Some polishes to new registry-image source props

- missing doc hovers
- test cases
- aws-region validation / completion
This commit is contained in:
Kris De Volder
2022-06-02 11:30:34 -07:00
parent 2ae3c80eb8
commit 02bae6af46
4 changed files with 94 additions and 36 deletions

View File

@@ -157,14 +157,32 @@ public class PipelineYmlSchema implements YamlSchema {
public final YType t_semver = f.yatomic("Semver")
.parseWith(ValueParsers.NE_STRING); //TODO: use real semver parser.
public final YType t_s3_region = f.yenum("S3Region",
//See: https://docs.aws.amazon.com/AmazonS3/latest/API/RESTBucketPUT.html
"us-west-1", "us-west-2",
"ca-central-1", "EU", "eu-west-1",
"eu-west-2", "eu-central-1",
"ap-south-1", "ap-southeast-1", "ap-southeast-2", "ap-northeast-1", "ap-northeast-2",
"sa-east-1",
"us-east-2"
public final YType t_aws_region = f.yenum("AWSRegion",
//See https://docs.aws.amazon.com/general/latest/gr/rande.html
"af-south-1",
"ap-east-1",
"ap-southeast-3",
"ap-south-1",
"ap-northeast-3",
"ap-northeast-2",
"ap-southeast-1",
"ap-southeast-2",
"ap-northeast-1",
"ca-central-1",
"cn-north-1",
"cn-northwest-1",
"eu-central-1",
"eu-west-1",
"eu-west-2",
"eu-south-1",
"eu-west-3",
"eu-north-1",
"me-south-1",
"us-east-1",
"us-east-2",
"us-west-1",
"us-west-2",
"sa-east-1"
);
public final YType t_day = f.yenum("Day",
@@ -673,7 +691,7 @@ public class PipelineYmlSchema implements YamlSchema {
resourceTypes.def("docker-image", source, get, put);
}
//registry_image
//registry-image
{
AbstractType source = f.ybean("RegistryImageSource");
addProp(source, "repository", t_ne_string).isPrimary(true);
@@ -686,7 +704,7 @@ public class PipelineYmlSchema implements YamlSchema {
addProp(source, "aws_access_key_id", t_ne_string);
addProp(source, "aws_secret_access_key", t_ne_string);
addProp(source, "aws_session_token", t_ne_string);
addProp(source, "aws_region", t_ne_string);
addProp(source, "aws_region", t_aws_region);
addProp(source, "aws_role_arn", t_ne_string);
addProp(source, "aws_role_arns", t_strings);
addProp(source, "debug", t_boolean);
@@ -715,6 +733,8 @@ public class PipelineYmlSchema implements YamlSchema {
addProp(put, "additional_tags", t_ne_string);
resourceTypes.def("registry-image", source, get, put);
source.require(Constraints.mutuallyExclusive("aws_role_arn", "aws_role_arns"));
}
//s3
{
@@ -730,7 +750,7 @@ public class PipelineYmlSchema implements YamlSchema {
addProp(source, "access_key_id", t_ne_string);
addProp(source, "secret_access_key", t_ne_string);
addProp(source, "session_token", t_ne_string);
addProp(source, "region_name", t_s3_region);
addProp(source, "region_name", t_aws_region);
addProp(source, "private", t_boolean);
addProp(source, "cloudfront_url", t_ne_string);
addProp(source, "endpoint", t_ne_string);
@@ -806,7 +826,7 @@ public class PipelineYmlSchema implements YamlSchema {
addProp(s3_source, "key", t_ne_string).isRequired(true);
addProp(s3_source, "access_key_id", t_ne_string).isRequired(true);
addProp(s3_source, "secret_access_key", t_ne_string).isRequired(true);
addProp(s3_source, "region_name", t_s3_region);
addProp(s3_source, "region_name", t_aws_region);
addProp(s3_source, "endpoint", t_ne_string);
addProp(s3_source, "disable_ssl", t_boolean);

View File

@@ -0,0 +1 @@
*Optional.* Hostname and credentials pointing to a docker registry mirror service.

View File

@@ -2603,30 +2603,6 @@ public class ConcourseEditorTest {
"my-docker-image|Unused 'Resource'",
"source|'repository' is required"
);
editor = harness.newEditor(
"resources:\n" +
"- name: my-docker-image\n" +
" type: registry-image\n" +
" source:\n" +
" repository: kdvolder/sts4-build-env\n" +
" tag: latest\n" +
" username: kdvolder\n" +
" password: {{docker_password}}\n" +
" debug: no-bool\n" +
" content_trust: {}\n"
);
editor.assertProblems(
"my-docker-image|Unused 'Resource'",
"no-bool|boolean",
"content_trust|Properties [repository_key, repository_key_id, repository_passphrase] are required"
);
editor.assertHoverContains("repository", "The name of the repository");
editor.assertHoverContains("tag", "name of the tag");
editor.assertHoverContains("username", "username to use");
editor.assertHoverContains("password", "password to use");
editor.assertHoverContains("debug", "debugging output will be printed");
editor = harness.newEditor(
"resources:\n" +
@@ -2634,6 +2610,63 @@ public class ConcourseEditorTest {
" type: registry-image\n" +
" source:\n" +
" repository: kdvolder/sts4-build-env\n" +
" insecure: this-is-not-safe\n" +
" tag: latest\n" +
" variant: some-suffix\n" +
" semver_constraint: invalid-semver-exp\n" +
" username: kdvolder\n" +
" password: {{docker_password}}\n" +
" aws_access_key_id: the-key-to-aws\n" +
" aws_secret_access_key: the-aws-secret\n" +
" aws_session_token: aws-is-in-session\n" +
" aws_region: bad-aws-region\n" +
" aws_role_arn: some-arn\n" +
" aws_role_arns: a-list-of-arns\n" +
" debug: no-bool\n" +
" registry_mirror: {}\n" +
" content_trust: {}\n"
);
editor.assertProblems(
"my-docker-image|Unused 'Resource'",
"this-is-not-safe|boolean",
//"invalid-semver-exp|Invalid semver constraint", //TODO: parse / check this?
"bad-aws-region|AWSRegion",
"aws_role_arn|Only one of 'aws_role_arn' and 'aws_role_arns'",
"aws_role_arns|Only one of 'aws_role_arn' and 'aws_role_arns'",
"a-list-of-arns|Expecting a 'Sequence'",
"no-bool|boolean",
"registry_mirror|'host' is required",
"content_trust|Properties [repository_key, repository_key_id, repository_passphrase] are required"
);
editor.assertHoverContains("repository", "The name of the repository");
editor.assertHoverContains("insecure", "Allow insecure registry");
editor.assertHoverContains("tag", "name of the tag");
editor.assertHoverContains("variant", "variant suffix");
editor.assertHoverContains("semver_constraint", "Constrain the returned semver");
editor.assertHoverContains("username", "username to use");
editor.assertHoverContains("password", "password to use");
editor.assertHoverContains("aws_access_key_id", "access key ID to use for authenticating with ECR");
editor.assertHoverContains("aws_secret_access_key", "secret access key to use for authenticating with ECR");
editor.assertHoverContains("aws_session_token", "session token to use");
editor.assertHoverContains("aws_region", "region to use");
editor.assertHoverContains("aws_role_arn", "this role will");
editor.assertHoverContains("aws_role_arns", "assumed in the specified order");
editor.assertHoverContains("debug", "debugging output will be printed");
editor.assertHoverContains("registry_mirror", "pointing to a docker registry mirror service");
editor = harness.newEditor(
"resources:\n" +
"- name: my-docker-image\n" +
" type: registry-image\n" +
" source:\n" +
" repository: kdvolder/sts4-build-env\n" +
" registry_mirror:\n" +
" host: mirrorhost\n" +
" username: mirroruser\n" +
" password: mirrorpass\n" +
" not_expected_in_mirror: bad\n" +
" content_trust:\n"+
" server: notary.server\n" +
" repository_key: repokey\n" +
@@ -2645,8 +2678,12 @@ public class ConcourseEditorTest {
);
editor.assertProblems(
"my-docker-image|Unused 'Resource'",
"not_expected_in_mirror|Unknown property",
"bogus_prop|Unknown property"
);
editor.assertHoverContains("host", "hostname pointing to a Docker registry");
editor.assertHoverContains("username", "username to use");
editor.assertHoverContains("password", "password to use");
editor.assertHoverContains("server", "URL for the notary server");
editor.assertHoverContains("repository_key_id", "ID used to sign the trusted collection");
editor.assertHoverContains("repository_key", "Target key used to sign");