master_test.go 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492
  1. /*
  2. Copyright 2014 The Kubernetes Authors.
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package master
  14. import (
  15. "context"
  16. "crypto/tls"
  17. "encoding/json"
  18. "io/ioutil"
  19. "net"
  20. "net/http"
  21. "net/http/httptest"
  22. "reflect"
  23. "strings"
  24. "testing"
  25. certificatesapiv1beta1 "k8s.io/api/certificates/v1beta1"
  26. apiv1 "k8s.io/api/core/v1"
  27. metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
  28. "k8s.io/apimachinery/pkg/runtime/schema"
  29. utilnet "k8s.io/apimachinery/pkg/util/net"
  30. "k8s.io/apimachinery/pkg/util/sets"
  31. "k8s.io/apimachinery/pkg/version"
  32. "k8s.io/apiserver/pkg/authorization/authorizerfactory"
  33. genericapiserver "k8s.io/apiserver/pkg/server"
  34. "k8s.io/apiserver/pkg/server/options"
  35. "k8s.io/apiserver/pkg/server/resourceconfig"
  36. serverstorage "k8s.io/apiserver/pkg/server/storage"
  37. etcd3testing "k8s.io/apiserver/pkg/storage/etcd3/testing"
  38. "k8s.io/client-go/discovery"
  39. "k8s.io/client-go/informers"
  40. "k8s.io/client-go/kubernetes"
  41. "k8s.io/client-go/kubernetes/fake"
  42. restclient "k8s.io/client-go/rest"
  43. kubeversion "k8s.io/component-base/version"
  44. "k8s.io/kubernetes/pkg/api/legacyscheme"
  45. "k8s.io/kubernetes/pkg/apis/batch"
  46. "k8s.io/kubernetes/pkg/apis/networking"
  47. apisstorage "k8s.io/kubernetes/pkg/apis/storage"
  48. kubeletclient "k8s.io/kubernetes/pkg/kubelet/client"
  49. "k8s.io/kubernetes/pkg/master/reconcilers"
  50. "k8s.io/kubernetes/pkg/master/storageversionhashdata"
  51. certificatesrest "k8s.io/kubernetes/pkg/registry/certificates/rest"
  52. corerest "k8s.io/kubernetes/pkg/registry/core/rest"
  53. "k8s.io/kubernetes/pkg/registry/registrytest"
  54. "github.com/stretchr/testify/assert"
  55. )
  56. // setUp is a convenience function for setting up for (most) tests.
  57. func setUp(t *testing.T) (*etcd3testing.EtcdTestServer, Config, *assert.Assertions) {
  58. server, storageConfig := etcd3testing.NewUnsecuredEtcd3TestClientServer(t)
  59. config := &Config{
  60. GenericConfig: genericapiserver.NewConfig(legacyscheme.Codecs),
  61. ExtraConfig: ExtraConfig{
  62. APIResourceConfigSource: DefaultAPIResourceConfigSource(),
  63. APIServerServicePort: 443,
  64. MasterCount: 1,
  65. EndpointReconcilerType: reconcilers.MasterCountReconcilerType,
  66. },
  67. }
  68. resourceEncoding := serverstorage.NewDefaultResourceEncodingConfig(legacyscheme.Scheme)
  69. // This configures the testing master the same way the real master is
  70. // configured. The storage versions of these resources are different
  71. // from the storage versions of other resources in their group.
  72. resourceEncodingOverrides := []schema.GroupVersionResource{
  73. batch.Resource("cronjobs").WithVersion("v1beta1"),
  74. apisstorage.Resource("volumeattachments").WithVersion("v1beta1"),
  75. networking.Resource("ingresses").WithVersion("v1beta1"),
  76. }
  77. resourceEncoding = resourceconfig.MergeResourceEncodingConfigs(resourceEncoding, resourceEncodingOverrides)
  78. storageFactory := serverstorage.NewDefaultStorageFactory(*storageConfig, "application/vnd.kubernetes.protobuf", legacyscheme.Codecs, resourceEncoding, DefaultAPIResourceConfigSource(), nil)
  79. etcdOptions := options.NewEtcdOptions(storageConfig)
  80. // unit tests don't need watch cache and it leaks lots of goroutines with etcd testing functions during unit tests
  81. etcdOptions.EnableWatchCache = false
  82. err := etcdOptions.ApplyWithStorageFactoryTo(storageFactory, config.GenericConfig)
  83. if err != nil {
  84. t.Fatal(err)
  85. }
  86. kubeVersion := kubeversion.Get()
  87. config.GenericConfig.Authorization.Authorizer = authorizerfactory.NewAlwaysAllowAuthorizer()
  88. config.GenericConfig.Version = &kubeVersion
  89. config.ExtraConfig.StorageFactory = storageFactory
  90. config.GenericConfig.LoopbackClientConfig = &restclient.Config{APIPath: "/api", ContentConfig: restclient.ContentConfig{NegotiatedSerializer: legacyscheme.Codecs}}
  91. config.GenericConfig.PublicAddress = net.ParseIP("192.168.10.4")
  92. config.GenericConfig.LegacyAPIGroupPrefixes = sets.NewString("/api")
  93. config.ExtraConfig.KubeletClientConfig = kubeletclient.KubeletClientConfig{Port: 10250}
  94. config.ExtraConfig.ProxyTransport = utilnet.SetTransportDefaults(&http.Transport{
  95. DialContext: func(ctx context.Context, network, addr string) (net.Conn, error) { return nil, nil },
  96. TLSClientConfig: &tls.Config{},
  97. })
  98. // set fake SecureServingInfo because the listener port is needed for the kubernetes service
  99. config.GenericConfig.SecureServing = &genericapiserver.SecureServingInfo{Listener: fakeLocalhost443Listener{}}
  100. clientset, err := kubernetes.NewForConfig(config.GenericConfig.LoopbackClientConfig)
  101. if err != nil {
  102. t.Fatalf("unable to create client set due to %v", err)
  103. }
  104. config.ExtraConfig.VersionedInformers = informers.NewSharedInformerFactory(clientset, config.GenericConfig.LoopbackClientConfig.Timeout)
  105. return server, *config, assert.New(t)
  106. }
  107. type fakeLocalhost443Listener struct{}
  108. func (fakeLocalhost443Listener) Accept() (net.Conn, error) {
  109. return nil, nil
  110. }
  111. func (fakeLocalhost443Listener) Close() error {
  112. return nil
  113. }
  114. func (fakeLocalhost443Listener) Addr() net.Addr {
  115. return &net.TCPAddr{
  116. IP: net.IPv4(127, 0, 0, 1),
  117. Port: 443,
  118. }
  119. }
  120. // TestLegacyRestStorageStrategies ensures that all Storage objects which are using the generic registry Store have
  121. // their various strategies properly wired up. This surfaced as a bug where strategies defined Export functions, but
  122. // they were never used outside of unit tests because the export strategies were not assigned inside the Store.
  123. func TestLegacyRestStorageStrategies(t *testing.T) {
  124. _, etcdserver, masterCfg, _ := newMaster(t)
  125. defer etcdserver.Terminate(t)
  126. storageProvider := corerest.LegacyRESTStorageProvider{
  127. StorageFactory: masterCfg.ExtraConfig.StorageFactory,
  128. ProxyTransport: masterCfg.ExtraConfig.ProxyTransport,
  129. KubeletClientConfig: masterCfg.ExtraConfig.KubeletClientConfig,
  130. EventTTL: masterCfg.ExtraConfig.EventTTL,
  131. ServiceIPRange: masterCfg.ExtraConfig.ServiceIPRange,
  132. ServiceNodePortRange: masterCfg.ExtraConfig.ServiceNodePortRange,
  133. LoopbackClientConfig: masterCfg.GenericConfig.LoopbackClientConfig,
  134. }
  135. _, apiGroupInfo, err := storageProvider.NewLegacyRESTStorage(masterCfg.GenericConfig.RESTOptionsGetter)
  136. if err != nil {
  137. t.Errorf("failed to create legacy REST storage: %v", err)
  138. }
  139. // Any new stores with export logic will need to be added here:
  140. exceptions := registrytest.StrategyExceptions{
  141. // Only these stores should have an export strategy defined:
  142. HasExportStrategy: []string{
  143. "secrets",
  144. "limitRanges",
  145. "nodes",
  146. "podTemplates",
  147. },
  148. }
  149. strategyErrors := registrytest.ValidateStorageStrategies(apiGroupInfo.VersionedResourcesStorageMap["v1"], exceptions)
  150. for _, err := range strategyErrors {
  151. t.Error(err)
  152. }
  153. }
  154. func TestCertificatesRestStorageStrategies(t *testing.T) {
  155. _, etcdserver, masterCfg, _ := newMaster(t)
  156. defer etcdserver.Terminate(t)
  157. certStorageProvider := certificatesrest.RESTStorageProvider{}
  158. apiGroupInfo, _, err := certStorageProvider.NewRESTStorage(masterCfg.ExtraConfig.APIResourceConfigSource, masterCfg.GenericConfig.RESTOptionsGetter)
  159. if err != nil {
  160. t.Fatalf("unexpected error from REST storage: %v", err)
  161. }
  162. exceptions := registrytest.StrategyExceptions{
  163. HasExportStrategy: []string{
  164. "certificatesigningrequests",
  165. },
  166. }
  167. strategyErrors := registrytest.ValidateStorageStrategies(
  168. apiGroupInfo.VersionedResourcesStorageMap[certificatesapiv1beta1.SchemeGroupVersion.Version], exceptions)
  169. for _, err := range strategyErrors {
  170. t.Error(err)
  171. }
  172. }
  173. func newMaster(t *testing.T) (*Master, *etcd3testing.EtcdTestServer, Config, *assert.Assertions) {
  174. etcdserver, config, assert := setUp(t)
  175. master, err := config.Complete().New(genericapiserver.NewEmptyDelegate())
  176. if err != nil {
  177. t.Fatalf("Error in bringing up the master: %v", err)
  178. }
  179. return master, etcdserver, config, assert
  180. }
  181. // TestVersion tests /version
  182. func TestVersion(t *testing.T) {
  183. s, etcdserver, _, _ := newMaster(t)
  184. defer etcdserver.Terminate(t)
  185. req, _ := http.NewRequest("GET", "/version", nil)
  186. resp := httptest.NewRecorder()
  187. s.GenericAPIServer.Handler.ServeHTTP(resp, req)
  188. if resp.Code != 200 {
  189. t.Fatalf("expected http 200, got: %d", resp.Code)
  190. }
  191. var info version.Info
  192. err := json.NewDecoder(resp.Body).Decode(&info)
  193. if err != nil {
  194. t.Errorf("unexpected error: %v", err)
  195. }
  196. if !reflect.DeepEqual(kubeversion.Get(), info) {
  197. t.Errorf("Expected %#v, Got %#v", kubeversion.Get(), info)
  198. }
  199. }
  200. func makeNodeList(nodes []string, nodeResources apiv1.NodeResources) *apiv1.NodeList {
  201. list := apiv1.NodeList{
  202. Items: make([]apiv1.Node, len(nodes)),
  203. }
  204. for i := range nodes {
  205. list.Items[i].Name = nodes[i]
  206. list.Items[i].Status.Capacity = nodeResources.Capacity
  207. }
  208. return &list
  209. }
  210. // TestGetNodeAddresses verifies that proper results are returned
  211. // when requesting node addresses.
  212. func TestGetNodeAddresses(t *testing.T) {
  213. assert := assert.New(t)
  214. fakeNodeClient := fake.NewSimpleClientset(makeNodeList([]string{"node1", "node2"}, apiv1.NodeResources{})).CoreV1().Nodes()
  215. addressProvider := nodeAddressProvider{fakeNodeClient}
  216. // Fail case (no addresses associated with nodes)
  217. addrs, err := addressProvider.externalAddresses()
  218. assert.Error(err, "addresses should have caused an error as there are no addresses.")
  219. assert.Equal([]string(nil), addrs)
  220. // Pass case with External type IP
  221. nodes, _ := fakeNodeClient.List(context.TODO(), metav1.ListOptions{})
  222. for index := range nodes.Items {
  223. nodes.Items[index].Status.Addresses = []apiv1.NodeAddress{{Type: apiv1.NodeExternalIP, Address: "127.0.0.1"}}
  224. fakeNodeClient.Update(context.TODO(), &nodes.Items[index], metav1.UpdateOptions{})
  225. }
  226. addrs, err = addressProvider.externalAddresses()
  227. assert.NoError(err, "addresses should not have returned an error.")
  228. assert.Equal([]string{"127.0.0.1", "127.0.0.1"}, addrs)
  229. }
  230. func TestGetNodeAddressesWithOnlySomeExternalIP(t *testing.T) {
  231. assert := assert.New(t)
  232. fakeNodeClient := fake.NewSimpleClientset(makeNodeList([]string{"node1", "node2", "node3"}, apiv1.NodeResources{})).CoreV1().Nodes()
  233. addressProvider := nodeAddressProvider{fakeNodeClient}
  234. // Pass case with 1 External type IP (index == 1) and nodes (indexes 0 & 2) have no External IP.
  235. nodes, _ := fakeNodeClient.List(context.TODO(), metav1.ListOptions{})
  236. nodes.Items[1].Status.Addresses = []apiv1.NodeAddress{{Type: apiv1.NodeExternalIP, Address: "127.0.0.1"}}
  237. fakeNodeClient.Update(context.TODO(), &nodes.Items[1], metav1.UpdateOptions{})
  238. addrs, err := addressProvider.externalAddresses()
  239. assert.NoError(err, "addresses should not have returned an error.")
  240. assert.Equal([]string{"127.0.0.1"}, addrs)
  241. }
  242. func decodeResponse(resp *http.Response, obj interface{}) error {
  243. defer resp.Body.Close()
  244. data, err := ioutil.ReadAll(resp.Body)
  245. if err != nil {
  246. return err
  247. }
  248. if err := json.Unmarshal(data, obj); err != nil {
  249. return err
  250. }
  251. return nil
  252. }
  253. // Because we need to be backwards compatible with release 1.1, at endpoints
  254. // that exist in release 1.1, the responses should have empty APIVersion.
  255. func TestAPIVersionOfDiscoveryEndpoints(t *testing.T) {
  256. master, etcdserver, _, assert := newMaster(t)
  257. defer etcdserver.Terminate(t)
  258. server := httptest.NewServer(master.GenericAPIServer.Handler.GoRestfulContainer.ServeMux)
  259. // /api exists in release-1.1
  260. resp, err := http.Get(server.URL + "/api")
  261. if err != nil {
  262. t.Errorf("unexpected error: %v", err)
  263. }
  264. apiVersions := metav1.APIVersions{}
  265. assert.NoError(decodeResponse(resp, &apiVersions))
  266. assert.Equal(apiVersions.APIVersion, "")
  267. // /api/v1 exists in release-1.1
  268. resp, err = http.Get(server.URL + "/api/v1")
  269. if err != nil {
  270. t.Errorf("unexpected error: %v", err)
  271. }
  272. resourceList := metav1.APIResourceList{}
  273. assert.NoError(decodeResponse(resp, &resourceList))
  274. assert.Equal(resourceList.APIVersion, "")
  275. // /apis exists in release-1.1
  276. resp, err = http.Get(server.URL + "/apis")
  277. if err != nil {
  278. t.Errorf("unexpected error: %v", err)
  279. }
  280. groupList := metav1.APIGroupList{}
  281. assert.NoError(decodeResponse(resp, &groupList))
  282. assert.Equal(groupList.APIVersion, "")
  283. // /apis/extensions exists in release-1.1
  284. resp, err = http.Get(server.URL + "/apis/extensions")
  285. if err != nil {
  286. t.Errorf("unexpected error: %v", err)
  287. }
  288. group := metav1.APIGroup{}
  289. assert.NoError(decodeResponse(resp, &group))
  290. assert.Equal(group.APIVersion, "")
  291. // /apis/extensions/v1beta1 exists in release-1.1
  292. resp, err = http.Get(server.URL + "/apis/extensions/v1beta1")
  293. if err != nil {
  294. t.Errorf("unexpected error: %v", err)
  295. }
  296. resourceList = metav1.APIResourceList{}
  297. assert.NoError(decodeResponse(resp, &resourceList))
  298. assert.Equal(resourceList.APIVersion, "")
  299. // /apis/autoscaling doesn't exist in release-1.1, so the APIVersion field
  300. // should be non-empty in the results returned by the server.
  301. resp, err = http.Get(server.URL + "/apis/autoscaling")
  302. if err != nil {
  303. t.Errorf("unexpected error: %v", err)
  304. }
  305. group = metav1.APIGroup{}
  306. assert.NoError(decodeResponse(resp, &group))
  307. assert.Equal(group.APIVersion, "v1")
  308. // apis/autoscaling/v1 doesn't exist in release-1.1, so the APIVersion field
  309. // should be non-empty in the results returned by the server.
  310. resp, err = http.Get(server.URL + "/apis/autoscaling/v1")
  311. if err != nil {
  312. t.Errorf("unexpected error: %v", err)
  313. }
  314. resourceList = metav1.APIResourceList{}
  315. assert.NoError(decodeResponse(resp, &resourceList))
  316. assert.Equal(resourceList.APIVersion, "v1")
  317. }
  318. // This test doesn't cover the apiregistration and apiextensions group, as they are installed by other apiservers.
  319. func TestStorageVersionHashes(t *testing.T) {
  320. master, etcdserver, _, _ := newMaster(t)
  321. defer etcdserver.Terminate(t)
  322. server := httptest.NewServer(master.GenericAPIServer.Handler.GoRestfulContainer.ServeMux)
  323. c := &restclient.Config{
  324. Host: server.URL,
  325. APIPath: "/api",
  326. ContentConfig: restclient.ContentConfig{NegotiatedSerializer: legacyscheme.Codecs},
  327. }
  328. discover := discovery.NewDiscoveryClientForConfigOrDie(c)
  329. all, err := discover.ServerResources()
  330. if err != nil {
  331. t.Error(err)
  332. }
  333. var count int
  334. for _, g := range all {
  335. for _, r := range g.APIResources {
  336. if strings.Contains(r.Name, "/") ||
  337. storageversionhashdata.NoStorageVersionHash.Has(g.GroupVersion+"/"+r.Name) {
  338. if r.StorageVersionHash != "" {
  339. t.Errorf("expect resource %s/%s to have empty storageVersionHash, got hash %q", g.GroupVersion, r.Name, r.StorageVersionHash)
  340. }
  341. continue
  342. }
  343. if r.StorageVersionHash == "" {
  344. t.Errorf("expect the storageVersionHash of %s/%s to exist", g.GroupVersion, r.Name)
  345. continue
  346. }
  347. // Uncomment the following line if you want to update storageversionhash/data.go
  348. // fmt.Printf("\"%s/%s\": \"%s\",\n", g.GroupVersion, r.Name, r.StorageVersionHash)
  349. expected := storageversionhashdata.GVRToStorageVersionHash[g.GroupVersion+"/"+r.Name]
  350. if r.StorageVersionHash != expected {
  351. t.Errorf("expect the storageVersionHash of %s/%s to be %q, got %q", g.GroupVersion, r.Name, expected, r.StorageVersionHash)
  352. }
  353. count++
  354. }
  355. }
  356. if count != len(storageversionhashdata.GVRToStorageVersionHash) {
  357. t.Errorf("please remove the redundant entries from GVRToStorageVersionHash")
  358. }
  359. }
  360. func TestStorageVersionHashEqualities(t *testing.T) {
  361. master, etcdserver, _, assert := newMaster(t)
  362. defer etcdserver.Terminate(t)
  363. server := httptest.NewServer(master.GenericAPIServer.Handler.GoRestfulContainer.ServeMux)
  364. // Test 1: extensions/v1beta1/ingresses and apps/v1/ingresses have
  365. // the same storage version hash.
  366. resp, err := http.Get(server.URL + "/apis/extensions/v1beta1")
  367. assert.Empty(err)
  368. extList := metav1.APIResourceList{}
  369. assert.NoError(decodeResponse(resp, &extList))
  370. var extIngressHash, appsIngressHash string
  371. for _, r := range extList.APIResources {
  372. if r.Name == "ingresses" {
  373. extIngressHash = r.StorageVersionHash
  374. assert.NotEmpty(extIngressHash)
  375. }
  376. }
  377. resp, err = http.Get(server.URL + "/apis/networking.k8s.io/v1beta1")
  378. assert.Empty(err)
  379. appsList := metav1.APIResourceList{}
  380. assert.NoError(decodeResponse(resp, &appsList))
  381. for _, r := range appsList.APIResources {
  382. if r.Name == "ingresses" {
  383. appsIngressHash = r.StorageVersionHash
  384. assert.NotEmpty(appsIngressHash)
  385. }
  386. }
  387. if len(extIngressHash) > 0 && len(appsIngressHash) > 0 {
  388. assert.Equal(extIngressHash, appsIngressHash)
  389. }
  390. // Test 2: batch/v1/jobs and batch/v1beta1/cronjobs have different
  391. // storage version hashes.
  392. resp, err = http.Get(server.URL + "/apis/batch/v1")
  393. assert.Empty(err)
  394. batchv1 := metav1.APIResourceList{}
  395. assert.NoError(decodeResponse(resp, &batchv1))
  396. var jobsHash string
  397. for _, r := range batchv1.APIResources {
  398. if r.Name == "jobs" {
  399. jobsHash = r.StorageVersionHash
  400. }
  401. }
  402. assert.NotEmpty(jobsHash)
  403. resp, err = http.Get(server.URL + "/apis/batch/v1beta1")
  404. assert.Empty(err)
  405. batchv1beta1 := metav1.APIResourceList{}
  406. assert.NoError(decodeResponse(resp, &batchv1beta1))
  407. var cronjobsHash string
  408. for _, r := range batchv1beta1.APIResources {
  409. if r.Name == "cronjobs" {
  410. cronjobsHash = r.StorageVersionHash
  411. }
  412. }
  413. assert.NotEmpty(cronjobsHash)
  414. assert.NotEqual(jobsHash, cronjobsHash)
  415. }
  416. func TestNoAlphaVersionsEnabledByDefault(t *testing.T) {
  417. config := DefaultAPIResourceConfigSource()
  418. for gv, enable := range config.GroupVersionConfigs {
  419. if enable && strings.Contains(gv.Version, "alpha") {
  420. t.Errorf("Alpha API version %s enabled by default", gv.String())
  421. }
  422. }
  423. }