diff --git a/tests/ansible/playbooks/openshell-k3s-ha-tls.yaml b/tests/ansible/playbooks/openshell-k3s-ha-tls.yaml new file mode 100644 index 0000000000..51df48660c --- /dev/null +++ b/tests/ansible/playbooks/openshell-k3s-ha-tls.yaml @@ -0,0 +1,112 @@ +# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. +# SPDX-License-Identifier: Apache-2.0 + +--- +- import_playbook: openshell-k3s.yaml + +- name: Add PostgreSQL and TLS to the K3s test installation + hosts: all + become: true + gather_facts: false + tasks: + - name: Copy PostgreSQL fixture + ansible.builtin.copy: + src: "{{ openshell_postgres_fixture }}" + dest: /var/lib/openshell/artifacts/postgres.yaml + mode: "0600" + + - name: Apply PostgreSQL fixture + ansible.builtin.command: + argv: [/usr/local/bin/k3s, kubectl, --namespace, openshell, apply, --filename, /var/lib/openshell/artifacts/postgres.yaml] + + - name: Wait for PostgreSQL + ansible.builtin.command: + argv: [/usr/local/bin/k3s, kubectl, --namespace, openshell, rollout, status, deployment/openshell-e2e-postgres, --timeout=300s] + changed_when: false + + - name: Write PostgreSQL and TLS values overlay + ansible.builtin.copy: + dest: /var/lib/openshell/artifacts/values-ha-tls.yaml + mode: "0600" + content: | + replicaCount: 3 + workload: + kind: deployment + server: + externalDbSecret: openshell-e2e-postgres-credentials + disableTls: false + auth: + # Kubernetes has no mTLS user-identity mode. Require the client + # certificate at the TLS layer and use the fixture's dev user. + allowUnauthenticatedUsers: true + + - name: Apply PostgreSQL and TLS overlay to OpenShell + ansible.builtin.command: + argv: + - /usr/local/bin/helm + - upgrade + - openshell + - /var/lib/openshell/artifacts/helm-chart.tgz + - --namespace + - openshell + - --values + - /var/lib/openshell/artifacts/values.yaml + - --values + - /var/lib/openshell/artifacts/values-ha-tls.yaml + - --wait + - --timeout=5m + environment: + KUBECONFIG: /etc/rancher/k3s/k3s.yaml + + - name: Restart gateway forwarder after TLS upgrade + ansible.builtin.systemd_service: + name: openshell-k3s-port-forward.service + state: restarted + + - name: Read chart client TLS Secret + ansible.builtin.command: + argv: [/usr/local/bin/k3s, kubectl, --namespace, openshell, get, secret, openshell-client-tls, --output, json] + register: k3s_client_tls + changed_when: false + no_log: true + + - name: Create guest mTLS directory + ansible.builtin.file: + path: /home/tmachine/.config/openshell/gateways/tmachine/mtls + state: directory + owner: tmachine + group: tmachine + mode: "0700" + + - name: Write guest client TLS bundle + ansible.builtin.copy: + content: "{{ (k3s_client_tls.stdout | from_json).data[item] | b64decode }}" + dest: "/home/tmachine/.config/openshell/gateways/tmachine/mtls/{{ item }}" + owner: tmachine + group: tmachine + mode: "0600" + loop: [ca.crt, tls.crt, tls.key] + no_log: true + + - name: Remove baseline guest gateway registration + become: false + ansible.builtin.command: + argv: [/usr/local/bin/openshell, gateway, remove, tmachine] + + - name: Register guest gateway + ansible.builtin.include_role: + name: openshell_client + apply: + become: false + vars: + openshell_client_gateway_endpoint: https://localhost:17670 + + - name: Wait for authenticated gateway API + become: false + ansible.builtin.command: + argv: [/usr/local/bin/openshell, sandbox, list, --output, json] + register: k3s_gateway_api + until: k3s_gateway_api.rc == 0 + retries: 24 + delay: 5 + changed_when: false diff --git a/tests/config.nix b/tests/config.nix index 4bf7488ff8..2cb6d99a04 100644 --- a/tests/config.nix +++ b/tests/config.nix @@ -94,6 +94,20 @@ let openshell_supervisor_image = "../artifacts/images/openshell-supervisor-tmachine.tar"; }; } + { + name = "k3s-ha-tls"; + use_galaxy = false; + playbooks = [ "ansible/playbooks/openshell-k3s-ha-tls.yaml" ]; + inputs = { + openshell_postgres_fixture = "../e2e/kubernetes/postgres-fixture.yaml"; + agent_sandbox_version = "0.5.0"; + openshell_cli_binary = "../artifacts/binaries/${muslTarget}/openshell"; + openshell_gateway_image = "../artifacts/images/openshell-gateway-tmachine.tar"; + openshell_helm_chart = "../artifacts/helm/helm-chart-0.0.0.tgz"; + openshell_sandbox_image = "../artifacts/images/openshell-sandbox-tmachine.tar"; + openshell_supervisor_image = "../artifacts/images/openshell-supervisor-tmachine.tar"; + }; + } { name = "none"; use_galaxy = false;