test(compose): validate bundle deployment contract

This commit is contained in:
2026-07-12 11:48:43 +02:00
parent 07967bf589
commit 10465917a5
3 changed files with 38 additions and 18 deletions
+7
View File
@@ -24,6 +24,9 @@ Updated:
Compose services without the legacy `external` profile.
- `scripts/test-default-compose.sh` asserts the exact installation command, tracked templates,
and absence of the legacy setup in the guide.
- `scripts/test-container-deployment.sh` now validates the bundle mount and rejects legacy
per-secret references; `.dockerignore` explicitly re-includes only the required vector policy
helper so the Docker build context remains safe.
The docs explicitly state that a PEM CA chain cannot be put in the strict single-line bundle. A
reviewed Compose override/secret-manager mount is required for `THT_SSL_CA`. Direct PostgreSQL
@@ -34,9 +37,13 @@ the base bundle mount is the only default mount.
- `sh -n scripts/docker-smoke.sh scripts/test-default-compose.sh` — passed.
- `./scripts/test-default-compose.sh` — passed.
- `./scripts/test-container-deployment.sh` — passed after migrating its local-vector assertions
to the single bundle and checking the `.dockerignore` deployment allowlist.
- `git diff --check` — passed.
- `./scripts/test-docker-smoke.sh` — passed after updating its static assertion to the default
no-profile invocation.
- `docker buildx build --file docker/core.Dockerfile --check .` — passed; BuildKit reported no
warnings after the `.dockerignore` parent-directory fix.
## Concerns