2022-09-23 20:39:38 +00:00
|
|
|
import ./make-test-python.nix (
|
|
|
|
{ lib, pkgs, ... }:
|
|
|
|
{
|
|
|
|
name = "endlessh-go";
|
|
|
|
meta.maintainers = with lib.maintainers; [ azahi ];
|
2024-12-10 19:26:33 +00:00
|
|
|
|
2022-09-23 20:39:38 +00:00
|
|
|
nodes = {
|
|
|
|
server =
|
|
|
|
{ ... }:
|
|
|
|
{
|
|
|
|
services.endlessh-go = {
|
|
|
|
enable = true;
|
|
|
|
prometheus.enable = true;
|
|
|
|
openFirewall = true;
|
|
|
|
};
|
|
|
|
|
|
|
|
specialisation = {
|
|
|
|
unprivileged.configuration = {
|
|
|
|
services.endlessh-go = {
|
|
|
|
port = 2222;
|
|
|
|
prometheus.port = 9229;
|
2024-12-10 19:26:33 +00:00
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2022-09-23 20:39:38 +00:00
|
|
|
privileged.configuration = {
|
|
|
|
services.endlessh-go = {
|
|
|
|
port = 22;
|
|
|
|
prometheus.port = 92;
|
2024-12-10 19:26:33 +00:00
|
|
|
};
|
|
|
|
};
|
2022-09-23 20:39:38 +00:00
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
client =
|
|
|
|
{ pkgs, ... }:
|
|
|
|
{
|
|
|
|
environment.systemPackages = with pkgs; [
|
|
|
|
curl
|
|
|
|
netcat
|
|
|
|
];
|
2024-12-10 19:26:33 +00:00
|
|
|
};
|
2022-09-23 20:39:38 +00:00
|
|
|
};
|
2024-12-10 19:26:33 +00:00
|
|
|
|
2022-09-23 20:39:38 +00:00
|
|
|
testScript = ''
|
|
|
|
def activate_specialisation(name: str):
|
|
|
|
server.succeed(f"/run/booted-system/specialisation/{name}/bin/switch-to-configuration test >&2")
|
2024-12-10 19:26:33 +00:00
|
|
|
|
2022-09-23 20:39:38 +00:00
|
|
|
start_all()
|
2024-12-10 19:26:33 +00:00
|
|
|
|
2022-09-23 20:39:38 +00:00
|
|
|
with subtest("Unprivileged"):
|
|
|
|
activate_specialisation("unprivileged")
|
|
|
|
server.wait_for_unit("endlessh-go.service")
|
|
|
|
server.wait_for_open_port(2222)
|
|
|
|
server.wait_for_open_port(9229)
|
2024-10-11 19:30:19 +00:00
|
|
|
server.fail("curl -sSf server:9229/metrics | grep -q endlessh_client_closed_count_total")
|
2022-09-23 20:39:38 +00:00
|
|
|
client.succeed("nc -dvW5 server 2222")
|
2024-10-11 19:30:19 +00:00
|
|
|
server.succeed("curl -sSf server:9229/metrics | grep -q endlessh_client_closed_count_total")
|
|
|
|
client.fail("curl -sSfm 5 server:9229/metrics")
|
2024-12-10 19:26:33 +00:00
|
|
|
|
2022-09-23 20:39:38 +00:00
|
|
|
with subtest("Privileged"):
|
|
|
|
activate_specialisation("privileged")
|
|
|
|
server.wait_for_unit("endlessh-go.service")
|
|
|
|
server.wait_for_open_port(22)
|
|
|
|
server.wait_for_open_port(92)
|
2024-10-11 19:30:19 +00:00
|
|
|
server.fail("curl -sSf server:92/metrics | grep -q endlessh_client_closed_count_total")
|
2022-09-23 20:39:38 +00:00
|
|
|
client.succeed("nc -dvW5 server 22")
|
2024-10-11 19:30:19 +00:00
|
|
|
server.succeed("curl -sSf server:92/metrics | grep -q endlessh_client_closed_count_total")
|
|
|
|
client.fail("curl -sSfm 5 server:92/metrics")
|
2022-09-23 20:39:38 +00:00
|
|
|
'';
|
|
|
|
}
|
|
|
|
)
|