feat: render revision-bound evidence configuration

This commit is contained in:
2026-08-09 19:39:03 +02:00
parent 3b9681a63a
commit 36fbd58277
4 changed files with 570 additions and 17 deletions
@@ -299,3 +299,278 @@ test("renders REST bindings through the legacy rest sections without secret valu
});
expect(yaml).not.toContain("\n api_key: ");
});
function evidenceWorkspace(source: Record<string, unknown>, policy?: Record<string, unknown>) {
return parseWorkspaceYaml(`${canonicalEvidenceWorkspace}\nevidence:\n source: ${JSON.stringify(source)}${
policy === undefined ? "" : `\n policy: ${JSON.stringify(policy)}`
}\n`);
}
const canonicalEvidenceWorkspace = `workspace:
schema_version: 3
id: psd-clinical
name: Runtime Evidence
language: en
dwh:
engine: postgres
database: analytics
schema: mart
supported_transports: [postgres_direct]
semantic_index:
vector_store:
engine: qdrant
collection: psd-clinical
dimensions: 1024
distance: cosine
embedding:
provider: ollama_internal
model: qwen3-embedding:0.6b
dimensions: 1024
llm_policy:
allowed: [zai/glm-5.2]
`;
const evidenceRevision = "1".repeat(40);
const evidenceContext = {
workspaceId: "psd-clinical",
workspaceRevision: evidenceRevision,
revisionContentRoot: `/srv/registry/snapshots/${evidenceRevision}`,
};
function evidenceRender(
source: Record<string, unknown>,
evidenceBinding: RuntimeBindings["evidence"] = { missing: [], values: {} },
policy?: Record<string, unknown>,
) {
return renderRuntimeConfig(
evidenceWorkspace(source, policy),
{ ...directBindings, evidence: evidenceBinding },
paths,
evidenceContext,
{},
semanticRuntime,
);
}
test("renders filesystem Evidence below the immutable revision content root with default policy", () => {
const yaml = evidenceRender({
type: "filesystem",
uri: "workspace-content/psd-clinical/evidence",
});
const rendered = parse(yaml);
expect(rendered.runtime_identity.workspace_revision).toBe(evidenceRevision);
expect(rendered.evidence).toEqual({
sources: [{
type: "filesystem",
root: `/srv/registry/snapshots/${evidenceRevision}/workspace-content/psd-clinical/evidence`,
patterns: ["**/*.md"],
max_bytes: 10_485_760,
}],
});
expect(rendered.vector).toEqual({
max_chunk_chars: 4_000,
retain_published_generations: 3,
});
expect(yaml).not.toContain("/srv/registry/repo");
});
test("renders public HTTP Evidence with exact fractional-second timeouts and every policy limit", () => {
const rendered = parse(evidenceRender({
type: "http",
uris: ["https://evidence.example.test/guide.md"],
authentication: "none",
connect_timeout_ms: 1_001,
read_timeout_ms: 30_001,
max_bytes: 12_345,
max_redirects: 0,
allow_private_hosts: true,
max_cache_bytes: 67_890,
}, undefined, {
max_chunk_chars: 2_501,
retain_published_generations: 7,
}));
expect(rendered.evidence).toEqual({
sources: [{
type: "http",
urls: ["https://evidence.example.test/guide.md"],
connect_timeout: 1.001,
read_timeout: 30.001,
max_bytes: 12_345,
max_redirects: 0,
allow_private_hosts: true,
max_cache_bytes: 67_890,
}],
});
expect(rendered.vector).toEqual({
max_chunk_chars: 2_501,
retain_published_generations: 7,
});
});
test("renders signed HTTP Evidence as provenance plus a validated file path only", () => {
const signedFile = "/run/secrets/evidence-signed-urls.json";
const yaml = evidenceRender({
type: "http",
uris: [
"https://evidence.example.test/guide.md",
"https://evidence.example.test/runbook.md",
],
authentication: "signed_urls_file",
}, {
missing: [],
values: { THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE: signedFile },
});
expect(parse(yaml).evidence.sources).toEqual([{
type: "http",
provenance_urls: [
"https://evidence.example.test/guide.md",
"https://evidence.example.test/runbook.md",
],
signed_urls_file: signedFile,
connect_timeout: 5,
read_timeout: 30,
max_bytes: 10_485_760,
max_redirects: 5,
allow_private_hosts: false,
max_cache_bytes: 67_108_864,
}]);
expect(yaml).not.toContain("SIGNED-URL-CANARY-CONTENT");
});
test("renders ambient S3 Evidence without credential keys", () => {
const rendered = parse(evidenceRender({
type: "s3",
uri: "s3://clinical-evidence/published/guides/",
credentials: "ambient",
region: "eu-west-1",
}));
expect(rendered.evidence.sources).toEqual([{
type: "s3",
bucket: "clinical-evidence",
prefix: "published/guides/",
region: "eu-west-1",
trusted_endpoint: false,
allow_private_endpoint: false,
allow_insecure_endpoint: false,
max_bytes: 10_485_760,
max_objects: 10_000,
max_pages: 100,
page_size: 1_000,
}]);
expect(JSON.stringify(rendered.evidence)).not.toMatch(/access_key|secret_key|session_token/);
});
test("renders static S3 Evidence with endpoint policy, limits, and file paths but no contents", () => {
const yaml = evidenceRender({
type: "s3",
uri: "s3://clinical-evidence/published/",
credentials: "static_files",
endpoint_url: "http://minio.internal:9000/",
region: "eu-central-1",
trusted_endpoint: true,
allow_private_endpoint: true,
allow_insecure_endpoint: true,
max_bytes: 222,
max_objects: 33,
max_pages: 4,
page_size: 5,
}, {
missing: [],
values: {
THT_WS_PSD_CLINICAL_EVIDENCE_ACCESS_KEY_FILE: "/run/secrets/evidence-access",
THT_WS_PSD_CLINICAL_EVIDENCE_SECRET_KEY_FILE: "/run/secrets/evidence-secret",
THT_WS_PSD_CLINICAL_EVIDENCE_SESSION_TOKEN_FILE: "/run/secrets/evidence-token",
},
});
expect(parse(yaml).evidence.sources).toEqual([{
type: "s3",
bucket: "clinical-evidence",
prefix: "published/",
endpoint_url: "http://minio.internal:9000/",
region: "eu-central-1",
access_key_file: "/run/secrets/evidence-access",
secret_key_file: "/run/secrets/evidence-secret",
session_token_file: "/run/secrets/evidence-token",
trusted_endpoint: true,
allow_private_endpoint: true,
allow_insecure_endpoint: true,
max_bytes: 222,
max_objects: 33,
max_pages: 4,
page_size: 5,
}]);
expect(yaml).not.toContain("ACCESS-CANARY-CONTENT");
expect(yaml).not.toContain("SECRET-CANARY-CONTENT");
expect(yaml).not.toContain("TOKEN-CANARY-CONTENT");
});
test("omits Evidence configuration and policy when the descriptor has no Evidence", () => {
const rendered = parse(renderRuntimeConfig(
workspaceV3,
directBindings,
paths,
evidenceContext,
{},
semanticRuntime,
));
expect(rendered).not.toHaveProperty("evidence");
expect(rendered).not.toHaveProperty("vector");
});
test.each([
{
source: {
type: "http", uris: ["https://evidence.example.test/guide.md"],
authentication: "signed_urls_file",
},
missing: "THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE",
},
{
source: {
type: "s3", uri: "s3://clinical-evidence/published/", credentials: "static_files",
},
missing: "THT_WS_PSD_CLINICAL_EVIDENCE_SECRET_KEY_FILE",
},
])("rejects missing required Evidence binding $missing before rendering", ({ source, missing }) => {
expect(() => evidenceRender(source, { missing: [missing], values: {} })).toThrow(
"runtime configuration requires complete Evidence bindings",
);
});
test("is byte deterministic and revision-bound for descriptor-identical content-only commits", () => {
const source = {
type: "filesystem",
uri: "workspace-content/psd-clinical/evidence",
};
const first = evidenceRender(source);
expect(evidenceRender(source)).toBe(first);
const nextRevision = "2".repeat(40);
const next = renderRuntimeConfig(
evidenceWorkspace(source),
directBindings,
paths,
{
workspaceId: "psd-clinical",
workspaceRevision: nextRevision,
revisionContentRoot: `/srv/registry/snapshots/${nextRevision}`,
},
{},
semanticRuntime,
);
const firstParsed = parse(first);
const nextParsed = parse(next);
expect(next).not.toBe(first);
expect(nextParsed.runtime_identity.workspace_revision).toBe(nextRevision);
expect(nextParsed.evidence.sources[0].root).toBe(
`/srv/registry/snapshots/${nextRevision}/workspace-content/psd-clinical/evidence`,
);
expect(nextParsed.evidence.sources[0].root).not.toBe(firstParsed.evidence.sources[0].root);
});