Functions have access to secrets/configmaps specified by the user (#399)
This commit solves part of the issue #52 , functions are able to access secrets/configmaps specified by the user. For now, CLI only accept one secret/configmap. For advanced users, it will be able to use YAML to declare multiple secrets/configmaps in later changes.
This commit is contained in:
committed by
Ta-Ching Chen
parent
4cf195768e
commit
1eb0453ce4
+24
-3
@@ -240,6 +240,25 @@ set_environment() {
|
||||
export PATH=$ROOT/fission:$PATH
|
||||
}
|
||||
|
||||
dump_builder_pod_logs() {
|
||||
bns=$1
|
||||
builderPods=$(kubectl -n $bns get pod -o name)
|
||||
|
||||
for p in $builderPods
|
||||
do
|
||||
echo "--- builder pod logs $p ---"
|
||||
containers=$(kubectl -n $bns get $p -o jsonpath={.spec.containers[*].name} --ignore-not-found)
|
||||
for c in $containers
|
||||
do
|
||||
echo "--- builder pod logs $p: container $c ---"
|
||||
kubectl -n $bns logs $p $c || true
|
||||
echo "--- end builder pod logs $p: container $c ---"
|
||||
done
|
||||
echo "--- end builder pod logs $p ---"
|
||||
done
|
||||
|
||||
}
|
||||
|
||||
dump_function_pod_logs() {
|
||||
ns=$1
|
||||
fns=$2
|
||||
@@ -248,11 +267,11 @@ dump_function_pod_logs() {
|
||||
for p in $functionPods
|
||||
do
|
||||
echo "--- function pod logs $p ---"
|
||||
containers=$(kubectl -n $fns get $p -o jsonpath={.spec.containers[*].name})
|
||||
containers=$(kubectl -n $fns get $p -o jsonpath={.spec.containers[*].name} --ignore-not-found)
|
||||
for c in $containers
|
||||
do
|
||||
echo "--- function pod logs $p: container $c ---"
|
||||
kubectl -n $fns logs $p $c
|
||||
kubectl -n $fns logs $p $c || true
|
||||
echo "--- end function pod logs $p: container $c ---"
|
||||
done
|
||||
echo "--- end function pod logs $p ---"
|
||||
@@ -265,7 +284,7 @@ dump_fission_logs() {
|
||||
component=$3
|
||||
|
||||
echo --- $component logs ---
|
||||
kubectl -n $ns get pod -o name | grep $component | xargs kubectl -n $ns logs
|
||||
kubectl -n $ns get pod -o name | grep $component | xargs kubectl -n $ns logs
|
||||
echo --- end $component logs ---
|
||||
}
|
||||
|
||||
@@ -316,6 +335,7 @@ dump_logs() {
|
||||
|
||||
ns=f-$id
|
||||
fns=f-func-$id
|
||||
bns=fission-builder
|
||||
|
||||
dump_all_fission_resources $ns
|
||||
dump_env_pods $fns
|
||||
@@ -324,6 +344,7 @@ dump_logs() {
|
||||
dump_fission_logs $ns $fns buildermgr
|
||||
dump_fission_logs $ns $fns executor
|
||||
dump_function_pod_logs $ns $fns
|
||||
dump_builder_pod_logs $bns
|
||||
dump_fission_crds
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
def main():
|
||||
path = "/configs/default/{{ FN_CFGMAP }}/TEST_KEY"
|
||||
f = open(path, "r")
|
||||
data = f.read()
|
||||
return data, 200
|
||||
@@ -0,0 +1,7 @@
|
||||
import os
|
||||
def main():
|
||||
cfgmap_path = "/configs/"
|
||||
secret_path = "/secrets/"
|
||||
if os.listdir(cfgmap_path) or os.listdir(secret_path):
|
||||
return "no", 400
|
||||
return "yes", 200
|
||||
@@ -0,0 +1,6 @@
|
||||
def main():
|
||||
path = "/secrets/default/{{ FN_SECRET }}/TEST_KEY"
|
||||
f = open(path, "r")
|
||||
data = f.read()
|
||||
#print()
|
||||
return data, 200
|
||||
+113
@@ -0,0 +1,113 @@
|
||||
#!/bin/bash
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
ROOT=$(dirname $0)/../..
|
||||
|
||||
fn=testnormal-$(date +%s)
|
||||
fn_secret=testsecret-$(date +%s)
|
||||
fn_cfgmap=testcfgmap-$(date +%s)
|
||||
|
||||
cp secret.py.template secret.py
|
||||
sed -i "s/{{ FN_SECRET }}/${fn_secret}/g" secret.py
|
||||
|
||||
cp cfgmap.py.template cfgmap.py
|
||||
sed -i "s/{{ FN_CFGMAP }}/${fn_cfgmap}/g" cfgmap.py
|
||||
|
||||
function cleanup {
|
||||
echo "Cleanup everything"
|
||||
kubectl delete secret -n default ${fn_secret}
|
||||
kubectl delete configmap -n default ${fn_cfgmap}
|
||||
fission function delete --name ${fn_secret}
|
||||
fission function delete --name ${fn_cfgmap}
|
||||
fission function delete --name ${fn}
|
||||
var=$(fission route list | grep ${fn_secret} | awk '{print $1;}')
|
||||
var2=$(fission route list | grep ${fn_cfgmap} | awk '{print $1;}')
|
||||
var3=$(fission route list | grep ${fn} | awk '{print $1;}')
|
||||
fission route delete --name ${var}
|
||||
fission route delete --name ${var2}
|
||||
fission route delete --name ${var3}
|
||||
}
|
||||
|
||||
# Create a hello world function in nodejs, test it with an http trigger
|
||||
echo "Pre-test cleanup"
|
||||
fission env delete --name python || true
|
||||
|
||||
echo "Creating python env"
|
||||
fission env create --name python --image fission/python-env
|
||||
trap "fission env delete --name python" EXIT
|
||||
|
||||
echo "Creating secret"
|
||||
kubectl create secret generic ${fn_secret} --from-literal=TEST_KEY="TESTVALUE" -n default
|
||||
trap "kubectl delete secret ${fn_secret} -n default" EXIT
|
||||
|
||||
|
||||
echo "Creating function with secret"
|
||||
fission fn create --name ${fn_secret} --env python --code secret.py --secret ${fn_secret}
|
||||
trap "fission fn delete --name ${fn_secret}" EXIT
|
||||
|
||||
echo "Creating route"
|
||||
fission route create --function ${fn_secret} --url /${fn_secret} --method GET
|
||||
|
||||
echo "Waiting for router to catch up"
|
||||
sleep 5
|
||||
|
||||
echo "HTTP GET on the function's route"
|
||||
res=$(curl http://${FISSION_ROUTER}/${fn_secret})
|
||||
val='TESTVALUE'
|
||||
|
||||
if [[ ${res} != ${val} ]]
|
||||
then
|
||||
echo "test secret failed"
|
||||
cleanup
|
||||
exit 1
|
||||
fi
|
||||
echo "test secret passed"
|
||||
|
||||
echo "Creating configmap"
|
||||
kubectl create configmap ${fn_cfgmap} --from-literal=TEST_KEY=TESTVALUE -n default
|
||||
trap "kubectl delete configmap ${fn_cfgmap} -n default" EXIT
|
||||
|
||||
echo "creating function with configmap"
|
||||
fission fn create --name ${fn_cfgmap} --env python --code cfgmap.py --configmap ${fn_cfgmap}
|
||||
trap "fission fn delete --name ${fn_cfgmap}" EXIT
|
||||
|
||||
echo "Creating route"
|
||||
fission route create --function ${fn_cfgmap} --url /${fn_cfgmap} --method GET
|
||||
|
||||
echo "Waiting for router to catch up"
|
||||
sleep 5
|
||||
|
||||
echo "HTTP GET on the function's route"
|
||||
rescfg=$(curl http://${FISSION_ROUTER}/${fn_cfgmap})
|
||||
|
||||
if [ ${rescfg} != ${val} ]
|
||||
then
|
||||
echo "test cfgmap failed"
|
||||
cleanup
|
||||
exit 1
|
||||
fi
|
||||
echo "test configmap passed"
|
||||
|
||||
echo "testing creating a function without a secret or configmap"
|
||||
fission function create --name ${fn} --env python --code empty.py
|
||||
trap "fission fn delete --name ${fn}" EXIT
|
||||
|
||||
echo "Creating route"
|
||||
fission route create --function ${fn} --url /${fn} --method GET
|
||||
|
||||
echo "Waiting for router to catch up"
|
||||
sleep 5
|
||||
|
||||
echo "HTTP GET on the function's route"
|
||||
resnormal=$(curl http://${FISSION_ROUTER}/${fn})
|
||||
if [ ${resnormal} != "yes" ]
|
||||
then
|
||||
echo "test empty failed"
|
||||
cleanup
|
||||
exit 1
|
||||
fi
|
||||
echo "test empty passed"
|
||||
|
||||
echo "All done."
|
||||
trap "cleanup" EXIT
|
||||
Reference in New Issue
Block a user