repositories / bugabinga.net
bugabinga.net
personal infrastructure for bugabinga!
owned by admin
scripts/local/test-verify-infra.sh
Raw#!/usr/bin/env bash
set -euo pipefail
repo_root="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
mkdir -p "${repo_root}/.verify-infra-test"
work="$(mktemp -d "${repo_root}/.verify-infra-test/verify-infra-test.XXXXXX")"
trap 'rm -rf -- "${work}"' EXIT
mkdir -p "${work}/scripts/local" "${work}/modules/klops/templates" "${work}/modules/klops/quadlets" "${work}/modules/klops/ci-quadlets" "${work}/services/toad/deploy" "${work}/fake-bin"
cp "${repo_root}/scripts/local/verify-infra.sh" "${work}/scripts/local/verify-infra.sh"
chmod +x "${work}/scripts/local/verify-infra.sh"
for file in backend.tf main.tf outputs.tf providers.tf secrets.tf variables.tf .terraform.lock.hcl modules/klops/main.tf modules/klops/providers.tf modules/klops/toad.tf modules/klops/variables.tf modules/klops/pkg-site.tf; do
mkdir -p "${work}/$(dirname "${file}")"
: >"${work}/${file}"
done
printf 'example.com {\n}\n' >"${work}/modules/klops/templates/Caddyfile.tftpl"
printf '%s\n' "\${luci_ssh_peer_port}" >"${work}/modules/klops/templates/luci.container.tftpl"
printf '%s\n' "\${relay_ipv4} \${relay_ipv6}" >"${work}/modules/klops/templates/ddns.container.tftpl"
printf '%s\n' "\${vcs_ssh_peer_port}" >"${work}/modules/klops/templates/soft-serve.container.tftpl"
printf '[Container]\nImage=example.invalid/test\n' >"${work}/modules/klops/quadlets/caddy.container"
printf '[Network]\n' >"${work}/modules/klops/quadlets/reverse.network"
printf 'fixture\n' >"${work}/modules/klops/ci-quadlets/README.md"
printf '[Container]\nImage=example.invalid/test\n' >"${work}/services/toad/deploy/toad.container"
printf '[Container]\nImage=example.invalid/test\n' >"${work}/services/toad/deploy/toad-ingress.container"
printf '[Network]\n' >"${work}/services/toad/deploy/toad.network"
printf 'example.com {\n}\n' >"${work}/services/toad/deploy/gateway.Caddyfile"
printf 'credential-canary\n' >"${work}/tracked.auto.tfvars"
printf 'credential-canary\n' >"${work}/.env"
cat >"${work}/fake-bin/tofu" <<EOF
#!/usr/bin/env bash
printf '%s|%s|%s|%s|%s\\n' "\$PWD" "\${TF_DATA_DIR:-}" "\${HOME:-}" "\${AWS_ACCESS_KEY_ID:-}" "\$*" >>"${work}/trace"
[[ ! -e tracked.auto.tfvars && ! -e .env ]] || exit 24
[[ ! -e fail-validate.tf || "\$*" != validate ]] || exit 23
EOF
cat >"${work}/fake-bin/caddy" <<'EOF'
#!/usr/bin/env bash
case "$1" in
fmt)
if grep -q unformatted "$2"; then
sed 's/unformatted/formatted/' "$2"
else
cat "$2"
fi
;;
adapt) printf '{}\n' ;;
esac
EOF
cat >"${work}/fake-bin/jq" <<'EOF'
#!/usr/bin/env bash
cat >/dev/null
EOF
cat >"${work}/fake-bin/podman-system-generator" <<EOF
#!/usr/bin/env bash
if [[ -e "\${QUADLET_UNIT_DIRS}/malformed.container" ]]; then
echo 'conversion error: malformed Quadlet' >&2
exit 0
fi
while IFS= read -r -d '' file; do
name="\$(basename "\${file}")"
case "\${name}" in
*.container) unit="\${name%.container}.service" ;;
*.pod) unit="\${name%.pod}-pod.service" ;;
*.network) unit="\${name%.network}-network.service" ;;
*.volume) unit="\${name%.volume}-volume.service" ;;
*.timer) unit="\${name}" ;;
*) continue ;;
esac
printf '%s\\n' "---\${unit}---"
done < <(find "\${QUADLET_UNIT_DIRS}" -type f -print0)
EOF
chmod +x "${work}/fake-bin/"{tofu,caddy,jq,podman-system-generator}
git -C "${work}" init --quiet
git -C "${work}" config user.email test@example.invalid
git -C "${work}" config user.name test
git -C "${work}" add .
git -C "${work}" add -f .env tracked.auto.tfvars
git -C "${work}" commit --quiet -m initial
run_verify() {
(
cd "${work}/modules"
PATH="${work}/fake-bin:${PATH}" \
AWS_ACCESS_KEY_ID=credential-canary \
AWS_SECRET_ACCESS_KEY=credential-canary \
QUADLET_GENERATOR="${work}/fake-bin/podman-system-generator" \
"${work}/scripts/local/verify-infra.sh" "$@"
)
}
expect_failure() {
if "$@" >/dev/null 2>&1; then
echo "expected failure: $*" >&2
exit 1
fi
}
run_verify all
for command in 'version' 'fmt -check -recursive' 'init -backend=false -input=false -lockfile=readonly' validate; do
grep -F "|${command}" "${work}/trace" >/dev/null
done
if grep -Fq credential-canary "${work}/trace"; then
echo "credential environment leaked" >&2
exit 1
fi
while IFS='|' read -r cwd data home _ command; do
[[ -n "${command}" ]] || continue
[[ "${cwd}" == "${work}/.verify-infra/verify-infra."* ]] || {
echo "OpenTofu used wrong working directory: ${cwd}" >&2
exit 1
}
[[ "${data}" == "${work}/.verify-infra/verify-infra."*/tf-data ]] || exit 1
[[ "${home}" == "${work}/.verify-infra/verify-infra."*/home ]] || exit 1
done <"${work}/trace"
[[ ! -e "${work}/.terraform" ]]
if find "${work}/.verify-infra" -mindepth 1 -print -quit | grep -q .; then
echo "verification did not clean up" >&2
exit 1
fi
ln -s /etc/passwd "${work}/modules/klops/quadlets/symlink.container"
git -C "${work}" add modules/klops/quadlets/symlink.container
git -C "${work}" commit --quiet -m symlink
expect_failure run_verify quadlets
rm "${work}/modules/klops/quadlets/symlink.container"
git -C "${work}" add -u
git -C "${work}" commit --quiet -m remove-symlink
mv "${work}/modules/klops/quadlets" "${work}/modules/klops/quadlets-real"
ln -s quadlets-real "${work}/modules/klops/quadlets"
expect_failure run_verify quadlets
rm "${work}/modules/klops/quadlets"
mv "${work}/modules/klops/quadlets-real" "${work}/modules/klops/quadlets"
printf 'unformatted\n' >"${work}/modules/klops/templates/Caddyfile.tftpl"
expect_failure run_verify tofu-route
printf 'example.com {\n}\n' >"${work}/modules/klops/templates/Caddyfile.tftpl"
touch "${work}/untracked.tf"
expect_failure run_verify tofu-route
rm "${work}/untracked.tf"
touch "${work}/fail-validate.tf"
git -C "${work}" add fail-validate.tf
expect_failure run_verify tofu-route
rm "${work}/fail-validate.tf"
if find "${work}/.verify-infra" -mindepth 1 -print -quit | grep -q .; then
echo "failed verification did not clean up" >&2
exit 1
fi
touch "${work}/modules/klops/quadlets/malformed.container"
git -C "${work}" add modules/klops/quadlets/malformed.container
expect_failure run_verify quadlets