feat: configure Git workspace registry

This commit is contained in:
2026-08-03 21:13:23 +02:00
parent 7ad0199f9b
commit 6e1321f93c
6 changed files with 213 additions and 2 deletions
+6
View File
@@ -29,6 +29,12 @@ test("loadConfig keeps local development defaults", () => {
thtBin: "tht",
piBin: "pi",
settingsFile: "data/settings.json",
workspaceRegistry: {
root: "/data/workspace-registry",
branch: "main",
maxImportBytes: 10 * 1024 * 1024,
maxImportEntries: 32,
},
});
expect(loadConfig({}).dataRoot).toBeUndefined();
});
+48
View File
@@ -0,0 +1,48 @@
import { expect, test } from "vitest";
import { loadConfig } from "../src/config.js";
test("loads a safe Git workspace registry configuration", () => {
const cfg = loadConfig({
THT_WORKSPACE_REGISTRY_ROOT: "/data/workspace-registry",
THT_WORKSPACE_GIT_REMOTE: "ssh://git@gitea.example/thoth/workspaces.git",
THT_WORKSPACE_GIT_BRANCH: "main",
THT_WORKSPACE_INSTALLATION_ID: "server-psd-1",
THT_WORKSPACE_SECRET_ROOTS: "/run/secrets,/data/secrets",
});
expect(cfg.workspaceRegistry).toMatchObject({
root: "/data/workspace-registry",
remoteUrl: "ssh://git@gitea.example/thoth/workspaces.git",
branch: "main",
installationId: "server-psd-1",
secretRoots: ["/run/secrets", "/data/secrets"],
});
});
test("uses safe workspace registry defaults", () => {
expect(loadConfig({}).workspaceRegistry).toMatchObject({
root: "/data/workspace-registry",
branch: "main",
maxImportBytes: 10 * 1024 * 1024,
maxImportEntries: 32,
});
});
test("rejects a relative registry root and invalid import limits", () => {
expect(() => loadConfig({ THT_WORKSPACE_REGISTRY_ROOT: "registry" })).toThrow(/registry/i);
expect(() => loadConfig({
THT_WORKSPACE_REGISTRY_ROOT: "/data/registry",
THT_WORKSPACE_MAX_IMPORT_BYTES: "0",
})).toThrow(/import/i);
expect(() => loadConfig({
THT_WORKSPACE_REGISTRY_ROOT: "/data/registry",
THT_WORKSPACE_MAX_IMPORT_ENTRIES: "1.5",
})).toThrow(/import/i);
});
test("rejects unsafe registry branch, installation ID, and secret roots", () => {
expect(() => loadConfig({ THT_WORKSPACE_GIT_BRANCH: "" })).toThrow(/branch/i);
expect(() => loadConfig({ THT_WORKSPACE_INSTALLATION_ID: "" })).toThrow(/installation/i);
expect(() => loadConfig({ THT_WORKSPACE_SECRET_ROOTS: "/run/secrets,relative" }))
.toThrow(/secret/i);
});