test(tmachine): add Debian installer profile (#3461)

* test(tmachine): add Debian installer profile

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* refactor(ci): centralize conformance matrix

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* test(ci): prefer packaged conformance artifacts

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* test(tmachine): use packaged Debian gateway service

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* test(tmachine): isolate Debian qualification config

Signed-off-by: Evan Lezar <elezar@nvidia.com>

---------

Signed-off-by: Simon Scatton <sscatton@nvidia.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
Co-authored-by: Evan Lezar <elezar@nvidia.com>
This commit is contained in:
Simon Scatton
2026-09-21 12:17:11 +02:00
committed by GitHub
co-authored by Evan Lezar
parent 1905069948
commit 65eb9167d1
14 changed files with 214 additions and 37 deletions
+10 -1
View File
@@ -39,6 +39,15 @@
- conformance_archive.stat.isreg | default(false)
fail_msg: OpenShell conformance test bundle did not contain tests.tar.zst
- name: Resolve installed OpenShell CLI
ansible.builtin.command:
argv:
- /bin/sh
- -c
- command -v openshell
register: openshell_cli
changed_when: false
- name: Run OpenShell conformance archive
ansible.builtin.command:
argv:
@@ -51,7 +60,7 @@
- /var/lib/openshell-conformance/tests
- --no-capture
environment:
OPENSHELL_BIN: /usr/local/bin/openshell
OPENSHELL_BIN: "{{ openshell_cli.stdout }}"
register: conformance_result
changed_when: false
failed_when: false
@@ -49,6 +49,15 @@
- provider_refresh_keycloak_test_archive.stat.isreg | default(false)
fail_msg: Keycloak provider refresh test bundle did not contain tests.tar.zst
- name: Resolve installed OpenShell CLI
ansible.builtin.command:
argv:
- /bin/sh
- -c
- command -v openshell
register: openshell_cli
changed_when: false
- name: Run Keycloak provider refresh archive
ansible.builtin.command:
argv:
@@ -61,7 +70,7 @@
- /var/lib/openshell-provider-refresh/tests
- --no-capture
environment:
OPENSHELL_BIN: /usr/local/bin/openshell
OPENSHELL_BIN: "{{ openshell_cli.stdout }}"
OPENSHELL_E2E_OIDC_ISSUER: http://127.0.0.1:8180/realms/openshell
OPENSHELL_E2E_OIDC_USERNAME: admin@test
OPENSHELL_E2E_OIDC_PASSWORD: admin
+114
View File
@@ -0,0 +1,114 @@
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
---
- name: Install OpenShell Debian package
hosts: all
gather_facts: false
tasks:
- name: Wait for SSH
ansible.builtin.wait_for_connection:
- name: Copy OpenShell Debian package
become: true
ansible.builtin.copy:
src: "{{ openshell_deb }}"
dest: /var/tmp/openshell.deb
mode: "0644"
- name: Install OpenShell Debian package
become: true
ansible.builtin.apt:
deb: /var/tmp/openshell.deb
- name: Copy OpenShell runtime images
become: true
ansible.builtin.copy:
src: "{{ item.src }}"
dest: "/var/tmp/{{ item.name }}.tar"
mode: "0644"
loop:
- name: openshell-sandbox
src: "{{ openshell_sandbox_image }}"
- name: openshell-supervisor
src: "{{ openshell_supervisor_image }}"
- name: Load OpenShell runtime images
become: true
ansible.builtin.command:
argv:
- docker
- load
- --input
- "/var/tmp/{{ item }}.tar"
loop:
- openshell-sandbox
- openshell-supervisor
# The package normally starts from its built-in runtime-image defaults.
# Qualification instead pins the candidate images staged by tmachine, so
# keep that override separate from the operator-owned gateway.toml.
- name: Create OpenShell qualification configuration directory
become: true
ansible.builtin.file:
path: /var/lib/openshell-qualification
state: directory
owner: root
group: root
mode: "0755"
- name: Configure candidate OpenShell runtime images for qualification
become: true
ansible.builtin.copy:
dest: /var/lib/openshell-qualification/gateway.toml
owner: root
group: root
mode: "0644"
content: |
[openshell]
version = 2
[openshell.drivers.docker]
sandbox_runtime_image = "docker.io/openshell/sandbox:tmachine"
supervisor_image = "docker.io/openshell/supervisor:tmachine"
- name: Create OpenShell environment directory
ansible.builtin.file:
path: /home/tmachine/.config/openshell
state: directory
mode: "0700"
- name: Select qualification gateway configuration
ansible.builtin.copy:
dest: /home/tmachine/.config/openshell/gateway.env
mode: "0600"
content: |
OPENSHELL_GATEWAY_CONFIG=/var/lib/openshell-qualification/gateway.toml
- name: Start tmachine user manager
ansible.builtin.include_role:
name: tmachine_user_manager
- name: Start packaged OpenShell gateway service
ansible.builtin.systemd_service:
name: openshell-gateway.service
scope: user
daemon_reload: true
enabled: true
state: started
environment:
XDG_RUNTIME_DIR: /run/user/1000
DBUS_SESSION_BUS_ADDRESS: unix:path=/run/user/1000/bus
- name: Wait for OpenShell gateway
ansible.builtin.wait_for:
host: 127.0.0.1
port: 17670
timeout: 60
- name: Register packaged OpenShell gateway
ansible.builtin.include_role:
name: openshell_client
vars:
openshell_client_gateway_endpoint: https://127.0.0.1:17670
openshell_client_gateway_name: openshell
+4 -24
View File
@@ -9,29 +9,9 @@
- name: Wait for SSH
ansible.builtin.wait_for_connection:
- name: Enable lingering for tmachine
become: true
ansible.builtin.command:
argv:
- loginctl
- enable-linger
- tmachine
changed_when: false
- name: Resolve tmachine UID
ansible.builtin.command:
argv:
- id
- -u
- tmachine
changed_when: false
register: tmachine_uid
- name: Start tmachine user manager
become: true
ansible.builtin.systemd_service:
name: "user@{{ tmachine_uid.stdout }}.service"
state: started
ansible.builtin.include_role:
name: tmachine_user_manager
- name: Enable rootless Podman socket
become: true
@@ -43,5 +23,5 @@
state: started
environment:
HOME: /home/tmachine
XDG_RUNTIME_DIR: "/run/user/{{ tmachine_uid.stdout }}"
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ tmachine_uid.stdout }}/bus"
XDG_RUNTIME_DIR: /run/user/1000
DBUS_SESSION_BUS_ADDRESS: unix:path=/run/user/1000/bus
@@ -2,13 +2,13 @@
# SPDX-License-Identifier: Apache-2.0
---
- name: Register OpenShell gateway for tmachine test client
- name: Register OpenShell gateway for test client
ansible.builtin.command:
argv:
- /usr/local/bin/openshell
- openshell
- gateway
- add
- http://127.0.0.1:17670
- "{{ openshell_client_gateway_endpoint | default('http://127.0.0.1:17670') }}"
- --local
- --name
- tmachine
- "{{ openshell_client_gateway_name | default('tmachine') }}"
@@ -43,7 +43,7 @@
become_user: "{{ openshell_gateway_user }}"
ansible.builtin.command:
argv:
- /usr/local/bin/openshell-gateway
- openshell-gateway
- generate-certs
- --output-dir
- /var/lib/openshell/pki
@@ -11,7 +11,7 @@ User={{ openshell_gateway_user }}
Group={{ openshell_gateway_user }}
Environment=HOME={{ openshell_gateway_home }}
{% block service %}{% endblock %}
ExecStart=/usr/local/bin/openshell-gateway --config /etc/openshell/gateway.toml
ExecStart=openshell-gateway --config /etc/openshell/gateway.toml
Restart=on-failure
[Install]
@@ -0,0 +1,18 @@
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
---
- name: Enable lingering for tmachine
become: true
ansible.builtin.command:
argv:
- loginctl
- enable-linger
- tmachine
changed_when: false
- name: Start tmachine user manager
become: true
ansible.builtin.systemd_service:
name: user@1000.service
state: started
+12
View File
@@ -84,6 +84,18 @@ let
openshell_sandbox_image = "../artifacts/images/openshell-sandbox-tmachine.tar";
};
}
{
name = "deb";
use_galaxy = false;
playbooks = [
"ansible/playbooks/openshell-deb.yaml"
];
inputs = {
openshell_deb = "../artifacts/packages/openshell.deb";
openshell_supervisor_image = "../artifacts/images/openshell-supervisor-tmachine.tar";
openshell_sandbox_image = "../artifacts/images/openshell-sandbox-tmachine.tar";
};
}
];
testsuites = [