Skip to content

Commit 77226d4

Browse files
committed
test(showcase): update integration tests to use Showcase Auto-TLS mode
TAG=agy CONV=385b9ab5-874c-4c9a-b331-66dab51fef61
1 parent afc05d1 commit 77226d4

3 files changed

Lines changed: 49 additions & 20 deletions

File tree

‎build-with-local-http-client.sh‎

Lines changed: 32 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -56,9 +56,39 @@ else
5656
popd
5757
fi
5858

59+
SHOWCASE_DIR="${SHOWCASE_DIR:-${PARENT_DIR}/gapic-showcase}"
60+
SHOWCASE_BIN="${SHOWCASE_DIR}/gapic-showcase"
61+
62+
if [ -f "${SHOWCASE_BIN}" ]; then
63+
echo "========================================================================="
64+
echo "Starting Showcase TLS server in background..."
65+
echo "========================================================================="
66+
67+
# Start showcase in Auto-TLS mode on port 7470
68+
"${SHOWCASE_BIN}" run \
69+
--port 7470 \
70+
--tls \
71+
--ca-cert-output-file /tmp/showcase-ca.pem > showcase-server.log 2>&1 &
72+
SHOWCASE_PID=$!
73+
74+
# Ensure we kill the background process on script exit
75+
trap "echo 'Stopping Showcase...'; kill ${SHOWCASE_PID} 2>/dev/null || true; wait ${SHOWCASE_PID} 2>/dev/null || true; rm -f /tmp/showcase-ca.pem" EXIT
76+
77+
# Wait a bit for the server to initialize and write the cert
78+
sleep 2
79+
else
80+
echo "========================================================================="
81+
echo "Warning: gapic-showcase binary not found at: ${SHOWCASE_BIN}"
82+
echo "Please ensure Showcase is running manually in TLS mode on port 7470,"
83+
echo "and its CA certificate is written to /tmp/showcase-ca.pem."
84+
echo "========================================================================="
85+
fi
86+
5987
echo "========================================================================="
6088
echo "Building and verifying gapic-showcase with PQC in google-cloud-java..."
6189
echo "========================================================================="
6290

63-
# Run the showcase tests
64-
mvn test -pl java-showcase/gapic-showcase -Dtest=ITPqc
91+
# Run the showcase tests using the secure endpoint and cert path
92+
mvn test -pl java-showcase/gapic-showcase -Dtest=ITPqc \
93+
-Dshowcase.secure.endpoint=localhost:7470 \
94+
-Dshowcase.ca.cert.path=/tmp/showcase-ca.pem

‎java-showcase/gapic-showcase/src/test/java/com/google/showcase/v1beta1/it/ITPqc.java‎

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -18,8 +18,6 @@
1818

1919
import static com.google.common.truth.Truth.assertThat;
2020
import static com.google.common.truth.Truth.assertWithMessage;
21-
import static com.google.showcase.v1beta1.it.util.TestClientInitializer.DEFAULT_GRPC_ENDPOINT;
22-
import static com.google.showcase.v1beta1.it.util.TestClientInitializer.DEFAULT_HTTPJSON_ENDPOINT;
2321

2422
import com.google.api.client.http.javanet.NetHttpTransport;
2523
import com.google.api.gax.core.NoCredentialsProvider;
@@ -115,7 +113,11 @@ public class ITPqc {
115113
private static final String EXPECTED_TLS_VERSION = "TLS 1.3";
116114
private static final String EXPECTED_TLS_CIPHER = "TLS_AES_128_GCM_SHA256";
117115

118-
private static final String DEFAULT_CA_CERT_PATH = "target/showcase-ca.pem";
116+
private static final String DEFAULT_CA_CERT_PATH =
117+
System.getProperty("showcase.ca.cert.path", "target/showcase-ca.pem");
118+
119+
private static final String SECURE_ENDPOINT =
120+
System.getProperty("showcase.secure.endpoint", "localhost:7470");
119121

120122
@BeforeAll
121123
static void setUp() {
@@ -132,7 +134,7 @@ void testGrpcPqc() throws Exception {
132134
ChannelCredentials creds =
133135
TlsChannelCredentials.newBuilder().trustManager(new File(DEFAULT_CA_CERT_PATH)).build();
134136

135-
ManagedChannel channel = Grpc.newChannelBuilder(DEFAULT_GRPC_ENDPOINT, creds).build();
137+
ManagedChannel channel = Grpc.newChannelBuilder(SECURE_ENDPOINT, creds).build();
136138
try {
137139
TransportChannel transportChannel = GrpcTransportChannel.create(channel);
138140

@@ -195,7 +197,7 @@ void testHttpJsonPqc() throws Exception {
195197
InstantiatingHttpJsonChannelProvider transportChannelProvider =
196198
EchoSettings.defaultHttpJsonTransportProviderBuilder()
197199
.setHttpTransport(transport)
198-
.setEndpoint(DEFAULT_HTTPJSON_ENDPOINT.replace("http://", "https://"))
200+
.setEndpoint("https://" + SECURE_ENDPOINT)
199201
.setInterceptorProvider(() -> Collections.singletonList(interceptor))
200202
.build();
201203

@@ -250,7 +252,7 @@ void testHttpJsonPqc_withExplicitSecurityProvider() throws Exception {
250252
InstantiatingHttpJsonChannelProvider transportChannelProvider =
251253
EchoSettings.defaultHttpJsonTransportProviderBuilder()
252254
.setHttpTransport(transport)
253-
.setEndpoint(DEFAULT_HTTPJSON_ENDPOINT.replace("http://", "https://"))
255+
.setEndpoint("https://" + SECURE_ENDPOINT)
254256
.setInterceptorProvider(() -> Collections.singletonList(interceptor))
255257
.build();
256258

‎pqc-verification/README.md‎

Lines changed: 9 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -30,24 +30,21 @@ git checkout feat-pqc-tls
3030
go build ./cmd/gapic-showcase
3131
```
3232

33-
### Step 2.2: Generate TLS Certificates
34-
Generate self-signed testing certificates using `openssl` (saved to `~/pqc-certs`):
35-
```shell
36-
mkdir -p ~/pqc-certs
37-
openssl req -x509 -newkey rsa:4096 -keyout ~/pqc-certs/server.key -out ~/pqc-certs/server.crt -sha256 -days 365 -nodes -subj "/CN=localhost"
38-
openssl x509 -outform pem -in ~/pqc-certs/server.crt -out ~/pqc-certs/ca.crt
39-
```
33+
### Step 2.2: Run the Showcase Server with Auto-TLS (Recommended)
34+
Start the Showcase server in Auto-TLS mode. This automatically generates a CA certificate in-memory at startup and saves it to the target directory:
4035

41-
### Step 2.3: Run the Showcase Server
42-
Start the Showcase server in TLS mode using the generated certificate:
4336
```shell
4437
# Run on secure port 7470
4538
./gapic-showcase run \
46-
--tls-cert ~/pqc-certs/server.crt \
47-
--tls-key ~/pqc-certs/server.key \
48-
--port 7470
39+
--port 7470 \
40+
--tls \
41+
--ca-cert-output-file /tmp/showcase-ca.pem
4942
```
5043

44+
*Note: The helper script `build-with-local-http-client.sh` will automatically launch and clean up this Showcase server if it finds the `gapic-showcase` repository cloned next to the `google-cloud-java` monorepo.*
45+
If running manually, execute the tests using:
46+
`mvn test -pl java-showcase/gapic-showcase -Dtest=ITPqc -Dshowcase.ca.cert.path=/tmp/showcase-ca.pem`
47+
5148
---
5249

5350
## 3. Running Local Verification Tests

0 commit comments

Comments
 (0)