feat: bind evidence credentials through local files

This commit is contained in:
2026-08-09 19:03:36 +02:00
parent c7a369f436
commit 7126b567b0
11 changed files with 839 additions and 18 deletions
+59
View File
@@ -190,6 +190,7 @@ llm_policy:
missing: [],
values: { THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL: "https://embedding.internal" },
},
evidence: { missing: [], values: {} },
};
const writerVariables = buildInstallationContract(writerWorkspace).variables
@@ -326,3 +327,61 @@ test("v3 installation contract omits external vector and embedding bindings", ()
expect(names.some((name) => name.includes("_EMBEDDING_"))).toBe(false);
expect(renderWorkspaceDocs(workspaceV3).markdown).not.toContain("Embedding service");
});
test.each([
{
mode: "signed HTTP",
source: {
type: "http", uris: ["https://evidence.example.test/guide.md"],
authentication: "signed_urls_file",
},
expected: ["THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE"],
},
{
mode: "static S3",
source: { type: "s3", uri: "s3://clinical-evidence/published/", credentials: "static_files" },
expected: [
"THT_WS_PSD_CLINICAL_EVIDENCE_ACCESS_KEY_FILE",
"THT_WS_PSD_CLINICAL_EVIDENCE_SECRET_KEY_FILE",
"THT_WS_PSD_CLINICAL_EVIDENCE_SESSION_TOKEN_FILE",
],
},
])("generates source-specific $mode Evidence file bindings", ({ source, expected }) => {
const descriptor = parseWorkspaceYaml(`${renderWorkspaceWithoutEvidence()}evidence:\n source: ${JSON.stringify(source)}\n`);
const contract = buildInstallationContract(descriptor);
const evidence = contract.variables.filter((variable) => variable.role === "EVIDENCE");
expect(contract.namespace).toBe("PSD_CLINICAL");
expect(evidence.map((variable) => variable.name)).toEqual(expected);
expect(evidence.every((variable) => variable.secret)).toBe(true);
expect(renderWorkspaceDocs(descriptor).envExample).not.toContain("CANARY-SECRET");
});
test.each([
{ type: "filesystem", uri: "workspace-content/psd-clinical/evidence" },
{ type: "http", uris: ["https://evidence.example.test/guide.md"], authentication: "none" },
{ type: "s3", uri: "s3://clinical-evidence/published/", credentials: "ambient" },
])("omits Evidence installation variables for $type modes without file credentials", (source) => {
const descriptor = parseWorkspaceYaml(`${renderWorkspaceWithoutEvidence()}evidence:\n source: ${JSON.stringify(source)}\n`);
expect(buildInstallationContract(descriptor).variables.some((variable) => variable.role === "EVIDENCE"))
.toBe(false);
});
function renderWorkspaceWithoutEvidence(): string {
return `workspace:
schema_version: 3
id: psd-clinical
name: Policlinico San Donato
language: it
dwh:
engine: postgres
database: postgres
schema: datawarehouse
supported_transports: [postgres_direct]
semantic_index:
vector_store: { engine: qdrant, collection: psd-clinical, dimensions: 1024, distance: cosine }
embedding: { provider: ollama_internal, model: qwen3-embedding:0.6b, dimensions: 1024 }
llm_policy: { allowed: [zai/glm-5.2] }
`;
}