feat: update topology test to use v2.0 images #141
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Copyright AGNTCY Contributors (https://github.com/agntcy) | |
| # SPDX-License-Identifier: Apache-2.0 | |
| # | |
| # KinD multicluster + ingress LoadBalancer (cloud-provider-kind) + Helm stack via Task. | |
| # Pulls published slim images and OCI Helm charts; slimctl from GitHub releases. | |
| name: test-slim-multicluster-private | |
| on: | |
| push: | |
| branches: | |
| - main | |
| pull_request: | |
| workflow_dispatch: | |
| inputs: | |
| override_slim_image_tag: | |
| description: "Override Slim data-plane image tag" | |
| required: false | |
| default: "" | |
| override_slim_controller_image_tag: | |
| description: "Override Slim control-plane image tag" | |
| required: false | |
| default: "" | |
| override_slim_chart_version: | |
| description: "Override slim Helm chart version (oci://ghcr.io/agntcy/slim/helm/slim)" | |
| required: false | |
| default: "" | |
| override_slim_control_plane_chart_version: | |
| description: "Override slim-control-plane Helm chart version" | |
| required: false | |
| default: "" | |
| override_slim_spire_chart_version: | |
| description: "Override slim-spire Helm chart version" | |
| required: false | |
| default: "" | |
| slimctl_version: | |
| description: "slimctl release version (e.g. 1.4.0)" | |
| required: false | |
| default: "1.4.0" | |
| permissions: | |
| contents: read | |
| packages: read | |
| defaults: | |
| run: | |
| working-directory: kind-slim-multi-host | |
| jobs: | |
| detect: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| should-run: ${{ steps.detect-suite.outputs.should-run }} | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - id: detect-suite | |
| uses: ./.github/actions/detect-suite-changes | |
| with: | |
| suite: slim-multicluster-private | |
| multicluster: | |
| needs: detect | |
| if: ${{ github.event_name == 'workflow_dispatch' || needs.detect.outputs.should-run == 'true' }} | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 90 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Resolve slim image and chart versions | |
| id: resolve-slim-versions | |
| shell: bash | |
| working-directory: ${{ github.workspace }} | |
| run: | | |
| set -euo pipefail | |
| if [ -n "${{ inputs.override_slim_image_tag }}" ]; then | |
| slim_tag="${{ inputs.override_slim_image_tag }}" | |
| else | |
| slim_tag="1.4.0" | |
| fi | |
| if [ -n "${{ inputs.override_slim_controller_image_tag }}" ]; then | |
| controller_tag="${{ inputs.override_slim_controller_image_tag }}" | |
| else | |
| controller_tag="1.4.0" | |
| fi | |
| if [ -n "${{ inputs.override_slim_chart_version }}" ]; then | |
| slim_chart_version="${{ inputs.override_slim_chart_version }}" | |
| else | |
| slim_chart_version="v1.4.0" | |
| fi | |
| if [ -n "${{ inputs.override_slim_control_plane_chart_version }}" ]; then | |
| ctrl_chart_version="${{ inputs.override_slim_control_plane_chart_version }}" | |
| else | |
| ctrl_chart_version="v1.4.0" | |
| fi | |
| if [ -n "${{ inputs.override_slim_spire_chart_version }}" ]; then | |
| slim_spire_chart_version="${{ inputs.override_slim_spire_chart_version }}" | |
| else | |
| slim_spire_chart_version="v1.4.0" | |
| fi | |
| if [ -n "${{ inputs.slimctl_version }}" ]; then | |
| slimctl_version="${{ inputs.slimctl_version }}" | |
| else | |
| slimctl_version="1.4.0" | |
| fi | |
| echo "slim_tag=${slim_tag}" >> "$GITHUB_OUTPUT" | |
| echo "controller_tag=${controller_tag}" >> "$GITHUB_OUTPUT" | |
| echo "slim_chart_version=${slim_chart_version}" >> "$GITHUB_OUTPUT" | |
| echo "ctrl_chart_version=${ctrl_chart_version}" >> "$GITHUB_OUTPUT" | |
| echo "slim_spire_chart_version=${slim_spire_chart_version}" >> "$GITHUB_OUTPUT" | |
| echo "slimctl_version=${slimctl_version}" >> "$GITHUB_OUTPUT" | |
| - name: Login to GitHub Container Registry | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Pull slim images from GHCR | |
| shell: bash | |
| working-directory: ${{ github.workspace }} | |
| env: | |
| SLIM_TAG: ${{ steps.resolve-slim-versions.outputs.slim_tag }} | |
| CTRL_TAG: ${{ steps.resolve-slim-versions.outputs.controller_tag }} | |
| run: | | |
| set -euo pipefail | |
| docker pull "ghcr.io/agntcy/slim:${SLIM_TAG}" | |
| docker pull "ghcr.io/agntcy/slim/control-plane:${CTRL_TAG}" | |
| - name: Setup Kubernetes tooling | |
| uses: ./.github/actions/setup-k8s | |
| with: | |
| kind-version: "0.24.0" | |
| helm-version: "3.14.4" | |
| - name: Install slimctl | |
| id: install-slimctl | |
| shell: bash | |
| working-directory: ${{ github.workspace }} | |
| env: | |
| SLIMCTL_VERSION: ${{ steps.resolve-slim-versions.outputs.slimctl_version }} | |
| run: | | |
| set -euo pipefail | |
| tarball="slimctl-linux-amd64-gnu.tar.gz" | |
| curl -fsSL -LO "https://github.com/agntcy/slim/releases/download/slimctl-v${SLIMCTL_VERSION}/${tarball}" | |
| tar -xzf "${tarball}" | |
| mkdir -p "${HOME}/.local/bin" | |
| install -m 0755 slimctl "${HOME}/.local/bin/slimctl" | |
| "${HOME}/.local/bin/slimctl" --help | head -1 | |
| echo "path=${HOME}/.local/bin/slimctl" >> "$GITHUB_OUTPUT" | |
| - name: Set up Go | |
| uses: actions/setup-go@v5 | |
| with: | |
| go-version: "1.23.x" | |
| - name: Install Task | |
| uses: go-task/setup-task@v2 | |
| with: | |
| version: 3.41.0 | |
| repo-token: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Task prereq | |
| run: task prereq | |
| - name: Install dnsutils | |
| run: sudo apt-get update && sudo apt-get install -y dnsutils | |
| - name: Task cluster:up (KinD clusters) | |
| run: task cluster:up | |
| - name: Load slim images into both KinD clusters | |
| shell: bash | |
| working-directory: ${{ github.workspace }} | |
| env: | |
| SLIM_TAG: ${{ steps.resolve-slim-versions.outputs.slim_tag }} | |
| CTRL_TAG: ${{ steps.resolve-slim-versions.outputs.controller_tag }} | |
| run: | | |
| set -euo pipefail | |
| for cluster in csit-a csit-b; do | |
| kind load docker-image "ghcr.io/agntcy/slim:${SLIM_TAG}" --name "${cluster}" | |
| kind load docker-image "ghcr.io/agntcy/slim/control-plane:${CTRL_TAG}" --name "${cluster}" | |
| done | |
| - name: Install ingress stack and Helm apps | |
| env: | |
| SLIM_IMAGE_TAG: ${{ steps.resolve-slim-versions.outputs.slim_tag }} | |
| CTRL_IMAGE_TAG: ${{ steps.resolve-slim-versions.outputs.controller_tag }} | |
| SLIMCTL_PATH: ${{ steps.install-slimctl.outputs.path }} | |
| run: | | |
| set -euo pipefail | |
| task \ | |
| SLIM_CHART_VERSION="${{ steps.resolve-slim-versions.outputs.slim_chart_version }}" \ | |
| CTRL_CHART_VERSION="${{ steps.resolve-slim-versions.outputs.ctrl_chart_version }}" \ | |
| SLIM_SPIRE_CHART_VERSION="${{ steps.resolve-slim-versions.outputs.slim_spire_chart_version }}" \ | |
| stack:install | |
| - name: Verify clusters | |
| run: | | |
| set -euo pipefail | |
| kubectl --context kind-csit-a get nodes | |
| kubectl --context kind-csit-b get nodes | |
| kubectl --context kind-csit-a -n ingress-nginx get pods | |
| - name: Verify ingress LoadBalancer on cluster A | |
| run: | | |
| set -euo pipefail | |
| test "$(kubectl --context kind-csit-a get svc ingress-nginx-controller -n ingress-nginx -o jsonpath='{.spec.type}')" = "LoadBalancer" | |
| - name: Verify CoreDNS cross-cluster alias on cluster B | |
| run: | | |
| set -euo pipefail | |
| kubectl --context kind-csit-b get configmap coredns -n kube-system -o jsonpath='{.data.Corefile}' | grep -q "BEGIN csit-cross-cluster" | |
| - name: Verify legacy csit.peer absent | |
| run: | | |
| set -euo pipefail | |
| for ctx in kind-csit-a kind-csit-b; do | |
| if kubectl --context "$ctx" get configmap coredns -n kube-system -o jsonpath='{.data.Corefile}' | grep -q "BEGIN csit-peer"; then | |
| echo "ERROR: legacy csit-peer block still present on $ctx" >&2 | |
| exit 1 | |
| fi | |
| done | |
| - name: Verify host DNS helper | |
| run: ./scripts/verify-local-dns-helper.sh | |
| - name: Verify DNS resolution (cluster B → controller hostname) | |
| run: | | |
| set -euo pipefail | |
| source .gen/ingress-a.env | |
| kubectl --context kind-csit-b run dns-verify-b \ | |
| -n default \ | |
| --rm \ | |
| --attach \ | |
| --restart=Never \ | |
| --image=docker.io/library/busybox:1.36 \ | |
| --command -- \ | |
| sh -c "nslookup control.cluster-a.csit.test | grep -F '${INGRESS_A_LB_IP}'" | |
| - name: Verify Helm releases (optional apps) | |
| run: | | |
| set -euo pipefail | |
| helm list --kube-context kind-csit-a --namespace admin | grep -q slim-control | |
| helm list --kube-context kind-csit-a --namespace cluster-a | grep -q agntcy-cluster-a | |
| helm list --kube-context kind-csit-b --namespace cluster-b | grep -q agntcy-cluster-b | |
| - name: Write verification summary report | |
| if: always() | |
| shell: bash | |
| working-directory: ${{ github.workspace }} | |
| run: | | |
| set -euo pipefail | |
| REPORT_DIR="integrations/agntcy-slim/multicluster-private/reports" | |
| mkdir -p "$REPORT_DIR" | |
| cat > "$REPORT_DIR/summary.html" <<HTML | |
| <!doctype html> | |
| <html lang="en"> | |
| <head> | |
| <meta charset="utf-8"> | |
| <title>Slim multicluster private verification</title> | |
| </head> | |
| <body> | |
| <h1>Slim multicluster private verification</h1> | |
| <ul> | |
| <li>Workflow: ${GITHUB_WORKFLOW}</li> | |
| <li>Run: ${GITHUB_RUN_ID}</li> | |
| <li>SHA: ${GITHUB_SHA}</li> | |
| <li>Ref: ${GITHUB_REF}</li> | |
| </ul> | |
| <p>Verification steps completed for KinD clusters csit-a and csit-b.</p> | |
| </body> | |
| </html> | |
| HTML | |
| - name: Teardown full stack | |
| if: always() | |
| run: task stack:down || true | |
| - name: Upload multicluster private test report | |
| if: always() | |
| uses: ./.github/actions/create-artifact | |
| with: | |
| artifact-name: slim-multicluster-private-test-result | |
| path-to-archive: integrations/agntcy-slim/multicluster-private/reports/ | |
| publish-pages: | |
| needs: [multicluster] | |
| if: always() && github.ref == 'refs/heads/main' && needs.multicluster.result != 'skipped' | |
| runs-on: ubuntu-latest | |
| concurrency: | |
| group: test-report-pages | |
| cancel-in-progress: false | |
| permissions: | |
| contents: write | |
| actions: read | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: ./.github/actions/publish-test-reports-pages | |
| with: | |
| suite: slim-multicluster-private | |
| source-run-id: ${{ github.run_id }} |