149 lines
6.0 KiB
Go
149 lines
6.0 KiB
Go
package instance_test
|
|
|
|
import (
|
|
"path/filepath"
|
|
"testing"
|
|
|
|
catalogdata "git.zaynet.fr/DoGaMa/DoGaMa-serv/catalog"
|
|
"git.zaynet.fr/DoGaMa/DoGaMa-serv/internal/catalog"
|
|
"git.zaynet.fr/DoGaMa/DoGaMa-serv/internal/instance"
|
|
)
|
|
|
|
func TestBuildPreviewIsDeterministicAndRedactsSecrets(t *testing.T) {
|
|
snapshots, err := catalog.LoadFS(catalogdata.Files, ".")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
request := instance.PreviewRequest{
|
|
DisplayName: "Family Palworld",
|
|
Slug: "family-palworld",
|
|
HostPorts: map[string]int{"game": 8211},
|
|
MountPaths: map[string]string{"saved": filepath.Join(string(filepath.Separator), "srv", "game-servers", "family-palworld", "saved")},
|
|
DataOrigin: "new",
|
|
BackupRetention: 7,
|
|
}
|
|
first, err := instance.BuildPreview(snapshots[0], request)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
second, err := instance.BuildPreview(snapshots[0], request)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if first.PlanDigest != second.PlanDigest || first.CanonicalJSON != second.CanonicalJSON {
|
|
t.Fatal("preview is not deterministic")
|
|
}
|
|
if first.Game.LogoURL != "/public/game-icons/palworld" || first.Game.ArtworkURL != "/public/game-artwork/palworld" || first.Game.IconURL != first.Game.LogoURL {
|
|
t.Fatalf("game artwork URLs = %#v", first.Game)
|
|
}
|
|
for _, setting := range first.Settings {
|
|
if setting.Secret && setting.Default != nil {
|
|
t.Fatalf("secret default leaked: %#v", setting)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestBuildPreviewUsesTemplateImageUserUnlessAdministratorSelectsOne(t *testing.T) {
|
|
snapshots, err := catalog.LoadFS(catalogdata.Files, ".")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
request := instance.PreviewRequest{
|
|
DisplayName: "Image user", Slug: "image-user", HostPorts: map[string]int{"game": 38211},
|
|
MountPaths: map[string]string{"saved": filepath.Join(t.TempDir(), "saved")}, DataOrigin: "new", BackupRetention: 7,
|
|
}
|
|
preview, err := instance.BuildPreview(snapshots[0], request)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if preview.DockerUser.Mode != instance.DockerUserImage || preview.DockerUserValue != "" {
|
|
t.Fatalf("image-mode preview = %#v", preview.DockerUser)
|
|
}
|
|
plan, err := preview.DeploymentPlan("abcdefghijklmnopqrstuvwx")
|
|
if err != nil || plan.User != "" {
|
|
t.Fatalf("image-mode plan user=%q error=%v", plan.User, err)
|
|
}
|
|
request.DockerUser.Mode = instance.DockerUserDoGaMa
|
|
request.RuntimeIdentity = &instance.RuntimeIdentity{UID: 1234, GID: 5678}
|
|
explicit, err := instance.BuildPreview(snapshots[0], request)
|
|
if err != nil || explicit.DockerUser.Mode != instance.DockerUserImage || explicit.DockerUserValue != "" {
|
|
t.Fatalf("explicit user preview=%#v error=%v", explicit.DockerUser, err)
|
|
}
|
|
}
|
|
|
|
func TestBuildPreviewUsesManagedIdentityAndVRisingEnvironmentMapping(t *testing.T) {
|
|
snapshots, err := catalog.LoadFS(catalogdata.Files, ".")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
vrising := snapshotByID(t, snapshots, "vrising-didstopia")
|
|
identity := instance.RuntimeIdentity{UID: 1234, GID: 5678}
|
|
preview, err := instance.BuildPreview(vrising, instance.PreviewRequest{DisplayName: "V Rising", HostPorts: map[string]int{"game": 38000, "query": 38001}, MountPaths: map[string]string{"persistent": filepath.Join(t.TempDir(), "persistent"), "server": filepath.Join(t.TempDir(), "server")}, DataOrigin: "new", BackupRetention: 7, RuntimeIdentity: &identity})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
plan, err := preview.DeploymentPlan("abcdefghijklmnopqrstuvwx")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if plan.User != "" || plan.Environment["PUID"] != "1234" || plan.Environment["PGID"] != "5678" {
|
|
t.Fatalf("V Rising runtime identity = user %q env %#v", plan.User, plan.Environment)
|
|
}
|
|
if len(plan.CapAdd) != 5 {
|
|
t.Fatalf("V Rising capabilities changed: %#v", plan.CapAdd)
|
|
}
|
|
managed := vrising
|
|
managed.Template.Container.UserMode = instance.DockerUserDoGaMa
|
|
managed.Template.Container.RuntimeUser.Mode = "docker"
|
|
managedPreview, err := instance.BuildPreview(managed, instance.PreviewRequest{DisplayName: "Managed", HostPorts: map[string]int{"game": 38002, "query": 38003}, MountPaths: map[string]string{"persistent": filepath.Join(t.TempDir(), "persistent"), "server": filepath.Join(t.TempDir(), "server")}, DataOrigin: "new", BackupRetention: 7, RuntimeIdentity: &identity})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
managedPlan, err := managedPreview.DeploymentPlan("abcdefghijklmnopqrstuvwx")
|
|
if err != nil || managedPlan.User != "1234:5678" {
|
|
t.Fatalf("managed runtime user = %q error=%v", managedPlan.User, err)
|
|
}
|
|
}
|
|
|
|
func TestBuildPreviewRejectsPrivatePortPublicationAndLowResources(t *testing.T) {
|
|
snapshots, err := catalog.LoadFS(catalogdata.Files, ".")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
base := instance.PreviewRequest{
|
|
DisplayName: "Family Palworld", Slug: "family-palworld",
|
|
HostPorts: map[string]int{"game": 8211, "rest_api": 8212},
|
|
MountPaths: map[string]string{"saved": "/srv/game-servers/family-palworld/saved"},
|
|
DataOrigin: "new", BackupRetention: 7,
|
|
}
|
|
if _, err := instance.BuildPreview(snapshots[0], base); err == nil {
|
|
t.Fatal("private integration port unexpectedly published")
|
|
}
|
|
base.HostPorts = map[string]int{"game": 8211}
|
|
base.Resources = catalog.Resources{CPUCores: 1, MemoryMB: 128, StorageGB: 1}
|
|
if _, err := instance.BuildPreview(snapshots[0], base); err == nil {
|
|
t.Fatal("below-minimum resources unexpectedly accepted")
|
|
}
|
|
}
|
|
|
|
func TestBuildPreviewRejectsUnknownPortAndMountIDs(t *testing.T) {
|
|
snapshots, err := catalog.LoadFS(catalogdata.Files, ".")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
base := instance.PreviewRequest{
|
|
DisplayName: "Family Palworld", Slug: "family-palworld",
|
|
HostPorts: map[string]int{"game": 8211, "unknown": 8212},
|
|
MountPaths: map[string]string{"saved": "/srv/game-servers/family-palworld/saved"},
|
|
DataOrigin: "new", BackupRetention: 7,
|
|
}
|
|
if _, err := instance.BuildPreview(snapshots[0], base); err == nil {
|
|
t.Fatal("unknown port ID unexpectedly accepted")
|
|
}
|
|
base.HostPorts = map[string]int{"game": 8211}
|
|
base.MountPaths["unknown"] = "/srv/game-servers/family-palworld/unknown"
|
|
if _, err := instance.BuildPreview(snapshots[0], base); err == nil {
|
|
t.Fatal("unknown mount ID unexpectedly accepted")
|
|
}
|
|
}
|