Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
112 changes: 112 additions & 0 deletions tests/ansible/playbooks/openshell-k3s-ha-tls.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,112 @@
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0

---
- import_playbook: openshell-k3s.yaml

- name: Add PostgreSQL and TLS to the K3s test installation
hosts: all
become: true
gather_facts: false
tasks:
- name: Copy PostgreSQL fixture
ansible.builtin.copy:
src: "{{ openshell_postgres_fixture }}"
dest: /var/lib/openshell/artifacts/postgres.yaml
mode: "0600"

- name: Apply PostgreSQL fixture
ansible.builtin.command:
argv: [/usr/local/bin/k3s, kubectl, --namespace, openshell, apply, --filename, /var/lib/openshell/artifacts/postgres.yaml]

- name: Wait for PostgreSQL
ansible.builtin.command:
argv: [/usr/local/bin/k3s, kubectl, --namespace, openshell, rollout, status, deployment/openshell-e2e-postgres, --timeout=300s]
changed_when: false

- name: Write PostgreSQL and TLS values overlay
ansible.builtin.copy:
dest: /var/lib/openshell/artifacts/values-ha-tls.yaml
mode: "0600"
content: |
replicaCount: 3
workload:
kind: deployment
server:
externalDbSecret: openshell-e2e-postgres-credentials
disableTls: false
auth:
# Kubernetes has no mTLS user-identity mode. Require the client
# certificate at the TLS layer and use the fixture's dev user.
allowUnauthenticatedUsers: true

- name: Apply PostgreSQL and TLS overlay to OpenShell
ansible.builtin.command:
argv:
- /usr/local/bin/helm
- upgrade
- openshell
- /var/lib/openshell/artifacts/helm-chart.tgz
- --namespace
- openshell
- --values
- /var/lib/openshell/artifacts/values.yaml
- --values
- /var/lib/openshell/artifacts/values-ha-tls.yaml
- --wait
- --timeout=5m
environment:
KUBECONFIG: /etc/rancher/k3s/k3s.yaml

- name: Restart gateway forwarder after TLS upgrade
ansible.builtin.systemd_service:
name: openshell-k3s-port-forward.service
state: restarted

- name: Read chart client TLS Secret
ansible.builtin.command:
argv: [/usr/local/bin/k3s, kubectl, --namespace, openshell, get, secret, openshell-client-tls, --output, json]
register: k3s_client_tls
changed_when: false
no_log: true

- name: Create guest mTLS directory
ansible.builtin.file:
path: /home/tmachine/.config/openshell/gateways/tmachine/mtls
state: directory
owner: tmachine
group: tmachine
mode: "0700"

- name: Write guest client TLS bundle
ansible.builtin.copy:
content: "{{ (k3s_client_tls.stdout | from_json).data[item] | b64decode }}"
dest: "/home/tmachine/.config/openshell/gateways/tmachine/mtls/{{ item }}"
owner: tmachine
group: tmachine
mode: "0600"
loop: [ca.crt, tls.crt, tls.key]
no_log: true

- name: Remove baseline guest gateway registration
become: false
ansible.builtin.command:
argv: [/usr/local/bin/openshell, gateway, remove, tmachine]

- name: Register guest gateway
ansible.builtin.include_role:
name: openshell_client
apply:
become: false
vars:
openshell_client_gateway_endpoint: https://localhost:17670

- name: Wait for authenticated gateway API
become: false
ansible.builtin.command:
argv: [/usr/local/bin/openshell, sandbox, list, --output, json]
register: k3s_gateway_api
until: k3s_gateway_api.rc == 0
retries: 24
delay: 5
changed_when: false
14 changes: 14 additions & 0 deletions tests/config.nix
Original file line number Diff line number Diff line change
Expand Up @@ -94,6 +94,20 @@ let
openshell_supervisor_image = "../artifacts/images/openshell-supervisor-tmachine.tar";
};
}
{
name = "k3s-ha-tls";
use_galaxy = false;
playbooks = [ "ansible/playbooks/openshell-k3s-ha-tls.yaml" ];
inputs = {
openshell_postgres_fixture = "../e2e/kubernetes/postgres-fixture.yaml";
agent_sandbox_version = "0.5.0";
openshell_cli_binary = "../artifacts/binaries/${muslTarget}/openshell";
openshell_gateway_image = "../artifacts/images/openshell-gateway-tmachine.tar";
openshell_helm_chart = "../artifacts/helm/helm-chart-0.0.0.tgz";
openshell_sandbox_image = "../artifacts/images/openshell-sandbox-tmachine.tar";
openshell_supervisor_image = "../artifacts/images/openshell-supervisor-tmachine.tar";
};
}
{
name = "none";
use_galaxy = false;
Expand Down
Loading