aboutsummaryrefslogtreecommitdiffstats
path: root/molecule/default/tests/test_ssh_connectivity.py
blob: 89b24a57c8514494b70897f3a246f67ab6da6558 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
"""Tests for SSH connectivity between client and server"""
import pytest

testinfra_hosts = ['borg-client', 'borg-client-2', 'borg-client-multi']


def test_ssh_connection_to_server(host):
    c = host.run('ssh -o BatchMode=yes -o ConnectTimeout=5 borg@borg-server echo test')
    assert c.rc == 0 or 'Connection refused' not in c.stderr


def test_no_password_prompt_on_connect(host):
    c = host.run('ssh -o BatchMode=yes -o PreferredAuthentications=publickey borg@borg-server exit')
    assert c.rc == 0


def test_known_hosts_has_correct_entry(host):
    known_hosts = host.file('/root/.ssh/known_hosts')
    content = known_hosts.content_string
    assert 'borg-server' in content
    assert 'ssh-' in content


def test_borg_can_connect_to_server(host):
    hostname = host.backend.get_hostname()

    if hostname == 'borg-client-multi':
        c = host.run('borg list borg@borg-server:/opt/borg/configs')
        assert c.rc == 0, 'Should be able to connect to configs repo'
    elif hostname == 'borg-client':
        c = host.run('borg list borg@borg-server:/opt/borg/borg-client')
        assert c.rc == 0
    elif hostname == 'borg-client-2':
        c = host.run('borg list borg@borg-server:/opt/borg/borg-client-2')
        assert c.rc == 0, 'Should be able to connect to borg-client-2 repo'
    else:
        pytest.fail(f"Unexpected hostname: {hostname}")


def test_borg_info_works(host):
    hostname = host.backend.get_hostname()

    if hostname == 'borg-client-multi':
        c = host.run('borg info borg@borg-server:/opt/borg/configs')
        assert c.rc == 0, 'Should be able to get info for configs repo'
        c2 = host.run('borg info borg@borg-server:/opt/borg/home-data')
        assert c2.rc == 0, 'Should be able to get info for home-data repo'
    elif hostname == 'borg-client':
        c = host.run('borg info borg@borg-server:/opt/borg/borg-client')
        assert c.rc == 0
    elif hostname == 'borg-client-2':
        c = host.run('borg info borg@borg-server:/opt/borg/borg-client-2')
        assert c.rc == 0, 'Should be able to get info for borg-client-2 repo'
    else:
        pytest.fail(f"Unexpected hostname: {hostname}")


def test_multi_instance_can_access_both_repos(host):
    hostname = host.backend.get_hostname()
    if hostname != 'borg-client-multi':
        return

    c1 = host.run('borg list borg@borg-server:/opt/borg/configs')
    assert c1.rc == 0, 'borg-client-multi should access configs repo'

    c2 = host.run('borg list borg@borg-server:/opt/borg/home-data')
    assert c2.rc == 0, 'borg-client-multi should access home-data repo'


def test_multi_instance_cannot_access_other_hosts_repos(host):
    """Verify borg-client-multi cannot access repos from other hosts"""
    hostname = host.backend.get_hostname()
    if hostname != 'borg-client-multi':
        return

    c1 = host.run('borg list borg@borg-server:/opt/borg/borg-client')
    assert c1.rc != 0, (
        'borg-client-multi should NOT access borg-client repo'
    )

    c2 = host.run('borg list borg@borg-server:/opt/borg/borg-client-2')
    assert c2.rc != 0, (
        'borg-client-multi should NOT access borg-client-2 repo'
    )


def test_single_host_cannot_access_multi_repos(host):
    """Verify single-instance hosts cannot access multi-instance repos"""
    hostname = host.backend.get_hostname()
    if hostname not in ['borg-client', 'borg-client-2']:
        return

    c1 = host.run('borg list borg@borg-server:/opt/borg/configs')
    assert c1.rc != 0, (
        f'{hostname} should NOT access configs repo (belongs to borg-client-multi)'
    )

    c2 = host.run('borg list borg@borg-server:/opt/borg/home-data')
    assert c2.rc != 0, (
        f'{hostname} should NOT access home-data repo (belongs to borg-client-multi)'
    )


def test_single_hosts_cannot_access_each_others_repos(host):
    """Verify single-instance hosts cannot access each other's repos"""
    hostname = host.backend.get_hostname()
    if hostname == 'borg-client':
        c = host.run('borg list borg@borg-server:/opt/borg/borg-client-2')
        assert c.rc != 0, (
            'borg-client should NOT access borg-client-2 repo'
        )
    elif hostname == 'borg-client-2':
        c = host.run('borg list borg@borg-server:/opt/borg/borg-client')
        assert c.rc != 0, (
            'borg-client-2 should NOT access borg-client repo'
        )