This repository has been archived by the owner on Mar 20, 2024. It is now read-only.
forked from cilium/cilium
-
Notifications
You must be signed in to change notification settings - Fork 0
/
cassandra.go
173 lines (140 loc) · 5.76 KB
/
cassandra.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
// Copyright 2018-2019 Authors of Cilium
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package RuntimeTest
import (
"fmt"
. "github.com/cilium/cilium/test/ginkgo-ext"
"github.com/cilium/cilium/test/helpers"
"github.com/cilium/cilium/test/helpers/constants"
. "github.com/onsi/gomega"
)
var _ = Describe("RuntimeCassandra", func() {
var (
vm *helpers.SSHMeta
cassandraIP string
)
containers := func(mode string) {
images := map[string]string{
"cass-server": constants.CassandraImage,
"cass-client": constants.CassandraImage,
}
cmds := map[string][]string{
"cass-client": {"sleep", "10000"},
}
switch mode {
case "create":
for k, v := range images {
cmd, ok := cmds[k]
var res *helpers.CmdRes
if ok {
res = vm.ContainerCreate(k, v, helpers.CiliumDockerNetwork, fmt.Sprintf("-l id.%s", k), cmd...)
} else {
res = vm.ContainerCreate(k, v, helpers.CiliumDockerNetwork, fmt.Sprintf("-l id.%s", k))
}
res.ExpectSuccess("failed to create container %s", k)
}
cassServer, err := vm.ContainerInspectNet("cass-server")
Expect(err).Should(BeNil(), "Could not get cass-server network info")
cassandraIP = cassServer["IPv4"]
case "delete":
for k := range images {
vm.ContainerRm(k)
}
}
}
runCqlsh := func(cmd string) *helpers.CmdRes {
logger.Infof("Executing command '%s'", cmd)
res := vm.ContainerExec("cass-client", fmt.Sprintf(
`cqlsh %s --connect-timeout=200 -e "%s"`, cassandraIP, cmd))
return res
}
setupPostsTable := func() {
r := runCqlsh("CREATE KEYSPACE posts_db WITH REPLICATION = { 'class' : 'NetworkTopologyStrategy', 'datacenter1' : 2 };")
r.ExpectSuccess("Unable to create keyspace 'posts_db'")
r = runCqlsh("CREATE TABLE posts_db.posts (username varchar, creation timeuuid, content varchar, PRIMARY KEY ((username), creation));")
r.ExpectSuccess("Unable to create 'posts' table")
r = runCqlsh("INSERT INTO posts_db.posts (username, creation, content) values ('dan', now(), 'Cilium Rocks!');")
r.ExpectSuccess("Unable to insert into 'posts' table")
}
// Waits for the server to be ready, by executing
// a command repeatedly until it succeeds, or a timeout occurs
waitForCassandraServer := func() error {
body := func() bool {
res := runCqlsh("SELECT * from system.local")
return res.WasSuccessful()
}
err := helpers.WithTimeout(body, "Cassandra server not ready", &helpers.TimeoutConfig{Timeout: helpers.HelperTimeout})
return err
}
BeforeAll(func() {
vm = helpers.InitRuntimeHelper(helpers.Runtime, logger)
ExpectCiliumReady(vm)
containers("create")
epsReady := vm.WaitEndpointsReady()
Expect(epsReady).Should(BeTrue(), "Endpoints are not ready after timeout")
err := waitForCassandraServer()
Expect(err).To(BeNil(), "Cassandra Server failed to come up")
// create keyspace, table, and do one insert
// with no policy in place
setupPostsTable()
})
AfterEach(func() {
vm.PolicyDelAll()
})
AfterAll(func() {
containers("delete")
vm.CloseSSHClient()
})
JustAfterEach(func() {
vm.ValidateNoErrorsInLogs(CurrentGinkgoTestDescription().Duration)
})
AfterFailed(func() {
vm.ReportFailed("cilium policy get")
})
It("Tests policy allowing all actions", func() {
_, err := vm.PolicyImportAndWait(vm.GetFullPath("Policies-cassandra-allow-all.json"), helpers.HelperTimeout)
Expect(err).Should(BeNil(), "Failed to import policy")
endPoints, err := vm.PolicyEndpointsSummary()
Expect(err).Should(BeNil(), "Cannot get endpoint list")
Expect(endPoints[helpers.Enabled]).To(Equal(1),
"Check number of endpoints with policy enforcement enabled")
Expect(endPoints[helpers.Disabled]).To(Equal(1),
"Check number of endpoints with policy enforcement disabled")
By("Inserting Value into Cassandra (no policy)")
r := runCqlsh("INSERT INTO posts_db.posts (username, creation, content) values ('alice', now(), 'Hello');")
r.ExpectSuccess("Unable to insert into 'posts_db.posts' table")
By("Reading values from Cassandra (no policy)")
r = runCqlsh("SELECT * FROM posts_db.posts;")
r.ExpectSuccess("Unable to select from 'posts' table")
r.ExpectContains("alice", "Did not get inserted data in select")
})
It("Tests policy disallowing Insert action", func() {
_, err := vm.PolicyImportAndWait(vm.GetFullPath("Policies-cassandra-no-insert-posts.json"), helpers.HelperTimeout)
Expect(err).Should(BeNil(), "Failed to import policy")
endPoints, err := vm.PolicyEndpointsSummary()
Expect(err).Should(BeNil(), "Cannot get endpoint list")
Expect(endPoints[helpers.Enabled]).To(Equal(1),
"Check number of endpoints with policy enforcement enabled")
Expect(endPoints[helpers.Disabled]).To(Equal(1),
"Check number of endpoints with policy enforcement disabled")
By("Inserting Value into Cassandra (denied by policy)")
r := runCqlsh("INSERT INTO posts_db.posts (username, creation, content) values ('bob', now(), 'Goodbye');")
r.ExpectFail("Able to insert into 'posts_db.posts' table, which should be denied by policy")
By("Reading values from Cassandra (allowed by policy)")
r = runCqlsh("SELECT * FROM posts_db.posts;")
r.ExpectSuccess("Unable to select from 'posts' table")
r.ExpectContains("alice", "Did not get inserted data in select")
r.ExpectDoesNotContain("bob", "Got value on select that should not have been inserted")
})
})