Repository navigation
Expand file tree
/
Copy pathrun
More file actions
executable file
·173 lines (144 loc) · 4.67 KB
/
Copy pathrun
File metadata and controls
executable file
·173 lines (144 loc) · 4.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
#!/bin/bash
set -eu -o pipefail
CONTAINER_NAME=tcpdump
IMAGE_NAME=timjdfletcher/${CONTAINER_NAME}
GOSS_IMAGE="timjdfletcher/goss"
IMAGE_TAG=tmp
PLATFORMS="linux/amd64,linux/arm64"
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
log() {
echo "==> $*"
}
_ensure_goss_image() {
if ! docker image inspect "${GOSS_IMAGE}:${IMAGE_TAG}" >/dev/null 2>&1; then
log "Goss image not found, building..."
(cd "${SCRIPT_DIR}/../goss" && ./run build)
fi
}
_ensure_goss() {
_ensure_goss_image
local goss_dir="${PWD}/.goss-bin"
if [ ! -x "${goss_dir}/goss" ]; then
log "Extracting goss from ${GOSS_IMAGE}:${IMAGE_TAG}..."
mkdir -p "${goss_dir}"
docker rm goss-extract 2>/dev/null || true
docker create --name goss-extract "${GOSS_IMAGE}:${IMAGE_TAG}" >/dev/null
docker cp goss-extract:/goss "${goss_dir}/goss"
docker rm goss-extract >/dev/null
fi
}
_buildx_setup() {
docker buildx use builder 2>/dev/null || docker buildx create --name builder --use
docker buildx inspect --bootstrap
}
build() {
log "Building ${IMAGE_NAME}:${IMAGE_TAG}"
_buildx_setup
docker buildx build --load --tag "${IMAGE_NAME}:${IMAGE_TAG}" .
docker tag "${IMAGE_NAME}:${IMAGE_TAG}" "${IMAGE_NAME}:latest"
}
test() {
build
_ensure_goss
log "Running goss build-time tests..."
docker run --rm \
-v "${PWD}/.goss-bin:/goss-bin:ro" \
-v "${PWD}/goss/tests:/goss:ro" \
--entrypoint "" \
"${IMAGE_NAME}:${IMAGE_TAG}" \
/goss-bin/goss --gossfile /goss/goss-dockerfile-tests.yaml validate
log "Running integration test (capture HTTP traffic)..."
# Generate a unique marker for this test run
local test_marker="tcpdump-test-$(date +%s)"
# Clean up any previous test
docker compose down --volumes --remove-orphans 2>/dev/null || true
# Start the test environment
docker compose up --detach --wait webserver
# Run tcpdump in background, capturing packets
log "Starting tcpdump capture..."
docker compose up --detach tcpdump
# Give tcpdump a moment to start
sleep 1
# Generate HTTP traffic with unique marker URL
log "Generating HTTP traffic (marker: ${test_marker})..."
docker run --rm --network tcpdump_default curlimages/curl:latest \
-s "http://webserver/${test_marker}" > /dev/null || true
docker run --rm --network tcpdump_default curlimages/curl:latest \
-s "http://webserver/${test_marker}" > /dev/null || true
# Wait for tcpdump to capture packets (it exits after -c 5)
log "Waiting for capture to complete..."
sleep 2
timeout 10 docker compose wait tcpdump 2>/dev/null || true
# Verify capture file exists and has content
log "Verifying capture file..."
docker run --rm \
-v tcpdump_capture:/capture:ro \
alpine:latest sh -c '
if [ -f /capture/test.pcap ] && [ -s /capture/test.pcap ]; then
echo " PASS: Capture file exists and has content"
ls -la /capture/test.pcap
else
echo " FAIL: Capture file missing or empty"
exit 1
fi
'
# Validate captured traffic contains our unique marker
log "Validating HTTP request captured (searching for marker)..."
if docker run --rm \
-v tcpdump_capture:/capture:ro \
"${IMAGE_NAME}:${IMAGE_TAG}" \
-r /capture/test.pcap -A 2>&1 | grep -q "${test_marker}"; then
echo " PASS: Found test marker in captured traffic"
else
echo " FAIL: Test marker '${test_marker}' not found in capture"
log "Captured traffic:"
docker run --rm \
-v tcpdump_capture:/capture:ro \
"${IMAGE_NAME}:${IMAGE_TAG}" \
-r /capture/test.pcap -A 2>&1 | head -30
exit 1
fi
# Cleanup
docker compose down --volumes --remove-orphans
log "All tests passed!"
}
clean() {
log "Cleaning up..."
docker compose down --volumes --remove-orphans 2>/dev/null || true
docker image rm "${IMAGE_NAME}:${IMAGE_TAG}" "${IMAGE_NAME}:latest" 2>/dev/null || true
docker buildx prune --force --filter "until=24h"
}
release() {
test
if ! CURRENT_TAG=$(git describe --tags --exact-match 2>/dev/null); then
log "Error: Current commit is not tagged."
exit 1
fi
log "Releasing ${CURRENT_TAG}"
_buildx_setup
docker buildx build \
--platform "${PLATFORMS}" \
--tag "${IMAGE_NAME}:${CURRENT_TAG}" \
--tag "${IMAGE_NAME}:latest" \
--push .
log "Release complete."
}
usage() {
cat <<EOF
Usage: ./run [COMMAND]
Commands:
build Build local image (${IMAGE_NAME}:${IMAGE_TAG})
test Build and run integration tests
clean Remove images and prune builder
release Test, build multi-arch, and push to Docker Hub
EOF
}
CMD=${1:-}
shift || true
case ${CMD} in
build) build ;;
test) test ;;
clean) clean ;;
release) release ;;
*) usage ;;
esac