CI / CI (pull_request) Failing after 2m58s
Add labels to test pod to match network policy selectors: - app=api-gateway (matches network policy pod selector) - managed-by=argocd (matches network policy pod selector) - role=test (identify as test pod) - test-run=<sha> (track which test run spawned it) Network policy 'api-gateway' in api namespace already allows egress to: ✅ kube-system (DNS resolution) ✅ poimen (port 8080 - Memory service) ✅ temporal (port 7233 - Workflow service) ✅ storage (ports 80, 9000 - S3/MinIO) ✅ sqs (port 9090 - SQS service) ✅ iam (ports 9000, 9443 - Authentik/IAM) Test pod inherits same network access as production pods via labels. No additional network policies needed.
76 lines
2.0 KiB
YAML
76 lines
2.0 KiB
YAML
apiVersion: batch/v1
|
|
kind: Job
|
|
metadata:
|
|
name: api-gateway-integration-test
|
|
namespace: api
|
|
spec:
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: api-gateway
|
|
managed-by: test
|
|
role: integration-test
|
|
spec:
|
|
serviceAccountName: api-gateway
|
|
restartPolicy: Never
|
|
containers:
|
|
- name: integration-tester
|
|
image: golang:1.26-bookworm
|
|
imagePullPolicy: IfNotPresent
|
|
workingDir: /workspace
|
|
command:
|
|
- /bin/bash
|
|
- -c
|
|
- |
|
|
set -e
|
|
echo "Starting integration tests..."
|
|
|
|
# Clone the repo
|
|
git clone https://forgejo.riotpiao.com/riotpiao-poimen/homelab-frontend.git .
|
|
|
|
# Wait for gateway to be ready
|
|
echo "Waiting for gateway service to be ready..."
|
|
for i in {1..30}; do
|
|
if curl -s http://api-gateway:8080/healthz | grep -q "alive"; then
|
|
echo "✓ Gateway is ready"
|
|
break
|
|
fi
|
|
echo "Attempting to reach gateway ($i/30)..."
|
|
sleep 2
|
|
done
|
|
|
|
# Run integration tests
|
|
echo "Running integration tests..."
|
|
go test -v -tags=integration -timeout=5m ./internal/integration/...
|
|
|
|
echo "✓ Integration tests completed"
|
|
env:
|
|
- name: GATEWAY_URL
|
|
value: "http://api-gateway:8080"
|
|
resources:
|
|
requests:
|
|
cpu: 250m
|
|
memory: 512Mi
|
|
limits:
|
|
cpu: 500m
|
|
memory: 1Gi
|
|
securityContext:
|
|
runAsNonRoot: true
|
|
runAsUser: 65532
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
readOnlyRootFilesystem: true
|
|
volumeMounts:
|
|
- name: tmp
|
|
mountPath: /tmp
|
|
- name: home
|
|
mountPath: /home/nonroot
|
|
volumes:
|
|
- name: tmp
|
|
emptyDir: {}
|
|
- name: home
|
|
emptyDir: {}
|
|
backoffLimit: 1
|