Improve robustness, security, and CI-friendliness of run-tests-in-docker.sh
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 45/100
- Tipo di issue
- Refactoring
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Stack tecnologico
- bash, docker
- Ambito
- devops, infrastructure, testing-qa
Direzione di ricerca
Inizia leggendo bin/run-tests-in-docker.sh e segui i relativi percorsi di build ed esecuzione Docker. Verifica come si comporta da una directory di lavoro diversa e come vengono restituiti gli errori dei container in CI. Il lavoro è completo quando sono coperte le modifiche richieste relative alla sicurezza della shell, alla gestione dei percorsi, alla riproducibilità, all’isolamento, ai mount in sola lettura, alla propagazione del codice di uscita e al logging, senza modificare l’interfaccia dello script.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Description
The bin/run-tests-in-docker.sh script currently works well for local testing, but it can be made more robust, secure, and CI-friendly with a few targeted improvements. These changes align the script more closely with production-grade container execution and common best practices for infrastructure scripts.
Motivation
Improve failure detection and error handling in CI environments
Make the script resilient to being executed from any working directory
Strengthen container sandboxing to better mirror Exercism’s production runner
Improve reproducibility and debuggability for contributors
Proposed Improvements
Stricter shell safety
Use #!/usr/bin/env bash with set -Eeuo pipefail instead of relying solely on -e
Path robustness
Resolve the project root dynamically instead of relying on $PWD
Ensures the script works correctly when executed from any directory or CI runner
More reproducible Docker builds
Add --pull and --no-cache to docker build to avoid stale base images
Stronger container isolation
Add resource limits and security flags:
--pids-limit
--memory
--cpus
--security-opt no-new-privileges
Better reflects the sandboxing used in production test runners
Read-only bind mounts
Mount test data and scripts as read-only to prevent accidental mutation
Explicit exit-code handling
Capture and propagate the container exit code to ensure CI fails correctly on test errors
Lightweight logging
Add clear, minimal log messages to improve traceability during CI failures
Benefits
More reliable CI behavior
Clearer failure modes and logs
Improved security posture of the Docker execution
Easier local and automated testing for contributors
Better alignment with Exercism’s production environment
Backwards Compatibility
These changes do not alter the external behavior of the script or its interface.
They only improve safety, clarity, and reliability.
- Lingua principale
- Java
- Stelle
- 11
- Fork
- 17
- Merge medio
- 3g 20h
- PR unite (30g)
- 5
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Nessun modello di pull request
- Nessuna guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
-
Make branch and label autocomplete matching locale-independentForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 83/100
jenkinsci/gitlab-plugin#1950 ·
-
It's not necessary to copy the memory block in the readWrite() of org.h2.store.fs.mem.FileMemDataAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
h2database/h2database#4435 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
micronaut-projects/micronaut-core#13717 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
ADORSYS-GIS/token-status-link#145 ·
I maintainer di solito rispondono entro 3 giorni