fix(ci): project private application secrets

This commit is contained in:
2026-08-25 18:47:49 +02:00
parent fd878b8c3e
commit 73b784a176
4 changed files with 84 additions and 18 deletions
+11 -4
View File
@@ -83,7 +83,7 @@ checker=(node --import "$tsx_loader" "$root/scripts/task13-runtime-fixture-check
echo "backend dependencies are required for the Task 13 runtime fixture contract" >&2
exit 2
}
"${checker[@]}" "$rendered" "$workspace" "$profile"
"${checker[@]}" "$rendered" "$workspace" "$profile" "$TASK13_SECRETS" "$TASK13_SESSION_RUNTIME_PASSWORD"
for mutation in \
wrong-service \
@@ -93,9 +93,9 @@ for mutation in \
wrong-embedding-service \
external-semantic-urls; do
mutated="$fixture/$mutation.json"
node - "$rendered" "$mutated" "$mutation" <<'NODE'
node - "$rendered" "$mutated" "$mutation" "$profile" <<'NODE'
const fs = require("fs");
const [source, destination, mutation] = process.argv.slice(2);
const [source, destination, mutation, profile] = process.argv.slice(2);
const config = JSON.parse(fs.readFileSync(source, "utf8"));
if (mutation === "wrong-service") {
const name = "THT_WS_TASK13_SMOKE_DWH_HOST";
@@ -105,7 +105,12 @@ if (mutation === "wrong-service") {
} else if (mutation === "wrong-value") {
config.services.core.environment.THT_WS_TASK13_SMOKE_DWH_HOST = "wrong.task13.invalid";
} else if (mutation === "wrong-secret-mount") {
config.secrets.thothii_secrets.file = source + ".missing";
if (profile === "local") {
const mount = config.services.core.volumes.find((item) => item.target === "/run/secrets");
mount.source = "wrong-application-secrets";
} else {
config.services.core.secrets[0].target = "wrong.secrets";
}
} else if (mutation === "wrong-qdrant-service") {
config.services.core.environment.THT_INTERNAL_QDRANT_URL = "http://vector:6333";
} else if (mutation === "wrong-embedding-service") {
@@ -117,6 +122,7 @@ if (mutation === "wrong-service") {
fs.writeFileSync(destination, JSON.stringify(config));
NODE
if "${checker[@]}" "$mutated" "$workspace" "$profile" \
"$TASK13_SECRETS" "$TASK13_SESSION_RUNTIME_PASSWORD" \
>"$fixture/$mutation.out" 2>"$fixture/$mutation.err"; then
echo "runtime fixture checker accepted mutation: $mutation" >&2
exit 1
@@ -141,6 +147,7 @@ if (mutation === "collection-reuse") {
fs.writeFileSync(destination, yaml.stringify(workspace));
NODE
if "${checker[@]}" "$rendered" "$mutated" "$profile" \
"$TASK13_SECRETS" "$TASK13_SESSION_RUNTIME_PASSWORD" \
>"$fixture/$mutation.out" 2>"$fixture/$mutation.err"; then
echo "runtime fixture checker accepted workspace mutation: $mutation" >&2
exit 1