This is an automated email from the ASF dual-hosted git repository. smolnar82 pushed a commit to branch knox_idf in repository https://gitbox.apache.org/repos/asf/knox.git
commit 8d6840b29069b3232a2a099732637a884e80bd44 Author: Sandor Molnar <[email protected]> AuthorDate: Wed Aug 12 11:51:36 2026 +0200 KNOX-3414: run KnoxIDF federation E2E tests optionally in PRs --- .github/PULL_REQUEST_TEMPLATE.md | 10 +++++++ .github/workflows/tests.yml | 56 ++++++++++++++++++++++++++++++++++++++++ 2 files changed, 66 insertions(+) diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md index ffec53663..d41f88fd3 100644 --- a/.github/PULL_REQUEST_TEMPLATE.md +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -13,6 +13,16 @@ ## Integration Tests (Please add or update integration tests [`.github/workflows/tests`](.github/workflows/tests) for the feature you are adding. If no unit test is added, please explain why. Check out [`.github/workflows/tests/README.md`](./workflows/tests/README.md) for instructions) +### Opt-in test suites (PR labels) +Some integration suites are expensive and are **not** run on every PR. Add the corresponding label to this PR to run them: + +| Label | Runs | +|-------|------| +| `test-federation` | KnoxIDF federation E2E (`test_knoxidf_federation.py`). Stands up a real Keycloak as an external OpenID Provider and drives the full broker flow. Adds a few minutes (image pull + realm import). | +| `skip-tests` | Skips the entire Docker Compose test job. | + +**When to add the label:** these labels only take effect on runs triggered by opening the PR, pushing a commit, or reopening the PR — the workflow does not run on a label change. Add the label **before opening the PR** (or before your next push). Adding it after the checks have already finished will **not** start a new run; push a commit or close/reopen the PR to trigger one with the label applied. + ## UI changes (If this patch involves UI changes, please attach a screen-shot; otherwise, remove this) diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 9fbd80c41..5c39d25d2 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -69,6 +69,61 @@ jobs: # Run the tests service defined in docker-compose.yml docker compose -f ./.github/workflows/compose/docker-compose.yml up --exit-code-from tests tests + # KnoxIDF federation E2E runs only when the PR carries the 'test-federation' + # label. It stands up a real Keycloak (external OpenID Provider) via the + # override compose file and pulls a multi-hundred-MB image plus minutes of + # realm import, so it is opt-in rather than on every PR. It runs here, before + # the single-EKU steps, so 'knox' is still in its base (non-mTLS) config; the + # override only adds a keycloak dependency to knox, it does not reconfigure it. + - name: Start Keycloak + Knox for federation + if: contains(github.event.pull_request.labels.*.name, 'test-federation') + run: | + # 'up -d knox' blocks until keycloak is service_healthy (override depends_on). + docker compose \ + -f ./.github/workflows/compose/docker-compose.yml \ + -f ./.github/workflows/compose/docker-compose.knoxidf-federation.yml \ + up -d knox keycloak + + - name: Wait for federation stack to stabilize + if: contains(github.event.pull_request.labels.*.name, 'test-federation') + run: sleep 30 # Adjust as needed for services startup time + + - name: Run KnoxIDF Federation Tests + id: knoxidf_federation_tests + if: contains(github.event.pull_request.labels.*.name, 'test-federation') + run: | + # Emit a distinct JUnit file so it reports as its own test suite. + docker compose \ + -f ./.github/workflows/compose/docker-compose.yml \ + -f ./.github/workflows/compose/docker-compose.knoxidf-federation.yml \ + run --rm tests bash -c "pip install -r requirements.txt \ + && pytest test_knoxidf_federation.py --junitxml=test-results-federation.xml" + + # Evidence gathering mirrors the single-EKU dumps: on a federation failure, + # capture container status and the knox + keycloak logs so a broker-flow + # failure (bad callback/issuer/JWKS) can be told apart from a Keycloak that + # never came up. + - name: Dump federation diagnostics on failure + if: failure() && steps.knoxidf_federation_tests.outcome == 'failure' + run: | + echo '===== docker compose ps -a =====' + docker compose \ + -f ./.github/workflows/compose/docker-compose.yml \ + -f ./.github/workflows/compose/docker-compose.knoxidf-federation.yml \ + ps -a || true + echo '===== knox container logs =====' + docker compose \ + -f ./.github/workflows/compose/docker-compose.yml \ + -f ./.github/workflows/compose/docker-compose.knoxidf-federation.yml \ + logs --no-color knox || true + echo '===== keycloak container logs =====' + docker compose \ + -f ./.github/workflows/compose/docker-compose.yml \ + -f ./.github/workflows/compose/docker-compose.knoxidf-federation.yml \ + logs --no-color keycloak || true + echo '===== gateway.log =====' + cat ./.github/workflows/compose/logs/gateway.log || true + # Single-EKU mTLS runs as its own pass. Its override turns on # gateway.client.auth.needed=true, which would break the default # (no-client-cert) tests above, so the gateway is recreated with the @@ -170,6 +225,7 @@ jobs: .github/workflows/tests/test-results.xml .github/workflows/tests/test-results-single-eku.xml .github/workflows/tests/test-results-single-eku-no-mtls.xml + .github/workflows/tests/test-results-federation.xml - name: Archive Knox Logs if: always()
