fix(ci): assert projected server auth status
This commit is contained in:
@@ -1645,8 +1645,8 @@ task13_assert_server_runtime() {
|
|||||||
status="$TASK13_TMP/server-auth-status.json"
|
status="$TASK13_TMP/server-auth-status.json"
|
||||||
task13_run_logged "server static OIDC status" task13_server_tht auth status --json
|
task13_run_logged "server static OIDC status" task13_server_tht auth status --json
|
||||||
task13_server_tht auth status --json >"$status"
|
task13_server_tht auth status --json >"$status"
|
||||||
node -e 'const value=JSON.parse(require("fs").readFileSync(process.argv[1], "utf8")); if(value.mode!=="oidc"||!/^sha256:[0-9a-f]{64}$/.test(value.configRevision)) process.exit(1)' "$status" \
|
node -e 'const value=JSON.parse(require("fs").readFileSync(process.argv[1], "utf8")); if(value.state!=="ready"||value.equal!==true||!/^[0-9a-f]{64}$/.test(value.generation)||value.canonicalRevision!==`sha256:${value.generation}`) process.exit(1)' "$status" \
|
||||||
|| task13_fail "server static OIDC status was not valid"
|
|| task13_fail "server authentication projection status was not valid"
|
||||||
diagnostics="$TASK13_TMP/server-auth-diagnostics.json"
|
diagnostics="$TASK13_TMP/server-auth-diagnostics.json"
|
||||||
task13_run_logged "server live OIDC diagnostics" task13_server_tht auth check --json
|
task13_run_logged "server live OIDC diagnostics" task13_server_tht auth check --json
|
||||||
task13_server_tht auth check --json >"$diagnostics"
|
task13_server_tht auth check --json >"$diagnostics"
|
||||||
@@ -2569,6 +2569,7 @@ task13_self_test_source_contract() {
|
|||||||
local server_auth_projection_environment server_auth_privileged_configure
|
local server_auth_projection_environment server_auth_privileged_configure
|
||||||
local server_fixture_reclamation server_runtime_config_probe server_workspace_config_permission
|
local server_fixture_reclamation server_runtime_config_probe server_workspace_config_permission
|
||||||
local server_runtime_selector_probe server_runtime_generation_probe server_runtime_direct_file_probe
|
local server_runtime_selector_probe server_runtime_generation_probe server_runtime_direct_file_probe
|
||||||
|
local server_runtime_projection_status_contract
|
||||||
local server_secret_source_owner server_secret_source_preparation server_tht_wrapper
|
local server_secret_source_owner server_secret_source_preparation server_tht_wrapper
|
||||||
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
||||||
workflow="$root/.github/workflows/deployment.yml"
|
workflow="$root/.github/workflows/deployment.yml"
|
||||||
@@ -2604,6 +2605,7 @@ task13_self_test_source_contract() {
|
|||||||
server_runtime_selector_probe='check_readable /run/thothii-auth/''CURRENT'
|
server_runtime_selector_probe='check_readable /run/thothii-auth/''CURRENT'
|
||||||
server_runtime_generation_probe='check_readable "/run/thothii-auth/generations/$projection_generation/''auth.yaml"'
|
server_runtime_generation_probe='check_readable "/run/thothii-auth/generations/$projection_generation/''auth.yaml"'
|
||||||
server_runtime_direct_file_probe='check_readable /run/thothii-auth/''auth.yaml'
|
server_runtime_direct_file_probe='check_readable /run/thothii-auth/''auth.yaml'
|
||||||
|
server_runtime_projection_status_contract='value.state!=="''ready"||value.equal!==true'
|
||||||
server_secret_source_preparation='task13_prepare_server_secret_''sources'
|
server_secret_source_preparation='task13_prepare_server_secret_''sources'
|
||||||
server_secret_source_owner='chown 10001:''10001 -- "$TASK13_SECRETS" "$TASK13_PI_AUTH"'
|
server_secret_source_owner='chown 10001:''10001 -- "$TASK13_SECRETS" "$TASK13_PI_AUTH"'
|
||||||
server_tht_wrapper='task13_server_''tht'
|
server_tht_wrapper='task13_server_''tht'
|
||||||
@@ -2691,6 +2693,8 @@ task13_self_test_source_contract() {
|
|||||||
|| task13_fail "the server runtime preconditions must verify the selected generation"
|
|| task13_fail "the server runtime preconditions must verify the selected generation"
|
||||||
! grep -Fq -- "$server_runtime_direct_file_probe" "$root/scripts/unified-deployment-smoke.sh" \
|
! grep -Fq -- "$server_runtime_direct_file_probe" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|| task13_fail "the server runtime preconditions must not require the forbidden direct-file fallback"
|
|| task13_fail "the server runtime preconditions must not require the forbidden direct-file fallback"
|
||||||
|
grep -Fq -- "$server_runtime_projection_status_contract" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|
|| task13_fail "the server status assertion must validate projection readiness"
|
||||||
grep -Fq -- "$server_workspace_config_permission" "$root/scripts/unified-deployment-smoke.sh" \
|
grep -Fq -- "$server_workspace_config_permission" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|| task13_fail "the server workspace fixture must be readable by the container UID"
|
|| task13_fail "the server workspace fixture must be readable by the container UID"
|
||||||
[[ "$(grep -Ec "^${server_secret_source_preparation}\\(\\)|^[[:space:]]+${server_secret_source_preparation}$" \
|
[[ "$(grep -Ec "^${server_secret_source_preparation}\\(\\)|^[[:space:]]+${server_secret_source_preparation}$" \
|
||||||
|
|||||||
Reference in New Issue
Block a user