vuls: init at 0.27.0
[NixPkgs.git] / nixos / tests / sslh.nix
blob30ffd389d4422c81fd9bdaa0ecf3e17b8ff46455
1 import ./make-test-python.nix {
2   name = "sslh";
4   nodes = {
5     server = { pkgs, lib, ... }: {
6       networking.firewall.allowedTCPPorts = [ 443 ];
7       networking.interfaces.eth1.ipv6.addresses = [
8         {
9           address = "fe00:aa:bb:cc::2";
10           prefixLength = 64;
11         }
12       ];
13       services.sslh = {
14         enable = true;
15         settings.transparent = true;
16         settings.protocols = [
17           { name = "ssh"; service = "ssh"; host = "localhost"; port = "22"; probe = "builtin"; }
18           { name = "http"; host = "localhost"; port = "80"; probe = "builtin"; }
19         ];
20       };
21       services.openssh.enable = true;
22       users.users.root.openssh.authorizedKeys.keyFiles = [ ./initrd-network-ssh/id_ed25519.pub ];
23       services.nginx = {
24         enable = true;
25         virtualHosts."localhost" = {
26           addSSL = false;
27           default = true;
28           root = pkgs.runCommand "testdir" {} ''
29             mkdir "$out"
30             echo hello world > "$out/index.html"
31           '';
32         };
33       };
34     };
35     client = { ... }: {
36       networking.interfaces.eth1.ipv6.addresses = [
37         {
38           address = "fe00:aa:bb:cc::1";
39           prefixLength = 64;
40         }
41       ];
42       networking.hosts."fe00:aa:bb:cc::2" = [ "server" ];
43       environment.etc.sshKey = {
44         source = ./initrd-network-ssh/id_ed25519; # dont use this anywhere else
45         mode = "0600";
46       };
47     };
48   };
50   testScript = ''
51     start_all()
53     server.wait_for_unit("sslh.service")
54     server.wait_for_unit("nginx.service")
55     server.wait_for_unit("sshd.service")
56     server.wait_for_open_port(80)
57     server.wait_for_open_port(443)
58     server.wait_for_open_port(22)
60     for arg in ["-6", "-4"]:
61         client.wait_until_succeeds(f"ping {arg} -c1 server")
63         # check that ssh through sslh works
64         client.succeed(
65             f"ssh {arg} -p 443 -i /etc/sshKey -o StrictHostKeyChecking=accept-new server 'echo $SSH_CONNECTION > /tmp/foo{arg}'"
66         )
68         # check that 1/ the above ssh command had an effect 2/ transparent proxying really works
69         ip = "fe00:aa:bb:cc::1" if arg == "-6" else "192.168.1."
70         server.succeed(f"grep '{ip}' /tmp/foo{arg}")
72         # check that http through sslh works
73         assert client.succeed(f"curl -f {arg} http://server:443").strip() == "hello world"
74   '';