Commit Graph
270 Commits
Author SHA1 Message Date
fheineckeandGus Luxton 1daf7d2302 [master forward-port] Fixed RPMs using artifacts compiled against a too-new version of glibc (#11026)
* Fixed RPMs using artifacts compiled against a too-new version of glibc

* Fixed RPM naming issue

* Apply suggestions from code review

Co-authored-by: Gus Luxton <gus@goteleport.com>

Co-authored-by: Gus Luxton <gus@goteleport.com>
2022-03-25 20:55:31 +00:00
3c74adf218 Add Helm unit tests (#11062)
* POC for Helm unit tests

This uses https://github.com/vbehar/helm3-unittest to define
expectations of our helm templates

* Test that enterprise is configured correctly

* Added tests for teleport-cluster

* Added tests for teleport-kube-agent

* Removed tests for teleport chart

* Add tests for teleport-cluster Deployment

* Run shorter tests first

* Fix Docker plugin installation and add update-helm-snapshots target

* Add README

* Fix lint syntax error and add some missing linters

* Add missing ImagePullPolicy to Deployment and StatefulSet

* Add Deployment tests for teleport-kube-agent

* Fix replicaCount logic

* Add clarification to values

* Add StatefulSet suite for teleport-kube-agent

* Update snapshots after merge with master

* Helm tests are quicker than bash tests

* Add tests for extraEnv

* Random space

* Tidy up formatting of multiple tests

* [debug] List helm plugins and directories

* Special case Helm linting when running in CI

* Make trailing line breaks consistent

* Special case Helm linting when running in CI

* Add contribution guidelines for Helm charts

* Add contribution guidelines to READMEs

* Deprecate old charts

* Typo

* Spacing

* Clarification

* Update examples/chart/CONTRIBUTING.md

* Don't erroneously set extraEnv for initContainers

* Rename update-helm-snapshots -> test-helm-update-snapshots for clarity

Co-authored-by: Gus Luxton <gus@goteleport.com>
Co-authored-by: Roman Tkachenko <roman@goteleport.com>
2022-03-20 19:01:58 +00:00
Gus Luxton 0d257c4e0b ci: Add helm3-unittest into CI Dockerfile (#11187)
Required for #11062 to work
2022-03-17 15:10:39 +11:00
Brian Joerger 3fc479c146 Update gomod path for beta/alpha pre-releases. (#10866) 2022-03-10 01:44:24 +00:00
Walt eae66c0ed3 Do not block apt publishing if there is a more current pre-release (#10804)
We do not publish pre-releases to apt repos, but we do publish them to
github.  That means we need to filter them out when considering if an
apt release should be published.  We don't want v8.3.3 to be blocked by
v9.0.0-dev.1, only by v9.0.0.

Honestly, this is a bit of a mess, but it only needs to hold out a bit
longer until https://github.com/gravitational/teleport/pull/10746 lands.

Contributes to https://github.com/gravitational/teleport/issues/10800
2022-03-04 06:46:27 +00:00
Tim Buckley 6d83fed8d7 Include tbot binary in Teleport packages and installs (#10646)
* Include tbot binary in Teleport packages and installs

This includes the tbot binary in .rpm, .deb, and .pkg distributions,
and ensures the binary is installed using the `install` script in
.tar.gz packages.

* Remove tbot from macOS client-only builds
2022-03-03 03:25:23 +00:00
Trent Clarke 3beb29832f Upgrade buildbox to go 1.17.7 & tag as teleport10 (#10611)
Prior to this patch the teleport buildbox version has been tagged with the Go version for the current release. This bit us during the Teleport 9 development cycle, as both Teleport 8 and 9 use the same version of Go but require different versions of Rust, and we were unable to distinguish between the 2 buildbox versions.

At the time, Teleport 8 was individually patched to create a new `teleport8` buildbox tag, decoupling the buildbox version from the Go version. This was never ported into master and now we find the teleport 9 branch sharing the same buildbox tag as master.

This patch forward-ports all the changes made to `branch/v8` and updates them for master, creating a new `teleport10` buildbox tag. The idea is that we will create a new tag for teleport11 at the same time the release branch for Teleport 10 is mad at some point in the future.

Once this is merged, Drone will create and push new buildbox images, which will become available for CI. A subsequent patch will update the CI scripts to use the new `teleport10` buildbox images.
2022-03-01 15:31:46 +11:00
Alan Parra 69c67fd0bf Read API_IMPORT_PATH from api/go.mod in make grpc (#10478)
API_IMPORT_PATH is consistently being resolved as an empty string, breaking
proto generation.

Since the path is fixed, it seems simpler to read api/go.mod and do away with
the Go program.

* Explicitly set API_IMPORT_PATH
* Delete the print-import-path program
* Read api module from api/go.mod, push variables to target
2022-02-22 19:39:35 +00:00
Jakub Nyckowski 7c19757d28 Install gcloud in /opt, so it can be accessed by non root (#10400) 2022-02-17 06:25:48 +00:00
Walt Della 7df4d77f47 Add a command to query the latest release
This gives us a robust way to find the latest published release for a
Major or Major.Minor version.  This logic is useful for our automation
that publishes up-to-date teleport:X docker images

Contributes to https://github.com/gravitational/teleport/issues/9494
2022-02-16 17:19:17 -08:00
Walt Della e5b9df2e89 Switch to testify
This saves us a couple lines of code and is a consistent review
recommendation. Better to learn it myself than keep pushing back. :)
2022-02-16 17:19:17 -08:00
Walt Della cf3109862f Exclude draft releases from latest version logic
These should not be factored in when checking for the latest release
when we decide if we should release apt packages.

This also fixes a bug in sorting logic, where we were sorting
lexigraphically instead of by semver.
2022-02-16 17:19:17 -08:00
Walt Della adcaf7bca7 Fix release sorting
9 was comparing greater than 10, due to use of lexographic sorting

This would cause us to fail to publish apt packages when we roll over to
a patch release > 9.
2022-02-16 17:19:17 -08:00
Walt Della d74ecdf86a Add an lexicographic test case
We are failing to sort properly when "9" is compared to "10".
2022-02-16 17:19:17 -08:00
Walt Della f49feacb24 Integrate version-check into build.assets/tooling
This is a unified home as suggested by Trent here:

  https://github.com/gravitational/teleport/pull/10295#discussion_r807499882

Furthermore, I've split cmd code from lib code, in preparation for a new
command that will reuse the library code.
2022-02-16 17:19:17 -08:00
Zac Bergquist eb487ce360 Remove CentOS 6 builds for Teleport 9 2022-02-15 18:40:48 -07:00
Zac Bergquist b2ffe8cc61 Update the PR description for auto webassets udpates (#10212)
The script for updating webassets uses the commit message from
webapps as the commit message for the PR to teleport.

This commit message is almost always a merged PR, which has the format:

    do some awesome thing (#123)

Where '#123' is the number of the **webapps** PR that was merged.

The problem with this is, when the teleport PR is created, it interprets
the #123 as the number of a **teleport** PR. And since the Teleport repo
has a lot more issues/PRs than webapps, Github ends up linking to an old
and completely unrelated PR.

Fix this by replacing (#123) with (gravitational/webapps#123), which
Github correctly renders as a link to the webapps PR in question.
2022-02-08 19:10:47 +00:00
rosstimothy 896261acaf Add more lint coverage (#10049)
* Add more lint coverage

golanglint-ci doesn't pick up subdirectories with their own go.mod
which left certain directories unlinted. To get around this we can
run golanglint-ci directly against those submodules.
2022-02-07 12:03:10 -05:00
Brian Joerger d33f51d17f x11 forwarding (#9897) 2022-02-04 23:47:03 +00:00
Brian Joerger 5d9a4033ef Add xauth binary to buildbox for X11 forwarding. (#10164) 2022-02-04 20:36:15 +00:00
Jakub Nyckowski c974f2781a Use SDK Cloud script to install gcloud (#9941)
* Use SDK Cloud script to install gcloud in buildbox Docker container

* Add missing gcloud components and dependencies.
2022-01-28 23:18:50 +00:00
Zac Bergquist 2aba666dc9 Update to Rust 1.58.1 (#9985)
In Rust 1.58, deriving Debug no longer counts as using a struct's
fields, so we need to allow dead_code for our structs that implement
RDP protocols. (Just because we don't use the fields doesn't mean
we shoudln't decode them)
2022-01-28 02:34:45 +00:00
Brian Joerger eb40cdc73e make protoc generation compatible with api v2+ (#9673)
Starting with the Teleport 9 release, we will be versioning the
API module. This change ensures that the generated protobuf code
imports the correct version of the API by:

- introducing a small new command to print the correct version
- adding import rewrite rules to the protoc invocation
2022-01-24 19:16:05 +00:00
Jakub Nyckowski 538fcaa980 Remove devbox - build box now supports AMR64. (#9847) 2022-01-20 01:05:25 +00:00
Walt 854053326a Conditionally publish deb packages (#9496)
This patch makes a couple changes:

  1. deb archives are not published to apt if they're not the latest
     release ever
  2. both rpm and deb archives are no longer published to yum / apt if
     they contain any pre-release indicator or build metadata
  3. nothing is published if the commit isn't tagged.

Contributes to https://github.com/gravitational/teleport/issues/8166
2022-01-14 03:52:15 +00:00
Edoardo Spadolini c7797fcb1f Don't shell out to go list when not needed (#9776) 2022-01-13 11:00:33 -05:00
Zac Bergquist d0eb86191d Remove vendor
- Remove the vendor directory
- Update bot to stop accounting for vendor
- Update linter config
- Remove update-vendor make target
2022-01-07 02:15:11 -07:00
Trent Clarke 4ba0248769 Restrores CI lint for non-go files (#9663)
Linting for non-go files was accidentally dropped in the transition to
GCB (sorry!). This patch restores linting for non-go files and fixes
any lint failures that have crept in during the interim.
2022-01-06 22:20:56 +11:00
Trent Clarke ea176c2b3c Attempts to make CI integration test logs more useful (#9626)
Actually tracking down the cause of a failure in the integration tests can 
be hard:

* It's hard to get an overall summary of what failed
* The tests sometimes emit no output before timing out, meaning any 
  diagnostic info is lost
* The emitted logs are too voluminous for a human to parse
* The emitted logs can present information out of order
* It's often hard to tell where the output from one test ends 
  and the next one begins

This patch attempts to address these concerns without attempting to rewrite 
any of the underlying teleport logging.

 * It improves the render-tests script to (optionally) report progress per-
   test, rather than on a per-package basis. My working hypothesis on the
   tests that time out with no output is that go test ./integration is
   waiting for the entire set of integration tests tests to be complete
   before reporting success or failure. Reporting on a per-test cycle gives
   faster feedback and means that any timed-out builds should give at least
   some idea of where they are stuck.

 * Adds the render-tests filter to the integration and integration-root make
   targets. This will show an overall summary of test results, as well as
    - Discarding log output from passing tests to increase signal-to-noise 
      ratio, and
    - Strongly delimiting the output from each failed test, making failures 
      easier to find.

 * Removes the notion of a failure-only logger in favour of post-processing
   the log events with render-tests. The failure-only logger catches log
   output from the tests and only forwards it to the console if the test 
   fails. Unfortunately, not all log output is guaranteed to pass through
   this logger (some teleport packages do not honour the configured logger,
   and reports from the go race detector certainly don't), meaning some 
   output is presented at the time it happens, and other output is batched
   and displayed at the end of the test. This makes working out what 
   happened where harder than it need be.

In addition, this patch also promotes the render-tests script into a fully-
fledged program, with appropriate makefile targets, make clean support, etc. 
It is now also more robust in the face on non-JSON output from go test 
(which happens if a package fails to compile).
2022-01-05 10:42:07 +11:00
Jakub Nyckowski e9450e32a3 Add ARM64 support for buildbox docker image (#9572)
* Update buildbox to use Python3.
* Remove non default rust targets from arm64 image.
* Add ETCD_UNSUPPORTED_ARCH for arm64 to etcd script to allow running etcd on arm64.
2021-12-29 03:33:22 +00:00
Joel a3ad9ca917 Fix devbox on AMD64 (#9462) 2021-12-16 23:26:19 +00:00
Edoardo Spadolini d027173547 Clean up make grpc and .pb.go generation (#9432)
* Ensure that slice.pb.go is generated by `make grpc`

* Clean up `make grpc`

* Disable the test target rules in Makefile when running inside the devbox
2021-12-16 22:20:53 +00:00
Joel 7951de5728 Split dev tools into a seperate docker container (#9410) 2021-12-15 20:11:52 +00:00
Zac Bergquist e2a0225c7c Fix make grpc (#9252)
- Ensure that the protoc include directory is readable by all users
- Switch back to the root user by default

Either of these changes would have fixed the issue on their own,
but I decided to include both as GRPC should be readable by non-root
users, and I wanted to preserve the original behavior of running
as root unless the $(NOROOT) flags are specified.

Additionally: clarify comments on the make targets, which are
confusingly named, and stop installing goimports since it seems
it was never used.
2021-12-07 07:46:08 -08:00
Zac Bergquist 6808d6acb4 Create separate builds for CentOS7 (+fips)
Add new buildboxes for centos7 and centos7-fips.

For now, we will continue to support both CentOS 6 and 7.
Eventually we will drop support for CentOS 6, and the only
supported CentOS builds will be these new CentOS 7 builds.

Fixes #9028
2021-12-02 10:30:03 -07:00
Joel 074dbe7f5d Fix the buildbox (again) (#8892)
* remove toolchain

* don't force env

* Revert "don't force env"

This reverts commit 1e216365f3.

* linter fix and update bindings

* spec toolchain version

* resolve perms
2021-11-08 14:54:07 -07:00
Joel ea64d9db29 Fix Rust buildbox (#8881) 2021-11-05 14:05:19 -07:00
JoelandZac Bergquist a833907647 Rust & Desktop Access fixes (#8822)
* update deps in manifest and lockfile

* fixes and updates to docker and profiles

* lint rust

* fix typo

* resolve clippy lints

* fix typo

* mark risk functions unsafe

* fmt + clean up the last lints#

* verify lockfile up to date

* disable lto since it doesn't work with two rust libs

* merge lock check and lint

* Add missing license header to Rust files

And update Makefile to ensure they are checked

Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
2021-11-05 12:35:20 -07:00
Brian Joerger 20da22ca35 API release automation with go script (#8484) 2021-10-28 10:15:47 -07:00
Trent Clarke 5463c799ea Fix race condition in PipeNetCon (#8643)
The race condition detector is being tripped by a concurrent `Write` and
`Close` in the `PipeNetCon` in several integration tests. This is a naive
fix to serialize the write and close operations to resolve the race
condition.

The affected tests were also not handling asynchronous error reporting
correctly (i.e. it's not legal to call `require.XYZ()` from a goroutine
other than the one executing the test function.). This patch introduces
some plumbing to marshal asynchronous errors back into the main test
routine before failing the test.
2021-10-28 09:38:51 +11:00
Zac Bergquist cdf053eba7 Stop linking lcrypto and lssl
The Rust code now uses vendored mode [1] to statically link openssl,
so we no longer need dynamic linking for these libraries.

This also resolves an issue where extra flags were needed to build
locally on macOS.

[1]: https://docs.rs/openssl/0.10.36/openssl/#vendored
2021-10-27 10:51:43 -06:00
Zac Bergquist edf9b927f4 Add Rust to buildbox
- Ensure Rust is installed in the buildbox image
- Install Rust toolchains for each arch we support
- Use openssl's vendor feature to ensure we always link a static lib
- Automatically include RDP client if Rust is detected
2021-10-27 10:51:43 -06:00
Trent Clarke eca9603376 Include package-level failures in formatted test output (#8698)
In some cases, it's possible for a package to be marked as a test
failure even if no tests inside it have failed. The motivating example
for this change is a timeout: a test overshooting the allotted timeout
is considered by go test to be a package-level failure, even if no
tests inside the package are considered failures.

This led to cases where the user would see an "All tests passed"
message from the go test filter, but still mysteriously fail the make
step.

To address this, the test renderer now:

  * treats package-level pass/fail/skip events as first-class citizens
    and includes them in its event count,
  * tracks the cached test output at both a package and individual test
    level, and
  * displays the whole package output if a package is marked as failed,
    but only if there is no obvious failed test top account for the
    package-level failure.

This patch also removes the json files created by the unit tests, as
they are not yet needed for anything.
2021-10-27 11:14:27 +11:00
Russell Jones 78b2c1e8b0 Fixed CentOS 6 builds.
Fixed issue that prevented Teleport 8 from being built on CentOS 6.
2021-10-25 10:52:55 -07:00
Russell Jones 675be8fc21 Updated Go to 1.17.2. 2021-10-22 14:01:25 -07:00
rosstimothy c730778960 Replace golint with revive (#8613) 2021-10-19 14:00:24 -04:00
Trent Clarke ad2ec86ab1 Revert "Adds Rust 1.55.0 to CI buildbox (#8606)" (#8652)
This reverts commit 179d7f975b.
2021-10-19 12:51:07 +11:00
Russell Jones 073f50ccd4 Remove webassets before Enterprise images.
Call "clean" target to remove webassets before building images.
2021-10-18 17:29:37 -07:00
Trent Clarke 179d7f975b Adds Rust 1.55.0 to CI buildbox (#8606) 2021-10-19 10:58:14 +11:00
Trent Clarke cc86d31d6d Make unit tests write JSON test logs (#8351)
This change makes the Teleport unit tests write a JSON log of all the tests that we run `make test-go`. It also includes a parsing script that will render the JSON log into a human-readable format during the test run, so that the working developer can see what the tests are doing without having to wade through JSON.

The log output is somewhat of a cross between the standard go test output, with pytest-style summaries at the end. 

I have limited the realtime report to package-level results (a package-level skip result means no tests file were found). It's trivial to output each test as it comes in, if that works better (but at ~1500 tests, it's a lot).

This is another step towards getting better visibility on our test suite. The idea is that we will eventually collect these test reports as build artifacts for further analysis.
2021-10-15 12:25:24 +11:00