pods_test.go 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665
  1. /*
  2. Copyright 2015 The Kubernetes Authors.
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package pods
  14. import (
  15. "context"
  16. "fmt"
  17. "strings"
  18. "testing"
  19. "k8s.io/api/core/v1"
  20. metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
  21. "k8s.io/apimachinery/pkg/runtime/schema"
  22. "k8s.io/apimachinery/pkg/types"
  23. utilfeature "k8s.io/apiserver/pkg/util/feature"
  24. clientset "k8s.io/client-go/kubernetes"
  25. typedv1 "k8s.io/client-go/kubernetes/typed/core/v1"
  26. restclient "k8s.io/client-go/rest"
  27. featuregatetesting "k8s.io/component-base/featuregate/testing"
  28. "k8s.io/kubernetes/pkg/features"
  29. "k8s.io/kubernetes/test/integration"
  30. "k8s.io/kubernetes/test/integration/framework"
  31. )
  32. func TestPodUpdateActiveDeadlineSeconds(t *testing.T) {
  33. _, s, closeFn := framework.RunAMaster(nil)
  34. defer closeFn()
  35. ns := framework.CreateTestingNamespace("pod-activedeadline-update", s, t)
  36. defer framework.DeleteTestingNamespace(ns, s, t)
  37. client := clientset.NewForConfigOrDie(&restclient.Config{Host: s.URL, ContentConfig: restclient.ContentConfig{GroupVersion: &schema.GroupVersion{Group: "", Version: "v1"}}})
  38. var (
  39. iZero = int64(0)
  40. i30 = int64(30)
  41. i60 = int64(60)
  42. iNeg = int64(-1)
  43. )
  44. prototypePod := func() *v1.Pod {
  45. return &v1.Pod{
  46. ObjectMeta: metav1.ObjectMeta{
  47. Name: "xxx",
  48. },
  49. Spec: v1.PodSpec{
  50. Containers: []v1.Container{
  51. {
  52. Name: "fake-name",
  53. Image: "fakeimage",
  54. },
  55. },
  56. },
  57. }
  58. }
  59. cases := []struct {
  60. name string
  61. original *int64
  62. update *int64
  63. valid bool
  64. }{
  65. {
  66. name: "no change, nil",
  67. original: nil,
  68. update: nil,
  69. valid: true,
  70. },
  71. {
  72. name: "no change, set",
  73. original: &i30,
  74. update: &i30,
  75. valid: true,
  76. },
  77. {
  78. name: "change to positive from nil",
  79. original: nil,
  80. update: &i60,
  81. valid: true,
  82. },
  83. {
  84. name: "change to smaller positive",
  85. original: &i60,
  86. update: &i30,
  87. valid: true,
  88. },
  89. {
  90. name: "change to larger positive",
  91. original: &i30,
  92. update: &i60,
  93. valid: false,
  94. },
  95. {
  96. name: "change to negative from positive",
  97. original: &i30,
  98. update: &iNeg,
  99. valid: false,
  100. },
  101. {
  102. name: "change to negative from nil",
  103. original: nil,
  104. update: &iNeg,
  105. valid: false,
  106. },
  107. // zero is not allowed, must be a positive integer
  108. {
  109. name: "change to zero from positive",
  110. original: &i30,
  111. update: &iZero,
  112. valid: false,
  113. },
  114. {
  115. name: "change to nil from positive",
  116. original: &i30,
  117. update: nil,
  118. valid: false,
  119. },
  120. }
  121. for i, tc := range cases {
  122. pod := prototypePod()
  123. pod.Spec.ActiveDeadlineSeconds = tc.original
  124. pod.ObjectMeta.Name = fmt.Sprintf("activedeadlineseconds-test-%v", i)
  125. if _, err := client.CoreV1().Pods(ns.Name).Create(context.TODO(), pod, metav1.CreateOptions{}); err != nil {
  126. t.Errorf("Failed to create pod: %v", err)
  127. }
  128. pod.Spec.ActiveDeadlineSeconds = tc.update
  129. _, err := client.CoreV1().Pods(ns.Name).Update(context.TODO(), pod, metav1.UpdateOptions{})
  130. if tc.valid && err != nil {
  131. t.Errorf("%v: failed to update pod: %v", tc.name, err)
  132. } else if !tc.valid && err == nil {
  133. t.Errorf("%v: unexpected allowed update to pod", tc.name)
  134. }
  135. integration.DeletePodOrErrorf(t, client, ns.Name, pod.Name)
  136. }
  137. }
  138. func TestPodReadOnlyFilesystem(t *testing.T) {
  139. _, s, closeFn := framework.RunAMaster(nil)
  140. defer closeFn()
  141. isReadOnly := true
  142. ns := framework.CreateTestingNamespace("pod-readonly-root", s, t)
  143. defer framework.DeleteTestingNamespace(ns, s, t)
  144. client := clientset.NewForConfigOrDie(&restclient.Config{Host: s.URL, ContentConfig: restclient.ContentConfig{GroupVersion: &schema.GroupVersion{Group: "", Version: "v1"}}})
  145. pod := &v1.Pod{
  146. ObjectMeta: metav1.ObjectMeta{
  147. Name: "xxx",
  148. },
  149. Spec: v1.PodSpec{
  150. Containers: []v1.Container{
  151. {
  152. Name: "fake-name",
  153. Image: "fakeimage",
  154. SecurityContext: &v1.SecurityContext{
  155. ReadOnlyRootFilesystem: &isReadOnly,
  156. },
  157. },
  158. },
  159. },
  160. }
  161. if _, err := client.CoreV1().Pods(ns.Name).Create(context.TODO(), pod, metav1.CreateOptions{}); err != nil {
  162. t.Errorf("Failed to create pod: %v", err)
  163. }
  164. integration.DeletePodOrErrorf(t, client, ns.Name, pod.Name)
  165. }
  166. func TestPodCreateEphemeralContainers(t *testing.T) {
  167. defer featuregatetesting.SetFeatureGateDuringTest(t, utilfeature.DefaultFeatureGate, features.EphemeralContainers, true)()
  168. _, s, closeFn := framework.RunAMaster(nil)
  169. defer closeFn()
  170. ns := framework.CreateTestingNamespace("pod-create-ephemeral-containers", s, t)
  171. defer framework.DeleteTestingNamespace(ns, s, t)
  172. client := clientset.NewForConfigOrDie(&restclient.Config{Host: s.URL, ContentConfig: restclient.ContentConfig{GroupVersion: &schema.GroupVersion{Group: "", Version: "v1"}}})
  173. pod := &v1.Pod{
  174. ObjectMeta: metav1.ObjectMeta{
  175. Name: "xxx",
  176. },
  177. Spec: v1.PodSpec{
  178. Containers: []v1.Container{
  179. {
  180. Name: "fake-name",
  181. Image: "fakeimage",
  182. ImagePullPolicy: "Always",
  183. TerminationMessagePolicy: "File",
  184. },
  185. },
  186. EphemeralContainers: []v1.EphemeralContainer{
  187. {
  188. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  189. Name: "debugger",
  190. Image: "debugimage",
  191. ImagePullPolicy: "Always",
  192. TerminationMessagePolicy: "File",
  193. },
  194. },
  195. },
  196. },
  197. }
  198. if _, err := client.CoreV1().Pods(ns.Name).Create(context.TODO(), pod, metav1.CreateOptions{}); err == nil {
  199. t.Errorf("Unexpected allowed creation of pod with ephemeral containers")
  200. integration.DeletePodOrErrorf(t, client, ns.Name, pod.Name)
  201. } else if !strings.HasSuffix(err.Error(), "spec.ephemeralContainers: Forbidden: cannot be set on create") {
  202. t.Errorf("Unexpected error when creating pod with ephemeral containers: %v", err)
  203. }
  204. }
  205. // setUpEphemeralContainers creates a pod that has Ephemeral Containers. This is a two step
  206. // process because Ephemeral Containers are not allowed during pod creation.
  207. func setUpEphemeralContainers(podsClient typedv1.PodInterface, pod *v1.Pod, containers []v1.EphemeralContainer) error {
  208. if _, err := podsClient.Create(context.TODO(), pod, metav1.CreateOptions{}); err != nil {
  209. return fmt.Errorf("failed to create pod: %v", err)
  210. }
  211. if len(containers) == 0 {
  212. return nil
  213. }
  214. pod.Spec.EphemeralContainers = containers
  215. if _, err := podsClient.Update(context.TODO(), pod, metav1.UpdateOptions{}); err == nil {
  216. return fmt.Errorf("unexpected allowed direct update of ephemeral containers during set up: %v", err)
  217. }
  218. ec, err := podsClient.GetEphemeralContainers(context.TODO(), pod.Name, metav1.GetOptions{})
  219. if err != nil {
  220. return fmt.Errorf("unable to get ephemeral containers for test case set up: %v", err)
  221. }
  222. ec.EphemeralContainers = containers
  223. if _, err = podsClient.UpdateEphemeralContainers(context.TODO(), pod.Name, ec, metav1.UpdateOptions{}); err != nil {
  224. return fmt.Errorf("failed to update ephemeral containers for test case set up: %v", err)
  225. }
  226. return nil
  227. }
  228. func TestPodPatchEphemeralContainers(t *testing.T) {
  229. defer featuregatetesting.SetFeatureGateDuringTest(t, utilfeature.DefaultFeatureGate, features.EphemeralContainers, true)()
  230. _, s, closeFn := framework.RunAMaster(nil)
  231. defer closeFn()
  232. ns := framework.CreateTestingNamespace("pod-patch-ephemeral-containers", s, t)
  233. defer framework.DeleteTestingNamespace(ns, s, t)
  234. client := clientset.NewForConfigOrDie(&restclient.Config{Host: s.URL, ContentConfig: restclient.ContentConfig{GroupVersion: &schema.GroupVersion{Group: "", Version: "v1"}}})
  235. testPod := func(name string) *v1.Pod {
  236. return &v1.Pod{
  237. ObjectMeta: metav1.ObjectMeta{
  238. Name: name,
  239. },
  240. Spec: v1.PodSpec{
  241. Containers: []v1.Container{
  242. {
  243. Name: "fake-name",
  244. Image: "fakeimage",
  245. ImagePullPolicy: "Always",
  246. TerminationMessagePolicy: "File",
  247. },
  248. },
  249. },
  250. }
  251. }
  252. cases := []struct {
  253. name string
  254. original []v1.EphemeralContainer
  255. patchType types.PatchType
  256. patchBody []byte
  257. valid bool
  258. }{
  259. {
  260. name: "create single container (strategic)",
  261. original: nil,
  262. patchType: types.StrategicMergePatchType,
  263. patchBody: []byte(`{
  264. "ephemeralContainers": [{
  265. "name": "debugger1",
  266. "image": "debugimage",
  267. "imagePullPolicy": "Always",
  268. "terminationMessagePolicy": "File"
  269. }]
  270. }`),
  271. valid: true,
  272. },
  273. {
  274. name: "create single container (merge)",
  275. original: nil,
  276. patchType: types.MergePatchType,
  277. patchBody: []byte(`{
  278. "ephemeralContainers":[{
  279. "name": "debugger1",
  280. "image": "debugimage",
  281. "imagePullPolicy": "Always",
  282. "terminationMessagePolicy": "File"
  283. }]
  284. }`),
  285. valid: true,
  286. },
  287. {
  288. name: "create single container (JSON)",
  289. original: nil,
  290. patchType: types.JSONPatchType,
  291. patchBody: []byte(`[{
  292. "op":"add",
  293. "path":"/ephemeralContainers/-",
  294. "value":{
  295. "name":"debugger1",
  296. "image":"debugimage",
  297. "imagePullPolicy": "Always",
  298. "terminationMessagePolicy": "File"
  299. }
  300. }]`),
  301. valid: true,
  302. },
  303. {
  304. name: "add single container (strategic)",
  305. original: []v1.EphemeralContainer{
  306. {
  307. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  308. Name: "debugger1",
  309. Image: "debugimage",
  310. ImagePullPolicy: "Always",
  311. TerminationMessagePolicy: "File",
  312. },
  313. },
  314. },
  315. patchType: types.StrategicMergePatchType,
  316. patchBody: []byte(`{
  317. "ephemeralContainers":[{
  318. "name": "debugger2",
  319. "image": "debugimage",
  320. "imagePullPolicy": "Always",
  321. "terminationMessagePolicy": "File"
  322. }]
  323. }`),
  324. valid: true,
  325. },
  326. {
  327. name: "add single container (merge)",
  328. original: []v1.EphemeralContainer{
  329. {
  330. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  331. Name: "debugger1",
  332. Image: "debugimage",
  333. ImagePullPolicy: "Always",
  334. TerminationMessagePolicy: "File",
  335. },
  336. },
  337. },
  338. patchType: types.MergePatchType,
  339. patchBody: []byte(`{
  340. "ephemeralContainers":[{
  341. "name": "debugger1",
  342. "image": "debugimage",
  343. "imagePullPolicy": "Always",
  344. "terminationMessagePolicy": "File"
  345. },{
  346. "name": "debugger2",
  347. "image": "debugimage",
  348. "imagePullPolicy": "Always",
  349. "terminationMessagePolicy": "File"
  350. }]
  351. }`),
  352. valid: true,
  353. },
  354. {
  355. name: "add single container (JSON)",
  356. original: []v1.EphemeralContainer{
  357. {
  358. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  359. Name: "debugger1",
  360. Image: "debugimage",
  361. ImagePullPolicy: "Always",
  362. TerminationMessagePolicy: "File",
  363. },
  364. },
  365. },
  366. patchType: types.JSONPatchType,
  367. patchBody: []byte(`[{
  368. "op":"add",
  369. "path":"/ephemeralContainers/-",
  370. "value":{
  371. "name":"debugger2",
  372. "image":"debugimage",
  373. "imagePullPolicy": "Always",
  374. "terminationMessagePolicy": "File"
  375. }
  376. }]`),
  377. valid: true,
  378. },
  379. {
  380. name: "remove all containers (merge)",
  381. original: []v1.EphemeralContainer{
  382. {
  383. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  384. Name: "debugger1",
  385. Image: "debugimage",
  386. ImagePullPolicy: "Always",
  387. TerminationMessagePolicy: "File",
  388. },
  389. },
  390. },
  391. patchType: types.MergePatchType,
  392. patchBody: []byte(`{"ephemeralContainers":[]}`),
  393. valid: false,
  394. },
  395. {
  396. name: "remove all containers (JSON)",
  397. original: []v1.EphemeralContainer{
  398. {
  399. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  400. Name: "debugger1",
  401. Image: "debugimage",
  402. ImagePullPolicy: "Always",
  403. TerminationMessagePolicy: "File",
  404. },
  405. },
  406. },
  407. patchType: types.JSONPatchType,
  408. patchBody: []byte(`[{"op":"remove","path":"/ephemeralContainers/0"}]`),
  409. valid: false,
  410. },
  411. }
  412. for i, tc := range cases {
  413. pod := testPod(fmt.Sprintf("ephemeral-container-test-%v", i))
  414. if err := setUpEphemeralContainers(client.CoreV1().Pods(ns.Name), pod, tc.original); err != nil {
  415. t.Errorf("%v: %v", tc.name, err)
  416. }
  417. if _, err := client.CoreV1().Pods(ns.Name).Patch(context.TODO(), pod.Name, tc.patchType, tc.patchBody, metav1.PatchOptions{}, "ephemeralcontainers"); tc.valid && err != nil {
  418. t.Errorf("%v: failed to update ephemeral containers: %v", tc.name, err)
  419. } else if !tc.valid && err == nil {
  420. t.Errorf("%v: unexpected allowed update to ephemeral containers", tc.name)
  421. }
  422. integration.DeletePodOrErrorf(t, client, ns.Name, pod.Name)
  423. }
  424. }
  425. func TestPodUpdateEphemeralContainers(t *testing.T) {
  426. defer featuregatetesting.SetFeatureGateDuringTest(t, utilfeature.DefaultFeatureGate, features.EphemeralContainers, true)()
  427. _, s, closeFn := framework.RunAMaster(nil)
  428. defer closeFn()
  429. ns := framework.CreateTestingNamespace("pod-update-ephemeral-containers", s, t)
  430. defer framework.DeleteTestingNamespace(ns, s, t)
  431. client := clientset.NewForConfigOrDie(&restclient.Config{Host: s.URL, ContentConfig: restclient.ContentConfig{GroupVersion: &schema.GroupVersion{Group: "", Version: "v1"}}})
  432. testPod := func(name string) *v1.Pod {
  433. return &v1.Pod{
  434. ObjectMeta: metav1.ObjectMeta{
  435. Name: name,
  436. },
  437. Spec: v1.PodSpec{
  438. Containers: []v1.Container{
  439. {
  440. Name: "fake-name",
  441. Image: "fakeimage",
  442. },
  443. },
  444. },
  445. }
  446. }
  447. cases := []struct {
  448. name string
  449. original []v1.EphemeralContainer
  450. update []v1.EphemeralContainer
  451. valid bool
  452. }{
  453. {
  454. name: "no change, nil",
  455. original: nil,
  456. update: nil,
  457. valid: true,
  458. },
  459. {
  460. name: "no change, set",
  461. original: []v1.EphemeralContainer{
  462. {
  463. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  464. Name: "debugger",
  465. Image: "debugimage",
  466. ImagePullPolicy: "Always",
  467. TerminationMessagePolicy: "File",
  468. },
  469. },
  470. },
  471. update: []v1.EphemeralContainer{
  472. {
  473. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  474. Name: "debugger",
  475. Image: "debugimage",
  476. ImagePullPolicy: "Always",
  477. TerminationMessagePolicy: "File",
  478. },
  479. },
  480. },
  481. valid: true,
  482. },
  483. {
  484. name: "add single container",
  485. original: nil,
  486. update: []v1.EphemeralContainer{
  487. {
  488. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  489. Name: "debugger",
  490. Image: "debugimage",
  491. ImagePullPolicy: "Always",
  492. TerminationMessagePolicy: "File",
  493. },
  494. },
  495. },
  496. valid: true,
  497. },
  498. {
  499. name: "remove all containers, nil",
  500. original: []v1.EphemeralContainer{
  501. {
  502. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  503. Name: "debugger",
  504. Image: "debugimage",
  505. ImagePullPolicy: "Always",
  506. TerminationMessagePolicy: "File",
  507. },
  508. },
  509. },
  510. update: nil,
  511. valid: false,
  512. },
  513. {
  514. name: "remove all containers, empty",
  515. original: []v1.EphemeralContainer{
  516. {
  517. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  518. Name: "debugger",
  519. Image: "debugimage",
  520. ImagePullPolicy: "Always",
  521. TerminationMessagePolicy: "File",
  522. },
  523. },
  524. },
  525. update: []v1.EphemeralContainer{},
  526. valid: false,
  527. },
  528. {
  529. name: "increase number of containers",
  530. original: []v1.EphemeralContainer{
  531. {
  532. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  533. Name: "debugger1",
  534. Image: "debugimage",
  535. ImagePullPolicy: "Always",
  536. TerminationMessagePolicy: "File",
  537. },
  538. },
  539. },
  540. update: []v1.EphemeralContainer{
  541. {
  542. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  543. Name: "debugger1",
  544. Image: "debugimage",
  545. ImagePullPolicy: "Always",
  546. TerminationMessagePolicy: "File",
  547. },
  548. },
  549. {
  550. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  551. Name: "debugger2",
  552. Image: "debugimage",
  553. ImagePullPolicy: "Always",
  554. TerminationMessagePolicy: "File",
  555. },
  556. },
  557. },
  558. valid: true,
  559. },
  560. {
  561. name: "decrease number of containers",
  562. original: []v1.EphemeralContainer{
  563. {
  564. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  565. Name: "debugger1",
  566. Image: "debugimage",
  567. ImagePullPolicy: "Always",
  568. TerminationMessagePolicy: "File",
  569. },
  570. },
  571. {
  572. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  573. Name: "debugger2",
  574. Image: "debugimage",
  575. ImagePullPolicy: "Always",
  576. TerminationMessagePolicy: "File",
  577. },
  578. },
  579. },
  580. update: []v1.EphemeralContainer{
  581. {
  582. EphemeralContainerCommon: v1.EphemeralContainerCommon{
  583. Name: "debugger1",
  584. Image: "debugimage",
  585. ImagePullPolicy: "Always",
  586. TerminationMessagePolicy: "File",
  587. },
  588. },
  589. },
  590. valid: false,
  591. },
  592. }
  593. for i, tc := range cases {
  594. pod := testPod(fmt.Sprintf("ephemeral-container-test-%v", i))
  595. if err := setUpEphemeralContainers(client.CoreV1().Pods(ns.Name), pod, tc.original); err != nil {
  596. t.Errorf("%v: %v", tc.name, err)
  597. }
  598. ec, err := client.CoreV1().Pods(ns.Name).GetEphemeralContainers(context.TODO(), pod.Name, metav1.GetOptions{})
  599. if err != nil {
  600. t.Errorf("%v: unable to get ephemeral containers: %v", tc.name, err)
  601. }
  602. ec.EphemeralContainers = tc.update
  603. if _, err := client.CoreV1().Pods(ns.Name).UpdateEphemeralContainers(context.TODO(), pod.Name, ec, metav1.UpdateOptions{}); tc.valid && err != nil {
  604. t.Errorf("%v: failed to update ephemeral containers: %v", tc.name, err)
  605. } else if !tc.valid && err == nil {
  606. t.Errorf("%v: unexpected allowed update to ephemeral containers", tc.name)
  607. }
  608. integration.DeletePodOrErrorf(t, client, ns.Name, pod.Name)
  609. }
  610. }