|
| 1 | +package e2e |
| 2 | + |
| 3 | +import ( |
| 4 | + "fmt" |
| 5 | + "strings" |
| 6 | + "testing" |
| 7 | + "time" |
| 8 | + |
| 9 | + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" |
| 10 | + utilrand "k8s.io/apimachinery/pkg/util/rand" |
| 11 | + "k8s.io/client-go/pkg/api" |
| 12 | + "k8s.io/client-go/pkg/api/v1" |
| 13 | + "k8s.io/client-go/pkg/apis/extensions/v1beta1" |
| 14 | +) |
| 15 | + |
| 16 | +func TestNetwork(t *testing.T) { |
| 17 | + // |
| 18 | + // 1. create nginx service |
| 19 | + di, _, err := api.Codecs.UniversalDecoder().Decode(nginxDepNT, nil, &v1beta1.Deployment{}) |
| 20 | + if err != nil { |
| 21 | + t.Fatalf("unable to decode deployment manifest: %v", err) |
| 22 | + } |
| 23 | + |
| 24 | + d, ok := di.(*v1beta1.Deployment) |
| 25 | + if !ok { |
| 26 | + t.Fatalf("expected manifest to decode into *api.deployment, got %T", di) |
| 27 | + } |
| 28 | + _, err = client.ExtensionsV1beta1().Deployments(namespace).Create(d) |
| 29 | + if err != nil { |
| 30 | + t.Fatal(err) |
| 31 | + } |
| 32 | + |
| 33 | + deleteDeployment := func() { |
| 34 | + delPropPolicy := metav1.DeletePropagationForeground |
| 35 | + client.ExtensionsV1beta1().Deployments(namespace).Delete("nginx-deployment-nt", &metav1.DeleteOptions{ |
| 36 | + PropagationPolicy: &delPropPolicy, |
| 37 | + }) |
| 38 | + } |
| 39 | + defer deleteDeployment() |
| 40 | + |
| 41 | + if err := retry(10, time.Second*10, getNginxPod); err != nil { |
| 42 | + t.Fatalf("timed out waiting for nginx pod: %v", err) |
| 43 | + } |
| 44 | + |
| 45 | + si, _, err := api.Codecs.UniversalDecoder().Decode(nginxSVCNT, nil, &v1.Service{}) |
| 46 | + if err != nil { |
| 47 | + t.Fatalf("unable to decode service manifest: %v", err) |
| 48 | + } |
| 49 | + s, ok := si.(*v1.Service) |
| 50 | + if !ok { |
| 51 | + t.Fatalf("expected manifest to decode into *api.service, got %T", si) |
| 52 | + } |
| 53 | + _, err = client.CoreV1().Services(namespace).Create(s) |
| 54 | + if err != nil { |
| 55 | + t.Fatal(err) |
| 56 | + } |
| 57 | + defer client.CoreV1().Services(namespace).Delete("nginx-service-nt", &metav1.DeleteOptions{}) |
| 58 | + |
| 59 | + // |
| 60 | + // 2. create a wget pod that hits the nginx service |
| 61 | + testPodName := fmt.Sprintf("%s-%s", "wget-pod-nt", utilrand.String(5)) |
| 62 | + wgetPodNT.ObjectMeta.Name = testPodName |
| 63 | + _, err = client.CoreV1().Pods(namespace).Create(wgetPodNT) |
| 64 | + if err != nil { |
| 65 | + t.Fatal(err) |
| 66 | + } |
| 67 | + |
| 68 | + if err := retry(10, time.Second*10, getPod(testPodName)); err != nil { |
| 69 | + t.Fatalf(fmt.Sprintf("timed out waiting for wget pod to succeed: %v", err)) |
| 70 | + } |
| 71 | + |
| 72 | + t.Run("DefaultDeny", HelperDefaultDeny) |
| 73 | + t.Run("NetworkPolicy", HelperPolicy) |
| 74 | +} |
| 75 | + |
| 76 | +func HelperDefaultDeny(t *testing.T) { |
| 77 | + // |
| 78 | + // 3. set DefaultDeny policy |
| 79 | + npi, _, err := api.Codecs.UniversalDecoder().Decode(defaultDenyNetworkPolicy, nil, &v1beta1.NetworkPolicy{}) |
| 80 | + if err != nil { |
| 81 | + t.Fatalf("unable to decode network policy manifest: %v", err) |
| 82 | + } |
| 83 | + |
| 84 | + np, ok := npi.(*v1beta1.NetworkPolicy) |
| 85 | + if !ok { |
| 86 | + t.Fatalf("expected manifest to decode into *api.networkpolicy, got %T", npi) |
| 87 | + } |
| 88 | + |
| 89 | + httpRestClient := client.ExtensionsV1beta1().RESTClient() |
| 90 | + uri := fmt.Sprintf("/apis/%s/%s/namespaces/%s/%s", |
| 91 | + strings.ToLower("extensions"), |
| 92 | + strings.ToLower("v1beta1"), |
| 93 | + strings.ToLower(namespace), |
| 94 | + strings.ToLower("NetworkPolicies")) |
| 95 | + |
| 96 | + result := httpRestClient.Post().RequestURI(uri).Body(np).Do() |
| 97 | + if result.Error() != nil { |
| 98 | + t.Fatal(result.Error()) |
| 99 | + } |
| 100 | + defer func() { |
| 101 | + uri = fmt.Sprintf("/apis/%s/%s/namespaces/%s/%s/%s", |
| 102 | + strings.ToLower("extensions"), |
| 103 | + strings.ToLower("v1beta1"), |
| 104 | + strings.ToLower(namespace), |
| 105 | + strings.ToLower("NetworkPolicies"), |
| 106 | + strings.ToLower(np.ObjectMeta.Name)) |
| 107 | + |
| 108 | + result = httpRestClient.Delete().RequestURI(uri).Do() |
| 109 | + if result.Error() != nil { |
| 110 | + t.Fatal(result.Error()) |
| 111 | + } |
| 112 | + |
| 113 | + }() |
| 114 | + |
| 115 | + // |
| 116 | + // 4. create a wget pod that fails to hit nginx service |
| 117 | + testPodName := fmt.Sprintf("%s-%s", "wget-pod-nt", utilrand.String(5)) |
| 118 | + wgetPodNT.ObjectMeta.Name = testPodName |
| 119 | + _, err = client.CoreV1().Pods(namespace).Create(wgetPodNT) |
| 120 | + if err != nil { |
| 121 | + t.Fatal(err) |
| 122 | + } |
| 123 | + |
| 124 | + if err := retry(10, time.Second*10, getFailedPod(testPodName)); err != nil { |
| 125 | + t.Fatalf(fmt.Sprintf("timed out waiting for wget pod to fail: %v", err)) |
| 126 | + } |
| 127 | +} |
| 128 | + |
| 129 | +func HelperPolicy(t *testing.T) { |
| 130 | + // |
| 131 | + // 5. create NetworkPolicy that allows `allow=access` |
| 132 | + npi, _, err := api.Codecs.UniversalDecoder().Decode(netPolicy, nil, &v1beta1.NetworkPolicy{}) |
| 133 | + if err != nil { |
| 134 | + t.Fatalf("unable to decode network policy manifest: %v", err) |
| 135 | + } |
| 136 | + |
| 137 | + np, ok := npi.(*v1beta1.NetworkPolicy) |
| 138 | + if !ok { |
| 139 | + t.Fatalf("expected manifest to decode into *api.networkpolicy, got %T", npi) |
| 140 | + } |
| 141 | + |
| 142 | + httpRestClient := client.ExtensionsV1beta1().RESTClient() |
| 143 | + uri := fmt.Sprintf("/apis/%s/%s/namespaces/%s/%s", |
| 144 | + strings.ToLower("extensions"), |
| 145 | + strings.ToLower("v1beta1"), |
| 146 | + strings.ToLower(namespace), |
| 147 | + strings.ToLower("NetworkPolicies")) |
| 148 | + |
| 149 | + result := httpRestClient.Post().RequestURI(uri).Body(np).Do() |
| 150 | + if result.Error() != nil { |
| 151 | + t.Fatal(result.Error()) |
| 152 | + } |
| 153 | + defer func() { |
| 154 | + uri = fmt.Sprintf("/apis/%s/%s/namespaces/%s/%s/%s", |
| 155 | + strings.ToLower("extensions"), |
| 156 | + strings.ToLower("v1beta1"), |
| 157 | + strings.ToLower(namespace), |
| 158 | + strings.ToLower("NetworkPolicies"), |
| 159 | + strings.ToLower(np.ObjectMeta.Name)) |
| 160 | + |
| 161 | + result = httpRestClient.Delete().RequestURI(uri).Do() |
| 162 | + if result.Error() != nil { |
| 163 | + t.Fatal(result.Error()) |
| 164 | + } |
| 165 | + |
| 166 | + }() |
| 167 | + |
| 168 | + // |
| 169 | + // 6. create a wget pod with label `allow=access` that hits the nginx service |
| 170 | + testPodName := fmt.Sprintf("%s-%s", "wget-pod-nt", utilrand.String(5)) |
| 171 | + wgetPodNT.ObjectMeta.Name = testPodName |
| 172 | + wgetPodNT.ObjectMeta.Labels = map[string]string{} |
| 173 | + wgetPodNT.ObjectMeta.Labels["allow"] = "access" |
| 174 | + _, err = client.CoreV1().Pods(namespace).Create(wgetPodNT) |
| 175 | + if err != nil { |
| 176 | + t.Fatal(err) |
| 177 | + } |
| 178 | + |
| 179 | + if err := retry(10, time.Second*10, getPod(testPodName)); err != nil { |
| 180 | + t.Fatalf(fmt.Sprintf("timed out waiting for wget pod to succeed: %v", err)) |
| 181 | + } |
| 182 | + |
| 183 | + // |
| 184 | + // 7. create a wget pod with label `allow=cant-access` that fails to the nginx service |
| 185 | + testPodName = fmt.Sprintf("%s-%s", "wget-pod-nt", utilrand.String(5)) |
| 186 | + wgetPodNT.ObjectMeta.Name = testPodName |
| 187 | + wgetPodNT.ObjectMeta.Labels["allow"] = "cant-access" |
| 188 | + _, err = client.CoreV1().Pods(namespace).Create(wgetPodNT) |
| 189 | + if err != nil { |
| 190 | + t.Fatal(err) |
| 191 | + } |
| 192 | + |
| 193 | + if err := retry(10, time.Second*10, getFailedPod(testPodName)); err != nil { |
| 194 | + t.Fatalf(fmt.Sprintf("timed out waiting for wget pod to fail: %v", err)) |
| 195 | + } |
| 196 | +} |
| 197 | + |
| 198 | +func getNginxPod() error { |
| 199 | + l, err := client.CoreV1().Pods(namespace).List(metav1.ListOptions{LabelSelector: "app=nginx"}) |
| 200 | + if err != nil || len(l.Items) == 0 { |
| 201 | + return fmt.Errorf("couldn't list pods: %v", err) |
| 202 | + } |
| 203 | + |
| 204 | + // take the first pod |
| 205 | + p := &l.Items[0] |
| 206 | + |
| 207 | + if p.Status.Phase != v1.PodRunning { |
| 208 | + return fmt.Errorf("pod not yet running: %v", p.Status.Phase) |
| 209 | + } |
| 210 | + return nil |
| 211 | +} |
| 212 | + |
| 213 | +func getPod(name string) func() error { |
| 214 | + return func() error { |
| 215 | + p, err := client.CoreV1().Pods(namespace).Get(name, metav1.GetOptions{}) |
| 216 | + if err != nil { |
| 217 | + return fmt.Errorf("couldn't get pod: %v", err) |
| 218 | + } |
| 219 | + if p.Status.Phase != v1.PodSucceeded { |
| 220 | + return fmt.Errorf("pod did not succeed: %v", p.Status.Phase) |
| 221 | + } |
| 222 | + return nil |
| 223 | + } |
| 224 | +} |
| 225 | + |
| 226 | +func getFailedPod(name string) func() error { |
| 227 | + return func() error { |
| 228 | + p, err := client.CoreV1().Pods(namespace).Get(name, metav1.GetOptions{}) |
| 229 | + if err != nil { |
| 230 | + return fmt.Errorf("couldn't get pod: %v", err) |
| 231 | + } |
| 232 | + if p.Status.Phase != v1.PodFailed { |
| 233 | + return fmt.Errorf("pod did not fail: %v", p.Status.Phase) |
| 234 | + } |
| 235 | + return nil |
| 236 | + } |
| 237 | +} |
| 238 | + |
| 239 | +var nginxDepNT = []byte(`apiVersion: apps/v1beta1 |
| 240 | +kind: Deployment |
| 241 | +metadata: |
| 242 | + name: nginx-deployment-nt |
| 243 | +spec: |
| 244 | + replicas: 3 |
| 245 | + template: |
| 246 | + metadata: |
| 247 | + labels: |
| 248 | + app: nginx |
| 249 | + spec: |
| 250 | + containers: |
| 251 | + - name: nginx |
| 252 | + image: nginx:1.8 |
| 253 | + ports: |
| 254 | + - containerPort: 80 |
| 255 | +`) |
| 256 | + |
| 257 | +var wgetPodNT = &v1.Pod{ |
| 258 | + ObjectMeta: metav1.ObjectMeta{ |
| 259 | + Namespace: namespace, |
| 260 | + }, |
| 261 | + Spec: v1.PodSpec{ |
| 262 | + Containers: []v1.Container{ |
| 263 | + { |
| 264 | + Name: "wget-container", |
| 265 | + Image: "busybox:1.26", |
| 266 | + Command: []string{"wget", "--timeout", "5", "nginx-service-nt"}, |
| 267 | + }, |
| 268 | + }, |
| 269 | + RestartPolicy: v1.RestartPolicyNever, |
| 270 | + }, |
| 271 | +} |
| 272 | + |
| 273 | +var nginxSVCNT = []byte(`apiVersion: v1 |
| 274 | +kind: Service |
| 275 | +metadata: |
| 276 | + name: nginx-service-nt |
| 277 | +spec: |
| 278 | + selector: |
| 279 | + app: nginx |
| 280 | + ports: |
| 281 | + - protocol: TCP |
| 282 | + port: 80 |
| 283 | + targetPort: 80 |
| 284 | +`) |
| 285 | + |
| 286 | +var defaultDenyNetworkPolicy = []byte(`kind: NetworkPolicy |
| 287 | +apiVersion: extensions/v1beta1 |
| 288 | +metadata: |
| 289 | + name: default-deny |
| 290 | +spec: |
| 291 | + podSelector: |
| 292 | +`) |
| 293 | + |
| 294 | +var netPolicy = []byte(`kind: NetworkPolicy |
| 295 | +apiVersion: extensions/v1beta1 |
| 296 | +metadata: |
| 297 | + name: access-nginx |
| 298 | +spec: |
| 299 | + podSelector: |
| 300 | + matchLabels: |
| 301 | + app: nginx |
| 302 | + ingress: |
| 303 | + - from: |
| 304 | + - podSelector: |
| 305 | + matchLabels: |
| 306 | + allow: access |
| 307 | +`) |
0 commit comments