fix: harden workspace runtime snapshots

This commit is contained in:
2026-08-03 22:10:09 +02:00
parent 049f8675c6
commit 5d7ebc5b01
6 changed files with 297 additions and 18 deletions
@@ -42,6 +42,7 @@ const directBindings: RuntimeBindings = {
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
THT_WS_PSD_CLINICAL_DWH_USER: "thoth_reader",
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: "/run/secrets/dwh-password",
THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE: "/run/secrets/dwh-ca.pem",
},
},
vector: {
@@ -52,6 +53,7 @@ const directBindings: RuntimeBindings = {
THT_WS_PSD_CLINICAL_VECTOR_PORT: "5432",
THT_WS_PSD_CLINICAL_VECTOR_USER: "vector_reader",
THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_FILE: "/run/secrets/vector-password",
THT_WS_PSD_CLINICAL_VECTOR_TLS_CA_FILE: "/run/secrets/vector-ca.pem",
},
},
embedding: {
@@ -74,12 +76,14 @@ test("renders a direct PostgreSQL binding to the legacy harness shape", () => {
schema: "datawarehouse",
user: "thoth_reader",
password_file: "/run/secrets/dwh-password",
ssl_ca_file: "/run/secrets/dwh-ca.pem",
transport: "direct",
},
vector_db: {
host: "vector.internal",
schema: "datawarehouse",
password_file: "/run/secrets/vector-password",
ssl_ca_file: "/run/secrets/vector-ca.pem",
},
embeddings: {
base_url: "http://embedding.internal:11434",
@@ -92,6 +96,28 @@ test("renders a direct PostgreSQL binding to the legacy harness shape", () => {
expect(yaml).toContain("schema: datawarehouse");
});
test("omits direct TLS fields when binding validation did not retain a file path", () => {
const dwhValues = { ...directBindings.dwh.values };
const vectorValues = { ...directBindings.vector.values };
delete dwhValues.THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE;
delete vectorValues.THT_WS_PSD_CLINICAL_VECTOR_TLS_CA_FILE;
const yaml = renderRuntimeConfig(workspace, {
...directBindings,
dwh: {
...directBindings.dwh,
values: dwhValues,
},
vector: {
...directBindings.vector,
values: vectorValues,
},
}, paths);
const rendered = parse(yaml);
expect(rendered.database).not.toHaveProperty("ssl_ca_file");
expect(rendered.vector_db).not.toHaveProperty("ssl_ca_file");
});
test("renders REST bindings through the legacy rest sections without secret values", () => {
const yaml = renderRuntimeConfig(workspace, {
...directBindings,