breaking: rename ingress-cert -> ingress & add generateingress-and-cert
This commit is contained in:
parent
38d8050472
commit
167c58be08
2 changed files with 74 additions and 12 deletions
|
@ -1,4 +1,4 @@
|
||||||
(ns dda.c4k-common.ingress-cert
|
(ns dda.c4k-common.ingress
|
||||||
(:require
|
(:require
|
||||||
[clojure.spec.alpha :as s]
|
[clojure.spec.alpha :as s]
|
||||||
#?(:cljs [shadow.resource :as rc])
|
#?(:cljs [shadow.resource :as rc])
|
||||||
|
@ -18,12 +18,17 @@
|
||||||
(s/def ::service-port pos-int?)
|
(s/def ::service-port pos-int?)
|
||||||
(s/def ::fqdns (s/coll-of pred/fqdn-string?))
|
(s/def ::fqdns (s/coll-of pred/fqdn-string?))
|
||||||
|
|
||||||
|
(def simple-ingress? (s/keys :req-un [::fqdns ::service-name ::service-port]
|
||||||
|
:opt-un [::issuer]))
|
||||||
|
|
||||||
(def ingress? (s/keys :req-un [::fqdns ::app-name ::ingress-name ::service-name ::service-port]
|
(def ingress? (s/keys :req-un [::fqdns ::app-name ::ingress-name ::service-name ::service-port]
|
||||||
:opt-un [::issuer ::cert-name]))
|
:opt-un [::issuer ::cert-name]))
|
||||||
|
|
||||||
(def certificate? (s/keys :req-un [::fqdns ::app-name ::cert-name]
|
(def certificate? (s/keys :req-un [::fqdns ::app-name ::cert-name]
|
||||||
:opt-un [::issuer]))
|
:opt-un [::issuer]))
|
||||||
|
|
||||||
|
(def ingress-defaults {:issuer "staging"})
|
||||||
|
|
||||||
#?(:cljs
|
#?(:cljs
|
||||||
(defmethod yaml/load-resource :ingress [resource-name]
|
(defmethod yaml/load-resource :ingress [resource-name]
|
||||||
(case resource-name
|
(case resource-name
|
||||||
|
@ -66,3 +71,14 @@
|
||||||
(assoc-in [:spec :commonName] (first fqdns))
|
(assoc-in [:spec :commonName] (first fqdns))
|
||||||
(assoc-in [:spec :dnsNames] fqdns)
|
(assoc-in [:spec :dnsNames] fqdns)
|
||||||
(assoc-in [:spec :issuerRef :name] letsencrypt-issuer))))
|
(assoc-in [:spec :issuerRef :name] letsencrypt-issuer))))
|
||||||
|
|
||||||
|
(defn-spec generate-ingress-and-cert any?
|
||||||
|
[simple-ingress-config simple-ingress?]
|
||||||
|
(let [{:keys [service-name]} simple-ingress-config
|
||||||
|
config (merge {:app-name service-name
|
||||||
|
:ingress-name service-name
|
||||||
|
:cert-name service-name}
|
||||||
|
ingress-defaults
|
||||||
|
simple-ingress-config)]
|
||||||
|
[(generate-certificate config)
|
||||||
|
(generate-ingress config)]))
|
|
@ -1,13 +1,14 @@
|
||||||
(ns dda.c4k-common.ingress-cert-test
|
(ns dda.c4k-common.ingress-test
|
||||||
(:require
|
(:require
|
||||||
#?(:clj [clojure.test :refer [deftest is are testing run-tests]]
|
#?(:clj [clojure.test :refer [deftest is are testing run-tests]]
|
||||||
:cljs [cljs.test :refer-macros [deftest is are testing run-tests]])
|
:cljs [cljs.test :refer-macros [deftest is are testing run-tests]])
|
||||||
[clojure.spec.test.alpha :as st]
|
[clojure.spec.test.alpha :as st]
|
||||||
[dda.c4k-common.ingress-cert :as cut]))
|
[dda.c4k-common.ingress :as cut]))
|
||||||
|
|
||||||
(st/instrument `cut/generate-host-rule)
|
(st/instrument `cut/generate-host-rule)
|
||||||
(st/instrument `cut/generate-ingress)
|
(st/instrument `cut/generate-ingress)
|
||||||
(st/instrument `cut/generate-certificate)
|
(st/instrument `cut/generate-certificate)
|
||||||
|
(st/instrument `cut/generate-ingress-and-cert)
|
||||||
|
|
||||||
(deftest should-generate-rule
|
(deftest should-generate-rule
|
||||||
(is (= {:host "test.com",
|
(is (= {:host "test.com",
|
||||||
|
@ -26,14 +27,19 @@
|
||||||
{:name "test-io-https-ingress",
|
{:name "test-io-https-ingress",
|
||||||
:namespace "default",
|
:namespace "default",
|
||||||
:labels {:app.kubernetes.part-of "c4k-common-app"},
|
:labels {:app.kubernetes.part-of "c4k-common-app"},
|
||||||
:annotations #:traefik.ingress.kubernetes.io{:router.entrypoints "web, websecure", :router.middlewares "default-redirect-https@kubernetescrd"}}}
|
:annotations {:traefik.ingress.kubernetes.io/router.entrypoints
|
||||||
|
"web, websecure"
|
||||||
|
:traefik.ingress.kubernetes.io/router.middlewares
|
||||||
|
"default-redirect-https@kubernetescrd"
|
||||||
|
:metallb.universe.tf/address-pool "public"}}}
|
||||||
(dissoc (cut/generate-ingress
|
(dissoc (cut/generate-ingress
|
||||||
{:issuer "prod"
|
{:issuer "prod"
|
||||||
:service-name "test-io-service"
|
:service-name "test-io-service"
|
||||||
:app-name "c4k-common-app"
|
:app-name "c4k-common-app"
|
||||||
:service-port 80
|
:service-port 80
|
||||||
:ingress-name "test-io-https-ingress"
|
:ingress-name "test-io-https-ingress"
|
||||||
:fqdns ["test.de" "www.test.de" "test-it.de" "www.test-it.de"]}) :spec)))
|
:fqdns ["test.de" "www.test.de" "test-it.de"
|
||||||
|
"www.test-it.de"]}) :spec)))
|
||||||
(is (= {:tls
|
(is (= {:tls
|
||||||
[{:hosts
|
[{:hosts
|
||||||
["test.de" "www.test.de" "test-it.de" "www.test-it.de"],
|
["test.de" "www.test.de" "test-it.de" "www.test-it.de"],
|
||||||
|
@ -52,12 +58,14 @@
|
||||||
:http
|
:http
|
||||||
{:paths [{:pathType "Prefix", :path "/", :backend {:service {:name "test-io-service", :port {:number 80}}}}]}}]}
|
{:paths [{:pathType "Prefix", :path "/", :backend {:service {:name "test-io-service", :port {:number 80}}}}]}}]}
|
||||||
(:spec (cut/generate-ingress {:issuer "prod"
|
(:spec (cut/generate-ingress {:issuer "prod"
|
||||||
:app-name "c4k-common-app"
|
:app-name "c4k-common-app"
|
||||||
:service-name "test-io-service"
|
:service-name "test-io-service"
|
||||||
:service-port 80
|
:service-port 80
|
||||||
:ingress-name "test-io-https-ingress"
|
:ingress-name "test-io-https-ingress"
|
||||||
:cert-name "test-io-cert"
|
:cert-name "test-io-cert"
|
||||||
:fqdns ["test.de" "www.test.de" "test-it.de" "www.test-it.de"]})))))
|
:fqdns ["test.de" "www.test.de"
|
||||||
|
"test-it.de"
|
||||||
|
"www.test-it.de"]})))))
|
||||||
|
|
||||||
(deftest should-generate-certificate
|
(deftest should-generate-certificate
|
||||||
(is (= {:apiVersion "cert-manager.io/v1",
|
(is (= {:apiVersion "cert-manager.io/v1",
|
||||||
|
@ -75,4 +83,42 @@
|
||||||
(cut/generate-certificate {:fqdns ["test.de" "test.org" "www.test.de" "www.test.org"]
|
(cut/generate-certificate {:fqdns ["test.de" "test.org" "www.test.de" "www.test.org"]
|
||||||
:app-name "c4k-common-app"
|
:app-name "c4k-common-app"
|
||||||
:cert-name "test-io-cert"
|
:cert-name "test-io-cert"
|
||||||
:issuer "prod"}))))
|
:issuer "prod"}))))
|
||||||
|
|
||||||
|
(deftest should-generate-ingress-and-cert
|
||||||
|
(is (= [{:apiVersion "cert-manager.io/v1",
|
||||||
|
:kind "Certificate",
|
||||||
|
:metadata
|
||||||
|
{:name "web",
|
||||||
|
:labels {:app.kubernetes.part-of "web"},
|
||||||
|
:namespace "default"},
|
||||||
|
:spec
|
||||||
|
{:secretName "web",
|
||||||
|
:commonName "test.jit.si",
|
||||||
|
:duration "2160h",
|
||||||
|
:renewBefore "360h",
|
||||||
|
:dnsNames ["test.jit.si"],
|
||||||
|
:issuerRef {:name "staging", :kind "ClusterIssuer"}}}
|
||||||
|
{:apiVersion "networking.k8s.io/v1",
|
||||||
|
:kind "Ingress",
|
||||||
|
:metadata
|
||||||
|
{:name "web",
|
||||||
|
:namespace "default",
|
||||||
|
:labels {:app.kubernetes.part-of "web"},
|
||||||
|
:annotations
|
||||||
|
{:traefik.ingress.kubernetes.io/router.entrypoints "web, websecure",
|
||||||
|
:traefik.ingress.kubernetes.io/router.middlewares
|
||||||
|
"default-redirect-https@kubernetescrd",
|
||||||
|
:metallb.universe.tf/address-pool "public"}},
|
||||||
|
:spec
|
||||||
|
{:tls [{:hosts ["test.jit.si"], :secretName "web"}],
|
||||||
|
:rules
|
||||||
|
[{:host "test.jit.si",
|
||||||
|
:http {:paths [{:path "/",
|
||||||
|
:pathType "Prefix",
|
||||||
|
:backend
|
||||||
|
{:service {:name "web",
|
||||||
|
:port {:number 80}}}}]}}]}}]
|
||||||
|
(cut/generate-ingress-and-cert {:fqdns ["test.jit.si"]
|
||||||
|
:service-name "web"
|
||||||
|
:service-port 80}))))
|
Loading…
Reference in a new issue