nix: add loadtest with unique JWTs
This loadtests the jwt decoding logic. For this it adds an optional `-k`(kind) parameter to `postgrest-loadtest` and `postgrest-loadtest-against`. Old kind (default): ``` postgrest-loadtest -k mixed postgrest-loadtest-against -k mixed ``` New kind: ``` postgrest-loadtest -k jwt postgrest-loadtest-against -k jwt ``` Internally it uses a dynamically generated targets file using python which looks like: ``` GET http://postgrest/authors_only Authorization: Bearer <jwt> GET http://postgrest/authors_only Authorization: Bearer <another-jwt> ... ``` Then this is used to run vegeta with the `-lazy` option.
This commit is contained in:
committed by
Steve Chavez
parent
a37ec1e1a5
commit
608f7ca45a
@@ -126,11 +126,15 @@ jobs:
|
|||||||
id: get-latest-tag
|
id: get-latest-tag
|
||||||
with:
|
with:
|
||||||
prefix: v
|
prefix: v
|
||||||
- name: Run loadtest
|
- name: Run loadtest (mixed)
|
||||||
run: |
|
run: |
|
||||||
postgrest-loadtest-against main ${{ steps.get-latest-tag.outputs.tag }}
|
postgrest-loadtest-against main ${{ steps.get-latest-tag.outputs.tag }}
|
||||||
postgrest-loadtest-report >> "$GITHUB_STEP_SUMMARY"
|
postgrest-loadtest-report >> "$GITHUB_STEP_SUMMARY"
|
||||||
|
|
||||||
|
- name: Run loadtest (jwt)
|
||||||
|
# TODO generate a report for this https://github.com/PostgREST/postgrest/issues/4022
|
||||||
|
run: |
|
||||||
|
postgrest-loadtest-against -k jwt main ${{ steps.get-latest-tag.outputs.tag }}
|
||||||
|
|
||||||
flake:
|
flake:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
@@ -24,3 +24,4 @@ coverage
|
|||||||
loadtest
|
loadtest
|
||||||
.history
|
.history
|
||||||
.docs-build
|
.docs-build
|
||||||
|
test/load/gen_targets.http
|
||||||
|
|||||||
Executable
+74
@@ -0,0 +1,74 @@
|
|||||||
|
# generates a file to be used by the vegeta load testing tool
|
||||||
|
import time
|
||||||
|
import hmac
|
||||||
|
import hashlib
|
||||||
|
import base64
|
||||||
|
import json
|
||||||
|
import argparse
|
||||||
|
import sys
|
||||||
|
|
||||||
|
SECRET = b"reallyreallyreallyreallyverysafe"
|
||||||
|
URL = "http://postgrest"
|
||||||
|
JWT_DURATION = 60
|
||||||
|
TOTAL_TARGETS = 40000 # tuned by hand to reduce result variance
|
||||||
|
|
||||||
|
|
||||||
|
def base64url_encode(data: bytes) -> str:
|
||||||
|
"""URL-safe Base64 encode without padding."""
|
||||||
|
return base64.urlsafe_b64encode(data).rstrip(b"=").decode("ascii")
|
||||||
|
|
||||||
|
|
||||||
|
def generate_jwt() -> str:
|
||||||
|
"""Generate an HS256 JWT"""
|
||||||
|
# Header & payload
|
||||||
|
header = {"alg": "HS256", "typ": "JWT"}
|
||||||
|
now = int(time.time())
|
||||||
|
payload = {
|
||||||
|
"iat": now,
|
||||||
|
"exp": now + JWT_DURATION,
|
||||||
|
"role": "postgrest_test_author",
|
||||||
|
}
|
||||||
|
|
||||||
|
# Encode to JSON and then to Base64URL
|
||||||
|
header_b = json.dumps(header, separators=(",", ":")).encode()
|
||||||
|
payload_b = json.dumps(payload, separators=(",", ":")).encode()
|
||||||
|
header_b64 = base64url_encode(header_b)
|
||||||
|
payload_b64 = base64url_encode(payload_b)
|
||||||
|
|
||||||
|
# Sign (HMAC‑SHA256) the "<header>.<payload>" string
|
||||||
|
signing_input = f"{header_b64}.{payload_b64}".encode()
|
||||||
|
signature = hmac.new(SECRET, signing_input, hashlib.sha256).digest()
|
||||||
|
signature_b64 = base64url_encode(signature)
|
||||||
|
|
||||||
|
return f"{header_b64}.{payload_b64}.{signature_b64}"
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
parser = argparse.ArgumentParser(
|
||||||
|
description="Generate Vegeta targets with unique JWTs"
|
||||||
|
)
|
||||||
|
parser.add_argument(
|
||||||
|
"output",
|
||||||
|
help="Path to write the generated targets file",
|
||||||
|
)
|
||||||
|
args = parser.parse_args()
|
||||||
|
|
||||||
|
lines = []
|
||||||
|
for _ in range(TOTAL_TARGETS):
|
||||||
|
token = generate_jwt()
|
||||||
|
lines.append(f"GET {URL}/authors_only")
|
||||||
|
lines.append(f"Authorization: Bearer {token}")
|
||||||
|
lines.append("") # blank line to separate requests
|
||||||
|
|
||||||
|
try:
|
||||||
|
with open(args.output, "w") as f:
|
||||||
|
f.write("\n".join(lines))
|
||||||
|
except IOError as e:
|
||||||
|
print(f"Error writing to {args.output}: {e}", file=sys.stderr)
|
||||||
|
sys.exit(1)
|
||||||
|
|
||||||
|
print(f"Generated {TOTAL_TARGETS} targets in {args.output}")
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
main()
|
||||||
+31
-12
@@ -29,7 +29,6 @@ let
|
|||||||
-max-workers 1 \
|
-max-workers 1 \
|
||||||
-workers 1 \
|
-workers 1 \
|
||||||
-rate 0 \
|
-rate 0 \
|
||||||
-duration 60s \
|
|
||||||
"''${_arg_leftovers[@]}"
|
"''${_arg_leftovers[@]}"
|
||||||
'';
|
'';
|
||||||
|
|
||||||
@@ -41,6 +40,8 @@ let
|
|||||||
args = [
|
args = [
|
||||||
"ARG_OPTIONAL_SINGLE([output], [o], [Filename to dump json output to], [./loadtest/result.bin])"
|
"ARG_OPTIONAL_SINGLE([output], [o], [Filename to dump json output to], [./loadtest/result.bin])"
|
||||||
"ARG_OPTIONAL_SINGLE([testdir], [t], [Directory to load tests and fixtures from], [./test/load])"
|
"ARG_OPTIONAL_SINGLE([testdir], [t], [Directory to load tests and fixtures from], [./test/load])"
|
||||||
|
"ARG_OPTIONAL_SINGLE([kind], [k], [Kind of loadtest (mixed: repeat mixed requests, jwt: run once over many requests with unique jwts)], [mixed])"
|
||||||
|
"ARG_TYPE_GROUP_SET([KIND], [KIND], [kind], [mixed,jwt])"
|
||||||
"ARG_LEFTOVERS([additional vegeta arguments])"
|
"ARG_LEFTOVERS([additional vegeta arguments])"
|
||||||
];
|
];
|
||||||
workingDir = "/";
|
workingDir = "/";
|
||||||
@@ -61,13 +62,29 @@ let
|
|||||||
mkdir -p "$(dirname "$_arg_output")"
|
mkdir -p "$(dirname "$_arg_output")"
|
||||||
abs_output="$(realpath "$_arg_output")"
|
abs_output="$(realpath "$_arg_output")"
|
||||||
|
|
||||||
# shellcheck disable=SC2145
|
case "$_arg_kind" in
|
||||||
${withTools.withPg} -f "$_arg_testdir"/fixtures.sql \
|
jwt)
|
||||||
${withTools.withSlowPg} \
|
${genTargets} "$_arg_testdir"/gen_targets.http
|
||||||
${withTools.withPgrst} \
|
|
||||||
${withTools.withSlowPgrst} \
|
# shellcheck disable=SC2145
|
||||||
sh -c "cd \"$_arg_testdir\" && ${runner} -targets targets.http -output \"$abs_output\" \"''${_arg_leftovers[@]}\""
|
${withTools.withPg} -f "$_arg_testdir"/fixtures.sql \
|
||||||
${vegeta}/bin/vegeta report -type=text "$_arg_output"
|
${withTools.withPgrst} \
|
||||||
|
sh -c "cd \"$_arg_testdir\" && ${runner} -lazy -targets gen_targets.http -output \"$abs_output\" \"''${_arg_leftovers[@]}\""
|
||||||
|
${vegeta}/bin/vegeta report -type=text "$_arg_output"
|
||||||
|
;;
|
||||||
|
|
||||||
|
*)
|
||||||
|
|
||||||
|
# shellcheck disable=SC2145
|
||||||
|
${withTools.withPg} -f "$_arg_testdir"/fixtures.sql \
|
||||||
|
${withTools.withSlowPg} \
|
||||||
|
${withTools.withPgrst} \
|
||||||
|
${withTools.withSlowPgrst} \
|
||||||
|
sh -c "cd \"$_arg_testdir\" && ${runner} -duration 60s -targets targets.http -output \"$abs_output\" \"''${_arg_leftovers[@]}\""
|
||||||
|
${vegeta}/bin/vegeta report -type=text "$_arg_output"
|
||||||
|
;;
|
||||||
|
|
||||||
|
esac
|
||||||
'';
|
'';
|
||||||
|
|
||||||
loadtestAgainst =
|
loadtestAgainst =
|
||||||
@@ -85,6 +102,7 @@ let
|
|||||||
'';
|
'';
|
||||||
args = [
|
args = [
|
||||||
"ARG_POSITIONAL_INF([target], [Commit-ish reference to compare with], 1)"
|
"ARG_POSITIONAL_INF([target], [Commit-ish reference to compare with], 1)"
|
||||||
|
"ARG_OPTIONAL_SINGLE([kind], [k], [Kind of loadtest], [mixed])"
|
||||||
];
|
];
|
||||||
positionalCompletion =
|
positionalCompletion =
|
||||||
''
|
''
|
||||||
@@ -99,7 +117,7 @@ let
|
|||||||
|
|
||||||
cat << EOF
|
cat << EOF
|
||||||
|
|
||||||
Running loadtest on "$tgt"...
|
Running "$_arg_kind" loadtest on "$tgt"...
|
||||||
|
|
||||||
EOF
|
EOF
|
||||||
|
|
||||||
@@ -108,7 +126,7 @@ let
|
|||||||
# Save the results in the current working tree, too,
|
# Save the results in the current working tree, too,
|
||||||
# otherwise they'd be lost in the temporary working tree
|
# otherwise they'd be lost in the temporary working tree
|
||||||
# created by withTools.withGit.
|
# created by withTools.withGit.
|
||||||
${withTools.withGit} "$tgt" ${loadtest} --output "$PWD/loadtest/$tgt.bin" --testdir "$PWD/test/load"
|
${withTools.withGit} "$tgt" ${loadtest} -k "$_arg_kind" --output "$PWD/loadtest/$tgt.bin" --testdir "$PWD/test/load"
|
||||||
|
|
||||||
cat << EOF
|
cat << EOF
|
||||||
|
|
||||||
@@ -120,11 +138,11 @@ let
|
|||||||
|
|
||||||
cat << EOF
|
cat << EOF
|
||||||
|
|
||||||
Running loadtest on HEAD...
|
Running $_arg_kind" loadtest on HEAD...
|
||||||
|
|
||||||
EOF
|
EOF
|
||||||
|
|
||||||
${loadtest} --output "$PWD/loadtest/head.bin" --testdir "$PWD/test/load"
|
${loadtest} -k "$_arg_kind" --output "$PWD/loadtest/head.bin" --testdir "$PWD/test/load"
|
||||||
|
|
||||||
cat << EOF
|
cat << EOF
|
||||||
|
|
||||||
@@ -180,6 +198,7 @@ let
|
|||||||
| ${toMarkdown}
|
| ${toMarkdown}
|
||||||
'';
|
'';
|
||||||
|
|
||||||
|
genTargets = writers.writePython3 "postgrest-gen-loadtest-targets" { } (builtins.readFile ./generate_targets.py);
|
||||||
in
|
in
|
||||||
buildToolbox {
|
buildToolbox {
|
||||||
name = "postgrest-loadtest";
|
name = "postgrest-loadtest";
|
||||||
|
|||||||
+11
-1
@@ -1,5 +1,7 @@
|
|||||||
CREATE ROLE postgrest_test_anonymous;
|
CREATE ROLE postgrest_test_anonymous;
|
||||||
|
CREATE ROLE postgrest_test_author;
|
||||||
GRANT postgrest_test_anonymous TO :PGUSER;
|
GRANT postgrest_test_anonymous TO :PGUSER;
|
||||||
|
GRANT postgrest_test_author TO :PGUSER;
|
||||||
CREATE SCHEMA test;
|
CREATE SCHEMA test;
|
||||||
|
|
||||||
-- PUT+PATCH target needs one record and column to modify
|
-- PUT+PATCH target needs one record and column to modify
|
||||||
@@ -31,10 +33,18 @@ CREATE TABLE test.roles (
|
|||||||
character TEXT
|
character TEXT
|
||||||
);
|
);
|
||||||
|
|
||||||
|
CREATE TABLE test.authors_only ();
|
||||||
|
|
||||||
CREATE FUNCTION test.call_me (name TEXT) RETURNS TEXT
|
CREATE FUNCTION test.call_me (name TEXT) RETURNS TEXT
|
||||||
STABLE LANGUAGE SQL AS $$
|
STABLE LANGUAGE SQL AS $$
|
||||||
SELECT 'Hello ' || name || ', how are you?';
|
SELECT 'Hello ' || name || ', how are you?';
|
||||||
$$;
|
$$;
|
||||||
|
|
||||||
GRANT USAGE ON SCHEMA test TO postgrest_test_anonymous;
|
GRANT USAGE ON SCHEMA test TO postgrest_test_anonymous, postgrest_test_author;
|
||||||
GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA test TO postgrest_test_anonymous;
|
GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA test TO postgrest_test_anonymous;
|
||||||
|
|
||||||
|
REVOKE ALL PRIVILEGES ON TABLE
|
||||||
|
authors_only
|
||||||
|
FROM postgrest_test_anonymous;
|
||||||
|
|
||||||
|
GRANT ALL ON TABLE authors_only TO postgrest_test_author;
|
||||||
|
|||||||
Reference in New Issue
Block a user