forked from trailofbits/algo
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
1 parent
eb40ade
commit 53dfc57
Showing
8 changed files
with
177 additions
and
143 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,160 @@ | ||
name: Main | ||
|
||
on: [push, pull_request] | ||
|
||
jobs: | ||
lint: | ||
runs-on: ubuntu-18.04 | ||
steps: | ||
- uses: actions/checkout@v1 | ||
- uses: actions/setup-python@v1 | ||
with: | ||
python-version: '3.7' | ||
|
||
- name: Install dependencies | ||
run: | | ||
sudo apt update -y | ||
python -m pip install --upgrade pip | ||
pip install -r requirements.txt | ||
sudo snap install shellcheck | ||
pip install ansible-lint | ||
- name: Checks and linters | ||
run: | | ||
/snap/bin/shellcheck algo install.sh | ||
ansible-playbook main.yml --syntax-check | ||
ansible-lint -v *.yml roles/{local,cloud-*}/*/*.yml | ||
scripted-deploy: | ||
runs-on: ubuntu-16.04 | ||
strategy: | ||
matrix: | ||
UBUNTU_VERSION: ["18.04", "19.04", "19.10"] | ||
steps: | ||
- uses: actions/checkout@v1 | ||
- uses: actions/setup-python@v1 | ||
with: | ||
python-version: '3.7' | ||
|
||
- name: Install dependencies | ||
run: | | ||
sudo apt update -y | ||
sudo add-apt-repository -yu ppa:wireguard/wireguard | ||
sudo apt install -y \ | ||
python3-pip \ | ||
lxd \ | ||
expect-dev \ | ||
debootstrap \ | ||
tree \ | ||
bridge-utils \ | ||
dnsutils \ | ||
build-essential \ | ||
libssl-dev \ | ||
libffi-dev \ | ||
python3-dev \ | ||
linux-headers-$(uname -r) \ | ||
wireguard \ | ||
libxml2-utils \ | ||
crudini \ | ||
fping \ | ||
strongswan \ | ||
libstrongswan-standard-plugins \ | ||
resolvconf | ||
python3 -m pip install --upgrade pip | ||
python3 -m pip install -r requirements.txt | ||
- name: Provision | ||
env: | ||
DEPLOY: cloud-init | ||
UBUNTU_VERSION: ${{ matrix.UBUNTU_VERSION }} | ||
run: | | ||
ssh-keygen -f ~/.ssh/id_rsa -t rsa -N '' | ||
# sed -i "s/^reduce_mtu:\s0$/reduce_mtu: 80/" config.cfg | ||
sudo -E ./tests/pre-deploy.sh | ||
- name: Deployment | ||
run: | | ||
until sudo lxc exec algo -- test -f /var/log/cloud-init-output.log; do echo 'Log file not found, Sleep for 3 seconds'; sleep 3; done | ||
( sudo lxc exec algo -- tail -f /var/log/cloud-init-output.log & ) | ||
until sudo lxc exec algo -- test -f /var/lib/cloud/data/result.json; do | ||
echo 'Cloud init is not finished. Sleep for 30 seconds'; | ||
sleep 30; | ||
done | ||
sudo lxc exec algo -- test -f /opt/algo/configs/localhost/.config.yml | ||
sudo lxc exec algo -- tar zcf /root/algo-configs.tar -C /opt/algo/configs/ . | ||
sudo lxc file pull algo/root/algo-configs.tar ./ | ||
sudo tar -C ./configs -zxf algo-configs.tar | ||
- name: Tests | ||
run: | | ||
set -x | ||
sudo -E bash -x ./tests/wireguard-client.sh | ||
sudo env "PATH=$PATH" ./tests/ipsec-client.sh | ||
sudo ./tests/ssh-tunnel.sh | ||
local-deploy: | ||
runs-on: ubuntu-16.04 | ||
strategy: | ||
matrix: | ||
UBUNTU_VERSION: ["18.04", "19.04", "19.10"] | ||
steps: | ||
- uses: actions/checkout@v1 | ||
- uses: actions/setup-python@v1 | ||
with: | ||
python-version: '3.7' | ||
|
||
- name: Install dependencies | ||
run: | | ||
set -x | ||
sudo add-apt-repository -yu ppa:wireguard/wireguard | ||
sudo add-apt-repository -yu ppa:ubuntu-lxc/stable | ||
sudo apt update -y | ||
sudo apt install -y \ | ||
python3-pip \ | ||
lxd \ | ||
expect-dev \ | ||
debootstrap \ | ||
tree \ | ||
bridge-utils \ | ||
dnsutils \ | ||
build-essential \ | ||
libssl-dev \ | ||
libffi-dev \ | ||
python3-dev \ | ||
linux-headers-$(uname -r) \ | ||
wireguard \ | ||
libxml2-utils \ | ||
crudini \ | ||
fping \ | ||
strongswan \ | ||
libstrongswan-standard-plugins \ | ||
resolvconf | ||
python3 -m pip install --upgrade pip | ||
python3 -m pip install -r requirements.txt | ||
- name: Provision | ||
env: | ||
DEPLOY: docker | ||
UBUNTU_VERSION: ${{ matrix.UBUNTU_VERSION }} | ||
run: | | ||
ssh-keygen -f ~/.ssh/id_rsa -t rsa -N '' | ||
sed -i "s/^reduce_mtu:\s0$/reduce_mtu: 80/" config.cfg | ||
sudo -E ./tests/pre-deploy.sh | ||
- name: Deployment | ||
env: | ||
DEPLOY: docker | ||
UBUNTU_VERSION: ${{ matrix.UBUNTU_VERSION }} | ||
run: | | ||
docker build -t local/algo . | ||
./tests/local-deploy.sh | ||
./tests/update-users.sh | ||
- name: Tests | ||
run: | | ||
set -x | ||
sudo bash -x ./tests/wireguard-client.sh | ||
sudo env "PATH=$PATH" bash -x ./tests/ipsec-client.sh | ||
sudo bash -x ./tests/ssh-tunnel.sh |
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -2,14 +2,14 @@ | |
|
||
set -euxo pipefail | ||
|
||
PASS=$(grep ^p12_password: configs/10.0.8.100/.config.yml | awk '{print $2}') | ||
PASS=$(grep ^p12_password: configs/10.0.8.100/.config.yml | awk '{print $2}' | cut -f2 -d\') | ||
|
||
ssh-keygen -p -P ${PASS} -N '' -f configs/10.0.8.100/ssh-tunnel/desktop.pem | ||
|
||
ssh -o StrictHostKeyChecking=no -D 127.0.0.1:1080 -f -q -C -N [email protected] -i configs/10.0.8.100/ssh-tunnel/desktop.pem -F configs/10.0.8.100/ssh_config | ||
|
||
git config --global http.proxy 'socks5://127.0.0.1:1080' | ||
|
||
git clone -vv https://github.com/trailofbits/algo /tmp/ssh-tunnel-check | ||
for i in {1..10}; do git clone -vv https://github.com/trailofbits/algo /tmp/ssh-tunnel-check && break || sleep 1; done | ||
|
||
echo "SSH tunneling tests passed" |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters