The stock TinyCore kernel config has "# CONFIG_SECURITY is not set" which caused make olddefconfig to silently revert all security configs in a single pass. Fix by applying security configs (AppArmor, Audit, LSM) after the first olddefconfig resolves base dependencies, then running a second pass. Added mandatory verification that exits on missing critical configs. All QEMU test scripts converted from broken -cdrom + -append pattern to direct kernel boot (-kernel + -initrd) via shared test/lib/qemu-helpers.sh helper library. The -append flag only works with -kernel, not -cdrom. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
86 lines
2.6 KiB
Bash
Executable File
86 lines
2.6 KiB
Bash
Executable File
#!/bin/bash
|
|
# test-k8s-ready.sh — Verify K8s node reaches Ready state
|
|
# Usage: ./test/integration/test-k8s-ready.sh <iso-path>
|
|
# Requires: kubectl on host, QEMU with port forwarding
|
|
set -euo pipefail
|
|
|
|
ISO="${1:?Usage: $0 <path-to-iso>}"
|
|
TIMEOUT_K8S=${TIMEOUT_K8S:-300}
|
|
API_PORT=6443
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
PROJECT_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
|
|
. "$SCRIPT_DIR/../lib/qemu-helpers.sh"
|
|
|
|
DATA_DISK=$(mktemp /tmp/kubesolo-data-XXXXXX.img)
|
|
dd if=/dev/zero of="$DATA_DISK" bs=1M count=1024 2>/dev/null
|
|
mkfs.ext4 -q -L KSOLODATA "$DATA_DISK" 2>/dev/null
|
|
|
|
QEMU_PID=""
|
|
EXTRACT_DIR=""
|
|
|
|
cleanup() {
|
|
[ -n "$QEMU_PID" ] && kill "$QEMU_PID" 2>/dev/null || true
|
|
rm -f "$DATA_DISK"
|
|
[ -n "$EXTRACT_DIR" ] && rm -rf "$EXTRACT_DIR"
|
|
}
|
|
trap cleanup EXIT
|
|
|
|
echo "==> K8s readiness test: $ISO"
|
|
|
|
# Extract kernel from ISO
|
|
EXTRACT_DIR="$(mktemp -d /tmp/kubesolo-extract-XXXXXX)"
|
|
extract_kernel_from_iso "$ISO" "$EXTRACT_DIR"
|
|
|
|
KVM_FLAG=$(detect_kvm)
|
|
[ -n "$KVM_FLAG" ] && echo " KVM acceleration: enabled"
|
|
|
|
# Launch QEMU with API port forwarded
|
|
# shellcheck disable=SC2086
|
|
qemu-system-x86_64 \
|
|
-m 2048 -smp 2 \
|
|
-nographic \
|
|
$KVM_FLAG \
|
|
-kernel "$VMLINUZ" \
|
|
-initrd "$INITRAMFS" \
|
|
-drive "file=$DATA_DISK,format=raw,if=virtio" \
|
|
-net "nic,model=virtio" \
|
|
-net "user,hostfwd=tcp::${API_PORT}-:6443" \
|
|
-append "console=ttyS0,115200n8 kubesolo.data=/dev/vda" \
|
|
&
|
|
QEMU_PID=$!
|
|
|
|
# Wait for API server
|
|
echo " Waiting for K8s API on localhost:${API_PORT}..."
|
|
ELAPSED=0
|
|
while [ "$ELAPSED" -lt "$TIMEOUT_K8S" ]; do
|
|
if kubectl --kubeconfig=/dev/null \
|
|
--server="https://localhost:${API_PORT}" \
|
|
--insecure-skip-tls-verify \
|
|
get nodes 2>/dev/null | grep -q "Ready"; then
|
|
echo ""
|
|
echo "==> PASS: K8s node is Ready (${ELAPSED}s)"
|
|
|
|
# Bonus: try deploying a pod
|
|
echo " Deploying test pod..."
|
|
kubectl --server="https://localhost:${API_PORT}" --insecure-skip-tls-verify \
|
|
run test-nginx --image=nginx:alpine --restart=Never 2>/dev/null || true
|
|
|
|
sleep 10
|
|
if kubectl --server="https://localhost:${API_PORT}" --insecure-skip-tls-verify \
|
|
get pod test-nginx 2>/dev/null | grep -q "Running"; then
|
|
echo "==> PASS: Test pod is Running"
|
|
else
|
|
echo "==> WARN: Test pod not Running (may need more time or image pull)"
|
|
fi
|
|
exit 0
|
|
fi
|
|
sleep 5
|
|
ELAPSED=$((ELAPSED + 5))
|
|
printf "\r Elapsed: %ds / %ds" "$ELAPSED" "$TIMEOUT_K8S"
|
|
done
|
|
|
|
echo ""
|
|
echo "==> FAIL: K8s node did not reach Ready within ${TIMEOUT_K8S}s"
|
|
exit 1
|