Merge branch 'main' into fix/add-typescript-devdep
This commit is contained in:
@@ -32,9 +32,6 @@ jobs:
|
|||||||
- name: Setup kubectl
|
- name: Setup kubectl
|
||||||
uses: azure/setup-kubectl@v4
|
uses: azure/setup-kubectl@v4
|
||||||
|
|
||||||
- name: Setup Helm
|
|
||||||
uses: azure/setup-helm@v4
|
|
||||||
|
|
||||||
- name: Install dependencies
|
- name: Install dependencies
|
||||||
run: npm ci
|
run: npm ci
|
||||||
|
|
||||||
@@ -61,8 +58,6 @@ jobs:
|
|||||||
env:
|
env:
|
||||||
HEADLAMP_URL: ${{ env.HEADLAMP_URL }}
|
HEADLAMP_URL: ${{ env.HEADLAMP_URL }}
|
||||||
HEADLAMP_TOKEN: ${{ env.HEADLAMP_TOKEN }}
|
HEADLAMP_TOKEN: ${{ env.HEADLAMP_TOKEN }}
|
||||||
AUTHENTIK_USERNAME: ${{ secrets.AUTHENTIK_USERNAME }}
|
|
||||||
AUTHENTIK_PASSWORD: ${{ secrets.AUTHENTIK_PASSWORD }}
|
|
||||||
|
|
||||||
- name: Teardown E2E instance
|
- name: Teardown E2E instance
|
||||||
if: always()
|
if: always()
|
||||||
|
|||||||
@@ -1,34 +0,0 @@
|
|||||||
---
|
|
||||||
# Headlamp Helm values for E2E testing.
|
|
||||||
#
|
|
||||||
# Uses the stock Headlamp image with the plugin loaded via a ConfigMap
|
|
||||||
# volume mount. No custom Docker images — the plugin dist/ is packaged
|
|
||||||
# as a ConfigMap by deploy-e2e-headlamp.sh.
|
|
||||||
#
|
|
||||||
# Usage:
|
|
||||||
# helm install headlamp-e2e headlamp/headlamp \
|
|
||||||
# -n privilegedescalation-dev \
|
|
||||||
# -f deployment/headlamp-e2e-values.yaml \
|
|
||||||
# --set image.registry=ghcr.io \
|
|
||||||
# --set image.repository=headlamp-k8s/headlamp \
|
|
||||||
# --set image.tag=latest
|
|
||||||
|
|
||||||
config:
|
|
||||||
pluginsDir: /headlamp/plugins
|
|
||||||
watchPlugins: false
|
|
||||||
|
|
||||||
clusterRoleBinding:
|
|
||||||
create: false
|
|
||||||
|
|
||||||
service:
|
|
||||||
type: ClusterIP
|
|
||||||
|
|
||||||
extraVolumes:
|
|
||||||
- name: polaris-plugin
|
|
||||||
configMap:
|
|
||||||
name: headlamp-polaris-plugin
|
|
||||||
|
|
||||||
extraVolumeMounts:
|
|
||||||
- name: polaris-plugin
|
|
||||||
mountPath: /headlamp/plugins/headlamp-polaris
|
|
||||||
readOnly: true
|
|
||||||
+8
-5
@@ -39,13 +39,16 @@ async function authenticateWithOIDC(page: Page, username: string, password: stri
|
|||||||
}
|
}
|
||||||
|
|
||||||
async function authenticateWithToken(page: Page, token: string): Promise<void> {
|
async function authenticateWithToken(page: Page, token: string): Promise<void> {
|
||||||
// Navigate to login — Headlamp redirects / to /c/main/login
|
|
||||||
await page.goto('/');
|
await page.goto('/');
|
||||||
await page.waitForURL('**/login');
|
// Headlamp goes to /token directly when no OIDC is configured,
|
||||||
|
// or through /login when OIDC is configured
|
||||||
|
await page.waitForURL(/\/(login|token)$/);
|
||||||
|
|
||||||
// Click the token auth option
|
if (page.url().includes('/login')) {
|
||||||
await page.getByRole('button', { name: /use a token/i }).click();
|
// OIDC login page — click "use a token" to reach token auth
|
||||||
await page.waitForURL('**/token');
|
await page.getByRole('button', { name: /use a token/i }).click();
|
||||||
|
await page.waitForURL('**/token');
|
||||||
|
}
|
||||||
|
|
||||||
// Fill the "ID token" field and submit
|
// Fill the "ID token" field and submit
|
||||||
await page.getByRole('textbox', { name: /id token/i }).fill(token);
|
await page.getByRole('textbox', { name: /id token/i }).fill(token);
|
||||||
|
|||||||
@@ -11,12 +11,11 @@
|
|||||||
# Prerequisites:
|
# Prerequisites:
|
||||||
# - Plugin built (dist/ exists with plugin-main.js + package.json)
|
# - Plugin built (dist/ exists with plugin-main.js + package.json)
|
||||||
# - kubectl configured with cluster access
|
# - kubectl configured with cluster access
|
||||||
# - Helm 3 installed
|
|
||||||
# - RBAC applied: kubectl apply -f deployment/e2e-ci-runner-rbac.yaml
|
# - RBAC applied: kubectl apply -f deployment/e2e-ci-runner-rbac.yaml
|
||||||
#
|
#
|
||||||
# Environment:
|
# Environment:
|
||||||
# E2E_NAMESPACE — namespace for E2E Headlamp (default: privilegedescalation-dev)
|
# E2E_NAMESPACE — namespace for E2E Headlamp (default: privilegedescalation-dev)
|
||||||
# E2E_RELEASE — Helm release name (default: headlamp-e2e)
|
# E2E_RELEASE — release/resource name prefix (default: headlamp-e2e)
|
||||||
# HEADLAMP_VERSION — Headlamp image tag (default: latest)
|
# HEADLAMP_VERSION — Headlamp image tag (default: latest)
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
@@ -59,28 +58,105 @@ kubectl create configmap headlamp-polaris-plugin \
|
|||||||
--from-file="$DIST_DIR" \
|
--from-file="$DIST_DIR" \
|
||||||
--from-file=package.json="$REPO_ROOT/package.json"
|
--from-file=package.json="$REPO_ROOT/package.json"
|
||||||
|
|
||||||
# --- Deploy with Helm ---
|
# --- Deploy Headlamp via kubectl apply ---
|
||||||
echo ""
|
echo ""
|
||||||
echo "Adding Headlamp Helm repo..."
|
echo "Deploying Headlamp E2E instance..."
|
||||||
helm repo add headlamp https://kubernetes-sigs.github.io/headlamp/ --force-update
|
|
||||||
helm repo update
|
|
||||||
|
|
||||||
echo "Installing/upgrading Headlamp E2E instance..."
|
kubectl apply -f - <<EOF
|
||||||
helm upgrade --install "$E2E_RELEASE" headlamp/headlamp \
|
apiVersion: v1
|
||||||
-n "$E2E_NAMESPACE" \
|
kind: ServiceAccount
|
||||||
-f "$REPO_ROOT/deployment/headlamp-e2e-values.yaml" \
|
metadata:
|
||||||
--set "image.registry=ghcr.io" \
|
name: ${E2E_RELEASE}
|
||||||
--set "image.repository=headlamp-k8s/headlamp" \
|
namespace: ${E2E_NAMESPACE}
|
||||||
--set "image.tag=${HEADLAMP_VERSION}" \
|
---
|
||||||
--wait \
|
apiVersion: apps/v1
|
||||||
--timeout 120s
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: ${E2E_RELEASE}
|
||||||
|
namespace: ${E2E_NAMESPACE}
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: headlamp
|
||||||
|
app.kubernetes.io/instance: ${E2E_RELEASE}
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: headlamp
|
||||||
|
app.kubernetes.io/instance: ${E2E_RELEASE}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: headlamp
|
||||||
|
app.kubernetes.io/instance: ${E2E_RELEASE}
|
||||||
|
spec:
|
||||||
|
serviceAccountName: ${E2E_RELEASE}
|
||||||
|
automountServiceAccountToken: true
|
||||||
|
securityContext: {}
|
||||||
|
containers:
|
||||||
|
- name: headlamp
|
||||||
|
image: ghcr.io/headlamp-k8s/headlamp:${HEADLAMP_VERSION}
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
securityContext:
|
||||||
|
runAsNonRoot: true
|
||||||
|
privileged: false
|
||||||
|
runAsUser: 100
|
||||||
|
runAsGroup: 101
|
||||||
|
args:
|
||||||
|
- "-in-cluster"
|
||||||
|
- "-in-cluster-context-name=main"
|
||||||
|
- "-plugins-dir=/headlamp/plugins"
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: 4466
|
||||||
|
protocol: TCP
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 5
|
||||||
|
failureThreshold: 6
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
initialDelaySeconds: 10
|
||||||
|
periodSeconds: 10
|
||||||
|
volumeMounts:
|
||||||
|
- name: polaris-plugin
|
||||||
|
mountPath: /headlamp/plugins/headlamp-polaris
|
||||||
|
readOnly: true
|
||||||
|
volumes:
|
||||||
|
- name: polaris-plugin
|
||||||
|
configMap:
|
||||||
|
name: headlamp-polaris-plugin
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: ${E2E_RELEASE}
|
||||||
|
namespace: ${E2E_NAMESPACE}
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: headlamp
|
||||||
|
app.kubernetes.io/instance: ${E2E_RELEASE}
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/name: headlamp
|
||||||
|
app.kubernetes.io/instance: ${E2E_RELEASE}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
port: 80
|
||||||
|
targetPort: http
|
||||||
|
protocol: TCP
|
||||||
|
EOF
|
||||||
|
|
||||||
echo "Waiting for rollout..."
|
echo "Waiting for rollout..."
|
||||||
kubectl rollout status "deployment/${E2E_RELEASE}-headlamp" \
|
kubectl rollout status "deployment/${E2E_RELEASE}" \
|
||||||
-n "$E2E_NAMESPACE" --timeout=120s
|
-n "$E2E_NAMESPACE" --timeout=120s
|
||||||
|
|
||||||
# --- Generate a service URL for tests ---
|
# --- Generate a service URL for tests ---
|
||||||
SVC_URL="http://${E2E_RELEASE}-headlamp.${E2E_NAMESPACE}.svc.cluster.local"
|
SVC_URL="http://${E2E_RELEASE}.${E2E_NAMESPACE}.svc.cluster.local"
|
||||||
echo ""
|
echo ""
|
||||||
echo "E2E Headlamp is ready at: ${SVC_URL}"
|
echo "E2E Headlamp is ready at: ${SVC_URL}"
|
||||||
echo " export HEADLAMP_URL=${SVC_URL}"
|
echo " export HEADLAMP_URL=${SVC_URL}"
|
||||||
|
|||||||
@@ -5,7 +5,7 @@
|
|||||||
#
|
#
|
||||||
# Environment:
|
# Environment:
|
||||||
# E2E_NAMESPACE — namespace to clean up (default: privilegedescalation-dev)
|
# E2E_NAMESPACE — namespace to clean up (default: privilegedescalation-dev)
|
||||||
# E2E_RELEASE — Helm release to uninstall (default: headlamp-e2e)
|
# E2E_RELEASE — release/resource name prefix (default: headlamp-e2e)
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
REPO_ROOT="$(cd "$(dirname "$0")/.." && pwd)"
|
REPO_ROOT="$(cd "$(dirname "$0")/.." && pwd)"
|
||||||
@@ -17,13 +17,15 @@ echo "=== E2E Headlamp Teardown ==="
|
|||||||
echo " Namespace: $E2E_NAMESPACE"
|
echo " Namespace: $E2E_NAMESPACE"
|
||||||
echo " Release: $E2E_RELEASE"
|
echo " Release: $E2E_RELEASE"
|
||||||
|
|
||||||
echo "Uninstalling Helm release..."
|
echo "Removing Headlamp Deployment, Service, and ServiceAccount..."
|
||||||
helm uninstall "$E2E_RELEASE" -n "$E2E_NAMESPACE" 2>/dev/null || echo "Release not found (already removed?)"
|
kubectl delete deployment "${E2E_RELEASE}" -n "$E2E_NAMESPACE" --ignore-not-found
|
||||||
|
kubectl delete service "${E2E_RELEASE}" -n "$E2E_NAMESPACE" --ignore-not-found
|
||||||
|
kubectl delete serviceaccount "${E2E_RELEASE}" -n "$E2E_NAMESPACE" --ignore-not-found
|
||||||
|
|
||||||
echo "Cleaning up ConfigMap..."
|
echo "Cleaning up ConfigMap..."
|
||||||
kubectl delete configmap headlamp-polaris-plugin -n "$E2E_NAMESPACE" --ignore-not-found
|
kubectl delete configmap headlamp-polaris-plugin -n "$E2E_NAMESPACE" --ignore-not-found
|
||||||
|
|
||||||
echo "Cleaning up service account..."
|
echo "Cleaning up test service account..."
|
||||||
kubectl delete serviceaccount headlamp-e2e-test -n "$E2E_NAMESPACE" --ignore-not-found
|
kubectl delete serviceaccount headlamp-e2e-test -n "$E2E_NAMESPACE" --ignore-not-found
|
||||||
|
|
||||||
# Clean up local env file
|
# Clean up local env file
|
||||||
|
|||||||
Reference in New Issue
Block a user