consul/agent/connect_ca_endpoint_test.go

117 lines
2.8 KiB
Go
Raw Normal View History

2018-03-20 10:36:05 -07:00
package agent
import (
2018-05-04 15:28:11 -07:00
"bytes"
2018-03-20 10:36:05 -07:00
"net/http"
"net/http/httptest"
"testing"
"time"
2018-03-20 10:36:05 -07:00
"github.com/stretchr/testify/require"
2018-03-21 10:20:35 -07:00
"github.com/hashicorp/consul/agent/connect"
2018-05-09 15:12:31 -07:00
ca "github.com/hashicorp/consul/agent/connect/ca"
2018-03-20 10:36:05 -07:00
"github.com/hashicorp/consul/agent/structs"
"github.com/stretchr/testify/assert"
)
func TestConnectCARoots_empty(t *testing.T) {
t.Parallel()
require := require.New(t)
a := NewTestAgent(t.Name(), "connect { enabled = false }")
2018-03-20 10:36:05 -07:00
defer a.Shutdown()
req, _ := http.NewRequest("GET", "/v1/connect/ca/roots", nil)
resp := httptest.NewRecorder()
_, err := a.srv.ConnectCARoots(resp, req)
require.Error(err)
require.Contains(err.Error(), "Connect must be enabled")
2018-03-20 10:36:05 -07:00
}
func TestConnectCARoots_list(t *testing.T) {
t.Parallel()
assert := assert.New(t)
a := NewTestAgent(t.Name(), "")
defer a.Shutdown()
// Set some CAs. Note that NewTestAgent already bootstraps one CA so this just
// adds a second and makes it active.
ca2 := connect.TestCAConfigSet(t, a, nil)
2018-03-21 10:20:35 -07:00
// List
req, _ := http.NewRequest("GET", "/v1/connect/ca/roots", nil)
resp := httptest.NewRecorder()
obj, err := a.srv.ConnectCARoots(resp, req)
2018-05-04 15:28:11 -07:00
assert.NoError(err)
value := obj.(structs.IndexedCARoots)
2018-03-21 10:20:35 -07:00
assert.Equal(value.ActiveRootID, ca2.ID)
assert.Len(value.Roots, 2)
// We should never have the secret information
for _, r := range value.Roots {
assert.Equal("", r.SigningCert)
assert.Equal("", r.SigningKey)
}
}
2018-05-04 15:28:11 -07:00
func TestConnectCAConfig(t *testing.T) {
t.Parallel()
assert := assert.New(t)
a := NewTestAgent(t.Name(), "")
defer a.Shutdown()
expected := &structs.ConsulCAProviderConfig{
RotationPeriod: 90 * 24 * time.Hour,
}
expected.LeafCertTTL = 72 * time.Hour
2018-05-04 15:28:11 -07:00
// Get the initial config.
{
req, _ := http.NewRequest("GET", "/v1/connect/ca/configuration", nil)
resp := httptest.NewRecorder()
obj, err := a.srv.ConnectCAConfiguration(resp, req)
assert.NoError(err)
value := obj.(structs.CAConfiguration)
2018-05-09 15:12:31 -07:00
parsed, err := ca.ParseConsulCAConfig(value.Config)
2018-05-04 15:28:11 -07:00
assert.NoError(err)
assert.Equal("consul", value.Provider)
assert.Equal(expected, parsed)
}
// Set the config.
{
body := bytes.NewBuffer([]byte(`
{
"Provider": "consul",
"Config": {
"LeafCertTTL": "72h",
"RotationPeriod": "1h"
}
}`))
2018-05-04 15:28:11 -07:00
req, _ := http.NewRequest("PUT", "/v1/connect/ca/configuration", body)
resp := httptest.NewRecorder()
_, err := a.srv.ConnectCAConfiguration(resp, req)
assert.NoError(err)
}
// The config should be updated now.
{
expected.RotationPeriod = time.Hour
2018-05-04 15:28:11 -07:00
req, _ := http.NewRequest("GET", "/v1/connect/ca/configuration", nil)
resp := httptest.NewRecorder()
obj, err := a.srv.ConnectCAConfiguration(resp, req)
assert.NoError(err)
value := obj.(structs.CAConfiguration)
2018-05-09 15:12:31 -07:00
parsed, err := ca.ParseConsulCAConfig(value.Config)
2018-05-04 15:28:11 -07:00
assert.NoError(err)
assert.Equal("consul", value.Provider)
assert.Equal(expected, parsed)
}
}