check / check (push) Failing after 3s
The Dockerfile's last stage is now the image of "Deployment" in SPEC.md: Ubuntu 26.04 with ca-certificates, nix-bin and runit from a dated snapshot whose InRelease files are checked by hash, nixpkgs from its release file checked by SHA-256, runsvinit built at a fixed commit, and smallwebwaf as a runit service. smallwebwaf answers /_smallwebwaf/healthz, and `smallwebwaf healthcheck` is the image's HEALTHCHECK. script/example-app builds an app on the image and checks it end to end. The Nix profile comes last on the PATH: first, busybox from nixpkgs replaced runit's own runsvdir and sv. SPEC.md is corrected to match what was built. Model: opus-5-5
48 lines
1.1 KiB
Go
48 lines
1.1 KiB
Go
package proxy_test
|
|
|
|
import (
|
|
"net/http"
|
|
"sync/atomic"
|
|
"testing"
|
|
|
|
"sneak.berlin/go/smallwebwaf/internal/proxy"
|
|
"sneak.berlin/go/smallwebwaf/internal/requestlog"
|
|
)
|
|
|
|
func TestHealthEndpointIsAnsweredBeforeAnyCheck(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
var calls atomic.Int32
|
|
|
|
app := startApp(t, func(http.ResponseWriter, *http.Request) {
|
|
calls.Add(1)
|
|
})
|
|
// With a limit of one request a minute, any request counted before
|
|
// the last one would have it refused.
|
|
addr, out := startProxy(t, app.URL, map[string]string{rateLimitPerMinute: "1"})
|
|
|
|
const healthChecks = 3
|
|
|
|
for range healthChecks {
|
|
got := get(t, addr, proxy.HealthPath)
|
|
wantStatus(t, got, http.StatusOK)
|
|
|
|
if string(got.body) != "ok\n" {
|
|
t.Errorf("health endpoint answered %q, want ok", got.body)
|
|
}
|
|
}
|
|
|
|
wantStatus(t, get(t, addr, "/"), http.StatusOK)
|
|
|
|
lines := out.requestLines(t, healthChecks+1)
|
|
for _, line := range lines[:healthChecks] {
|
|
wantLine(t, line, http.StatusOK, requestlog.ActionAdmin)
|
|
}
|
|
|
|
wantLine(t, lines[healthChecks], http.StatusOK, requestlog.ActionForward)
|
|
|
|
if calls.Load() != 1 {
|
|
t.Errorf("the app was called %d times, want once", calls.Load())
|
|
}
|
|
}
|