Files
ThothII/harness/tests/test_workspace.py
T
marcopan 276717005d fix(harness): drop THOTH_SSL_CA from REQUIRED_L2 + isolate profile in workspace test
Two fixes found while unblocking the L2 setup:

1. conftest: THOTH_SSL_CA is NOT an L2 prerequisite. The DWH endpoint presents a
   public cert (*.policlinicosandonato.it, signed by GoDaddy), already in the
   certifi bundle, so the REST clients validate TLS with verify=True -- no CA file
   needed. The ssl_ca line was commented out in ChironeWp3's nsp.yaml too.

2. test_workspace: the profile-default assertion collided with the operator's real
   harness/.env once load_dotenv (D3) started injecting THOTH_PROFILE into the
   process env. The test now dels THOTH_PROFILE to assert the actual *default*
   (server), regardless of what the operator set in .env.

Suite: 109 passed.
2026-06-27 06:45:00 +02:00

84 lines
3.2 KiB
Python

from pathlib import Path
from nsp.workspace import load_workspace, WorkspaceError
def test_load_workspace_expands_env_vars(monkeypatch, tmp_path):
# Isolate profile: load_dotenv (conftest D3) injects THOTH_PROFILE from the real
# harness/.env into os.environ; this test asserts the *default* (server), so it
# must del THOTH_PROFILE rather than inherit whatever the operator set.
monkeypatch.delenv("THOTH_PROFILE", raising=False)
monkeypatch.setenv("THOTH_VEC_API_KEY", "secret-reader")
monkeypatch.setenv("THOTH_VEC_WRITE_API_KEY", "secret-writer")
monkeypatch.setenv("THOTH_VEC_REST_URL", "https://example/vector/v1/")
monkeypatch.setenv("THOTH_DWH_REST_URL", "https://example/dwh/")
monkeypatch.setenv("THOTH_DWH_API_KEY", "dwh-key")
monkeypatch.setenv("THOTH_DB_HOST", "h")
monkeypatch.setenv("THOTH_DB_NAME", "db")
monkeypatch.setenv("THOTH_DB_USER", "u")
monkeypatch.setenv("THOTH_DB_PASSWORD", "p")
monkeypatch.setenv("THOTH_VEC_HOST", "vh")
monkeypatch.setenv("THOTH_VEC_USER", "vu")
monkeypatch.setenv("THOTH_VEC_PASSWORD", "vp")
monkeypatch.setenv("THOTH_OLLAMA_URL", "http://ollama")
monkeypatch.setenv("THOTH_DOCS_ROOT", str(tmp_path / "docs"))
yaml = tmp_path / "w.yaml"
yaml.write_text(
"database:\n"
" host: ${THOTH_DB_HOST}\n"
" port: 5432\n"
" database: ${THOTH_DB_NAME}\n"
" schema: datawarehouse\n"
" user: ${THOTH_DB_USER}\n"
" password: ${THOTH_DB_PASSWORD}\n"
" transport: rest\n"
"rest:\n"
" base_url: ${THOTH_DWH_REST_URL}\n"
" api_key: ${THOTH_DWH_API_KEY}\n"
"vector_db:\n"
" host: ${THOTH_VEC_HOST}\n"
" port: 5438\n"
" database: postgres\n"
" schema: vectors\n"
" user: ${THOTH_VEC_USER}\n"
" password: ${THOTH_VEC_PASSWORD}\n"
"vector_rest:\n"
" base_url: ${THOTH_VEC_REST_URL}\n"
" api_key: ${THOTH_VEC_API_KEY}\n"
"vector_write_rest:\n"
" base_url: ${THOTH_VEC_REST_URL}\n"
" api_key: ${THOTH_VEC_WRITE_API_KEY}\n"
"embeddings:\n"
" base_url: ${THOTH_OLLAMA_URL}\n"
" model: nomic-embed-text-v2-moe\n"
" dim: 768\n"
"evidence:\n"
" source_root: ${THOTH_DOCS_ROOT}\n"
)
ws = load_workspace(yaml)
# Dual vector key (top-level, per Config reale): reader and writer separate
assert ws.vector_rest.api_key == "secret-reader"
assert ws.vector_write_rest.api_key == "secret-writer"
# DWH key distinct from vector keys
assert ws.rest.api_key == "dwh-key"
# profile default = server
assert ws.profile == "server"
def test_load_workspace_missing_env_raises(monkeypatch, tmp_path):
monkeypatch.delenv("THOTH_VEC_API_KEY", raising=False)
yaml = tmp_path / "w.yaml"
yaml.write_text(
"database:\n"
" host: h\n port: 5432\n database: db\n schema: s\n"
" user: u\n password: p\n transport: direct\n"
"vector_rest:\n"
" base_url: 'https://v/'\n"
" api_key: '${THOTH_VEC_API_KEY}'\n"
)
try:
load_workspace(yaml)
assert False, "should have raised"
except WorkspaceError as e:
assert "THOTH_VEC_API_KEY" in str(e)