E2E-1 (real cluster): hybrid Helm tests with local chart + Kind preload
Summary
Companion to the existing HelmChartUpgradeE2ETests (contract-tier Pattern 2 — captures script but doesn't execute). This PR adds Execution-tier hybrid tests that ACTUALLY run helm against a real Kind cluster and verify resources materialise as kubectl-queryable objects.
Resolves the audit's most pointed feedback: "目前的測試是不是模擬真實 k8s 的 target 情況進行真實用集群來測試的,不是 mock 的為了測試而通過". Answer: contract-tier
Stability-first design (every choice)
| Risk | Mitigation |
|---|---|
helm repo add bitnami public-network flakiness |
Local test chart at Resources/test-charts/squid-test-chart/ — zero net deps |
| Docker Hub rate limits (100 pulls / 6h / IP) |
KindClusterFixture.TryPreloadImagesAsync runs kind load docker-image busybox:latest on init |
| Pod-Ready timing flakiness (20-60s) | Assert kubectl get deployment exists with right spec — never wait for pod Ready |
| Cross-test state pollution | GUID-suffixed namespace + release per test; aggressive finally cleanup |
| No-helm-CLI runners |
IsHelmCliAvailableAsync → skip with clear console message pointing to azure/setup-helm@v4
|
5 new tests
| Test | Style coverage | Verifies |
|---|---|---|
RealHelm_BasicChartInstall_DeploymentExistsInKind |
Theory (both) | Real install + Deployment exists with default spec |
RealHelm_InlineKeyValues_AppliedToDeployment |
Theory (both) | InlineValues flow through to real Deployment.spec.replicas |
RealHelm_SensitiveInlineValue_NotInProcessArgv_OnRealAgent |
KubernetesApi | P0-Phase10.2 SECURITY on real cluster: script body has no secret, inline-values.yaml does, Deployment's env carries it — end-to-end value flow without argv leak |
RealHelm_SecondInstallSameRelease_IsIdempotentUpgrade |
KubernetesApi | Two identical runs → 1 Deployment + helm revision=2 |
All tagged [Trait("Tier", "Execution")]. Existing HelmChartUpgradeE2ETests tagged [Trait("Tier", "Contract")]. Two-tier model: Contract on every CI commit (fast), Execution on slower pipeline.
Files
-
Resources/test-charts/squid-test-chart/(new): minimal Helm chart (Chart.yaml + values.yaml + 1 template), busybox image, no remote deps -
Infrastructure/KindClusterFixture.cs: addedTryPreloadImagesAsyncstep inInitializeAsync -
Squid.E2ETests.csproj:Resources/test-charts/**/*withCopyToOutputDirectory=PreserveNewest -
Pipeline/HelmChartUpgradeE2ETests.cs: tagged[Trait("Tier", "Contract")] -
Pipeline/HelmChartUpgradeRealClusterE2ETests.cs(new): 5 execution-tier test methods
Note on CI workflow
There's currently no GitHub Actions workflow for Squid.E2ETests (only Tentacle / upgrade-matrix workflows exist). The contract tests in PRs #290 / #291 also haven't been CI-verified yet at the E2E project level. A follow-up will add e2e-k8s-pipeline.yml that:
- Sets up Kind via
helm/kind-action@v1 - Installs helm via
azure/setup-helm@v4 - Runs
dotnet test --filter Tier=Contract(fast pipeline) - Runs
dotnet test --filter Tier=Execution(slower pipeline, possibly on schedule)
For this PR: tests verified to build clean locally; ready when CI workflow lands.