#!/usr/bin/env bash # Regression test for copyable installation examples and secret-path validation. set -euo pipefail root="$(cd "$(dirname "$0")/.." && pwd -P)" output="$(mktemp "${TMPDIR:-/tmp}/thoth-install-docs-test.XXXXXX")" trap 'rm -f "$output"' EXIT HUP INT TERM "$root/scripts/verify-workspace-install-docs.sh" --fixtures-only >"$output" for fixture in \ "local manual requires generated connector override and Compose preflight" \ "server manual requires generated connector override and Compose preflight" \ "local documented shell environment fixture" \ "server documented shell environment fixture" \ "copied local base fixture" \ "copied server PostgreSQL/TLS fixture" \ "copied HTTPS Git override fixture" \ "copied SSH Git override fixture" \ "copied connector binding/secret fixture" \ "core process sees connector bindings and secret files" \ "non-path secret-file fixture rejected" \ "literal secret-source fixture rejected" \ "relative secret-source fixture rejected" \ "non-normalized secret-source fixture rejected"; do grep -Fqx "$fixture passed" "$output" >/dev/null || { echo "missing fixture verification: $fixture" >&2 cat "$output" >&2 exit 1 } done for manual in \ "$root/docs/install/local-workspace-registry.md" \ "$root/docs/install/server-workspace-registry.md"; do grep -Fq 'export THT_SOURCE_ROOT=/absolute/path/to/ThothII' "$manual" || { echo "installation manual does not publish a self-contained THT_SOURCE_ROOT export: $manual" >&2 exit 1 } grep -Fq 'export THT_WORKSPACE_BINDINGS_ENV_FILE="$(pwd -P)/workspace-bindings.env"' "$manual" || { echo "installation manual does not publish a self-contained bindings export: $manual" >&2 exit 1 } if rg -n 'source[[:space:]]+\.env' "$manual"; then echo "installation manual unsafely imports operator .env: $manual" >&2 exit 1 fi done if rg -n 'connector-secrets\.workspace-registry|docker compose' \ "$root/docs/install/local-workspace-registry.md" \ "$root/docs/install/server-workspace-registry.md"; then echo "installation manuals still document a bypassed Compose or copied connector override path" >&2 exit 1 fi