Browse Source

Test with Podman in CI

pull/34/head
Jordan Potter 2 years ago
parent
commit
9756675e31
  1. 106
      .github/workflows/ci.yml

106
.github/workflows/ci.yml

@ -1,16 +1,18 @@
name: Continuous Integration name: Continuous Integration
on: on: push
push:
branches: # on:
- main # push:
schedule: # branches:
- cron: "0 0 * * TUE" # - main
# schedule:
# - cron: "0 0 * * TUE"
concurrency: ${{ github.workflow }} concurrency: ${{ github.workflow }}
jobs: jobs:
build: publish:
name: Publish name: Publish
runs-on: ubuntu-latest runs-on: ubuntu-latest
permissions: permissions:
@ -21,16 +23,10 @@ jobs:
- name: Checkout code - name: Checkout code
uses: actions/checkout@v4 uses: actions/checkout@v4
- name: Get date - name: Install WireGuard
id: date
uses: josStorer/get-current-time@v2
with:
format: YYYY-MM-DD
- name: Install wireguard
run: sudo apt-get install wireguard run: sudo apt-get install wireguard
- name: Download WireGuard config - name: Create WireGuard config
run: echo "${{ secrets.WIREGUARD_CONF }}" > wireguard.conf run: echo "${{ secrets.WIREGUARD_CONF }}" > wireguard.conf
- name: Set up QEMU - name: Set up QEMU
@ -39,43 +35,57 @@ jobs:
- name: Set up Buildx - name: Set up Buildx
uses: docker/setup-buildx-action@v3 uses: docker/setup-buildx-action@v3
- name: Build local image for testing - name: Build local Docker image for testing
uses: docker/build-push-action@v5 uses: docker/build-push-action@v5
with: with:
pull: true pull: true
load: true load: true
tags: wireguard tags: wireguard:test
- name: Test curl - name: Copy Docker image to Podman
run: | run: |
docker run --rm -d --name wireguard --cap-add NET_ADMIN --cap-add SYS_MODULE --sysctl net.ipv4.conf.all.src_valid_mark=1 -v ${{ github.workspace }}/wireguard.conf:/etc/wireguard/wg0.conf wireguard sudo podman pull docker-daemon:docker.io/library/wireguard:test
docker run --rm --net=container:wireguard curlimages/curl --retry 3 --retry-delay 5 ifconfig.io
docker stop wireguard # - name: Test tunnel
# run: |
# for cmd in "docker" "sudo podman"; do
# $cmd run --rm -d --name wireguard --cap-add NET_ADMIN --cap-add NET_RAW --cap-add SYS_MODULE --sysctl net.ipv4.conf.all.src_valid_mark=1 -v ${{ github.workspace }}/wireguard.conf:/etc/wireguard/wg0.conf wireguard:test
# normal_ip=$($cmd run --rm curlimages/curl --retry 3 --retry-delay 5 ifconfig.io)
# wireguard_ip=$($cmd run --rm --net=container:wireguard curlimages/curl --retry 3 --retry-delay 5 ifconfig.io)
# if [ "$normal_ip" = "$wireguard_ip" ]; then echo "normal ip and wireguard ip are the same" && exit 1; fi
# $cmd stop wireguard
# done
- name: Test kill switch - name: Test kill switch
run: | run: |
docker run --rm -d --name wireguard --cap-add NET_ADMIN --cap-add SYS_MODULE --sysctl net.ipv4.conf.all.src_valid_mark=1 -v ${{ github.workspace }}/wireguard.conf:/etc/wireguard/wg0.conf wireguard for cmd in "docker" "sudo podman"; do
docker run --rm --net=container:wireguard curlimages/curl --retry 3 --retry-delay 5 ifconfig.io $cmd run --rm -d --name wireguard --cap-add NET_ADMIN --cap-add NET_RAW --cap-add SYS_MODULE --sysctl net.ipv4.conf.all.src_valid_mark=1 -v ${{ github.workspace }}/wireguard.conf:/etc/wireguard/wg0.conf wireguard:test
docker exec wireguard wg-quick down wg0 $cmd run --rm --net=container:wireguard curlimages/curl --retry 3 --retry-delay 5 ifconfig.io
! docker run --rm --net=container:wireguard curlimages/curl --retry 3 --retry-delay 5 ifconfig.io $cmd exec wireguard wg-quick down wg0
docker stop wireguard ! $cmd run --rm --net=container:wireguard curlimages/curl --retry 3 --retry-delay 5 ifconfig.io
$cmd stop wireguard
done
- name: Test local subnets - name: Test local subnets
run: | run: |
ip_address=$(ip route get 1.2.3.4 | awk '{print $7}') for cmd in "docker" "sudo podman"; do
docker run --rm -d --name nginx -p 8080:80 nginx ip_address=$(ip route get 1.2.3.4 | awk '{print $7}')
docker run --rm -d --name wireguard --cap-add NET_ADMIN --cap-add SYS_MODULE --sysctl net.ipv4.conf.all.src_valid_mark=1 -v ${{ github.workspace }}/wireguard.conf:/etc/wireguard/wg0.conf -e LOCAL_SUBNETS=$ip_address/32 wireguard $cmd run --rm -d --name nginx -p 8080:80 nginx
sleep 3 $cmd run --rm -d --name wireguard --cap-add NET_ADMIN --cap-add NET_RAW --cap-add SYS_MODULE --sysctl net.ipv4.conf.all.src_valid_mark=1 -v ${{ github.workspace }}/wireguard.conf:/etc/wireguard/wg0.conf -e LOCAL_SUBNETS=$ip_address/32 wireguard:test
docker run --rm --net=container:wireguard curlimages/curl --retry 3 --retry-delay 5 $ip_address:8080 sleep 3
docker stop wireguard nginx $cmd run --rm --net=container:wireguard curlimages/curl --retry 3 --retry-delay 5 $ip_address:8080
$cmd stop wireguard nginx
done
- name: Test exposed ports - name: Test exposed ports
run: | run: |
docker run --rm -d --name wireguard --cap-add NET_ADMIN --cap-add SYS_MODULE --sysctl net.ipv4.conf.all.src_valid_mark=1 -v ${{ github.workspace }}/wireguard.conf:/etc/wireguard/wg0.conf -p 8080:80 wireguard for cmd in "docker" "sudo podman"; do
docker run --rm -d --name nginx --net=container:wireguard nginx $cmd run --rm -d --name wireguard --cap-add NET_ADMIN --cap-add NET_RAW --cap-add SYS_MODULE --sysctl net.ipv4.conf.all.src_valid_mark=1 -v ${{ github.workspace }}/wireguard.conf:/etc/wireguard/wg0.conf -p 8080:80 wireguard:test
sleep 3 $cmd run --rm -d --name nginx --net=container:wireguard nginx
curl --retry 3 --retry-delay 5 localhost:8080 sleep 3
docker stop wireguard nginx curl --retry 3 --retry-delay 5 localhost:8080
$cmd stop wireguard nginx
done
- name: Log into Docker Hub - name: Log into Docker Hub
uses: docker/login-action@v3 uses: docker/login-action@v3
@ -90,6 +100,12 @@ jobs:
username: ${{ github.actor }} username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }} password: ${{ secrets.GITHUB_TOKEN }}
- name: Get date
id: date
uses: josStorer/get-current-time@v2
with:
format: YYYY-MM-DD
- name: Get metadata for image - name: Get metadata for image
id: metadata id: metadata
uses: docker/metadata-action@v5 uses: docker/metadata-action@v5
@ -105,15 +121,15 @@ jobs:
uses: docker/build-push-action@v5 uses: docker/build-push-action@v5
with: with:
pull: true pull: true
push: true # push: true
tags: ${{ steps.metadata.outputs.tags }} tags: ${{ steps.metadata.outputs.tags }}
labels: ${{ steps.metadata.outputs.labels }} labels: ${{ steps.metadata.outputs.labels }}
platforms: linux/amd64,linux/arm64,linux/arm/v6,linux/arm/v7 platforms: linux/amd64,linux/arm64,linux/arm/v6,linux/arm/v7
- name: Update Docker Hub description # - name: Update Docker Hub description
uses: peter-evans/dockerhub-description@v3 # uses: peter-evans/dockerhub-description@v3
with: # with:
repository: jordanpotter/wireguard # repository: jordanpotter/wireguard
username: jordanpotter # username: jordanpotter
password: ${{ secrets.DOCKERHUB_ACCESS_TOKEN }} # password: ${{ secrets.DOCKERHUB_ACCESS_TOKEN }}
short-description: ${{ github.event.repository.description }} # short-description: ${{ github.event.repository.description }}

Loading…
Cancel
Save