A run-once step may name what it reads: the pair run-once + restart-on is no longer refused (novox/hq ADR 0099)

This commit is contained in:
2026-09-21 23:31:06 +02:00
parent 52d39f0740
commit e4da83496f
2 changed files with 12 additions and 21 deletions
+7 -8
View File
@@ -77,17 +77,16 @@ func TestARunOnceMustBeABoolean(t *testing.T) {
}
}
func TestARunOnceContainerCannotAlsoDeclareRestartOn(t *testing.T) {
// restart-on brings a running container back; a run-once step does not stay running. The pair
// is a contradiction, refused at the manifest rather than surfacing far away on the host.
func TestARunOnceStepMayNameWhatItReads(t *testing.T) {
// For a step, restart-on means *run again* when what it reads changed: a gate that fetches a
// provider's root names the binding file it reads, so a provider that moved is fetched again
// (novox/hq ADR 0099). Accepted here, and the host's digest does the rest.
digest := "@sha256:" + strings.Repeat("a", 64)
bad := []byte(`{"module":"m","resources":[
good := []byte(`{"module":"m","resources":[
{"id":"conf","type":"file","path":"/x","content":"y"},
{"id":"seed","type":"container","name":"seed","image":"registry.example/x` + digest + `","run-once":true,"restart-on":["conf"]}
]}`)
if _, err := ParseManifest(bad); err == nil {
t.Error("a run-once container that also declared restart-on was accepted")
} else if !strings.Contains(err.Error(), "restart-on") {
t.Errorf("refused for the wrong reason: %v", err)
if _, err := ParseManifest(good); err != nil {
t.Errorf("a run-once step naming what it reads was refused: %v", err)
}
}