-
Notifications
You must be signed in to change notification settings - Fork 1.8k
87 lines (76 loc) · 2.63 KB
/
kube-integration-tests-non-root.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
name: Kube Integration Tests (Non-root)
run-name: Kube Integration Tests (Non-root) - ${{ github.run_id }} - @${{ github.actor }}
on:
push:
branches:
- master
- branch/*
pull_request:
paths:
- '.github/workflows/kube-integration-tests-non-root.yaml'
- '**.go'
- 'go.mod'
- 'go.sum'
- 'build.assets/Makefile'
- 'build.assets/Dockerfile*'
- 'Makefile'
merge_group:
paths:
- '.github/workflows/kube-integration-tests-non-root.yaml'
- '**.go'
- 'go.mod'
- 'go.sum'
- 'build.assets/Makefile'
- 'build.assets/Dockerfile*'
- 'Makefile'
env:
TEST_KUBE: true
KUBECONFIG: /home/.kube/config
jobs:
test:
name: Kube Integration Tests (Non-root)
if: ${{ !startsWith(github.head_ref, 'dependabot/') }}
runs-on: ubuntu-22.04-16core
permissions:
contents: read
packages: read
container:
image: ghcr.io/gravitational/teleport-buildbox:teleport14
env:
WEBASSETS_SKIP_BUILD: 1
options: --cap-add=SYS_ADMIN --privileged
steps:
- name: Checkout Teleport
uses: actions/checkout@v4
- name: Prepare workspace
uses: ./.github/actions/prepare-workspace
- name: Chown
run: |
mkdir -p $(go env GOMODCACHE)
mkdir -p $(go env GOCACHE)
chown -Rf ci:ci ${GITHUB_WORKSPACE} $(go env GOMODCACHE) $(go env GOCACHE)
continue-on-error: true
- name: Create KinD cluster
uses: helm/kind-action@dda0770415bac9fc20092cacbc54aa298604d140 # v1.8.0
with:
cluster_name: kind
config: fixtures/kind/config.yaml
# The current container where tests run isn't linked to the KinD network and
# we won't be able to access the KinD control plane without linking them.
# This step is required because our tests run in teleport-buildbox container
# and by default the KinD container network isn't exposed to it.
# Connecting the network allow us to access the control plane using DNS kind-control-plane.
# It also copies the default kubeconfig and places it in /home/.kube so ci user
# is able to access it.
- name: Link test container to KinD network
run: |
docker network connect kind $(cat /etc/hostname)
kubectl config set-cluster kind-kind --server=https://kind-control-plane:6443
kubectl cluster-info
kubectl apply -f fixtures/ci-teleport-rbac/ci-teleport.yaml
cp -r $HOME/.kube /home/
chown -R ci:ci /home/.kube
- name: Run tests
timeout-minutes: 40
run: |
runuser -u ci -g ci make integration-kube RDPCLIENT_SKIP_BUILD=1