NAS-118930 / 23.10 / Improve/Refactor Common Library (#917)

* fix

* fix

* some more

* somefixs

* whops

* initial structure

* finish up configmap

* secret class

* runtest secret

* move files arround

* ignore

* make clear on call template that need root context

* imagePullSecret (minus targetSelector)

* move out of the way

* clean up comment

* deployment basic spec

* daemonset basic spec

* statefulset spec

* split file

* docs

* update values

* job spec

* job docs

* cronJob basic spec

* job in cron test

* add common version

* podsepc

* whoopsis

* selectorlabels and pod metadata

* job and cron pod metadata

* update docs

* consistent order

* get ready for pod

* first targetSelector

* remove todo

* update docs

* add hostnet and enableservicelinks

* update selector logic

* update docs

* add tests for restartpolicy

* schedulerName

* priorityclassname

* hostname

* termperiodsec

* nodeselector

* add fail case

* host aliases

* dns policy

* dns config

* tolerations

* serviceaccoutn class, spawner, saname selector

* add pod todo

* update some tests

* add runtimeclassname

* controllers -> workload and plurar to singular

* require at least 1 primary on enabled SAs

* fix script

* remove wrong comment

* update naming scheme

* update rbac values ref

* rbac docs

* rbac's

* append short name, for future use

* update comments

* initial service wireframe

* shorten line

* simplify labels and update tests

* service selectors

* simplify error messages

* finish clusterIP type

* loadbalancer

* noedport

* externalname

* external ip

* update service

* fix highlighting

* session affinity

* add comment

* update comments

* service ports

* fix indentation

* externalname can have no ports

* fixup externalIP

* add pvc class and spawner and tests

* add nfs and emptyDir vols

* example

* extend docs a bit

* not create pvc if existing claim is set

* helm... you are dumb really. how this fixes an unrelated test

* add configmap

* add secret vol

* add pvc vol

* add hostpath

* finish volumes

* initial podsec

* podsec context with some todo's to check

* automatic sysctls

* remove todo

* update doc struct

* split docs

* split service docs

* initial container plumbing

* fix tests

* fix test

* rename to class

* command and args

* termination

* add lifecycle

* int value from tpl

* another case

* fix service protocol tpl

* update readme

* ports

* update todo

* cleanup values a bit

* only add sysctl when port is bellow 1024

* whops, thats a different range

* update avlue

* move some old docs to the "to be deleted" dir

* externalinteface validation

* update an error message and apply externalinterface annotations to workloads

* external interfaces

* TZ - TIMEZONE

* update rdoc

* reduce code duple

* device vol type

* initial certificate plumbing

* update comments

* finish secret creation of certificate

* cert dosc

* volumeMounts

* scale certs

* doc

* add tests for volMounts

* values updates

* update todo

* add test case

* remove some todo

* update todos

* vct

* remove tdoo

* restore default

* rename function

* make selectorlabels a bit better

* trim

* some cleanup

* update some ci values

* update ci

* rollingup defaults

* rename dir

* fix nil pointers

* check the same strategy var

* whops

* fix tests

* typo

* not a good day for copy paste

* move check

* move another check

* fix some tests for upcoming probes

* one mroe

* split docs

* add default probes for `main` and docs

* add probes and some ci testruns

* whops

* fix an edge case

* add an error for edge case

* runtests

* runtest updaets

* update

* check if podvalues exist first

* force types

* force only one of the 2

* quote labels and annotaions values

* job/cron have auto gen selectors

* remove false test

* fix maxsureg

* fix end

* different fix

* fix some tests

* fix rollUp

* try to fix 3.9.4 helm

* move file to helpers

* use capital types in probes and lifecycle

* Revert "use capital types in probes and lifecycle"

This reverts commit 380ebd5f1f.

* typo

* use lowercase for protocol everywhere

* rbac runtest

* prune old

* add resources

* add resources

* fix rbc

* fix sa naming in pod

* fix test

* 44 suppl group on gpu

* remove todo

* extract function in another file

* whops

* add securityContext implementation

* add fail cases

* add rest of the tests

* remove todo

* envFrom

* minify

* env list

* add env

* add envdupe check tests

* add fixed envs

* replace containers with callers

* add callers

* add initContainer

* add init run test

* reset default test val

* add  name tests

* add some more tests

* rename

* validate workload type only if enabled

* lint fix for 3.9.4

* add tpl on init enabled

* whops

* fix init

* echo

* echo

* args...

* list

* comment out disabled persistences

* fix some typos and improve resources `requests` requirement

* improve docs a bit

* require name,description,version,type

* add some wording regarding what Helm Template column means

* add title as requirement

* remove scheduler

* remove priority class name

* remove nfs + externalIP

* remove LB

* remove STS & VCT

* fix a test

* remove nodeselector

* remove DS

* remove pvc

* remove todo

* conditionally print the type, as we might want to use the template to select all objects inthe chart

* add some docs

* docs for notes

* add `tls.` in the certificate secret, according to k8s docs

* add some basic docs around the rest of the options

* clean values.yaml

* catch an edge case

* remove externalName

* set autmountSA on SA to false

* add note about the automountSA
This commit is contained in:
Stavros Kois
2023-02-20 15:23:33 +02:00
committed by GitHub
parent fcf667fc8f
commit 5b1abdd839
258 changed files with 21205 additions and 0 deletions
@@ -0,0 +1,39 @@
name: str(required=True)
title: str(required=True)
description: str(required=True)
version: str(required=True)
type: str(required=True)
kubeVersion: str()
apiVersion: str()
appVersion: any(str(), num())
upstream_version: any(str(), num(), required=False)
home: str()
icon: str()
sources: list(str(), required=False)
dependencies: list(include('dependency'), required=False)
deprecated: bool(required=False)
engine: str(required=False)
condition: str(required=False)
keywords: list(str(), required=False)
tags: str(required=False)
maintainers: list(include('maintainer'))
annotations: map(str(), str(), required=False)
---
maintainer:
name: str()
email: str(required=False)
url: str(required=True)
---
dependency:
name: str()
repository: str()
version: str()
condition: str(required=False)
tags: list(str(), required=False)
import-values: any(list(str()), list(include('import-value')), required=False)
enabled: bool(required=False)
alias: str(required=False)
---
import-value:
child: str()
parent: str()
@@ -0,0 +1,8 @@
remote: origin
target-branch: master
helm-extra-args: --timeout 600s --debug
chart-yaml-schema: .github/ct-install-config/chart_schema.yaml
chart-dirs:
- library
- charts
excluded-charts: []
+7
View File
@@ -0,0 +1,7 @@
remote: origin
target-branch: master
helm-extra-args: --timeout 600s --debug
chart-yaml-schema: .github/ct-install-config/chart_schema.yaml
chart-dirs:
- library
excluded-charts: []
+42
View File
@@ -0,0 +1,42 @@
---
rules:
braces:
min-spaces-inside: 0
max-spaces-inside: 0
min-spaces-inside-empty: -1
max-spaces-inside-empty: -1
brackets:
min-spaces-inside: 0
max-spaces-inside: 0
min-spaces-inside-empty: -1
max-spaces-inside-empty: -1
colons:
max-spaces-before: 0
max-spaces-after: 1
commas:
max-spaces-before: 0
min-spaces-after: 1
max-spaces-after: 1
comments:
require-starting-space: true
min-spaces-from-content: 2
document-end: disable
document-start: disable # No --- to start a file
empty-lines:
max: 2
max-start: 0
max-end: 0
hyphens:
max-spaces-after: 1
indentation:
spaces: consistent
indent-sequences: whatever # - list indentation will handle both indentation and without
check-multi-line-strings: false
key-duplicates: enable
line-length: disable # Lines can be any length
new-line-at-end-of-file: enable
new-lines:
type: unix
trailing-spaces: enable
truthy:
level: warning
+196
View File
@@ -0,0 +1,196 @@
name: Common Library Tests
on:
pull_request:
paths:
- library/**
- .github/workflows/common_library_tests.yaml
jobs:
lint:
name: Lint Common
runs-on: ubuntu-22.04
strategy:
fail-fast: false
matrix:
helm-version:
- v3.9.4
- v3.10.3
- v3.11.1
steps:
- name: Checkout
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # tag=v3
with:
fetch-depth: 1
- name: Install Helm
uses: azure/setup-helm@5119fcb9089d432beecbf79bb2c7915207344b78 # tag=v3
with:
version: ${{ matrix.helm-version }}
- uses: actions/setup-python@2c3dd9e7e29afd70cc0950079bde6c979d1f69f9 # tag=v4
with:
python-version: "3.10"
- name: Set up chart-testing
uses: helm/chart-testing-action@afea100a513515fbd68b0e72a7bb0ae34cb62aec # tag=v2.3.1
- name: Run chart-testing (lint)
id: lint
run: |
ct lint --config .github/ct-install-config/ct-lint.yaml \
--lint-conf .github/ct-install-config/lint-conf.yaml \
--charts library/common-test \
--debug
unittest:
needs:
- lint
name: Unit Tests
runs-on: ubuntu-22.04
env:
helmUnitVersion: 0.2.11
strategy:
fail-fast: false
matrix:
helm-version:
- v3.9.4
- v3.10.3
- v3.11.1
steps:
- name: Checkout
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # tag=v3
with:
fetch-depth: 1
- name: Install Helm
uses: azure/setup-helm@f382f75448129b3be48f8121b9857be18d815a82 # tag=v3
with:
version: ${{ matrix.helm-version }}
- name: Run Unit-tests
shell: bash
run: |
# Retry helm plugin install
helm plugin install https://github.com/quintush/helm-unittest --version v${helmUnitVersion} || \
helm plugin install https://github.com/quintush/helm-unittest --version v${helmUnitVersion} || \
helm plugin install https://github.com/quintush/helm-unittest --version v${helmUnitVersion} || \
helm plugin install https://github.com/quintush/helm-unittest --version v${helmUnitVersion}
# Run tests
cd library/common-test/
helm dependency update
helm unittest --helm3 -f "tests/*/*.yaml" .
install:
needs:
- lint
name: Install Charts
runs-on: ubuntu-22.04
strategy:
fail-fast: false
matrix:
# We run tests on k3s version of latest SCALE release, SCALE nightly and manually defined "latest"
k3s-version:
- v1.25.3+k3s1
# We run tests on Helm version of latest SCALE release, SCALE nightly and manually defined "latest"
helm-version:
- v3.11.1
values:
- basic-values.yaml
- configmap-values.yaml
- secrets-values.yaml
- imagePullSecret-values.yaml
- job-values.yaml
- cron-values.yaml
- persistence-values.yaml
- rbac-values.yaml
- init-values.yaml
steps:
- name: Checkout
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # tag=v3
with:
fetch-depth: 1
- name: Install Helm
uses: azure/setup-helm@f382f75448129b3be48f8121b9857be18d815a82 # tag=v3
with:
version: ${{ matrix.helm-version }}
- uses: actions/setup-python@2c3dd9e7e29afd70cc0950079bde6c979d1f69f9 # tag=v4
with:
python-version: "3.10"
- name: Set up chart-testing
uses: helm/chart-testing-action@afea100a513515fbd68b0e72a7bb0ae34cb62aec # tag=v2.3.1
- name: Create k3d cluster - Attempt 1/3
continue-on-error: true
id: createc1
uses: nolar/setup-k3d-k3s@293b8e5822a20bc0d5bcdd4826f1a665e72aba96 # tag=v1.0.9
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
version: ${{ matrix.k3s-version }}
# Flags found here https://github.com/k3d-io/k3d
k3d-args: --k3s-arg --disable=metrics-server@server:*
- name: Wait 10 second to retry
if: steps.createc1.outcome=='failure'
run: |
sleep 10
- name: Create k3d cluster - Attempt 2/3
continue-on-error: true
if: steps.createc1.outcome=='failure'
id: createc2
uses: nolar/setup-k3d-k3s@293b8e5822a20bc0d5bcdd4826f1a665e72aba96 # tag=v1.0.9
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
version: ${{ matrix.k3s-version }}
# Flags found here https://github.com/k3d-io/k3d
k3d-args: --k3s-arg --disable=metrics-server@server:*
- name: Wait 10 second to retry
if: steps.createc2.outcome=='failure'
run: |
sleep 10
- name: Create k3d cluster - Attempt 3/3
id: createc3
if: steps.createc2.outcome=='failure'
uses: nolar/setup-k3d-k3s@293b8e5822a20bc0d5bcdd4826f1a665e72aba96 # tag=v1.0.9
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
version: ${{ matrix.k3s-version }}
# Flags found here https://github.com/k3d-io/k3d
k3d-args: --k3s-arg --disable=metrics-server@server:*
# Install Kail to grab logs from tests, as there are cases ct-install fail to output logs
- name: Install Kail
run: |
export KAIL_VERSION=v0.16.1
wget https://github.com/boz/kail/releases/download/${KAIL_VERSION}/kail_${KAIL_VERSION}_linux_amd64.tar.gz
tar -xvzf kail_${KAIL_VERSION}_linux_amd64.tar.gz
chmod +x kail
- name: Run chart-testing (install)
run: |
# Move all ci values on a temp location (or skip if already moved from another matrix job)
mv library/common-test/ci library/common-test/runtests || echo "Nothing to move"
# Move one values.yaml to the correct location to run the test
mv -f library/common-test/runtests/${{ matrix.values }} library/common-test/values.yaml
# Stat kail on the background to grab logs from tests
./kail --ignore-ns kube-system >> /tmp/output.log &
# Actually run the test
ct install --config .github/ct-install-config/ct-install.yaml \
--charts library/common-test \
--debug || (echo -e "\n\n--===PODLOGS===--\n\n" && \
cat /tmp/output.log && \
rm -f /tmp/output.log && exit 1)
kill $!
echo -e "\n\n--===PODLOGS===--\n\n"
cat /tmp/output.log
rm -f /tmp/output.log
+3
View File
@@ -34,3 +34,6 @@ npm-debug.log
tests/artifacts/
tests/test-report.txt
tests/test-report.xml
__snapshot__/
library/common-test/Chart.lock
library/common-test/charts
+10
View File
@@ -0,0 +1,10 @@
# https://github.com/DavidAnson/markdownlint/blob/main/doc/Rules.md#md033
# Do not warn for "Inline HTML"
MD033: false
# https://github.com/DavidAnson/markdownlint/blob/v0.26.2/doc/Rules.md#md024
# Multiple headings with the same content
MD024: false
MD013:
line_length: 300
+33
View File
@@ -0,0 +1,33 @@
#!/bin/bash
chart_path=library/common-test
if [ ! $1 == "template" ]; then
if [ $1 == "-f" ] && [ ! -z $2 ]; then
extra_args=("-f" "$chart_path/ci/$2")
fi
fi
function cleanup {
if [ -d "$chart_path/charts" ]; then
echo "🧹 Cleaning up charts..."
rm -r "$chart_path/charts"
rm "$chart_path/Chart.lock"
fi
}
cleanup
echo "Building common..."
helm dependency update "$chart_path"
if [ $1 == "template" ]; then
echo "🧪 Running <helm template ./$chart_path"
helm template -f "$chart_path/default-values.yaml" "./$chart_path" --debug
else
echo "🏁 Running <helm install --dry-run --debug common-test ${extra_args[@]} ./$chart_path"
helm install --dry-run --debug common-test "${extra_args[@]}" "./$chart_path"
fi
helm lint "./$chart_path"
cleanup
+17
View File
@@ -0,0 +1,17 @@
name: common-test
title: Common Library Chart Testing
version: 1.0.0
apiVersion: v2
appVersion: v1.0.0
kubeVersion: '>=1.16.0-0'
description: A chart for the common library chart-testing
home: http://localhost
type: application
icon: https://localhost/icon
dependencies:
- name: common
repository: file://../common/1.0.0
version: ~1.0.0
maintainers:
- name: truenas
url: https://www.truenas.com/
+42
View File
@@ -0,0 +1,42 @@
image:
repository: traefik/whoami
pullPolicy: IfNotPresent
tag: latest
service:
main:
enabled: true
primary: true
ports:
main:
enabled: true
primary: true
protocol: http
port: 8080
workload:
main:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
main:
enabled: true
primary: true
args:
- --port
- "8080"
probes:
liveness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
readiness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
startup:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
@@ -0,0 +1,77 @@
image:
repository: traefik/whoami
pullPolicy: IfNotPresent
tag: latest
service:
main:
enabled: true
primary: true
ports:
main:
enabled: true
primary: true
protocol: http
port: 8080
workload:
main:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
main:
enabled: true
primary: true
args:
- --port
- "8080"
probes:
liveness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
readiness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
startup:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
key1: value1
key2: 80
key3: pair
key4: value2
key5: 81
key6: false
envFrom:
- configMapRef:
name: kv-test
configmap:
kv-test:
enabled: true
data:
key: "{{ .Values.key1 }}"
key1: "{{ .Values.key4 }}"
key2: "{{ .Values.key5 }}"
key3: "{{ .Values.key6 }}"
file-test:
enabled: true
data:
nginx.conf2: |
alias {{ .Values.key3 }}
listen {{ .Values.key2 }}
function {
# some json
"key": {
"key2": "value",
"key3": "value2"
}
}
+44
View File
@@ -0,0 +1,44 @@
image:
repository: traefik/whoami
pullPolicy: IfNotPresent
tag: latest
service:
main:
enabled: true
primary: true
ports:
main:
enabled: true
primary: true
protocol: http
port: 8080
workload:
main:
enabled: true
primary: true
type: CronJob
schedule: "*/1 * * * *"
podSpec:
restartPolicy: OnFailure
containers:
main:
enabled: true
primary: true
args:
- --port
- "8080"
probes:
liveness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
readiness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
startup:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
@@ -0,0 +1,58 @@
image:
repository: traefik/whoami
pullPolicy: IfNotPresent
tag: latest
service:
main:
enabled: true
primary: true
ports:
main:
enabled: true
primary: true
protocol: http
port: 8080
workload:
main:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
main:
enabled: true
primary: true
args:
- --port
- "8080"
probes:
liveness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
readiness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
startup:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
registry: quay.io
user: user
pass: secret_pass
email: mail@example.com
imagePullSecret:
image-secret-name:
enabled: true
labels: {}
annotations: {}
data:
registry: "{{ .Values.registry }}"
username: "{{ .Values.user }}"
password: "{{ .Values.pass }}"
email: "{{ .Values.email }}"
+61
View File
@@ -0,0 +1,61 @@
image:
repository: traefik/whoami
pullPolicy: IfNotPresent
tag: latest
initImage:
repository: bash
pullPolicy: IfNotPresent
tag: latest
workload:
main:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
main:
enabled: true
primary: true
args:
- --port
- "8080"
probes:
liveness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
readiness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
startup:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
initContainers:
init-cont:
enabled: true
type: init
imageSelector: initImage
args:
- echo
- "Hello World"
install-cont:
enabled: true
type: install
imageSelector: initImage
args:
- echo
- "Hello World"
service:
main:
enabled: true
primary: true
ports:
main:
enabled: true
primary: true
protocol: http
port: 8080
+43
View File
@@ -0,0 +1,43 @@
image:
repository: traefik/whoami
pullPolicy: IfNotPresent
tag: latest
service:
main:
enabled: true
primary: true
ports:
main:
enabled: true
primary: true
protocol: http
port: 8080
workload:
main:
enabled: true
primary: true
type: Job
podSpec:
restartPolicy: Never
containers:
main:
enabled: true
primary: true
args:
- --port
- "8080"
probes:
liveness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
readiness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
startup:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
@@ -0,0 +1,73 @@
image:
repository: tccr.io/truecharts/whoami
pullPolicy: IfNotPresent
tag: 1.8.7@sha256:8c61f0ca92fd806fcb4ed1465cb793c05443f37951554b105b0f2dc686a95772
service:
main:
enabled: true
primary: true
ports:
main:
enabled: true
primary: true
port: 8080
workload:
main:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
main:
enabled: true
primary: true
args:
- --port
- "8080"
probes:
liveness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
readiness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
startup:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
persistence:
emptydir:
enabled: true
type: emptyDir
mountPath: /emptydir
emptydir-mem:
enabled: true
type: emptyDir
mountPath: /emptydirmem
medium: Memory
emptydir-size:
enabled: true
type: emptyDir
mountPath: /emptydirsize
size: 1Gi
emptydir-memsize:
enabled: true
type: emptyDir
mountPath: /emptydirmemsize
medium: Memory
size: 1Gi
hostpath-stock:
enabled: true
type: hostPath
hostPath: /usr
mountPath: /hptest
hostPathType: ""
+114
View File
@@ -0,0 +1,114 @@
image:
repository: traefik/whoami
pullPolicy: IfNotPresent
tag: latest
service:
main:
enabled: true
primary: true
ports:
main:
enabled: true
primary: true
protocol: http
port: 8080
workload:
main:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
main:
enabled: true
primary: true
args:
- --port
- "8080"
probes:
liveness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
readiness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
startup:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
workload2:
enabled: true
primary: false
type: Deployment
podSpec:
containers:
main:
enabled: true
primary: true
args:
- --port
- "8080"
probes:
liveness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
readiness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
startup:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
rbac:
main:
enabled: true
primary: true
clusterWide: true
allServiceAccounts: true
labels:
key: value
key1: value1
annotations:
key: value
key1: value1
rules:
- apiGroups:
- ""
resources:
- services
- endpoints
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- list
- watch
serviceAccount:
sa-name:
enabled: true
primary: true
labels:
key: value
key2: value
annotations:
key: value
key2: value
other-sa-name:
enabled: true
targetSelector:
- workload2
@@ -0,0 +1,77 @@
image:
repository: traefik/whoami
pullPolicy: IfNotPresent
tag: latest
service:
main:
enabled: true
primary: true
ports:
main:
enabled: true
primary: true
protocol: http
port: 8080
workload:
main:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
main:
enabled: true
primary: true
args:
- --port
- "8080"
probes:
liveness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
readiness:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
startup:
enabled: true
type: http
port: "{{ .Values.service.main.ports.main.port }}"
key1: value1
key2: 80
key3: pair
key4: value2
key5: 81
key6: false
envFrom:
- secretRef:
name: kv-test
secret:
kv-test:
enabled: true
data:
key: "{{ .Values.key1 }}"
key1: "{{ .Values.key4 }}"
key2: "{{ .Values.key5 }}"
key3: "{{ .Values.key6 }}"
file-test:
enabled: true
data:
nginx.conf2: |
alias {{ .Values.key3 }}
listen {{ .Values.key2 }}
function {
# some json
"key": {
"key2": "value",
"key3": "value2"
}
}
+15
View File
@@ -0,0 +1,15 @@
workload:
main:
enabled: true
podSpec:
containers:
main:
enabled: true
service:
main:
enabled: true
ports:
main:
enabled: true
port: 80
+1
View File
@@ -0,0 +1 @@
{{- include "ix.v1.common.lib.chart.notes" $ -}}
@@ -0,0 +1 @@
{{- include "ix.v1.common.loader.all" . -}}
@@ -0,0 +1,30 @@
suite: certificate data test
templates:
- common.yaml
chart:
appVersion: &appVer v9.9.9
tests:
- it: should pass with secret created for certificate
set:
ixCertificates:
"1":
certificate: some_cert
privatekey: some_key
scaleCertificate:
my-cert:
enabled: true
id: 1
asserts:
- documentIndex: &secretDoc 0
isKind:
of: Secret
- documentIndex: *secretDoc
equal:
path: data
value:
tls.crt: c29tZV9jZXJ0
tls.key: c29tZV9rZXk=
- documentIndex: *secretDoc
equal:
path: type
value: kubernetes.io/tls
@@ -0,0 +1,59 @@
suite: certificate metadata test
templates:
- common.yaml
chart:
appVersion: &appVer v9.9.9
tests:
- it: should pass with certificate created with labels and annotations
set:
label1: label1
label2: global_label2
annotation1: annotation1
annotation2: global_annotation2
global:
labels:
g_label1: global_label1
g_label2: "{{ .Values.label2 }}"
annotations:
g_annotation1: global_annotation1
g_annotation2: "{{ .Values.annotation2 }}"
ixCertificates:
"1":
certificate: some_cert
privatekey: some_key
scaleCertificate:
my-cert:
enabled: true
id: 1
labels:
label1: "{{ .Values.label1 }}"
label2: label2
annotations:
annotation1: "{{ .Values.annotation1 }}"
annotation2: annotation2
asserts:
- documentIndex: &secretDoc 0
isKind:
of: Secret
- documentIndex: *secretDoc
equal:
path: metadata.annotations
value:
annotation1: annotation1
annotation2: annotation2
g_annotation1: global_annotation1
g_annotation2: global_annotation2
- documentIndex: *secretDoc
equal:
path: metadata.labels
value:
app: common-test-1.0.0
release: RELEASE-NAME
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/version: *appVer
g_label1: global_label1
g_label2: global_label2
label1: label1
label2: label2
@@ -0,0 +1,41 @@
suite: certificate name test
templates:
- common.yaml
tests:
- it: should generate correct name
set:
ixCertificates:
"1":
certificate: some_cert
privatekey: some_key
"2":
certificate: some_cert
privatekey: some_key
scaleCertificate:
my-cert1:
enabled: true
id: 1
my-cert2:
enabled: true
id: 2
asserts:
- documentIndex: &secretDoc 0
isKind:
of: Secret
- documentIndex: *secretDoc
isAPIVersion:
of: v1
- documentIndex: *secretDoc
equal:
path: metadata.name
value: release-name-common-test-my-cert1
- documentIndex: &otherSecretDoc 1
isKind:
of: Secret
- documentIndex: *otherSecretDoc
isAPIVersion:
of: v1
- documentIndex: *otherSecretDoc
equal:
path: metadata.name
value: release-name-common-test-my-cert2
@@ -0,0 +1,143 @@
suite: certificate validation test
templates:
- common.yaml
tests:
- it: should fail with name longer than 63 characters
set:
scaleCertificate:
my-certificate-super-long-name-that-is-longer-than-63-characters:
enabled: true
id: 1
asserts:
- failedTemplate:
errorMessage: Name [release-name-common-test-my-certificate-super-long-name-that-is-longer-than-63-characters] is not valid. Must start and end with an alphanumeric lowercase character. It can contain '-'. And must be at most 63 characters.
- it: should fail with name starting with underscore
set:
scaleCertificate:
_my-cert:
enabled: true
id: 1
asserts:
- failedTemplate:
errorMessage: Name [release-name-common-test-_my-cert] is not valid. Must start and end with an alphanumeric lowercase character. It can contain '-'. And must be at most 63 characters.
- it: should fail with labels not a dict
set:
scaleCertificate:
my-cert:
enabled: true
labels: "not a dict"
id: 1
asserts:
- failedTemplate:
errorMessage: Certificate - Expected <labels> to be a dictionary, but got [string]
- it: should fail with annotations not a dict
set:
scaleCertificate:
my-cert:
enabled: true
annotations: "not a dict"
id: 1
asserts:
- failedTemplate:
errorMessage: Certificate - Expected <annotations> to be a dictionary, but got [string]
- it: should fail without id
set:
scaleCertificate:
my-cert:
enabled: true
id: ""
asserts:
- failedTemplate:
errorMessage: Certificate - Expected non-empty <id>
- it: should fail with targetSelector not a dict
set:
scaleCertificate:
my-cert:
enabled: true
id: 1
targetSelector: "not a dict"
asserts:
- failedTemplate:
errorMessage: Certificate - Expected <targetSelector> to be a [map], but got [string]
- it: should fail with empty ixCertificates when cert is defined
set:
ixCertificates: []
scaleCertificate:
my-cert:
enabled: true
id: 1
asserts:
- failedTemplate:
errorMessage: Certificate - Expected non-empty <ixCertificates>
- it: should fail with not defined id in ixCertificates when cert is defined
set:
ixCertificates:
"2":
key: value
scaleCertificate:
my-cert:
enabled: true
id: 1
asserts:
- failedTemplate:
errorMessage: Certificate - Expected certificate with <id> ["1"] to exist in <ixCertificates>
- it: should fail with with revoked cert
set:
ixCertificates:
"1":
revoked: true
scaleCertificate:
my-cert:
enabled: true
id: 1
asserts:
- failedTemplate:
errorMessage: Certificate - Expected non-revoked certificate with <id> ["1"]
- it: should fail with with expired cert
set:
ixCertificates:
"1":
expired: true
scaleCertificate:
my-cert:
enabled: true
id: 1
asserts:
- failedTemplate:
errorMessage: Certificate - Expected non-expired certificate with <id> ["1"]
- it: should fail with with empty certificate
set:
ixCertificates:
"1":
certificate: ""
scaleCertificate:
my-cert:
enabled: true
id: 1
asserts:
- failedTemplate:
errorMessage: Certificate - Expected non-empty [certificate] in certificate with <id> ["1"] in <ixCertificates>
- it: should fail with with empty privatekey
set:
ixCertificates:
"1":
certificate: some_value
privatekey: ""
scaleCertificate:
my-cert:
enabled: true
id: 1
asserts:
- failedTemplate:
errorMessage: Certificate - Expected non-empty [privatekey] in certificate with <id> ["1"] in <ixCertificates>
@@ -0,0 +1,92 @@
suite: configmap data test
templates:
- common.yaml
tests:
- it: should pass with key-value data
set:
configmap:
my-configmap1:
enabled: true
data:
foo: bar
asserts:
- documentIndex: &configmapDoc 0
isKind:
of: ConfigMap
- documentIndex: *configmapDoc
equal:
path: data
value:
foo: bar
- it: should pass with key-value data from tpl
set:
data: bar
configmap:
my-configmap1:
enabled: true
data:
foo: "{{ .Values.data }}"
asserts:
- documentIndex: *configmapDoc
equal:
path: data
value:
foo: bar
- it: should pass with scalar data
set:
configmap:
my-configmap1:
enabled: true
data:
foo: |
some multi line
string text
asserts:
- documentIndex: *configmapDoc
equal:
path: data
value:
foo: |
some multi line
string text
- it: should pass with scalar data with tpl
set:
data: Some other text
configmap:
my-configmap:
enabled: true
data:
foo: |
file start
{{ .Values.data }}
asserts:
- documentIndex: *configmapDoc
equal:
path: data
value:
foo: |
file start
Some other text
- it: should pass with scalar data from tpl
set:
data: |
Some other text
some_text
configmap:
my-configmap1:
enabled: true
data:
foo: |
{{- .Values.data | nindent 2 }}
asserts:
- documentIndex: *configmapDoc
equal:
path: data
value:
foo: |
Some other text
some_text
@@ -0,0 +1,56 @@
suite: configmap metadata test
templates:
- common.yaml
chart:
appVersion: &appVer v9.9.9
tests:
- it: should pass with configmap created with labels and annotations
set:
label1: label1
label2: global_label2
annotation1: annotation1
annotation2: global_annotation2
global:
labels:
g_label1: global_label1
g_label2: "{{ .Values.label2 }}"
annotations:
g_annotation1: global_annotation1
g_annotation2: "{{ .Values.annotation2 }}"
configmap:
my-configmap1:
enabled: true
labels:
label1: "{{ .Values.label1 }}"
label2: label2
annotations:
annotation1: "{{ .Values.annotation1 }}"
annotation2: annotation2
data:
foo: bar
asserts:
- documentIndex: &configMapDoc 0
isKind:
of: ConfigMap
- documentIndex: *configMapDoc
equal:
path: metadata.annotations
value:
annotation1: annotation1
annotation2: annotation2
g_annotation1: global_annotation1
g_annotation2: global_annotation2
- documentIndex: *configMapDoc
equal:
path: metadata.labels
value:
app: common-test-1.0.0
release: RELEASE-NAME
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/version: *appVer
g_label1: global_label1
g_label2: global_label2
label1: label1
label2: label2
@@ -0,0 +1,36 @@
suite: configmap name test
templates:
- common.yaml
tests:
- it: should generate correct name
set:
configmap:
my-configmap1:
enabled: true
data:
foo: bar
my-configmap2:
enabled: true
data:
foo: bar
asserts:
- documentIndex: &configmapDoc 0
isKind:
of: ConfigMap
- documentIndex: *configmapDoc
isAPIVersion:
of: v1
- documentIndex: *configmapDoc
equal:
path: metadata.name
value: release-name-common-test-my-configmap1
- documentIndex: &otherConfigmapDoc 1
isKind:
of: ConfigMap
- documentIndex: *otherConfigmapDoc
isAPIVersion:
of: v1
- documentIndex: *otherConfigmapDoc
equal:
path: metadata.name
value: release-name-common-test-my-configmap2
@@ -0,0 +1,69 @@
suite: configmap validation test
templates:
- common.yaml
tests:
- it: should fail with name longer than 63 characters
set:
configmap:
my-configmap-super-long-name-that-is-longer-than-63-characters:
enabled: true
data:
foo: bar
asserts:
- failedTemplate:
errorMessage: Name [release-name-common-test-my-configmap-super-long-name-that-is-longer-than-63-characters] is not valid. Must start and end with an alphanumeric lowercase character. It can contain '-'. And must be at most 63 characters.
- it: should fail with name starting with underscore
set:
configmap:
_my-configmap:
enabled: true
data:
foo: bar
asserts:
- failedTemplate:
errorMessage: Name [release-name-common-test-_my-configmap] is not valid. Must start and end with an alphanumeric lowercase character. It can contain '-'. And must be at most 63 characters.
- it: should fail with labels not a dict
set:
configmap:
my-configmap:
enabled: true
labels: "not a dict"
data:
foo: bar
asserts:
- failedTemplate:
errorMessage: ConfigMap - Expected <labels> to be a dictionary, but got [string]
- it: should fail with annotations not a dict
set:
configmap:
my-configmap:
enabled: true
annotations: "not a dict"
data:
foo: bar
asserts:
- failedTemplate:
errorMessage: ConfigMap - Expected <annotations> to be a dictionary, but got [string]
- it: should fail with data not a dict
set:
configmap:
my-configmap:
enabled: true
data: "not a dict"
asserts:
- failedTemplate:
errorMessage: ConfigMap - Expected <data> to be a dictionary, but got [string]
- it: should fail with empty data
set:
configmap:
my-configmap:
enabled: true
data: {}
asserts:
- failedTemplate:
errorMessage: ConfigMap - Expected non-empty <data>
@@ -0,0 +1,123 @@
suite: container arg test
templates:
- common.yaml
tests:
- it: should create the correct multiple args
set:
some_port: 80
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
args:
- --port
- "{{ .Values.some_port }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
args:
- --port
- "80"
- it: should create the correct arg command
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
args: --accept-eula
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
args:
- --accept-eula
- it: should create the correct multiple args and extraArgs
set:
some_path: /some/path
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
args:
- --port
- "80"
extraArgs:
- --accept-eula
- --path
- "{{ .Values.some_path }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
args:
- --port
- "80"
- --accept-eula
- --path
- /some/path
@@ -0,0 +1,118 @@
suite: container command test
templates:
- common.yaml
tests:
- it: should create the correct command in scalar
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
command:
- /bin/sh
- -c
- |
echo "Using image {{ .Values.image.repository }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
command:
- /bin/sh
- -c
- |
echo "Using image nginx"
- it: should create the correct single command
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
command: ./start.sh
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
command:
- ./start.sh
- it: should create the correct multiple command
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
command:
- ./print.sh
- "{{ .Values.image.repository }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
command:
- ./print.sh
- nginx
@@ -0,0 +1,360 @@
suite: container envFixed test
templates:
- common.yaml
tests:
- it: should create the correct fixed envs
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
TZ: Europe/London
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
env:
- name: TZ
value: Europe/London
- name: UMASK
value: "002"
- name: UMASK_SET
value: "002"
- name: S6_READ_ONLY_ROOT
value: "1"
- it: should create the correct fixed envs when running as root
set:
image: *image
TZ: Europe/London
securityContext:
container:
runAsUser: 0
runAsGroup: 0
runAsNonRoot: false
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
env:
- name: TZ
value: Europe/London
- name: UMASK
value: "002"
- name: UMASK_SET
value: "002"
- name: PUID
value: "568"
- name: USER_ID
value: "568"
- name: UID
value: "568"
- name: PGID
value: "568"
- name: GROUP_ID
value: "568"
- name: GID
value: "568"
- name: S6_READ_ONLY_ROOT
value: "1"
- it: should create the correct fixed envs when running as root and changed fsGroup
set:
image: *image
TZ: Europe/London
securityContext:
container:
runAsUser: 0
runAsGroup: 0
runAsNonRoot: false
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
securityContext:
fsGroup: 1000
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
env:
- name: TZ
value: Europe/London
- name: UMASK
value: "002"
- name: UMASK_SET
value: "002"
- name: PUID
value: "568"
- name: USER_ID
value: "568"
- name: UID
value: "568"
- name: PGID
value: "1000"
- name: GROUP_ID
value: "1000"
- name: GID
value: "1000"
- name: S6_READ_ONLY_ROOT
value: "1"
- it: should create the correct fixed envs when running as root and not readonly
set:
image: *image
TZ: Europe/London
securityContext:
container:
runAsUser: 0
runAsGroup: 0
runAsNonRoot: false
readOnlyRootFilesystem: false
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
env:
- name: TZ
value: Europe/London
- name: UMASK
value: "002"
- name: UMASK_SET
value: "002"
- name: PUID
value: "568"
- name: USER_ID
value: "568"
- name: UID
value: "568"
- name: PGID
value: "568"
- name: GROUP_ID
value: "568"
- name: GID
value: "568"
- it: should create the correct fixed envs with GPU
set:
scaleGPU:
- gpu:
nvidia.com/gpu: 1
targetSelector:
workload-name:
- container-name1
image: *image
TZ: Europe/London
containerOptions:
NVIDIA_CAPS:
- compute
- video
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
env:
- name: TZ
value: Europe/London
- name: UMASK
value: "002"
- name: UMASK_SET
value: "002"
- name: NVIDIA_DRIVER_CAPABILITIES
value: "compute,video"
- name: S6_READ_ONLY_ROOT
value: "1"
- it: should create the correct fixed envs with GPU and overrided on container level
set:
scaleGPU:
- gpu:
nvidia.com/gpu: 1
targetSelector:
workload-name:
- container-name1
image: *image
TZ: Europe/London
containerOptions:
NVIDIA_CAPS:
- compute
- video
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
fixedEnv:
NVIDIA_CAPS:
- all
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
env:
- name: TZ
value: Europe/London
- name: UMASK
value: "002"
- name: UMASK_SET
value: "002"
- name: NVIDIA_DRIVER_CAPABILITIES
value: "all"
- name: S6_READ_ONLY_ROOT
value: "1"
# Failures
- it: it should fail with NVIDIA_CAPS having invalid values
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
fixedEnv:
NVIDIA_CAPS:
- invalid
- compute
asserts:
- failedTemplate:
errorMessage: Container - Expected <fixedEnv.NVIDIA_CAPS> entry to be one of [all, compute, utility, graphics, video], but got [invalid]
- it: it should fail with NVIDIA_CAPS not having unique values
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
fixedEnv:
NVIDIA_CAPS:
- compute
- compute
asserts:
- failedTemplate:
errorMessage: Container - Expected <fixedEnv.NVIDIA_CAPS> to have only unique values, but got [compute, compute]
@@ -0,0 +1,258 @@
suite: container envFrom test
templates:
- common.yaml
tests:
- it: should create the correct envFrom
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
configmap:
configmap-name:
enabled: true
data:
key1: value1
key2: value2
secret:
secret-name:
enabled: true
data:
key3: value3
key4: value4
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
envFrom:
- configMapRef:
name: configmap-name
- secretRef:
name: secret-name
asserts:
- documentIndex: &deploymentDoc 2
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
envFrom:
- configMapRef:
name: release-name-common-test-configmap-name
- secretRef:
name: release-name-common-test-secret-name
- it: should create the correct envFrom without expanding the name
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
some_config_name: configmap-name
some_secret_name: secret-name
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
envFrom:
- configMapRef:
name: "{{ .Values.some_config_name }}"
expandObjectName: false
- secretRef:
name: "{{ .Values.some_secret_name }}"
expandObjectName: false
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
envFrom:
- configMapRef:
name: configmap-name
- secretRef:
name: secret-name
# Failures
- it: it should fail without a valid ref
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
envFrom:
- invalidRef:
name: invalid-name
asserts:
- failedTemplate:
errorMessage: Container - Expected <envFrom> entry to have one of [configMapRef, secretRef]
- it: it should fail with both refs in the same entry
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
envFrom:
- configMapRef:
name: configmap-name
secretRef:
name: secret-name
asserts:
- failedTemplate:
errorMessage: Container - Expected <envFrom> entry to have only one of [configMapRef, secretRef], but got both
- it: it should fail with empty name in configMapRef
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
envFrom:
- configMapRef:
name: ""
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <envFrom.configMapRef.name>
- it: it should fail with empty name in secretRef
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
envFrom:
- secretRef:
name: ""
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <envFrom.secretRef.name>
- it: it should fail without defined configmap
set:
image: *image
configmap:
configmap-name:
enabled: true
data:
key1: value1
key2: value2
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
envFrom:
- configMapRef:
name: configmap-other-name
asserts:
- failedTemplate:
errorMessage: Container - Expected ConfigMap [configmap-other-name] defined in <envFrom> to exist
- it: it should fail without defined secret
set:
image: *image
secret:
secret-name:
enabled: true
data:
key1: value1
key2: value2
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
envFrom:
- secretRef:
name: secret-other-name
asserts:
- failedTemplate:
errorMessage: Container - Expected Secret [secret-other-name] defined in <envFrom> to exist
@@ -0,0 +1,85 @@
suite: container envList test
templates:
- common.yaml
tests:
- it: should create the correct envList
set:
some_value: value1
some_other_value: 2
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
envList:
- name: env1
value: "{{ .Values.some_value }}"
- name: env2
value: "{{ .Values.some_other_value }}"
- name: env3
value: ""
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].env
content:
name: env1
value: value1
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].env
content:
name: env2
value: "2"
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].env
content:
name: env3
value: ""
# Failures
- it: it should fail with empty name
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
envList:
- name: ""
value: some_value
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <envList.name>
@@ -0,0 +1,252 @@
suite: container env dupe test
templates:
- common.yaml
tests:
# Failures
- it: should fail with dupe env in env and envList
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
env:
VAR1: some_value
envList:
- name: VAR1
value: 123
asserts:
- failedTemplate:
errorMessage: Container - Environment Variable [VAR1] in [envList] tried to override the Environment Variable that is already defined in [env]
- it: should fail with dupe env in env and envFrom configmap
set:
image: *image
configmap:
configmap-name:
enabled: true
data:
VAR1: value
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
VAR1: some_value
envFrom:
- configMapRef:
name: configmap-name
asserts:
- failedTemplate:
errorMessage: Container - Environment Variable [VAR1] in [env] tried to override the Environment Variable that is already defined in [ConfigMap - configmap-name]
- it: should fail with dupe env in env and envFrom secret
set:
image: *image
secret:
secret-name:
enabled: true
data:
VAR1: value
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
VAR1: some_value
envFrom:
- secretRef:
name: secret-name
asserts:
- failedTemplate:
errorMessage: Container - Environment Variable [VAR1] in [env] tried to override the Environment Variable that is already defined in [Secret - secret-name]
- it: should fail with dupe env in envList and envFrom secret
set:
image: *image
secret:
secret-name:
enabled: true
data:
VAR1: value
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
envList:
- name: VAR1
value: some_value
envFrom:
- secretRef:
name: secret-name
asserts:
- failedTemplate:
errorMessage: Container - Environment Variable [VAR1] in [envList] tried to override the Environment Variable that is already defined in [Secret - secret-name]
- it: should fail with dupe env in envList and envFrom configmap
set:
image: *image
configmap:
configmap-name:
enabled: true
data:
VAR1: value
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
envList:
- name: VAR1
value: some_value
envFrom:
- configMapRef:
name: configmap-name
asserts:
- failedTemplate:
errorMessage: Container - Environment Variable [VAR1] in [envList] tried to override the Environment Variable that is already defined in [ConfigMap - configmap-name]
- it: should fail with dupe env in fixedEnv and env
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
TZ: some_value
asserts:
- failedTemplate:
errorMessage: Container - Environment Variable [TZ] in [env] tried to override the Environment Variable that is already defined in [fixedEnv]
- it: should fail with dupe env in fixedEnv and envList
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
envList:
- name: TZ
value: some_value
asserts:
- failedTemplate:
errorMessage: Container - Environment Variable [TZ] in [envList] tried to override the Environment Variable that is already defined in [fixedEnv]
- it: should fail with dupe env in fixedEnv and envFrom configmap
set:
image: *image
configmap:
configmap-name:
enabled: true
data:
TZ: value
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
envFrom:
- configMapRef:
name: configmap-name
asserts:
- failedTemplate:
errorMessage: Container - Environment Variable [TZ] in [fixedEnv] tried to override the Environment Variable that is already defined in [ConfigMap - configmap-name]
- it: should fail with dupe env in fixedEnv and envFrom secret
set:
image: *image
secret:
secret-name:
enabled: true
data:
TZ: value
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
envFrom:
- secretRef:
name: secret-name
asserts:
- failedTemplate:
errorMessage: Container - Environment Variable [TZ] in [fixedEnv] tried to override the Environment Variable that is already defined in [Secret - secret-name]
@@ -0,0 +1,402 @@
suite: container env test
templates:
- common.yaml
tests:
- it: should create the correct env
set:
some_value: value1
some_other_value: 2
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
configmap:
configmap-name:
enabled: true
data:
key1: value1
key2: value2
secret:
secret-name:
enabled: true
data:
key1: value1
key2: value2
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
env:
VAR1: "{{ .Values.some_value }}"
VAR2: some_value
VAR3:
configMapKeyRef:
name: configmap-name
key: key1
VAR4:
secretKeyRef:
name: secret-name
key: key2
VAR5:
configMapKeyRef:
expandObjectName: false
name: configmap-name
key: key3
VAR6:
secretKeyRef:
expandObjectName: false
name: secret-name
key: key4
VAR7:
fieldRef:
fieldPath: metadata.name
asserts:
- documentIndex: &deploymentDoc 2
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].env
content:
name: VAR1
value: value1
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].env
content:
name: VAR2
value: some_value
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].env
content:
name: VAR3
valueFrom:
configMapKeyRef:
key: key1
name: release-name-common-test-configmap-name
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].env
content:
name: VAR4
valueFrom:
secretKeyRef:
key: key2
name: release-name-common-test-secret-name
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].env
content:
name: VAR5
valueFrom:
configMapKeyRef:
key: key3
name: configmap-name
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].env
content:
name: VAR6
valueFrom:
secretKeyRef:
key: key4
name: secret-name
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].env
content:
name: VAR7
valueFrom:
fieldRef:
fieldPath: metadata.name
# Failures
- it: it should fail invalid ref
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
VAR:
invalidKeyRef: {}
asserts:
- failedTemplate:
errorMessage: Container - Expected <env> with a ref to have one of [configMapKeyRef, secretKeyRef, fieldRef], but got [invalidKeyRef]
- it: it should fail with more than one ref
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
VAR:
configMapKeyRef: {}
secretKeyRef: {}
asserts:
- failedTemplate:
errorMessage: Container - Expected <env> with a ref to have one of [configMapKeyRef, secretKeyRef, fieldRef], but got [configMapKeyRef, secretKeyRef]
- it: it should fail with empty name in configMapKeyRef
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
VAR:
configMapKeyRef:
name: ""
key: key
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <env.configMapKeyRef.name>
- it: it should fail with empty key in configMapKeyRef
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
VAR:
configMapKeyRef:
name: name
key: ""
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <env.configMapKeyRef.key>
- it: it should fail with empty name in secretKeyRef
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
VAR:
secretKeyRef:
name: ""
key: key
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <env.secretKeyRef.name>
- it: it should fail with empty key in secretKeyRef
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
VAR:
secretKeyRef:
name: name
key: ""
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <env.secretKeyRef.key>
- it: it should fail with referenced secret not defined
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
VAR:
secretKeyRef:
name: secret-name
key: somekey
asserts:
- failedTemplate:
errorMessage: Container - Expected in <env> the referenced Secret [secret-name] to be defined
- it: it should fail with referenced configmap not defined
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
VAR:
configMapKeyRef:
name: configmap-name
key: somekey
asserts:
- failedTemplate:
errorMessage: Container - Expected in <env> the referenced Configmap [configmap-name] to be defined
- it: it should fail with referenced key in configmap not defined
set:
image: *image
configmap:
configmap-name:
enabled: true
data:
key1: value1
key2: value2
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
VAR:
configMapKeyRef:
name: configmap-name
key: somekey
asserts:
- failedTemplate:
errorMessage: Container - Expected in <env> the referenced key [somekey] in Configmap [configmap-name] to be defined
- it: it should fail with referenced key in secret not defined
set:
image: *image
secret:
secret-name:
enabled: true
data:
key1: value1
key2: value2
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
VAR:
secretKeyRef:
name: secret-name
key: somekey
asserts:
- failedTemplate:
errorMessage: Container - Expected in <env> the referenced key [somekey] in Secret [secret-name] to be defined
- it: it should fail with empty fieldPath in fieldRef
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
env:
VAR:
fieldRef:
fieldPath: ""
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <env.fieldRef.fieldPath>
@@ -0,0 +1,139 @@
suite: container image test
templates:
- common.yaml
tests:
- it: should generate correct image
set:
imageDictToUse: image
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
imageGPU:
repository: some-gpu-image
tag: 5.20.0
pullPolicy: Always
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: "{{ .Values.imageDictToUse }}"
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
container-name2:
enabled: true
primary: false
imageSelector: imageGPU
probes: *probes
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
image: nginx:1.19.0
imagePullPolicy: IfNotPresent
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[1]
content:
image: some-gpu-image:5.20.0
imagePullPolicy: Always
# Failures
- it: should fail with imageSelector trying to access non-existent image
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image-dict-that-does-not-exist
asserts:
- failedTemplate:
errorMessage: Container - Expected <.Values.image-dict-that-does-not-exist> to exist
- it: should fail with empty repository in selected image
set:
image:
repository: ""
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <.Values.image.repository>
- it: should fail with empty tag in selected image
set:
image:
repository: nginx
tag: ""
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <.Values.image.tag>
- it: should fail with invalid pullPolicy selected image
set:
image:
repository: nginx
tag: 1.19.0
pullPolicy: invalid
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
asserts:
- failedTemplate:
errorMessage: Container - Expected <.Values.image.pullPolicy> to be one of [IfNotPresent, Always, Never], but got [invalid]
@@ -0,0 +1,272 @@
suite: container lifecycle test
templates:
- common.yaml
tests:
- it: should pass with lifecycle
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
lifecycle:
postStart:
type: exec
command:
- echo
- hello
preStop:
type: http
port: 80
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
lifecycle:
postStart:
exec:
command:
- echo
- hello
preStop:
httpGet:
port: 80
path: /
scheme: HTTP
- it: should pass with lifecycle
set:
image: *image
some_command: ./some_command
some_port: 80
some_host: some_host
some_path: /api/v1
some_value: 123
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
lifecycle:
postStart:
type: https
port: "{{ .Values.some_port }}"
host: "{{ .Values.some_host }}"
path: "{{ .Values.some_path }}"
httpHeaders:
key: "{{ .Values.some_value }}"
preStop:
type: exec
command: "{{ .Values.some_command }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
lifecycle:
postStart:
httpGet:
port: 80
path: /api/v1
scheme: HTTPS
host: some_host
httpHeaders:
- name: key
value: "123"
preStop:
exec:
command:
- ./some_command
# Failures
- it: should fail with invalid lifecycle hook
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
probes: *probes
imageSelector: image
lifecycle:
invalid: {}
asserts:
- failedTemplate:
errorMessage: Container - Expected <lifecycle> <hook> to be one of [preStop, postStart], but got [invalid]
- it: should fail with empty lifecycle type
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
lifecycle:
preStop:
command: []
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <lifecycle> <type>
- it: should fail with invalid lifecycle type
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
lifecycle:
preStop:
type: invalid
command: []
asserts:
- failedTemplate:
errorMessage: Container - Expected <lifecycle> <type> to be one of [exec, http, https], but got [invalid]
- it: should fail with empty command on exec lifecycle type
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
lifecycle:
preStop:
type: exec
command: []
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <lifecycle> <command> on [exec] type
- it: should fail with empty port on http lifecycle type
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
lifecycle:
preStop:
type: http
port: ""
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <lifecycle> <port> on [http] type
- it: should fail with path not starting with / on http lifecycle type
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
lifecycle:
preStop:
type: http
port: 80
path: "api/v1"
asserts:
- failedTemplate:
errorMessage: Container - Expected <lifecycle> <path> to start with a forward slash [/] on <http> type
- it: should fail with empty value on httpHeaders on http lifecycle type
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
lifecycle:
preStop:
type: http
port: 80
httpHeaders:
key: ""
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <value> on <httpHeaders>
@@ -0,0 +1,50 @@
suite: container name test
templates:
- common.yaml
tests:
- it: should generate correct container name
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
name: release-name-common-test
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[1]
content:
name: release-name-common-test-container-name2
@@ -0,0 +1,284 @@
suite: container ports test
templates:
- common.yaml
tests:
- it: should create the correct ports without selector
set:
some_port: 80
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
service:
my-service1:
enabled: true
primary: true
ports:
port-name:
enabled: true
primary: true
port: "{{ .Values.some_port }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
ports:
- name: port-name
containerPort: 80
protocol: TCP
- documentIndex: &otherDeploymentDoc 1
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
isNull:
path: spec.template.spec.containers[0].ports
- it: should create the correct ports with selector
set:
some_port: 53
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
service:
my-service1:
enabled: true
primary: true
targetSelector: workload-name1
ports:
port-name:
enabled: true
primary: true
targetSelector: container-name1
port: 1234
my-service2:
enabled: true
primary: false
targetSelector: workload-name2
ports:
port-name:
enabled: true
primary: true
targetSelector: container-name1
port: 54
targetPort: "{{ .Values.some_port }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
ports:
- name: port-name
containerPort: 1234
protocol: TCP
- documentIndex: &otherDeploymentDoc 1
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
ports:
- name: port-name
containerPort: 53
protocol: TCP
- it: should create the correct ports with hostPort
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
service:
my-service1:
enabled: true
primary: true
ports:
port-name:
enabled: true
primary: true
port: 1234
targetPort: 5678
hostPort: 20000
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
ports:
- name: port-name
containerPort: 5678
protocol: TCP
hostPort: 20000
- it: should create the correct protocol from tpl
set:
some_protocol: https
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
service:
my-service1:
enabled: true
primary: true
ports:
port-name:
enabled: true
primary: true
port: 1234
protocol: "{{ .Values.some_protocol }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
ports:
- name: port-name
containerPort: 1234
protocol: TCP
- it: should create the correct protocol
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
service:
my-service1:
enabled: true
primary: true
ports:
port-name:
enabled: true
primary: true
port: 1234
protocol: udp
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
ports:
- name: port-name
containerPort: 1234
protocol: UDP
@@ -0,0 +1,673 @@
suite: container probe test
templates:
- common.yaml
tests:
- it: should create the probes correctly
set:
some_port: 80
some_path: /healthz
some_command: echo
probe_type: exec
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: true
type: http
port: "{{ .Values.some_port }}"
path: "{{ .Values.some_path }}"
readiness:
enabled: true
type: tcp
port: 123
startup:
enabled: true
type: "{{ .Values.probe_type }}"
command:
- "{{ .Values.some_command }}"
- hello
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
livenessProbe:
httpGet:
path: /healthz
port: 80
scheme: HTTP
failureThreshold: 5
initialDelaySeconds: 10
periodSeconds: 10
successThreshold: 1
timeoutSeconds: 5
readinessProbe:
tcpSocket:
port: 123
failureThreshold: 5
initialDelaySeconds: 10
periodSeconds: 10
successThreshold: 2
timeoutSeconds: 5
startupProbe:
exec:
command:
- echo
- hello
failureThreshold: 60
initialDelaySeconds: 10
periodSeconds: 5
successThreshold: 1
timeoutSeconds: 2
- it: should create https probe
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: true
type: https
port: 443
spec:
initialDelaySeconds: 120
timeoutSeconds: 10
periodSeconds: 15
successThreshold: 1
failureThreshold: 3
readiness:
enabled: true
type: tcp
port: 443
spec:
initialDelaySeconds: 50
timeoutSeconds: 30
periodSeconds: 8
successThreshold: 5
failureThreshold: 9
startup:
enabled: true
type: tcp
port: 443
spec:
initialDelaySeconds: 25
timeoutSeconds: 40
periodSeconds: 7
successThreshold: 1
failureThreshold: 12
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
livenessProbe:
httpGet:
path: /
port: 443
scheme: HTTPS
failureThreshold: 3
initialDelaySeconds: 120
periodSeconds: 15
successThreshold: 1
timeoutSeconds: 10
readinessProbe:
tcpSocket:
port: 443
failureThreshold: 9
initialDelaySeconds: 50
periodSeconds: 8
successThreshold: 5
timeoutSeconds: 30
startupProbe:
tcpSocket:
port: 443
failureThreshold: 12
initialDelaySeconds: 25
periodSeconds: 7
successThreshold: 1
timeoutSeconds: 40
# Failures
- it: should fail with invalid probe
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
invalid:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected probe to be one of [liveness, readiness, startup], but got [invalid]
- it: should fail without probes defined
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: {}
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <probes>
- it: should fail without liveness defined
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected <probes.liveness> to be defined
- it: should fail without readiness defined
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected <probes.readiness> to be defined
- it: should fail without startup defined
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: false
readiness:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected <probes.startup> to be defined
- it: should fail with invalid type
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: true
type: invalid
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected probe type to be one of [http, https, tcp, grpc, exec], but got [invalid]
- it: should fail with successThreshold more than 1 on liveness
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: true
type: http
port: 8080
spec:
successThreshold: 2
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected <probes> <successThreshold> to be 1 on [liveness] probe
- it: should fail with successThreshold more than 1 on startup
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
startup:
enabled: true
type: http
port: 8080
spec:
successThreshold: 2
readiness:
enabled: false
liveness:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected <probes> <successThreshold> to be 1 on [startup] probe
- it: should fail with initialDelaySeconds not a number
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: true
type: http
port: 8080
spec:
initialDelaySeconds: invalid
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected <probes> <initialDelaySeconds> to be a number, but got [invalid]
- it: should fail with failureThreshold not a number
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: true
type: http
port: 8080
spec:
failureThreshold: invalid
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected <probes> <failureThreshold> to be a number, but got [invalid]
- it: should fail with successThreshold not a number
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: true
type: http
port: 8080
spec:
successThreshold: invalid
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected <probes> <successThreshold> to be a number, but got [invalid]
- it: should fail with timeoutSeconds not a number
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: true
type: http
port: 8080
spec:
timeoutSeconds: invalid
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected <probes> <timeoutSeconds> to be a number, but got [invalid]
- it: should fail with periodSeconds not a number
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: true
type: http
port: 8080
spec:
periodSeconds: invalid
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected <probes> <periodSeconds> to be a number, but got [invalid]
- it: should fail with empty command on exec type
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: true
type: exec
command: []
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <probes> <command> on [exec] type
- it: should fail with empty port on grpc type
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: true
type: grpc
port: ""
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <probes> <port> on [grpc] type
- it: should fail with empty port on tcp type
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: true
type: tcp
port: ""
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <probes> <port> on [tcp] type
- it: should fail with empty port on http type
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: true
type: http
port: ""
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <probes> <port> on [http] type
- it: should fail with invalid path on http type
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: true
type: http
port: 8080
path: not-starting-with-slash
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected <probes> <path> to start with a forward slash [/] on <http> type
- it: should fail with empty value in http headers
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: true
type: http
port: not-starting-with-slash
httpHeaders:
key:
readiness:
enabled: false
startup:
enabled: false
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <value> on <httpHeaders>
@@ -0,0 +1,877 @@
suite: container resources test
templates:
- common.yaml
tests:
- it: should create the resources correctly
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 4000m
memory: 8Gi
requests:
cpu: 10m
memory: 50Mi
- it: should override the default limits
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
resources:
limits:
cpu: 2000m
memory: 4Gi
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 2000m
memory: 4Gi
requests:
cpu: 10m
memory: 50Mi
- it: should override the default limits.cpu
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
resources:
limits:
cpu: 2000m
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 2000m
memory: 8Gi
requests:
cpu: 10m
memory: 50Mi
- it: should override the default limits.memory
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
resources:
limits:
memory: 4Gi
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 4000m
memory: 4Gi
requests:
cpu: 10m
memory: 50Mi
- it: should not render limits.cpu
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
resources:
limits:
cpu: 0
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
memory: 8Gi
requests:
cpu: 10m
memory: 50Mi
- it: should not render limits.memory
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
resources:
limits:
memory: 0
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 4000m
requests:
cpu: 10m
memory: 50Mi
- it: should override the default requests
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
resources:
requests:
cpu: 200m
memory: 1Gi
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 4000m
memory: 8Gi
requests:
cpu: 200m
memory: 1Gi
- it: should override the default requests.cpu
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
resources:
requests:
cpu: 200m
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 4000m
memory: 8Gi
requests:
cpu: 200m
memory: 50Mi
- it: should override the default requests.memory
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
resources:
requests:
memory: 1Gi
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 4000m
memory: 8Gi
requests:
cpu: 10m
memory: 1Gi
- it: should assign GPU on the primary pod/container
set:
image: *image
scaleGPU:
- gpu:
nvidia.com/gpu: 1
global:
ixChartContext:
addNvidiaRuntimeClass: true
nvidiaRuntimeClassName: nvidia
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.runtimeClassName
value: nvidia
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 4000m
memory: 8Gi
nvidia.com/gpu: "1"
requests:
cpu: 10m
memory: 50Mi
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[1]
content:
resources:
limits:
cpu: 4000m
memory: 8Gi
requests:
cpu: 10m
memory: 50Mi
- documentIndex: &otherDeploymentDoc 1
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *otherDeploymentDoc
isNull:
path: spec.template.spec.runtimeClassName
- documentIndex: *otherDeploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 4000m
memory: 8Gi
requests:
cpu: 10m
memory: 50Mi
- it: should assign GPU on the selected pod/container
set:
image: *image
global:
ixChartContext:
addNvidiaRuntimeClass: true
nvidiaRuntimeClassName: nvidia
scaleGPU:
- gpu:
nvidia.com/gpu: 1
targetSelector:
workload-name2:
- container-name1
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.runtimeClassName
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 4000m
memory: 8Gi
requests:
cpu: 10m
memory: 50Mi
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[1]
content:
resources:
limits:
cpu: 4000m
memory: 8Gi
requests:
cpu: 10m
memory: 50Mi
- documentIndex: &otherDeploymentDoc 1
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *otherDeploymentDoc
equal:
path: spec.template.spec.runtimeClassName
value: nvidia
- documentIndex: *otherDeploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 4000m
memory: 8Gi
nvidia.com/gpu: "1"
requests:
cpu: 10m
memory: 50Mi
- it: should assign GPU on the selected pods/containers
set:
image: *image
global:
ixChartContext:
addNvidiaRuntimeClass: true
nvidiaRuntimeClassName: nvidia
scaleGPU:
- gpu:
nvidia.com/gpu: 1
targetSelector:
workload-name1:
- container-name1
- container-name2
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.runtimeClassName
value: nvidia
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 4000m
memory: 8Gi
nvidia.com/gpu: "1"
requests:
cpu: 10m
memory: 50Mi
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[1]
content:
resources:
limits:
cpu: 4000m
memory: 8Gi
nvidia.com/gpu: "1"
requests:
cpu: 10m
memory: 50Mi
- documentIndex: &otherDeploymentDoc 1
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *otherDeploymentDoc
isNull:
path: spec.template.spec.runtimeClassName
- documentIndex: *otherDeploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
resources:
limits:
cpu: 4000m
memory: 8Gi
requests:
cpu: 10m
memory: 50Mi
# Failures
- it: should fail with empty requests
set:
image: *image
containerOptions:
resources:
requests:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <resources.requests>
- it: should fail with empty requests.cpu
set:
image: *image
containerOptions:
resources:
requests:
cpu: ""
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <resources.requests.cpu>
- it: should fail with empty requests.memory
set:
image: *image
containerOptions:
resources:
requests:
cpu: 10m
memory: ""
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <resources.requests.memory>
- it: should fail with invalid format in requests.cpu
set:
image: *image
containerOptions:
resources:
requests:
cpu: 10MB
memory: 50Mi
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- failedTemplate:
errorMessage: Container - Expected <resources.requests.cpu> to have one of the following formats [(Plain Integer - eg. 1), (Float - eg. 0.5), (Milicpu - eg. 500m)], but got [10MB]
- it: should fail with invalid format in limits.cpu
set:
image: *image
containerOptions:
resources:
requests:
cpu: 10m
memory: 50Mi
limits:
cpu: 10MB
memory: 8Gi
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- failedTemplate:
errorMessage: Container - Expected <resources.limits.cpu> to have one of the following formats [(Plain Integer - eg. 1), (Float - eg. 0.5), (Milicpu - eg. 500m)], but got [10MB]
- it: should fail with invalid format in requests.memory
set:
image: *image
containerOptions:
resources:
requests:
cpu: 10m
memory: 50MB
limits:
cpu: 4000m
memory: 8Gi
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- failedTemplate:
errorMessage: Container - Expected <resources.requests.memory> to have one of the following formats [(Suffixed with E/P/T/G/M/K - eg. 1G), (Suffixed with Ei/Pi/Ti/Gi/Mi/Ki - eg. 1Gi), (Plain Integer in bytes - eg. 1024), (Exponent - eg. 134e6)], but got [50MB]
- it: should fail with invalid format in limits.memory
set:
image: *image
containerOptions:
resources:
requests:
cpu: 10m
memory: 50Mi
limits:
cpu: 4000m
memory: 8GB
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- failedTemplate:
errorMessage: Container - Expected <resources.limits.memory> to have one of the following formats [(Suffixed with E/P/T/G/M/K - eg. 1G), (Suffixed with Ei/Pi/Ti/Gi/Mi/Ki - eg. 1Gi), (Plain Integer in bytes - eg. 1024), (Exponent - eg. 134e6)], but got [8GB]
- it: should fail with empty gpu in defined entry
set:
image: *image
scaleGPU:
- gpu:
targetSelector:
workload-name1:
- container-name1
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <scaleGPU.gpu>
- it: should fail with empty list under workload in targetSelector
set:
image: *image
scaleGPU:
- gpu:
key: value
targetSelector:
workload-name1: []
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty list under pod in <scaleGPU.targetSelector>
- it: should fail with empty value in gpu
set:
image: *image
scaleGPU:
- gpu:
key: ""
targetSelector:
workload-name1:
- container-name1
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <scaleGPU> <value>
@@ -0,0 +1,778 @@
suite: container security context test
templates:
- common.yaml
tests:
- it: should create the securityContext correctly
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
securityContext:
runAsUser: 568
runAsGroup: 568
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
privileged: false
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
capabilities:
add: []
drop:
- ALL
- it: should override the securityContext runAsUser and runAsNonRoot
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
runAsUser: 0
runAsNonRoot: false
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
securityContext:
runAsUser: 0
runAsGroup: 568
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
privileged: false
runAsNonRoot: false
seccompProfile:
type: RuntimeDefault
capabilities:
add: []
drop:
- ALL
- it: should override the securityContext runAsGroup and runAsNonRoot
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
runAsGroup: 0
runAsNonRoot: false
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
securityContext:
runAsUser: 568
runAsGroup: 0
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
privileged: false
runAsNonRoot: false
seccompProfile:
type: RuntimeDefault
capabilities:
add: []
drop:
- ALL
- it: should override the securityContext readOnlyRootFilesystem
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
readOnlyRootFilesystem: false
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
securityContext:
runAsUser: 568
runAsGroup: 568
readOnlyRootFilesystem: false
allowPrivilegeEscalation: false
privileged: false
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
capabilities:
add: []
drop:
- ALL
- it: should override the securityContext privileged
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
privileged: true
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
securityContext:
runAsUser: 568
runAsGroup: 568
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
privileged: true
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
capabilities:
add: []
drop:
- ALL
- it: should override the securityContext allowPrivilegeEscalation
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
allowPrivilegeEscalation: true
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
securityContext:
runAsUser: 568
runAsGroup: 568
readOnlyRootFilesystem: true
allowPrivilegeEscalation: true
privileged: false
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
capabilities:
add: []
drop:
- ALL
- it: should override the securityContext capabilities.add
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
capabilities:
add:
- NET_ADMIN
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
securityContext:
runAsUser: 568
runAsGroup: 568
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
privileged: false
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
capabilities:
add:
- NET_ADMIN
drop:
- ALL
- it: should override the securityContext capabilities.drop
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
capabilities:
drop:
- NET_ADMIN
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
securityContext:
runAsUser: 568
runAsGroup: 568
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
privileged: false
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
capabilities:
add: []
drop:
- NET_ADMIN
- it: should override the securityContext seccompProfile.type
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
seccompProfile:
type: Unconfined
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
securityContext:
runAsUser: 568
runAsGroup: 568
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
privileged: false
runAsNonRoot: true
seccompProfile:
type: Unconfined
capabilities:
add: []
drop:
- ALL
- it: should override the securityContext all
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
runAsUser: 1000
runAsGroup: 1000
readOnlyRootFilesystem: false
allowPrivilegeEscalation: true
privileged: true
runAsNonRoot: false
capabilities:
add:
- NET_ADMIN
drop:
- NET_BIND_SERVICE
seccompProfile:
type: Localhost
profile: path/to/profile.json
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
securityContext:
runAsUser: 1000
runAsGroup: 1000
readOnlyRootFilesystem: false
allowPrivilegeEscalation: true
privileged: true
runAsNonRoot: false
seccompProfile:
type: Localhost
localhostProfile: path/to/profile.json
capabilities:
add:
- NET_ADMIN
drop:
- NET_BIND_SERVICE
# Failures
- it: should fail with empty securityContext
set:
image: *image
securityContext:
container:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- failedTemplate:
errorMessage: Container - Expected non-empty <.Values.securityContext.container>
- it: should fail with runAsNonRoot not a bool
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
runAsNonRoot: "true"
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.runAsNonRoot> to be [bool], but got [true] of type [string]
- it: should fail with readOnlyRootFilesystem not a bool
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
readOnlyRootFilesystem: "true"
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.readOnlyRootFilesystem> to be [bool], but got [true] of type [string]
- it: should fail with allowPrivilegeEscalation not a bool
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
allowPrivilegeEscalation: "true"
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.allowPrivilegeEscalation> to be [bool], but got [true] of type [string]
- it: should fail with privileged not a bool
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
privileged: "true"
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.privileged> to be [bool], but got [true] of type [string]
- it: should fail with runAsUser not an int
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
runAsUser: "568"
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.runAsUser> to be [int], but got [568] of type [string]
- it: should fail with runAsGroup not an int
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
runAsGroup: "568"
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.runAsGroup> to be [int], but got [568] of type [string]
- it: should fail without seccompProfile
set:
image: *image
securityContext:
container:
seccompProfile:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.seccompProfile> to be defined
- it: should fail with invalid seccompProfile
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
seccompProfile:
type: invalid
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.seccompProfile> to be one of [RuntimeDefault, Localhost, Unconfined], but got [invalid]
- it: should fail without profile on seccompProfile Localhost
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
seccompProfile:
type: Localhost
profile: ""
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.seccompProfile.profile> to be defined on type [Localhost]
- it: should fail without capabilities
set:
image: *image
securityContext:
container:
capabilities:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.capabilities> to be defined
- it: should fail capabilities.add not a list
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
capabilities:
add: invalid
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.capabilities.add> to be [list], but got [string]
- it: should fail capabilities.drop not a list
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
capabilities:
drop: invalid
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.capabilities.drop> to be [list], but got [string]
- it: should fail when trying to run as non root but with root user
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
runAsNonRoot: true
runAsUser: 0
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.runAsNonRoot> to be [false] with either [runAsUser, runAsGroup] set to [0]
- it: should fail when trying to run as non root but with root group
set:
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
securityContext:
runAsNonRoot: true
runAsGroup: 0
asserts:
- failedTemplate:
errorMessage: Container - Expected <securityContext.runAsNonRoot> to be [false] with either [runAsUser, runAsGroup] set to [0]
@@ -0,0 +1,143 @@
suite: container termination test
templates:
- common.yaml
tests:
- it: should pass with termination set
set:
some_path: /dev/termination-log
some_policy: File
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
termination:
messagePath: "{{ .Values.some_path }}"
messagePolicy: "{{ .Values.some_policy }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
terminationMessagePath: /dev/termination-log
terminationMessagePolicy: File
- it: should pass with termination path only
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
termination:
messagePath: /some/path
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
terminationMessagePath: /some/path
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.containers[0].terminationMessagePolicy
- it: should pass with termination policy only
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
termination:
messagePolicy: File
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
terminationMessagePolicy: File
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.containers[0].terminationMessagePath
# Failures
- it: should fail with invalid policy
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
termination:
messagePolicy: SomeInvalidPolicy
asserts:
- failedTemplate:
errorMessage: Container - Expected <termination.messagePolicy> to be one of [File, FallbackToLogsOnError], but got [SomeInvalidPolicy]
@@ -0,0 +1,72 @@
suite: container tty and stdin test
templates:
- common.yaml
tests:
- it: should pass without tty and stdin
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
tty: false
stdin: false
- it: should pass with tty and stdin enabled
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
tty: true
stdin: true
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.containers[0]
content:
tty: true
stdin: true
@@ -0,0 +1,41 @@
suite: container validation test
templates:
- common.yaml
tests:
- it: should fail with more than one primary container on a workload
set:
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
container-name2:
enabled: true
primary: true
asserts:
- failedTemplate:
errorMessage: Container - Only one container can be primary per workload
- it: should fail with no primary container on a workload
set:
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: false
container-name2:
enabled: true
primary: false
asserts:
- failedTemplate:
errorMessage: Container - At least one enabled container must be primary per workload
@@ -0,0 +1,709 @@
suite: container volumeMounts test
templates:
- common.yaml
tests:
- it: should pass with shared volume on multiple workloads and containers with targetSelectAll
set:
some_path: /some/path
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
workload-name2:
enabled: true
primary: false
type: Job
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
persistence:
shared-vol:
enabled: true
type: emptyDir
mountPath: "{{ .Values.some_path }}"
targetSelectAll: true
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].volumeMounts
content:
name: shared-vol
mountPath: /some/path
readOnly: false
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[1].volumeMounts
content:
name: shared-vol
mountPath: /some/path
readOnly: false
- documentIndex: &jobDoc 1
isKind:
of: Job
- documentIndex: *jobDoc
isAPIVersion:
of: batch/v1
- documentIndex: *jobDoc
contains:
path: spec.template.spec.containers[0].volumeMounts
content:
name: shared-vol
mountPath: /some/path
readOnly: false
- documentIndex: *jobDoc
contains:
path: spec.template.spec.containers[1].volumeMounts
content:
name: shared-vol
mountPath: /some/path
readOnly: false
- it: should pass with volume on primary workload and container
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
workload-name2:
enabled: true
primary: false
type: Job
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
persistence:
some-vol:
enabled: true
type: emptyDir
mountPath: /some/path
readOnly: true
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].volumeMounts
content:
name: some-vol
mountPath: /some/path
readOnly: true
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.containers[1].volumeMounts
- documentIndex: &jobDoc 1
isKind:
of: Job
- documentIndex: *jobDoc
isAPIVersion:
of: batch/v1
- documentIndex: *jobDoc
isNull:
path: spec.template.spec.containers[0].volumeMounts
- documentIndex: *jobDoc
isNull:
path: spec.template.spec.containers[1].volumeMounts
- it: should pass with volume with selected pod and container
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
workload-name2:
enabled: true
primary: false
type: Job
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
persistence:
some-vol:
enabled: true
type: emptyDir
mountPath: /some/path
readOnly: true
targetSelector:
workload-name:
container-name2: {}
workload-name2:
container-name1: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.containers[0].volumeMounts
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[1].volumeMounts
content:
name: some-vol
mountPath: /some/path
readOnly: true
- documentIndex: &jobDoc 1
isKind:
of: Job
- documentIndex: *jobDoc
isAPIVersion:
of: batch/v1
- documentIndex: *jobDoc
contains:
path: spec.template.spec.containers[0].volumeMounts
content:
name: some-vol
mountPath: /some/path
readOnly: true
- documentIndex: *jobDoc
isNull:
path: spec.template.spec.containers[1].volumeMounts
- it: should pass with volume with selected pod and multiple containers
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
workload-name2:
enabled: true
primary: false
type: Job
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
persistence:
some-vol:
enabled: true
type: emptyDir
mountPath: /some/path
readOnly: true
targetSelector:
workload-name:
container-name1: {}
container-name2: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].volumeMounts
content:
name: some-vol
mountPath: /some/path
readOnly: true
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[1].volumeMounts
content:
name: some-vol
mountPath: /some/path
readOnly: true
- documentIndex: &jobDoc 1
isKind:
of: Job
- documentIndex: *jobDoc
isAPIVersion:
of: batch/v1
- documentIndex: *jobDoc
isNull:
path: spec.template.spec.containers[0].volumeMounts
- documentIndex: *jobDoc
isNull:
path: spec.template.spec.containers[1].volumeMounts
- it: should pass with volume with selected pod and containers and specific values
set:
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
workload-name2:
enabled: true
primary: false
type: Job
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
persistence:
some-vol:
enabled: true
type: emptyDir
mountPath: /some/path
readOnly: true
targetSelector:
workload-name:
container-name1:
mountPath: /some/other/path
readOnly: false
mountPropagation: None
subPath: /some/sub/path
container-name2: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].volumeMounts
content:
name: some-vol
mountPath: /some/other/path
readOnly: false
mountPropagation: None
subPath: /some/sub/path
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[1].volumeMounts
content:
name: some-vol
mountPath: /some/path
readOnly: true
- documentIndex: &jobDoc 1
isKind:
of: Job
- documentIndex: *jobDoc
isAPIVersion:
of: batch/v1
- documentIndex: *jobDoc
isNull:
path: spec.template.spec.containers[0].volumeMounts
- documentIndex: *jobDoc
isNull:
path: spec.template.spec.containers[1].volumeMounts
- it: should pass with volume with selected pod and containers and specific values from tpl
set:
some_path: /some/other/path
some_propagation: None
some_sub_path: /some/sub/path
image: *image
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
container-name2:
enabled: true
primary: false
imageSelector: image
probes: *probes
persistence:
some-vol:
enabled: true
type: emptyDir
mountPath: /some/path
readOnly: true
targetSelector:
workload-name:
container-name1:
mountPath: "{{ .Values.some_path }}"
readOnly: false
mountPropagation: "{{ .Values.some_propagation }}"
subPath: "{{ .Values.some_sub_path }}"
container-name2: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].volumeMounts
content:
name: some-vol
mountPath: /some/other/path
readOnly: false
mountPropagation: None
subPath: /some/sub/path
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[1].volumeMounts
content:
name: some-vol
mountPath: /some/path
readOnly: true
- it: should pass with cert mounted as volume with subPath
set:
image: *image
ixCertificates:
"1":
certificate: some_cert
key: some_key
scaleCertificate:
cert-name:
enabled: false
id: 1
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
persistence:
cert-vol:
enabled: true
type: secret
objectName: cert-name
readOnly: true
targetSelector:
workload-name:
container-name1:
mountPath: /some/path/cert.crt
readOnly: true
subPath: cert.crt
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].volumeMounts
content:
name: cert-vol
mountPath: /some/path/cert.crt
readOnly: true
subPath: cert.crt
- it: should pass with cert mounted as volume with subPath
set:
image: *image
ixCertificates:
"1":
certificate: some_cert
key: some_key
scaleCertificate:
cert-name:
enabled: false
id: 1
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
persistence:
cert-vol:
enabled: true
type: secret
objectName: cert-name
readOnly: true
items:
- key: tls.crt
path: cert.crt
targetSelector:
workload-name:
container-name1:
mountPath: /some/path
readOnly: true
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.containers[0].volumeMounts
content:
name: cert-vol
mountPath: /some/path
readOnly: true
# Failures
- it: should fail with invalid mountPropagation
set:
image: *image
workload:
workload-name: &workload
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
persistence:
vol-name:
enabled: true
type: emptyDir
mountPath: /some/path
mountPropagation: HostToContainer
targetSelector:
workload-name:
container-name1:
mountPropagation: invalid
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <mountPropagation> to be one of [None, HostToContainer, Bidirectional], but got [invalid]
- it: should fail with non-boolean readOnly
set:
image: *image
workload:
workload-name: *workload
persistence:
vol-name:
enabled: true
type: emptyDir
mountPath: /some/path
targetSelector:
workload-name:
container-name1:
readOnly: invalid
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <readOnly> to be [boolean], but got [string]
- it: should fail with empty readOnly
set:
image: *image
workload:
workload-name: *workload
persistence:
vol-name:
enabled: true
type: emptyDir
mountPath: /some/path
targetSelector:
workload-name:
container-name1:
readOnly:
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <readOnly> to be [boolean], but got [invalid]
- it: should fail with empty mountPath
set:
image: *image
workload:
workload-name: *workload
persistence:
vol-name:
enabled: true
type: emptyDir
mountPath: ""
targetSelector:
workload-name:
container-name1: {}
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <mountPath>
- it: should fail with mountPath not starting with /
set:
image: *image
workload:
workload-name: *workload
persistence:
vol-name:
enabled: true
type: emptyDir
targetSelector:
workload-name:
container-name1:
mountPath: some/path
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <mountPath> to start with a forward slash [/]
- it: should fail with non-dict targetSelect.workloadName
set:
image: *image
workload:
workload-name: *workload
persistence:
vol-name:
enabled: true
type: emptyDir
targetSelector:
workload-name: string
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <targetSelector.workload-name> to be a [dict], but got [string]
- it: should fail with empty targetSelect.workloadName
set:
image: *image
workload:
workload-name: *workload
persistence:
vol-name:
enabled: true
type: emptyDir
targetSelector:
workload-name: {}
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <targetSelector.workload-name>
@@ -0,0 +1,85 @@
suite: cronjob metadata test
templates:
- common.yaml
chart:
appVersion: &appVer v9.9.9
tests:
- it: should pass with cronjob created with labels and annotations
set:
label1: label1
label2: global_label2
annotation1: annotation1
annotation2: global_annotation2
global:
labels:
g_label1: global_label1
g_label2: "{{ .Values.label2 }}"
annotations:
g_annotation1: global_annotation1
g_annotation2: "{{ .Values.annotation2 }}"
workload:
workload-name:
enabled: true
primary: true
type: CronJob
schedule: "*/1 * * * *"
labels:
label1: "{{ .Values.label1 }}"
label2: label2
annotations:
annotation1: "{{ .Values.annotation1 }}"
annotation2: annotation2
podSpec:
labels:
pod-label1: pod-label1
pod-label2: "{{ .Values.label2 }}"
annotations:
pod-annotation1: pod-annotation1
pod-annotation2: "{{ .Values.annotation2 }}"
asserts:
- documentIndex: &cronJobDoc 0
isKind:
of: CronJob
- documentIndex: *cronJobDoc
equal:
path: metadata.annotations
value:
annotation1: annotation1
annotation2: annotation2
g_annotation1: global_annotation1
g_annotation2: global_annotation2
- documentIndex: *cronJobDoc
equal:
path: metadata.labels
value:
app: common-test-1.0.0
release: RELEASE-NAME
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/version: *appVer
g_label1: global_label1
g_label2: global_label2
label1: label1
label2: label2
- documentIndex: *cronJobDoc
equal:
path: spec.jobTemplate.spec.template.metadata.labels
value:
pod.name: workload-name
app: common-test-1.0.0
release: RELEASE-NAME
app.kubernetes.io/instance: RELEASE-NAME
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: common-test
app.kubernetes.io/version: v9.9.9
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
g_label1: global_label1
g_label2: global_label2
pod-label1: pod-label1
pod-label2: global_label2
- documentIndex: *cronJobDoc
matchRegex:
path: spec.jobTemplate.spec.template.metadata.annotations.rollme
pattern: '^[0-9a-zA-Z]{5}$'
@@ -0,0 +1,83 @@
suite: cronjob spec test
templates:
- common.yaml
tests:
- it: should pass with workload enabled
set:
workload:
workload-name:
enabled: true
primary: true
type: CronJob
schedule: "* * * * *"
podSpec: {}
asserts:
- documentIndex: &cronJobDoc 0
isKind:
of: CronJob
- documentIndex: *cronJobDoc
isAPIVersion:
of: batch/v1
- documentIndex: *cronJobDoc
isSubset:
path: spec
content:
schedule: "* * * * *"
timeZone: UTC
concurrencyPolicy: Forbid
failedJobsHistoryLimit: 1
successfulJobsHistoryLimit: 3
startingDeadlineSeconds:
- documentIndex: *cronJobDoc
isSubset:
path: spec.jobTemplate.spec
content:
backoffLimit: 5
completionMode: NonIndexed
completions:
parallelism: 1
ttlSecondsAfterFinished: 120
- it: should apply spec correctly
set:
cron: "*/5 * * * *"
someTimezone: America/New_York
workload:
workload-name:
enabled: true
primary: true
type: CronJob
schedule: "{{ .Values.cron }}"
timezone: "{{ .Values.someTimezone }}"
concurrencyPolicy: Allow
failedJobsHistoryLimit: 2
successfulJobsHistoryLimit: 4
startingDeadlineSeconds: 100
backoffLimit: 5
completionMode: Indexed
completions: 5
parallelism: 5
ttlSecondsAfterFinished: 100
activeDeadlineSeconds: 100
podSpec: {}
asserts:
- documentIndex: *cronJobDoc
isSubset:
path: spec
content:
schedule: "*/5 * * * *"
concurrencyPolicy: Allow
failedJobsHistoryLimit: 2
successfulJobsHistoryLimit: 4
startingDeadlineSeconds: 100
timeZone: America/New_York
- documentIndex: *cronJobDoc
isSubset:
path: spec.jobTemplate.spec
content:
backoffLimit: 5
completionMode: Indexed
completions: 5
parallelism: 5
ttlSecondsAfterFinished: 100
activeDeadlineSeconds: 100
@@ -0,0 +1,43 @@
suite: cronjob validation test
templates:
- common.yaml
tests:
- it: should fail with invalid concurrencyPolicy
set:
workload:
workload-name:
enabled: true
primary: true
type: CronJob
concurrencyPolicy: not-a-policy
podSpec: {}
asserts:
- failedTemplate:
errorMessage: CronJob - Expected <concurrencyPolicy> to be one of [Allow, Forbid, Replace], but got [not-a-policy]
- it: should fail with empty schedule
set:
workload:
workload-name:
enabled: true
primary: true
type: CronJob
schedule:
podSpec: {}
asserts:
- failedTemplate:
errorMessage: CronJob - Expected non-empty <schedule>
- it: should fail with invalid completionMode (make sure job validation kicks in)
set:
workload:
workload-name:
enabled: true
primary: true
type: CronJob
schedule: "* * * * *"
completionMode: not-a-mode
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Job - Expected <completionMode> to be one of [Indexed, NonIndexed], but got [not-a-mode]
@@ -0,0 +1,148 @@
suite: deployment metadata test
templates:
- common.yaml
chart:
appVersion: &appVer v9.9.9
tests:
- it: should pass with deployment created with labels and annotations
set:
label1: label1
label2: global_label2
annotation1: annotation1
annotation2: global_annotation2
global:
labels:
g_label1: global_label1
g_label2: "{{ .Values.label2 }}"
annotations:
g_annotation1: global_annotation1
g_annotation2: "{{ .Values.annotation2 }}"
workload:
workload-name:
enabled: true
primary: true
type: Deployment
labels:
label1: "{{ .Values.label1 }}"
label2: label2
annotations:
annotation1: "{{ .Values.annotation1 }}"
annotation2: annotation2
podSpec:
labels:
pod-label1: pod-label1
pod-label2: "{{ .Values.label2 }}"
annotations:
pod-annotation1: pod-annotation1
pod-annotation2: "{{ .Values.annotation2 }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: metadata.annotations
value:
annotation1: annotation1
annotation2: annotation2
g_annotation1: global_annotation1
g_annotation2: global_annotation2
- documentIndex: *deploymentDoc
equal:
path: metadata.labels
value:
app: common-test-1.0.0
release: RELEASE-NAME
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/version: *appVer
g_label1: global_label1
g_label2: global_label2
label1: label1
label2: label2
- documentIndex: *deploymentDoc
equal:
path: spec.selector.matchLabels
value:
pod.name: workload-name
app.kubernetes.io/name: common-test
app.kubernetes.io/instance: RELEASE-NAME
- documentIndex: *deploymentDoc
equal:
path: spec.template.metadata.labels
value:
pod.name: workload-name
app: common-test-1.0.0
release: RELEASE-NAME
app.kubernetes.io/instance: RELEASE-NAME
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: common-test
app.kubernetes.io/version: v9.9.9
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
g_label1: global_label1
g_label2: global_label2
pod-label1: pod-label1
pod-label2: global_label2
- documentIndex: *deploymentDoc
matchRegex:
path: spec.template.metadata.annotations.rollme
pattern: '^[0-9a-zA-Z]{5}$'
- it: should pass with 2 deployment created with correct selector labels
set:
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec: {}
other-workload-name:
enabled: true
primary: false
type: Deployment
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: metadata.name
value: release-name-common-test-other-workload-name
- documentIndex: *deploymentDoc
equal:
path: spec.selector.matchLabels
value:
pod.name: other-workload-name
app.kubernetes.io/name: common-test
app.kubernetes.io/instance: RELEASE-NAME
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.metadata.labels
content:
pod.name: other-workload-name
app.kubernetes.io/instance: RELEASE-NAME
app.kubernetes.io/name: common-test
- documentIndex: &otherDeploymentDoc 1
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
equal:
path: metadata.name
value: release-name-common-test
- documentIndex: *otherDeploymentDoc
equal:
path: spec.selector.matchLabels
value:
pod.name: workload-name
app.kubernetes.io/name: common-test
app.kubernetes.io/instance: RELEASE-NAME
- documentIndex: *otherDeploymentDoc
isSubset:
path: spec.template.metadata.labels
content:
pod.name: workload-name
app.kubernetes.io/instance: RELEASE-NAME
app.kubernetes.io/name: common-test
@@ -0,0 +1,96 @@
suite: deployment spec test
templates:
- common.yaml
tests:
- it: should pass with workload enabled
set:
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec
content:
replicas: 1
revisionHistoryLimit: 3
strategy:
type: Recreate
- it: should apply spec correctly
set:
workload:
workload-name:
enabled: true
primary: true
type: Deployment
replicas: 2
revisionHistoryLimit: 4
strategy: RollingUpdate
rollingUpdate:
maxSurge: 5
maxUnavailable: 5
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
isSubset:
path: spec
content:
replicas: 2
revisionHistoryLimit: 4
strategy:
type: RollingUpdate
rollingUpdate:
maxSurge: 5
maxUnavailable: 5
- it: should apply maxSurge with 0
set:
workload:
workload-name:
enabled: true
primary: true
type: Deployment
strategy: RollingUpdate
rollingUpdate:
maxSurge: 0
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
isSubset:
path: spec
content:
strategy:
type: RollingUpdate
rollingUpdate:
maxSurge: 0
- it: should apply maxUnavailable with 0
set:
workload:
workload-name:
enabled: true
primary: true
type: Deployment
strategy: RollingUpdate
rollingUpdate:
maxUnavailable: 0
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
isSubset:
path: spec
content:
strategy:
type: RollingUpdate
rollingUpdate:
maxUnavailable: 0
@@ -0,0 +1,30 @@
suite: deployment validation test
templates:
- common.yaml
tests:
- it: should fail with invalid strategy
set:
workload:
workload-name:
enabled: true
primary: true
type: Deployment
strategy: not-a-strategy
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Deployment - Expected <strategy> to be one of [Recreate, RollingUpdate], but got [not-a-strategy]
- it: should fail with rollingUpdate not a dict
set:
workload:
workload-name:
enabled: true
primary: true
type: Deployment
strategy: RollingUpdate
rollingUpdate: "not a dict"
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Deployment - Expected <rollingUpdate> to be a dictionary, but got [string]
@@ -0,0 +1,238 @@
suite: externalInterface metadata test
templates:
- common.yaml
release:
name: release-name
tests:
- it: should generate correct annotations without selector
set:
# Simulate middleware injection
ixExternalInterfacesConfiguration:
- '{"cniVersion": "0.3.1", "name": "ix-release-name-0", "type": "macvlan", "master": "ens3s0", "ipam": {"type": "dhcp"}}'
- '{"cniVersion": "0.3.1", "name": "ix-release-name-0", "type": "macvlan", "master": "ens4s0", "ipam": {"type": "dhcp"}}'
ixExternalInterfacesConfigurationNames:
- ix-release-name-0
- ix-release-name-1
scaleExternalInterface:
- hostInterface: enp0s3
ipam:
type: dhcp
- hostInterface: enp0s4
ipam:
type: dhcp
image: &image
repository: nginx
tag: 1.21.4
pullPolicy: IfNotPresent
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: &probes
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- documentIndex: &deploymentDoc 2
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
equal:
path: metadata.name
value: release-name-common-test
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.metadata.annotations
content:
k8s.v1.cni.cncf.io/networks: ix-release-name-0, ix-release-name-1
- documentIndex: &otherDeploymentDoc 3
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *otherDeploymentDoc
equal:
path: metadata.name
value: release-name-common-test-workload-name2
- documentIndex: *otherDeploymentDoc
isNotSubset:
path: spec.template.metadata.annotations
content:
k8s.v1.cni.cncf.io/networks: ix-release-name-0, ix-release-name-1
- it: should generate correct annotations with targetSelectAll
set:
# Simulate middleware injection
ixExternalInterfacesConfiguration:
- '{"cniVersion": "0.3.1", "name": "ix-release-name-0", "type": "macvlan", "master": "ens3s0", "ipam": {"type": "dhcp"}}'
- '{"cniVersion": "0.3.1", "name": "ix-release-name-0", "type": "macvlan", "master": "ens4s0", "ipam": {"type": "dhcp"}}'
ixExternalInterfacesConfigurationNames:
- ix-release-name-0
- ix-release-name-1
scaleExternalInterface:
- hostInterface: enp0s3
ipam:
type: dhcp
targetSelectAll: true
- hostInterface: enp0s4
ipam:
type: dhcp
targetSelectAll: true
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
workload-name2:
enabled: true
primary: false
type: Job
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
equal:
path: metadata.name
value: release-name-common-test
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.metadata.annotations
content:
k8s.v1.cni.cncf.io/networks: ix-release-name-0, ix-release-name-1
- documentIndex: &jobDoc 3
isKind:
of: Job
- documentIndex: *jobDoc
isAPIVersion:
of: batch/v1
- documentIndex: *jobDoc
equal:
path: metadata.name
value: release-name-common-test-workload-name2
- documentIndex: *jobDoc
isSubset:
path: spec.template.metadata.annotations
content:
k8s.v1.cni.cncf.io/networks: ix-release-name-0, ix-release-name-1
- it: should generate correct annotations with targetSelector
set:
# Simulate middleware injection
ixExternalInterfacesConfiguration:
- '{"cniVersion": "0.3.1", "name": "ix-release-name-0", "type": "macvlan", "master": "ens3s0", "ipam": {"type": "dhcp"}}'
- '{"cniVersion": "0.3.1", "name": "ix-release-name-0", "type": "macvlan", "master": "ens4s0", "ipam": {"type": "dhcp"}}'
ixExternalInterfacesConfigurationNames:
- ix-release-name-0
- ix-release-name-1
scaleExternalInterface:
- hostInterface: enp0s3
ipam:
type: dhcp
targetSelector:
- workload-name1
- workload-name2
- hostInterface: enp0s4
ipam:
type: dhcp
targetSelector:
- workload-name1
image: *image
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
workload-name2:
enabled: true
primary: false
type: CronJob
schedule: "*/1 * * * *"
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes: *probes
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
equal:
path: metadata.name
value: release-name-common-test
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.metadata.annotations
content:
k8s.v1.cni.cncf.io/networks: ix-release-name-0, ix-release-name-1
- documentIndex: &cronJobDoc 3
isKind:
of: CronJob
- documentIndex: *cronJobDoc
isAPIVersion:
of: batch/v1
- documentIndex: *cronJobDoc
equal:
path: metadata.name
value: release-name-common-test-workload-name2
- documentIndex: *cronJobDoc
isSubset:
path: spec.jobTemplate.spec.template.metadata.annotations
content:
k8s.v1.cni.cncf.io/networks: ix-release-name-0
@@ -0,0 +1,43 @@
suite: externalInterface name test
templates:
- common.yaml
release:
name: release-name
tests:
- it: should generate correct name NetworkAttachmentDefinition
set:
# Simulate middleware injection
ixExternalInterfacesConfiguration:
- '{"cniVersion": "0.3.1", "name": "ix-release-name-0", "type": "macvlan", "master": "ens3s0", "ipam": {"type": "dhcp"}}'
- '{"cniVersion": "0.3.1", "name": "ix-release-name-0", "type": "macvlan", "master": "ens4s0", "ipam": {"type": "dhcp"}}'
ixExternalInterfacesConfigurationNames:
- ix-release-name-0
- ix-release-name-1
scaleExternalInterface:
- hostInterface: enp0s3
ipam:
type: dhcp
- hostInterface: enp0s4
ipam:
type: dhcp
asserts:
- documentIndex: &networkDoc 0
isKind:
of: NetworkAttachmentDefinition
- documentIndex: *networkDoc
isAPIVersion:
of: k8s.cni.cncf.io/v1
- documentIndex: *networkDoc
equal:
path: metadata.name
value: ix-release-name-0
- documentIndex: &otherNetworkDoc 1
isKind:
of: NetworkAttachmentDefinition
- documentIndex: *otherNetworkDoc
isAPIVersion:
of: k8s.cni.cncf.io/v1
- documentIndex: *otherNetworkDoc
equal:
path: metadata.name
value: ix-release-name-1
@@ -0,0 +1,137 @@
suite: external interface validation test
templates:
- common.yaml
release:
name: release-name
tests:
- it: should fail with targetSelector not a list
set:
scaleExternalInterface:
- targetSelector: "not a list"
asserts:
- failedTemplate:
errorMessage: External Interface - Expected <targetSelector> to be a [list], but got [string]
- it: should fail with empty hostInterface
set:
scaleExternalInterface:
- hostInterface: ""
asserts:
- failedTemplate:
errorMessage: External Interface - Expected non-empty <hostInterface>
- it: should fail with empty ipam
set:
scaleExternalInterface:
- hostInterface: enp0s3
ipam: {}
asserts:
- failedTemplate:
errorMessage: External Interface - Expected non-empty <ipam>
- it: should fail with empty ipam.type
set:
scaleExternalInterface:
- hostInterface: enp0s3
ipam:
type: ""
asserts:
- failedTemplate:
errorMessage: External Interface - Expected non-empty <ipam.type>
- it: should fail with invalid ipam.type
set:
scaleExternalInterface:
- hostInterface: enp0s3
ipam:
type: invalid
asserts:
- failedTemplate:
errorMessage: External Interface - Expected <ipam.type> to be one of [dhcp, static], but got [invalid]
- it: should fail with non-empty staticIPConfigurations on dhcp
set:
scaleExternalInterface:
- hostInterface: enp0s3
ipam:
type: dhcp
staticIPConfigurations:
- ipAddress: 1.2.3.4
asserts:
- failedTemplate:
errorMessage: External Interface - Expected empty <staticIPConfigurations> and <staticRoutes> when <ipam.type> is not [static]
- it: should fail with non-empty staticRoutes on dhcp
set:
scaleExternalInterface:
- hostInterface: enp0s3
ipam:
type: dhcp
staticRoutes:
- gateway: 1.2.3.4
destination: 1.2.3.4
asserts:
- failedTemplate:
errorMessage: External Interface - Expected empty <staticIPConfigurations> and <staticRoutes> when <ipam.type> is not [static]
- it: should fail with empty staticIPConfigurations on static
set:
scaleExternalInterface:
- hostInterface: enp0s3
ipam:
type: static
staticIPConfigurations: []
asserts:
- failedTemplate:
errorMessage: External Interface - Expected non-empty <staticIPConfigurations> when <ipam.type> is [static]
- it: should fail with empty gateway on staticRoutes on static
set:
scaleExternalInterface:
- hostInterface: enp0s3
ipam:
type: static
staticIPConfigurations:
- ipAddress: 1.2.3.4
staticRoutes:
- gateway: ""
destination: 1.2.3.4
asserts:
- failedTemplate:
errorMessage: External Interface - Expected non-empty <gateway> in <staticRoutes>
- it: should fail with empty destination on staticRoutes on static
set:
scaleExternalInterface:
- hostInterface: enp0s3
ipam:
type: static
staticIPConfigurations:
- ipAddress: 1.2.3.4
staticRoutes:
- gateway: 1.2.3.4
destination: ""
asserts:
- failedTemplate:
errorMessage: External Interface - Expected non-empty <destination> in <staticRoutes>
- it: should fail with empty ixExternalInterfaceConfigurationNames when interface is defined
set:
# Simulate middleware injection
ixExternalInterfacesConfiguration:
- '{"cniVersion": "0.3.1", "name": "ix-release-name-0", "type": "macvlan", "master": "ens3s0", "ipam": {"type": "dhcp"}}'
ixExternalInterfaceConfigurationNames: []
scaleExternalInterface:
- hostInterface: enp0s3
ipam:
type: dhcp
workload:
workload-name1:
enabled: true
primary: true
type: CronJob
schedule: "*/1 * * * *"
podSpec: {}
asserts:
- failedTemplate:
errorMessage: External Interface - Expected non empty <ixExternalInterfaceConfigurationNames>
@@ -0,0 +1,48 @@
suite: imagePullSecret data test
templates:
- common.yaml
tests:
- it: should pass with data
set:
imagePullSecret:
my-secret1:
enabled: true
data:
registry: reg
username: user
password: pass
email: mail
asserts:
- documentIndex: &secretDoc 0
isKind:
of: Secret
- documentIndex: *secretDoc
equal:
path: data
value:
.dockerconfigjson: eyJhdXRocyI6eyJyZWdpc3RyeSI6eyJhdXRoIjoiZFhObGNqcHdZWE56IiwiZW1haWwiOiJtYWlsIiwicGFzc3dvcmQiOiJwYXNzIiwidXNlcm5hbWUiOiJ1c2VyIn19fQ==
- documentIndex: *secretDoc
equal:
path: type
value: kubernetes.io/dockerconfigjson
- it: should pass with data from tpl
set:
registry: quay.io
user: user
pass: secret_pass
email: mail@example.com
imagePullSecret:
my-secret1:
enabled: true
data:
registry: "{{ .Values.registry }}"
username: "{{ .Values.user }}"
password: "{{ .Values.pass }}"
email: "{{ .Values.email }}"
asserts:
- documentIndex: *secretDoc
equal:
path: data
value:
.dockerconfigjson: eyJhdXRocyI6eyJyZWdpc3RyeSI6eyJhdXRoIjoiZFhObGNqcHpaV055WlhSZmNHRnpjdz09IiwiZW1haWwiOiJtYWlsQGV4YW1wbGUuY29tIiwicGFzc3dvcmQiOiJzZWNyZXRfcGFzcyIsInVzZXJuYW1lIjoidXNlciJ9fX0=
@@ -0,0 +1,59 @@
suite: imagePullSecret metadata test
templates:
- common.yaml
chart:
appVersion: &appVer v9.9.9
tests:
- it: should pass with secret created with labels and annotations
set:
label1: label1
label2: global_label2
annotation1: annotation1
annotation2: global_annotation2
global:
labels:
g_label1: global_label1
g_label2: "{{ .Values.label2 }}"
annotations:
g_annotation1: global_annotation1
g_annotation2: "{{ .Values.annotation2 }}"
imagePullSecret:
my-secret1:
enabled: true
labels:
label1: "{{ .Values.label1 }}"
label2: label2
annotations:
annotation1: "{{ .Values.annotation1 }}"
annotation2: annotation2
data:
registry: reg
username: user
password: pass
email: mail
asserts:
- documentIndex: &secretDoc 0
isKind:
of: Secret
- documentIndex: *secretDoc
equal:
path: metadata.annotations
value:
annotation1: annotation1
annotation2: annotation2
g_annotation1: global_annotation1
g_annotation2: global_annotation2
- documentIndex: *secretDoc
equal:
path: metadata.labels
value:
app: common-test-1.0.0
release: RELEASE-NAME
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/version: *appVer
g_label1: global_label1
g_label2: global_label2
label1: label1
label2: label2
@@ -0,0 +1,42 @@
suite: imagePullSecret name test
templates:
- common.yaml
tests:
- it: should generate correct name
set:
imagePullSecret:
my-pull-secret1:
enabled: true
data:
registry: reg1
username: user1
password: pass1
email: mail1
my-pull-secret2:
enabled: true
data:
registry: reg2
username: user2
password: pass2
email: mail2
asserts:
- documentIndex: &secretDoc 0
isKind:
of: Secret
- documentIndex: *secretDoc
isAPIVersion:
of: v1
- documentIndex: *secretDoc
equal:
path: metadata.name
value: release-name-common-test-my-pull-secret1
- documentIndex: &otherSecretDoc 1
isKind:
of: Secret
- documentIndex: *otherSecretDoc
isAPIVersion:
of: v1
- documentIndex: *otherSecretDoc
equal:
path: metadata.name
value: release-name-common-test-my-pull-secret2
@@ -0,0 +1,129 @@
suite: imagePullSecret validation test
templates:
- common.yaml
tests:
- it: should fail with name longer than 63 characters
set:
imagePullSecret:
my-pull-secret-super-long-name-that-is-longer-than-63-characters:
enabled: true
data: &data
registry: reg
username: user
password: pass
email: mail
asserts:
- failedTemplate:
errorMessage: Name [release-name-common-test-my-pull-secret-super-long-name-that-is-longer-than-63-characters] is not valid. Must start and end with an alphanumeric lowercase character. It can contain '-'. And must be at most 63 characters.
- it: should fail with name starting with underscore
set:
imagePullSecret:
_my-pull-secret:
enabled: true
data: *data
asserts:
- failedTemplate:
errorMessage: Name [release-name-common-test-_my-pull-secret] is not valid. Must start and end with an alphanumeric lowercase character. It can contain '-'. And must be at most 63 characters.
- it: should fail with labels not a dict
set:
imagePullSecret:
my-pull-secret:
enabled: true
labels: "not a dict"
data: *data
asserts:
- failedTemplate:
errorMessage: Image Pull Secret - Expected <labels> to be a dictionary, but got [string]
- it: should fail with annotations not a dict
set:
imagePullSecret:
my-pull-secret:
enabled: true
annotations: "not a dict"
data: *data
asserts:
- failedTemplate:
errorMessage: Image Pull Secret - Expected <annotations> to be a dictionary, but got [string]
- it: should fail with data not a dict
set:
imagePullSecret:
my-pull-secret:
enabled: true
data: "not a dict"
asserts:
- failedTemplate:
errorMessage: Image Pull Secret - Expected <data> to be a dictionary, but got [string]
- it: should fail with empty data
set:
imagePullSecret:
my-pull-secret:
enabled: true
data: {}
asserts:
- failedTemplate:
errorMessage: Image Pull Secret - Expected non-empty <data>
- it: should fail with empty registry key
set:
imagePullSecret:
my-pull-secret:
enabled: true
type: ""
data:
registry: ""
username: user
password: pass
email: mail
asserts:
- failedTemplate:
errorMessage: Image Pull Secret - Expected non-empty <registry>
- it: should fail with empty username key
set:
imagePullSecret:
my-pull-secret:
enabled: true
type: ""
data:
registry: registry
username: ""
password: pass
email: mail
asserts:
- failedTemplate:
errorMessage: Image Pull Secret - Expected non-empty <username>
- it: should fail with empty password key
set:
imagePullSecret:
my-pull-secret:
enabled: true
type: ""
data:
registry: registry
username: user
password: ""
email: mail
asserts:
- failedTemplate:
errorMessage: Image Pull Secret - Expected non-empty <password>
- it: should fail with empty email key
set:
imagePullSecret:
my-pull-secret:
enabled: true
type: ""
data:
registry: registry
username: user
password: pass
email: ""
asserts:
- failedTemplate:
errorMessage: Image Pull Secret - Expected non-empty <email>
@@ -0,0 +1,153 @@
suite: init container data test
templates:
- common.yaml
tests:
- it: should generate correct init container
set:
initType: install
render: true
persistence:
shared-vol:
enabled: true
type: emptyDir
mountPath: /some/path
targetSelector:
workload-name:
container-name2: {}
image:
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
initImage:
repository: bash
tag: latest
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
initContainers:
container-name1:
enabled: "{{ .Values.render }}"
type: init
imageSelector: initImage
container-name3:
enabled: true
type: upgrade
imageSelector: initImage
container-name2:
enabled: true
type: "{{ .Values.initType }}"
imageSelector: initImage
probes:
liveness:
enabled: true
readiness:
enabled: true
startup:
enabled: true
command:
- /bin/sh
- -c
- |
echo "Using image {{ .Values.initImage.repository }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.initContainers[0]
content:
name: release-name-common-test-install-container-name2
image: bash:latest
command:
- /bin/sh
- -c
- |
echo "Using image bash"
volumeMounts:
- name: shared-vol
mountPath: /some/path
readOnly: false
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers[0].livenessProbe
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers[0].readinessProbe
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers[0].startupProbe
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.initContainers[1]
content:
name: release-name-common-test-init-container-name1
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers[1].command
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers[1].volumeMounts
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers[2]
- it: should NOT generate render init container
set:
render: false
image:
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
initContainers:
container-name1:
enabled: "{{ .Values.render }}"
type: init
imageSelector: image
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers
@@ -0,0 +1,155 @@
suite: init container data test (upgrade)
templates:
- common.yaml
release:
upgrade: true
tests:
- it: should generate correct init container
set:
initType: upgrade
render: true
persistence:
shared-vol:
enabled: true
type: emptyDir
mountPath: /some/path
targetSelector:
workload-name:
container-name2: {}
image:
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
initImage:
repository: bash
tag: latest
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: "{{ .Values.render }}"
primary: true
imageSelector: image
probes:
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
initContainers:
container-name1:
enabled: true
type: init
imageSelector: initImage
container-name3:
enabled: true
type: install
imageSelector: initImage
container-name2:
enabled: true
type: "{{ .Values.initType }}"
imageSelector: initImage
probes:
liveness:
enabled: true
readiness:
enabled: true
startup:
enabled: true
command:
- /bin/sh
- -c
- |
echo "Using image {{ .Values.initImage.repository }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.initContainers[0]
content:
name: release-name-common-test-upgrade-container-name2
image: bash:latest
command:
- /bin/sh
- -c
- |
echo "Using image bash"
volumeMounts:
- name: shared-vol
mountPath: /some/path
readOnly: false
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers[0].livenessProbe
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers[0].readinessProbe
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers[0].startupProbe
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.initContainers[1]
content:
name: release-name-common-test-init-container-name1
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers[1].command
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers[1].volumeMounts
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers[2]
- it: should NOT generate render init container
set:
render: false
image:
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
initContainers:
container-name1:
enabled: "{{ .Values.render }}"
type: upgrade
imageSelector: image
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.initContainers
@@ -0,0 +1,42 @@
suite: init container name test
templates:
- common.yaml
tests:
- it: should generate correct init container name
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
initContainers:
container-name1:
enabled: true
type: init
imageSelector: image
container-name2:
enabled: true
type: install
imageSelector: image
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.initContainers[0]
content:
name: release-name-common-test-install-container-name2
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.initContainers[1]
content:
name: release-name-common-test-init-container-name1
@@ -0,0 +1,44 @@
suite: init container name test (upgrade)
templates:
- common.yaml
release:
upgrade: true
tests:
- it: should generate correct init container name
set:
image: &image
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
initContainers:
container-name1:
enabled: true
type: init
imageSelector: image
container-name2:
enabled: true
type: upgrade
imageSelector: image
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isAPIVersion:
of: apps/v1
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.initContainers[0]
content:
name: release-name-common-test-upgrade-container-name2
- documentIndex: *deploymentDoc
isSubset:
path: spec.template.spec.initContainers[1]
content:
name: release-name-common-test-init-container-name1
@@ -0,0 +1,68 @@
suite: init container data test (upgrade)
templates:
- common.yaml
tests:
# Failures
- it: should fail with empty type on init container
set:
image:
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
initContainers:
container-name1:
enabled: true
type: ""
asserts:
- failedTemplate:
errorMessage: InitContainer - Expected non-empty <type>
- it: should fail with invalid type on init container
set:
image:
repository: nginx
tag: 1.19.0
pullPolicy: IfNotPresent
workload:
workload-name:
enabled: true
primary: true
type: Deployment
podSpec:
containers:
container-name1:
enabled: true
primary: true
imageSelector: image
probes:
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
initContainers:
container-name1:
enabled: true
type: invalid
asserts:
- failedTemplate:
errorMessage: InitContainer - Expected <type> to be one of [init, install, upgrade], but got [invalid]
@@ -0,0 +1,84 @@
suite: job metadata test
templates:
- common.yaml
chart:
appVersion: &appVer v9.9.9
tests:
- it: should pass with job created with labels and annotations
set:
label1: label1
label2: global_label2
annotation1: annotation1
annotation2: global_annotation2
global:
labels:
g_label1: global_label1
g_label2: "{{ .Values.label2 }}"
annotations:
g_annotation1: global_annotation1
g_annotation2: "{{ .Values.annotation2 }}"
workload:
workload-name:
enabled: true
primary: true
type: Job
labels:
label1: "{{ .Values.label1 }}"
label2: label2
annotations:
annotation1: "{{ .Values.annotation1 }}"
annotation2: annotation2
podSpec:
labels:
pod-label1: pod-label1
pod-label2: "{{ .Values.label2 }}"
annotations:
pod-annotation1: pod-annotation1
pod-annotation2: "{{ .Values.annotation2 }}"
asserts:
- documentIndex: &jobDoc 0
isKind:
of: Job
- documentIndex: *jobDoc
equal:
path: metadata.annotations
value:
annotation1: annotation1
annotation2: annotation2
g_annotation1: global_annotation1
g_annotation2: global_annotation2
- documentIndex: *jobDoc
equal:
path: metadata.labels
value:
app: common-test-1.0.0
release: RELEASE-NAME
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/version: *appVer
g_label1: global_label1
g_label2: global_label2
label1: label1
label2: label2
- documentIndex: *jobDoc
equal:
path: spec.template.metadata.labels
value:
pod.name: workload-name
app: common-test-1.0.0
release: RELEASE-NAME
app.kubernetes.io/instance: RELEASE-NAME
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: common-test
app.kubernetes.io/version: v9.9.9
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
g_label1: global_label1
g_label2: global_label2
pod-label1: pod-label1
pod-label2: global_label2
- documentIndex: *jobDoc
matchRegex:
path: spec.template.metadata.annotations.rollme
pattern: '^[0-9a-zA-Z]{5}$'
@@ -0,0 +1,54 @@
suite: job spec test
templates:
- common.yaml
tests:
- it: should pass with workload enabled
set:
workload:
workload-name:
enabled: true
primary: true
type: Job
podSpec: {}
asserts:
- documentIndex: &jobDoc 0
isKind:
of: Job
- documentIndex: *jobDoc
isAPIVersion:
of: batch/v1
- documentIndex: *jobDoc
isSubset:
path: spec
content:
backoffLimit: 5
completionMode: NonIndexed
completions:
parallelism: 1
ttlSecondsAfterFinished: 120
- it: should apply spec correctly
set:
workload:
workload-name:
enabled: true
primary: true
type: Job
backoffLimit: 5
completionMode: Indexed
completions: 5
parallelism: 5
ttlSecondsAfterFinished: 100
activeDeadlineSeconds: 100
podSpec: {}
asserts:
- documentIndex: *jobDoc
isSubset:
path: spec
content:
backoffLimit: 5
completionMode: Indexed
completions: 5
parallelism: 5
ttlSecondsAfterFinished: 100
activeDeadlineSeconds: 100
@@ -0,0 +1,45 @@
suite: job validation test
templates:
- common.yaml
tests:
- it: should fail with invalid completionMode
set:
workload:
workload-name:
enabled: true
primary: true
type: Job
completionMode: not-a-mode
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Job - Expected <completionMode> to be one of [Indexed, NonIndexed], but got [not-a-mode]
- it: should fail with completionMode to Indexed and no completions
set:
workload:
workload-name:
enabled: true
primary: true
type: Job
completionMode: Indexed
completions:
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Job - Expected <completions> to be set when <completionMode> is set to [Indexed]
- it: should fail with completionMode to Indexed and no parallelism
set:
workload:
workload-name:
enabled: true
primary: true
type: Job
completionMode: Indexed
completions: 5
parallelism:
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Job - Expected <parallelism> to be set when <completionMode> is set to [Indexed]
@@ -0,0 +1,35 @@
suite: persistence validation test
templates:
- common.yaml
tests:
- it: should fail with pod targetSelector not a map
set:
workload:
main:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
targetSelector: not-a-map
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <targetSelector> to be [dict], but got [string]
- it: should fail with invalid type
set:
workload:
main:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: not-a-type
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <type> to be one of [emptyDir, hostPath, ixVolume, secret, configmap, device], but got [not-a-type]
@@ -0,0 +1,75 @@
suite: pod auto mount sa token test
templates:
- common.yaml
tests:
- it: should pass with automountServiceAccountToken disabled from "global"
set:
podOptions:
automountServiceAccountToken: false
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.automountServiceAccountToken
value: false
- it: should pass with automountServiceAccountToken enabled from "global"
set:
podOptions:
automountServiceAccountToken: true
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.automountServiceAccountToken
value: true
- it: should pass with disabled automountServiceAccountToken from pod
set:
podOptions:
automountServiceAccountToken: true
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
automountServiceAccountToken: false
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.automountServiceAccountToken
value: false
- it: should pass with enabled automountServiceAccountToken from pod
set:
podOptions:
automountServiceAccountToken: false
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
automountServiceAccountToken: true
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.automountServiceAccountToken
value: true
@@ -0,0 +1,237 @@
suite: pod dns config test
templates:
- common.yaml
tests:
- it: should pass with empty dnsConfig
set:
podOptions:
dnsConfig:
nameservers: []
searches: []
options: []
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.dnsConfig
- it: should pass with dnsConfig from "global"
set:
podOptions:
dnsConfig:
nameservers:
- 1.1.1.1
- 2.2.2.2
searches:
- example.com
- example.org
options:
- name: ndots
value: "2"
- name: edns0
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.dnsConfig
value:
nameservers:
- 1.1.1.1
- 2.2.2.2
searches:
- example.com
- example.org
options:
- name: ndots
value: "2"
- name: edns0
- it: should pass with dnsPolicy from "pod"
set:
podOptions:
dnsConfig:
nameservers:
- 1.1.1.1
searches:
- example.org
options:
- name: edns0
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
dnsConfig:
nameservers:
- 1.1.1.1
- 2.2.2.2
searches:
- example.com
- example.org
options:
- name: ndots
value: "2"
- name: edns0
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.dnsConfig
value:
nameservers:
- 1.1.1.1
- 2.2.2.2
searches:
- example.com
- example.org
options:
- name: ndots
value: "2"
- name: edns0
- it: should pass with dnsPolicy from "pod" with tpl
set:
ns1: 1.1.1.1
s1: example.com
property: ndots
value: 2
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
dnsPolicy: None
dnsConfig:
nameservers:
- "{{ .Values.ns1 }}"
- 2.2.2.2
searches:
- "{{ .Values.s1 }}"
- example.org
options:
- name: "{{ .Values.property }}"
value: "{{ .Values.value }}"
- name: edns0
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.dnsConfig
value:
nameservers:
- 1.1.1.1
- 2.2.2.2
searches:
- example.com
- example.org
options:
- name: ndots
value: "2"
- name: edns0
# Failures
- it: should fail with dnsPolicy set to None and no nameservers
set:
podOptions:
dnsPolicy: None
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
dnsConfig:
nameservers: []
asserts:
- failedTemplate:
errorMessage: Expected non-empty <dnsConfig.nameservers> with <dnsPolicy> set to [None].
- it: should fail with dnsPolicy set to None and no searches
set:
podOptions:
dnsPolicy: None
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
dnsConfig:
nameservers:
- 1.1.1.1
searches: []
asserts:
- failedTemplate:
errorMessage: Expected non-empty <dnsConfig.searches> with <dnsPolicy> set to [None].
- it: should fail with dnsPolicy set to None and no options
set:
podOptions:
dnsPolicy: None
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
dnsConfig:
nameservers:
- 1.1.1.1
searches:
- example.com
options: []
asserts:
- failedTemplate:
errorMessage: Expected non-empty <dnsConfig.options> with <dnsPolicy> set to [None].
- it: should fail with more than 3 nameservers
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
dnsConfig:
nameservers:
- 1.1.1.1
- 1.1.1.1
- 1.1.1.1
- 1.1.1.1
asserts:
- failedTemplate:
errorMessage: Expected no more than [3] <dnsConfig.nameservers>, but got [4]
- it: should fail with more than 6 Searches
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
dnsConfig:
searches:
- example.com
- example.com
- example.com
- example.com
- example.com
- example.com
- example.com
asserts:
- failedTemplate:
errorMessage: Expected no more than [6] <dnsConfig.searches>, but got [7]
@@ -0,0 +1,106 @@
suite: pod dns policy test
templates:
- common.yaml
tests:
- it: should pass with empty dnsPolicy
set:
podOptions:
dnsPolicy: ""
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.dnsPolicy
value: ClusterFirst
- it: should pass with dnsPolicy from "global"
set:
podOptions:
dnsPolicy: Default
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.dnsPolicy
value: Default
- it: should pass with dnsPolicy from "pod"
set:
podOptions:
dnsPolicy: None
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
dnsPolicy: ClusterFirst
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.dnsPolicy
value: ClusterFirst
- it: should pass with dnsPolicy from "pod" with tpl
set:
policy: ClusterFirst
podOptions:
dnsPolicy: None
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
dnsPolicy: "{{ .Values.policy }}"
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.dnsPolicy
value: ClusterFirst
- it: should pass with hostNetwork enabled
set:
podOptions:
dnsPolicy: None
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
dnsPolicy: ClusterFirst
hostNetwork: true
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.dnsPolicy
value: ClusterFirstWithHostNet
# Failures
- it: should fail with invalid dnsPolicy
set:
podOptions:
dnsPolicy: Invalid
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Expected <dnsPolicy> to be one of [ClusterFirst, ClusterFirstWithHostNet, Default, None], but got [Invalid]
@@ -0,0 +1,75 @@
suite: pod enableServiceLinks test
templates:
- common.yaml
tests:
- it: should pass with enableServiceLinks disabled from "global"
set:
podOptions:
enableServiceLinks: false
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.enableServiceLinks
value: false
- it: should pass with enableServiceLinks enabled from "global"
set:
podOptions:
enableServiceLinks: true
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.enableServiceLinks
value: true
- it: should pass with disabled enableServiceLinks from pod
set:
podOptions:
enableServiceLinks: true
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
enableServiceLinks: false
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.enableServiceLinks
value: false
- it: should pass with enabled enableServiceLinks from pod
set:
podOptions:
enableServiceLinks: false
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
enableServiceLinks: true
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.enableServiceLinks
value: true
@@ -0,0 +1,126 @@
suite: pod hostAliases test
templates:
- common.yaml
tests:
- it: should pass with empty hostAliases
set:
podOptions:
hostAliases: ""
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.hostAliases
- it: should pass with hostAliases from "global"
set:
podOptions:
hostAliases:
- ip: 10.10.10.100
hostnames:
- myserver.local
- storage.local
- ip: 10.10.10.101
hostnames:
- myotherserver.local
- backups.local
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.hostAliases
value:
- ip: 10.10.10.100
hostnames:
- myserver.local
- storage.local
- ip: 10.10.10.101
hostnames:
- myotherserver.local
- backups.local
- it: should pass with hostAliases from "pod"
set:
podOptions:
hostAliases:
- ip: 10.10.10.100
hostnames:
- myserver.local
- storage.local
- ip: 10.10.10.101
hostnames:
- myotherserver.local
- backups.local
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
hostAliases:
- ip: 10.10.10.200
hostnames:
- server.local
- mystorage.local
- ip: 10.10.10.201
hostnames:
- otherserver.local
- mybackups.local
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.hostAliases
value:
- ip: 10.10.10.200
hostnames:
- server.local
- mystorage.local
- ip: 10.10.10.201
hostnames:
- otherserver.local
- mybackups.local
- it: should pass with hostaliases from "pod" with tpl
set:
ip: 10.10.10.200
host1: server.local
host2: mystorage.local
podOptions:
hostAliases:
- ip: 10.10.10.100
hostnames:
- myserver.local
- storage.local
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
hostAliases:
- ip: "{{ .Values.ip }}"
hostnames:
- "{{ .Values.host1 }}"
- "{{ .Values.host2 }}"
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.hostAliases
value:
- ip: 10.10.10.200
hostnames:
- server.local
- mystorage.local
@@ -0,0 +1,75 @@
suite: pod hostnetwork test
templates:
- common.yaml
tests:
- it: should pass with hostnetwork disabled from "global"
set:
podOptions:
hostNetwork: false
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.hostNetwork
value: false
- it: should pass with hostnetwork enabled from "global"
set:
podOptions:
hostNetwork: true
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.hostNetwork
value: true
- it: should pass with disabled hostnetwork from pod
set:
podOptions:
hostNetwork: true
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
hostNetwork: false
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.hostNetwork
value: false
- it: should pass with enabled hostnetwork from pod
set:
podOptions:
hostNetwork: false
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
hostNetwork: true
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.hostNetwork
value: true
@@ -0,0 +1,56 @@
suite: pod hostname test
templates:
- common.yaml
tests:
- it: should pass with empty hostname
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.hostname
- it: should pass with hostname set
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
hostname: some-other-hostname
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.hostname
value: some-other-hostname
- it: should pass with hostname from "pod" with tpl
set:
host: some-other-hostname
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
hostname: "{{ .Values.host }}"
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.hostname
value: some-other-hostname
@@ -0,0 +1,155 @@
suite: pod imagePullSecret test
templates:
- common.yaml
tests:
- it: should assign multiple imagePullSecret to primary pod
set:
workload:
workload-name1:
enabled: true
primary: true
type: CronJob
schedule: "* * * * *"
podSpec: {}
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec: {}
imagePullSecret:
pull-secret1:
enabled: true
data:
registry: reg
username: user
password: pass
email: mail
pull-secret2:
enabled: true
data:
registry: reg
username: user
password: pass
email: mail
asserts:
- documentIndex: &cronJobDoc 2
isKind:
of: CronJob
- documentIndex: *cronJobDoc
equal:
path: metadata.name
value: release-name-common-test
- documentIndex: *cronJobDoc
equal:
path: spec.jobTemplate.spec.template.spec.imagePullSecrets
value:
- name: release-name-common-test-pull-secret1
- name: release-name-common-test-pull-secret2
- documentIndex: &otherDeploymentDoc 3
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
isNull:
path: spec.template.spec.imagePullSecrets
- it: should assign multiple imagePullSecret to all pods
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec: {}
imagePullSecret:
pull-secret1:
enabled: true
data:
registry: reg
username: user
password: pass
email: mail
targetSelectAll: true
pull-secret2:
enabled: true
data:
registry: reg
username: user
password: pass
email: mail
targetSelectAll: true
asserts:
- documentIndex: &deploymentDoc 2
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.imagePullSecrets
value:
- name: release-name-common-test-pull-secret1
- name: release-name-common-test-pull-secret2
- documentIndex: &otherDeploymentDoc 3
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
equal:
path: spec.template.spec.imagePullSecrets
value:
- name: release-name-common-test-pull-secret1
- name: release-name-common-test-pull-secret2
- it: should assign imagePullSecret to selected pods
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec: {}
imagePullSecret:
pull-secret1:
enabled: true
data:
registry: reg
username: user
password: pass
email: mail
targetSelector:
- workload-name1
- workload-name2
pull-secret2:
enabled: true
data:
registry: reg
username: user
password: pass
email: mail
targetSelector:
- workload-name1
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.imagePullSecrets
value:
- name: release-name-common-test-pull-secret1
- name: release-name-common-test-pull-secret2
- documentIndex: &otherDeploymentDoc 3
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
equal:
path: spec.template.spec.imagePullSecrets
value:
- name: release-name-common-test-pull-secret1
@@ -0,0 +1,137 @@
suite: pod restart policy test
templates:
- common.yaml
tests:
- it: should pass with restartPolicy empty
set:
podOptions:
restartPolicy: ""
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.restartPolicy
value: Always
- it: should pass with restartPolicy set from "global"
set:
podOptions:
restartPolicy: Always
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.restartPolicy
value: Always
- it: should pass with restartPolicy set from "pod"
set:
podOptions:
restartPolicy: Never
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
restartPolicy: Always
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.restartPolicy
value: Always
- it: should pass with restartPolicy set from "pod" on Jobs
set:
podOptions:
restartPolicy: Never
workload:
workload-name1:
enabled: true
primary: true
type: Job
podSpec:
restartPolicy: OnFailure
asserts:
- documentIndex: &jobDoc 0
isKind:
of: Job
- documentIndex: *jobDoc
equal:
path: spec.template.spec.restartPolicy
value: OnFailure
- it: should pass with restartPolicy set from "pod" on Jobs from tpl
set:
policy: OnFailure
podOptions:
restartPolicy: Never
workload:
workload-name1:
enabled: true
primary: true
type: Job
podSpec:
restartPolicy: "{{ .Values.policy }}"
asserts:
- documentIndex: *jobDoc
equal:
path: spec.template.spec.restartPolicy
value: OnFailure
# Failures
- it: should fail with restartPolicy to Never on Deployment
set:
podOptions:
restartPolicy: Never
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Expected <restartPolicy to be [Always] for [Deployment] but got [Never]
- it: should fail with restartPolicy to invalid on global
set:
podOptions:
restartPolicy: invalid
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Expected <restartPolicy to be one of [Never, Always, OnFailure] but got [invalid]
- it: should fail with restartPolicy to invalid-policy on pod
set:
podOptions:
restartPolicy: invalid
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
restartPolicy: invalid-policy
asserts:
- failedTemplate:
errorMessage: Expected <restartPolicy to be one of [Never, Always, OnFailure] but got [invalid-policy]
@@ -0,0 +1,191 @@
suite: pod runtime class name test
templates:
- common.yaml
tests:
- it: should pass with empty runtimeClassName
set:
podOptions:
runtimeClassName: ""
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.runtimeClassName
- it: should pass with runtimeClassName from "global"
set:
podOptions:
runtimeClassName: some-runtime-class
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.runtimeClassName
value: some-runtime-class
- it: should pass with runtimeClassName from "pod"
set:
podOptions:
runtimeClassName: some-runtime-class
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
runtimeClassName: some-other-runtime-class
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.runtimeClassName
value: some-other-runtime-class
- it: should pass with runtimeClassName from "pod" with tpl
set:
runtimeClass: some-other-runtime-class
podOptions:
runtimeClassName: some-runtime-class
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
runtimeClassName: "{{ .Values.runtimeClass }}"
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.runtimeClassName
value: some-other-runtime-class
- it: should pass with runtimeClassName from ixChartContext with targetSelector
set:
scaleGPU:
- gpu:
key: value
targetSelector:
workload-name1:
- container-name1
workload-name3:
- container-name1
global:
ixChartContext:
addNvidiaRuntimeClass: true
nvidiaRuntimeClassName: ix-runtime
podOptions:
runtimeClassName: some-class
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
runtimeClassName: some-other-class
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec:
runtimeClassName: some-class
workload-name3:
enabled: true
primary: false
type: Deployment
podSpec:
runtimeClassName: some-class
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.runtimeClassName
value: ix-runtime
- documentIndex: &deploymentDoc 1
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.runtimeClassName
value: some-class
- documentIndex: &otherDeploymentDoc 2
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
equal:
path: spec.template.spec.runtimeClassName
value: ix-runtime
- it: should pass with runtimeClassName from ixChartContext without targetSelector (on primary workload)
set:
scaleGPU:
- gpu:
key: value
global:
ixChartContext:
addNvidiaRuntimeClass: true
nvidiaRuntimeClassName: ix-runtime
workload:
workload-name1:
enabled: true
primary: true
type: Job
podSpec:
runtimeClassName: some-other-class
workload-name2:
enabled: true
primary: false
type: CronJob
schedule: "* * * * *"
podSpec: {}
asserts:
- documentIndex: &jobDoc 0
isKind:
of: Job
- documentIndex: *jobDoc
equal:
path: spec.template.spec.runtimeClassName
value: ix-runtime
- documentIndex: &cronJobDoc 1
isKind:
of: CronJob
- documentIndex: *cronJobDoc
isNull:
path: spec.jobTemplate.spec.template.spec.runtimeClassName
- it: should pass with runtimeClassName not set from ixChartContext without gpu value
set:
scaleGPU:
- gpu: {}
targetSelector:
workload-name1:
- container-name1
global:
ixChartContext:
addNvidiaRuntimeClass: true
nvidiaRuntimeClassName: ix-runtime
workload:
workload-name1:
enabled: true
primary: true
type: Job
podSpec:
runtimeClassName: some-other-class
asserts:
- documentIndex: *jobDoc
isKind:
of: Job
- documentIndex: *jobDoc
equal:
path: spec.template.spec.runtimeClassName
value: some-other-class
@@ -0,0 +1,497 @@
suite: pod securityContext test
templates:
- common.yaml
tests:
- it: should pass with securityContext from "global"
set:
securityContext:
pod:
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
supplementalGroups:
- 1000
- 1001
sysctls:
- name: some_name
value: "some_value"
- name: some_other_name
value: "some_other_value"
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.securityContext
value:
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
supplementalGroups:
- 1000
- 1001
sysctls:
- name: some_name
value: "some_value"
- name: some_other_name
value: "some_other_value"
- it: should pass with securityContext from "global" and partial override with "pod"
set:
securityContext:
pod:
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
supplementalGroups:
- 1000
- 1001
sysctls:
- name: some_name
value: "some_value"
- name: some_other_name
value: "some_other_value"
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
securityContext:
fsGroup: 1001
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.securityContext
value:
fsGroup: 1001
fsGroupChangePolicy: OnRootMismatch
supplementalGroups:
- 1000
- 1001
sysctls:
- name: some_name
value: "some_value"
- name: some_other_name
value: "some_other_value"
- it: should pass with securityContext from "global" and full override with "pod"
set:
some_sysctl_name: some_name
some_sysctl_value: 2
securityContext:
pod:
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
supplementalGroups:
- 1000
- 1001
sysctls:
- name: some_name
value: "some_value"
- name: some_other_name
value: "some_other_value"
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
securityContext:
fsGroup: 1001
fsGroupChangePolicy: Always
supplementalGroups:
- 1002
- 1003
sysctls:
- name: "{{ .Values.some_sysctl_name }}"
value: "{{ .Values.some_sysctl_value }}"
- name: some_other_name
value: "some_different_value"
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.securityContext
value:
fsGroup: 1001
fsGroupChangePolicy: Always
supplementalGroups:
- 1002
- 1003
sysctls:
- name: some_name
value: "2"
- name: some_other_name
value: "some_different_value"
- it: should pass with sysctls automatically appended based on services
set:
some_sysctl_name: some_name
some_sysctl_value: 2
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
securityContext:
fsGroup: 1001
fsGroupChangePolicy: Always
supplementalGroups:
- 1002
- 1003
sysctls:
- name: "{{ .Values.some_sysctl_name }}"
value: "{{ .Values.some_sysctl_value }}"
- name: some_other_name
value: "some_different_value"
workload-name2:
enabled: true
type: Deployment
podSpec: {}
service:
service-name1:
enabled: true
primary: true
type: ClusterIP
ports:
port-name:
enabled: true
primary: true
port: 80
service-name2:
enabled: true
type: ClusterIP
ports:
port-name:
enabled: true
primary: true
port: 53
service-name3:
enabled: true
type: ClusterIP
targetSelector: workload-name2
ports:
port-name:
enabled: true
primary: true
port: 443
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.securityContext
value:
fsGroup: 1001
fsGroupChangePolicy: Always
supplementalGroups:
- 1002
- 1003
sysctls:
- name: some_name
value: "2"
- name: some_other_name
value: "some_different_value"
- name: net.ipv4.ip_unprivileged_port_start
value: "53"
- documentIndex: &otherdeploymentDoc 1
isKind:
of: Deployment
- documentIndex: *otherdeploymentDoc
equal:
path: spec.template.spec.securityContext
value:
fsGroup: 568
fsGroupChangePolicy: OnRootMismatch
supplementalGroups: []
sysctls:
- name: net.ipv4.ip_unprivileged_port_start
value: "443"
- it: should pass with no sysctls port_start automatically appended based on services when port is higher than 1024
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
service:
service-name1:
enabled: true
primary: true
type: ClusterIP
ports:
port-name:
enabled: true
primary: true
port: 25000
targetPort: 3000
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.securityContext
value:
fsGroup: 568
fsGroupChangePolicy: OnRootMismatch
supplementalGroups: []
sysctls: []
- it: should pass with with gpu assigned to primary pod
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
securityContext:
supplementalGroups:
- 1000
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec: {}
scaleGPU:
- gpu:
nvidia: "1"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.securityContext
value:
fsGroup: 568
fsGroupChangePolicy: OnRootMismatch
supplementalGroups:
- 1000
- 44
sysctls: []
- documentIndex: &otherDeploymentDoc 1
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
equal:
path: spec.template.spec.securityContext
value:
fsGroup: 568
fsGroupChangePolicy: OnRootMismatch
supplementalGroups: []
sysctls: []
- it: should pass with with gpu assigned to specific pod
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
securityContext:
supplementalGroups:
- 1000
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec: {}
scaleGPU:
- gpu:
nvidia: "1"
targetSelector:
workload-name1:
- container-name1
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.securityContext
value:
fsGroup: 568
fsGroupChangePolicy: OnRootMismatch
supplementalGroups:
- 1000
- 44
sysctls: []
- documentIndex: &otherDeploymentDoc 1
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
equal:
path: spec.template.spec.securityContext
value:
fsGroup: 568
fsGroupChangePolicy: OnRootMismatch
supplementalGroups: []
sysctls: []
- it: should pass with with gpu assigned to multiple pod
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
securityContext:
supplementalGroups:
- 1000
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec: {}
scaleGPU:
- gpu:
nvidia: "1"
targetSelector:
workload-name1:
- container-name1
workload-name2:
- container-name1
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.securityContext
value:
fsGroup: 568
fsGroupChangePolicy: OnRootMismatch
supplementalGroups:
- 1000
- 44
sysctls: []
- documentIndex: &otherDeploymentDoc 1
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
equal:
path: spec.template.spec.securityContext
value:
fsGroup: 568
fsGroupChangePolicy: OnRootMismatch
supplementalGroups:
- 44
sysctls: []
# Failures
- it: should fail with empty securityContext from "global"
set:
securityContext:
pod: null
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Pod - Expected non-empty <.Values.securityContext.pod>
- it: should fail with empty fsGroup
set:
securityContext:
pod:
fsGroup: ""
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Pod - Expected non-empty <fsGroup>
- it: should fail with empty fsGroupChangePolicy
set:
securityContext:
pod:
fsGroup: 568
fsGroupChangePolicy: ""
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Pod - Expected non-empty <fsGroupChangePolicy>
- it: should fail with invalid fsGroupChangePolicy
set:
securityContext:
pod:
fsGroup: 568
fsGroupChangePolicy: invalid
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Pod - Expected <fsGroupChangePolicy> to be one of [Always, OnRootMismatch], but got [invalid]
- it: should fail with empty name in sysctls
set:
securityContext:
pod:
fsGroup: 568
fsGroupChangePolicy: OnRootMismatch
sysctls:
- name: ""
value: "some_value"
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Pod - Expected non-empty <name> in <sysctls>
- it: should fail with empty value in sysctls
set:
securityContext:
pod:
fsGroup: 568
fsGroupChangePolicy: OnRootMismatch
sysctls:
- name: some_name
value: ""
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- failedTemplate:
errorMessage: Pod - Expected non-empty <value> in <sysctls>
@@ -0,0 +1,174 @@
suite: pod service account name test
templates:
- common.yaml
tests:
- it: should assign serviceAccount to primary pod
set:
workload:
workload-name1:
enabled: true
primary: true
type: CronJob
schedule: "* * * * *"
podSpec: {}
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec: {}
serviceAccount:
sa-name1:
enabled: true
primary: true
asserts:
- documentIndex: &cronJobDoc 1
isKind:
of: CronJob
- documentIndex: *cronJobDoc
equal:
path: metadata.name
value: release-name-common-test
- documentIndex: *cronJobDoc
equal:
path: spec.jobTemplate.spec.template.spec.serviceAccountName
value: release-name-common-test
- documentIndex: &otherDeploymentDoc 2
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
equal:
path: spec.template.spec.serviceAccountName
value: default
- it: should assign serviceAccount to all pods
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec: {}
serviceAccount:
sa-name1:
enabled: true
primary: true
targetSelectAll: true
asserts:
- documentIndex: &deploymentDoc 1
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.serviceAccountName
value: release-name-common-test
- documentIndex: &otherDeploymentDoc 2
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
equal:
path: spec.template.spec.serviceAccountName
value: release-name-common-test
- it: should assign serviceAccount to selected pods
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec: {}
serviceAccount:
sa-name1:
enabled: true
primary: true
targetSelector:
- workload-name1
sa-name2:
enabled: true
primary: false
targetSelector:
- workload-name2
asserts:
- documentIndex: &deploymentDoc 2
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.serviceAccountName
value: release-name-common-test
- documentIndex: &otherDeploymentDoc 3
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
equal:
path: spec.template.spec.serviceAccountName
value: release-name-common-test-sa-name2
- it: should assign serviceAccount to selected pods
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
workload-name2:
enabled: true
primary: false
type: Deployment
podSpec: {}
serviceAccount:
sa-name1:
enabled: true
primary: true
targetSelector:
- workload-name1
- workload-name2
asserts:
- documentIndex: &deploymentDoc 1
isKind:
of: Deployment
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.serviceAccountName
value: release-name-common-test
- documentIndex: &otherDeploymentDoc 2
isKind:
of: Deployment
- documentIndex: *otherDeploymentDoc
equal:
path: spec.template.spec.serviceAccountName
value: release-name-common-test
# Failures
- it: should fail with more than 1 SA assigned to a pod
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
serviceAccount:
sa-name1:
enabled: true
primary: true
targetSelector:
- workload-name1
sa-name2:
enabled: true
targetSelector:
- workload-name1
asserts:
- failedTemplate:
errorMessage: Expected at most 1 ServiceAccount to be assigned on a pod [workload-name1]. But [2] were assigned
@@ -0,0 +1,72 @@
suite: pod termination grace period test
templates:
- common.yaml
tests:
- it: should pass with empty terminationGracePeriodSeconds
set:
podOptions:
terminationGracePeriodSeconds: ""
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.terminationGracePeriodSeconds
- it: should pass with terminationGracePeriodSeconds from "global"
set:
podOptions:
terminationGracePeriodSeconds: 100
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.terminationGracePeriodSeconds
value: 100
- it: should pass with terminationGracePeriodSeconds from "pod"
set:
podOptions:
terminationGracePeriodSeconds: 100
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
terminationGracePeriodSeconds: 150
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.terminationGracePeriodSeconds
value: 150
- it: should pass with terminationGracePeriodSeconds from "pod" with tpl
set:
period: 125
podOptions:
terminationGracePeriodSeconds: 50
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
terminationGracePeriodSeconds: "{{ .Values.period }}"
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.terminationGracePeriodSeconds
value: 125
@@ -0,0 +1,201 @@
suite: pod tolerations test
templates:
- common.yaml
tests:
- it: should pass with empty tolerations
set:
podOptions:
tolerations: []
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
isNull:
path: spec.template.spec.tolerations
- it: should pass with tolerations from "global"
set:
podOptions:
tolerations:
- operator: Exists
effect: NoExecute
tolerationSeconds: 3600
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.tolerations
value:
- operator: Exists
effect: NoExecute
tolerationSeconds: 3600
- it: should pass with tolerations from "pod"
set:
podOptions:
tolerations:
- operator: Exists
effect: NoExecute
tolerationSeconds: 3600
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
tolerations:
- operator: Exists
effect: NoSchedule
tolerationSeconds: 1800
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.tolerations
value:
- operator: Exists
effect: NoSchedule
tolerationSeconds: 1800
- it: should pass with tolerations from "pod" with tpl
set:
op: Exists
effect: NoSchedule
op1: Equal
effect1: PreferNoSchedule
key: key
value: value
podOptions:
tolerations:
- operator: Exists
effect: NoExecute
tolerationSeconds: 3600
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
tolerations:
- operator: "{{ .Values.op }}"
effect: "{{ .Values.effect }}"
tolerationSeconds: 1800
- operator: "{{ .Values.op1 }}"
effect: "{{ .Values.effect1 }}"
tolerationSeconds: 1800
key: "{{ .Values.key }}"
value: "{{ .Values.value }}"
asserts:
- documentIndex: *deploymentDoc
equal:
path: spec.template.spec.tolerations
value:
- operator: Exists
effect: NoSchedule
tolerationSeconds: 1800
- operator: Equal
effect: PreferNoSchedule
tolerationSeconds: 1800
key: key
value: value
# Failures
- it: should fail with invalid operator
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
tolerations:
- operator: Invalid
asserts:
- failedTemplate:
errorMessage: Expected <tolerations.operator> to be one of [Exists, Equal] but got [Invalid]
- it: should fail with empty key and operator set to Equal
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
tolerations:
- operator: Equal
value: value
asserts:
- failedTemplate:
errorMessage: Expected non-empty <tolerations.key> and <tolerations.value> with <tolerations.operator> set to [Equal]
- it: should fail with empty value and operator set to Equal
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
tolerations:
- operator: Equal
key: key
asserts:
- failedTemplate:
errorMessage: Expected non-empty <tolerations.key> and <tolerations.value> with <tolerations.operator> set to [Equal]
- it: should fail with value set and operator set to Exists
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
tolerations:
- operator: Exists
value: value
asserts:
- failedTemplate:
errorMessage: Expected empty <tolerations.value> with <tolerations.operator> set to [Exists], but got [value]
- it: should fail with effect set to Invalid
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
tolerations:
- operator: Exists
effect: Invalid
asserts:
- failedTemplate:
errorMessage: Expected <tolerations.effect> to be one of [NoExecute, NoSchedule, PreferNoSchedule], but got [Invalid]
- it: should fail with tolerationSeconds not a number
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec:
tolerations:
- operator: Exists
tolerationSeconds: not-a-number
asserts:
- failedTemplate:
errorMessage: Expected <tolerations.tolerationSeconds> to be a number, but got [not-a-number]
@@ -0,0 +1,210 @@
suite: pod configmap volume test
templates:
- common.yaml
tests:
- it: should pass with configmap volume
set:
some_object: some-object-name
some_mode: "0777"
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
conf-vol:
enabled: true
type: configmap
objectName: "{{ .Values.some_object }}"
defaultMode: "{{ .Values.some_mode }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: conf-vol
configMap:
name: release-name-common-test-some-object-name
defaultMode: 0777
- it: should pass with configmap volume with items
set:
some_object: some-object-name
some_mode: "0777"
some_key: some-key
some_path: some-path
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
conf-vol:
enabled: true
type: configmap
objectName: "{{ .Values.some_object }}"
defaultMode: "{{ .Values.some_mode }}"
items:
- key: "{{ .Values.some_key }}"
path: "{{ .Values.some_path }}"
- key: some-other-key
path: some-other-path
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: conf-vol
configMap:
name: release-name-common-test-some-object-name
defaultMode: 0777
items:
- key: some-key
path: some-path
- key: some-other-key
path: some-other-path
- it: should pass with configmap volume without expanding object name
set:
some_object: some-object-name
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
conf-vol:
enabled: true
type: configmap
objectName: "{{ .Values.some_object }}"
expandObjectName: false
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: conf-vol
configMap:
name: some-object-name
# Failures
- it: should fail without objectName in configmap
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: configmap
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <objectName> on <configmap> type
- it: should fail with empty objectName in configmap
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: configmap
objectName: ""
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <objectName> on <configmap> type
- it: should fail with defaultMode not a string in configmap
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: configmap
objectName: some-object-name
defaultMode: 1234
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <defaultMode> to be [string], but got [float64]
- it: should fail with defaultMode not in format of "0000"-"0777" in configmap
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: configmap
objectName: some-object-name
defaultMode: "123"
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <defaultMode> to have be in format of ["0777"], but got ["123"]
- it: should fail without key in items in configmap
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: configmap
objectName: some-object-name
items:
- key: ""
path: some-path
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <items.key>
- it: should fail without path in items in configmap
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: configmap
objectName: some-object-name
items:
- key: some-key
path: ""
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <items.path>
@@ -0,0 +1,110 @@
suite: pod device volume test
templates:
- common.yaml
tests:
- it: should pass with device volume
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
dev-vol:
enabled: true
type: device
hostPath: /dev/something
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: dev-vol
hostPath:
path: /dev/something
- it: should pass with device volume and type
set:
some_path: /dev/something
some_type: BlockDevice
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
dev-vol:
enabled: true
type: device
hostPath: "{{ .Values.some_path }}"
hostPathType: "{{ .Values.some_type }}"
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: dev-vol
hostPath:
path: /dev/something
type: BlockDevice
# Failures
- it: should fail without hostPath
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: device
hostPath: ""
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <hostPath> on <device> type
- it: should fail with relative hostPath
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: device
hostPath: some-path
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <hostPath> to start with a forward slash [/] on <device> type
- it: should fail with invalid hostPathType
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: device
hostPath: /some-path
hostPathType: invalid
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <hostPathType> to be one of [DirectoryOrCreate, Directory, FileOrCreate, File, Socket, CharDevice, BlockDevice], but got [invalid]
@@ -0,0 +1,123 @@
suite: pod emptyDir volume test
templates:
- common.yaml
tests:
- it: should pass with emptyDir volume
set:
some_medium: Memory
some_size: 2Gi
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
emptyDir-vol:
enabled: true
type: emptyDir
medium: "{{ .Values.some_medium }}"
size: "{{ .Values.some_size }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: emptyDir-vol
emptyDir:
medium: Memory
sizeLimit: 2Gi
- it: should pass with emptyDir volume bare bones
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
emptyDir-vol:
enabled: true
type: emptyDir
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: emptyDir-vol
emptyDir: {}
- it: should pass with emptyDir volume with medium set
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
emptyDir-vol:
enabled: true
type: emptyDir
medium: Memory
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: emptyDir-vol
emptyDir:
medium: Memory
- it: should pass with emptyDir volume with size set
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
emptyDir-vol:
enabled: true
type: emptyDir
size: 3Gi
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: emptyDir-vol
emptyDir:
sizeLimit: 3Gi
# Failures
- it: should fail with invalid medium in emptyDir
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: emptyDir
medium: not-a-valid-medium
asserts:
- failedTemplate:
errorMessage: Persistence - Expected [medium] to be one of ["", Memory], but got [not-a-valid-medium] on <emptyDir> type
@@ -0,0 +1,110 @@
suite: pod hostPath volume test
templates:
- common.yaml
tests:
- it: should pass with hostPath volume
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
host-vol:
enabled: true
type: hostPath
hostPath: /some-path
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: host-vol
hostPath:
path: /some-path
- it: should pass with hostPath volume and type
set:
some_path: /some-path
some_type: DirectoryOrCreate
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
host-vol:
enabled: true
type: hostPath
hostPath: "{{ .Values.some_path }}"
hostPathType: "{{ .Values.some_type }}"
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: host-vol
hostPath:
path: /some-path
type: DirectoryOrCreate
# Failures
- it: should fail without hostPath
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: hostPath
hostPath: ""
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <hostPath> on <hostPath> type
- it: should fail with relative hostPath
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: hostPath
hostPath: some-path
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <hostPath> to start with a forward slash [/] on <hostPath> type
- it: should fail with invalid hostPathType
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: hostPath
hostPath: /some-path
hostPathType: invalid
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <hostPathType> to be one of [DirectoryOrCreate, Directory, FileOrCreate, File, Socket, CharDevice, BlockDevice], but got [invalid]
@@ -0,0 +1,137 @@
suite: pod ixVolume volume test
templates:
- common.yaml
tests:
- it: should pass with ixVolume volume
set:
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
ixVolumes:
- /mnt/pool/ix-applications/ix-app
persistence:
ix-vol:
enabled: true
type: ixVolume
datasetName: ix-app
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: ix-vol
hostPath:
path: /mnt/pool/ix-applications/ix-app
- it: should pass with hostPath volume and type
set:
some_dataset: ix-app
some_type: DirectoryOrCreate
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
ixVolumes:
- /mnt/pool/ix-applications/ix-app
persistence:
ix-vol:
enabled: true
type: ixVolume
datasetName: "{{ .Values.some_dataset }}"
hostPathType: "{{ .Values.some_type }}"
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: ix-vol
hostPath:
path: /mnt/pool/ix-applications/ix-app
type: DirectoryOrCreate
# Failures
- it: should fail without datasetName
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: ixVolume
datasetname: ""
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <datasetName> on <ixVolume> type
- it: should fail with empty ixVolumes
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
ixVolumes: []
persistence:
volume1:
enabled: true
type: ixVolume
datasetName: ix-app
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <ixVolumes> in values on <ixVolume> type
- it: should fail with empty ixVolumes
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
ixVolumes:
- /mnt/pool/ix-applications/ix-wrong-app
- /mnt/pool/ix-applications/ix-other-app
persistence:
volume1:
enabled: true
type: ixVolume
datasetName: ix-app
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <datasetName> [ix-app] to exist on <ixVolumes> list, but list contained [/mnt/pool/ix-applications/ix-wrong-app, /mnt/pool/ix-applications/ix-other-app] on <ixVolume> type
- it: should fail with invalid hostPathType
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
ixVolumes:
- /mnt/pool/ix-applications/ix-app
persistence:
volume1:
enabled: true
type: ixVolume
datasetName: ix-app
hostPathType: invalid
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <hostPathType> to be one of [DirectoryOrCreate, Directory, FileOrCreate, File, Socket, CharDevice, BlockDevice], but got [invalid]
@@ -0,0 +1,211 @@
suite: pod secret volume test
templates:
- common.yaml
tests:
- it: should pass with secret volume
set:
some_object: some-object-name
some_mode: "0777"
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
secret-vol:
enabled: true
type: secret
objectName: "{{ .Values.some_object }}"
defaultMode: "{{ .Values.some_mode }}"
asserts:
- documentIndex: &deploymentDoc 0
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: secret-vol
secret:
secretName: release-name-common-test-some-object-name
defaultMode: 0777
- it: should pass with secret volume with items
set:
some_object: some-object-name
some_mode: "0777"
some_key: some-key
some_path: some-path
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
secret-vol:
enabled: true
type: secret
objectName: "{{ .Values.some_object }}"
defaultMode: "{{ .Values.some_mode }}"
items:
- key: "{{ .Values.some_key }}"
path: "{{ .Values.some_path }}"
- key: some-other-key
path: some-other-path
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: secret-vol
secret:
secretName: release-name-common-test-some-object-name
defaultMode: 0777
items:
- key: some-key
path: some-path
- key: some-other-key
path: some-other-path
- it: should pass with secret volume without expanding object name
set:
some_object: some-object-name
workload:
workload-name1:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
secret-vol:
enabled: true
type: secret
objectName: "{{ .Values.some_object }}"
expandObjectName: false
asserts:
- documentIndex: *deploymentDoc
isKind:
of: Deployment
- documentIndex: *deploymentDoc
contains:
path: spec.template.spec.volumes
content:
name: secret-vol
secret:
secretName: some-object-name
# Failures
- it: should fail without objectName in secret
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: secret
objectName: ""
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <objectName> on <secret> type
- it: should fail with empty objectName in secret
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: secret
objectName: ""
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <objectName> on <secret> type
- it: should fail with defaultMode not a string in secret
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: secret
objectName: some-object-name
defaultMode: 1234
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <defaultMode> to be [string], but got [float64]
- it: should fail with defaultMode not in format of "0000"-"0777" in secret
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: secret
objectName: some-object-name
defaultMode: "123"
asserts:
- failedTemplate:
errorMessage: Persistence - Expected <defaultMode> to have be in format of ["0777"], but got ["123"]
- it: should fail without key in items in secret
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: secret
objectName: some-object-name
items:
- key: ""
path: some-path
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <items.key>
- it: should fail without path in items in secret
set:
workload:
some-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
persistence:
volume1:
enabled: true
type: secret
objectName: some-object-name
items:
- key: some-key
path: ""
asserts:
- failedTemplate:
errorMessage: Persistence - Expected non-empty <items.path>
@@ -0,0 +1,250 @@
suite: rbac data test
templates:
- common.yaml
tests:
- it: should pass with rules and subjects added with tpl and primary rbac/sa
set:
some_verb: list
some_group: apps
some_resource: deployments
some_kind: some-kind
some_name: some-name
some_api_group: rbac.authorization.k8s.io
serviceAccount:
my-sa:
enabled: true
primary: true
my-other-sa:
enabled: true
primary: false
rbac:
my-rbac:
enabled: true
primary: true
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- "{{ .Values.some_group }}"
resources:
- "{{ .Values.some_resource }}"
verbs:
- "{{ .Values.some_verb }}"
subjects:
- kind: a-kind
name: a-name
apiGroup: rbac.authorization.k8s.io
- kind: "{{ .Values.some_kind }}"
name: "{{ .Values.some_name }}"
apiGroup: "{{ .Values.some_api_group }}"
asserts:
- documentIndex: &roleDoc 2
isKind:
of: Role
- documentIndex: *roleDoc
equal:
path: metadata.name
value: release-name-common-test
- documentIndex: *roleDoc
equal:
path: rules
value:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- deployments
verbs:
- list
- documentIndex: &roleBinding 3
isKind:
of: RoleBinding
- documentIndex: *roleBinding
equal:
path: metadata.name
value: release-name-common-test
- documentIndex: *roleBinding
equal:
path: subjects
value:
- kind: ServiceAccount
name: release-name-common-test
namespace: NAMESPACE
- kind: a-kind
name: a-name
apiGroup: rbac.authorization.k8s.io
- kind: some-kind
name: some-name
apiGroup: rbac.authorization.k8s.io
- it: should pass with rules and subjects added with tpl and allSA on clusterWide
set:
some_verb: list
some_group: apps
some_resource: deployments
some_kind: some-kind
some_name: some-name
some_api_group: rbac.authorization.k8s.io
serviceAccount:
my-sa:
enabled: true
primary: true
my-other-sa:
enabled: true
primary: false
rbac:
z-rbac:
enabled: true
primary: true
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
my-rbac2:
enabled: true
clusterWide: true
allServiceAccounts: true
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- "{{ .Values.some_group }}"
resources:
- "{{ .Values.some_resource }}"
verbs:
- "{{ .Values.some_verb }}"
subjects:
- kind: a-kind
name: a-name
apiGroup: rbac.authorization.k8s.io
- kind: "{{ .Values.some_kind }}"
name: "{{ .Values.some_name }}"
apiGroup: "{{ .Values.some_api_group }}"
asserts:
- documentIndex: &clusterRoleDoc 2
isKind:
of: ClusterRole
- documentIndex: *clusterRoleDoc
equal:
path: metadata.name
value: release-name-common-test-my-rbac2
- documentIndex: *clusterRoleDoc
equal:
path: rules
value:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- deployments
verbs:
- list
- documentIndex: &clusterRoleBinding 3
isKind:
of: ClusterRoleBinding
- documentIndex: *clusterRoleBinding
equal:
path: metadata.name
value: release-name-common-test-my-rbac2
- documentIndex: *clusterRoleBinding
equal:
path: subjects
value:
- kind: ServiceAccount
name: release-name-common-test-my-other-sa
namespace: NAMESPACE
- kind: ServiceAccount
name: release-name-common-test
namespace: NAMESPACE
- apiGroup: rbac.authorization.k8s.io
kind: a-kind
name: a-name
- apiGroup: rbac.authorization.k8s.io
kind: some-kind
name: some-name
- it: should pass with serviceAccount selector
set:
serviceAccount:
my-sa:
enabled: true
primary: true
my-other-sa:
enabled: true
primary: false
rbac:
z-rbac:
enabled: true
primary: true
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
my-rbac3:
enabled: true
serviceAccounts:
- my-other-sa
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
asserts:
- documentIndex: &roleDoc 2
isKind:
of: Role
- documentIndex: *roleDoc
equal:
path: metadata.name
value: release-name-common-test-my-rbac3
- documentIndex: *roleDoc
equal:
path: rules
value:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- documentIndex: &roleBinding 3
isKind:
of: RoleBinding
- documentIndex: *roleBinding
equal:
path: metadata.name
value: release-name-common-test-my-rbac3
- documentIndex: *roleBinding
equal:
path: subjects
value:
- kind: ServiceAccount
name: release-name-common-test-my-other-sa
namespace: NAMESPACE
@@ -0,0 +1,163 @@
suite: rbac metadata test
templates:
- common.yaml
chart:
appVersion: &appVer v9.9.9
tests:
- it: should pass with rbac created with labels and annotations
set:
label1: label1
label2: global_label2
annotation1: annotation1
annotation2: global_annotation2
global:
labels:
g_label1: global_label1
g_label2: "{{ .Values.label2 }}"
annotations:
g_annotation1: global_annotation1
g_annotation2: "{{ .Values.annotation2 }}"
serviceAccount:
my-sa1:
enabled: true
primary: true
rbac:
my-rbac1:
enabled: true
primary: true
labels:
label1: "{{ .Values.label1 }}"
label2: label2
annotations:
annotation1: "{{ .Values.annotation1 }}"
annotation2: annotation2
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- list
- watch
my-rbac2:
enabled: true
primary: false
clusterWide: true
allServiceAccounts: true
labels:
label1: "{{ .Values.label1 }}"
label2: label2
annotations:
annotation1: "{{ .Values.annotation1 }}"
annotation2: annotation2
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- list
- watch
asserts:
- documentIndex: &roleDoc 1
isKind:
of: Role
- documentIndex: *roleDoc
equal:
path: metadata.annotations
value:
annotation1: annotation1
annotation2: annotation2
g_annotation1: global_annotation1
g_annotation2: global_annotation2
- documentIndex: *roleDoc
equal:
path: metadata.labels
value:
app: common-test-1.0.0
release: RELEASE-NAME
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/version: *appVer
g_label1: global_label1
g_label2: global_label2
label1: label1
label2: label2
- documentIndex: &roleBindingDoc 2
isKind:
of: RoleBinding
- documentIndex: *roleBindingDoc
equal:
path: metadata.annotations
value:
annotation1: annotation1
annotation2: annotation2
g_annotation1: global_annotation1
g_annotation2: global_annotation2
- documentIndex: *roleBindingDoc
equal:
path: metadata.labels
value:
app: common-test-1.0.0
release: RELEASE-NAME
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/version: *appVer
g_label1: global_label1
g_label2: global_label2
label1: label1
label2: label2
- documentIndex: &clusterRoleDoc 3
isKind:
of: ClusterRole
- documentIndex: *clusterRoleDoc
equal:
path: metadata.annotations
value:
annotation1: annotation1
annotation2: annotation2
g_annotation1: global_annotation1
g_annotation2: global_annotation2
- documentIndex: *clusterRoleDoc
equal:
path: metadata.labels
value:
app: common-test-1.0.0
release: RELEASE-NAME
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/version: *appVer
g_label1: global_label1
g_label2: global_label2
label1: label1
label2: label2
- documentIndex: &clusterRoleBindingDoc 4
isKind:
of: ClusterRoleBinding
- documentIndex: *clusterRoleBindingDoc
equal:
path: metadata.annotations
value:
annotation1: annotation1
annotation2: annotation2
g_annotation1: global_annotation1
g_annotation2: global_annotation2
- documentIndex: *clusterRoleBindingDoc
equal:
path: metadata.labels
value:
app: common-test-1.0.0
release: RELEASE-NAME
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/version: *appVer
g_label1: global_label1
g_label2: global_label2
label1: label1
label2: label2
@@ -0,0 +1,105 @@
suite: rbac name test
templates:
- common.yaml
tests:
- it: should generate correct name
set:
serviceAccount:
my-sa:
enabled: true
primary: true
rbac:
my-rbac:
enabled: true
primary: true
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
my-rbac2:
enabled: true
clusterWide: true
allServiceAccounts: true
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
my-rbac3:
enabled: true
allServiceAccounts: true
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
asserts:
- documentIndex: &roleDoc 1
isKind:
of: Role
- documentIndex: *roleDoc
isAPIVersion:
of: rbac.authorization.k8s.io/v1
- documentIndex: *roleDoc
equal:
path: metadata.name
value: release-name-common-test
- documentIndex: &roleBindingDoc 2
isKind:
of: RoleBinding
- documentIndex: *roleBindingDoc
isAPIVersion:
of: rbac.authorization.k8s.io/v1
- documentIndex: *roleBindingDoc
equal:
path: metadata.name
value: release-name-common-test
- documentIndex: &clusterRoleDoc 3
isKind:
of: ClusterRole
- documentIndex: *clusterRoleDoc
isAPIVersion:
of: rbac.authorization.k8s.io/v1
- documentIndex: *clusterRoleDoc
equal:
path: metadata.name
value: release-name-common-test-my-rbac2
- documentIndex: &clusterRoleBindingDoc 4
isKind:
of: ClusterRoleBinding
- documentIndex: *clusterRoleBindingDoc
isAPIVersion:
of: rbac.authorization.k8s.io/v1
- documentIndex: *clusterRoleBindingDoc
equal:
path: metadata.name
value: release-name-common-test-my-rbac2
- documentIndex: &otherRoleDoc 5
isKind:
of: Role
- documentIndex: *otherRoleDoc
isAPIVersion:
of: rbac.authorization.k8s.io/v1
- documentIndex: *otherRoleDoc
equal:
path: metadata.name
value: release-name-common-test-my-rbac3
- documentIndex: &otherRoleBindingDoc 6
isKind:
of: RoleBinding
- documentIndex: *otherRoleBindingDoc
isAPIVersion:
of: rbac.authorization.k8s.io/v1
- documentIndex: *otherRoleBindingDoc
equal:
path: metadata.name
value: release-name-common-test-my-rbac3
@@ -0,0 +1,250 @@
suite: rbac validation test
templates:
- common.yaml
tests:
- it: should fail with name longer than 63 characters
set:
rbac:
zmy-rbac:
enabled: true
primary: true
my-rbac-has-super-long-name-that-is-longer-than-63-characters-too-bad:
enabled: true
primary: false
asserts:
- failedTemplate:
errorMessage: Name [release-name-common-test-my-rbac-has-super-long-name-that-is-longer-than-63-characters-too-bad] is not valid. Must start and end with an alphanumeric lowercase character. It can contain '-'. And must be at most 63 characters.
- it: should fail with name starting with underscore
set:
rbac:
my-rbac:
enabled: true
primary: true
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
_my-rbac2:
enabled: true
primary: false
asserts:
- failedTemplate:
errorMessage: Name [release-name-common-test-_my-rbac2] is not valid. Must start and end with an alphanumeric lowercase character. It can contain '-'. And must be at most 63 characters.
- it: should fail with labels not a dict
set:
rbac:
my-rbac:
enabled: true
primary: true
labels: "not a dict"
asserts:
- failedTemplate:
errorMessage: RBAC - Expected <labels> to be a dictionary, but got [string]
- it: should fail with annotations not a dict
set:
rbac:
my-rbac:
enabled: true
primary: true
annotations: "not a dict"
asserts:
- failedTemplate:
errorMessage: RBAC - Expected <annotations> to be a dictionary, but got [string]
- it: should fail with more than 1 primary rbac
set:
rbac:
my-rbac:
enabled: true
primary: true
my-rbac2:
enabled: true
primary: true
asserts:
- failedTemplate:
errorMessage: RBAC - Only one rbac can be primary
- it: should fail without any primary on enabled rbac
set:
rbac:
my-rbac:
enabled: true
primary: false
my-rbac2:
enabled: true
primary: false
asserts:
- failedTemplate:
errorMessage: RBAC - At least one enabled rbac must be primary
- it: should fail without rules in rbac
set:
rbac:
my-rbac:
enabled: true
primary: true
asserts:
- failedTemplate:
errorMessage: RBAC - Expected non-empty <rbac.rules>
- it: should fail without apiGroups in rules in rbac
set:
rbac:
my-rbac:
enabled: true
primary: true
rules:
- resources:
- pods
verbs:
- get
asserts:
- failedTemplate:
errorMessage: RBAC - Expected non-empty <rbac.rules.apiGroups>
- it: should fail without resources in rules in rbac
set:
rbac:
my-rbac:
enabled: true
primary: true
rules:
- apiGroups:
- ""
verbs:
- get
asserts:
- failedTemplate:
errorMessage: RBAC - Expected non-empty <rbac.rules.resources>
- it: should fail without verbs in rules in rbac
set:
rbac:
my-rbac:
enabled: true
primary: true
rules:
- apiGroups:
- ""
resources:
- pods
asserts:
- failedTemplate:
errorMessage: RBAC - Expected non-empty <rbac.rules.verbs>
- it: should fail with empty entry in resources in rules in rbac
set:
rbac:
my-rbac:
enabled: true
primary: true
rules:
- apiGroups:
- ""
resources:
- pods
- ""
verbs:
- get
asserts:
- failedTemplate:
errorMessage: RBAC - Expected non-empty entry in <rbac.rules.resources>
- it: should fail with empty entry in verbs in rules in rbac
set:
rbac:
my-rbac:
enabled: true
primary: true
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- ""
asserts:
- failedTemplate:
errorMessage: RBAC - Expected non-empty entry in <rbac.rules.verbs>
- it: should fail with empty kind in subjects in rbac
set:
serviceAccount:
my-service-account:
enabled: true
primary: true
rbac:
my-rbac:
enabled: true
primary: true
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
subjects:
- kind: ""
name: my-name
apiGroup: my-apiGroup
asserts:
- failedTemplate:
errorMessage: RBAC - Expected non-empty <rbac.subjects.kind>
- it: should fail with empty name in subjects in rbac
set:
serviceAccount:
my-service-account:
enabled: true
primary: true
rbac:
my-rbac:
enabled: true
primary: true
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
subjects:
- kind: my-kind
name: ""
apiGroup: my-apiGroup
asserts:
- failedTemplate:
errorMessage: RBAC - Expected non-empty <rbac.subjects.name>
- it: should fail with empty apiGroup in subjects in rbac
set:
serviceAccount:
my-service-account:
enabled: true
primary: true
rbac:
my-rbac:
enabled: true
primary: true
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
subjects:
- kind: my-kind
name: my-name
apiGroup: ""
asserts:
- failedTemplate:
errorMessage: RBAC - Expected non-empty <rbac.subjects.apiGroup>
@@ -0,0 +1,111 @@
suite: secret data test
templates:
- common.yaml
tests:
- it: should pass with key-value data
set:
secret:
my-secret1:
enabled: true
data:
foo: bar
asserts:
- documentIndex: &secretDoc 0
isKind:
of: Secret
- documentIndex: *secretDoc
equal:
path: stringData
value:
foo: bar
- documentIndex: *secretDoc
equal:
path: type
value: Opaque
- it: should pass with custom secret type
set:
secret:
my-secret1:
enabled: true
type: SomeCustomType
data:
foo: bar
asserts:
- documentIndex: *secretDoc
equal:
path: type
value: SomeCustomType
- it: should pass with key-value data from tpl
set:
data: bar
secret:
my-secret1:
enabled: true
data:
foo: "{{ .Values.data }}"
asserts:
- documentIndex: *secretDoc
equal:
path: stringData
value:
foo: bar
- it: should pass with scalar data
set:
secret:
my-secret1:
enabled: true
data:
foo: |
some multi line
string text
asserts:
- documentIndex: *secretDoc
equal:
path: stringData
value:
foo: |
some multi line
string text
- it: should pass with scalar data with tpl
set:
data: Some other text
secret:
my-secret:
enabled: true
data:
foo: |
file start
{{ .Values.data }}
asserts:
- documentIndex: *secretDoc
equal:
path: stringData
value:
foo: |
file start
Some other text
- it: should pass with scalar data from tpl
set:
data: |
Some other text
some_text
secret:
my-secret:
enabled: true
data:
foo: |
{{- .Values.data | nindent 2 }}
asserts:
- documentIndex: *secretDoc
equal:
path: stringData
value:
foo: |
Some other text
some_text
@@ -0,0 +1,56 @@
suite: secret metadata test
templates:
- common.yaml
chart:
appVersion: &appVer v9.9.9
tests:
- it: should pass with secret created with labels and annotations
set:
label1: label1
label2: global_label2
annotation1: annotation1
annotation2: global_annotation2
global:
labels:
g_label1: global_label1
g_label2: "{{ .Values.label2 }}"
annotations:
g_annotation1: global_annotation1
g_annotation2: "{{ .Values.annotation2 }}"
secret:
my-secret1:
enabled: true
labels:
label1: "{{ .Values.label1 }}"
label2: label2
annotations:
annotation1: "{{ .Values.annotation1 }}"
annotation2: annotation2
data:
foo: bar
asserts:
- documentIndex: &secretDoc 0
isKind:
of: Secret
- documentIndex: *secretDoc
equal:
path: metadata.annotations
value:
annotation1: annotation1
annotation2: annotation2
g_annotation1: global_annotation1
g_annotation2: global_annotation2
- documentIndex: *secretDoc
equal:
path: metadata.labels
value:
app: common-test-1.0.0
release: RELEASE-NAME
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/version: *appVer
g_label1: global_label1
g_label2: global_label2
label1: label1
label2: label2
@@ -0,0 +1,36 @@
suite: secret name test
templates:
- common.yaml
tests:
- it: should generate correct name
set:
secret:
my-secret1:
enabled: true
data:
foo: bar
my-secret2:
enabled: true
data:
foo: bar
asserts:
- documentIndex: &secretDoc 0
isKind:
of: Secret
- documentIndex: *secretDoc
isAPIVersion:
of: v1
- documentIndex: *secretDoc
equal:
path: metadata.name
value: release-name-common-test-my-secret1
- documentIndex: &otherSecretDoc 1
isKind:
of: Secret
- documentIndex: *otherSecretDoc
isAPIVersion:
of: v1
- documentIndex: *otherSecretDoc
equal:
path: metadata.name
value: release-name-common-test-my-secret2
@@ -0,0 +1,81 @@
suite: secret validation test
templates:
- common.yaml
tests:
- it: should fail with name longer than 63 characters
set:
secret:
my-secret-super-long-name-that-is-longer-than-63-characters:
enabled: true
data:
foo: bar
asserts:
- failedTemplate:
errorMessage: Name [release-name-common-test-my-secret-super-long-name-that-is-longer-than-63-characters] is not valid. Must start and end with an alphanumeric lowercase character. It can contain '-'. And must be at most 63 characters.
- it: should fail with name starting with underscore
set:
secret:
_my-secret:
enabled: true
data:
foo: bar
asserts:
- failedTemplate:
errorMessage: Name [release-name-common-test-_my-secret] is not valid. Must start and end with an alphanumeric lowercase character. It can contain '-'. And must be at most 63 characters.
- it: should fail with labels not a dict
set:
secret:
my-secret:
enabled: true
labels: "not a dict"
data:
foo: bar
asserts:
- failedTemplate:
errorMessage: Secret - Expected <labels> to be a dictionary, but got [string]
- it: should fail with annotations not a dict
set:
secret:
my-secret:
enabled: true
annotations: "not a dict"
data:
foo: bar
asserts:
- failedTemplate:
errorMessage: Secret - Expected <annotations> to be a dictionary, but got [string]
- it: should fail with data not a dict
set:
secret:
my-secret:
enabled: true
data: "not a dict"
asserts:
- failedTemplate:
errorMessage: Secret - Expected <data> to be a dictionary, but got [string]
- it: should fail with empty data
set:
secret:
my-secret:
enabled: true
data: {}
asserts:
- failedTemplate:
errorMessage: Secret - Expected non-empty <data>
- it: should fail with empty type key
set:
secret:
my-secret:
enabled: true
type: ""
data:
foo: bar
asserts:
- failedTemplate:
errorMessage: Secret - Found <type> key, but it's empty
@@ -0,0 +1,126 @@
suite: service clusterIP test
templates:
- common.yaml
tests:
- it: should pass with type ClusterIP
set:
service:
my-service:
enabled: true
primary: true
type: ClusterIP
ports:
port-name:
enabled: true
primary: true
port: 12345
workload:
my-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &serviceDoc 1
isKind:
of: Service
- documentIndex: *serviceDoc
isAPIVersion:
of: v1
- documentIndex: *serviceDoc
equal:
path: metadata.name
value: release-name-common-test
- documentIndex: *serviceDoc
equal:
path: spec
value:
type: ClusterIP
publishNotReadyAddresses: false
ports:
- name: port-name
port: 12345
protocol: TCP
targetPort: 12345
selector:
app.kubernetes.io/instance: RELEASE-NAME
app.kubernetes.io/name: common-test
pod.name: my-workload
- it: should pass with type ClusterIP and available options set
set:
some_policy: PreferDualStack
some_family: IPv6
some_ip: 172.16.20.35
some_other_ip: 10.200.34.53
some_affinity: ClientIP
some_timeout: 100
some_port: 12344
some_target_port: 12346
some_protocol: http
service:
my-service:
enabled: true
primary: true
type: ClusterIP
clusterIP: "{{ .Values.some_ip }}"
publishNotReadyAddresses: true
ipFamilyPolicy: "{{ .Values.some_policy }}"
ipFamilies:
- IPv4
- "{{ .Values.some_family }}"
externalIPs:
- "{{ .Values.some_other_ip }}"
- 10.200.34.54
sessionAffinity: "{{ .Values.some_affinity }}"
sessionAffinityConfig:
clientIP:
timeoutSeconds: "{{ .Values.some_timeout }}"
ports:
port-name:
enabled: true
primary: true
port: 12345
port-name2:
enabled: true
port: "{{ .Values.some_port }}"
targetPort: "{{ .Values.some_target_port }}"
protocol: "{{ .Values.some_protocol }}"
workload:
my-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: *serviceDoc
equal:
path: spec
value:
type: ClusterIP
clusterIP: 172.16.20.35
ipFamilyPolicy: PreferDualStack
publishNotReadyAddresses: true
ipFamilies:
- IPv4
- IPv6
externalIPs:
- 10.200.34.53
- 10.200.34.54
sessionAffinity: ClientIP
sessionAffinityConfig:
clientIP:
timeoutSeconds: 100
ports:
- name: port-name
port: 12345
protocol: TCP
targetPort: 12345
- name: port-name2
port: 12344
protocol: TCP
targetPort: 12346
selector:
app.kubernetes.io/instance: RELEASE-NAME
app.kubernetes.io/name: common-test
pod.name: my-workload
@@ -0,0 +1,158 @@
suite: service metadata test
templates:
- common.yaml
chart:
appVersion: &appVer v9.9.9
tests:
- it: should pass with service created with labels and annotations
set:
label1: label1
label2: global_label2
annotation1: annotation1
annotation2: global_annotation2
global:
labels:
g_label1: global_label1
g_label2: "{{ .Values.label2 }}"
annotations:
g_annotation1: global_annotation1
g_annotation2: "{{ .Values.annotation2 }}"
service:
my-service1:
enabled: true
primary: true
labels:
label1: "{{ .Values.label1 }}"
label2: label2
annotations:
annotation1: "{{ .Values.annotation1 }}"
annotation2: annotation2
ports:
port-name:
enabled: true
primary: true
port: 12345
my-service2:
enabled: true
primary: false
ports:
port-name:
enabled: true
primary: true
port: 1234
workload:
my-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &serviceDoc 1
isKind:
of: Service
- documentIndex: *serviceDoc
equal:
path: metadata.annotations
value:
annotation1: annotation1
annotation2: annotation2
g_annotation1: global_annotation1
g_annotation2: global_annotation2
- documentIndex: *serviceDoc
equal:
path: metadata.labels
value:
app: common-test-1.0.0
release: RELEASE-NAME
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/version: *appVer
app.kubernetes.io/instance: RELEASE-NAME
app.kubernetes.io/name: common-test
service.name: release-name-common-test
g_label1: global_label1
g_label2: global_label2
label1: label1
label2: label2
- documentIndex: &otherServiceDoc 2
isKind:
of: Service
- documentIndex: *otherServiceDoc
equal:
path: metadata.labels
value:
service.name: release-name-common-test-my-service2
app: common-test-1.0.0
app.kubernetes.io/instance: RELEASE-NAME
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: common-test
app.kubernetes.io/version: *appVer
g_label1: global_label1
g_label2: global_label2
helm-revision: "0"
helm.sh/chart: common-test-1.0.0
release: RELEASE-NAME
- it: should pass with correct selector with targetSelector
set:
service:
my-service1:
enabled: true
primary: true
targetSelector: my-workload
ports:
port-name:
enabled: true
primary: true
port: 12345
workload:
my-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: *serviceDoc
isKind:
of: Service
- documentIndex: *serviceDoc
equal:
path: spec.selector
value:
pod.name: my-workload
app.kubernetes.io/name: common-test
app.kubernetes.io/instance: RELEASE-NAME
- it: should pass with correct selector without targetSelector
set:
service:
my-service1:
enabled: true
primary: true
ports:
port-name:
enabled: true
primary: true
port: 12345
workload:
my-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
my-workload2:
enabled: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &serviceDoc 2
isKind:
of: Service
- documentIndex: *serviceDoc
equal:
path: spec.selector
value:
pod.name: my-workload
app.kubernetes.io/name: common-test
app.kubernetes.io/instance: RELEASE-NAME
@@ -0,0 +1,49 @@
suite: service name test
templates:
- common.yaml
tests:
- it: should generate correct name
set:
service:
my-service1:
enabled: true
primary: true
ports:
port-name:
enabled: true
primary: true
port: 12344
my-service2:
enabled: true
ports:
port-name:
enabled: true
primary: true
port: 12345
workload:
my-workload:
enabled: true
primary: true
type: Deployment
podSpec: {}
asserts:
- documentIndex: &serviceDoc 1
isKind:
of: Service
- documentIndex: *serviceDoc
isAPIVersion:
of: v1
- documentIndex: *serviceDoc
equal:
path: metadata.name
value: release-name-common-test
- documentIndex: &otherServiceDoc 2
isKind:
of: Service
- documentIndex: *otherServiceDoc
isAPIVersion:
of: v1
- documentIndex: *otherServiceDoc
equal:
path: metadata.name
value: release-name-common-test-my-service2

Some files were not shown because too many files have changed in this diff Show More