Compare commits
1
Commits
next
..
d0f1348f50
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d0f1348f50 |
@@ -268,12 +268,6 @@ upaas fails the deploy instead of building. A Dockerfile that uses
|
|||||||
`RUN --network` needs Docker Engine 23.0 or later unless its `# syntax=` line
|
`RUN --network` needs Docker Engine 23.0 or later unless its `# syntax=` line
|
||||||
names Dockerfile frontend 1.3 or later, such as `docker/dockerfile:1`.
|
names Dockerfile frontend 1.3 or later, such as `docker/dockerfile:1`.
|
||||||
|
|
||||||
The build context leaves out the files the app's ignore file names, as
|
|
||||||
`docker build` does: `<Dockerfile>.dockerignore` next to the app's Dockerfile if
|
|
||||||
there is one, otherwise `.dockerignore` at the root of the repository. The
|
|
||||||
Dockerfile and `.dockerignore` are always sent, even when the ignore file names
|
|
||||||
them.
|
|
||||||
|
|
||||||
Session secrets are automatically generated on first startup and persisted to
|
Session secrets are automatically generated on first startup and persisted to
|
||||||
`$UPAAS_DATA_DIR/session.key`.
|
`$UPAAS_DATA_DIR/session.key`.
|
||||||
|
|
||||||
|
|||||||
@@ -20,30 +20,10 @@ regress.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
- 2026-10-03: An app's build context leaves out the files its `.dockerignore`
|
|
||||||
names, such as `.git/config`, as `docker build` does; before, every file in
|
|
||||||
the clone was sent. An ignore file next to the Dockerfile,
|
|
||||||
`<Dockerfile>.dockerignore`, is read instead when there is one. The Dockerfile
|
|
||||||
and `.dockerignore` are always sent. An ignore file that cannot be read, or
|
|
||||||
holds a pattern Docker rejects, fails the build (#274).
|
|
||||||
|
|
||||||
- 2026-10-03: `make test`, and so `docker build .`, fits a machine with 4 GiB of
|
|
||||||
memory: tests hash passwords with 1 MiB instead of upaasd's 64 MiB, so
|
|
||||||
`GOMAXPROCS=4 make test` peaks at about 1.4 GiB instead of 2.7 GiB. upaasd
|
|
||||||
still hashes with 64 MiB, and one test hashes and verifies a password at that
|
|
||||||
cost (#261).
|
|
||||||
|
|
||||||
- 2026-10-02: In a window too narrow for the top bar, such as 390 px, the New
|
- 2026-10-02: In a window too narrow for the top bar, such as 390 px, the New
|
||||||
App and Logout buttons move to a second row instead of running into "by
|
App and Logout buttons move to a second row instead of running into "by
|
||||||
@sneak"; the bar keeps a gap between its two sides at every width (#272).
|
@sneak"; the bar keeps a gap between its two sides at every width (#272).
|
||||||
|
|
||||||
- 2026-10-02: App names may contain dots, such as `sneak.berlin`: lowercase
|
|
||||||
letters and numbers joined by single dots or by hyphens, 2 to 63 characters.
|
|
||||||
Docker accepts every such name in the image name `upaas-<name>`; a dot needs a
|
|
||||||
letter or number on both sides because Docker requires it. The new and edit
|
|
||||||
app forms check the same rule; browsers ignored their old pattern, which was
|
|
||||||
not a valid regular expression there (#260).
|
|
||||||
|
|
||||||
- 2026-10-02: On the Applications list, a long repository URL now wraps within
|
- 2026-10-02: On the Applications list, a long repository URL now wraps within
|
||||||
its column instead of making the table wider than its card, which cut off the
|
its column instead of making the table wider than its card, which cut off the
|
||||||
Actions column and the Deploy buttons. In a window too narrow for the table,
|
Actions column and the Deploy buttons. In a window too narrow for the table,
|
||||||
|
|||||||
@@ -4,7 +4,6 @@ go 1.25
|
|||||||
|
|
||||||
require (
|
require (
|
||||||
github.com/99designs/basicauth-go v0.0.0-20230316000542-bf6f9cbbf0f8
|
github.com/99designs/basicauth-go v0.0.0-20230316000542-bf6f9cbbf0f8
|
||||||
github.com/distribution/reference v0.6.0
|
|
||||||
github.com/docker/docker v27.3.1+incompatible
|
github.com/docker/docker v27.3.1+incompatible
|
||||||
github.com/docker/go-connections v0.6.0
|
github.com/docker/go-connections v0.6.0
|
||||||
github.com/go-chi/chi/v5 v5.2.3
|
github.com/go-chi/chi/v5 v5.2.3
|
||||||
@@ -15,7 +14,6 @@ require (
|
|||||||
github.com/joho/godotenv v1.5.1
|
github.com/joho/godotenv v1.5.1
|
||||||
github.com/mattn/go-sqlite3 v1.14.32
|
github.com/mattn/go-sqlite3 v1.14.32
|
||||||
github.com/moby/buildkit v0.16.0
|
github.com/moby/buildkit v0.16.0
|
||||||
github.com/moby/patternmatcher v0.6.0
|
|
||||||
github.com/oklog/ulid/v2 v2.1.1
|
github.com/oklog/ulid/v2 v2.1.1
|
||||||
github.com/prometheus/client_golang v1.23.2
|
github.com/prometheus/client_golang v1.23.2
|
||||||
github.com/spf13/viper v1.21.0
|
github.com/spf13/viper v1.21.0
|
||||||
@@ -41,6 +39,7 @@ require (
|
|||||||
github.com/containerd/ttrpc v1.2.5 // indirect
|
github.com/containerd/ttrpc v1.2.5 // indirect
|
||||||
github.com/containerd/typeurl/v2 v2.2.0 // indirect
|
github.com/containerd/typeurl/v2 v2.2.0 // indirect
|
||||||
github.com/davecgh/go-spew v1.1.1 // indirect
|
github.com/davecgh/go-spew v1.1.1 // indirect
|
||||||
|
github.com/distribution/reference v0.6.0 // indirect
|
||||||
github.com/docker/go-units v0.5.0 // indirect
|
github.com/docker/go-units v0.5.0 // indirect
|
||||||
github.com/felixge/httpsnoop v1.0.4 // indirect
|
github.com/felixge/httpsnoop v1.0.4 // indirect
|
||||||
github.com/fsnotify/fsnotify v1.9.0 // indirect
|
github.com/fsnotify/fsnotify v1.9.0 // indirect
|
||||||
@@ -61,6 +60,7 @@ require (
|
|||||||
github.com/klauspost/compress v1.18.2 // indirect
|
github.com/klauspost/compress v1.18.2 // indirect
|
||||||
github.com/moby/docker-image-spec v1.3.1 // indirect
|
github.com/moby/docker-image-spec v1.3.1 // indirect
|
||||||
github.com/moby/locker v1.0.1 // indirect
|
github.com/moby/locker v1.0.1 // indirect
|
||||||
|
github.com/moby/patternmatcher v0.6.0 // indirect
|
||||||
github.com/moby/sys/sequential v0.6.0 // indirect
|
github.com/moby/sys/sequential v0.6.0 // indirect
|
||||||
github.com/moby/sys/signal v0.7.1 // indirect
|
github.com/moby/sys/signal v0.7.1 // indirect
|
||||||
github.com/moby/sys/user v0.4.0 // indirect
|
github.com/moby/sys/user v0.4.0 // indirect
|
||||||
|
|||||||
@@ -1,114 +0,0 @@
|
|||||||
package docker
|
|
||||||
|
|
||||||
import (
|
|
||||||
"errors"
|
|
||||||
"fmt"
|
|
||||||
"io"
|
|
||||||
"io/fs"
|
|
||||||
"os"
|
|
||||||
"path/filepath"
|
|
||||||
"strings"
|
|
||||||
|
|
||||||
"github.com/docker/docker/pkg/archive"
|
|
||||||
"github.com/moby/patternmatcher"
|
|
||||||
"github.com/moby/patternmatcher/ignorefile"
|
|
||||||
)
|
|
||||||
|
|
||||||
// defaultDockerfileName is the Dockerfile Docker builds when none is named.
|
|
||||||
const defaultDockerfileName = "Dockerfile"
|
|
||||||
|
|
||||||
// defaultDockerignoreName is the ignore file at the root of a build context,
|
|
||||||
// read when the Dockerfile has no ignore file of its own.
|
|
||||||
const defaultDockerignoreName = ".dockerignore"
|
|
||||||
|
|
||||||
// tarBuildContext returns a tar of the build context in contextDir that leaves
|
|
||||||
// out the files the app's ignore file names, as docker build does; Docker does
|
|
||||||
// not apply the ignore file to a build context sent as a tar. dockerfile is
|
|
||||||
// the path of the Dockerfile inside contextDir.
|
|
||||||
func tarBuildContext(contextDir, dockerfile string) (io.ReadCloser, error) {
|
|
||||||
excludes, err := readDockerignore(contextDir, dockerfile)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
return archive.TarWithOptions(contextDir, &archive.TarOptions{
|
|
||||||
ExcludePatterns: excludes,
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
// readDockerignore returns the patterns of the files to leave out of the
|
|
||||||
// build context in contextDir, read as docker build reads them for the
|
|
||||||
// Dockerfile at dockerfile: from <dockerfile>.dockerignore next to the
|
|
||||||
// Dockerfile if there is one, otherwise from .dockerignore at the root of the
|
|
||||||
// context. Without either file there are no patterns.
|
|
||||||
func readDockerignore(contextDir, dockerfile string) ([]string, error) {
|
|
||||||
// Docker reads the Dockerfile path as a path inside the build context:
|
|
||||||
// cleaned, with a leading / and any .. that would lead out of the context
|
|
||||||
// dropped, so ./Dockerfile and /Dockerfile both name the Dockerfile at the
|
|
||||||
// root.
|
|
||||||
dockerfile = strings.TrimPrefix(filepath.Join("/", dockerfile), "/")
|
|
||||||
if dockerfile == "" {
|
|
||||||
dockerfile = defaultDockerfileName
|
|
||||||
}
|
|
||||||
|
|
||||||
// Reading through os.Root keeps the read inside the build context, even
|
|
||||||
// when the ignore file is a symlink.
|
|
||||||
root, err := os.OpenRoot(contextDir)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
defer func() { _ = root.Close() }()
|
|
||||||
|
|
||||||
// When a Dockerfile named Dockerfile is missing, Docker builds a
|
|
||||||
// lowercase dockerfile in the same directory instead, and docker build
|
|
||||||
// then reads dockerfile.dockerignore as its ignore file.
|
|
||||||
if filepath.Base(dockerfile) == defaultDockerfileName {
|
|
||||||
lowercase := filepath.Join(filepath.Dir(dockerfile), "dockerfile")
|
|
||||||
|
|
||||||
_, dockerfileErr := root.Lstat(dockerfile)
|
|
||||||
_, lowercaseErr := root.Lstat(lowercase)
|
|
||||||
|
|
||||||
if errors.Is(dockerfileErr, fs.ErrNotExist) && lowercaseErr == nil {
|
|
||||||
dockerfile = lowercase
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
name := dockerfile + defaultDockerignoreName
|
|
||||||
|
|
||||||
file, err := root.Open(name)
|
|
||||||
if errors.Is(err, fs.ErrNotExist) {
|
|
||||||
name = defaultDockerignoreName
|
|
||||||
file, err = root.Open(name)
|
|
||||||
}
|
|
||||||
|
|
||||||
if errors.Is(err, fs.ErrNotExist) {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("failed to read %s: %w", name, err)
|
|
||||||
}
|
|
||||||
|
|
||||||
defer func() { _ = file.Close() }()
|
|
||||||
|
|
||||||
excludes, err := ignorefile.ReadAll(file)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("failed to read %s: %w", name, err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Like the docker command line, never leave out .dockerignore or the
|
|
||||||
// Dockerfile: Docker reads the Dockerfile from the context.
|
|
||||||
for _, keep := range []string{defaultDockerignoreName, filepath.ToSlash(dockerfile)} {
|
|
||||||
excluded, err := patternmatcher.MatchesOrParentMatches(keep, excludes)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("invalid pattern in %s: %w", name, err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if excluded {
|
|
||||||
excludes = append(excludes, "!"+keep)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return excludes, nil
|
|
||||||
}
|
|
||||||
@@ -1,326 +0,0 @@
|
|||||||
package docker //nolint:testpackage // tests the unexported performBuild
|
|
||||||
|
|
||||||
import (
|
|
||||||
"archive/tar"
|
|
||||||
"errors"
|
|
||||||
"io"
|
|
||||||
"log/slog"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"os"
|
|
||||||
"path/filepath"
|
|
||||||
"slices"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/docker/docker/client"
|
|
||||||
)
|
|
||||||
|
|
||||||
// File names used in more than one test build context, as constants to
|
|
||||||
// satisfy the goconst linter.
|
|
||||||
const (
|
|
||||||
testMainGo = "main.go"
|
|
||||||
testSecretFile = "secret.txt"
|
|
||||||
testDeployDockerfile = "deploy/Dockerfile"
|
|
||||||
testLowercaseDockerfile = "dockerfile"
|
|
||||||
)
|
|
||||||
|
|
||||||
// TestPerformBuildFollowsDockerignore runs builds against a fake Docker API
|
|
||||||
// and checks which files the build context sent to it holds.
|
|
||||||
func TestPerformBuildFollowsDockerignore(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
dockerfile string
|
|
||||||
files map[string]string // path in the context: contents
|
|
||||||
want []string // files sent in the build context
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
name: "no ignore file",
|
|
||||||
dockerfile: defaultDockerfileName,
|
|
||||||
files: map[string]string{defaultDockerfileName: "", testMainGo: ""},
|
|
||||||
want: []string{defaultDockerfileName, testMainGo},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "excludes and re-includes",
|
|
||||||
dockerfile: defaultDockerfileName,
|
|
||||||
files: map[string]string{
|
|
||||||
defaultDockerignoreName: "secret.txt\n*.md\n!README.md\n",
|
|
||||||
defaultDockerfileName: "",
|
|
||||||
"NOTES.md": "",
|
|
||||||
"README.md": "",
|
|
||||||
testMainGo: "",
|
|
||||||
testSecretFile: "",
|
|
||||||
},
|
|
||||||
want: []string{
|
|
||||||
defaultDockerignoreName, defaultDockerfileName, "README.md", testMainGo,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "keeps the Dockerfile and .dockerignore",
|
|
||||||
dockerfile: defaultDockerfileName,
|
|
||||||
files: map[string]string{
|
|
||||||
defaultDockerignoreName: "Dockerfile\n.dockerignore\nsecret.txt\n",
|
|
||||||
defaultDockerfileName: "",
|
|
||||||
testMainGo: "",
|
|
||||||
testSecretFile: "",
|
|
||||||
},
|
|
||||||
want: []string{defaultDockerignoreName, defaultDockerfileName, testMainGo},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "an ignore file next to the Dockerfile wins over .dockerignore",
|
|
||||||
dockerfile: testDeployDockerfile,
|
|
||||||
files: map[string]string{
|
|
||||||
defaultDockerignoreName: "main.go\n",
|
|
||||||
testDeployDockerfile: "",
|
|
||||||
"deploy/Dockerfile.dockerignore": "secret.txt\n",
|
|
||||||
testMainGo: "",
|
|
||||||
testSecretFile: "",
|
|
||||||
},
|
|
||||||
want: []string{
|
|
||||||
defaultDockerignoreName,
|
|
||||||
testDeployDockerfile,
|
|
||||||
"deploy/Dockerfile.dockerignore",
|
|
||||||
testMainGo,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
contextDir := t.TempDir()
|
|
||||||
writeFiles(t, contextDir, tt.files)
|
|
||||||
|
|
||||||
got, err := buildContextFiles(t, contextDir, tt.dockerfile)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if !slices.Equal(got, tt.want) {
|
|
||||||
t.Errorf("build context holds %q, want %q", got, tt.want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestPerformBuildKeepsLowercaseDockerfile checks that when the Dockerfile
|
|
||||||
// named Dockerfile is missing, the lowercase dockerfile Docker builds instead
|
|
||||||
// stays in the build context, and its own ignore file is read.
|
|
||||||
func TestPerformBuildKeepsLowercaseDockerfile(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
files map[string]string // path in the context: contents
|
|
||||||
want []string // files sent in the build context
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
name: "kept when the ignore file names it",
|
|
||||||
files: map[string]string{
|
|
||||||
defaultDockerignoreName: "*\n",
|
|
||||||
testLowercaseDockerfile: "",
|
|
||||||
},
|
|
||||||
want: []string{defaultDockerignoreName, testLowercaseDockerfile},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "its own ignore file wins over .dockerignore",
|
|
||||||
files: map[string]string{
|
|
||||||
defaultDockerignoreName: "main.go\n",
|
|
||||||
testLowercaseDockerfile: "",
|
|
||||||
"dockerfile.dockerignore": "secret.txt\n",
|
|
||||||
testMainGo: "",
|
|
||||||
testSecretFile: "",
|
|
||||||
},
|
|
||||||
want: []string{
|
|
||||||
defaultDockerignoreName,
|
|
||||||
testLowercaseDockerfile,
|
|
||||||
"dockerfile.dockerignore",
|
|
||||||
testMainGo,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
contextDir := t.TempDir()
|
|
||||||
writeFiles(t, contextDir, tt.files)
|
|
||||||
|
|
||||||
got, err := buildContextFiles(t, contextDir, defaultDockerfileName)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if !slices.Equal(got, tt.want) {
|
|
||||||
t.Errorf("build context holds %q, want %q", got, tt.want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestPerformBuildReadsDockerfilePathInsideContext checks that ./Dockerfile
|
|
||||||
// and /Dockerfile name the Dockerfile at the root of the context, as Docker
|
|
||||||
// reads them, so an ignore file that names the Dockerfile does not leave it
|
|
||||||
// out.
|
|
||||||
func TestPerformBuildReadsDockerfilePathInsideContext(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
for _, dockerfile := range []string{"./Dockerfile", "/Dockerfile"} {
|
|
||||||
t.Run(dockerfile, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
contextDir := t.TempDir()
|
|
||||||
writeFiles(t, contextDir, map[string]string{
|
|
||||||
defaultDockerignoreName: "Dockerfile\nsecret.txt\n",
|
|
||||||
defaultDockerfileName: "",
|
|
||||||
testMainGo: "",
|
|
||||||
testSecretFile: "",
|
|
||||||
})
|
|
||||||
|
|
||||||
got, err := buildContextFiles(t, contextDir, dockerfile)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
want := []string{defaultDockerignoreName, defaultDockerfileName, testMainGo}
|
|
||||||
if !slices.Equal(got, want) {
|
|
||||||
t.Errorf("build context holds %q, want %q", got, want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestPerformBuildFailsOnMalformedDockerignore checks that a pattern the
|
|
||||||
// docker command line would reject fails the build.
|
|
||||||
func TestPerformBuildFailsOnMalformedDockerignore(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
contextDir := t.TempDir()
|
|
||||||
writeFiles(t, contextDir, map[string]string{defaultDockerignoreName: "[\n"})
|
|
||||||
|
|
||||||
_, err := buildContextFiles(t, contextDir, defaultDockerfileName)
|
|
||||||
|
|
||||||
want := "failed to create build context: " +
|
|
||||||
"invalid pattern in .dockerignore: syntax error in pattern"
|
|
||||||
if err == nil || err.Error() != want {
|
|
||||||
t.Errorf("got error %v, want %q", err, want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestPerformBuildFailsOnUnreadableDockerignore checks that an ignore file
|
|
||||||
// that cannot be read, here because it is a directory, fails the build.
|
|
||||||
func TestPerformBuildFailsOnUnreadableDockerignore(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
contextDir := t.TempDir()
|
|
||||||
|
|
||||||
err := os.Mkdir(filepath.Join(contextDir, defaultDockerignoreName), 0o750)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
_, err = buildContextFiles(t, contextDir, defaultDockerfileName)
|
|
||||||
|
|
||||||
want := "failed to create build context: failed to read .dockerignore: "
|
|
||||||
if err == nil || !strings.HasPrefix(err.Error(), want) {
|
|
||||||
t.Errorf("got error %v, want one starting %q", err, want)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// writeFiles writes files, a map of paths inside dir to their contents,
|
|
||||||
// creating the directories they are in.
|
|
||||||
func writeFiles(t *testing.T, dir string, files map[string]string) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
for name, contents := range files {
|
|
||||||
path := filepath.Join(dir, name)
|
|
||||||
|
|
||||||
err := os.MkdirAll(filepath.Dir(path), 0o750)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
err = os.WriteFile(path, []byte(contents), 0o600)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// buildContextFiles runs a build of contextDir against a fake Docker API and
|
|
||||||
// returns the names of the files in the build context sent to it, sorted.
|
|
||||||
func buildContextFiles(t *testing.T, contextDir, dockerfile string) ([]string, error) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
sent := make(chan []string, 1)
|
|
||||||
|
|
||||||
srv := httptest.NewServer(http.HandlerFunc(
|
|
||||||
func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
switch {
|
|
||||||
case strings.HasSuffix(r.URL.Path, "/version"):
|
|
||||||
_, _ = w.Write([]byte(`{"Version":"27.3.1","ApiVersion":"1.47"}`))
|
|
||||||
case strings.HasSuffix(r.URL.Path, "/session"):
|
|
||||||
serveSession(t, w, r, make(chan string, 1))
|
|
||||||
case strings.HasSuffix(r.URL.Path, "/build"):
|
|
||||||
sent <- tarFileNames(t, r.Body)
|
|
||||||
default:
|
|
||||||
t.Errorf("unexpected request to %s", r.URL.Path)
|
|
||||||
}
|
|
||||||
},
|
|
||||||
))
|
|
||||||
t.Cleanup(srv.Close)
|
|
||||||
|
|
||||||
dockerAPI, err := client.NewClientWithOpts(
|
|
||||||
client.WithHost("tcp://" + srv.Listener.Addr().String()),
|
|
||||||
)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
c := &Client{docker: dockerAPI, log: slog.Default()}
|
|
||||||
|
|
||||||
_, err = c.performBuild(t.Context(), BuildImageOptions{
|
|
||||||
ContextDir: contextDir,
|
|
||||||
DockerfilePath: dockerfile,
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
return <-sent, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// tarFileNames returns the names of the regular files in the tar read from r,
|
|
||||||
// sorted.
|
|
||||||
func tarFileNames(t *testing.T, r io.Reader) []string {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
var names []string
|
|
||||||
|
|
||||||
reader := tar.NewReader(r)
|
|
||||||
|
|
||||||
for {
|
|
||||||
header, err := reader.Next()
|
|
||||||
if errors.Is(err, io.EOF) {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
|
|
||||||
if err != nil {
|
|
||||||
t.Errorf("reading the build context: %v", err)
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
if header.Typeflag == tar.TypeReg {
|
|
||||||
names = append(names, header.Name)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
slices.Sort(names)
|
|
||||||
|
|
||||||
return names
|
|
||||||
}
|
|
||||||
@@ -25,6 +25,7 @@ import (
|
|||||||
"github.com/docker/docker/api/types/network"
|
"github.com/docker/docker/api/types/network"
|
||||||
"github.com/docker/docker/api/types/versions"
|
"github.com/docker/docker/api/types/versions"
|
||||||
"github.com/docker/docker/client"
|
"github.com/docker/docker/client"
|
||||||
|
"github.com/docker/docker/pkg/archive"
|
||||||
"github.com/docker/docker/pkg/jsonmessage"
|
"github.com/docker/docker/pkg/jsonmessage"
|
||||||
"github.com/docker/docker/pkg/stdcopy"
|
"github.com/docker/docker/pkg/stdcopy"
|
||||||
"github.com/docker/go-connections/nat"
|
"github.com/docker/go-connections/nat"
|
||||||
@@ -659,7 +660,7 @@ func (c *Client) performBuild(
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Create tar archive of build context
|
// Create tar archive of build context
|
||||||
tarArchive, err := tarBuildContext(opts.ContextDir, opts.DockerfilePath)
|
tarArchive, err := archive.TarWithOptions(opts.ContextDir, &archive.TarOptions{})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return "", fmt.Errorf("failed to create build context: %w", err)
|
return "", fmt.Errorf("failed to create build context: %w", err)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -13,15 +13,12 @@ const (
|
|||||||
appNameMaxLength = 63
|
appNameMaxLength = 63
|
||||||
)
|
)
|
||||||
|
|
||||||
// validAppNameRe matches runs of lowercase letters and digits joined by
|
// validAppNameRe matches names containing only lowercase alphanumeric characters and
|
||||||
// single dots or by hyphens, such as "my-app" or "sneak.berlin". Docker
|
// hyphens, starting and ending with an alphanumeric character.
|
||||||
// accepts every name it allows as the app's image name, upaas-<name>; a
|
var validAppNameRe = regexp.MustCompile(`^[a-z0-9][a-z0-9-]*[a-z0-9]$`)
|
||||||
// dot needs a letter or digit on both sides because Docker requires it.
|
|
||||||
// It also keeps the name from being "." or ".." or starting or ending
|
|
||||||
// with a dot, so it is safe as a directory and file name. The pattern
|
|
||||||
// attribute of the name field on the new and edit app forms is the same.
|
|
||||||
var validAppNameRe = regexp.MustCompile(`^[a-z0-9]+((\.|-+)[a-z0-9]+)*$`)
|
|
||||||
|
|
||||||
|
// validateAppName checks that the given app name is safe for use in Docker
|
||||||
|
// container names, image tags, and file system paths.
|
||||||
var (
|
var (
|
||||||
errAppNameLength = errors.New(
|
errAppNameLength = errors.New(
|
||||||
"app name must be between " +
|
"app name must be between " +
|
||||||
@@ -29,14 +26,11 @@ var (
|
|||||||
strconv.Itoa(appNameMaxLength) + " characters",
|
strconv.Itoa(appNameMaxLength) + " characters",
|
||||||
)
|
)
|
||||||
errAppNamePattern = errors.New(
|
errAppNamePattern = errors.New(
|
||||||
"app name must contain only lowercase letters, numbers, hyphens, " +
|
"app name must contain only lowercase letters, numbers, " +
|
||||||
"and dots, must start and end with a letter or number, " +
|
"and hyphens, and must start and end with a letter or number",
|
||||||
"and must have a letter or number on both sides of each dot",
|
|
||||||
)
|
)
|
||||||
)
|
)
|
||||||
|
|
||||||
// validateAppName checks that the given app name is safe for use in Docker
|
|
||||||
// container names, image tags, and file system paths.
|
|
||||||
func validateAppName(name string) error {
|
func validateAppName(name string) error {
|
||||||
if len(name) < appNameMinLength || len(name) > appNameMaxLength {
|
if len(name) < appNameMinLength || len(name) > appNameMaxLength {
|
||||||
return errAppNameLength
|
return errAppNameLength
|
||||||
|
|||||||
@@ -1,16 +1,7 @@
|
|||||||
package handlers //nolint:testpackage // testing unexported validateAppName
|
package handlers //nolint:testpackage // testing unexported validateAppName
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
|
||||||
"strconv"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
"github.com/stretchr/testify/assert"
|
|
||||||
"github.com/stretchr/testify/require"
|
|
||||||
|
|
||||||
"sneak.berlin/go/upaas/internal/models"
|
|
||||||
"sneak.berlin/go/upaas/templates"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func TestValidateAppName(t *testing.T) {
|
func TestValidateAppName(t *testing.T) {
|
||||||
@@ -27,10 +18,6 @@ func TestValidateAppName(t *testing.T) {
|
|||||||
{"valid two chars", "ab", false},
|
{"valid two chars", "ab", false},
|
||||||
{"valid complex", "my-cool-app-v2", false},
|
{"valid complex", "my-cool-app-v2", false},
|
||||||
{"valid all numbers", "123", false},
|
{"valid all numbers", "123", false},
|
||||||
{"valid double hyphen", "my--app", false},
|
|
||||||
{"valid domain", "sneak.berlin", false},
|
|
||||||
{"valid two dots", "www.sneak.berlin", false},
|
|
||||||
{"valid dot and hyphen", "my-app.example.com", false},
|
|
||||||
{"empty", "", true},
|
{"empty", "", true},
|
||||||
{"single char", "a", true},
|
{"single char", "a", true},
|
||||||
{"too long", "a" + string(make([]byte, 63)), true},
|
{"too long", "a" + string(make([]byte, 63)), true},
|
||||||
@@ -49,12 +36,7 @@ func TestValidateAppName(t *testing.T) {
|
|||||||
{"starts with hyphen", "-myapp", true},
|
{"starts with hyphen", "-myapp", true},
|
||||||
{"ends with hyphen", "myapp-", true},
|
{"ends with hyphen", "myapp-", true},
|
||||||
{"underscore", "my_app", true},
|
{"underscore", "my_app", true},
|
||||||
{"two dots in a row", "a..b", true},
|
{"dot", "my.app", true},
|
||||||
{"starts with dot", ".a", true},
|
|
||||||
{"ends with dot", "a.", true},
|
|
||||||
{"only dots", "..", true},
|
|
||||||
{"hyphen before dot", "a-.b", true},
|
|
||||||
{"hyphen after dot", "a.-b", true},
|
|
||||||
{"slash", "my/app", true},
|
{"slash", "my/app", true},
|
||||||
{"path traversal", "../etc/passwd", true},
|
{"path traversal", "../etc/passwd", true},
|
||||||
{"special chars", "app@name!", true},
|
{"special chars", "app@name!", true},
|
||||||
@@ -72,42 +54,3 @@ func TestValidateAppName(t *testing.T) {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestValidateAppNameErrorMentionsDots(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
err := validateAppName("a..b")
|
|
||||||
|
|
||||||
require.ErrorIs(t, err, errAppNamePattern)
|
|
||||||
assert.Contains(t, err.Error(), "dots")
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestAppFormsCheckAppNameLikeServer checks that the name field on the new
|
|
||||||
// and edit app forms has the server's pattern and length limits, and that
|
|
||||||
// its hint mentions dots.
|
|
||||||
func TestAppFormsCheckAppNameLikeServer(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
pattern := strings.TrimSuffix(strings.TrimPrefix(validAppNameRe.String(), "^"), "$")
|
|
||||||
|
|
||||||
pages := map[string]map[string]any{
|
|
||||||
"app_new.html": {},
|
|
||||||
"app_edit.html": {dataKeyApp: &models.App{}},
|
|
||||||
}
|
|
||||||
|
|
||||||
for page, data := range pages {
|
|
||||||
var out bytes.Buffer
|
|
||||||
|
|
||||||
require.NoError(t, templates.GetParsed().ExecuteTemplate(&out, page, data))
|
|
||||||
|
|
||||||
// The name field and its hint, up to the end of their div.
|
|
||||||
_, field, found := strings.Cut(out.String(), `id="name"`)
|
|
||||||
require.True(t, found, page)
|
|
||||||
|
|
||||||
field, _, _ = strings.Cut(field, "</div>")
|
|
||||||
assert.Contains(t, field, `pattern="`+pattern+`"`, page)
|
|
||||||
assert.Contains(t, field, `minlength="`+strconv.Itoa(appNameMinLength)+`"`, page)
|
|
||||||
assert.Contains(t, field, `maxlength="`+strconv.Itoa(appNameMaxLength)+`"`, page)
|
|
||||||
assert.Contains(t, field, "hyphens, and dots", page)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -109,9 +109,6 @@ func createAppServices(
|
|||||||
})
|
})
|
||||||
require.NoError(t, authErr)
|
require.NoError(t, authErr)
|
||||||
|
|
||||||
// 1 MiB per password hash instead of 64 MiB; see auth.Service.ArgonMemory.
|
|
||||||
authSvc.ArgonMemory = 1024
|
|
||||||
|
|
||||||
appSvc, appErr := app.New(fx.Lifecycle(nil), app.ServiceParams{
|
appSvc, appErr := app.New(fx.Lifecycle(nil), app.ServiceParams{
|
||||||
Logger: logInstance,
|
Logger: logInstance,
|
||||||
Database: dbInstance,
|
Database: dbInstance,
|
||||||
|
|||||||
@@ -59,13 +59,6 @@ type ServiceParams struct {
|
|||||||
|
|
||||||
// Service provides authentication functionality.
|
// Service provides authentication functionality.
|
||||||
type Service struct {
|
type Service struct {
|
||||||
// ArgonMemory is the memory each argon2id hash takes, in KiB. New sets
|
|
||||||
// argonMemory, 64 MiB, and upaasd never changes it. Tests lower it, since
|
|
||||||
// many 64 MiB hashes at once under the race detector need more memory
|
|
||||||
// than a 4 GiB build machine has. A hash verifies only with the value it
|
|
||||||
// was made with.
|
|
||||||
ArgonMemory uint32
|
|
||||||
|
|
||||||
log *slog.Logger
|
log *slog.Logger
|
||||||
db *database.Database
|
db *database.Database
|
||||||
store *sessions.CookieStore
|
store *sessions.CookieStore
|
||||||
@@ -84,11 +77,10 @@ func New(_ fx.Lifecycle, params ServiceParams) (*Service, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
return &Service{
|
return &Service{
|
||||||
ArgonMemory: argonMemory,
|
log: params.Logger.Get(),
|
||||||
log: params.Logger.Get(),
|
db: params.Database,
|
||||||
db: params.Database,
|
store: store,
|
||||||
store: store,
|
params: ¶ms,
|
||||||
params: ¶ms,
|
|
||||||
}, nil
|
}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -105,7 +97,7 @@ func (svc *Service) HashPassword(password string) (string, error) {
|
|||||||
[]byte(password),
|
[]byte(password),
|
||||||
salt,
|
salt,
|
||||||
argonTime,
|
argonTime,
|
||||||
svc.ArgonMemory,
|
argonMemory,
|
||||||
argonThreads,
|
argonThreads,
|
||||||
argonKeyLen,
|
argonKeyLen,
|
||||||
)
|
)
|
||||||
@@ -140,7 +132,7 @@ func (svc *Service) VerifyPassword(hashedPassword, password string) bool {
|
|||||||
[]byte(password),
|
[]byte(password),
|
||||||
salt,
|
salt,
|
||||||
argonTime,
|
argonTime,
|
||||||
svc.ArgonMemory,
|
argonMemory,
|
||||||
argonThreads,
|
argonThreads,
|
||||||
argonKeyLen,
|
argonKeyLen,
|
||||||
)
|
)
|
||||||
|
|||||||
@@ -65,10 +65,6 @@ func setupTestService(t *testing.T) (*auth.Service, func()) {
|
|||||||
})
|
})
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
// 1 MiB per hash instead of 64 MiB; see Service.ArgonMemory. The tests
|
|
||||||
// that use setupAuthService keep 64 MiB.
|
|
||||||
svc.ArgonMemory = 1024
|
|
||||||
|
|
||||||
// t.TempDir() automatically cleans up after test
|
// t.TempDir() automatically cleans up after test
|
||||||
cleanup := func() {}
|
cleanup := func() {}
|
||||||
|
|
||||||
@@ -241,21 +237,6 @@ func TestVerifyPassword(testingT *testing.T) {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
// TestHashPasswordWithUpaasdMemory hashes and verifies a password with the
|
|
||||||
// memory New sets, which upaasd uses. setupTestService lowers it.
|
|
||||||
func TestHashPasswordWithUpaasdMemory(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
svc := setupAuthService(t, false)
|
|
||||||
require.Equal(t, uint32(64*1024), svc.ArgonMemory)
|
|
||||||
|
|
||||||
hash, err := svc.HashPassword("correctpassword")
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
assert.True(t, svc.VerifyPassword(hash, "correctpassword"))
|
|
||||||
assert.False(t, svc.VerifyPassword(hash, "wrongpassword"))
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestIsSetupRequired(testingT *testing.T) {
|
func TestIsSetupRequired(testingT *testing.T) {
|
||||||
testingT.Parallel()
|
testingT.Parallel()
|
||||||
|
|
||||||
|
|||||||
@@ -1,121 +0,0 @@
|
|||||||
package deploy_test
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"log/slog"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"net/url"
|
|
||||||
"os"
|
|
||||||
"slices"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/distribution/reference"
|
|
||||||
"github.com/docker/docker/daemon/names"
|
|
||||||
"github.com/stretchr/testify/assert"
|
|
||||||
"github.com/stretchr/testify/require"
|
|
||||||
|
|
||||||
"sneak.berlin/go/upaas/internal/database"
|
|
||||||
"sneak.berlin/go/upaas/internal/globals"
|
|
||||||
"sneak.berlin/go/upaas/internal/handlers"
|
|
||||||
"sneak.berlin/go/upaas/internal/logger"
|
|
||||||
"sneak.berlin/go/upaas/internal/models"
|
|
||||||
"sneak.berlin/go/upaas/internal/service/app"
|
|
||||||
)
|
|
||||||
|
|
||||||
// TestDeployAppWithDotInName creates an app named sneak.berlin through the
|
|
||||||
// new app form, as a user does, then builds and deploys it against a fake
|
|
||||||
// Docker API and checks that Docker accepts the names of the image it
|
|
||||||
// builds and of the container it runs, using Docker's own rules for each.
|
|
||||||
func TestDeployAppWithDotInName(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
api := &fakeImageAPI{
|
|
||||||
images: map[string][]string{},
|
|
||||||
shortSHA: "abc1234",
|
|
||||||
nextID: "sha256:built",
|
|
||||||
}
|
|
||||||
svc, db := newImageTestService(t, api)
|
|
||||||
ctx := context.Background()
|
|
||||||
|
|
||||||
createdApp := createAppWithForm(t, db, "sneak.berlin")
|
|
||||||
|
|
||||||
deployment := models.NewDeployment(db)
|
|
||||||
deployment.AppID = createdApp.ID
|
|
||||||
require.NoError(t, deployment.Save(ctx))
|
|
||||||
|
|
||||||
imageID, err := svc.BuildImage(ctx, createdApp, deployment)
|
|
||||||
require.NoError(t, err)
|
|
||||||
require.NoError(t, svc.DeployContainer(ctx, createdApp, deployment, imageID))
|
|
||||||
|
|
||||||
images, _ := api.state()
|
|
||||||
|
|
||||||
api.mu.Lock()
|
|
||||||
containers := slices.Clone(api.containers)
|
|
||||||
api.mu.Unlock()
|
|
||||||
|
|
||||||
require.Equal(t, map[string][]string{
|
|
||||||
"sha256:built": {"upaas-sneak.berlin:abc1234"},
|
|
||||||
}, images)
|
|
||||||
|
|
||||||
_, err = reference.ParseNormalizedNamed("upaas-sneak.berlin:abc1234")
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
require.Equal(t, []string{"upaas-sneak.berlin"}, containers)
|
|
||||||
assert.Regexp(t, names.RestrictedNamePattern, containers[0])
|
|
||||||
|
|
||||||
assert.DirExists(t, svc.GetBuildDirExported(createdApp.Name))
|
|
||||||
}
|
|
||||||
|
|
||||||
// createAppWithForm posts the new app form with the given name, which
|
|
||||||
// checks the name as it does for a user, and returns the app it created.
|
|
||||||
func createAppWithForm(
|
|
||||||
t *testing.T,
|
|
||||||
db *database.Database,
|
|
||||||
name string,
|
|
||||||
) *models.App {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
log := logger.NewForTest(slog.New(slog.NewTextHandler(os.Stderr, nil)))
|
|
||||||
|
|
||||||
appSvc, err := app.New(nil, app.ServiceParams{Logger: log, Database: db})
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
globalInstance, err := globals.New(nil)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
handlersInstance, err := handlers.New(nil, handlers.Params{
|
|
||||||
Logger: log,
|
|
||||||
Globals: globalInstance,
|
|
||||||
Database: db,
|
|
||||||
App: appSvc,
|
|
||||||
})
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
form := url.Values{
|
|
||||||
"name": {name},
|
|
||||||
"repo_url": {"git@example.com:sneak/" + name + ".git"},
|
|
||||||
}
|
|
||||||
request := httptest.NewRequestWithContext(
|
|
||||||
t.Context(), http.MethodPost, "/apps", strings.NewReader(form.Encode()),
|
|
||||||
)
|
|
||||||
request.Header.Set("Content-Type", "application/x-www-form-urlencoded")
|
|
||||||
|
|
||||||
recorder := httptest.NewRecorder()
|
|
||||||
|
|
||||||
handlersInstance.HandleAppCreate().ServeHTTP(recorder, request)
|
|
||||||
|
|
||||||
// The form redirects to the new app's page; it shows the form again,
|
|
||||||
// with the error, when it refuses the name.
|
|
||||||
require.Equal(t, http.StatusSeeOther, recorder.Code, recorder.Body.String())
|
|
||||||
|
|
||||||
appID, found := strings.CutPrefix(recorder.Header().Get("Location"), "/apps/")
|
|
||||||
require.True(t, found)
|
|
||||||
|
|
||||||
createdApp, err := models.FindApp(t.Context(), db, appID)
|
|
||||||
require.NoError(t, err)
|
|
||||||
require.NotNil(t, createdApp)
|
|
||||||
|
|
||||||
return createdApp
|
|
||||||
}
|
|
||||||
@@ -35,13 +35,12 @@ import (
|
|||||||
// an image's last tag, or an untagged image by its ID, deletes the image.
|
// an image's last tag, or an untagged image by its ID, deletes the image.
|
||||||
// It also answers the steps of a git clone that reports shortSHA.
|
// It also answers the steps of a git clone that reports shortSHA.
|
||||||
type fakeImageAPI struct {
|
type fakeImageAPI struct {
|
||||||
mu sync.Mutex
|
mu sync.Mutex
|
||||||
images map[string][]string // image ID -> tags
|
images map[string][]string // image ID -> tags
|
||||||
shortSHA string // the commit's short hash the clone reports
|
shortSHA string // the commit's short hash the clone reports
|
||||||
nextID string // ID of the image the next build creates
|
nextID string // ID of the image the next build creates
|
||||||
removed []string // each tag or ID removed
|
removed []string // each tag or ID removed
|
||||||
forced bool // whether a removal was forced
|
forced bool // whether a removal was forced
|
||||||
containers []string // name of each named container created
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (api *fakeImageAPI) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
func (api *fakeImageAPI) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
||||||
@@ -68,11 +67,6 @@ func (api *fakeImageAPI) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
|||||||
case strings.HasSuffix(r.URL.Path, "/version"):
|
case strings.HasSuffix(r.URL.Path, "/version"):
|
||||||
_, _ = w.Write([]byte(`{"Version":"27.3.1","ApiVersion":"1.47"}`))
|
_, _ = w.Write([]byte(`{"Version":"27.3.1","ApiVersion":"1.47"}`))
|
||||||
case strings.HasSuffix(r.URL.Path, "/containers/create"):
|
case strings.HasSuffix(r.URL.Path, "/containers/create"):
|
||||||
// The git clone's container has no name; the app's has.
|
|
||||||
if containerName := r.URL.Query().Get("name"); containerName != "" {
|
|
||||||
api.containers = append(api.containers, containerName)
|
|
||||||
}
|
|
||||||
|
|
||||||
_, _ = w.Write([]byte(`{"Id":"gitcontainer"}`))
|
_, _ = w.Write([]byte(`{"Id":"gitcontainer"}`))
|
||||||
case strings.HasSuffix(r.URL.Path, "/logs"):
|
case strings.HasSuffix(r.URL.Path, "/logs"):
|
||||||
writeCloneOutput(w, api.shortSHA)
|
writeCloneOutput(w, api.shortSHA)
|
||||||
|
|||||||
@@ -113,16 +113,6 @@ func (svc *Service) BuildImage(
|
|||||||
return svc.buildImage(ctx, app, deployment)
|
return svc.buildImage(ctx, app, deployment)
|
||||||
}
|
}
|
||||||
|
|
||||||
// DeployContainer exposes deployContainerWithTimeout for testing.
|
|
||||||
func (svc *Service) DeployContainer(
|
|
||||||
ctx context.Context,
|
|
||||||
app *models.App,
|
|
||||||
deployment *models.Deployment,
|
|
||||||
imageID docker.ImageID,
|
|
||||||
) error {
|
|
||||||
return svc.deployContainerWithTimeout(ctx, app, deployment, imageID)
|
|
||||||
}
|
|
||||||
|
|
||||||
// BuildContainerOptionsExported exposes buildContainerOptions for testing.
|
// BuildContainerOptionsExported exposes buildContainerOptions for testing.
|
||||||
func (svc *Service) BuildContainerOptionsExported(
|
func (svc *Service) BuildContainerOptionsExported(
|
||||||
ctx context.Context,
|
ctx context.Context,
|
||||||
|
|||||||
@@ -30,12 +30,10 @@
|
|||||||
name="name"
|
name="name"
|
||||||
value="{{.App.Name}}"
|
value="{{.App.Name}}"
|
||||||
required
|
required
|
||||||
minlength="2"
|
pattern="[a-z0-9-]+"
|
||||||
maxlength="63"
|
|
||||||
pattern="[a-z0-9]+((\.|-+)[a-z0-9]+)*"
|
|
||||||
class="input"
|
class="input"
|
||||||
>
|
>
|
||||||
<p class="text-sm text-gray-500 mt-1">Lowercase letters, numbers, hyphens, and dots, such as my-app or example.com</p>
|
<p class="text-sm text-gray-500 mt-1">Lowercase letters, numbers, and hyphens only</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="form-group">
|
<div class="form-group">
|
||||||
|
|||||||
@@ -30,13 +30,11 @@
|
|||||||
name="name"
|
name="name"
|
||||||
value="{{.Name}}"
|
value="{{.Name}}"
|
||||||
required
|
required
|
||||||
minlength="2"
|
pattern="[a-z0-9-]+"
|
||||||
maxlength="63"
|
|
||||||
pattern="[a-z0-9]+((\.|-+)[a-z0-9]+)*"
|
|
||||||
class="input"
|
class="input"
|
||||||
placeholder="my-app"
|
placeholder="my-app"
|
||||||
>
|
>
|
||||||
<p class="text-sm text-gray-500 mt-1">Lowercase letters, numbers, hyphens, and dots, such as my-app or example.com</p>
|
<p class="text-sm text-gray-500 mt-1">Lowercase letters, numbers, and hyphens only</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="form-group">
|
<div class="form-group">
|
||||||
|
|||||||
Reference in New Issue
Block a user