Squashed commit: [8058e6aba] 1 error left [b0157b252] 2 errors [7fa494907] 4 errors [03139391e] 6 failures, 4 errors [7f017ea23] 12 errors [3e9ad758d] 0 failures, 13 errors [e24a3cb3e] 3 failures, 13 errors [6edcaa655] 4 failures 14 errors [9623bda57] 6 failures, 13 errors [04c35c995] 4 failed 22 errors [5f5335c15] 9 failures [9a33540e2] down to 20 failures [0e7b73b49] remove old tests [5cc6d11b7] fixup the resources [8c508d45a] some more progress [4acef3c3b] some more work [85cdb5d06] some ports cleanup [1987ac2ec] lint before unit [6fa221789] enable unit tests [c212b695d] other name [b78594518] common test name fix [ef6597e79] indent [8cbcfb5e4] common test rename [1ca838c16] seperate common tests [ef052b022] create two seperate job for common testing [67eb0e9b3] use devcontainer for release shizzle [0c47c482b] make it a sudo [4d8900b16] force install jq [9660cdd47] try something else [e2b611917] bump common to run tests (to fix them) [277241bbf] only use the new devcontainer for the release tests for now... [9c7b68e0f] Revert "remove setup chart testing action" This reverts commit 6987914587a58ab5a52a05b836d60ef91f1619d5. [444914311] Revert "use integrated k3d" This reverts commit d9bcb2f35d154b0afe1eb851729c37789b6ba0ea. (+6 squashed commit) Squashed commit: [313446184] Revert "correct k3s version" This reverts commit 81fa8a43c41c2449b7411e0d59a3c2bbe0aef1ea. [41b4d4795] Revert "version name tryout" This reverts commit bbb8dcead9f9426872390b8f89b1fd0e661534bb. [b64df97a0] Revert "change version" This reverts commit 8080395dc80e606769ad9790b35d35fac4d1d3ed. [ed63220d4] Revert "use k3s kubectl" This reverts commit ea81735d939e838ad595835ea09b54bff817dd83. [6267a2908] Revert "use normal kubectl" This reverts commit 216d3799111d47f65dd20dd85ccb8fbc586a9c2b. [f48ddde73] Revert "try to set kubectl context" This reverts commit a5e8a532c5620e0d9d4cb7a53a371ba200265612. [a5e8a532c] try to set kubectl context [216d37991] use normal kubectl [ea81735d9] use k3s kubectl [8080395dc] change version [bbb8dcead] version name tryout [81fa8a43c] correct k3s version [d9bcb2f35] use integrated k3d [698791458] remove setup chart testing action [5bd7cf01d] bump common-test
320 lines
11 KiB
Ruby
320 lines
11 KiB
Ruby
# frozen_string_literal: true
|
|
require_relative '../../test_helper'
|
|
|
|
class Test < ChartTest
|
|
@@chart = Chart.new('charts/library/common-test')
|
|
|
|
describe @@chart.name do
|
|
describe 'initContainer::permissions' do
|
|
it 'initContainer exists by default' do
|
|
deployment = chart.resources(kind: "Deployment").first
|
|
initContainer = deployment["spec"]["template"]["spec"]["initContainers"][0]
|
|
refute_nil(initContainer)
|
|
end
|
|
|
|
it 'persistenceList do not affect permissions job by default' do
|
|
values = {
|
|
persistenceList: [
|
|
{
|
|
name: "data",
|
|
enabled: true,
|
|
mountPath: "/data",
|
|
hostPath: "/tmp"
|
|
}
|
|
]
|
|
}
|
|
chart.value values
|
|
deployment = chart.resources(kind: "Deployment").first
|
|
assert_nil(deployment["spec"]["template"]["spec"]["initContainers"][0]["volumeMounts"])
|
|
end
|
|
it 'persistenceList.setPermissions adds volume(mounts)' do
|
|
values = {
|
|
persistenceList: [
|
|
{
|
|
name: "data",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/data",
|
|
hostPath: "/tmp"
|
|
}
|
|
]
|
|
}
|
|
chart.value values
|
|
deployment = chart.resources(kind: "Deployment").first
|
|
assert_equal("data", deployment["spec"]["template"]["spec"]["volumes"][0]["name"])
|
|
assert_equal("data", deployment["spec"]["template"]["spec"]["initContainers"][0]["volumeMounts"][0]["name"])
|
|
end
|
|
it 'supports multiple persistenceList' do
|
|
values = {
|
|
persistenceList: [
|
|
{
|
|
name: "data",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/data",
|
|
hostPath: "/tmp"
|
|
},
|
|
{
|
|
name: "configlist",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/configlist",
|
|
hostPath: "/tmp"
|
|
}
|
|
]
|
|
}
|
|
chart.value values
|
|
deployment = chart.resources(kind: "Deployment").first
|
|
initContainer = deployment["spec"]["template"]["spec"]["initContainers"][0]
|
|
|
|
# Check that all persistenceList volumes have mounts
|
|
values[:persistenceList].each { |value|
|
|
volumeMount = initContainer["volumeMounts"].find{ |v| v["name"] == "" + value[:name].to_s }
|
|
refute_nil(volumeMount)
|
|
}
|
|
end
|
|
|
|
it 'supports setting mountPath' do
|
|
values = {
|
|
persistenceList: [
|
|
{
|
|
name: "data",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/data",
|
|
hostPath: "/tmp"
|
|
}
|
|
]
|
|
}
|
|
chart.value values
|
|
deployment = chart.resources(kind: "Deployment").first
|
|
initContainer = deployment["spec"]["template"]["spec"]["initContainers"][0]
|
|
|
|
volumeMount = initContainer["volumeMounts"].find{ |v| v["name"] == "data" }
|
|
refute_nil(volumeMount)
|
|
assert_equal("/data", volumeMount["mountPath"])
|
|
end
|
|
|
|
it 'could mount multiple volumes' do
|
|
values = {
|
|
persistenceList: [
|
|
{
|
|
name: "data",
|
|
enabled: true,
|
|
type: "hostPath",
|
|
setPermissions: true,
|
|
mountPath: "/data",
|
|
hostPath: "/tmp1"
|
|
},
|
|
{
|
|
name: "configlist",
|
|
enabled: true,
|
|
type: "hostPath",
|
|
setPermissions: true,
|
|
mountPath: "/configlist",
|
|
hostPath: "/tmp2"
|
|
}
|
|
]
|
|
}
|
|
chart.value values
|
|
deployment = chart.resources(kind: "Deployment").first
|
|
volumes = deployment["spec"]["template"]["spec"]["volumes"]
|
|
|
|
volume = volumes.find{ |v| v["name"] == "data"}
|
|
refute_nil(volume)
|
|
assert_equal('/tmp1', volume["hostPath"]["path"])
|
|
|
|
volume = volumes.find{ |v| v["name"] == "configlist"}
|
|
refute_nil(volume)
|
|
assert_equal('/tmp2', volume["hostPath"]["path"])
|
|
end
|
|
|
|
it 'can process default (568:568) permissions for multiple volumes' do
|
|
results= {
|
|
command: ["/bin/sh", "-c", "echo 'Automatically correcting permissions...';chown -R :568 '/configlist'; chmod -R g+w '/configlist';chown -R :568 '/data'; chmod -R g+w '/data';"]
|
|
}
|
|
values = {
|
|
persistenceList: [
|
|
{
|
|
name: "data",
|
|
enabled: true,
|
|
type: "hostPath",
|
|
setPermissions: true,
|
|
mountPath: "/data",
|
|
hostPath: "/tmp1"
|
|
},
|
|
{
|
|
name: "configlist",
|
|
enabled: true,
|
|
type: "hostPath",
|
|
setPermissions: true,
|
|
mountPath: "/configlist",
|
|
hostPath: "/tmp2"
|
|
}
|
|
]
|
|
}
|
|
chart.value values
|
|
deployment = chart.resources(kind: "Deployment").first
|
|
initContainer = deployment["spec"]["template"]["spec"]["initContainers"][0]
|
|
assert_equal(results[:command], initContainer["command"])
|
|
end
|
|
|
|
it 'outputs default permissions with irrelevant podSecurityContext' do
|
|
results= {
|
|
command: ["/bin/sh", "-c", "echo 'Automatically correcting permissions...';chown -R :568 '/configlist'; chmod -R g+w '/configlist';chown -R :568 '/data'; chmod -R g+w '/data';"]
|
|
}
|
|
values = {
|
|
podSecurityContext: {
|
|
allowPrivilegeEscalation: false
|
|
},
|
|
persistenceList: [
|
|
{
|
|
name: "data",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/data",
|
|
hostPath: "/tmp1"
|
|
},
|
|
{
|
|
name: "configlist",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/configlist",
|
|
hostPath: "/tmp2"
|
|
}
|
|
]
|
|
}
|
|
chart.value values
|
|
deployment = chart.resources(kind: "Deployment").first
|
|
initContainer = deployment["spec"]["template"]["spec"]["initContainers"][0]
|
|
assert_equal(results[:command], initContainer["command"])
|
|
end
|
|
|
|
it 'outputs fsgroup permissions for multiple volumes when set' do
|
|
results= {
|
|
command: ["/bin/sh", "-c", "echo 'Automatically correcting permissions...';chown -R :666 '/configlist'; chmod -R g+w '/configlist';chown -R :666 '/data'; chmod -R g+w '/data';"]
|
|
}
|
|
values = {
|
|
podSecurityContext: {
|
|
fsGroup: 666
|
|
},
|
|
persistenceList: [
|
|
{
|
|
name: "data",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/data",
|
|
hostPath: "/tmp1"
|
|
},
|
|
{
|
|
name: "configlist",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/configlist",
|
|
hostPath: "/tmp2"
|
|
}
|
|
]
|
|
}
|
|
chart.value values
|
|
deployment = chart.resources(kind: "Deployment").first
|
|
initContainer = deployment["spec"]["template"]["spec"]["initContainers"][0]
|
|
assert_equal(results[:command], initContainer["command"])
|
|
end
|
|
|
|
it 'outputs runAsUser permissions for multiple volumes when set' do
|
|
results= {
|
|
command: ["/bin/sh", "-c", "echo 'Automatically correcting permissions...';chown -R :568 '/configlist'; chmod -R g+w '/configlist';chown -R :568 '/data'; chmod -R g+w '/data';"]
|
|
}
|
|
values = {
|
|
podSecurityContext: {
|
|
runAsUser: 999
|
|
},
|
|
persistenceList: [
|
|
{
|
|
name: "data",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/data",
|
|
hostPath: "/tmp1"
|
|
},
|
|
{
|
|
name: "configlist",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/configlist",
|
|
hostPath: "/tmp2"
|
|
}
|
|
]
|
|
}
|
|
chart.value values
|
|
deployment = chart.resources(kind: "Deployment").first
|
|
initContainer = deployment["spec"]["template"]["spec"]["initContainers"][0]
|
|
assert_equal(results[:command], initContainer["command"])
|
|
end
|
|
|
|
it 'outputs fsGroup AND runAsUser permissions for multiple volumes when both are set' do
|
|
results= {
|
|
command: ["/bin/sh", "-c", "echo 'Automatically correcting permissions...';chown -R :666 '/configlist'; chmod -R g+w '/configlist';chown -R :666 '/data'; chmod -R g+w '/data';"]
|
|
}
|
|
values = {
|
|
podSecurityContext: {
|
|
fsGroup: 666,
|
|
runAsUser: 999
|
|
},
|
|
persistenceList: [
|
|
{
|
|
name: "data",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/data",
|
|
hostPath: "/tmp1"
|
|
},
|
|
{
|
|
name: "configlist",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/configlist",
|
|
hostPath: "/tmp2"
|
|
}
|
|
]
|
|
}
|
|
chart.value values
|
|
deployment = chart.resources(kind: "Deployment").first
|
|
initContainer = deployment["spec"]["template"]["spec"]["initContainers"][0]
|
|
assert_equal(results[:command], initContainer["command"])
|
|
end
|
|
it 'outputs PUID AND PGID permissions for multiple volumes when both are set' do
|
|
results= {
|
|
command: ["/bin/sh", "-c", "echo 'Automatically correcting permissions...';chown -R :568 '/configlist'; chmod -R g+w '/configlist';chown -R :568 '/data'; chmod -R g+w '/data';"]
|
|
}
|
|
values = {
|
|
env: {
|
|
PGID: 666,
|
|
PUID: 999
|
|
},
|
|
persistenceList: [
|
|
{
|
|
name: "data",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/data",
|
|
hostPath: "/tmp1"
|
|
},
|
|
{
|
|
name: "configlist",
|
|
enabled: true,
|
|
setPermissions: true,
|
|
mountPath: "/configlist",
|
|
hostPath: "/tmp2"
|
|
}
|
|
]
|
|
}
|
|
chart.value values
|
|
deployment = chart.resources(kind: "Deployment").first
|
|
initContainer = deployment["spec"]["template"]["spec"]["initContainers"][0]
|
|
assert_equal(results[:command], initContainer["command"])
|
|
end
|
|
end
|
|
end
|
|
end
|