forked from osbuild/bootc-image-builder
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
test: add anaconda-iso build tests with signed containers
Add anaconda-iso iso build tests with signed containers. The rest of the images can be also added to the test once [1] and [2] are merged [1] osbuild/images#990 [2] osbuild/osbuild#1906 Signed-off-by: Miguel Martín <[email protected]>
- Loading branch information
Showing
3 changed files
with
135 additions
and
7 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,9 +1,11 @@ | ||
import dataclasses | ||
import os | ||
import pathlib | ||
import platform | ||
import shutil | ||
import socket | ||
import subprocess | ||
import tempfile | ||
import time | ||
|
||
import boto3 | ||
|
@@ -147,3 +149,97 @@ def create_filesystem_customizations(rootfs: str): | |
"-v", "/var/lib/containers/storage:/var/lib/containers/storage", | ||
"--security-opt", "label=type:unconfined_t", | ||
] | ||
|
||
|
||
def get_ip_from_default_route(): | ||
default_route = subprocess.run([ | ||
"ip", | ||
"route", | ||
"list", | ||
"default" | ||
], check=True, capture_output=True).stdout | ||
return default_route.split()[8].decode("utf-8") | ||
|
||
|
||
@dataclasses.dataclass | ||
class GPGConfig(): | ||
email: str = "[email protected]" | ||
pub_key: str = "/etc/pki/rpm-gpg/RPM-GPG-KEY-booc-image-builder" | ||
passphrase: str = "redhat" | ||
|
||
|
||
@dataclasses.dataclass | ||
class RegistryConfig(): | ||
local_registry: str = "localhost:5000" | ||
sigstore_dir: str = "/var/lib/containers/sigstore" | ||
lookaside_config: str = "/etc/containers/registries.d/bib.yaml" | ||
|
||
|
||
def sign_container_image(gpg_config: GPGConfig, registry_config: RegistryConfig, container_ref): | ||
if not os.path.exists(gpg_config.pub_key): | ||
subprocess.run([ | ||
"gpg", | ||
"--quick-gen-key", | ||
"--batch", | ||
"--passphrase", gpg_config.passphrase, | ||
gpg_config.email | ||
], check=True) | ||
subprocess.run([ | ||
"gpg", | ||
"--output", gpg_config.pub_key, | ||
"--armor", | ||
"--export", | ||
gpg_config.email | ||
], check=True) | ||
subprocess.run([ | ||
"podman", "image", "trust", "set", | ||
"--pubkeysfile", gpg_config.pub_key, | ||
"--type", "signedBy", | ||
registry_config.local_registry | ||
], check=True) | ||
|
||
registry_lookaside_config = f"""docker: | ||
{registry_config.local_registry}: | ||
lookaside: file:///{registry_config.sigstore_dir} | ||
""" | ||
with open(registry_config.lookaside_config, mode="w", encoding="utf-8") as f: | ||
f.write(registry_lookaside_config) | ||
|
||
registry_container_name = subprocess.run([ | ||
"podman", "ps", "-a", "--filter", "name=registry", "--format", "{{.Names}}" | ||
], check=True, capture_output=True).stdout.decode("utf-8").strip() | ||
|
||
if registry_container_name != "registry": | ||
subprocess.run([ | ||
"podman", "run", "-d", | ||
"-p", "5000:5000", | ||
"--restart", "always", | ||
"--name", "registry", | ||
"registry:2" | ||
], check=True) | ||
|
||
registry_container_state = subprocess.run([ | ||
"podman", "ps", "-a", "--filter", "name=registry", "--format", "{{.State}}" | ||
], check=True, capture_output=True).stdout.decode("utf-8").strip() | ||
|
||
if registry_container_state in ("paused", "exited"): | ||
subprocess.run([ | ||
"podman", "start", "registry" | ||
], check=True, ) | ||
|
||
container_ref_path = container_ref[container_ref.index('/'):] | ||
signed_container_ref = f"{registry_config.local_registry}{container_ref_path}" | ||
with tempfile.NamedTemporaryFile(mode="w") as f: | ||
f.write(gpg_config.passphrase) | ||
f.flush() | ||
subprocess.run([ | ||
"skopeo", "copy", | ||
"--dest-tls-verify=false", | ||
"--remove-signatures", | ||
"--sign-by", gpg_config.email, | ||
"--sign-passphrase-file", f.name, | ||
f"docker://{container_ref}", | ||
f"docker://{signed_container_ref}", | ||
], check=True) | ||
|
||
return signed_container_ref |