | oc create \-f \-
|
|
||||||
|
|
||||||
.fi
|
|
||||||
.RE
|
|
||||||
|
|
||||||
.PP
|
|
||||||
If the database cluster directory is not initialized, the entrypoint script will
|
|
||||||
first run \fB\fCinitdb\fR
|
|
||||||
\[la]http://www.postgresql.org/docs/12/static/app-initdb.html\[ra]
|
|
||||||
and setup necessary database users and passwords. After the database is initialized,
|
|
||||||
or if it was already present, \fB\fCpostgres\fR
|
|
||||||
\[la]http://www.postgresql.org/docs/12/static/app-postgres.html\[ra]
|
|
||||||
is executed and will run as PID 1. You can stop the detached container by running
|
|
||||||
\fB\fCpodman stop postgresql\_database\fR\&.
|
|
||||||
|
|
||||||
.SH Environment variables and volumes
|
|
||||||
.PP
|
|
||||||
The image recognizes the following environment variables that you can set during
|
|
||||||
initialization by passing \fB\fC\-e VAR=VALUE\fR to the Docker run command.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fCPOSTGRESQL\_USER\fR\fP
|
|
||||||
.br
|
|
||||||
User name for PostgreSQL account to be created
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fCPOSTGRESQL\_PASSWORD\fR\fP
|
|
||||||
.br
|
|
||||||
Password for the user account
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fCPOSTGRESQL\_DATABASE\fR\fP
|
|
||||||
.br
|
|
||||||
Database name
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fCPOSTGRESQL\_ADMIN\_PASSWORD\fR\fP
|
|
||||||
.br
|
|
||||||
Password for the \fB\fCpostgres\fR admin account (optional)
|
|
||||||
|
|
||||||
.PP
|
|
||||||
Alternatively, the following options are related to migration scenario:
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fCPOSTGRESQL\_MIGRATION\_REMOTE\_HOST\fR\fP
|
|
||||||
.br
|
|
||||||
Hostname/IP to migrate from
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fCPOSTGRESQL\_MIGRATION\_ADMIN\_PASSWORD\fR\fP
|
|
||||||
.br
|
|
||||||
Password for the remote 'postgres' admin user
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fCPOSTGRESQL\_MIGRATION\_IGNORE\_ERRORS (optional, default 'no')\fR\fP
|
|
||||||
.br
|
|
||||||
Set to 'yes' to ignore sql import errors
|
|
||||||
|
|
||||||
.PP
|
|
||||||
The following environment variables influence the PostgreSQL configuration file. They are all optional.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fCPOSTGRESQL\_MAX\_CONNECTIONS (default: 100)\fR\fP
|
|
||||||
.br
|
|
||||||
The maximum number of client connections allowed
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fCPOSTGRESQL\_MAX\_PREPARED\_TRANSACTIONS (default: 0)\fR\fP
|
|
||||||
.br
|
|
||||||
Sets the maximum number of transactions that can be in the "prepared" state. If you are using prepared transactions, you will probably want this to be at least as large as max\_connections
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fCPOSTGRESQL\_SHARED\_BUFFERS (default: 32M)\fR\fP
|
|
||||||
.br
|
|
||||||
Sets how much memory is dedicated to PostgreSQL to use for caching data
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fCPOSTGRESQL\_EFFECTIVE\_CACHE\_SIZE (default: 128M)\fR\fP
|
|
||||||
.br
|
|
||||||
Set to an estimate of how much memory is available for disk caching by the operating system and within the database itself
|
|
||||||
|
|
||||||
.PP
|
|
||||||
You can also set the following mount points by passing the \fB\fC\-v /host/dir:/container/dir:Z\fR flag to Docker.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fC/var/lib/pgsql/data\fR\fP
|
|
||||||
.br
|
|
||||||
PostgreSQL database cluster directory
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fBNotice: When mouting a directory from the host into the container, ensure that the mounted
|
|
||||||
directory has the appropriate permissions and that the owner and group of the directory
|
|
||||||
matches the user UID or name which is running inside the container.\fP
|
|
||||||
|
|
||||||
.PP
|
|
||||||
Typically (unless you use \fB\fCpodman run \-u\fR option) processes in container
|
|
||||||
run under UID 26, so \-\- on GNU/Linux \-\- you can fix the datadir permissions
|
|
||||||
for example by:
|
|
||||||
|
|
||||||
.PP
|
|
||||||
.RS
|
|
||||||
|
|
||||||
.nf
|
|
||||||
$ setfacl \-m u:26:\-wx /your/data/dir
|
|
||||||
$ podman run <...> \-v /your/data/dir:/var/lib/pgsql/data:Z <...>
|
|
||||||
|
|
||||||
.fi
|
|
||||||
.RE
|
|
||||||
|
|
||||||
.SH Data migration
|
|
||||||
.PP
|
|
||||||
PostgreSQL container supports migration of data from remote PostgreSQL server.
|
|
||||||
You can run it like:
|
|
||||||
|
|
||||||
.PP
|
|
||||||
.RS
|
|
||||||
|
|
||||||
.nf
|
|
||||||
$ podman run \-d \-\-name postgresql\_database \\
|
|
||||||
\-e POSTGRESQL\_MIGRATION\_REMOTE\_HOST=172.17.0.2 \\
|
|
||||||
\-e POSTGRESQL\_MIGRATION\_ADMIN\_PASSWORD=remoteAdminP@ssword \\
|
|
||||||
[ OPTIONAL\_CONFIGURATION\_VARIABLES ]
|
|
||||||
openshift/postgresql\-92\-centos7
|
|
||||||
|
|
||||||
.fi
|
|
||||||
.RE
|
|
||||||
|
|
||||||
.PP
|
|
||||||
The migration is done the \fBdump and restore\fP way (running \fB\fCpg\_dumpall\fR against
|
|
||||||
remote cluster and importing the dump locally by \fB\fCpsql\fR). Because the process
|
|
||||||
is streamed (unix pipeline), there are no intermediate dump files created during
|
|
||||||
this process to not waste additional storage space.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
If some SQL commands fail during applying, the default behavior
|
|
||||||
of the migration script is to fail as well to ensure the \fBall\fP or \fBnothing\fP
|
|
||||||
result of scripted, unattended migration. In most common cases, successful
|
|
||||||
migration is expected (but not guaranteed!), given you migrate from
|
|
||||||
a previous version of PostgreSQL server container, that is created using
|
|
||||||
the same principles as this one (e.g. migration from
|
|
||||||
\fB\fCopenshift/postgresql\-92\-centos7\fR to \fB\fCcentos/postgresql\-95\-centos7\fR).
|
|
||||||
Migration from a different kind of PostgreSQL container can likely fail.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
If this \fBall\fP or \fBnothing\fP principle is inadequate for you, and you know
|
|
||||||
what you are doing, there's optional \fB\fCPOSTGRESQL\_MIGRATION\_IGNORE\_ERRORS\fR option
|
|
||||||
which does \fBbest effort\fP migration (some data might be lost, it is up to user
|
|
||||||
to review the standard error output and fix the issues manually in
|
|
||||||
post\-migration time).
|
|
||||||
|
|
||||||
.PP
|
|
||||||
Please keep in mind that the container image provides help for users'
|
|
||||||
convenience, but fully automatic migration is not guaranteed. Thus, before you
|
|
||||||
start proceeding with the database migration, get prepared to perform manual
|
|
||||||
steps in order to get all your data migrated.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
Note that you might not use variables like \fB\fCPOSTGRESQL\_USER\fR in migration
|
|
||||||
scenario, all the data (including info about databases, roles or passwords are
|
|
||||||
copied from old cluster). Ensure that you use the same
|
|
||||||
\fB\fCOPTIONAL\_CONFIGURATION\_VARIABLES\fR as you used for initialization of the old
|
|
||||||
PostgreSQL container. If some non\-default configuration is done on remote
|
|
||||||
cluster, you might need to copy the configuration files manually, too.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
Security warning: Note that the IP communication between old and new PostgreSQL
|
|
||||||
clusters is not encrypted by default, it is up to user to configure SSL on
|
|
||||||
remote cluster or ensure security via different means.
|
|
||||||
|
|
||||||
.SH PostgreSQL auto\-tuning
|
|
||||||
.PP
|
|
||||||
When the PostgreSQL image is run with the \fB\fC\-\-memory\fR parameter set and if there
|
|
||||||
are no values provided for \fB\fCPOSTGRESQL\_SHARED\_BUFFERS\fR and
|
|
||||||
\fB\fCPOSTGRESQL\_EFFECTIVE\_CACHE\_SIZE\fR those values are automatically calculated
|
|
||||||
based on the value provided in the \fB\fC\-\-memory\fR parameter.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
The values are calculated based on the
|
|
||||||
upstream
|
|
||||||
\[la]https://wiki.postgresql.org/wiki/Tuning_Your_PostgreSQL_Server\[ra]
|
|
||||||
formulas. For the \fB\fCshared\_buffers\fR we use 1/4 of given memory and for the
|
|
||||||
\fB\fCeffective\_cache\_size\fR we set the value to 1/2 of the given memory.
|
|
||||||
|
|
||||||
.SH PostgreSQL admin account
|
|
||||||
.PP
|
|
||||||
The admin account \fB\fCpostgres\fR has no password set by default, only allowing local
|
|
||||||
connections. You can set it by setting the \fB\fCPOSTGRESQL\_ADMIN\_PASSWORD\fR environment
|
|
||||||
variable when initializing your container. This will allow you to login to the
|
|
||||||
\fB\fCpostgres\fR account remotely. Local connections will still not require a password.
|
|
||||||
|
|
||||||
.SH Changing passwords
|
|
||||||
.PP
|
|
||||||
Since passwords are part of the image configuration, the only supported method
|
|
||||||
to change passwords for the database user (\fB\fCPOSTGRESQL\_USER\fR) and \fB\fCpostgres\fR
|
|
||||||
admin user is by changing the environment variables \fB\fCPOSTGRESQL\_PASSWORD\fR and
|
|
||||||
\fB\fCPOSTGRESQL\_ADMIN\_PASSWORD\fR, respectively.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
Changing database passwords through SQL statements or any way other than through
|
|
||||||
the environment variables aforementioned will cause a mismatch between the
|
|
||||||
values stored in the variables and the actual passwords. Whenever a database
|
|
||||||
container starts it will reset the passwords to the values stored in the
|
|
||||||
environment variables.
|
|
||||||
|
|
||||||
.SH Upgrading database (by switching to newer PostgreSQL image version)
|
|
||||||
.PP
|
|
||||||
** Warning! Please, before you decide to do the data directory upgrade, always
|
|
||||||
ensure that you've carefully backed up all your data and that you are OK with
|
|
||||||
potential manual rollback! **
|
|
||||||
|
|
||||||
.PP
|
|
||||||
This image supports automatic upgrade of data directory created by
|
|
||||||
the PostgreSQL server version 10 (and \fIonly\fP this version) \- provided by sclorg
|
|
||||||
image. The upgrade process is designed so that you should be able to just
|
|
||||||
switch from \fIimage A\fP to \fIimage B\fP, and set the \fB\fC$POSTGRESQL\_UPGRADE\fR variable
|
|
||||||
appropriately to explicitly request the database data transformation.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
The upgrade process is internally implemented via \fB\fCpg\_upgrade\fR binary, and for
|
|
||||||
that purpose the container needs to contain two versions of PostgreSQL server
|
|
||||||
(have a look at \fB\fCman pg\_upgrade\fR for more info).
|
|
||||||
|
|
||||||
.PP
|
|
||||||
For the \fB\fCpg\_upgrade\fR process \- and the new server version, we need to initialize
|
|
||||||
a brand new data directory. That's data directory is created automatically by
|
|
||||||
container tooling under /var/lib/pgsql/data, which is usually external
|
|
||||||
bind\-mountpoint. The \fB\fCpg\_upgrade\fR execution is then similar to dump\&restore
|
|
||||||
approach \-\- it starts both old and new PostgreSQL servers (within container) and
|
|
||||||
"dumps" the old datadir while and at the same time it "restores" it into new
|
|
||||||
datadir. This operation requires a lot of data files copying, so you can decide
|
|
||||||
what type of upgrade you'll do by setting \fB\fC$POSTGRESQL\_UPGRADE\fR appropriately:
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fCcopy\fR\fP
|
|
||||||
.br
|
|
||||||
The data files are copied from old datadir to new datadir. This option has low risk of data loss in case of some upgrade failure.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
\fB\fB\fChardlink\fR\fP
|
|
||||||
.br
|
|
||||||
Data files are hard\-linked from old to the new data directory, which brings performance optimization \- but the old directory becomes unusable, even in case of failure.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
Note that because we copy data directory, you need to make sure that you have
|
|
||||||
enough space for the copy; upgrade failure because of not enough space might
|
|
||||||
lead to data loss.
|
|
||||||
|
|
||||||
.SH Extending image
|
|
||||||
.PP
|
|
||||||
This image can be extended in Openshift using the \fB\fCSource\fR build strategy or via the standalone
|
|
||||||
source\-to\-image
|
|
||||||
\[la]https://github.com/openshift/source-to-image\[ra] application (where available).
|
|
||||||
For this, we will assume that you are using the \fB\fCrhscl/postgresql\-12\-rhel7\fR image,
|
|
||||||
available via \fB\fCpostgresql:12\fR imagestream tag in Openshift.
|
|
||||||
|
|
||||||
.PP
|
|
||||||
For example to build customized image \fB\fCnew\-postgresql\fR
|
|
||||||
with configuration from \fB\fChttps://github.com/sclorg/postgresql\-container/tree/master/examples/extending\-image\fR run:
|
|
||||||
|
|
||||||
.PP
|
|
||||||
.RS
|
|
||||||
|
|
||||||
.nf
|
|
||||||
$ oc new\-app postgresql:12\~https://github.com/sclorg/postgresql\-container.git \\
|
|
||||||
\-\-name new\-postgresql \\
|
|
||||||
\-\-context\-dir examples/extending\-image/ \\
|
|
||||||
\-e POSTGRESQL\_USER=user \\
|
|
||||||
\-e POSTGRESQL\_DATABASE=db \\
|
|
||||||
\-e POSTGRESQL\_PASSWORD=password
|
|
||||||
|
|
||||||
.fi
|
|
||||||
.RE
|
|
||||||
|
|
||||||
.PP
|
|
||||||
or via \fB\fCs2i\fR:
|
|
||||||
|
|
||||||
.PP
|
|
||||||
.RS
|
|
||||||
|
|
||||||
.nf
|
|
||||||
$ s2i build \-\-context\-dir examples/extending\-image/ https://github.com/sclorg/postgresql\-container.git rhscl/postgresql\-12\-rhel7 new\-postgresql
|
|
||||||
|
|
||||||
.fi
|
|
||||||
.RE
|
|
||||||
|
|
||||||
.PP
|
|
||||||
The directory passed to Openshift should contain one or more of the
|
|
||||||
following directories:
|
|
||||||
|
|
||||||
.SS \fB\fCpostgresql\-pre\-start/\fR
|
|
||||||
.PP
|
|
||||||
Source all \fB\fC*.sh\fR files from this directory during early start of the
|
|
||||||
container. There's no PostgreSQL daemon running on background.
|
|
||||||
|
|
||||||
.SS \fB\fCpostgresql\-cfg/\fR
|
|
||||||
.PP
|
|
||||||
Contained configuration files (\fB\fC*.conf\fR) will be included at the end of image
|
|
||||||
postgresql.conf file.
|
|
||||||
|
|
||||||
.SS \fB\fCpostgresql\-init/\fR
|
|
||||||
.PP
|
|
||||||
Contained shell scripts (\fB\fC*.sh\fR) are sourced when the database is freshly
|
|
||||||
initialized (after successful initdb run which made the data directory
|
|
||||||
non\-empty). At the time of sourcing these scripts, the local PostgreSQL
|
|
||||||
server is running. For re\-deployments scenarios with persistent data
|
|
||||||
directory, the scripts are not sourced (no\-op).
|
|
||||||
|
|
||||||
.SS \fB\fCpostgresql\-start/\fR
|
|
||||||
.PP
|
|
||||||
Same sematics as \fB\fCpostgresql\-init/\fR, except that these scripts are
|
|
||||||
always sourced (after \fB\fCpostgresql\-init/\fR scripts, if they exist).
|
|
||||||
|
|
||||||
.ti 0
|
|
||||||
\l'\n(.lu'
|
|
||||||
|
|
||||||
.PP
|
|
||||||
During the s2i build all provided files are copied into \fB\fC/opt/app\-root/src\fR
|
|
||||||
directory in the new image. Only one
|
|
||||||
file with the same name can be used for customization and user provided files
|
|
||||||
are preferred over default files in \fB\fC/usr/share/container\-scripts/\fR\-
|
|
||||||
so it is possible to overwrite them.
|
|
||||||
|
|
||||||
.SH Troubleshooting
|
|
||||||
.PP
|
|
||||||
At first the postgres daemon writes its logs to the standard output, so these are available in the container log. The log can be examined by running:
|
|
||||||
|
|
||||||
.PP
|
|
||||||
.RS
|
|
||||||
|
|
||||||
.nf
|
|
||||||
podman logs <container>
|
|
||||||
|
|
||||||
.fi
|
|
||||||
.RE
|
|
||||||
|
|
||||||
.PP
|
|
||||||
Then log output is redirected to logging collector process and will appear in directory "pg\_log".
|
|
||||||
|
|
||||||
.SH See also
|
|
||||||
.PP
|
|
||||||
Dockerfile and other sources for this container image are available on
|
|
||||||
https://github.com/sclorg/postgresql\-container.
|
|
||||||
In that repository, the Dockerfile for CentOS is called Dockerfile, the Dockerfile
|
|
||||||
for RHEL7 is called Dockerfile.rhel7, the Dockerfile for RHEL8 is called Dockerfile.rhel8,
|
|
||||||
and the Dockerfile for Fedora is called Dockerfile.fedora.
|
|
||||||
|
|
@ -1,3 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
exec "$@"
|
|
||||||
|
|
@ -1,58 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
export ENABLE_REPLICATION=${ENABLE_REPLICATION:-false}
|
|
||||||
|
|
||||||
set -eu
|
|
||||||
export_vars=$(cgroup-limits) ; export $export_vars
|
|
||||||
|
|
||||||
source "${CONTAINER_SCRIPTS_PATH}/common.sh"
|
|
||||||
|
|
||||||
set_pgdata
|
|
||||||
|
|
||||||
process_extending_files \
|
|
||||||
"${APP_DATA}/src/postgresql-pre-start" \
|
|
||||||
"${CONTAINER_SCRIPTS_PATH}/pre-start"
|
|
||||||
|
|
||||||
check_env_vars
|
|
||||||
generate_passwd_file
|
|
||||||
generate_postgresql_config
|
|
||||||
|
|
||||||
# Is this brand new data volume?
|
|
||||||
PG_INITIALIZED=false
|
|
||||||
|
|
||||||
if [ ! -f "$PGDATA/postgresql.conf" ]; then
|
|
||||||
initialize_database
|
|
||||||
PG_INITIALIZED=:
|
|
||||||
else
|
|
||||||
try_pgupgrade
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Use insanely large timeout (24h) to ensure that the potential recovery has
|
|
||||||
# enough time here to happen (unless liveness probe kills us). Note that in
|
|
||||||
# case of server failure this command still exists immediately.
|
|
||||||
pg_ctl start -w --timeout 86400 -o "-h ''"
|
|
||||||
|
|
||||||
# This is just a pedantic safety measure (the timeout above is unlikely to
|
|
||||||
# happen), but `pt_ctl -w` is not reliable prior to PostgreSQL v10 where it
|
|
||||||
# returns exit_status=0 even if the server is still starting. For more info
|
|
||||||
# see the issue#297 and
|
|
||||||
# https://www.postgresql.org/message-id/CAB7nPqSJs85wK9aknm%3D_jmS6GnH3SQBhpzKcqs8Qo2LhEg2etw%40mail.gmail.com
|
|
||||||
pg_isready
|
|
||||||
|
|
||||||
if $PG_INITIALIZED ; then
|
|
||||||
process_extending_files \
|
|
||||||
"${APP_DATA}/src/postgresql-init" \
|
|
||||||
"${CONTAINER_SCRIPTS_PATH}/init"
|
|
||||||
migrate_db
|
|
||||||
create_users
|
|
||||||
fi
|
|
||||||
|
|
||||||
process_extending_files \
|
|
||||||
"${APP_DATA}/src/postgresql-start" \
|
|
||||||
"${CONTAINER_SCRIPTS_PATH}/start"
|
|
||||||
|
|
||||||
pg_ctl stop
|
|
||||||
|
|
||||||
unset_env_vars
|
|
||||||
echo "Starting server..."
|
|
||||||
exec postgres "$@"
|
|
||||||
|
|
@ -1,5 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
export ENABLE_REPLICATION=true
|
|
||||||
|
|
||||||
exec run-postgresql "$@"
|
|
||||||
|
|
@ -1,39 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
export ENABLE_REPLICATION=true
|
|
||||||
|
|
||||||
set -eu
|
|
||||||
export_vars=$(cgroup-limits) ; export $export_vars
|
|
||||||
|
|
||||||
source "$CONTAINER_SCRIPTS_PATH"/common.sh
|
|
||||||
|
|
||||||
set_pgdata
|
|
||||||
|
|
||||||
function initialize_replica() {
|
|
||||||
echo "Initializing PostgreSQL slave ..."
|
|
||||||
# TODO: Validate and reuse existing data?
|
|
||||||
rm -rf $PGDATA
|
|
||||||
PGPASSWORD="${POSTGRESQL_MASTER_PASSWORD}" pg_basebackup -X fetch --no-password --pgdata ${PGDATA} --host=${MASTER_FQDN} --port=5432 -U "${POSTGRESQL_MASTER_USER}"
|
|
||||||
|
|
||||||
# PostgreSQL recovery configuration.
|
|
||||||
generate_postgresql_recovery_config
|
|
||||||
cat >> "$PGDATA/postgresql.auto.conf" <<EOF
|
|
||||||
|
|
||||||
# Custom OpenShift recovery configuration:
|
|
||||||
include '${POSTGRESQL_RECOVERY_FILE}'
|
|
||||||
EOF
|
|
||||||
# activate standby mode
|
|
||||||
touch "$PGDATA/standby.signal"
|
|
||||||
}
|
|
||||||
|
|
||||||
check_env_vars
|
|
||||||
generate_passwd_file
|
|
||||||
generate_postgresql_config
|
|
||||||
|
|
||||||
wait_for_postgresql_master
|
|
||||||
export MASTER_FQDN=$(postgresql_master_addr)
|
|
||||||
initialize_replica
|
|
||||||
|
|
||||||
unset_env_vars
|
|
||||||
echo "Starting server..."
|
|
||||||
exec postgres "$@"
|
|
||||||
|
|
@ -1,4 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
cat /usr/share/container-scripts/postgresql/README.md
|
|
||||||
|
|
||||||
|
|
@ -1,27 +0,0 @@
|
||||||
#! /bin/sh
|
|
||||||
|
|
||||||
# Try whether the PostgreSQL in container accepts connections.
|
|
||||||
#
|
|
||||||
# With --live, be tolerant to starting PG server. If the /bin/postgres binary
|
|
||||||
# has not been executed yet (the shell script is initializing the container),
|
|
||||||
# wait for it (this script might run forever, we expect that the timeout is
|
|
||||||
# maintained externally).
|
|
||||||
|
|
||||||
test -z "$ENABLED_COLLECTIONS" || . scl_source enable $ENABLED_COLLECTIONS
|
|
||||||
|
|
||||||
if test x"$1" = "x--live"; then
|
|
||||||
# Since livenessProbe is about to detect container deadlocks, and we
|
|
||||||
# so far don't know about real deadlocks to be detected -- we keep
|
|
||||||
# liveness probe to report that container is always ready (as long as
|
|
||||||
# we are able to execute shell, enable collections, etc., which is
|
|
||||||
# good for container sanity testing anyways).
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Readiness check follows, the --timeout is set to "infinite" because it
|
|
||||||
# is handled externally (readinessProbe.timeoutSeconds).
|
|
||||||
pg_isready -q \
|
|
||||||
-h 127.0.0.1 \
|
|
||||||
${POSTGRESQL_USER+-U "$POSTGRESQL_USER"} \
|
|
||||||
${POSTGRESQL_DATABASE+-d "$POSTGRESQL_DATABASE"} \
|
|
||||||
--timeout 0
|
|
||||||
|
|
@ -1,39 +0,0 @@
|
||||||
#!/bin/sh
|
|
||||||
|
|
||||||
documentation="\
|
|
||||||
Recursively fix permissions on the given directories to allow GID=0
|
|
||||||
read/write regular files and read/write/execute directories.
|
|
||||||
|
|
||||||
To run this command, you have to be in the group root=0!"
|
|
||||||
|
|
||||||
uid=26
|
|
||||||
write=w
|
|
||||||
|
|
||||||
usage ()
|
|
||||||
{
|
|
||||||
cat >&2 <<EOF
|
|
||||||
$0: Error: ${1-usage error}
|
|
||||||
|
|
||||||
Usage: $0 [--read-only] DIR [DIR ..]
|
|
||||||
|
|
||||||
$documentation
|
|
||||||
EOF
|
|
||||||
exit 1
|
|
||||||
}
|
|
||||||
|
|
||||||
while test $# -gt 0; do
|
|
||||||
case $1 in
|
|
||||||
--read-only) write= ; shift ;;
|
|
||||||
*) break ;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
|
|
||||||
test $# -eq 0 && usage "no DIR specified"
|
|
||||||
|
|
||||||
for dir; do
|
|
||||||
test -d "$dir" || usage "no such directory '$dir'"
|
|
||||||
echo >&2 "fixing permissions on '$dir' directory"
|
|
||||||
find "$dir" -exec chown "$uid:0" {} \;
|
|
||||||
find "$dir" -exec chmod "g+r$write" {} \;
|
|
||||||
find "$dir" -type d -exec chmod g+x {} +
|
|
||||||
done
|
|
||||||
|
|
@ -1,330 +0,0 @@
|
||||||
PostgreSQL 12 SQL Database Server container image
|
|
||||||
===============================================
|
|
||||||
|
|
||||||
This container image includes PostgreSQL 12 SQL database server for OpenShift and general usage.
|
|
||||||
Users can choose between RHEL, CentOS and Fedora based images.
|
|
||||||
The RHEL images are available in the [Red Hat Container Catalog](https://access.redhat.com/containers/),
|
|
||||||
the CentOS images are available on [Docker Hub](https://hub.docker.com/r/centos/),
|
|
||||||
and the Fedora images are available in [Fedora Registry](https://registry.fedoraproject.org/).
|
|
||||||
The resulting image can be run using [podman](https://github.com/containers/libpod).
|
|
||||||
|
|
||||||
Note: while the examples in this README are calling `podman`, you can replace any such calls by `docker` with the same arguments
|
|
||||||
|
|
||||||
|
|
||||||
Description
|
|
||||||
-----------
|
|
||||||
|
|
||||||
This container image provides a containerized packaging of the PostgreSQL postgres daemon
|
|
||||||
and client application. The postgres server daemon accepts connections from clients
|
|
||||||
and provides access to content from PostgreSQL databases on behalf of the clients.
|
|
||||||
You can find more information on the PostgreSQL project from the project Web site
|
|
||||||
(https://www.postgresql.org/).
|
|
||||||
|
|
||||||
|
|
||||||
Usage
|
|
||||||
-----
|
|
||||||
|
|
||||||
For this, we will assume that you are using the `rhscl/postgresql-12-rhel7` image, available via `postgresql:12` imagestream tag in Openshift.
|
|
||||||
If you want to set only the mandatory environment variables and not store the database
|
|
||||||
in a host directory, execute the following command:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ podman run -d --name postgresql_database -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db -p 5432:5432 rhscl/postgresql-12-rhel7
|
|
||||||
```
|
|
||||||
|
|
||||||
This will create a container named `postgresql_database` running PostgreSQL with
|
|
||||||
database `db` and user with credentials `user:pass`.
|
|
||||||
> Note: user `postgres` is reserved for internal usage
|
|
||||||
|
|
||||||
Port 5432 will be exposed
|
|
||||||
and mapped to the host. If you want your database to be persistent across container
|
|
||||||
executions, also add a `-v /host/db/path:/var/lib/pgsql/data` argument (see
|
|
||||||
below). This will be the PostgreSQL database cluster directory.
|
|
||||||
|
|
||||||
The same can be achieved in an Openshift instance using templates provided by Openshift or available in [examples](https://github.com/sclorg/postgresql-container/tree/master/examples):
|
|
||||||
|
|
||||||
```
|
|
||||||
$ oc process -f examples/postgresql-ephemeral-template.json -p POSTGRESQL_VERSION=12 -p POSTGRESQL_USER=user -p POSTGRESQL_PASSWORD=pass -p POSTGRESQL_DATABASE=db | oc create -f -
|
|
||||||
```
|
|
||||||
|
|
||||||
If the database cluster directory is not initialized, the entrypoint script will
|
|
||||||
first run [`initdb`](http://www.postgresql.org/docs/12/static/app-initdb.html)
|
|
||||||
and setup necessary database users and passwords. After the database is initialized,
|
|
||||||
or if it was already present, [`postgres`](http://www.postgresql.org/docs/12/static/app-postgres.html)
|
|
||||||
is executed and will run as PID 1. You can stop the detached container by running
|
|
||||||
`podman stop postgresql_database`.
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
Environment variables and volumes
|
|
||||||
---------------------------------
|
|
||||||
|
|
||||||
The image recognizes the following environment variables that you can set during
|
|
||||||
initialization by passing `-e VAR=VALUE` to the Docker run command.
|
|
||||||
|
|
||||||
**`POSTGRESQL_USER`**
|
|
||||||
User name for PostgreSQL account to be created
|
|
||||||
|
|
||||||
**`POSTGRESQL_PASSWORD`**
|
|
||||||
Password for the user account
|
|
||||||
|
|
||||||
**`POSTGRESQL_DATABASE`**
|
|
||||||
Database name
|
|
||||||
|
|
||||||
**`POSTGRESQL_ADMIN_PASSWORD`**
|
|
||||||
Password for the `postgres` admin account (optional)
|
|
||||||
|
|
||||||
|
|
||||||
Alternatively, the following options are related to migration scenario:
|
|
||||||
|
|
||||||
**`POSTGRESQL_MIGRATION_REMOTE_HOST`**
|
|
||||||
Hostname/IP to migrate from
|
|
||||||
|
|
||||||
**`POSTGRESQL_MIGRATION_ADMIN_PASSWORD`**
|
|
||||||
Password for the remote 'postgres' admin user
|
|
||||||
|
|
||||||
**`POSTGRESQL_MIGRATION_IGNORE_ERRORS (optional, default 'no')`**
|
|
||||||
Set to 'yes' to ignore sql import errors
|
|
||||||
|
|
||||||
|
|
||||||
The following environment variables influence the PostgreSQL configuration file. They are all optional.
|
|
||||||
|
|
||||||
**`POSTGRESQL_MAX_CONNECTIONS (default: 100)`**
|
|
||||||
The maximum number of client connections allowed
|
|
||||||
|
|
||||||
**`POSTGRESQL_MAX_PREPARED_TRANSACTIONS (default: 0)`**
|
|
||||||
Sets the maximum number of transactions that can be in the "prepared" state. If you are using prepared transactions, you will probably want this to be at least as large as max_connections
|
|
||||||
|
|
||||||
**`POSTGRESQL_SHARED_BUFFERS (default: 32M)`**
|
|
||||||
Sets how much memory is dedicated to PostgreSQL to use for caching data
|
|
||||||
|
|
||||||
**`POSTGRESQL_EFFECTIVE_CACHE_SIZE (default: 128M)`**
|
|
||||||
Set to an estimate of how much memory is available for disk caching by the operating system and within the database itself
|
|
||||||
|
|
||||||
|
|
||||||
You can also set the following mount points by passing the `-v /host/dir:/container/dir:Z` flag to Docker.
|
|
||||||
|
|
||||||
**`/var/lib/pgsql/data`**
|
|
||||||
PostgreSQL database cluster directory
|
|
||||||
|
|
||||||
|
|
||||||
**Notice: When mouting a directory from the host into the container, ensure that the mounted
|
|
||||||
directory has the appropriate permissions and that the owner and group of the directory
|
|
||||||
matches the user UID or name which is running inside the container.**
|
|
||||||
|
|
||||||
Typically (unless you use `podman run -u` option) processes in container
|
|
||||||
run under UID 26, so -- on GNU/Linux -- you can fix the datadir permissions
|
|
||||||
for example by:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ setfacl -m u:26:-wx /your/data/dir
|
|
||||||
$ podman run <...> -v /your/data/dir:/var/lib/pgsql/data:Z <...>
|
|
||||||
```
|
|
||||||
|
|
||||||
|
|
||||||
Data migration
|
|
||||||
----------------------
|
|
||||||
|
|
||||||
PostgreSQL container supports migration of data from remote PostgreSQL server.
|
|
||||||
You can run it like:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ podman run -d --name postgresql_database \
|
|
||||||
-e POSTGRESQL_MIGRATION_REMOTE_HOST=172.17.0.2 \
|
|
||||||
-e POSTGRESQL_MIGRATION_ADMIN_PASSWORD=remoteAdminP@ssword \
|
|
||||||
[ OPTIONAL_CONFIGURATION_VARIABLES ]
|
|
||||||
openshift/postgresql-92-centos7
|
|
||||||
```
|
|
||||||
|
|
||||||
The migration is done the **dump and restore** way (running `pg_dumpall` against
|
|
||||||
remote cluster and importing the dump locally by `psql`). Because the process
|
|
||||||
is streamed (unix pipeline), there are no intermediate dump files created during
|
|
||||||
this process to not waste additional storage space.
|
|
||||||
|
|
||||||
If some SQL commands fail during applying, the default behavior
|
|
||||||
of the migration script is to fail as well to ensure the **all** or **nothing**
|
|
||||||
result of scripted, unattended migration. In most common cases, successful
|
|
||||||
migration is expected (but not guaranteed!), given you migrate from
|
|
||||||
a previous version of PostgreSQL server container, that is created using
|
|
||||||
the same principles as this one (e.g. migration from
|
|
||||||
`openshift/postgresql-92-centos7` to `centos/postgresql-95-centos7`).
|
|
||||||
Migration from a different kind of PostgreSQL container can likely fail.
|
|
||||||
|
|
||||||
If this **all** or **nothing** principle is inadequate for you, and you know
|
|
||||||
what you are doing, there's optional `POSTGRESQL_MIGRATION_IGNORE_ERRORS` option
|
|
||||||
which does **best effort** migration (some data might be lost, it is up to user
|
|
||||||
to review the standard error output and fix the issues manually in
|
|
||||||
post-migration time).
|
|
||||||
|
|
||||||
Please keep in mind that the container image provides help for users'
|
|
||||||
convenience, but fully automatic migration is not guaranteed. Thus, before you
|
|
||||||
start proceeding with the database migration, get prepared to perform manual
|
|
||||||
steps in order to get all your data migrated.
|
|
||||||
|
|
||||||
Note that you might not use variables like `POSTGRESQL_USER` in migration
|
|
||||||
scenario, all the data (including info about databases, roles or passwords are
|
|
||||||
copied from old cluster). Ensure that you use the same
|
|
||||||
`OPTIONAL_CONFIGURATION_VARIABLES` as you used for initialization of the old
|
|
||||||
PostgreSQL container. If some non-default configuration is done on remote
|
|
||||||
cluster, you might need to copy the configuration files manually, too.
|
|
||||||
|
|
||||||
Security warning: Note that the IP communication between old and new PostgreSQL
|
|
||||||
clusters is not encrypted by default, it is up to user to configure SSL on
|
|
||||||
remote cluster or ensure security via different means.
|
|
||||||
|
|
||||||
PostgreSQL auto-tuning
|
|
||||||
--------------------
|
|
||||||
|
|
||||||
When the PostgreSQL image is run with the `--memory` parameter set and if there
|
|
||||||
are no values provided for `POSTGRESQL_SHARED_BUFFERS` and
|
|
||||||
`POSTGRESQL_EFFECTIVE_CACHE_SIZE` those values are automatically calculated
|
|
||||||
based on the value provided in the `--memory` parameter.
|
|
||||||
|
|
||||||
The values are calculated based on the
|
|
||||||
[upstream](https://wiki.postgresql.org/wiki/Tuning_Your_PostgreSQL_Server)
|
|
||||||
formulas. For the `shared_buffers` we use 1/4 of given memory and for the
|
|
||||||
`effective_cache_size` we set the value to 1/2 of the given memory.
|
|
||||||
|
|
||||||
PostgreSQL admin account
|
|
||||||
------------------------
|
|
||||||
The admin account `postgres` has no password set by default, only allowing local
|
|
||||||
connections. You can set it by setting the `POSTGRESQL_ADMIN_PASSWORD` environment
|
|
||||||
variable when initializing your container. This will allow you to login to the
|
|
||||||
`postgres` account remotely. Local connections will still not require a password.
|
|
||||||
|
|
||||||
|
|
||||||
Changing passwords
|
|
||||||
------------------
|
|
||||||
|
|
||||||
Since passwords are part of the image configuration, the only supported method
|
|
||||||
to change passwords for the database user (`POSTGRESQL_USER`) and `postgres`
|
|
||||||
admin user is by changing the environment variables `POSTGRESQL_PASSWORD` and
|
|
||||||
`POSTGRESQL_ADMIN_PASSWORD`, respectively.
|
|
||||||
|
|
||||||
Changing database passwords through SQL statements or any way other than through
|
|
||||||
the environment variables aforementioned will cause a mismatch between the
|
|
||||||
values stored in the variables and the actual passwords. Whenever a database
|
|
||||||
container starts it will reset the passwords to the values stored in the
|
|
||||||
environment variables.
|
|
||||||
|
|
||||||
|
|
||||||
Upgrading database (by switching to newer PostgreSQL image version)
|
|
||||||
-------------------------------------------------------------------
|
|
||||||
|
|
||||||
** Warning! Please, before you decide to do the data directory upgrade, always
|
|
||||||
ensure that you've carefully backed up all your data and that you are OK with
|
|
||||||
potential manual rollback! **
|
|
||||||
|
|
||||||
This image supports automatic upgrade of data directory created by
|
|
||||||
the PostgreSQL server version 10 (and _only_ this version) - provided by sclorg
|
|
||||||
image. The upgrade process is designed so that you should be able to just
|
|
||||||
switch from *image A* to *image B*, and set the `$POSTGRESQL_UPGRADE` variable
|
|
||||||
appropriately to explicitly request the database data transformation.
|
|
||||||
|
|
||||||
The upgrade process is internally implemented via `pg_upgrade` binary, and for
|
|
||||||
that purpose the container needs to contain two versions of PostgreSQL server
|
|
||||||
(have a look at `man pg_upgrade` for more info).
|
|
||||||
|
|
||||||
For the `pg_upgrade` process - and the new server version, we need to initialize
|
|
||||||
a brand new data directory. That's data directory is created automatically by
|
|
||||||
container tooling under /var/lib/pgsql/data, which is usually external
|
|
||||||
bind-mountpoint. The `pg_upgrade` execution is then similar to dump&restore
|
|
||||||
approach -- it starts both old and new PostgreSQL servers (within container) and
|
|
||||||
"dumps" the old datadir while and at the same time it "restores" it into new
|
|
||||||
datadir. This operation requires a lot of data files copying, so you can decide
|
|
||||||
what type of upgrade you'll do by setting `$POSTGRESQL_UPGRADE` appropriately:
|
|
||||||
|
|
||||||
**`copy`**
|
|
||||||
The data files are copied from old datadir to new datadir. This option has low risk of data loss in case of some upgrade failure.
|
|
||||||
|
|
||||||
**`hardlink`**
|
|
||||||
Data files are hard-linked from old to the new data directory, which brings performance optimization - but the old directory becomes unusable, even in case of failure.
|
|
||||||
|
|
||||||
|
|
||||||
Note that because we copy data directory, you need to make sure that you have
|
|
||||||
enough space for the copy; upgrade failure because of not enough space might
|
|
||||||
lead to data loss.
|
|
||||||
|
|
||||||
|
|
||||||
Extending image
|
|
||||||
----------------
|
|
||||||
|
|
||||||
This image can be extended in Openshift using the `Source` build strategy or via the standalone
|
|
||||||
[source-to-image](https://github.com/openshift/source-to-image) application (where available).
|
|
||||||
For this, we will assume that you are using the `rhscl/postgresql-12-rhel7` image,
|
|
||||||
available via `postgresql:12` imagestream tag in Openshift.
|
|
||||||
|
|
||||||
For example to build customized image `new-postgresql`
|
|
||||||
with configuration from `https://github.com/sclorg/postgresql-container/tree/master/examples/extending-image` run:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ oc new-app postgresql:12~https://github.com/sclorg/postgresql-container.git \
|
|
||||||
--name new-postgresql \
|
|
||||||
--context-dir examples/extending-image/ \
|
|
||||||
-e POSTGRESQL_USER=user \
|
|
||||||
-e POSTGRESQL_DATABASE=db \
|
|
||||||
-e POSTGRESQL_PASSWORD=password
|
|
||||||
```
|
|
||||||
|
|
||||||
or via `s2i`:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ s2i build --context-dir examples/extending-image/ https://github.com/sclorg/postgresql-container.git rhscl/postgresql-12-rhel7 new-postgresql
|
|
||||||
```
|
|
||||||
|
|
||||||
The directory passed to Openshift should contain one or more of the
|
|
||||||
following directories:
|
|
||||||
|
|
||||||
|
|
||||||
##### `postgresql-pre-start/`
|
|
||||||
|
|
||||||
Source all `*.sh` files from this directory during early start of the
|
|
||||||
container. There's no PostgreSQL daemon running on background.
|
|
||||||
|
|
||||||
|
|
||||||
##### `postgresql-cfg/`
|
|
||||||
|
|
||||||
Contained configuration files (`*.conf`) will be included at the end of image
|
|
||||||
postgresql.conf file.
|
|
||||||
|
|
||||||
|
|
||||||
##### `postgresql-init/`
|
|
||||||
|
|
||||||
Contained shell scripts (`*.sh`) are sourced when the database is freshly
|
|
||||||
initialized (after successful initdb run which made the data directory
|
|
||||||
non-empty). At the time of sourcing these scripts, the local PostgreSQL
|
|
||||||
server is running. For re-deployments scenarios with persistent data
|
|
||||||
directory, the scripts are not sourced (no-op).
|
|
||||||
|
|
||||||
|
|
||||||
##### `postgresql-start/`
|
|
||||||
|
|
||||||
Same sematics as `postgresql-init/`, except that these scripts are
|
|
||||||
always sourced (after `postgresql-init/` scripts, if they exist).
|
|
||||||
|
|
||||||
|
|
||||||
----------------------------------------------
|
|
||||||
|
|
||||||
During the s2i build all provided files are copied into `/opt/app-root/src`
|
|
||||||
directory in the new image. Only one
|
|
||||||
file with the same name can be used for customization and user provided files
|
|
||||||
are preferred over default files in `/usr/share/container-scripts/`-
|
|
||||||
so it is possible to overwrite them.
|
|
||||||
|
|
||||||
|
|
||||||
Troubleshooting
|
|
||||||
---------------
|
|
||||||
At first the postgres daemon writes its logs to the standard output, so these are available in the container log. The log can be examined by running:
|
|
||||||
|
|
||||||
podman logs <container>
|
|
||||||
|
|
||||||
Then log output is redirected to logging collector process and will appear in directory "pg_log".
|
|
||||||
|
|
||||||
|
|
||||||
See also
|
|
||||||
--------
|
|
||||||
Dockerfile and other sources for this container image are available on
|
|
||||||
https://github.com/sclorg/postgresql-container.
|
|
||||||
In that repository, the Dockerfile for CentOS is called Dockerfile, the Dockerfile
|
|
||||||
for RHEL7 is called Dockerfile.rhel7, the Dockerfile for RHEL8 is called Dockerfile.rhel8,
|
|
||||||
and the Dockerfile for Fedora is called Dockerfile.fedora.
|
|
||||||
|
|
@ -1,479 +0,0 @@
|
||||||
# Configuration settings.
|
|
||||||
export POSTGRESQL_MAX_CONNECTIONS=${POSTGRESQL_MAX_CONNECTIONS:-100}
|
|
||||||
export POSTGRESQL_MAX_PREPARED_TRANSACTIONS=${POSTGRESQL_MAX_PREPARED_TRANSACTIONS:-0}
|
|
||||||
|
|
||||||
# Perform auto-tuning based on the container cgroups limits (only when the
|
|
||||||
# limits are set).
|
|
||||||
# Users can still override this by setting the POSTGRESQL_SHARED_BUFFERS
|
|
||||||
# and POSTGRESQL_EFFECTIVE_CACHE_SIZE variables.
|
|
||||||
if [[ "${NO_MEMORY_LIMIT:-}" == "true" || -z "${MEMORY_LIMIT_IN_BYTES:-}" ]]; then
|
|
||||||
export POSTGRESQL_SHARED_BUFFERS=${POSTGRESQL_SHARED_BUFFERS:-32MB}
|
|
||||||
export POSTGRESQL_EFFECTIVE_CACHE_SIZE=${POSTGRESQL_EFFECTIVE_CACHE_SIZE:-128MB}
|
|
||||||
else
|
|
||||||
# Use 1/4 of given memory for shared buffers
|
|
||||||
shared_buffers_computed="$(($MEMORY_LIMIT_IN_BYTES/1024/1024/4))MB"
|
|
||||||
# Setting effective_cache_size to 1/2 of total memory would be a normal conservative setting,
|
|
||||||
effective_cache="$(($MEMORY_LIMIT_IN_BYTES/1024/1024/2))MB"
|
|
||||||
export POSTGRESQL_SHARED_BUFFERS=${POSTGRESQL_SHARED_BUFFERS:-$shared_buffers_computed}
|
|
||||||
export POSTGRESQL_EFFECTIVE_CACHE_SIZE=${POSTGRESQL_EFFECTIVE_CACHE_SIZE:-$effective_cache}
|
|
||||||
fi
|
|
||||||
|
|
||||||
export POSTGRESQL_RECOVERY_FILE=$HOME/openshift-custom-recovery.conf
|
|
||||||
export POSTGRESQL_CONFIG_FILE=$HOME/openshift-custom-postgresql.conf
|
|
||||||
|
|
||||||
postinitdb_actions=
|
|
||||||
|
|
||||||
# match . files when moving userdata below
|
|
||||||
shopt -s dotglob
|
|
||||||
# extglob enables the !(userdata) glob pattern below.
|
|
||||||
shopt -s extglob
|
|
||||||
|
|
||||||
function usage() {
|
|
||||||
if [ $# == 1 ]; then
|
|
||||||
echo >&2 "error: $1"
|
|
||||||
fi
|
|
||||||
|
|
||||||
cat >&2 <<EOF
|
|
||||||
For general container run, you must either specify the following environment
|
|
||||||
variables:
|
|
||||||
POSTGRESQL_USER POSTGRESQL_PASSWORD POSTGRESQL_DATABASE
|
|
||||||
Or the following environment variable:
|
|
||||||
POSTGRESQL_ADMIN_PASSWORD
|
|
||||||
Or both.
|
|
||||||
|
|
||||||
To migrate data from different PostgreSQL container:
|
|
||||||
POSTGRESQL_MIGRATION_REMOTE_HOST (hostname or IP address)
|
|
||||||
POSTGRESQL_MIGRATION_ADMIN_PASSWORD (password of remote 'postgres' user)
|
|
||||||
And optionally:
|
|
||||||
POSTGRESQL_MIGRATION_IGNORE_ERRORS=yes (default is 'no')
|
|
||||||
|
|
||||||
Optional settings:
|
|
||||||
POSTGRESQL_MAX_CONNECTIONS (default: 100)
|
|
||||||
POSTGRESQL_MAX_PREPARED_TRANSACTIONS (default: 0)
|
|
||||||
POSTGRESQL_SHARED_BUFFERS (default: 32MB)
|
|
||||||
|
|
||||||
For more information see /usr/share/container-scripts/postgresql/README.md
|
|
||||||
within the container or visit https://github.com/sclorg/postgresql-container.
|
|
||||||
EOF
|
|
||||||
exit 1
|
|
||||||
}
|
|
||||||
|
|
||||||
function check_env_vars() {
|
|
||||||
if [[ -v POSTGRESQL_USER || -v POSTGRESQL_PASSWORD || -v POSTGRESQL_DATABASE ]]; then
|
|
||||||
# one var means all three must be specified
|
|
||||||
[[ -v POSTGRESQL_USER && -v POSTGRESQL_PASSWORD && -v POSTGRESQL_DATABASE ]] || usage
|
|
||||||
|
|
||||||
[ ${#POSTGRESQL_USER} -le 63 ] || usage "PostgreSQL username too long (maximum 63 characters)"
|
|
||||||
[ ${#POSTGRESQL_DATABASE} -le 63 ] || usage "Database name too long (maximum 63 characters)"
|
|
||||||
postinitdb_actions+=",simple_db"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -v POSTGRESQL_ADMIN_PASSWORD ]; then
|
|
||||||
postinitdb_actions+=",admin_pass"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -v POSTGRESQL_MIGRATION_REMOTE_HOST -a \
|
|
||||||
-v POSTGRESQL_MIGRATION_ADMIN_PASSWORD ]; then
|
|
||||||
postinitdb_actions+=",migration"
|
|
||||||
fi
|
|
||||||
|
|
||||||
case "$postinitdb_actions" in
|
|
||||||
,simple_db,admin_pass) ;;
|
|
||||||
,migration|,simple_db|,admin_pass) ;;
|
|
||||||
*) usage ;;
|
|
||||||
esac
|
|
||||||
}
|
|
||||||
|
|
||||||
# Make sure env variables don't propagate to PostgreSQL process.
|
|
||||||
function unset_env_vars() {
|
|
||||||
unset POSTGRESQL_{DATABASE,USER,PASSWORD,ADMIN_PASSWORD}
|
|
||||||
}
|
|
||||||
|
|
||||||
# postgresql_master_addr lookups the 'postgresql-master' DNS and get list of the available
|
|
||||||
# endpoints. Each endpoint is a PostgreSQL container with the 'master' PostgreSQL running.
|
|
||||||
function postgresql_master_addr() {
|
|
||||||
local service_name=${POSTGRESQL_MASTER_SERVICE_NAME:-postgresql-master}
|
|
||||||
local endpoints=$(dig ${service_name} A +search | grep ";${service_name}" | cut -d ';' -f 2 2>/dev/null)
|
|
||||||
# FIXME: This is for debugging (docker run)
|
|
||||||
if [ -v POSTGRESQL_MASTER_IP ]; then
|
|
||||||
endpoints=${POSTGRESQL_MASTER_IP:-}
|
|
||||||
fi
|
|
||||||
if [ -z "$endpoints" ]; then
|
|
||||||
>&2 echo "Failed to resolve PostgreSQL master IP address"
|
|
||||||
exit 3
|
|
||||||
fi
|
|
||||||
echo -n "$(echo $endpoints | cut -d ' ' -f 1)"
|
|
||||||
}
|
|
||||||
|
|
||||||
# Converts the version in format x.y or x.y.z to a number.
|
|
||||||
version2number ()
|
|
||||||
{
|
|
||||||
local old_IFS=$IFS
|
|
||||||
local to_print= depth=${2-3} width=${3-2} sum=0 one_part
|
|
||||||
IFS='.'
|
|
||||||
set -- $1
|
|
||||||
while test $depth -ge 1; do
|
|
||||||
depth=$(( depth - 1 ))
|
|
||||||
part=${1-0} ; shift || :
|
|
||||||
printf "%0${width}d" "$part"
|
|
||||||
done
|
|
||||||
IFS=$old_IFS
|
|
||||||
}
|
|
||||||
|
|
||||||
# On non-intel arches, data_sync_retry = off does not work
|
|
||||||
# Upstream discussion: https://www.postgresql.org/message-id/CA+mCpegfOUph2U4ZADtQT16dfbkjjYNJL1bSTWErsazaFjQW9A@mail.gmail.com
|
|
||||||
# Upstream changes that caused this issue:
|
|
||||||
# https://github.com/postgres/postgres/commit/483520eca426fb1b428e8416d1d014ac5ad80ef4
|
|
||||||
# https://github.com/postgres/postgres/commit/9ccdd7f66e3324d2b6d3dec282cfa9ff084083f1
|
|
||||||
# RHBZ: https://bugzilla.redhat.com/show_bug.cgi?id=1779150
|
|
||||||
# Special handle of data_sync_retry should handle only in some cases.
|
|
||||||
# These cases are: non-intel architectures, and version higher or equal 12.0, 10.7, 9.6.12
|
|
||||||
# Return value 0 means the hack is needed.
|
|
||||||
function should_hack_data_sync_retry() {
|
|
||||||
[ "$(uname -p)" == 'x86_64' ] && return 1
|
|
||||||
local version_number=$(version2number "$(pg_ctl -V | sed -e 's/^pg_ctl (PostgreSQL) //')")
|
|
||||||
# this matches all 12.x and versions of 10.x where we need the hack
|
|
||||||
[ "$version_number" -ge 100700 ] && return 0
|
|
||||||
# this matches all 10.x that were not matched above
|
|
||||||
[ "$version_number" -ge 100000 ] && return 1
|
|
||||||
# this matches all 9.x where need the hack
|
|
||||||
[ "$version_number" -ge 090612 ] && return 0
|
|
||||||
# all rest should be older 9.x releases
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
|
|
||||||
# New config is generated every time a container is created. It only contains
|
|
||||||
# additional custom settings and is included from $PGDATA/postgresql.conf.
|
|
||||||
function generate_postgresql_config() {
|
|
||||||
envsubst \
|
|
||||||
< "${CONTAINER_SCRIPTS_PATH}/openshift-custom-postgresql.conf.template" \
|
|
||||||
> "${POSTGRESQL_CONFIG_FILE}"
|
|
||||||
|
|
||||||
if [ "${ENABLE_REPLICATION}" == "true" ]; then
|
|
||||||
envsubst \
|
|
||||||
< "${CONTAINER_SCRIPTS_PATH}/openshift-custom-postgresql-replication.conf.template" \
|
|
||||||
>> "${POSTGRESQL_CONFIG_FILE}"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if should_hack_data_sync_retry ; then
|
|
||||||
echo "data_sync_retry = on" >>"${POSTGRESQL_CONFIG_FILE}"
|
|
||||||
fi
|
|
||||||
|
|
||||||
(
|
|
||||||
shopt -s nullglob
|
|
||||||
for conf in "${APP_DATA}"/src/postgresql-cfg/*.conf; do
|
|
||||||
echo include \'${conf}\' >> "${POSTGRESQL_CONFIG_FILE}"
|
|
||||||
done
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
function generate_postgresql_recovery_config() {
|
|
||||||
envsubst \
|
|
||||||
< "${CONTAINER_SCRIPTS_PATH}/openshift-custom-recovery.conf.template" \
|
|
||||||
> "${POSTGRESQL_RECOVERY_FILE}"
|
|
||||||
}
|
|
||||||
|
|
||||||
# Generate passwd file based on current uid
|
|
||||||
function generate_passwd_file() {
|
|
||||||
export USER_ID=$(id -u)
|
|
||||||
export GROUP_ID=$(id -g)
|
|
||||||
grep -v -e ^postgres -e ^$USER_ID /etc/passwd > "$HOME/passwd"
|
|
||||||
echo "postgres:x:${USER_ID}:${GROUP_ID}:PostgreSQL Server:${HOME}:/bin/bash" >> "$HOME/passwd"
|
|
||||||
export LD_PRELOAD=libnss_wrapper.so
|
|
||||||
export NSS_WRAPPER_PASSWD=${HOME}/passwd
|
|
||||||
export NSS_WRAPPER_GROUP=/etc/group
|
|
||||||
}
|
|
||||||
|
|
||||||
initdb_wrapper ()
|
|
||||||
{
|
|
||||||
# Initialize the database cluster with utf8 support enabled by default.
|
|
||||||
# This might affect performance, see:
|
|
||||||
# http://www.postgresql.org/docs/12/static/locale.html
|
|
||||||
LANG=${LANG:-en_US.utf8} "$@"
|
|
||||||
}
|
|
||||||
|
|
||||||
function initialize_database() {
|
|
||||||
initdb_wrapper initdb
|
|
||||||
|
|
||||||
# PostgreSQL configuration.
|
|
||||||
cat >> "$PGDATA/postgresql.conf" <<EOF
|
|
||||||
|
|
||||||
# Custom OpenShift configuration:
|
|
||||||
include '${POSTGRESQL_CONFIG_FILE}'
|
|
||||||
EOF
|
|
||||||
|
|
||||||
# Access control configuration.
|
|
||||||
# FIXME: would be nice-to-have if we could allow connections only from
|
|
||||||
# specific hosts / subnet
|
|
||||||
cat >> "$PGDATA/pg_hba.conf" <<EOF
|
|
||||||
|
|
||||||
#
|
|
||||||
# Custom OpenShift configuration starting at this point.
|
|
||||||
#
|
|
||||||
|
|
||||||
# Allow connections from all hosts.
|
|
||||||
host all all all md5
|
|
||||||
|
|
||||||
# Allow replication connections from all hosts.
|
|
||||||
host replication all all md5
|
|
||||||
EOF
|
|
||||||
}
|
|
||||||
|
|
||||||
function create_users() {
|
|
||||||
if [[ ",$postinitdb_actions," = *,simple_db,* ]]; then
|
|
||||||
createuser "$POSTGRESQL_USER"
|
|
||||||
createdb --owner="$POSTGRESQL_USER" "$POSTGRESQL_DATABASE"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -v POSTGRESQL_MASTER_USER ]; then
|
|
||||||
createuser "$POSTGRESQL_MASTER_USER"
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
migrate_db ()
|
|
||||||
{
|
|
||||||
test "$postinitdb_actions" = ",migration" || return 0
|
|
||||||
|
|
||||||
# Migration path.
|
|
||||||
(
|
|
||||||
if [ ${POSTGRESQL_MIGRATION_IGNORE_ERRORS-no} = no ]; then
|
|
||||||
echo '\set ON_ERROR_STOP on'
|
|
||||||
fi
|
|
||||||
# initdb automatically creates 'postgres' role; creating it again would
|
|
||||||
# fail the whole migration so we drop it here
|
|
||||||
PGPASSWORD="$POSTGRESQL_MIGRATION_ADMIN_PASSWORD" \
|
|
||||||
pg_dumpall -h "$POSTGRESQL_MIGRATION_REMOTE_HOST" \
|
|
||||||
| grep -v '^CREATE ROLE postgres;'
|
|
||||||
) | psql
|
|
||||||
}
|
|
||||||
|
|
||||||
function set_pgdata ()
|
|
||||||
{
|
|
||||||
export PGDATA=$HOME/data/userdata
|
|
||||||
# create a subdirectory that the user owns
|
|
||||||
mkdir -p "$PGDATA"
|
|
||||||
# backwards compatibility case, we used to put the data here,
|
|
||||||
# move it into our new expected location (userdata)
|
|
||||||
if [ -e ${HOME}/data/PG_VERSION ]; then
|
|
||||||
pushd "${HOME}/data"
|
|
||||||
# move everything except the userdata directory itself, into the userdata directory.
|
|
||||||
mv !(userdata) "userdata"
|
|
||||||
popd
|
|
||||||
fi
|
|
||||||
# ensure sane perms for postgresql startup
|
|
||||||
chmod 700 "$PGDATA"
|
|
||||||
}
|
|
||||||
|
|
||||||
function wait_for_postgresql_master() {
|
|
||||||
while true; do
|
|
||||||
master_fqdn=$(postgresql_master_addr)
|
|
||||||
echo "Waiting for PostgreSQL master (${master_fqdn}) to accept connections ..."
|
|
||||||
if [ -v POSTGRESQL_ADMIN_PASSWORD ]; then
|
|
||||||
PGPASSWORD=${POSTGRESQL_ADMIN_PASSWORD} psql "postgresql://postgres@${master_fqdn}" -c "SELECT 1;" && return 0
|
|
||||||
else
|
|
||||||
PGPASSWORD=${POSTGRESQL_PASSWORD} psql "postgresql://${POSTGRESQL_USER}@${master_fqdn}/${POSTGRESQL_DATABASE}" -c "SELECT 1;" && return 0
|
|
||||||
fi
|
|
||||||
sleep 1
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
run_pgupgrade ()
|
|
||||||
(
|
|
||||||
optimized=false
|
|
||||||
old_raw_version=${POSTGRESQL_PREV_VERSION//\./}
|
|
||||||
new_raw_version=${POSTGRESQL_VERSION//\./}
|
|
||||||
|
|
||||||
if test "$old_raw_version" = 92; then
|
|
||||||
old_collection=postgresql92
|
|
||||||
else
|
|
||||||
old_collection=rh-postgresql$old_raw_version
|
|
||||||
fi
|
|
||||||
|
|
||||||
old_pgengine=/opt/rh/$old_collection/root/usr/bin
|
|
||||||
new_pgengine=/opt/rh/rh-postgresql${new_raw_version}/root/usr/bin
|
|
||||||
PGDATA_new="${PGDATA}-new"
|
|
||||||
|
|
||||||
printf >&2 "\n========== \$PGDATA upgrade: %s -> %s ==========\n\n" \
|
|
||||||
"$POSTGRESQL_PREV_VERSION" \
|
|
||||||
"$POSTGRESQL_VERSION"
|
|
||||||
|
|
||||||
info_msg () { printf >&2 "\n===> $*\n\n" ;}
|
|
||||||
|
|
||||||
# pg_upgrade writes logs to cwd, so go to the persistent storage first
|
|
||||||
cd "$HOME"/data
|
|
||||||
|
|
||||||
# disable this because of scl_source, 'set +u' just makes the code ugly
|
|
||||||
# anyways
|
|
||||||
set +u
|
|
||||||
|
|
||||||
# we need to have the old SCL enabled, otherwise the $old_pgengine is not
|
|
||||||
# working. The scl_source script doesn't pay attention to non-zero exit
|
|
||||||
# statuses, so use 'set +e'.
|
|
||||||
set +e
|
|
||||||
source scl_source enable $old_collection
|
|
||||||
set -e
|
|
||||||
|
|
||||||
case $POSTGRESQL_UPGRADE in
|
|
||||||
copy) # we accept this
|
|
||||||
;;
|
|
||||||
hardlink)
|
|
||||||
optimized=:
|
|
||||||
;;
|
|
||||||
*)
|
|
||||||
echo >&2 "Unsupported value: \$POSTGRESQL_UPGRADE=$POSTGRESQL_UPGRADE"
|
|
||||||
false
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
# Ensure $PGDATA_new doesn't exist yet, so we can immediately remove it if
|
|
||||||
# there's some problem.
|
|
||||||
test ! -e "$PGDATA_new"
|
|
||||||
|
|
||||||
# initialize the database
|
|
||||||
info_msg "Initialize new data directory; we will migrate to that."
|
|
||||||
initdb_cmd=( initdb_wrapper "$new_pgengine"/initdb "$PGDATA_new" )
|
|
||||||
eval "\${initdb_cmd[@]} ${POSTGRESQL_UPGRADE_INITDB_OPTIONS-}" || \
|
|
||||||
{ rm -rf "$PGDATA_new" ; false ; }
|
|
||||||
|
|
||||||
upgrade_cmd=(
|
|
||||||
"$new_pgengine"/pg_upgrade
|
|
||||||
"--old-bindir=$old_pgengine"
|
|
||||||
"--new-bindir=$new_pgengine"
|
|
||||||
"--old-datadir=$PGDATA"
|
|
||||||
"--new-datadir=$PGDATA_new"
|
|
||||||
)
|
|
||||||
|
|
||||||
# Dangerous --link option, we loose $DATADIR if something goes wrong.
|
|
||||||
! $optimized || upgrade_cmd+=(--link)
|
|
||||||
|
|
||||||
# User-specififed options for pg_upgrade.
|
|
||||||
eval "upgrade_cmd+=(${POSTGRESQL_UPGRADE_PGUPGRADE_OPTIONS-})"
|
|
||||||
|
|
||||||
# On non-intel arches the data_sync_retry set to on
|
|
||||||
sed -i -e 's/data_sync_retry/#data_sync_retry/' "${POSTGRESQL_CONFIG_FILE}"
|
|
||||||
|
|
||||||
# the upgrade
|
|
||||||
info_msg "Starting the pg_upgrade process."
|
|
||||||
|
|
||||||
# Once we stop support for PostgreSQL 9.4, we don't need
|
|
||||||
# REDHAT_PGUPGRADE_FROM_RHEL hack as we don't upgrade from 9.2 -- that means
|
|
||||||
# that we don't need to fiddle with unix_socket_director{y,ies} option.
|
|
||||||
REDHAT_PGUPGRADE_FROM_RHEL=1 \
|
|
||||||
"${upgrade_cmd[@]}" || { cat $(find "$PGDATA_new"/.. -name pg_upgrade_server.log) ; rm -rf "$PGDATA_new" && false ; }
|
|
||||||
|
|
||||||
# Move the important configuration and remove old data. This is highly
|
|
||||||
# careless, but we can't do more for this over-automatized process.
|
|
||||||
info_msg "Swap the old and new PGDATA and cleanup."
|
|
||||||
mv "$PGDATA"/*.conf "$PGDATA_new"
|
|
||||||
rm -rf "$PGDATA"
|
|
||||||
mv "$PGDATA_new" "$PGDATA"
|
|
||||||
|
|
||||||
# Get back the option we changed above
|
|
||||||
sed -i -e 's/#data_sync_retry/data_sync_retry/' "${POSTGRESQL_CONFIG_FILE}"
|
|
||||||
|
|
||||||
info_msg "Upgrade DONE."
|
|
||||||
)
|
|
||||||
|
|
||||||
|
|
||||||
# Run right after container startup, when the data volume is already initialized
|
|
||||||
# (not initialized by this container run) and thus there exists a chance that
|
|
||||||
# the data was generated by incompatible PostgreSQL major version.
|
|
||||||
try_pgupgrade ()
|
|
||||||
{
|
|
||||||
local versionfile="$PGDATA"/PG_VERSION version upgrade_available
|
|
||||||
|
|
||||||
# This file always exists.
|
|
||||||
test -f "$versionfile"
|
|
||||||
version=$(cat "$versionfile")
|
|
||||||
|
|
||||||
# If we don't support pg_upgrade, skip.
|
|
||||||
test -z "${POSTGRESQL_PREV_VERSION-}" && return 0
|
|
||||||
|
|
||||||
if test "$POSTGRESQL_VERSION" = "$version"; then
|
|
||||||
# No need to call pg_upgrade.
|
|
||||||
|
|
||||||
# Mistakenly requests upgrade? If not, just start the DB.
|
|
||||||
test -z "${POSTGRESQL_UPGRADE-}" && return 0
|
|
||||||
|
|
||||||
# Make _sure_ we have this safety-belt here, otherwise our users would
|
|
||||||
# just specify '-e POSTGRESQL_UPGRADE=hardlink' permanently, even for
|
|
||||||
# re-deployment cases when upgrade is not needed. Setting such
|
|
||||||
# unfortunate default could mean that pg_upgrade might (after some user
|
|
||||||
# mistake) migrate (or even destruct, especially with --link) the old data
|
|
||||||
# directory with limited rollback options, if any.
|
|
||||||
echo >&2
|
|
||||||
echo >&2 "== WARNING!! =="
|
|
||||||
echo >&2 "PostgreSQL server version matches the datadir PG_VERSION."
|
|
||||||
echo >&2 "The \$POSTGRESQL_UPGRADE makes no sense and you probably"
|
|
||||||
echo >&2 "made some mistake, keeping the variable set you might"
|
|
||||||
echo >&2 "risk a data loss in future!"
|
|
||||||
echo >&2 "==============="
|
|
||||||
echo >&2
|
|
||||||
|
|
||||||
# Exit here, but allow _really explicit_ foot-shot.
|
|
||||||
${POSTGRESQL_UPGRADE_FORCE-false}
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
# At this point in code we know that PG_VERSION doesn't match the PostgreSQL
|
|
||||||
# server major version; this might mean that user either (a) mistakenly
|
|
||||||
# deploys from a bad image, or (b) user wants to perform upgrade. For the
|
|
||||||
# upgrade we require explicit request -- just to avoid disasters in (a)-cases.
|
|
||||||
|
|
||||||
if test -z "${POSTGRESQL_UPGRADE-}"; then
|
|
||||||
echo >&2 "Incompatible data directory. This container image provides"
|
|
||||||
echo >&2 "PostgreSQL '$POSTGRESQL_VERSION', but data directory is of"
|
|
||||||
echo >&2 "version '$version'."
|
|
||||||
echo >&2
|
|
||||||
echo >&2 "This image supports automatic data directory upgrade from"
|
|
||||||
echo >&2 "'$POSTGRESQL_PREV_VERSION', please _carefully_ consult image documentation"
|
|
||||||
echo >&2 "about how to use the '\$POSTGRESQL_UPGRADE' startup option."
|
|
||||||
# We could wait for postgresql startup failure (there's no risk of data dir
|
|
||||||
# corruption), but fail rather early.
|
|
||||||
false
|
|
||||||
fi
|
|
||||||
|
|
||||||
# We support pg_upgrade process only from previous version of this container
|
|
||||||
# (upgrade to N to N+1 is possible, so e.g. 9.4 to 9.5).
|
|
||||||
if test "$POSTGRESQL_PREV_VERSION" != "$version"; then
|
|
||||||
echo >&2 "With this container image you can only upgrade from data directory"
|
|
||||||
echo >&2 "of version '$POSTGRESQL_PREV_VERSION', not '$version'."
|
|
||||||
false
|
|
||||||
fi
|
|
||||||
|
|
||||||
run_pgupgrade
|
|
||||||
}
|
|
||||||
|
|
||||||
# get_matched_files PATTERN DIR [DIR ...]
|
|
||||||
# ---------------------------------------
|
|
||||||
# Print all basenames for files matching PATTERN in DIRs.
|
|
||||||
get_matched_files ()
|
|
||||||
{
|
|
||||||
local pattern=$1 dir
|
|
||||||
shift
|
|
||||||
for dir; do
|
|
||||||
test -d "$dir" || continue
|
|
||||||
find -L "$dir" -maxdepth 1 -type f -name "$pattern" -printf "%f\n"
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
# process_extending_files DIR [DIR ...]
|
|
||||||
# -------------------------------------
|
|
||||||
# Source all *.sh files in DIRs in alphabetical order, but if the file exists in
|
|
||||||
# more then one DIR, source only the first occurrence (first found wins).
|
|
||||||
process_extending_files()
|
|
||||||
{
|
|
||||||
local filename dir
|
|
||||||
while read filename ; do
|
|
||||||
for dir in "$@"; do
|
|
||||||
local file="$dir/$filename"
|
|
||||||
if test -f "$file"; then
|
|
||||||
echo "=> sourcing $file ..."
|
|
||||||
source "$file"
|
|
||||||
set -e # ensure that users don't mistakenly change this
|
|
||||||
break
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
done <<<"$(get_matched_files '*.sh' "$@" | sort -u)"
|
|
||||||
}
|
|
||||||
|
|
@ -1,7 +0,0 @@
|
||||||
# required on master for replication
|
|
||||||
wal_level = hot_standby # minimal, archive, hot_standby, or logical
|
|
||||||
max_wal_senders = 6 # max number of walsender processes
|
|
||||||
wal_keep_segments = 400 # in logfile segments, 16MB each; 0 disables
|
|
||||||
|
|
||||||
# required on replicas for replication
|
|
||||||
hot_standby = on
|
|
||||||
|
|
@ -1,21 +0,0 @@
|
||||||
#
|
|
||||||
# Custom OpenShift configuration.
|
|
||||||
#
|
|
||||||
# NOTE: This file is rewritten every time the container is started!
|
|
||||||
# Changes to this file will be overwritten.
|
|
||||||
#
|
|
||||||
|
|
||||||
# Listen on all interfaces.
|
|
||||||
listen_addresses = '*'
|
|
||||||
|
|
||||||
# Determines the maximum number of concurrent connections to the database server. Default: 100
|
|
||||||
max_connections = ${POSTGRESQL_MAX_CONNECTIONS}
|
|
||||||
|
|
||||||
# Allow each connection to use a prepared transaction
|
|
||||||
max_prepared_transactions = ${POSTGRESQL_MAX_PREPARED_TRANSACTIONS}
|
|
||||||
|
|
||||||
# Sets the amount of memory the database server uses for shared memory buffers. Default: 32MB
|
|
||||||
shared_buffers = ${POSTGRESQL_SHARED_BUFFERS}
|
|
||||||
|
|
||||||
# Sets the planner's assumption about the effective size of the disk cache that is available to a single query
|
|
||||||
effective_cache_size = ${POSTGRESQL_EFFECTIVE_CACHE_SIZE}
|
|
||||||
|
|
@ -1,8 +0,0 @@
|
||||||
#
|
|
||||||
# Custom OpenShift configuration.
|
|
||||||
#
|
|
||||||
# NOTE: This file is rewritten every time the container is started!
|
|
||||||
# Changes to this file will be overwritten.
|
|
||||||
#
|
|
||||||
|
|
||||||
primary_conninfo = 'host=${MASTER_FQDN} port=5432 user=${POSTGRESQL_MASTER_USER} password=${POSTGRESQL_MASTER_PASSWORD}'
|
|
||||||
|
|
@ -1,3 +0,0 @@
|
||||||
# This will make scl collection binaries work out of box.
|
|
||||||
unset BASH_ENV PROMPT_COMMAND ENV
|
|
||||||
source scl_source enable $ENABLED_COLLECTIONS
|
|
||||||
|
|
@ -1,23 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
_psql () { psql --set ON_ERROR_STOP=1 "$@" ; }
|
|
||||||
|
|
||||||
if [[ ",$postinitdb_actions," = *,simple_db,* ]]; then
|
|
||||||
_psql --set=username="$POSTGRESQL_USER" \
|
|
||||||
--set=password="$POSTGRESQL_PASSWORD" \
|
|
||||||
<<< "ALTER USER :\"username\" WITH ENCRYPTED PASSWORD :'password';"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -v POSTGRESQL_MASTER_USER ]; then
|
|
||||||
_psql --set=masteruser="$POSTGRESQL_MASTER_USER" \
|
|
||||||
--set=masterpass="$POSTGRESQL_MASTER_PASSWORD" \
|
|
||||||
<<'EOF'
|
|
||||||
ALTER USER :"masteruser" WITH REPLICATION;
|
|
||||||
ALTER USER :"masteruser" WITH ENCRYPTED PASSWORD :'masterpass';
|
|
||||||
EOF
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -v POSTGRESQL_ADMIN_PASSWORD ]; then
|
|
||||||
_psql --set=adminpass="$POSTGRESQL_ADMIN_PASSWORD" \
|
|
||||||
<<<"ALTER USER \"postgres\" WITH ENCRYPTED PASSWORD :'adminpass';"
|
|
||||||
fi
|
|
||||||
|
|
@ -1,14 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
|
|
||||||
set -o errexit
|
|
||||||
set -o nounset
|
|
||||||
set -o pipefail
|
|
||||||
|
|
||||||
shopt -s dotglob
|
|
||||||
echo "---> Installing application source ..."
|
|
||||||
|
|
||||||
|
|
||||||
mv /tmp/src/* ./
|
|
||||||
|
|
||||||
# Fix source directory permissions
|
|
||||||
/usr/libexec/fix-permissions --read-only ./
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
/usr/bin/run-postgresql
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
groff -t -man -ETascii /help.1
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
../common/check_imagestreams.py
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
../examples/
|
|
||||||
|
|
@ -1,42 +0,0 @@
|
||||||
#! /bin/sh
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
die() { echo "$*" >&2 ; exit 1; }
|
|
||||||
|
|
||||||
test -z "$CID" && die "Please specify \$CID variable"
|
|
||||||
# test -d common || die "Please run me from git root directory"
|
|
||||||
|
|
||||||
pagila_mirror=https://dl.fedoraproject.org/pub/epel/7/x86_64/Packages/p/
|
|
||||||
pagila_base="pagila-0.10.1-3.el7.noarch.rpm"
|
|
||||||
pagila=$pagila_mirror$pagila_base
|
|
||||||
pagila_file="$PWD/postgresql-container-pagila.sql"
|
|
||||||
pagila_sha256sum=b968d9498d866bff8f47d9e50edf49feeff108d4164bff2aa167dc3eae802701
|
|
||||||
|
|
||||||
(
|
|
||||||
flock --timeout 180 9
|
|
||||||
|
|
||||||
# Already downloaded?
|
|
||||||
test ! -f "$pagila_file" || exit 0
|
|
||||||
|
|
||||||
set -o pipefail
|
|
||||||
curl -s "$pagila" > "$pagila_base"
|
|
||||||
for file in ./usr/share/pagila/pagila-schema.sql \
|
|
||||||
./usr/share/pagila/pagila-data.sql \
|
|
||||||
./usr/share/pagila/pagila-insert-data.sql ; \
|
|
||||||
do
|
|
||||||
rpm2cpio "$pagila_base" | cpio --extract --to-stdout "$file"
|
|
||||||
done >"$pagila_file"
|
|
||||||
) 9<"$0"
|
|
||||||
|
|
||||||
case $(sha256sum "$pagila_file") in
|
|
||||||
"$pagila_sha256sum"*) ;;
|
|
||||||
*) false ;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
# Deliberately using a separate container, otherwise the docker exec with redirection
|
|
||||||
# does not work in podman 1.6.x due to https://bugzilla.redhat.com/show_bug.cgi?id=1827324
|
|
||||||
# This change can be reverted to the previous variant, once this BZ is fixed.
|
|
||||||
server_ip=$(docker inspect --format='{{.NetworkSettings.IPAddress}}' "$CID")
|
|
||||||
admin_pass=$(docker exec "$CID" bash -c 'echo $POSTGRESQL_ADMIN_PASSWORD')
|
|
||||||
docker run --rm -i "$IMAGE_NAME" bash -c "PGPASSWORD=$admin_pass psql -h $server_ip" <"$pagila_file" &>/dev/null
|
|
||||||
|
|
@ -1,147 +0,0 @@
|
||||||
DEBUG=false
|
|
||||||
|
|
||||||
info () { echo >&2 " * $*" ; }
|
|
||||||
debug () { ! ${DEBUG} || echo >&2 " ~ $*" ; }
|
|
||||||
error () { echo >&2 "ERROR: $*" ; false ; }
|
|
||||||
|
|
||||||
get_image_id ()
|
|
||||||
{
|
|
||||||
local old_IFS=$IFS
|
|
||||||
local result
|
|
||||||
|
|
||||||
# split "$1" into "$1 $2 .." on colons
|
|
||||||
IFS=:
|
|
||||||
set -- $1
|
|
||||||
IFS=$old_IFS
|
|
||||||
case $2 in
|
|
||||||
local)
|
|
||||||
# Default to $IMAGE_NAME if it is set since .image-id might not exist
|
|
||||||
echo "${IMAGE_NAME-$(cat "$1"/.image-id)}"
|
|
||||||
;;
|
|
||||||
remote)
|
|
||||||
local version=${1//\./}
|
|
||||||
case $OS in
|
|
||||||
rhel7)
|
|
||||||
ns=rhscl
|
|
||||||
if test "$version" -eq 92; then
|
|
||||||
ns=openshift3
|
|
||||||
fi
|
|
||||||
image=registry.redhat.io/$ns/postgresql-${version}-rhel7
|
|
||||||
;;
|
|
||||||
centos7)
|
|
||||||
ns=centos
|
|
||||||
if test "$version" -eq 92; then
|
|
||||||
ns=openshift
|
|
||||||
fi
|
|
||||||
local image=docker.io/$ns/postgresql-${1//\./}-centos7
|
|
||||||
;;
|
|
||||||
rhel8)
|
|
||||||
ns=rhel8
|
|
||||||
local image=registry.redhat.io/$ns/postgresql-${version}
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
docker pull "$image" >/dev/null
|
|
||||||
echo "$image"
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
}
|
|
||||||
|
|
||||||
data_pagila_create ()
|
|
||||||
{
|
|
||||||
debug "initializing pagila database"
|
|
||||||
CID="$CID" ./test/pagila.sh
|
|
||||||
}
|
|
||||||
|
|
||||||
data_pagila_check ()
|
|
||||||
{
|
|
||||||
debug "doing pagila check"
|
|
||||||
local exp_output='28
|
|
||||||
16
|
|
||||||
2'
|
|
||||||
# Deliberately moving heredoc into the container, otherwise it does not work
|
|
||||||
# in podman 1.6.x due to https://bugzilla.redhat.com/show_bug.cgi?id=1827324
|
|
||||||
local output=$(docker exec -i "$CID" bash -c "psql -tA <<EOF
|
|
||||||
select count(*) from information_schema.tables where table_schema = 'public';
|
|
||||||
select count(*) from information_schema.triggers;
|
|
||||||
select count(*) from staff;
|
|
||||||
EOF"
|
|
||||||
)
|
|
||||||
test "$exp_output" = "$output" \
|
|
||||||
|| error "Unexpected output: '$output', expected: '$exp_output'"
|
|
||||||
}
|
|
||||||
|
|
||||||
data_empty_create ()
|
|
||||||
{
|
|
||||||
# Deliberately moving heredoc into the container, otherwise it does not work
|
|
||||||
# in podman 1.6.x due to https://bugzilla.redhat.com/show_bug.cgi?id=1827324
|
|
||||||
docker exec -i "$CID" bash -c "psql &>/dev/null <<EOF
|
|
||||||
create table blah (id int);
|
|
||||||
insert into blah values (1), (2), (3);
|
|
||||||
EOF"
|
|
||||||
}
|
|
||||||
|
|
||||||
data_empty_check ()
|
|
||||||
{
|
|
||||||
debug "doing empty check"
|
|
||||||
local exp_output='1
|
|
||||||
2
|
|
||||||
3'
|
|
||||||
# Deliberately moving heredoc into the container, otherwise it does not work
|
|
||||||
# in podman 1.6.x due to https://bugzilla.redhat.com/show_bug.cgi?id=1827324
|
|
||||||
local output=$(docker exec -i "$CID" bash -c "psql -tA <<EOF
|
|
||||||
select * from blah order by id;
|
|
||||||
EOF"
|
|
||||||
)
|
|
||||||
test "$exp_output" = "$output" || error "Unexpected output '$output'"
|
|
||||||
}
|
|
||||||
|
|
||||||
# wait_for_postgres CID
|
|
||||||
wait_for_postgres ()
|
|
||||||
{
|
|
||||||
local cid=$1
|
|
||||||
local stop_after=${2-30}
|
|
||||||
local counter=0
|
|
||||||
|
|
||||||
debug "Waiting for PG server to come up in $cid container"
|
|
||||||
while test $counter -lt "$stop_after"
|
|
||||||
do
|
|
||||||
# the "-h localhost" is crucial here as the container runs postgresql
|
|
||||||
# server twice and we don't want to connect to the first process (see
|
|
||||||
# run-postgresql script)
|
|
||||||
output=$(docker exec -i "$cid" bash -c \
|
|
||||||
"psql -h localhost -tA -c 'select 1;' 2>/dev/null || :")
|
|
||||||
case $output in
|
|
||||||
1*) return ;;
|
|
||||||
"") ;;
|
|
||||||
*) echo "$output" ; false ;;
|
|
||||||
esac
|
|
||||||
sleep 1
|
|
||||||
counter=$(( counter + 1 ))
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# version2number VERSION [DEPTH] [WIDTH]
|
|
||||||
# --------------------------------------
|
|
||||||
version2number ()
|
|
||||||
{
|
|
||||||
local old_IFS=$IFS
|
|
||||||
local to_print= depth=${2-3} width=${3-2} sum=0 one_part
|
|
||||||
IFS='.'
|
|
||||||
set -- $1
|
|
||||||
while test $depth -ge 1; do
|
|
||||||
depth=$(( depth - 1 ))
|
|
||||||
part=${1-0} ; shift || :
|
|
||||||
printf "%0${width}d" "$part"
|
|
||||||
done
|
|
||||||
IFS=$old_IFS
|
|
||||||
}
|
|
||||||
|
|
||||||
# container_ip CONTAINER_ID
|
|
||||||
# -------------------------
|
|
||||||
container_ip()
|
|
||||||
{
|
|
||||||
docker inspect --format='{{.NetworkSettings.IPAddress}}' "$1"
|
|
||||||
}
|
|
||||||
|
|
||||||
# vi: set ft=sh
|
|
||||||
1
test/run
1
test/run
|
|
@ -1 +0,0 @@
|
||||||
run_test
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
run-openshift-local-cluster
|
|
||||||
|
|
@ -1,456 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
#
|
|
||||||
# Test the Postgresql image in OpenShift.
|
|
||||||
#
|
|
||||||
# IMAGE_NAME specifies a name of the candidate image used for testing.
|
|
||||||
# The image has to be available before this script is executed.
|
|
||||||
#
|
|
||||||
|
|
||||||
THISDIR=$(dirname ${BASH_SOURCE[0]})
|
|
||||||
TEMPLATES="$THISDIR/examples"
|
|
||||||
REMOTE_TEMPLATES="https://raw.githubusercontent.com/openshift/origin/master/examples/db-templates"
|
|
||||||
|
|
||||||
source "$THISDIR"/pg-test-lib.sh
|
|
||||||
source "$THISDIR"/test-lib-openshift.sh
|
|
||||||
source "$THISDIR"/test-lib-postgresql.sh
|
|
||||||
|
|
||||||
set -exo nounset
|
|
||||||
|
|
||||||
trap ct_os_cleanup EXIT SIGINT
|
|
||||||
|
|
||||||
ct_os_check_compulsory_vars
|
|
||||||
|
|
||||||
# Populate template variables if not set already
|
|
||||||
if [ -z "${EPHEMERAL_TEMPLATES:-}" ]; then
|
|
||||||
EPHEMERAL_TEMPLATES="
|
|
||||||
$REMOTE_TEMPLATES/postgresql-ephemeral-template.json
|
|
||||||
$TEMPLATES/postgresql-ephemeral-template.json"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -z "${PERSISTENT_TEMPLATES:-}" ]; then
|
|
||||||
PERSISTENT_TEMPLATES="
|
|
||||||
$REMOTE_TEMPLATES/postgresql-persistent-template.json
|
|
||||||
$TEMPLATES/postgresql-persistent-template.json"
|
|
||||||
fi
|
|
||||||
|
|
||||||
function assert_cmd_fails() {
|
|
||||||
if eval "$@" &>/dev/null; then
|
|
||||||
echo " FAIL"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
echo " PASS"
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
|
|
||||||
function insert_postgresql_data() {
|
|
||||||
local image_name=$1 ; shift
|
|
||||||
local user=$1 ; shift
|
|
||||||
local pass=$1 ; shift
|
|
||||||
local database=$1 ; shift
|
|
||||||
local pod_ip=$1; shift
|
|
||||||
|
|
||||||
: "Inserting data into the database"
|
|
||||||
local cmd="PGPASSWORD=$pass psql -c \"CREATE TABLE testing (a integer); INSERT INTO testing VALUES (42);\""
|
|
||||||
local cmd_args="-h $pod_ip -U $user -d $database"
|
|
||||||
docker run --rm "$image_name" bash -c "$cmd $cmd_args"
|
|
||||||
}
|
|
||||||
|
|
||||||
function check_postgresql_data() {
|
|
||||||
local image_name=$1 ; shift
|
|
||||||
local user=$1 ; shift
|
|
||||||
local pass=$1 ; shift
|
|
||||||
local database=$1 ; shift
|
|
||||||
local pod_ip=$1; shift
|
|
||||||
local timeout=${1:-60}
|
|
||||||
SECONDS=0
|
|
||||||
|
|
||||||
: "Checking whether the data can be accessed"
|
|
||||||
local cmd="PGPASSWORD=$pass psql -c \"select * from testing;\""
|
|
||||||
local cmd_args="-h $pod_ip -U $user -d $database"
|
|
||||||
while true ; do
|
|
||||||
result=$(docker run --rm "$image_name" bash -c "$cmd -At $cmd_args")
|
|
||||||
if [ "$result" = "42" ]; then
|
|
||||||
echo " PASS"
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
echo -n "."
|
|
||||||
[ $SECONDS -gt $timeout ] && break
|
|
||||||
sleep 3
|
|
||||||
done
|
|
||||||
echo " FAIL"
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
function check_postgresql_os_service_connection() {
|
|
||||||
local util_image_name=$1 ; shift
|
|
||||||
local service_name=$1 ; shift
|
|
||||||
local user=$1 ; shift
|
|
||||||
local pass=$1 ; shift
|
|
||||||
local database=$1 ; shift
|
|
||||||
local timeout=${1:-60} ; shift || :
|
|
||||||
local pod_ip=$(ct_os_get_service_ip ${service_name})
|
|
||||||
|
|
||||||
: " Service ${service_name} check ..."
|
|
||||||
|
|
||||||
local cmd="PGPASSWORD=${pass} pg_isready -t 15 -h ${pod_ip} -U ${user} -d ${database}"
|
|
||||||
local expected_value='accepting connections'
|
|
||||||
local output
|
|
||||||
local ret
|
|
||||||
SECONDS=0
|
|
||||||
|
|
||||||
echo -n "Waiting for ${service_name} service becoming ready ..."
|
|
||||||
while true ; do
|
|
||||||
output=$(docker run --rm ${util_image_name} bash -c "${cmd}" || :)
|
|
||||||
echo "${output}" | grep -qe "${expected_value}" && ret=0 || ret=1
|
|
||||||
if [ ${ret} -eq 0 ] ; then
|
|
||||||
echo " PASS"
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
echo -n "."
|
|
||||||
[ ${SECONDS} -gt ${timeout} ] && break
|
|
||||||
sleep 3
|
|
||||||
done
|
|
||||||
echo " FAIL"
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_postgresql_pure_image() {
|
|
||||||
local image_name=$1
|
|
||||||
local image_name_no_namespace=${image_name##*/}
|
|
||||||
local service_name=${image_name_no_namespace}
|
|
||||||
|
|
||||||
ct_os_new_project
|
|
||||||
ct_os_upload_image "${image_name}"
|
|
||||||
# Create a specific imagestream tag for the image so that oc cannot use anything else
|
|
||||||
ct_os_upload_image "${image_name}" "$image_name_no_namespace:testing"
|
|
||||||
|
|
||||||
ct_os_deploy_pure_image "$image_name_no_namespace:testing" \
|
|
||||||
--name "${service_name}" \
|
|
||||||
--env POSTGRESQL_ADMIN_PASSWORD=test
|
|
||||||
|
|
||||||
ct_os_wait_pod_ready "${service_name}" 60
|
|
||||||
check_postgresql_os_service_connection "${image_name}" "${service_name}" postgres test postgres
|
|
||||||
|
|
||||||
ct_os_delete_project
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_postgresql_template() {
|
|
||||||
local image_name=$1; shift
|
|
||||||
local template=$1
|
|
||||||
local image_name_no_namespace=${image_name##*/}
|
|
||||||
local service_name=${image_name_no_namespace}
|
|
||||||
|
|
||||||
ct_os_new_project
|
|
||||||
ct_os_upload_image "${image_name}" "postgresql:$VERSION"
|
|
||||||
|
|
||||||
ct_os_deploy_template_image "$template" \
|
|
||||||
NAMESPACE="$(oc project -q)" \
|
|
||||||
POSTGRESQL_VERSION="$VERSION" \
|
|
||||||
DATABASE_SERVICE_NAME="${service_name}" \
|
|
||||||
POSTGRESQL_USER=testu \
|
|
||||||
POSTGRESQL_PASSWORD=testp \
|
|
||||||
POSTGRESQL_DATABASE=testdb
|
|
||||||
|
|
||||||
ct_os_wait_pod_ready "${service_name}" 60
|
|
||||||
check_postgresql_os_service_connection "${image_name}" "${service_name}" testu testp testdb
|
|
||||||
|
|
||||||
ct_os_delete_project
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_postgresql_update() {
|
|
||||||
local image_name=$1; shift
|
|
||||||
local template=$1
|
|
||||||
local image_name_no_registry=${image_name#*/}
|
|
||||||
local service_name=${image_name_no_registry#*/}
|
|
||||||
local user="testu" pass="testp" db="testdb"
|
|
||||||
local registry="" old_image="" pod_ip=""
|
|
||||||
local version released=:
|
|
||||||
|
|
||||||
old_image=$(get_image_id "$VERSION:remote")
|
|
||||||
|
|
||||||
for version in $NOT_RELEASED_VERSIONS; do
|
|
||||||
case $image_name in
|
|
||||||
*$version*)
|
|
||||||
released=false
|
|
||||||
break
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
|
|
||||||
if docker pull "$old_image" 2>/dev/null; then
|
|
||||||
# Check if we do not have a stale unreleased versions list
|
|
||||||
# Fail only on rhel, on centos the image is likely already released
|
|
||||||
$released || [ "$OS" = "centos7" ]
|
|
||||||
elif $released; then
|
|
||||||
false "image '$old_image' should already be available"
|
|
||||||
else
|
|
||||||
return # not yet released image, skip
|
|
||||||
fi
|
|
||||||
|
|
||||||
|
|
||||||
ct_os_new_project
|
|
||||||
ct_os_upload_image "$old_image" "postgresql:$VERSION"
|
|
||||||
ct_os_deploy_template_image "$template" \
|
|
||||||
NAMESPACE="$(oc project -q)" \
|
|
||||||
POSTGRESQL_VERSION="$VERSION" \
|
|
||||||
DATABASE_SERVICE_NAME="$service_name" \
|
|
||||||
POSTGRESQL_USER="$user" \
|
|
||||||
POSTGRESQL_PASSWORD="$pass" \
|
|
||||||
POSTGRESQL_DATABASE="$db"
|
|
||||||
|
|
||||||
ct_os_wait_pod_ready "${service_name}" 60
|
|
||||||
check_postgresql_os_service_connection "$image_name" "$service_name" "$user" "$pass" "$db"
|
|
||||||
|
|
||||||
pod_ip=$(ct_os_get_service_ip "$service_name")
|
|
||||||
insert_postgresql_data "$image_name" "$user" "$pass" "$db" "$pod_ip"
|
|
||||||
|
|
||||||
ct_os_upload_image "$image_name" "postgresql:$VERSION"
|
|
||||||
: "Waiting for a few seconds while the pods get restarted"
|
|
||||||
sleep 5
|
|
||||||
|
|
||||||
ct_os_wait_pod_ready "$service_name" 60
|
|
||||||
check_postgresql_os_service_connection "$image_name" "$service_name" "$user" "$pass" "$db"
|
|
||||||
|
|
||||||
check_postgresql_data "$image_name" "$user" "$pass" "$db" "$pod_ip"
|
|
||||||
ct_os_delete_project
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_postgresql_replication() {
|
|
||||||
local image_name=$1
|
|
||||||
local image_name_no_namespace=${image_name##*/}
|
|
||||||
local master_service_name=${image_name_no_namespace}-master
|
|
||||||
local slave_service_name=${image_name_no_namespace}-slave
|
|
||||||
local istag="postgresql:$VERSION"
|
|
||||||
local user="testu" pass="testp" db="testdb"
|
|
||||||
local master_name="" master_ip="" slave_name="" slave_ip=""
|
|
||||||
|
|
||||||
ct_os_new_project
|
|
||||||
ct_os_upload_image "${image_name}" "$istag"
|
|
||||||
|
|
||||||
ct_os_deploy_template_image "$TEMPLATES/replica/postgresql_replica.json" \
|
|
||||||
NAMESPACE="$(oc project -q)" \
|
|
||||||
IMAGESTREAMTAG="$istag" \
|
|
||||||
POSTGRESQL_MASTER_SERVICE_NAME="$master_service_name" \
|
|
||||||
POSTGRESQL_SLAVE_SERVICE_NAME="$slave_service_name" \
|
|
||||||
POSTGRESQL_USER=testu \
|
|
||||||
POSTGRESQL_PASSWORD=testp \
|
|
||||||
POSTGRESQL_DATABASE=testdb
|
|
||||||
|
|
||||||
ct_os_wait_pod_ready "$master_service_name" 60
|
|
||||||
ct_os_wait_pod_ready "$slave_service_name" 60
|
|
||||||
|
|
||||||
# Force unused rc removal as we do not need rollbacks during testing
|
|
||||||
oc patch "dc/$master_service_name" -p '{"spec":{"revisionHistoryLimit":0}}'
|
|
||||||
oc patch "dc/$slave_service_name" -p '{"spec":{"revisionHistoryLimit":0}}'
|
|
||||||
|
|
||||||
master_name=$(ct_os_get_pod_name "$master_service_name")
|
|
||||||
slave_name=$(ct_os_get_pod_name "$slave_service_name")
|
|
||||||
master_ip=$(ct_os_get_pod_ip "$master_name")
|
|
||||||
slave_ip=$(ct_os_get_pod_ip "$slave_name")
|
|
||||||
insert_postgresql_data "$image_name" "$user" "$pass" "$db" "$master_ip"
|
|
||||||
check_postgresql_data "$image_name" "$user" "$pass" "$db" "$slave_ip"
|
|
||||||
|
|
||||||
: "Changing POSTGRESQL_PASSWORD for master and slave"
|
|
||||||
pass=redhat
|
|
||||||
oc set env "dc/$master_service_name" -e POSTGRESQL_PASSWORD="$pass"
|
|
||||||
oc set env "dc/$slave_service_name" -e POSTGRESQL_PASSWORD="$pass"
|
|
||||||
ct_os_wait_pod_ready "$master_service_name-2" 60
|
|
||||||
ct_os_wait_pod_ready "$slave_service_name-2" 60
|
|
||||||
# We need to get new pod names and IPs
|
|
||||||
master_name=$(ct_os_get_pod_name "$master_service_name")
|
|
||||||
slave_name=$(ct_os_get_pod_name "$slave_service_name")
|
|
||||||
master_ip=$(ct_os_get_pod_ip "$master_name")
|
|
||||||
slave_ip=$(ct_os_get_pod_ip "$slave_name")
|
|
||||||
check_postgresql_data "$image_name" "$user" "$pass" "$db" "$master_ip"
|
|
||||||
check_postgresql_data "$image_name" "$user" "$pass" "$db" "$slave_ip"
|
|
||||||
|
|
||||||
: "Redeploying slave node"
|
|
||||||
oc rollout latest "$slave_service_name"
|
|
||||||
ct_os_wait_pod_ready "$slave_service_name-3" 60
|
|
||||||
slave_name=$(ct_os_get_pod_name "$slave_service_name")
|
|
||||||
slave_ip=$(ct_os_get_pod_ip "$slave_name")
|
|
||||||
check_postgresql_data "$image_name" "$user" "$pass" "$db" "$slave_ip"
|
|
||||||
|
|
||||||
: "Scaling slaves to 2"
|
|
||||||
oc scale --replicas 2 "dc/$slave_service_name"
|
|
||||||
ct_os_wait_rc_ready "$slave_service_name" 60
|
|
||||||
slave_name=$(ct_os_get_pod_name "$slave_service_name")
|
|
||||||
for slave in $slave_name; do
|
|
||||||
ct_os_wait_pod_ready "$slave" 60
|
|
||||||
slave_ip=$(ct_os_get_pod_ip "$slave")
|
|
||||||
check_postgresql_data "$image_name" "$user" "$pass" "$db" "$slave_ip"
|
|
||||||
done
|
|
||||||
|
|
||||||
ct_os_delete_project
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_postgresql_persistent_redeploy() {
|
|
||||||
local image_name=$1; shift
|
|
||||||
local template=$1
|
|
||||||
local image_name_no_namespace=${image_name##*/}
|
|
||||||
local service_name=$image_name_no_namespace
|
|
||||||
local user="testu" pass="testp" db="testdb"
|
|
||||||
local registry="" old_image="" pod_ip=""
|
|
||||||
|
|
||||||
ct_os_new_project
|
|
||||||
ct_os_upload_image "$image_name" "postgresql:$VERSION"
|
|
||||||
|
|
||||||
ct_os_deploy_template_image "$template" \
|
|
||||||
NAMESPACE="$(oc project -q)" \
|
|
||||||
POSTGRESQL_VERSION="$VERSION" \
|
|
||||||
DATABASE_SERVICE_NAME="$service_name" \
|
|
||||||
POSTGRESQL_USER="$user" \
|
|
||||||
POSTGRESQL_PASSWORD="$pass" \
|
|
||||||
POSTGRESQL_DATABASE="$db"
|
|
||||||
|
|
||||||
ct_os_wait_pod_ready "$service_name" 60
|
|
||||||
check_postgresql_os_service_connection "$image_name" "$service_name" testu testp testdb
|
|
||||||
|
|
||||||
pod_ip=$(ct_os_get_service_ip "$service_name")
|
|
||||||
insert_postgresql_data "$image_name" "$user" "$pass" "$db" "$pod_ip"
|
|
||||||
|
|
||||||
: "Redeploying pod"
|
|
||||||
oc rollout latest "$service_name"
|
|
||||||
: "Waiting for a few seconds while the pod gets restarted"
|
|
||||||
sleep 5
|
|
||||||
|
|
||||||
ct_os_wait_pod_ready "$service_name" 60
|
|
||||||
check_postgresql_os_service_connection "$image_name" "$service_name" "$user" "$pass" "$db"
|
|
||||||
|
|
||||||
: "This should succeed"
|
|
||||||
check_postgresql_data "$image_name" "$user" "$pass" "$db" "$pod_ip" 0
|
|
||||||
ct_os_delete_project
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_postgresql_ephemeral_redeploy() {
|
|
||||||
local image_name=$1; shift
|
|
||||||
local template=$1
|
|
||||||
local image_name_no_namespace=${image_name##*/}
|
|
||||||
local service_name=$image_name_no_namespace
|
|
||||||
local user="testu" pass="testp" db="testdb"
|
|
||||||
local registry="" old_image="" pod_ip=""
|
|
||||||
|
|
||||||
ct_os_new_project
|
|
||||||
ct_os_upload_image "$image_name" "postgresql:$VERSION"
|
|
||||||
|
|
||||||
ct_os_deploy_template_image "$template" \
|
|
||||||
NAMESPACE="$(oc project -q)" \
|
|
||||||
POSTGRESQL_VERSION="$VERSION" \
|
|
||||||
DATABASE_SERVICE_NAME="$service_name" \
|
|
||||||
POSTGRESQL_USER="$user" \
|
|
||||||
POSTGRESQL_PASSWORD="$pass" \
|
|
||||||
POSTGRESQL_DATABASE="$db"
|
|
||||||
|
|
||||||
ct_os_wait_pod_ready "$service_name" 60
|
|
||||||
check_postgresql_os_service_connection "$image_name" "$service_name" testu testp testdb
|
|
||||||
|
|
||||||
pod_ip=$(ct_os_get_service_ip "$service_name")
|
|
||||||
insert_postgresql_data "$image_name" "$user" "$pass" "$db" "$pod_ip"
|
|
||||||
|
|
||||||
: "Redeploying pod"
|
|
||||||
oc rollout latest "$service_name"
|
|
||||||
: "Waiting for a few seconds while the pod gets restarted"
|
|
||||||
sleep 5
|
|
||||||
|
|
||||||
ct_os_wait_pod_ready "$service_name" 60
|
|
||||||
check_postgresql_os_service_connection "$image_name" "$service_name" "$user" "$pass" "$db"
|
|
||||||
|
|
||||||
: "This should fail"
|
|
||||||
assert_cmd_fails check_postgresql_data "$image_name" "$user" "$pass" "$db" "$pod_ip" 0
|
|
||||||
ct_os_delete_project
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_postgresql_configmap_start() {
|
|
||||||
local image_name=$1; shift
|
|
||||||
local template="$TEMPLATES/postgresql-ephemeral-template.json"
|
|
||||||
local image_name_no_namespace=${image_name##*/}
|
|
||||||
local service_name=$image_name_no_namespace
|
|
||||||
local user="testu" pass="testp" db="testdb"
|
|
||||||
local registry="" old_image="" pod_ip="" tmpdir=""
|
|
||||||
local test_string=""
|
|
||||||
|
|
||||||
ct_os_new_project
|
|
||||||
ct_os_upload_image "$image_name" "postgresql:$VERSION"
|
|
||||||
|
|
||||||
ct_os_deploy_template_image "$template" \
|
|
||||||
NAMESPACE="$(oc project -q)" \
|
|
||||||
POSTGRESQL_VERSION="$VERSION" \
|
|
||||||
DATABASE_SERVICE_NAME="$service_name" \
|
|
||||||
POSTGRESQL_USER="$user" \
|
|
||||||
POSTGRESQL_PASSWORD="$pass" \
|
|
||||||
POSTGRESQL_DATABASE="$db"
|
|
||||||
|
|
||||||
ct_os_wait_pod_ready "$service_name" 60
|
|
||||||
check_postgresql_os_service_connection "$image_name" "$service_name" testu testp testdb
|
|
||||||
|
|
||||||
# Create a simple configMap with a start.sh script
|
|
||||||
tmpdir=$(mktemp -d)
|
|
||||||
test_string="Start is working"
|
|
||||||
echo "echo $test_string" >> "$tmpdir/start.sh"
|
|
||||||
oc create configmap postgresql-start --from-file="$tmpdir/start.sh"
|
|
||||||
oc set volume "dc/$service_name" --add -t configmap --configmap-name=postgresql-start -m /opt/app-root/src/postgresql-start --name postgresql-start
|
|
||||||
|
|
||||||
# Wait for redeploy
|
|
||||||
ct_os_wait_pod_ready "$service_name-2" 60
|
|
||||||
check_postgresql_os_service_connection "$image_name" "$service_name" testu testp testdb
|
|
||||||
|
|
||||||
# Check logs for the test string
|
|
||||||
oc logs "$(ct_os_get_pod_name "$service_name")" | grep "$test_string"
|
|
||||||
|
|
||||||
ct_os_delete_project
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_ephemeral_tests() {
|
|
||||||
local image_name=$1
|
|
||||||
for template in $EPHEMERAL_TEMPLATES; do
|
|
||||||
test_postgresql_ephemeral_redeploy "$image_name" "$template"
|
|
||||||
test_postgresql_template "$image_name" "$template"
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_persistent_tests() {
|
|
||||||
local image_name=$1
|
|
||||||
for template in $PERSISTENT_TEMPLATES; do
|
|
||||||
test_postgresql_persistent_redeploy "$image_name" "$template"
|
|
||||||
test_postgresql_update "$image_name" "$template"
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
ct_os_cluster_up
|
|
||||||
# Print oc logs on failure
|
|
||||||
ct_os_enable_print_logs
|
|
||||||
|
|
||||||
test_postgresql_pure_image "$IMAGE_NAME"
|
|
||||||
test_postgresql_replication "$IMAGE_NAME"
|
|
||||||
run_ephemeral_tests "$IMAGE_NAME"
|
|
||||||
run_persistent_tests "$IMAGE_NAME"
|
|
||||||
test_postgresql_configmap_start "$IMAGE_NAME"
|
|
||||||
|
|
||||||
# test with the just built image and an integrated template
|
|
||||||
echo "Running test_postgresql_integration with ${IMAGE_NAME}"
|
|
||||||
test_postgresql_integration "${IMAGE_NAME}"
|
|
||||||
|
|
||||||
# test with a released image and an integrated template
|
|
||||||
PUBLIC_IMAGE_NAME=${PUBLIC_IMAGE_NAME:-$(ct_get_public_image_name "${OS}" "${BASE_IMAGE_NAME}" "${VERSION}")}
|
|
||||||
|
|
||||||
# Try pulling the image first to see if it is accessible
|
|
||||||
if docker pull "${PUBLIC_IMAGE_NAME}"; then
|
|
||||||
echo "Running test_postgresql_integration with ${PUBLIC_IMAGE_NAME}"
|
|
||||||
test_postgresql_integration "${PUBLIC_IMAGE_NAME}"
|
|
||||||
else
|
|
||||||
echo "Warning: ${PUBLIC_IMAGE_NAME} could not be downloaded via 'docker'"
|
|
||||||
# ignore possible failure of this test for centos images
|
|
||||||
[ "${OS}" == "rhel7" ] && false "ERROR: Failed to pull image"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Check the imagestream
|
|
||||||
echo "Running test_mariadb_imagestream"
|
|
||||||
test_postgresql_imagestream
|
|
||||||
|
|
||||||
OS_TESTSUITE_RESULT=0
|
|
||||||
|
|
||||||
ct_os_cluster_down
|
|
||||||
|
|
||||||
# vim: set tabstop=2:shiftwidth=2:expandtab:
|
|
||||||
|
|
||||||
|
|
@ -1,36 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
#
|
|
||||||
# Test the PostgreSQL image in OpenShift (remote cluster)
|
|
||||||
#
|
|
||||||
# IMAGE_NAME specifies a name of the candidate image used for testing.
|
|
||||||
# The image has to be available before this script is executed.
|
|
||||||
# VERSION specifies the major version of the PostgreSQL in format of X.Y
|
|
||||||
# OS specifies RHEL version (e.g. OS=rhel7)
|
|
||||||
#
|
|
||||||
|
|
||||||
THISDIR=$(dirname ${BASH_SOURCE[0]})
|
|
||||||
|
|
||||||
source ${THISDIR}/test-lib-postgresql.sh
|
|
||||||
|
|
||||||
set -eo nounset
|
|
||||||
|
|
||||||
trap ct_os_cleanup EXIT SIGINT
|
|
||||||
|
|
||||||
ct_os_check_compulsory_vars
|
|
||||||
|
|
||||||
oc status || false "It looks like oc is not properly logged in."
|
|
||||||
|
|
||||||
export CT_SKIP_NEW_PROJECT=true
|
|
||||||
export CT_SKIP_UPLOAD_IMAGE=true
|
|
||||||
export CT_NAMESPACE=openshift
|
|
||||||
|
|
||||||
# Check the template
|
|
||||||
test_postgresql_integration "${IMAGE_NAME}"
|
|
||||||
|
|
||||||
# Check the imagestream
|
|
||||||
test_postgresql_imagestream
|
|
||||||
|
|
||||||
OS_TESTSUITE_RESULT=0
|
|
||||||
|
|
||||||
# vim: set tabstop=2:shiftwidth=2:expandtab:
|
|
||||||
|
|
||||||
|
|
@ -1,56 +0,0 @@
|
||||||
#! /bin/bash
|
|
||||||
|
|
||||||
set -e
|
|
||||||
. test/pg-test-lib.sh
|
|
||||||
ADMIN_PASSWORD=redhat
|
|
||||||
|
|
||||||
test $# -eq 2 || error "two args expected: $0 FROM TO"
|
|
||||||
|
|
||||||
cleanup()
|
|
||||||
{
|
|
||||||
set +e
|
|
||||||
set -- $container_from $container_to
|
|
||||||
if test $# -gt 0; then
|
|
||||||
docker stop "$@" >/dev/null
|
|
||||||
docker rm -f "$@"
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
trap cleanup EXIT
|
|
||||||
|
|
||||||
from=$1
|
|
||||||
to=$2
|
|
||||||
image_from=$(get_image_id "$from")
|
|
||||||
image_to=$(get_image_id "$to")
|
|
||||||
|
|
||||||
assert_migration_succeeds ()
|
|
||||||
{
|
|
||||||
info "starting PostgreSQL server v$from"
|
|
||||||
container_from=$(docker run -e POSTGRESQL_ADMIN_PASSWORD="$ADMIN_PASSWORD" -d "$image_from")
|
|
||||||
wait_for_postgres "$container_from"
|
|
||||||
|
|
||||||
eval "CID=\$container_from data_${1}_create"
|
|
||||||
eval "CID=\$container_from data_${1}_check"
|
|
||||||
|
|
||||||
ip=$(container_ip "$container_from")
|
|
||||||
|
|
||||||
info "starting new PostgreSQL server v$to with migration options"
|
|
||||||
container_to=$(docker run \
|
|
||||||
-e POSTGRESQL_MIGRATION_REMOTE_HOST="$ip" \
|
|
||||||
-e POSTGRESQL_MIGRATION_ADMIN_PASSWORD="$ADMIN_PASSWORD" \
|
|
||||||
-d "$image_to")
|
|
||||||
|
|
||||||
# Prolong a waiting time here a bit since both dump and restore is done in
|
|
||||||
# uncertain environment (usually both is done on the same hardware).
|
|
||||||
wait_for_postgres "$container_to" 100
|
|
||||||
|
|
||||||
info "check that the migration passed"
|
|
||||||
eval "CID=\$container_to data_${1}_check"
|
|
||||||
|
|
||||||
docker stop "$container_from"
|
|
||||||
docker rm -f "$container_from"
|
|
||||||
docker stop "$container_to"
|
|
||||||
docker rm -f "$container_to"
|
|
||||||
container_from= container_to=
|
|
||||||
}
|
|
||||||
|
|
||||||
assert_migration_succeeds pagila
|
|
||||||
929
test/run_test
929
test/run_test
|
|
@ -1,929 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
#
|
|
||||||
# Test the PostgreSQL image.
|
|
||||||
#
|
|
||||||
# IMAGE_NAME specifies the name of the candidate image used for testing.
|
|
||||||
# The image has to be available before this script is executed.
|
|
||||||
#
|
|
||||||
|
|
||||||
set -exo nounset
|
|
||||||
shopt -s nullglob
|
|
||||||
|
|
||||||
# library from container-common-scripts
|
|
||||||
. test/test-lib.sh
|
|
||||||
|
|
||||||
# local library
|
|
||||||
. test/pg-test-lib.sh
|
|
||||||
|
|
||||||
TEST_LIST="\
|
|
||||||
run_container_creation_tests
|
|
||||||
run_general_tests
|
|
||||||
run_change_password_test
|
|
||||||
run_replication_test
|
|
||||||
run_master_restart_test
|
|
||||||
run_doc_test
|
|
||||||
run_s2i_test
|
|
||||||
run_test_cfg_hook
|
|
||||||
run_s2i_bake_data_test
|
|
||||||
run_s2i_enable_ssl_test
|
|
||||||
run_upgrade_test
|
|
||||||
run_migration_test
|
|
||||||
run_pgaudit_test
|
|
||||||
run_latest_imagestreams_test
|
|
||||||
"
|
|
||||||
|
|
||||||
test $# -eq 1 -a "${1-}" == --list && echo "$TEST_LIST" && exit 0
|
|
||||||
test -n "${IMAGE_NAME-}" || false 'make sure $IMAGE_NAME is defined'
|
|
||||||
test -n "${VERSION-}" || false 'make sure $VERSION is defined'
|
|
||||||
test -n "${OS-}" || false 'make sure $OS is defined'
|
|
||||||
|
|
||||||
CIDFILE_DIR=$(mktemp --suffix=postgresql_test_cidfiles -d)
|
|
||||||
|
|
||||||
volumes_to_clean=
|
|
||||||
images_to_clean=()
|
|
||||||
files_to_clean=
|
|
||||||
test_dir="$(readlink -f "$(dirname "$0")")"
|
|
||||||
test_short_summary=''
|
|
||||||
TESTSUITE_RESULT=1
|
|
||||||
|
|
||||||
_cleanup_commands_space=
|
|
||||||
_cleanup_commands=
|
|
||||||
|
|
||||||
add_cleanup_command ()
|
|
||||||
{
|
|
||||||
local cmd= space=
|
|
||||||
for arg; do
|
|
||||||
cmd+="$space$(printf "%q" "$arg")"
|
|
||||||
space=' '
|
|
||||||
done
|
|
||||||
_cleanup_commands+="$_cleanup_commands_space$cmd"
|
|
||||||
_cleanup_commands_space='
|
|
||||||
'
|
|
||||||
}
|
|
||||||
function cleanup() {
|
|
||||||
# Print a big fat separator to find the error easier
|
|
||||||
echo "=================================== Cleanup begins here ============================="
|
|
||||||
|
|
||||||
for cidfile in $CIDFILE_DIR/* ; do
|
|
||||||
CONTAINER=$(cat $cidfile)
|
|
||||||
|
|
||||||
echo "Stopping and removing container $CONTAINER..."
|
|
||||||
docker stop $CONTAINER
|
|
||||||
exit_status=$(docker inspect -f '{{.State.ExitCode}}' $CONTAINER)
|
|
||||||
if [ "$exit_status" != "0" ]; then
|
|
||||||
echo "Dumping logs for $CONTAINER"
|
|
||||||
docker logs $CONTAINER
|
|
||||||
fi
|
|
||||||
docker rm $CONTAINER
|
|
||||||
rm $cidfile
|
|
||||||
echo "Done."
|
|
||||||
done
|
|
||||||
rmdir $CIDFILE_DIR
|
|
||||||
|
|
||||||
ct_path_foreach "$volumes_to_clean" cleanup_volume_dir
|
|
||||||
|
|
||||||
if test -n "${images_to_clean-}"; then
|
|
||||||
# Workaround for RHEL 7 bash bug:
|
|
||||||
# https://bugzilla.redhat.com/show_bug.cgi?id=1636393
|
|
||||||
for image in "${images_to_clean[@]}"; do
|
|
||||||
docker rmi -f "$image"
|
|
||||||
done
|
|
||||||
fi
|
|
||||||
|
|
||||||
ct_path_foreach "$files_to_clean" rm
|
|
||||||
|
|
||||||
echo "$_cleanup_commands" | while read -r line; do
|
|
||||||
eval "$line"
|
|
||||||
done
|
|
||||||
|
|
||||||
echo "$test_short_summary"
|
|
||||||
|
|
||||||
if [ $TESTSUITE_RESULT -eq 0 ] ; then
|
|
||||||
echo "Tests for ${IMAGE_NAME} succeeded."
|
|
||||||
else
|
|
||||||
echo "Tests for ${IMAGE_NAME} failed."
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
trap cleanup EXIT
|
|
||||||
|
|
||||||
cleanup_volume_dir ()
|
|
||||||
{
|
|
||||||
test ! -d "$1" && : "WARN: cleaned $1 for some reason" && return 0
|
|
||||||
# When we run this test script as non-root (we should?), the PostgreSQL server
|
|
||||||
# within container is still run under 'postgres' user. It means that, taking
|
|
||||||
# into account 0077 umask of PostgreSQL server, we are unable to remove files
|
|
||||||
# created by server. That's why we need to let docker escalate the privileges
|
|
||||||
# again.
|
|
||||||
local datadir=/var/lib/pgsql/data
|
|
||||||
docker run -v "$1:$datadir:Z" --rm "$IMAGE_NAME" /bin/sh -c "/bin/rm -rf $datadir/userdata"
|
|
||||||
rmdir "$1"
|
|
||||||
}
|
|
||||||
|
|
||||||
function get_cid() {
|
|
||||||
local id="$1" ; shift || return 1
|
|
||||||
echo $(cat "$CIDFILE_DIR/$id")
|
|
||||||
}
|
|
||||||
|
|
||||||
function get_container_ip() {
|
|
||||||
local id="$1" ; shift
|
|
||||||
docker inspect --format='{{.NetworkSettings.IPAddress}}' $(get_cid "$id")
|
|
||||||
}
|
|
||||||
|
|
||||||
function get_ip_from_cid() {
|
|
||||||
local cid="$1"; shift
|
|
||||||
docker inspect --format='{{.NetworkSettings.IPAddress}}' $cid
|
|
||||||
}
|
|
||||||
|
|
||||||
function postgresql_cmd() {
|
|
||||||
docker run --rm -e PGPASSWORD="$PASS" "$IMAGE_NAME" psql "postgresql://$PGUSER@$CONTAINER_IP:5432/${DB-db}" "$@"
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_connection() {
|
|
||||||
local name=$1 ; shift
|
|
||||||
ip=$(get_container_ip $name)
|
|
||||||
echo " Testing PostgreSQL connection to $ip..."
|
|
||||||
local max_attempts=20
|
|
||||||
local sleep_time=2
|
|
||||||
for i in $(seq $max_attempts); do
|
|
||||||
echo " Trying to connect..."
|
|
||||||
set +e
|
|
||||||
# Don't let the code come here if neither user nor admin is able to
|
|
||||||
# connect.
|
|
||||||
if [ -v PGUSER ] && [ -v PASS ]; then
|
|
||||||
CONTAINER_IP=$ip postgresql_cmd <<< "SELECT 1;"
|
|
||||||
else
|
|
||||||
PGUSER=postgres PASS=$ADMIN_PASS CONTAINER_IP=$ip DB=postgres postgresql_cmd <<< "SELECT 1;"
|
|
||||||
fi
|
|
||||||
status=$?
|
|
||||||
set -e
|
|
||||||
if [ $status -eq 0 ]; then
|
|
||||||
echo " Success!"
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
sleep $sleep_time
|
|
||||||
done
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_postgresql() {
|
|
||||||
echo " Testing PostgreSQL"
|
|
||||||
postgresql_cmd <<< "CREATE EXTENSION 'uuid-ossp';" # to test contrib package
|
|
||||||
postgresql_cmd <<< "CREATE TABLE tbl (col1 VARCHAR(20), col2 VARCHAR(20));"
|
|
||||||
postgresql_cmd <<< "INSERT INTO tbl VALUES ('foo1', 'bar1');"
|
|
||||||
postgresql_cmd <<< "INSERT INTO tbl VALUES ('foo2', 'bar2');"
|
|
||||||
postgresql_cmd <<< "INSERT INTO tbl VALUES ('foo3', 'bar3');"
|
|
||||||
postgresql_cmd <<< "SELECT * FROM tbl;"
|
|
||||||
#postgresql_cmd <<< "DROP TABLE tbl;"
|
|
||||||
echo " Success!"
|
|
||||||
}
|
|
||||||
|
|
||||||
function create_container() {
|
|
||||||
local name=$1 ; shift
|
|
||||||
local cargs=${DOCKER_ARGS:-}
|
|
||||||
# TODO: fix all create_container() invocations so that we don't need this,
|
|
||||||
# e.g. multiline DOCKER_ARGS var should end by trailing backslashes
|
|
||||||
cargs=$(echo "$cargs" | tr '\n' ' ')
|
|
||||||
cidfile="$CIDFILE_DIR/$name"
|
|
||||||
# create container with a cidfile in a directory for cleanup
|
|
||||||
eval "docker run $cargs --cidfile \$cidfile -d \$IMAGE_NAME \"\$@\""
|
|
||||||
echo "Created container $(cat $cidfile)"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
create_volume_dir ()
|
|
||||||
{
|
|
||||||
volume_dir=`mktemp -d --tmpdir pg-testdata.XXXXX`
|
|
||||||
setfacl -m u:26:-wx "$volume_dir"
|
|
||||||
ct_path_append volumes_to_clean "$volume_dir"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
create_temp_file ()
|
|
||||||
{
|
|
||||||
temp_file=`mktemp --tmpdir pg-testfile.XXXXX`
|
|
||||||
setfacl -m u:26:rw- "$temp_file"
|
|
||||||
ct_path_append files_to_clean "$temp_file"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
function assert_login_access() {
|
|
||||||
local PGUSER=$1 ; shift
|
|
||||||
local PASS=$1 ; shift
|
|
||||||
local success=$1 ; shift
|
|
||||||
|
|
||||||
echo "testing login as $PGUSER:$PASS; should_success=$success"
|
|
||||||
|
|
||||||
if postgresql_cmd <<<'SELECT 1;' ; then
|
|
||||||
if $success ; then
|
|
||||||
echo " $PGUSER($PASS) access granted as expected"
|
|
||||||
return
|
|
||||||
fi
|
|
||||||
else
|
|
||||||
if ! $success ; then
|
|
||||||
echo " $PGUSER($PASS) access denied as expected"
|
|
||||||
return
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
echo " $PGUSER($PASS) login assertion failed"
|
|
||||||
exit 1
|
|
||||||
}
|
|
||||||
|
|
||||||
function assert_local_access() {
|
|
||||||
local id="$1" ; shift
|
|
||||||
docker exec -i $(get_cid "$id") bash -c psql <<< "SELECT 1;"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# Make sure the invocation of docker run fails.
|
|
||||||
function assert_container_creation_fails() {
|
|
||||||
|
|
||||||
# Time the docker run command. It should fail. If it doesn't fail,
|
|
||||||
# postgresql will keep running so we kill it with SIGKILL to make sure
|
|
||||||
# timeout returns a non-zero value.
|
|
||||||
set +e
|
|
||||||
timeout -s 9 --preserve-status 60s docker run --rm "$@" $IMAGE_NAME
|
|
||||||
ret=$?
|
|
||||||
set -e
|
|
||||||
|
|
||||||
# Timeout will exit with a high number.
|
|
||||||
if [ $ret -gt 30 ]; then
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# assert_container_creation_succeeds NAME [ARGS]
|
|
||||||
# ----------------------------------------------
|
|
||||||
# Chcek that 'docker run' with IMAGE_NAME succeeds with docker arguments
|
|
||||||
# specified as ARGS.
|
|
||||||
assert_container_creation_succeeds ()
|
|
||||||
{
|
|
||||||
local check_env=false
|
|
||||||
local name=pg-success-"$(ct_random_string)"
|
|
||||||
local PGUSER='' PGPASS='' DB='' ADMIN_PASS=
|
|
||||||
local docker_args=
|
|
||||||
|
|
||||||
for arg; do
|
|
||||||
docker_args+=" $(printf "%q" "$arg")"
|
|
||||||
if $check_env; then
|
|
||||||
local env=${arg//=*/}
|
|
||||||
local val=${arg//$env=/}
|
|
||||||
case $env in
|
|
||||||
POSTGRESQL_ADMIN_PASSWORD) ADMIN_PASS=$val ;;
|
|
||||||
POSTGRESQL_USER) PGUSER=$val ;;
|
|
||||||
POSTGRESQL_PASSWORD) PGPASS=$val ;;
|
|
||||||
POSTGRESQL_DATABASE) DB=$val ;;
|
|
||||||
esac
|
|
||||||
check_env=false
|
|
||||||
elif test "$arg" = -e; then
|
|
||||||
check_env=:
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
|
|
||||||
DOCKER_ARGS=$docker_args create_container "$name"
|
|
||||||
|
|
||||||
if test -n "$PGUSER" && test -n "$PGPASS"; then
|
|
||||||
PGUSER=$PGUSER PASS=$PGPASS DB=$DB test_connection "$name"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if test -n "$ADMIN_PASS"; then
|
|
||||||
PGUSER=postgres PASS=$ADMIN_PASS DB=$DB test_connection "$name"
|
|
||||||
fi
|
|
||||||
|
|
||||||
docker stop "$(get_cid "$name")"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
function try_image_invalid_combinations() {
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass "$@"
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_USER=user -e POSTGRESQL_DATABASE=db "$@"
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db "$@"
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_container_creation_tests() {
|
|
||||||
echo " Testing image entrypoint usage"
|
|
||||||
try_image_invalid_combinations
|
|
||||||
try_image_invalid_combinations -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
|
|
||||||
|
|
||||||
VERY_LONG_IDENTIFIER="very_long_identifier_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_USER= -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_USER=$VERY_LONG_IDENTIFIER -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
|
|
||||||
assert_container_creation_succeeds -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD="\"" -e POSTGRESQL_DATABASE=db -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
|
|
||||||
assert_container_creation_succeeds -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=9invalid -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=$VERY_LONG_IDENTIFIER -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
|
|
||||||
assert_container_creation_succeeds -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db -e POSTGRESQL_ADMIN_PASSWORD="\""
|
|
||||||
echo " Success!"
|
|
||||||
|
|
||||||
assert_container_creation_succeeds -e POSTGRESQL_ADMIN_PASSWORD="the @password"
|
|
||||||
assert_container_creation_succeeds -e POSTGRESQL_PASSWORD="the pass" -e POSTGRESQL_USER="the user" -e POSTGRESQL_DATABASE="the db"
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_config_option() {
|
|
||||||
local name=$1 ; shift
|
|
||||||
local setting=$1 ; shift
|
|
||||||
local value=$1 ; shift
|
|
||||||
|
|
||||||
docker exec $(get_cid ${name}) grep -q "${setting} = ${value}" /var/lib/pgsql/openshift-custom-postgresql.conf
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# wait_ready
|
|
||||||
# ----------
|
|
||||||
# Wait until the PG container becomes ready
|
|
||||||
wait_ready ()
|
|
||||||
{
|
|
||||||
while ! docker exec "$(get_cid "$1")" /usr/libexec/check-container ; do
|
|
||||||
sleep 1
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# assert_runtime_option option value
|
|
||||||
# ----------------------------------
|
|
||||||
assert_runtime_option ()
|
|
||||||
{
|
|
||||||
local name=$1 option=$2 value=$3
|
|
||||||
wait_ready "$name"
|
|
||||||
set -- $(docker exec "$(get_cid "$name")" bash -c "psql -tA -c 'SHOW $option;'")
|
|
||||||
test "$value" = "$1"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
function run_configuration_tests() {
|
|
||||||
local name=$1 ; shift
|
|
||||||
echo " Testing image configuration settings"
|
|
||||||
test_config_option ${name} max_connections ${POSTGRESQL_MAX_CONNECTIONS}
|
|
||||||
test_config_option ${name} max_prepared_transactions ${POSTGRESQL_MAX_PREPARED_TRANSACTIONS}
|
|
||||||
test_config_option ${name} shared_buffers ${POSTGRESQL_SHARED_BUFFERS}
|
|
||||||
echo " Success!"
|
|
||||||
}
|
|
||||||
|
|
||||||
test_scl_usage() {
|
|
||||||
local name="$1"
|
|
||||||
local run_cmd="$2"
|
|
||||||
local expected="$3"
|
|
||||||
|
|
||||||
echo " Testing the image SCL enable"
|
|
||||||
out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${run_cmd}")
|
|
||||||
if ! echo "${out}" | grep -q "${expected}"; then
|
|
||||||
echo "ERROR[/bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
out=$(docker exec $(get_cid $name) /bin/bash -c "${run_cmd}" 2>&1)
|
|
||||||
if ! echo "${out}" | grep -q "${expected}"; then
|
|
||||||
echo "ERROR[exec /bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
out=$(docker exec $(get_cid $name) /bin/sh -ic "${run_cmd}" 2>&1)
|
|
||||||
if ! echo "${out}" | grep -q "${expected}"; then
|
|
||||||
echo "ERROR[exec /bin/sh -ic "${run_cmd}"] Expected '${expected}', got '${out}'"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
function run_tests() {
|
|
||||||
echo " Testing general usage (run_tests) with '$1' as argument"
|
|
||||||
local name=$1 ; shift
|
|
||||||
|
|
||||||
user_login=false
|
|
||||||
admin_login=false
|
|
||||||
envs=
|
|
||||||
# NOTE: We work wrongly with variables so please don't try to pass spaces
|
|
||||||
# within PGUSER/PASS/ADMIN_PASS variables.
|
|
||||||
[ -v PGUSER ] && envs+=" -e POSTGRESQL_USER=$PGUSER"
|
|
||||||
[ -v PASS ] && envs+=" -e POSTGRESQL_PASSWORD=$PASS"
|
|
||||||
if [ -v PGUSER ] && [ -v PASS ]; then
|
|
||||||
envs+=" -e POSTGRESQL_DATABASE=db"
|
|
||||||
user_login=:
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -v ADMIN_PASS ]; then
|
|
||||||
envs="$envs -e POSTGRESQL_ADMIN_PASSWORD=$ADMIN_PASS"
|
|
||||||
admin_login=:
|
|
||||||
fi
|
|
||||||
if [ -v POSTGRESQL_MAX_CONNECTIONS ]; then
|
|
||||||
envs="$envs -e POSTGRESQL_MAX_CONNECTIONS=$POSTGRESQL_MAX_CONNECTIONS"
|
|
||||||
fi
|
|
||||||
if [ -v POSTGRESQL_MAX_PREPARED_TRANSACTIONS ]; then
|
|
||||||
envs="$envs -e POSTGRESQL_MAX_PREPARED_TRANSACTIONS=$POSTGRESQL_MAX_PREPARED_TRANSACTIONS"
|
|
||||||
fi
|
|
||||||
if [ -v POSTGRESQL_SHARED_BUFFERS ]; then
|
|
||||||
envs="$envs -e POSTGRESQL_SHARED_BUFFERS=$POSTGRESQL_SHARED_BUFFERS"
|
|
||||||
fi
|
|
||||||
DOCKER_ARGS="${DOCKER_ARGS:-} $envs" create_container $name
|
|
||||||
CONTAINER_IP=$(get_container_ip $name)
|
|
||||||
test_connection $name
|
|
||||||
echo " Testing scl usage"
|
|
||||||
test_scl_usage $name 'psql --version' "$VERSION"
|
|
||||||
|
|
||||||
echo " Testing login accesses"
|
|
||||||
assert_login_access "${PGUSER:-}" "${PASS-}" "$user_login"
|
|
||||||
assert_login_access "${PGUSER:-}" "${PASS-}_foo" false
|
|
||||||
|
|
||||||
assert_login_access postgres "${ADMIN_PASS-}" "$admin_login"
|
|
||||||
assert_login_access postgres "${ADMIN_PASS-}_foo" false
|
|
||||||
|
|
||||||
assert_local_access $name
|
|
||||||
run_configuration_tests $name
|
|
||||||
echo " Success!"
|
|
||||||
|
|
||||||
if $user_login; then
|
|
||||||
test_postgresql $name
|
|
||||||
fi
|
|
||||||
|
|
||||||
if $admin_login; then
|
|
||||||
DB=postgres PGUSER=postgres PASS=$ADMIN_PASS test_postgresql $name
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_slave() {
|
|
||||||
local suffix="$1"; shift
|
|
||||||
docker run $cluster_args -e POSTGRESQL_MASTER_IP=${master_hostname} \
|
|
||||||
-d --cidfile ${CIDFILE_DIR}/slave-${suffix}.cid $IMAGE_NAME run-postgresql-slave
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_master() {
|
|
||||||
local suffix="$1"; shift
|
|
||||||
master_args=${master_args-}
|
|
||||||
docker run $cluster_args $master_args \
|
|
||||||
-d --cidfile ${CIDFILE_DIR}/master-${suffix}.cid $IMAGE_NAME run-postgresql-master >/dev/null
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_slave_visibility() {
|
|
||||||
local max_attempts=30
|
|
||||||
|
|
||||||
for slave in $slave_cids; do
|
|
||||||
slave_ip=$(get_ip_from_cid $slave)
|
|
||||||
if [ -z "$slave_ip" ]; then
|
|
||||||
echo "Failed to get IP for slave $slave."
|
|
||||||
echo "Dumping logs for $slave"
|
|
||||||
docker logs "$slave"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
for i in $(seq $max_attempts); do
|
|
||||||
result="$(postgresql_cmd -c "select client_addr from pg_stat_replication;" | grep "$slave_ip" || true)"
|
|
||||||
if [[ -n "${result}" ]]; then
|
|
||||||
echo "${slave_ip} successfully registered as SLAVE for ${master_ip}"
|
|
||||||
break
|
|
||||||
fi
|
|
||||||
if [[ "${i}" == "${max_attempts}" ]]; then
|
|
||||||
echo "The ${slave_ip} failed to register in MASTER"
|
|
||||||
echo "Dumping logs for $slave"
|
|
||||||
docker logs $slave
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
sleep 1
|
|
||||||
done
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_value_replication() {
|
|
||||||
local max_attempts=30
|
|
||||||
|
|
||||||
# Setup the replication data
|
|
||||||
local value
|
|
||||||
value=24
|
|
||||||
postgresql_cmd -c "CREATE TABLE $table_name (a integer); INSERT INTO $table_name VALUES ($value);"
|
|
||||||
|
|
||||||
# Read value from slaves and check whether it is expected
|
|
||||||
for slave in $slave_cids; do
|
|
||||||
slave_ip=$(get_ip_from_cid $slave)
|
|
||||||
CONTAINER_IP=$slave_ip
|
|
||||||
for i in $(seq $max_attempts); do
|
|
||||||
result="$(postgresql_cmd -At -c "select * from $table_name" || :)"
|
|
||||||
if [[ "$result" == "$value" ]]; then
|
|
||||||
echo "${slave_ip} successfully got value from MASTER ${master_ip}"
|
|
||||||
break
|
|
||||||
fi
|
|
||||||
if [[ "${i}" == "${max_attempts}" ]]; then
|
|
||||||
echo "The ${slave_ip} failed to see value added on MASTER"
|
|
||||||
echo "Dumping logs for $slave"
|
|
||||||
docker logs $slave
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
sleep 1
|
|
||||||
done
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
function setup_replication_cluster() {
|
|
||||||
# Run the PostgreSQL master
|
|
||||||
run_master "$cid_suffix"
|
|
||||||
|
|
||||||
# Run the PostgreSQL slaves
|
|
||||||
local i
|
|
||||||
master_ip=$(get_container_ip "master-$cid_suffix.cid")
|
|
||||||
local cluster_args="$cluster_args --add-host postgresql-master:$master_ip"
|
|
||||||
local master_hostname="postgresql-master"
|
|
||||||
for i in $(seq ${slave_num:-1}); do
|
|
||||||
slave_cids="$slave_cids $(run_slave $cid_suffix-$i)"
|
|
||||||
done
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_master_restart_test() {
|
|
||||||
local DB=postgres
|
|
||||||
local PGUSER=master
|
|
||||||
local PASS=master
|
|
||||||
|
|
||||||
echo "Testing failed master restart"
|
|
||||||
local cluster_args="-e POSTGRESQL_ADMIN_PASSWORD=pass -e POSTGRESQL_MASTER_USER=$PGUSER -e POSTGRESQL_MASTER_PASSWORD=$PASS"
|
|
||||||
local cid_suffix="mrestart"
|
|
||||||
local table_name="t1"
|
|
||||||
local master_ip=
|
|
||||||
local slave_cids=
|
|
||||||
|
|
||||||
create_volume_dir
|
|
||||||
local master_args="-v ${volume_dir}:/var/lib/pgsql/data:Z"
|
|
||||||
|
|
||||||
# Setup the cluster
|
|
||||||
slave_num=2 setup_replication_cluster
|
|
||||||
|
|
||||||
# Check if the master knows about the slaves
|
|
||||||
CONTAINER_IP=$master_ip
|
|
||||||
test_slave_visibility
|
|
||||||
|
|
||||||
echo "Kill the master and create a new one"
|
|
||||||
local cidfile=$CIDFILE_DIR/master-$cid_suffix.cid
|
|
||||||
docker kill $(cat $cidfile)
|
|
||||||
# Don't forget to remove its .cid file
|
|
||||||
rm $cidfile
|
|
||||||
|
|
||||||
run_master $cid_suffix
|
|
||||||
CONTAINER_IP=$(get_container_ip master-$cid_suffix.cid)
|
|
||||||
|
|
||||||
# Update master_ip in slaves
|
|
||||||
for slave in $slave_cids; do
|
|
||||||
docker exec -u 0 $slave bash -c "sed \"s/$master_ip/$CONTAINER_IP/g\" /etc/hosts >/tmp/hosts && cp /tmp/hosts /etc/hosts"
|
|
||||||
done
|
|
||||||
master_ip=$CONTAINER_IP
|
|
||||||
# Check if the new master sees existing slaves
|
|
||||||
test_slave_visibility
|
|
||||||
|
|
||||||
# Check if the replication works
|
|
||||||
table_name="t1" test_value_replication
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_replication_test() {
|
|
||||||
local DB=postgres
|
|
||||||
local PGUSER=master
|
|
||||||
local PASS=master
|
|
||||||
|
|
||||||
echo "Testing master-slave replication"
|
|
||||||
local cluster_args="-e POSTGRESQL_ADMIN_PASSWORD=pass -e POSTGRESQL_MASTER_USER=$PGUSER -e POSTGRESQL_MASTER_PASSWORD=$PASS"
|
|
||||||
local cid_suffix="basic"
|
|
||||||
local master_ip=
|
|
||||||
local slave_cids=
|
|
||||||
|
|
||||||
# Setup the cluster
|
|
||||||
setup_replication_cluster
|
|
||||||
|
|
||||||
# Check if the master knows about the slaves
|
|
||||||
CONTAINER_IP=$master_ip
|
|
||||||
test_slave_visibility
|
|
||||||
|
|
||||||
# Do some real work to test replication in practice
|
|
||||||
table_name="t1" test_value_replication
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_change_password_test() {
|
|
||||||
echo " Testing password change"
|
|
||||||
local name="change_password"
|
|
||||||
|
|
||||||
local database='db'
|
|
||||||
local user='user'
|
|
||||||
local password='password'
|
|
||||||
local admin_password='adminPassword'
|
|
||||||
|
|
||||||
create_volume_dir
|
|
||||||
local volume_options="-v ${volume_dir}:/var/lib/pgsql/data:Z"
|
|
||||||
|
|
||||||
DOCKER_ARGS="
|
|
||||||
-e POSTGRESQL_DATABASE=${database}
|
|
||||||
-e POSTGRESQL_USER=${user}
|
|
||||||
-e POSTGRESQL_PASSWORD=${password}
|
|
||||||
-e POSTGRESQL_ADMIN_PASSWORD=${admin_password}
|
|
||||||
$volume_options
|
|
||||||
" create_container ${name}
|
|
||||||
|
|
||||||
# need to set these because `postgresql_cmd` relies on global variables
|
|
||||||
PGUSER=${user}
|
|
||||||
PASS=${password}
|
|
||||||
|
|
||||||
# need this to wait for the container to start up
|
|
||||||
CONTAINER_IP=$(get_container_ip ${name})
|
|
||||||
test_connection ${name}
|
|
||||||
|
|
||||||
echo " Testing login"
|
|
||||||
|
|
||||||
assert_login_access ${user} ${password} true
|
|
||||||
assert_login_access 'postgres' ${admin_password} true
|
|
||||||
|
|
||||||
echo " Changing passwords"
|
|
||||||
|
|
||||||
docker stop $(get_cid ${name})
|
|
||||||
DOCKER_ARGS="
|
|
||||||
-e POSTGRESQL_DATABASE=${database}
|
|
||||||
-e POSTGRESQL_USER=${user}
|
|
||||||
-e POSTGRESQL_PASSWORD=NEW_${password}
|
|
||||||
-e POSTGRESQL_ADMIN_PASSWORD=NEW_${admin_password}
|
|
||||||
$volume_options
|
|
||||||
" create_container "${name}_NEW"
|
|
||||||
|
|
||||||
# need to set this because `postgresql_cmd` relies on global variables
|
|
||||||
PASS="NEW_${password}"
|
|
||||||
|
|
||||||
# need this to wait for the container to start up
|
|
||||||
CONTAINER_IP=$(get_container_ip "${name}_NEW")
|
|
||||||
test_connection "${name}_NEW"
|
|
||||||
|
|
||||||
echo " Testing login with new passwords"
|
|
||||||
|
|
||||||
assert_login_access ${user} "NEW_${password}" true
|
|
||||||
assert_login_access ${user} ${password} false
|
|
||||||
|
|
||||||
assert_login_access 'postgres' "NEW_${admin_password}" true
|
|
||||||
assert_login_access 'postgres' ${admin_password} false
|
|
||||||
|
|
||||||
echo " Success!"
|
|
||||||
}
|
|
||||||
|
|
||||||
run_upgrade_test ()
|
|
||||||
{
|
|
||||||
# Do not run on Fedora or RHEL8 until the upgrade script
|
|
||||||
# is fixed for non-SCL use cases
|
|
||||||
{ [ "${OS}" == "fedora" ] || [ "${OS}" == "rhel8" ]; } && return 0
|
|
||||||
|
|
||||||
local upgrade_path="none 9.2 9.4 9.5 9.6 10 12 none" prev= act=
|
|
||||||
for act in $upgrade_path; do
|
|
||||||
if test "$act" = $VERSION; then
|
|
||||||
break
|
|
||||||
fi
|
|
||||||
prev=$act
|
|
||||||
done
|
|
||||||
test "$prev" != none
|
|
||||||
# Check if the previous image is available in the registry
|
|
||||||
docker pull "$(get_image_id "$prev:remote")" || return 0
|
|
||||||
|
|
||||||
# TODO: We run this script from $VERSION directory, through test/run symlink.
|
|
||||||
test/run_upgrade_test "$prev:remote" "$VERSION:local"
|
|
||||||
}
|
|
||||||
|
|
||||||
run_migration_test ()
|
|
||||||
{
|
|
||||||
[ "${OS}" == "fedora" ] && return 0
|
|
||||||
|
|
||||||
local from_version
|
|
||||||
# Only test a subset of the migration path on non-intel hosts
|
|
||||||
if [ "$(uname -i)" == "x86_64" ]; then
|
|
||||||
local upgrade_path="9.2 9.4 9.5 9.6 10 12"
|
|
||||||
else
|
|
||||||
local upgrade_path="10 12"
|
|
||||||
fi
|
|
||||||
|
|
||||||
for from_version in $upgrade_path; do
|
|
||||||
# Do not test migration from $VERSION:remote to $VERSION:local
|
|
||||||
test $(version2number $from_version) -lt $(version2number "$VERSION") \
|
|
||||||
|| break
|
|
||||||
# Skip if the previous image is not available in the registry
|
|
||||||
docker pull "$(get_image_id "$from_version:remote")" || continue
|
|
||||||
test/run_migration_test $from_version:remote $VERSION:local
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
run_doc_test() {
|
|
||||||
local tmpdir=$(mktemp -d)
|
|
||||||
local f
|
|
||||||
echo " Testing documentation in the container image"
|
|
||||||
# Extract the help files from the container
|
|
||||||
for f in help.1 ; do
|
|
||||||
docker run --rm ${IMAGE_NAME} /bin/bash -c "cat /${f}" >${tmpdir}/$(basename ${f})
|
|
||||||
# Check whether the files include some important information
|
|
||||||
for term in "POSTGRESQL\_ADMIN\_PASSWORD" volume 5432 ; do
|
|
||||||
if ! cat ${tmpdir}/$(basename ${f}) | grep -F -q -e "${term}" ; then
|
|
||||||
echo "ERROR: File /${f} does not include '${term}'."
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
done
|
|
||||||
# Check whether the files use the correct format
|
|
||||||
if ! file ${tmpdir}/help.1 | grep -q roff ; then
|
|
||||||
echo "ERROR: /help.1 is not in troff or groff format"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
echo " Success!"
|
|
||||||
echo
|
|
||||||
}
|
|
||||||
|
|
||||||
test_the_app_image () {
|
|
||||||
local container_name=$1
|
|
||||||
local mount_opts=$2
|
|
||||||
echo " Testing s2i app image with invalid configuration"
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db
|
|
||||||
echo " Testing s2i app image with correct configuration"
|
|
||||||
|
|
||||||
DOCKER_ARGS="
|
|
||||||
-e POSTGRESQL_DATABASE=db
|
|
||||||
-e POSTGRESQL_USER=user
|
|
||||||
-e POSTGRESQL_PASSWORD=password
|
|
||||||
-e POSTGRESQL_ADMIN_PASSWORD=password
|
|
||||||
-e POSTGRESQL_BACKUP_USER=backuser
|
|
||||||
-e POSTGRESQL_BACKUP_PASSWORD=pass
|
|
||||||
${mount_opts}
|
|
||||||
" create_container "$container_name"
|
|
||||||
|
|
||||||
# need this to wait for the container to start up
|
|
||||||
PGUSER=user PASS=password test_connection "$container_name"
|
|
||||||
PGUSER=backuser PASS=pass DB=backup test_connection "$container_name"
|
|
||||||
|
|
||||||
docker stop "$(get_cid $container_name)" >/dev/null
|
|
||||||
}
|
|
||||||
|
|
||||||
run_s2i_test() {
|
|
||||||
local temp_file
|
|
||||||
echo " Testing s2i usage"
|
|
||||||
ct_s2i_usage "${IMAGE_NAME}" --pull-policy=never 1>/dev/null
|
|
||||||
|
|
||||||
echo " Testing s2i build"
|
|
||||||
|
|
||||||
local s2i_image_name=$IMAGE_NAME-testapp_$(ct_random_string)
|
|
||||||
images_to_clean+=( "$s2i_image_name" )
|
|
||||||
|
|
||||||
ct_s2i_build_as_df "file://${test_dir}/test-app" "${IMAGE_NAME}" "$s2i_image_name" 1>/dev/null
|
|
||||||
IMAGE_NAME=$s2i_image_name test_the_app_image s2i_config_build ""
|
|
||||||
|
|
||||||
echo " Testing s2i mount"
|
|
||||||
create_temp_file
|
|
||||||
cat "$test_dir"/test-app/postgresql-init/backup_user.sh >> "$temp_file"
|
|
||||||
|
|
||||||
# Test against original image, not the s2i one. But even if so, we expect
|
|
||||||
# user mouns the directory under "s2i" direcetory $APP_DATA/src.
|
|
||||||
local mount_point=/opt/app-root/src/postgresql-init/add_backup_user.sh
|
|
||||||
test_the_app_image _s2i_test_mount "-v ${temp_file}:$mount_point:z,ro"
|
|
||||||
echo " Success!"
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_general_tests() {
|
|
||||||
PGUSER=user PASS=pass POSTGRESQL_MAX_CONNECTIONS=42 POSTGRESQL_MAX_PREPARED_TRANSACTIONS=42 POSTGRESQL_SHARED_BUFFERS=64MB run_tests no_admin
|
|
||||||
PGUSER=user1 PASS=pass1 ADMIN_PASS=r00t run_tests admin
|
|
||||||
DB=postgres ADMIN_PASS=r00t run_tests only_admin
|
|
||||||
# Test with arbitrary uid for the container
|
|
||||||
DOCKER_ARGS="-u 12345" PGUSER=user2 PASS=pass run_tests no_admin_altuid
|
|
||||||
DOCKER_ARGS="-u 12345" PGUSER=user3 PASS=pass1 ADMIN_PASS=r00t run_tests admin_altuid
|
|
||||||
DB=postgres DOCKER_ARGS="-u 12345" ADMIN_PASS=rOOt run_tests only_admin_altuid
|
|
||||||
}
|
|
||||||
|
|
||||||
run_test_cfg_hook()
|
|
||||||
{
|
|
||||||
local volume_dir name=pg-test-cfg-dir
|
|
||||||
volume_dir=$(mktemp -d --tmpdir pg-hook-volume.XXXXX)
|
|
||||||
add_cleanup_command /bin/rm -rf "$volume_dir"
|
|
||||||
setfacl -R -m u:26:rwx "$volume_dir"
|
|
||||||
cp -r "$test_dir"/examples/custom-config/* "$volume_dir"
|
|
||||||
setfacl -R -m u:26:rwx "$volume_dir"
|
|
||||||
|
|
||||||
DOCKER_ARGS="
|
|
||||||
-e POSTGRESQL_ADMIN_PASSWORD=password
|
|
||||||
-v $volume_dir:/opt/app-root/src:Z
|
|
||||||
" create_container "$name"
|
|
||||||
assert_runtime_option "$name" shared_buffers 111MB
|
|
||||||
|
|
||||||
# Check that POSTGRESQL_SHARED_BUFFERS has effect.
|
|
||||||
DOCKER_ARGS="
|
|
||||||
-e POSTGRESQL_ADMIN_PASSWORD=password
|
|
||||||
-e POSTGRESQL_SHARED_BUFFERS=113MB
|
|
||||||
" create_container "$name-2"
|
|
||||||
assert_runtime_option "$name-2" shared_buffers 113MB
|
|
||||||
|
|
||||||
# Check that volume has priority over POSTGRESQL_SHARED_BUFFERS.
|
|
||||||
DOCKER_ARGS="
|
|
||||||
-e POSTGRESQL_ADMIN_PASSWORD=password
|
|
||||||
-e POSTGRESQL_SHARED_BUFFERS=113MB
|
|
||||||
-v $volume_dir:/opt/app-root/src:Z
|
|
||||||
" create_container "$name-3"
|
|
||||||
assert_runtime_option "$name-3" shared_buffers 111MB
|
|
||||||
}
|
|
||||||
|
|
||||||
run_s2i_enable_ssl_test()
|
|
||||||
{
|
|
||||||
local s2i_image_name="$IMAGE_NAME-ssl_$(ct_random_string)"
|
|
||||||
ct_s2i_build_as_df "file://$test_dir/examples/enable-ssl" "${IMAGE_NAME}" "$s2i_image_name" 1>/dev/null
|
|
||||||
images_to_clean+=( "$s2i_image_name" )
|
|
||||||
|
|
||||||
local container_name=enable-ssl-test
|
|
||||||
|
|
||||||
DOCKER_ARGS="-e POSTGRESQL_ADMIN_PASSWORD=password" \
|
|
||||||
IMAGE_NAME="$s2i_image_name" create_container "$container_name"
|
|
||||||
|
|
||||||
wait_ready "$container_name"
|
|
||||||
CONTAINER_IP=$(get_container_ip $container_name)
|
|
||||||
|
|
||||||
DB=postgres assert_login_access postgres password true
|
|
||||||
|
|
||||||
docker run --rm -e PGPASSWORD="password" "$IMAGE_NAME" psql "postgresql://postgres@$CONTAINER_IP:5432/postgres?sslmode=require" || \
|
|
||||||
false "FAIL: Did not manage to connect using SSL only."
|
|
||||||
|
|
||||||
docker stop "$(get_cid "$container_name")"
|
|
||||||
}
|
|
||||||
|
|
||||||
run_s2i_bake_data_test ()
|
|
||||||
{
|
|
||||||
local s2i_image_name="$IMAGE_NAME-bake_$(ct_random_string)"
|
|
||||||
ct_s2i_build_as_df "file://$test_dir/examples/s2i-dump-data" "${IMAGE_NAME}" "$s2i_image_name" 1>/dev/null
|
|
||||||
images_to_clean+=( "$s2i_image_name" )
|
|
||||||
|
|
||||||
local container_name=bake-data-test
|
|
||||||
|
|
||||||
DOCKER_ARGS="-e POSTGRESQL_ADMIN_PASSWORD=password" \
|
|
||||||
IMAGE_NAME="$s2i_image_name" create_container "$container_name"
|
|
||||||
|
|
||||||
wait_ready "$container_name"
|
|
||||||
|
|
||||||
test "hello world" == "$(docker exec "$(get_cid "$container_name")" \
|
|
||||||
bash -c "psql -tA -c 'SELECT * FROM test;'")"
|
|
||||||
|
|
||||||
docker stop "$(get_cid "$container_name")"
|
|
||||||
}
|
|
||||||
|
|
||||||
run_pgaudit_test()
|
|
||||||
{
|
|
||||||
# extension pgaudit is not available for older versions
|
|
||||||
case ${VERSION} in
|
|
||||||
9.6|10|11) echo "pgaudit not expected, test skipped."; return ;;
|
|
||||||
*) ;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
local config_dir data_dir name=pg-test-pgaudit
|
|
||||||
|
|
||||||
# create a dir for config
|
|
||||||
config_dir=$(mktemp -d --tmpdir pg-hook-volume.XXXXX)
|
|
||||||
add_cleanup_command /bin/rm -rf "$config_dir"
|
|
||||||
cp -r "$test_dir"/examples/pgaudit/* "$config_dir"
|
|
||||||
setfacl -R -m u:26:rwx "$config_dir"
|
|
||||||
|
|
||||||
# create a dir for data
|
|
||||||
create_volume_dir
|
|
||||||
data_dir="${volume_dir}"
|
|
||||||
|
|
||||||
DOCKER_ARGS="
|
|
||||||
-e POSTGRESQL_ADMIN_PASSWORD=password
|
|
||||||
-v ${config_dir}:/opt/app-root/src:Z
|
|
||||||
-v ${data_dir}:/var/lib/pgsql/data:Z
|
|
||||||
" create_container "$name"
|
|
||||||
|
|
||||||
assert_runtime_option "$name" shared_preload_libraries pgaudit
|
|
||||||
wait_ready "$name"
|
|
||||||
|
|
||||||
# enable the pgaudit extension
|
|
||||||
# Deliberately moving heredoc into the container, otherwise it does not work
|
|
||||||
# in podman 1.6.x due to https://bugzilla.redhat.com/show_bug.cgi?id=1827324
|
|
||||||
docker exec -i $(get_cid "$name") bash -c "psql <<EOSQL
|
|
||||||
CREATE EXTENSION pgaudit;
|
|
||||||
SET pgaudit.log = 'read, ddl';
|
|
||||||
CREATE DATABASE pgaudittest;
|
|
||||||
EOSQL"
|
|
||||||
|
|
||||||
# simulate some trafic that should be audited
|
|
||||||
docker exec -i $(get_cid "$name") bash -c "psql pgaudittest <<EOSQL
|
|
||||||
SET pgaudit.log = 'read, ddl';
|
|
||||||
CREATE TABLE account (id int, name text, password text, description text);
|
|
||||||
INSERT INTO account (id, name, password, description) VALUES (1, 'user1', 'HASH1', 'blah, blah');
|
|
||||||
SELECT * FROM account;
|
|
||||||
EOSQL"
|
|
||||||
|
|
||||||
# give server some time for write all audit messages
|
|
||||||
sleep 1
|
|
||||||
|
|
||||||
grep -E 'AUDIT: SESSION,.*,.*,DDL,CREATE DATABASE,,,CREATE DATABASE pgaudittest' "${data_dir}"/userdata/log/postgresql-*.log
|
|
||||||
grep -E 'AUDIT: SESSION,.*,.*,READ,SELECT,,,SELECT' "${data_dir}"/userdata/log/postgresql-*.log
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_latest_imagestreams_test() {
|
|
||||||
local result=1
|
|
||||||
# Switch to root directory of a container
|
|
||||||
echo "Testing the latest version in imagestreams"
|
|
||||||
pushd "${test_dir}/.." >/dev/null || return 1
|
|
||||||
ct_check_latest_imagestreams
|
|
||||||
result=$?
|
|
||||||
popd >/dev/null || return 1
|
|
||||||
return $result
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_all_tests() {
|
|
||||||
for test_case in $TEST_LIST; do
|
|
||||||
: "Running test $test_case"
|
|
||||||
$test_case
|
|
||||||
done;
|
|
||||||
}
|
|
||||||
|
|
||||||
# configuration defaults
|
|
||||||
POSTGRESQL_MAX_CONNECTIONS=100
|
|
||||||
POSTGRESQL_MAX_PREPARED_TRANSACTIONS=0
|
|
||||||
POSTGRESQL_SHARED_BUFFERS=32MB
|
|
||||||
|
|
||||||
# Run the chosen tests
|
|
||||||
TEST_LIST=${TESTS:-$TEST_LIST} run_all_tests
|
|
||||||
|
|
||||||
TESTSUITE_RESULT=0
|
|
||||||
echo "All tests passed."
|
|
||||||
|
|
@ -1,847 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
#
|
|
||||||
# Test the PostgreSQL image.
|
|
||||||
#
|
|
||||||
# IMAGE_NAME specifies the name of the candidate image used for testing.
|
|
||||||
# The image has to be available before this script is executed.
|
|
||||||
#
|
|
||||||
|
|
||||||
set -exo nounset
|
|
||||||
shopt -s nullglob
|
|
||||||
|
|
||||||
# library from container-common-scripts
|
|
||||||
. test/test-lib.sh
|
|
||||||
|
|
||||||
# local library
|
|
||||||
. test/pg-test-lib.sh
|
|
||||||
|
|
||||||
TEST_LIST="\
|
|
||||||
run_container_creation_tests
|
|
||||||
run_general_tests
|
|
||||||
run_change_password_test
|
|
||||||
run_replication_test
|
|
||||||
run_master_restart_test
|
|
||||||
run_doc_test
|
|
||||||
run_s2i_test
|
|
||||||
run_test_cfg_hook
|
|
||||||
run_s2i_bake_data_test
|
|
||||||
run_s2i_enable_ssl_test
|
|
||||||
run_upgrade_test
|
|
||||||
run_migration_test
|
|
||||||
"
|
|
||||||
|
|
||||||
test $# -eq 1 -a "${1-}" == --list && echo "$TEST_LIST" && exit 0
|
|
||||||
test -n "${IMAGE_NAME-}" || false 'make sure $IMAGE_NAME is defined'
|
|
||||||
test -n "${VERSION-}" || false 'make sure $VERSION is defined'
|
|
||||||
test -n "${OS-}" || false 'make sure $OS is defined'
|
|
||||||
|
|
||||||
CIDFILE_DIR=$(mktemp --suffix=postgresql_test_cidfiles -d)
|
|
||||||
|
|
||||||
volumes_to_clean=
|
|
||||||
images_to_clean=()
|
|
||||||
files_to_clean=
|
|
||||||
test_dir="$(readlink -f "$(dirname "$0")")"
|
|
||||||
|
|
||||||
_cleanup_commands_space=
|
|
||||||
_cleanup_commands=
|
|
||||||
|
|
||||||
add_cleanup_command ()
|
|
||||||
{
|
|
||||||
local cmd= space=
|
|
||||||
for arg; do
|
|
||||||
cmd+="$space$(printf "%q" "$arg")"
|
|
||||||
space=' '
|
|
||||||
done
|
|
||||||
_cleanup_commands+="$_cleanup_commands_space$cmd"
|
|
||||||
_cleanup_commands_space='
|
|
||||||
'
|
|
||||||
}
|
|
||||||
function cleanup() {
|
|
||||||
for cidfile in $CIDFILE_DIR/* ; do
|
|
||||||
CONTAINER=$(cat $cidfile)
|
|
||||||
|
|
||||||
echo "Stopping and removing container $CONTAINER..."
|
|
||||||
docker stop $CONTAINER
|
|
||||||
exit_status=$(docker inspect -f '{{.State.ExitCode}}' $CONTAINER)
|
|
||||||
if [ "$exit_status" != "0" ]; then
|
|
||||||
echo "Dumping logs for $CONTAINER"
|
|
||||||
docker logs $CONTAINER
|
|
||||||
fi
|
|
||||||
docker rm $CONTAINER
|
|
||||||
rm $cidfile
|
|
||||||
echo "Done."
|
|
||||||
done
|
|
||||||
rmdir $CIDFILE_DIR
|
|
||||||
|
|
||||||
ct_path_foreach "$volumes_to_clean" cleanup_volume_dir
|
|
||||||
|
|
||||||
if test -n "${images_to_clean-}"; then
|
|
||||||
# Workaround for RHEL 7 bash bug:
|
|
||||||
# https://bugzilla.redhat.com/show_bug.cgi?id=1636393
|
|
||||||
for image in "${images_to_clean[@]}"; do
|
|
||||||
docker rmi -f "$image"
|
|
||||||
done
|
|
||||||
fi
|
|
||||||
|
|
||||||
ct_path_foreach "$files_to_clean" rm
|
|
||||||
|
|
||||||
echo "$_cleanup_commands" | while read -r line; do
|
|
||||||
eval "$line"
|
|
||||||
done
|
|
||||||
}
|
|
||||||
trap cleanup EXIT
|
|
||||||
|
|
||||||
cleanup_volume_dir ()
|
|
||||||
{
|
|
||||||
test ! -d "$1" && : "WARN: cleaned $1 for some reason" && return 0
|
|
||||||
# When we run this test script as non-root (we should?), the PostgreSQL server
|
|
||||||
# within container is still run under 'postgres' user. It means that, taking
|
|
||||||
# into account 0077 umask of PostgreSQL server, we are unable to remove files
|
|
||||||
# created by server. That's why we need to let docker escalate the privileges
|
|
||||||
# again.
|
|
||||||
local datadir=/var/lib/pgsql/data
|
|
||||||
docker run -v "$1:$datadir:Z" --rm "$IMAGE_NAME" /bin/sh -c "/bin/rm -rf $datadir/userdata"
|
|
||||||
rmdir "$1"
|
|
||||||
}
|
|
||||||
|
|
||||||
function get_cid() {
|
|
||||||
local id="$1" ; shift || return 1
|
|
||||||
echo $(cat "$CIDFILE_DIR/$id")
|
|
||||||
}
|
|
||||||
|
|
||||||
function get_container_ip() {
|
|
||||||
local id="$1" ; shift
|
|
||||||
docker inspect --format='{{.NetworkSettings.IPAddress}}' $(get_cid "$id")
|
|
||||||
}
|
|
||||||
|
|
||||||
function get_ip_from_cid() {
|
|
||||||
local cid="$1"; shift
|
|
||||||
docker inspect --format='{{.NetworkSettings.IPAddress}}' $cid
|
|
||||||
}
|
|
||||||
|
|
||||||
function postgresql_cmd() {
|
|
||||||
docker run --rm -e PGPASSWORD="$PASS" "$IMAGE_NAME" psql "postgresql://$PGUSER@$CONTAINER_IP:5432/${DB-db}" "$@"
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_connection() {
|
|
||||||
local name=$1 ; shift
|
|
||||||
ip=$(get_container_ip $name)
|
|
||||||
echo " Testing PostgreSQL connection to $ip..."
|
|
||||||
local max_attempts=20
|
|
||||||
local sleep_time=2
|
|
||||||
for i in $(seq $max_attempts); do
|
|
||||||
echo " Trying to connect..."
|
|
||||||
set +e
|
|
||||||
# Don't let the code come here if neither user nor admin is able to
|
|
||||||
# connect.
|
|
||||||
if [ -v PGUSER ] && [ -v PASS ]; then
|
|
||||||
CONTAINER_IP=$ip postgresql_cmd <<< "SELECT 1;"
|
|
||||||
else
|
|
||||||
PGUSER=postgres PASS=$ADMIN_PASS CONTAINER_IP=$ip DB=postgres postgresql_cmd <<< "SELECT 1;"
|
|
||||||
fi
|
|
||||||
status=$?
|
|
||||||
set -e
|
|
||||||
if [ $status -eq 0 ]; then
|
|
||||||
echo " Success!"
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
sleep $sleep_time
|
|
||||||
done
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_postgresql() {
|
|
||||||
echo " Testing PostgreSQL"
|
|
||||||
postgresql_cmd <<< "CREATE EXTENSION 'uuid-ossp';" # to test contrib package
|
|
||||||
postgresql_cmd <<< "CREATE TABLE tbl (col1 VARCHAR(20), col2 VARCHAR(20));"
|
|
||||||
postgresql_cmd <<< "INSERT INTO tbl VALUES ('foo1', 'bar1');"
|
|
||||||
postgresql_cmd <<< "INSERT INTO tbl VALUES ('foo2', 'bar2');"
|
|
||||||
postgresql_cmd <<< "INSERT INTO tbl VALUES ('foo3', 'bar3');"
|
|
||||||
postgresql_cmd <<< "SELECT * FROM tbl;"
|
|
||||||
#postgresql_cmd <<< "DROP TABLE tbl;"
|
|
||||||
echo " Success!"
|
|
||||||
}
|
|
||||||
|
|
||||||
function create_container() {
|
|
||||||
local name=$1 ; shift
|
|
||||||
local cargs=${DOCKER_ARGS:-}
|
|
||||||
# TODO: fix all create_container() invocations so that we don't need this,
|
|
||||||
# e.g. multiline DOCKER_ARGS var should end by trailing backslashes
|
|
||||||
cargs=$(echo "$cargs" | tr '\n' ' ')
|
|
||||||
cidfile="$CIDFILE_DIR/$name"
|
|
||||||
# create container with a cidfile in a directory for cleanup
|
|
||||||
eval "docker run $cargs --cidfile \$cidfile -d \$IMAGE_NAME \"\$@\""
|
|
||||||
echo "Created container $(cat $cidfile)"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
create_volume_dir ()
|
|
||||||
{
|
|
||||||
volume_dir=`mktemp -d --tmpdir pg-testdata.XXXXX`
|
|
||||||
setfacl -m u:26:-wx "$volume_dir"
|
|
||||||
ct_path_append volumes_to_clean "$volume_dir"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
create_temp_file ()
|
|
||||||
{
|
|
||||||
temp_file=`mktemp --tmpdir pg-testfile.XXXXX`
|
|
||||||
setfacl -m u:26:rw- "$temp_file"
|
|
||||||
ct_path_append files_to_clean "$temp_file"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
function assert_login_access() {
|
|
||||||
local PGUSER=$1 ; shift
|
|
||||||
local PASS=$1 ; shift
|
|
||||||
local success=$1 ; shift
|
|
||||||
|
|
||||||
echo "testing login as $PGUSER:$PASS; should_success=$success"
|
|
||||||
|
|
||||||
if postgresql_cmd <<<'SELECT 1;' ; then
|
|
||||||
if $success ; then
|
|
||||||
echo " $PGUSER($PASS) access granted as expected"
|
|
||||||
return
|
|
||||||
fi
|
|
||||||
else
|
|
||||||
if ! $success ; then
|
|
||||||
echo " $PGUSER($PASS) access denied as expected"
|
|
||||||
return
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
echo " $PGUSER($PASS) login assertion failed"
|
|
||||||
exit 1
|
|
||||||
}
|
|
||||||
|
|
||||||
function assert_local_access() {
|
|
||||||
local id="$1" ; shift
|
|
||||||
docker exec -i $(get_cid "$id") bash -c psql <<< "SELECT 1;"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# Make sure the invocation of docker run fails.
|
|
||||||
function assert_container_creation_fails() {
|
|
||||||
|
|
||||||
# Time the docker run command. It should fail. If it doesn't fail,
|
|
||||||
# postgresql will keep running so we kill it with SIGKILL to make sure
|
|
||||||
# timeout returns a non-zero value.
|
|
||||||
set +e
|
|
||||||
timeout -s 9 --preserve-status 60s docker run --rm "$@" $IMAGE_NAME
|
|
||||||
ret=$?
|
|
||||||
set -e
|
|
||||||
|
|
||||||
# Timeout will exit with a high number.
|
|
||||||
if [ $ret -gt 30 ]; then
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# assert_container_creation_succeeds NAME [ARGS]
|
|
||||||
# ----------------------------------------------
|
|
||||||
# Chcek that 'docker run' with IMAGE_NAME succeeds with docker arguments
|
|
||||||
# specified as ARGS.
|
|
||||||
assert_container_creation_succeeds ()
|
|
||||||
{
|
|
||||||
local check_env=false
|
|
||||||
local name=pg-success-"$(ct_random_string)"
|
|
||||||
local PGUSER='' PGPASS='' DB='' ADMIN_PASS=
|
|
||||||
local docker_args=
|
|
||||||
|
|
||||||
for arg; do
|
|
||||||
docker_args+=" $(printf "%q" "$arg")"
|
|
||||||
if $check_env; then
|
|
||||||
local env=${arg//=*/}
|
|
||||||
local val=${arg//$env=/}
|
|
||||||
case $env in
|
|
||||||
POSTGRESQL_ADMIN_PASSWORD) ADMIN_PASS=$val ;;
|
|
||||||
POSTGRESQL_USER) PGUSER=$val ;;
|
|
||||||
POSTGRESQL_PASSWORD) PGPASS=$val ;;
|
|
||||||
POSTGRESQL_DATABASE) DB=$val ;;
|
|
||||||
esac
|
|
||||||
check_env=false
|
|
||||||
elif test "$arg" = -e; then
|
|
||||||
check_env=:
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
|
|
||||||
DOCKER_ARGS=$docker_args create_container "$name"
|
|
||||||
|
|
||||||
if test -n "$PGUSER" && test -n "$PGPASS"; then
|
|
||||||
PGUSER=$PGUSER PASS=$PGPASS DB=$DB test_connection "$name"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if test -n "$ADMIN_PASS"; then
|
|
||||||
PGUSER=postgres PASS=$ADMIN_PASS DB=$DB test_connection "$name"
|
|
||||||
fi
|
|
||||||
|
|
||||||
docker stop "$(get_cid "$name")"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
function try_image_invalid_combinations() {
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass "$@"
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_USER=user -e POSTGRESQL_DATABASE=db "$@"
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db "$@"
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_container_creation_tests() {
|
|
||||||
echo " Testing image entrypoint usage"
|
|
||||||
try_image_invalid_combinations
|
|
||||||
try_image_invalid_combinations -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
|
|
||||||
|
|
||||||
VERY_LONG_IDENTIFIER="very_long_identifier_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_USER= -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_USER=$VERY_LONG_IDENTIFIER -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
|
|
||||||
assert_container_creation_succeeds -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD="\"" -e POSTGRESQL_DATABASE=db -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
|
|
||||||
assert_container_creation_succeeds -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=9invalid -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=$VERY_LONG_IDENTIFIER -e POSTGRESQL_ADMIN_PASSWORD=admin_pass
|
|
||||||
assert_container_creation_succeeds -e POSTGRESQL_USER=user -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db -e POSTGRESQL_ADMIN_PASSWORD="\""
|
|
||||||
echo " Success!"
|
|
||||||
|
|
||||||
assert_container_creation_succeeds -e POSTGRESQL_ADMIN_PASSWORD="the @password"
|
|
||||||
assert_container_creation_succeeds -e POSTGRESQL_PASSWORD="the pass" -e POSTGRESQL_USER="the user" -e POSTGRESQL_DATABASE="the db"
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_config_option() {
|
|
||||||
local name=$1 ; shift
|
|
||||||
local setting=$1 ; shift
|
|
||||||
local value=$1 ; shift
|
|
||||||
|
|
||||||
docker exec $(get_cid ${name}) grep -q "${setting} = ${value}" /var/lib/pgsql/openshift-custom-postgresql.conf
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# wait_ready
|
|
||||||
# ----------
|
|
||||||
# Wait until the PG container becomes ready
|
|
||||||
wait_ready ()
|
|
||||||
{
|
|
||||||
while ! docker exec "$(get_cid "$1")" /usr/libexec/check-container ; do
|
|
||||||
sleep 1
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# assert_runtime_option option value
|
|
||||||
# ----------------------------------
|
|
||||||
assert_runtime_option ()
|
|
||||||
{
|
|
||||||
local name=$1 option=$2 value=$3
|
|
||||||
wait_ready "$name"
|
|
||||||
set -- $(docker exec "$(get_cid "$name")" bash -c "psql -tA -c 'SHOW $option;'")
|
|
||||||
test "$value" = "$1"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
function run_configuration_tests() {
|
|
||||||
local name=$1 ; shift
|
|
||||||
echo " Testing image configuration settings"
|
|
||||||
test_config_option ${name} max_connections ${POSTGRESQL_MAX_CONNECTIONS}
|
|
||||||
test_config_option ${name} max_prepared_transactions ${POSTGRESQL_MAX_PREPARED_TRANSACTIONS}
|
|
||||||
test_config_option ${name} shared_buffers ${POSTGRESQL_SHARED_BUFFERS}
|
|
||||||
echo " Success!"
|
|
||||||
}
|
|
||||||
|
|
||||||
test_scl_usage() {
|
|
||||||
local name="$1"
|
|
||||||
local run_cmd="$2"
|
|
||||||
local expected="$3"
|
|
||||||
|
|
||||||
echo " Testing the image SCL enable"
|
|
||||||
out=$(docker run --rm ${IMAGE_NAME} /bin/bash -c "${run_cmd}")
|
|
||||||
if ! echo "${out}" | grep -q "${expected}"; then
|
|
||||||
echo "ERROR[/bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
out=$(docker exec $(get_cid $name) /bin/bash -c "${run_cmd}" 2>&1)
|
|
||||||
if ! echo "${out}" | grep -q "${expected}"; then
|
|
||||||
echo "ERROR[exec /bin/bash -c "${run_cmd}"] Expected '${expected}', got '${out}'"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
out=$(docker exec $(get_cid $name) /bin/sh -ic "${run_cmd}" 2>&1)
|
|
||||||
if ! echo "${out}" | grep -q "${expected}"; then
|
|
||||||
echo "ERROR[exec /bin/sh -ic "${run_cmd}"] Expected '${expected}', got '${out}'"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
function run_tests() {
|
|
||||||
echo " Testing general usage (run_tests) with '$1' as argument"
|
|
||||||
local name=$1 ; shift
|
|
||||||
|
|
||||||
user_login=false
|
|
||||||
admin_login=false
|
|
||||||
envs=
|
|
||||||
# NOTE: We work wrongly with variables so please don't try to pass spaces
|
|
||||||
# within PGUSER/PASS/ADMIN_PASS variables.
|
|
||||||
[ -v PGUSER ] && envs+=" -e POSTGRESQL_USER=$PGUSER"
|
|
||||||
[ -v PASS ] && envs+=" -e POSTGRESQL_PASSWORD=$PASS"
|
|
||||||
if [ -v PGUSER ] && [ -v PASS ]; then
|
|
||||||
envs+=" -e POSTGRESQL_DATABASE=db"
|
|
||||||
user_login=:
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -v ADMIN_PASS ]; then
|
|
||||||
envs="$envs -e POSTGRESQL_ADMIN_PASSWORD=$ADMIN_PASS"
|
|
||||||
admin_login=:
|
|
||||||
fi
|
|
||||||
if [ -v POSTGRESQL_MAX_CONNECTIONS ]; then
|
|
||||||
envs="$envs -e POSTGRESQL_MAX_CONNECTIONS=$POSTGRESQL_MAX_CONNECTIONS"
|
|
||||||
fi
|
|
||||||
if [ -v POSTGRESQL_MAX_PREPARED_TRANSACTIONS ]; then
|
|
||||||
envs="$envs -e POSTGRESQL_MAX_PREPARED_TRANSACTIONS=$POSTGRESQL_MAX_PREPARED_TRANSACTIONS"
|
|
||||||
fi
|
|
||||||
if [ -v POSTGRESQL_SHARED_BUFFERS ]; then
|
|
||||||
envs="$envs -e POSTGRESQL_SHARED_BUFFERS=$POSTGRESQL_SHARED_BUFFERS"
|
|
||||||
fi
|
|
||||||
DOCKER_ARGS="${DOCKER_ARGS:-} $envs" create_container $name
|
|
||||||
CONTAINER_IP=$(get_container_ip $name)
|
|
||||||
test_connection $name
|
|
||||||
echo " Testing scl usage"
|
|
||||||
test_scl_usage $name 'psql --version' "$VERSION"
|
|
||||||
|
|
||||||
echo " Testing login accesses"
|
|
||||||
assert_login_access "${PGUSER:-}" "${PASS-}" "$user_login"
|
|
||||||
assert_login_access "${PGUSER:-}" "${PASS-}_foo" false
|
|
||||||
|
|
||||||
assert_login_access postgres "${ADMIN_PASS-}" "$admin_login"
|
|
||||||
assert_login_access postgres "${ADMIN_PASS-}_foo" false
|
|
||||||
|
|
||||||
assert_local_access $name
|
|
||||||
run_configuration_tests $name
|
|
||||||
echo " Success!"
|
|
||||||
|
|
||||||
if $user_login; then
|
|
||||||
test_postgresql $name
|
|
||||||
fi
|
|
||||||
|
|
||||||
if $admin_login; then
|
|
||||||
DB=postgres PGUSER=postgres PASS=$ADMIN_PASS test_postgresql $name
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_slave() {
|
|
||||||
local suffix="$1"; shift
|
|
||||||
docker run $cluster_args -e POSTGRESQL_MASTER_IP=${master_hostname} \
|
|
||||||
-d --cidfile ${CIDFILE_DIR}/slave-${suffix}.cid $IMAGE_NAME run-postgresql-slave
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_master() {
|
|
||||||
local suffix="$1"; shift
|
|
||||||
master_args=${master_args-}
|
|
||||||
docker run $cluster_args $master_args \
|
|
||||||
-d --cidfile ${CIDFILE_DIR}/master-${suffix}.cid $IMAGE_NAME run-postgresql-master >/dev/null
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_slave_visibility() {
|
|
||||||
local max_attempts=30
|
|
||||||
|
|
||||||
for slave in $slave_cids; do
|
|
||||||
slave_ip=$(get_ip_from_cid $slave)
|
|
||||||
if [ -z "$slave_ip" ]; then
|
|
||||||
echo "Failed to get IP for slave $slave."
|
|
||||||
echo "Dumping logs for $slave"
|
|
||||||
docker logs "$slave"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
for i in $(seq $max_attempts); do
|
|
||||||
result="$(postgresql_cmd -c "select client_addr from pg_stat_replication;" | grep "$slave_ip" || true)"
|
|
||||||
if [[ -n "${result}" ]]; then
|
|
||||||
echo "${slave_ip} successfully registered as SLAVE for ${master_ip}"
|
|
||||||
break
|
|
||||||
fi
|
|
||||||
if [[ "${i}" == "${max_attempts}" ]]; then
|
|
||||||
echo "The ${slave_ip} failed to register in MASTER"
|
|
||||||
echo "Dumping logs for $slave"
|
|
||||||
docker logs $slave
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
sleep 1
|
|
||||||
done
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
function test_value_replication() {
|
|
||||||
local max_attempts=30
|
|
||||||
|
|
||||||
# Setup the replication data
|
|
||||||
local value
|
|
||||||
value=24
|
|
||||||
postgresql_cmd -c "CREATE TABLE $table_name (a integer); INSERT INTO $table_name VALUES ($value);"
|
|
||||||
|
|
||||||
# Read value from slaves and check whether it is expected
|
|
||||||
for slave in $slave_cids; do
|
|
||||||
slave_ip=$(get_ip_from_cid $slave)
|
|
||||||
CONTAINER_IP=$slave_ip
|
|
||||||
for i in $(seq $max_attempts); do
|
|
||||||
result="$(postgresql_cmd -At -c "select * from $table_name" || :)"
|
|
||||||
if [[ "$result" == "$value" ]]; then
|
|
||||||
echo "${slave_ip} successfully got value from MASTER ${master_ip}"
|
|
||||||
break
|
|
||||||
fi
|
|
||||||
if [[ "${i}" == "${max_attempts}" ]]; then
|
|
||||||
echo "The ${slave_ip} failed to see value added on MASTER"
|
|
||||||
echo "Dumping logs for $slave"
|
|
||||||
docker logs $slave
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
sleep 1
|
|
||||||
done
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
function setup_replication_cluster() {
|
|
||||||
# Run the PostgreSQL master
|
|
||||||
run_master "$cid_suffix"
|
|
||||||
|
|
||||||
# Run the PostgreSQL slaves
|
|
||||||
local i
|
|
||||||
master_ip=$(get_container_ip "master-$cid_suffix.cid")
|
|
||||||
local cluster_args="$cluster_args --add-host postgresql-master:$master_ip"
|
|
||||||
local master_hostname="postgresql-master"
|
|
||||||
for i in $(seq ${slave_num:-1}); do
|
|
||||||
slave_cids="$slave_cids $(run_slave $cid_suffix-$i)"
|
|
||||||
done
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_master_restart_test() {
|
|
||||||
local DB=postgres
|
|
||||||
local PGUSER=master
|
|
||||||
local PASS=master
|
|
||||||
|
|
||||||
echo "Testing failed master restart"
|
|
||||||
local cluster_args="-e POSTGRESQL_ADMIN_PASSWORD=pass -e POSTGRESQL_MASTER_USER=$PGUSER -e POSTGRESQL_MASTER_PASSWORD=$PASS"
|
|
||||||
local cid_suffix="mrestart"
|
|
||||||
local table_name="t1"
|
|
||||||
local master_ip=
|
|
||||||
local slave_cids=
|
|
||||||
|
|
||||||
create_volume_dir
|
|
||||||
local master_args="-v ${volume_dir}:/var/lib/pgsql/data:Z"
|
|
||||||
|
|
||||||
# Setup the cluster
|
|
||||||
slave_num=2 setup_replication_cluster
|
|
||||||
|
|
||||||
# Check if the master knows about the slaves
|
|
||||||
CONTAINER_IP=$master_ip
|
|
||||||
test_slave_visibility
|
|
||||||
|
|
||||||
echo "Kill the master and create a new one"
|
|
||||||
local cidfile=$CIDFILE_DIR/master-$cid_suffix.cid
|
|
||||||
docker kill $(cat $cidfile)
|
|
||||||
# Don't forget to remove its .cid file
|
|
||||||
rm $cidfile
|
|
||||||
|
|
||||||
run_master $cid_suffix
|
|
||||||
CONTAINER_IP=$(get_container_ip master-$cid_suffix.cid)
|
|
||||||
|
|
||||||
# Update master_ip in slaves
|
|
||||||
for slave in $slave_cids; do
|
|
||||||
docker exec -u 0 $slave bash -c "sed \"s/$master_ip/$CONTAINER_IP/g\" /etc/hosts >/tmp/hosts && cp /tmp/hosts /etc/hosts"
|
|
||||||
done
|
|
||||||
master_ip=$CONTAINER_IP
|
|
||||||
# Check if the new master sees existing slaves
|
|
||||||
test_slave_visibility
|
|
||||||
|
|
||||||
# Check if the replication works
|
|
||||||
table_name="t1" test_value_replication
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_replication_test() {
|
|
||||||
local DB=postgres
|
|
||||||
local PGUSER=master
|
|
||||||
local PASS=master
|
|
||||||
|
|
||||||
echo "Testing master-slave replication"
|
|
||||||
local cluster_args="-e POSTGRESQL_ADMIN_PASSWORD=pass -e POSTGRESQL_MASTER_USER=$PGUSER -e POSTGRESQL_MASTER_PASSWORD=$PASS"
|
|
||||||
local cid_suffix="basic"
|
|
||||||
local master_ip=
|
|
||||||
local slave_cids=
|
|
||||||
|
|
||||||
# Setup the cluster
|
|
||||||
setup_replication_cluster
|
|
||||||
|
|
||||||
# Check if the master knows about the slaves
|
|
||||||
CONTAINER_IP=$master_ip
|
|
||||||
test_slave_visibility
|
|
||||||
|
|
||||||
# Do some real work to test replication in practice
|
|
||||||
table_name="t1" test_value_replication
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_change_password_test() {
|
|
||||||
echo " Testing password change"
|
|
||||||
local name="change_password"
|
|
||||||
|
|
||||||
local database='db'
|
|
||||||
local user='user'
|
|
||||||
local password='password'
|
|
||||||
local admin_password='adminPassword'
|
|
||||||
|
|
||||||
create_volume_dir
|
|
||||||
local volume_options="-v ${volume_dir}:/var/lib/pgsql/data:Z"
|
|
||||||
|
|
||||||
DOCKER_ARGS="
|
|
||||||
-e POSTGRESQL_DATABASE=${database}
|
|
||||||
-e POSTGRESQL_USER=${user}
|
|
||||||
-e POSTGRESQL_PASSWORD=${password}
|
|
||||||
-e POSTGRESQL_ADMIN_PASSWORD=${admin_password}
|
|
||||||
$volume_options
|
|
||||||
" create_container ${name}
|
|
||||||
|
|
||||||
# need to set these because `postgresql_cmd` relies on global variables
|
|
||||||
PGUSER=${user}
|
|
||||||
PASS=${password}
|
|
||||||
|
|
||||||
# need this to wait for the container to start up
|
|
||||||
CONTAINER_IP=$(get_container_ip ${name})
|
|
||||||
test_connection ${name}
|
|
||||||
|
|
||||||
echo " Testing login"
|
|
||||||
|
|
||||||
assert_login_access ${user} ${password} true
|
|
||||||
assert_login_access 'postgres' ${admin_password} true
|
|
||||||
|
|
||||||
echo " Changing passwords"
|
|
||||||
|
|
||||||
docker stop $(get_cid ${name})
|
|
||||||
DOCKER_ARGS="
|
|
||||||
-e POSTGRESQL_DATABASE=${database}
|
|
||||||
-e POSTGRESQL_USER=${user}
|
|
||||||
-e POSTGRESQL_PASSWORD=NEW_${password}
|
|
||||||
-e POSTGRESQL_ADMIN_PASSWORD=NEW_${admin_password}
|
|
||||||
$volume_options
|
|
||||||
" create_container "${name}_NEW"
|
|
||||||
|
|
||||||
# need to set this because `postgresql_cmd` relies on global variables
|
|
||||||
PASS="NEW_${password}"
|
|
||||||
|
|
||||||
# need this to wait for the container to start up
|
|
||||||
CONTAINER_IP=$(get_container_ip "${name}_NEW")
|
|
||||||
test_connection "${name}_NEW"
|
|
||||||
|
|
||||||
echo " Testing login with new passwords"
|
|
||||||
|
|
||||||
assert_login_access ${user} "NEW_${password}" true
|
|
||||||
assert_login_access ${user} ${password} false
|
|
||||||
|
|
||||||
assert_login_access 'postgres' "NEW_${admin_password}" true
|
|
||||||
assert_login_access 'postgres' ${admin_password} false
|
|
||||||
|
|
||||||
echo " Success!"
|
|
||||||
}
|
|
||||||
|
|
||||||
run_upgrade_test ()
|
|
||||||
{
|
|
||||||
# Do not run on Fedora or RHEL8 until the upgrade script
|
|
||||||
# is fixed for non-SCL use cases
|
|
||||||
{ [ "${OS}" == "fedora" ] || [ "${OS}" == "rhel8" ]; } && return 0
|
|
||||||
|
|
||||||
local upgrade_path="none 9.2 9.4 9.5 9.6 10 none" prev= act=
|
|
||||||
for act in $upgrade_path; do
|
|
||||||
if test "$act" = $VERSION; then
|
|
||||||
break
|
|
||||||
fi
|
|
||||||
prev=$act
|
|
||||||
done
|
|
||||||
test "$prev" != none
|
|
||||||
# Check if the previous image is available in the registry
|
|
||||||
docker pull "$(get_image_id "$prev:remote")" || return 0
|
|
||||||
|
|
||||||
# TODO: We run this script from $VERSION directory, through test/run symlink.
|
|
||||||
test/run_upgrade_test "$prev:remote" "$VERSION:local"
|
|
||||||
}
|
|
||||||
|
|
||||||
run_migration_test ()
|
|
||||||
{
|
|
||||||
[ "${OS}" == "fedora" ] && return 0
|
|
||||||
|
|
||||||
local from_version
|
|
||||||
# Only test a subset of the migration path on non-intel hosts
|
|
||||||
if [ "$(uname -i)" == "x86_64" ]; then
|
|
||||||
local upgrade_path="9.2 9.4 9.5 9.6 10"
|
|
||||||
else
|
|
||||||
local upgrade_path="10"
|
|
||||||
fi
|
|
||||||
|
|
||||||
for from_version in $upgrade_path; do
|
|
||||||
# Do not test migration from $VERSION:remote to $VERSION:local
|
|
||||||
test $(version2number $from_version) -lt $(version2number "$VERSION") \
|
|
||||||
|| break
|
|
||||||
# Skip if the previous image is not available in the registry
|
|
||||||
docker pull "$(get_image_id "$from_version:remote")" || continue
|
|
||||||
test/run_migration_test $from_version:remote $VERSION:local
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
run_doc_test() {
|
|
||||||
local tmpdir=$(mktemp -d)
|
|
||||||
local f
|
|
||||||
echo " Testing documentation in the container image"
|
|
||||||
# Extract the help files from the container
|
|
||||||
for f in help.1 ; do
|
|
||||||
docker run --rm ${IMAGE_NAME} /bin/bash -c "cat /${f}" >${tmpdir}/$(basename ${f})
|
|
||||||
# Check whether the files include some important information
|
|
||||||
for term in "POSTGRESQL\_ADMIN\_PASSWORD" volume 5432 ; do
|
|
||||||
if ! cat ${tmpdir}/$(basename ${f}) | grep -F -q -e "${term}" ; then
|
|
||||||
echo "ERROR: File /${f} does not include '${term}'."
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
done
|
|
||||||
# Check whether the files use the correct format
|
|
||||||
if ! file ${tmpdir}/help.1 | grep -q roff ; then
|
|
||||||
echo "ERROR: /help.1 is not in troff or groff format"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
echo " Success!"
|
|
||||||
echo
|
|
||||||
}
|
|
||||||
|
|
||||||
test_the_app_image () {
|
|
||||||
local container_name=$1
|
|
||||||
local mount_opts=$2
|
|
||||||
echo " Testing s2i app image with invalid configuration"
|
|
||||||
assert_container_creation_fails -e POSTGRESQL_PASSWORD=pass -e POSTGRESQL_DATABASE=db
|
|
||||||
echo " Testing s2i app image with correct configuration"
|
|
||||||
|
|
||||||
DOCKER_ARGS="
|
|
||||||
-e POSTGRESQL_DATABASE=db
|
|
||||||
-e POSTGRESQL_USER=user
|
|
||||||
-e POSTGRESQL_PASSWORD=password
|
|
||||||
-e POSTGRESQL_ADMIN_PASSWORD=password
|
|
||||||
-e POSTGRESQL_BACKUP_USER=backuser
|
|
||||||
-e POSTGRESQL_BACKUP_PASSWORD=pass
|
|
||||||
${mount_opts}
|
|
||||||
" create_container "$container_name"
|
|
||||||
|
|
||||||
# need this to wait for the container to start up
|
|
||||||
PGUSER=user PASS=password test_connection "$container_name"
|
|
||||||
PGUSER=backuser PASS=pass DB=backup test_connection "$container_name"
|
|
||||||
|
|
||||||
docker stop "$(get_cid $container_name)" >/dev/null
|
|
||||||
}
|
|
||||||
|
|
||||||
run_s2i_test() {
|
|
||||||
local temp_file
|
|
||||||
echo " Testing s2i usage"
|
|
||||||
ct_s2i_usage "${IMAGE_NAME}" --pull-policy=never 1>/dev/null
|
|
||||||
|
|
||||||
echo " Testing s2i build"
|
|
||||||
|
|
||||||
local s2i_image_name=$IMAGE_NAME-testapp_$(ct_random_string)
|
|
||||||
images_to_clean+=( "$s2i_image_name" )
|
|
||||||
|
|
||||||
ct_s2i_build_as_df "file://${test_dir}/test-app" "${IMAGE_NAME}" "$s2i_image_name" 1>/dev/null
|
|
||||||
IMAGE_NAME=$s2i_image_name test_the_app_image s2i_config_build ""
|
|
||||||
|
|
||||||
echo " Testing s2i mount"
|
|
||||||
create_temp_file
|
|
||||||
cat "$test_dir"/test-app/postgresql-init/backup_user.sh >> "$temp_file"
|
|
||||||
|
|
||||||
# Test against original image, not the s2i one. But even if so, we expect
|
|
||||||
# user mouns the directory under "s2i" direcetory $APP_DATA/src.
|
|
||||||
local mount_point=/opt/app-root/src/postgresql-init/add_backup_user.sh
|
|
||||||
test_the_app_image _s2i_test_mount "-v ${temp_file}:$mount_point:z,ro"
|
|
||||||
echo " Success!"
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_general_tests() {
|
|
||||||
PGUSER=user PASS=pass POSTGRESQL_MAX_CONNECTIONS=42 POSTGRESQL_MAX_PREPARED_TRANSACTIONS=42 POSTGRESQL_SHARED_BUFFERS=64MB run_tests no_admin
|
|
||||||
PGUSER=user1 PASS=pass1 ADMIN_PASS=r00t run_tests admin
|
|
||||||
DB=postgres ADMIN_PASS=r00t run_tests only_admin
|
|
||||||
# Test with arbitrary uid for the container
|
|
||||||
DOCKER_ARGS="-u 12345" PGUSER=user2 PASS=pass run_tests no_admin_altuid
|
|
||||||
DOCKER_ARGS="-u 12345" PGUSER=user3 PASS=pass1 ADMIN_PASS=r00t run_tests admin_altuid
|
|
||||||
DB=postgres DOCKER_ARGS="-u 12345" ADMIN_PASS=rOOt run_tests only_admin_altuid
|
|
||||||
}
|
|
||||||
|
|
||||||
run_test_cfg_hook()
|
|
||||||
{
|
|
||||||
local volume_dir name=pg-test-cfg-dir
|
|
||||||
volume_dir=$(mktemp -d --tmpdir pg-hook-volume.XXXXX)
|
|
||||||
add_cleanup_command /bin/rm -rf "$volume_dir"
|
|
||||||
setfacl -R -m u:26:rwx "$volume_dir"
|
|
||||||
cp -r "$test_dir"/examples/custom-config/* "$volume_dir"
|
|
||||||
setfacl -R -m u:26:rwx "$volume_dir"
|
|
||||||
|
|
||||||
DOCKER_ARGS="
|
|
||||||
-e POSTGRESQL_ADMIN_PASSWORD=password
|
|
||||||
-v $volume_dir:/opt/app-root/src:Z
|
|
||||||
" create_container "$name"
|
|
||||||
assert_runtime_option "$name" shared_buffers 111MB
|
|
||||||
|
|
||||||
# Check that POSTGRESQL_SHARED_BUFFERS has effect.
|
|
||||||
DOCKER_ARGS="
|
|
||||||
-e POSTGRESQL_ADMIN_PASSWORD=password
|
|
||||||
-e POSTGRESQL_SHARED_BUFFERS=113MB
|
|
||||||
" create_container "$name-2"
|
|
||||||
assert_runtime_option "$name-2" shared_buffers 113MB
|
|
||||||
|
|
||||||
# Check that volume has priority over POSTGRESQL_SHARED_BUFFERS.
|
|
||||||
DOCKER_ARGS="
|
|
||||||
-e POSTGRESQL_ADMIN_PASSWORD=password
|
|
||||||
-e POSTGRESQL_SHARED_BUFFERS=113MB
|
|
||||||
-v $volume_dir:/opt/app-root/src:Z
|
|
||||||
" create_container "$name-3"
|
|
||||||
assert_runtime_option "$name-3" shared_buffers 111MB
|
|
||||||
}
|
|
||||||
|
|
||||||
run_s2i_enable_ssl_test()
|
|
||||||
{
|
|
||||||
local s2i_image_name="$IMAGE_NAME-ssl_$(ct_random_string)"
|
|
||||||
ct_s2i_build_as_df "file://$test_dir/examples/enable-ssl" "${IMAGE_NAME}" "$s2i_image_name" 1>/dev/null
|
|
||||||
images_to_clean+=( "$s2i_image_name" )
|
|
||||||
|
|
||||||
local container_name=enable-ssl-test
|
|
||||||
|
|
||||||
DOCKER_ARGS="-e POSTGRESQL_ADMIN_PASSWORD=password" \
|
|
||||||
IMAGE_NAME="$s2i_image_name" create_container "$container_name"
|
|
||||||
|
|
||||||
wait_ready "$container_name"
|
|
||||||
CONTAINER_IP=$(get_container_ip $container_name)
|
|
||||||
|
|
||||||
DB=postgres assert_login_access postgres password true
|
|
||||||
|
|
||||||
docker run --rm -e PGPASSWORD="password" "$IMAGE_NAME" psql "postgresql://postgres@$CONTAINER_IP:5432/postgres?sslmode=require" || \
|
|
||||||
false "FAIL: Did not manage to connect using SSL only."
|
|
||||||
|
|
||||||
docker stop "$(get_cid "$container_name")"
|
|
||||||
}
|
|
||||||
|
|
||||||
run_s2i_bake_data_test ()
|
|
||||||
{
|
|
||||||
local s2i_image_name="$IMAGE_NAME-bake_$(ct_random_string)"
|
|
||||||
ct_s2i_build_as_df "file://$test_dir/examples/s2i-dump-data" "${IMAGE_NAME}" "$s2i_image_name" 1>/dev/null
|
|
||||||
images_to_clean+=( "$s2i_image_name" )
|
|
||||||
|
|
||||||
local container_name=bake-data-test
|
|
||||||
|
|
||||||
DOCKER_ARGS="-e POSTGRESQL_ADMIN_PASSWORD=password" \
|
|
||||||
IMAGE_NAME="$s2i_image_name" create_container "$container_name"
|
|
||||||
|
|
||||||
wait_ready "$container_name"
|
|
||||||
|
|
||||||
test "hello world" == "$(docker exec "$(get_cid "$container_name")" \
|
|
||||||
bash -c "psql -tA -c 'SELECT * FROM test;'")"
|
|
||||||
|
|
||||||
docker stop "$(get_cid "$container_name")"
|
|
||||||
}
|
|
||||||
|
|
||||||
function run_all_tests() {
|
|
||||||
for test_case in $TEST_LIST; do
|
|
||||||
: "Running test $test_case"
|
|
||||||
$test_case
|
|
||||||
done;
|
|
||||||
}
|
|
||||||
|
|
||||||
# configuration defaults
|
|
||||||
POSTGRESQL_MAX_CONNECTIONS=100
|
|
||||||
POSTGRESQL_MAX_PREPARED_TRANSACTIONS=0
|
|
||||||
POSTGRESQL_SHARED_BUFFERS=32MB
|
|
||||||
|
|
||||||
# Run the chosen tests
|
|
||||||
TEST_LIST=${TESTS:-$TEST_LIST} run_all_tests
|
|
||||||
|
|
@ -1,97 +0,0 @@
|
||||||
#! /bin/bash
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
. test/pg-test-lib.sh
|
|
||||||
|
|
||||||
ADMIN_PASSWORD=redhat
|
|
||||||
|
|
||||||
STEPS=( "$@" )
|
|
||||||
|
|
||||||
quote_args ()
|
|
||||||
{
|
|
||||||
quote_args_result=
|
|
||||||
local space=
|
|
||||||
for arg; do
|
|
||||||
quote_args_result+="$space$(printf "%q" "$arg")"
|
|
||||||
space=' '
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
quote_args_print ()
|
|
||||||
{
|
|
||||||
quote_args "$@"
|
|
||||||
echo "$quote_args_result"
|
|
||||||
}
|
|
||||||
|
|
||||||
# background_container IMAGE DOCKER_ARGS CMD
|
|
||||||
background_container ()
|
|
||||||
{
|
|
||||||
CID=$(eval "docker run -d $2 $1 $3")
|
|
||||||
test -n "$CID"
|
|
||||||
}
|
|
||||||
|
|
||||||
# run_server DATADIR IMAGE_ID DOCKER_ARGS
|
|
||||||
run_server ()
|
|
||||||
{
|
|
||||||
local datadir=$1
|
|
||||||
local image_id=$2
|
|
||||||
local docker_args=$(quote_args_print -e POSTGRESQL_ADMIN_PASSWORD="$ADMIN_PASSWORD")
|
|
||||||
docker_args+=' '$(quote_args_print -v "$datadir:/var/lib/pgsql/data:Z")
|
|
||||||
docker_args+=" $3"
|
|
||||||
background_container "$image_id" "$docker_args"
|
|
||||||
}
|
|
||||||
|
|
||||||
# init_datadir IMAGE_ID dataspec
|
|
||||||
# ------------------------------
|
|
||||||
init_datadir ()
|
|
||||||
{
|
|
||||||
local image_id=$1
|
|
||||||
DATADIR=$(mktemp -d)
|
|
||||||
setfacl -m u:26:rwx "$DATADIR"
|
|
||||||
run_server "$DATADIR" "$image_id"
|
|
||||||
wait_for_postgres "$CID"
|
|
||||||
|
|
||||||
eval "data_$2_create"
|
|
||||||
eval "data_$2_check"
|
|
||||||
|
|
||||||
docker stop "$CID" >/dev/null
|
|
||||||
docker rm -f "$CID" >/dev/null
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# check_upgrade_path {hardlink|copy} dataspec
|
|
||||||
assert_upgrade_succeeds ()
|
|
||||||
{
|
|
||||||
info "Initializing datadir with $VERSION_FROM PostgreSQL"
|
|
||||||
local INIT_IMAGE=$(get_image_id "$VERSION_FROM")
|
|
||||||
local dataspec=$2
|
|
||||||
init_datadir "$INIT_IMAGE" "$dataspec"
|
|
||||||
|
|
||||||
info "Running upgrade '$1/$dataspec'"
|
|
||||||
|
|
||||||
for upgrade_to in "${UPGRADE_PATH[@]}"; do
|
|
||||||
info "Upgrading to $upgrade_to"
|
|
||||||
UPGRADE_IMAGE=$(get_image_id "$upgrade_to")
|
|
||||||
run_server "$DATADIR" "$UPGRADE_IMAGE" "-e POSTGRESQL_UPGRADE=$1"
|
|
||||||
wait_for_postgres "$CID"
|
|
||||||
eval "data_${dataspec}_check"
|
|
||||||
debug "the upgrading container of version '$upgrade_to' responded"
|
|
||||||
docker stop "$CID" >/dev/null
|
|
||||||
docker rm -f "$CID" >/dev/null
|
|
||||||
|
|
||||||
run_server "$DATADIR" "$UPGRADE_IMAGE"
|
|
||||||
wait_for_postgres "$CID"
|
|
||||||
eval "data_${dataspec}_check"
|
|
||||||
debug "restarted server of version '$upgrade_to' responded"
|
|
||||||
docker stop "$CID" >/dev/null
|
|
||||||
docker rm -f "$CID" >/dev/null
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
VERSION_FROM=$1 ; shift
|
|
||||||
UPGRADE_PATH=( "$@" )
|
|
||||||
for data in empty pagila; do
|
|
||||||
assert_upgrade_succeeds hardlink "$data"
|
|
||||||
assert_upgrade_succeeds copy "$data"
|
|
||||||
done
|
|
||||||
|
|
@ -1,12 +0,0 @@
|
||||||
# Check that user credentials for backup is set
|
|
||||||
|
|
||||||
[[ -v POSTGRESQL_BACKUP_USER && -v POSTGRESQL_BACKUP_PASSWORD ]] || usage "You have to set all variables for user for doing backup: POSTGRESQL_BACKUP_USER, POSTGRESQL_BACKUP_PASSWORD"
|
|
||||||
|
|
||||||
# create backup user with 'backup' database
|
|
||||||
psql --variable=user="$POSTGRESQL_BACKUP_USER" \
|
|
||||||
--variable=password="$POSTGRESQL_BACKUP_PASSWORD" \
|
|
||||||
<<<"
|
|
||||||
CREATE USER :user SUPERUSER password :'password';
|
|
||||||
CREATE DATABASE backup OWNER = :user;
|
|
||||||
ALTER USER :user set default_transaction_read_only = on;
|
|
||||||
"
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
../common/test-lib-openshift.sh
|
|
||||||
|
|
@ -1,39 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
#
|
|
||||||
# Functions for tests for the PostgreSQL image in OpenShift.
|
|
||||||
#
|
|
||||||
# IMAGE_NAME specifies a name of the candidate image used for testing.
|
|
||||||
# The image has to be available before this script is executed.
|
|
||||||
#
|
|
||||||
|
|
||||||
THISDIR=$(dirname ${BASH_SOURCE[0]})
|
|
||||||
|
|
||||||
source ${THISDIR}/test-lib.sh
|
|
||||||
source ${THISDIR}/test-lib-openshift.sh
|
|
||||||
|
|
||||||
function test_postgresql_integration() {
|
|
||||||
local image_name=$1
|
|
||||||
local service_name=postgresql
|
|
||||||
ct_os_template_exists postgresql-ephemeral && t=postgresql-ephemeral || t=postgresql-persistent
|
|
||||||
ct_os_test_template_app_func "${image_name}" \
|
|
||||||
"${t}" \
|
|
||||||
"${service_name}" \
|
|
||||||
"ct_os_check_cmd_internal '<SAME_IMAGE>' '${service_name}-testing' 'PGPASSWORD=testp pg_isready -t 15 -h <IP> -U testu -d testdb' 'accepting connections' 120" \
|
|
||||||
"-p POSTGRESQL_VERSION=${VERSION} \
|
|
||||||
-p DATABASE_SERVICE_NAME="${service_name}-testing" \
|
|
||||||
-p POSTGRESQL_USER=testu \
|
|
||||||
-p POSTGRESQL_PASSWORD=testp \
|
|
||||||
-p POSTGRESQL_DATABASE=testdb"
|
|
||||||
}
|
|
||||||
|
|
||||||
# Check the imagestream
|
|
||||||
function test_postgresql_imagestream() {
|
|
||||||
case ${OS} in
|
|
||||||
rhel7|centos7) ;;
|
|
||||||
*) echo "Imagestream testing not supported for $OS environment." ; return 0 ;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
ct_os_test_image_stream_template "${THISDIR}/../imagestreams/postgresql-${OS%[0-9]*}.json" "${THISDIR}/../examples/postgresql-ephemeral-template.json" postgresql "-p POSTGRESQL_VERSION=${VERSION}"
|
|
||||||
}
|
|
||||||
|
|
||||||
# vim: set tabstop=2:shiftwidth=2:expandtab:
|
|
||||||
|
|
@ -1 +0,0 @@
|
||||||
../common/test-lib.sh
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue