mirror of
https://github.com/Sea-Haven-Industries/file-share.git
synced 2026-09-30 15:53:18 +00:00
Wire run-tests into CI and add assertions for SG, IAM, instance, DLM, and the imported volume attachment. Use @swc/jest because ts-jest cannot consume TypeScript 7's compiler API.
127 lines
3.6 KiB
TypeScript
127 lines
3.6 KiB
TypeScript
import * as cdk from "aws-cdk-lib";
|
|
import { Match, Template } from "aws-cdk-lib/assertions";
|
|
import * as fs from "node:fs";
|
|
import * as path from "node:path";
|
|
import { FileShareStack } from "../lib/file-share-stack";
|
|
|
|
const context = JSON.parse(
|
|
fs.readFileSync(path.join(__dirname, "..", "cdk.context.json"), "utf8"),
|
|
) as Record<string, unknown>;
|
|
|
|
const app = new cdk.App({ context });
|
|
const stack = new FileShareStack(app, "TestFileShare", {
|
|
env: { account: "328440206208", region: "us-east-1" },
|
|
});
|
|
const template = Template.fromStack(stack);
|
|
|
|
describe("FileShareStack security group", () => {
|
|
it("allows SMB, FileBrowser, and SFTP from the office VPN", () => {
|
|
template.hasResourceProperties("AWS::EC2::SecurityGroup", {
|
|
GroupName: "file-share",
|
|
SecurityGroupIngress: Match.arrayWith([
|
|
Match.objectLike({
|
|
CidrIp: "10.10.0.0/16",
|
|
FromPort: 445,
|
|
ToPort: 445,
|
|
IpProtocol: "tcp",
|
|
}),
|
|
Match.objectLike({
|
|
CidrIp: "10.10.0.0/16",
|
|
FromPort: 8080,
|
|
ToPort: 8080,
|
|
IpProtocol: "tcp",
|
|
}),
|
|
Match.objectLike({
|
|
CidrIp: "10.10.0.0/16",
|
|
FromPort: 22,
|
|
ToPort: 22,
|
|
IpProtocol: "tcp",
|
|
}),
|
|
]),
|
|
});
|
|
});
|
|
|
|
it("allows SMB and FileBrowser from the VPC CIDR", () => {
|
|
template.hasResourceProperties("AWS::EC2::SecurityGroup", {
|
|
SecurityGroupIngress: Match.arrayWith([
|
|
Match.objectLike({
|
|
CidrIp: "10.20.0.0/16",
|
|
FromPort: 445,
|
|
ToPort: 445,
|
|
IpProtocol: "tcp",
|
|
}),
|
|
Match.objectLike({
|
|
CidrIp: "10.20.0.0/16",
|
|
FromPort: 8080,
|
|
ToPort: 8080,
|
|
IpProtocol: "tcp",
|
|
}),
|
|
]),
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("FileShareStack instance IAM", () => {
|
|
it("attaches AmazonSSMManagedInstanceCore to the instance role", () => {
|
|
template.hasResourceProperties("AWS::IAM::Role", {
|
|
RoleName: "file-share-instance",
|
|
ManagedPolicyArns: Match.arrayWith([
|
|
Match.objectLike({
|
|
"Fn::Join": Match.arrayWith([
|
|
Match.arrayWith([
|
|
Match.stringLikeRegexp("AmazonSSMManagedInstanceCore"),
|
|
]),
|
|
]),
|
|
}),
|
|
]),
|
|
});
|
|
});
|
|
|
|
it("scopes Secrets Manager GetSecretValue to file-share/*", () => {
|
|
template.hasResourceProperties("AWS::IAM::Policy", {
|
|
PolicyDocument: {
|
|
Statement: Match.arrayWith([
|
|
Match.objectLike({
|
|
Action: "secretsmanager:GetSecretValue",
|
|
Effect: "Allow",
|
|
Resource:
|
|
"arn:aws:secretsmanager:us-east-1:328440206208:secret:file-share/*",
|
|
}),
|
|
]),
|
|
},
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("FileShareStack instance", () => {
|
|
it("uses t4g.small with an encrypted root volume", () => {
|
|
template.hasResourceProperties("AWS::EC2::Instance", {
|
|
InstanceType: "t4g.small",
|
|
BlockDeviceMappings: Match.arrayWith([
|
|
Match.objectLike({
|
|
DeviceName: "/dev/xvda",
|
|
Ebs: Match.objectLike({
|
|
Encrypted: true,
|
|
VolumeType: "gp3",
|
|
}),
|
|
}),
|
|
]),
|
|
});
|
|
});
|
|
});
|
|
|
|
describe("FileShareStack DLM and data volume", () => {
|
|
it("enables the nightly snapshot lifecycle policy", () => {
|
|
template.hasResourceProperties("AWS::DLM::LifecyclePolicy", {
|
|
State: "ENABLED",
|
|
Description: "Nightly EBS snapshots for file share data volume",
|
|
});
|
|
});
|
|
|
|
it("attaches the imported data volume by ID", () => {
|
|
template.hasResourceProperties("AWS::EC2::VolumeAttachment", {
|
|
VolumeId: "vol-04d951cccacc435b5",
|
|
Device: "/dev/xvdf",
|
|
});
|
|
});
|
|
});
|