Skip to content

Commit

Permalink
Validate the availability of traefik container before updating CA cer…
Browse files Browse the repository at this point in the history
…tificates
  • Loading branch information
gatici committed Oct 9, 2023
1 parent 2fe7a29 commit 8f1bc7e
Show file tree
Hide file tree
Showing 2 changed files with 49 additions and 0 deletions.
3 changes: 3 additions & 0 deletions src/charm.py
Original file line number Diff line number Diff line change
Expand Up @@ -278,6 +278,9 @@ def _update_received_ca_certs(self, event: Optional[CertificateTransferAvailable
Calling this function from upgrade-charm might be too early though. Pebble-ready is
preferred.
"""
if not self.container.can_connect():
return

if event:
self.container.push(
_RECV_CA_TEMPLATE.substitute(rel_id=event.relation_id), event.ca, make_dirs=True
Expand Down
46 changes: 46 additions & 0 deletions tests/unit/test_charm.py
Original file line number Diff line number Diff line change
Expand Up @@ -410,6 +410,52 @@ def test_tcp_config(self):
assert yaml.safe_load(static_config)["entryPoints"][prefix] == expected_entrypoint


class TestTraefikCertTransferInterface(unittest.TestCase):
def setUp(self):
self.harness: Harness[TraefikIngressCharm] = Harness(TraefikIngressCharm)
self.harness.set_model_name("test-model")
self.addCleanup(self.harness.cleanup)
patcher = patch.object(TraefikIngressCharm, "version", property(lambda *_: "0.0.0"))
self.mock_version = patcher.start()
self.addCleanup(patcher.stop)
self.container_name = "traefik"

@patch("ops.model.Container.exec")
@patch("charm._get_loadbalancer_status", lambda **__: "10.0.0.1")
@patch("charm.KubernetesServicePatch", lambda *_, **__: None)
def test_given_container_can_connect_when_receive_ca_cert_relation_joins_then_ca_certs_are_updated(
self, patch_exec
):
provider_app = "self-signed-certificates"
self.harness.set_leader(True)
self.harness.begin_with_initial_hooks()
self.harness.set_can_connect(container=self.container_name, val=True)
certificate_transfer_rel_id = self.harness.add_relation(
relation_name="receive-ca-cert", remote_app=provider_app
)
self.harness.add_relation_unit(
relation_id=certificate_transfer_rel_id, remote_unit_name=f"{provider_app}/0"
)
patch_exec.assert_called_once_with(["update-ca-certificates", "--fresh"])

@patch("ops.model.Container.exec")
@patch("charm._get_loadbalancer_status", lambda **__: "10.0.0.1")
@patch("charm.KubernetesServicePatch", lambda *_, **__: None)
def test_given_container_not_ready_when_receive_ca_cert_relation_joins_then_ca_certs_are_not_updated(
self, patch_exec
):
provider_app = "self-signed-certificates"
self.harness.set_leader(True)
self.harness.set_can_connect(container=self.container_name, val=False)
certificate_transfer_rel_id = self.harness.add_relation(
relation_name="receive-ca-cert", remote_app=provider_app
)
self.harness.add_relation_unit(
relation_id=certificate_transfer_rel_id, remote_unit_name=f"{provider_app}/0"
)
patch_exec.assert_not_called()


class TestConfigOptionsValidation(unittest.TestCase):
@patch("charm._get_loadbalancer_status", lambda **_: "10.0.0.1")
@patch("charm.KubernetesServicePatch", lambda *_, **__: None)
Expand Down

0 comments on commit 8f1bc7e

Please sign in to comment.