Functions have access to secrets/configmaps specified by the user (#399)

This commit solves part of the issue #52 , functions are able to access secrets/configmaps specified by the user. For now, CLI only accept one secret/configmap. For advanced users, it will be able to use YAML to declare multiple secrets/configmaps in later changes.
This commit is contained in:
prithviramesh
2018-02-05 17:49:26 +08:00
committed by Ta-Ching Chen
parent 4cf195768e
commit 1eb0453ce4
14 changed files with 411 additions and 31 deletions
+24 -3
View File
@@ -240,6 +240,25 @@ set_environment() {
export PATH=$ROOT/fission:$PATH
}
dump_builder_pod_logs() {
bns=$1
builderPods=$(kubectl -n $bns get pod -o name)
for p in $builderPods
do
echo "--- builder pod logs $p ---"
containers=$(kubectl -n $bns get $p -o jsonpath={.spec.containers[*].name} --ignore-not-found)
for c in $containers
do
echo "--- builder pod logs $p: container $c ---"
kubectl -n $bns logs $p $c || true
echo "--- end builder pod logs $p: container $c ---"
done
echo "--- end builder pod logs $p ---"
done
}
dump_function_pod_logs() {
ns=$1
fns=$2
@@ -248,11 +267,11 @@ dump_function_pod_logs() {
for p in $functionPods
do
echo "--- function pod logs $p ---"
containers=$(kubectl -n $fns get $p -o jsonpath={.spec.containers[*].name})
containers=$(kubectl -n $fns get $p -o jsonpath={.spec.containers[*].name} --ignore-not-found)
for c in $containers
do
echo "--- function pod logs $p: container $c ---"
kubectl -n $fns logs $p $c
kubectl -n $fns logs $p $c || true
echo "--- end function pod logs $p: container $c ---"
done
echo "--- end function pod logs $p ---"
@@ -265,7 +284,7 @@ dump_fission_logs() {
component=$3
echo --- $component logs ---
kubectl -n $ns get pod -o name | grep $component | xargs kubectl -n $ns logs
kubectl -n $ns get pod -o name | grep $component | xargs kubectl -n $ns logs
echo --- end $component logs ---
}
@@ -316,6 +335,7 @@ dump_logs() {
ns=f-$id
fns=f-func-$id
bns=fission-builder
dump_all_fission_resources $ns
dump_env_pods $fns
@@ -324,6 +344,7 @@ dump_logs() {
dump_fission_logs $ns $fns buildermgr
dump_fission_logs $ns $fns executor
dump_function_pod_logs $ns $fns
dump_builder_pod_logs $bns
dump_fission_crds
}
@@ -0,0 +1,5 @@
def main():
path = "/configs/default/{{ FN_CFGMAP }}/TEST_KEY"
f = open(path, "r")
data = f.read()
return data, 200
+7
View File
@@ -0,0 +1,7 @@
import os
def main():
cfgmap_path = "/configs/"
secret_path = "/secrets/"
if os.listdir(cfgmap_path) or os.listdir(secret_path):
return "no", 400
return "yes", 200
@@ -0,0 +1,6 @@
def main():
path = "/secrets/default/{{ FN_SECRET }}/TEST_KEY"
f = open(path, "r")
data = f.read()
#print()
return data, 200
+113
View File
@@ -0,0 +1,113 @@
#!/bin/bash
set -euo pipefail
ROOT=$(dirname $0)/../..
fn=testnormal-$(date +%s)
fn_secret=testsecret-$(date +%s)
fn_cfgmap=testcfgmap-$(date +%s)
cp secret.py.template secret.py
sed -i "s/{{ FN_SECRET }}/${fn_secret}/g" secret.py
cp cfgmap.py.template cfgmap.py
sed -i "s/{{ FN_CFGMAP }}/${fn_cfgmap}/g" cfgmap.py
function cleanup {
echo "Cleanup everything"
kubectl delete secret -n default ${fn_secret}
kubectl delete configmap -n default ${fn_cfgmap}
fission function delete --name ${fn_secret}
fission function delete --name ${fn_cfgmap}
fission function delete --name ${fn}
var=$(fission route list | grep ${fn_secret} | awk '{print $1;}')
var2=$(fission route list | grep ${fn_cfgmap} | awk '{print $1;}')
var3=$(fission route list | grep ${fn} | awk '{print $1;}')
fission route delete --name ${var}
fission route delete --name ${var2}
fission route delete --name ${var3}
}
# Create a hello world function in nodejs, test it with an http trigger
echo "Pre-test cleanup"
fission env delete --name python || true
echo "Creating python env"
fission env create --name python --image fission/python-env
trap "fission env delete --name python" EXIT
echo "Creating secret"
kubectl create secret generic ${fn_secret} --from-literal=TEST_KEY="TESTVALUE" -n default
trap "kubectl delete secret ${fn_secret} -n default" EXIT
echo "Creating function with secret"
fission fn create --name ${fn_secret} --env python --code secret.py --secret ${fn_secret}
trap "fission fn delete --name ${fn_secret}" EXIT
echo "Creating route"
fission route create --function ${fn_secret} --url /${fn_secret} --method GET
echo "Waiting for router to catch up"
sleep 5
echo "HTTP GET on the function's route"
res=$(curl http://${FISSION_ROUTER}/${fn_secret})
val='TESTVALUE'
if [[ ${res} != ${val} ]]
then
echo "test secret failed"
cleanup
exit 1
fi
echo "test secret passed"
echo "Creating configmap"
kubectl create configmap ${fn_cfgmap} --from-literal=TEST_KEY=TESTVALUE -n default
trap "kubectl delete configmap ${fn_cfgmap} -n default" EXIT
echo "creating function with configmap"
fission fn create --name ${fn_cfgmap} --env python --code cfgmap.py --configmap ${fn_cfgmap}
trap "fission fn delete --name ${fn_cfgmap}" EXIT
echo "Creating route"
fission route create --function ${fn_cfgmap} --url /${fn_cfgmap} --method GET
echo "Waiting for router to catch up"
sleep 5
echo "HTTP GET on the function's route"
rescfg=$(curl http://${FISSION_ROUTER}/${fn_cfgmap})
if [ ${rescfg} != ${val} ]
then
echo "test cfgmap failed"
cleanup
exit 1
fi
echo "test configmap passed"
echo "testing creating a function without a secret or configmap"
fission function create --name ${fn} --env python --code empty.py
trap "fission fn delete --name ${fn}" EXIT
echo "Creating route"
fission route create --function ${fn} --url /${fn} --method GET
echo "Waiting for router to catch up"
sleep 5
echo "HTTP GET on the function's route"
resnormal=$(curl http://${FISSION_ROUTER}/${fn})
if [ ${resnormal} != "yes" ]
then
echo "test empty failed"
cleanup
exit 1
fi
echo "test empty passed"
echo "All done."
trap "cleanup" EXIT