Files
artifactapi/e2e-docker
unkin-agent 7f77666709 Add Alpine/apk local repository support (#114)
## Why

The alpine provider only supported remote (proxy) repositories, so there was no way to publish first-party `.apk` packages the way `rpm-local` and `deb-local` already allow. This extends the existing alpine provider into a real apk repository: uploaded `.apk` files are parsed in pure Go and a per-arch `APKINDEX.tar.gz` is generated on demand, at parity with rpm repodata and deb Packages generation. (The metadata-only `github_alpine` type is a separate follow-up and is not part of this PR.)

## How

- Implements `LocalUploader` / `LocalIndexer` / `PostUploadHook` / `PostDeleteHook` on the existing `alpine` provider, leaving the remote proxy methods (`UpstreamURL`/`ContentType`/`AuthHeaders`/`RewriteResponse`/`Classify`) intact.
- Parses the `.apk` (up to three concatenated, independently gzipped tar streams) in pure Go: locates the control stream by its `.PKGINFO` member, reads the `key = value` fields, and computes the apk pull checksum `C:` = `Q1` + base64(sha1(**control gzip stream bytes**)) — the sha1 of the second gzip member, not of the whole file.
- Derives arch from `.PKGINFO` and records download size (`S:` blob size) and installed size (`I:` from `.PKGINFO size`).
- Generates an **unsigned** per-arch `APKINDEX.tar.gz` = gzip(tar(`APKINDEX`)) filtered by requested arch (clients use `--allow-untrusted`, matching rpm `gpgcheck=0` / deb `[trusted=yes]`), applying the same dot-segment normalization as deb so `./<arch>/APKINDEX.tar.gz` resolves. Non-index / `.apk` paths return `false` so the generic file streamer serves the stored blob.
- Adds `AlpineMetadata` plus **separate** `AlpineMetadataStore` / `AlpineMetadataReader` / `AlpineMetadataDeleter` interfaces (type-asserted from the generic hooks) so the shared rpm/deb metadata interfaces and their test doubles are untouched.
- Adds the `alpine_metadata` table (keyed by `repo_name` + `file_path`, per-arch index) and its `Insert`/`Delete`/`List` DB methods.
- Adds `testsupport.MinimalApk`, unit tests (`.PKGINFO` parse, Q1 checksum over the control stream, per-arch filtering, empty-field omission, `./` dot-segment handling, ValidateUpload accept/reject), and a `dockere2e` `TestLocalAlpineIndex`.

## Consumption

`/etc/apk/repositories` line = `<url>/api/v1/local/<name>` (apk appends `/<arch>/APKINDEX.tar.gz`); `apk update --allow-untrusted && apk add --allow-untrusted <pkg>`. Packages live at `/api/v1/local/<name>/<arch>/<file>.apk`.

## Verification

`go build ./...`, `go vet ./...` (incl. `-tags dockere2e`), `go mod tidy` (no change), `make test` (`-race`), and `pre-commit run --all-files` all pass.

Reviewed-on: #114
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-08-12 20:39:27 +10:00
..

Dockerised end-to-end suite

Black-box tests that run against a fully containerised artifactapi stack (built image + Postgres + Redis + MinIO) plus a static mock upstream. Unlike the in-process e2e/ suite (testcontainers, server run in-process), these only speak HTTP to the running product, so they exercise the shipped container image.

Run

make docker-e2e          # build image, compose up, run suite, compose down

scripts/docker-e2e.sh builds and starts docker-compose.yml + docker-compose.e2e.yml, waits for /health, then runs go test -tags=dockere2e ./e2e-docker/... and tears everything down.

The stack publishes artifactapi on host port 8001 (to avoid colliding with a local instance on 8000). Override with ARTIFACTAPI_URL to point the tests at an already-running stack.

Coverage

  • Repository lifecycle — add / change / delete for remote, local and virtual repos.
  • Caching — one immutable artifact per remote package type (generic, docker, helm, pypi, npm, rpm, alpine, puppet, terraform, goproxy) proxied through the mock upstream: first fetch X-Artifact-Source: remote, second cache, bytes verified against the origin fixture.
  • Local uploads — generic (upload/download), pypi (wheel + generated simple/ index), rpm (real package + automatic repodata generation).
  • Virtual repositories — pypi simple-index merge and helm index.yaml merge across two members.

Fixtures

fixtures/ is served by the mock upstream at its web root. Paths mirror each provider's upstream URL layout (e.g. v2/... for docker, v1/providers/... for terraform). The RPM under fixtures/rpmrepo/Packages/ is a real package so the rpm provider can parse its metadata for repodata generation.