fix(harness): drop THOTH_SSL_CA from REQUIRED_L2 + isolate profile in workspace test

Two fixes found while unblocking the L2 setup:

1. conftest: THOTH_SSL_CA is NOT an L2 prerequisite. The DWH endpoint presents a
   public cert (*.policlinicosandonato.it, signed by GoDaddy), already in the
   certifi bundle, so the REST clients validate TLS with verify=True -- no CA file
   needed. The ssl_ca line was commented out in ChironeWp3's nsp.yaml too.

2. test_workspace: the profile-default assertion collided with the operator's real
   harness/.env once load_dotenv (D3) started injecting THOTH_PROFILE into the
   process env. The test now dels THOTH_PROFILE to assert the actual *default*
   (server), regardless of what the operator set in .env.

Suite: 109 passed.
This commit is contained in:
2026-06-27 06:45:00 +02:00
parent 50d5f9c9cf
commit 276717005d
2 changed files with 8 additions and 1 deletions
+4 -1
View File
@@ -23,7 +23,10 @@ load_dotenv(_ROOT / ".env")
# L2 connection prerequisites (spec Testing Strategy). If any is missing/empty, L2
# tests are SKIPPED (not failed) so the default run (pytest = L0+L1) stays green.
REQUIRED_L2 = ["THOTH_DWH_API_KEY", "THOTH_VEC_API_KEY", "THOTH_VEC_WRITE_API_KEY", "THOTH_SSL_CA"]
# NOTE: THOTH_SSL_CA is NOT required -- the DWH endpoint presents a public cert
# (*.policlinicosandonato.it signed by GoDaddy), already in the certifi bundle, so
# the clients fall back to verify=True and TLS validates without a CA file.
REQUIRED_L2 = ["THOTH_DWH_API_KEY", "THOTH_VEC_API_KEY", "THOTH_VEC_WRITE_API_KEY"]
@pytest.fixture(scope="session")
+4
View File
@@ -4,6 +4,10 @@ from nsp.workspace import load_workspace, WorkspaceError
def test_load_workspace_expands_env_vars(monkeypatch, tmp_path):
# Isolate profile: load_dotenv (conftest D3) injects THOTH_PROFILE from the real
# harness/.env into os.environ; this test asserts the *default* (server), so it
# must del THOTH_PROFILE rather than inherit whatever the operator set.
monkeypatch.delenv("THOTH_PROFILE", raising=False)
monkeypatch.setenv("THOTH_VEC_API_KEY", "secret-reader")
monkeypatch.setenv("THOTH_VEC_WRITE_API_KEY", "secret-writer")
monkeypatch.setenv("THOTH_VEC_REST_URL", "https://example/vector/v1/")