#
# Copyright 2021 The Sigstore Authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
#     http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.

name: e2e-tests

# Run on every push, and allow it to be run manually.
on:
  push:
    paths:
      - '**'
      - '!**.md'
      - '!doc/**'
      - '!**.txt'
      - '!images/**'
      - '!LICENSE'
      - 'test/**'
    branches:
      - "main"
  pull_request:
  workflow_dispatch:

jobs:
  e2e-cross:
    strategy:
      matrix:
        os: [macos-latest, ubuntu-latest]
    runs-on: ${{ matrix.os }}

    steps:
      - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
        with:
          persist-credentials: false

      - name: Extract version of Go to use
        run: echo "GOVERSION=$(awk -F'[:@]' '/FROM golang/{print $2; exit}' Dockerfile)" >> $GITHUB_ENV

      - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
        with:
          go-version: '${{ env.GOVERSION }}'
          check-latest: true
          cache: false

      - name: Run cross platform e2e tests
        run: go test -tags=e2e,cross -v ./test/...

  e2e-test-pkcs11:
    runs-on: ubuntu-latest

    steps:
      - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
        with:
          persist-credentials: false

      - name: Extract version of Go to use
        run: echo "GOVERSION=$(awk -F'[:@]' '/FROM golang/{print $2; exit}' Dockerfile)" >> $GITHUB_ENV

      - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
        with:
          go-version: '${{ env.GOVERSION }}'
          check-latest: true
          cache: false

      - name: Run pkcs11 end-to-end tests
        shell: bash
        run: ./test/e2e_test_pkcs11.sh

  e2e-kms:
    runs-on: ubuntu-latest
    services:
      vault:
        image: hashicorp/vault:latest
        env:
          VAULT_DEV_ROOT_TOKEN_ID: root
        options: >-
          --cap-add=IPC_LOCK
          --health-cmd "VAULT_ADDR=http://127.0.0.1:8200 vault status"
          --health-interval 1s
          --health-timeout 5s
          --health-retries 5
          --restart always
        ports:
          - 8200:8200

    env:
      VAULT_TOKEN: "root"
      VAULT_ADDR: "http://localhost:8200"
      COSIGN_YES: "true"
      SCAFFOLDING_RELEASE_VERSION: "v0.7.24"
    steps:
      - name: Checkout
        uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
        with:
          persist-credentials: false

      - name: setup vault
        uses: cpanato/vault-installer@fe568170412f5d81202ec528148f05176efbecc1 # v1.4.0

      - name: Extract version of Go to use
        run: echo "GOVERSION=$(awk -F'[:@]' '/FROM golang/{print $2; exit}' Dockerfile)" >> $GITHUB_ENV

      - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
        with:
          go-version: '${{ env.GOVERSION }}'
          check-latest: true
          cache: false

      - uses: imjasonh/setup-crane@6da1ae018866400525525ce74ff892880c099987 # v0.5

      - name: Install cluster + sigstore
        uses: sigstore/scaffolding/actions/setup@main
        with:
          version: ${{ env.SCAFFOLDING_RELEASE_VERSION }}

      - name: enable vault transit
        run: vault secrets enable transit

      - name: Acceptance Tests
        run: go test -tags=e2e,kms -v ./test/...

  e2e-registry:
    runs-on: ubuntu-latest

    env:
      SCAFFOLDING_RELEASE_VERSION: "v0.7.24"

    steps:
    - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
      with:
        persist-credentials: false

    - name: Extract version of Go to use
      run: echo "GOVERSION=$(awk -F'[:@]' '/FROM golang/{print $2; exit}' Dockerfile)" >> $GITHUB_ENV

    - uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
      with:
        go-version: '${{ env.GOVERSION }}'
        check-latest: true
        cache: false

    - name: Setup mirror
      uses: chainguard-dev/actions/setup-mirror@c69a264ec2a5934c3186c618f368fc1c86f16cff # v1.6.19
      with:
        mirror: mirror.gcr.io

    - name: Install cluster + sigstore
      uses: sigstore/scaffolding/actions/setup@main
      with:
        version: ${{ env.SCAFFOLDING_RELEASE_VERSION }}

    - name: Setup local insecure registry
      run: |
        # Create a self-signed SSL cert
        mkdir -p insecure-certs
        openssl req \
          -subj "/C=US/ST=WA/L=Flavorton/O=Tests-R-Us/OU=Dept. of Insecurity/CN=example.com/emailAddress=testing@example.com" \
          -newkey rsa:4096 -nodes -sha256 -keyout insecure-certs/domain.key \
          -x509 -days 365 -out insecure-certs/domain.crt
        # Run a registry.
        docker run -d  --restart=always \
          --name $INSECURE_REGISTRY_NAME \
          -v "$(pwd)"/insecure-certs:/insecure-certs \
          -e REGISTRY_HTTP_ADDR=0.0.0.0:$INSECURE_REGISTRY_PORT \
          -e REGISTRY_HTTP_TLS_CERTIFICATE=/insecure-certs/domain.crt \
          -e REGISTRY_HTTP_TLS_KEY=/insecure-certs/domain.key \
          -p $INSECURE_REGISTRY_PORT:$INSECURE_REGISTRY_PORT \
          registry:2
        sudo echo "127.0.0.1 $INSECURE_REGISTRY_NAME" | sudo tee -a /etc/hosts
      env:
        # https://github.com/google/go-containerregistry/pull/125 allows insecure registry for
        # '*.local' hostnames.
        INSECURE_REGISTRY_NAME: insecure-registry.notlocal
        INSECURE_REGISTRY_PORT: 5001

    - name: Run Insecure Registry Tests
      run: go test -tags=e2e,registry -v ./test/...
      env:
        COSIGN_TEST_REPO: insecure-registry.notlocal:5001
        TUF_ROOT_JSON: ${{ github.workspace }}/root.json

    - name: Setup local insecure OCI 1.1 registry
      run: |
        # Create a self-signed SSL cert
        mkdir -p insecure-certs
        openssl req \
          -subj "/C=US/ST=WA/L=Flavorton/O=Tests-R-Us/OU=Dept. of Insecurity/CN=example.com/emailAddress=testing@example.com" \
          -newkey rsa:4096 -nodes -sha256 -keyout insecure-certs/domain.key \
          -x509 -days 365 -out insecure-certs/domain.crt
        cat > config.json << EOF
        {
          "distSpecVersion": "1.1.0-dev",
          "storage": {
            "rootDirectory": "/tmp/zot"
          },
          "http": {
            "address": "0.0.0.0",
            "port": "5002",
            "realm": "zot",
            "tls": {
              "cert": "/insecure-certs/domain.crt",
              "key": "/insecure-certs/domain.key"
            }
          },
          "log": {
            "level": "debug"
          }
        }
        EOF
        # Run a registry.
        docker run -d  --restart=always \
          --name $INSECURE_OCI_REGISTRY_NAME \
          -v "$(pwd)"/insecure-certs:/insecure-certs \
          -v "$(pwd)"/config.json:/etc/zot/config.json \
          -p $INSECURE_OCI_REGISTRY_PORT:$INSECURE_OCI_REGISTRY_PORT \
          ghcr.io/project-zot/zot-minimal-linux-amd64:$ZOT_VERSION
        sudo echo "127.0.0.1 $INSECURE_OCI_REGISTRY_NAME" | sudo tee -a /etc/hosts
      env:
        ZOT_VERSION: v2.0.0-rc6
        # https://github.com/google/go-containerregistry/pull/125 allows insecure registry for
        # '*.local' hostnames.
        INSECURE_OCI_REGISTRY_NAME: insecure-oci-registry.notlocal
        INSECURE_OCI_REGISTRY_PORT: 5002


    - name: Run Insecure OCI 1.1 Registry Tests
      run: go test -tags=e2e,registry -v ./test/...
      env:
        OCI11: yes
        COSIGN_TEST_REPO: insecure-oci-registry.notlocal:5002
        TUF_ROOT_JSON: ${{ github.workspace }}/root.json

    - name: Set up local HTTP registry
      run: |
        docker run -d --restart=always \
          --name $HTTP_REGISTRY_NAME \
          -p $HTTP_REGISTRY_PORT:5000 registry:2.8.1
        sudo echo "127.0.0.1 $HTTP_REGISTRY_NAME" | sudo tee -a /etc/hosts
      env:
        HTTP_REGISTRY_NAME: http-registry.notlocal
        HTTP_REGISTRY_PORT: 5003

    - name: Run HTTP registry tests
      run: go test -tags=e2e,registry -v ./test/...
      env:
        COSIGN_TEST_REPO: http-registry.notlocal:5003
        TUF_ROOT_JSON: ${{ github.workspace }}/root.json

    - name: Collect diagnostics
      if: ${{ failure() }}
      uses: chainguard-dev/actions/kind-diag@c69a264ec2a5934c3186c618f368fc1c86f16cff # v1.6.19
