test(molecule): run make test in parallel on one image #17
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "test/fast-molecule"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
make testran the 15 molecule scenarios one after another, each on itsown image rebuilt at every create, and was too slow to run before a role
change. The target was under ~5 minutes on a 20-core machine with the
same scenarios and assertions.
What changed
make testruns the scenarios throughtests/molecule/run.sh, ten ata time (
make test J=4to change it), with one log per scenario in.molecule-logs/and a timing table at the end. The first failure,by exit status or by an
^ERRORline, stops the run, and the runner No changes this sessiondestroys every scenario that started. Ctrl-C stops and destroys too,
and a second Ctrl-C during cleanup exits at once.
tests/molecule/Containerfile:Debian 12 with systemd and python3. It also carries the roles'
packages, downloaded but not installed, so each role still installs
them for real without fetching them. The 15
Dockerfile.j2files aregone. The podman driver used to rebuild one shared tag from a different
Dockerfile at every create, which would have raced in parallel.
openssh-servermoved intohardening-basic'sprepare.yml.MOLECULE_ROLESlists the slowest roles first, soscan-share(~300s)no longer waits for a free slot.
tag_propagationwrites its output to.molecule-logs/and printsits tail only on failure.
scan-share): their
fail_msgrendered to a list or dict, whichansible-core 2.21 rejects before evaluating the assertion, so those
tasks failed on every run. They now render as JSON.
Scenarios, assertions and role tasks are otherwise unchanged. The Makefile
keeps its four targets. CONTRIBUTING#molecule describes the runner.
The shared castrum-apt-archives volume broke parallel runs: apt does not wait for /var/cache/apt/archives/lock, so a second container installing at the same time failed at once ("held by process 0"). The image now carries the packages the roles install, downloaded but not installed, so each container has its own copy of the cache: roles still install for real, nothing is fetched during the run, and nothing is shared between containers.