mirror of
https://github.com/psviderski/uncloud.git
synced 2026-08-26 11:03:34 +00:00
feat: Initial support for Compose configs (#116)
This commit is contained in:
@@ -0,0 +1,125 @@
|
||||
// Implementation of Config feature from the Compose spec
|
||||
package api
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strconv"
|
||||
)
|
||||
|
||||
// ConfigSpec defines a configuration object that can be mounted into containers
|
||||
type ConfigSpec struct {
|
||||
Name string
|
||||
|
||||
// Content of the config when specified inline
|
||||
Content []byte `json:",omitempty"`
|
||||
|
||||
// Note: NOT IMPLEMENTED
|
||||
// External indicates this config already exists and should not be created
|
||||
// External bool `json:",omitempty"`
|
||||
|
||||
// Note: NOT IMPLEMENTED
|
||||
// Labels for the config
|
||||
// Labels map[string]string `json:",omitempty"`
|
||||
|
||||
// TODO: add support for "environment"
|
||||
}
|
||||
|
||||
func (c *ConfigSpec) Validate() error {
|
||||
if c.Name == "" {
|
||||
return fmt.Errorf("config name is required")
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// Equals compares two ConfigSpec instances
|
||||
func (c *ConfigSpec) Equals(other ConfigSpec) bool {
|
||||
return c.Name == other.Name &&
|
||||
bytes.Equal(c.Content, other.Content)
|
||||
}
|
||||
|
||||
// ConfigMount defines how a config is mounted into a container
|
||||
type ConfigMount struct {
|
||||
// ConfigName references a config defined in ServiceSpec.Configs by its Name field
|
||||
ConfigName string
|
||||
// ContainerPath is the absolute path where the config is mounted in the container
|
||||
ContainerPath string `json:",omitempty"`
|
||||
// Uid for the mounted config file
|
||||
Uid string `json:",omitempty"`
|
||||
// Gid for the mounted config file
|
||||
Gid string `json:",omitempty"`
|
||||
// Mode (file permissions) for the mounted config file
|
||||
Mode *os.FileMode `json:",omitempty"`
|
||||
}
|
||||
|
||||
func (c *ConfigMount) GetNumericUid() (*uint64, error) {
|
||||
if c.Uid == "" {
|
||||
return nil, nil
|
||||
}
|
||||
uid, err := strconv.ParseUint(c.Uid, 10, 64)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("invalid Uid '%s': %w", c.Uid, err)
|
||||
}
|
||||
if int(uid) < 0 {
|
||||
return nil, fmt.Errorf("invalid Uid '%s': value too high", c.Uid)
|
||||
}
|
||||
return &uid, nil
|
||||
}
|
||||
|
||||
func (c *ConfigMount) GetNumericGid() (*uint64, error) {
|
||||
if c.Gid == "" {
|
||||
return nil, nil
|
||||
}
|
||||
gid, err := strconv.ParseUint(c.Gid, 10, 64)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("invalid Gid '%s': %w", c.Gid, err)
|
||||
}
|
||||
if int(gid) < 0 {
|
||||
return nil, fmt.Errorf("invalid Gid '%s': value too high", c.Gid)
|
||||
}
|
||||
return &gid, nil
|
||||
}
|
||||
|
||||
func (c *ConfigMount) Validate() error {
|
||||
if c.ConfigName == "" {
|
||||
return fmt.Errorf("config mount source is required")
|
||||
}
|
||||
if _, err := c.GetNumericUid(); err != nil {
|
||||
return err
|
||||
}
|
||||
if _, err := c.GetNumericGid(); err != nil {
|
||||
return err
|
||||
}
|
||||
if c.ContainerPath != "" && !filepath.IsAbs(c.ContainerPath) {
|
||||
return fmt.Errorf("container path must be absolute")
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// ValidateConfigsAndMounts takes config specs and config mounts and validates that all mounts refer to existing specs
|
||||
func ValidateConfigsAndMounts(configs []ConfigSpec, mounts []ConfigMount) error {
|
||||
configMap := make(map[string]struct{})
|
||||
for _, cfg := range configs {
|
||||
if err := cfg.Validate(); err != nil {
|
||||
return fmt.Errorf("invalid config: %w", err)
|
||||
}
|
||||
if _, ok := configMap[cfg.Name]; ok {
|
||||
return fmt.Errorf("duplicate config name: '%s'", cfg.Name)
|
||||
}
|
||||
|
||||
configMap[cfg.Name] = struct{}{}
|
||||
}
|
||||
|
||||
for _, mount := range mounts {
|
||||
if err := mount.Validate(); err != nil {
|
||||
return fmt.Errorf("invalid config mount: %w", err)
|
||||
}
|
||||
if _, exists := configMap[mount.ConfigName]; !exists {
|
||||
return fmt.Errorf("config mount source '%s' does not refer to any defined config", mount.ConfigName)
|
||||
}
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
@@ -0,0 +1,294 @@
|
||||
package api
|
||||
|
||||
import (
|
||||
"os"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
// uint64Ptr is a convenience function to create a pointer to a uint64 value
|
||||
func uint64Ptr(v uint64) *uint64 {
|
||||
return &v
|
||||
}
|
||||
|
||||
func TestConfigMount_GetNumericUid(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
uid string
|
||||
expected *uint64
|
||||
wantErr string
|
||||
}{
|
||||
{
|
||||
name: "empty uid returns nil",
|
||||
uid: "",
|
||||
expected: nil,
|
||||
},
|
||||
{
|
||||
name: "valid numeric uid",
|
||||
uid: "1000",
|
||||
expected: uint64Ptr(1000),
|
||||
},
|
||||
{
|
||||
name: "zero uid",
|
||||
uid: "0",
|
||||
expected: uint64Ptr(0),
|
||||
},
|
||||
{
|
||||
name: "invalid non-numeric uid",
|
||||
uid: "root",
|
||||
wantErr: "invalid Uid 'root'",
|
||||
},
|
||||
{
|
||||
name: "negative uid",
|
||||
uid: "-1",
|
||||
wantErr: "invalid Uid",
|
||||
},
|
||||
{
|
||||
name: "very large uid",
|
||||
uid: "18446744073709551615", // max uint64
|
||||
wantErr: "invalid Uid '18446744073709551615': value too high",
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
mount := &ConfigMount{Uid: tt.uid}
|
||||
uid, err := mount.GetNumericUid()
|
||||
|
||||
if tt.wantErr != "" {
|
||||
require.Error(t, err)
|
||||
assert.Contains(t, err.Error(), tt.wantErr)
|
||||
assert.Nil(t, uid)
|
||||
return
|
||||
}
|
||||
|
||||
require.NoError(t, err)
|
||||
if tt.expected == nil {
|
||||
assert.Nil(t, uid)
|
||||
} else {
|
||||
require.NotNil(t, uid)
|
||||
assert.Equal(t, *tt.expected, *uid)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestConfigMount_GetNumericGid(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
gid string
|
||||
expected *uint64
|
||||
wantErr string
|
||||
}{
|
||||
{
|
||||
name: "empty gid returns nil",
|
||||
gid: "",
|
||||
expected: nil,
|
||||
},
|
||||
{
|
||||
name: "valid numeric gid",
|
||||
gid: "1000",
|
||||
expected: uint64Ptr(1000),
|
||||
},
|
||||
{
|
||||
name: "zero gid",
|
||||
gid: "0",
|
||||
expected: uint64Ptr(0),
|
||||
},
|
||||
{
|
||||
name: "invalid non-numeric gid",
|
||||
gid: "wheel",
|
||||
wantErr: "invalid Gid 'wheel'",
|
||||
},
|
||||
{
|
||||
name: "negative gid",
|
||||
gid: "-1",
|
||||
wantErr: "invalid Gid",
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
mount := &ConfigMount{Gid: tt.gid}
|
||||
gid, err := mount.GetNumericGid()
|
||||
|
||||
if tt.wantErr != "" {
|
||||
require.Error(t, err)
|
||||
assert.Contains(t, err.Error(), tt.wantErr)
|
||||
assert.Nil(t, gid)
|
||||
return
|
||||
}
|
||||
|
||||
require.NoError(t, err)
|
||||
if tt.expected == nil {
|
||||
assert.Nil(t, gid)
|
||||
} else {
|
||||
require.NotNil(t, gid)
|
||||
assert.Equal(t, *tt.expected, *gid)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestValidateConfigsAndMounts(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
mode := os.FileMode(0o644)
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
configs []ConfigSpec
|
||||
mounts []ConfigMount
|
||||
wantErr string
|
||||
}{
|
||||
{
|
||||
name: "empty configs and mounts",
|
||||
configs: []ConfigSpec{},
|
||||
mounts: []ConfigMount{},
|
||||
},
|
||||
{
|
||||
name: "valid configs without mounts",
|
||||
configs: []ConfigSpec{
|
||||
{Name: "config1", Content: []byte("content1")},
|
||||
{Name: "config2", Content: []byte("content2")},
|
||||
},
|
||||
mounts: []ConfigMount{},
|
||||
},
|
||||
{
|
||||
name: "valid configs with valid mounts",
|
||||
configs: []ConfigSpec{
|
||||
{Name: "config1", Content: []byte("content1")},
|
||||
{Name: "config2", Content: []byte("content2")},
|
||||
},
|
||||
mounts: []ConfigMount{
|
||||
{ConfigName: "config1", ContainerPath: "/etc/config1"},
|
||||
{ConfigName: "config2", ContainerPath: "/etc/config2", Uid: "1000", Gid: "1000"},
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "config with empty name",
|
||||
configs: []ConfigSpec{
|
||||
{Name: "", Content: []byte("content")},
|
||||
},
|
||||
mounts: []ConfigMount{},
|
||||
wantErr: "config name is required",
|
||||
},
|
||||
{
|
||||
name: "duplicate config names",
|
||||
configs: []ConfigSpec{
|
||||
{Name: "config1", Content: []byte("content1")},
|
||||
{Name: "config1", Content: []byte("content2")},
|
||||
},
|
||||
mounts: []ConfigMount{},
|
||||
wantErr: "duplicate config name: 'config1'",
|
||||
},
|
||||
{
|
||||
name: "mount with empty config name",
|
||||
configs: []ConfigSpec{
|
||||
{Name: "config1", Content: []byte("content1")},
|
||||
},
|
||||
mounts: []ConfigMount{
|
||||
{ConfigName: "", ContainerPath: "/etc/config"},
|
||||
},
|
||||
wantErr: "config mount source is required",
|
||||
},
|
||||
{
|
||||
name: "mount referencing non-existent config",
|
||||
configs: []ConfigSpec{
|
||||
{Name: "config1", Content: []byte("content1")},
|
||||
},
|
||||
mounts: []ConfigMount{
|
||||
{ConfigName: "nonexistent", ContainerPath: "/etc/config"},
|
||||
},
|
||||
wantErr: "config mount source 'nonexistent' does not refer to any defined config",
|
||||
},
|
||||
{
|
||||
name: "mount with invalid uid",
|
||||
configs: []ConfigSpec{
|
||||
{Name: "config1", Content: []byte("content1")},
|
||||
},
|
||||
mounts: []ConfigMount{
|
||||
{ConfigName: "config1", ContainerPath: "/etc/config", Uid: "invalid"},
|
||||
},
|
||||
wantErr: "invalid Uid 'invalid'",
|
||||
},
|
||||
{
|
||||
name: "mount with invalid gid",
|
||||
configs: []ConfigSpec{
|
||||
{Name: "config1", Content: []byte("content1")},
|
||||
},
|
||||
mounts: []ConfigMount{
|
||||
{ConfigName: "config1", ContainerPath: "/etc/config", Gid: "invalid"},
|
||||
},
|
||||
wantErr: "invalid Gid 'invalid'",
|
||||
},
|
||||
{
|
||||
name: "mount with relative container path",
|
||||
configs: []ConfigSpec{
|
||||
{Name: "config1", Content: []byte("content1")},
|
||||
},
|
||||
mounts: []ConfigMount{
|
||||
{ConfigName: "config1", ContainerPath: "relative/path"},
|
||||
},
|
||||
wantErr: "container path must be absolute",
|
||||
},
|
||||
{
|
||||
name: "mount with empty container path",
|
||||
configs: []ConfigSpec{
|
||||
{Name: "config1", Content: []byte("content1")},
|
||||
},
|
||||
mounts: []ConfigMount{
|
||||
{ConfigName: "config1", ContainerPath: ""},
|
||||
},
|
||||
// Empty path is allowed
|
||||
},
|
||||
{
|
||||
name: "mount with absolute container path",
|
||||
configs: []ConfigSpec{
|
||||
{Name: "config1", Content: []byte("content1")},
|
||||
},
|
||||
mounts: []ConfigMount{
|
||||
{ConfigName: "config1", ContainerPath: "/absolute/path"},
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "complex valid scenario",
|
||||
configs: []ConfigSpec{
|
||||
{Name: "nginx-conf", Content: []byte("server { listen 80; }")},
|
||||
{Name: "app-config", Content: []byte("debug=true")},
|
||||
{Name: "cert", Content: []byte("-----BEGIN CERTIFICATE-----")},
|
||||
},
|
||||
mounts: []ConfigMount{
|
||||
{ConfigName: "nginx-conf", ContainerPath: "/etc/nginx/nginx.conf", Uid: "0", Gid: "0", Mode: &mode},
|
||||
{ConfigName: "app-config", ContainerPath: "/app/config.env"},
|
||||
{ConfigName: "cert", ContainerPath: "/etc/ssl/cert.pem", Uid: "1000", Gid: "1000"},
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
err := ValidateConfigsAndMounts(tt.configs, tt.mounts)
|
||||
|
||||
if tt.wantErr != "" {
|
||||
require.Error(t, err)
|
||||
assert.Contains(t, err.Error(), tt.wantErr)
|
||||
return
|
||||
}
|
||||
|
||||
require.NoError(t, err)
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -60,6 +60,8 @@ type ServiceSpec struct {
|
||||
Replicas uint `json:",omitempty"`
|
||||
// Volumes is list of data volumes that can be mounted into the container.
|
||||
Volumes []VolumeSpec
|
||||
// Configs is list of configuration objects that can be mounted into the container.
|
||||
Configs []ConfigSpec
|
||||
}
|
||||
|
||||
// CaddyConfig returns the Caddy reverse proxy configuration for the service or an empty string if it's not defined.
|
||||
@@ -79,6 +81,15 @@ func (s *ServiceSpec) Volume(name string) (VolumeSpec, bool) {
|
||||
return VolumeSpec{}, false
|
||||
}
|
||||
|
||||
func (s *ServiceSpec) Config(name string) (ConfigSpec, bool) {
|
||||
for _, c := range s.Configs {
|
||||
if c.Name == name {
|
||||
return c, true
|
||||
}
|
||||
}
|
||||
return ConfigSpec{}, false
|
||||
}
|
||||
|
||||
// MountedDockerVolumes returns the list of volumes of VolumeTypeVolume type that are mounted into the container.
|
||||
func (s *ServiceSpec) MountedDockerVolumes() []VolumeSpec {
|
||||
volumes := make(map[string]VolumeSpec)
|
||||
@@ -157,6 +168,7 @@ func (s *ServiceSpec) Validate() error {
|
||||
}
|
||||
}
|
||||
|
||||
// Validate volumes
|
||||
volumeNames := make(map[string]struct{})
|
||||
for _, v := range s.Volumes {
|
||||
if err := v.Validate(); err != nil {
|
||||
@@ -177,6 +189,11 @@ func (s *ServiceSpec) Validate() error {
|
||||
}
|
||||
}
|
||||
|
||||
// Validate configs
|
||||
if err := ValidateConfigsAndMounts(s.Configs, s.Container.ConfigMounts); err != nil {
|
||||
return fmt.Errorf("validate service configs and mounts: %w", err)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -230,6 +247,9 @@ type ContainerSpec struct {
|
||||
// VolumeMounts specifies how volumes are mounted into the container filesystem.
|
||||
// Each mount references a volume defined in ServiceSpec.Volumes.
|
||||
VolumeMounts []VolumeMount
|
||||
// ConfigMounts specifies how configs are mounted into the container filesystem.
|
||||
// Each mount references a config defined in ServiceSpec.Configs.
|
||||
ConfigMounts []ConfigMount
|
||||
// Volumes is list of data volumes to mount into the container.
|
||||
// TODO(lhf): delete all usage, has been replaced with []VolumeMounts.
|
||||
Volumes []string
|
||||
|
||||
Reference in New Issue
Block a user