package overlay import ( "strings" "testing" ) func TestTheNetworkCarriesRegistryTrust(t *testing.T) { // novox/hq ADR 0082: being on the network is what grants a machine the right to pull from the // mesh's artifact store in the clear, so the network module writes the runtime's trust — and // writes nothing when the mesh has no store to trust. nodes := []Node{ {Name: "anchor", Site: "lab", Hub: true, Endpoint: "192.0.2.10:51820", Key: "k1", Address: "10.42.0.1"}, {Name: "node2", Site: "lab", Key: "k2", Address: "10.42.0.2"}, } g, err := From(nodes, "10.42.0.0/16", "") if err != nil { t.Fatal(err) } plain, _, err := g.Resources("node2") if err != nil { t.Fatal(err) } for _, r := range plain { if r["id"] == "registry-trust" { t.Fatal("trust was written with no artifact store to trust") } } g.TrustRegistry("anchor.internal:5000") trusted, part, err := g.Resources("node2") if err != nil || !part { t.Fatalf("resources: %v part=%v", err, part) } var file, service map[string]any for _, r := range trusted { switch r["id"] { case "registry-trust": file = r case "registry-trust-reload": service = r } } if file == nil || service == nil { t.Fatalf("the trust file or its reload is missing: %v", trusted) } if file["path"] != "/etc/docker/daemon.json" || file["merge"] != "json" { t.Fatalf("the trust is not a merged daemon.json: %v", file) } if content, _ := file["content"].(string); !strings.Contains(content, `"anchor.internal:5000"`) { t.Fatalf("the trust does not name the store: %v", file["content"]) } if service["unit"] != "docker.service" { t.Fatalf("the reload does not restart the runtime: %v", service) } }