fix: validate deployment rollback and server topology
This commit is contained in:
@@ -279,10 +279,12 @@ services:
|
||||
PI_THINKING: low
|
||||
THT_WORKSPACE_INSTALLATION_ID: task13-smoke
|
||||
THT_WORKSPACE_REGISTRY_ROOT: /data/workspace-registry
|
||||
THT_WS_TASK13_SMOKE_DWH_TRANSPORT: postgres_direct
|
||||
THT_WS_TASK13_SMOKE_DWH_HOST: dwh.task13.invalid
|
||||
THT_WS_TASK13_SMOKE_DWH_PORT: "5432"
|
||||
THT_WS_TASK13_SMOKE_DWH_USER: task13_reader
|
||||
THT_WS_TASK13_SMOKE_DWH_PASSWORD_FILE: /run/secrets/thothii.secrets
|
||||
THT_WS_TASK13_SMOKE_VECTOR_TRANSPORT: pgvector_direct
|
||||
THT_WS_TASK13_SMOKE_VECTOR_HOST: vector.task13.invalid
|
||||
THT_WS_TASK13_SMOKE_VECTOR_PORT: "5432"
|
||||
THT_WS_TASK13_SMOKE_VECTOR_USER: task13_vector_reader
|
||||
@@ -372,7 +374,10 @@ EOF
|
||||
chmod 0600 "$TASK13_SERVER_WORKSPACE_CONFIG"
|
||||
|
||||
mkdir -p "$TASK13_SERVER_DATA" "$TASK13_SERVER_PI_STATE" "$TASK13_SERVER_REGISTRY"
|
||||
chmod 0777 "$TASK13_SERVER_DATA" "$TASK13_SERVER_PI_STATE" "$TASK13_SERVER_REGISTRY"
|
||||
"$TASK13_ROOT/scripts/prepare-server-pi-state.sh" \
|
||||
"$TASK13_SERVER_PI_STATE" "$(id -u)" "$(id -g)" >>"$TASK13_LOG"
|
||||
chmod 0777 "$TASK13_SERVER_DATA" "$TASK13_SERVER_PI_STATE" \
|
||||
"$TASK13_SERVER_PI_STATE/agent" "$TASK13_SERVER_REGISTRY"
|
||||
data_root="$TASK13_SERVER_DATA"
|
||||
pi_root="$TASK13_SERVER_PI_STATE"
|
||||
registry_root="$TASK13_SERVER_REGISTRY"
|
||||
@@ -387,10 +392,12 @@ services:
|
||||
labels:
|
||||
io.thothii.task13.run: "$TASK13_RUN_ID"
|
||||
environment:
|
||||
THT_WS_TASK13_SMOKE_DWH_TRANSPORT: postgres_direct
|
||||
THT_WS_TASK13_SMOKE_DWH_HOST: dwh.task13.invalid
|
||||
THT_WS_TASK13_SMOKE_DWH_PORT: "5432"
|
||||
THT_WS_TASK13_SMOKE_DWH_USER: task13_reader
|
||||
THT_WS_TASK13_SMOKE_DWH_PASSWORD_FILE: /run/secrets/thothii.secrets
|
||||
THT_WS_TASK13_SMOKE_VECTOR_TRANSPORT: pgvector_direct
|
||||
THT_WS_TASK13_SMOKE_VECTOR_HOST: vector.task13.invalid
|
||||
THT_WS_TASK13_SMOKE_VECTOR_PORT: "5432"
|
||||
THT_WS_TASK13_SMOKE_VECTOR_USER: task13_vector_reader
|
||||
@@ -602,6 +609,14 @@ task13_assert_runtime() {
|
||||
task13_run_logged "thothctl Pi doctor" "$TASK13_THOTHCTL" --installation "$TASK13_INSTALLATION" pi doctor
|
||||
}
|
||||
|
||||
task13_server_auth_headers() {
|
||||
TASK13_SERVER_AUTH_HEADERS=(
|
||||
-H 'x-thoth-trusted-principal-issuer: task13-proxy'
|
||||
-H 'x-thoth-trusted-principal-subject: task13-user'
|
||||
-H 'x-thoth-trusted-principal-display-name: Task 13 User'
|
||||
)
|
||||
}
|
||||
|
||||
task13_assert_server_runtime() {
|
||||
local frontend unauthenticated authenticated session_status core_id frontend_id
|
||||
local expected_core_image expected_frontend_image
|
||||
@@ -641,11 +656,10 @@ task13_assert_server_runtime() {
|
||||
"http://$frontend/api/workspaces")"
|
||||
[[ "$unauthenticated" == 401 ]] || task13_fail "server profile did not enforce upstream auth"
|
||||
authenticated="$TASK13_TMP/server-workspaces.out"
|
||||
task13_server_auth_headers
|
||||
curl --connect-timeout "$TASK13_CURL_CONNECT_TIMEOUT" --max-time "$TASK13_CURL_MAX_TIME" \
|
||||
--fail --silent --show-error \
|
||||
-H 'x-thoth-principal-issuer: task13-proxy' \
|
||||
-H 'x-thoth-principal-subject: task13-user' \
|
||||
-H 'x-thoth-principal-display-name: Task 13 User' \
|
||||
"${TASK13_SERVER_AUTH_HEADERS[@]}" \
|
||||
"http://$frontend/api/workspaces" >"$authenticated"
|
||||
grep -Fq 'Task 13 Smoke' "$authenticated" \
|
||||
|| task13_fail "authenticated server route did not expose the disposable registry"
|
||||
@@ -653,8 +667,7 @@ task13_assert_server_runtime() {
|
||||
session_status="$(curl --connect-timeout "$TASK13_CURL_CONNECT_TIMEOUT" \
|
||||
--max-time "$TASK13_CURL_MAX_TIME" --silent --output "$TASK13_TMP/server-sessions.out" \
|
||||
--write-out '%{http_code}' \
|
||||
-H 'x-thoth-principal-issuer: task13-proxy' \
|
||||
-H 'x-thoth-principal-subject: task13-user' \
|
||||
"${TASK13_SERVER_AUTH_HEADERS[@]}" \
|
||||
"http://$frontend/api/sessions")"
|
||||
[[ "$session_status" == 503 ]] \
|
||||
|| task13_fail "disposable unavailable session dependency did not fail closed with 503"
|
||||
@@ -1162,35 +1175,15 @@ task13_self_test_rollback_fixture_contract() {
|
||||
}
|
||||
|
||||
task13_self_test_runtime_binding_fixture() {
|
||||
local fixture_source
|
||||
fixture_source="$(declare -f task13_write_fixture_files)"
|
||||
for variable in \
|
||||
THT_WS_TASK13_SMOKE_DWH_HOST \
|
||||
THT_WS_TASK13_SMOKE_DWH_PORT \
|
||||
THT_WS_TASK13_SMOKE_DWH_USER \
|
||||
THT_WS_TASK13_SMOKE_DWH_PASSWORD_FILE \
|
||||
THT_WS_TASK13_SMOKE_VECTOR_HOST \
|
||||
THT_WS_TASK13_SMOKE_VECTOR_PORT \
|
||||
THT_WS_TASK13_SMOKE_VECTOR_USER \
|
||||
THT_WS_TASK13_SMOKE_VECTOR_PASSWORD_FILE \
|
||||
THT_WS_TASK13_SMOKE_EMBEDDING_BASE_URL; do
|
||||
grep -Fq "$variable" <<<"$fixture_source" \
|
||||
|| task13_fail "rollback fixture lacks runtime binding: $variable"
|
||||
done
|
||||
local root
|
||||
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
||||
"$root/scripts/test-task13-runtime-fixtures.sh" local
|
||||
}
|
||||
|
||||
task13_self_test_server_runtime_binding_fixture() {
|
||||
local fixture_source
|
||||
fixture_source="$(declare -f task13_write_server_fixture_files)"
|
||||
for variable in \
|
||||
THT_WS_TASK13_SMOKE_DWH_HOST \
|
||||
THT_WS_TASK13_SMOKE_DWH_PASSWORD_FILE \
|
||||
THT_WS_TASK13_SMOKE_VECTOR_HOST \
|
||||
THT_WS_TASK13_SMOKE_VECTOR_PASSWORD_FILE \
|
||||
THT_WS_TASK13_SMOKE_EMBEDDING_BASE_URL; do
|
||||
grep -Fq "$variable" <<<"$fixture_source" \
|
||||
|| task13_fail "server fixture lacks runtime binding: $variable"
|
||||
done
|
||||
local root
|
||||
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
||||
"$root/scripts/test-task13-runtime-fixtures.sh" server
|
||||
}
|
||||
|
||||
task13_self_test_stopped_project_containers() {
|
||||
@@ -1325,6 +1318,21 @@ task13_self_test_server_release_contract() {
|
||||
|| task13_fail "workflow lacks an outer timeout for the Linux server smoke"
|
||||
}
|
||||
|
||||
task13_self_test_server_auth_hop_contract() {
|
||||
local joined
|
||||
task13_server_auth_headers
|
||||
joined="${TASK13_SERVER_AUTH_HEADERS[*]}"
|
||||
for header in \
|
||||
x-thoth-trusted-principal-issuer \
|
||||
x-thoth-trusted-principal-subject \
|
||||
x-thoth-trusted-principal-display-name; do
|
||||
[[ "$joined" == *"$header:"* ]] \
|
||||
|| task13_fail "server smoke omits trusted frontend hop header: $header"
|
||||
done
|
||||
[[ "$joined" != *'x-thoth-principal-issuer:'* ]] \
|
||||
|| task13_fail "server smoke sends public identity headers to the frontend hop"
|
||||
}
|
||||
|
||||
task13_self_test_source_contract() {
|
||||
local root host_network push_command registry_function workflow uses_count pinned_uses_count
|
||||
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
||||
@@ -1385,6 +1393,7 @@ task13_self_test() {
|
||||
task13_self_test_public_timeout_contract
|
||||
task13_self_test_windows_release_contract
|
||||
task13_self_test_server_release_contract
|
||||
task13_self_test_server_auth_hop_contract
|
||||
task13_self_test_source_contract
|
||||
printf 'Task 13 smoke safety contracts passed.\n'
|
||||
}
|
||||
@@ -1400,6 +1409,7 @@ task13_self_test_case() {
|
||||
timeout-public) task13_self_test_public_timeout_contract ;;
|
||||
windows) task13_self_test_windows_release_contract ;;
|
||||
server) task13_self_test_server_release_contract ;;
|
||||
server-auth) task13_self_test_server_auth_hop_contract ;;
|
||||
*) task13_fail "unknown Task 13 self-test case: $1" ;;
|
||||
esac
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user