package catalogue import ( "strings" "testing" ) // novox/hq issue 190, step 5 (ADR 0222): what the mesh computes for a module is held to the rule // every module is — no two modules on a machine declare one path, unit, name or package. The // private network once declared the container runtime's file and service beside the runtime's own // module, and nothing refused it, because the collision check only ever saw catalogue manifests. func runtimesOwn() Manifest { return Manifest{Module: "docker", Resources: []map[string]any{ {"id": "daemon", "type": "file", "path": "/etc/docker/daemon.json", "into": "json", "content": `{"live-restore": true}`}, {"id": "runtime", "type": "service", "unit": "docker.service", "state": "running", "reload-on": []any{"daemon"}}, }} } func TestAGeneratedResourceCollidingWithAModulesIsRefused(t *testing.T) { r := Resolution{Node: "workstation", Modules: []Manifest{ {Module: "mesh-network", Computed: "mesh-network", Provides: Offers("private-network")}, runtimesOwn(), }} _, err := r.Declaration(Rendering{Generators: map[string]Generator{"mesh-network": reloading{}}}) if err == nil { t.Fatal("a generated resource declaring the runtime's file beside the runtime's module was accepted") } for _, want := range []string{"mesh-network", "docker", "/etc/docker/daemon.json", "docker.service"} { if !strings.Contains(err.Error(), want) { t.Errorf("the refusal does not name %s: %v", want, err) } } } func TestAGeneratedResourceBesideAModulesOwnIsComposed(t *testing.T) { r := Resolution{Node: "workstation", Modules: []Manifest{ {Module: "mesh-network", Computed: "mesh-network", Provides: Offers("private-network")}, runtimesOwn(), }} gen := &fake{on: map[string]bool{"workstation": true}} out, err := r.Declaration(Rendering{Generators: map[string]Generator{"mesh-network": gen}}) if err != nil { t.Fatalf("disjoint resources were refused: %v", err) } if fileNamed(out, "docker.daemon") == nil { t.Fatalf("the runtime's own file is missing: %v", out) } // And a machine not on the network yet generates nothing, which collides with nothing. if _, err := r.Declaration(Rendering{Generators: map[string]Generator{"mesh-network": &fake{}}}); err != nil { t.Fatalf("a machine off the network was refused: %v", err) } } // The catalogue's container runtime module states the mesh's registry itself (ADR 0222). func TestTheRuntimesModuleTrustsTheMeshsRegistry(t *testing.T) { docker := catalogueManifest(t, "docker") r := Resolution{Node: "workstation", Modules: []Manifest{docker}} out, err := r.Declaration(Rendering{ SeatReach: map[string]string{"mesh-artifact-store": "anchor.internal:5100"}, }) if err != nil { t.Fatal(err) } daemon := fileNamed(out, "docker.daemon") if daemon == nil || daemon["into"] != "json" { t.Fatalf("the runtime's file is not written into: %v", daemon) } content, _ := daemon["content"].(string) if !strings.Contains(content, `"insecure-registries": ["anchor.internal:5100"]`) || !strings.Contains(content, `"live-restore": true`) { t.Fatalf("the runtime's file says %q", content) } out, err = r.Declaration(Rendering{}) if err != nil { t.Fatal(err) } if content, _ := fileNamed(out, "docker.daemon")["content"].(string); strings.Contains(content, "insecure-registries") { t.Fatalf("with no store on the network, the runtime is told %q", content) } }