feat: complete catalog-driven preprocessing
Publish documentation / publish (push) Successful in 2m12s
Publish documentation / publish (push) Successful in 2m12s
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
import { execFile } from "node:child_process";
|
||||
import {
|
||||
chmodSync, existsSync, mkdtempSync, mkdirSync, readFileSync, readdirSync, realpathSync, rmSync,
|
||||
chmodSync, existsSync, mkdtempSync, mkdirSync, readFileSync, readdirSync, rmSync,
|
||||
writeFileSync,
|
||||
} from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
@@ -25,11 +25,6 @@ const canonicalWorkspace = `workspace:
|
||||
id: psd-clinical
|
||||
name: Runtime handoff
|
||||
language: en
|
||||
dwh:
|
||||
engine: postgres
|
||||
database: analytics
|
||||
schema: mart
|
||||
supported_transports: [postgres_direct]
|
||||
`;
|
||||
|
||||
const filesystemWorkspace = `${canonicalWorkspace}evidence:
|
||||
@@ -106,6 +101,38 @@ async function fixture(workspaceSource = filesystemWorkspace) {
|
||||
const registry = new WorkspaceRegistry(registryConfig);
|
||||
await registry.bootstrap();
|
||||
const revision = (await registry.list())[0];
|
||||
const workspaceSecretStore = new WorkspaceSecretStore({
|
||||
root: join(root, "workspace-secrets"),
|
||||
runtimeRoot: join(root, "workspace-secret-runtime"),
|
||||
installationId: "test",
|
||||
});
|
||||
workspaceSecretStore.putMany("psd-clinical", {
|
||||
"catalog.dwh.password": "dwh-password-value",
|
||||
"evidence.signed_urls": secretContents["evidence-signed-urls.json"],
|
||||
"evidence.access_key": secretContents["evidence-access"],
|
||||
"evidence.secret_key": secretContents["evidence-secret"],
|
||||
"evidence.session_token": secretContents["evidence-token"],
|
||||
});
|
||||
const catalogDatabase = {
|
||||
id: "database-1",
|
||||
workspaceId: "psd-clinical",
|
||||
engine: "postgres" as const,
|
||||
databaseName: "analytics",
|
||||
schema: "mart",
|
||||
binding: {
|
||||
transport: "postgres_direct" as const,
|
||||
host: "dwh.invalid",
|
||||
port: 5432,
|
||||
username: "reader",
|
||||
},
|
||||
version: 1,
|
||||
createdAt: "2026-01-01T00:00:00Z",
|
||||
updatedAt: "2026-01-01T00:00:00Z",
|
||||
connectionStatus: "reachable" as const,
|
||||
metadataContentRevision: 1,
|
||||
preprocessingStatus: "failed" as const,
|
||||
};
|
||||
const catalogRepository = { getByWorkspace: async () => catalogDatabase } as any;
|
||||
const environment = {
|
||||
THT_WS_PSD_CLINICAL_DWH_TRANSPORT: "postgres_direct",
|
||||
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.invalid",
|
||||
@@ -119,7 +146,10 @@ async function fixture(workspaceSource = filesystemWorkspace) {
|
||||
};
|
||||
for (const [name, value] of Object.entries(environment)) vi.stubEnv(name, value);
|
||||
vi.stubEnv("THT_HOME", join(root, "home"));
|
||||
return { root, source, dataRoot, secretRoot, registry, registryConfig, revision };
|
||||
return {
|
||||
root, source, dataRoot, secretRoot, registry, registryConfig, revision,
|
||||
workspaceSecretStore, catalogDatabase, catalogRepository,
|
||||
};
|
||||
}
|
||||
|
||||
function runnerFor(f: Awaited<ReturnType<typeof fixture>>): ThtRunner {
|
||||
@@ -130,6 +160,8 @@ function runnerFor(f: Awaited<ReturnType<typeof fixture>>): ThtRunner {
|
||||
dataRoot: f.dataRoot,
|
||||
runtimeSnapshotRoot: join(f.registryConfig.root, "snapshots", "runtime"),
|
||||
secretRoots: f.registryConfig.secretRoots,
|
||||
workspaceSecretStore: f.workspaceSecretStore,
|
||||
catalogRepository: f.catalogRepository,
|
||||
} as any);
|
||||
}
|
||||
|
||||
@@ -165,7 +197,7 @@ test("ThtRunner uses a vault secret only for the lifetime of its runtime lease",
|
||||
runtimeRoot,
|
||||
installationId: "test",
|
||||
});
|
||||
secretStore.put("psd-clinical", "dwh.password", "vault-runtime-password");
|
||||
secretStore.put("psd-clinical", "catalog.dwh.password", "vault-runtime-password");
|
||||
const runner = new ThtRunner({
|
||||
thtBin,
|
||||
harnessDir,
|
||||
@@ -174,9 +206,10 @@ test("ThtRunner uses a vault secret only for the lifetime of its runtime lease",
|
||||
runtimeSnapshotRoot: join(f.registryConfig.root, "snapshots", "runtime"),
|
||||
secretRoots: f.registryConfig.secretRoots,
|
||||
workspaceSecretStore: secretStore,
|
||||
catalogRepository: f.catalogRepository,
|
||||
} as any);
|
||||
|
||||
const lease = runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
|
||||
const lease = await runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
|
||||
const rendered = parse(readFileSync(lease.path, "utf8")) as {
|
||||
database: { password_file: string };
|
||||
};
|
||||
@@ -185,30 +218,11 @@ test("ThtRunner uses a vault secret only for the lifetime of its runtime lease",
|
||||
expect(existsSync(rendered.database.password_file)).toBe(false);
|
||||
});
|
||||
|
||||
test("ThtRunner binds and cleans the effective relationship snapshot with its runtime lease", async () => {
|
||||
const f = await fixture();
|
||||
const runner = runnerFor(f);
|
||||
const relationships = JSON.stringify({
|
||||
schemaVersion: 1,
|
||||
workspaceId: "psd-clinical",
|
||||
relationships: [],
|
||||
});
|
||||
|
||||
const lease = runner.acquireWorkspaceRuntime(f.revision.snapshotPath, relationships);
|
||||
const rendered = parse(readFileSync(lease.path, "utf8")) as {
|
||||
paths: { effective_relationships: string };
|
||||
};
|
||||
|
||||
expect(readFileSync(rendered.paths.effective_relationships, "utf8")).toBe(relationships);
|
||||
lease.release();
|
||||
expect(existsSync(rendered.paths.effective_relationships)).toBe(false);
|
||||
});
|
||||
|
||||
test("separate runtime leases hand off byte-identical revision Evidence configs accepted by tht", async () => {
|
||||
const f = await fixture();
|
||||
const runner = runnerFor(f);
|
||||
const first = runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
|
||||
const second = runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
|
||||
const first = await runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
|
||||
const second = await runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
|
||||
const expectedRoot = join(
|
||||
f.registryConfig.root,
|
||||
"snapshots",
|
||||
@@ -263,7 +277,7 @@ test("separate runtime leases hand off byte-identical revision Evidence configs
|
||||
test("real Evidence-content-only commit changes runtime identity and root with identical descriptor YAML", async () => {
|
||||
const f = await fixture();
|
||||
const runner = runnerFor(f);
|
||||
const first = runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
|
||||
const first = await runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
|
||||
const descriptorBefore = readFileSync(f.revision.snapshotPath, "utf8");
|
||||
writeFileSync(
|
||||
join(f.source, "psd-clinical", "evidence", "guide.md"),
|
||||
@@ -274,7 +288,7 @@ test("real Evidence-content-only commit changes runtime identity and root with i
|
||||
await git(f.source, ["push", "origin", "main"]);
|
||||
await f.registry.pull();
|
||||
const current = (await f.registry.list())[0];
|
||||
const second = runner.acquireWorkspaceRuntime(current.snapshotPath);
|
||||
const second = await runner.acquireWorkspaceRuntime(current.snapshotPath);
|
||||
|
||||
try {
|
||||
expect(current.commit).not.toBe(f.revision.commit);
|
||||
@@ -317,13 +331,13 @@ test("signed HTTP Evidence resolves its file binding and config check never capt
|
||||
max_cache_bytes: 67890
|
||||
`));
|
||||
const runner = runnerFor(f);
|
||||
const lease = runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
|
||||
const lease = await runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
|
||||
try {
|
||||
const yaml = readFileSync(lease.path, "utf8");
|
||||
expect(parse(yaml).evidence.sources).toEqual([{
|
||||
type: "http",
|
||||
provenance_urls: ["https://evidence.example.test/guide.md"],
|
||||
signed_urls_file: realpathSync(join(f.secretRoot, "evidence-signed-urls.json")),
|
||||
signed_urls_file: expect.stringContaining("/workspace-secret-runtime/"),
|
||||
connect_timeout: 1.25,
|
||||
read_timeout: 30.001,
|
||||
max_bytes: 12_345,
|
||||
@@ -343,7 +357,7 @@ test("signed HTTP Evidence resolves its file binding and config check never capt
|
||||
}
|
||||
});
|
||||
|
||||
test("static S3 Evidence resolves only configured secret-root file paths", async () => {
|
||||
test("static S3 Evidence resolves only ephemeral vault materializations", async () => {
|
||||
const f = await fixture(evidenceWorkspace(` type: s3
|
||||
uri: s3://clinical-evidence/published/
|
||||
endpoint_url: https://s3.example.test/
|
||||
@@ -361,7 +375,7 @@ test("static S3 Evidence resolves only configured secret-root file paths", async
|
||||
retain_published_generations: 7
|
||||
`));
|
||||
const runner = runnerFor(f);
|
||||
const lease = runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
|
||||
const lease = await runner.acquireWorkspaceRuntime(f.revision.snapshotPath);
|
||||
try {
|
||||
const yaml = readFileSync(lease.path, "utf8");
|
||||
expect(parse(yaml).evidence.sources).toEqual([{
|
||||
@@ -370,9 +384,9 @@ test("static S3 Evidence resolves only configured secret-root file paths", async
|
||||
prefix: "published/",
|
||||
endpoint_url: "https://s3.example.test/",
|
||||
region: "eu-west-1",
|
||||
access_key_file: realpathSync(join(f.secretRoot, "evidence-access")),
|
||||
secret_key_file: realpathSync(join(f.secretRoot, "evidence-secret")),
|
||||
session_token_file: realpathSync(join(f.secretRoot, "evidence-token")),
|
||||
access_key_file: expect.stringContaining("/workspace-secret-runtime/"),
|
||||
secret_key_file: expect.stringContaining("/workspace-secret-runtime/"),
|
||||
session_token_file: expect.stringContaining("/workspace-secret-runtime/"),
|
||||
trusted_endpoint: true,
|
||||
allow_private_endpoint: true,
|
||||
allow_insecure_endpoint: false,
|
||||
|
||||
Reference in New Issue
Block a user