66 lines
3.5 KiB
Bash
66 lines
3.5 KiB
Bash
#!/usr/bin/env bash
|
|
# Disposable acceptance fixture, separate from the ThothII Metadata Catalog.
|
|
set -euo pipefail
|
|
umask 077
|
|
|
|
if [[ $# -ne 1 || "$1" != /* || -e "$1" ]]; then
|
|
echo 'Usage: bash scripts/prepare-chinook-test.sh /absolute/NEW-private-directory' >&2
|
|
exit 2
|
|
fi
|
|
test_dir="$1"
|
|
container="${CHINOOK_TEST_CONTAINER:-thothii-test-chinook}"
|
|
port="${CHINOOK_TEST_PORT:-55432}"
|
|
[[ "$container" =~ ^[a-zA-Z0-9][a-zA-Z0-9_.-]+$ ]] || exit 2
|
|
[[ "$port" =~ ^[1-9][0-9]{0,4}$ ]] && (( port <= 65535 )) || exit 2
|
|
for executable in docker curl openssl; do command -v "$executable" >/dev/null; done
|
|
docker info >/dev/null
|
|
if docker container inspect "$container" >/dev/null 2>&1; then
|
|
echo "Container $container already exists; this command never resets an existing database." >&2
|
|
exit 2
|
|
fi
|
|
mkdir "$test_dir"
|
|
test_dir="$(cd "$test_dir" && pwd -P)"
|
|
sql="$test_dir/Chinook_PostgreSql.sql"
|
|
curl --fail --location --proto '=https' --tlsv1.2 --max-time 120 \
|
|
'https://github.com/lerocha/chinook-database/releases/download/v1.4.5/Chinook_PostgreSql.sql' \
|
|
--output "$sql"
|
|
expected=e3fde5c1a5b51a2a91429a702c9ca6e69ba56e6c7f5e112724d70c3d03db695e
|
|
actual="$(openssl dgst -sha256 "$sql")"
|
|
[[ "${actual##* }" == "$expected" ]] || { echo 'Chinook checksum mismatch.' >&2; exit 1; }
|
|
openssl rand -hex 24 > "$test_dir/reader-password"
|
|
printf 'POSTGRES_PASSWORD=%s\n' "$(openssl rand -hex 24)" > "$test_dir/postgres.env"
|
|
printf '%s\n' "$container" > "$test_dir/container-name"
|
|
|
|
# Use the same PostgreSQL linux/amd64 image as the initial installation prerelease.
|
|
# PostgreSQL gets its own anonymous data volume; stop/start preserves it.
|
|
docker run --detach --name "$container" --platform linux/amd64 \
|
|
--publish "127.0.0.1:${port}:5432" \
|
|
--env-file "$test_dir/postgres.env" \
|
|
docker.io/library/postgres@sha256:45cd22f8d32e189d245403954882f88e7a8714301fda80dab6da90f1265b25a3 >/dev/null
|
|
ready=false
|
|
for ((attempt = 0; attempt < 90; attempt++)); do
|
|
# The entrypoint's temporary bootstrap server has only a Unix socket.
|
|
if docker exec "$container" pg_isready -h 127.0.0.1 -U postgres -d postgres >/dev/null 2>&1; then
|
|
ready=true
|
|
break
|
|
fi
|
|
sleep 1
|
|
done
|
|
[[ "$ready" == true ]] || { echo "PostgreSQL did not start. Inspect docker logs $container." >&2; exit 1; }
|
|
# The upstream script drops/recreates chinook: it is used only in this NEW container.
|
|
docker exec -i "$container" psql -X -U postgres -d postgres -v ON_ERROR_STOP=1 < "$sql" > "$test_dir/import.log" 2>&1
|
|
{
|
|
printf "CREATE ROLE thoth_reader LOGIN PASSWORD '%s';\n" "$(cat "$test_dir/reader-password")"
|
|
cat <<'SQL'
|
|
GRANT CONNECT ON DATABASE chinook TO thoth_reader;
|
|
GRANT USAGE ON SCHEMA public TO thoth_reader;
|
|
GRANT SELECT ON ALL TABLES IN SCHEMA public TO thoth_reader;
|
|
ALTER ROLE thoth_reader SET default_transaction_read_only = on;
|
|
SQL
|
|
} | docker exec -i "$container" psql -X -U postgres -d chinook -v ON_ERROR_STOP=1 > "$test_dir/reader-setup.log" 2>&1
|
|
docker exec "$container" psql -X -U postgres -d chinook -v ON_ERROR_STOP=1 -c \
|
|
"SELECT (SELECT count(*) FROM information_schema.tables WHERE table_schema='public' AND table_type='BASE TABLE') AS tables, (SELECT count(*) FROM track) AS tracks, (SELECT count(*) FROM invoice) AS invoices, (SELECT count(*) FROM invoice_line) AS invoice_lines;"
|
|
printf '\nReady: container=%s, host=127.0.0.1, port=%s, database=chinook, schema=public, user=thoth_reader\n' "$container" "$port"
|
|
printf 'Protected password file: %s/reader-password\n' "$test_dir"
|
|
printf 'Use this read-only account for ThothII. Evidence is absent. No ThothII stack was started.\n'
|