feat: render private semantic service endpoints
This commit is contained in:
@@ -37,10 +37,29 @@ test("loadConfig keeps local development defaults", () => {
|
||||
maxImportBytes: 10 * 1024 * 1024,
|
||||
maxImportEntries: 32,
|
||||
},
|
||||
internalQdrantUrl: "http://qdrant:6333",
|
||||
internalEmbeddingUrl: "http://embedding:11434",
|
||||
internalEmbeddingModel: "qwen3-embedding:0.6b",
|
||||
internalEmbeddingDimensions: 1024,
|
||||
});
|
||||
expect(loadConfig({}).dataRoot).toBeUndefined();
|
||||
});
|
||||
|
||||
test("loadConfig accepts only the allowed internal semantic runtime hosts", () => {
|
||||
expect(loadConfig({
|
||||
THT_INTERNAL_QDRANT_URL: "http://localhost:6333",
|
||||
THT_INTERNAL_EMBEDDING_URL: "http://127.0.0.1:11434",
|
||||
})).toMatchObject({
|
||||
internalQdrantUrl: "http://localhost:6333",
|
||||
internalEmbeddingUrl: "http://127.0.0.1:11434",
|
||||
});
|
||||
|
||||
expect(() => loadConfig({ THT_INTERNAL_QDRANT_URL: "http://qdrant.internal:6333" }))
|
||||
.toThrow(/internal.*qdrant|host validation|invalid/i);
|
||||
expect(() => loadConfig({ THT_INTERNAL_EMBEDDING_URL: "http://example.com:11434" }))
|
||||
.toThrow(/internal.*embedding|host validation|invalid/i);
|
||||
});
|
||||
|
||||
test("loadConfig enables the legacy workspace request only through explicit local mode", () => {
|
||||
expect(loadConfig({ THT_LEGACY_WORKSPACE_MODE: "local" }).legacyWorkspaceMode).toBe(true);
|
||||
|
||||
|
||||
@@ -1,6 +1,11 @@
|
||||
import { expect, test } from "vitest";
|
||||
import { parse } from "yaml";
|
||||
import { renderRuntimeConfig, type RuntimeBindings, type RuntimePaths } from "../src/workspaces/runtime-renderer.js";
|
||||
import {
|
||||
renderRuntimeConfig,
|
||||
type RuntimeBindings,
|
||||
type RuntimePaths,
|
||||
type SemanticRuntimeConfig,
|
||||
} from "../src/workspaces/runtime-renderer.js";
|
||||
import { supportsSessionRuntime } from "../src/workspaces/bindings.js";
|
||||
import { parseWorkspaceYaml } from "../src/workspaces/schema.js";
|
||||
|
||||
@@ -58,6 +63,12 @@ const paths: RuntimePaths = {
|
||||
artifacts: "/data/workspaces/psd-clinical/artifacts",
|
||||
indexes: "/data/workspaces/psd-clinical/indexes",
|
||||
};
|
||||
const semanticRuntime: SemanticRuntimeConfig = {
|
||||
internalQdrantUrl: "http://qdrant:6333",
|
||||
internalEmbeddingUrl: "http://embedding:11434",
|
||||
internalEmbeddingModel: "qwen3-embedding:0.6b",
|
||||
internalEmbeddingDimensions: 1024,
|
||||
};
|
||||
const legacyWorkspace = parseWorkspaceYaml(`workspace:
|
||||
schema_version: 1
|
||||
id: psd-clinical
|
||||
@@ -174,8 +185,56 @@ test("refuses to render a v1 descriptor until an explicit migration creates v2",
|
||||
|
||||
test("fails closed for v3 runtime rendering and session support", () => {
|
||||
expect(supportsSessionRuntime(directBindings)).toBe(true);
|
||||
expect(() => renderRuntimeConfig(workspaceV3, directBindings, paths))
|
||||
.toThrow(/unsupported|schema version 3|qdrant|ollama_internal/i);
|
||||
const rendered = parse(renderRuntimeConfig(workspaceV3, directBindings, paths, undefined, {}, semanticRuntime));
|
||||
|
||||
expect(rendered.resources).toMatchObject({
|
||||
vector: {
|
||||
engine: "qdrant",
|
||||
base_url: "http://qdrant:6333",
|
||||
collection: "psd-clinical",
|
||||
},
|
||||
});
|
||||
expect(rendered.embeddings).toMatchObject({
|
||||
provider: "ollama_internal",
|
||||
base_url: "http://embedding:11434",
|
||||
model: "qwen3-embedding:0.6b",
|
||||
dimensions: 1024,
|
||||
});
|
||||
});
|
||||
|
||||
test("schema v3 runtime rendering never exposes external semantic endpoints from bindings", () => {
|
||||
const rendered = parse(renderRuntimeConfig(workspaceV3, {
|
||||
...directBindings,
|
||||
vector: {
|
||||
transport: "rest_api",
|
||||
missing: [],
|
||||
values: {
|
||||
THT_WS_PSD_CLINICAL_VECTOR_BASE_URL: "https://vector.example.test",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE: "/run/secrets/vector-api-key",
|
||||
},
|
||||
},
|
||||
embedding: {
|
||||
transport: "rest_api",
|
||||
missing: [],
|
||||
values: {
|
||||
THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL: "https://embedding.example.test",
|
||||
},
|
||||
},
|
||||
}, paths, undefined, {}, semanticRuntime));
|
||||
|
||||
expect(rendered.resources.vector).toMatchObject({
|
||||
engine: "qdrant",
|
||||
base_url: "http://qdrant:6333",
|
||||
collection: "psd-clinical",
|
||||
});
|
||||
expect(rendered.embeddings).toMatchObject({
|
||||
provider: "ollama_internal",
|
||||
base_url: "http://embedding:11434",
|
||||
model: "qwen3-embedding:0.6b",
|
||||
dimensions: 1024,
|
||||
});
|
||||
expect(JSON.stringify(rendered)).not.toContain("vector.example.test");
|
||||
expect(JSON.stringify(rendered)).not.toContain("embedding.example.test");
|
||||
});
|
||||
|
||||
test("omits direct TLS fields when binding validation did not retain a file path", () => {
|
||||
|
||||
@@ -222,9 +222,35 @@ test("never treats a vector reader credential as the optional writer binding", (
|
||||
|
||||
test("fails closed for v3 external semantic bindings", () => {
|
||||
expect(() => resolveBinding(workspaceV3, "VECTOR", {}, ["/run/secrets"]))
|
||||
.toThrow(/unsupported|schema version 3|semantic/i);
|
||||
.not.toThrow();
|
||||
expect(() => resolveBinding(workspaceV3, "EMBEDDING", {}, ["/run/secrets"]))
|
||||
.toThrow(/unsupported|schema version 3|semantic/i);
|
||||
expect(() => resolveRuntimeBindings(workspaceV3, {}, ["/run/secrets"]))
|
||||
.toThrow(/unsupported|schema version 3|semantic/i);
|
||||
.not.toThrow();
|
||||
expect(() => resolveRuntimeBindings(workspaceV3, {
|
||||
THT_WS_PSD_CLINICAL_VECTOR_TRANSPORT: "rest_api",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_BASE_URL: "https://vector.example.test",
|
||||
THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL: "https://embedding.example.test",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE: "/run/secrets/vector-api-key",
|
||||
}, ["/run/secrets"])).not.toThrow();
|
||||
});
|
||||
|
||||
test("schema v3 ignores external semantic binding variables and reports only DWH requirements", () => {
|
||||
const password = secretPath("dwh-password");
|
||||
const bindings = resolveRuntimeBindings(workspaceV3, {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
||||
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
|
||||
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
|
||||
THT_WS_PSD_CLINICAL_DWH_USER: "reader",
|
||||
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: password.path,
|
||||
THT_WS_PSD_CLINICAL_VECTOR_TRANSPORT: "rest_api",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_BASE_URL: "https://vector.example.test",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE: "/run/secrets/vector-api-key",
|
||||
THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL: "https://embedding.example.test",
|
||||
THT_WS_PSD_CLINICAL_EMBEDDING_API_KEY_FILE: "/run/secrets/embedding-api-key",
|
||||
}, [password.root]);
|
||||
|
||||
expect(bindings.dwh.missing).toEqual([]);
|
||||
expect(bindings.vector.missing).toEqual([]);
|
||||
expect(bindings.embedding.missing).toEqual([]);
|
||||
expect(bindings.vector.values).toEqual({});
|
||||
expect(bindings.embedding.values).toEqual({});
|
||||
});
|
||||
|
||||
@@ -97,6 +97,20 @@ test("renders English UI headings and workspace-language Italian prose", () => {
|
||||
expect(docs.envExample).toContain("THT_WS_PSD_CLINICAL_VECTOR_TRANSPORT=");
|
||||
});
|
||||
|
||||
test("schema v3 installation contracts expose only DWH bindings and no semantic variables", () => {
|
||||
const contract = buildInstallationContract(workspaceV3);
|
||||
const names = contract.variables.map((variable) => variable.name);
|
||||
const docs = renderWorkspaceDocs(workspaceV3);
|
||||
|
||||
expect(contract.variables.every((variable) => variable.role === "DWH")).toBe(true);
|
||||
expect(names).toContain("THT_WS_PSD_CLINICAL_DWH_TRANSPORT");
|
||||
expect(names.some((name) => /_VECTOR_|_EMBEDDING_/.test(name))).toBe(false);
|
||||
expect(docs.envExample).not.toContain("_VECTOR_");
|
||||
expect(docs.envExample).not.toContain("_EMBEDDING_");
|
||||
expect(docs.markdown).not.toContain("Vector store");
|
||||
expect(docs.markdown).not.toContain("Embedding service");
|
||||
});
|
||||
|
||||
test("renders the vector store identity and creates writer credentials only when declared", () => {
|
||||
const writerWorkspace = parseWorkspaceYaml(`workspace:
|
||||
schema_version: 2
|
||||
|
||||
Reference in New Issue
Block a user