test: gate unified compose deployment

This commit is contained in:
2026-08-05 13:41:33 +02:00
parent b44a1b9ad9
commit 2ae89c075e
6 changed files with 1313 additions and 0 deletions
+39
View File
@@ -89,6 +89,45 @@ volume afterward. It never targets the fixed `thothii` operator project or its v
`KEEP_SMOKE_RESOURCES=1` to retain that smoke project's resources for inspection; remove them
later with `docker compose --project-name "$SMOKE_PROJECT" down --volumes`.
## Unified deployment release gates
Task 13 adds a no-secret release gate around the canonical base plus local Compose profile. Its
deterministic safety check does not contact the Docker daemon:
```sh
bash scripts/unified-deployment-smoke.sh --self-test
```
The two Docker smokes are separate release jobs. Each creates a unique Compose project, temporary
Git workspace remote, fixture provider, image names, and run label. Its exit trap removes only
resources carrying that exact run identity and never performs a global Docker prune.
```sh
bash scripts/unified-deployment-smoke.sh
bash scripts/thothctl-update-smoke.sh
```
The unified smoke builds and starts `frontend` and `core`, verifies the embedded Pi and internal
registry, recreates with the Git remote offline, activates a valid Git update, rejects invalid Git
content while retaining the valid snapshot, and checks the four persistence volumes. Both smokes
inject a digest-pinned non-core candidate under a deliberately mismatched Pi version and require
`thothctl pi update` to roll back while preserving settings, sessions, Pi state, registry revision,
and mount identity. Fixture credentials are generated locally; neither command needs a real
provider key or a repository secret. CI gives each smoke one 30-minute outer timeout and does not
retry it.
On a native Windows clone, the release contract is:
```powershell
.\scripts\test-windows-clone-contract.ps1 `
-ThothctlPath "$PWD\dist\thothctl\thothctl-windows-amd64.exe"
```
It checks Git's CRLF/LF attributes and bytes, renders exactly `core` plus `frontend` with Docker
Compose without starting containers, and invokes the native Windows `thothctl`. The GitHub Actions
deployment workflow runs the deterministic Linux gates, both bounded Docker smokes, and this
Windows clone contract with immutable action pins and supported pinned Node/Go toolchains.
## Optional local pgvector and recovery
The local-vector overlay reads `THT_VECTOR_BOOTSTRAP_PASSWORD`,