fix: harden workspace registry deployment

This commit is contained in:
2026-08-04 07:42:35 +02:00
parent f71feecaea
commit 802b564200
11 changed files with 132 additions and 14 deletions
+18
View File
@@ -39,6 +39,24 @@ test("loadConfig keeps local development defaults", () => {
expect(loadConfig({}).dataRoot).toBeUndefined();
});
test("loadConfig enables the legacy workspace request only through explicit local mode", () => {
expect(loadConfig({ THT_LEGACY_WORKSPACE_MODE: "local" }).legacyWorkspaceMode).toBe(true);
expect(() => loadConfig({
THT_LEGACY_WORKSPACE_MODE: "local",
AUTH_MODE: "upstream",
THT_SESSION_STORAGE: "postgres",
THT_SESSION_DB_HOST: "db.internal",
THT_SESSION_DB_NAME: "thoth",
THT_SESSION_RUNTIME_USER: "thoth_sessions_app",
THT_SESSION_RUNTIME_PASSWORD_FILE: "/run/secrets/session_runtime_password",
THT_SESSION_DB_SSLMODE: "verify-full",
THT_SESSION_DB_SSLROOTCERT: "/run/secrets/session_ca.pem",
})).toThrow(/legacy workspace mode requires local session storage/);
expect(() => loadConfig({ THT_LEGACY_WORKSPACE_MODE: "true" }))
.toThrow(/legacy workspace mode configuration is invalid/);
});
test("loadConfig rejects unauthenticated public exposure", () => {
expect(() => loadConfig({
THOTH_PUBLIC_EXPOSURE: "true",
+3 -1
View File
@@ -29,7 +29,9 @@ async function readUntil(
}
test("loop F1: crea sessione → SSE riceve il widget → risponde → il modello riparte (follow-up)", async () => {
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
const app = buildApp(loadConfig({
THT_HARNESS_DIR: "../harness", THT_LEGACY_WORKSPACE_MODE: "local",
}), {
thtRunner: {
ollamaEnsure: async () => ({ ok: true }),
searchPack: async () => {},
+39
View File
@@ -173,6 +173,45 @@ test("new sessions are created through the authenticated principal, not a client
expect(principal).toMatchObject({ issuer: "portal", subject: "alice" });
});
test("new sessions reject the client legacy workspace field unless local legacy mode is explicit", async () => {
const sessionNew = vi.fn(async () => ({ id: "legacy" }));
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
thtRunner: { sessionNew, searchPack: async () => {} } as any,
readiness: { ensure: async () => ({ ok: true }) } as any,
mgr: { get: () => undefined, createFor: () => ({ bridge: { onClientEvent: () => {} } }), configure: async () => {}, start: () => {} } as any,
getSettings: () => ({}) as any,
});
const response = await app.inject({
method: "POST", url: "/sessions", payload: { question: "q", workspace: "legacy" },
});
expect(response.statusCode).toBe(409);
expect(response.json()).toMatchObject({ code: "workspace_revision_unavailable" });
expect(sessionNew).not.toHaveBeenCalled();
});
test("explicit local legacy mode permits the unpinned client workspace request", async () => {
const sessionNew = vi.fn(async () => ({ id: "legacy" }));
const app = buildApp(loadConfig({
THT_HARNESS_DIR: "../harness", THT_LEGACY_WORKSPACE_MODE: "local",
}), {
thtRunner: { sessionNew, searchPack: async () => {} } as any,
readiness: { ensure: async () => ({ ok: true }) } as any,
mgr: { get: () => undefined, createFor: () => ({ bridge: { onClientEvent: () => {} } }), configure: async () => {}, start: () => {} } as any,
getSettings: () => ({}) as any,
});
const response = await app.inject({
method: "POST", url: "/sessions", payload: { question: "q", workspace: "legacy" },
});
expect(response.statusCode).toBe(200);
expect(sessionNew).toHaveBeenCalledWith(expect.objectContaining({
workspaceConfigPath: undefined, workspaceId: undefined, workspaceRevision: undefined,
}));
});
test("creates a session from the active immutable workspace revision", async () => {
const sessionNew = vi.fn(async () => ({ id: "pinned" }));
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
+21 -1
View File
@@ -1,9 +1,10 @@
import { existsSync, readFileSync, rmSync } from "node:fs";
import { existsSync, readFileSync, rmSync, writeFileSync } from "node:fs";
import { mkdtemp } from "node:fs/promises";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { afterEach, expect, test } from "vitest";
import {
main,
migrateLegacyWorkspace,
writeMigratedWorkspace,
} from "../src/workspaces/migrate-legacy.js";
@@ -48,13 +49,29 @@ test("writes versioned repository artifacts atomically without replacing a prior
expect(existsSync(destination)).toBe(true);
});
test("CLI accepts an explicit valid ID when a legacy filename contains dots", async () => {
const root = await mkdtemp(join(tmpdir(), "thoth-workspace-migrate-"));
temporaryRoots.push(root);
const input = join(root, "psd.clinical.yaml");
writeFileSync(input, readFixture("local.yaml"));
await main(["--input", input, "--output", root, "--id", "psd-clinical"]);
const destination = join(root, "workspaces", "psd-clinical.yaml");
expect(parseWorkspaceYaml(readFileSync(destination, "utf8"))).toMatchObject({
workspace: { id: "psd-clinical", schema_version: 1 },
});
});
test("declares a durable isolated registry volume and only read-only Git credential mounts", () => {
const compose = readFileSync(new URL("../../compose.yaml", import.meta.url), "utf8");
const development = readFileSync(new URL("../../docker-compose.dev.yml", import.meta.url), "utf8");
const dockerfile = readFileSync(new URL("../../docker/core.Dockerfile", import.meta.url), "utf8");
const smoke = readFileSync(new URL("../../scripts/workspace-registry-smoke.sh", import.meta.url), "utf8");
for (const source of [compose, development]) {
expect(source).toContain("THT_WORKSPACE_REGISTRY_ROOT: /data/workspace-registry");
expect(source).toContain("THT_WORKSPACE_GIT_REMOTE: ${THT_WORKSPACE_GIT_REMOTE:?set THT_WORKSPACE_GIT_REMOTE}");
expect(source).toContain("workspace-registry:/data/workspace-registry");
expect(source).toMatch(/workspace-registry-git-credentials:ro/);
expect(source).toMatch(/workspace-registry-git-ca:ro/);
@@ -62,4 +79,7 @@ test("declares a durable isolated registry volume and only read-only Git credent
expect(source).toMatch(/workspace-registry-git-known-hosts:ro/);
}
expect(dockerfile).toMatch(/mkdir -p \/data\/workspace-registry && chown -R thoth:thoth \/data\/workspace-registry/);
expect(smoke).toContain('core_remote="/fixtures/offline.git"');
expect(smoke).toContain('"degraded":true');
expect(smoke).toContain('core_remote="/fixtures/remote.git"');
});