oscerd commented on code in PR #27429:
URL: https://github.com/apache/camel/pull/27429#discussion_r4194307435


##########
test-infra/camel-test-infra-spiffe/src/main/java/org/apache/camel/test/infra/spiffe/services/SpiffeLocalContainerInfraService.java:
##########
@@ -0,0 +1,302 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *      http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.test.infra.spiffe.services;
+
+import java.io.IOException;
+import java.nio.file.Files;
+import java.nio.file.Path;
+import java.time.Duration;
+
+import com.sun.security.auth.module.UnixSystem;
+import org.apache.camel.spi.annotations.InfraService;
+import org.apache.camel.test.infra.common.LocalPropertyResolver;
+import org.apache.camel.test.infra.common.services.ContainerService;
+import org.apache.camel.test.infra.spiffe.common.SpiffeProperties;
+import org.slf4j.Logger;
+import org.slf4j.LoggerFactory;
+import org.testcontainers.containers.BindMode;
+import org.testcontainers.containers.Container;
+import org.testcontainers.containers.GenericContainer;
+import org.testcontainers.containers.Network;
+import org.testcontainers.containers.SelinuxContext;
+import 
org.testcontainers.containers.startupcheck.IsRunningStartupCheckStrategy;
+import org.testcontainers.containers.wait.strategy.Wait;
+import org.testcontainers.utility.MountableFile;
+
+/**
+ * Runs a SPIRE server and agent so a test can fetch SVIDs from a real 
Workload API.
+ * <p>
+ * The agent's Workload API Unix socket is bind-mounted to a short host path 
(the {@code AF_UNIX} {@code sun_path} limit
+ * is ~108 bytes, so a socket under a deep temp tree would fail to connect 
from the host). The agent runs in the host
+ * PID namespace because the {@code unix} workload attestor resolves the 
calling process through {@code /proc}, which a
+ * container cannot see otherwise; a single registration entry is created for 
{@code unix:uid:<the test process uid>} so
+ * the test JVM is issued {@code spiffe://<trustDomain>/workload}.
+ */
+@InfraService(service = SpiffeInfraService.class,
+              description = "SPIFFE/SPIRE server and agent exposing the 
Workload API",
+              serviceAlias = { "spiffe" })
+public class SpiffeLocalContainerInfraService implements SpiffeInfraService, 
ContainerService<GenericContainer<?>> {
+
+    public static final String TRUST_DOMAIN = "example.org";
+    public static final String AGENT_SPIFFE_ID = "spiffe://" + TRUST_DOMAIN + 
"/agent";
+    public static final String WORKLOAD_SPIFFE_ID = "spiffe://" + TRUST_DOMAIN 
+ "/workload";
+
+    private static final Logger LOG = 
LoggerFactory.getLogger(SpiffeLocalContainerInfraService.class);
+
+    private static final String SERVER_ALIAS = "spire-server";
+    private static final int SERVER_PORT = 8081;
+    private static final String SERVER_BIN = "/opt/spire/bin/spire-server";
+    private static final String SERVER_CONF = 
"/opt/spire/conf/server/server.conf";
+    private static final String AGENT_CONF = 
"/opt/spire/conf/agent/agent.conf";
+    private static final String SOCKET_CONTAINER_DIR = 
"/tmp/spire-agent/public";
+    private static final String SOCKET_FILE = "api.sock";
+    private static final String SERVER_CONF_RESOURCE = 
"org/apache/camel/test/infra/spiffe/services/spire-server.conf";
+    private static final String AGENT_CONF_RESOURCE = 
"org/apache/camel/test/infra/spiffe/services/spire-agent.conf";
+
+    private final String serverImage;
+    private final String agentImage;
+
+    private Network network;
+    private GenericContainer<?> server;
+    private GenericContainer<?> agent;
+    private Path hostSocketDir;
+    private String socketPath;
+
+    public SpiffeLocalContainerInfraService() {
+        
this(LocalPropertyResolver.getProperty(SpiffeLocalContainerInfraService.class,
+                SpiffeProperties.SPIFFE_SERVER_CONTAINER),
+             
LocalPropertyResolver.getProperty(SpiffeLocalContainerInfraService.class,
+                     SpiffeProperties.SPIFFE_AGENT_CONTAINER));
+    }
+
+    public SpiffeLocalContainerInfraService(String serverImage, String 
agentImage) {
+        this.serverImage = serverImage;
+        this.agentImage = agentImage;
+    }
+
+    @Override
+    public void initialize() {
+        try {
+            doInitialize();
+        } catch (RuntimeException e) {
+            // a partial start would leak the server container, the network 
and the temp socket directory, and a
+            // TestServiceUtil.tryInitialize() retry would overwrite the 
fields and orphan them; tear down whatever
+            // came up before propagating
+            cleanup();
+            throw e;
+        }
+    }
+
+    private void doInitialize() {
+        createHostSocketDir();
+        network = Network.newNetwork();
+
+        // the image entrypoint is "spire-server run", so only -config is 
passed; the config is copied in (no bind mount
+        // needed for it) and port 8081 is exposed purely so the 
listening-port wait can tell when the API is up
+        server = new GenericContainer<>(serverImage)
+                .withNetwork(network)
+                .withNetworkAliases(SERVER_ALIAS)
+                
.withCopyFileToContainer(MountableFile.forClasspathResource(SERVER_CONF_RESOURCE),
 SERVER_CONF)
+                .withExposedPorts(SERVER_PORT)
+                .withCommand("-config", SERVER_CONF)
+                .waitingFor(Wait.forListeningPort());
+        LOG.info("Starting the SPIRE server container");
+        server.start();
+        waitForServerHealthy();
+
+        String joinToken = generateJoinToken();
+        createWorkloadEntry();
+
+        // the agent needs the host PID namespace so the unix workload 
attestor can resolve the host test process, and
+        // the socket directory bind-mounted (SELinux-shared) so the host can 
reach the Workload API socket it creates
+        agent = new GenericContainer<>(agentImage)
+                .withNetwork(network)
+                
.withCopyFileToContainer(MountableFile.forClasspathResource(AGENT_CONF_RESOURCE),
 AGENT_CONF)
+                .withCreateContainerCmdModifier(cmd -> 
cmd.getHostConfig().withPidMode("host"))

Review Comment:
   Good point — enforced in 174a07a. Both ITs are now `@EnabledOnOs(OS.LINUX)`, 
so `mvn verify` skips them on macOS/Windows (Docker Desktop's VM) and any 
non-Linux host rather than running and failing; they still run on a Linux 
Docker host (CI and Linux dev), where the host PID namespace and the 
bind-mounted Workload API socket work. The `skipITs.ppc64le`/`skipITs.s390x` 
properties continue to cover the non-amd64 CI architectures. Verified locally 
on Linux: both ITs still run (6 tests), not skipped.
   
   _Claude Code on behalf of oscerd_
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to