feat: render private semantic service endpoints

This commit is contained in:
2026-08-08 17:17:02 +02:00
parent f7b9f3276b
commit bc8afe0205
10 changed files with 372 additions and 19 deletions
+30 -4
View File
@@ -222,9 +222,35 @@ test("never treats a vector reader credential as the optional writer binding", (
test("fails closed for v3 external semantic bindings", () => {
expect(() => resolveBinding(workspaceV3, "VECTOR", {}, ["/run/secrets"]))
.toThrow(/unsupported|schema version 3|semantic/i);
.not.toThrow();
expect(() => resolveBinding(workspaceV3, "EMBEDDING", {}, ["/run/secrets"]))
.toThrow(/unsupported|schema version 3|semantic/i);
expect(() => resolveRuntimeBindings(workspaceV3, {}, ["/run/secrets"]))
.toThrow(/unsupported|schema version 3|semantic/i);
.not.toThrow();
expect(() => resolveRuntimeBindings(workspaceV3, {
THT_WS_PSD_CLINICAL_VECTOR_TRANSPORT: "rest_api",
THT_WS_PSD_CLINICAL_VECTOR_BASE_URL: "https://vector.example.test",
THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL: "https://embedding.example.test",
THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE: "/run/secrets/vector-api-key",
}, ["/run/secrets"])).not.toThrow();
});
test("schema v3 ignores external semantic binding variables and reports only DWH requirements", () => {
const password = secretPath("dwh-password");
const bindings = resolveRuntimeBindings(workspaceV3, {
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
THT_WS_PSD_CLINICAL_DWH_USER: "reader",
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: password.path,
THT_WS_PSD_CLINICAL_VECTOR_TRANSPORT: "rest_api",
THT_WS_PSD_CLINICAL_VECTOR_BASE_URL: "https://vector.example.test",
THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE: "/run/secrets/vector-api-key",
THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL: "https://embedding.example.test",
THT_WS_PSD_CLINICAL_EMBEDDING_API_KEY_FILE: "/run/secrets/embedding-api-key",
}, [password.root]);
expect(bindings.dwh.missing).toEqual([]);
expect(bindings.vector.missing).toEqual([]);
expect(bindings.embedding.missing).toEqual([]);
expect(bindings.vector.values).toEqual({});
expect(bindings.embedding.values).toEqual({});
});