feat: bind evidence credentials through local files

This commit is contained in:
2026-08-09 19:03:36 +02:00
parent c7a369f436
commit 7126b567b0
11 changed files with 839 additions and 18 deletions
@@ -141,6 +141,7 @@ const bindings: RuntimeBindings = {
THT_WS_PSD_CLINICAL_EMBEDDING_TLS_CA_FILE: "/run/secrets/embedding-ca",
},
},
evidence: { missing: [], values: {} },
};
const writerBindings: RuntimeBindings = {
@@ -190,6 +191,7 @@ const bindingsV3: RuntimeBindings = {
vector: { transport: "rest_api", missing: [], values: {} },
vectorWriter: { transport: "rest_api", missing: [], values: {} },
embedding: { transport: "rest_api", missing: [], values: {} },
evidence: { missing: [], values: {} },
};
function successfulAdapters(overrides: Partial<DiagnosticAdapters> = {}): DiagnosticAdapters {
@@ -960,3 +962,55 @@ test("attempts bounded cleanup when a timed-out write may already have created t
expect(adapters.removeDiagnosticRecord).toHaveBeenCalledOnce();
expect(result.activatable).toBe(false);
});
test.each([
{
source: {
type: "http", uris: ["https://evidence.example.test/guide.md"],
authentication: "signed_urls_file",
},
field: "evidence.source.authentication",
variable: "THT_WS_PSD_CLINICAL_EVIDENCE_SIGNED_URLS_FILE",
},
{
source: { type: "s3", uri: "s3://clinical-evidence/published/", credentials: "static_files" },
field: "evidence.source.credentials",
variable: "THT_WS_PSD_CLINICAL_EVIDENCE_ACCESS_KEY_FILE",
},
])("reports sanitized v3 Evidence binding diagnostics for $field", async ({ source, field, variable }) => {
const descriptor = parseWorkspaceYaml(`${renderEvidenceWorkspace()}evidence:\n source: ${JSON.stringify(source)}\n`);
const resolved: RuntimeBindings = {
...resolveRuntimeBindings(descriptor, {
[variable]: "CANARY-UNSAFE-RELATIVE-PATH",
}, ["/run/secrets"]),
dwh: bindings.dwh,
};
const result = await createProductionWorkspaceDiagnoser(5_000)(descriptor, resolved, { writeProbe: false });
expect(result).toEqual({
activatable: false,
diagnostics: expect.arrayContaining([expect.objectContaining({
code: "binding_missing", field, variable,
})]),
});
expect(JSON.stringify(result)).not.toContain("CANARY-UNSAFE-RELATIVE-PATH");
});
function renderEvidenceWorkspace(): string {
return `workspace:
schema_version: 3
id: psd-clinical
name: Policlinico San Donato
language: it
dwh:
engine: postgres
database: warehouse
schema: datawarehouse
supported_transports: [postgres_direct]
semantic_index:
vector_store: { engine: qdrant, collection: psd-clinical, dimensions: 1024, distance: cosine }
embedding: { provider: ollama_internal, model: qwen3-embedding:0.6b, dimensions: 1024 }
llm_policy: { allowed: [zai/glm-5.2] }
`;
}