This commit is contained in:
@@ -0,0 +1,54 @@
|
||||
package servicedefaults
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net/netip"
|
||||
"testing"
|
||||
|
||||
"github.com/itworx/pulse/internal/probe"
|
||||
)
|
||||
|
||||
type resolver map[string][]netip.Addr
|
||||
|
||||
func (r resolver) LookupIP(_ context.Context, host string) ([]netip.Addr, error) { return r[host], nil }
|
||||
|
||||
func TestDesiredBuildsBoundedPublicServiceGraph(t *testing.T) {
|
||||
addresses := resolver{"pulse.example": {netip.MustParseAddr("203.0.113.10")}, "auth.example": {netip.MustParseAddr("198.51.100.20")}}
|
||||
seeds, err := desired(context.Background(), Options{PublicURL: "https://pulse.example", OIDCIssuer: "https://auth.example/application/o/pulse/"}, probe.NetworkPolicy{}, addresses)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(seeds) != 2 || len(seeds[0].probes) != 2 || len(seeds[1].probes) != 1 {
|
||||
t.Fatalf("unexpected defaults: %#v", seeds)
|
||||
}
|
||||
if seeds[0].probes[0].target.Path != "/healthz" || seeds[1].probes[0].target.Path != "/application/o/pulse/.well-known/openid-configuration" {
|
||||
t.Fatalf("unexpected targets: %#v %#v", seeds[0].probes[0].target, seeds[1].probes[0].target)
|
||||
}
|
||||
if seeds[0].id == seeds[1].id || seeds[0].id != stableID("service:pulse") {
|
||||
t.Fatal("service identities are not deterministic and distinct")
|
||||
}
|
||||
}
|
||||
|
||||
func TestDesiredRejectsUnsafeOrPartialConfiguration(t *testing.T) {
|
||||
public := resolver{"pulse.example": {netip.MustParseAddr("203.0.113.10")}, "private.example": {netip.MustParseAddr("10.0.0.10")}}
|
||||
tests := []Options{
|
||||
{PublicURL: "https://pulse.example"},
|
||||
{PublicURL: "http://pulse.example", OIDCIssuer: "https://pulse.example"},
|
||||
{PublicURL: "https://user:secret@pulse.example", OIDCIssuer: "https://pulse.example"},
|
||||
{PublicURL: "https://private.example", OIDCIssuer: "https://pulse.example"},
|
||||
{PublicURL: "https://169.254.169.254", OIDCIssuer: "https://pulse.example"},
|
||||
}
|
||||
for _, options := range tests {
|
||||
if _, err := desired(context.Background(), options, probe.NetworkPolicy{}, public); err == nil {
|
||||
t.Fatalf("unsafe configuration was accepted: %#v", options)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestDesiredAllowsExplicitPrivateNetworkOnly(t *testing.T) {
|
||||
private := resolver{"pulse.internal": {netip.MustParseAddr("10.0.0.10")}, "auth.internal": {netip.MustParseAddr("10.0.0.11")}}
|
||||
policy := probe.NetworkPolicy{AllowedNetworks: []netip.Prefix{netip.MustParsePrefix("10.0.0.0/24")}}
|
||||
if _, err := desired(context.Background(), Options{PublicURL: "https://pulse.internal", OIDCIssuer: "https://auth.internal"}, policy, private); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user