4 Commits
Author SHA1 Message Date
Admin Bot 6eb53a4d1c fix: rewrite Tekton integration tests for X-Service routing
CI / CI (pull_request) In progress
FIXES:
- Remove stale files: k8s/argocd-apps/, k8s/tekton/base/, overlays/
  (Tekton infra is in homelab repo, not here)
- Fix step.resources → step.computeResources (Tekton v1 API)
- Fix Task: use curl sidecar pattern instead of distroless image
  (distroless has no shell/curl/go)
- Fix routing: use X-Service + X-Resource headers, not path-based
- Extract test script to scripts/integration-test.sh (ConfigMap mount)
- Install kubectl in CI runner (was missing)
- Prune README to essentials

TASK ARCHITECTURE:
  sidecar: gateway image (mounts config secret, runs on localhost)
  step: curlimages/curl (runs integration-test.sh from ConfigMap)

TEST COVERAGE:
  health, header validation, memory, s3, sqs, workflow, iam
2026-09-13 21:12:15 +09:00
Admin Bot ba6958e6f3 feat: proper CI/CD workflow with integration testing
CI / CI (pull_request) Failing after 2m57s
BREAKING CHANGE: CI now requires kubeconfig to run integration tests

Changes:
- Build image with commit SHA tag (NOT latest yet)
- Deploy dedicated test pod from new image
- Run full integration test suite against test pod
- Only promote to latest tag AFTER tests pass
- Cleanup test pod after run

CI/CD Flow:
  1. go vet + go test (unit tests)
  2. Build image: api-gateway:<sha>
  3. Push to registry
  4. Deploy test pod with <sha> image
  5. Run integration tests (memory, S3, SQS, workflow, IAM, health)
  6. If tests pass: tag as latest and push
  7. If tests fail: keep <sha> tag, don't promote to latest
  8. Cleanup test pod

This ensures:
- New code is tested in cluster before production deployment
- ArgoCD only pulls latest after tests pass
- Failed builds don't get promoted to production
- Full test coverage of all adapters

Requires: KUBECONFIG_B64 secret in Gitea for cluster access
2026-09-13 14:38:47 +09:00
Admin Bot d27a271c76 feat: add Tekton Pipelines for integration testing
CI / CI (pull_request) Failing after 3m38s
Implement Kubernetes-native CI/CD with Tekton Pipelines:

ARCHITECTURE:
- Tekton Task: Runs integration tests in container
- Tekton Pipeline: Orchestrates test execution
- ArgoCD Application: Manages Tekton installation
- CI: Triggers PipelineRun, reads results, promotes image

FLOW:
1. CI builds image:sha
2. CI creates PipelineRun with new image
3. Tekton controller watches PipelineRun
4. Task executes integration tests
5. Results written to PipelineRun status
6. CI reads status, promotes to :latest if pass
7. ArgoCD detects :latest change and deploys

BENEFITS:
✓ Kubernetes-native (CRDs, no external dependencies)
✓ DRY (parameterized Task/Pipeline)
✓ SOLID (single responsibility, clean interfaces)
✓ GitOps (Tekton managed by ArgoCD)
✓ Observable (logs, status, results)
✓ Secure (non-root, resource limits)

FILES:
- k8s/tekton/task-integration-test.yaml: Task definition
- k8s/tekton/pipeline-integration-test.yaml: Pipeline definition
- k8s/tekton/kustomization.yaml: Kustomize management
- k8s/tekton/README.md: Documentation
- k8s/argocd-apps/tekton.yaml: ArgoCD Application
- .gitea/workflows/ci.yaml: Updated CI to use Tekton

NEXT:
1. Merge PR
2. ArgoCD syncs and installs Tekton
3. First git push triggers PipelineRun
4. Integration tests run in cluster
5. Results feedback to CI
2026-09-13 14:28:51 +09:00
Admin Bot 1e8b0c4ad6 fix: allow paperless namespace ingress to api-gateway
CI / CI (pull_request) Failing after 3m7s
paperless-ai needs LLM API access for document auto-tagging
2026-09-13 13:53:24 +09:00
8 changed files with 374 additions and 23 deletions
+71 -22
View File
@@ -17,10 +17,13 @@ jobs:
name: CI name: CI
runs-on: golang runs-on: golang
steps: steps:
- name: Install Node.js and Docker - name: Install dependencies
run: | run: |
apt-get update apt-get update
apt-get install -y nodejs docker.io apt-get install -y docker.io curl
curl -sLO "https://dl.k8s.io/release/$(curl -sL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl"
chmod +x kubectl && mv kubectl /usr/local/bin/
kubectl version --client
- name: Checkout code - name: Checkout code
uses: actions/checkout@v4 uses: actions/checkout@v4
@@ -47,36 +50,82 @@ jobs:
run: | run: |
docker build --no-cache \ docker build --no-cache \
-t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \ -t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \
-t "${IMAGE}:latest" \
-f Dockerfile . -f Dockerfile .
- name: Push Docker image - name: Push image (SHA tag)
run: | run: docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}"
docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}"
docker push "${IMAGE}:latest"
echo "✓ Pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}"
- name: Prune unused images
run: docker image prune -a --force 2>&1 | tail -3 || true
# ── Tekton integration tests ─────────────────────────────
- name: Setup kubeconfig - name: Setup kubeconfig
run: | run: |
mkdir -p ~/.kube mkdir -p ~/.kube
echo "${KUBECONFIG_B64}" | base64 -d > ~/.kube/config echo "${KUBECONFIG_B64}" | base64 -d > ~/.kube/config
kubectl cluster-info
env: env:
KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }} KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }}
continue-on-error: true
- name: Install kubectl - name: Trigger Tekton PipelineRun
id: tekton
run: | run: |
curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl" SHA="${{ steps.sha.outputs.short_sha }}"
chmod +x kubectl RUN_NAME="integration-test-${SHA}"
sudo mv kubectl /usr/local/bin/
- name: Run integration tests against cluster # Clean up any previous run with the same name
kubectl delete pipelinerun "${RUN_NAME}" -n api --ignore-not-found
# Create PipelineRun — spins up gateway sidecar + curl tests
cat <<YAML | kubectl create -f -
apiVersion: tekton.dev/v1
kind: PipelineRun
metadata:
name: ${RUN_NAME}
namespace: api
labels:
commit-sha: "${SHA}"
spec:
pipelineRef:
name: integration-test-pipeline
params:
- name: image
value: "${IMAGE}:${SHA}"
YAML
echo "✓ PipelineRun created: ${RUN_NAME}"
# Wait for completion (Succeeded or Failed)
echo "Waiting for tests (timeout 5m)..."
if kubectl wait pipelinerun/"${RUN_NAME}" -n api \
--for=condition=Succeeded --timeout=5m 2>/dev/null; then
echo "result=pass" >> $GITHUB_OUTPUT
else
echo "result=fail" >> $GITHUB_OUTPUT
fi
# Print logs + results
echo ""
echo "=== Test Logs ==="
kubectl logs -n api "pipelinerun/${RUN_NAME}" --all-containers 2>/dev/null || true
echo ""
REASON=$(kubectl get pipelinerun "${RUN_NAME}" -n api \
-o jsonpath='{.status.conditions[0].reason}')
SUMMARY=$(kubectl get pipelinerun "${RUN_NAME}" -n api \
-o jsonpath='{.status.results[?(@.name=="test-summary")].value}')
echo "Status: ${REASON}"
echo "Summary: ${SUMMARY}"
- name: Gate on test result
if: steps.tekton.outputs.result != 'pass'
run: | run: |
echo "Running integration tests against production cluster..." echo "✗ Integration tests FAILED — image NOT promoted"
go test -v -tags=integration ./internal/integration/... || true exit 1
env:
GATEWAY_URL: http://api-gateway.api.svc.cluster.local:8080 # ── Promote only after tests pass ────────────────────────
continue-on-error: true - name: Promote image to latest
run: |
docker tag "${IMAGE}:${{ steps.sha.outputs.short_sha }}" "${IMAGE}:latest"
docker push "${IMAGE}:latest"
echo "✓ Promoted to latest"
- name: Cleanup
if: always()
run: docker image prune -af 2>&1 | tail -3 || true
+1 -1
View File
@@ -247,7 +247,7 @@ func TestIntegrationIAMService(t *testing.T) {
} }
defer resp.Body.Close() defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body) _, _ = io.ReadAll(resp.Body)
t.Logf("IAM list users response: %d", resp.StatusCode) t.Logf("IAM list users response: %d", resp.StatusCode)
// IAM (Authentik) should respond - 200, 404, or auth error all prove routing works // IAM (Authentik) should respond - 200, 404, or auth error all prove routing works
+8
View File
@@ -46,6 +46,14 @@ spec:
ports: ports:
- protocol: TCP - protocol: TCP
port: 8080 port: 8080
# Allow from paperless namespace (paperless-ai document auto-tagging)
- from:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: paperless
ports:
- protocol: TCP
port: 8080
egress: egress:
# Allow DNS # Allow DNS
- to: - to:
+58
View File
@@ -0,0 +1,58 @@
# Tekton Integration Tests
Curl-based integration tests for the API gateway, orchestrated by Tekton.
## How It Works
```
CI pushes image:sha → creates PipelineRun → Tekton spins up gateway sidecar
→ runs curl tests → reports pass/fail → CI promotes to :latest if pass
```
The Task runs the gateway image as a **sidecar** (same pod, localhost),
then executes `scripts/integration-test.sh` which tests every adapter
via `X-Service` + `X-Resource` header routing.
## Files
| File | Purpose |
|------|---------|
| `task-integration-test.yaml` | Task: sidecar gateway + curl test step |
| `pipeline-integration-test.yaml` | Pipeline: wraps the Task |
| `scripts/integration-test.sh` | Test script (mounted as ConfigMap) |
| `kustomization.yaml` | Generates ConfigMap from script |
## Manual Run
```bash
kubectl apply -k k8s/tekton/
kubectl create -f - <<'EOF'
apiVersion: tekton.dev/v1
kind: PipelineRun
metadata:
name: integration-test-manual
namespace: api
spec:
pipelineRef:
name: integration-test-pipeline
params:
- name: image
value: forgejo.riotpiao.com/rock/api-gateway:latest
EOF
# Watch
kubectl logs -f -n api pipelinerun/integration-test-manual -c step-run-tests
```
## Updating Tests
Edit `scripts/integration-test.sh`, then:
```bash
kubectl apply -k k8s/tekton/ # recreates ConfigMap
```
## Tekton Infrastructure
Tekton Pipelines is installed in `~/workplace/homelab` via ArgoCD
(`k8s/argocd/apps/06-ci-cd.yaml` → vendored `k8s/infra/tekton/release.yaml`).
+16
View File
@@ -0,0 +1,16 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: api
resources:
- task-integration-test.yaml
- pipeline-integration-test.yaml
generatorOptions:
disableNameSuffixHash: true
configMapGenerator:
- name: integration-test-script
files:
- scripts/integration-test.sh
+30
View File
@@ -0,0 +1,30 @@
apiVersion: tekton.dev/v1
kind: Pipeline
metadata:
name: integration-test-pipeline
namespace: api
labels:
app: api-gateway
component: testing
spec:
description: >
Run integration tests against a gateway image.
Spins up the image as a sidecar, tests via curl, reports pass/fail.
params:
- name: image
type: string
description: "Container image to test (repo:sha)"
results:
- name: test-result
description: "pass or fail"
value: $(tasks.integration-test.results.result)
- name: test-summary
description: "e.g. 8/8 passed"
value: $(tasks.integration-test.results.summary)
tasks:
- name: integration-test
taskRef:
name: integration-test
params:
- name: image
value: $(params.image)
+115
View File
@@ -0,0 +1,115 @@
#!/bin/sh
set -e
# Integration test runner for API gateway.
# Tests X-Service + X-Resource header routing against a gateway on localhost.
#
# Required env:
# GW — gateway base URL (e.g. http://localhost:8080)
# RESULTS_DIR — directory to write Tekton results
PASS=0; FAIL=0; TOTAL=0
assert() {
NAME="$1"; EXPECT="$2"
shift 2
# remaining args are the full curl flags
TOTAL=$((TOTAL + 1))
CODE=$(curl -s -o /dev/null -w '%{http_code}' "$@" 2>/dev/null || echo "000")
if [ "$CODE" = "$EXPECT" ]; then
echo "${NAME} (${CODE})"
PASS=$((PASS + 1))
else
echo "${NAME} — expected ${EXPECT}, got ${CODE}"
FAIL=$((FAIL + 1))
fi
}
# ── Wait for sidecar gateway to be fully ready ──
echo "⏳ Waiting for gateway sidecar..."
READY=false
for i in $(seq 1 60); do
CODE=$(curl -s -o /dev/null -w '%{http_code}' "${GW}/healthz" 2>/dev/null || echo "000")
if [ "$CODE" = "200" ]; then
sleep 1
C2=$(curl -s -o /dev/null -w '%{http_code}' "${GW}/healthz" 2>/dev/null || echo "000")
C3=$(curl -s -o /dev/null -w '%{http_code}' "${GW}/healthz" 2>/dev/null || echo "000")
if [ "$C2" = "200" ] && [ "$C3" = "200" ]; then
READY=true
echo "✓ Gateway ready (stable after 3 checks)"
break
fi
fi
sleep 2
done
if [ "$READY" = "false" ]; then
echo "✗ Gateway never became ready"
echo "fail" > "${RESULTS_DIR}/result"
echo "0/0 gateway timeout" > "${RESULTS_DIR}/summary"
exit 1
fi
echo ""
echo "═══ Integration Tests ═══"
echo ""
# ── Health (path-based, no headers) ──
echo "▸ Health"
assert "GET /healthz" 200 \
-X GET "${GW}/healthz"
assert "GET /readyz" 200 \
-X GET "${GW}/readyz"
# ── Routing: missing headers → 400 ──
echo "▸ Header validation"
assert "no X-Service → 400" 400 \
-X GET "${GW}/"
assert "X-Service without X-Resource → 400" 400 \
-X GET -H "X-Service: memory" "${GW}/"
assert "unknown service → 404" 404 \
-X GET -H "X-Service: nonexistent" -H "X-Resource: foo" "${GW}/"
# ── Memory service (POST, no auth) ──
echo "▸ Memory service"
assert "memory/query (POST)" 200 \
-X POST -H "X-Service: memory" -H "X-Resource: query" \
-H "Content-Type: application/json" -d '{"query":"test"}' "${GW}/"
assert "memory/ingest (POST)" 200 \
-X POST -H "X-Service: memory" -H "X-Resource: ingest" \
-H "Content-Type: application/json" \
-d '{"content":"integration test","metadata":{"source":"tekton"}}' "${GW}/"
# ── S3 service (GET, no auth → MinIO 403) ──
echo "▸ S3 service"
assert "s3/list-objects (GET → 403)" 403 \
-X GET -H "X-Service: s3" -H "X-Resource: list-objects" "${GW}/"
# ── SQS service (GET, auth required → 401) ──
echo "▸ SQS service"
assert "sqs/list-queues (GET → 401)" 401 \
-X GET -H "X-Service: sqs" -H "X-Resource: list-queues" "${GW}/"
# ── Workflow service (gRPC, GET) ──
echo "▸ Workflow service"
assert "workflow/list (GET → upstream err)" 502 \
-X GET -H "X-Service: workflow" -H "X-Resource: list" "${GW}/"
# ── IAM service (GET, Authentik) ──
echo "▸ IAM service"
assert "iam/list-users (GET → Authentik redirect)" 302 \
-X GET -H "X-Service: iam" -H "X-Resource: list-users" "${GW}/"
echo ""
echo "═══ Results: ${PASS}/${TOTAL} passed, ${FAIL} failed ═══"
# Write Tekton results
if [ "$FAIL" -eq 0 ]; then
echo "pass" > "${RESULTS_DIR}/result"
else
echo "fail" > "${RESULTS_DIR}/result"
fi
echo "${PASS}/${TOTAL} passed, ${FAIL} failed" > "${RESULTS_DIR}/summary"
[ "$FAIL" -eq 0 ]
+75
View File
@@ -0,0 +1,75 @@
apiVersion: tekton.dev/v1
kind: Task
metadata:
name: integration-test
namespace: api
labels:
app: api-gateway
component: testing
spec:
description: >
Spin up a gateway pod from the given image as a sidecar,
run curl-based integration tests, report pass/fail.
params:
- name: image
type: string
description: "Container image to test (repo:tag)"
- name: gateway-port
type: string
default: "8080"
results:
- name: result
type: string
- name: summary
type: string
sidecars:
- name: gateway
image: $(params.image)
env:
- name: LISTEN_ADDR
value: "0.0.0.0:$(params.gateway-port)"
- name: CONFIG_PATH
value: /etc/gateway/config.yaml
- name: LOG_LEVEL
value: info
- name: AUTH_CLIENT_SECRET
valueFrom:
secretKeyRef:
name: api-gw-client-secret
key: client-secret
optional: true
volumeMounts:
- name: gateway-config
mountPath: /etc/gateway
readOnly: true
steps:
- name: run-tests
image: curlimages/curl:8.13.0
env:
- name: GW
value: "http://localhost:$(params.gateway-port)"
- name: RESULTS_DIR
value: /tekton/results
command: ["sh", "/scripts/integration-test.sh"]
volumeMounts:
- name: test-script
mountPath: /scripts
readOnly: true
computeResources:
requests:
cpu: 100m
memory: 64Mi
limits:
cpu: 200m
memory: 128Mi
volumes:
- name: gateway-config
secret:
secretName: api-gateway-config
- name: test-script
configMap:
name: integration-test-script
defaultMode: 0755