Files
artifactapi/e2e-docker
unkin-agent 1837f6ef8c
ci/woodpecker/tag/docker Pipeline failed
Add rpm virtual repositories (#131)
Virtual repos only merge helm and pypi, so several rpm repos (e.g. many github_rpm remotes) cannot be served as one yum repo.

- merge member primary/filelists/other into one repodata set; member order wins duplicate NEVRAs
- read member repodata through local, github_rpm and proxied remote paths
- prefix package locations (incl. xml:base under a member upstream) with the member name and 302 them to the member route
- reject absolute and dot-segment member paths; escape the redirect and keep its query
- return 502 when any member's repodata is unavailable
- reuse each virtual's merge for 60s behind singleflight; serve data files from its current and previous merge (per replica)
- add merger/engine unit tests and a dockerised dnf e2e case

Reviewed-on: #131
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-09 22:07:20 +11:00
..

Dockerised end-to-end suite

Black-box tests that run against a fully containerised artifactapi stack (built image + Postgres + Redis + MinIO) plus a static mock upstream. Unlike the in-process e2e/ suite (testcontainers, server run in-process), these only speak HTTP to the running product, so they exercise the shipped container image.

Run

make docker-e2e          # build image, compose up, run suite, compose down

scripts/docker-e2e.sh builds and starts docker-compose.yml + docker-compose.e2e.yml, waits for /health, then runs go test -tags=dockere2e ./e2e-docker/... and tears everything down.

The stack publishes artifactapi on host port 8001 (to avoid colliding with a local instance on 8000). Override with ARTIFACTAPI_URL to point the tests at an already-running stack.

Coverage

  • Repository lifecycle — add / change / delete for remote, local and virtual repos.
  • Caching — one immutable artifact per remote package type (generic, docker, helm, pypi, npm, rpm, alpine, puppet, terraform, goproxy, cargo) proxied through the mock upstream: first fetch X-Artifact-Source: remote, second cache, bytes verified against the origin fixture.
  • Local uploads — generic (upload/download), pypi (wheel + generated simple/ index), rpm (real package + automatic repodata generation).
  • Virtual repositories — pypi simple-index merge and helm index.yaml merge across two members.
  • Mirrorlist — an rpm remote with a mirrorlist of extra upstream mirrors (pool = base_url + mirrorlist): round-robin distribution across both mirrors (constant-body mockupstreama / mockupstreamb), failover past a dead primary, no-mirrorlist regression, and a real dnf (stock rockylinux:9 container) makecache + install through a two-mirror rpm remote whose base_url is dead — a dead mirror must not break the client.
  • Mirror strategy (least_conn) — a mirror_strategy: least_conn rpm remote over the two constant-body mirrors exercises the least-connections selection path end-to-end (both mirrors serve, all requests succeed), plus a real dnf install through a least_conn remote with a dead primary (failover unchanged). The precise least-loaded pick is asserted deterministically in the proxy unit test, since an in-flight-skew assertion over HTTP is timing-sensitive.

Fixtures

fixtures/ is served by the mock upstream at its web root. Paths mirror each provider's upstream URL layout (e.g. v2/... for docker, v1/providers/... for terraform). The RPM under fixtures/rpmrepo/Packages/ is a real package so the rpm provider can parse its metadata for repodata generation.