54 lines
2.1 KiB
Python
54 lines
2.1 KiB
Python
from pathlib import Path
|
|
import unittest
|
|
|
|
|
|
ROOT = Path(__file__).resolve().parents[1]
|
|
PLAYBOOK = ROOT / "deploy" / "ansible" / "guestops-operations.yml"
|
|
|
|
|
|
class AnsibleOperationsTests(unittest.TestCase):
|
|
def test_operations_require_release_and_private_inputs(self):
|
|
text = PLAYBOOK.read_text(encoding="utf-8")
|
|
for required in (
|
|
"/srv/guestops/current",
|
|
"guestops_release_commit is match('^[0-9a-f]{40}$')",
|
|
"guestops_backup_recipient is match('^[A-Fa-f0-9]{40}$')",
|
|
"guestops_durable_logs_configured | bool",
|
|
"/etc/guestops/backup.env",
|
|
"/etc/guestops/backup-transfer.env",
|
|
"/etc/guestops/backup-transfer.key",
|
|
"/etc/guestops/backup-known-hosts",
|
|
"no_log: true",
|
|
):
|
|
self.assertIn(required, text)
|
|
|
|
def test_public_key_units_monitoring_and_evidence_are_integrated(self):
|
|
text = PLAYBOOK.read_text(encoding="utf-8")
|
|
ordered = (
|
|
"Import recovery public key only",
|
|
"Verify installed systemd units",
|
|
"Enable transfer retry and monitoring timers",
|
|
"Install restricted Zabbix status item",
|
|
"Generate initial non-sensitive monitoring status",
|
|
"Retain monitoring status on the Ansible controller",
|
|
)
|
|
positions = [text.index(item) for item in ordered]
|
|
self.assertEqual(positions, sorted(positions))
|
|
self.assertIn("guestops_enable_backup_schedule: false", text)
|
|
self.assertNotIn("ansible.builtin.shell", text)
|
|
self.assertNotIn("PRIVATE KEY", text)
|
|
|
|
def test_systemd_units_follow_selected_release(self):
|
|
for name in (
|
|
"guestops-backup.service",
|
|
"guestops-backup-transfer.service",
|
|
"guestops-monitor-status.service",
|
|
):
|
|
text = (ROOT / "deploy" / "systemd" / name).read_text(encoding="utf-8")
|
|
self.assertIn("/srv/guestops/current", text)
|
|
self.assertNotIn("WorkingDirectory=/srv/guestops\n", text)
|
|
|
|
|
|
if __name__ == "__main__":
|
|
unittest.main()
|