Merge remote-tracking branch 'origin/release-next' into ziti-edge-quicker-quickstart

This commit is contained in:
dovholuknf
2023-09-06 16:22:16 -04:00
22 changed files with 391 additions and 30 deletions
+33 -8
View File
@@ -206,22 +206,31 @@ jobs:
runs-on: ubuntu-20.04
needs: [ fablab-smoketest ]
steps:
# allow time for investigation unless the workflow is cancelled or the smoketest succeeded or was skipped
- name: Sleep If Failed
if: needs.fablab-smoketest.result != 'success' && needs.fablab-smoketest.result != 'skipped'
if: needs.fablab-smoketest.result != 'success' && needs.fablab-smoketest.result != 'skipped' && needs.fablab-smoketest.result != 'cancelled'
run: |
sleep 30m
# release cloud resources if the smoketest succeeded, failed, or was cancelled; unnecessary if skipped
- name: Teardown Test Environment
if: always() && needs.fablab-smoketest.result != 'skipped'
if: needs.fablab-smoketest.result != 'skipped'
env:
FABLAB_PASSPHRASE: ${{ secrets.FABLAB_PASSPHRASE }}
run: |
aws s3 cp s3://ziti-smoketest-fablab-instances/simple-transfer-${GITHUB_RUN_NUMBER}.tar.gz.gpg .
gpg --quiet --batch --yes --decrypt --passphrase=${FABLAB_PASSPHRASE} --output simple-transfer-${GITHUB_RUN_NUMBER}.tar.gz simple-transfer-${GITHUB_RUN_NUMBER}.tar.gz.gpg
tar -xzf simple-transfer-${GITHUB_RUN_NUMBER}.tar.gz
./simple-transfer-${GITHUB_RUN_NUMBER}/simple-transfer import simple-transfer-${GITHUB_RUN_NUMBER}
./simple-transfer-${GITHUB_RUN_NUMBER}/simple-transfer dispose
aws s3 rm s3://ziti-smoketest-fablab-instances/simple-transfer-${GITHUB_RUN_NUMBER}.tar.gz.gpg
if aws s3api head-object \
--bucket ziti-smoketest-fablab-instances \
--key simple-transfer-${GITHUB_RUN_NUMBER}.tar.gz.gpg
then
aws s3 cp s3://ziti-smoketest-fablab-instances/simple-transfer-${GITHUB_RUN_NUMBER}.tar.gz.gpg .
gpg --quiet --batch --yes --decrypt --passphrase=${FABLAB_PASSPHRASE} --output simple-transfer-${GITHUB_RUN_NUMBER}.tar.gz simple-transfer-${GITHUB_RUN_NUMBER}.tar.gz.gpg
tar -xzf simple-transfer-${GITHUB_RUN_NUMBER}.tar.gz
./simple-transfer-${GITHUB_RUN_NUMBER}/simple-transfer import simple-transfer-${GITHUB_RUN_NUMBER}
./simple-transfer-${GITHUB_RUN_NUMBER}/simple-transfer dispose
aws s3 rm s3://ziti-smoketest-fablab-instances/simple-transfer-${GITHUB_RUN_NUMBER}.tar.gz.gpg
else
echo "WARN: No instance archive found for simple-transfer-${GITHUB_RUN_NUMBER}.tar.gz.gpg" >&2
fi
publish:
name: Publish Binaries
@@ -381,3 +390,19 @@ jobs:
secrets: inherit
with:
ziti-version: ${{ needs.publish.outputs.ZITI_VERSION }}
# call on release-next and main branches to publish linux packages to
# "testing" and "release" package repos in Artifactory
call-publish-linux-packages:
# always() re-enables evaluating conditionals in forks even if Windows or
# macOS builds were skipped
if: |
always()
&& needs.publish.result == 'success'
&& (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/release-next')
name: Publish Linux Packages
needs: publish
uses: ./.github/workflows/publish-linux-packages.yml
secrets: inherit
with:
ziti-version: ${{ needs.publish.outputs.ZITI_VERSION }}
+5 -10
View File
@@ -8,11 +8,6 @@ on:
type: string
required: true
# cancel older, redundant runs of same workflow on same branch
concurrency:
group: ${{ github.workflow }}-${{github.event_name}}-${{ github.head_ref || github.ref_name }}
cancel-in-progress: true
jobs:
publish-docker-images:
runs-on: ubuntu-latest
@@ -70,11 +65,11 @@ jobs:
with:
builder: ${{ steps.buildx.outputs.name }}
context: ${{ github.workspace }}/
file: ${{ github.workspace }}/docker-images/ziti-cli/Dockerfile
file: ${{ github.workspace }}/dist/docker-images/ziti-cli/Dockerfile
platforms: linux/amd64,linux/arm64
tags: ${{ steps.tagprep_cli.outputs.DOCKER_TAGS }}
build-args: |
DOCKER_BUILD_DIR=./docker-images/ziti-cli
DOCKER_BUILD_DIR=./dist/docker-images/ziti-cli
push: true
- name: Set Up Container Image Tags for Controller Container
@@ -97,7 +92,7 @@ jobs:
uses: docker/build-push-action@v3
with:
builder: ${{ steps.buildx.outputs.name }}
context: ${{ github.workspace }}/docker-images/ziti-controller/
context: ${{ github.workspace }}/dist/docker-images/ziti-controller/
platforms: linux/amd64,linux/arm64
tags: ${{ steps.tagprep_ctrl.outputs.DOCKER_TAGS }}
build-args: |
@@ -122,7 +117,7 @@ jobs:
uses: docker/build-push-action@v3
with:
builder: ${{ steps.buildx.outputs.name }}
context: ${{ github.workspace }}/docker-images/ziti-router/
context: ${{ github.workspace }}/dist/docker-images/ziti-router/
platforms: linux/amd64,linux/arm64
tags: ${{ steps.tagprep_router.outputs.DOCKER_TAGS }}
build-args: |
@@ -151,7 +146,7 @@ jobs:
uses: docker/build-push-action@v3
with:
builder: ${{ steps.buildx.outputs.name }}
context: ${{ github.workspace }}/docker-images/ziti-tunnel/
context: ${{ github.workspace }}/dist/docker-images/ziti-tunnel/
platforms: linux/amd64,linux/arm64
tags: ${{ steps.tagprep_tun.outputs.DOCKER_TAGS }}
build-args: |
@@ -0,0 +1,121 @@
name: Publish Linux Packages
on:
workflow_call:
inputs:
ziti-version:
description: generated by 'ziti-ci get-current-version'
type: string
required: true
jobs:
publish-linux-packages:
runs-on: ubuntu-latest
strategy:
matrix:
package_name:
- ziti-cli
arch:
- goreleaser: amd64
gox: amd64
deb: amd64
rpm: x86_64
- goreleaser: arm64
gox: arm64
deb: arm64
rpm: aarch64
- goreleaser: armv7
gox: arm
deb: armv7
rpm: armv7
nfpm_packager:
- rpm
- deb
# - archlinux # (pacman)
# - apk
env:
ZITI_VERSION: ${{ inputs.ziti-version || github.event.inputs.ziti-version }}
ZITI_MAINTAINER: "OpenZiti Maintainers <developers@openziti.org>"
ZITI_HOMEPAGE: "https://openziti.io"
ZITI_VENDOR: "NetFoundry"
GOARCH: ${{ matrix.arch.goreleaser }}
steps:
- name: Checkout Workspace
uses: actions/checkout@v3
- name: Download Linux Release Artifacts
uses: actions/download-artifact@v3
with:
name: linux-release-${{ github.run_id }}
path: release/
- name: Move Release Artifact for Architecture to Predictable Location for nfpm
run: |
mv -v ./release/${{ matrix.arch.gox }}/linux/ziti \
./release/ziti
- name: Build Package
id: nfpm
uses: burningalchemist/action-gh-nfpm@v1
# uses: netfoundry/action-gh-nfpm@main
with:
nfpm_version: "2.32.0"
packager: ${{ matrix.nfpm_packager }}
config: dist/dist-packages/linux/nfpm-${{ matrix.package_name }}.yaml
target: release/
- name: get the package name from the output
run: echo ${{ steps.nfpm.outputs.package }}
shell: bash
- run: ls -lh release/
- name: upload package artifact to build summary page
uses: actions/upload-artifact@v3
with:
name: ${{ matrix.package_name }}-${{ matrix.arch.goreleaser }}-${{ matrix.nfpm_packager }}
path: ./release/${{ matrix.package_name }}*.${{ matrix.nfpm_packager }}
if-no-files-found: error
- name: Configure jFrog CLI
uses: jfrog/setup-jfrog-cli@v3
env:
JF_ENV_1: ${{ secrets.ZITI_ARTIFACTORY_CLI_CONFIG_PACKAGE_UPLOAD }}
- name: Upload RPM to Artifactory testing repo
if: ${{ !github.event.release.published && matrix.nfpm_packager == 'rpm' }}
run: >
jf rt upload
./release/${{ matrix.package_name }}*.${{ matrix.nfpm_packager }}
/zitipax-openziti-rpm-stable/testing/${{ matrix.arch.rpm }}/
--recursive=false
--flat=true
- name: Upload RPM to Artifactory release repo
if: ${{ github.event.release.published && matrix.nfpm_packager == 'rpm' }}
run: >
jf rt upload
./release/${{ matrix.package_name }}*.${{ matrix.nfpm_packager }}
/zitipax-openziti-rpm-stable/release/${{ matrix.arch.rpm }}/
--recursive=false
--flat=true
- name: Upload DEB to Artifactory testing repo
if: ${{ !github.event.release.published && matrix.nfpm_packager == 'deb' }}
run: >
jf rt upload
./release/${{ matrix.package_name }}*.${{ matrix.nfpm_packager }}
/zitipax-openziti-deb-stable/pool/${{ matrix.package_name }}/testing/${{ matrix.arch.deb }}/
--deb=testing/main/${{ matrix.arch.deb }}
--recursive=false
--flat=true
- name: Upload DEB to Artifactory release repo
if: ${{ github.event.release.published && matrix.nfpm_packager == 'deb' }}
run: >
jf rt upload
./release/${{ matrix.package_name }}*.${{ matrix.nfpm_packager }}
/zitipax-openziti-deb-stable/pool/${{ matrix.package_name }}/release/${{ matrix.arch.deb }}/
--deb=release/main/${{ matrix.arch.deb }}
--recursive=false
--flat=true
+31
View File
@@ -0,0 +1,31 @@
name: Test Quickstart
on:
workflow_dispatch:
# test quickstart changes after merge
push:
branches:
- release-next
- main
paths:
- 'quickstart/**'
# test quickstart changes before merge
pull_request:
paths:
- 'quickstart/**'
# cancel older, redundant runs of same workflow on same branch
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.ref_name }}
cancel-in-progress: true
jobs:
compose-test:
name: Test Compose Quickstart
runs-on: ubuntu-latest
steps:
- name: Shallow checkout
uses: actions/checkout@v3
- name: Install zsh
run: sudo apt-get update && sudo apt-get install --yes zsh
- name: Build and run a quickstart container image
run: ./quickstart/test/compose-test.zsh
+1 -1
View File
@@ -5,4 +5,4 @@ Please refer to [the local development README](./doc/002-local-dev.md) for build
## Crossbuilds
When you push to your repo fork then GitHub Actions will automatically crossbuild for several OSs and CPU architectures. You'll then be able to download the built artifacts from the GitHub UI. The easiest way to crossbuild the Linux exectuables locally is to build and run the crossbuild container. Please refer to [the crossbuild container README](../Dockerfile.linux-build.README) for those steps. For hints on crossbuilding for MacOS and Windows see [the main GitHub Actions workflow](../.github/workflows/main.yml) which defines the steps that are run when you push to GitHub.
When you push to your repo fork then GitHub Actions will automatically crossbuild for several OSs and CPU architectures. You'll then be able to download the built artifacts from the GitHub UI. The easiest way to crossbuild the Linux exectuables locally is to build and run the crossbuild container. Please refer to [the crossbuild container README](./docker-images/cross-build/README.md) for those steps. For hints on crossbuilding for MacOS and Windows see [the main GitHub Actions workflow](../.github/workflows/main.yml) which defines the steps that are run when you push to GitHub.
+6
View File
@@ -0,0 +1,6 @@
# nfpm-configs
These are `nfpm` configuration files. `nfpm` generates Linux packages, e.g.,
RPM. These files reference environment variables set in GitHub Actions workflow
`.github/workflows/publish-linux-install-packages.yml`.
+30
View File
@@ -0,0 +1,30 @@
# nfpm configuration file
#
# check https://nfpm.goreleaser.com/configuration for detailed usage
#
name: ziti-cli
arch: ${GOARCH}
platform: linux
version: ${ZITI_VERSION}
maintainer: ${ZITI_MAINTAINER}
description: >
The ziti-cli package provides the ziti executable binary as a command line
interface for Ziti.
vendor: ${ZITI_VENDOR}
homepage: ${ZITI_HOMEPAGE}
license: Apache-2.0
contents:
- src: ./release/ziti
dst: /opt/openziti/bin/ziti
file_info:
mode: 0755
- src: /opt/openziti/bin/ziti
dst: /usr/bin/ziti
type: symlink
# packager-neutral scripts may be overriden by packager-specific scripts
# scripts:
# preinstall: ./scripts/preinstall.sh
# postinstall: ./scripts/postinstall.sh
# preremove: ./scripts/preremove.sh
# postremove: ./scripts/postremove.sh
@@ -12,9 +12,9 @@ This article supports local development by providing a local containerized metho
You only need to build the container image once unless you change the Dockerfile or `./linux-build.sh` (the container's entrypoint).
```bash
# build a container image named "zitibuilder" with the same version of Go that's declared in go.mod
# build a container image named "ziti-go-builder" with the same version of Go that's declared in go.mod
docker buildx build \
--tag=zitibuilder \
--tag=ziti-go-builder \
--build-arg uid=$UID \
--build-arg gid=$GID \
--build-arg golang_version=$(grep -Po '^go\s+\K\d+\.\d+(\.\d+)?$' go.mod) \
@@ -34,16 +34,16 @@ Executing the following `docker run` command will:
# build for all three architectures: amd64 arm arm64
docker run \
--rm \
--name=zitibuilder \
--name=ziti-go-builder \
--volume=$PWD:/mnt \
zitibuilder
ziti-go-builder
# build only amd64
docker run \
--rm \
--name=zitibuilder \
--name=ziti-go-builder \
--volume=$PWD:/mnt \
zitibuilder \
ziti-go-builder \
amd64
```
@@ -53,7 +53,7 @@ You will find the built artifacts in `./release`.
```bash
❯ docker buildx build \
--tag=zitibuilder \
--tag=ziti-go-builder \
--build-arg uid=$UID \
--build-arg gid=$GID \
--build-arg golang_version="$(/bin/grep -Po '^go\s+\K\d+\.\d+(\.\d+)?$' go.mod)" \
@@ -89,9 +89,9 @@ You will find the built artifacts in `./release`.
❯ docker run \
--rm \
--name=zitibuilder \
--name=ziti-go-builder \
--volume=$PWD:/mnt \
zitibuilder
ziti-go-builder
Number of parallel builds: 4
--> linux/arm: github.com/openziti/ziti/ziti
+1 -1
View File
@@ -7,7 +7,7 @@ ZITI_BIN="${SCRIPT_DIR}/image/ziti-bin"
case "${1:-}" in
--build)
mkdir -p "${ZITI_BIN}"
go build -o "${ZITI_BIN}" "${SCRIPT_DIR}/../../..."
GOOS="linux" go build -o "${ZITI_BIN}" "${SCRIPT_DIR}/../../..."
shift
;;
esac
+1 -1
View File
@@ -173,7 +173,7 @@ services:
command: "/var/openziti/scripts/run-router.sh private"
web-test-blue:
image: crccheck/hello-world
image: openziti/hello-world
ports:
- ${ZITI_INTERFACE:-0.0.0.0}:80:8000
networks:
+153
View File
@@ -0,0 +1,153 @@
#!/usr/bin/env zsh
#
# this script tests the quickstart's ziti-cli-functions.sh, container image creation process, and Compose project by
# gathering files from a particular GitHub repo ref or a filesystem path and running the quickstart's Go test suite
# against the running Compose project
#
set -euo pipefail
function down_project() {
# don't destroy volumes or temp dir so we can inspect when running locally
docker compose kill
# rm -rf "${TESTDIR}"
echo "INFO: Stopped Compose project: ${TESTDIR}"
}
DATESTAMP=$(date +%Y%m%d%H%M%S)
# generate a random password for the controller's admin user to ensure we're testing the expected instance
ZITI_PWD="$(set +o pipefail; LC_ALL=C tr -dc -- -A-Z-a-z-0-9 < /dev/urandom 2>/dev/null | head -c5)"
BASENAME="$(basename "$0")"
DIRNAME="$(dirname "$0")"
if [[ -n "${ZITI_QUICK_DIR:-}" ]]; then
if [[ -d "${ZITI_QUICK_DIR}" ]]; then
ZITI_QUICK_DIR="$(realpath "${ZITI_QUICK_DIR}")"
else
if [[ -d "${DIRNAME}/${ZITI_QUICK_DIR}" ]]; then
ZITI_QUICK_DIR="$(realpath "${DIRNAME}/${ZITI_QUICK_DIR}")"
else
echo "ERROR: ZITI_QUICK_DIR is set but is not a directory: ${ZITI_QUICK_DIR}" >&2
exit 1
fi
fi
fi
# avoid re-using directories from previous runs to keep this one-shot (non-idempotent) script simple because we needn't
# consider the state of the test dir
TESTDIR="$(mktemp -d -t "${BASENAME%.*}.${DATESTAMP}.XXX")"
# if unset, set ZITI_QUICK_DIR to this script's parent dir which is always the quickstart root in the git repo
if [[ -z "${ZITI_QUICK_DIR:-}" ]]; then
ZITI_QUICK_DIR="$(realpath "${DIRNAME}/..")"
fi
# if unset, set ZITI_QUICK_IMAGE_TAG to this run's dirname
if [[ -z "${ZITI_QUICK_IMAGE_TAG:-}" ]]; then
ZITI_QUICK_IMAGE_TAG=$(basename "${TESTDIR}")
fi
# case "${1:-}" in
# shift
# ;;
# --help|-h)
# echo "Usage: $BASENAME [--local|--help]"
# exit 0
# ;;
# esac
cd "${TESTDIR}"
echo "INFO: Testing Compose project $PWD"
declare -a QUICK_FILES=(
../go.{mod,sum}
test/{quickstart_test.go,compose.override.yml}
docker/{simplified-docker-compose.yml,.env}
)
# TODO: re-add cert checks files after https://github.com/openziti/ziti/pull/1278
# test/{quickstart_test.go,compose.override.yml,check-cert-chains.zsh}
# download the quickstart Go test suite files from GitHub unless a local dir is specified
if [[ -n "${ZITI_QUICK_DIR:-}" ]]; then
for FILE in "${QUICK_FILES[@]}"; do
cp "${ZITI_QUICK_DIR}/${FILE}" .
done
if [[ -n "${ZITI_QUICK_IMAGE_TAG:-}" ]]; then
if [[ -x "${ZITI_QUICK_DIR:-}/docker/createLocalImage.sh" ]]; then
(
cd "${ZITI_QUICK_DIR}/docker"
unset ZITI_VERSION ZITI_OVERRIDE_VERSION # always build the local source
./createLocalImage.sh --build "${ZITI_QUICK_IMAGE_TAG}"
)
else
echo "ERROR: ZITI_QUICK_IMAGE_TAG is set but ZITI_QUICK_DIR/docker/createLocalImage.sh is not executable" >&2
exit 1
fi
fi
elif [[ -n "${ZITI_QUICK_IMAGE_TAG:-}" ]]; then
echo "ERROR: ZITI_QUICK_IMAGE_TAG is set but ZITI_QUICK_DIR is not set" >&2
exit 1
else
echo "ERROR: ZITI_QUICK_IMAGE_TAG is not set, try running with --local" >&2
exit 1
fi
# rename the simplified Compose file to the default Compose project file name
mv ./simplified-docker-compose.yml ./compose.yml
# learn the expected Go version from the Go mod file so we can pull the correct container image
ZITI_GO_VERSION="$(awk '/^go[[:space:]]+/ {print $2}' ./go.mod)"
# make this var available in the Compose project
sed -Ee "s/^(#[[:space:]]+)?(ZITI_GO_VERSION)=.*/\2=${ZITI_GO_VERSION}/" \
-e "s/^(#[[:space:]]+)?(ZITI_PWD)=.*/\2=${ZITI_PWD}/" \
-e "s/^(#[[:space:]]+)?(ZITI_INTERFACE)=.*/\2=${ZITI_INTERFACE:-127.0.0.1}/" ./.env > ./.env.tmp
mv ./.env.tmp ./.env
# pull images preemptively that we never build locally because pull=never when using a local quickstart image
for IMAGE in \
"golang:${ZITI_GO_VERSION}-alpine" \
"openziti/zac:latest"
do
docker pull --quiet "${IMAGE}" &>/dev/null
done
# any halt after this point should cause the Compose project to be torn down
trap down_project SIGTERM SIGINT EXIT
# if ZITI_QUICK_IMAGE_TAG is set then run the locally-built image
if [[ -n "${ZITI_QUICK_IMAGE_TAG:-}" ]]; then
sed -Ee "s/^(#[[:space:]]+)?(ZITI_VERSION)=.*/\2=${ZITI_QUICK_IMAGE_TAG}/" ./.env > ./.env.tmp
mv ./.env.tmp ./.env
docker compose up --detach --pull=never &>/dev/null # no pull because local quickstart image
else
echo "ERROR: ZITI_QUICK_IMAGE_TAG is not set" >&2
exit 1
fi
# copy files that are not present in older quickstart container images to the persistent volume; this allows us to run
# the test suite against them and investigate if the test fails and the container is destroyed
# for FILE in \
# ""
# check-cert-chains.zsh
# TODO: re-add cert checks to cp list after https://github.com/openziti/ziti/pull/1278
# do
# docker compose cp \
# "./${FILE}" \
# "ziti-controller:/persistent/${FILE}" &>/dev/null
# done
# TODO: build these executables into the container image?
# wait for the controller and router to be ready and run the certificate check script; NOUNSET option is enabled after
# sourcing quickstart functions and env because there are some unset variables in those
docker compose exec ziti-controller \
bash -eo pipefail -c '
source "${ZITI_SCRIPTS}/ziti-cli-functions.sh" >/dev/null;
echo "INFO: waiting for controller";
source /persistent/ziti.env >/dev/null;
_wait_for_controller >/dev/null;
echo "INFO: waiting for public router";
source /persistent/ziti.env >/dev/null;
_wait_for_public_router >/dev/null;
'
# TODO: re-add cert checks to above test suite after https://github.com/openziti/ziti/pull/1278
# zsh /persistent/check-cert-chains.zsh;
docker compose run quickstart-test
echo -e "\nINFO: Test completed successfully."