Compare commits
6
Commits
3cb0ba7687
..
next
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7cf7059d3a | ||
|
|
2a2c52074d | ||
|
|
d3b9c6fca9 | ||
|
|
23f378cfde | ||
|
|
db3b47e423 | ||
|
|
b101bc1a80 |
+30
-6
@@ -1,11 +1,35 @@
|
|||||||
# .git is sent so that `make build` in the Dockerfile can stamp the commit into
|
# .git is sent so that `make build` in the Dockerfile can stamp the commit into
|
||||||
# upaas. List no tracked file here: git would see it as deleted in the build and
|
# upaas. List no tracked file here: git would see it as deleted in the build and
|
||||||
# the version would end in -dirty.
|
# the version would end in -dirty.
|
||||||
|
|
||||||
|
# The patterns of .gitignore; **/ makes Docker match them in every directory.
|
||||||
|
**/.DS_Store
|
||||||
|
**/Thumbs.db
|
||||||
|
**/*.swp
|
||||||
|
**/*.swo
|
||||||
|
**/*~
|
||||||
|
**/*.bak
|
||||||
|
**/.idea/
|
||||||
|
**/.vscode/
|
||||||
|
**/*.sublime-*
|
||||||
|
**/node_modules/
|
||||||
|
**/.env
|
||||||
|
**/.env.*
|
||||||
|
**/*.pem
|
||||||
|
**/*.key
|
||||||
|
**/bin/
|
||||||
|
**/*.exe
|
||||||
|
**/*.exe~
|
||||||
|
**/*.dll
|
||||||
|
**/*.so
|
||||||
|
**/*.dylib
|
||||||
|
**/*.test
|
||||||
|
**/*.out
|
||||||
|
/data/
|
||||||
|
|
||||||
|
# Git never applies its ignore patterns inside .git; send all of it again.
|
||||||
|
!.git/**
|
||||||
|
|
||||||
# .git is sent without its config, because a remote URL there can carry a
|
# .git is sent without its config, because a remote URL there can carry a
|
||||||
# credential; `git describe` does not need it.
|
# credential; `git describe` does not need it. Keep this after !.git/**.
|
||||||
.git/config
|
.git/config
|
||||||
.env
|
|
||||||
bin/
|
|
||||||
.vscode/
|
|
||||||
.idea/
|
|
||||||
*.test
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# .dockerignore repeats these patterns; change both together.
|
||||||
|
|
||||||
# OS
|
# OS
|
||||||
.DS_Store
|
.DS_Store
|
||||||
Thumbs.db
|
Thumbs.db
|
||||||
@@ -29,3 +31,6 @@ bin/
|
|||||||
*.dylib
|
*.dylib
|
||||||
*.test
|
*.test
|
||||||
*.out
|
*.out
|
||||||
|
|
||||||
|
# upaasd's data directory when it runs from the checkout (UPAAS_DATA_DIR default)
|
||||||
|
/data/
|
||||||
|
|||||||
@@ -268,6 +268,12 @@ upaas fails the deploy instead of building. A Dockerfile that uses
|
|||||||
`RUN --network` needs Docker Engine 23.0 or later unless its `# syntax=` line
|
`RUN --network` needs Docker Engine 23.0 or later unless its `# syntax=` line
|
||||||
names Dockerfile frontend 1.3 or later, such as `docker/dockerfile:1`.
|
names Dockerfile frontend 1.3 or later, such as `docker/dockerfile:1`.
|
||||||
|
|
||||||
|
The build context leaves out the files the app's ignore file names, as
|
||||||
|
`docker build` does: `<Dockerfile>.dockerignore` next to the app's Dockerfile if
|
||||||
|
there is one, otherwise `.dockerignore` at the root of the repository. The
|
||||||
|
Dockerfile and `.dockerignore` are always sent, even when the ignore file names
|
||||||
|
them.
|
||||||
|
|
||||||
Session secrets are automatically generated on first startup and persisted to
|
Session secrets are automatically generated on first startup and persisted to
|
||||||
`$UPAAS_DATA_DIR/session.key`.
|
`$UPAAS_DATA_DIR/session.key`.
|
||||||
|
|
||||||
|
|||||||
@@ -20,6 +20,23 @@ regress.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-10-03: An app's build context leaves out the files its `.dockerignore`
|
||||||
|
names, such as `.git/config`, as `docker build` does; before, every file in
|
||||||
|
the clone was sent. An ignore file next to the Dockerfile,
|
||||||
|
`<Dockerfile>.dockerignore`, is read instead when there is one. The Dockerfile
|
||||||
|
and `.dockerignore` are always sent. An ignore file that cannot be read, or
|
||||||
|
holds a pattern Docker rejects, fails the build (#274).
|
||||||
|
|
||||||
|
- 2026-10-03: `make test`, and so `docker build .`, fits a machine with 4 GiB of
|
||||||
|
memory: tests hash passwords with 1 MiB instead of upaasd's 64 MiB, so
|
||||||
|
`GOMAXPROCS=4 make test` peaks at about 1.4 GiB instead of 2.7 GiB. upaasd
|
||||||
|
still hashes with 64 MiB, and one test hashes and verifies a password at that
|
||||||
|
cost (#261).
|
||||||
|
|
||||||
|
- 2026-10-02: In a window too narrow for the top bar, such as 390 px, the New
|
||||||
|
App and Logout buttons move to a second row instead of running into "by
|
||||||
|
@sneak"; the bar keeps a gap between its two sides at every width (#272).
|
||||||
|
|
||||||
- 2026-10-02: App names may contain dots, such as `sneak.berlin`: lowercase
|
- 2026-10-02: App names may contain dots, such as `sneak.berlin`: lowercase
|
||||||
letters and numbers joined by single dots or by hyphens, 2 to 63 characters.
|
letters and numbers joined by single dots or by hyphens, 2 to 63 characters.
|
||||||
Docker accepts every such name in the image name `upaas-<name>`; a dot needs a
|
Docker accepts every such name in the image name `upaas-<name>`; a dot needs a
|
||||||
@@ -27,6 +44,16 @@ regress.
|
|||||||
app forms check the same rule; browsers ignored their old pattern, which was
|
app forms check the same rule; browsers ignored their old pattern, which was
|
||||||
not a valid regular expression there (#260).
|
not a valid regular expression there (#260).
|
||||||
|
|
||||||
|
- 2026-10-02: On the Applications list, a long repository URL now wraps within
|
||||||
|
its column instead of making the table wider than its card, which cut off the
|
||||||
|
Actions column and the Deploy buttons. In a window too narrow for the table,
|
||||||
|
the card scrolls sideways instead of cutting the table off (#262).
|
||||||
|
|
||||||
|
- 2026-10-02: `docker build .` no longer sends git-ignored files, such as
|
||||||
|
`.env.local`, `*.key` files or upaasd's `data/` directory with its session
|
||||||
|
key, into the build stages and the build cache: `.dockerignore` now leaves out
|
||||||
|
everything `.gitignore` does, and `data/` is git-ignored (#266).
|
||||||
|
|
||||||
- 2026-10-02: `.dockerignore` leaves out `.git/config`, so a remote URL there
|
- 2026-10-02: `.dockerignore` leaves out `.git/config`, so a remote URL there
|
||||||
that carries a credential no longer goes into the Docker build; the image
|
that carries a credential no longer goes into the Docker build; the image
|
||||||
still shows the commit it was built from (#269).
|
still shows the commit it was built from (#269).
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ require (
|
|||||||
github.com/joho/godotenv v1.5.1
|
github.com/joho/godotenv v1.5.1
|
||||||
github.com/mattn/go-sqlite3 v1.14.32
|
github.com/mattn/go-sqlite3 v1.14.32
|
||||||
github.com/moby/buildkit v0.16.0
|
github.com/moby/buildkit v0.16.0
|
||||||
|
github.com/moby/patternmatcher v0.6.0
|
||||||
github.com/oklog/ulid/v2 v2.1.1
|
github.com/oklog/ulid/v2 v2.1.1
|
||||||
github.com/prometheus/client_golang v1.23.2
|
github.com/prometheus/client_golang v1.23.2
|
||||||
github.com/spf13/viper v1.21.0
|
github.com/spf13/viper v1.21.0
|
||||||
@@ -60,7 +61,6 @@ require (
|
|||||||
github.com/klauspost/compress v1.18.2 // indirect
|
github.com/klauspost/compress v1.18.2 // indirect
|
||||||
github.com/moby/docker-image-spec v1.3.1 // indirect
|
github.com/moby/docker-image-spec v1.3.1 // indirect
|
||||||
github.com/moby/locker v1.0.1 // indirect
|
github.com/moby/locker v1.0.1 // indirect
|
||||||
github.com/moby/patternmatcher v0.6.0 // indirect
|
|
||||||
github.com/moby/sys/sequential v0.6.0 // indirect
|
github.com/moby/sys/sequential v0.6.0 // indirect
|
||||||
github.com/moby/sys/signal v0.7.1 // indirect
|
github.com/moby/sys/signal v0.7.1 // indirect
|
||||||
github.com/moby/sys/user v0.4.0 // indirect
|
github.com/moby/sys/user v0.4.0 // indirect
|
||||||
|
|||||||
@@ -0,0 +1,114 @@
|
|||||||
|
package docker
|
||||||
|
|
||||||
|
import (
|
||||||
|
"errors"
|
||||||
|
"fmt"
|
||||||
|
"io"
|
||||||
|
"io/fs"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
|
||||||
|
"github.com/docker/docker/pkg/archive"
|
||||||
|
"github.com/moby/patternmatcher"
|
||||||
|
"github.com/moby/patternmatcher/ignorefile"
|
||||||
|
)
|
||||||
|
|
||||||
|
// defaultDockerfileName is the Dockerfile Docker builds when none is named.
|
||||||
|
const defaultDockerfileName = "Dockerfile"
|
||||||
|
|
||||||
|
// defaultDockerignoreName is the ignore file at the root of a build context,
|
||||||
|
// read when the Dockerfile has no ignore file of its own.
|
||||||
|
const defaultDockerignoreName = ".dockerignore"
|
||||||
|
|
||||||
|
// tarBuildContext returns a tar of the build context in contextDir that leaves
|
||||||
|
// out the files the app's ignore file names, as docker build does; Docker does
|
||||||
|
// not apply the ignore file to a build context sent as a tar. dockerfile is
|
||||||
|
// the path of the Dockerfile inside contextDir.
|
||||||
|
func tarBuildContext(contextDir, dockerfile string) (io.ReadCloser, error) {
|
||||||
|
excludes, err := readDockerignore(contextDir, dockerfile)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
return archive.TarWithOptions(contextDir, &archive.TarOptions{
|
||||||
|
ExcludePatterns: excludes,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
// readDockerignore returns the patterns of the files to leave out of the
|
||||||
|
// build context in contextDir, read as docker build reads them for the
|
||||||
|
// Dockerfile at dockerfile: from <dockerfile>.dockerignore next to the
|
||||||
|
// Dockerfile if there is one, otherwise from .dockerignore at the root of the
|
||||||
|
// context. Without either file there are no patterns.
|
||||||
|
func readDockerignore(contextDir, dockerfile string) ([]string, error) {
|
||||||
|
// Docker reads the Dockerfile path as a path inside the build context:
|
||||||
|
// cleaned, with a leading / and any .. that would lead out of the context
|
||||||
|
// dropped, so ./Dockerfile and /Dockerfile both name the Dockerfile at the
|
||||||
|
// root.
|
||||||
|
dockerfile = strings.TrimPrefix(filepath.Join("/", dockerfile), "/")
|
||||||
|
if dockerfile == "" {
|
||||||
|
dockerfile = defaultDockerfileName
|
||||||
|
}
|
||||||
|
|
||||||
|
// Reading through os.Root keeps the read inside the build context, even
|
||||||
|
// when the ignore file is a symlink.
|
||||||
|
root, err := os.OpenRoot(contextDir)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
defer func() { _ = root.Close() }()
|
||||||
|
|
||||||
|
// When a Dockerfile named Dockerfile is missing, Docker builds a
|
||||||
|
// lowercase dockerfile in the same directory instead, and docker build
|
||||||
|
// then reads dockerfile.dockerignore as its ignore file.
|
||||||
|
if filepath.Base(dockerfile) == defaultDockerfileName {
|
||||||
|
lowercase := filepath.Join(filepath.Dir(dockerfile), "dockerfile")
|
||||||
|
|
||||||
|
_, dockerfileErr := root.Lstat(dockerfile)
|
||||||
|
_, lowercaseErr := root.Lstat(lowercase)
|
||||||
|
|
||||||
|
if errors.Is(dockerfileErr, fs.ErrNotExist) && lowercaseErr == nil {
|
||||||
|
dockerfile = lowercase
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
name := dockerfile + defaultDockerignoreName
|
||||||
|
|
||||||
|
file, err := root.Open(name)
|
||||||
|
if errors.Is(err, fs.ErrNotExist) {
|
||||||
|
name = defaultDockerignoreName
|
||||||
|
file, err = root.Open(name)
|
||||||
|
}
|
||||||
|
|
||||||
|
if errors.Is(err, fs.ErrNotExist) {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("failed to read %s: %w", name, err)
|
||||||
|
}
|
||||||
|
|
||||||
|
defer func() { _ = file.Close() }()
|
||||||
|
|
||||||
|
excludes, err := ignorefile.ReadAll(file)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("failed to read %s: %w", name, err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Like the docker command line, never leave out .dockerignore or the
|
||||||
|
// Dockerfile: Docker reads the Dockerfile from the context.
|
||||||
|
for _, keep := range []string{defaultDockerignoreName, filepath.ToSlash(dockerfile)} {
|
||||||
|
excluded, err := patternmatcher.MatchesOrParentMatches(keep, excludes)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("invalid pattern in %s: %w", name, err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if excluded {
|
||||||
|
excludes = append(excludes, "!"+keep)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return excludes, nil
|
||||||
|
}
|
||||||
@@ -0,0 +1,326 @@
|
|||||||
|
package docker //nolint:testpackage // tests the unexported performBuild
|
||||||
|
|
||||||
|
import (
|
||||||
|
"archive/tar"
|
||||||
|
"errors"
|
||||||
|
"io"
|
||||||
|
"log/slog"
|
||||||
|
"net/http"
|
||||||
|
"net/http/httptest"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"slices"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"github.com/docker/docker/client"
|
||||||
|
)
|
||||||
|
|
||||||
|
// File names used in more than one test build context, as constants to
|
||||||
|
// satisfy the goconst linter.
|
||||||
|
const (
|
||||||
|
testMainGo = "main.go"
|
||||||
|
testSecretFile = "secret.txt"
|
||||||
|
testDeployDockerfile = "deploy/Dockerfile"
|
||||||
|
testLowercaseDockerfile = "dockerfile"
|
||||||
|
)
|
||||||
|
|
||||||
|
// TestPerformBuildFollowsDockerignore runs builds against a fake Docker API
|
||||||
|
// and checks which files the build context sent to it holds.
|
||||||
|
func TestPerformBuildFollowsDockerignore(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
dockerfile string
|
||||||
|
files map[string]string // path in the context: contents
|
||||||
|
want []string // files sent in the build context
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
name: "no ignore file",
|
||||||
|
dockerfile: defaultDockerfileName,
|
||||||
|
files: map[string]string{defaultDockerfileName: "", testMainGo: ""},
|
||||||
|
want: []string{defaultDockerfileName, testMainGo},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "excludes and re-includes",
|
||||||
|
dockerfile: defaultDockerfileName,
|
||||||
|
files: map[string]string{
|
||||||
|
defaultDockerignoreName: "secret.txt\n*.md\n!README.md\n",
|
||||||
|
defaultDockerfileName: "",
|
||||||
|
"NOTES.md": "",
|
||||||
|
"README.md": "",
|
||||||
|
testMainGo: "",
|
||||||
|
testSecretFile: "",
|
||||||
|
},
|
||||||
|
want: []string{
|
||||||
|
defaultDockerignoreName, defaultDockerfileName, "README.md", testMainGo,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "keeps the Dockerfile and .dockerignore",
|
||||||
|
dockerfile: defaultDockerfileName,
|
||||||
|
files: map[string]string{
|
||||||
|
defaultDockerignoreName: "Dockerfile\n.dockerignore\nsecret.txt\n",
|
||||||
|
defaultDockerfileName: "",
|
||||||
|
testMainGo: "",
|
||||||
|
testSecretFile: "",
|
||||||
|
},
|
||||||
|
want: []string{defaultDockerignoreName, defaultDockerfileName, testMainGo},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "an ignore file next to the Dockerfile wins over .dockerignore",
|
||||||
|
dockerfile: testDeployDockerfile,
|
||||||
|
files: map[string]string{
|
||||||
|
defaultDockerignoreName: "main.go\n",
|
||||||
|
testDeployDockerfile: "",
|
||||||
|
"deploy/Dockerfile.dockerignore": "secret.txt\n",
|
||||||
|
testMainGo: "",
|
||||||
|
testSecretFile: "",
|
||||||
|
},
|
||||||
|
want: []string{
|
||||||
|
defaultDockerignoreName,
|
||||||
|
testDeployDockerfile,
|
||||||
|
"deploy/Dockerfile.dockerignore",
|
||||||
|
testMainGo,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
contextDir := t.TempDir()
|
||||||
|
writeFiles(t, contextDir, tt.files)
|
||||||
|
|
||||||
|
got, err := buildContextFiles(t, contextDir, tt.dockerfile)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if !slices.Equal(got, tt.want) {
|
||||||
|
t.Errorf("build context holds %q, want %q", got, tt.want)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestPerformBuildKeepsLowercaseDockerfile checks that when the Dockerfile
|
||||||
|
// named Dockerfile is missing, the lowercase dockerfile Docker builds instead
|
||||||
|
// stays in the build context, and its own ignore file is read.
|
||||||
|
func TestPerformBuildKeepsLowercaseDockerfile(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
files map[string]string // path in the context: contents
|
||||||
|
want []string // files sent in the build context
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
name: "kept when the ignore file names it",
|
||||||
|
files: map[string]string{
|
||||||
|
defaultDockerignoreName: "*\n",
|
||||||
|
testLowercaseDockerfile: "",
|
||||||
|
},
|
||||||
|
want: []string{defaultDockerignoreName, testLowercaseDockerfile},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "its own ignore file wins over .dockerignore",
|
||||||
|
files: map[string]string{
|
||||||
|
defaultDockerignoreName: "main.go\n",
|
||||||
|
testLowercaseDockerfile: "",
|
||||||
|
"dockerfile.dockerignore": "secret.txt\n",
|
||||||
|
testMainGo: "",
|
||||||
|
testSecretFile: "",
|
||||||
|
},
|
||||||
|
want: []string{
|
||||||
|
defaultDockerignoreName,
|
||||||
|
testLowercaseDockerfile,
|
||||||
|
"dockerfile.dockerignore",
|
||||||
|
testMainGo,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
contextDir := t.TempDir()
|
||||||
|
writeFiles(t, contextDir, tt.files)
|
||||||
|
|
||||||
|
got, err := buildContextFiles(t, contextDir, defaultDockerfileName)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if !slices.Equal(got, tt.want) {
|
||||||
|
t.Errorf("build context holds %q, want %q", got, tt.want)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestPerformBuildReadsDockerfilePathInsideContext checks that ./Dockerfile
|
||||||
|
// and /Dockerfile name the Dockerfile at the root of the context, as Docker
|
||||||
|
// reads them, so an ignore file that names the Dockerfile does not leave it
|
||||||
|
// out.
|
||||||
|
func TestPerformBuildReadsDockerfilePathInsideContext(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
for _, dockerfile := range []string{"./Dockerfile", "/Dockerfile"} {
|
||||||
|
t.Run(dockerfile, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
contextDir := t.TempDir()
|
||||||
|
writeFiles(t, contextDir, map[string]string{
|
||||||
|
defaultDockerignoreName: "Dockerfile\nsecret.txt\n",
|
||||||
|
defaultDockerfileName: "",
|
||||||
|
testMainGo: "",
|
||||||
|
testSecretFile: "",
|
||||||
|
})
|
||||||
|
|
||||||
|
got, err := buildContextFiles(t, contextDir, dockerfile)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
want := []string{defaultDockerignoreName, defaultDockerfileName, testMainGo}
|
||||||
|
if !slices.Equal(got, want) {
|
||||||
|
t.Errorf("build context holds %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestPerformBuildFailsOnMalformedDockerignore checks that a pattern the
|
||||||
|
// docker command line would reject fails the build.
|
||||||
|
func TestPerformBuildFailsOnMalformedDockerignore(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
contextDir := t.TempDir()
|
||||||
|
writeFiles(t, contextDir, map[string]string{defaultDockerignoreName: "[\n"})
|
||||||
|
|
||||||
|
_, err := buildContextFiles(t, contextDir, defaultDockerfileName)
|
||||||
|
|
||||||
|
want := "failed to create build context: " +
|
||||||
|
"invalid pattern in .dockerignore: syntax error in pattern"
|
||||||
|
if err == nil || err.Error() != want {
|
||||||
|
t.Errorf("got error %v, want %q", err, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestPerformBuildFailsOnUnreadableDockerignore checks that an ignore file
|
||||||
|
// that cannot be read, here because it is a directory, fails the build.
|
||||||
|
func TestPerformBuildFailsOnUnreadableDockerignore(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
contextDir := t.TempDir()
|
||||||
|
|
||||||
|
err := os.Mkdir(filepath.Join(contextDir, defaultDockerignoreName), 0o750)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
_, err = buildContextFiles(t, contextDir, defaultDockerfileName)
|
||||||
|
|
||||||
|
want := "failed to create build context: failed to read .dockerignore: "
|
||||||
|
if err == nil || !strings.HasPrefix(err.Error(), want) {
|
||||||
|
t.Errorf("got error %v, want one starting %q", err, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// writeFiles writes files, a map of paths inside dir to their contents,
|
||||||
|
// creating the directories they are in.
|
||||||
|
func writeFiles(t *testing.T, dir string, files map[string]string) {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
for name, contents := range files {
|
||||||
|
path := filepath.Join(dir, name)
|
||||||
|
|
||||||
|
err := os.MkdirAll(filepath.Dir(path), 0o750)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
err = os.WriteFile(path, []byte(contents), 0o600)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// buildContextFiles runs a build of contextDir against a fake Docker API and
|
||||||
|
// returns the names of the files in the build context sent to it, sorted.
|
||||||
|
func buildContextFiles(t *testing.T, contextDir, dockerfile string) ([]string, error) {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
sent := make(chan []string, 1)
|
||||||
|
|
||||||
|
srv := httptest.NewServer(http.HandlerFunc(
|
||||||
|
func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
switch {
|
||||||
|
case strings.HasSuffix(r.URL.Path, "/version"):
|
||||||
|
_, _ = w.Write([]byte(`{"Version":"27.3.1","ApiVersion":"1.47"}`))
|
||||||
|
case strings.HasSuffix(r.URL.Path, "/session"):
|
||||||
|
serveSession(t, w, r, make(chan string, 1))
|
||||||
|
case strings.HasSuffix(r.URL.Path, "/build"):
|
||||||
|
sent <- tarFileNames(t, r.Body)
|
||||||
|
default:
|
||||||
|
t.Errorf("unexpected request to %s", r.URL.Path)
|
||||||
|
}
|
||||||
|
},
|
||||||
|
))
|
||||||
|
t.Cleanup(srv.Close)
|
||||||
|
|
||||||
|
dockerAPI, err := client.NewClientWithOpts(
|
||||||
|
client.WithHost("tcp://" + srv.Listener.Addr().String()),
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
c := &Client{docker: dockerAPI, log: slog.Default()}
|
||||||
|
|
||||||
|
_, err = c.performBuild(t.Context(), BuildImageOptions{
|
||||||
|
ContextDir: contextDir,
|
||||||
|
DockerfilePath: dockerfile,
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
return <-sent, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// tarFileNames returns the names of the regular files in the tar read from r,
|
||||||
|
// sorted.
|
||||||
|
func tarFileNames(t *testing.T, r io.Reader) []string {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
var names []string
|
||||||
|
|
||||||
|
reader := tar.NewReader(r)
|
||||||
|
|
||||||
|
for {
|
||||||
|
header, err := reader.Next()
|
||||||
|
if errors.Is(err, io.EOF) {
|
||||||
|
break
|
||||||
|
}
|
||||||
|
|
||||||
|
if err != nil {
|
||||||
|
t.Errorf("reading the build context: %v", err)
|
||||||
|
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
if header.Typeflag == tar.TypeReg {
|
||||||
|
names = append(names, header.Name)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
slices.Sort(names)
|
||||||
|
|
||||||
|
return names
|
||||||
|
}
|
||||||
@@ -25,7 +25,6 @@ import (
|
|||||||
"github.com/docker/docker/api/types/network"
|
"github.com/docker/docker/api/types/network"
|
||||||
"github.com/docker/docker/api/types/versions"
|
"github.com/docker/docker/api/types/versions"
|
||||||
"github.com/docker/docker/client"
|
"github.com/docker/docker/client"
|
||||||
"github.com/docker/docker/pkg/archive"
|
|
||||||
"github.com/docker/docker/pkg/jsonmessage"
|
"github.com/docker/docker/pkg/jsonmessage"
|
||||||
"github.com/docker/docker/pkg/stdcopy"
|
"github.com/docker/docker/pkg/stdcopy"
|
||||||
"github.com/docker/go-connections/nat"
|
"github.com/docker/go-connections/nat"
|
||||||
@@ -660,7 +659,7 @@ func (c *Client) performBuild(
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Create tar archive of build context
|
// Create tar archive of build context
|
||||||
tarArchive, err := archive.TarWithOptions(opts.ContextDir, &archive.TarOptions{})
|
tarArchive, err := tarBuildContext(opts.ContextDir, opts.DockerfilePath)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return "", fmt.Errorf("failed to create build context: %w", err)
|
return "", fmt.Errorf("failed to create build context: %w", err)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,77 @@
|
|||||||
|
package handlers_test
|
||||||
|
|
||||||
|
import (
|
||||||
|
"net/http"
|
||||||
|
"net/http/httptest"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"github.com/stretchr/testify/assert"
|
||||||
|
"github.com/stretchr/testify/require"
|
||||||
|
|
||||||
|
"sneak.berlin/go/upaas/internal/service/app"
|
||||||
|
)
|
||||||
|
|
||||||
|
// TestDashboardTableFitsCard checks that the card around the app table
|
||||||
|
// scrolls sideways instead of hiding what does not fit, and that a long
|
||||||
|
// repository URL wraps instead of pushing the action buttons out.
|
||||||
|
func TestDashboardTableFitsCard(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
testCtx := setupTestHandlers(t)
|
||||||
|
|
||||||
|
repoURL := "https://git.example.com/user/" +
|
||||||
|
"a-repository-name-long-enough-to-push-the-action-buttons-out.git"
|
||||||
|
|
||||||
|
_, err := testCtx.appSvc.CreateApp(t.Context(), app.CreateAppInput{
|
||||||
|
Name: "long-url-app",
|
||||||
|
RepoURL: repoURL,
|
||||||
|
})
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
request := httptest.NewRequestWithContext(t.Context(), http.MethodGet, "/", nil)
|
||||||
|
recorder := httptest.NewRecorder()
|
||||||
|
|
||||||
|
testCtx.handlers.HandleDashboard().ServeHTTP(recorder, request)
|
||||||
|
|
||||||
|
require.Equal(t, http.StatusOK, recorder.Code)
|
||||||
|
|
||||||
|
body := recorder.Body.String()
|
||||||
|
|
||||||
|
beforeTable, _, found := strings.Cut(body, `<table class="table">`)
|
||||||
|
require.True(t, found, "dashboard has no app table")
|
||||||
|
|
||||||
|
cardTag := beforeTable[strings.LastIndex(beforeTable, "<div"):]
|
||||||
|
assert.Contains(t, cardTag, "overflow-x-auto")
|
||||||
|
assert.NotContains(t, cardTag, "overflow-hidden")
|
||||||
|
|
||||||
|
beforeURL, _, found := strings.Cut(body, ">"+repoURL+"</td>")
|
||||||
|
require.True(t, found, "dashboard has no repository cell")
|
||||||
|
|
||||||
|
cellTag := beforeURL[strings.LastIndex(beforeURL, "<td"):]
|
||||||
|
assert.Contains(t, cellTag, "whitespace-normal")
|
||||||
|
assert.Contains(t, cellTag, "break-all")
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestTopBarWrapsWhenNarrow checks that the top bar keeps a gap between the
|
||||||
|
// µPaaS title and the New App and Logout buttons, and puts the buttons on a
|
||||||
|
// second row in a window too narrow for one, instead of letting them meet.
|
||||||
|
func TestTopBarWrapsWhenNarrow(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
testCtx := setupTestHandlers(t)
|
||||||
|
|
||||||
|
request := httptest.NewRequestWithContext(t.Context(), http.MethodGet, "/", nil)
|
||||||
|
recorder := httptest.NewRecorder()
|
||||||
|
|
||||||
|
testCtx.handlers.HandleDashboard().ServeHTTP(recorder, request)
|
||||||
|
|
||||||
|
require.Equal(t, http.StatusOK, recorder.Code)
|
||||||
|
|
||||||
|
_, afterNav, found := strings.Cut(recorder.Body.String(), `<nav class="app-bar">`)
|
||||||
|
require.True(t, found, "dashboard has no top bar")
|
||||||
|
|
||||||
|
rowTag, _, _ := strings.Cut(strings.TrimSpace(afterNav), ">")
|
||||||
|
assert.Contains(t, rowTag, "flex-wrap")
|
||||||
|
assert.Contains(t, rowTag, "gap-")
|
||||||
|
}
|
||||||
@@ -109,6 +109,9 @@ func createAppServices(
|
|||||||
})
|
})
|
||||||
require.NoError(t, authErr)
|
require.NoError(t, authErr)
|
||||||
|
|
||||||
|
// 1 MiB per password hash instead of 64 MiB; see auth.Service.ArgonMemory.
|
||||||
|
authSvc.ArgonMemory = 1024
|
||||||
|
|
||||||
appSvc, appErr := app.New(fx.Lifecycle(nil), app.ServiceParams{
|
appSvc, appErr := app.New(fx.Lifecycle(nil), app.ServiceParams{
|
||||||
Logger: logInstance,
|
Logger: logInstance,
|
||||||
Database: dbInstance,
|
Database: dbInstance,
|
||||||
|
|||||||
@@ -59,6 +59,13 @@ type ServiceParams struct {
|
|||||||
|
|
||||||
// Service provides authentication functionality.
|
// Service provides authentication functionality.
|
||||||
type Service struct {
|
type Service struct {
|
||||||
|
// ArgonMemory is the memory each argon2id hash takes, in KiB. New sets
|
||||||
|
// argonMemory, 64 MiB, and upaasd never changes it. Tests lower it, since
|
||||||
|
// many 64 MiB hashes at once under the race detector need more memory
|
||||||
|
// than a 4 GiB build machine has. A hash verifies only with the value it
|
||||||
|
// was made with.
|
||||||
|
ArgonMemory uint32
|
||||||
|
|
||||||
log *slog.Logger
|
log *slog.Logger
|
||||||
db *database.Database
|
db *database.Database
|
||||||
store *sessions.CookieStore
|
store *sessions.CookieStore
|
||||||
@@ -77,6 +84,7 @@ func New(_ fx.Lifecycle, params ServiceParams) (*Service, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
return &Service{
|
return &Service{
|
||||||
|
ArgonMemory: argonMemory,
|
||||||
log: params.Logger.Get(),
|
log: params.Logger.Get(),
|
||||||
db: params.Database,
|
db: params.Database,
|
||||||
store: store,
|
store: store,
|
||||||
@@ -97,7 +105,7 @@ func (svc *Service) HashPassword(password string) (string, error) {
|
|||||||
[]byte(password),
|
[]byte(password),
|
||||||
salt,
|
salt,
|
||||||
argonTime,
|
argonTime,
|
||||||
argonMemory,
|
svc.ArgonMemory,
|
||||||
argonThreads,
|
argonThreads,
|
||||||
argonKeyLen,
|
argonKeyLen,
|
||||||
)
|
)
|
||||||
@@ -132,7 +140,7 @@ func (svc *Service) VerifyPassword(hashedPassword, password string) bool {
|
|||||||
[]byte(password),
|
[]byte(password),
|
||||||
salt,
|
salt,
|
||||||
argonTime,
|
argonTime,
|
||||||
argonMemory,
|
svc.ArgonMemory,
|
||||||
argonThreads,
|
argonThreads,
|
||||||
argonKeyLen,
|
argonKeyLen,
|
||||||
)
|
)
|
||||||
|
|||||||
@@ -65,6 +65,10 @@ func setupTestService(t *testing.T) (*auth.Service, func()) {
|
|||||||
})
|
})
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// 1 MiB per hash instead of 64 MiB; see Service.ArgonMemory. The tests
|
||||||
|
// that use setupAuthService keep 64 MiB.
|
||||||
|
svc.ArgonMemory = 1024
|
||||||
|
|
||||||
// t.TempDir() automatically cleans up after test
|
// t.TempDir() automatically cleans up after test
|
||||||
cleanup := func() {}
|
cleanup := func() {}
|
||||||
|
|
||||||
@@ -237,6 +241,21 @@ func TestVerifyPassword(testingT *testing.T) {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// TestHashPasswordWithUpaasdMemory hashes and verifies a password with the
|
||||||
|
// memory New sets, which upaasd uses. setupTestService lowers it.
|
||||||
|
func TestHashPasswordWithUpaasdMemory(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
svc := setupAuthService(t, false)
|
||||||
|
require.Equal(t, uint32(64*1024), svc.ArgonMemory)
|
||||||
|
|
||||||
|
hash, err := svc.HashPassword("correctpassword")
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
assert.True(t, svc.VerifyPassword(hash, "correctpassword"))
|
||||||
|
assert.False(t, svc.VerifyPassword(hash, "wrongpassword"))
|
||||||
|
}
|
||||||
|
|
||||||
func TestIsSetupRequired(testingT *testing.T) {
|
func TestIsSetupRequired(testingT *testing.T) {
|
||||||
testingT.Parallel()
|
testingT.Parallel()
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -26,7 +26,7 @@
|
|||||||
|
|
||||||
{{define "nav"}}
|
{{define "nav"}}
|
||||||
<nav class="app-bar">
|
<nav class="app-bar">
|
||||||
<div class="max-w-6xl mx-auto flex justify-between items-center">
|
<div class="max-w-6xl mx-auto flex flex-wrap justify-between items-center gap-3">
|
||||||
<div class="flex items-center gap-3">
|
<div class="flex items-center gap-3">
|
||||||
<a href="/" class="text-xl font-medium text-gray-900 hover:text-primary-600 transition-colors">µPaaS</a>
|
<a href="/" class="text-xl font-medium text-gray-900 hover:text-primary-600 transition-colors">µPaaS</a>
|
||||||
<span class="text-sm text-gray-500">by <a href="https://sneak.berlin" class="text-primary-600 hover:text-primary-800">@sneak</a></span>
|
<span class="text-sm text-gray-500">by <a href="https://sneak.berlin" class="text-primary-600 hover:text-primary-800">@sneak</a></span>
|
||||||
|
|||||||
@@ -20,7 +20,7 @@
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
{{if .AppStats}}
|
{{if .AppStats}}
|
||||||
<div class="card overflow-hidden">
|
<div class="card overflow-x-auto">
|
||||||
<table class="table">
|
<table class="table">
|
||||||
<thead class="table-header">
|
<thead class="table-header">
|
||||||
<tr>
|
<tr>
|
||||||
@@ -41,7 +41,7 @@
|
|||||||
{{.App.Name}}
|
{{.App.Name}}
|
||||||
</a>
|
</a>
|
||||||
</td>
|
</td>
|
||||||
<td class="text-gray-500 font-mono text-xs">{{.App.RepoURL}}</td>
|
<td class="text-gray-500 font-mono text-xs whitespace-normal break-all">{{.App.RepoURL}}</td>
|
||||||
<td class="text-gray-500">{{.App.Branch}}</td>
|
<td class="text-gray-500">{{.App.Branch}}</td>
|
||||||
<td>
|
<td>
|
||||||
{{if eq .App.Status "running"}}
|
{{if eq .App.Status "running"}}
|
||||||
|
|||||||
Reference in New Issue
Block a user