secret accept is refused for a name the module does not declare, and a pair delivery for a requirement or local it has not got (novox/hq issue 078)

This commit is contained in:
2026-09-21 23:31:06 +02:00
parent e4da83496f
commit 35c5c2bb9b
4 changed files with 148 additions and 11 deletions
+63 -6
View File
@@ -52,8 +52,10 @@ func twoNodesWithKeys(t *testing.T) (*Inventory, context.Context) {
// before it can (novox/hq 04-ISSUES/022). Two of them, because "two consumers on one node"
// is the case that key exists for.
for _, m := range []string{"gitea", "keycloak"} {
if err := inv.RegisterModule(ctx, catalogue.Manifest{Module: m, Version: "1"},
Source{}); err != nil {
// Each requires what a test delivers to it: a pair credential is refused for a
// requirement the module does not have (novox/hq 04-ISSUES/078).
if err := inv.RegisterModule(ctx, catalogue.Manifest{Module: m, Version: "1",
Requires: []string{"secret", "postgres-database"}}, Source{}); err != nil {
t.Fatal(err)
}
}
@@ -404,8 +406,8 @@ func TestACredentialGoesWhenEitherMachineDoes(t *testing.T) {
// secret was delivered — which it was.
func TestASecretTheMeshWasGivenIsNotReinventedWhenTheMachineRejoins(t *testing.T) {
inv, ctx := twoNodesWithKeys(t)
if err := inv.RegisterModule(ctx, catalogue.Manifest{Module: "builder", Version: "1"},
Source{}); err != nil {
if err := inv.RegisterModule(ctx, catalogue.Manifest{Module: "builder", Version: "1",
OwnSecrets: map[string]string{"broker": "/run/broker"}}, Source{}); err != nil {
t.Fatal(err)
}
const url = "amqps://builder:the-password-the-broker-was-told@broker/"
@@ -436,8 +438,8 @@ func TestASecretTheMeshWasGivenIsNotReinventedWhenTheMachineRejoins(t *testing.T
// that would make the refusal above useless if it were wrong.
func TestASecretTheMeshWasGivenSurvivesAnOrdinaryPush(t *testing.T) {
inv, ctx := twoNodesWithKeys(t)
if err := inv.RegisterModule(ctx, catalogue.Manifest{Module: "builder", Version: "1"},
Source{}); err != nil {
if err := inv.RegisterModule(ctx, catalogue.Manifest{Module: "builder", Version: "1",
OwnSecrets: map[string]string{"broker": "/run/broker"}}, Source{}); err != nil {
t.Fatal(err)
}
if err := inv.AcceptSecretForModule(ctx, "consumer", "builder", "broker",
@@ -715,3 +717,58 @@ func TestTheOperatorRecoversEachLocalNameApart(t *testing.T) {
t.Fatalf("the export does not name the local names: %v", kept)
}
}
// **A delivered secret is accepted only under a name the module declares** (novox/hq
// 04-ISSUES/078). A value stored under a name nothing reads is a delivery that changed nothing
// and reported success; refused, naming what the module does declare.
func TestADeliveredSecretIsRefusedUnderANameTheModuleDoesNotDeclare(t *testing.T) {
inv, ctx := twoNodesWithKeys(t)
if err := inv.RegisterModule(ctx, catalogue.Manifest{Module: "step-ca", Version: "1",
OwnSecrets: map[string]string{"password": "/run/password"}}, Source{}); err != nil {
t.Fatal(err)
}
err := inv.AcceptSecretForModule(ctx, "consumer", "step-ca", "root-key", "not-a-key")
if err == nil {
t.Fatal("a secret delivered under a name the module does not declare was accepted")
}
for _, want := range []string{"root-key", "password"} {
if !strings.Contains(err.Error(), want) {
t.Errorf("the refusal does not say %q: %v", want, err)
}
}
if err := inv.AcceptSecretForModule(ctx, "consumer", "step-ca", "password", "hunter2"); err != nil {
t.Fatalf("a secret delivered under a declared name was refused: %v", err)
}
// A module the mesh does not know is said, not stored.
err = inv.AcceptSecretForModule(ctx, "consumer", "nobody", "password", "hunter2")
if err == nil || !strings.Contains(err.Error(), "module add") {
t.Errorf("a delivery to an unknown module was not refused with the remedy: %v", err)
}
}
func TestADeliveredPairCredentialIsRefusedForARequirementTheModuleDoesNotHave(t *testing.T) {
inv, ctx := twoNodesWithKeys(t)
// gitea requires secret and postgres-database (the fixture); not an object store.
err := inv.AcceptSecretForPair(ctx, "object-store", "consumer", "gitea", "provider", "", "hunter2")
if err == nil || !strings.Contains(err.Error(), "postgres-database") {
t.Fatalf("a pair credential for a requirement the module does not have was not refused naming what it requires: %v", err)
}
// A module keeping several secrets for one requirement (ADR 0094) takes a delivery only
// under one of its locals.
m := catalogue.Manifest{Module: "mailu", Version: "1", Requires: []string{"secret"},
SecretsMany: map[string]map[string]string{"secret": {"admin": "/run/admin", "api-token": "/run/api-token"}}}
if err := inv.RegisterModule(ctx, m, Source{}); err != nil {
t.Fatal(err)
}
err = inv.AcceptSecretForPair(ctx, "secret", "consumer", "mailu", "provider", "", "hunter2")
if err == nil || !strings.Contains(err.Error(), "--local") {
t.Errorf("a delivery to a module keeping several secrets, with no local named, was not refused: %v", err)
}
err = inv.AcceptSecretForPair(ctx, "secret", "consumer", "mailu", "provider", "secret-key", "hunter2")
if err == nil || !strings.Contains(err.Error(), "api-token") {
t.Errorf("a delivery under a local the module does not keep was not refused naming the ones it keeps: %v", err)
}
if err := inv.AcceptSecretForPair(ctx, "secret", "consumer", "mailu", "provider", "admin", "hunter2"); err != nil {
t.Errorf("a delivery under a kept local was refused: %v", err)
}
}