davsclaus commented on code in PR #27429:
URL: https://github.com/apache/camel/pull/27429#discussion_r4194245728


##########
test-infra/camel-test-infra-spiffe/src/main/java/org/apache/camel/test/infra/spiffe/services/SpiffeLocalContainerInfraService.java:
##########
@@ -0,0 +1,302 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *      http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.test.infra.spiffe.services;
+
+import java.io.IOException;
+import java.nio.file.Files;
+import java.nio.file.Path;
+import java.time.Duration;
+
+import com.sun.security.auth.module.UnixSystem;
+import org.apache.camel.spi.annotations.InfraService;
+import org.apache.camel.test.infra.common.LocalPropertyResolver;
+import org.apache.camel.test.infra.common.services.ContainerService;
+import org.apache.camel.test.infra.spiffe.common.SpiffeProperties;
+import org.slf4j.Logger;
+import org.slf4j.LoggerFactory;
+import org.testcontainers.containers.BindMode;
+import org.testcontainers.containers.Container;
+import org.testcontainers.containers.GenericContainer;
+import org.testcontainers.containers.Network;
+import org.testcontainers.containers.SelinuxContext;
+import 
org.testcontainers.containers.startupcheck.IsRunningStartupCheckStrategy;
+import org.testcontainers.containers.wait.strategy.Wait;
+import org.testcontainers.utility.MountableFile;
+
+/**
+ * Runs a SPIRE server and agent so a test can fetch SVIDs from a real 
Workload API.
+ * <p>
+ * The agent's Workload API Unix socket is bind-mounted to a short host path 
(the {@code AF_UNIX} {@code sun_path} limit
+ * is ~108 bytes, so a socket under a deep temp tree would fail to connect 
from the host). The agent runs in the host
+ * PID namespace because the {@code unix} workload attestor resolves the 
calling process through {@code /proc}, which a
+ * container cannot see otherwise; a single registration entry is created for 
{@code unix:uid:<the test process uid>} so
+ * the test JVM is issued {@code spiffe://<trustDomain>/workload}.
+ */
+@InfraService(service = SpiffeInfraService.class,
+              description = "SPIFFE/SPIRE server and agent exposing the 
Workload API",
+              serviceAlias = { "spiffe" })
+public class SpiffeLocalContainerInfraService implements SpiffeInfraService, 
ContainerService<GenericContainer<?>> {
+
+    public static final String TRUST_DOMAIN = "example.org";
+    public static final String AGENT_SPIFFE_ID = "spiffe://" + TRUST_DOMAIN + 
"/agent";
+    public static final String WORKLOAD_SPIFFE_ID = "spiffe://" + TRUST_DOMAIN 
+ "/workload";
+
+    private static final Logger LOG = 
LoggerFactory.getLogger(SpiffeLocalContainerInfraService.class);
+
+    private static final String SERVER_ALIAS = "spire-server";
+    private static final int SERVER_PORT = 8081;
+    private static final String SERVER_BIN = "/opt/spire/bin/spire-server";
+    private static final String SERVER_CONF = 
"/opt/spire/conf/server/server.conf";
+    private static final String AGENT_CONF = 
"/opt/spire/conf/agent/agent.conf";
+    private static final String SOCKET_CONTAINER_DIR = 
"/tmp/spire-agent/public";
+    private static final String SOCKET_FILE = "api.sock";
+    private static final String SERVER_CONF_RESOURCE = 
"org/apache/camel/test/infra/spiffe/services/spire-server.conf";
+    private static final String AGENT_CONF_RESOURCE = 
"org/apache/camel/test/infra/spiffe/services/spire-agent.conf";
+
+    private final String serverImage;
+    private final String agentImage;
+
+    private Network network;
+    private GenericContainer<?> server;
+    private GenericContainer<?> agent;
+    private Path hostSocketDir;
+    private String socketPath;
+
+    public SpiffeLocalContainerInfraService() {
+        
this(LocalPropertyResolver.getProperty(SpiffeLocalContainerInfraService.class,
+                SpiffeProperties.SPIFFE_SERVER_CONTAINER),
+             
LocalPropertyResolver.getProperty(SpiffeLocalContainerInfraService.class,
+                     SpiffeProperties.SPIFFE_AGENT_CONTAINER));
+    }
+
+    public SpiffeLocalContainerInfraService(String serverImage, String 
agentImage) {
+        this.serverImage = serverImage;
+        this.agentImage = agentImage;
+    }
+
+    @Override
+    public void initialize() {
+        try {
+            doInitialize();
+        } catch (RuntimeException e) {
+            // a partial start would leak the server container, the network 
and the temp socket directory, and a
+            // TestServiceUtil.tryInitialize() retry would overwrite the 
fields and orphan them; tear down whatever
+            // came up before propagating
+            cleanup();
+            throw e;
+        }
+    }
+
+    private void doInitialize() {
+        createHostSocketDir();
+        network = Network.newNetwork();
+
+        // the image entrypoint is "spire-server run", so only -config is 
passed; the config is copied in (no bind mount
+        // needed for it) and port 8081 is exposed purely so the 
listening-port wait can tell when the API is up
+        server = new GenericContainer<>(serverImage)
+                .withNetwork(network)
+                .withNetworkAliases(SERVER_ALIAS)
+                
.withCopyFileToContainer(MountableFile.forClasspathResource(SERVER_CONF_RESOURCE),
 SERVER_CONF)
+                .withExposedPorts(SERVER_PORT)
+                .withCommand("-config", SERVER_CONF)
+                .waitingFor(Wait.forListeningPort());
+        LOG.info("Starting the SPIRE server container");
+        server.start();
+        waitForServerHealthy();
+
+        String joinToken = generateJoinToken();
+        createWorkloadEntry();
+
+        // the agent needs the host PID namespace so the unix workload 
attestor can resolve the host test process, and
+        // the socket directory bind-mounted (SELinux-shared) so the host can 
reach the Workload API socket it creates
+        agent = new GenericContainer<>(agentImage)
+                .withNetwork(network)
+                
.withCopyFileToContainer(MountableFile.forClasspathResource(AGENT_CONF_RESOURCE),
 AGENT_CONF)
+                .withCreateContainerCmdModifier(cmd -> 
cmd.getHostConfig().withPidMode("host"))

Review Comment:
   Thanks for documenting it, and for fixing the client-auth point. To be 
clear, I was not asking to make the ITs portable, only that they skip where 
they cannot work: as component ITs run by default, `mvn verify` in camel-spiffe 
runs them on a macOS developer machine too (the skip only covers ppc64le and 
s390x, so Apple Silicon and Intel Macs both run them), where they fail rather 
than skip. An `@EnabledOnOs(OS.LINUX)` on `SpiffeWorkloadApiIT` and 
`SpiffeMutualTlsIT` (or the same check in the infra service, turning it into a 
skip) would keep them running on the Linux CI and out of the way elsewhere.
   
   _Claude Code on behalf of davsclaus_



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to