A take acts on the preview it showed; a setting is judged where it is stored; a kept network and a minted secret are said (hq ADR 0163)
take ends its preview with a digest and --yes names it, as the flip does; a changed preview or an account older than the flip allows is refused. A module the machine holds nothing for has nothing to compare, and --yes suffices. A published port's reach is said as the machine reported it. Every secret the module holds on the machine is listed with where it came from, and one the mesh minted for a service whose data was found refuses unless --mint names it. One judgement of a module's settings against its definition, in the catalogue: settings set refuses what cannot compose or reaches nothing, naming node, module, layer and key; Compose leaves out a module whose definition moved under a stored setting, the envelope says so (left_out), plan and push say it by name, and the machine is told everything else. A stray setting no longer refuses the whole machine where it is read (issue 096). The per-machine setting networks keeps a found network for a taken container, on an adopted machine only; the container's declaration carries it and the preview names it (rule 4).
This commit is contained in:
@@ -934,3 +934,47 @@ func TestASharedCredentialIsOneValueSealedToEveryHolder(t *testing.T) {
|
||||
t.Fatalf("a consumer binding after an acceptance must be refused with the way out: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
// SecretsOf is every secret a module holds on a machine with where each came from — what a take
|
||||
// reads to refuse minting over a service that already has a value (novox/hq ADR 0163, rule 2).
|
||||
func TestSecretsOfSaysEachSecretsOriginAndProvider(t *testing.T) {
|
||||
inv, ctx := twoNodesWithKeys(t)
|
||||
if err := inv.RegisterModule(ctx, catalogue.Manifest{Module: "forge", Version: "1",
|
||||
Requires: []string{"secret", "postgres-database"},
|
||||
Secrets: map[string]string{"secret": "/run/secret", "postgres-database": "/run/pg"},
|
||||
OwnSecrets: catalogue.OwnSecrets{"admin": {Path: "/run/admin"}}}, Source{}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := inv.SecretForModule(ctx, "consumer", "forge", "admin"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := inv.SecretFor(ctx, "postgres-database", "consumer", "forge", "provider", ""); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := inv.AcceptSecretForPair(ctx, "secret", "consumer", "forge", "provider", "", "hunter2"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
got, err := inv.SecretsOf(ctx, "consumer", "forge")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
want := []SecretState{
|
||||
{Name: "admin", Origin: OriginMade},
|
||||
{Name: "postgres-database", Origin: OriginMade, Provider: "provider"},
|
||||
{Name: "secret", Origin: OriginAccepted, Provider: "provider"},
|
||||
}
|
||||
if len(got) != len(want) {
|
||||
t.Fatalf("got %+v", got)
|
||||
}
|
||||
for i := range want {
|
||||
if got[i] != want[i] {
|
||||
t.Errorf("secret %d: got %+v, want %+v", i, got[i], want[i])
|
||||
}
|
||||
}
|
||||
if !got[0].Own() || got[1].Own() {
|
||||
t.Error("own and required are not told apart")
|
||||
}
|
||||
if other, _ := inv.SecretsOf(ctx, "consumer", "gitea"); len(other) != 0 {
|
||||
t.Fatalf("another module's secrets: %+v", other)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user