diff --git a/.github/compose/compose.yaml b/.github/compose/compose.yaml index a8a22eef..0749d38d 100644 --- a/.github/compose/compose.yaml +++ b/.github/compose/compose.yaml @@ -7,6 +7,7 @@ services: environment: CODER_HTTP_ADDRESS: 0.0.0.0:7080 CODER_PG_CONNECTION_URL: postgresql://coder:coder@database/coder?sslmode=disable + CODER_WILDCARD_ACCESS_URL: "*.localhost" KUBECONFIG: /home/coder/.kube/config volumes: - ${CODER_KUBECONFIG}:/home/coder/.kube/config:ro diff --git a/.github/workflows/test-template.yaml b/.github/workflows/test-template.yaml index ddcf9476..f640f528 100644 --- a/.github/workflows/test-template.yaml +++ b/.github/workflows/test-template.yaml @@ -166,6 +166,51 @@ jobs: # this otherwise unrelated readiness check ambiguous. run: coder ping --num 3 --timeout 30s "${WORKSPACE_NAME}.main" + - name: Confirm File Browser sidecar and Coder app + shell: bash + run: | + deployment_name="$(kubectl --namespace coder get deployment \ + --selector "com.coder.workspace.name=${WORKSPACE_NAME}" \ + --output jsonpath='{.items[0].metadata.name}')" + session_token="$(<"${HOME}/.config/coderv2/session")" + + # The second agent is the sidecar's PID 1. Prove Coder can route to it + # before probing the process and application that it owns. + coder ping --num 3 --timeout 30s "${WORKSPACE_NAME}.filebrowser" + + kubectl --namespace coder exec "deployment/${deployment_name}" --container filebrowser -- \ + sh -c 'tr "\0" " " /dev/null + # Expand the command substitution inside the sidecar, not on the runner. + # shellcheck disable=SC2016 + kubectl --namespace coder exec "deployment/${deployment_name}" --container filebrowser -- \ + sh -c 'test "$(cat /srv/.filebrowser-sidecar-test)" = workspace && printf sidecar > /srv/.filebrowser-sidecar-test' + [[ "$(coder ssh "${WORKSPACE_NAME}.main" -- cat /home/coder/.filebrowser-sidecar-test)" == "sidecar" ]] + + # File Browser requires the subdomain proxy because its root-relative + # assets cannot survive Coder's path-prefix stripping. Exercise both the + # configured home source and frontend through that proxy, not only the + # Pod-local listener. + app_url="http://files--${WORKSPACE_NAME}--ci.localhost:7080" + served_marker="$(curl --fail --silent --show-error \ + --header "Coder-Session-Token: ${session_token}" \ + "${app_url}/api/resources/download?source=srv&file=/.filebrowser-sidecar-test")" + [[ "${served_marker}" == "sidecar" ]] + app_html="$(curl --fail --silent --show-error \ + --header "Coder-Session-Token: ${session_token}" "${app_url}/")" + grep --quiet '