.github/scripts/test_verify_ecr_promote_digest.sh
Adam Moussa 3027650f8e
feat(ci): add docker and ECR image reusables (#164)
* feat(ci): add docker build and ECR image publish reusables

Image repos need a registry-free build check and an ECR publish that stops
at a mutable tag, without an ECS or Lambda update.

* fix(ci): retry ECR digest checks when describe-images fails

A tag that is not visible yet makes the AWS CLI exit non-zero, and set -e
was aborting the retry loop on that first error.
2026-10-06 18:22:23 +00:00

124 lines
3.5 KiB
Bash
Executable file

#!/usr/bin/env bash
# The verifier must retry a failed describe-images call. set -e used to abort
# the loop on the first ImageNotFoundException.
set -euo pipefail
root="$(cd "$(dirname "$0")/.." && pwd)"
verifier="${root}/.github/actions/verify-ecr-promote-digest/verify.sh"
failures=0
assert_eq() {
local name="$1"
local got="$2"
local want="$3"
if [ "${got}" != "${want}" ]; then
echo "${name}: got ${got}, want ${want}" >&2
failures=$((failures + 1))
fi
}
run_case() {
local name="$1"
local expect_status="$2"
local stub_dir
stub_dir="$(mktemp -d)"
cat > "${stub_dir}/aws" <<'EOF'
#!/usr/bin/env bash
set -euo pipefail
tag=""
for arg in "$@"; do
case "${arg}" in
imageTag=*) tag="${arg#imageTag=}" ;;
esac
done
if [ -z "${tag}" ]; then
echo "stub aws: missing image tag" >&2
exit 1
fi
dir="${AWS_STUB_DIR}"
count_file="${dir}/count-${tag}"
n=0
if [ -f "${count_file}" ]; then
n="$(cat "${count_file}")"
fi
n=$((n + 1))
printf '%s\n' "${n}" > "${count_file}"
line="$(sed -n "${n}p" "${dir}/behavior-${tag}" || true)"
if [ -z "${line}" ]; then
line="$(tail -n 1 "${dir}/behavior-${tag}")"
fi
case "${line}" in
ok\ *)
printf '%s\n' "${line#ok }"
;;
fail)
echo "ImageNotFoundException: ${tag}" >&2
exit 254
;;
*)
echo "stub aws: no behavior for ${tag} call ${n}" >&2
exit 1
;;
esac
EOF
chmod +x "${stub_dir}/aws"
shift 2
while [ "$#" -gt 0 ]; do
printf '%s\n' "$2" > "${stub_dir}/behavior-$1"
shift 2
done
set +e
IMAGE_NAME=actions-runner \
SHA=0123456789abcdef0123456789abcdef01234567 \
PROMOTE_TAG=current \
DIGEST_RETRY_SLEEP=0 \
AWS_STUB_DIR="${stub_dir}" \
PATH="${stub_dir}:${PATH}" \
bash "${verifier}" >"${stub_dir}/out" 2>"${stub_dir}/err"
status=$?
set -e
if [ "${status}" -ne "${expect_status}" ]; then
echo "${name}: exit ${status}, want ${expect_status}" >&2
cat "${stub_dir}/err" >&2
failures=$((failures + 1))
fi
sha_calls=0
promote_calls=0
if [ -f "${stub_dir}/count-sha-0123456789abcdef0123456789abcdef01234567" ]; then
sha_calls="$(cat "${stub_dir}/count-sha-0123456789abcdef0123456789abcdef01234567")"
fi
if [ -f "${stub_dir}/count-current" ]; then
promote_calls="$(cat "${stub_dir}/count-current")"
fi
printf '%s\n' "${sha_calls}" > "${stub_dir}/sha_calls"
printf '%s\n' "${promote_calls}" > "${stub_dir}/promote_calls"
# shellcheck disable=SC2034
CASE_DIR="${stub_dir}"
}
run_case "match on first read" 0 \
"sha-0123456789abcdef0123456789abcdef01234567" "ok sha256:aaa" \
"current" "ok sha256:aaa"
assert_eq "match on first read sha calls" "$(cat "${CASE_DIR}/sha_calls")" "1"
assert_eq "match on first read promote calls" "$(cat "${CASE_DIR}/promote_calls")" "1"
rm -rf "${CASE_DIR}"
run_case "retry when promote tag is not visible yet" 0 \
"sha-0123456789abcdef0123456789abcdef01234567" "ok sha256:aaa" \
"current" "$(printf 'fail\nok sha256:aaa')"
assert_eq "not visible yet sha calls" "$(cat "${CASE_DIR}/sha_calls")" "2"
assert_eq "not visible yet promote calls" "$(cat "${CASE_DIR}/promote_calls")" "2"
rm -rf "${CASE_DIR}"
run_case "give up when describe-images keeps failing" 1 \
"sha-0123456789abcdef0123456789abcdef01234567" "fail" \
"current" "fail"
assert_eq "keep failing sha calls" "$(cat "${CASE_DIR}/sha_calls")" "6"
assert_eq "keep failing promote calls" "$(cat "${CASE_DIR}/promote_calls")" "6"
rm -rf "${CASE_DIR}"
if [ "${failures}" -ne 0 ]; then
echo "${failures} assertion(s) failed" >&2
exit 1
fi
echo "verify_ecr_promote_digest: ok"