The controller's tools can issue a module its bus account
A module's account was mintable only from the controller's command line, so a rollout that gave a module one could not be finished through the mesh's own tools (novox/hq issue 191). The issue verb runs module issue for a module on a machine; the caller pushes the machine after.
This commit is contained in:
@@ -73,6 +73,22 @@ func TestRotateTakesAProvisionOrAnOwnSecret(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// `issue` is `module issue` at a shell: the module and the machine, and nothing that would push. A
|
||||
// module's bus account was mintable only from the controller's command line, so an agent working
|
||||
// through the tools could not finish a rollout that gave a module one (novox/hq issue 191).
|
||||
func TestIssueGivesAModuleItsAccountOnAMachine(t *testing.T) {
|
||||
argv, err := argvFor("issue", map[string]any{"node": "ace", "module": "route-proxy"})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if strings.Join(argv, " ") != "module issue route-proxy --node ace" {
|
||||
t.Fatalf("issue runs %v", argv)
|
||||
}
|
||||
if _, err := argvFor("issue", map[string]any{"module": "route-proxy"}); err == nil {
|
||||
t.Error("an account was issued without saying which machine reads it")
|
||||
}
|
||||
}
|
||||
|
||||
// A required argument missing is refused in the verb's own words, before anything runs.
|
||||
func TestAVerbMissingWhatItNeedsIsRefused(t *testing.T) {
|
||||
if _, err := argvFor("node", map[string]any{}); err == nil || !strings.Contains(err.Error(), `node needs "node"`) {
|
||||
|
||||
Reference in New Issue
Block a user