Initial server source import
This commit is contained in:
@@ -0,0 +1,202 @@
|
||||
# Invoke through python3 docker/verify.py, never with the production Compose file.
|
||||
# The verifier supplies immutable IDs for these already-built local images.
|
||||
name: ${TRUF_WORKER_TEST_PROJECT:?Invoke python3 docker/verify.py}
|
||||
|
||||
x-isolated: &isolated
|
||||
pull_policy: never
|
||||
read_only: true
|
||||
user: "10001:10001"
|
||||
cap_drop: [ALL]
|
||||
security_opt: [no-new-privileges:true]
|
||||
network_mode: none
|
||||
init: false
|
||||
# Override Docker client proxy defaults without importing host credentials.
|
||||
environment:
|
||||
HTTP_PROXY: ""
|
||||
http_proxy: ""
|
||||
HTTPS_PROXY: ""
|
||||
https_proxy: ""
|
||||
FTP_PROXY: ""
|
||||
ftp_proxy: ""
|
||||
ALL_PROXY: ""
|
||||
all_proxy: ""
|
||||
NO_PROXY: "*"
|
||||
no_proxy: "*"
|
||||
tmpfs:
|
||||
- /run/truf:rw,nosuid,nodev,noexec,size=64m,mode=0700,uid=10001,gid=10001
|
||||
- /tmp:rw,nosuid,nodev,noexec,size=128m,mode=1777
|
||||
cpus: 2.0
|
||||
mem_limit: 6g
|
||||
pids_limit: 512
|
||||
shm_size: 256m
|
||||
stop_signal: SIGTERM
|
||||
stop_grace_period: 600s
|
||||
restart: "no"
|
||||
logging:
|
||||
driver: json-file
|
||||
options:
|
||||
max-size: "16m"
|
||||
max-file: "4"
|
||||
|
||||
x-runtime: &runtime
|
||||
<<: *isolated
|
||||
image: ${TRUF_WORKER_TEST_RUNTIME_IMAGE:?Invoke python3 docker/verify.py}
|
||||
volumes:
|
||||
- type: volume
|
||||
source: data
|
||||
target: /data
|
||||
|
||||
services:
|
||||
tools:
|
||||
<<: *isolated
|
||||
image: ${TRUF_WORKER_TEST_TEST_IMAGE:?Invoke python3 docker/verify.py}
|
||||
volumes:
|
||||
# Only the test tree is copied up, never the test image's application.
|
||||
- type: volume
|
||||
source: tools
|
||||
target: /opt/truf/tests
|
||||
volume:
|
||||
nocopy: false
|
||||
entrypoint: [/usr/local/bin/python3, -I, -S, -B, -c]
|
||||
command:
|
||||
- |
|
||||
import hashlib
|
||||
import json
|
||||
import os
|
||||
from pathlib import Path
|
||||
import stat
|
||||
|
||||
try:
|
||||
assert os.getuid() == os.geteuid() == os.getgid() == 10001
|
||||
root = Path('/opt/truf/tests')
|
||||
fixture_files = {
|
||||
root / 'fixtures/worker_tls_cert.pem',
|
||||
root / 'fixtures/worker_tls_key.pem',
|
||||
}
|
||||
pending = [root]
|
||||
files = []
|
||||
size = 0
|
||||
entries = 0
|
||||
while pending:
|
||||
path = pending.pop()
|
||||
entries += 1
|
||||
assert entries <= 512
|
||||
details = path.lstat()
|
||||
assert (details.st_uid, details.st_gid) == (10001, 10001)
|
||||
if stat.S_ISDIR(details.st_mode):
|
||||
assert stat.S_IMODE(details.st_mode) == 0o700
|
||||
pending.extend(path.iterdir())
|
||||
assert len(pending) + len(files) <= 512
|
||||
else:
|
||||
assert stat.S_ISREG(details.st_mode)
|
||||
assert stat.S_IMODE(details.st_mode) == 0o600
|
||||
assert (path.suffix == '.py' or path in fixture_files)
|
||||
assert details.st_size <= 4 * 1024 * 1024
|
||||
files.append(path)
|
||||
size += details.st_size
|
||||
assert size <= 64 * 1024 * 1024
|
||||
assert root / 'container_e2e.py' in files
|
||||
assert fixture_files <= set(files)
|
||||
tree = hashlib.sha256()
|
||||
for path in sorted(files):
|
||||
tree.update(path.relative_to(root).as_posix().encode('utf-8') + b'\0')
|
||||
tree.update(hashlib.sha256(path.read_bytes()).digest())
|
||||
summary = {
|
||||
'counts': {'ok': 1, 'tool_files': len(files), 'tool_bytes': size},
|
||||
'hashes': {
|
||||
'tools_tree_sha256': tree.hexdigest(),
|
||||
'driver_sha256': hashlib.sha256((root / 'container_e2e.py').read_bytes()).hexdigest(),
|
||||
},
|
||||
}
|
||||
except Exception:
|
||||
summary = {'counts': {'ok': 0, 'tools_seed_failed': 1}, 'hashes': {}}
|
||||
print(json.dumps(summary, sort_keys=True))
|
||||
raise SystemExit(0 if summary['counts']['ok'] else 1)
|
||||
|
||||
provision:
|
||||
<<: *runtime
|
||||
user: "0:0"
|
||||
cap_add: [CHOWN, DAC_OVERRIDE, FOWNER]
|
||||
command: [provision]
|
||||
|
||||
prepare:
|
||||
<<: *runtime
|
||||
volumes:
|
||||
- type: volume
|
||||
source: data
|
||||
target: /data
|
||||
- type: volume
|
||||
source: tools
|
||||
target: /opt/truf/tests
|
||||
read_only: true
|
||||
volume:
|
||||
nocopy: true
|
||||
entrypoint: [/usr/local/bin/python3, -I, -S, -B, /opt/truf/tests/container_e2e.py]
|
||||
command: [prepare, --config, /data/config/e2e.yaml]
|
||||
|
||||
runtime:
|
||||
<<: *runtime
|
||||
volumes:
|
||||
- type: volume
|
||||
source: data
|
||||
target: /data
|
||||
- type: volume
|
||||
source: tools
|
||||
target: /opt/truf/tests
|
||||
read_only: true
|
||||
volume:
|
||||
nocopy: true
|
||||
# Preserve the production image's tini -> container_runtime entrypoint.
|
||||
# Do not add Compose init, a shell supervisor, or a test-image server.
|
||||
command: [run, --config, /data/config/e2e.yaml]
|
||||
healthcheck:
|
||||
test: [CMD, /usr/local/bin/python3, -I, -S, -B, /opt/truf/app/container_runtime.py, health, --config, /data/config/e2e.yaml]
|
||||
interval: 5s
|
||||
timeout: 15s
|
||||
start_period: 240s
|
||||
retries: 3
|
||||
|
||||
stopped:
|
||||
<<: *runtime
|
||||
volumes:
|
||||
- type: volume
|
||||
source: data
|
||||
target: /data
|
||||
read_only: true
|
||||
volume:
|
||||
nocopy: true
|
||||
entrypoint: [/usr/local/bin/python3, -I, -S, -B, -c]
|
||||
command:
|
||||
- |
|
||||
import json
|
||||
import os
|
||||
import runpy
|
||||
|
||||
try:
|
||||
runtime = runpy.run_path('/opt/truf/app/container_runtime.py')
|
||||
runtime['require_container']()
|
||||
runtime['private_path']('/data/postgres-linux', directory=True)
|
||||
marker = runtime['_read_json'](runtime['INITIALIZED'])
|
||||
assert marker.get('pg_major') == 16
|
||||
try:
|
||||
os.lstat('/data/postgres-linux/postmaster.pid')
|
||||
except FileNotFoundError:
|
||||
pass
|
||||
else:
|
||||
raise AssertionError
|
||||
summary = {'counts': {
|
||||
'ok': 1, 'private_postgres_directory': 1,
|
||||
'postgres_pid_absent': 1, 'initialized': 1,
|
||||
}, 'hashes': {}}
|
||||
except Exception:
|
||||
summary = {'counts': {'ok': 0, 'stopped_data_check_failed': 1}, 'hashes': {}}
|
||||
print(json.dumps(summary, sort_keys=True))
|
||||
raise SystemExit(0 if summary['counts']['ok'] else 1)
|
||||
|
||||
volumes:
|
||||
data:
|
||||
name: ${TRUF_WORKER_TEST_PROJECT:?Invoke python3 docker/verify.py}_data
|
||||
driver: local
|
||||
tools:
|
||||
name: ${TRUF_WORKER_TEST_PROJECT:?Invoke python3 docker/verify.py}_tools
|
||||
driver: local
|
||||
Reference in New Issue
Block a user