soteria/internal/server/longhorn_live_policy_test.go

55 lines
2.1 KiB
Go

package server
import (
"context"
"testing"
"time"
"scm.bstein.dev/bstein/soteria/internal/api"
"scm.bstein.dev/bstein/soteria/internal/config"
"scm.bstein.dev/bstein/soteria/internal/k8s"
)
// TestLiveRWOLonghornPolicy protects live workloads without a second mount.
func TestLiveRWOLonghornPolicy(t *testing.T) {
client := &policyCycleTestKubeClient{
inventoryTestKubeClient: &inventoryTestKubeClient{
fakeKubeClient: &fakeKubeClient{
pvcs: []k8s.PVCSummary{{Namespace: "apps", Name: "data", VolumeName: "vol-data", Phase: "Bound", AccessModes: []string{"ReadWriteOnce"}}},
pvcMounts: map[string][]k8s.PVCMount{"apps/data": {{PodName: "database-0", NodeName: "worker", Phase: "Running"}}},
},
},
}
backend := &fakeLonghornClient{}
srv := &Server{
cfg: &config.Config{BackupDriver: "longhorn", BackupMaxAge: 24 * time.Hour, PolicyBackupsPerCycle: 1},
client: client, longhorn: backend, metrics: newTelemetry(),
policies: map[string]api.BackupPolicy{"apps__all": {ID: "apps__all", Namespace: "apps", IntervalHours: 1, Enabled: true, Dedupe: true}},
}
srv.runPolicyCycle(context.Background())
if backend.createSnapshotName == "" {
t.Fatal("live RWO workload did not receive a Longhorn snapshot")
}
if len(client.backupRequests) != 0 {
t.Fatal("Longhorn policy attempted to launch a filesystem-mount job")
}
if metricCount(srv.metrics.policyBackups, map[string]string{"result": "success"}) != 1 {
t.Fatal("expected one successful policy backup")
}
}
// TestLonghornExclusionAppliesToManualRequests prevents bypassing local-only policy.
func TestLonghornExclusionAppliesToManualRequests(t *testing.T) {
backend := &fakeLonghornClient{}
srv := &Server{
cfg: &config.Config{BackupDriver: "longhorn", ExcludedPVCs: []string{"hermes/*"}},
client: &fakeKubeClient{}, longhorn: backend,
}
for _, dryRun := range []bool{false, true} {
_, code, err := srv.executeBackup(context.Background(), api.BackupRequest{Namespace: "hermes", PVC: "workspace", DryRun: dryRun}, "test")
if err == nil || code != "validation_error" || backend.createSnapshotName != "" {
t.Fatal("excluded Longhorn PVC reached the backup backend")
}
}
}