Offer only what this machine can deliver
The installer knew one distribution: Debian, with docker, on a new enough release. Everything else it would have offered and then failed at. Three facts now decide what the matrix offers, and each is read from the machine rather than assumed: - The container runtime. Docker where the machine has one, podman on the Red Hat family, which ships no docker at all. Both go through the same compose plugin: compose speaks the Docker API and podman serves it, so there is one compose file and one deployment path, not two. Telling a Fedora operator to add Docker's own repository to a machine that already has a container runtime would have been the wrong trade. - glibc. The server binary is downloaded, not built here, and it is linked against 2.39. Rocky 9 (2.34), Debian 12 and Ubuntu 22.04 cannot run it, so the host shape is refused there with the version found and the container shape named as the answer -- rather than installing a file that cannot start. - The operating system itself. This compiles for macOS and Windows because Go compiles anything, and on either it would read no os-release, find no systemd, and describe a machine that does not exist. It now says what it is and exits. Two bugs the other distributions found, both of which Debian could not have: - The survey reported the first thing in the way and stopped, so on Fedora it asked to start podman.socket, and then -- having done it -- asked for the compose plugin. Needs are named now, not described, and reported together. - apply used the survey taken before dependencies were installed, so on a machine that had no runtime at all it installed podman and then reached for docker. It re-surveys after resolving, and stops if containers still are not usable. The lab takes DISTRO now: debian13, debian12, ubuntu2404, fedora, rocky9, arch, each with its own disk and ssh port so several can be up at once. The cases no longer say "docker" either. install-local passes on Debian 13, Fedora 43 and Rocky 9 -- 20 checks each, ending with a sign-in to the webmail the installer put there.
This commit is contained in:
@@ -21,6 +21,20 @@ has() { grep -q -- "$2" <<<"$1" && ok "$3" || { bad "$3"; echo "$1" | tail -20
|
||||
|
||||
DIR=/var/lib/inbuxa
|
||||
|
||||
# Whichever runtime this machine has. The installer picks docker where there
|
||||
# is one and podman on the Red Hat family; a case that says "docker" only
|
||||
# tests half the distributions it is run on.
|
||||
if command -v docker >/dev/null 2>&1; then
|
||||
RT=docker
|
||||
compose() { docker compose -f "$DIR/compose.yaml" "$@"; }
|
||||
else
|
||||
RT=podman
|
||||
compose() {
|
||||
DOCKER_HOST=unix:///run/podman/podman.sock \
|
||||
/usr/local/lib/docker/cli-plugins/docker-compose -f "$DIR/compose.yaml" "$@"
|
||||
}
|
||||
fi
|
||||
|
||||
echo "==> installing"
|
||||
OUT="$(/tmp/inbuxa install --local --domain example.test --install-deps --yes 2>&1)"; rc=$?
|
||||
echo "$OUT" | grep -v '^ |' | tail -24 | sed 's/^/ /'
|
||||
@@ -38,7 +52,7 @@ grep -q "_domainkey" "$DIR/dns.zone" && ok "and the DKIM key it generated" || ba
|
||||
|
||||
echo
|
||||
echo "==> what it left running"
|
||||
STATE="$(docker compose -f $DIR/compose.yaml ps --format '{{.Service}} {{.State}}')"
|
||||
STATE="$(compose ps --format '{{.Service}} {{.State}}')"
|
||||
for s in server console webmail; do
|
||||
grep -q "^$s running" <<<"$STATE" && ok "$s is running" || { bad "$s is not running"; echo "$STATE" | sed 's/^/ /'; }
|
||||
done
|
||||
@@ -52,7 +66,7 @@ curl -fsS http://127.0.0.1:8080/api/health 2>/dev/null | grep -q '"ok":true' &&
|
||||
|
||||
echo
|
||||
echo "==> the bootstrap credential did not outlive the setup"
|
||||
ENVOUT="$(docker inspect --format '{{range .Config.Env}}{{println .}}{{end}}' "$(docker compose -f $DIR/compose.yaml ps -q server)")"
|
||||
ENVOUT="$($RT inspect --format '{{range .Config.Env}}{{println .}}{{end}}' "$(compose ps -q server)")"
|
||||
grep -q "RECOVERY_ADMIN" <<<"$ENVOUT" && { bad "the server still carries a recovery admin"; echo "$ENVOUT" | grep RECOVERY | sed 's/^/ /'; } || ok "no recovery admin in the running server"
|
||||
grep -q "INBUXA_WEBMAIL_CLIENT_SECRET" <<<"$ENVOUT" && ok "the webmail's client secret is where it belongs" || bad "the server has no webmail client secret"
|
||||
|
||||
@@ -70,7 +84,7 @@ grep -q "urn:ietf:params:jmap:mail" /tmp/login.json && ok "and the session carri
|
||||
echo
|
||||
echo "==> running it again converges rather than duplicating"
|
||||
OUT="$(/tmp/inbuxa install --local --domain example.test --yes 2>&1)"; rc=$?
|
||||
COUNT=$(docker compose -f $DIR/compose.yaml ps --format '{{.Service}}' | sort -u | wc -l)
|
||||
COUNT=$(compose ps --format '{{.Service}}' | sort -u | wc -l)
|
||||
[ "$COUNT" = 3 ] && ok "still three services, not six" || bad "$COUNT services after a second run"
|
||||
|
||||
echo
|
||||
|
||||
@@ -26,6 +26,20 @@ MAIL=mx.lab.test # not "mail": proves the names follow --mail-host
|
||||
CONSOLE=console.lab.test
|
||||
WEBMAIL=webmail.lab.test
|
||||
DIR=/var/lib/inbuxa
|
||||
|
||||
# Whichever runtime this machine has. The installer picks docker where there
|
||||
# is one and podman on the Red Hat family; a case that says "docker" only
|
||||
# tests half the distributions it is run on.
|
||||
if command -v docker >/dev/null 2>&1; then
|
||||
RT=docker
|
||||
compose() { docker compose -f "$DIR/compose.yaml" "$@"; }
|
||||
else
|
||||
RT=podman
|
||||
compose() {
|
||||
DOCKER_HOST=unix:///run/podman/podman.sock \
|
||||
/usr/local/lib/docker/cli-plugins/docker-compose -f "$DIR/compose.yaml" "$@"
|
||||
}
|
||||
fi
|
||||
WORK=/tmp/lab
|
||||
LABNET=inbuxa-e2e
|
||||
LABSUBNET=172.31.254.0/24
|
||||
@@ -35,7 +49,7 @@ rm -rf "$WORK"; mkdir -p "$WORK"
|
||||
|
||||
echo "==> what the installer needs, before the lab"
|
||||
/tmp/inbuxa deps --console container --webmail container --install >/dev/null 2>&1 || true
|
||||
docker version >/dev/null 2>&1 && ok "docker is usable" || { bad "no docker"; exit 1; }
|
||||
{ docker version >/dev/null 2>&1 || podman version >/dev/null 2>&1; } && ok "a container runtime is usable" || { bad "no docker"; exit 1; }
|
||||
|
||||
echo
|
||||
echo "==> standing up a private CA and a DNS stub"
|
||||
@@ -145,7 +159,7 @@ CODE=$(curl -s -o /dev/null -w '%{http_code}' --cacert "$WORK/chain.pem" --resol
|
||||
|
||||
echo
|
||||
echo "==> and nothing was left behind that should not be"
|
||||
ENVOUT="$(docker inspect --format '{{range .Config.Env}}{{println .}}{{end}}' "$(docker compose -f $DIR/compose.yaml ps -q server)")"
|
||||
ENVOUT="$($RT inspect --format '{{range .Config.Env}}{{println .}}{{end}}' "$(compose ps -q server)")"
|
||||
grep -q "RECOVERY_ADMIN" <<<"$ENVOUT" && bad "the server still carries a recovery admin" || ok "no recovery admin on the server"
|
||||
|
||||
echo
|
||||
|
||||
Reference in New Issue
Block a user