Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
128 changes: 128 additions & 0 deletions .github/workflows/ui.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,128 @@
name: UI tests

on:
pull_request:
push:
branches:
- master

jobs:
ui-e2e-tests:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0

- name: Free disk space (delete unused tools)
id: delete-unused-tools
continue-on-error: true
shell: bash
run: |
free_disk_space=22
# delete preinstalled unused tools
cleanup=(
/usr/share/dotnet
/usr/share/miniconda
/usr/share/swift
/usr/share/kotlinc
/opt/ghc
/opt/hostedtoolcache/CodeQL
/opt/hostedtoolcache/Ruby
/opt/az
/usr/local/lib/android
)
for d in "${cleanup[@]}"; do
if [[ -d "$d" ]]; then
rm -rf -- "$d" && echo "deleted $d"
else
echo "$d not found"
continue
fi
free=$(df -BGB --output=avail / | tail -1)
if [[ ${free%GB} -ge "${free_disk_space}" ]]; then
echo "Reached requested free disk space ${free_disk_space} [${free} free]."
exit 0
fi
done
df -h

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Create KinD Cluster
uses: helm/kind-action@v1
with:
cluster_name: kind

- name: tags
run: |
echo "TAG=$(make tag)" | tee -a "$GITHUB_ENV"

- name: Build Docker image
uses: docker/build-push-action@v5
with:
file: image/Dockerfile
context: .
push: false
load: true
tags: quay.io/rhacs-eng/infra-server:${{ env.TAG }}
cache-from: type=gha
cache-to: type=gha,mode=max

- name: Load into KinD
run: |
# Check cluster name
kind get clusters
#docker build -t quay.io/rhacs-eng/infra-server:${{ env.TAG }} -f image/Dockerfile .
kind load docker-image quay.io/rhacs-eng/infra-server:${{ env.TAG }} --name kind
docker images | grep infra-server

- name: Deploy
run: make deploy-local

- name: Wait for pods
run: kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m

- name: Start port-forward
run: |
kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 &
echo "PORT_FORWARD_PID=$!" >> "$GITHUB_ENV"
sleep 5
# Verify port-forward is working
timeout 10 sh -c 'until curl -k -f https://localhost:8443/v1/whoami 2>/dev/null; do sleep 1; done' || echo "Warning: Backend may not be ready"

- name: Run E2E tests
uses: cypress-io/github-action@v6
with:
working-directory: ui
start: npm run start
wait-on: 'http://localhost:3001'
wait-on-timeout: 60
command: npm run cypress:run:e2e
env:
BROWSER: none
PORT: 3001
# Backend uses HTTPS with self-signed cert (see scripts/deploy/helm.sh)
INFRA_API_ENDPOINT: https://localhost:8443

- name: Upload test artifacts
if: failure()
uses: actions/upload-artifact@v4
with:
name: cypress-artifacts
path: |
ui/cypress/videos
ui/cypress/screenshots
retention-days: 7

- name: Cleanup port-forward
if: always()
run: |
# Kill by PID if available, otherwise kill by process name
if [ -n "${{ env.PORT_FORWARD_PID }}" ]; then
echo "Cleaning up port-forward (PID: ${{ env.PORT_FORWARD_PID }})..."
kill ${{ env.PORT_FORWARD_PID }} 2>/dev/null || true
fi
# Fallback: kill any remaining port-forward processes
pkill -f "kubectl port-forward.*8443:8443" 2>/dev/null || true
6 changes: 6 additions & 0 deletions DEPLOYMENT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -116,6 +116,12 @@ Use the environment variable `TEST_MODE` to disable certain infra service behavi

This is used in the infra PR clusters to set the login referer and disable telemetry.

#### Deployments for testing only (no secrets)

For test clusters (such as a local KinD/Colima), you can use the deploy-local make target to skip loading secrets. The flavor provisioning actions that require secrets will not be accessible, and integrations such as with Slack will be disabled.

`make deploy-local`

### Rollback

Use `helm rollback infra-server <REVISION>`.
Expand Down
25 changes: 25 additions & 0 deletions Makefile
Original file line numberDiff line numberDiff line change
Expand Up@@ -253,6 +253,31 @@ helm-deploy: pre-check helm-dependency-update create-namespaces
helm-diff: pre-check helm-dependency-update create-namespaces
@./scripts/deploy/helm.sh diff $(VERSION) $(ENVIRONMENT) $(SECRET_VERSION)

## Deploy to local cluster (e.g., Colima) without GCP Secret Manager
.PHONY: deploy-local
deploy-local: helm-dependency-update create-namespaces
TEST_MODE=true ./scripts/deploy/helm.sh deploy-local $(shell make tag) local

## Run UI E2E tests against local deployment
.PHONY: test-e2e
test-e2e:
@echo "test-e2e starting..." >&2
@echo "Waiting for infra-server to be ready..." >&2
@kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m >&2 || \
(echo "ERROR: infra-server pods did not become ready" >&2 && exit 1)
@echo "Starting port-forward and running E2E tests..." >&2
@kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 & \
PF_PID=$$!; \
cleanup() { \
echo "" >&2; \
echo "Cleaning up port-forward (PID: $$PF_PID)..." >&2; \
kill $$PF_PID 2>/dev/null || true; \
}; \
trap cleanup EXIT; \
sleep 5; \
echo "Running Cypress E2E tests..." >&2; \
cd ui && BROWSER=none PORT=3001 INFRA_API_ENDPOINT=http://localhost:8443 npm run test:e2e

## Bounce pods
.PHONY: bounce-infra-pods
bounce-infra-pods:
Expand Down
30 changes: 30 additions & 0 deletions chart/infra-server/configuration/local-values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
environment: local

# Set local deploy mode to true for local development
localDeploy: true

# Enable test mode for faster cluster resume intervals
testMode: true

# Use local Docker images when available, pull from registry if not present
# Works with Colima (shared Docker daemon) and kind (after kind load docker-image)
# IfNotPresent provides flexibility: uses local images when available, pulls when needed
imagePullPolicy: IfNotPresent

# Pull secrets for container registries - dummy values for local development
pullSecrets:
docker:
registry: "docker.io"
username: "dummy"
password: "dummy"
quay:
registry: "quay.io"
username: "dummy"
password: "dummy"
stackrox:
registry: "stackrox.io"
username: "dummy"
password: "dummy"

# Alertmanager configuration
alertmanagerSlackTeam: "dummy-team"
2 changes: 2 additions & 0 deletions chart/infra-server/templates/argo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -7,3 +8,4 @@ metadata:
data:
credentials.json: |-
{{ required ".Values.google_credentials_json is undefined" .Values.google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aro/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -16,3 +17,4 @@ data:
{{ .Values.aroClusterManager.azureSPSecretVal | b64enc }}
REDHAT_PULL_SECRET_BASE64: |-
{{ .Values.aroClusterManager.redHatPullSecretBase64 | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aws/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -10,3 +11,4 @@ data:
{{ .Values.aws.accessKeyId | b64enc }}
AWS_SECRET_ACCESS_KEY: |-
{{ .Values.aws.secretAccessKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/azure/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}

---

Expand All@@ -18,3 +19,4 @@ data:
{{ .Values.azure.sp_tenant | b64enc }}
ACR_TO_ATTACH: |-
{{ .Values.azure.aks_attached_acr | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/demo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand DownExpand Up@@ -90,3 +91,4 @@ data:
.dockerconfigjson: {{ template "pull-secret" .Values.pullSecrets.quay }}

---
{{- end }}
4 changes: 3 additions & 1 deletion chart/infra-server/templates/deployment.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,8 +27,10 @@ spec:
- name: infra-server
image: quay.io/rhacs-eng/infra-server:{{ required "A valid .Values.tag entry is required!" .Values.tag }}
env:
{{- if not .Values.localDeploy }}
- name: GOOGLE_APPLICATION_CREDENTIALS
value: /configuration/google-credentials.json
{{- end }}
- name: TEST_MODE
value: "{{ .Values.testMode }}"
readinessProbe:
Expand All@@ -47,7 +49,7 @@ spec:
containerPort: 8443
- name: metrics
containerPort: 9101
imagePullPolicy: Always
imagePullPolicy: {{ .Values.imagePullPolicy | default "Always" }}
volumeMounts:
- mountPath: /configuration
name: configuration
Expand Down
2 changes: 2 additions & 0 deletions chart/infra-server/templates/gke/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand All@@ -13,3 +14,4 @@ data:
{{ required ".Values.gke__gke_provisioner_json is undefined" .Values.gke__gke_provisioner_json }}

---
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/ibm/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -8,3 +9,4 @@ metadata:
data:
IBM_ROKS_API_KEY: |-
{{ .Values.ibmCloudSecrets.ibmRoksApiKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/monitoring/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -6,3 +7,4 @@ metadata:
namespace: monitoring
data:
webhookURL: "{{ .Values.alertmanagerSlackWebhook | b64enc }}"
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift-4/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand DownExpand Up@@ -43,3 +44,4 @@ metadata:
data:
REDHAT_PULL_SECRET: |-
{{ required ".Values.openshift_4__redhat_pull_secret_json is undefined" .Values.openshift_4__redhat_pull_secret_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand All@@ -9,3 +10,4 @@ metadata:
data:
google-credentials.json: |-
{{ required ".Values.openshift__google_credentials_json is undefined" .Values.openshift__google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/osd/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -19,3 +20,4 @@ data:
{{ .Values.osdClusterManager.gcpSaCredsJsonBase64 | b64enc }}
GCP_SERVICE_ACCOUNT_KEY_BASE64: |-
{{ .Values.osdClusterManager.gcpServiceAccountKeyBase64 | b64enc }}
{{- end }}
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
128 changes: 128 additions & 0 deletions .github/workflows/ui.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,128 @@
name: UI tests

on:
pull_request:
push:
branches:
- master

jobs:
ui-e2e-tests:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0

- name: Free disk space (delete unused tools)
id: delete-unused-tools
continue-on-error: true
shell: bash
run: |
free_disk_space=22
# delete preinstalled unused tools
cleanup=(
/usr/share/dotnet
/usr/share/miniconda
/usr/share/swift
/usr/share/kotlinc
/opt/ghc
/opt/hostedtoolcache/CodeQL
/opt/hostedtoolcache/Ruby
/opt/az
/usr/local/lib/android
)
for d in "${cleanup[@]}"; do
if [[ -d "$d" ]]; then
rm -rf -- "$d" && echo "deleted $d"
else
echo "$d not found"
continue
fi
free=$(df -BGB --output=avail / | tail -1)
if [[ ${free%GB} -ge "${free_disk_space}" ]]; then
echo "Reached requested free disk space ${free_disk_space} [${free} free]."
exit 0
fi
done
df -h

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Create KinD Cluster
uses: helm/kind-action@v1
with:
cluster_name: kind

- name: tags
run: |
echo "TAG=$(make tag)" | tee -a "$GITHUB_ENV"

- name: Build Docker image
uses: docker/build-push-action@v5
with:
file: image/Dockerfile
context: .
push: false
load: true
tags: quay.io/rhacs-eng/infra-server:${{ env.TAG }}
cache-from: type=gha
cache-to: type=gha,mode=max

- name: Load into KinD
run: |
# Check cluster name
kind get clusters
#docker build -t quay.io/rhacs-eng/infra-server:${{ env.TAG }} -f image/Dockerfile .
kind load docker-image quay.io/rhacs-eng/infra-server:${{ env.TAG }} --name kind
docker images | grep infra-server

- name: Deploy
run: make deploy-local

- name: Wait for pods
run: kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m

- name: Start port-forward
run: |
kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 &
echo "PORT_FORWARD_PID=$!" >> "$GITHUB_ENV"
sleep 5
# Verify port-forward is working
timeout 10 sh -c 'until curl -k -f https://localhost:8443/v1/whoami 2>/dev/null; do sleep 1; done' || echo "Warning: Backend may not be ready"

- name: Run E2E tests
uses: cypress-io/github-action@v6
with:
working-directory: ui
start: npm run start
wait-on: 'http://localhost:3001'
wait-on-timeout: 60
command: npm run cypress:run:e2e
env:
BROWSER: none
PORT: 3001
# Backend uses HTTPS with self-signed cert (see scripts/deploy/helm.sh)
INFRA_API_ENDPOINT: https://localhost:8443

- name: Upload test artifacts
if: failure()
uses: actions/upload-artifact@v4
with:
name: cypress-artifacts
path: |
ui/cypress/videos
ui/cypress/screenshots
retention-days: 7

- name: Cleanup port-forward
if: always()
run: |
# Kill by PID if available, otherwise kill by process name
if [ -n "${{ env.PORT_FORWARD_PID }}" ]; then
echo "Cleaning up port-forward (PID: ${{ env.PORT_FORWARD_PID }})..."
kill ${{ env.PORT_FORWARD_PID }} 2>/dev/null || true
fi
# Fallback: kill any remaining port-forward processes
pkill -f "kubectl port-forward.*8443:8443" 2>/dev/null || true
6 changes: 6 additions & 0 deletions DEPLOYMENT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -116,6 +116,12 @@ Use the environment variable `TEST_MODE` to disable certain infra service behavi

This is used in the infra PR clusters to set the login referer and disable telemetry.

#### Deployments for testing only (no secrets)

For test clusters (such as a local KinD/Colima), you can use the deploy-local make target to skip loading secrets. The flavor provisioning actions that require secrets will not be accessible, and integrations such as with Slack will be disabled.

`make deploy-local`

### Rollback

Use `helm rollback infra-server <REVISION>`.
Expand Down
25 changes: 25 additions & 0 deletions Makefile
Original file line numberDiff line numberDiff line change
Expand Up@@ -253,6 +253,31 @@ helm-deploy: pre-check helm-dependency-update create-namespaces
helm-diff: pre-check helm-dependency-update create-namespaces
@./scripts/deploy/helm.sh diff $(VERSION) $(ENVIRONMENT) $(SECRET_VERSION)

## Deploy to local cluster (e.g., Colima) without GCP Secret Manager
.PHONY: deploy-local
deploy-local: helm-dependency-update create-namespaces
TEST_MODE=true ./scripts/deploy/helm.sh deploy-local $(shell make tag) local

## Run UI E2E tests against local deployment
.PHONY: test-e2e
test-e2e:
@echo "test-e2e starting..." >&2
@echo "Waiting for infra-server to be ready..." >&2
@kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m >&2 || \
(echo "ERROR: infra-server pods did not become ready" >&2 && exit 1)
@echo "Starting port-forward and running E2E tests..." >&2
@kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 & \
PF_PID=$$!; \
cleanup() { \
echo "" >&2; \
echo "Cleaning up port-forward (PID: $$PF_PID)..." >&2; \
kill $$PF_PID 2>/dev/null || true; \
}; \
trap cleanup EXIT; \
sleep 5; \
echo "Running Cypress E2E tests..." >&2; \
cd ui && BROWSER=none PORT=3001 INFRA_API_ENDPOINT=http://localhost:8443 npm run test:e2e

## Bounce pods
.PHONY: bounce-infra-pods
bounce-infra-pods:
Expand Down
30 changes: 30 additions & 0 deletions chart/infra-server/configuration/local-values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
environment: local

# Set local deploy mode to true for local development
localDeploy: true

# Enable test mode for faster cluster resume intervals
testMode: true

# Use local Docker images when available, pull from registry if not present
# Works with Colima (shared Docker daemon) and kind (after kind load docker-image)
# IfNotPresent provides flexibility: uses local images when available, pulls when needed
imagePullPolicy: IfNotPresent

# Pull secrets for container registries - dummy values for local development
pullSecrets:
docker:
registry: "docker.io"
username: "dummy"
password: "dummy"
quay:
registry: "quay.io"
username: "dummy"
password: "dummy"
stackrox:
registry: "stackrox.io"
username: "dummy"
password: "dummy"

# Alertmanager configuration
alertmanagerSlackTeam: "dummy-team"
2 changes: 2 additions & 0 deletions chart/infra-server/templates/argo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -7,3 +8,4 @@ metadata:
data:
credentials.json: |-
{{ required ".Values.google_credentials_json is undefined" .Values.google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aro/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -16,3 +17,4 @@ data:
{{ .Values.aroClusterManager.azureSPSecretVal | b64enc }}
REDHAT_PULL_SECRET_BASE64: |-
{{ .Values.aroClusterManager.redHatPullSecretBase64 | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aws/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -10,3 +11,4 @@ data:
{{ .Values.aws.accessKeyId | b64enc }}
AWS_SECRET_ACCESS_KEY: |-
{{ .Values.aws.secretAccessKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/azure/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}

---

Expand All@@ -18,3 +19,4 @@ data:
{{ .Values.azure.sp_tenant | b64enc }}
ACR_TO_ATTACH: |-
{{ .Values.azure.aks_attached_acr | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/demo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand DownExpand Up@@ -90,3 +91,4 @@ data:
.dockerconfigjson: {{ template "pull-secret" .Values.pullSecrets.quay }}

---
{{- end }}
4 changes: 3 additions & 1 deletion chart/infra-server/templates/deployment.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,8 +27,10 @@ spec:
- name: infra-server
image: quay.io/rhacs-eng/infra-server:{{ required "A valid .Values.tag entry is required!" .Values.tag }}
env:
{{- if not .Values.localDeploy }}
- name: GOOGLE_APPLICATION_CREDENTIALS
value: /configuration/google-credentials.json
{{- end }}
- name: TEST_MODE
value: "{{ .Values.testMode }}"
readinessProbe:
Expand All@@ -47,7 +49,7 @@ spec:
containerPort: 8443
- name: metrics
containerPort: 9101
imagePullPolicy: Always
imagePullPolicy: {{ .Values.imagePullPolicy | default "Always" }}
volumeMounts:
- mountPath: /configuration
name: configuration
Expand Down
2 changes: 2 additions & 0 deletions chart/infra-server/templates/gke/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand All@@ -13,3 +14,4 @@ data:
{{ required ".Values.gke__gke_provisioner_json is undefined" .Values.gke__gke_provisioner_json }}

---
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/ibm/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -8,3 +9,4 @@ metadata:
data:
IBM_ROKS_API_KEY: |-
{{ .Values.ibmCloudSecrets.ibmRoksApiKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/monitoring/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -6,3 +7,4 @@ metadata:
namespace: monitoring
data:
webhookURL: "{{ .Values.alertmanagerSlackWebhook | b64enc }}"
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift-4/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand DownExpand Up@@ -43,3 +44,4 @@ metadata:
data:
REDHAT_PULL_SECRET: |-
{{ required ".Values.openshift_4__redhat_pull_secret_json is undefined" .Values.openshift_4__redhat_pull_secret_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand All@@ -9,3 +10,4 @@ metadata:
data:
google-credentials.json: |-
{{ required ".Values.openshift__google_credentials_json is undefined" .Values.openshift__google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/osd/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -19,3 +20,4 @@ data:
{{ .Values.osdClusterManager.gcpSaCredsJsonBase64 | b64enc }}
GCP_SERVICE_ACCOUNT_KEY_BASE64: |-
{{ .Values.osdClusterManager.gcpServiceAccountKeyBase64 | b64enc }}
{{- end }}
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
128 changes: 128 additions & 0 deletions .github/workflows/ui.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,128 @@
name: UI tests

on:
pull_request:
push:
branches:
- master

jobs:
ui-e2e-tests:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0

- name: Free disk space (delete unused tools)
id: delete-unused-tools
continue-on-error: true
shell: bash
run: |
free_disk_space=22
# delete preinstalled unused tools
cleanup=(
/usr/share/dotnet
/usr/share/miniconda
/usr/share/swift
/usr/share/kotlinc
/opt/ghc
/opt/hostedtoolcache/CodeQL
/opt/hostedtoolcache/Ruby
/opt/az
/usr/local/lib/android
)
for d in "${cleanup[@]}"; do
if [[ -d "$d" ]]; then
rm -rf -- "$d" && echo "deleted $d"
else
echo "$d not found"
continue
fi
free=$(df -BGB --output=avail / | tail -1)
if [[ ${free%GB} -ge "${free_disk_space}" ]]; then
echo "Reached requested free disk space ${free_disk_space} [${free} free]."
exit 0
fi
done
df -h

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Create KinD Cluster
uses: helm/kind-action@v1
with:
cluster_name: kind

- name: tags
run: |
echo "TAG=$(make tag)" | tee -a "$GITHUB_ENV"

- name: Build Docker image
uses: docker/build-push-action@v5
with:
file: image/Dockerfile
context: .
push: false
load: true
tags: quay.io/rhacs-eng/infra-server:${{ env.TAG }}
cache-from: type=gha
cache-to: type=gha,mode=max

- name: Load into KinD
run: |
# Check cluster name
kind get clusters
#docker build -t quay.io/rhacs-eng/infra-server:${{ env.TAG }} -f image/Dockerfile .
kind load docker-image quay.io/rhacs-eng/infra-server:${{ env.TAG }} --name kind
docker images | grep infra-server

- name: Deploy
run: make deploy-local

- name: Wait for pods
run: kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m

- name: Start port-forward
run: |
kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 &
echo "PORT_FORWARD_PID=$!" >> "$GITHUB_ENV"
sleep 5
# Verify port-forward is working
timeout 10 sh -c 'until curl -k -f https://localhost:8443/v1/whoami 2>/dev/null; do sleep 1; done' || echo "Warning: Backend may not be ready"

- name: Run E2E tests
uses: cypress-io/github-action@v6
with:
working-directory: ui
start: npm run start
wait-on: 'http://localhost:3001'
wait-on-timeout: 60
command: npm run cypress:run:e2e
env:
BROWSER: none
PORT: 3001
# Backend uses HTTPS with self-signed cert (see scripts/deploy/helm.sh)
INFRA_API_ENDPOINT: https://localhost:8443

- name: Upload test artifacts
if: failure()
uses: actions/upload-artifact@v4
with:
name: cypress-artifacts
path: |
ui/cypress/videos
ui/cypress/screenshots
retention-days: 7

- name: Cleanup port-forward
if: always()
run: |
# Kill by PID if available, otherwise kill by process name
if [ -n "${{ env.PORT_FORWARD_PID }}" ]; then
echo "Cleaning up port-forward (PID: ${{ env.PORT_FORWARD_PID }})..."
kill ${{ env.PORT_FORWARD_PID }} 2>/dev/null || true
fi
# Fallback: kill any remaining port-forward processes
pkill -f "kubectl port-forward.*8443:8443" 2>/dev/null || true
6 changes: 6 additions & 0 deletions DEPLOYMENT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -116,6 +116,12 @@ Use the environment variable `TEST_MODE` to disable certain infra service behavi

This is used in the infra PR clusters to set the login referer and disable telemetry.

#### Deployments for testing only (no secrets)

For test clusters (such as a local KinD/Colima), you can use the deploy-local make target to skip loading secrets. The flavor provisioning actions that require secrets will not be accessible, and integrations such as with Slack will be disabled.

`make deploy-local`

### Rollback

Use `helm rollback infra-server <REVISION>`.
Expand Down
25 changes: 25 additions & 0 deletions Makefile
Original file line numberDiff line numberDiff line change
Expand Up@@ -253,6 +253,31 @@ helm-deploy: pre-check helm-dependency-update create-namespaces
helm-diff: pre-check helm-dependency-update create-namespaces
@./scripts/deploy/helm.sh diff $(VERSION) $(ENVIRONMENT) $(SECRET_VERSION)

## Deploy to local cluster (e.g., Colima) without GCP Secret Manager
.PHONY: deploy-local
deploy-local: helm-dependency-update create-namespaces
TEST_MODE=true ./scripts/deploy/helm.sh deploy-local $(shell make tag) local

## Run UI E2E tests against local deployment
.PHONY: test-e2e
test-e2e:
@echo "test-e2e starting..." >&2
@echo "Waiting for infra-server to be ready..." >&2
@kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m >&2 || \
(echo "ERROR: infra-server pods did not become ready" >&2 && exit 1)
@echo "Starting port-forward and running E2E tests..." >&2
@kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 & \
PF_PID=$$!; \
cleanup() { \
echo "" >&2; \
echo "Cleaning up port-forward (PID: $$PF_PID)..." >&2; \
kill $$PF_PID 2>/dev/null || true; \
}; \
trap cleanup EXIT; \
sleep 5; \
echo "Running Cypress E2E tests..." >&2; \
cd ui && BROWSER=none PORT=3001 INFRA_API_ENDPOINT=http://localhost:8443 npm run test:e2e

## Bounce pods
.PHONY: bounce-infra-pods
bounce-infra-pods:
Expand Down
30 changes: 30 additions & 0 deletions chart/infra-server/configuration/local-values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
environment: local

# Set local deploy mode to true for local development
localDeploy: true

# Enable test mode for faster cluster resume intervals
testMode: true

# Use local Docker images when available, pull from registry if not present
# Works with Colima (shared Docker daemon) and kind (after kind load docker-image)
# IfNotPresent provides flexibility: uses local images when available, pulls when needed
imagePullPolicy: IfNotPresent

# Pull secrets for container registries - dummy values for local development
pullSecrets:
docker:
registry: "docker.io"
username: "dummy"
password: "dummy"
quay:
registry: "quay.io"
username: "dummy"
password: "dummy"
stackrox:
registry: "stackrox.io"
username: "dummy"
password: "dummy"

# Alertmanager configuration
alertmanagerSlackTeam: "dummy-team"
2 changes: 2 additions & 0 deletions chart/infra-server/templates/argo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -7,3 +8,4 @@ metadata:
data:
credentials.json: |-
{{ required ".Values.google_credentials_json is undefined" .Values.google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aro/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -16,3 +17,4 @@ data:
{{ .Values.aroClusterManager.azureSPSecretVal | b64enc }}
REDHAT_PULL_SECRET_BASE64: |-
{{ .Values.aroClusterManager.redHatPullSecretBase64 | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aws/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -10,3 +11,4 @@ data:
{{ .Values.aws.accessKeyId | b64enc }}
AWS_SECRET_ACCESS_KEY: |-
{{ .Values.aws.secretAccessKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/azure/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}

---

Expand All@@ -18,3 +19,4 @@ data:
{{ .Values.azure.sp_tenant | b64enc }}
ACR_TO_ATTACH: |-
{{ .Values.azure.aks_attached_acr | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/demo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand DownExpand Up@@ -90,3 +91,4 @@ data:
.dockerconfigjson: {{ template "pull-secret" .Values.pullSecrets.quay }}

---
{{- end }}
4 changes: 3 additions & 1 deletion chart/infra-server/templates/deployment.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,8 +27,10 @@ spec:
- name: infra-server
image: quay.io/rhacs-eng/infra-server:{{ required "A valid .Values.tag entry is required!" .Values.tag }}
env:
{{- if not .Values.localDeploy }}
- name: GOOGLE_APPLICATION_CREDENTIALS
value: /configuration/google-credentials.json
{{- end }}
- name: TEST_MODE
value: "{{ .Values.testMode }}"
readinessProbe:
Expand All@@ -47,7 +49,7 @@ spec:
containerPort: 8443
- name: metrics
containerPort: 9101
imagePullPolicy: Always
imagePullPolicy: {{ .Values.imagePullPolicy | default "Always" }}
volumeMounts:
- mountPath: /configuration
name: configuration
Expand Down
2 changes: 2 additions & 0 deletions chart/infra-server/templates/gke/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand All@@ -13,3 +14,4 @@ data:
{{ required ".Values.gke__gke_provisioner_json is undefined" .Values.gke__gke_provisioner_json }}

---
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/ibm/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -8,3 +9,4 @@ metadata:
data:
IBM_ROKS_API_KEY: |-
{{ .Values.ibmCloudSecrets.ibmRoksApiKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/monitoring/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -6,3 +7,4 @@ metadata:
namespace: monitoring
data:
webhookURL: "{{ .Values.alertmanagerSlackWebhook | b64enc }}"
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift-4/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand DownExpand Up@@ -43,3 +44,4 @@ metadata:
data:
REDHAT_PULL_SECRET: |-
{{ required ".Values.openshift_4__redhat_pull_secret_json is undefined" .Values.openshift_4__redhat_pull_secret_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand All@@ -9,3 +10,4 @@ metadata:
data:
google-credentials.json: |-
{{ required ".Values.openshift__google_credentials_json is undefined" .Values.openshift__google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/osd/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -19,3 +20,4 @@ data:
{{ .Values.osdClusterManager.gcpSaCredsJsonBase64 | b64enc }}
GCP_SERVICE_ACCOUNT_KEY_BASE64: |-
{{ .Values.osdClusterManager.gcpServiceAccountKeyBase64 | b64enc }}
{{- end }}
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
128 changes: 128 additions & 0 deletions .github/workflows/ui.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,128 @@
name: UI tests

on:
pull_request:
push:
branches:
- master

jobs:
ui-e2e-tests:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0

- name: Free disk space (delete unused tools)
id: delete-unused-tools
continue-on-error: true
shell: bash
run: |
free_disk_space=22
# delete preinstalled unused tools
cleanup=(
/usr/share/dotnet
/usr/share/miniconda
/usr/share/swift
/usr/share/kotlinc
/opt/ghc
/opt/hostedtoolcache/CodeQL
/opt/hostedtoolcache/Ruby
/opt/az
/usr/local/lib/android
)
for d in "${cleanup[@]}"; do
if [[ -d "$d" ]]; then
rm -rf -- "$d" && echo "deleted $d"
else
echo "$d not found"
continue
fi
free=$(df -BGB --output=avail / | tail -1)
if [[ ${free%GB} -ge "${free_disk_space}" ]]; then
echo "Reached requested free disk space ${free_disk_space} [${free} free]."
exit 0
fi
done
df -h

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Create KinD Cluster
uses: helm/kind-action@v1
with:
cluster_name: kind

- name: tags
run: |
echo "TAG=$(make tag)" | tee -a "$GITHUB_ENV"

- name: Build Docker image
uses: docker/build-push-action@v5
with:
file: image/Dockerfile
context: .
push: false
load: true
tags: quay.io/rhacs-eng/infra-server:${{ env.TAG }}
cache-from: type=gha
cache-to: type=gha,mode=max

- name: Load into KinD
run: |
# Check cluster name
kind get clusters
#docker build -t quay.io/rhacs-eng/infra-server:${{ env.TAG }} -f image/Dockerfile .
kind load docker-image quay.io/rhacs-eng/infra-server:${{ env.TAG }} --name kind
docker images | grep infra-server

- name: Deploy
run: make deploy-local

- name: Wait for pods
run: kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m

- name: Start port-forward
run: |
kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 &
echo "PORT_FORWARD_PID=$!" >> "$GITHUB_ENV"
sleep 5
# Verify port-forward is working
timeout 10 sh -c 'until curl -k -f https://localhost:8443/v1/whoami 2>/dev/null; do sleep 1; done' || echo "Warning: Backend may not be ready"

- name: Run E2E tests
uses: cypress-io/github-action@v6
with:
working-directory: ui
start: npm run start
wait-on: 'http://localhost:3001'
wait-on-timeout: 60
command: npm run cypress:run:e2e
env:
BROWSER: none
PORT: 3001
# Backend uses HTTPS with self-signed cert (see scripts/deploy/helm.sh)
INFRA_API_ENDPOINT: https://localhost:8443

- name: Upload test artifacts
if: failure()
uses: actions/upload-artifact@v4
with:
name: cypress-artifacts
path: |
ui/cypress/videos
ui/cypress/screenshots
retention-days: 7

- name: Cleanup port-forward
if: always()
run: |
# Kill by PID if available, otherwise kill by process name
if [ -n "${{ env.PORT_FORWARD_PID }}" ]; then
echo "Cleaning up port-forward (PID: ${{ env.PORT_FORWARD_PID }})..."
kill ${{ env.PORT_FORWARD_PID }} 2>/dev/null || true
fi
# Fallback: kill any remaining port-forward processes
pkill -f "kubectl port-forward.*8443:8443" 2>/dev/null || true
6 changes: 6 additions & 0 deletions DEPLOYMENT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -116,6 +116,12 @@ Use the environment variable `TEST_MODE` to disable certain infra service behavi

This is used in the infra PR clusters to set the login referer and disable telemetry.

#### Deployments for testing only (no secrets)

For test clusters (such as a local KinD/Colima), you can use the deploy-local make target to skip loading secrets. The flavor provisioning actions that require secrets will not be accessible, and integrations such as with Slack will be disabled.

`make deploy-local`

### Rollback

Use `helm rollback infra-server <REVISION>`.
Expand Down
25 changes: 25 additions & 0 deletions Makefile
Original file line numberDiff line numberDiff line change
Expand Up@@ -253,6 +253,31 @@ helm-deploy: pre-check helm-dependency-update create-namespaces
helm-diff: pre-check helm-dependency-update create-namespaces
@./scripts/deploy/helm.sh diff $(VERSION) $(ENVIRONMENT) $(SECRET_VERSION)

## Deploy to local cluster (e.g., Colima) without GCP Secret Manager
.PHONY: deploy-local
deploy-local: helm-dependency-update create-namespaces
TEST_MODE=true ./scripts/deploy/helm.sh deploy-local $(shell make tag) local

## Run UI E2E tests against local deployment
.PHONY: test-e2e
test-e2e:
@echo "test-e2e starting..." >&2
@echo "Waiting for infra-server to be ready..." >&2
@kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m >&2 || \
(echo "ERROR: infra-server pods did not become ready" >&2 && exit 1)
@echo "Starting port-forward and running E2E tests..." >&2
@kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 & \
PF_PID=$$!; \
cleanup() { \
echo "" >&2; \
echo "Cleaning up port-forward (PID: $$PF_PID)..." >&2; \
kill $$PF_PID 2>/dev/null || true; \
}; \
trap cleanup EXIT; \
sleep 5; \
echo "Running Cypress E2E tests..." >&2; \
cd ui && BROWSER=none PORT=3001 INFRA_API_ENDPOINT=http://localhost:8443 npm run test:e2e

## Bounce pods
.PHONY: bounce-infra-pods
bounce-infra-pods:
Expand Down
30 changes: 30 additions & 0 deletions chart/infra-server/configuration/local-values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
environment: local

# Set local deploy mode to true for local development
localDeploy: true

# Enable test mode for faster cluster resume intervals
testMode: true

# Use local Docker images when available, pull from registry if not present
# Works with Colima (shared Docker daemon) and kind (after kind load docker-image)
# IfNotPresent provides flexibility: uses local images when available, pulls when needed
imagePullPolicy: IfNotPresent

# Pull secrets for container registries - dummy values for local development
pullSecrets:
docker:
registry: "docker.io"
username: "dummy"
password: "dummy"
quay:
registry: "quay.io"
username: "dummy"
password: "dummy"
stackrox:
registry: "stackrox.io"
username: "dummy"
password: "dummy"

# Alertmanager configuration
alertmanagerSlackTeam: "dummy-team"
2 changes: 2 additions & 0 deletions chart/infra-server/templates/argo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -7,3 +8,4 @@ metadata:
data:
credentials.json: |-
{{ required ".Values.google_credentials_json is undefined" .Values.google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aro/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -16,3 +17,4 @@ data:
{{ .Values.aroClusterManager.azureSPSecretVal | b64enc }}
REDHAT_PULL_SECRET_BASE64: |-
{{ .Values.aroClusterManager.redHatPullSecretBase64 | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aws/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -10,3 +11,4 @@ data:
{{ .Values.aws.accessKeyId | b64enc }}
AWS_SECRET_ACCESS_KEY: |-
{{ .Values.aws.secretAccessKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/azure/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}

---

Expand All@@ -18,3 +19,4 @@ data:
{{ .Values.azure.sp_tenant | b64enc }}
ACR_TO_ATTACH: |-
{{ .Values.azure.aks_attached_acr | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/demo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand DownExpand Up@@ -90,3 +91,4 @@ data:
.dockerconfigjson: {{ template "pull-secret" .Values.pullSecrets.quay }}

---
{{- end }}
4 changes: 3 additions & 1 deletion chart/infra-server/templates/deployment.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,8 +27,10 @@ spec:
- name: infra-server
image: quay.io/rhacs-eng/infra-server:{{ required "A valid .Values.tag entry is required!" .Values.tag }}
env:
{{- if not .Values.localDeploy }}
- name: GOOGLE_APPLICATION_CREDENTIALS
value: /configuration/google-credentials.json
{{- end }}
- name: TEST_MODE
value: "{{ .Values.testMode }}"
readinessProbe:
Expand All@@ -47,7 +49,7 @@ spec:
containerPort: 8443
- name: metrics
containerPort: 9101
imagePullPolicy: Always
imagePullPolicy: {{ .Values.imagePullPolicy | default "Always" }}
volumeMounts:
- mountPath: /configuration
name: configuration
Expand Down
2 changes: 2 additions & 0 deletions chart/infra-server/templates/gke/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand All@@ -13,3 +14,4 @@ data:
{{ required ".Values.gke__gke_provisioner_json is undefined" .Values.gke__gke_provisioner_json }}

---
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/ibm/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -8,3 +9,4 @@ metadata:
data:
IBM_ROKS_API_KEY: |-
{{ .Values.ibmCloudSecrets.ibmRoksApiKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/monitoring/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -6,3 +7,4 @@ metadata:
namespace: monitoring
data:
webhookURL: "{{ .Values.alertmanagerSlackWebhook | b64enc }}"
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift-4/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand DownExpand Up@@ -43,3 +44,4 @@ metadata:
data:
REDHAT_PULL_SECRET: |-
{{ required ".Values.openshift_4__redhat_pull_secret_json is undefined" .Values.openshift_4__redhat_pull_secret_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand All@@ -9,3 +10,4 @@ metadata:
data:
google-credentials.json: |-
{{ required ".Values.openshift__google_credentials_json is undefined" .Values.openshift__google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/osd/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -19,3 +20,4 @@ data:
{{ .Values.osdClusterManager.gcpSaCredsJsonBase64 | b64enc }}
GCP_SERVICE_ACCOUNT_KEY_BASE64: |-
{{ .Values.osdClusterManager.gcpServiceAccountKeyBase64 | b64enc }}
{{- end }}
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
128 changes: 128 additions & 0 deletions .github/workflows/ui.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,128 @@
name: UI tests

on:
pull_request:
push:
branches:
- master

jobs:
ui-e2e-tests:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0

- name: Free disk space (delete unused tools)
id: delete-unused-tools
continue-on-error: true
shell: bash
run: |
free_disk_space=22
# delete preinstalled unused tools
cleanup=(
/usr/share/dotnet
/usr/share/miniconda
/usr/share/swift
/usr/share/kotlinc
/opt/ghc
/opt/hostedtoolcache/CodeQL
/opt/hostedtoolcache/Ruby
/opt/az
/usr/local/lib/android
)
for d in "${cleanup[@]}"; do
if [[ -d "$d" ]]; then
rm -rf -- "$d" && echo "deleted $d"
else
echo "$d not found"
continue
fi
free=$(df -BGB --output=avail / | tail -1)
if [[ ${free%GB} -ge "${free_disk_space}" ]]; then
echo "Reached requested free disk space ${free_disk_space} [${free} free]."
exit 0
fi
done
df -h

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Create KinD Cluster
uses: helm/kind-action@v1
with:
cluster_name: kind

- name: tags
run: |
echo "TAG=$(make tag)" | tee -a "$GITHUB_ENV"

- name: Build Docker image
uses: docker/build-push-action@v5
with:
file: image/Dockerfile
context: .
push: false
load: true
tags: quay.io/rhacs-eng/infra-server:${{ env.TAG }}
cache-from: type=gha
cache-to: type=gha,mode=max

- name: Load into KinD
run: |
# Check cluster name
kind get clusters
#docker build -t quay.io/rhacs-eng/infra-server:${{ env.TAG }} -f image/Dockerfile .
kind load docker-image quay.io/rhacs-eng/infra-server:${{ env.TAG }} --name kind
docker images | grep infra-server

- name: Deploy
run: make deploy-local

- name: Wait for pods
run: kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m

- name: Start port-forward
run: |
kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 &
echo "PORT_FORWARD_PID=$!" >> "$GITHUB_ENV"
sleep 5
# Verify port-forward is working
timeout 10 sh -c 'until curl -k -f https://localhost:8443/v1/whoami 2>/dev/null; do sleep 1; done' || echo "Warning: Backend may not be ready"

- name: Run E2E tests
uses: cypress-io/github-action@v6
with:
working-directory: ui
start: npm run start
wait-on: 'http://localhost:3001'
wait-on-timeout: 60
command: npm run cypress:run:e2e
env:
BROWSER: none
PORT: 3001
# Backend uses HTTPS with self-signed cert (see scripts/deploy/helm.sh)
INFRA_API_ENDPOINT: https://localhost:8443

- name: Upload test artifacts
if: failure()
uses: actions/upload-artifact@v4
with:
name: cypress-artifacts
path: |
ui/cypress/videos
ui/cypress/screenshots
retention-days: 7

- name: Cleanup port-forward
if: always()
run: |
# Kill by PID if available, otherwise kill by process name
if [ -n "${{ env.PORT_FORWARD_PID }}" ]; then
echo "Cleaning up port-forward (PID: ${{ env.PORT_FORWARD_PID }})..."
kill ${{ env.PORT_FORWARD_PID }} 2>/dev/null || true
fi
# Fallback: kill any remaining port-forward processes
pkill -f "kubectl port-forward.*8443:8443" 2>/dev/null || true
6 changes: 6 additions & 0 deletions DEPLOYMENT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -116,6 +116,12 @@ Use the environment variable `TEST_MODE` to disable certain infra service behavi

This is used in the infra PR clusters to set the login referer and disable telemetry.

#### Deployments for testing only (no secrets)

For test clusters (such as a local KinD/Colima), you can use the deploy-local make target to skip loading secrets. The flavor provisioning actions that require secrets will not be accessible, and integrations such as with Slack will be disabled.

`make deploy-local`

### Rollback

Use `helm rollback infra-server <REVISION>`.
Expand Down
25 changes: 25 additions & 0 deletions Makefile
Original file line numberDiff line numberDiff line change
Expand Up@@ -253,6 +253,31 @@ helm-deploy: pre-check helm-dependency-update create-namespaces
helm-diff: pre-check helm-dependency-update create-namespaces
@./scripts/deploy/helm.sh diff $(VERSION) $(ENVIRONMENT) $(SECRET_VERSION)

## Deploy to local cluster (e.g., Colima) without GCP Secret Manager
.PHONY: deploy-local
deploy-local: helm-dependency-update create-namespaces
TEST_MODE=true ./scripts/deploy/helm.sh deploy-local $(shell make tag) local

## Run UI E2E tests against local deployment
.PHONY: test-e2e
test-e2e:
@echo "test-e2e starting..." >&2
@echo "Waiting for infra-server to be ready..." >&2
@kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m >&2 || \
(echo "ERROR: infra-server pods did not become ready" >&2 && exit 1)
@echo "Starting port-forward and running E2E tests..." >&2
@kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 & \
PF_PID=$$!; \
cleanup() { \
echo "" >&2; \
echo "Cleaning up port-forward (PID: $$PF_PID)..." >&2; \
kill $$PF_PID 2>/dev/null || true; \
}; \
trap cleanup EXIT; \
sleep 5; \
echo "Running Cypress E2E tests..." >&2; \
cd ui && BROWSER=none PORT=3001 INFRA_API_ENDPOINT=http://localhost:8443 npm run test:e2e

## Bounce pods
.PHONY: bounce-infra-pods
bounce-infra-pods:
Expand Down
30 changes: 30 additions & 0 deletions chart/infra-server/configuration/local-values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
environment: local

# Set local deploy mode to true for local development
localDeploy: true

# Enable test mode for faster cluster resume intervals
testMode: true

# Use local Docker images when available, pull from registry if not present
# Works with Colima (shared Docker daemon) and kind (after kind load docker-image)
# IfNotPresent provides flexibility: uses local images when available, pulls when needed
imagePullPolicy: IfNotPresent

# Pull secrets for container registries - dummy values for local development
pullSecrets:
docker:
registry: "docker.io"
username: "dummy"
password: "dummy"
quay:
registry: "quay.io"
username: "dummy"
password: "dummy"
stackrox:
registry: "stackrox.io"
username: "dummy"
password: "dummy"

# Alertmanager configuration
alertmanagerSlackTeam: "dummy-team"
2 changes: 2 additions & 0 deletions chart/infra-server/templates/argo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -7,3 +8,4 @@ metadata:
data:
credentials.json: |-
{{ required ".Values.google_credentials_json is undefined" .Values.google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aro/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -16,3 +17,4 @@ data:
{{ .Values.aroClusterManager.azureSPSecretVal | b64enc }}
REDHAT_PULL_SECRET_BASE64: |-
{{ .Values.aroClusterManager.redHatPullSecretBase64 | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aws/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -10,3 +11,4 @@ data:
{{ .Values.aws.accessKeyId | b64enc }}
AWS_SECRET_ACCESS_KEY: |-
{{ .Values.aws.secretAccessKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/azure/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}

---

Expand All@@ -18,3 +19,4 @@ data:
{{ .Values.azure.sp_tenant | b64enc }}
ACR_TO_ATTACH: |-
{{ .Values.azure.aks_attached_acr | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/demo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand DownExpand Up@@ -90,3 +91,4 @@ data:
.dockerconfigjson: {{ template "pull-secret" .Values.pullSecrets.quay }}

---
{{- end }}
4 changes: 3 additions & 1 deletion chart/infra-server/templates/deployment.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,8 +27,10 @@ spec:
- name: infra-server
image: quay.io/rhacs-eng/infra-server:{{ required "A valid .Values.tag entry is required!" .Values.tag }}
env:
{{- if not .Values.localDeploy }}
- name: GOOGLE_APPLICATION_CREDENTIALS
value: /configuration/google-credentials.json
{{- end }}
- name: TEST_MODE
value: "{{ .Values.testMode }}"
readinessProbe:
Expand All@@ -47,7 +49,7 @@ spec:
containerPort: 8443
- name: metrics
containerPort: 9101
imagePullPolicy: Always
imagePullPolicy: {{ .Values.imagePullPolicy | default "Always" }}
volumeMounts:
- mountPath: /configuration
name: configuration
Expand Down
2 changes: 2 additions & 0 deletions chart/infra-server/templates/gke/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand All@@ -13,3 +14,4 @@ data:
{{ required ".Values.gke__gke_provisioner_json is undefined" .Values.gke__gke_provisioner_json }}

---
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/ibm/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -8,3 +9,4 @@ metadata:
data:
IBM_ROKS_API_KEY: |-
{{ .Values.ibmCloudSecrets.ibmRoksApiKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/monitoring/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -6,3 +7,4 @@ metadata:
namespace: monitoring
data:
webhookURL: "{{ .Values.alertmanagerSlackWebhook | b64enc }}"
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift-4/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand DownExpand Up@@ -43,3 +44,4 @@ metadata:
data:
REDHAT_PULL_SECRET: |-
{{ required ".Values.openshift_4__redhat_pull_secret_json is undefined" .Values.openshift_4__redhat_pull_secret_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand All@@ -9,3 +10,4 @@ metadata:
data:
google-credentials.json: |-
{{ required ".Values.openshift__google_credentials_json is undefined" .Values.openshift__google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/osd/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -19,3 +20,4 @@ data:
{{ .Values.osdClusterManager.gcpSaCredsJsonBase64 | b64enc }}
GCP_SERVICE_ACCOUNT_KEY_BASE64: |-
{{ .Values.osdClusterManager.gcpServiceAccountKeyBase64 | b64enc }}
{{- end }}
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
128 changes: 128 additions & 0 deletions .github/workflows/ui.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,128 @@
name: UI tests

on:
pull_request:
push:
branches:
- master

jobs:
ui-e2e-tests:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0

- name: Free disk space (delete unused tools)
id: delete-unused-tools
continue-on-error: true
shell: bash
run: |
free_disk_space=22
# delete preinstalled unused tools
cleanup=(
/usr/share/dotnet
/usr/share/miniconda
/usr/share/swift
/usr/share/kotlinc
/opt/ghc
/opt/hostedtoolcache/CodeQL
/opt/hostedtoolcache/Ruby
/opt/az
/usr/local/lib/android
)
for d in "${cleanup[@]}"; do
if [[ -d "$d" ]]; then
rm -rf -- "$d" && echo "deleted $d"
else
echo "$d not found"
continue
fi
free=$(df -BGB --output=avail / | tail -1)
if [[ ${free%GB} -ge "${free_disk_space}" ]]; then
echo "Reached requested free disk space ${free_disk_space} [${free} free]."
exit 0
fi
done
df -h

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Create KinD Cluster
uses: helm/kind-action@v1
with:
cluster_name: kind

- name: tags
run: |
echo "TAG=$(make tag)" | tee -a "$GITHUB_ENV"

- name: Build Docker image
uses: docker/build-push-action@v5
with:
file: image/Dockerfile
context: .
push: false
load: true
tags: quay.io/rhacs-eng/infra-server:${{ env.TAG }}
cache-from: type=gha
cache-to: type=gha,mode=max

- name: Load into KinD
run: |
# Check cluster name
kind get clusters
#docker build -t quay.io/rhacs-eng/infra-server:${{ env.TAG }} -f image/Dockerfile .
kind load docker-image quay.io/rhacs-eng/infra-server:${{ env.TAG }} --name kind
docker images | grep infra-server

- name: Deploy
run: make deploy-local

- name: Wait for pods
run: kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m

- name: Start port-forward
run: |
kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 &
echo "PORT_FORWARD_PID=$!" >> "$GITHUB_ENV"
sleep 5
# Verify port-forward is working
timeout 10 sh -c 'until curl -k -f https://localhost:8443/v1/whoami 2>/dev/null; do sleep 1; done' || echo "Warning: Backend may not be ready"

- name: Run E2E tests
uses: cypress-io/github-action@v6
with:
working-directory: ui
start: npm run start
wait-on: 'http://localhost:3001'
wait-on-timeout: 60
command: npm run cypress:run:e2e
env:
BROWSER: none
PORT: 3001
# Backend uses HTTPS with self-signed cert (see scripts/deploy/helm.sh)
INFRA_API_ENDPOINT: https://localhost:8443

- name: Upload test artifacts
if: failure()
uses: actions/upload-artifact@v4
with:
name: cypress-artifacts
path: |
ui/cypress/videos
ui/cypress/screenshots
retention-days: 7

- name: Cleanup port-forward
if: always()
run: |
# Kill by PID if available, otherwise kill by process name
if [ -n "${{ env.PORT_FORWARD_PID }}" ]; then
echo "Cleaning up port-forward (PID: ${{ env.PORT_FORWARD_PID }})..."
kill ${{ env.PORT_FORWARD_PID }} 2>/dev/null || true
fi
# Fallback: kill any remaining port-forward processes
pkill -f "kubectl port-forward.*8443:8443" 2>/dev/null || true
6 changes: 6 additions & 0 deletions DEPLOYMENT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -116,6 +116,12 @@ Use the environment variable `TEST_MODE` to disable certain infra service behavi

This is used in the infra PR clusters to set the login referer and disable telemetry.

#### Deployments for testing only (no secrets)

For test clusters (such as a local KinD/Colima), you can use the deploy-local make target to skip loading secrets. The flavor provisioning actions that require secrets will not be accessible, and integrations such as with Slack will be disabled.

`make deploy-local`

### Rollback

Use `helm rollback infra-server <REVISION>`.
Expand Down
25 changes: 25 additions & 0 deletions Makefile
Original file line numberDiff line numberDiff line change
Expand Up@@ -253,6 +253,31 @@ helm-deploy: pre-check helm-dependency-update create-namespaces
helm-diff: pre-check helm-dependency-update create-namespaces
@./scripts/deploy/helm.sh diff $(VERSION) $(ENVIRONMENT) $(SECRET_VERSION)

## Deploy to local cluster (e.g., Colima) without GCP Secret Manager
.PHONY: deploy-local
deploy-local: helm-dependency-update create-namespaces
TEST_MODE=true ./scripts/deploy/helm.sh deploy-local $(shell make tag) local

## Run UI E2E tests against local deployment
.PHONY: test-e2e
test-e2e:
@echo "test-e2e starting..." >&2
@echo "Waiting for infra-server to be ready..." >&2
@kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m >&2 || \
(echo "ERROR: infra-server pods did not become ready" >&2 && exit 1)
@echo "Starting port-forward and running E2E tests..." >&2
@kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 & \
PF_PID=$$!; \
cleanup() { \
echo "" >&2; \
echo "Cleaning up port-forward (PID: $$PF_PID)..." >&2; \
kill $$PF_PID 2>/dev/null || true; \
}; \
trap cleanup EXIT; \
sleep 5; \
echo "Running Cypress E2E tests..." >&2; \
cd ui && BROWSER=none PORT=3001 INFRA_API_ENDPOINT=http://localhost:8443 npm run test:e2e

## Bounce pods
.PHONY: bounce-infra-pods
bounce-infra-pods:
Expand Down
30 changes: 30 additions & 0 deletions chart/infra-server/configuration/local-values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
environment: local

# Set local deploy mode to true for local development
localDeploy: true

# Enable test mode for faster cluster resume intervals
testMode: true

# Use local Docker images when available, pull from registry if not present
# Works with Colima (shared Docker daemon) and kind (after kind load docker-image)
# IfNotPresent provides flexibility: uses local images when available, pulls when needed
imagePullPolicy: IfNotPresent

# Pull secrets for container registries - dummy values for local development
pullSecrets:
docker:
registry: "docker.io"
username: "dummy"
password: "dummy"
quay:
registry: "quay.io"
username: "dummy"
password: "dummy"
stackrox:
registry: "stackrox.io"
username: "dummy"
password: "dummy"

# Alertmanager configuration
alertmanagerSlackTeam: "dummy-team"
2 changes: 2 additions & 0 deletions chart/infra-server/templates/argo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -7,3 +8,4 @@ metadata:
data:
credentials.json: |-
{{ required ".Values.google_credentials_json is undefined" .Values.google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aro/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -16,3 +17,4 @@ data:
{{ .Values.aroClusterManager.azureSPSecretVal | b64enc }}
REDHAT_PULL_SECRET_BASE64: |-
{{ .Values.aroClusterManager.redHatPullSecretBase64 | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aws/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -10,3 +11,4 @@ data:
{{ .Values.aws.accessKeyId | b64enc }}
AWS_SECRET_ACCESS_KEY: |-
{{ .Values.aws.secretAccessKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/azure/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}

---

Expand All@@ -18,3 +19,4 @@ data:
{{ .Values.azure.sp_tenant | b64enc }}
ACR_TO_ATTACH: |-
{{ .Values.azure.aks_attached_acr | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/demo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand DownExpand Up@@ -90,3 +91,4 @@ data:
.dockerconfigjson: {{ template "pull-secret" .Values.pullSecrets.quay }}

---
{{- end }}
4 changes: 3 additions & 1 deletion chart/infra-server/templates/deployment.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,8 +27,10 @@ spec:
- name: infra-server
image: quay.io/rhacs-eng/infra-server:{{ required "A valid .Values.tag entry is required!" .Values.tag }}
env:
{{- if not .Values.localDeploy }}
- name: GOOGLE_APPLICATION_CREDENTIALS
value: /configuration/google-credentials.json
{{- end }}
- name: TEST_MODE
value: "{{ .Values.testMode }}"
readinessProbe:
Expand All@@ -47,7 +49,7 @@ spec:
containerPort: 8443
- name: metrics
containerPort: 9101
imagePullPolicy: Always
imagePullPolicy: {{ .Values.imagePullPolicy | default "Always" }}
volumeMounts:
- mountPath: /configuration
name: configuration
Expand Down
2 changes: 2 additions & 0 deletions chart/infra-server/templates/gke/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand All@@ -13,3 +14,4 @@ data:
{{ required ".Values.gke__gke_provisioner_json is undefined" .Values.gke__gke_provisioner_json }}

---
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/ibm/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -8,3 +9,4 @@ metadata:
data:
IBM_ROKS_API_KEY: |-
{{ .Values.ibmCloudSecrets.ibmRoksApiKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/monitoring/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -6,3 +7,4 @@ metadata:
namespace: monitoring
data:
webhookURL: "{{ .Values.alertmanagerSlackWebhook | b64enc }}"
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift-4/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand DownExpand Up@@ -43,3 +44,4 @@ metadata:
data:
REDHAT_PULL_SECRET: |-
{{ required ".Values.openshift_4__redhat_pull_secret_json is undefined" .Values.openshift_4__redhat_pull_secret_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand All@@ -9,3 +10,4 @@ metadata:
data:
google-credentials.json: |-
{{ required ".Values.openshift__google_credentials_json is undefined" .Values.openshift__google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/osd/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -19,3 +20,4 @@ data:
{{ .Values.osdClusterManager.gcpSaCredsJsonBase64 | b64enc }}
GCP_SERVICE_ACCOUNT_KEY_BASE64: |-
{{ .Values.osdClusterManager.gcpServiceAccountKeyBase64 | b64enc }}
{{- end }}
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
128 changes: 128 additions & 0 deletions .github/workflows/ui.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,128 @@
name: UI tests

on:
pull_request:
push:
branches:
- master

jobs:
ui-e2e-tests:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0

- name: Free disk space (delete unused tools)
id: delete-unused-tools
continue-on-error: true
shell: bash
run: |
free_disk_space=22
# delete preinstalled unused tools
cleanup=(
/usr/share/dotnet
/usr/share/miniconda
/usr/share/swift
/usr/share/kotlinc
/opt/ghc
/opt/hostedtoolcache/CodeQL
/opt/hostedtoolcache/Ruby
/opt/az
/usr/local/lib/android
)
for d in "${cleanup[@]}"; do
if [[ -d "$d" ]]; then
rm -rf -- "$d" && echo "deleted $d"
else
echo "$d not found"
continue
fi
free=$(df -BGB --output=avail / | tail -1)
if [[ ${free%GB} -ge "${free_disk_space}" ]]; then
echo "Reached requested free disk space ${free_disk_space} [${free} free]."
exit 0
fi
done
df -h

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Create KinD Cluster
uses: helm/kind-action@v1
with:
cluster_name: kind

- name: tags
run: |
echo "TAG=$(make tag)" | tee -a "$GITHUB_ENV"

- name: Build Docker image
uses: docker/build-push-action@v5
with:
file: image/Dockerfile
context: .
push: false
load: true
tags: quay.io/rhacs-eng/infra-server:${{ env.TAG }}
cache-from: type=gha
cache-to: type=gha,mode=max

- name: Load into KinD
run: |
# Check cluster name
kind get clusters
#docker build -t quay.io/rhacs-eng/infra-server:${{ env.TAG }} -f image/Dockerfile .
kind load docker-image quay.io/rhacs-eng/infra-server:${{ env.TAG }} --name kind
docker images | grep infra-server

- name: Deploy
run: make deploy-local

- name: Wait for pods
run: kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m

- name: Start port-forward
run: |
kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 &
echo "PORT_FORWARD_PID=$!" >> "$GITHUB_ENV"
sleep 5
# Verify port-forward is working
timeout 10 sh -c 'until curl -k -f https://localhost:8443/v1/whoami 2>/dev/null; do sleep 1; done' || echo "Warning: Backend may not be ready"

- name: Run E2E tests
uses: cypress-io/github-action@v6
with:
working-directory: ui
start: npm run start
wait-on: 'http://localhost:3001'
wait-on-timeout: 60
command: npm run cypress:run:e2e
env:
BROWSER: none
PORT: 3001
# Backend uses HTTPS with self-signed cert (see scripts/deploy/helm.sh)
INFRA_API_ENDPOINT: https://localhost:8443

- name: Upload test artifacts
if: failure()
uses: actions/upload-artifact@v4
with:
name: cypress-artifacts
path: |
ui/cypress/videos
ui/cypress/screenshots
retention-days: 7

- name: Cleanup port-forward
if: always()
run: |
# Kill by PID if available, otherwise kill by process name
if [ -n "${{ env.PORT_FORWARD_PID }}" ]; then
echo "Cleaning up port-forward (PID: ${{ env.PORT_FORWARD_PID }})..."
kill ${{ env.PORT_FORWARD_PID }} 2>/dev/null || true
fi
# Fallback: kill any remaining port-forward processes
pkill -f "kubectl port-forward.*8443:8443" 2>/dev/null || true
6 changes: 6 additions & 0 deletions DEPLOYMENT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -116,6 +116,12 @@ Use the environment variable `TEST_MODE` to disable certain infra service behavi

This is used in the infra PR clusters to set the login referer and disable telemetry.

#### Deployments for testing only (no secrets)

For test clusters (such as a local KinD/Colima), you can use the deploy-local make target to skip loading secrets. The flavor provisioning actions that require secrets will not be accessible, and integrations such as with Slack will be disabled.

`make deploy-local`

### Rollback

Use `helm rollback infra-server <REVISION>`.
Expand Down
25 changes: 25 additions & 0 deletions Makefile
Original file line numberDiff line numberDiff line change
Expand Up@@ -253,6 +253,31 @@ helm-deploy: pre-check helm-dependency-update create-namespaces
helm-diff: pre-check helm-dependency-update create-namespaces
@./scripts/deploy/helm.sh diff $(VERSION) $(ENVIRONMENT) $(SECRET_VERSION)

## Deploy to local cluster (e.g., Colima) without GCP Secret Manager
.PHONY: deploy-local
deploy-local: helm-dependency-update create-namespaces
TEST_MODE=true ./scripts/deploy/helm.sh deploy-local $(shell make tag) local

## Run UI E2E tests against local deployment
.PHONY: test-e2e
test-e2e:
@echo "test-e2e starting..." >&2
@echo "Waiting for infra-server to be ready..." >&2
@kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m >&2 || \
(echo "ERROR: infra-server pods did not become ready" >&2 && exit 1)
@echo "Starting port-forward and running E2E tests..." >&2
@kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 & \
PF_PID=$$!; \
cleanup() { \
echo "" >&2; \
echo "Cleaning up port-forward (PID: $$PF_PID)..." >&2; \
kill $$PF_PID 2>/dev/null || true; \
}; \
trap cleanup EXIT; \
sleep 5; \
echo "Running Cypress E2E tests..." >&2; \
cd ui && BROWSER=none PORT=3001 INFRA_API_ENDPOINT=http://localhost:8443 npm run test:e2e

## Bounce pods
.PHONY: bounce-infra-pods
bounce-infra-pods:
Expand Down
30 changes: 30 additions & 0 deletions chart/infra-server/configuration/local-values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
environment: local

# Set local deploy mode to true for local development
localDeploy: true

# Enable test mode for faster cluster resume intervals
testMode: true

# Use local Docker images when available, pull from registry if not present
# Works with Colima (shared Docker daemon) and kind (after kind load docker-image)
# IfNotPresent provides flexibility: uses local images when available, pulls when needed
imagePullPolicy: IfNotPresent

# Pull secrets for container registries - dummy values for local development
pullSecrets:
docker:
registry: "docker.io"
username: "dummy"
password: "dummy"
quay:
registry: "quay.io"
username: "dummy"
password: "dummy"
stackrox:
registry: "stackrox.io"
username: "dummy"
password: "dummy"

# Alertmanager configuration
alertmanagerSlackTeam: "dummy-team"
2 changes: 2 additions & 0 deletions chart/infra-server/templates/argo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -7,3 +8,4 @@ metadata:
data:
credentials.json: |-
{{ required ".Values.google_credentials_json is undefined" .Values.google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aro/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -16,3 +17,4 @@ data:
{{ .Values.aroClusterManager.azureSPSecretVal | b64enc }}
REDHAT_PULL_SECRET_BASE64: |-
{{ .Values.aroClusterManager.redHatPullSecretBase64 | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aws/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -10,3 +11,4 @@ data:
{{ .Values.aws.accessKeyId | b64enc }}
AWS_SECRET_ACCESS_KEY: |-
{{ .Values.aws.secretAccessKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/azure/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}

---

Expand All@@ -18,3 +19,4 @@ data:
{{ .Values.azure.sp_tenant | b64enc }}
ACR_TO_ATTACH: |-
{{ .Values.azure.aks_attached_acr | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/demo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand DownExpand Up@@ -90,3 +91,4 @@ data:
.dockerconfigjson: {{ template "pull-secret" .Values.pullSecrets.quay }}

---
{{- end }}
4 changes: 3 additions & 1 deletion chart/infra-server/templates/deployment.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,8 +27,10 @@ spec:
- name: infra-server
image: quay.io/rhacs-eng/infra-server:{{ required "A valid .Values.tag entry is required!" .Values.tag }}
env:
{{- if not .Values.localDeploy }}
- name: GOOGLE_APPLICATION_CREDENTIALS
value: /configuration/google-credentials.json
{{- end }}
- name: TEST_MODE
value: "{{ .Values.testMode }}"
readinessProbe:
Expand All@@ -47,7 +49,7 @@ spec:
containerPort: 8443
- name: metrics
containerPort: 9101
imagePullPolicy: Always
imagePullPolicy: {{ .Values.imagePullPolicy | default "Always" }}
volumeMounts:
- mountPath: /configuration
name: configuration
Expand Down
2 changes: 2 additions & 0 deletions chart/infra-server/templates/gke/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand All@@ -13,3 +14,4 @@ data:
{{ required ".Values.gke__gke_provisioner_json is undefined" .Values.gke__gke_provisioner_json }}

---
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/ibm/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -8,3 +9,4 @@ metadata:
data:
IBM_ROKS_API_KEY: |-
{{ .Values.ibmCloudSecrets.ibmRoksApiKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/monitoring/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -6,3 +7,4 @@ metadata:
namespace: monitoring
data:
webhookURL: "{{ .Values.alertmanagerSlackWebhook | b64enc }}"
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift-4/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand DownExpand Up@@ -43,3 +44,4 @@ metadata:
data:
REDHAT_PULL_SECRET: |-
{{ required ".Values.openshift_4__redhat_pull_secret_json is undefined" .Values.openshift_4__redhat_pull_secret_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand All@@ -9,3 +10,4 @@ metadata:
data:
google-credentials.json: |-
{{ required ".Values.openshift__google_credentials_json is undefined" .Values.openshift__google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/osd/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -19,3 +20,4 @@ data:
{{ .Values.osdClusterManager.gcpSaCredsJsonBase64 | b64enc }}
GCP_SERVICE_ACCOUNT_KEY_BASE64: |-
{{ .Values.osdClusterManager.gcpServiceAccountKeyBase64 | b64enc }}
{{- end }}
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
128 changes: 128 additions & 0 deletions .github/workflows/ui.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,128 @@
name: UI tests

on:
pull_request:
push:
branches:
- master

jobs:
ui-e2e-tests:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0

- name: Free disk space (delete unused tools)
id: delete-unused-tools
continue-on-error: true
shell: bash
run: |
free_disk_space=22
# delete preinstalled unused tools
cleanup=(
/usr/share/dotnet
/usr/share/miniconda
/usr/share/swift
/usr/share/kotlinc
/opt/ghc
/opt/hostedtoolcache/CodeQL
/opt/hostedtoolcache/Ruby
/opt/az
/usr/local/lib/android
)
for d in "${cleanup[@]}"; do
if [[ -d "$d" ]]; then
rm -rf -- "$d" && echo "deleted $d"
else
echo "$d not found"
continue
fi
free=$(df -BGB --output=avail / | tail -1)
if [[ ${free%GB} -ge "${free_disk_space}" ]]; then
echo "Reached requested free disk space ${free_disk_space} [${free} free]."
exit 0
fi
done
df -h

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Create KinD Cluster
uses: helm/kind-action@v1
with:
cluster_name: kind

- name: tags
run: |
echo "TAG=$(make tag)" | tee -a "$GITHUB_ENV"

- name: Build Docker image
uses: docker/build-push-action@v5
with:
file: image/Dockerfile
context: .
push: false
load: true
tags: quay.io/rhacs-eng/infra-server:${{ env.TAG }}
cache-from: type=gha
cache-to: type=gha,mode=max

- name: Load into KinD
run: |
# Check cluster name
kind get clusters
#docker build -t quay.io/rhacs-eng/infra-server:${{ env.TAG }} -f image/Dockerfile .
kind load docker-image quay.io/rhacs-eng/infra-server:${{ env.TAG }} --name kind
docker images | grep infra-server

- name: Deploy
run: make deploy-local

- name: Wait for pods
run: kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m

- name: Start port-forward
run: |
kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 &
echo "PORT_FORWARD_PID=$!" >> "$GITHUB_ENV"
sleep 5
# Verify port-forward is working
timeout 10 sh -c 'until curl -k -f https://localhost:8443/v1/whoami 2>/dev/null; do sleep 1; done' || echo "Warning: Backend may not be ready"

- name: Run E2E tests
uses: cypress-io/github-action@v6
with:
working-directory: ui
start: npm run start
wait-on: 'http://localhost:3001'
wait-on-timeout: 60
command: npm run cypress:run:e2e
env:
BROWSER: none
PORT: 3001
# Backend uses HTTPS with self-signed cert (see scripts/deploy/helm.sh)
INFRA_API_ENDPOINT: https://localhost:8443

- name: Upload test artifacts
if: failure()
uses: actions/upload-artifact@v4
with:
name: cypress-artifacts
path: |
ui/cypress/videos
ui/cypress/screenshots
retention-days: 7

- name: Cleanup port-forward
if: always()
run: |
# Kill by PID if available, otherwise kill by process name
if [ -n "${{ env.PORT_FORWARD_PID }}" ]; then
echo "Cleaning up port-forward (PID: ${{ env.PORT_FORWARD_PID }})..."
kill ${{ env.PORT_FORWARD_PID }} 2>/dev/null || true
fi
# Fallback: kill any remaining port-forward processes
pkill -f "kubectl port-forward.*8443:8443" 2>/dev/null || true
6 changes: 6 additions & 0 deletions DEPLOYMENT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -116,6 +116,12 @@ Use the environment variable `TEST_MODE` to disable certain infra service behavi

This is used in the infra PR clusters to set the login referer and disable telemetry.

#### Deployments for testing only (no secrets)

For test clusters (such as a local KinD/Colima), you can use the deploy-local make target to skip loading secrets. The flavor provisioning actions that require secrets will not be accessible, and integrations such as with Slack will be disabled.

`make deploy-local`

### Rollback

Use `helm rollback infra-server <REVISION>`.
Expand Down
25 changes: 25 additions & 0 deletions Makefile
Original file line numberDiff line numberDiff line change
Expand Up@@ -253,6 +253,31 @@ helm-deploy: pre-check helm-dependency-update create-namespaces
helm-diff: pre-check helm-dependency-update create-namespaces
@./scripts/deploy/helm.sh diff $(VERSION) $(ENVIRONMENT) $(SECRET_VERSION)

## Deploy to local cluster (e.g., Colima) without GCP Secret Manager
.PHONY: deploy-local
deploy-local: helm-dependency-update create-namespaces
TEST_MODE=true ./scripts/deploy/helm.sh deploy-local $(shell make tag) local

## Run UI E2E tests against local deployment
.PHONY: test-e2e
test-e2e:
@echo "test-e2e starting..." >&2
@echo "Waiting for infra-server to be ready..." >&2
@kubectl wait --for=condition=ready pod -l app=infra-server -n infra --timeout=3m >&2 || \
(echo "ERROR: infra-server pods did not become ready" >&2 && exit 1)
@echo "Starting port-forward and running E2E tests..." >&2
@kubectl port-forward -n infra svc/infra-server-service 8443:8443 >/dev/null 2>&1 & \
PF_PID=$$!; \
cleanup() { \
echo "" >&2; \
echo "Cleaning up port-forward (PID: $$PF_PID)..." >&2; \
kill $$PF_PID 2>/dev/null || true; \
}; \
trap cleanup EXIT; \
sleep 5; \
echo "Running Cypress E2E tests..." >&2; \
cd ui && BROWSER=none PORT=3001 INFRA_API_ENDPOINT=http://localhost:8443 npm run test:e2e

## Bounce pods
.PHONY: bounce-infra-pods
bounce-infra-pods:
Expand Down
30 changes: 30 additions & 0 deletions chart/infra-server/configuration/local-values.yaml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
environment: local

# Set local deploy mode to true for local development
localDeploy: true

# Enable test mode for faster cluster resume intervals
testMode: true

# Use local Docker images when available, pull from registry if not present
# Works with Colima (shared Docker daemon) and kind (after kind load docker-image)
# IfNotPresent provides flexibility: uses local images when available, pulls when needed
imagePullPolicy: IfNotPresent

# Pull secrets for container registries - dummy values for local development
pullSecrets:
docker:
registry: "docker.io"
username: "dummy"
password: "dummy"
quay:
registry: "quay.io"
username: "dummy"
password: "dummy"
stackrox:
registry: "stackrox.io"
username: "dummy"
password: "dummy"

# Alertmanager configuration
alertmanagerSlackTeam: "dummy-team"
2 changes: 2 additions & 0 deletions chart/infra-server/templates/argo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -7,3 +8,4 @@ metadata:
data:
credentials.json: |-
{{ required ".Values.google_credentials_json is undefined" .Values.google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aro/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -16,3 +17,4 @@ data:
{{ .Values.aroClusterManager.azureSPSecretVal | b64enc }}
REDHAT_PULL_SECRET_BASE64: |-
{{ .Values.aroClusterManager.redHatPullSecretBase64 | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/aws/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -10,3 +11,4 @@ data:
{{ .Values.aws.accessKeyId | b64enc }}
AWS_SECRET_ACCESS_KEY: |-
{{ .Values.aws.secretAccessKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/azure/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}

---

Expand All@@ -18,3 +19,4 @@ data:
{{ .Values.azure.sp_tenant | b64enc }}
ACR_TO_ATTACH: |-
{{ .Values.azure.aks_attached_acr | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/demo/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand DownExpand Up@@ -90,3 +91,4 @@ data:
.dockerconfigjson: {{ template "pull-secret" .Values.pullSecrets.quay }}

---
{{- end }}
4 changes: 3 additions & 1 deletion chart/infra-server/templates/deployment.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,8 +27,10 @@ spec:
- name: infra-server
image: quay.io/rhacs-eng/infra-server:{{ required "A valid .Values.tag entry is required!" .Values.tag }}
env:
{{- if not .Values.localDeploy }}
- name: GOOGLE_APPLICATION_CREDENTIALS
value: /configuration/google-credentials.json
{{- end }}
- name: TEST_MODE
value: "{{ .Values.testMode }}"
readinessProbe:
Expand All@@ -47,7 +49,7 @@ spec:
containerPort: 8443
- name: metrics
containerPort: 9101
imagePullPolicy: Always
imagePullPolicy: {{ .Values.imagePullPolicy | default "Always" }}
volumeMounts:
- mountPath: /configuration
name: configuration
Expand Down
2 changes: 2 additions & 0 deletions chart/infra-server/templates/gke/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---

apiVersion: v1
Expand All@@ -13,3 +14,4 @@ data:
{{ required ".Values.gke__gke_provisioner_json is undefined" .Values.gke__gke_provisioner_json }}

---
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/ibm/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -8,3 +9,4 @@ metadata:
data:
IBM_ROKS_API_KEY: |-
{{ .Values.ibmCloudSecrets.ibmRoksApiKey | b64enc }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/monitoring/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -6,3 +7,4 @@ metadata:
namespace: monitoring
data:
webhookURL: "{{ .Values.alertmanagerSlackWebhook | b64enc }}"
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift-4/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand DownExpand Up@@ -43,3 +44,4 @@ metadata:
data:
REDHAT_PULL_SECRET: |-
{{ required ".Values.openshift_4__redhat_pull_secret_json is undefined" .Values.openshift_4__redhat_pull_secret_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/openshift/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
apiVersion: v1
kind: Secret
type: Opaque
Expand All@@ -9,3 +10,4 @@ metadata:
data:
google-credentials.json: |-
{{ required ".Values.openshift__google_credentials_json is undefined" .Values.openshift__google_credentials_json }}
{{- end }}
2 changes: 2 additions & 0 deletions chart/infra-server/templates/osd/secrets.yaml
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
{{- if not .Values.localDeploy }}
---
apiVersion: v1
kind: Secret
Expand All@@ -19,3 +20,4 @@ data:
{{ .Values.osdClusterManager.gcpSaCredsJsonBase64 | b64enc }}
GCP_SERVICE_ACCOUNT_KEY_BASE64: |-
{{ .Values.osdClusterManager.gcpServiceAccountKeyBase64 | b64enc }}
{{- end }}
Loading
Loading