docker_cli_service_create_test.go 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450
  1. //go:build !windows
  2. // +build !windows
  3. package main
  4. import (
  5. "encoding/json"
  6. "fmt"
  7. "path/filepath"
  8. "strings"
  9. "testing"
  10. "github.com/docker/docker/api/types"
  11. "github.com/docker/docker/api/types/mount"
  12. "github.com/docker/docker/api/types/swarm"
  13. "github.com/docker/docker/integration-cli/checker"
  14. "gotest.tools/v3/assert"
  15. "gotest.tools/v3/poll"
  16. )
  17. func (s *DockerSwarmSuite) TestServiceCreateMountVolume(c *testing.T) {
  18. d := s.AddDaemon(c, true, true)
  19. out, err := d.Cmd("service", "create", "--no-resolve-image", "--detach=true", "--mount", "type=volume,source=foo,target=/foo,volume-nocopy", "busybox", "top")
  20. assert.NilError(c, err, out)
  21. id := strings.TrimSpace(out)
  22. var tasks []swarm.Task
  23. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  24. tasks = d.GetServiceTasks(c, id)
  25. return len(tasks) > 0, ""
  26. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  27. task := tasks[0]
  28. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  29. if task.NodeID == "" || task.Status.ContainerStatus == nil {
  30. task = d.GetTask(c, task.ID)
  31. }
  32. return task.NodeID != "" && task.Status.ContainerStatus != nil, ""
  33. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  34. // check container mount config
  35. out, err = s.nodeCmd(c, task.NodeID, "inspect", "--format", "{{json .HostConfig.Mounts}}", task.Status.ContainerStatus.ContainerID)
  36. assert.NilError(c, err, out)
  37. var mountConfig []mount.Mount
  38. assert.Assert(c, json.Unmarshal([]byte(out), &mountConfig) == nil)
  39. assert.Equal(c, len(mountConfig), 1)
  40. assert.Equal(c, mountConfig[0].Source, "foo")
  41. assert.Equal(c, mountConfig[0].Target, "/foo")
  42. assert.Equal(c, mountConfig[0].Type, mount.TypeVolume)
  43. assert.Assert(c, mountConfig[0].VolumeOptions != nil)
  44. assert.Assert(c, mountConfig[0].VolumeOptions.NoCopy)
  45. // check container mounts actual
  46. out, err = s.nodeCmd(c, task.NodeID, "inspect", "--format", "{{json .Mounts}}", task.Status.ContainerStatus.ContainerID)
  47. assert.NilError(c, err, out)
  48. var mounts []types.MountPoint
  49. assert.Assert(c, json.Unmarshal([]byte(out), &mounts) == nil)
  50. assert.Equal(c, len(mounts), 1)
  51. assert.Equal(c, mounts[0].Type, mount.TypeVolume)
  52. assert.Equal(c, mounts[0].Name, "foo")
  53. assert.Equal(c, mounts[0].Destination, "/foo")
  54. assert.Equal(c, mounts[0].RW, true)
  55. }
  56. func (s *DockerSwarmSuite) TestServiceCreateWithSecretSimple(c *testing.T) {
  57. d := s.AddDaemon(c, true, true)
  58. serviceName := "test-service-secret"
  59. testName := "test_secret"
  60. id := d.CreateSecret(c, swarm.SecretSpec{
  61. Annotations: swarm.Annotations{
  62. Name: testName,
  63. },
  64. Data: []byte("TESTINGDATA"),
  65. })
  66. assert.Assert(c, id != "", "secrets: %s", id)
  67. out, err := d.Cmd("service", "create", "--detach", "--no-resolve-image", "--name", serviceName, "--secret", testName, "busybox", "top")
  68. assert.NilError(c, err, out)
  69. out, err = d.Cmd("service", "inspect", "--format", "{{ json .Spec.TaskTemplate.ContainerSpec.Secrets }}", serviceName)
  70. assert.NilError(c, err)
  71. var refs []swarm.SecretReference
  72. assert.Assert(c, json.Unmarshal([]byte(out), &refs) == nil)
  73. assert.Equal(c, len(refs), 1)
  74. assert.Equal(c, refs[0].SecretName, testName)
  75. assert.Assert(c, refs[0].File != nil)
  76. assert.Equal(c, refs[0].File.Name, testName)
  77. assert.Equal(c, refs[0].File.UID, "0")
  78. assert.Equal(c, refs[0].File.GID, "0")
  79. out, err = d.Cmd("service", "rm", serviceName)
  80. assert.NilError(c, err, out)
  81. d.DeleteSecret(c, testName)
  82. }
  83. func (s *DockerSwarmSuite) TestServiceCreateWithSecretSourceTargetPaths(c *testing.T) {
  84. d := s.AddDaemon(c, true, true)
  85. testPaths := map[string]string{
  86. "app": "/etc/secret",
  87. "test_secret": "test_secret",
  88. "relative_secret": "relative/secret",
  89. "escapes_in_container": "../secret",
  90. }
  91. var secretFlags []string
  92. for testName, testTarget := range testPaths {
  93. id := d.CreateSecret(c, swarm.SecretSpec{
  94. Annotations: swarm.Annotations{
  95. Name: testName,
  96. },
  97. Data: []byte("TESTINGDATA " + testName + " " + testTarget),
  98. })
  99. assert.Assert(c, id != "", "secrets: %s", id)
  100. secretFlags = append(secretFlags, "--secret", fmt.Sprintf("source=%s,target=%s", testName, testTarget))
  101. }
  102. serviceName := "svc"
  103. serviceCmd := []string{"service", "create", "--detach", "--no-resolve-image", "--name", serviceName}
  104. serviceCmd = append(serviceCmd, secretFlags...)
  105. serviceCmd = append(serviceCmd, "busybox", "top")
  106. out, err := d.Cmd(serviceCmd...)
  107. assert.NilError(c, err, out)
  108. out, err = d.Cmd("service", "inspect", "--format", "{{ json .Spec.TaskTemplate.ContainerSpec.Secrets }}", serviceName)
  109. assert.NilError(c, err)
  110. var refs []swarm.SecretReference
  111. assert.Assert(c, json.Unmarshal([]byte(out), &refs) == nil)
  112. assert.Equal(c, len(refs), len(testPaths))
  113. var tasks []swarm.Task
  114. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  115. tasks = d.GetServiceTasks(c, serviceName)
  116. return len(tasks) > 0, ""
  117. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  118. task := tasks[0]
  119. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  120. if task.NodeID == "" || task.Status.ContainerStatus == nil {
  121. task = d.GetTask(c, task.ID)
  122. }
  123. return task.NodeID != "" && task.Status.ContainerStatus != nil, ""
  124. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  125. for testName, testTarget := range testPaths {
  126. path := testTarget
  127. if !filepath.IsAbs(path) {
  128. path = filepath.Join("/run/secrets", path)
  129. }
  130. out, err := d.Cmd("exec", task.Status.ContainerStatus.ContainerID, "cat", path)
  131. assert.NilError(c, err)
  132. assert.Equal(c, out, "TESTINGDATA "+testName+" "+testTarget)
  133. }
  134. out, err = d.Cmd("service", "rm", serviceName)
  135. assert.NilError(c, err, out)
  136. }
  137. func (s *DockerSwarmSuite) TestServiceCreateWithSecretReferencedTwice(c *testing.T) {
  138. d := s.AddDaemon(c, true, true)
  139. id := d.CreateSecret(c, swarm.SecretSpec{
  140. Annotations: swarm.Annotations{
  141. Name: "mysecret",
  142. },
  143. Data: []byte("TESTINGDATA"),
  144. })
  145. assert.Assert(c, id != "", "secrets: %s", id)
  146. serviceName := "svc"
  147. out, err := d.Cmd("service", "create", "--detach", "--no-resolve-image", "--name", serviceName, "--secret", "source=mysecret,target=target1", "--secret", "source=mysecret,target=target2", "busybox", "top")
  148. assert.NilError(c, err, out)
  149. out, err = d.Cmd("service", "inspect", "--format", "{{ json .Spec.TaskTemplate.ContainerSpec.Secrets }}", serviceName)
  150. assert.NilError(c, err)
  151. var refs []swarm.SecretReference
  152. assert.Assert(c, json.Unmarshal([]byte(out), &refs) == nil)
  153. assert.Equal(c, len(refs), 2)
  154. var tasks []swarm.Task
  155. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  156. tasks = d.GetServiceTasks(c, serviceName)
  157. return len(tasks) > 0, ""
  158. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  159. task := tasks[0]
  160. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  161. if task.NodeID == "" || task.Status.ContainerStatus == nil {
  162. task = d.GetTask(c, task.ID)
  163. }
  164. return task.NodeID != "" && task.Status.ContainerStatus != nil, ""
  165. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  166. for _, target := range []string{"target1", "target2"} {
  167. assert.NilError(c, err, out)
  168. path := filepath.Join("/run/secrets", target)
  169. out, err := d.Cmd("exec", task.Status.ContainerStatus.ContainerID, "cat", path)
  170. assert.NilError(c, err)
  171. assert.Equal(c, out, "TESTINGDATA")
  172. }
  173. out, err = d.Cmd("service", "rm", serviceName)
  174. assert.NilError(c, err, out)
  175. }
  176. func (s *DockerSwarmSuite) TestServiceCreateWithConfigSimple(c *testing.T) {
  177. d := s.AddDaemon(c, true, true)
  178. serviceName := "test-service-config"
  179. testName := "test_config"
  180. id := d.CreateConfig(c, swarm.ConfigSpec{
  181. Annotations: swarm.Annotations{
  182. Name: testName,
  183. },
  184. Data: []byte("TESTINGDATA"),
  185. })
  186. assert.Assert(c, id != "", "configs: %s", id)
  187. out, err := d.Cmd("service", "create", "--detach", "--no-resolve-image", "--name", serviceName, "--config", testName, "busybox", "top")
  188. assert.NilError(c, err, out)
  189. out, err = d.Cmd("service", "inspect", "--format", "{{ json .Spec.TaskTemplate.ContainerSpec.Configs }}", serviceName)
  190. assert.NilError(c, err)
  191. var refs []swarm.ConfigReference
  192. assert.Assert(c, json.Unmarshal([]byte(out), &refs) == nil)
  193. assert.Equal(c, len(refs), 1)
  194. assert.Equal(c, refs[0].ConfigName, testName)
  195. assert.Assert(c, refs[0].File != nil)
  196. assert.Equal(c, refs[0].File.Name, testName)
  197. assert.Equal(c, refs[0].File.UID, "0")
  198. assert.Equal(c, refs[0].File.GID, "0")
  199. out, err = d.Cmd("service", "rm", serviceName)
  200. assert.NilError(c, err, out)
  201. d.DeleteConfig(c, testName)
  202. }
  203. func (s *DockerSwarmSuite) TestServiceCreateWithConfigSourceTargetPaths(c *testing.T) {
  204. d := s.AddDaemon(c, true, true)
  205. testPaths := map[string]string{
  206. "app": "/etc/config",
  207. "test_config": "test_config",
  208. "relative_config": "relative/config",
  209. }
  210. var configFlags []string
  211. for testName, testTarget := range testPaths {
  212. id := d.CreateConfig(c, swarm.ConfigSpec{
  213. Annotations: swarm.Annotations{
  214. Name: testName,
  215. },
  216. Data: []byte("TESTINGDATA " + testName + " " + testTarget),
  217. })
  218. assert.Assert(c, id != "", "configs: %s", id)
  219. configFlags = append(configFlags, "--config", fmt.Sprintf("source=%s,target=%s", testName, testTarget))
  220. }
  221. serviceName := "svc"
  222. serviceCmd := []string{"service", "create", "--detach", "--no-resolve-image", "--name", serviceName}
  223. serviceCmd = append(serviceCmd, configFlags...)
  224. serviceCmd = append(serviceCmd, "busybox", "top")
  225. out, err := d.Cmd(serviceCmd...)
  226. assert.NilError(c, err, out)
  227. out, err = d.Cmd("service", "inspect", "--format", "{{ json .Spec.TaskTemplate.ContainerSpec.Configs }}", serviceName)
  228. assert.NilError(c, err)
  229. var refs []swarm.ConfigReference
  230. assert.Assert(c, json.Unmarshal([]byte(out), &refs) == nil)
  231. assert.Equal(c, len(refs), len(testPaths))
  232. var tasks []swarm.Task
  233. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  234. tasks = d.GetServiceTasks(c, serviceName)
  235. return len(tasks) > 0, ""
  236. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  237. task := tasks[0]
  238. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  239. if task.NodeID == "" || task.Status.ContainerStatus == nil {
  240. task = d.GetTask(c, task.ID)
  241. }
  242. return task.NodeID != "" && task.Status.ContainerStatus != nil, ""
  243. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  244. for testName, testTarget := range testPaths {
  245. path := testTarget
  246. if !filepath.IsAbs(path) {
  247. path = filepath.Join("/", path)
  248. }
  249. out, err := d.Cmd("exec", task.Status.ContainerStatus.ContainerID, "cat", path)
  250. assert.NilError(c, err)
  251. assert.Equal(c, out, "TESTINGDATA "+testName+" "+testTarget)
  252. }
  253. out, err = d.Cmd("service", "rm", serviceName)
  254. assert.NilError(c, err, out)
  255. }
  256. func (s *DockerSwarmSuite) TestServiceCreateWithConfigReferencedTwice(c *testing.T) {
  257. d := s.AddDaemon(c, true, true)
  258. id := d.CreateConfig(c, swarm.ConfigSpec{
  259. Annotations: swarm.Annotations{
  260. Name: "myconfig",
  261. },
  262. Data: []byte("TESTINGDATA"),
  263. })
  264. assert.Assert(c, id != "", "configs: %s", id)
  265. serviceName := "svc"
  266. out, err := d.Cmd("service", "create", "--detach", "--no-resolve-image", "--name", serviceName, "--config", "source=myconfig,target=target1", "--config", "source=myconfig,target=target2", "busybox", "top")
  267. assert.NilError(c, err, out)
  268. out, err = d.Cmd("service", "inspect", "--format", "{{ json .Spec.TaskTemplate.ContainerSpec.Configs }}", serviceName)
  269. assert.NilError(c, err)
  270. var refs []swarm.ConfigReference
  271. assert.Assert(c, json.Unmarshal([]byte(out), &refs) == nil)
  272. assert.Equal(c, len(refs), 2)
  273. var tasks []swarm.Task
  274. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  275. tasks = d.GetServiceTasks(c, serviceName)
  276. return len(tasks) > 0, ""
  277. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  278. task := tasks[0]
  279. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  280. if task.NodeID == "" || task.Status.ContainerStatus == nil {
  281. task = d.GetTask(c, task.ID)
  282. }
  283. return task.NodeID != "" && task.Status.ContainerStatus != nil, ""
  284. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  285. for _, target := range []string{"target1", "target2"} {
  286. assert.NilError(c, err, out)
  287. path := filepath.Join("/", target)
  288. out, err := d.Cmd("exec", task.Status.ContainerStatus.ContainerID, "cat", path)
  289. assert.NilError(c, err)
  290. assert.Equal(c, out, "TESTINGDATA")
  291. }
  292. out, err = d.Cmd("service", "rm", serviceName)
  293. assert.NilError(c, err, out)
  294. }
  295. func (s *DockerSwarmSuite) TestServiceCreateMountTmpfs(c *testing.T) {
  296. d := s.AddDaemon(c, true, true)
  297. out, err := d.Cmd("service", "create", "--no-resolve-image", "--detach=true", "--mount", "type=tmpfs,target=/foo,tmpfs-size=1MB", "busybox", "sh", "-c", "mount | grep foo; exec tail -f /dev/null")
  298. assert.NilError(c, err, out)
  299. id := strings.TrimSpace(out)
  300. var tasks []swarm.Task
  301. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  302. tasks = d.GetServiceTasks(c, id)
  303. return len(tasks) > 0, ""
  304. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  305. task := tasks[0]
  306. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  307. if task.NodeID == "" || task.Status.ContainerStatus == nil {
  308. task = d.GetTask(c, task.ID)
  309. }
  310. return task.NodeID != "" && task.Status.ContainerStatus != nil, ""
  311. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  312. // check container mount config
  313. out, err = s.nodeCmd(c, task.NodeID, "inspect", "--format", "{{json .HostConfig.Mounts}}", task.Status.ContainerStatus.ContainerID)
  314. assert.NilError(c, err, out)
  315. var mountConfig []mount.Mount
  316. assert.Assert(c, json.Unmarshal([]byte(out), &mountConfig) == nil)
  317. assert.Equal(c, len(mountConfig), 1)
  318. assert.Equal(c, mountConfig[0].Source, "")
  319. assert.Equal(c, mountConfig[0].Target, "/foo")
  320. assert.Equal(c, mountConfig[0].Type, mount.TypeTmpfs)
  321. assert.Assert(c, mountConfig[0].TmpfsOptions != nil)
  322. assert.Equal(c, mountConfig[0].TmpfsOptions.SizeBytes, int64(1048576))
  323. // check container mounts actual
  324. out, err = s.nodeCmd(c, task.NodeID, "inspect", "--format", "{{json .Mounts}}", task.Status.ContainerStatus.ContainerID)
  325. assert.NilError(c, err, out)
  326. var mounts []types.MountPoint
  327. assert.Assert(c, json.Unmarshal([]byte(out), &mounts) == nil)
  328. assert.Equal(c, len(mounts), 1)
  329. assert.Equal(c, mounts[0].Type, mount.TypeTmpfs)
  330. assert.Equal(c, mounts[0].Name, "")
  331. assert.Equal(c, mounts[0].Destination, "/foo")
  332. assert.Equal(c, mounts[0].RW, true)
  333. out, err = s.nodeCmd(c, task.NodeID, "logs", task.Status.ContainerStatus.ContainerID)
  334. assert.NilError(c, err, out)
  335. assert.Assert(c, strings.HasPrefix(strings.TrimSpace(out), "tmpfs on /foo type tmpfs"))
  336. assert.Assert(c, strings.Contains(strings.TrimSpace(out), "size=1024k"))
  337. }
  338. func (s *DockerSwarmSuite) TestServiceCreateWithNetworkAlias(c *testing.T) {
  339. d := s.AddDaemon(c, true, true)
  340. out, err := d.Cmd("network", "create", "--scope=swarm", "test_swarm_br")
  341. assert.NilError(c, err, out)
  342. out, err = d.Cmd("service", "create", "--no-resolve-image", "--detach=true", "--network=name=test_swarm_br,alias=srv_alias", "--name=alias_tst_container", "busybox", "top")
  343. assert.NilError(c, err, out)
  344. id := strings.TrimSpace(out)
  345. var tasks []swarm.Task
  346. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  347. tasks = d.GetServiceTasks(c, id)
  348. return len(tasks) > 0, ""
  349. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  350. task := tasks[0]
  351. poll.WaitOn(c, pollCheck(c, func(c *testing.T) (interface{}, string) {
  352. if task.NodeID == "" || task.Status.ContainerStatus == nil {
  353. task = d.GetTask(c, task.ID)
  354. }
  355. return task.NodeID != "" && task.Status.ContainerStatus != nil, ""
  356. }, checker.Equals(true)), poll.WithTimeout(defaultReconciliationTimeout))
  357. // check container alias config
  358. out, err = s.nodeCmd(c, task.NodeID, "inspect", "--format", "{{json .NetworkSettings.Networks.test_swarm_br.Aliases}}", task.Status.ContainerStatus.ContainerID)
  359. assert.NilError(c, err, out)
  360. // Make sure the only alias seen is the container-id
  361. var aliases []string
  362. assert.Assert(c, json.Unmarshal([]byte(out), &aliases) == nil)
  363. assert.Equal(c, len(aliases), 1)
  364. assert.Assert(c, strings.Contains(task.Status.ContainerStatus.ContainerID, aliases[0]))
  365. }