test: make install docs fixtures self-contained
This commit is contained in:
@@ -8,7 +8,8 @@ verifier_functions="$(mktemp "${TMPDIR:-/tmp}/thoth-install-docs-functions.XXXXX
|
||||
negative_root="$(mktemp -d "${TMPDIR:-/tmp}/thoth-install-docs-negative.XXXXXX")"
|
||||
trap 'rm -f "$output" "$verifier_functions"; rm -rf "$negative_root"' EXIT HUP INT TERM
|
||||
|
||||
"$root/scripts/verify-workspace-install-docs.sh" --fixtures-only >"$output"
|
||||
env -u TMPDIR -u THT_AUTH_CONFIG_ROOT \
|
||||
"$root/scripts/verify-workspace-install-docs.sh" --fixtures-only >"$output"
|
||||
|
||||
for fixture in \
|
||||
"internal semantic infrastructure documentation contract" \
|
||||
|
||||
@@ -914,7 +914,7 @@ for (const block of [setupPowerShell, healthPowerShell, updatePowerShell, backup
|
||||
}
|
||||
NODE
|
||||
local update_fixture update_script fake_bin calls output status
|
||||
update_fixture="$(mktemp -d "${TMPDIR%/}/thoth-source-update.XXXXXX")"
|
||||
update_fixture="$(mktemp -d "${TMPDIR:-/tmp}/thoth-source-update.XXXXXX")"
|
||||
trap 'rm -rf "$update_fixture"' RETURN
|
||||
update_script="$update_fixture/update.sh"
|
||||
awk '
|
||||
@@ -1063,7 +1063,7 @@ if (!warningPattern.test(shell.slice(Math.max(0, rewriteAt - 180), rewriteAt)) |
|
||||
}
|
||||
NODE
|
||||
local repair_root repair_script real_git partial_repo clean_repo partial_output repair_status
|
||||
repair_root="$(mktemp -d "${TMPDIR%/}/thoth-crlf-repair.XXXXXX")"
|
||||
repair_root="$(mktemp -d "${TMPDIR:-/tmp}/thoth-crlf-repair.XXXXXX")"
|
||||
trap 'rm -rf "$repair_root"' RETURN
|
||||
repair_script="$repair_root/repair.sh"
|
||||
awk '
|
||||
@@ -1869,8 +1869,8 @@ verify_local_installation_example() {
|
||||
return 1
|
||||
}
|
||||
|
||||
local fixture source_copy operator_dir copied_example env_file
|
||||
fixture="$(mktemp -d "${TMPDIR%/}/thoth local install.XXXXXX")"
|
||||
local fixture source_copy operator_dir copied_example env_file auth_config_root
|
||||
fixture="$(mktemp -d "${TMPDIR:-/tmp}/thoth local install.XXXXXX")"
|
||||
trap 'rm -rf "$fixture"' RETURN
|
||||
[[ "$fixture" == *" "* ]] || {
|
||||
echo "local installation fixture path does not contain spaces" >&2
|
||||
@@ -1878,7 +1878,8 @@ verify_local_installation_example() {
|
||||
}
|
||||
source_copy="$fixture/ThothII source"
|
||||
operator_dir="$fixture/operator files"
|
||||
mkdir -p "$source_copy/deploy/pi" "$operator_dir"
|
||||
auth_config_root="$operator_dir/auth config"
|
||||
mkdir -p "$source_copy/deploy/pi" "$operator_dir" "$auth_config_root"
|
||||
cp "$root/compose.yaml" "$source_copy/compose.yaml"
|
||||
cp "$root/deploy/compose.local.yaml" "$source_copy/deploy/compose.local.yaml"
|
||||
cp "$root/deploy/compose.git-ssh.yaml" "$source_copy/deploy/compose.git-ssh.yaml"
|
||||
@@ -1897,6 +1898,7 @@ verify_local_installation_example() {
|
||||
"THT_SECRETS_FILE=$operator_dir/thothii.secrets" \
|
||||
"THT_WORKSPACE_GIT_SSH_KEY_FILE=$operator_dir/git-ssh-key" \
|
||||
"THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE=$operator_dir/git-known-hosts" \
|
||||
"THT_AUTH_CONFIG_ROOT=$auth_config_root" \
|
||||
>"$env_file"
|
||||
|
||||
copied_example="$fixture/thothii-installation.yaml"
|
||||
@@ -1925,12 +1927,19 @@ verify_local_installation_example() {
|
||||
local rendered="$fixture/local-installation.json"
|
||||
"$root/scripts/compose-with-preflight.sh" --env-file "$descriptor_env" \
|
||||
"${files[@]}" config --format json >"$rendered"
|
||||
node - "$rendered" <<'NODE'
|
||||
node - "$rendered" "$auth_config_root" <<'NODE'
|
||||
const fs = require("fs");
|
||||
const config = JSON.parse(fs.readFileSync(process.argv[2], "utf8"));
|
||||
const [path, authConfigRoot] = process.argv.slice(2);
|
||||
const config = JSON.parse(fs.readFileSync(path, "utf8"));
|
||||
if (Object.keys(config.services).sort().join(",") !== "core,embedding,embedding-model-init,frontend,qdrant") {
|
||||
throw new Error("local installation example must render the internal semantic stack");
|
||||
}
|
||||
const authMount = (config.services.core.volumes || []).find(
|
||||
(mount) => mount.target === "/run/thothii-auth",
|
||||
);
|
||||
if (!authMount || authMount.source !== authConfigRoot || authMount.read_only !== true) {
|
||||
throw new Error("local installation example must mount its fixture auth root read-only");
|
||||
}
|
||||
const output = JSON.stringify(config);
|
||||
for (const secret of [
|
||||
"fixture-local-pi-key",
|
||||
@@ -1952,8 +1961,8 @@ verify_server_installation_example() {
|
||||
return 1
|
||||
}
|
||||
|
||||
local fixture source_copy operator_dir copied_example env_file backup_root
|
||||
fixture="$(mktemp -d "${TMPDIR%/}/thoth server install.XXXXXX")"
|
||||
local fixture source_copy operator_dir copied_example env_file backup_root auth_config_root
|
||||
fixture="$(mktemp -d "${TMPDIR:-/tmp}/thoth server install.XXXXXX")"
|
||||
trap 'rm -rf "$fixture"' RETURN
|
||||
[[ "$fixture" == *" "* ]] || {
|
||||
echo "server installation fixture path does not contain spaces" >&2
|
||||
@@ -1962,8 +1971,10 @@ verify_server_installation_example() {
|
||||
source_copy="$fixture/ThothII server source"
|
||||
operator_dir="$fixture/server operator files"
|
||||
backup_root="$fixture/server backups"
|
||||
auth_config_root="$operator_dir/auth config"
|
||||
mkdir -p "$source_copy/deploy/pi" "$source_copy/deploy/workspaces" \
|
||||
"$operator_dir/data/workspace-secrets" "$operator_dir/pi-state" "$operator_dir/workspace-registry" "$backup_root"
|
||||
"$operator_dir/data/workspace-secrets" "$operator_dir/pi-state" "$operator_dir/workspace-registry" \
|
||||
"$auth_config_root" "$backup_root"
|
||||
"$root/scripts/prepare-server-pi-state.sh" \
|
||||
"$operator_dir/pi-state" "$(id -u)" "$(id -g)" >/dev/null
|
||||
cp "$root/compose.yaml" "$source_copy/compose.yaml"
|
||||
@@ -1997,6 +2008,7 @@ verify_server_installation_example() {
|
||||
"THT_PI_STATE_ROOT=$operator_dir/pi-state" \
|
||||
"THT_WORKSPACE_REGISTRY_ROOT=$operator_dir/workspace-registry" \
|
||||
"THT_BACKUP_ROOT=$backup_root" \
|
||||
"THT_AUTH_CONFIG_ROOT=$auth_config_root" \
|
||||
"THT_SERVER_WORKSPACE_CONFIG=$source_copy/deploy/workspaces/server-sessions.yaml.example" \
|
||||
'THT_LLM_URL=https://llm.example.invalid' \
|
||||
'THT_SESSION_DB_HOST=sessions.example.invalid' \
|
||||
@@ -2035,14 +2047,19 @@ verify_server_installation_example() {
|
||||
local rendered="$fixture/server-installation.json"
|
||||
"$root/scripts/compose-with-preflight.sh" --env-file "$descriptor_env" \
|
||||
"${files[@]}" config --format json >"$rendered"
|
||||
node - "$rendered" <<'NODE'
|
||||
node - "$rendered" "$auth_config_root" <<'NODE'
|
||||
const fs = require("fs");
|
||||
const config = JSON.parse(fs.readFileSync(process.argv[2], "utf8"));
|
||||
const [path, authConfigRoot] = process.argv.slice(2);
|
||||
const config = JSON.parse(fs.readFileSync(path, "utf8"));
|
||||
if (Object.keys(config.services).sort().join(",") !== "core,embedding,embedding-model-init,frontend,qdrant") {
|
||||
throw new Error("server installation example must render the internal semantic stack");
|
||||
}
|
||||
const core = config.services.core;
|
||||
const frontend = config.services.frontend;
|
||||
const authMount = (core.volumes || []).find((mount) => mount.target === "/run/thothii-auth");
|
||||
if (!authMount || authMount.source !== authConfigRoot || authMount.read_only !== true) {
|
||||
throw new Error("server installation example must mount its fixture auth root read-only");
|
||||
}
|
||||
if (core.environment?.THOTH_PUBLIC_EXPOSURE !== "true" ||
|
||||
core.environment?.THT_AUTH_CONFIG_FILE !== "/run/thothii-auth/auth.yaml") {
|
||||
throw new Error("server installation example must expose only the authenticated frontend");
|
||||
@@ -2131,10 +2148,12 @@ write_private() {
|
||||
}
|
||||
|
||||
verify_compose_fixtures() {
|
||||
local fixture profile rendered
|
||||
fixture="$(mktemp -d "${TMPDIR%/}/thoth-install-fixtures.XXXXXX")"
|
||||
local fixture profile rendered auth_config_root
|
||||
fixture="$(mktemp -d "${TMPDIR:-/tmp}/thoth-install-fixtures.XXXXXX")"
|
||||
trap 'rm -rf "$fixture"' RETURN
|
||||
mkdir -p "$fixture/data/workspace-secrets" "$fixture/pi-state" "$fixture/workspace-registry"
|
||||
auth_config_root="$fixture/auth-config"
|
||||
mkdir -p "$fixture/data/workspace-secrets" "$fixture/pi-state" \
|
||||
"$fixture/workspace-registry" "$auth_config_root"
|
||||
|
||||
write_private "$fixture/pi-auth.json" '{"zai":{"type":"api_key","key":"fixture-native-auth-key"}}'
|
||||
write_private "$fixture/thothii.secrets" 'THT_MODEL_API_KEY=fixture-model-api-key'
|
||||
@@ -2153,6 +2172,7 @@ verify_compose_fixtures() {
|
||||
"THT_DATA_ROOT=$fixture/data" \
|
||||
"THT_PI_STATE_ROOT=$fixture/pi-state" \
|
||||
"THT_WORKSPACE_REGISTRY_ROOT=$fixture/workspace-registry" \
|
||||
"THT_AUTH_CONFIG_ROOT=$auth_config_root" \
|
||||
"THT_SERVER_WORKSPACE_CONFIG=$fixture/server-sessions.yaml" \
|
||||
'THT_SESSION_DB_HOST=sessions.example.invalid' \
|
||||
'THT_SESSION_DB_NAME=thoth_sessions' \
|
||||
@@ -2178,14 +2198,18 @@ verify_compose_fixtures() {
|
||||
"$root/scripts/compose-with-preflight.sh" --env-file "$fixture/operator.env" \
|
||||
"${files[@]}" config --format json >"$rendered"
|
||||
|
||||
node - "$rendered" "$profile" <<'NODE'
|
||||
node - "$rendered" "$profile" "$auth_config_root" <<'NODE'
|
||||
const fs = require("fs");
|
||||
const [path, profile] = process.argv.slice(2);
|
||||
const [path, profile, authConfigRoot] = process.argv.slice(2);
|
||||
const config = JSON.parse(fs.readFileSync(path, "utf8"));
|
||||
if (Object.keys(config.services).sort().join(",") !== "core,embedding,embedding-model-init,frontend,qdrant") {
|
||||
throw new Error(profile + ": mandatory stack must include the internal semantic services");
|
||||
}
|
||||
const core = config.services.core;
|
||||
const authMount = (core.volumes || []).find((mount) => mount.target === "/run/thothii-auth");
|
||||
if (!authMount || authMount.source !== authConfigRoot || authMount.read_only !== true) {
|
||||
throw new Error(profile + ": core must mount its fixture auth root read-only");
|
||||
}
|
||||
for (const target of [
|
||||
"/home/thoth/.pi/agent/auth.json",
|
||||
"/home/thoth/.pi/agent/models.json",
|
||||
|
||||
Reference in New Issue
Block a user