mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-09-28 10:50:15 +00:00
nixos/nebula: move tunless test to existing test
This commit is contained in:
@@ -1241,7 +1241,6 @@ in
|
||||
nebula-lighthouse-service = runTest ./nebula-lighthouse-service.nix;
|
||||
nebula.connectivity = runTest ./nebula/connectivity.nix;
|
||||
nebula.reload = runTest ./nebula/reload.nix;
|
||||
nebula.tunless = runTest ./nebula/tunless.nix;
|
||||
neo4j = runTest ./neo4j.nix;
|
||||
netbird = runTest ./netbird.nix;
|
||||
netbird-relay = runTest ./netbird-relay.nix;
|
||||
|
||||
@@ -1,6 +1,9 @@
|
||||
{ pkgs, lib, ... }:
|
||||
{
|
||||
pkgs,
|
||||
lib,
|
||||
...
|
||||
}:
|
||||
let
|
||||
|
||||
# We'll need to be able to trade cert files between nodes via scp.
|
||||
inherit (import ../ssh-keys.nix pkgs)
|
||||
snakeOilPrivateKey
|
||||
@@ -44,13 +47,11 @@ let
|
||||
}
|
||||
extraConfig
|
||||
];
|
||||
|
||||
in
|
||||
{
|
||||
name = "nebula";
|
||||
|
||||
nodes = {
|
||||
|
||||
lighthouse =
|
||||
{ ... }@args:
|
||||
makeNebulaNode args "lighthouse" {
|
||||
@@ -97,6 +98,24 @@ in
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
# A lighthouse can run without a tun interface, no device name = skip length check pr 565501
|
||||
services.nebula.networks.tunless = {
|
||||
ca = "/etc/nebula/ca.crt";
|
||||
cert = "/etc/nebula/lighthouse.crt";
|
||||
key = "/etc/nebula/lighthouse.key";
|
||||
isLighthouse = true;
|
||||
listen = {
|
||||
host = "0.0.0.0";
|
||||
port = 4243;
|
||||
};
|
||||
tun = {
|
||||
disable = true;
|
||||
device = "nebula.tunless-too-long";
|
||||
};
|
||||
user = "nebula-smoke";
|
||||
group = "nebula-smoke";
|
||||
};
|
||||
};
|
||||
|
||||
allowAny =
|
||||
@@ -265,12 +284,10 @@ in
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
testScript =
|
||||
let
|
||||
|
||||
setUpPrivateKey = name: ''
|
||||
${name}.start()
|
||||
${name}.succeed(
|
||||
@@ -379,6 +396,11 @@ in
|
||||
lighthouse.wait_until_succeeds("ping -c1 -W1 10.0.100.1", timeout=10)
|
||||
lighthouse.wait_until_succeeds("ping -c1 -W1 2001:db8::1", timeout=10)
|
||||
|
||||
# The tunless network starts without a tun device despite its (deliberately over-long) configured device name. pr 565501
|
||||
lighthouse.wait_for_unit("nebula@tunless.service")
|
||||
lighthouse.wait_until_succeeds("ss -lun | grep -q ':4243'", timeout=10)
|
||||
lighthouse.fail("ip link show nebula.tunless-too-long")
|
||||
|
||||
# Start all the machines to be set up
|
||||
allowAny.start()
|
||||
allowFromLighthouse.start()
|
||||
|
||||
@@ -1,43 +0,0 @@
|
||||
{ ... }:
|
||||
{
|
||||
name = "nebula";
|
||||
|
||||
nodes = {
|
||||
lighthouse =
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
environment.systemPackages = [ pkgs.nebula ];
|
||||
|
||||
services.nebula.networks.smoke = {
|
||||
# Note that these paths won't exist when the machine is first booted.
|
||||
ca = "/etc/nebula/ca.crt";
|
||||
cert = "/etc/nebula/lighthouse.crt";
|
||||
key = "/etc/nebula/lighthouse.key";
|
||||
isLighthouse = true;
|
||||
listen = {
|
||||
host = "0.0.0.0";
|
||||
port = 4242;
|
||||
};
|
||||
# A lighthouse can run without a tun interface. The device name is
|
||||
# unused then, so the length assertion must not apply to it.
|
||||
tun.disable = true;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
testScript = ''
|
||||
# Create the certificate and sign the lighthouse's keys.
|
||||
lighthouse.succeed(
|
||||
"mkdir -p /etc/nebula",
|
||||
'nebula-cert ca -duration $((10*365*24*60))m -name "Smoke Test" -out-crt /etc/nebula/ca.crt -out-key /etc/nebula/ca.key',
|
||||
'nebula-cert sign -duration $((365*24*60))m -ca-crt /etc/nebula/ca.crt -ca-key /etc/nebula/ca.key -name "lighthouse" -groups "lighthouse" -networks "10.0.100.1/24" -out-crt /etc/nebula/lighthouse.crt -out-key /etc/nebula/lighthouse.key',
|
||||
'chown -R nebula-smoke:nebula-smoke /etc/nebula'
|
||||
)
|
||||
|
||||
# Restart nebula to pick up the keys and verify it listens without creating a tun device.
|
||||
lighthouse.systemctl("restart nebula@smoke.service")
|
||||
lighthouse.wait_for_unit("nebula@smoke.service")
|
||||
lighthouse.wait_until_succeeds("ss -lun | grep -q ':4242'", timeout=10)
|
||||
lighthouse.fail("ip link show nebula.smoke")
|
||||
'';
|
||||
}
|
||||
@@ -54,7 +54,6 @@ buildGoModule (finalAttrs: {
|
||||
inherit (nixosTests.nebula)
|
||||
connectivity
|
||||
reload
|
||||
tunless
|
||||
;
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user