daemon.json and docker.service belong to the docker module, which holds node-container-runtime
and now states the registry itself through ${seat:mesh-artifact-store:reach} (hq ADR 0222). The
overlay stops generating registry-trust and registry-trust-reload. A generated resource is now
held to the collision check every module is, so a second writer cannot come back through
computed code; resolution never saw what a generator declares.
85 lines
3.3 KiB
Go
85 lines
3.3 KiB
Go
package catalogue
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// novox/hq issue 190, step 5 (ADR 0222): what the mesh computes for a module is held to the rule
|
|
// every module is — no two modules on a machine declare one path, unit, name or package. The
|
|
// private network once declared the container runtime's file and service beside the runtime's own
|
|
// module, and nothing refused it, because the collision check only ever saw catalogue manifests.
|
|
|
|
func runtimesOwn() Manifest {
|
|
return Manifest{Module: "docker", Resources: []map[string]any{
|
|
{"id": "daemon", "type": "file", "path": "/etc/docker/daemon.json", "into": "json",
|
|
"content": `{"live-restore": true}`},
|
|
{"id": "runtime", "type": "service", "unit": "docker.service", "state": "running",
|
|
"reload-on": []any{"daemon"}},
|
|
}}
|
|
}
|
|
|
|
func TestAGeneratedResourceCollidingWithAModulesIsRefused(t *testing.T) {
|
|
r := Resolution{Node: "workstation", Modules: []Manifest{
|
|
{Module: "mesh-network", Computed: "mesh-network", Provides: Offers("private-network")},
|
|
runtimesOwn(),
|
|
}}
|
|
_, err := r.Declaration(Rendering{Generators: map[string]Generator{"mesh-network": reloading{}}})
|
|
if err == nil {
|
|
t.Fatal("a generated resource declaring the runtime's file beside the runtime's module was accepted")
|
|
}
|
|
for _, want := range []string{"mesh-network", "docker", "/etc/docker/daemon.json", "docker.service"} {
|
|
if !strings.Contains(err.Error(), want) {
|
|
t.Errorf("the refusal does not name %s: %v", want, err)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestAGeneratedResourceBesideAModulesOwnIsComposed(t *testing.T) {
|
|
r := Resolution{Node: "workstation", Modules: []Manifest{
|
|
{Module: "mesh-network", Computed: "mesh-network", Provides: Offers("private-network")},
|
|
runtimesOwn(),
|
|
}}
|
|
gen := &fake{on: map[string]bool{"workstation": true}}
|
|
out, err := r.Declaration(Rendering{Generators: map[string]Generator{"mesh-network": gen}})
|
|
if err != nil {
|
|
t.Fatalf("disjoint resources were refused: %v", err)
|
|
}
|
|
if fileNamed(out, "docker.daemon") == nil {
|
|
t.Fatalf("the runtime's own file is missing: %v", out)
|
|
}
|
|
// And a machine not on the network yet generates nothing, which collides with nothing.
|
|
if _, err := r.Declaration(Rendering{Generators: map[string]Generator{"mesh-network": &fake{}}}); err != nil {
|
|
t.Fatalf("a machine off the network was refused: %v", err)
|
|
}
|
|
}
|
|
|
|
// The catalogue's container runtime module states the mesh's registry itself (ADR 0222).
|
|
func TestTheRuntimesModuleTrustsTheMeshsRegistry(t *testing.T) {
|
|
docker := catalogueManifest(t, "docker")
|
|
r := Resolution{Node: "workstation", Modules: []Manifest{docker}}
|
|
out, err := r.Declaration(Rendering{
|
|
SeatReach: map[string]string{"mesh-artifact-store": "anchor.internal:5100"},
|
|
})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
daemon := fileNamed(out, "docker.daemon")
|
|
if daemon == nil || daemon["into"] != "json" {
|
|
t.Fatalf("the runtime's file is not written into: %v", daemon)
|
|
}
|
|
content, _ := daemon["content"].(string)
|
|
if !strings.Contains(content, `"insecure-registries": ["anchor.internal:5100"]`) ||
|
|
!strings.Contains(content, `"live-restore": true`) {
|
|
t.Fatalf("the runtime's file says %q", content)
|
|
}
|
|
|
|
out, err = r.Declaration(Rendering{})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if content, _ := fileNamed(out, "docker.daemon")["content"].(string); strings.Contains(content, "insecure-registries") {
|
|
t.Fatalf("with no store on the network, the runtime is told %q", content)
|
|
}
|
|
}
|