Repository navigation
Add integration tests - #24
Merged
Merged
Conversation
Add an integration source set and an integrationTest task that test the running app, as started by docker compose -f build.yaml up. Like other JLab projects, the task is not part of build: it needs the containers, which take minutes to build and start. The tests log in to Keycloak with the demo users and with the adm client's service account, which uses client credentials as CI deploys do, then call the app over HTTPS: - DeployIT: deploys to the sshd container as an admin and as the service account, and checks each job on the log page: a failing command keeps its exit code and output, a prompt gets no input, and an unknown host is recorded. Other users, invalid and missing versions, unknown envs, and requests without a token are refused. - InventoryIT: only admins can add app envs. The tests add their own app envs with unique names and remove them afterwards, removing their deploy jobs too. They wait up to 5 minutes for the services to start. ADM_URL and KEYCLOAK_URL point them at other ports. To get tokens for demo users, the test realm's adm client now allows the password grant. container/keycloak/initdb.d/03_customize.sh, which does that, is now executable: the Keycloak image runs only executable scripts, so it was skipped before, and the deployer-group role it creates never existed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
CodeQL flagged the TrustManager that accepted any certificate. Trust the JDK's CAs plus the self-signed certificate of the jeffersonlab/wildfly image instead, saved as a test resource. A different certificate now fails the TLS handshake. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
slominskir
approved these changes
Oct 1, 2026
Contributor
Author
|
Two commits since you started reviewing:
The squash template uses the first commit's message, which still describes the PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds integration tests that run against the app and its services in containers, following the pattern of JLab projects such as myquery and epics2web: an
integrationsource set (src/integration/java) and anintegrationTesttask. The task is not part of./gradlew build.Running them
The tests wait up to 5 minutes for the app, Oracle and Keycloak to be ready (
ADM_READY_TIMEOUT_SECONDS).ADM_URLandKEYCLOAK_URLpoint them at other ports. The README's Develop section says the same.Tests
The tests use real Keycloak tokens, like CI's deploy workflow: the demo users
tbrown(admin) andjadams(user) by password, and theadmclient's service account (service-account-adm) by client credentials. Requests go to the app over HTTPS as bearer tokens.DeployIT(10): deploys to the sshd container and reads each job from/log:tbrowndeploys the demo envlocal-demo: exit 0, stdout1.0.0;1.0.0; touch /tmp/pwned), a missing version (Reject a deploy request without a version #22), an unknown env, and a request without a token (302 to Keycloak's login).InventoryIT(2): an admin can add and remove an app env;jadamscan't add one.Each run adds its own app envs, named
it-plus a random suffix, and removes them at the end, which removes their deploy jobs too (ON DELETE CASCADE). So runs leave the demo data as they found it, and two runs against one stack don't collide.Other changes
container/keycloak/initdb.d/03_customize.shnow also enables the password grant on the test realm'sadmclient, so tests can get tokens for demo users. This only affects the local test realm.*.shfiles, so it was silently skipped before, the same problem as Make the sshd container's entrypoint executable #18. Its existing setup (thedeployer-grouprole forjsmith) never ran either; it does now.CI: please add this job
The GitHub App can't change workflows, so this PR doesn't touch
.github/workflows/ci.yaml. To run the tests on every PR, like myquery does, add this job:I haven't been able to run that job. One risk:
Dockerfile-sshddownloadshttp://pki.jlab.org/JLabCA.crtby default. It's reachable from the agent VM, but I don't know whether GitHub's runners can reach it. If they can't, add--build-arg, or setCUSTOM_CRT_URLto empty for the sshd build inbuild.yaml.Checks
On the agent VM, with the stack started by
docker compose -f build.yaml up -d --build:./gradlew integrationTest: 12 passed in 16 s, and again on a second run. Noit-envs were left afterwards.sshdcontainer stopped, the 4 tests that run a deploy command fail, as they should../gradlew clean spotlessCheck buildstill runs only the unit tests.The first
--buildon a fresh machine took about 13 minutes, mostly downloading images (Oracle XE alone is 4.5 GB). After that, the stack was ready about 2 minutes afterup.🤖 Generated with Claude Code