mirror of
https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin.git
synced 2026-07-21 19:48:59 +02:00
✨ tests: add binary e2e suite (Traefik binary + Go mock LAPI), run it in CI
Add a second e2e suite that runs Traefik as a downloaded binary with the plugin loaded from source, and replaces Crowdsec with a small stdlib-only Go LAPI mock driven via /admin endpoints. No Docker, no real Crowdsec. The mock lives in its own nested Go module (tests/e2e/mock/mocklapi) so it stays out of the plugin module's build, lint, test and vendor. This suite validates the plugin's own behaviour (live/none/stream modes, caching, trusted-IP bypass, ban/captcha rendering). Crowdsec and AppSec correctness are out of scope on purpose — they are validated upstream by the maintainer — so the AppSec scenario is intentionally absent and the README says so to avoid misfiled issues. CI now runs this suite only (`make e2e_mock`), since it needs neither Docker nor a real Crowdsec. The Docker suite (tests/e2e/scenarios) is kept for local debugging (`make e2e`). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -14,21 +14,27 @@ permissions:
|
||||
|
||||
jobs:
|
||||
e2e:
|
||||
name: e2e
|
||||
name: e2e (binary + mock LAPI)
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
# A single runner runs every scenario sequentially. Docker caches the
|
||||
# Traefik/Crowdsec/whoami images locally, so they are pulled only once
|
||||
# for the whole suite instead of once per scenario. `-k` keeps going
|
||||
# after a failing scenario so the logs cover all of them, while make
|
||||
# still exits non-zero if any scenario failed.
|
||||
- name: Run scenarios
|
||||
run: make -k e2e
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v6
|
||||
with:
|
||||
go-version: "1.23"
|
||||
# CI runs the binary/mock suite only: Traefik as a downloaded binary +
|
||||
# a small LAPI mock (no Docker, no real Crowdsec). It validates the
|
||||
# plugin's own behaviour. Crowdsec / AppSec correctness is upstream's
|
||||
# responsibility, so those are intentionally out of scope here. The
|
||||
# Docker suite (tests/e2e/scenarios) stays available for local debugging.
|
||||
# `-k` keeps going after a failing scenario so the logs cover all of
|
||||
# them, while make still exits non-zero if any scenario failed.
|
||||
- name: Run mock scenarios
|
||||
run: make -k e2e_mock
|
||||
- name: Upload logs on failure
|
||||
if: failure()
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: e2e-logs
|
||||
path: /tmp/e2e-*.log
|
||||
path: /tmp/e2e-mock-*.log
|
||||
if-no-files-found: ignore
|
||||
|
||||
Reference in New Issue
Block a user