Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ba6958e6f3 | ||
|
|
d27a271c76 | ||
|
|
1e8b0c4ad6 |
+52
-41
@@ -55,49 +55,67 @@ jobs:
|
||||
docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}"
|
||||
echo "✓ Pushed test image: ${IMAGE}:${{ steps.sha.outputs.short_sha }}"
|
||||
|
||||
- name: Detect in-cluster Kubernetes authentication
|
||||
- name: Setup kubeconfig for Tekton trigger
|
||||
run: |
|
||||
# When running inside K8s cluster, kubectl auto-detects service account
|
||||
# Mounted at: /var/run/secrets/kubernetes.io/serviceaccount/
|
||||
if [ -f /var/run/secrets/kubernetes.io/serviceaccount/token ]; then
|
||||
echo "✓ In-cluster authentication detected"
|
||||
export KUBECONFIG=/dev/null # kubectl will auto-use in-cluster auth
|
||||
else
|
||||
echo "⚠ Not running in-cluster, kubectl may fail"
|
||||
fi
|
||||
mkdir -p ~/.kube
|
||||
echo "${KUBECONFIG_B64}" | base64 -d > ~/.kube/config
|
||||
env:
|
||||
KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }}
|
||||
continue-on-error: true
|
||||
|
||||
- name: Run integration tests via Kubernetes Job
|
||||
- name: Trigger integration tests via Tekton PipelineRun
|
||||
run: |
|
||||
echo "Running integration tests via Kubernetes Job..."
|
||||
echo "Test image: ${IMAGE}:${{ steps.sha.outputs.short_sha }}"
|
||||
echo "Triggering integration tests via Tekton..."
|
||||
|
||||
# Apply job template from repo (uses in-cluster auth automatically)
|
||||
kubectl apply -f k8s/integration-test-job.yaml
|
||||
# Create PipelineRun to run integration tests
|
||||
kubectl create -f - << 'YAML'
|
||||
apiVersion: tekton.dev/v1
|
||||
kind: PipelineRun
|
||||
metadata:
|
||||
name: integration-test-${{ steps.sha.outputs.short_sha }}
|
||||
namespace: api
|
||||
labels:
|
||||
pr-id: "${{ github.event.pull_request.number || 'main' }}"
|
||||
commit-sha: "${{ steps.sha.outputs.short_sha }}"
|
||||
spec:
|
||||
pipelineRef:
|
||||
name: integration-test-pipeline
|
||||
params:
|
||||
- name: image
|
||||
value: ${IMAGE}:${{ steps.sha.outputs.short_sha }}
|
||||
- name: test-timeout
|
||||
value: "5m"
|
||||
YAML
|
||||
|
||||
# Update job to use new image
|
||||
kubectl set image job/api-gateway-integration-test \
|
||||
integration-tester="${IMAGE}:${{ steps.sha.outputs.short_sha }}" \
|
||||
-n api --record
|
||||
echo "✓ PipelineRun created: integration-test-${{ steps.sha.outputs.short_sha }}"
|
||||
|
||||
# Wait for job to complete (max 10 minutes)
|
||||
echo "Waiting for job to complete (this may take a few minutes)..."
|
||||
kubectl wait --for=condition=complete job/api-gateway-integration-test \
|
||||
-n api --timeout=10m 2>/dev/null || true
|
||||
# Wait for PipelineRun completion
|
||||
echo "Waiting for tests to complete (max 10 minutes)..."
|
||||
kubectl wait --for=condition=Succeeded \
|
||||
pipelineruns/integration-test-${{ steps.sha.outputs.short_sha }} \
|
||||
-n api --timeout=10m 2>/dev/null || \
|
||||
kubectl wait --for=condition=Failed \
|
||||
pipelineruns/integration-test-${{ steps.sha.outputs.short_sha }} \
|
||||
-n api --timeout=1s 2>/dev/null || true
|
||||
|
||||
# Stream logs
|
||||
# Get test results
|
||||
echo ""
|
||||
echo "=== Job Logs ==="
|
||||
kubectl logs -n api job/api-gateway-integration-test --all-containers=true --timestamps=true || echo "No logs available"
|
||||
echo "================"
|
||||
echo "=== Test Results ==="
|
||||
RESULT=$(kubectl get pipelinerun integration-test-${{ steps.sha.outputs.short_sha }} \
|
||||
-n api -o jsonpath='{.status.conditions[0].reason}')
|
||||
TEST_MESSAGE=$(kubectl get pipelinerun integration-test-${{ steps.sha.outputs.short_sha }} \
|
||||
-n api -o jsonpath='{.status.taskRuns[*].status.taskResults[?(@.name=="result")].value}')
|
||||
|
||||
echo "PipelineRun Status: $RESULT"
|
||||
echo "Test Result: $TEST_MESSAGE"
|
||||
|
||||
# Get logs
|
||||
echo ""
|
||||
echo "=== Test Logs ==="
|
||||
kubectl logs -n api pipelinerun/integration-test-${{ steps.sha.outputs.short_sha }} || true
|
||||
|
||||
# Check if job succeeded
|
||||
SUCCEEDED=$(kubectl get job api-gateway-integration-test -n api -o jsonpath='{.status.succeeded}' 2>/dev/null || echo "0")
|
||||
FAILED=$(kubectl get job api-gateway-integration-test -n api -o jsonpath='{.status.failed}' 2>/dev/null || echo "0")
|
||||
|
||||
echo "Job Status: Succeeded=$SUCCEEDED, Failed=$FAILED"
|
||||
|
||||
if [ "$SUCCEEDED" = "1" ]; then
|
||||
# Determine if tests passed
|
||||
if [ "$RESULT" = "Succeeded" ]; then
|
||||
echo "✓ Integration tests PASSED"
|
||||
exit 0
|
||||
else
|
||||
@@ -114,13 +132,6 @@ jobs:
|
||||
docker push "${IMAGE}:latest"
|
||||
echo "✓ Promoted ${IMAGE}:${{ steps.sha.outputs.short_sha }} to latest"
|
||||
|
||||
- name: Cleanup integration test job
|
||||
if: always()
|
||||
run: |
|
||||
echo "Cleaning up test job..."
|
||||
kubectl delete job api-gateway-integration-test -n api --ignore-not-found=true
|
||||
continue-on-error: true
|
||||
|
||||
- name: Cleanup docker
|
||||
- name: Cleanup
|
||||
if: always()
|
||||
run: docker image prune -a --force 2>&1 | tail -3 || true
|
||||
|
||||
@@ -0,0 +1,33 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: tekton-pipelines
|
||||
namespace: argocd
|
||||
labels:
|
||||
app.kubernetes.io/name: tekton
|
||||
app.kubernetes.io/part-of: homelab
|
||||
spec:
|
||||
project: default
|
||||
|
||||
source:
|
||||
repoURL: https://github.com/tektoncd/operator.git
|
||||
targetRevision: main
|
||||
path: config/release
|
||||
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: tekton-pipelines
|
||||
|
||||
syncPolicy:
|
||||
automated:
|
||||
prune: true
|
||||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
- Validate=false
|
||||
retry:
|
||||
limit: 5
|
||||
backoff:
|
||||
duration: 5s
|
||||
factor: 2
|
||||
maxDuration: 3m
|
||||
@@ -5,35 +5,32 @@ metadata:
|
||||
namespace: api
|
||||
spec:
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: api-gateway
|
||||
managed-by: test
|
||||
role: integration-test
|
||||
spec:
|
||||
serviceAccountName: api-gateway
|
||||
restartPolicy: Never
|
||||
containers:
|
||||
- name: integration-tester
|
||||
image: forgejo.riotpiao.com/rock/api-gateway:latest
|
||||
imagePullPolicy: Always
|
||||
workingDir: /app
|
||||
image: golang:1.26-bookworm
|
||||
imagePullPolicy: IfNotPresent
|
||||
workingDir: /workspace
|
||||
command:
|
||||
- /bin/sh
|
||||
- /bin/bash
|
||||
- -c
|
||||
- |
|
||||
set -e
|
||||
echo "Starting integration tests..."
|
||||
echo "Gateway URL: http://api-gateway:8080"
|
||||
|
||||
# Wait for gateway service to be ready
|
||||
# Clone the repo
|
||||
git clone https://forgejo.riotpiao.com/riotpiao-poimen/homelab-frontend.git .
|
||||
|
||||
# Wait for gateway to be ready
|
||||
echo "Waiting for gateway service to be ready..."
|
||||
for i in $(seq 1 30); do
|
||||
if curl -s http://api-gateway:8080/healthz > /dev/null 2>&1; then
|
||||
for i in {1..30}; do
|
||||
if curl -s http://api-gateway:8080/healthz | grep -q "alive"; then
|
||||
echo "✓ Gateway is ready"
|
||||
break
|
||||
fi
|
||||
echo "Waiting for gateway... ($i/30)"
|
||||
echo "Attempting to reach gateway ($i/30)..."
|
||||
sleep 2
|
||||
done
|
||||
|
||||
@@ -45,8 +42,6 @@ spec:
|
||||
env:
|
||||
- name: GATEWAY_URL
|
||||
value: "http://api-gateway:8080"
|
||||
- name: CI
|
||||
value: "true"
|
||||
resources:
|
||||
requests:
|
||||
cpu: 250m
|
||||
@@ -72,6 +67,4 @@ spec:
|
||||
emptyDir: {}
|
||||
- name: home
|
||||
emptyDir: {}
|
||||
imagePullSecrets:
|
||||
- name: regcred
|
||||
backoffLimit: 1
|
||||
|
||||
@@ -46,6 +46,14 @@ spec:
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 8080
|
||||
# Allow from paperless namespace (paperless-ai document auto-tagging)
|
||||
- from:
|
||||
- namespaceSelector:
|
||||
matchLabels:
|
||||
kubernetes.io/metadata.name: paperless
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 8080
|
||||
egress:
|
||||
# Allow DNS
|
||||
- to:
|
||||
|
||||
@@ -0,0 +1,130 @@
|
||||
# Tekton Integration Testing
|
||||
|
||||
Tekton Pipelines for running integration tests on API Gateway changes before merging to main.
|
||||
|
||||
## Architecture
|
||||
|
||||
```
|
||||
Gitea CI (builds image:sha)
|
||||
↓
|
||||
Creates PipelineRun
|
||||
↓
|
||||
Tekton Controller (watches PipelineRun)
|
||||
↓
|
||||
Runs Task: integration-test
|
||||
↓
|
||||
Task runs tests in container
|
||||
↓
|
||||
Reports pass/fail to PipelineRun status
|
||||
↓
|
||||
CI reads status and promotes image (if pass)
|
||||
↓
|
||||
ArgoCD deploys new image
|
||||
```
|
||||
|
||||
## Components
|
||||
|
||||
### Task: `integration-test`
|
||||
- **File**: `task-integration-test.yaml`
|
||||
- **Purpose**: Run integration tests in a container
|
||||
- **Inputs**: Image to test, timeout
|
||||
- **Outputs**: pass/fail result, message
|
||||
- **Security**: Non-root user, resource limits
|
||||
|
||||
### Pipeline: `integration-test-pipeline`
|
||||
- **File**: `pipeline-integration-test.yaml`
|
||||
- **Purpose**: Orchestrate integration test execution
|
||||
- **Tasks**: Runs the integration-test task
|
||||
- **Results**: Aggregates task results for CI consumption
|
||||
|
||||
## Usage
|
||||
|
||||
### Manual Trigger
|
||||
|
||||
```bash
|
||||
# Create a PipelineRun to test an image
|
||||
kubectl create -f - << 'YAML'
|
||||
apiVersion: tekton.dev/v1
|
||||
kind: PipelineRun
|
||||
metadata:
|
||||
name: integration-test-manual
|
||||
namespace: api
|
||||
spec:
|
||||
pipelineRef:
|
||||
name: integration-test-pipeline
|
||||
params:
|
||||
- name: image
|
||||
value: forgejo.riotpiao.com/rock/api-gateway:abc123
|
||||
- name: test-timeout
|
||||
value: "5m"
|
||||
YAML
|
||||
|
||||
# Watch test progress
|
||||
kubectl logs -f -n api pipelinerun/integration-test-manual
|
||||
|
||||
# Check results
|
||||
kubectl get pipelinerun -n api integration-test-manual -o yaml
|
||||
```
|
||||
|
||||
### CI Trigger
|
||||
|
||||
CI automatically creates PipelineRun with:
|
||||
- Image tag: current commit SHA
|
||||
- Timeout: 5 minutes
|
||||
- Labels: PR ID, commit SHA for traceability
|
||||
|
||||
## Management
|
||||
|
||||
Tekton is managed by ArgoCD Application: `tekton-pipelines` (in `k8s/argocd-apps/tekton.yaml`)
|
||||
|
||||
To update:
|
||||
1. Edit manifest files
|
||||
2. Commit to git
|
||||
3. ArgoCD syncs automatically
|
||||
|
||||
Do NOT manually apply manifests - let ArgoCD manage everything.
|
||||
|
||||
## Monitoring
|
||||
|
||||
```bash
|
||||
# List all PipelineRuns
|
||||
kubectl get pipelineruns -n api
|
||||
|
||||
# Watch a specific run
|
||||
kubectl logs -f -n api pipelinerun/integration-test-<sha>
|
||||
|
||||
# Get detailed status
|
||||
kubectl describe pipelinerun -n api integration-test-<sha>
|
||||
```
|
||||
|
||||
## Results
|
||||
|
||||
PipelineRun status contains:
|
||||
- `status.conditions[0].reason`: Succeeded | Failed | Unknown
|
||||
- `status.taskRuns[*].status.taskResults`: Test outputs
|
||||
- Pod logs: Detailed test output
|
||||
|
||||
## Best Practices
|
||||
|
||||
1. **DRY**: Task and Pipeline are parameterized, reusable
|
||||
2. **SOLID**: Single responsibility (Task runs tests, Pipeline orchestrates)
|
||||
3. **GitOps**: Everything in git, managed by ArgoCD
|
||||
4. **Security**: Non-root containers, resource limits, no hardcoded values
|
||||
5. **Observability**: Clear logging, status tracking, result aggregation
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
**PipelineRun stuck in Running**
|
||||
- Check pod logs: `kubectl logs -n api pod/<task-pod>`
|
||||
- Check gateway availability: `kubectl get pods -n api -l app=api-gateway`
|
||||
- Increase timeout in pipeline params
|
||||
|
||||
**Tests failing**
|
||||
- Check test logs: `kubectl logs -n api pipelinerun/<run-name>`
|
||||
- Verify gateway is ready and accessible
|
||||
- Check downstream services (memory, S3, etc.)
|
||||
|
||||
**Image not promoted**
|
||||
- CI only promotes if PipelineRun succeeds
|
||||
- Check PipelineRun status: `kubectl get pipelinerun <name> -n api -o yaml`
|
||||
- Review CI logs in Gitea for error details
|
||||
@@ -0,0 +1,44 @@
|
||||
# Tekton Pipelines Release manifest
|
||||
# Source: https://storage.googleapis.com/tekton-releases/pipeline/latest/release.yaml
|
||||
# This is managed by ArgoCD - do NOT manually apply
|
||||
# ArgoCD syncs this from git
|
||||
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: tekton-pipelines
|
||||
labels:
|
||||
managed-by: argocd
|
||||
|
||||
---
|
||||
# CRDs and RBAC are part of the full release manifest
|
||||
# Using a reference approach for cleaner GitOps
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: ApplicationSet
|
||||
metadata:
|
||||
name: tekton-pipelines
|
||||
namespace: argocd
|
||||
spec:
|
||||
generators:
|
||||
- list:
|
||||
elements:
|
||||
- name: tekton-pipelines
|
||||
template:
|
||||
metadata:
|
||||
name: tekton-pipelines
|
||||
namespace: argocd
|
||||
spec:
|
||||
project: default
|
||||
source:
|
||||
repoURL: https://github.com/tektoncd/operator
|
||||
targetRevision: main
|
||||
path: config/release
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: tekton-pipelines
|
||||
syncPolicy:
|
||||
automated:
|
||||
prune: true
|
||||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
@@ -0,0 +1,15 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
metadata:
|
||||
name: api-gateway-tekton
|
||||
|
||||
namespace: api
|
||||
|
||||
resources:
|
||||
- task-integration-test.yaml
|
||||
- pipeline-integration-test.yaml
|
||||
|
||||
commonLabels:
|
||||
app: api-gateway
|
||||
component: testing
|
||||
managed-by: argocd
|
||||
@@ -0,0 +1,35 @@
|
||||
apiVersion: tekton.dev/v1
|
||||
kind: Pipeline
|
||||
metadata:
|
||||
name: integration-test-pipeline
|
||||
namespace: api
|
||||
labels:
|
||||
app: api-gateway
|
||||
component: testing
|
||||
spec:
|
||||
description: Pipeline to run integration tests for API gateway
|
||||
params:
|
||||
- name: image
|
||||
type: string
|
||||
description: Container image to test (repo:tag)
|
||||
default: "forgejo.riotpiao.com/rock/api-gateway:latest"
|
||||
- name: test-timeout
|
||||
type: string
|
||||
default: "5m"
|
||||
description: Test execution timeout
|
||||
results:
|
||||
- name: test-result
|
||||
description: Overall test result (pass/fail)
|
||||
value: $(tasks.run-integration-tests.results.result)
|
||||
- name: test-message
|
||||
description: Test summary message
|
||||
value: $(tasks.run-integration-tests.results.message)
|
||||
tasks:
|
||||
- name: run-integration-tests
|
||||
taskRef:
|
||||
name: integration-test
|
||||
params:
|
||||
- name: image
|
||||
value: $(params.image)
|
||||
- name: timeout
|
||||
value: $(params.test-timeout)
|
||||
@@ -0,0 +1,85 @@
|
||||
apiVersion: tekton.dev/v1
|
||||
kind: Task
|
||||
metadata:
|
||||
name: integration-test
|
||||
namespace: api
|
||||
labels:
|
||||
app: api-gateway
|
||||
component: testing
|
||||
spec:
|
||||
description: Run integration tests for API gateway
|
||||
params:
|
||||
- name: image
|
||||
type: string
|
||||
description: Container image to test (including tag)
|
||||
- name: timeout
|
||||
type: string
|
||||
default: "5m"
|
||||
description: Test timeout
|
||||
results:
|
||||
- name: result
|
||||
description: Test result (pass/fail)
|
||||
type: string
|
||||
- name: message
|
||||
description: Test summary message
|
||||
type: string
|
||||
steps:
|
||||
- name: run-tests
|
||||
image: $(params.image)
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 65532
|
||||
allowPrivilegeEscalation: false
|
||||
env:
|
||||
- name: GATEWAY_URL
|
||||
value: "http://api-gateway:8080"
|
||||
- name: CI
|
||||
value: "true"
|
||||
script: |
|
||||
#!/bin/sh
|
||||
set -e
|
||||
|
||||
echo "🧪 Starting integration tests..."
|
||||
echo "Image: $(params.image)"
|
||||
echo "Gateway: $GATEWAY_URL"
|
||||
echo ""
|
||||
|
||||
# Wait for gateway to be ready
|
||||
echo "Waiting for gateway service..."
|
||||
for i in $(seq 1 30); do
|
||||
if curl -s $GATEWAY_URL/healthz > /dev/null 2>&1; then
|
||||
echo "✓ Gateway is ready"
|
||||
break
|
||||
fi
|
||||
echo "Attempt $i/30: Waiting for gateway..."
|
||||
sleep 2
|
||||
done
|
||||
|
||||
# Run integration tests
|
||||
echo "Running integration tests..."
|
||||
if go test -v -tags=integration -timeout=$(params.timeout) ./internal/integration/...; then
|
||||
echo "pass" | tee $(results.result.path)
|
||||
echo "✓ All integration tests passed" | tee $(results.message.path)
|
||||
exit 0
|
||||
else
|
||||
echo "fail" | tee $(results.result.path)
|
||||
echo "✗ Some integration tests failed" | tee $(results.message.path)
|
||||
exit 1
|
||||
fi
|
||||
volumeMounts:
|
||||
- name: tmp
|
||||
mountPath: /tmp
|
||||
- name: home
|
||||
mountPath: /home/nonroot
|
||||
resources:
|
||||
requests:
|
||||
cpu: 250m
|
||||
memory: 512Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 1Gi
|
||||
volumes:
|
||||
- name: tmp
|
||||
emptyDir: {}
|
||||
- name: home
|
||||
emptyDir: {}
|
||||
Reference in New Issue
Block a user