feat: resolve workspace bindings into runtime configs

This commit is contained in:
2026-08-03 21:49:57 +02:00
parent 5a654939a5
commit 049f8675c6
6 changed files with 528 additions and 3 deletions
+7
View File
@@ -169,6 +169,13 @@ test("buildArgv appends -c AFTER the subcommand (never a global -c)", () => {
]);
});
test("buildArgv passes an absolute immutable snapshot after the tht subcommand", () => {
const r = new ThtRunner({ thtBin: "tht", harnessDir: "/nope", configPath: "config/tht.yaml" });
expect(r.buildArgv(["session", "new"], "/data/workspace-registry/snapshots/a/psd-clinical.yaml")).toEqual([
"session", "new", "-c", "/data/workspace-registry/snapshots/a/psd-clinical.yaml",
]);
});
test("sqlPreview argv has no positional file — uses --session to resolve path", async () => {
// The harness preview_cmd now resolves sql_final.sql from the session workspace;
// the backend must NOT pass a sessions/<id>/sql_final.sql positional arg.
@@ -0,0 +1,131 @@
import { expect, test } from "vitest";
import { parse } from "yaml";
import { renderRuntimeConfig, type RuntimeBindings, type RuntimePaths } from "../src/workspaces/runtime-renderer.js";
import { parseWorkspaceYaml } from "../src/workspaces/schema.js";
const workspace = parseWorkspaceYaml(`workspace:
schema_version: 1
id: psd-clinical
name: Policlinico San Donato
language: it
dwh:
engine: postgres
database: postgres
schema: datawarehouse
supported_transports: [postgres_direct, rest_api]
semantic_index:
vector_store:
engine: pgvector
collection: clinical_documents
dimensions: 768
distance: cosine
supported_transports: [pgvector_direct, rest_api]
embedding:
provider: ollama_compatible
model: nomic-embed-text-v2-moe
dimensions: 768
llm_policy:
allowed: [zai/glm-5.2]
`);
const paths: RuntimePaths = {
sessions: "/data/workspaces/psd-clinical/sessions",
artifacts: "/data/workspaces/psd-clinical/artifacts",
indexes: "/data/workspaces/psd-clinical/indexes",
};
const directBindings: RuntimeBindings = {
dwh: {
transport: "postgres_direct",
missing: [],
values: {
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
THT_WS_PSD_CLINICAL_DWH_USER: "thoth_reader",
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: "/run/secrets/dwh-password",
},
},
vector: {
transport: "pgvector_direct",
missing: [],
values: {
THT_WS_PSD_CLINICAL_VECTOR_HOST: "vector.internal",
THT_WS_PSD_CLINICAL_VECTOR_PORT: "5432",
THT_WS_PSD_CLINICAL_VECTOR_USER: "vector_reader",
THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_FILE: "/run/secrets/vector-password",
},
},
embedding: {
transport: "rest_api",
missing: [],
values: { THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL: "http://embedding.internal:11434" },
},
};
test("renders a direct PostgreSQL binding to the legacy harness shape", () => {
const yaml = renderRuntimeConfig(workspace, directBindings, paths);
const rendered = parse(yaml);
expect(rendered).toMatchObject({
language: "it",
database: {
host: "dwh.internal",
port: 5432,
database: "postgres",
schema: "datawarehouse",
user: "thoth_reader",
password_file: "/run/secrets/dwh-password",
transport: "direct",
},
vector_db: {
host: "vector.internal",
schema: "datawarehouse",
password_file: "/run/secrets/vector-password",
},
embeddings: {
base_url: "http://embedding.internal:11434",
model: "nomic-embed-text-v2-moe",
dim: 768,
},
paths,
});
expect(yaml).toContain("type: postgres_direct");
expect(yaml).toContain("schema: datawarehouse");
});
test("renders REST bindings through the legacy rest sections without secret values", () => {
const yaml = renderRuntimeConfig(workspace, {
...directBindings,
dwh: {
transport: "rest_api",
missing: [],
values: {
THT_WS_PSD_CLINICAL_DWH_BASE_URL: "https://dwh.example.test",
THT_WS_PSD_CLINICAL_DWH_API_KEY_FILE: "/run/secrets/dwh-api-key",
THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE: "/run/secrets/ca.pem",
},
},
vector: {
transport: "rest_api",
missing: [],
values: {
THT_WS_PSD_CLINICAL_VECTOR_BASE_URL: "https://vector.example.test",
THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE: "/run/secrets/vector-api-key",
},
},
}, paths);
const rendered = parse(yaml);
expect(rendered).toMatchObject({
database: { transport: "rest", schema: "datawarehouse" },
rest: {
base_url: "https://dwh.example.test",
api_key_file: "/run/secrets/dwh-api-key",
ssl_ca_file: "/run/secrets/ca.pem",
},
vector_rest: {
base_url: "https://vector.example.test",
api_key_file: "/run/secrets/vector-api-key",
},
});
expect(yaml).not.toContain("\n api_key: ");
});
+120
View File
@@ -0,0 +1,120 @@
import { mkdirSync, mkdtempSync, rmSync, writeFileSync } from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { afterEach, expect, test } from "vitest";
import { resolveBinding } from "../src/workspaces/bindings.js";
import { parseWorkspaceYaml } from "../src/workspaces/schema.js";
const workspace = parseWorkspaceYaml(`workspace:
schema_version: 1
id: psd-clinical
name: Policlinico San Donato
language: it
dwh:
engine: postgres
database: postgres
schema: datawarehouse
supported_transports: [postgres_direct, rest_api, ssh_tunnel]
semantic_index:
vector_store:
engine: pgvector
collection: clinical_documents
dimensions: 768
distance: cosine
supported_transports: [pgvector_direct, rest_api, ssh_tunnel]
embedding:
provider: ollama_compatible
model: nomic-embed-text-v2-moe
dimensions: 768
llm_policy:
allowed: [zai/glm-5.2]
`);
const temporaryRoots: string[] = [];
afterEach(() => {
temporaryRoots.splice(0).forEach((root) => rmSync(root, { recursive: true, force: true }));
});
function secretPath(name: string): { root: string; path: string } {
const root = mkdtempSync(join(tmpdir(), "thoth-binding-"));
temporaryRoots.push(root);
const secrets = join(root, "secrets");
mkdirSync(secrets);
const path = join(secrets, name);
writeFileSync(path, "");
return { root: secrets, path };
}
test("marks a portable workspace non-activatable when its local REST key file is absent", () => {
const result = resolveBinding(workspace, "DWH", {
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api",
THT_WS_PSD_CLINICAL_DWH_BASE_URL: "https://dwh.example.test",
}, ["/run/secrets"]);
expect(result.missing).toContain("THT_WS_PSD_CLINICAL_DWH_API_KEY_FILE");
});
test("resolves direct bindings from the stable workspace namespace", () => {
const password = secretPath("dwh-password");
const result = resolveBinding(workspace, "DWH", {
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
THT_WS_PSD_CLINICAL_DWH_USER: "thoth_reader",
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: password.path,
}, [password.root]);
expect(result).toMatchObject({
transport: "postgres_direct",
missing: [],
values: {
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: password.path,
},
});
});
test("reports only a FILE variable name when a secret path is outside the configured roots", () => {
const outside = secretPath("outside-password");
const allowed = secretPath("allowed-password");
const result = resolveBinding(workspace, "DWH", {
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
THT_WS_PSD_CLINICAL_DWH_USER: "thoth_reader",
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: outside.path,
}, [allowed.root]);
expect(result.missing).toEqual(["THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE"]);
expect(result.missing.join("\n")).not.toContain(outside.path);
});
test("reports an invalid optional secret file instead of silently dropping it", () => {
const password = secretPath("dwh-password");
const result = resolveBinding(workspace, "DWH", {
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
THT_WS_PSD_CLINICAL_DWH_USER: "thoth_reader",
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: password.path,
THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE: "relative-ca.pem",
}, [password.root]);
expect(result.missing).toContain("THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE");
});
test("rejects a selected transport that the canonical workspace does not support", () => {
const directOnly = {
...workspace,
dwh: { ...workspace.dwh, supported_transports: ["postgres_direct"] },
};
const result = resolveBinding(directOnly, "DWH", {
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api",
}, ["/run/secrets"]);
expect(result).toMatchObject({
transport: "rest_api",
missing: ["THT_WS_PSD_CLINICAL_DWH_TRANSPORT"],
});
});