#!/usr/bin/env bash # Generate Task 13 fixtures and validate rendered bindings with the production workspace resolver. set -euo pipefail profile="${1:-}" [[ "$profile" == local || "$profile" == server ]] || { echo "usage: $0 local|server" >&2 exit 2 } root="$(cd "$(dirname "$0")/.." && pwd -P)" tmp_parent="${TMPDIR:-/tmp}" tmp_parent="${tmp_parent%/}" fixture="$(mktemp -d "$tmp_parent/thoth-task13-runtime-$profile.XXXXXX")" trap 'rm -rf "$fixture"' EXIT HUP INT TERM # shellcheck source=./unified-deployment-smoke.sh source "$root/scripts/unified-deployment-smoke.sh" TASK13_ROOT="$root" TASK13_TMP="$fixture" TASK13_RUN_ID="fixture-$profile" TASK13_PROJECT="thothii-task13-$profile" TASK13_PROFILE="$profile" TASK13_CORE_IMAGE="task13-core-$profile:fixture" TASK13_FRONTEND_IMAGE="task13-frontend-$profile:fixture" TASK13_SECRET_VALUE="task13-runtime-secret-$profile" TASK13_BRANCH=main TASK13_ENV_FILE="$fixture/operator.env" TASK13_OVERRIDE="$fixture/compose.task13.yaml" TASK13_LOG="$fixture/task13.log" : >"$TASK13_LOG" TASK13_INSTALLATION="$fixture/thothii-installation.yaml" TASK13_PI_AUTH="$fixture/pi-auth.json" TASK13_SECRETS="$fixture/thothii.secrets" TASK13_SESSION_RUNTIME_PASSWORD="$fixture/runtime-password" TASK13_PI_MODELS="$fixture/models.json" TASK13_PI_SETTINGS="$fixture/settings.json" TASK13_LLM_SERVER="$fixture/fake-llm.mjs" TASK13_LLM_CONTAINER="$TASK13_PROJECT-llm" TASK13_REMOTE="$fixture/remote.git" TASK13_CURRENT_IMAGE_OVERRIDE="$fixture/current-image.yaml" mkdir -p "$TASK13_REMOTE" workspace="$fixture/task13-smoke.yaml" cat >"$workspace" <<'EOF' workspace: schema_version: 3 id: task13-smoke name: Task 13 Smoke language: en dwh: engine: postgres database: warehouse schema: analytics supported_transports: [postgres_direct] semantic_index: vector_store: engine: qdrant collection: task13-smoke dimensions: 1024 distance: cosine embedding: provider: ollama_internal model: qwen3-embedding:0.6b dimensions: 1024 llm_policy: default: local-qwen/task13-smoke allowed: [local-qwen/task13-smoke] EOF if [[ "$profile" == local ]]; then task13_write_fixture_files task13_write_environment /fixtures/remote.git compose_files=(-f "$root/compose.yaml" -f "$root/deploy/compose.local.yaml" -f "$TASK13_OVERRIDE") else TASK13_SERVER_DATA="$fixture/Server Data" TASK13_SERVER_PI_STATE="$fixture/Server Pi State" TASK13_SERVER_REGISTRY="$fixture/Server Registry" TASK13_SERVER_WORKSPACE_CONFIG="$fixture/server-sessions.yaml" TASK13_SESSION_RUNTIME_PASSWORD="$fixture/session-runtime-password" TASK13_SESSION_MIGRATOR_PASSWORD_FILE="$fixture/session-migrator-password" TASK13_SESSION_CA="$fixture/session-ca.pem" TASK13_SESSION_PASSWORD="fixture-private-token-$profile" TASK13_SESSION_MIGRATOR_PASSWORD="fixture-migrator-token-$profile" task13_write_server_fixture_files compose_files=( -f "$root/compose.yaml" -f "$root/deploy/compose.server.yaml" -f "$root/deploy/compose.session-server.yaml.example" -f "$TASK13_OVERRIDE" ) fi rendered="$fixture/rendered.json" docker compose --project-name "$TASK13_PROJECT" --project-directory "$root" \ --env-file "$TASK13_ENV_FILE" "${compose_files[@]}" config --format json >"$rendered" task13_assert_rendered_contract tsx_loader="$root/backend/node_modules/tsx/dist/loader.mjs" checker=(node --import "$tsx_loader" "$root/scripts/task13-runtime-fixture-check.ts") [[ -f "$tsx_loader" ]] || { echo "backend dependencies are required for the Task 13 runtime fixture contract" >&2 exit 2 } "${checker[@]}" "$rendered" "$workspace" "$profile" for mutation in wrong-service wrong-value wrong-secret-mount; do mutated="$fixture/$mutation.json" node - "$rendered" "$mutated" "$mutation" <<'NODE' const fs = require("fs"); const [source, destination, mutation] = process.argv.slice(2); const config = JSON.parse(fs.readFileSync(source, "utf8")); if (mutation === "wrong-service") { const name = "THT_WS_TASK13_SMOKE_DWH_HOST"; config.services.frontend.environment ||= {}; config.services.frontend.environment[name] = config.services.core.environment[name]; delete config.services.core.environment[name]; } else if (mutation === "wrong-value") { config.services.core.environment.THT_WS_TASK13_SMOKE_DWH_HOST = "wrong.task13.invalid"; } else { config.secrets.thothii_secrets.file = source + ".missing"; } fs.writeFileSync(destination, JSON.stringify(config)); NODE if "${checker[@]}" "$mutated" "$workspace" "$profile" \ >"$fixture/$mutation.out" 2>"$fixture/$mutation.err"; then echo "runtime fixture checker accepted mutation: $mutation" >&2 exit 1 fi done echo "Task 13 $profile rendered runtime fixture contract passed."