package overlay import ( "fmt" "strings" "testing" ) func TestTheNetworkCarriesRegistryTrust(t *testing.T) { // novox/hq ADR 0082: being on the network is what grants a machine the right to pull from the // mesh's artifact store in the clear, so the network module writes the runtime's trust — and // writes nothing when the mesh has no store to trust. nodes := []Node{ {Name: "anchor", Site: "lab", Hub: true, Endpoint: "192.0.2.10:51820", Key: "k1", Address: "10.42.0.1"}, {Name: "node2", Site: "lab", Key: "k2", Address: "10.42.0.2"}, } g, err := From(nodes, "10.42.0.0/16", "") if err != nil { t.Fatal(err) } plain, _, err := g.Resources("node2") if err != nil { t.Fatal(err) } for _, r := range plain { if r["id"] == "registry-trust" { t.Fatal("trust was written with no artifact store to trust") } } g.TrustRegistry("anchor.internal:5000") trusted, part, err := g.Resources("node2") if err != nil || !part { t.Fatalf("resources: %v part=%v", err, part) } var file, service map[string]any for _, r := range trusted { switch r["id"] { case "registry-trust": file = r case "registry-trust-reload": service = r } } if file == nil || service == nil { t.Fatalf("the trust file or its reload is missing: %v", trusted) } if file["path"] != "/etc/docker/daemon.json" || file["merge"] != "json" || file["into"] != "json" { t.Fatalf("the trust is not written into daemon.json (ADR 0102): %v", file) } if content, _ := file["content"].(string); !strings.Contains(content, `"anchor.internal:5000"`) { t.Fatalf("the trust does not name the store: %v", file["content"]) } if service["unit"] != "docker.service" { t.Fatalf("the reload is not the runtime's: %v", service) } // Reloaded, never restarted: a restart stops every container on the machine (ADR 0102). if _, restarts := service["restart-on"]; restarts { t.Fatalf("the runtime is restarted for its trust: %v", service) } if fmt.Sprint(service["reload-on"]) != "[registry-trust]" { t.Fatalf("the runtime is not reloaded for its trust: %v", service) } }