diff --git a/.github/workflows/deploy-docker.yml b/.github/workflows/deploy-docker.yml index 072c8662f..d4f3488d5 100644 --- a/.github/workflows/deploy-docker.yml +++ b/.github/workflows/deploy-docker.yml @@ -181,6 +181,7 @@ jobs: if: failure() # Setup tmate session + - uses: actions/checkout@v4 - name: Setup tmate session uses: mxschmitt/action-tmate@v3 with: diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index d6325cbb8..92db55ed9 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -190,6 +190,7 @@ jobs: if: failure() # Setup tmate session + - uses: actions/checkout@v4 - name: Setup tmate session env: ACTIONS_STEP_DEBUG: ${{ secrets.ACTIONS_STEP_DEBUG}} diff --git a/ci-runner/features/steps/ci.py b/ci-runner/features/steps/ci.py index 3cb461066..ecbe231b0 100644 --- a/ci-runner/features/steps/ci.py +++ b/ci-runner/features/steps/ci.py @@ -1,19 +1,22 @@ import json -from behave import * +from behave import given, when, then from selenium.webdriver.support.expected_conditions import staleness_of, title_is, presence_of_element_located from selenium.webdriver.common.by import By + @given('we visit {url}') def step_impl(context, url): context.last_sub = None context.browser.get(url) + @given('we choose {idp}') def step_impl(context, idp): # Wait for DS to load - context.wait.until(title_is('SURF Research Access Management (Acceptance environment)'), - 'Timeout waiting for landing page') + context.wait.until(presence_of_element_located( + (By.ID, "add_button")), + 'Timeout waiting for Add another institution') # Click "Add another institution" add_button = context.browser.find_element(By.ID, 'add_button') @@ -32,16 +35,18 @@ def step_impl(context, idp): context.browser.find_element(By.XPATH, f"//div[@class='text-truncate label primary' and text()='{idp}']").click() context.wait.until(staleness_of(search)) + @given('we arrive at {url}') def step_impl(context, url): # Wait for IdP to load - assert(url in context.browser.current_url), "Error loading URL" + assert (url in context.browser.current_url), "Error loading URL" + @when('we login as {user}') def step_impl(context, user): # Login as user context.wait.until(presence_of_element_located( - (By.XPATH, f"//form")), + (By.XPATH, "//form")), 'Timeout waiting for result') test = user.split(':') username = test[0] @@ -50,6 +55,7 @@ def step_impl(context, user): context.browser.find_element(By.ID, 'password').send_keys(password) context.browser.find_element(By.XPATH, '//button[@type="submit"]').click() + @then('sub is {sub}') def step_impl(context, sub): context.wait.until(title_is('Test RP'), @@ -63,7 +69,8 @@ def step_impl(context, sub): output = json.loads(context.browser.find_element(By.ID, 'id_token').text) token_sub = output.get('sub', None) - assert(token_sub == sub), "No valid identifier found" + assert (token_sub == sub), "No valid identifier found" + @then('tokens are {file}') def step_impl(context, file): @@ -72,7 +79,7 @@ def step_impl(context, file): # Test RP title title = context.browser.title - assert(title == "Test RP"), "Error loading OP return url" + assert (title == "Test RP"), "Error loading OP return url" # Test user attributes id_token = json.loads(context.browser.find_element(By.ID, 'id_token').text) @@ -86,26 +93,26 @@ def step_impl(context, file): for claim, value in user_claims['id_token'].items(): if type(value) is list: - assert(set(id_token[claim]) == set(value)), f"id_token {claim} did not contain {value}" + assert (set(id_token[claim]) == set(value)), f"id_token {claim} did not contain {value}" else: - assert(id_token[claim] == value), f"id_token {claim} did not contain {value}" + assert (id_token[claim] == value), f"id_token {claim} did not contain {value}" for claim, value in user_claims['access_token_1'].items(): if type(value) is list: - assert(set(access_token_1[claim]) == set(value)), f"access_token_1 {claim} did not contain {value}" + assert (set(access_token_1[claim]) == set(value)), f"access_token_1 {claim} did not contain {value}" else: - assert(access_token_1[claim] == value), f"access_token_1 {claim} did not contain {value}" + assert (access_token_1[claim] == value), f"access_token_1 {claim} did not contain {value}" for claim, value in user_claims['access_token_2'].items(): if type(value) is list: - assert(set(access_token_2[claim]) == set(value)), f"access_token_2 {claim} did not contain {value}" + assert (set(access_token_2[claim]) == set(value)), f"access_token_2 {claim} did not contain {value}" else: - assert(access_token_2[claim] == value), f"access_token_2 {claim} did not contain {value}" + assert (access_token_2[claim] == value), f"access_token_2 {claim} did not contain {value}" for claim, value in user_claims['user_info'].items(): if type(value) is list: - assert(set(user_info_1[claim]) == set(value)), f"user_info_1 {claim} did not contain {value}" - assert(set(user_info_2[claim]) == set(value)), f"user_info_2 {claim} did not contain {value}" + assert (set(user_info_1[claim]) == set(value)), f"user_info_1 {claim} did not contain {value}" + assert (set(user_info_2[claim]) == set(value)), f"user_info_2 {claim} did not contain {value}" else: - assert(user_info_1[claim] == value), f"user_info_1 {claim} did not contain {value}" - assert(user_info_2[claim] == value), f"user_info_2 {claim} did not contain {value}" + assert (user_info_1[claim] == value), f"user_info_1 {claim} did not contain {value}" + assert (user_info_2[claim] == value), f"user_info_2 {claim} did not contain {value}" diff --git a/environments/ci/group_vars/all.yml b/environments/ci/group_vars/all.yml index fbc7bafa8..faa50fb55 100644 --- a/environments/ci/group_vars/all.yml +++ b/environments/ci/group_vars/all.yml @@ -13,7 +13,7 @@ admin_email: "admin@{{base_domain}}" is_aws: false is_dev: true experimental_features: true -debian_dist: "bookworm" # CI needs bookworm because of SSP +debian_dist: "bookworm" servers: dns: diff --git a/environments/ci/group_vars/ci.yml b/environments/ci/group_vars/ci.yml index 11a9b5858..61b6e871c 100644 --- a/environments/ci/group_vars/ci.yml +++ b/environments/ci/group_vars/ci.yml @@ -140,3 +140,5 @@ sbs_ssid_identity_providers: sbs_encryption_key: secret sbs_cron_job_responsible: True + +sbs_id_scope: "scz-vm.net" diff --git a/environments/docker/group_vars/all.yml b/environments/docker/group_vars/all.yml index 6859d658f..15d539c54 100644 --- a/environments/docker/group_vars/all.yml +++ b/environments/docker/group_vars/all.yml @@ -15,6 +15,7 @@ is_aws: false is_dev: true sram_ansible_nolog: false experimental_features: true +debian_dist: "bookworm" servers: dns: diff --git a/environments/docker/group_vars/container.yml b/environments/docker/group_vars/container.yml index 755331841..ab5274c1e 100644 --- a/environments/docker/group_vars/container.yml +++ b/environments/docker/group_vars/container.yml @@ -236,3 +236,5 @@ sbs_send_exceptions: True sbs_send_js_exceptions: True sbs_exceptions_mail: sram-beheer@{{base_domain}} sbs_cron_job_responsible: True + +sbs_id_scope: "scz-vm.net" diff --git a/environments/vm/group_vars/all.yml b/environments/vm/group_vars/all.yml index 63d8bde23..4c17e7b2a 100644 --- a/environments/vm/group_vars/all.yml +++ b/environments/vm/group_vars/all.yml @@ -14,6 +14,7 @@ is_aws: false is_dev: true sram_ansible_nolog: false experimental_features: true +debian_dist: "bookworm" servers: dns: diff --git a/environments/vm/group_vars/sbs.yml b/environments/vm/group_vars/sbs.yml index 705705e87..a7e79365f 100644 --- a/environments/vm/group_vars/sbs.yml +++ b/environments/vm/group_vars/sbs.yml @@ -76,3 +76,5 @@ sbs_ssid_identity_providers: sbs_encryption_key: secret sbs_cron_job_responsible: True + +sbs_id_scope: "scz-vm.net" diff --git a/roles/apt/defaults/main.yml b/roles/apt/defaults/main.yml index b82dbb1a8..369eb3dc5 100644 --- a/roles/apt/defaults/main.yml +++ b/roles/apt/defaults/main.yml @@ -1,5 +1,5 @@ --- -debian_dist: 'bullseye' +# debian_dist: 'bookworm' deb_host: >- {% if is_aws | default(false) -%} diff --git a/roles/db_server/defaults/main.yml b/roles/db_server/defaults/main.yml index 0ffc52925..ed97d539c 100644 --- a/roles/db_server/defaults/main.yml +++ b/roles/db_server/defaults/main.yml @@ -1,2 +1 @@ --- -debian_dist: 'bullseye' diff --git a/roles/sbs/templates/config.yml.j2 b/roles/sbs/templates/config.yml.j2 index 0c817e55b..66f604e88 100644 --- a/roles/sbs/templates/config.yml.j2 +++ b/roles/sbs/templates/config.yml.j2 @@ -51,7 +51,6 @@ oidc: base_scope: "{{ base_domain }}" entitlement_group_namespace: "{{ sbs_urn_namespace }}" eppn_scope: " {{ sbs_eppn_scope }}" -scim_schema_sram: "urn:mace:surf.nl:sram:scim:extension" collaboration_creation_allowed_entitlement: "urn:mace:surf.nl:sram:allow-create-co" {% if environment_name == "prd" %} @@ -124,7 +123,6 @@ feature: sbs_swagger_enabled: {{ sbs_swagger_enabled }} admin_platform_backdoor_totp: {{ sbs_admin_platform_backdoor_totp }} past_dates_allowed: {{ sbs_past_dates_allowed }} - mock_scim_enabled: {{ sbs_mock_scim_enabled }} metadata: idp_url: "{{sbs_idp_metadata_url}}" @@ -226,11 +224,15 @@ open_requests: enabled: {{ sbs_open_requests_enabled }} cron_day_of_week: 1 -scim_sweep: - # Do we enable scim sweeps? - enabled: {{ sbs_scim_sweep }} - # How often do we check if scim sweeps are needed per service - cron_minutes_expression: "*/15" +scim: + id_scope: "{{ sbs_id_scope }}" + schema_sram: "urn:mace:surf.nl:sram:scim:extension" + mock_scim_enabled: {{ sbs_mock_scim_enabled }} + sweep: + # Do we enable scim sweeps? + enabled: {{ sbs_scim_sweep }} + # How often do we check if scim sweeps are needed per service + cron_minutes_expression: "*/15" ldap: url: "{{ sbs_ldap_url }}" diff --git a/roles/zabbix-agent/defaults/main.yml b/roles/zabbix-agent/defaults/main.yml index d9efcbc2f..d49a216b7 100644 --- a/roles/zabbix-agent/defaults/main.yml +++ b/roles/zabbix-agent/defaults/main.yml @@ -1,4 +1,5 @@ --- +zabbix_version: "7.4" zabbix_psk_file: "/etc/zabbix/zabbix-agent2.psk" zabbix_templates_default: - "Linux by Zabbix agent active" @@ -7,4 +8,3 @@ zabbix_templates_extra: [] zabbix_validate_certs: true zabbix_passive_check: true -debian_dist: "bullseye" diff --git a/roles/zabbix-agent/tasks/main.yml b/roles/zabbix-agent/tasks/main.yml index 535b60096..3af9e8840 100644 --- a/roles/zabbix-agent/tasks/main.yml +++ b/roles/zabbix-agent/tasks/main.yml @@ -21,10 +21,11 @@ - "5_4" - "6_2" - "6_4" + - "7_2" - name: "Zabbix repo: install source" apt_repository: - repo: "deb https://repo.zabbix.com/zabbix/7.2/stable/debian {{debian_dist}} main" + repo: "deb https://repo.zabbix.com/zabbix/{{ zabbix_version }}/stable/debian {{ debian_dist }} main" state: "present" - name: "Ensure that packages are installed" @@ -32,6 +33,7 @@ name: "zabbix-agent2" state: "latest" install_recommends: false + update_cache: true - name: "Make sure the zabbix user can read journald entries" ansible.builtin.user: