mirror of
https://github.com/Sea-Haven-Industries/file-share.git
synced 2026-09-30 05:33:10 +00:00
fix(ci): enable Jest CDK stack tests
Wire run-tests into CI and add assertions for SG, IAM, instance, DLM, and the imported volume attachment. Use @swc/jest because ts-jest cannot consume TypeScript 7's compiler API.
This commit is contained in:
parent
8b17fe81c0
commit
b92624994e
5 changed files with 4116 additions and 1 deletions
1
.github/workflows/ci.yaml
vendored
1
.github/workflows/ci.yaml
vendored
|
|
@ -11,3 +11,4 @@ jobs:
|
|||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4
|
||||
with:
|
||||
node-version: "24"
|
||||
run-tests: true
|
||||
|
|
|
|||
3955
package-lock.json
generated
3955
package-lock.json
generated
File diff suppressed because it is too large
Load diff
32
package.json
32
package.json
|
|
@ -6,14 +6,19 @@
|
|||
},
|
||||
"scripts": {
|
||||
"build": "tsc",
|
||||
"test": "jest",
|
||||
"cdk": "cdk",
|
||||
"synth": "cdk synth",
|
||||
"deploy": "cdk deploy",
|
||||
"diff": "cdk diff"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@swc/core": "1.13.5",
|
||||
"@swc/jest": "0.2.39",
|
||||
"@types/jest": "29.5.14",
|
||||
"@types/node": "^24.13.3",
|
||||
"aws-cdk": "^2.1133.0",
|
||||
"jest": "29.7.0",
|
||||
"source-map-support": "^0.5.21",
|
||||
"tsx": "4.23.1",
|
||||
"typescript": "~7.0.2"
|
||||
|
|
@ -21,5 +26,32 @@
|
|||
"dependencies": {
|
||||
"aws-cdk-lib": "2.262.1",
|
||||
"constructs": "^10.7.1"
|
||||
},
|
||||
"jest": {
|
||||
"testEnvironment": "node",
|
||||
"roots": [
|
||||
"<rootDir>/test"
|
||||
],
|
||||
"testMatch": [
|
||||
"**/test/**/*.test.ts"
|
||||
],
|
||||
"transform": {
|
||||
"^.+\\.tsx?$": [
|
||||
"@swc/jest",
|
||||
{
|
||||
"jsc": {
|
||||
"parser": {
|
||||
"syntax": "typescript",
|
||||
"tsx": false
|
||||
},
|
||||
"target": "es2022"
|
||||
},
|
||||
"module": {
|
||||
"type": "commonjs"
|
||||
}
|
||||
}
|
||||
]
|
||||
},
|
||||
"clearMocks": true
|
||||
}
|
||||
}
|
||||
|
|
|
|||
127
test/file-share-stack.test.ts
Normal file
127
test/file-share-stack.test.ts
Normal file
|
|
@ -0,0 +1,127 @@
|
|||
import * as cdk from "aws-cdk-lib";
|
||||
import { Match, Template } from "aws-cdk-lib/assertions";
|
||||
import * as fs from "node:fs";
|
||||
import * as path from "node:path";
|
||||
import { FileShareStack } from "../lib/file-share-stack";
|
||||
|
||||
const context = JSON.parse(
|
||||
fs.readFileSync(path.join(__dirname, "..", "cdk.context.json"), "utf8"),
|
||||
) as Record<string, unknown>;
|
||||
|
||||
const app = new cdk.App({ context });
|
||||
const stack = new FileShareStack(app, "TestFileShare", {
|
||||
env: { account: "328440206208", region: "us-east-1" },
|
||||
});
|
||||
const template = Template.fromStack(stack);
|
||||
|
||||
describe("FileShareStack security group", () => {
|
||||
it("allows SMB, FileBrowser, and SFTP from the office VPN", () => {
|
||||
template.hasResourceProperties("AWS::EC2::SecurityGroup", {
|
||||
GroupName: "file-share",
|
||||
SecurityGroupIngress: Match.arrayWith([
|
||||
Match.objectLike({
|
||||
CidrIp: "10.10.0.0/16",
|
||||
FromPort: 445,
|
||||
ToPort: 445,
|
||||
IpProtocol: "tcp",
|
||||
}),
|
||||
Match.objectLike({
|
||||
CidrIp: "10.10.0.0/16",
|
||||
FromPort: 8080,
|
||||
ToPort: 8080,
|
||||
IpProtocol: "tcp",
|
||||
}),
|
||||
Match.objectLike({
|
||||
CidrIp: "10.10.0.0/16",
|
||||
FromPort: 22,
|
||||
ToPort: 22,
|
||||
IpProtocol: "tcp",
|
||||
}),
|
||||
]),
|
||||
});
|
||||
});
|
||||
|
||||
it("allows SMB and FileBrowser from the VPC CIDR", () => {
|
||||
template.hasResourceProperties("AWS::EC2::SecurityGroup", {
|
||||
SecurityGroupIngress: Match.arrayWith([
|
||||
Match.objectLike({
|
||||
CidrIp: "10.20.0.0/16",
|
||||
FromPort: 445,
|
||||
ToPort: 445,
|
||||
IpProtocol: "tcp",
|
||||
}),
|
||||
Match.objectLike({
|
||||
CidrIp: "10.20.0.0/16",
|
||||
FromPort: 8080,
|
||||
ToPort: 8080,
|
||||
IpProtocol: "tcp",
|
||||
}),
|
||||
]),
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
describe("FileShareStack instance IAM", () => {
|
||||
it("attaches AmazonSSMManagedInstanceCore to the instance role", () => {
|
||||
template.hasResourceProperties("AWS::IAM::Role", {
|
||||
RoleName: "file-share-instance",
|
||||
ManagedPolicyArns: Match.arrayWith([
|
||||
Match.objectLike({
|
||||
"Fn::Join": Match.arrayWith([
|
||||
Match.arrayWith([
|
||||
Match.stringLikeRegexp("AmazonSSMManagedInstanceCore"),
|
||||
]),
|
||||
]),
|
||||
}),
|
||||
]),
|
||||
});
|
||||
});
|
||||
|
||||
it("scopes Secrets Manager GetSecretValue to file-share/*", () => {
|
||||
template.hasResourceProperties("AWS::IAM::Policy", {
|
||||
PolicyDocument: {
|
||||
Statement: Match.arrayWith([
|
||||
Match.objectLike({
|
||||
Action: "secretsmanager:GetSecretValue",
|
||||
Effect: "Allow",
|
||||
Resource:
|
||||
"arn:aws:secretsmanager:us-east-1:328440206208:secret:file-share/*",
|
||||
}),
|
||||
]),
|
||||
},
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
describe("FileShareStack instance", () => {
|
||||
it("uses t4g.small with an encrypted root volume", () => {
|
||||
template.hasResourceProperties("AWS::EC2::Instance", {
|
||||
InstanceType: "t4g.small",
|
||||
BlockDeviceMappings: Match.arrayWith([
|
||||
Match.objectLike({
|
||||
DeviceName: "/dev/xvda",
|
||||
Ebs: Match.objectLike({
|
||||
Encrypted: true,
|
||||
VolumeType: "gp3",
|
||||
}),
|
||||
}),
|
||||
]),
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
describe("FileShareStack DLM and data volume", () => {
|
||||
it("enables the nightly snapshot lifecycle policy", () => {
|
||||
template.hasResourceProperties("AWS::DLM::LifecyclePolicy", {
|
||||
State: "ENABLED",
|
||||
Description: "Nightly EBS snapshots for file share data volume",
|
||||
});
|
||||
});
|
||||
|
||||
it("attaches the imported data volume by ID", () => {
|
||||
template.hasResourceProperties("AWS::EC2::VolumeAttachment", {
|
||||
VolumeId: "vol-04d951cccacc435b5",
|
||||
Device: "/dev/xvdf",
|
||||
});
|
||||
});
|
||||
});
|
||||
|
|
@ -20,5 +20,5 @@
|
|||
"resolveJsonModule": true,
|
||||
"esModuleInterop": true
|
||||
},
|
||||
"exclude": ["node_modules", "cdk.out"]
|
||||
"exclude": ["node_modules", "cdk.out", "test"]
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue