Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion tests/templates/kuttl/ldap/30-test-opensearch.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ spec:
- -c
args:
- |
pip install opensearch-py==3.1.0
pip install opensearch-py==3.2.0
python scripts/test.py
env:
# required for pip install
Expand Down
15 changes: 15 additions & 0 deletions tests/templates/kuttl/repository-azure-plugin/00-patch-ns.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# see https://github.com/stackabletech/issues/issues/566
---
apiVersion: kuttl.dev/v1beta1
kind: TestStep
commands:
- script: |
kubectl patch namespace $NAMESPACE --patch='
{
"metadata": {
"labels": {
"pod-security.kubernetes.io/enforce": "privileged"
}
}
}'
timeout: 120
31 changes: 31 additions & 0 deletions tests/templates/kuttl/repository-azure-plugin/01-rbac.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: test-service-account
---
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: test-role
rules:
- apiGroups:
- security.openshift.io
resources:
- securitycontextconstraints
resourceNames:
- privileged
verbs:
- use
---
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: test-role-binding
subjects:
- kind: ServiceAccount
name: test-service-account
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: test-role
10 changes: 10 additions & 0 deletions tests/templates/kuttl/repository-azure-plugin/02-assert.yaml.j2
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
---
apiVersion: kuttl.dev/v1beta1
kind: TestAssert
{% if lookup('env', 'VECTOR_AGGREGATOR') %}
---
apiVersion: v1
kind: ConfigMap
metadata:
name: vector-aggregator-discovery
{% endif %}
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
{% if lookup('env', 'VECTOR_AGGREGATOR') %}
---
apiVersion: v1
kind: ConfigMap
metadata:
name: vector-aggregator-discovery
data:
ADDRESS: {{ lookup('env', 'VECTOR_AGGREGATOR') }}
{% endif %}
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
---
apiVersion: secrets.stackable.tech/v1alpha1
kind: TrustStore
metadata:
name: truststore-pem
spec:
secretClassName: tls
format: tls-pem
targetKind: ConfigMap
8 changes: 8 additions & 0 deletions tests/templates/kuttl/repository-azure-plugin/10-assert.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: azurite
status:
readyReplicas: 1
replicas: 1
Original file line number Diff line number Diff line change
@@ -0,0 +1,99 @@
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: azurite
labels:
app.kubernetes.io/name: azurite
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: azurite
serviceName: azurite
template:
metadata:
labels:
app.kubernetes.io/name: azurite
spec:
containers:
- name: azurite
image: mcr.microsoft.com/azure-storage/azurite:3.37.0
command:
- azurite-blob
- --location
- /data
- --disableTelemetry
# The account name is in the URL path, not in the FQDN hostname.
- --disableProductStyleUrl
- --blobHost
- 0.0.0.0
- --cert
- /tls/tls.crt
- --key
- /tls/tls.key
ports:
- containerPort: 10000
name: blobs
securityContext:
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
privileged: false
volumeMounts:
- name: storage
mountPath: /data
- name: tls
mountPath: /tls
securityContext:
runAsNonRoot: true
runAsGroup: 1000
runAsUser: 1000
fsGroup: 1000
serviceAccountName: test-service-account
volumes:
- name: tls
ephemeral:
volumeClaimTemplate:
metadata:
annotations:
secrets.stackable.tech/class: tls
secrets.stackable.tech/scope: service=azurite
spec:
storageClassName: secrets.stackable.tech
accessModes:
- ReadWriteOnce
resources:
requests:
storage: "1"
volumeClaimTemplates:
- metadata:
name: storage
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 100Mi
---
apiVersion: v1
kind: Service
metadata:
name: azurite
spec:
selector:
app.kubernetes.io/name: azurite
ports:
- port: 10000
targetPort: 10000
---
apiVersion: v1
kind: Secret
metadata:
name: azurite-credentials
stringData:
# The default storage account of Azurite, see https://github.com/Azure/Azurite#default-storage-account.
AZURITE_ACCOUNT_NAME: devstoreaccount1
AZURITE_ACCOUNT_KEY: Eby8vdM02xNOcqFlqUwJPLlmEtlCDXJ1OUzFT50uSRZ6IFsuFq2UVErCz4I6tq/K1SZFPTOtr/KBHBeksoGMGw==
Comment thread
siegfriedweber marked this conversation as resolved.
7 changes: 7 additions & 0 deletions tests/templates/kuttl/repository-azure-plugin/11-assert.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
apiVersion: batch/v1
kind: Job
metadata:
name: create-azure-storage-container
status:
succeeded: 1
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
---
apiVersion: batch/v1
kind: Job
metadata:
name: create-azure-storage-container
spec:
template:
spec:
containers:
- name: create-azure-storage-container
image: mcr.microsoft.com/azure-cli:2.91.0
command:
- az
- storage
- container
- create
- --name
- opensearch-remote
envFrom:
- secretRef:
name: azurite-credentials
env:
- name: NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: AZURE_STORAGE_CONNECTION_STRING
value: "\
DefaultEndpointsProtocol=https;\
AccountName=$(AZURITE_ACCOUNT_NAME);\
AccountKey=$(AZURITE_ACCOUNT_KEY);\
BlobEndpoint=https://azurite.$(NAMESPACE).svc.cluster.local:10000/$(AZURITE_ACCOUNT_NAME);\
"
- name: REQUESTS_CA_BUNDLE
value: /tls/ca.crt
# The home directory of the user is not writable, so let the Azure
# CLI store its configuration in the writable /tmp directory.
- name: AZURE_CONFIG_DIR
value: /tmp/.azure
securityContext:
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
privileged: false
volumeMounts:
- name: tls
mountPath: /tls
# The Azure CLI requires a writable temporary directory, also for
# its configuration (see AZURE_CONFIG_DIR).
- name: tmp
mountPath: /tmp
securityContext:
runAsNonRoot: true
runAsGroup: 1000
runAsUser: 1000
fsGroup: 1000
serviceAccountName: test-service-account
volumes:
- name: tls
configMap:
name: truststore-pem
- name: tmp
emptyDir: {}
restartPolicy: OnFailure
20 changes: 20 additions & 0 deletions tests/templates/kuttl/repository-azure-plugin/20-assert.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
---
apiVersion: kuttl.dev/v1beta1
kind: TestAssert
timeout: 600
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: opensearch-nodes-cluster-manager
status:
readyReplicas: 3
replicas: 3
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: opensearch-nodes-data
status:
readyReplicas: 2
replicas: 2
Loading
Loading