fix: render registry workspaces for harness
This commit is contained in:
@@ -23,12 +23,12 @@ const expected = {
|
||||
THT_WS_TASK13_SMOKE_DWH_HOST: "dwh.task13.invalid",
|
||||
THT_WS_TASK13_SMOKE_DWH_PORT: "5432",
|
||||
THT_WS_TASK13_SMOKE_DWH_USER: "task13_reader",
|
||||
THT_WS_TASK13_SMOKE_DWH_PASSWORD_FILE: "/run/secrets/thothii.secrets",
|
||||
THT_WS_TASK13_SMOKE_DWH_PASSWORD_FILE: "/run/secrets/task13-runtime-password",
|
||||
THT_WS_TASK13_SMOKE_VECTOR_TRANSPORT: "pgvector_direct",
|
||||
THT_WS_TASK13_SMOKE_VECTOR_HOST: "vector.task13.invalid",
|
||||
THT_WS_TASK13_SMOKE_VECTOR_PORT: "5432",
|
||||
THT_WS_TASK13_SMOKE_VECTOR_USER: "task13_vector_reader",
|
||||
THT_WS_TASK13_SMOKE_VECTOR_PASSWORD_FILE: "/run/secrets/thothii.secrets",
|
||||
THT_WS_TASK13_SMOKE_VECTOR_PASSWORD_FILE: "/run/secrets/task13-runtime-password",
|
||||
THT_WS_TASK13_SMOKE_EMBEDDING_BASE_URL: profile === "local"
|
||||
? `http://${config.name}-llm:9000`
|
||||
: "https://embedding.task13.invalid",
|
||||
@@ -55,6 +55,14 @@ if (coreBundle.length !== 1) throw new Error("core lacks exactly one runtime sec
|
||||
if ((frontend.secrets || []).length !== 0) throw new Error("frontend received a runtime secret");
|
||||
|
||||
const mounts = core.volumes || [];
|
||||
const runtimePasswordMounts = mounts.filter(
|
||||
(mount: any) => mount.target === "/run/secrets/task13-runtime-password",
|
||||
);
|
||||
if (runtimePasswordMounts.length !== 1 || runtimePasswordMounts[0].type !== "bind"
|
||||
|| !runtimePasswordMounts[0].read_only || !statSync(runtimePasswordMounts[0].source).isFile()) {
|
||||
throw new Error("runtime fixture lacks one readable, read-only password-file bind");
|
||||
}
|
||||
accessSync(runtimePasswordMounts[0].source, constants.R_OK);
|
||||
for (const target of [
|
||||
"/home/thoth/.pi/agent/auth.json",
|
||||
"/home/thoth/.pi/agent/models.json",
|
||||
@@ -73,9 +81,9 @@ for (const target of [
|
||||
}
|
||||
|
||||
const resolverEnvironment = { ...core.environment };
|
||||
resolverEnvironment.THT_WS_TASK13_SMOKE_DWH_PASSWORD_FILE = bundleSource;
|
||||
resolverEnvironment.THT_WS_TASK13_SMOKE_VECTOR_PASSWORD_FILE = bundleSource;
|
||||
const bindings = resolveRuntimeBindings(workspace, resolverEnvironment, [dirname(bundleSource)]);
|
||||
resolverEnvironment.THT_WS_TASK13_SMOKE_DWH_PASSWORD_FILE = runtimePasswordMounts[0].source;
|
||||
resolverEnvironment.THT_WS_TASK13_SMOKE_VECTOR_PASSWORD_FILE = runtimePasswordMounts[0].source;
|
||||
const bindings = resolveRuntimeBindings(workspace, resolverEnvironment, [dirname(runtimePasswordMounts[0].source)]);
|
||||
for (const [role, binding] of Object.entries(bindings)) {
|
||||
if ((binding as any).missing.length !== 0) {
|
||||
throw new Error(`workspace resolver reports missing ${role} bindings: ${(binding as any).missing.join(",")}`);
|
||||
@@ -88,18 +96,20 @@ const runtime = parse(renderRuntimeConfig(workspace, bindings, {
|
||||
}));
|
||||
if (runtime.database.host !== expected.THT_WS_TASK13_SMOKE_DWH_HOST
|
||||
|| runtime.database.user !== expected.THT_WS_TASK13_SMOKE_DWH_USER
|
||||
|| runtime.database.password_file !== bundleSource) {
|
||||
|| runtime.database.password_file !== runtimePasswordMounts[0].source) {
|
||||
throw new Error("workspace resolver produced the wrong DWH runtime");
|
||||
}
|
||||
if (runtime.vector_db.host !== expected.THT_WS_TASK13_SMOKE_VECTOR_HOST
|
||||
|| runtime.vector_db.user !== expected.THT_WS_TASK13_SMOKE_VECTOR_USER
|
||||
|| runtime.vector_db.password_file !== bundleSource) {
|
||||
|| runtime.vector_db.password_file !== runtimePasswordMounts[0].source) {
|
||||
throw new Error("workspace resolver produced the wrong vector runtime");
|
||||
}
|
||||
if (runtime.embeddings.base_url !== expected.THT_WS_TASK13_SMOKE_EMBEDDING_BASE_URL) {
|
||||
throw new Error("workspace resolver produced the wrong embedding runtime");
|
||||
}
|
||||
const secret = readFileSync(bundleSource, "utf8").trim();
|
||||
if (JSON.stringify(config).includes(secret) || JSON.stringify(runtime).includes(secret)) {
|
||||
throw new Error("fixture render or resolver output leaked secret content");
|
||||
}
|
||||
const runtimePassword = readFileSync(runtimePasswordMounts[0].source, "utf8");
|
||||
if (JSON.stringify(config).includes(secret)) throw new Error("fixture render leaked application bundle content");
|
||||
if (JSON.stringify(runtime).includes(secret)) throw new Error("runtime render leaked application bundle content");
|
||||
if (JSON.stringify(config).includes(runtimePassword)) throw new Error("fixture render leaked runtime password content");
|
||||
if (JSON.stringify(runtime).includes(runtimePassword)) throw new Error("runtime render leaked runtime password content");
|
||||
|
||||
Reference in New Issue
Block a user