Skip to content

E2E-1 (real cluster): hybrid Helm tests with local chart + Kind preload

Placeholder ppxd requested to merge feat/e2e-1-hybrid-helm-real-cluster into main

Summary

Companion to the existing HelmChartUpgradeE2ETests (contract-tier Pattern 2 — captures script but doesn't execute). This PR adds Execution-tier hybrid tests that ACTUALLY run helm against a real Kind cluster and verify resources materialise as kubectl-queryable objects.

Resolves the audit's most pointed feedback: "目前的測試是不是模擬真實 k8s 的 target 情況進行真實用集群來測試的,不是 mock 的為了測試而通過". Answer: contract-tier ❌, this PR's execution-tier ✅.

Stability-first design (every choice)

Risk Mitigation
helm repo add bitnami public-network flakiness Local test chart at Resources/test-charts/squid-test-chart/ — zero net deps
Docker Hub rate limits (100 pulls / 6h / IP) KindClusterFixture.TryPreloadImagesAsync runs kind load docker-image busybox:latest on init
Pod-Ready timing flakiness (20-60s) Assert kubectl get deployment exists with right spec — never wait for pod Ready
Cross-test state pollution GUID-suffixed namespace + release per test; aggressive finally cleanup
No-helm-CLI runners IsHelmCliAvailableAsync → skip with clear console message pointing to azure/setup-helm@v4

5 new tests

Test Style coverage Verifies
RealHelm_BasicChartInstall_DeploymentExistsInKind Theory (both) Real install + Deployment exists with default spec
RealHelm_InlineKeyValues_AppliedToDeployment Theory (both) InlineValues flow through to real Deployment.spec.replicas
RealHelm_SensitiveInlineValue_NotInProcessArgv_OnRealAgent KubernetesApi P0-Phase10.2 SECURITY on real cluster: script body has no secret, inline-values.yaml does, Deployment's env carries it — end-to-end value flow without argv leak
RealHelm_SecondInstallSameRelease_IsIdempotentUpgrade KubernetesApi Two identical runs → 1 Deployment + helm revision=2

All tagged [Trait("Tier", "Execution")]. Existing HelmChartUpgradeE2ETests tagged [Trait("Tier", "Contract")]. Two-tier model: Contract on every CI commit (fast), Execution on slower pipeline.

Files

  • Resources/test-charts/squid-test-chart/ (new): minimal Helm chart (Chart.yaml + values.yaml + 1 template), busybox image, no remote deps
  • Infrastructure/KindClusterFixture.cs: added TryPreloadImagesAsync step in InitializeAsync
  • Squid.E2ETests.csproj: Resources/test-charts/**/* with CopyToOutputDirectory=PreserveNewest
  • Pipeline/HelmChartUpgradeE2ETests.cs: tagged [Trait("Tier", "Contract")]
  • Pipeline/HelmChartUpgradeRealClusterE2ETests.cs (new): 5 execution-tier test methods

Note on CI workflow

There's currently no GitHub Actions workflow for Squid.E2ETests (only Tentacle / upgrade-matrix workflows exist). The contract tests in PRs #290 / #291 also haven't been CI-verified yet at the E2E project level. A follow-up will add e2e-k8s-pipeline.yml that:

  1. Sets up Kind via helm/kind-action@v1
  2. Installs helm via azure/setup-helm@v4
  3. Runs dotnet test --filter Tier=Contract (fast pipeline)
  4. Runs dotnet test --filter Tier=Execution (slower pipeline, possibly on schedule)

For this PR: tests verified to build clean locally; ready when CI workflow lands.

🤖 Generated with Claude Code

Merge request reports

Loading