feat: testinfra demo and librepages blog basic testing

This commit is contained in:
Aravinth Manivannan 2022-10-07 22:28:59 +05:30
parent 8e40bd2af8
commit 98250214fe
Signed by: realaravinth
GPG key ID: AD9F0F08E855ED88
4 changed files with 238 additions and 0 deletions

View file

@ -1,3 +1,13 @@
## Infrastructure
### Testing
- [serverspec.org](https://serverspec.org/tutorial.html): Ruby based
simple, infrastructure testing. Please see [here](./sandbox/serverspec/getting-started) for a simple example.
- [testinfra](https://testinfra.readthedocs.io/en/latest/): python-based
infrastructure testing
## DevSecOps
1. (DevSec Hardening Framework](https://dev-sec.io/): Automatic Server

View file

@ -0,0 +1,157 @@
.env
# Byte-compiled / optimized / DLL files
__pycache__/
*.py[cod]
*$py.class
# C extensions
*.so
# Distribution / packaging
.Python
build/
develop-eggs/
dist/
downloads/
eggs/
.eggs/
lib/
lib64/
parts/
sdist/
var/
wheels/
share/python-wheels/
*.egg-info/
.installed.cfg
*.egg
MANIFEST
# PyInstaller
# Usually these files are written by a python script from a template
# before PyInstaller builds the exe, so as to inject date/other infos into it.
*.manifest
*.spec
# Installer logs
pip-log.txt
pip-delete-this-directory.txt
# Unit test / coverage reports
htmlcov/
.tox/
.nox/
.coverage
.coverage.*
.cache
nosetests.xml
coverage.xml
*.cover
*.py,cover
.hypothesis/
.pytest_cache/
cover/
# Translations
*.mo
*.pot
# Django stuff:
*.log
local_settings.py
db.sqlite3
db.sqlite3-journal
# Flask stuff:
instance/
.webassets-cache
# Scrapy stuff:
.scrapy
# Sphinx documentation
docs/_build/
# PyBuilder
.pybuilder/
target/
# Jupyter Notebook
.ipynb_checkpoints
# IPython
profile_default/
ipython_config.py
# pyenv
# For a library or package, you might want to ignore these files since the code is
# intended to run in multiple environments; otherwise, check them in:
# .python-version
# pipenv
# According to pypa/pipenv#598, it is recommended to include Pipfile.lock in version control.
# However, in case of collaboration, if having platform-specific dependencies or dependencies
# having no cross-platform support, pipenv may install dependencies that don't work, or not
# install all needed dependencies.
#Pipfile.lock
# poetry
# Similar to Pipfile.lock, it is generally recommended to include poetry.lock in version control.
# This is especially recommended for binary packages to ensure reproducibility, and is more
# commonly ignored for libraries.
# https://python-poetry.org/docs/basic-usage/#commit-your-poetrylock-file-to-version-control
#poetry.lock
# PEP 582; used by e.g. github.com/David-OConnor/pyflow
__pypackages__/
# Celery stuff
celerybeat-schedule
celerybeat.pid
# SageMath parsed files
*.sage.py
# Environments
.env
.venv
env/
venv/
ENV/
env.bak/
venv.bak/
# Spyder project settings
.spyderproject
.spyproject
# Rope project settings
.ropeproject
# mkdocs documentation
/site
# mypy
.mypy_cache/
.dmypy.json
dmypy.json
# Pyre type checker
.pyre/
# pytype static type analyzer
.pytype/
# Cython debug symbols
cython_debug/
# PyCharm
# JetBrains specific template is maintained in a separate JetBrains.gitignore that can
# be found at https://github.com/github/gitignore/blob/main/Global/JetBrains.gitignore
# and can be added to the global gitignore or merged into this file. For a more nuclear
# option (not recommended) you can uncomment the following to ignore the entire idea folder.
#.idea/
keys
htmlcov/
tmp/
static/

View file

@ -0,0 +1,55 @@
# see https://librepages.org/blog/2022-09-10-how-to-publish-website-without-librepages/
import os
DOMAIN = os.getenv("DOMAIN")
def test_nginx_is_installed(host):
pkg = host.package("nginx-common")
assert pkg.is_installed
def test_nginx_service_running_and_enabled(host):
service = host.service("nginx")
assert service.is_running
assert service.is_enabled
def test_nginx_is_listening(host):
for addr in ["0.0.0.0:80", "0.0.0.0:443"]:
socket = host.socket(f"tcp://{addr}")
assert socket.is_listening
def test_ufw_is_installed(host):
pkg = host.package("ufw")
assert pkg.is_installed
def test_ufw_service_running_and_enabled(host):
service = host.service("ufw")
assert service.is_running
assert service.is_enabled
def test_fail2ban_is_installed(host):
pkg = host.package("fail2ban")
assert pkg.is_installed
def test_fail2ban_is_enabled_and_running(host):
service = host.service("fail2ban")
assert service.is_running
assert service.is_enabled
def test_ssh_is_installed(host):
pkg = host.package("openssh-server")
assert pkg.is_installed
def test_ssh_is_enabled_and_running(host):
service = host.service("sshd")
assert service.is_running
assert service.is_enabled

View file

@ -0,0 +1,16 @@
def test_passwd_file(host):
passwd = host.file("/etc/passwd")
assert passwd.contains("atm")
assert passwd.user == "root"
assert passwd.group == "root"
assert passwd.mode == 0o644
def test_nginx_is_installed(host):
print(host)
assert host.exists("sc")
# cargo = host.package("sc")
# print(cargo)
# assert cargo.is_installed