|
| 1 | +package test |
| 2 | + |
| 3 | +import ( |
| 4 | + "testing" |
| 5 | + |
| 6 | + "github.com/aws/aws-sdk-go/service/s3" |
| 7 | + "github.com/chanzuckerberg/cztack/testutil" |
| 8 | + "github.com/gruntwork-io/terratest/modules/aws" |
| 9 | + "github.com/gruntwork-io/terratest/modules/terraform" |
| 10 | + "github.com/stretchr/testify/require" |
| 11 | +) |
| 12 | + |
| 13 | +func TestPrivateBucketDefaults(t *testing.T) { |
| 14 | + |
| 15 | + test := &testutil.Test{ |
| 16 | + Options: func(t *testing.T) *terraform.Options { |
| 17 | + project := testutil.UniqueId() |
| 18 | + env := testutil.UniqueId() |
| 19 | + service := testutil.UniqueId() |
| 20 | + owner := testutil.UniqueId() |
| 21 | + |
| 22 | + bucketName := testutil.UniqueId() |
| 23 | + |
| 24 | + return testutil.Options( |
| 25 | + testutil.DefaultRegion, |
| 26 | + map[string]interface{}{ |
| 27 | + "project": project, |
| 28 | + "env": env, |
| 29 | + "service": service, |
| 30 | + "owner": owner, |
| 31 | + |
| 32 | + "bucket_name": bucketName, |
| 33 | + }, |
| 34 | + ) |
| 35 | + }, |
| 36 | + |
| 37 | + Validate: func(t *testing.T, options *terraform.Options) { |
| 38 | + r := require.New(t) |
| 39 | + region := options.EnvVars["AWS_DEFAULT_REGION"] |
| 40 | + bucket := options.Vars["bucket_name"].(string) |
| 41 | + |
| 42 | + // get a client to query for other assertions |
| 43 | + s3Client := aws.NewS3Client(t, region) |
| 44 | + |
| 45 | + acl, err := s3Client.GetBucketAcl(&s3.GetBucketAclInput{ |
| 46 | + Bucket: &bucket, |
| 47 | + }) |
| 48 | + |
| 49 | + r.NoError(err) |
| 50 | + r.Len(acl.Grants, 2) |
| 51 | + |
| 52 | + r.Equal("CanonicalUser", *acl.Grants[0].Grantee.Type) |
| 53 | + r.Equal("FULL_CONTROL", *acl.Grants[0].Permission) |
| 54 | + r.Equal("c4c1ede66af53448b93c283ce9448c4ba468c9432aa01d700d3878632f77d2d0", *acl.Grants[1].Grantee.ID) |
| 55 | + r.Equal("FULL_CONTROL", *acl.Grants[1].Permission) |
| 56 | + }, |
| 57 | + } |
| 58 | + test.Run(t) |
| 59 | +} |
0 commit comments