fix(deploy): generalize connector secret overrides
This commit is contained in:
@@ -64,30 +64,40 @@ compose_fixture() {
|
||||
local name="$1" directory="$2"; shift 2
|
||||
(
|
||||
cd "$directory"
|
||||
docker compose --env-file .env "$@" config --quiet
|
||||
"$root/scripts/compose-with-preflight.sh" --env-file .env "$@" config --quiet
|
||||
)
|
||||
echo "$name passed"
|
||||
}
|
||||
|
||||
prepare_binding_fixture() {
|
||||
local directory="$1"
|
||||
cp "$root/docs/install/examples/workspace-bindings.env.example" "$directory/workspace-bindings.env"
|
||||
printf '%s\n' \
|
||||
'THT_WS_NORTH_STAR_RESEARCH_DWH_TRANSPORT=postgres_direct' \
|
||||
'THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_FILE=/run/secrets/north-star-research-dwh-password' \
|
||||
'THT_WS_NORTH_STAR_RESEARCH_VECTOR_TRANSPORT=rest_api' \
|
||||
'THT_WS_NORTH_STAR_RESEARCH_VECTOR_API_KEY_FILE=/run/secrets/north-star-research-vector-api-key' \
|
||||
>"$directory/workspace-bindings.env"
|
||||
printf 'THT_WORKSPACE_BINDINGS_ENV_FILE=%s\n' "$directory/workspace-bindings.env" >>"$directory/.env"
|
||||
}
|
||||
|
||||
verify_connector_fixture() {
|
||||
local directory="$1" rendered project
|
||||
local directory="$1" rendered project connector_override
|
||||
project="thoth-install-connector-fixture-$$"
|
||||
connector_override="$directory/connector-secrets.local.yaml"
|
||||
"$root/scripts/generate-connector-secrets-override.sh" \
|
||||
--bindings-env "$directory/workspace-bindings.env" --operator-env "$directory/.env" \
|
||||
--output "$connector_override" >/dev/null
|
||||
rendered="$(
|
||||
cd "$directory"
|
||||
docker compose --env-file .env -f compose.workspace-registry.yaml -f connector-secrets.yaml config
|
||||
"$root/scripts/compose-with-preflight.sh" --env-file .env \
|
||||
-f compose.workspace-registry.yaml -f connector-secrets.local.yaml config
|
||||
)"
|
||||
for expected in \
|
||||
'THT_WS_PSD_CLINICAL_DWH_TRANSPORT: postgres_direct' \
|
||||
'THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: /run/secrets/psd-clinical-dwh-password' \
|
||||
'THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_FILE: /run/secrets/psd-clinical-vector-password' \
|
||||
'target: psd-clinical-dwh-password' \
|
||||
'target: psd-clinical-vector-password'; do
|
||||
'THT_WS_NORTH_STAR_RESEARCH_DWH_TRANSPORT: postgres_direct' \
|
||||
'THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_FILE: /run/secrets/north-star-research-dwh-password' \
|
||||
'THT_WS_NORTH_STAR_RESEARCH_VECTOR_API_KEY_FILE: /run/secrets/north-star-research-vector-api-key' \
|
||||
'target: north-star-research-dwh-password' \
|
||||
'target: north-star-research-vector-api-key'; do
|
||||
grep -Fq "$expected" <<<"$rendered" || {
|
||||
echo "connector fixture does not give core required binding or secret target: $expected" >&2
|
||||
return 1
|
||||
@@ -96,33 +106,33 @@ verify_connector_fixture() {
|
||||
echo "copied connector binding/secret fixture passed"
|
||||
if ! (
|
||||
cd "$directory"
|
||||
docker compose --project-name "$project" --env-file .env -f compose.workspace-registry.yaml -f connector-secrets.yaml \
|
||||
run --rm --no-deps --build --entrypoint sh core -c '
|
||||
test "$THT_WS_PSD_CLINICAL_DWH_TRANSPORT" = postgres_direct
|
||||
test "$THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE" = /run/secrets/psd-clinical-dwh-password
|
||||
test "$THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_FILE" = /run/secrets/psd-clinical-vector-password
|
||||
test -f "$THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE"
|
||||
test -f "$THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_FILE"
|
||||
"$root/scripts/compose-with-preflight.sh" --project-name "$project" --env-file .env \
|
||||
-f compose.workspace-registry.yaml -f connector-secrets.local.yaml run --rm --no-deps --build --entrypoint sh core -c '
|
||||
test "$THT_WS_NORTH_STAR_RESEARCH_DWH_TRANSPORT" = postgres_direct
|
||||
test "$THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_FILE" = /run/secrets/north-star-research-dwh-password
|
||||
test "$THT_WS_NORTH_STAR_RESEARCH_VECTOR_API_KEY_FILE" = /run/secrets/north-star-research-vector-api-key
|
||||
test -f "$THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_FILE"
|
||||
test -f "$THT_WS_NORTH_STAR_RESEARCH_VECTOR_API_KEY_FILE"
|
||||
'
|
||||
); then
|
||||
(
|
||||
cd "$directory"
|
||||
docker compose --project-name "$project" --env-file .env -f compose.workspace-registry.yaml -f connector-secrets.yaml \
|
||||
down --volumes --remove-orphans
|
||||
"$root/scripts/compose-with-preflight.sh" --project-name "$project" --env-file .env \
|
||||
-f compose.workspace-registry.yaml -f connector-secrets.local.yaml down --volumes --remove-orphans
|
||||
) || true
|
||||
return 1
|
||||
fi
|
||||
(
|
||||
cd "$directory"
|
||||
docker compose --project-name "$project" --env-file .env -f compose.workspace-registry.yaml -f connector-secrets.yaml \
|
||||
down --volumes --remove-orphans
|
||||
"$root/scripts/compose-with-preflight.sh" --project-name "$project" --env-file .env \
|
||||
-f compose.workspace-registry.yaml -f connector-secrets.local.yaml down --volumes --remove-orphans
|
||||
)
|
||||
echo "core process sees connector bindings and secret files passed"
|
||||
}
|
||||
|
||||
verify_copied_operator_fixtures() {
|
||||
local fixture_root local_dir server_dir https_dir ssh_dir connector_dir
|
||||
fixture_root="$(mktemp -d "${TMPDIR:-/tmp}/thoth-install-fixtures.XXXXXX")"
|
||||
fixture_root="$(mktemp -d "${TMPDIR%/}/thoth-install-fixtures.XXXXXX")"
|
||||
trap 'rm -rf "$fixture_root"' RETURN
|
||||
local_dir="$fixture_root/local"; server_dir="$fixture_root/server"
|
||||
https_dir="$fixture_root/https"; ssh_dir="$fixture_root/ssh"; connector_dir="$fixture_root/connector"
|
||||
@@ -168,12 +178,11 @@ verify_copied_operator_fixtures() {
|
||||
compose_fixture "copied SSH Git override fixture" "$ssh_dir" -f compose.workspace-registry.yaml -f git-ssh.yaml
|
||||
|
||||
cp "$root/docs/install/examples/local-compose.workspace-registry.yaml" "$connector_dir/compose.workspace-registry.yaml"
|
||||
cp "$root/docs/install/examples/connector-secrets.workspace-registry.yaml" "$connector_dir/connector-secrets.yaml"
|
||||
: >"$connector_dir/dwh-password"; : >"$connector_dir/vector-password"
|
||||
printf '%s\n' \
|
||||
"THT_SOURCE_ROOT=$root" \
|
||||
"THT_WS_PSD_CLINICAL_DWH_PASSWORD_SOURCE=$connector_dir/dwh-password" \
|
||||
"THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_SOURCE=$connector_dir/vector-password" >"$connector_dir/.env"
|
||||
"THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_SOURCE=$connector_dir/dwh-password" \
|
||||
"THT_WS_NORTH_STAR_RESEARCH_VECTOR_API_KEY_SOURCE=$connector_dir/vector-password" >"$connector_dir/.env"
|
||||
prepare_binding_fixture "$connector_dir"
|
||||
verify_connector_fixture "$connector_dir"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user