test_oc_csr_approve.py 6.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184
  1. import os
  2. import sys
  3. import pytest
  4. from ansible.module_utils.basic import AnsibleModule
  5. try:
  6. # python3, mock is built in.
  7. from unittest.mock import patch
  8. except ImportError:
  9. # In python2, mock is installed via pip.
  10. from mock import patch
  11. MODULE_PATH = os.path.realpath(os.path.join(__file__, os.pardir, os.pardir, 'library'))
  12. sys.path.insert(1, MODULE_PATH)
  13. import oc_csr_approve # noqa
  14. # base path for text files with sample outputs.
  15. ASSET_PATH = os.path.realpath(os.path.join(__file__, os.pardir, 'test_data'))
  16. RUN_CMD_MOCK = 'ansible.module_utils.basic.AnsibleModule.run_command'
  17. class DummyModule(AnsibleModule):
  18. def _load_params(self):
  19. self.params = {}
  20. def exit_json(*args, **kwargs):
  21. return 0
  22. def fail_json(*args, **kwargs):
  23. raise Exception(kwargs['msg'])
  24. def test_parse_subject_cn():
  25. subject = 'subject=/C=US/CN=fedora1.openshift.io/L=Raleigh/O=Red Hat/ST=North Carolina/OU=OpenShift\n'
  26. assert oc_csr_approve.parse_subject_cn(subject) == 'fedora1.openshift.io'
  27. subject = 'subject=C = US, CN = test.io, L = City, O = Company, ST = State, OU = Dept\n'
  28. assert oc_csr_approve.parse_subject_cn(subject) == 'test.io'
  29. def test_get_ready_nodes():
  30. output_file = os.path.join(ASSET_PATH, 'oc_get_nodes.json')
  31. with open(output_file) as stdoutfile:
  32. oc_get_nodes_stdout = stdoutfile.read()
  33. module = DummyModule({})
  34. with patch(RUN_CMD_MOCK) as call_mock:
  35. call_mock.return_value = (0, oc_get_nodes_stdout, '')
  36. ready_nodes = oc_csr_approve.get_ready_nodes(module, 'oc', '/dev/null')
  37. assert ready_nodes == ['fedora1.openshift.io', 'fedora3.openshift.io']
  38. def test_get_csrs():
  39. module = DummyModule({})
  40. output_file = os.path.join(ASSET_PATH, 'oc_csr_approve_pending.json')
  41. with open(output_file) as stdoutfile:
  42. oc_get_csr_out = stdoutfile.read()
  43. # mock oc get csr call to cluster
  44. with patch(RUN_CMD_MOCK) as call_mock:
  45. call_mock.return_value = (0, oc_get_csr_out, '')
  46. csrs = oc_csr_approve.get_csrs(module, 'oc', '/dev/null')
  47. assert csrs[0]['kind'] == "CertificateSigningRequest"
  48. output_file = os.path.join(ASSET_PATH, 'openssl1.txt')
  49. with open(output_file) as stdoutfile:
  50. openssl_out = stdoutfile.read()
  51. # mock openssl req call.
  52. node_list = ['fedora2.mguginolocal.com']
  53. with patch(RUN_CMD_MOCK) as call_mock:
  54. call_mock.return_value = (0, openssl_out, '')
  55. csr_dict = oc_csr_approve.process_csrs(module, csrs, node_list, "client")
  56. # actually run openssl req call.
  57. csr_dict = oc_csr_approve.process_csrs(module, csrs, node_list, "client")
  58. assert csr_dict['node-csr-TkefytQp8Dz4Xp7uzcw605MocvI0gWuEOGNrHhOjGNQ'] == 'fedora2.mguginolocal.com'
  59. def test_confirm_needed_requests_present():
  60. module = DummyModule({})
  61. csr_dict = {'some-csr': 'fedora1.openshift.io'}
  62. not_ready_nodes = ['host1']
  63. with pytest.raises(Exception) as err:
  64. oc_csr_approve.confirm_needed_requests_present(
  65. module, not_ready_nodes, csr_dict)
  66. assert 'Exception: Could not find csr for nodes: host1' in str(err)
  67. not_ready_nodes = ['fedora1.openshift.io']
  68. # this should complete silently
  69. oc_csr_approve.confirm_needed_requests_present(
  70. module, not_ready_nodes, csr_dict)
  71. def test_approve_csrs():
  72. module = DummyModule({})
  73. oc_bin = 'oc'
  74. oc_conf = '/dev/null'
  75. csr_dict = {'csr-1': 'example.openshift.io'}
  76. with patch(RUN_CMD_MOCK) as call_mock:
  77. call_mock.return_value = (0, 'csr-1 ok', '')
  78. client_approve_results = oc_csr_approve.approve_csrs(
  79. module, oc_bin, oc_conf, csr_dict, 'client')
  80. assert client_approve_results == ['csr-1 ok']
  81. def test_get_ready_nodes_server():
  82. module = DummyModule({})
  83. oc_bin = 'oc'
  84. oc_conf = '/dev/null'
  85. nodes_list = ['fedora1.openshift.io']
  86. with patch(RUN_CMD_MOCK) as call_mock:
  87. call_mock.return_value = (0, 'ok', '')
  88. ready_nodes_server = oc_csr_approve.get_ready_nodes_server(
  89. module, oc_bin, oc_conf, nodes_list)
  90. assert ready_nodes_server == ['fedora1.openshift.io']
  91. def test_get_csrs_server():
  92. module = DummyModule({})
  93. output_file = os.path.join(ASSET_PATH, 'oc_csr_server_multiple_pends_one_host.json')
  94. with open(output_file) as stdoutfile:
  95. oc_get_csr_out = stdoutfile.read()
  96. # mock oc get csr call to cluster
  97. with patch(RUN_CMD_MOCK) as call_mock:
  98. call_mock.return_value = (0, oc_get_csr_out, '')
  99. csrs = oc_csr_approve.get_csrs(module, 'oc', '/dev/null')
  100. assert csrs[0]['kind'] == "CertificateSigningRequest"
  101. output_file = os.path.join(ASSET_PATH, 'openssl1.txt')
  102. with open(output_file) as stdoutfile:
  103. openssl_out = stdoutfile.read()
  104. node_list = ['fedora1.openshift.io']
  105. # mock openssl req call.
  106. with patch(RUN_CMD_MOCK) as call_mock:
  107. call_mock.return_value = (0, openssl_out, '')
  108. csr_dict = oc_csr_approve.process_csrs(module, csrs, node_list, "server")
  109. # actually run openssl req call.
  110. node_list = ['fedora2.mguginolocal.com']
  111. csr_dict = oc_csr_approve.process_csrs(module, csrs, node_list, "server")
  112. assert csr_dict['csr-2cxkp'] == 'fedora2.mguginolocal.com'
  113. def test_verify_server_csrs():
  114. module = DummyModule({})
  115. oc_bin = 'oc'
  116. oc_conf = '/dev/null'
  117. result = {}
  118. ready_nodes_server = ['fedora1.openshift.io']
  119. node_list = ['fedora1.openshift.io']
  120. with patch('oc_csr_approve.get_ready_nodes_server') as call_mock:
  121. call_mock.return_value = ready_nodes_server
  122. # This should silently return
  123. oc_csr_approve.verify_server_csrs(module, result, oc_bin, oc_conf,
  124. node_list)
  125. node_list = ['fedora1.openshift.io', 'fedora2.openshift.io']
  126. with patch('oc_csr_approve.get_ready_nodes_server') as call_mock:
  127. call_mock.return_value = ready_nodes_server
  128. with pytest.raises(Exception) as err:
  129. oc_csr_approve.verify_server_csrs(module, result, oc_bin, oc_conf,
  130. node_list)
  131. assert 'after approving server certs: fedora2.openshift.io' in str(err)
  132. if __name__ == '__main__':
  133. test_parse_subject_cn()
  134. test_get_ready_nodes()
  135. test_get_csrs()
  136. test_confirm_needed_requests_present()
  137. test_approve_csrs()
  138. test_get_ready_nodes_server()
  139. test_get_csrs_server()
  140. test_verify_server_csrs()