feat: configure workspace runtime secrets through API
This commit is contained in:
@@ -12,6 +12,7 @@ import { buildApp } from "../src/app.js";
|
||||
import { loadConfig } from "../src/config.js";
|
||||
import { ThtRunner } from "../src/tht/tht-runner.js";
|
||||
import { WorkspaceRegistry } from "../src/workspaces/registry.js";
|
||||
import { WorkspaceSecretStore } from "../src/workspaces/secret-store.js";
|
||||
import type { WorkspaceRegistryConfig } from "../src/workspaces/types.js";
|
||||
|
||||
const runFile = promisify(execFile);
|
||||
@@ -166,6 +167,36 @@ test("real schema-v3 registry revision loads through ThtRunner and the harness c
|
||||
expect(readdirSync(join(f.registryConfig.root, "snapshots", "runtime"))).toEqual([]);
|
||||
});
|
||||
|
||||
test("ThtRunner uses a vault secret only for the lifetime of its runtime lease", async () => {
|
||||
const f = await fixture();
|
||||
vi.stubEnv("THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE", "");
|
||||
const vaultRoot = join(f.root, "workspace-secrets");
|
||||
const runtimeRoot = join(f.root, "workspace-secret-runtime");
|
||||
const secretStore = new WorkspaceSecretStore({
|
||||
root: vaultRoot,
|
||||
runtimeRoot,
|
||||
installationId: "test",
|
||||
});
|
||||
secretStore.put("psd-clinical", "dwh.password", "vault-runtime-password");
|
||||
const runner = new ThtRunner({
|
||||
thtBin,
|
||||
harnessDir,
|
||||
configPath: "config/tht.yaml",
|
||||
dataRoot: f.dataRoot,
|
||||
runtimeSnapshotRoot: join(f.registryConfig.root, "snapshots", "runtime"),
|
||||
secretRoots: f.registryConfig.secretRoots,
|
||||
workspaceSecretStore: secretStore,
|
||||
} as any);
|
||||
|
||||
const lease = runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
|
||||
const rendered = parse(readFileSync(lease.path, "utf8")) as {
|
||||
database: { password_file: string };
|
||||
};
|
||||
expect(readFileSync(rendered.database.password_file, "utf8")).toBe("vault-runtime-password");
|
||||
lease.release();
|
||||
expect(existsSync(rendered.database.password_file)).toBe(false);
|
||||
});
|
||||
|
||||
test("separate runtime leases hand off byte-identical revision Evidence configs accepted by tht", async () => {
|
||||
const f = await fixture();
|
||||
const runner = runnerFor(f);
|
||||
|
||||
Reference in New Issue
Block a user