full-mesh.sh 2.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142
  1. #!/usr/bin/env bash
  2. # shellcheck disable=SC1091
  3. . lib.sh
  4. setup_suite() {
  5. # shellcheck disable=SC2016
  6. _kubectl patch ds -n kube-system kilo -p '{"spec": {"template":{"spec":{"containers":[{"name":"kilo","args":["--hostname=$(NODE_NAME)","--create-interface=false","--kubeconfig=/etc/kubernetes/kubeconfig","--mesh-granularity=full"]}]}}}}'
  7. block_until_ready_by_name kube-system kilo-userspace
  8. }
  9. test_full_mesh_connectivity() {
  10. assert "retry 30 5 '' check_ping" "should be able to ping all Pods"
  11. assert "retry 10 5 'the adjacency matrix is not complete yet' check_adjacent 3" "adjacency should return the right number of successful pings"
  12. echo "sleep for 30s (one reconciliation period) and try again..."
  13. sleep 30
  14. assert "retry 10 5 'the adjacency matrix is not complete yet' check_adjacent 3" "adjacency should return the right number of successful pings after reconciling"
  15. }
  16. test_full_mesh_peer() {
  17. check_peer wg99 e2e 10.5.0.1/32 full
  18. }
  19. test_full_mesh_allowed_location_ips() {
  20. docker exec kind-cluster-kilo-control-plane ip address add 10.6.0.1/32 dev eth0
  21. _kubectl annotate node kind-cluster-kilo-control-plane kilo.squat.ai/allowed-location-ips=10.6.0.1/32
  22. assert_equals Unauthorized "$(retry 10 5 'IP is not yet routable' curl_pod -m 1 -s -k https://10.6.0.1:10250/healthz)" "should be able to make HTTP request to allowed location IP"
  23. _kubectl annotate node kind-cluster-kilo-control-plane kilo.squat.ai/allowed-location-ips-
  24. assert "retry 10 5 'IP is still routable' _not curl_pod -m 1 -s -k https://10.6.0.1:10250/healthz" "should not be able to make HTTP request to allowed location IP"
  25. docker exec kind-cluster-kilo-control-plane ip address delete 10.6.0.1/32 dev eth0
  26. }
  27. test_reject_peer_empty_allowed_ips() {
  28. assert_fail "create_peer e2e '' 0 foo" "should not be able to create Peer with empty allowed IPs"
  29. }
  30. test_reject_peer_empty_public_key() {
  31. assert_fail "create_peer e2e 10.5.0.1/32 0 ''" "should not be able to create Peer with empty public key"
  32. }
  33. test_mesh_granularity_auto_detect() {
  34. assert_equals "$(_kgctl graph)" "$(_kgctl graph --mesh-granularity full)"
  35. }