diff --git a/harness/tests/conftest.py b/harness/tests/conftest.py index 81081d1f..cb6e904d 100644 --- a/harness/tests/conftest.py +++ b/harness/tests/conftest.py @@ -23,7 +23,10 @@ load_dotenv(_ROOT / ".env") # L2 connection prerequisites (spec Testing Strategy). If any is missing/empty, L2 # tests are SKIPPED (not failed) so the default run (pytest = L0+L1) stays green. -REQUIRED_L2 = ["THOTH_DWH_API_KEY", "THOTH_VEC_API_KEY", "THOTH_VEC_WRITE_API_KEY", "THOTH_SSL_CA"] +# NOTE: THOTH_SSL_CA is NOT required -- the DWH endpoint presents a public cert +# (*.policlinicosandonato.it signed by GoDaddy), already in the certifi bundle, so +# the clients fall back to verify=True and TLS validates without a CA file. +REQUIRED_L2 = ["THOTH_DWH_API_KEY", "THOTH_VEC_API_KEY", "THOTH_VEC_WRITE_API_KEY"] @pytest.fixture(scope="session") diff --git a/harness/tests/test_workspace.py b/harness/tests/test_workspace.py index 3285e5fb..4332f8fa 100644 --- a/harness/tests/test_workspace.py +++ b/harness/tests/test_workspace.py @@ -4,6 +4,10 @@ from nsp.workspace import load_workspace, WorkspaceError def test_load_workspace_expands_env_vars(monkeypatch, tmp_path): + # Isolate profile: load_dotenv (conftest D3) injects THOTH_PROFILE from the real + # harness/.env into os.environ; this test asserts the *default* (server), so it + # must del THOTH_PROFILE rather than inherit whatever the operator set. + monkeypatch.delenv("THOTH_PROFILE", raising=False) monkeypatch.setenv("THOTH_VEC_API_KEY", "secret-reader") monkeypatch.setenv("THOTH_VEC_WRITE_API_KEY", "secret-writer") monkeypatch.setenv("THOTH_VEC_REST_URL", "https://example/vector/v1/")