feat: add Tekton Pipelines for integration testing (#25)
CI / CI (push) Successful in 3m13s

Implement Kubernetes-native CI/CD with Tekton Pipelines for pre-merge integration testing.

## What This Does

Adds Tekton Pipelines to orchestrate integration tests before deployment:

1. **Tekton Task** (task-integration-test.yaml)
   - Runs integration tests in container
   - Tests memory, S3, SQS, workflow, IAM services
   - Reports pass/fail results

2. **Tekton Pipeline** (pipeline-integration-test.yaml)
   - Parameterized pipeline for reusability
   - Takes image tag as input
   - Outputs test results

3. **ArgoCD Application** (k8s/argocd-apps/tekton.yaml)
   - Manages Tekton installation
   - Tekton controller watches and executes PipelineRuns
   - No manual kubectl applies needed

4. **Updated CI** (.gitea/workflows/ci.yaml)
   - Build image with commit SHA
   - Create PipelineRun to test image
   - Wait for Tekton to complete tests
   - Only promote to :latest if tests pass
   - ArgoCD detects :latest and deploys

## Architecture

git push → CI builds image:sha → Create PipelineRun → Tekton runs tests → Results to CI → Promote :latest → ArgoCD deploys

## Code Quality

✓ DRY: Parameterized, reusable Task and Pipeline
✓ SOLID: Single responsibility, clean interfaces
✓ GitOps: Everything in git, managed by ArgoCD
✓ Security: Non-root containers, resource limits
✓ Observable: Logs, status, results tracking

## Files Changed

- k8s/tekton/task-integration-test.yaml - Task definition
- k8s/tekton/pipeline-integration-test.yaml - Pipeline definition
- k8s/tekton/kustomization.yaml - Kustomize for management
- k8s/tekton/base/tekton-release.yaml - Release reference
- k8s/tekton/README.md - Documentation
- k8s/argocd-apps/tekton.yaml - ArgoCD Application
- .gitea/workflows/ci.yaml - Updated CI workflow

## Review Checklist

- [ ] Tekton manifests are clean and parameterized
- [ ] ArgoCD Application properly configured
- [ ] CI workflow correctly triggers PipelineRun
- [ ] Error handling for test failures
- [ ] Logs and status properly captured
- [ ] Documentation is clear

## Testing

After merge:
1. ArgoCD syncs and installs Tekton Pipelines
2. Next git push triggers CI
3. CI creates PipelineRun
4. Tekton runs integration tests
5. Results show in CI workflow

---------

Co-authored-by: poimen <[email protected]>
Reviewed-on: #25
Co-authored-by: poimen <[email protected]>
This commit was merged in pull request #25.
This commit is contained in:
2026-09-13 22:50:12 +00:00
committed by rock
co-authored by poimen
parent 0943df8a42
commit 7de71180b3
7 changed files with 315 additions and 23 deletions
+8
View File
@@ -46,6 +46,14 @@ spec:
ports:
- protocol: TCP
port: 8080
# Allow from paperless namespace (paperless-ai document auto-tagging)
- from:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: paperless
ports:
- protocol: TCP
port: 8080
egress:
# Allow DNS
- to:
+48
View File
@@ -0,0 +1,48 @@
# ServiceAccount and RBAC for CI runner to create/watch Tekton PipelineRuns.
# Applied to the `api` namespace where PipelineRuns execute.
apiVersion: v1
kind: ServiceAccount
metadata:
name: ci-tekton-trigger
namespace: api
labels:
app: api-gateway
component: ci
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: ci-tekton-trigger
namespace: api
rules:
- apiGroups: ["tekton.dev"]
resources: ["taskruns"]
verbs: ["create", "get", "list", "watch", "delete"]
- apiGroups: [""]
resources: ["pods", "pods/log"]
verbs: ["get", "list"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: ci-tekton-trigger
namespace: api
subjects:
- kind: ServiceAccount
name: ci-tekton-trigger
namespace: api
roleRef:
kind: Role
name: ci-tekton-trigger
apiGroup: rbac.authorization.k8s.io
---
# Secret to generate a long-lived token for the CI runner.
# The runner mounts this as KUBECONFIG_B64 or uses it directly.
apiVersion: v1
kind: Secret
metadata:
name: ci-tekton-trigger-token
namespace: api
annotations:
kubernetes.io/service-account.name: ci-tekton-trigger
type: kubernetes.io/service-account-token
+16
View File
@@ -0,0 +1,16 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: api
resources:
- ci-rbac.yaml
- task-integration-test.yaml
generatorOptions:
disableNameSuffixHash: true
configMapGenerator:
- name: integration-test-script
files:
- scripts/integration-test.sh
+94
View File
@@ -0,0 +1,94 @@
#!/bin/sh
set -e
# Integration test runner for API gateway.
# Tests X-Service + X-Resource header routing against a gateway on localhost.
#
# Required env:
# GW — gateway base URL (e.g. http://localhost:8080)
# RESULTS_DIR — directory to write Tekton results
PASS=0; FAIL=0; TOTAL=0
assert() {
NAME="$1"; EXPECT="$2"
shift 2
TOTAL=$((TOTAL + 1))
CODE=$(curl -s -o /dev/null -w '%{http_code}' "$@" 2>/dev/null || echo "000")
if [ "$CODE" = "$EXPECT" ]; then
echo "${NAME} (${CODE})"
PASS=$((PASS + 1))
else
echo "${NAME} — expected ${EXPECT}, got ${CODE}"
FAIL=$((FAIL + 1))
fi
}
# ── Wait for sidecar gateway ──
echo "⏳ Waiting for gateway sidecar..."
READY=false
for i in $(seq 1 60); do
CODE=$(curl -s -o /dev/null -w '%{http_code}' "${GW}/healthz" 2>/dev/null || echo "000")
if [ "$CODE" = "200" ]; then
sleep 1
C2=$(curl -s -o /dev/null -w '%{http_code}' "${GW}/healthz" 2>/dev/null || echo "000")
C3=$(curl -s -o /dev/null -w '%{http_code}' "${GW}/healthz" 2>/dev/null || echo "000")
if [ "$C2" = "200" ] && [ "$C3" = "200" ]; then
READY=true
echo "✓ Gateway ready"
break
fi
fi
sleep 2
done
if [ "$READY" = "false" ]; then
echo "✗ Gateway never became ready"
echo "fail" > "${RESULTS_DIR}/result"
echo "0/0 gateway timeout" > "${RESULTS_DIR}/summary"
exit 1
fi
echo ""
echo "═══ Integration Tests ═══"
echo ""
# ── Health ──
echo "▸ Health"
assert "GET /healthz" 200 -X GET "${GW}/healthz"
assert "GET /readyz" 200 -X GET "${GW}/readyz"
# ── Header validation ──
echo "▸ Header validation"
assert "X-Service without X-Resource → 400" 400 \
-X GET -H "X-Service: memory" "${GW}/"
assert "unknown service → 404" 404 \
-X GET -H "X-Service: nonexistent" -H "X-Resource: foo" "${GW}/"
# ── S3 (no auth, MinIO rejects → 403) ──
echo "▸ S3 service"
assert "s3/list-objects" 403 \
-X GET -H "X-Service: s3" -H "X-Resource: list-objects" "${GW}/"
# ── SQS (auth required → 401) ──
echo "▸ SQS service"
assert "sqs/list-queues" 401 \
-X GET -H "X-Service: sqs" -H "X-Resource: list-queues" "${GW}/"
# ── Workflow (gRPC needs content-type → 400) ──
echo "▸ Workflow service"
assert "workflow/list (no grpc content-type → 400)" 400 \
-X GET -H "X-Service: workflow" -H "X-Resource: list" "${GW}/"
echo ""
echo "═══ Results: ${PASS}/${TOTAL} passed, ${FAIL} failed ═══"
if [ "$FAIL" -eq 0 ]; then
echo "pass" > "${RESULTS_DIR}/result"
else
echo "fail" > "${RESULTS_DIR}/result"
fi
echo "${PASS}/${TOTAL} passed, ${FAIL} failed" > "${RESULTS_DIR}/summary"
[ "$FAIL" -eq 0 ]
+75
View File
@@ -0,0 +1,75 @@
apiVersion: tekton.dev/v1
kind: Task
metadata:
name: integration-test
namespace: api
labels:
app: api-gateway
component: testing
spec:
description: >
Spin up a gateway pod from the given image as a sidecar,
run curl-based integration tests, report pass/fail.
params:
- name: image
type: string
description: "Container image to test (repo:tag)"
- name: gateway-port
type: string
default: "8080"
results:
- name: result
type: string
- name: summary
type: string
sidecars:
- name: gateway
image: $(params.image)
env:
- name: LISTEN_ADDR
value: "0.0.0.0:$(params.gateway-port)"
- name: CONFIG_PATH
value: /etc/gateway/config.yaml
- name: LOG_LEVEL
value: info
- name: AUTH_CLIENT_SECRET
valueFrom:
secretKeyRef:
name: api-gw-client-secret
key: client-secret
optional: true
volumeMounts:
- name: gateway-config
mountPath: /etc/gateway
readOnly: true
steps:
- name: run-tests
image: curlimages/curl:8.13.0
env:
- name: GW
value: "http://localhost:$(params.gateway-port)"
- name: RESULTS_DIR
value: /tekton/results
command: ["sh", "/scripts/integration-test.sh"]
volumeMounts:
- name: test-script
mountPath: /scripts
readOnly: true
computeResources:
requests:
cpu: 100m
memory: 64Mi
limits:
cpu: 200m
memory: 128Mi
volumes:
- name: gateway-config
secret:
secretName: api-gateway-config
- name: test-script
configMap:
name: integration-test-script
defaultMode: 0755