A given own secret the module reads at start is held by nobody but that module, so the mesh need not read it to replace it: secret rotate now works on it, and a value given through secret accept is replaced on its own after the module's first good start under the mesh. Only a value an outside party issues (own-secrets "issued-by": "outside") or one the module applies stays as given, refused with the reason.
46 lines
1.9 KiB
Go
46 lines
1.9 KiB
Go
package main
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/novox/mesh-controller/internal/link"
|
|
)
|
|
|
|
// A rotation asked through the seat carries why to the command, which records it in the hand-act
|
|
// log (novox/hq ADR 0228); why with a provision is refused as passed over, not dropped.
|
|
func TestARotationThroughTheSeatCarriesWhy(t *testing.T) {
|
|
argv, err := argvFor("rotate", map[string]any{"node": "anchor", "module": "letta",
|
|
"secret": "server-password", "why": "leaked into logs", "cause": "leaked"})
|
|
if err != nil || strings.Join(argv, " ") != "secret rotate anchor letta server-password --why leaked into logs --cause leaked" {
|
|
t.Fatalf("%v %v", argv, err)
|
|
}
|
|
argv, err = argvFor("rotate", map[string]any{"node": "anchor", "module": "letta", "secret": "server-password"})
|
|
if err != nil || strings.Join(argv, " ") != "secret rotate anchor letta server-password" {
|
|
t.Fatalf("without why: %v %v", argv, err)
|
|
}
|
|
if argv, err := argvFor("rotate", map[string]any{"provision": "postgres-database", "why": "leaked"}); err == nil {
|
|
t.Fatalf("why beside a provision was passed over: %v", argv)
|
|
}
|
|
}
|
|
|
|
// Only a clean account of a declaration is a good start; a refusal, a failure or a bare word that
|
|
// the machine is there is not (novox/hq ADR 0228).
|
|
func TestAGoodStartIsACleanAccountOfADeclaration(t *testing.T) {
|
|
for _, c := range []struct {
|
|
report link.Report
|
|
good bool
|
|
}{
|
|
{link.Report{Node: "anchor", Declared: "d", Applied: []string{"container:letta"}}, true},
|
|
{link.Report{Node: "anchor", Declared: "d", Applied: []string{}}, true},
|
|
{link.Report{Node: "anchor"}, false},
|
|
{link.Report{Node: "anchor", Applied: []string{"x"}}, false},
|
|
{link.Report{Node: "anchor", Declared: "d", Applied: []string{"x"}, Failed: map[string]string{"y": "no"}}, false},
|
|
{link.Report{Node: "anchor", Declared: "d", Refused: "older"}, false},
|
|
} {
|
|
if got := startedWell(c.report); got != c.good {
|
|
t.Errorf("%+v: a good start = %v, want %v", c.report, got, c.good)
|
|
}
|
|
}
|
|
}
|