package api
import (
"testing"
"time"
"github.com/stretchr/testify/require"
"github.com/hashicorp/consul/sdk/testutil"
"github.com/hashicorp/consul/sdk/testutil/retry"
)
func TestAPI_ConnectCARoots_empty ( t * testing . T ) {
t . Parallel ( )
c , s := makeClientWithConfig ( t , nil , func ( c * testutil . TestServerConfig ) {
// Don't bootstrap CA
c . Connect = nil
} )
defer s . Stop ( )
s . WaitForSerfCheck ( t )
connect := c . Connect ( )
_ , _ , err := connect . CARoots ( nil )
bulk rewrite using this script
set -euo pipefail
unset CDPATH
cd "$(dirname "$0")"
for f in $(git grep '\brequire := require\.New(' | cut -d':' -f1 | sort -u); do
echo "=== require: $f ==="
sed -i '/require := require.New(t)/d' $f
# require.XXX(blah) but not require.XXX(tblah) or require.XXX(rblah)
sed -i 's/\brequire\.\([a-zA-Z0-9_]*\)(\([^tr]\)/require.\1(t,\2/g' $f
# require.XXX(tblah) but not require.XXX(t, blah)
sed -i 's/\brequire\.\([a-zA-Z0-9_]*\)(\(t[^,]\)/require.\1(t,\2/g' $f
# require.XXX(rblah) but not require.XXX(r, blah)
sed -i 's/\brequire\.\([a-zA-Z0-9_]*\)(\(r[^,]\)/require.\1(t,\2/g' $f
gofmt -s -w $f
done
for f in $(git grep '\bassert := assert\.New(' | cut -d':' -f1 | sort -u); do
echo "=== assert: $f ==="
sed -i '/assert := assert.New(t)/d' $f
# assert.XXX(blah) but not assert.XXX(tblah) or assert.XXX(rblah)
sed -i 's/\bassert\.\([a-zA-Z0-9_]*\)(\([^tr]\)/assert.\1(t,\2/g' $f
# assert.XXX(tblah) but not assert.XXX(t, blah)
sed -i 's/\bassert\.\([a-zA-Z0-9_]*\)(\(t[^,]\)/assert.\1(t,\2/g' $f
# assert.XXX(rblah) but not assert.XXX(r, blah)
sed -i 's/\bassert\.\([a-zA-Z0-9_]*\)(\(r[^,]\)/assert.\1(t,\2/g' $f
gofmt -s -w $f
done
3 years ago
require . Error ( t , err )
require . Contains ( t , err . Error ( ) , "Connect must be enabled" )
}
func TestAPI_ConnectCARoots_list ( t * testing . T ) {
t . Parallel ( )
c , s := makeClient ( t )
defer s . Stop ( )
// This fails occasionally if server doesn't have time to bootstrap CA so
// retry
retry . Run ( t , func ( r * retry . R ) {
connect := c . Connect ( )
list , meta , err := connect . CARoots ( nil )
r . Check ( err )
if meta . LastIndex == 0 {
r . Fatalf ( "expected roots raft index to be > 0" )
}
if v := len ( list . Roots ) ; v != 1 {
r . Fatalf ( "expected 1 root, got %d" , v )
}
// connect.TestClusterID causes import cycle so hard code it
if list . TrustDomain != "11111111-2222-3333-4444-555555555555.consul" {
r . Fatalf ( "expected fixed trust domain got '%s'" , list . TrustDomain )
}
} )
}
func TestAPI_ConnectCAConfig_get_set ( t * testing . T ) {
t . Parallel ( )
c , s := makeClient ( t )
defer s . Stop ( )
s . WaitForSerfCheck ( t )
expected := & ConsulCAProviderConfig {
IntermediateCertTTL : 365 * 24 * time . Hour ,
}
expected . LeafCertTTL = 72 * time . Hour
expected . RootCertTTL = 10 * 365 * 24 * time . Hour
// This fails occasionally if server doesn't have time to bootstrap CA so
// retry
retry . Run ( t , func ( r * retry . R ) {
connect := c . Connect ( )
conf , _ , err := connect . CAGetConfig ( nil )
r . Check ( err )
if conf . Provider != "consul" {
r . Fatalf ( "expected default provider, got %q" , conf . Provider )
}
parsed , err := ParseConsulCAConfig ( conf . Config )
r . Check ( err )
require . Equal ( r , expected , parsed )
// Change a config value and update
conf . Config [ "PrivateKey" ] = ""
conf . Config [ "IntermediateCertTTL" ] = 300 * 24 * time . Hour
conf . Config [ "RootCertTTL" ] = 11 * 365 * 24 * time . Hour
// Pass through some state as if the provider stored it so we can make sure
// we can read it again.
conf . Config [ "test_state" ] = map [ string ] string { "foo" : "bar" }
_ , err = connect . CASetConfig ( conf , nil )
r . Check ( err )
updated , _ , err := connect . CAGetConfig ( nil )
r . Check ( err )
expected . IntermediateCertTTL = 300 * 24 * time . Hour
expected . RootCertTTL = 11 * 365 * 24 * time . Hour
parsed , err = ParseConsulCAConfig ( updated . Config )
r . Check ( err )
require . Equal ( r , expected , parsed )
require . Equal ( r , "bar" , updated . State [ "foo" ] )
} )
}