import { execFileSync } from "node:child_process"; import { existsSync, readFileSync } from "node:fs"; import { expect, test } from "vitest"; test("declares a durable isolated registry volume and only read-only Git credential mounts", () => { const compose = readFileSync(new URL("../../compose.yaml", import.meta.url), "utf8"); const development = readFileSync(new URL("../../docker-compose.dev.yml", import.meta.url), "utf8"); const gitHttps = readFileSync(new URL("../../deploy/compose.git-https.yaml", import.meta.url), "utf8"); const gitSsh = readFileSync(new URL("../../deploy/compose.git-ssh.yaml", import.meta.url), "utf8"); const dockerfile = readFileSync(new URL("../../docker/core.Dockerfile", import.meta.url), "utf8"); const smoke = readFileSync(new URL("../../scripts/workspace-registry-smoke.sh", import.meta.url), "utf8"); for (const source of [compose, development]) { expect(source).toContain("THT_WORKSPACE_REGISTRY_ROOT: /data/workspace-registry"); expect(source).toContain("THT_WORKSPACE_GIT_REMOTE: ${THT_WORKSPACE_GIT_REMOTE:?set THT_WORKSPACE_GIT_REMOTE}"); expect(source).toContain("workspace-registry:/data/workspace-registry"); } expect(compose).not.toMatch(/workspace-registry-git-(?:credentials|ca|ssh-key|known-hosts):ro/); expect(gitHttps).toMatch(/workspace-registry-git-credentials:ro/); expect(gitHttps).toMatch(/workspace-registry-git-ca:ro/); expect(gitSsh).toMatch(/workspace-registry-git-ssh-key:ro/); expect(gitSsh).toMatch(/workspace-registry-git-known-hosts:ro/); expect(dockerfile).toMatch(/mkdir -p[^\n]*\/data\/workspace-registry/); expect(dockerfile).toMatch(/chown -R thoth:thoth \/home\/thoth\/\.pi \/data/); expect(smoke).toContain('core_remote="/fixtures/offline.git"'); expect(smoke).toContain('"degraded":true'); expect(smoke).toContain('core_remote="/fixtures/remote.git"'); }); test("workspace registry smoke image cleanup is scoped to the per-run image identity", () => { const output = execFileSync("bash", ["scripts/workspace-registry-smoke.sh"], { cwd: new URL("../..", import.meta.url), env: { ...process.env, WORKSPACE_REGISTRY_SMOKE_SELF_TEST: "image-cleanup-identity" }, encoding: "utf8", }); expect(output).toContain("workspace registry smoke image cleanup identity self-test passed"); }); test("workspace migration source modules are absent from the live backend boundary", () => { expect(existsSync(new URL("../src/workspaces/migrate-legacy.ts", import.meta.url))).toBe(false); expect(existsSync(new URL("../src/workspaces/migrate-v2-qdrant.ts", import.meta.url))).toBe(false); });