Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add e2e test for HTTP cert SAN update and verification #1244

Merged

Conversation

thbkrkr
Copy link
Contributor

@thbkrkr thbkrkr commented Jul 15, 2019

Add an e2e test to cover SAN usage and cert verification in 5 steps:

  • Create an ES cluster with a load balancer HTTP service
  • Retrieve the ES CA certificate
  • Eventually retrieve the ES load balancer public IP
  • Check that ES is not reachable with cert verification (error contains x509: cannot validate certificate)
  • Add the load balancer IP to the SAN and update the ES definition
  • Check that ES is reachable with cert verification (and returns 401)
    --- PASS: TestUpdateHTTPCertSAN (238.56s)
    --- PASS: TestUpdateHTTPCertSAN/K8S_should_be_accessible (0.17s)
    --- PASS: TestUpdateHTTPCertSAN/Elasticsearch_CRDs_should_exist (0.07s)
    --- PASS: TestUpdateHTTPCertSAN/Remove_Elasticsearch_if_it_already_exists (0.17s)
    --- PASS: TestUpdateHTTPCertSAN/Creating_an_Elasticsearch_cluster_should_succeed (0.08s)
    --- PASS: TestUpdateHTTPCertSAN/Elasticsearch_cluster_should_be_created (0.05s)
    --- PASS: TestUpdateHTTPCertSAN/ES_certificate_authority_should_be_set_and_deployed (3.18s)
    --- PASS: TestUpdateHTTPCertSAN/ES_version_should_be_the_expected_one (0.06s)
    --- PASS: TestUpdateHTTPCertSAN/ES_pods_should_eventually_be_running (150.88s)
    --- PASS: TestUpdateHTTPCertSAN/ES_services_should_be_created (0.06s)
    --- PASS: TestUpdateHTTPCertSAN/ES_pods_should_eventually_be_ready (12.33s)
    --- PASS: TestUpdateHTTPCertSAN/ES_pods_should_eventually_have_a_certificate (0.12s)
    --- PASS: TestUpdateHTTPCertSAN/ES_services_should_have_endpoints (0.06s)
    --- PASS: TestUpdateHTTPCertSAN/ES_cluster_health_should_eventually_be_green (9.20s)
    --- PASS: TestUpdateHTTPCertSAN/ES_cluster_UUID_should_eventually_appear_in_the_ES_status (0.06s)
    --- PASS: TestUpdateHTTPCertSAN/Elastic_password_should_be_available (0.06s)
    --- PASS: TestUpdateHTTPCertSAN/Elasticsearch_data_volumes_should_be_of_the_specified_type (0.07s)
    --- PASS: TestUpdateHTTPCertSAN/Every_secret_should_be_set_so_that_we_can_build_an_ES_client (0.11s)
    --- PASS: TestUpdateHTTPCertSAN/ES_cluster_health_endpoint_should_eventually_be_reachable (2.89s)
    --- PASS: TestUpdateHTTPCertSAN/ES_version_should_be_the_expected_one#01 (0.06s)
    --- PASS: TestUpdateHTTPCertSAN/ES_endpoint_should_eventually_be_reachable (0.06s)
    --- PASS: TestUpdateHTTPCertSAN/ES_nodes_topology_should_eventually_be_the_expected_one (0.13s)
    --- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 
    --- PASS: TestUpdateHTTPCertSAN/Retrieve_ES_certificate (0.10s)
    --- PASS: TestUpdateHTTPCertSAN/Retrieve_ES_public_IP (0.05s)
    --- PASS: TestUpdateHTTPCertSAN/Check_ES_is_not_reachable_with_cert_verification (0.12s)
    --- PASS: TestUpdateHTTPCertSAN/Add_load_balancer_IP_to_the_SAN (0.12s)
    --- PASS: TestUpdateHTTPCertSAN/Check_ES_is_reachable_with_cert_verification (50.07s)
    --- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 
    --- PASS: TestUpdateHTTPCertSAN/Deleting_Elasticsearch_should_return_no_error (0.07s)
    --- PASS: TestUpdateHTTPCertSAN/Elasticsearch_should_not_be_there_anymore (3.11s)
    --- PASS: TestUpdateHTTPCertSAN/Elasticsearch_pods_should_be_eventually_be_removed (3.12s)
PASS
ok      github.com/elastic/cloud-on-k8s/operators/test/e2e/es   238.572s

Resolves #724.

Copy link
Contributor

@sebgl sebgl left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@thbkrkr thbkrkr merged commit ef4782d into elastic:master Jul 16, 2019
@thbkrkr thbkrkr deleted the add-e2e-test-update-http-cert-san-verif branch July 16, 2019 15:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Create an e2e test to cover SAN usage and cert verification
2 participants