mirror of
https://github.com/tailscale/github-action.git
synced 2026-08-20 13:09:20 +00:00
Add support for workload identity federation based authentication. Updates https://github.com/tailscale/corp/issues/31264 Signed-off-by: Mario Minardi <mario@tailscale.com>
167 lines
4.9 KiB
YAML
167 lines
4.9 KiB
YAML
name: "Integration Tests"
|
|
|
|
permissions:
|
|
id-token: write # This is required for requesting the JWT for workload identity
|
|
|
|
on:
|
|
pull_request:
|
|
workflow_dispatch:
|
|
push:
|
|
branches:
|
|
- main
|
|
|
|
jobs:
|
|
# Matrix test for all supported platforms and architectures
|
|
|
|
integration-tests:
|
|
name: ${{ matrix.os }} (${{ matrix.arch }}) (${{ matrix.credential-type }}) tailscale-${{ matrix.version }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
# Linux tests (AMD64)
|
|
- os: ubuntu-latest
|
|
runner-os: Linux
|
|
arch: amd64
|
|
version: latest
|
|
ping: 100.99.0.2,lax-pve.pineapplefish.ts.net,lax-pve
|
|
credential-type: oauth
|
|
|
|
# Try unstable too
|
|
- os: ubuntu-latest
|
|
runner-os: Linux
|
|
arch: amd64
|
|
version: unstable
|
|
credential-type: oauth
|
|
|
|
# Try a pinned version
|
|
- os: ubuntu-latest
|
|
runner-os: Linux
|
|
arch: amd64
|
|
credential-type: oauth
|
|
# leave version blank to fall back to default
|
|
|
|
# Linux tests (ARM64)
|
|
- os: ubuntu-24.04-arm
|
|
runner-os: Linux
|
|
arch: arm64
|
|
version: latest
|
|
credential-type: oauth
|
|
|
|
# Windows tests (AMD64)
|
|
- os: windows-latest
|
|
runner-os: Windows
|
|
arch: amd64
|
|
version: latest
|
|
ping: 100.99.0.2,lax-pve.pineapplefish.ts.net,lax-pve
|
|
credential-type: oauth
|
|
|
|
# Windows tests (ARM64)
|
|
- os: windows-11-arm
|
|
runner-os: Windows
|
|
arch: arm64
|
|
version: latest
|
|
credential-type: oauth
|
|
|
|
# macOS 13 (AMD64)
|
|
- os: macos-13
|
|
runner-os: macOS
|
|
arch: amd64
|
|
version: latest
|
|
ping: 100.99.0.2,lax-pve.pineapplefish.ts.net,lax-pve
|
|
credential-type: oauth
|
|
|
|
# macOS 14 (ARM)
|
|
- os: macos-14
|
|
runner-os: macOS
|
|
arch: arm64
|
|
version: latest
|
|
ping: 100.99.0.2,lax-pve.pineapplefish.ts.net,lax-pve
|
|
credential-type: oauth
|
|
|
|
# macOS latest (ARM)
|
|
- os: macos-latest
|
|
runner-os: macOS
|
|
arch: arm64
|
|
version: latest
|
|
ping: 100.99.0.2,lax-pve.pineapplefish.ts.net,lax-pve
|
|
credential-type: oauth
|
|
|
|
# Try workload identity for each platform
|
|
- os: macos-latest
|
|
runner-os: macOS
|
|
arch: amd64
|
|
version: latest
|
|
ping: 100.99.0.2,lax-pve.pineapplefish.ts.net,lax-pve
|
|
credential-type: workload-identity
|
|
|
|
- os: windows-latest
|
|
runner-os: Windows
|
|
arch: amd64
|
|
ping: 100.99.0.2,lax-pve.pineapplefish.ts.net,lax-pve
|
|
credential-type: workload-identity
|
|
# leave version blank to fall back to default
|
|
|
|
# Try adding in an unstable
|
|
- os: ubuntu-latest
|
|
runner-os: Linux
|
|
arch: amd64
|
|
version: unstable
|
|
credential-type: workload-identity
|
|
|
|
|
|
runs-on: ${{ matrix.os }}
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
|
|
with:
|
|
node-version: "24"
|
|
cache: "npm"
|
|
|
|
- name: Install Dependencies
|
|
run: npm ci
|
|
|
|
- name: Build Action
|
|
run: npm run build
|
|
|
|
# Test with OAuth authentication
|
|
- name: Test Action
|
|
id: tailscale-oauth
|
|
uses: ./
|
|
with:
|
|
oauth-client-id: ${{ matrix.credential-type == 'oauth' && secrets.TS_AUTH_KEYS_OAUTH_CLIENT_ID || secrets.TS_WORKLOAD_IDENTITY_CLIENT_ID }}
|
|
oauth-secret: ${{ matrix.credential-type == 'oauth' && secrets.TS_AUTH_KEYS_OAUTH_CLIENT_SECRET || '' }}
|
|
audience: ${{ matrix.credential-type == 'workload-identity' && secrets.TS_AUDIENCE || ''}}
|
|
tags: "tag:ci"
|
|
version: "${{ matrix.version }}"
|
|
use-cache: false
|
|
timeout: "5m"
|
|
retry: 3
|
|
ping: "${{ matrix.ping }}"
|
|
|
|
# Look up names to make sure MagicDNS is working
|
|
- name: Look up qualified name
|
|
run: nslookup lax-pve.pineapplefish.ts.net
|
|
|
|
- name: Look up unqualified name
|
|
run: nslookup lax-pve
|
|
|
|
# Test Tailscale status command
|
|
- name: Check Tailscale Status
|
|
if: steps.tailscale-oauth.outcome == 'success'
|
|
run: |
|
|
echo "Testing Tailscale status command..."
|
|
if [ "${{ matrix.runner-os }}" == "Windows" ]; then
|
|
# Windows uses system-installed binary without sudo
|
|
tailscale status
|
|
tailscale version
|
|
else
|
|
# Linux and macOS use system-installed binary with sudo
|
|
sudo -E tailscale status
|
|
tailscale version
|
|
fi
|
|
shell: bash
|