Offer only what this machine can deliver

The installer knew one distribution: Debian, with docker, on a new enough
release. Everything else it would have offered and then failed at.

Three facts now decide what the matrix offers, and each is read from the
machine rather than assumed:

- The container runtime. Docker where the machine has one, podman on the Red
  Hat family, which ships no docker at all. Both go through the same compose
  plugin: compose speaks the Docker API and podman serves it, so there is one
  compose file and one deployment path, not two. Telling a Fedora operator to
  add Docker's own repository to a machine that already has a container
  runtime would have been the wrong trade.

- glibc. The server binary is downloaded, not built here, and it is linked
  against 2.39. Rocky 9 (2.34), Debian 12 and Ubuntu 22.04 cannot run it, so
  the host shape is refused there with the version found and the container
  shape named as the answer -- rather than installing a file that cannot
  start.

- The operating system itself. This compiles for macOS and Windows because Go
  compiles anything, and on either it would read no os-release, find no
  systemd, and describe a machine that does not exist. It now says what it is
  and exits.

Two bugs the other distributions found, both of which Debian could not have:

- The survey reported the first thing in the way and stopped, so on Fedora it
  asked to start podman.socket, and then -- having done it -- asked for the
  compose plugin. Needs are named now, not described, and reported together.

- apply used the survey taken before dependencies were installed, so on a
  machine that had no runtime at all it installed podman and then reached for
  docker. It re-surveys after resolving, and stops if containers still are
  not usable.

The lab takes DISTRO now: debian13, debian12, ubuntu2404, fedora, rocky9,
arch, each with its own disk and ssh port so several can be up at once. The
cases no longer say "docker" either. install-local passes on Debian 13,
Fedora 43 and Rocky 9 -- 20 checks each, ending with a sign-in to the webmail
the installer put there.
This commit is contained in:
2026-09-22 22:22:45 -07:00
parent 8725d8c11b
commit e55ff6b2df
14 changed files with 525 additions and 96 deletions
+17 -3
View File
@@ -21,6 +21,20 @@ has() { grep -q -- "$2" <<<"$1" && ok "$3" || { bad "$3"; echo "$1" | tail -20
DIR=/var/lib/inbuxa
# Whichever runtime this machine has. The installer picks docker where there
# is one and podman on the Red Hat family; a case that says "docker" only
# tests half the distributions it is run on.
if command -v docker >/dev/null 2>&1; then
RT=docker
compose() { docker compose -f "$DIR/compose.yaml" "$@"; }
else
RT=podman
compose() {
DOCKER_HOST=unix:///run/podman/podman.sock \
/usr/local/lib/docker/cli-plugins/docker-compose -f "$DIR/compose.yaml" "$@"
}
fi
echo "==> installing"
OUT="$(/tmp/inbuxa install --local --domain example.test --install-deps --yes 2>&1)"; rc=$?
echo "$OUT" | grep -v '^ |' | tail -24 | sed 's/^/ /'
@@ -38,7 +52,7 @@ grep -q "_domainkey" "$DIR/dns.zone" && ok "and the DKIM key it generated" || ba
echo
echo "==> what it left running"
STATE="$(docker compose -f $DIR/compose.yaml ps --format '{{.Service}} {{.State}}')"
STATE="$(compose ps --format '{{.Service}} {{.State}}')"
for s in server console webmail; do
grep -q "^$s running" <<<"$STATE" && ok "$s is running" || { bad "$s is not running"; echo "$STATE" | sed 's/^/ /'; }
done
@@ -52,7 +66,7 @@ curl -fsS http://127.0.0.1:8080/api/health 2>/dev/null | grep -q '"ok":true' &&
echo
echo "==> the bootstrap credential did not outlive the setup"
ENVOUT="$(docker inspect --format '{{range .Config.Env}}{{println .}}{{end}}' "$(docker compose -f $DIR/compose.yaml ps -q server)")"
ENVOUT="$($RT inspect --format '{{range .Config.Env}}{{println .}}{{end}}' "$(compose ps -q server)")"
grep -q "RECOVERY_ADMIN" <<<"$ENVOUT" && { bad "the server still carries a recovery admin"; echo "$ENVOUT" | grep RECOVERY | sed 's/^/ /'; } || ok "no recovery admin in the running server"
grep -q "INBUXA_WEBMAIL_CLIENT_SECRET" <<<"$ENVOUT" && ok "the webmail's client secret is where it belongs" || bad "the server has no webmail client secret"
@@ -70,7 +84,7 @@ grep -q "urn:ietf:params:jmap:mail" /tmp/login.json && ok "and the session carri
echo
echo "==> running it again converges rather than duplicating"
OUT="$(/tmp/inbuxa install --local --domain example.test --yes 2>&1)"; rc=$?
COUNT=$(docker compose -f $DIR/compose.yaml ps --format '{{.Service}}' | sort -u | wc -l)
COUNT=$(compose ps --format '{{.Service}}' | sort -u | wc -l)
[ "$COUNT" = 3 ] && ok "still three services, not six" || bad "$COUNT services after a second run"
echo
+16 -2
View File
@@ -26,6 +26,20 @@ MAIL=mx.lab.test # not "mail": proves the names follow --mail-host
CONSOLE=console.lab.test
WEBMAIL=webmail.lab.test
DIR=/var/lib/inbuxa
# Whichever runtime this machine has. The installer picks docker where there
# is one and podman on the Red Hat family; a case that says "docker" only
# tests half the distributions it is run on.
if command -v docker >/dev/null 2>&1; then
RT=docker
compose() { docker compose -f "$DIR/compose.yaml" "$@"; }
else
RT=podman
compose() {
DOCKER_HOST=unix:///run/podman/podman.sock \
/usr/local/lib/docker/cli-plugins/docker-compose -f "$DIR/compose.yaml" "$@"
}
fi
WORK=/tmp/lab
LABNET=inbuxa-e2e
LABSUBNET=172.31.254.0/24
@@ -35,7 +49,7 @@ rm -rf "$WORK"; mkdir -p "$WORK"
echo "==> what the installer needs, before the lab"
/tmp/inbuxa deps --console container --webmail container --install >/dev/null 2>&1 || true
docker version >/dev/null 2>&1 && ok "docker is usable" || { bad "no docker"; exit 1; }
{ docker version >/dev/null 2>&1 || podman version >/dev/null 2>&1; } && ok "a container runtime is usable" || { bad "no docker"; exit 1; }
echo
echo "==> standing up a private CA and a DNS stub"
@@ -145,7 +159,7 @@ CODE=$(curl -s -o /dev/null -w '%{http_code}' --cacert "$WORK/chain.pem" --resol
echo
echo "==> and nothing was left behind that should not be"
ENVOUT="$(docker inspect --format '{{range .Config.Env}}{{println .}}{{end}}' "$(docker compose -f $DIR/compose.yaml ps -q server)")"
ENVOUT="$($RT inspect --format '{{range .Config.Env}}{{println .}}{{end}}' "$(compose ps -q server)")"
grep -q "RECOVERY_ADMIN" <<<"$ENVOUT" && bad "the server still carries a recovery admin" || ok "no recovery admin on the server"
echo
+5 -3
View File
@@ -5,11 +5,13 @@
# Stop the lab machine and remove its disks. The base image stays, so up.sh
# is quick the next time; --all takes that too.
set -euo pipefail
LAB="${LAB:-$HOME/.cache/inbuxa-lab}"
SSH_PORT="${SSH_PORT:-2222}"
. "$(dirname "$0")/lib.sh"
DISTRO="${DISTRO:-debian13}"
LAB="${LAB:-$HOME/.cache/inbuxa-lab/$DISTRO}"
SSH_PORT="${SSH_PORT:-$(distro_port "$DISTRO")}"
DISK="$LAB/lab.qcow2"; CLEAN="$LAB/lab-clean.qcow2"; SEED="$LAB/seed.iso"
LOG="$LAB/console.log"; PIDFILE="$LAB/qemu.pid"
. "$(dirname "$0")/lib.sh"
vm_stop
rm -f "$DISK" "$CLEAN" "$SEED" "$PIDFILE" "$LAB/monitor.sock"
+40 -1
View File
@@ -2,7 +2,11 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
#
# Shared by the four scripts beside it: how the lab machine is started,
# stopped and talked to. Sourced, never run.
# stopped and talked to, and which distribution it runs. Sourced, never run.
#
# One lab per distribution, each with its own directory, disk and ssh port,
# so Fedora and Debian can be up at once and a case can be run against both
# without either noticing the other.
#
# One machine at a time, identified by its pid file. qemu is given a monitor
# on a unix socket so a stop is a clean powerdown rather than pulling the
@@ -13,6 +17,41 @@
# the machine resets in a loop at "Booting Debian GNU/Linux" forever. -display
# none is what makes it headless; the adapter has to be there.
# The distributions this installer claims to support: Debian and Red Hat and
# Arch, and the derivatives people actually run. Each is the distribution's
# own cloud image, which is cloud-init seeded and needs no interaction.
#
# Fedora and Rocky are here because they are where the interesting
# differences live: podman instead of docker, firewalld on by default, and --
# on Rocky -- a glibc older than the server binary needs.
distro_image() {
case "${1:-debian13}" in
debian13) echo "https://cloud.debian.org/images/cloud/trixie/latest/debian-13-genericcloud-amd64.qcow2" ;;
debian12) echo "https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-genericcloud-amd64.qcow2" ;;
ubuntu2404) echo "https://cloud-images.ubuntu.com/releases/24.04/release/ubuntu-24.04-server-cloudimg-amd64.img" ;;
# Fedora's image name carries a build number that changes with every
# release, so this is pinned rather than guessed; check the mirror index
# when moving it.
fedora) echo "https://dl.fedoraproject.org/pub/fedora/linux/releases/43/Cloud/x86_64/images/Fedora-Cloud-Base-Generic-43-1.6.x86_64.qcow2" ;;
rocky9) echo "https://download.rockylinux.org/pub/rocky/9/images/x86_64/Rocky-9-GenericCloud.latest.x86_64.qcow2" ;;
arch) echo "https://geo.mirror.pkgbuild.com/images/latest/Arch-Linux-x86_64-cloudimg.qcow2" ;;
*) echo "" ;;
esac
}
# Each lab gets its own ssh port, so several can be up at once.
distro_port() {
case "${1:-debian13}" in
debian13) echo 2222 ;;
debian12) echo 2223 ;;
ubuntu2404) echo 2224 ;;
fedora) echo 2225 ;;
rocky9) echo 2226 ;;
arch) echo 2227 ;;
*) echo 2222 ;;
esac
}
vm_running() {
[ -f "$PIDFILE" ] && kill -0 "$(cat "$PIDFILE")" 2>/dev/null
}
+5 -3
View File
@@ -6,11 +6,13 @@
# machine is as fresh as a new VPS -- which is what makes a test run free to
# create users, write units and take ports.
set -euo pipefail
LAB="${LAB:-$HOME/.cache/inbuxa-lab}"
MEM="${MEM:-4096}"; VCPUS="${VCPUS:-2}"; SSH_PORT="${SSH_PORT:-2222}"
. "$(dirname "$0")/lib.sh"
DISTRO="${DISTRO:-debian13}"
LAB="${LAB:-$HOME/.cache/inbuxa-lab/$DISTRO}"
MEM="${MEM:-4096}"; VCPUS="${VCPUS:-2}"; SSH_PORT="${SSH_PORT:-$(distro_port "$DISTRO")}"
DISK="$LAB/lab.qcow2"; CLEAN="$LAB/lab-clean.qcow2"; SEED="$LAB/seed.iso"
LOG="$LAB/console.log"; PIDFILE="$LAB/qemu.pid"
. "$(dirname "$0")/lib.sh"
[ -f "$CLEAN" ] || { echo "no clean copy -- run e2e/vm/up.sh first" >&2; exit 1; }
+5 -3
View File
@@ -12,11 +12,13 @@
set -euo pipefail
CASE="${1:?usage: run.sh e2e/cases/<case>.sh}"
ROOT="$(cd "$(dirname "$0")/../.." && pwd)"
LAB="${LAB:-$HOME/.cache/inbuxa-lab}"
MEM="${MEM:-4096}"; VCPUS="${VCPUS:-2}"; SSH_PORT="${SSH_PORT:-2222}"
. "$(dirname "$0")/lib.sh"
DISTRO="${DISTRO:-debian13}"
LAB="${LAB:-$HOME/.cache/inbuxa-lab/$DISTRO}"
MEM="${MEM:-4096}"; VCPUS="${VCPUS:-2}"; SSH_PORT="${SSH_PORT:-$(distro_port "$DISTRO")}"
DISK="$LAB/lab.qcow2"; CLEAN="$LAB/lab-clean.qcow2"; SEED="$LAB/seed.iso"
LOG="$LAB/console.log"; PIDFILE="$LAB/qemu.pid"
. "$(dirname "$0")/lib.sh"
[ -f "$ROOT/$CASE" ] || { echo "no such case: $CASE" >&2; exit 1; }
[ "${KEEP:-}" = 1 ] || "$(dirname "$0")/reset.sh"
+18 -8
View File
@@ -7,10 +7,17 @@
# The installer writes units, creates users, takes 25 and 443 and can install
# a web server. None of that belongs on a workstation, and none of it can be
# proved in a container either -- systemd, users and ports are the thing under
# test. So: a Debian cloud image in qemu, seeded with cloud-init, with a copy
# of the disk kept the moment it is up. Every run starts from that copy, so a
# run can break the machine as thoroughly as it likes.
# test. So: a distribution's own cloud image in qemu, seeded with cloud-init,
# with a copy of the disk kept the moment it is up. Every run starts from that
# copy, so a run can break the machine as thoroughly as it likes.
#
# DISTRO picks which: debian13 (the default), debian12, ubuntu2404, fedora,
# rocky9 or arch. They are not interchangeable, which is the point -- podman
# rather than docker on the Red Hat family, firewalld on by default there, and
# a glibc on Rocky 9 older than the server binary needs. Each has its own
# directory and ssh port, so several can be up at once.
#
# DISTRO=fedora e2e/vm/up.sh
# e2e/vm/up.sh build it and keep a clean copy (idempotent)
# e2e/vm/reset.sh back to the clean copy, a few seconds
# e2e/vm/run.sh build the installer, copy it in, run a case inside
@@ -24,13 +31,16 @@
# Needs: qemu-system-x86_64, /dev/kvm, xorriso, ssh, curl.
set -euo pipefail
LAB="${LAB:-$HOME/.cache/inbuxa-lab}"
. "$(dirname "$0")/lib.sh"
DISTRO="${DISTRO:-debian13}"
LAB="${LAB:-$HOME/.cache/inbuxa-lab/$DISTRO}"
MEM="${MEM:-4096}"
VCPUS="${VCPUS:-2}"
DISK_GB="${DISK_GB:-20}"
SSH_PORT="${SSH_PORT:-2222}"
BASE_URL="https://cloud.debian.org/images/cloud/trixie/latest/debian-13-genericcloud-amd64.qcow2"
BASE="$LAB/debian-13-base.qcow2"
SSH_PORT="${SSH_PORT:-$(distro_port "$DISTRO")}"
BASE_URL="${BASE_URL:-$(distro_image "$DISTRO")}"
BASE="$LAB/base.qcow2"
DISK="$LAB/lab.qcow2"
CLEAN="$LAB/lab-clean.qcow2"
SEED="$LAB/seed.iso"
@@ -39,8 +49,8 @@ PIDFILE="$LAB/qemu.pid"
KEY="${KEY:-$HOME/.ssh/id_ed25519.pub}"
say() { echo "==> $*"; }
. "$(dirname "$0")/lib.sh"
[ -n "$BASE_URL" ] || { echo "unknown distribution '$DISTRO' (debian13, debian12, ubuntu2404, fedora, rocky9, arch)" >&2; exit 1; }
[ -r "$KEY" ] || { echo "no public key at $KEY (set KEY=)" >&2; exit 1; }
[ -w /dev/kvm ] || { echo "no writable /dev/kvm -- is this user in the kvm group?" >&2; exit 1; }