test: gate unified compose deployment

This commit is contained in:
2026-08-05 13:41:33 +02:00
parent b44a1b9ad9
commit 2ae89c075e
6 changed files with 1313 additions and 0 deletions
+29
View File
@@ -3,6 +3,35 @@
> Starting-point snapshot for new sessions. Last updated: 2026-08-05 (portable deployment decoupled).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
## Unified deployment release gate — Task 13 (2026-08-05)
- **Release coverage.** `scripts/unified-deployment-smoke.sh` gates the two-service render/build,
frontend-to-core routing, embedded pinned Pi, Git registry bootstrap, offline recreation, valid
update, invalid-update retention, and the four persistent stores. `scripts/thothctl-update-smoke.sh`
independently exercises the bad-Pi update and automatic rollback path.
- **Isolation and disclosure boundary.** Every run generates a unique temporary root, Compose
project, container/image names, transaction image tags, and run label. The rollback fixture uses
an immutable public digest as a deliberately dead core rather than a host-local image registry.
Cleanup checks ownership before removing exact containers, Compose resources, image references,
control state, and temporary files. There is no global prune. Failure diagnostics are bounded
and sanitized, and all credentials/endpoints used by the smokes are disposable fixtures rather
than operator or repository secrets.
- **Cross-platform CI contract.** `.github/workflows/deployment.yml` uses immutable action commits,
pinned supported Node and Go versions, runs LF/Compose/secret/coupling/docs/TypeScript gates on
Linux, runs each Docker smoke once under its own outer timeout, and builds/invokes native Windows
`thothctl` after the PowerShell clone/LF/Compose contract. Native Windows execution remains an
explicit manual release gate in addition to CI; no Windows Docker container startup is claimed
by the static clone job.
- **Validation status.** Deterministic Phase A gates, backend **434/434** plus TypeScript,
frontend **386/386** plus TypeScript, and harness **862 passed / 5 L2 deselected** are green.
The unified one-shot Docker run passed frontend/core/internal Pi, registry bootstrap, offline
recreation, valid update, invalid-update retention, and persistence before Docker Desktop
refused the daemon-to-host local-registry push; the update-only run reached the same boundary.
Both exact run/project resource sets were independently proved absent. The local-registry
fixture was then removed in favor of the immutable dead-core digest, but the requested no-retry
rule leaves automatic rollback/preservation pending in CI or a fresh manual release run. Native
Windows PowerShell execution is also still a manual release gate.
## Portable deployment decoupling — LIVE 2026-08-05
- **Mandatory stack.** The supported Compose stack is exactly `frontend` plus `core`; use the