mirror of
https://github.com/edgelesssys/constellation.git
synced 2025-02-11 12:38:42 -05:00
![Moritz Sanft](/assets/img/avatar_default.png)
* [wip] use state file in CLI Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> tidy Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * use state file in CLI Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> take clusterConfig from IDFile for compat Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> various fixes Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> wip Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * add GCP-specific values in Helm loader test Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * remove unnecessary pointer Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * write ClusterValues in one step Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * move stub to test file Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * remove mention of id-file Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * move output to `migrateTerraform` Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * unconditional assignments converting from idFile Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * move require block in go modules file Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * fall back to id file on upgrade Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * tidy Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * fix linter check Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * add notice to remove Terraform state check on manual migration Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * add `name` field Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> fix name tests Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * return early if no Terraform diff Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * tidy Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * return infrastructure state even if no diff exists Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * add TODO to remove comment Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * use state-file in miniconstellation Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * cli: remove id-file (#2402) * remove id-file from `constellation create` Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * add file renaming to handler * rename id-file after upgrade * use idFile on `constellation init` Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * remove id-file from `constellation verify` Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * linter fixes Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * remove id-file from `constellation mini` * remove id-file from `constellation recover` * linter fixes * remove id-file from `constellation terminate` * fix initSecret type * fix recover argument precedence * fix terminate test * generate * add TODO to remove id-file removal * Update cli/internal/cmd/init.go Co-authored-by: Adrian Stobbe <stobbe.adrian@gmail.com> * fix verify arg parse logic Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * add version test Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * remove id-file from docs * add file not found log * use state-file in miniconstellation Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * remove id-file from `constellation iam destroy` Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * remove id-file from `cdbg deploy` Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> --------- Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> Co-authored-by: Adrian Stobbe <stobbe.adrian@gmail.com> * use state-file in CI Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> * update orchestration docs --------- Signed-off-by: Moritz Sanft <58110325+msanft@users.noreply.github.com> Co-authored-by: Adrian Stobbe <stobbe.adrian@gmail.com>
217 lines
5.5 KiB
Go
217 lines
5.5 KiB
Go
/*
|
|
Copyright (c) Edgeless Systems GmbH
|
|
SPDX-License-Identifier: AGPL-3.0-only
|
|
*/
|
|
package cmd
|
|
|
|
import (
|
|
"bytes"
|
|
"errors"
|
|
"testing"
|
|
|
|
"github.com/edgelesssys/constellation/v2/internal/cloud/gcpshared"
|
|
"github.com/edgelesssys/constellation/v2/internal/constants"
|
|
"github.com/edgelesssys/constellation/v2/internal/file"
|
|
"github.com/edgelesssys/constellation/v2/internal/logger"
|
|
"github.com/spf13/afero"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
func TestIAMDestroy(t *testing.T) {
|
|
require := require.New(t)
|
|
someError := errors.New("failed")
|
|
|
|
newFsExists := func() file.Handler {
|
|
fh := file.NewHandler(afero.NewMemMapFs())
|
|
require.NoError(fh.Write(constants.GCPServiceAccountKeyFilename, []byte("{}")))
|
|
return fh
|
|
}
|
|
newFsMissing := func() file.Handler {
|
|
fh := file.NewHandler(afero.NewMemMapFs())
|
|
return fh
|
|
}
|
|
newFsWithAdminConf := func() file.Handler {
|
|
fh := file.NewHandler(afero.NewMemMapFs())
|
|
require.NoError(fh.Write(constants.AdminConfFilename, []byte("")))
|
|
return fh
|
|
}
|
|
newFsWithStateFile := func() file.Handler {
|
|
fh := file.NewHandler(afero.NewMemMapFs())
|
|
require.NoError(fh.Write(constants.StateFilename, []byte("")))
|
|
return fh
|
|
}
|
|
|
|
testCases := map[string]struct {
|
|
iamDestroyer *stubIAMDestroyer
|
|
fh file.Handler
|
|
stdin string
|
|
yesFlag string
|
|
wantErr bool
|
|
wantDestroyCalled bool
|
|
}{
|
|
"cluster running admin conf": {
|
|
fh: newFsWithAdminConf(),
|
|
iamDestroyer: &stubIAMDestroyer{},
|
|
yesFlag: "false",
|
|
wantErr: true,
|
|
},
|
|
"cluster running cluster state": {
|
|
fh: newFsWithStateFile(),
|
|
iamDestroyer: &stubIAMDestroyer{},
|
|
yesFlag: "false",
|
|
wantErr: true,
|
|
},
|
|
"file missing abort": {
|
|
fh: newFsMissing(),
|
|
stdin: "n\n",
|
|
yesFlag: "false",
|
|
iamDestroyer: &stubIAMDestroyer{},
|
|
},
|
|
"file missing": {
|
|
fh: newFsMissing(),
|
|
stdin: "y\n",
|
|
yesFlag: "false",
|
|
iamDestroyer: &stubIAMDestroyer{},
|
|
wantDestroyCalled: true,
|
|
},
|
|
"file exists abort": {
|
|
fh: newFsExists(),
|
|
stdin: "n\n",
|
|
yesFlag: "false",
|
|
iamDestroyer: &stubIAMDestroyer{},
|
|
},
|
|
"error destroying user": {
|
|
fh: newFsMissing(),
|
|
stdin: "y\n",
|
|
yesFlag: "false",
|
|
iamDestroyer: &stubIAMDestroyer{destroyErr: someError},
|
|
wantErr: true,
|
|
wantDestroyCalled: true,
|
|
},
|
|
"gcp delete error": {
|
|
fh: newFsExists(),
|
|
yesFlag: "true",
|
|
iamDestroyer: &stubIAMDestroyer{getTfStateKeyErr: someError},
|
|
wantErr: true,
|
|
},
|
|
}
|
|
|
|
for name, tc := range testCases {
|
|
t.Run(name, func(t *testing.T) {
|
|
assert := assert.New(t)
|
|
|
|
cmd := newIAMDestroyCmd()
|
|
cmd.SetOut(&bytes.Buffer{})
|
|
cmd.SetErr(&bytes.Buffer{})
|
|
cmd.SetIn(bytes.NewBufferString(tc.stdin))
|
|
|
|
// register persistent flags manually
|
|
cmd.Flags().String("tf-log", "NONE", "")
|
|
cmd.Flags().String("workspace", "", "")
|
|
|
|
assert.NoError(cmd.Flags().Set("yes", tc.yesFlag))
|
|
|
|
c := &destroyCmd{log: logger.NewTest(t)}
|
|
|
|
err := c.iamDestroy(cmd, &nopSpinner{}, tc.iamDestroyer, tc.fh)
|
|
|
|
if tc.wantErr {
|
|
assert.Error(err)
|
|
} else {
|
|
assert.NoError(err)
|
|
}
|
|
assert.Equal(tc.wantDestroyCalled, tc.iamDestroyer.destroyCalled)
|
|
})
|
|
}
|
|
}
|
|
|
|
func TestDeleteGCPServiceAccountKeyFile(t *testing.T) {
|
|
require := require.New(t)
|
|
someError := errors.New("failed")
|
|
|
|
gcpFile := `
|
|
{
|
|
"auth_provider_x509_cert_url": "",
|
|
"auth_uri": "",
|
|
"client_email": "",
|
|
"client_id": "",
|
|
"client_x509_cert_url": "",
|
|
"private_key": "",
|
|
"private_key_id": "",
|
|
"project_id": "",
|
|
"token_uri": "",
|
|
"type": ""
|
|
}
|
|
`
|
|
|
|
newFs := func() file.Handler {
|
|
fs := file.NewHandler(afero.NewMemMapFs())
|
|
require.NoError(fs.Write(constants.GCPServiceAccountKeyFilename, []byte(gcpFile)))
|
|
return fs
|
|
}
|
|
newFsInvalidJSON := func() file.Handler {
|
|
fh := file.NewHandler(afero.NewMemMapFs())
|
|
require.NoError(fh.Write(constants.GCPServiceAccountKeyFilename, []byte("asdf")))
|
|
return fh
|
|
}
|
|
|
|
testCases := map[string]struct {
|
|
destroyer *stubIAMDestroyer
|
|
fsHandler file.Handler
|
|
stdin string
|
|
wantErr bool
|
|
wantProceed bool
|
|
wantGetSaKeyCalled bool
|
|
}{
|
|
"invalid gcp json": {
|
|
destroyer: &stubIAMDestroyer{},
|
|
fsHandler: newFsInvalidJSON(),
|
|
wantErr: true,
|
|
},
|
|
"error getting key terraform": {
|
|
destroyer: &stubIAMDestroyer{getTfStateKeyErr: someError},
|
|
fsHandler: newFs(),
|
|
wantErr: true,
|
|
wantGetSaKeyCalled: true,
|
|
},
|
|
"keys not same": {
|
|
destroyer: &stubIAMDestroyer{gcpSaKey: gcpshared.ServiceAccountKey{
|
|
Type: "somethingelse",
|
|
}},
|
|
fsHandler: newFs(),
|
|
wantGetSaKeyCalled: true,
|
|
wantProceed: true,
|
|
},
|
|
"valid": {
|
|
destroyer: &stubIAMDestroyer{},
|
|
fsHandler: newFs(),
|
|
wantGetSaKeyCalled: true,
|
|
wantProceed: true,
|
|
},
|
|
}
|
|
|
|
for name, tc := range testCases {
|
|
t.Run(name, func(t *testing.T) {
|
|
assert := assert.New(t)
|
|
|
|
cmd := newIAMDestroyCmd()
|
|
cmd.SetOut(&bytes.Buffer{})
|
|
cmd.SetErr(&bytes.Buffer{})
|
|
cmd.SetIn(bytes.NewBufferString(tc.stdin))
|
|
|
|
c := &destroyCmd{log: logger.NewTest(t)}
|
|
|
|
proceed, err := c.deleteGCPServiceAccountKeyFile(cmd, tc.destroyer, tc.fsHandler)
|
|
if tc.wantErr {
|
|
assert.Error(err)
|
|
} else {
|
|
assert.NoError(err)
|
|
}
|
|
|
|
assert.Equal(tc.wantProceed, proceed)
|
|
assert.Equal(tc.wantGetSaKeyCalled, tc.destroyer.getTfStateKeyCalled)
|
|
})
|
|
}
|
|
}
|