blob: 2409aed551fb95b0002aebdc3550895451a5af99 [file] [log] [blame]
Lorenz Brunfc5dbc62020-05-28 12:18:07 +02001// Copyright 2020 The Monogon Project Authors.
2//
3// SPDX-License-Identifier: Apache-2.0
4//
5// Licensed under the Apache License, Version 2.0 (the "License");
6// you may not use this file except in compliance with the License.
7// You may obtain a copy of the License at
8//
9// http://www.apache.org/licenses/LICENSE-2.0
10//
11// Unless required by applicable law or agreed to in writing, software
12// distributed under the License is distributed on an "AS IS" BASIS,
13// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14// See the License for the specific language governing permissions and
15// limitations under the License.
16
17package e2e
18
19import (
20 "context"
Serge Bazanski54e212a2023-06-14 13:45:11 +020021 "crypto/tls"
22 "crypto/x509"
Lorenz Brunfc5dbc62020-05-28 12:18:07 +020023 "errors"
24 "fmt"
Serge Bazanski2cfafc92023-03-21 16:42:47 +010025 "io"
Leopold Schabele28e6d72020-06-03 11:39:25 +020026 "net"
Lorenz Brunfc5dbc62020-05-28 12:18:07 +020027 "net/http"
28 _ "net/http"
29 _ "net/http/pprof"
Serge Bazanski54e212a2023-06-14 13:45:11 +020030 "net/url"
Lorenz Brun3ff5af32020-06-24 16:34:11 +020031 "os"
Lorenz Brun5e4fc2d2020-09-22 18:35:15 +020032 "strings"
Lorenz Brunfc5dbc62020-05-28 12:18:07 +020033 "testing"
34 "time"
35
Tim Windelschmidt2a1d1b22024-02-06 07:07:42 +010036 "github.com/bazelbuild/rules_go/go/runfiles"
Serge Bazanskibe742842022-04-04 13:18:50 +020037 "google.golang.org/grpc"
Lorenz Brunfc5dbc62020-05-28 12:18:07 +020038 corev1 "k8s.io/api/core/v1"
Lorenz Brun30167f52021-03-17 17:49:01 +010039 "k8s.io/apimachinery/pkg/api/resource"
Lorenz Brunfc5dbc62020-05-28 12:18:07 +020040 metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
41 podv1 "k8s.io/kubernetes/pkg/api/v1/pod"
42
Tim Windelschmidt2a1d1b22024-02-06 07:07:42 +010043 apb "source.monogon.dev/metropolis/proto/api"
44
Serge Bazanski31370b02021-01-07 16:31:14 +010045 common "source.monogon.dev/metropolis/node"
Serge Bazanski6dff6d62022-01-28 18:15:14 +010046 "source.monogon.dev/metropolis/node/core/identity"
Serge Bazanskibe742842022-04-04 13:18:50 +020047 "source.monogon.dev/metropolis/node/core/rpc"
Lorenz Brun150f24a2023-07-13 20:11:06 +020048 "source.monogon.dev/metropolis/pkg/localregistry"
Serge Bazanski05f813b2023-03-16 17:58:39 +010049 "source.monogon.dev/metropolis/test/launch"
Serge Bazanski66e58952021-10-05 17:06:56 +020050 "source.monogon.dev/metropolis/test/launch/cluster"
Mateusz Zalegaddf19b42022-06-22 12:27:37 +020051 "source.monogon.dev/metropolis/test/util"
Lorenz Brunfc5dbc62020-05-28 12:18:07 +020052)
53
Leopold Schabeld603f842020-06-09 17:48:09 +020054const (
55 // Timeout for the global test context.
56 //
Serge Bazanski216fe7b2021-05-21 18:36:16 +020057 // Bazel would eventually time out the test after 900s ("large") if, for
58 // some reason, the context cancellation fails to abort it.
Leopold Schabeld603f842020-06-09 17:48:09 +020059 globalTestTimeout = 600 * time.Second
60
61 // Timeouts for individual end-to-end tests of different sizes.
Serge Bazanski1ebd1e12020-07-13 19:17:16 +020062 smallTestTimeout = 60 * time.Second
Leopold Schabeld603f842020-06-09 17:48:09 +020063 largeTestTimeout = 120 * time.Second
64)
65
Serge Bazanskia0bc6d32023-06-28 18:57:40 +020066// TestE2ECore exercisees the core functionality of Metropolis: maintaining a
67// control plane, changing node roles, ...
68//
69// The tests are performed against an in-memory cluster.
70func TestE2ECore(t *testing.T) {
Lorenz Brunfc5dbc62020-05-28 12:18:07 +020071 // Set a global timeout to make sure this terminates
Leopold Schabeld603f842020-06-09 17:48:09 +020072 ctx, cancel := context.WithTimeout(context.Background(), globalTestTimeout)
Serge Bazanski1f9a03b2021-08-17 13:40:53 +020073 defer cancel()
Serge Bazanski66e58952021-10-05 17:06:56 +020074
Tim Windelschmidt2a1d1b22024-02-06 07:07:42 +010075 rPath, err := runfiles.Rlocation("_main/metropolis/test/e2e/testimages_manifest.prototxt")
76 if err != nil {
77 t.Fatalf("Resolving registry manifest failed: %v", err)
78 }
79 df, err := os.ReadFile(rPath)
80 if err != nil {
81 t.Fatalf("Reading registry manifest failed: %v", err)
82 }
83 lr, err := localregistry.FromBazelManifest(df)
Lorenz Brun150f24a2023-07-13 20:11:06 +020084 if err != nil {
85 t.Fatalf("Creating test image registry failed: %v", err)
86 }
Serge Bazanski66e58952021-10-05 17:06:56 +020087 // Launch cluster.
Serge Bazanskie78a0892021-10-07 17:03:49 +020088 clusterOptions := cluster.ClusterOptions{
Lorenz Brun150f24a2023-07-13 20:11:06 +020089 NumNodes: 2,
90 LocalRegistry: lr,
Serge Bazanskie78a0892021-10-07 17:03:49 +020091 }
92 cluster, err := cluster.LaunchCluster(ctx, clusterOptions)
Lorenz Brunfc5dbc62020-05-28 12:18:07 +020093 if err != nil {
Serge Bazanski66e58952021-10-05 17:06:56 +020094 t.Fatalf("LaunchCluster failed: %v", err)
Lorenz Brunfc5dbc62020-05-28 12:18:07 +020095 }
Serge Bazanski66e58952021-10-05 17:06:56 +020096 defer func() {
97 err := cluster.Close()
98 if err != nil {
99 t.Fatalf("cluster Close failed: %v", err)
Lorenz Brunfc5dbc62020-05-28 12:18:07 +0200100 }
101 }()
Serge Bazanski1f9a03b2021-08-17 13:40:53 +0200102
Serge Bazanski05f813b2023-03-16 17:58:39 +0100103 launch.Log("E2E: Cluster running, starting tests...")
Lorenz Brunfc5dbc62020-05-28 12:18:07 +0200104
Serge Bazanskibe742842022-04-04 13:18:50 +0200105 // Dial first node's curator.
Serge Bazanski8535cb52023-03-29 14:15:08 +0200106 creds := rpc.NewAuthenticatedCredentials(cluster.Owner, rpc.WantInsecure())
Serge Bazanskibe742842022-04-04 13:18:50 +0200107 remote := net.JoinHostPort(cluster.NodeIDs[0], common.CuratorServicePort.PortString())
108 cl, err := grpc.Dial(remote, grpc.WithContextDialer(cluster.DialNode), grpc.WithTransportCredentials(creds))
109 if err != nil {
110 t.Fatalf("failed to dial first node's curator: %v", err)
111 }
112 defer cl.Close()
113 mgmt := apb.NewManagementClient(cl)
114
Serge Bazanskia0bc6d32023-06-28 18:57:40 +0200115 util.TestEventual(t, "Retrieving cluster directory sucessful", ctx, 60*time.Second, func(ctx context.Context) error {
116 res, err := mgmt.GetClusterInfo(ctx, &apb.GetClusterInfoRequest{})
117 if err != nil {
118 return fmt.Errorf("GetClusterInfo: %w", err)
119 }
Serge Bazanskibf68fa92021-10-05 17:53:58 +0200120
Serge Bazanskia0bc6d32023-06-28 18:57:40 +0200121 // Ensure that the expected node count is present.
122 nodes := res.ClusterDirectory.Nodes
123 if want, got := clusterOptions.NumNodes, len(nodes); want != got {
124 return fmt.Errorf("wanted %d nodes in cluster directory, got %d", want, got)
125 }
Serge Bazanski6dff6d62022-01-28 18:15:14 +0100126
Serge Bazanskia0bc6d32023-06-28 18:57:40 +0200127 // Ensure the nodes have the expected addresses.
128 addresses := make(map[string]bool)
129 for _, n := range nodes {
130 if len(n.Addresses) != 1 {
131 return fmt.Errorf("node %s has no addresss", identity.NodeID(n.PublicKey))
Lorenz Brunfc5dbc62020-05-28 12:18:07 +0200132 }
Serge Bazanskia0bc6d32023-06-28 18:57:40 +0200133 address := n.Addresses[0].Host
134 addresses[address] = true
135 }
Serge Bazanski2cfafc92023-03-21 16:42:47 +0100136
Serge Bazanskia0bc6d32023-06-28 18:57:40 +0200137 for _, address := range []string{"10.1.0.2", "10.1.0.3"} {
138 if !addresses[address] {
139 return fmt.Errorf("address %q not found in directory", address)
Lorenz Brun30167f52021-03-17 17:49:01 +0100140 }
Serge Bazanskia0bc6d32023-06-28 18:57:40 +0200141 }
142 return nil
Lorenz Brunfc5dbc62020-05-28 12:18:07 +0200143 })
Serge Bazanskia0bc6d32023-06-28 18:57:40 +0200144 util.TestEventual(t, "Heartbeat test successful", ctx, 20*time.Second, cluster.AllNodesHealthy)
145 util.TestEventual(t, "Node rejoin successful", ctx, 60*time.Second, func(ctx context.Context) error {
146 // Ensure nodes rejoin the cluster after a reboot by reboting the 1st node.
147 if err := cluster.RebootNode(ctx, 1); err != nil {
148 return fmt.Errorf("while rebooting a node: %w", err)
149 }
150 return nil
151 })
152 util.TestEventual(t, "Heartbeat test successful", ctx, 20*time.Second, cluster.AllNodesHealthy)
153 util.TestEventual(t, "Prometheus node metrics retrieved", ctx, smallTestTimeout, func(ctx context.Context) error {
154 pool := x509.NewCertPool()
155 pool.AddCert(cluster.CACertificate)
156 cl := http.Client{
157 Transport: &http.Transport{
158 TLSClientConfig: &tls.Config{
159 Certificates: []tls.Certificate{cluster.Owner},
160 RootCAs: pool,
161 },
162 DialContext: func(ctx context.Context, _, addr string) (net.Conn, error) {
163 return cluster.DialNode(ctx, addr)
164 },
165 },
166 }
167 u := url.URL{
168 Scheme: "https",
169 Host: net.JoinHostPort(cluster.NodeIDs[0], common.MetricsPort.PortString()),
170 Path: "/metrics/node",
171 }
172 res, err := cl.Get(u.String())
173 if err != nil {
174 return err
175 }
176 defer res.Body.Close()
177 if res.StatusCode != 200 {
178 return fmt.Errorf("status code %d", res.StatusCode)
179 }
180
181 body, err := io.ReadAll(res.Body)
182 if err != nil {
183 return err
184 }
185 needle := "node_uname_info"
186 if !strings.Contains(string(body), needle) {
187 return util.Permanent(fmt.Errorf("could not find %q in returned response", needle))
188 }
189 return nil
190 })
191}
192
193// TestE2ECore exercisees the Kubernetes functionality of Metropolis.
194//
195// The tests are performed against an in-memory cluster.
196func TestE2EKubernetes(t *testing.T) {
197 // Set a global timeout to make sure this terminates
198 ctx, cancel := context.WithTimeout(context.Background(), globalTestTimeout)
199 defer cancel()
200
Tim Windelschmidt2a1d1b22024-02-06 07:07:42 +0100201 rPath, err := runfiles.Rlocation("_main/metropolis/test/e2e/testimages_manifest.prototxt")
202 if err != nil {
203 t.Fatalf("Resolving registry manifest failed: %v", err)
204 }
205 df, err := os.ReadFile(rPath)
206 if err != nil {
207 t.Fatalf("Reading registry manifest failed: %v", err)
208 }
209 lr, err := localregistry.FromBazelManifest(df)
Lorenz Brun150f24a2023-07-13 20:11:06 +0200210 if err != nil {
211 t.Fatalf("Creating test image registry failed: %v", err)
212 }
213
Serge Bazanskia0bc6d32023-06-28 18:57:40 +0200214 // Launch cluster.
215 clusterOptions := cluster.ClusterOptions{
Lorenz Brun150f24a2023-07-13 20:11:06 +0200216 NumNodes: 2,
217 LocalRegistry: lr,
Serge Bazanskia0bc6d32023-06-28 18:57:40 +0200218 }
219 cluster, err := cluster.LaunchCluster(ctx, clusterOptions)
220 if err != nil {
221 t.Fatalf("LaunchCluster failed: %v", err)
222 }
223 defer func() {
224 err := cluster.Close()
225 if err != nil {
226 t.Fatalf("cluster Close failed: %v", err)
227 }
228 }()
229
230 clientSet, err := cluster.GetKubeClientSet()
231 if err != nil {
232 t.Fatal(err)
233 }
234 util.TestEventual(t, "Add KubernetesWorker roles", ctx, smallTestTimeout, func(ctx context.Context) error {
235 // Make everything but the first node into KubernetesWorkers.
236 for i := 1; i < clusterOptions.NumNodes; i++ {
237 err := cluster.MakeKubernetesWorker(ctx, cluster.NodeIDs[i])
238 if err != nil {
239 return util.Permanent(fmt.Errorf("MakeKubernetesWorker: %w", err))
240 }
241 }
242 return nil
243 })
244 util.TestEventual(t, "Node is registered and ready", ctx, largeTestTimeout, func(ctx context.Context) error {
245 nodes, err := clientSet.CoreV1().Nodes().List(ctx, metav1.ListOptions{})
246 if err != nil {
247 return err
248 }
249 if len(nodes.Items) < 1 {
250 return errors.New("node not yet registered")
251 }
252 node := nodes.Items[0]
253 for _, cond := range node.Status.Conditions {
254 if cond.Type != corev1.NodeReady {
255 continue
256 }
257 if cond.Status != corev1.ConditionTrue {
258 return fmt.Errorf("node not ready: %v", cond.Message)
259 }
260 }
261 return nil
262 })
263 util.TestEventual(t, "Simple deployment", ctx, largeTestTimeout, func(ctx context.Context) error {
264 _, err := clientSet.AppsV1().Deployments("default").Create(ctx, makeTestDeploymentSpec("test-deploy-1"), metav1.CreateOptions{})
265 return err
266 })
267 util.TestEventual(t, "Simple deployment is running", ctx, largeTestTimeout, func(ctx context.Context) error {
268 res, err := clientSet.CoreV1().Pods("default").List(ctx, metav1.ListOptions{LabelSelector: "name=test-deploy-1"})
269 if err != nil {
270 return err
271 }
272 if len(res.Items) == 0 {
273 return errors.New("pod didn't get created")
274 }
275 pod := res.Items[0]
276 if podv1.IsPodAvailable(&pod, 1, metav1.NewTime(time.Now())) {
277 return nil
278 }
279 events, err := clientSet.CoreV1().Events("default").List(ctx, metav1.ListOptions{FieldSelector: fmt.Sprintf("involvedObject.name=%s,involvedObject.namespace=default", pod.Name)})
280 if err != nil || len(events.Items) == 0 {
281 return fmt.Errorf("pod is not ready: %v", pod.Status.Phase)
282 } else {
283 return fmt.Errorf("pod is not ready: %v", events.Items[0].Message)
284 }
285 })
286 util.TestEventual(t, "Simple deployment with gvisor", ctx, largeTestTimeout, func(ctx context.Context) error {
287 deployment := makeTestDeploymentSpec("test-deploy-2")
288 gvisorStr := "gvisor"
289 deployment.Spec.Template.Spec.RuntimeClassName = &gvisorStr
290 _, err := clientSet.AppsV1().Deployments("default").Create(ctx, deployment, metav1.CreateOptions{})
291 return err
292 })
293 util.TestEventual(t, "Simple deployment is running on gvisor", ctx, largeTestTimeout, func(ctx context.Context) error {
294 res, err := clientSet.CoreV1().Pods("default").List(ctx, metav1.ListOptions{LabelSelector: "name=test-deploy-2"})
295 if err != nil {
296 return err
297 }
298 if len(res.Items) == 0 {
299 return errors.New("pod didn't get created")
300 }
301 pod := res.Items[0]
302 if podv1.IsPodAvailable(&pod, 1, metav1.NewTime(time.Now())) {
303 return nil
304 }
305 events, err := clientSet.CoreV1().Events("default").List(ctx, metav1.ListOptions{FieldSelector: fmt.Sprintf("involvedObject.name=%s,involvedObject.namespace=default", pod.Name)})
306 if err != nil || len(events.Items) == 0 {
307 return fmt.Errorf("pod is not ready: %v", pod.Status.Phase)
308 } else {
309 var errorMsg strings.Builder
310 for _, msg := range events.Items {
311 errorMsg.WriteString(" | ")
312 errorMsg.WriteString(msg.Message)
313 }
314 return fmt.Errorf("pod is not ready: %v", errorMsg.String())
315 }
316 })
317 util.TestEventual(t, "Simple StatefulSet with PVC", ctx, largeTestTimeout, func(ctx context.Context) error {
318 _, err := clientSet.AppsV1().StatefulSets("default").Create(ctx, makeTestStatefulSet("test-statefulset-1", corev1.PersistentVolumeFilesystem), metav1.CreateOptions{})
319 return err
320 })
321 util.TestEventual(t, "Simple StatefulSet with PVC is running", ctx, largeTestTimeout, func(ctx context.Context) error {
322 res, err := clientSet.CoreV1().Pods("default").List(ctx, metav1.ListOptions{LabelSelector: "name=test-statefulset-1"})
323 if err != nil {
324 return err
325 }
326 if len(res.Items) == 0 {
327 return errors.New("pod didn't get created")
328 }
329 pod := res.Items[0]
330 if podv1.IsPodAvailable(&pod, 1, metav1.NewTime(time.Now())) {
331 return nil
332 }
333 events, err := clientSet.CoreV1().Events("default").List(ctx, metav1.ListOptions{FieldSelector: fmt.Sprintf("involvedObject.name=%s,involvedObject.namespace=default", pod.Name)})
334 if err != nil || len(events.Items) == 0 {
335 return fmt.Errorf("pod is not ready: %v", pod.Status.Phase)
336 } else {
337 return fmt.Errorf("pod is not ready: %v", events.Items[0].Message)
338 }
339 })
340 util.TestEventual(t, "Simple StatefulSet with Block PVC", ctx, largeTestTimeout, func(ctx context.Context) error {
341 _, err := clientSet.AppsV1().StatefulSets("default").Create(ctx, makeTestStatefulSet("test-statefulset-2", corev1.PersistentVolumeBlock), metav1.CreateOptions{})
342 return err
343 })
344 util.TestEventual(t, "Simple StatefulSet with Block PVC is running", ctx, largeTestTimeout, func(ctx context.Context) error {
345 res, err := clientSet.CoreV1().Pods("default").List(ctx, metav1.ListOptions{LabelSelector: "name=test-statefulset-2"})
346 if err != nil {
347 return err
348 }
349 if len(res.Items) == 0 {
350 return errors.New("pod didn't get created")
351 }
352 pod := res.Items[0]
353 if podv1.IsPodAvailable(&pod, 1, metav1.NewTime(time.Now())) {
354 return nil
355 }
356 events, err := clientSet.CoreV1().Events("default").List(ctx, metav1.ListOptions{FieldSelector: fmt.Sprintf("involvedObject.name=%s,involvedObject.namespace=default", pod.Name)})
357 if err != nil || len(events.Items) == 0 {
358 return fmt.Errorf("pod is not ready: %v", pod.Status.Phase)
359 } else {
360 return fmt.Errorf("pod is not ready: %v", events.Items[0].Message)
361 }
362 })
363 util.TestEventual(t, "In-cluster self-test job", ctx, smallTestTimeout, func(ctx context.Context) error {
364 _, err := clientSet.BatchV1().Jobs("default").Create(ctx, makeSelftestSpec("selftest"), metav1.CreateOptions{})
365 return err
366 })
367 util.TestEventual(t, "In-cluster self-test job passed", ctx, smallTestTimeout, func(ctx context.Context) error {
368 res, err := clientSet.BatchV1().Jobs("default").Get(ctx, "selftest", metav1.GetOptions{})
369 if err != nil {
370 return err
371 }
372 if res.Status.Failed > 0 {
373 pods, err := clientSet.CoreV1().Pods("default").List(ctx, metav1.ListOptions{
374 LabelSelector: "job-name=selftest",
375 })
376 if err != nil {
377 return util.Permanent(fmt.Errorf("job failed but failed to find pod: %w", err))
378 }
379 if len(pods.Items) < 1 {
380 return fmt.Errorf("job failed but pod does not exist")
381 }
382 lines, err := getPodLogLines(ctx, clientSet, pods.Items[0].Name, 1)
383 if err != nil {
384 return fmt.Errorf("job failed but could not get logs: %w", err)
385 }
386 if len(lines) > 0 {
387 return util.Permanent(fmt.Errorf("job failed, last log line: %s", lines[0]))
388 }
389 return util.Permanent(fmt.Errorf("job failed, empty log"))
390 }
391 if res.Status.Succeeded > 0 {
392 return nil
393 }
394 return fmt.Errorf("job still running")
395 })
396 if os.Getenv("HAVE_NESTED_KVM") != "" {
397 util.TestEventual(t, "Pod for KVM/QEMU smoke test", ctx, smallTestTimeout, func(ctx context.Context) error {
398 runcRuntimeClass := "runc"
399 _, err := clientSet.CoreV1().Pods("default").Create(ctx, &corev1.Pod{
400 ObjectMeta: metav1.ObjectMeta{
401 Name: "vm-smoketest",
402 },
403 Spec: corev1.PodSpec{
404 Containers: []corev1.Container{{
405 Name: "vm-smoketest",
406 ImagePullPolicy: corev1.PullNever,
Lorenz Brun150f24a2023-07-13 20:11:06 +0200407 Image: "test.monogon.internal/metropolis/vm/smoketest:smoketest_container",
Serge Bazanskia0bc6d32023-06-28 18:57:40 +0200408 Resources: corev1.ResourceRequirements{
409 Limits: corev1.ResourceList{
410 "devices.monogon.dev/kvm": *resource.NewQuantity(1, ""),
411 },
412 },
413 }},
414 RuntimeClassName: &runcRuntimeClass,
415 RestartPolicy: corev1.RestartPolicyNever,
416 },
417 }, metav1.CreateOptions{})
418 return err
419 })
420 util.TestEventual(t, "KVM/QEMU smoke test completion", ctx, smallTestTimeout, func(ctx context.Context) error {
421 pod, err := clientSet.CoreV1().Pods("default").Get(ctx, "vm-smoketest", metav1.GetOptions{})
422 if err != nil {
423 return fmt.Errorf("failed to get pod: %w", err)
424 }
425 if pod.Status.Phase == corev1.PodSucceeded {
426 return nil
427 }
428 events, err := clientSet.CoreV1().Events("default").List(ctx, metav1.ListOptions{FieldSelector: fmt.Sprintf("involvedObject.name=%s,involvedObject.namespace=default", pod.Name)})
429 if err != nil || len(events.Items) == 0 {
430 return fmt.Errorf("pod is not ready: %v", pod.Status.Phase)
431 } else {
432 return fmt.Errorf("pod is not ready: %v", events.Items[len(events.Items)-1].Message)
433 }
434 })
435 }
Lorenz Brunfc5dbc62020-05-28 12:18:07 +0200436}