From bf24dde8873318b7c33433f2b2aeedbac10b5382 Mon Sep 17 00:00:00 2001 From: Peter Pathirana Date: Wed, 16 Sep 2026 22:29:12 +0000 Subject: [PATCH] ci(internal-workflows): test File Browser sidecar --- .github/compose/compose.yaml | 1 + .github/workflows/test-template.yaml | 60 ++++++++++++++++++- .../homelab-workspace/deployment.tf | 2 +- 3 files changed, 61 insertions(+), 2 deletions(-) diff --git a/.github/compose/compose.yaml b/.github/compose/compose.yaml index a8a22eef..0749d38d 100644 --- a/.github/compose/compose.yaml +++ b/.github/compose/compose.yaml @@ -7,6 +7,7 @@ services: environment: CODER_HTTP_ADDRESS: 0.0.0.0:7080 CODER_PG_CONNECTION_URL: postgresql://coder:coder@database/coder?sslmode=disable + CODER_WILDCARD_ACCESS_URL: "*.localhost" KUBECONFIG: /home/coder/.kube/config volumes: - ${CODER_KUBECONFIG}:/home/coder/.kube/config:ro diff --git a/.github/workflows/test-template.yaml b/.github/workflows/test-template.yaml index ddcf9476..f640f528 100644 --- a/.github/workflows/test-template.yaml +++ b/.github/workflows/test-template.yaml @@ -166,6 +166,51 @@ jobs: # this otherwise unrelated readiness check ambiguous. run: coder ping --num 3 --timeout 30s "${WORKSPACE_NAME}.main" + - name: Confirm File Browser sidecar and Coder app + shell: bash + run: | + deployment_name="$(kubectl --namespace coder get deployment \ + --selector "com.coder.workspace.name=${WORKSPACE_NAME}" \ + --output jsonpath='{.items[0].metadata.name}')" + session_token="$(<"${HOME}/.config/coderv2/session")" + + # The second agent is the sidecar's PID 1. Prove Coder can route to it + # before probing the process and application that it owns. + coder ping --num 3 --timeout 30s "${WORKSPACE_NAME}.filebrowser" + + kubectl --namespace coder exec "deployment/${deployment_name}" --container filebrowser -- \ + sh -c 'tr "\0" " " /dev/null + # Expand the command substitution inside the sidecar, not on the runner. + # shellcheck disable=SC2016 + kubectl --namespace coder exec "deployment/${deployment_name}" --container filebrowser -- \ + sh -c 'test "$(cat /srv/.filebrowser-sidecar-test)" = workspace && printf sidecar > /srv/.filebrowser-sidecar-test' + [[ "$(coder ssh "${WORKSPACE_NAME}.main" -- cat /home/coder/.filebrowser-sidecar-test)" == "sidecar" ]] + + # File Browser requires the subdomain proxy because its root-relative + # assets cannot survive Coder's path-prefix stripping. Exercise both the + # configured home source and frontend through that proxy, not only the + # Pod-local listener. + app_url="http://files--${WORKSPACE_NAME}--ci.localhost:7080" + served_marker="$(curl --fail --silent --show-error \ + --header "Coder-Session-Token: ${session_token}" \ + "${app_url}/api/resources/download?source=srv&file=/.filebrowser-sidecar-test")" + [[ "${served_marker}" == "sidecar" ]] + app_html="$(curl --fail --silent --show-error \ + --header "Coder-Session-Token: ${session_token}" "${app_url}/")" + grep --quiet '' <<<"${app_html}" + asset_path="$(grep --only-matching --max-count=1 '/public/static/[^"]*' <<<"${app_html}")" + [[ -n "${asset_path}" ]] + curl --fail --silent --show-error \ + --header "Coder-Session-Token: ${session_token}" \ + --output /dev/null "${app_url}${asset_path}" + - name: Run command over workspace SSH shell: bash run: | @@ -315,4 +360,17 @@ jobs: - name: Show Coder logs on failure if: failure() - run: docker compose -f "${COMPOSE_FILE}" logs + shell: bash + run: | + kubectl --namespace coder get pods --output wide || true + kubectl --namespace coder logs \ + --selector "com.coder.workspace.name=${WORKSPACE_NAME}" \ + --all-containers --prefix --tail=200 || true + pod_name="$(kubectl --namespace coder get pods \ + --selector "com.coder.workspace.name=${WORKSPACE_NAME}" \ + --output jsonpath='{.items[0].metadata.name}')" + kubectl --namespace coder exec "pod/${pod_name}" --container filebrowser -- \ + cat /tmp/coder-startup-script.log || true + kubectl --namespace coder exec "pod/${pod_name}" --container filebrowser -- \ + cat /tmp/filebrowser.log || true + docker compose -f "${COMPOSE_FILE}" logs diff --git a/templates/kubernetes/homelab-workspace/deployment.tf b/templates/kubernetes/homelab-workspace/deployment.tf index 5d77f406..757479af 100644 --- a/templates/kubernetes/homelab-workspace/deployment.tf +++ b/templates/kubernetes/homelab-workspace/deployment.tf @@ -162,7 +162,7 @@ resource "kubernetes_deployment_v1" "deployment" { value = "/home/filebrowser/data" } env { - name = "USER" + name = "USER" # The image's filebrowser account uses /bin/true. The agent uses # this account only to select a shell; the Pod still enforces the # non-root UID below.