Audit details * Audit logs and broadcasts accept `details` whose values are included as log tags and MRSK_* env vars passed to the broadcast command * Commands may return execution options to the CLI in their args list * Introduce `mrsk broadcast` helper for sending audit broadcasts * Report UTC time, not local time, in audit logs. Standardize on ISO 8601 format
71 lines
2.2 KiB
Ruby
71 lines
2.2 KiB
Ruby
require "test_helper"
|
|
|
|
class CommandsAuditorTest < ActiveSupport::TestCase
|
|
setup do
|
|
@config = {
|
|
service: "app", image: "dhh/app", registry: { "username" => "dhh", "password" => "secret" }, servers: [ "1.1.1.1" ],
|
|
audit_broadcast_cmd: "bin/audit_broadcast"
|
|
}
|
|
|
|
@auditor = new_command
|
|
end
|
|
|
|
test "record" do
|
|
assert_equal [
|
|
:echo,
|
|
"[#{@auditor.details[:recorded_at]}]", "[#{@auditor.details[:performer]}]",
|
|
"app removed container",
|
|
">>", "mrsk-app-audit.log"
|
|
], @auditor.record("app removed container")
|
|
end
|
|
|
|
test "record with destination" do
|
|
new_command(destination: "staging").tap do |auditor|
|
|
assert_equal [
|
|
:echo,
|
|
"[#{auditor.details[:recorded_at]}]", "[#{auditor.details[:performer]}]", "[#{auditor.details[:destination]}]",
|
|
"app removed container",
|
|
">>", "mrsk-app-staging-audit.log"
|
|
], auditor.record("app removed container")
|
|
end
|
|
end
|
|
|
|
test "record with command details" do
|
|
new_command(role: "web").tap do |auditor|
|
|
assert_equal [
|
|
:echo,
|
|
"[#{auditor.details[:recorded_at]}]", "[#{auditor.details[:performer]}]", "[#{auditor.details[:role]}]",
|
|
"app removed container",
|
|
">>", "mrsk-app-audit.log"
|
|
], auditor.record("app removed container")
|
|
end
|
|
end
|
|
|
|
test "record with arg details" do
|
|
assert_equal [
|
|
:echo,
|
|
"[#{@auditor.details[:recorded_at]}]", "[#{@auditor.details[:performer]}]", "[value]",
|
|
"app removed container",
|
|
">>", "mrsk-app-audit.log"
|
|
], @auditor.record("app removed container", detail: "value")
|
|
end
|
|
|
|
test "broadcast" do
|
|
assert_equal [
|
|
"bin/audit_broadcast",
|
|
"'[#{@auditor.details[:performer]}] [value] app removed container'",
|
|
env: {
|
|
"MRSK_RECORDED_AT" => @auditor.details[:recorded_at],
|
|
"MRSK_PERFORMER" => @auditor.details[:performer],
|
|
"MRSK_EVENT" => "app removed container",
|
|
"MRSK_DETAIL" => "value"
|
|
}
|
|
], @auditor.broadcast("app removed container", detail: "value")
|
|
end
|
|
|
|
private
|
|
def new_command(destination: nil, **details)
|
|
Mrsk::Commands::Auditor.new(Mrsk::Configuration.new(@config, destination: destination, version: "123"), **details)
|
|
end
|
|
end
|