refactor: remove legacy workspace runtime branches
This commit is contained in:
@@ -1,36 +1,14 @@
|
||||
import { chmodSync, mkdirSync, mkdtempSync, realpathSync, rmSync, symlinkSync, writeFileSync } from "node:fs";
|
||||
import {
|
||||
chmodSync, mkdirSync, mkdtempSync, realpathSync, rmSync, symlinkSync, writeFileSync,
|
||||
} from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { afterEach, expect, test } from "vitest";
|
||||
import { resolveBinding, resolveEvidenceBinding, resolveRuntimeBindings, supportsSessionRuntime } from "../src/workspaces/bindings.js";
|
||||
import {
|
||||
resolveBinding, resolveEvidenceBinding, resolveRuntimeBindings, supportsSessionRuntime,
|
||||
} from "../src/workspaces/bindings.js";
|
||||
import { parseWorkspaceYaml } from "../src/workspaces/schema.js";
|
||||
|
||||
const workspace = parseWorkspaceYaml(`workspace:
|
||||
schema_version: 2
|
||||
id: psd-clinical
|
||||
name: Policlinico San Donato
|
||||
language: it
|
||||
dwh:
|
||||
engine: postgres
|
||||
database: postgres
|
||||
schema: datawarehouse
|
||||
supported_transports: [postgres_direct, rest_api, ssh_tunnel]
|
||||
semantic_index:
|
||||
vector_store:
|
||||
engine: pgvector
|
||||
database: postgres
|
||||
schema: vectors
|
||||
collection: clinical_documents
|
||||
dimensions: 768
|
||||
distance: cosine
|
||||
supported_transports: [pgvector_direct, rest_api, ssh_tunnel]
|
||||
embedding:
|
||||
provider: ollama_compatible
|
||||
model: nomic-embed-text-v2-moe
|
||||
dimensions: 768
|
||||
llm_policy:
|
||||
allowed: [zai/glm-5.2]
|
||||
`);
|
||||
const workspaceV3 = parseWorkspaceYaml(`workspace:
|
||||
schema_version: 3
|
||||
id: psd-clinical
|
||||
@@ -40,19 +18,11 @@ dwh:
|
||||
engine: postgres
|
||||
database: postgres
|
||||
schema: datawarehouse
|
||||
supported_transports: [postgres_direct, rest_api]
|
||||
supported_transports: [postgres_direct, rest_api, ssh_tunnel]
|
||||
semantic_index:
|
||||
vector_store:
|
||||
engine: qdrant
|
||||
collection: psd-clinical
|
||||
dimensions: 1024
|
||||
distance: cosine
|
||||
embedding:
|
||||
provider: ollama_internal
|
||||
model: qwen3-embedding:0.6b
|
||||
dimensions: 1024
|
||||
llm_policy:
|
||||
allowed: [zai/glm-5.2]
|
||||
vector_store: { engine: qdrant, collection: psd-clinical, dimensions: 1024, distance: cosine }
|
||||
embedding: { provider: ollama_internal, model: qwen3-embedding:0.6b, dimensions: 1024 }
|
||||
llm_policy: { allowed: [zai/glm-5.2] }
|
||||
`);
|
||||
const temporaryRoots: string[] = [];
|
||||
|
||||
@@ -70,80 +40,13 @@ function secretPath(name: string): { root: string; path: string } {
|
||||
return { root: secrets, path };
|
||||
}
|
||||
|
||||
test("marks a portable workspace non-activatable when its local REST key file is absent", () => {
|
||||
const result = resolveBinding(workspace, "DWH", {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api",
|
||||
THT_WS_PSD_CLINICAL_DWH_BASE_URL: "https://dwh.example.test",
|
||||
}, ["/run/secrets"]);
|
||||
|
||||
expect(result.missing).toContain("THT_WS_PSD_CLINICAL_DWH_API_KEY_FILE");
|
||||
});
|
||||
|
||||
test("does not require a REST secret file when its declared diagnostic uses auth none", () => {
|
||||
const unauthenticatedWorkspace = parseWorkspaceYaml(`workspace:
|
||||
schema_version: 2
|
||||
id: psd-clinical
|
||||
name: Policlinico San Donato
|
||||
language: it
|
||||
dwh:
|
||||
engine: postgres
|
||||
database: postgres
|
||||
schema: datawarehouse
|
||||
supported_transports: [rest_api]
|
||||
semantic_index:
|
||||
vector_store:
|
||||
engine: pgvector
|
||||
database: postgres
|
||||
schema: vectors
|
||||
collection: clinical_documents
|
||||
dimensions: 768
|
||||
distance: cosine
|
||||
supported_transports: [rest_api]
|
||||
embedding:
|
||||
provider: ollama_compatible
|
||||
model: nomic-embed-text-v2-moe
|
||||
dimensions: 768
|
||||
diagnostics:
|
||||
dwh_rest:
|
||||
method: POST
|
||||
path: /rpc/ping
|
||||
auth: none
|
||||
response: { database: database, schema: schema }
|
||||
vector_rest:
|
||||
metadata:
|
||||
method: GET
|
||||
path: /vector/metadata
|
||||
auth: none
|
||||
response: { collection: collection, dimensions: dimensions, distance: distance }
|
||||
embedding:
|
||||
method: GET
|
||||
path: /models
|
||||
auth: none
|
||||
response: { model: model, dimensions: dimensions }
|
||||
llm_policy:
|
||||
allowed: [zai/glm-5.2]
|
||||
`);
|
||||
|
||||
const bindings = resolveRuntimeBindings(unauthenticatedWorkspace, {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api",
|
||||
THT_WS_PSD_CLINICAL_DWH_BASE_URL: "https://dwh.example.test",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_TRANSPORT: "rest_api",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_BASE_URL: "https://vector.example.test",
|
||||
THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL: "https://embedding.example.test",
|
||||
}, ["/run/secrets"]);
|
||||
|
||||
expect(bindings.dwh.missing).toEqual([]);
|
||||
expect(bindings.vector.missing).toEqual([]);
|
||||
expect(bindings.embedding.missing).toEqual([]);
|
||||
});
|
||||
|
||||
test("resolves direct bindings from the stable workspace namespace", () => {
|
||||
test("resolves schema-v3 direct DWH bindings from the stable namespace", () => {
|
||||
const password = secretPath("dwh-password");
|
||||
const result = resolveBinding(workspace, "DWH", {
|
||||
const result = resolveBinding(workspaceV3, "DWH", {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
||||
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
|
||||
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
|
||||
THT_WS_PSD_CLINICAL_DWH_USER: "thoth_reader",
|
||||
THT_WS_PSD_CLINICAL_DWH_USER: "reader",
|
||||
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: password.path,
|
||||
}, [password.root]);
|
||||
|
||||
@@ -158,82 +61,72 @@ test("resolves direct bindings from the stable workspace namespace", () => {
|
||||
});
|
||||
});
|
||||
|
||||
test("reports only a FILE variable name when a secret path is outside the configured roots", () => {
|
||||
test("requires schema-v3 REST credentials unless the DWH diagnostic declares auth none", () => {
|
||||
expect(resolveBinding(workspaceV3, "DWH", {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api",
|
||||
THT_WS_PSD_CLINICAL_DWH_BASE_URL: "https://dwh.example.test",
|
||||
}, []).missing).toContain("THT_WS_PSD_CLINICAL_DWH_API_KEY_FILE");
|
||||
|
||||
const noAuth = parseWorkspaceYaml(`workspace:
|
||||
schema_version: 3
|
||||
id: psd-clinical
|
||||
name: No auth
|
||||
language: en
|
||||
dwh:
|
||||
engine: postgres
|
||||
database: postgres
|
||||
schema: public
|
||||
supported_transports: [rest_api]
|
||||
semantic_index:
|
||||
vector_store: { engine: qdrant, collection: psd-clinical, dimensions: 1024, distance: cosine }
|
||||
embedding: { provider: ollama_internal, model: qwen3-embedding:0.6b, dimensions: 1024 }
|
||||
diagnostics:
|
||||
dwh_rest:
|
||||
method: GET
|
||||
path: /health
|
||||
auth: none
|
||||
response: { database: database, schema: schema }
|
||||
llm_policy: { allowed: [zai/glm-5.2] }
|
||||
`);
|
||||
expect(resolveBinding(noAuth, "DWH", {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api",
|
||||
THT_WS_PSD_CLINICAL_DWH_BASE_URL: "https://dwh.example.test",
|
||||
}, []).missing).toEqual([]);
|
||||
});
|
||||
|
||||
test("rejects unsupported transports and secret paths outside configured roots", () => {
|
||||
const outside = secretPath("outside-password");
|
||||
const allowed = secretPath("allowed-password");
|
||||
const result = resolveBinding(workspace, "DWH", {
|
||||
const directOnly = parseWorkspaceYaml(`workspace:
|
||||
schema_version: 3
|
||||
id: psd-clinical
|
||||
name: Direct only
|
||||
language: en
|
||||
dwh:
|
||||
engine: postgres
|
||||
database: postgres
|
||||
schema: public
|
||||
supported_transports: [postgres_direct]
|
||||
semantic_index:
|
||||
vector_store: { engine: qdrant, collection: psd-clinical, dimensions: 1024, distance: cosine }
|
||||
embedding: { provider: ollama_internal, model: qwen3-embedding:0.6b, dimensions: 1024 }
|
||||
llm_policy: { allowed: [zai/glm-5.2] }
|
||||
`);
|
||||
expect(resolveBinding(directOnly, "DWH", {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api",
|
||||
}, []).missing).toContain("THT_WS_PSD_CLINICAL_DWH_TRANSPORT");
|
||||
const result = resolveBinding(workspaceV3, "DWH", {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
||||
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
|
||||
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
|
||||
THT_WS_PSD_CLINICAL_DWH_USER: "thoth_reader",
|
||||
THT_WS_PSD_CLINICAL_DWH_USER: "reader",
|
||||
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: outside.path,
|
||||
}, [allowed.root]);
|
||||
|
||||
expect(result.missing).toEqual(["THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE"]);
|
||||
expect(result.missing.join("\n")).not.toContain(outside.path);
|
||||
expect(result.missing).toContain("THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE");
|
||||
expect(JSON.stringify(result)).not.toContain(outside.path);
|
||||
});
|
||||
|
||||
test("reports an invalid optional secret file instead of silently dropping it", () => {
|
||||
const password = secretPath("dwh-password");
|
||||
const result = resolveBinding(workspace, "DWH", {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
||||
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
|
||||
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
|
||||
THT_WS_PSD_CLINICAL_DWH_USER: "thoth_reader",
|
||||
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: password.path,
|
||||
THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE: "relative-ca.pem",
|
||||
}, [password.root]);
|
||||
|
||||
expect(result.missing).toContain("THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE");
|
||||
expect(result.values).not.toHaveProperty("THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE");
|
||||
});
|
||||
|
||||
test("rejects a selected transport that the canonical workspace does not support", () => {
|
||||
const directOnly = {
|
||||
...workspace,
|
||||
dwh: { ...workspace.dwh, supported_transports: ["postgres_direct"] },
|
||||
};
|
||||
const result = resolveBinding(directOnly, "DWH", {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "rest_api",
|
||||
}, ["/run/secrets"]);
|
||||
|
||||
expect(result).toMatchObject({
|
||||
transport: "rest_api",
|
||||
missing: ["THT_WS_PSD_CLINICAL_DWH_TRANSPORT"],
|
||||
});
|
||||
});
|
||||
|
||||
test("never treats a vector reader credential as the optional writer binding", () => {
|
||||
const readerKey = secretPath("vector-reader-key");
|
||||
const writerWorkspace = {
|
||||
...workspace,
|
||||
semantic_index: { ...workspace.semantic_index, vector_writer: {} },
|
||||
};
|
||||
const resolveWriter = () => resolveBinding(writerWorkspace, "VECTOR_WRITER" as never, {
|
||||
THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE: readerKey.path,
|
||||
}, [readerKey.root]);
|
||||
|
||||
expect(resolveWriter).not.toThrow();
|
||||
expect(resolveWriter()).toMatchObject({
|
||||
missing: ["THT_WS_PSD_CLINICAL_VECTOR_WRITER_API_KEY_FILE"],
|
||||
values: {},
|
||||
});
|
||||
});
|
||||
|
||||
test("fails closed for v3 external semantic bindings", () => {
|
||||
expect(() => resolveBinding(workspaceV3, "VECTOR", {}, ["/run/secrets"]))
|
||||
.not.toThrow();
|
||||
expect(() => resolveBinding(workspaceV3, "EMBEDDING", {}, ["/run/secrets"]))
|
||||
.not.toThrow();
|
||||
expect(() => resolveRuntimeBindings(workspaceV3, {
|
||||
THT_WS_PSD_CLINICAL_VECTOR_TRANSPORT: "rest_api",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_BASE_URL: "https://vector.example.test",
|
||||
THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL: "https://embedding.example.test",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE: "/run/secrets/vector-api-key",
|
||||
}, ["/run/secrets"])).not.toThrow();
|
||||
});
|
||||
|
||||
test("schema v3 ignores external semantic binding variables and reports only DWH requirements", () => {
|
||||
test("runtime bindings contain only DWH and Evidence roles", () => {
|
||||
const password = secretPath("dwh-password");
|
||||
const bindings = resolveRuntimeBindings(workspaceV3, {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
||||
@@ -241,21 +134,13 @@ test("schema v3 ignores external semantic binding variables and reports only DWH
|
||||
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
|
||||
THT_WS_PSD_CLINICAL_DWH_USER: "reader",
|
||||
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: password.path,
|
||||
THT_WS_PSD_CLINICAL_VECTOR_TRANSPORT: "rest_api",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_BASE_URL: "https://vector.example.test",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE: "/run/secrets/vector-api-key",
|
||||
THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL: "https://embedding.example.test",
|
||||
THT_WS_PSD_CLINICAL_EMBEDDING_API_KEY_FILE: "/run/secrets/embedding-api-key",
|
||||
THT_WS_PSD_CLINICAL_VECTOR_BASE_URL: "https://ignored.example.test",
|
||||
}, [password.root]);
|
||||
|
||||
expect(Object.keys(bindings)).toEqual(["dwh", "evidence"]);
|
||||
expect(bindings.dwh.missing).toEqual([]);
|
||||
expect(bindings.vector.missing).toEqual([]);
|
||||
expect(bindings.embedding.missing).toEqual([]);
|
||||
expect(bindings.vector.values).toEqual({});
|
||||
expect(bindings.embedding.values).toEqual({});
|
||||
expect(supportsSessionRuntime(bindings)).toBe(true);
|
||||
});
|
||||
|
||||
|
||||
function withEvidence(source: Record<string, unknown>) {
|
||||
return parseWorkspaceYaml(`workspace:
|
||||
schema_version: 3
|
||||
|
||||
Reference in New Issue
Block a user