This is an automated email from the ASF dual-hosted git repository.

smolnar82 pushed a commit to branch knox_idf
in repository https://gitbox.apache.org/repos/asf/knox.git

commit 8d6840b29069b3232a2a099732637a884e80bd44
Author: Sandor Molnar <[email protected]>
AuthorDate: Wed Aug 12 11:51:36 2026 +0200

    KNOX-3414: run KnoxIDF federation E2E tests optionally in PRs
---
 .github/PULL_REQUEST_TEMPLATE.md | 10 +++++++
 .github/workflows/tests.yml      | 56 ++++++++++++++++++++++++++++++++++++++++
 2 files changed, 66 insertions(+)

diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md
index ffec53663..d41f88fd3 100644
--- a/.github/PULL_REQUEST_TEMPLATE.md
+++ b/.github/PULL_REQUEST_TEMPLATE.md
@@ -13,6 +13,16 @@
 ## Integration Tests
 (Please add or update integration tests 
[`.github/workflows/tests`](.github/workflows/tests) for the feature you are 
adding. If no unit test is added, please explain why. Check out 
[`.github/workflows/tests/README.md`](./workflows/tests/README.md) for 
instructions)
 
+### Opt-in test suites (PR labels)
+Some integration suites are expensive and are **not** run on every PR. Add the 
corresponding label to this PR to run them:
+
+| Label | Runs |
+|-------|------|
+| `test-federation` | KnoxIDF federation E2E (`test_knoxidf_federation.py`). 
Stands up a real Keycloak as an external OpenID Provider and drives the full 
broker flow. Adds a few minutes (image pull + realm import). |
+| `skip-tests` | Skips the entire Docker Compose test job. |
+
+**When to add the label:** these labels only take effect on runs triggered by 
opening the PR, pushing a commit, or reopening the PR — the workflow does not 
run on a label change. Add the label **before opening the PR** (or before your 
next push). Adding it after the checks have already finished will **not** start 
a new run; push a commit or close/reopen the PR to trigger one with the label 
applied.
+
 ## UI changes
 (If this patch involves UI changes, please attach a screen-shot; otherwise, 
remove this)
 
diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml
index 9fbd80c41..5c39d25d2 100644
--- a/.github/workflows/tests.yml
+++ b/.github/workflows/tests.yml
@@ -69,6 +69,61 @@ jobs:
           # Run the tests service defined in docker-compose.yml
           docker compose -f ./.github/workflows/compose/docker-compose.yml up 
--exit-code-from tests tests
 
+      # KnoxIDF federation E2E runs only when the PR carries the 
'test-federation'
+      # label. It stands up a real Keycloak (external OpenID Provider) via the
+      # override compose file and pulls a multi-hundred-MB image plus minutes 
of
+      # realm import, so it is opt-in rather than on every PR. It runs here, 
before
+      # the single-EKU steps, so 'knox' is still in its base (non-mTLS) 
config; the
+      # override only adds a keycloak dependency to knox, it does not 
reconfigure it.
+      - name: Start Keycloak + Knox for federation
+        if: contains(github.event.pull_request.labels.*.name, 
'test-federation')
+        run: |
+          # 'up -d knox' blocks until keycloak is service_healthy (override 
depends_on).
+          docker compose \
+            -f ./.github/workflows/compose/docker-compose.yml \
+            -f 
./.github/workflows/compose/docker-compose.knoxidf-federation.yml \
+            up -d knox keycloak
+
+      - name: Wait for federation stack to stabilize
+        if: contains(github.event.pull_request.labels.*.name, 
'test-federation')
+        run: sleep 30  # Adjust as needed for services startup time
+
+      - name: Run KnoxIDF Federation Tests
+        id: knoxidf_federation_tests
+        if: contains(github.event.pull_request.labels.*.name, 
'test-federation')
+        run: |
+          # Emit a distinct JUnit file so it reports as its own test suite.
+          docker compose \
+            -f ./.github/workflows/compose/docker-compose.yml \
+            -f 
./.github/workflows/compose/docker-compose.knoxidf-federation.yml \
+            run --rm tests bash -c "pip install -r requirements.txt \
+            && pytest test_knoxidf_federation.py 
--junitxml=test-results-federation.xml"
+
+      # Evidence gathering mirrors the single-EKU dumps: on a federation 
failure,
+      # capture container status and the knox + keycloak logs so a broker-flow
+      # failure (bad callback/issuer/JWKS) can be told apart from a Keycloak 
that
+      # never came up.
+      - name: Dump federation diagnostics on failure
+        if: failure() && steps.knoxidf_federation_tests.outcome == 'failure'
+        run: |
+          echo '===== docker compose ps -a ====='
+          docker compose \
+            -f ./.github/workflows/compose/docker-compose.yml \
+            -f 
./.github/workflows/compose/docker-compose.knoxidf-federation.yml \
+            ps -a || true
+          echo '===== knox container logs ====='
+          docker compose \
+            -f ./.github/workflows/compose/docker-compose.yml \
+            -f 
./.github/workflows/compose/docker-compose.knoxidf-federation.yml \
+            logs --no-color knox || true
+          echo '===== keycloak container logs ====='
+          docker compose \
+            -f ./.github/workflows/compose/docker-compose.yml \
+            -f 
./.github/workflows/compose/docker-compose.knoxidf-federation.yml \
+            logs --no-color keycloak || true
+          echo '===== gateway.log ====='
+          cat ./.github/workflows/compose/logs/gateway.log || true
+
       # Single-EKU mTLS runs as its own pass. Its override turns on
       # gateway.client.auth.needed=true, which would break the default
       # (no-client-cert) tests above, so the gateway is recreated with the
@@ -170,6 +225,7 @@ jobs:
             .github/workflows/tests/test-results.xml
             .github/workflows/tests/test-results-single-eku.xml
             .github/workflows/tests/test-results-single-eku-no-mtls.xml
+            .github/workflows/tests/test-results-federation.xml
 
       - name: Archive Knox Logs
         if: always()

Reply via email to