diff --git a/CHANGELOG.md b/CHANGELOG.md index 4ef7b3a..405371d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,6 +8,10 @@ and this project adheres to [Semantic Versioning](http://semver.org/spec/v2.0.0. ## [2.4.0] - 2024-05-17 +### Added +- Support for Windows TAS envrionments. + [cyberark/cloudfoundry-conjur-buildpack#184](https://github.com/cyberark/cloudfoundry-conjur-buildpack/pull/184) + ### Changed - Project Go version bumped to 1.22, and support for deprecated Go version 1.20 removed. [cyberark/cloudfoundry-conjur-buildpack#183](https://github.com/cyberark/cloudfoundry-conjur-buildpack/pull/183) diff --git a/bin/supply.bat b/bin/supply.bat new file mode 100644 index 0000000..eaee136 --- /dev/null +++ b/bin/supply.bat @@ -0,0 +1,2 @@ +@echo off +powershell.exe -ExecutionPolicy Unrestricted %~dp0\supply.ps1 %* \ No newline at end of file diff --git a/bin/supply.ps1 b/bin/supply.ps1 new file mode 100644 index 0000000..bd7b018 --- /dev/null +++ b/bin/supply.ps1 @@ -0,0 +1,33 @@ + +$buildDir=$args[0] +$depsDir=$args[2] +$indexDir=$args[3] + +# Validate that secret.yml exists +if (![System.IO.File]::Exists("$buildDir\secrets.yml")) +{ + echo "Unable to find a secrets.yml...exiting" + exit 1 +} + +# Validate that VCAP_SERVICES contains 'cyberark-conjur' +$vcapJson = echo $env:VCAP_SERVICES | ConvertFrom-Json + +if ("true" -ne $Env:CONJUR_BUILDPACK_BYPASS_SERVICE_CHECK ) +{ + if( !("cyberark-conjur" -in $vcapJson.PSobject.Properties.Name) ) + { + echo "No credentials for cyberark-conjur service found in VCAP_SERVICES... exit" + exit 1 + } +} + +pushd $depsDir\$indexDir + mkdir profile.d | Out-Null + copy $PSScriptRoot\..\lib\0001_retrieve-secrets.bat .\profile.d\ +popd + +pushd $buildDir + mkdir .conjur | Out-Null + copy $PSScriptRoot\..\vendor\conjur-win-env.exe .\.conjur\ +popd \ No newline at end of file diff --git a/ci/test_e2e b/ci/test_e2e index 3fa4d4b..3fc1f18 100755 --- a/ci/test_e2e +++ b/ci/test_e2e @@ -47,6 +47,11 @@ pushd ../tests/integration/apps/java ./bin/build popd +announce 'Building the Dotnet Windows test application...' +pushd ../tests/integration/apps/dotnet-windows + ./build +popd + announce 'Running Cucumber tests...' # Run tests against latest build of buildpack (including integration tests against remote foundation) docker compose \ diff --git a/conjur-env/Dockerfile b/conjur-env/Dockerfile index 03c29be..3a669bc 100644 --- a/conjur-env/Dockerfile +++ b/conjur-env/Dockerfile @@ -1,10 +1,6 @@ FROM golang:1.22 MAINTAINER CyberArk Software, Inc. -ENV GOOS=linux \ - GOARCH=amd64 \ - CGO_ENABLED=0 - WORKDIR /conjur-env COPY go.mod go.sum /conjur-env/ diff --git a/conjur-env/build.sh b/conjur-env/build.sh index 094875a..df4ac34 100755 --- a/conjur-env/build.sh +++ b/conjur-env/build.sh @@ -6,3 +6,4 @@ rm -rf ../vendor/conjur-env docker compose build docker compose run --rm conjur-env-builder +docker compose run --rm conjur-win-env-builder diff --git a/conjur-env/docker-compose.yml b/conjur-env/docker-compose.yml index b101a55..3f33f95 100644 --- a/conjur-env/docker-compose.yml +++ b/conjur-env/docker-compose.yml @@ -2,7 +2,22 @@ services: conjur-env-builder: build: context: . + environment: + - GOOS=linux + - GOARCH=amd64 + - CGO_ENABLED=0 volumes: - .:/conjur-env - ../vendor:/pkg command: go build -o /pkg/conjur-env -a -ldflags '-extldflags "-static"' . + conjur-win-env-builder: + build: + context: . + environment: + - GOOS=windows + - GOARCH=amd64 + - CGO_ENABLED=0 + volumes: + - .:/conjur-env + - ../vendor:/pkg + command: go build -o /pkg/conjur-win-env.exe -a -ldflags '-extldflags "-static"' . \ No newline at end of file diff --git a/lib/0001_retrieve-secrets.bat b/lib/0001_retrieve-secrets.bat new file mode 100644 index 0000000..1e4bf54 --- /dev/null +++ b/lib/0001_retrieve-secrets.bat @@ -0,0 +1,9 @@ +@echo off + +pushd %USERPROFILE%\app + for /f "tokens=1,2 delims=: " %%a in ('.conjur\conjur-win-env.exe') do ( + for /f %%i in ('powershell -executionpolicy Unrestricted -Command "[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('%%b'))"') do ( + set %%a=%%i + ) + ) +popd \ No newline at end of file diff --git a/manifest.yml b/manifest.yml index d1bcdca..68f5893 100644 --- a/manifest.yml +++ b/manifest.yml @@ -52,8 +52,12 @@ include_files: - VERSION - bin/compile - bin/supply +- bin/supply.bat +- bin/supply.ps1 - lib/0001_retrieve-secrets.sh +- lib/0001_retrieve-secrets.bat - lib/install_go.sh - vendor/conjur-env +- vendor/conjur-win-env.exe - manifest.yml language: conjur # used solely to name the .zip diff --git a/tests/integration/apps/dotnet-windows/.gitignore b/tests/integration/apps/dotnet-windows/.gitignore new file mode 100644 index 0000000..5e57f18 --- /dev/null +++ b/tests/integration/apps/dotnet-windows/.gitignore @@ -0,0 +1,484 @@ +## Ignore Visual Studio temporary files, build results, and +## files generated by popular Visual Studio add-ons. +## +## Get latest from `dotnet new gitignore` + +# dotenv files +.env + +# User-specific files +*.rsuser +*.suo +*.user +*.userosscache +*.sln.docstates + +# User-specific files (MonoDevelop/Xamarin Studio) +*.userprefs + +# Mono auto generated files +mono_crash.* + +# Build results +[Dd]ebug/ +[Dd]ebugPublic/ +[Rr]elease/ +[Rr]eleases/ +x64/ +x86/ +[Ww][Ii][Nn]32/ +[Aa][Rr][Mm]/ +[Aa][Rr][Mm]64/ +bld/ +[Bb]in/ +[Oo]bj/ +[Ll]og/ +[Ll]ogs/ + +# Visual Studio 2015/2017 cache/options directory +.vs/ +# Uncomment if you have tasks that create the project's static files in wwwroot +#wwwroot/ + +# Visual Studio 2017 auto generated files +Generated\ Files/ + +# MSTest test Results +[Tt]est[Rr]esult*/ +[Bb]uild[Ll]og.* + +# NUnit +*.VisualState.xml +TestResult.xml +nunit-*.xml + +# Build Results of an ATL Project +[Dd]ebugPS/ +[Rr]eleasePS/ +dlldata.c + +# Benchmark Results +BenchmarkDotNet.Artifacts/ + +# .NET +project.lock.json +project.fragment.lock.json +artifacts/ + +# Tye +.tye/ + +# ASP.NET Scaffolding +ScaffoldingReadMe.txt + +# StyleCop +StyleCopReport.xml + +# Files built by Visual Studio +*_i.c +*_p.c +*_h.h +*.ilk +*.meta +*.obj +*.iobj +*.pch +*.pdb +*.ipdb +*.pgc +*.pgd +*.rsp +*.sbr +*.tlb +*.tli +*.tlh +*.tmp +*.tmp_proj +*_wpftmp.csproj +*.log +*.tlog +*.vspscc +*.vssscc +.builds +*.pidb +*.svclog +*.scc + +# Chutzpah Test files +_Chutzpah* + +# Visual C++ cache files +ipch/ +*.aps +*.ncb +*.opendb +*.opensdf +*.sdf +*.cachefile +*.VC.db +*.VC.VC.opendb + +# Visual Studio profiler +*.psess +*.vsp +*.vspx +*.sap + +# Visual Studio Trace Files +*.e2e + +# TFS 2012 Local Workspace +$tf/ + +# Guidance Automation Toolkit +*.gpState + +# ReSharper is a .NET coding add-in +_ReSharper*/ +*.[Rr]e[Ss]harper +*.DotSettings.user + +# TeamCity is a build add-in +_TeamCity* + +# DotCover is a Code Coverage Tool +*.dotCover + +# AxoCover is a Code Coverage Tool +.axoCover/* +!.axoCover/settings.json + +# Coverlet is a free, cross platform Code Coverage Tool +coverage*.json +coverage*.xml +coverage*.info + +# Visual Studio code coverage results +*.coverage +*.coveragexml + +# NCrunch +_NCrunch_* +.*crunch*.local.xml +nCrunchTemp_* + +# MightyMoose +*.mm.* +AutoTest.Net/ + +# Web workbench (sass) +.sass-cache/ + +# Installshield output folder +[Ee]xpress/ + +# DocProject is a documentation generator add-in +DocProject/buildhelp/ +DocProject/Help/*.HxT +DocProject/Help/*.HxC +DocProject/Help/*.hhc +DocProject/Help/*.hhk +DocProject/Help/*.hhp +DocProject/Help/Html2 +DocProject/Help/html + +# Click-Once directory +publish/ + +# Publish Web Output +*.[Pp]ublish.xml +*.azurePubxml +# Note: Comment the next line if you want to checkin your web deploy settings, +# but database connection strings (with potential passwords) will be unencrypted +*.pubxml +*.publishproj + +# Microsoft Azure Web App publish settings. Comment the next line if you want to +# checkin your Azure Web App publish settings, but sensitive information contained +# in these scripts will be unencrypted +PublishScripts/ + +# NuGet Packages +*.nupkg +# NuGet Symbol Packages +*.snupkg +# The packages folder can be ignored because of Package Restore +**/[Pp]ackages/* +# except build/, which is used as an MSBuild target. +!**/[Pp]ackages/build/ +# Uncomment if necessary however generally it will be regenerated when needed +#!**/[Pp]ackages/repositories.config +# NuGet v3's project.json files produces more ignorable files +*.nuget.props +*.nuget.targets + +# Microsoft Azure Build Output +csx/ +*.build.csdef + +# Microsoft Azure Emulator +ecf/ +rcf/ + +# Windows Store app package directories and files +AppPackages/ +BundleArtifacts/ +Package.StoreAssociation.xml +_pkginfo.txt +*.appx +*.appxbundle +*.appxupload + +# Visual Studio cache files +# files ending in .cache can be ignored +*.[Cc]ache +# but keep track of directories ending in .cache +!?*.[Cc]ache/ + +# Others +ClientBin/ +~$* +*~ +*.dbmdl +*.dbproj.schemaview +*.jfm +*.pfx +*.publishsettings +orleans.codegen.cs + +# Including strong name files can present a security risk +# (https://github.com/github/gitignore/pull/2483#issue-259490424) +#*.snk + +# Since there are multiple workflows, uncomment next line to ignore bower_components +# (https://github.com/github/gitignore/pull/1529#issuecomment-104372622) +#bower_components/ + +# RIA/Silverlight projects +Generated_Code/ + +# Backup & report files from converting an old project file +# to a newer Visual Studio version. Backup files are not needed, +# because we have git ;-) +_UpgradeReport_Files/ +Backup*/ +UpgradeLog*.XML +UpgradeLog*.htm +ServiceFabricBackup/ +*.rptproj.bak + +# SQL Server files +*.mdf +*.ldf +*.ndf + +# Business Intelligence projects +*.rdl.data +*.bim.layout +*.bim_*.settings +*.rptproj.rsuser +*- [Bb]ackup.rdl +*- [Bb]ackup ([0-9]).rdl +*- [Bb]ackup ([0-9][0-9]).rdl + +# Microsoft Fakes +FakesAssemblies/ + +# GhostDoc plugin setting file +*.GhostDoc.xml + +# Node.js Tools for Visual Studio +.ntvs_analysis.dat +node_modules/ + +# Visual Studio 6 build log +*.plg + +# Visual Studio 6 workspace options file +*.opt + +# Visual Studio 6 auto-generated workspace file (contains which files were open etc.) +*.vbw + +# Visual Studio 6 auto-generated project file (contains which files were open etc.) +*.vbp + +# Visual Studio 6 workspace and project file (working project files containing files to include in project) +*.dsw +*.dsp + +# Visual Studio 6 technical files +*.ncb +*.aps + +# Visual Studio LightSwitch build output +**/*.HTMLClient/GeneratedArtifacts +**/*.DesktopClient/GeneratedArtifacts +**/*.DesktopClient/ModelManifest.xml +**/*.Server/GeneratedArtifacts +**/*.Server/ModelManifest.xml +_Pvt_Extensions + +# Paket dependency manager +.paket/paket.exe +paket-files/ + +# FAKE - F# Make +.fake/ + +# CodeRush personal settings +.cr/personal + +# Python Tools for Visual Studio (PTVS) +__pycache__/ +*.pyc + +# Cake - Uncomment if you are using it +# tools/** +# !tools/packages.config + +# Tabs Studio +*.tss + +# Telerik's JustMock configuration file +*.jmconfig + +# BizTalk build output +*.btp.cs +*.btm.cs +*.odx.cs +*.xsd.cs + +# OpenCover UI analysis results +OpenCover/ + +# Azure Stream Analytics local run output +ASALocalRun/ + +# MSBuild Binary and Structured Log +*.binlog + +# NVidia Nsight GPU debugger configuration file +*.nvuser + +# MFractors (Xamarin productivity tool) working folder +.mfractor/ + +# Local History for Visual Studio +.localhistory/ + +# Visual Studio History (VSHistory) files +.vshistory/ + +# BeatPulse healthcheck temp database +healthchecksdb + +# Backup folder for Package Reference Convert tool in Visual Studio 2017 +MigrationBackup/ + +# Ionide (cross platform F# VS Code tools) working folder +.ionide/ + +# Fody - auto-generated XML schema +FodyWeavers.xsd + +# VS Code files for those working on multiple tools +.vscode/* +!.vscode/settings.json +!.vscode/tasks.json +!.vscode/launch.json +!.vscode/extensions.json +*.code-workspace + +# Local History for Visual Studio Code +.history/ + +# Windows Installer files from build outputs +*.cab +*.msi +*.msix +*.msm +*.msp + +# JetBrains Rider +*.sln.iml +.idea + +## +## Visual studio for Mac +## + + +# globs +Makefile.in +*.userprefs +*.usertasks +config.make +config.status +aclocal.m4 +install-sh +autom4te.cache/ +*.tar.gz +tarballs/ +test-results/ + +# Mac bundle stuff +*.dmg +*.app + +# content below from: https://github.com/github/gitignore/blob/master/Global/macOS.gitignore +# General +.DS_Store +.AppleDouble +.LSOverride + +# Icon must end with two \r +Icon + + +# Thumbnails +._* + +# Files that might appear in the root of a volume +.DocumentRevisions-V100 +.fseventsd +.Spotlight-V100 +.TemporaryItems +.Trashes +.VolumeIcon.icns +.com.apple.timemachine.donotpresent + +# Directories potentially created on remote AFP share +.AppleDB +.AppleDesktop +Network Trash Folder +Temporary Items +.apdisk + +# content below from: https://github.com/github/gitignore/blob/master/Global/Windows.gitignore +# Windows thumbnail cache files +Thumbs.db +ehthumbs.db +ehthumbs_vista.db + +# Dump file +*.stackdump + +# Folder config file +[Dd]esktop.ini + +# Recycle Bin used on file shares +$RECYCLE.BIN/ + +# Windows Installer files +*.cab +*.msi +*.msix +*.msm +*.msp + +# Windows shortcuts +*.lnk + +# Vim temporary swap files +*.swp diff --git a/tests/integration/apps/dotnet-windows/Program.cs b/tests/integration/apps/dotnet-windows/Program.cs new file mode 100644 index 0000000..aca332d --- /dev/null +++ b/tests/integration/apps/dotnet-windows/Program.cs @@ -0,0 +1,15 @@ +var builder = WebApplication.CreateBuilder(args); +var app = builder.Build(); + +app.MapGet("/", () => { + var body = $""" +

Visit us @ www.conjur.org!

+

Space-wide Secrets

+

Database Username: {app.Configuration["SPACE_USERNAME"]}

+

Database Password: {app.Configuration["SPACE_PASSWORD"]}

+ """; + + return body; +}); + +app.Run(); diff --git a/tests/integration/apps/dotnet-windows/Properties/launchSettings.json b/tests/integration/apps/dotnet-windows/Properties/launchSettings.json new file mode 100644 index 0000000..9e006a8 --- /dev/null +++ b/tests/integration/apps/dotnet-windows/Properties/launchSettings.json @@ -0,0 +1,38 @@ +{ + "$schema": "http://json.schemastore.org/launchsettings.json", + "iisSettings": { + "windowsAuthentication": false, + "anonymousAuthentication": true, + "iisExpress": { + "applicationUrl": "http://localhost:17019", + "sslPort": 44320 + } + }, + "profiles": { + "http": { + "commandName": "Project", + "dotnetRunMessages": true, + "launchBrowser": true, + "applicationUrl": "http://localhost:5259", + "environmentVariables": { + "ASPNETCORE_ENVIRONMENT": "Development" + } + }, + "https": { + "commandName": "Project", + "dotnetRunMessages": true, + "launchBrowser": true, + "applicationUrl": "https://localhost:7187;http://localhost:5259", + "environmentVariables": { + "ASPNETCORE_ENVIRONMENT": "Development" + } + }, + "IIS Express": { + "commandName": "IISExpress", + "launchBrowser": true, + "environmentVariables": { + "ASPNETCORE_ENVIRONMENT": "Development" + } + } + } +} diff --git a/tests/integration/apps/dotnet-windows/appsettings.Development.json b/tests/integration/apps/dotnet-windows/appsettings.Development.json new file mode 100644 index 0000000..ff66ba6 --- /dev/null +++ b/tests/integration/apps/dotnet-windows/appsettings.Development.json @@ -0,0 +1,8 @@ +{ + "Logging": { + "LogLevel": { + "Default": "Information", + "Microsoft.AspNetCore": "Warning" + } + } +} diff --git a/tests/integration/apps/dotnet-windows/appsettings.json b/tests/integration/apps/dotnet-windows/appsettings.json new file mode 100644 index 0000000..4d56694 --- /dev/null +++ b/tests/integration/apps/dotnet-windows/appsettings.json @@ -0,0 +1,9 @@ +{ + "Logging": { + "LogLevel": { + "Default": "Information", + "Microsoft.AspNetCore": "Warning" + } + }, + "AllowedHosts": "*" +} diff --git a/tests/integration/apps/dotnet-windows/build b/tests/integration/apps/dotnet-windows/build new file mode 100755 index 0000000..4775c2f --- /dev/null +++ b/tests/integration/apps/dotnet-windows/build @@ -0,0 +1,10 @@ +#!/bin/bash + +rm -rf publish + +docker run \ + --rm \ + -v $(pwd):/app \ + -w /app \ + mcr.microsoft.com/dotnet/sdk:8.0 \ + dotnet publish -r win-x64 --self-contained -c Release -o publish diff --git a/tests/integration/apps/dotnet-windows/dotnet-windows.csproj b/tests/integration/apps/dotnet-windows/dotnet-windows.csproj new file mode 100644 index 0000000..c8f8fd9 --- /dev/null +++ b/tests/integration/apps/dotnet-windows/dotnet-windows.csproj @@ -0,0 +1,16 @@ + + + + net8.0 + enable + enable + dotnet_windows + + + + + PreserveNewest + + + + diff --git a/tests/integration/apps/dotnet-windows/dotnet-windows.sln b/tests/integration/apps/dotnet-windows/dotnet-windows.sln new file mode 100644 index 0000000..cefb719 --- /dev/null +++ b/tests/integration/apps/dotnet-windows/dotnet-windows.sln @@ -0,0 +1,25 @@ + +Microsoft Visual Studio Solution File, Format Version 12.00 +# Visual Studio Version 17 +VisualStudioVersion = 17.5.002.0 +MinimumVisualStudioVersion = 10.0.40219.1 +Project("{9A19103F-16F7-4668-BE54-9A1E7A4F7556}") = "dotnet-windows", "dotnet-windows.csproj", "{2279089D-DD72-41B6-BFFD-86E9C38ED42E}" +EndProject +Global + GlobalSection(SolutionConfigurationPlatforms) = preSolution + Debug|Any CPU = Debug|Any CPU + Release|Any CPU = Release|Any CPU + EndGlobalSection + GlobalSection(ProjectConfigurationPlatforms) = postSolution + {2279089D-DD72-41B6-BFFD-86E9C38ED42E}.Debug|Any CPU.ActiveCfg = Debug|Any CPU + {2279089D-DD72-41B6-BFFD-86E9C38ED42E}.Debug|Any CPU.Build.0 = Debug|Any CPU + {2279089D-DD72-41B6-BFFD-86E9C38ED42E}.Release|Any CPU.ActiveCfg = Release|Any CPU + {2279089D-DD72-41B6-BFFD-86E9C38ED42E}.Release|Any CPU.Build.0 = Release|Any CPU + EndGlobalSection + GlobalSection(SolutionProperties) = preSolution + HideSolutionNode = FALSE + EndGlobalSection + GlobalSection(ExtensibilityGlobals) = postSolution + SolutionGuid = {950B82AD-FA27-41ED-A5A5-3773A7BA5B8B} + EndGlobalSection +EndGlobal diff --git a/tests/integration/apps/dotnet-windows/manifest.yml.template b/tests/integration/apps/dotnet-windows/manifest.yml.template new file mode 100755 index 0000000..142af13 --- /dev/null +++ b/tests/integration/apps/dotnet-windows/manifest.yml.template @@ -0,0 +1,12 @@ +applications: +- name: dotnet-windows-app + random-route: true + stack: windows + path: publish + memory: 1G + command: .\dotnet-windows.exe --urls http://0.0.0.0:8080 + buildpacks: + - {conjur_buildpack} + - binary_buildpack + env: + CONJUR_BUILDPACK_BYPASS_SERVICE_CHECK: true \ No newline at end of file diff --git a/tests/integration/apps/dotnet-windows/secrets.yml b/tests/integration/apps/dotnet-windows/secrets.yml new file mode 100755 index 0000000..595eccd --- /dev/null +++ b/tests/integration/apps/dotnet-windows/secrets.yml @@ -0,0 +1,2 @@ +SPACE_USERNAME: space_username #!var secrets/username +SPACE_PASSWORD: space_password #!var secrets/password \ No newline at end of file diff --git a/tests/integration/features/integration.feature b/tests/integration/features/integration.feature index 9a905ad..dc8087e 100644 --- a/tests/integration/features/integration.feature +++ b/tests/integration/features/integration.feature @@ -39,3 +39,10 @@ Feature: Integrations Tests for remote TAS foundation Scenario: Java online buildpack integration When I push a "java" app with the "online" buildpack Then the secrets.yml values are available in the app + + # Our CI pipeline does not support Windows buildpacks. This can + # be tested locally against a TAS environment that supports Windows. + + # Scenario: Dotnet offline windows buildpack integration + # When I push a "dotnet-windows" app with the "offline" buildpack + # Then the secrets.yml values are available in the app