diff --git a/frontend/e2e/auth.spec.ts b/frontend/e2e/auth.spec.ts index c6510f59..e24dff2d 100644 --- a/frontend/e2e/auth.spec.ts +++ b/frontend/e2e/auth.spec.ts @@ -59,7 +59,7 @@ async function expectShell(page: Page): Promise { async function signInLocally(page: Page, account: "ordinary" | "admin", remember = false): Promise { await page.getByLabel("Username").fill(stack.localAccount(account).username); - await page.getByLabel("Password").fill(stack.localAccount(account).password); + await page.getByLabel("Password", { exact: true }).fill(stack.localAccount(account).password); const rememberControl = page.getByRole("checkbox", { name: /remember me/i }); if (remember) await rememberControl.check(); await page.getByRole("button", { name: "Sign in", exact: true }).click(); diff --git a/frontend/e2e/f1.spec.ts b/frontend/e2e/f1.spec.ts index 919f14e8..73d55e66 100644 --- a/frontend/e2e/f1.spec.ts +++ b/frontend/e2e/f1.spec.ts @@ -29,7 +29,7 @@ test.afterAll(async () => { async function signInLocally(page: Page): Promise { const account = stack.localAccount("ordinary"); await page.getByLabel("Username").fill(account.username); - await page.getByLabel("Password").fill(account.password); + await page.getByLabel("Password", { exact: true }).fill(account.password); await page.getByRole("button", { name: "Sign in", exact: true }).click(); await expect(page.getByTestId("app-shell")).toBeVisible({ timeout: 30_000 }); } diff --git a/scripts/test-canonical-install-compose.sh b/scripts/test-canonical-install-compose.sh index 695bc980..586c70aa 100755 --- a/scripts/test-canonical-install-compose.sh +++ b/scripts/test-canonical-install-compose.sh @@ -20,7 +20,8 @@ done printf '%s\n' '{}' >"$tmp/pi-auth.json" printf '%s\n' 'THT_MODEL_API_KEY=fixture-model-api-key' >"$tmp/thothii.secrets" -chmod 0600 "$tmp/pi-auth.json" "$tmp/thothii.secrets" +printf '%s\n' 'schema_version: 1' >"$tmp/thothii-installation.yaml" +chmod 0600 "$tmp/pi-auth.json" "$tmp/thothii.secrets" "$tmp/thothii-installation.yaml" mkdir -p "$tmp/data" "$tmp/pi-state" "$tmp/workspace-registry" "$tmp/auth" chmod 0700 "$tmp/auth" "$root/scripts/prepare-server-pi-state.sh" "$tmp/pi-state" "$(id -u)" "$(id -g)" >/dev/null @@ -37,6 +38,7 @@ for profile in local server; do 'THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git' \ "PI_AUTH_FILE=$tmp/pi-auth.json" \ "THT_SECRETS_FILE=$tmp/thothii.secrets" \ + "THT_INSTALLATION_CONFIG_SOURCE=$tmp/thothii-installation.yaml" \ "THT_AUTH_CONFIG_ROOT=$tmp/auth" if [[ "$profile" == server ]]; then printf '%s\n' \ @@ -108,15 +110,18 @@ if (JSON.stringify(config).includes("fixture-model-api-key")) { NODE done -for profile in local server; do - manual="$root/docs/install/$profile-workspace-registry.md" - grep -Fq -- '--env-file "$THT_OPERATOR_ENV"' "$manual" \ - && grep -Fq -- "-f \"\$THT_SOURCE_ROOT/compose.yaml\" -f \"\$THT_SOURCE_ROOT/deploy/compose.$profile.yaml\"" "$manual" || { - echo "$profile manual lacks the canonical base+profile command" >&2 +for manual in "$root/README.md" "$root/docs/installazione-docker-4-contesti.md"; do + grep -Fq -- './scripts/run-stack.sh' "$manual" || { + echo "${manual#"$root/"} lacks the canonical local launcher" >&2 + exit 1 + } + grep -Fq -- 'docker compose --env-file deploy/env/server.env' "$manual" \ + && grep -Fq -- '-f compose.yaml -f deploy/compose.server.yaml' "$manual" || { + echo "${manual#"$root/"} lacks the canonical server base+profile command" >&2 exit 1 } if rg -q 'local-compose\.workspace-registry|server-compose\.workspace-registry' "$manual"; then - echo "$profile manual still references a superseded standalone Compose example" >&2 + echo "${manual#"$root/"} still references a superseded standalone Compose example" >&2 exit 1 fi done diff --git a/scripts/test-compose-secret-policy.sh b/scripts/test-compose-secret-policy.sh index 848466a5..23216c2c 100755 --- a/scripts/test-compose-secret-policy.sh +++ b/scripts/test-compose-secret-policy.sh @@ -121,6 +121,7 @@ assert_unsafe_source_rejected() { write_secret "$fixture_root/pi-auth.json" 'fixture-pi-auth' write_secret "$fixture_root/thothii.secrets" 'THT_MODEL_API_KEY=fixture-model-api-key' +write_secret "$fixture_root/thothii-installation.yaml" 'schema_version: 1' write_secret "$fixture_root/ssh-private-key" 'fixture-ssh-private-key' write_secret "$fixture_root/ssh-known-hosts" 'fixture-ssh-known-hosts' write_secret "$fixture_root/https-credentials" 'fixture-https-credentials' @@ -133,6 +134,7 @@ printf '%s\n' \ 'THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git' \ "PI_AUTH_FILE=$fixture_root/pi-auth.json" \ "THT_SECRETS_FILE=$fixture_root/thothii.secrets" \ + "THT_INSTALLATION_CONFIG_SOURCE=$fixture_root/thothii-installation.yaml" \ "THT_AUTH_CONFIG_ROOT=$fixture_root/auth" \ "THT_WORKSPACE_BINDINGS_ENV_FILE=$fixture_root/workspace-bindings.env" \ "THT_WORKSPACE_GIT_SSH_KEY_FILE=$fixture_root/ssh-private-key" \ @@ -152,13 +154,13 @@ connector_override="$fixture_root/compose.connector-secrets.local.yaml" --output "$connector_override" render base -assert_render_contract base '' 'thothii.secrets' +assert_render_contract base '' '/run/secrets/catalog_runtime_password,thothii.secrets' render ssh -f "$root/deploy/compose.git-ssh.yaml" -assert_render_contract ssh '/run/secrets/workspace-registry-git-known-hosts,/run/secrets/workspace-registry-git-ssh-key' 'thothii.secrets' +assert_render_contract ssh '/run/secrets/workspace-registry-git-known-hosts,/run/secrets/workspace-registry-git-ssh-key' '/run/secrets/catalog_runtime_password,thothii.secrets' render https -f "$root/deploy/compose.git-https.yaml" -assert_render_contract https '/run/secrets/workspace-registry-git-ca,/run/secrets/workspace-registry-git-credentials' 'thothii.secrets' +assert_render_contract https '/run/secrets/workspace-registry-git-ca,/run/secrets/workspace-registry-git-credentials' '/run/secrets/catalog_runtime_password,thothii.secrets' render connector -f "$connector_override" -assert_render_contract connector '' 'north-star-research-dwh-password,thothii.secrets' +assert_render_contract connector '' '/run/secrets/catalog_runtime_password,north-star-research-dwh-password,thothii.secrets' assert_missing_source_rejected THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_SOURCE assert_unsafe_source_rejected 'relative/secret' relative-source diff --git a/scripts/test-server-pi-state-topology.sh b/scripts/test-server-pi-state-topology.sh index 8f8f2d78..122f9a90 100755 --- a/scripts/test-server-pi-state-topology.sh +++ b/scripts/test-server-pi-state-topology.sh @@ -34,17 +34,19 @@ printf '%s\n' preserved-placeholder >"$pi_state/agent/models.json" printf '{}\n' >"$fixture/pi-auth.json" printf 'THT_MODEL_API_KEY=fixture-model-key\n' >"$fixture/thothii.secrets" +printf 'schema_version: 1\n' >"$fixture/thothii-installation.yaml" printf 'fixture-session-password\n' >"$fixture/session-runtime-password" printf 'fixture-session-migrator-password\n' >"$fixture/session-migrator-password" printf 'fixture-session-ca\n' >"$fixture/session-ca.pem" cp "$root/deploy/workspaces/server-sessions.yaml.example" "$fixture/server-sessions.yaml" -chmod 0600 "$fixture"/*.json "$fixture"/*.secrets "$fixture"/*password "$fixture"/*.pem +chmod 0600 "$fixture"/*.json "$fixture"/*.secrets "$fixture"/*.yaml "$fixture"/*password "$fixture"/*.pem cat >"$fixture/server.env" <"$tmp/thothii-installation.yaml" render_profile() { local profile=$1 @@ -164,6 +165,7 @@ assert_remote_required() { THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git \ PI_AUTH_FILE=/dev/null \ THT_SECRETS_FILE=/dev/null \ +THT_INSTALLATION_CONFIG_SOURCE="$tmp/thothii-installation.yaml" \ THT_AUTH_CONFIG_ROOT=/tmp/thothii-auth \ docker compose -f compose.yaml config --format json >"$tmp/base.json" node - "$tmp/base.json" <<'NODE' diff --git a/scripts/unified-deployment-smoke.sh b/scripts/unified-deployment-smoke.sh index 53be5201..41c6e0af 100755 --- a/scripts/unified-deployment-smoke.sh +++ b/scripts/unified-deployment-smoke.sh @@ -396,6 +396,7 @@ task13_write_environment() { printf 'MAX_PI_PROCESSES=2\n' printf 'PI_AUTH_FILE=%s\n' "$TASK13_PI_AUTH" printf 'THT_SECRETS_FILE=%s\n' "$TASK13_SECRETS" + printf 'THT_INSTALLATION_CONFIG_SOURCE=%s\n' "$TASK13_INSTALLATION" printf 'THT_AUTH_CONFIG_ROOT=%s\n' "$TASK13_AUTH_ROOT" printf 'THT_WORKSPACE_GIT_REMOTE=%s\n' "$remote" printf 'THT_WORKSPACE_GIT_BRANCH=%s\n' "$TASK13_BRANCH" @@ -781,6 +782,7 @@ EOF printf 'MAX_PI_PROCESSES=2\n' printf 'PI_AUTH_FILE=%s\n' "$TASK13_PI_AUTH" printf 'THT_SECRETS_FILE=%s\n' "$TASK13_SECRETS" + printf 'THT_INSTALLATION_CONFIG_SOURCE=%s\n' "$TASK13_INSTALLATION" printf 'THT_AUTH_CONFIG_ROOT=%s\n' "$TASK13_AUTH_ROOT" printf 'THT_AUTH_RUNTIME_ROOT=%s\n' "$TASK13_AUTH_RUNTIME_ROOT" printf 'THT_WORKSPACE_GIT_REMOTE=/fixtures/remote.git\n' @@ -931,7 +933,7 @@ task13_build_tht() { task13_assert_rendered_contract() { local services rendered services="$(task13_compose config --services | sort)" - [[ "$services" == $'core\nembedding\nembedding-model-init\nfrontend\nqdrant' ]] \ + [[ "$services" == $'catalog-db\ncore\nembedding\nembedding-model-init\nfrontend\nqdrant' ]] \ || task13_fail "rendered stack is not the mandatory internal semantic topology" rendered="$TASK13_TMP/rendered-compose.yaml" task13_compose config >"$rendered"