-
Notifications
You must be signed in to change notification settings - Fork 8
252 lines (216 loc) · 7.75 KB
/
Copy pathci.yaml
File metadata and controls
252 lines (216 loc) · 7.75 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
name: CI
on:
push:
paths:
- ".github/workflows/ci.yaml"
- ".config/nextest.toml"
- "src/**"
- "tests/**"
- "Cargo.toml"
- "Cargo.lock"
pull_request: {}
env:
RUSTFLAGS: -D warnings
CARGO_TERM_COLOR: always
TEST_STATS_DELAY: 5000
jobs:
lint:
name: Lint
strategy:
matrix:
runner:
- "ubuntu-22.04"
- "ubuntu-24.04"
runs-on: ${{ matrix.runner }}
steps:
- uses: actions/checkout@v6
- name: Free up disk space
run: .github/scripts/free_disk_space.sh
- uses: dtolnay/rust-toolchain@stable
with:
components: rustfmt, clippy
- name: Lint (clippy)
run: cargo clippy
- name: Lint (rustfmt)
run: cargo fmt --all --check
build:
name: Non-TLS tests
strategy:
matrix:
rabbitmq-series:
- "3.12"
- "3.13"
- "4.0"
- "4.1"
- "4.2"
rust-version:
- stable
- beta
runner:
- "ubuntu-22.04"
- "ubuntu-24.04"
# - "ubuntu-24.04-arm"
runs-on: ${{ matrix.runner }}
services:
rabbitmq:
image: rabbitmq:${{ matrix.rabbitmq-series }}-management
ports:
- 15672:15672
- 5672:5672
steps:
- uses: actions/checkout@v6
- name: Free up disk space
run: .github/scripts/free_disk_space.sh
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
with:
toolchain: ${{ matrix.rust-version }}
- uses: taiki-e/install-action@nextest
- name: Wait for node to start booting
run: sleep 15
- name: Configure broker
run: RUST_HTTP_API_CLIENT_RABBITMQCTL=DOCKER:${{job.services.rabbitmq.id}} bin/ci/before_build.sh
- name: Run tests
run: RUST_BACKTRACE=1 NEXTEST_RETRIES=2 cargo nextest run --cargo-profile ci --workspace --no-fail-fast --all-features
tls-tests:
name: TLS tests
strategy:
matrix:
rabbitmq-series:
- "3.12"
- "3.13"
- "4.0"
- "4.1"
- "4.2"
rust-version:
- stable
runner:
- "ubuntu-22.04"
- "ubuntu-24.04"
- "ubuntu-24.04-arm"
runs-on: ${{ matrix.runner }}
steps:
- uses: actions/checkout@v6
- name: Free up disk space
run: .github/scripts/free_disk_space.sh
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
with:
toolchain: ${{ matrix.rust-version }}
- uses: taiki-e/install-action@nextest
- name: Clone tls-gen
run: git clone --depth 1 https://github.com/rabbitmq/tls-gen.git target/tls-gen
- name: Generate TLS certificates
run: |
cd target/tls-gen/basic
make CN=localhost
- name: Create certs directory
run: mkdir -p tests/tls/certs
- name: Copy certificates
run: |
cp target/tls-gen/basic/result/ca_certificate.pem tests/tls/certs/
cp target/tls-gen/basic/result/server_localhost_certificate.pem tests/tls/certs/server_certificate.pem
cp target/tls-gen/basic/result/server_localhost_key.pem tests/tls/certs/server_key.pem
cp target/tls-gen/basic/result/client_localhost_certificate.pem tests/tls/certs/client_certificate.pem
cp target/tls-gen/basic/result/client_localhost_key.pem tests/tls/certs/client_key.pem
chmod o+r tests/tls/certs/*
chmod g+r tests/tls/certs/*
- name: Create RabbitMQ TLS configuration
run: |
cat > tests/tls/certs/rabbitmq.conf << 'EOF'
management.ssl.port = 15671
management.ssl.cacertfile = /certs/ca_certificate.pem
management.ssl.certfile = /certs/server_certificate.pem
management.ssl.keyfile = /certs/server_key.pem
management.tcp.port = 15672
loopback_users = none
EOF
sed -i 's/^[[:space:]]*//' tests/tls/certs/rabbitmq.conf
echo "Generated config:"
cat tests/tls/certs/rabbitmq.conf
echo -n "rabbitmq-test-cookie" > tests/tls/certs/.erlang.cookie
chmod 600 tests/tls/certs/.erlang.cookie
- name: Start RabbitMQ with TLS
run: |
docker run -d --name rabbitmq-tls \
-p 15671:15671 \
-p 15672:15672 \
-p 5672:5672 \
-v ${{ github.workspace }}/tests/tls/certs/.erlang.cookie:/var/lib/rabbitmq/.erlang.cookie \
-v ${{ github.workspace }}/tests/tls/certs:/certs:ro \
-v ${{ github.workspace }}/tests/tls/certs/rabbitmq.conf:/etc/rabbitmq/conf.d/10-tls.conf:ro \
rabbitmq:${{ matrix.rabbitmq-series }}-management
- name: Wait for RabbitMQ to start
run: |
for i in $(seq 1 30); do
if docker exec rabbitmq-tls rabbitmqctl await_startup --timeout 60; then
echo "RabbitMQ is ready"
exit 0
fi
echo "Waiting for container... ($i/30)"
sleep 2
done
echo "RabbitMQ failed to start. Container logs:"
docker logs rabbitmq-tls
exit 1
- name: Verify TLS listener
run: |
docker exec rabbitmq-tls rabbitmq-diagnostics listeners
echo "Checking if TLS port 15671 is listening..."
docker exec rabbitmq-tls rabbitmq-diagnostics listeners | grep -E "15671|ssl" || echo "Note: TLS listener output"
- name: Debug TLS certificates
run: |
echo "=== CA Certificate ==="
openssl x509 -in tests/tls/certs/ca_certificate.pem -noout -subject -issuer
echo "=== Server Certificate ==="
openssl x509 -in tests/tls/certs/server_certificate.pem -noout -subject -issuer
echo "=== Verify server cert against CA ==="
openssl verify -CAfile tests/tls/certs/ca_certificate.pem tests/tls/certs/server_certificate.pem
echo "=== Test TLS connection with curl ==="
curl -v --cacert tests/tls/certs/ca_certificate.pem https://localhost:15671/api/overview -u guest:guest 2>&1 | head -30 || true
echo "=== Certificate file permissions ==="
ls -la tests/tls/certs/
- name: Configure broker
run: |
docker exec rabbitmq-tls rabbitmqctl add_vhost / || true
docker exec rabbitmq-tls rabbitmqctl add_user guest guest || true
docker exec rabbitmq-tls rabbitmqctl set_permissions -p / guest ".*" ".*" ".*"
- name: Run TLS tests
run: |
TLS_CERTS_DIR=${{ github.workspace }}/tests/tls/certs \
RUST_BACKTRACE=1 \
cargo nextest run --cargo-profile ci -E 'test(tls_tests::)' --run-ignored=only --no-fail-fast
- name: Stop RabbitMQ container
if: always()
run: docker stop rabbitmq-tls && docker rm rabbitmq-tls || true
audit:
name: Security audit
runs-on: ubuntu-latest
permissions:
checks: write
contents: read
steps:
- uses: actions/checkout@v6
- uses: dtolnay/rust-toolchain@stable
- run: cargo generate-lockfile
- uses: rustsec/audit-check@v2
with:
token: ${{ secrets.GITHUB_TOKEN }}
dependabot:
needs: [lint, build, tls-tests]
runs-on: ubuntu-latest
permissions:
pull-requests: write
contents: write
if: ${{ github.actor == 'dependabot[bot]' && github.event_name == 'pull_request' }}
steps:
- id: metadata
uses: dependabot/fetch-metadata@v2
with:
github-token: "${{ secrets.GITHUB_TOKEN }}"
- run: |
gh pr review --approve "$PR_URL"
gh pr merge --merge --auto "$PR_URL"
env:
PR_URL: ${{ github.event.pull_request.html_url }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}