headscale/integration
Kristoffer Dalby 2b5e52b08b
validate policy against nodes, error if not valid (#2089)
* validate policy against nodes, error if not valid

this commit aims to improve the feedback of "runtime" policy
errors which would only manifest when the rules are compiled to
filter rules with nodes.

this change will in;

file-based mode load the nodes from the db and try to compile the rules on
start up and return an error if they would not work as intended.

database-based mode prevent a new ACL being written to the database if
it does not compile with the current set of node.

Fixes #2073
Fixes #2044

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* ensure stderr can be used in err checks

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* test policy set validation

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* add new integration test to ghaction

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* add back defer for cli tst

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

---------

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>
2024-08-30 16:58:29 +02:00
..
dockertestutil validate policy against nodes, error if not valid (#2089) 2024-08-30 16:58:29 +02:00
hsic validate policy against nodes, error if not valid (#2089) 2024-08-30 16:58:29 +02:00
integrationutil Add go profiling flag, and enable on integration tests (#1382) 2023-04-27 16:57:11 +02:00
tsic Redo DNS configuration (#2034) 2024-08-19 11:41:05 +02:00
acl_test.go feat: implements apis for managing headscale policy (#1792) 2024-07-18 07:38:25 +02:00
auth_oidc_test.go metrics, tuning in tests, db cleanups, fix concurrency issue (#1895) 2024-04-21 18:28:17 +02:00
auth_web_flow_test.go metrics, tuning in tests, db cleanups, fix concurrency issue (#1895) 2024-04-21 18:28:17 +02:00
cli_test.go validate policy against nodes, error if not valid (#2089) 2024-08-30 16:58:29 +02:00
control.go reformat code (#2019) 2024-07-22 08:56:00 +02:00
dns_test.go Redo DNS configuration (#2034) 2024-08-19 11:41:05 +02:00
embedded_derp_test.go test embedded derp with derp updater, check client health (#2030) 2024-08-11 07:44:59 +02:00
general_test.go Redo DNS configuration (#2034) 2024-08-19 11:41:05 +02:00
README.md Add section about running locally 2023-02-03 16:25:58 +01:00
route_test.go fix route table migration wiping routes 0.22 -> 0.23 (#2076) 2024-08-27 18:54:28 +02:00
run.sh implement selfupdate and pass expiry (#1647) 2024-01-05 10:41:56 +01:00
scenario.go Redo DNS configuration (#2034) 2024-08-19 11:41:05 +02:00
scenario_test.go metrics, tuning in tests, db cleanups, fix concurrency issue (#1895) 2024-04-21 18:28:17 +02:00
ssh_test.go metrics, tuning in tests, db cleanups, fix concurrency issue (#1895) 2024-04-21 18:28:17 +02:00
tailscale.go Redo DNS configuration (#2034) 2024-08-19 11:41:05 +02:00
utils.go Fix typos (#1860) 2024-05-19 23:49:27 +02:00

Integration testing

Headscale relies on integration testing to ensure we remain compatible with Tailscale.

This is typically performed by starting a Headscale server and running a test "scenario" with an array of Tailscale clients and versions.

Headscale's test framework and the current set of scenarios are defined in this directory.

Tests are located in files ending with _test.go and the framework are located in the rest.

Running integration tests locally

The easiest way to run tests locally is to use [act](INSERT LINK), a local GitHub Actions runner:

act pull_request -W .github/workflows/test-integration-v2-TestPingAllByIP.yaml

Alternatively, the docker run command in each GitHub workflow file can be used.

Running integration tests on GitHub Actions

Each test currently runs as a separate workflows in GitHub actions, to add new test, run go generate inside ../cmd/gh-action-integration-generator/ and commit the result.