A machine runs many consumers of one provision, each with its own credential. When one module leaks its credential, `rotate <provision> --consumer <machine>` was the narrowest act and replaced every module's on that machine, restarting all of them. --module (and the verb's module argument beside provision) rotates only that module's.
28 lines
1.0 KiB
Go
28 lines
1.0 KiB
Go
package main
|
|
|
|
import (
|
|
"testing"
|
|
|
|
"github.com/novox/mesh-controller/internal/inventory"
|
|
)
|
|
|
|
// One consuming module's credential, and not its neighbours' on the same machine (novox/hq issue
|
|
// 268): a module that leaked its database password is no reason to restart every other consumer.
|
|
func TestARotationNarrowedToAModuleTouchesOnlyThatModulesCredential(t *testing.T) {
|
|
holders := []inventory.Holder{
|
|
{Provision: "postgres-database", Consumer: "ace", ConsumerModule: "letta", Provider: "ace"},
|
|
{Provision: "postgres-database", Consumer: "ace", ConsumerModule: "n8n", Provider: "ace"},
|
|
{Provision: "postgres-database", Consumer: "ace", ConsumerModule: "letta", Local: "reader", Provider: "ace"},
|
|
}
|
|
got := ofModule(holders, "letta")
|
|
if len(got) != 2 || got[0].ConsumerModule != "letta" || got[1].Local != "reader" {
|
|
t.Fatalf("narrowed to letta: %+v", got)
|
|
}
|
|
if len(ofModule(holders, "")) != 3 {
|
|
t.Fatal("no module named narrowed anyway")
|
|
}
|
|
if len(ofModule(holders, "absent")) != 0 {
|
|
t.Fatal("a module holding nothing matched")
|
|
}
|
|
}
|