feat(execd): add filesystem execution identity core #1716
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Node Agent Tests | |
| on: | |
| pull_request: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| changes: | |
| uses: ./.github/workflows/detect-changes.yml | |
| with: | |
| area: nodeagent | |
| test: | |
| needs: changes | |
| if: needs.changes.outputs.relevant == 'true' | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 20 | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - uses: actions/setup-go@v6 | |
| with: | |
| go-version: '1.25.9' | |
| cache-dependency-path: | | |
| components/nodeagent/go.sum | |
| components/internal/go.sum | |
| - uses: azure/setup-helm@v4 | |
| with: | |
| version: v3.16.3 | |
| - name: Check formatting | |
| working-directory: components/nodeagent | |
| run: make fmt-check | |
| - name: Verify syscall BPF bytecode | |
| working-directory: components/nodeagent | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y clang-18 libbpf-dev=1:1.3.0-2build2 | |
| make verify-syscalls-bpf CLANG=clang-18 | |
| - name: Vet, test, and build | |
| working-directory: components/nodeagent | |
| run: | | |
| make vet | |
| make test | |
| GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build ./... | |
| GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go test -exec=/bin/true ./... | |
| make integration-compile | |
| make build | |
| - name: Validate Helm chart | |
| run: | | |
| helm lint manifests/charts/node-agent | |
| helm template nodeagent manifests/charts/node-agent \ | |
| > /tmp/nodeagent-default-sources.yaml | |
| grep -A1 'name: NODEAGENT_SOURCES' /tmp/nodeagent-default-sources.yaml \ | |
| | grep -q 'value: "container-logs"' | |
| helm template nodeagent manifests/charts/node-agent \ | |
| --set 'config.sources={source-a,source-b}' \ | |
| > /tmp/nodeagent-non-log-sources.yaml | |
| helm template nodeagent manifests/charts/node-agent \ | |
| --set 'config.sources={syscalls}' \ | |
| > /tmp/nodeagent-syscalls.yaml | |
| grep -A8 'capabilities:' /tmp/nodeagent-syscalls.yaml | grep -q -- '- BPF' | |
| grep -A8 'capabilities:' /tmp/nodeagent-syscalls.yaml | grep -q -- '- PERFMON' | |
| grep -A1 'name: NODEAGENT_SYSCALL_CGROUP_ROOT' /tmp/nodeagent-syscalls.yaml \ | |
| | grep -q 'value: /host/sys/fs/cgroup' | |
| grep -A2 'mountPath: /host/sys/fs/cgroup' /tmp/nodeagent-syscalls.yaml | grep -q 'readOnly: true' | |
| grep -A2 'mountPath: /sys/kernel/tracing' /tmp/nodeagent-syscalls.yaml | grep -q 'readOnly: true' | |
| grep -q 'name: host-cgroup' /tmp/nodeagent-syscalls.yaml | |
| grep -q 'name: host-tracing' /tmp/nodeagent-syscalls.yaml | |
| grep -q 'path: "/sys/fs/cgroup"' /tmp/nodeagent-syscalls.yaml | |
| grep -q 'path: "/sys/kernel/tracing"' /tmp/nodeagent-syscalls.yaml | |
| helm template nodeagent manifests/charts/node-agent \ | |
| --set 'config.sources={syscalls}' \ | |
| --set containerSecurityContext=null \ | |
| > /tmp/nodeagent-syscalls-no-secctx.yaml | |
| grep -A8 'capabilities:' /tmp/nodeagent-syscalls-no-secctx.yaml | grep -q -- '- BPF' | |
| grep -A8 'capabilities:' /tmp/nodeagent-syscalls-no-secctx.yaml | grep -q -- '- PERFMON' | |
| if grep -Eq -- '- (BPF|PERFMON)' /tmp/nodeagent-default-sources.yaml; then | |
| echo "eBPF capabilities rendered while the syscalls Source is disabled" >&2 | |
| exit 1 | |
| fi | |
| for nodeagent_syscall_marker in NODEAGENT_SYSCALL_CGROUP_ROOT 'name: host-cgroup' 'name: host-tracing'; do | |
| if grep -q "${nodeagent_syscall_marker}" /tmp/nodeagent-default-sources.yaml; then | |
| echo "syscalls host access rendered while the Source is disabled: ${nodeagent_syscall_marker}" >&2 | |
| exit 1 | |
| fi | |
| done | |
| helm template nodeagent manifests/charts/node-agent \ | |
| --set 'config.sources={container-logs,source-a}' \ | |
| > /tmp/nodeagent-mixed-sources.yaml | |
| grep -A1 'name: NODEAGENT_SOURCES' /tmp/nodeagent-mixed-sources.yaml \ | |
| | grep -q 'value: "container-logs,source-a"' | |
| grep -q 'NODEAGENT_LOG_ROOT' /tmp/nodeagent-mixed-sources.yaml | |
| grep -q 'name: pod-logs' /tmp/nodeagent-mixed-sources.yaml | |
| helm template nodeagent manifests/charts/node-agent \ | |
| --set 'config.sources={source-a,source-b}' \ | |
| --set hostPaths.logs=null \ | |
| --set config.maxLineBytes=null \ | |
| --set config.partialTimeout=null \ | |
| --set config.endedStateRetention=null >/dev/null | |
| grep -A1 'name: NODEAGENT_SOURCES' /tmp/nodeagent-non-log-sources.yaml \ | |
| | grep -q 'value: "source-a,source-b"' | |
| for nodeagent_log_marker in NODEAGENT_LOG_ROOT NODEAGENT_MAX_LINE_BYTES NODEAGENT_PARTIAL_TIMEOUT NODEAGENT_ENDED_STATE_RETENTION 'name: pod-logs'; do | |
| if ! grep -q "${nodeagent_log_marker}" /tmp/nodeagent-default-sources.yaml; then | |
| echo "container-log marker missing from the default render: ${nodeagent_log_marker}" >&2 | |
| exit 1 | |
| fi | |
| if grep -q "${nodeagent_log_marker}" /tmp/nodeagent-non-log-sources.yaml; then | |
| echo "container-log host access rendered while the Source is disabled: ${nodeagent_log_marker}" >&2 | |
| exit 1 | |
| fi | |
| done | |
| for nodeagent_common_marker in NODEAGENT_STATE_DIR 'name: state'; do | |
| if ! grep -q "${nodeagent_common_marker}" /tmp/nodeagent-non-log-sources.yaml; then | |
| echo "common marker missing while only non-log Sources are enabled: ${nodeagent_common_marker}" >&2 | |
| exit 1 | |
| fi | |
| done | |
| # Template-enforced required values must fail the render. | |
| if helm template nodeagent manifests/charts/node-agent \ | |
| --set hostPaths.logs=null >/dev/null 2>&1; then | |
| echo "container-logs Source rendered without hostPaths.logs" >&2 | |
| exit 1 | |
| fi | |
| for nodeagent_syscall_host_path in cgroup tracing; do | |
| if helm template nodeagent manifests/charts/node-agent \ | |
| --set 'config.sources={syscalls}' \ | |
| --set "hostPaths.${nodeagent_syscall_host_path}=null" >/dev/null 2>&1; then | |
| echo "syscalls Source rendered without hostPaths.${nodeagent_syscall_host_path}" >&2 | |
| exit 1 | |
| fi | |
| done | |
| helm template nodeagent manifests/charts/node-agent \ | |
| --set 'config.sources={source-a,source-b}' \ | |
| --set hostPaths.cgroup=null \ | |
| --set hostPaths.tracing=null >/dev/null | |
| helm template nodeagent manifests/charts/node-agent \ | |
| --set sink.type=oss \ | |
| --set sink.oss.endpoint=https://oss-cn-hangzhou.aliyuncs.com \ | |
| --set sink.oss.bucket=test-bucket \ | |
| --set sink.oss.keyPrefix=nodeagent-test \ | |
| --set sink.oss.existingSecret=oss-credentials >/dev/null | |
| if helm template nodeagent manifests/charts/node-agent \ | |
| --set sink.type=oss \ | |
| --set sink.oss.endpoint=https://oss-cn-hangzhou.aliyuncs.com \ | |
| --set sink.oss.bucket=test-bucket \ | |
| --set sink.oss.keyPrefix=nodeagent-test >/dev/null 2>&1; then | |
| echo "OSS sink rendered without sink.oss.existingSecret" >&2 | |
| exit 1 | |
| fi | |
| helm dependency build manifests/charts/opensandbox | |
| helm template opensandbox manifests/charts/opensandbox \ | |
| --set opensandbox-node-agent.enabled=true \ | |
| --show-only charts/opensandbox-node-agent/templates/daemonset.yaml \ | |
| > /tmp/opensandbox-nodeagent-umbrella.yaml | |
| grep -q '^kind: DaemonSet$' /tmp/opensandbox-nodeagent-umbrella.yaml | |
| grep -q 'app.kubernetes.io/component: node-agent' /tmp/opensandbox-nodeagent-umbrella.yaml | |
| helm template opensandbox manifests/charts/opensandbox \ | |
| > /tmp/opensandbox-default.yaml | |
| if grep -q 'app.kubernetes.io/component: node-agent' /tmp/opensandbox-default.yaml; then | |
| echo "node-agent rendered while disabled by default" | |
| exit 1 | |
| fi | |
| kind-smoke: | |
| needs: [changes, test] | |
| if: needs.changes.outputs.relevant == 'true' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - uses: azure/setup-helm@v4 | |
| with: | |
| version: v3.16.3 | |
| - uses: azure/setup-kubectl@v4 | |
| with: | |
| version: v1.34.0 | |
| - name: Install Kind | |
| run: | | |
| curl --retry 3 -fsSLo /tmp/kind https://kind.sigs.k8s.io/dl/v0.30.0/kind-linux-amd64 | |
| echo '517ab7fc89ddeed5fa65abf71530d90648d9638ef0c4cde22c2c11f8097b8889 /tmp/kind' | sha256sum -c - | |
| chmod +x /tmp/kind | |
| sudo mv /tmp/kind /usr/local/bin/kind | |
| - name: Run file-sink restart smoke test | |
| run: bash components/nodeagent/test/kind-smoke.sh | |
| required: | |
| name: Node Agent CI | |
| if: always() | |
| needs: [changes, test, kind-smoke] | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 5 | |
| steps: | |
| - name: Verify required jobs | |
| env: | |
| RELEVANT: ${{ needs.changes.outputs.relevant }} | |
| CHANGES_RESULT: ${{ needs.changes.result }} | |
| TEST_RESULT: ${{ needs.test.result }} | |
| KIND_RESULT: ${{ needs.kind-smoke.result }} | |
| run: | | |
| if [[ "$CHANGES_RESULT" != "success" ]]; then | |
| echo "change detection failed: $CHANGES_RESULT" | |
| exit 1 | |
| fi | |
| echo "relevant=$RELEVANT test=$TEST_RESULT kind-smoke=$KIND_RESULT" | |
| if [[ "$RELEVANT" == "true" ]]; then | |
| [[ "$TEST_RESULT" == "success" && "$KIND_RESULT" == "success" ]] | |
| else | |
| [[ "$RELEVANT" == "false" && "$TEST_RESULT" == "skipped" && "$KIND_RESULT" == "skipped" ]] | |
| fi |