fix(docs): enforce compose preflight workflow
This commit is contained in:
@@ -9,6 +9,8 @@ trap 'rm -f "$output"' EXIT HUP INT TERM
|
||||
"$root/scripts/verify-workspace-install-docs.sh" --fixtures-only >"$output"
|
||||
|
||||
for fixture in \
|
||||
"local manual requires generated connector override and Compose preflight" \
|
||||
"server manual requires generated connector override and Compose preflight" \
|
||||
"copied local base fixture" \
|
||||
"copied server PostgreSQL/TLS fixture" \
|
||||
"copied HTTPS Git override fixture" \
|
||||
@@ -25,3 +27,10 @@ for fixture in \
|
||||
exit 1
|
||||
}
|
||||
done
|
||||
|
||||
if rg -n 'connector-secrets\.workspace-registry|docker compose' \
|
||||
"$root/docs/install/local-workspace-registry.md" \
|
||||
"$root/docs/install/server-workspace-registry.md"; then
|
||||
echo "installation manuals still document a bypassed Compose or copied connector override path" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
@@ -60,6 +60,26 @@ verify_server_public_contract() {
|
||||
done
|
||||
}
|
||||
|
||||
verify_manual_supported_path() {
|
||||
local profile="$1" manual="$2"
|
||||
local generator='"$THT_SOURCE_ROOT/scripts/generate-connector-secrets-override.sh" --bindings-env "$THT_WORKSPACE_BINDINGS_ENV_FILE" --operator-env .env --output connector-secrets.local.yaml'
|
||||
local wrapper='"$THT_SOURCE_ROOT/scripts/compose-with-preflight.sh" --env-file .env'
|
||||
|
||||
grep -Fq "$generator" "$manual" || {
|
||||
echo "$profile manual does not document the connector override generator" >&2
|
||||
return 1
|
||||
}
|
||||
grep -Fq "$wrapper" "$manual" || {
|
||||
echo "$profile manual does not document the Compose preflight wrapper" >&2
|
||||
return 1
|
||||
}
|
||||
if grep -Eq 'connector-secrets\.workspace-registry|docker compose' "$manual"; then
|
||||
echo "$profile manual documents a bypassed Compose or copied connector override path" >&2
|
||||
return 1
|
||||
fi
|
||||
echo "$profile manual requires generated connector override and Compose preflight passed"
|
||||
}
|
||||
|
||||
compose_fixture() {
|
||||
local name="$1" directory="$2"; shift 2
|
||||
(
|
||||
@@ -130,6 +150,21 @@ verify_connector_fixture() {
|
||||
echo "core process sees connector bindings and secret files passed"
|
||||
}
|
||||
|
||||
verify_documented_operator_path() {
|
||||
local profile="$1" directory="$2" connector_override
|
||||
connector_override="$directory/connector-secrets.local.yaml"
|
||||
"$root/scripts/generate-connector-secrets-override.sh" \
|
||||
--bindings-env "$directory/workspace-bindings.env" --operator-env "$directory/.env" \
|
||||
--output "$connector_override" >/dev/null
|
||||
(
|
||||
cd "$directory"
|
||||
"$root/scripts/compose-with-preflight.sh" --env-file .env \
|
||||
-f compose.workspace-registry.yaml -f git-ssh.workspace-registry.yaml \
|
||||
-f connector-secrets.local.yaml config --quiet
|
||||
)
|
||||
echo "$profile documented generator and preflight fixture passed"
|
||||
}
|
||||
|
||||
verify_copied_operator_fixtures() {
|
||||
local fixture_root local_dir server_dir https_dir ssh_dir connector_dir
|
||||
fixture_root="$(mktemp -d "${TMPDIR%/}/thoth-install-fixtures.XXXXXX")"
|
||||
@@ -177,6 +212,22 @@ verify_copied_operator_fixtures() {
|
||||
prepare_binding_fixture "$ssh_dir"
|
||||
compose_fixture "copied SSH Git override fixture" "$ssh_dir" -f compose.workspace-registry.yaml -f git-ssh.yaml
|
||||
|
||||
: >"$server_dir/git-ssh-key"; : >"$server_dir/git-known-hosts"
|
||||
: >"$server_dir/dwh-password"; : >"$server_dir/vector-api-key"
|
||||
printf '%s\n' \
|
||||
"THT_WORKSPACE_GIT_SSH_KEY_FILE=$server_dir/git-ssh-key" \
|
||||
"THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE=$server_dir/git-known-hosts" \
|
||||
"THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_SOURCE=$server_dir/dwh-password" \
|
||||
"THT_WS_NORTH_STAR_RESEARCH_VECTOR_API_KEY_SOURCE=$server_dir/vector-api-key" >>"$server_dir/.env"
|
||||
cp "$root/docs/install/examples/git-ssh.workspace-registry.yaml" "$server_dir/git-ssh.workspace-registry.yaml"
|
||||
: >"$ssh_dir/dwh-password"; : >"$ssh_dir/vector-api-key"
|
||||
printf '%s\n' \
|
||||
"THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_SOURCE=$ssh_dir/dwh-password" \
|
||||
"THT_WS_NORTH_STAR_RESEARCH_VECTOR_API_KEY_SOURCE=$ssh_dir/vector-api-key" >>"$ssh_dir/.env"
|
||||
cp "$root/docs/install/examples/git-ssh.workspace-registry.yaml" "$ssh_dir/git-ssh.workspace-registry.yaml"
|
||||
verify_documented_operator_path local "$ssh_dir"
|
||||
verify_documented_operator_path server "$server_dir"
|
||||
|
||||
cp "$root/docs/install/examples/local-compose.workspace-registry.yaml" "$connector_dir/compose.workspace-registry.yaml"
|
||||
: >"$connector_dir/dwh-password"; : >"$connector_dir/vector-password"
|
||||
printf '%s\n' \
|
||||
@@ -218,6 +269,8 @@ verify_copied_operator_fixtures() {
|
||||
case "$profile" in
|
||||
--fixtures-only)
|
||||
[[ $# -eq 1 ]] || { echo "usage: $0 --fixtures-only" >&2; exit 2; }
|
||||
verify_manual_supported_path local "$root/docs/install/local-workspace-registry.md"
|
||||
verify_manual_supported_path server "$root/docs/install/server-workspace-registry.md"
|
||||
verify_copied_operator_fixtures
|
||||
exit 0
|
||||
;;
|
||||
@@ -292,28 +345,11 @@ verify_path_variable_values "$example"
|
||||
verify_path_variable_values "$root/docs/install/examples/git-https.workspace-registry.yaml"
|
||||
verify_path_variable_values "$root/docs/install/examples/git-ssh.workspace-registry.yaml"
|
||||
verify_path_variable_values "$root/docs/install/examples/workspace-bindings.env.example"
|
||||
verify_path_variable_values "$root/docs/install/examples/connector-secrets.workspace-registry.yaml"
|
||||
verify_server_public_contract
|
||||
verify_manual_supported_path "$profile" "$manual"
|
||||
|
||||
commands="$(mktemp "${TMPDIR:-/tmp}/thoth-install-docs.XXXXXX")"
|
||||
trap 'rm -f "$commands"' EXIT HUP INT TERM
|
||||
|
||||
# A runnable documentation command is a sh fence immediately following this marker. Commands
|
||||
# outside the marker are explanatory/operator commands and are deliberately never executed here.
|
||||
awk '
|
||||
/^<!--[[:space:]]*verify:command[[:space:]]*-->[[:space:]]*$/ { marked=1; next }
|
||||
marked && /^```(sh|bash|shell)[[:space:]]*$/ { in_fence=1; marked=0; seen=1; next }
|
||||
in_fence && /^```[[:space:]]*$/ { in_fence=0; next }
|
||||
in_fence { print }
|
||||
' "$manual" >"$commands"
|
||||
|
||||
[[ -s "$commands" ]] || { echo "no marked runnable commands in $profile manual" >&2; exit 1; }
|
||||
|
||||
echo "== Validate $profile documented Compose example =="
|
||||
(
|
||||
cd "$root"
|
||||
bash "$commands"
|
||||
)
|
||||
echo "== Validate copied operator fixtures and documented optional Git transports =="
|
||||
verify_copied_operator_fixtures
|
||||
|
||||
echo "== Run isolated workspace-registry bootstrap and recovery smoke =="
|
||||
(
|
||||
@@ -321,7 +357,4 @@ echo "== Run isolated workspace-registry bootstrap and recovery smoke =="
|
||||
env -u WORKSPACE_GIT_REMOTE ./scripts/workspace-registry-smoke.sh
|
||||
)
|
||||
|
||||
echo "== Validate copied operator fixtures and optional Git transports =="
|
||||
verify_copied_operator_fixtures
|
||||
|
||||
echo "$profile installation documentation verification passed"
|
||||
|
||||
Reference in New Issue
Block a user