import { expect, test } from "vitest"; import { parse } from "yaml"; import { renderRuntimeConfig, type RuntimeBindings, type RuntimePaths } from "../src/workspaces/runtime-renderer.js"; import { supportsSessionRuntime } from "../src/workspaces/bindings.js"; import { parseWorkspaceYaml } from "../src/workspaces/schema.js"; const workspace = parseWorkspaceYaml(`workspace: schema_version: 2 id: psd-clinical name: Policlinico San Donato language: it dwh: engine: postgres database: postgres schema: datawarehouse supported_transports: [postgres_direct, rest_api] semantic_index: vector_store: engine: pgvector database: postgres schema: vectors collection: clinical_documents dimensions: 768 distance: cosine supported_transports: [pgvector_direct, rest_api] embedding: provider: ollama_compatible model: nomic-embed-text-v2-moe dimensions: 768 llm_policy: allowed: [zai/glm-5.2] `); const paths: RuntimePaths = { sessions: "/data/workspaces/psd-clinical/sessions", artifacts: "/data/workspaces/psd-clinical/artifacts", indexes: "/data/workspaces/psd-clinical/indexes", }; const legacyWorkspace = parseWorkspaceYaml(`workspace: schema_version: 1 id: psd-clinical name: Policlinico San Donato language: it dwh: engine: postgres database: postgres schema: datawarehouse supported_transports: [postgres_direct] semantic_index: vector_store: engine: pgvector collection: clinical_documents dimensions: 768 distance: cosine supported_transports: [pgvector_direct] embedding: provider: ollama_compatible model: nomic-embed-text-v2-moe dimensions: 768 llm_policy: allowed: [zai/glm-5.2] `); const directBindings: RuntimeBindings = { dwh: { transport: "postgres_direct", missing: [], values: { THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal", THT_WS_PSD_CLINICAL_DWH_PORT: "5432", THT_WS_PSD_CLINICAL_DWH_USER: "thoth_reader", THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: "/run/secrets/dwh-password", THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE: "/run/secrets/dwh-ca.pem", }, }, vector: { transport: "pgvector_direct", missing: [], values: { THT_WS_PSD_CLINICAL_VECTOR_HOST: "vector.internal", THT_WS_PSD_CLINICAL_VECTOR_PORT: "5432", THT_WS_PSD_CLINICAL_VECTOR_USER: "vector_reader", THT_WS_PSD_CLINICAL_VECTOR_PASSWORD_FILE: "/run/secrets/vector-password", THT_WS_PSD_CLINICAL_VECTOR_TLS_CA_FILE: "/run/secrets/vector-ca.pem", }, }, vectorWriter: { transport: "rest_api", missing: [], values: {} }, embedding: { transport: "rest_api", missing: [], values: { THT_WS_PSD_CLINICAL_EMBEDDING_BASE_URL: "http://embedding.internal:11434" }, }, }; test("runtime support stays fail-closed for either SSH connector", () => { expect(supportsSessionRuntime(directBindings)).toBe(true); expect(supportsSessionRuntime({ ...directBindings, dwh: { ...directBindings.dwh, transport: "ssh_tunnel" }, })).toBe(false); expect(supportsSessionRuntime({ ...directBindings, vector: { ...directBindings.vector, transport: "ssh_tunnel" }, })).toBe(false); }); test("renders a direct PostgreSQL binding to the legacy harness shape", () => { const yaml = renderRuntimeConfig(workspace, directBindings, paths, { workspaceId: "psd-clinical", workspaceRevision: "a".repeat(40), }); const rendered = parse(yaml); expect(rendered).toMatchObject({ runtime_identity: { workspace_id: "psd-clinical", workspace_revision: "a".repeat(40), source_identity: "workspace://psd-clinical", }, language: "it", database: { host: "dwh.internal", port: 5432, database: "postgres", schema: "datawarehouse", user: "thoth_reader", password_file: "/run/secrets/dwh-password", ssl_ca_file: "/run/secrets/dwh-ca.pem", transport: "direct", }, vector_db: { host: "vector.internal", database: "postgres", schema: "vectors", password_file: "/run/secrets/vector-password", ssl_ca_file: "/run/secrets/vector-ca.pem", }, embeddings: { base_url: "http://embedding.internal:11434", model: "nomic-embed-text-v2-moe", dim: 768, }, paths, }); expect(yaml).toContain("type: postgres_direct"); expect(yaml).toContain("schema: datawarehouse"); }); test("refuses to render a v1 descriptor until an explicit migration creates v2", () => { expect(() => renderRuntimeConfig(legacyWorkspace, directBindings, paths)).toThrow(/migrat/i); }); test("omits direct TLS fields when binding validation did not retain a file path", () => { const dwhValues = { ...directBindings.dwh.values }; const vectorValues = { ...directBindings.vector.values }; delete dwhValues.THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE; delete vectorValues.THT_WS_PSD_CLINICAL_VECTOR_TLS_CA_FILE; const yaml = renderRuntimeConfig(workspace, { ...directBindings, dwh: { ...directBindings.dwh, values: dwhValues, }, vector: { ...directBindings.vector, values: vectorValues, }, }, paths); const rendered = parse(yaml); expect(rendered.database).not.toHaveProperty("ssl_ca_file"); expect(rendered.vector_db).not.toHaveProperty("ssl_ca_file"); }); test("renders REST bindings through the legacy rest sections without secret values", () => { const yaml = renderRuntimeConfig(workspace, { ...directBindings, dwh: { transport: "rest_api", missing: [], values: { THT_WS_PSD_CLINICAL_DWH_BASE_URL: "https://dwh.example.test", THT_WS_PSD_CLINICAL_DWH_API_KEY_FILE: "/run/secrets/dwh-api-key", THT_WS_PSD_CLINICAL_DWH_TLS_CA_FILE: "/run/secrets/ca.pem", }, }, vector: { transport: "rest_api", missing: [], values: { THT_WS_PSD_CLINICAL_VECTOR_BASE_URL: "https://vector.example.test", THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE: "/run/secrets/vector-api-key", }, }, }, paths); const rendered = parse(yaml); expect(rendered).toMatchObject({ database: { transport: "rest", schema: "datawarehouse" }, rest: { base_url: "https://dwh.example.test", api_key_file: "/run/secrets/dwh-api-key", ssl_ca_file: "/run/secrets/ca.pem", }, vector_rest: { base_url: "https://vector.example.test", api_key_file: "/run/secrets/vector-api-key", }, }); expect(yaml).not.toContain("\n api_key: "); });