A jail reads a log; a container's output went to a file of the runtime's own under a path that changes on recreate, so no jail could read a container's service. logging: journald runs the container with the journal as its driver, named in the spec so moving it recreates it; any other place is refused.
44 lines
1.4 KiB
Go
44 lines
1.4 KiB
Go
package apply
|
|
|
|
import (
|
|
"context"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/novox/mesh-host/internal/declaration"
|
|
"github.com/novox/mesh-host/internal/store"
|
|
)
|
|
|
|
// A container declared to log to the journal is run with the journal as its log driver, and the
|
|
// place it logs is part of its spec, so moving it recreates the container (novox/hq ADR 0179).
|
|
func TestAContainerLoggingToTheJournalIsRunThatWayAndRecreatedWhenMoved(t *testing.T) {
|
|
pinned := "postgres@sha256:" + strings.Repeat("a", 64)
|
|
var ran []string
|
|
run := func(_ context.Context, cmd string, args ...string) (string, error) {
|
|
if cmd == "docker" && len(args) > 0 && args[0] == "run" {
|
|
ran = args
|
|
return "deadbeef\n", nil
|
|
}
|
|
return "", nil
|
|
}
|
|
d := parseTrusted(t, `{"declaration":1,"resources":[
|
|
{"id":"front","type":"container","name":"front","image":"`+pinned+`","logging":"journald"}
|
|
]}`)
|
|
_, _, _ = Apply(context.Background(), archHost(t), d, store.State{}, store.OriginCarried, run, nil, nil)
|
|
sent := false
|
|
for i, a := range ran {
|
|
if a == "--log-driver" && i+1 < len(ran) && ran[i+1] == "journald" {
|
|
sent = true
|
|
}
|
|
}
|
|
if !sent {
|
|
t.Fatalf("the container's output was not sent to the journal: %v", ran)
|
|
}
|
|
with := d.Resources[0].(*declaration.Container)
|
|
without := *with
|
|
without.Logging = ""
|
|
if containerSpec(with, inputs{}) == containerSpec(&without, inputs{}) {
|
|
t.Fatal("where a container logs is not part of its spec, so moving it would not recreate it")
|
|
}
|
|
}
|