Use nftables to configure firewall #1903
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: Test | |
on: [push, pull_request] | |
jobs: | |
test: | |
runs-on: ubuntu-22.04 | |
strategy: | |
matrix: | |
python-version: [3.11] | |
steps: | |
- uses: actions/checkout@v2 | |
with: | |
submodules: true | |
- name: Checkout submodules | |
run: git submodule update --init | |
- name: Set up Python ${{ matrix.python-version }} | |
uses: actions/setup-python@v1 | |
with: | |
python-version: ${{ matrix.python-version }} | |
- name: Install ubuntu dependencies | |
run: | | |
sudo apt-get update | |
sudo apt-get install iptables nftables python3-nftables | |
- name: Install python dependencies | |
run: | | |
python -m pip install --upgrade pip | |
# pip install setuptools==75.5.0 | |
pip install -e .[dev] | |
- name: Lint with flake8 | |
run: | | |
flake8 . | |
- name: Build binary - normal | |
run: | | |
mkdir -p ./dist | |
docker build . -t node-cli-builder | |
docker run -v /home/ubuntu/dist:/app/dist node-cli-builder scripts/build.sh test test normal | |
docker rm -f $(docker ps -aq) | |
- name: Check build - normal | |
run: sudo /home/ubuntu/dist/skale-test-Linux-x86_64 | |
- name: Build binary - sync | |
run: | | |
mkdir -p ./dist | |
docker build . -t node-cli-builder | |
docker run -v /home/ubuntu/dist:/app/dist node-cli-builder scripts/build.sh test test sync | |
docker rm -f $(docker ps -aq) | |
- name: Check build - sync | |
run: sudo /home/ubuntu/dist/skale-test-Linux-x86_64-sync | |
- name: Run prepare test build | |
run: | | |
scripts/build.sh test test normal | |
- name: Run tests | |
run: | | |
export PYTHONPATH=${PYTHONPATH}:/usr/lib/python3/dist-packages/ | |
bash ./scripts/run_tests.sh | |
- name: Run nftables tests | |
run: | | |
bash ./scripts/run_tests.sh | |
docker build . -t node-cli-tester && docker run --name tester --cap-add=NET_ADMIN --cap-add=NET_RAW --rm tester scripts/run_nftables_test.sh |