A given own secret the module reads at start is held by nobody but that module, so the mesh need not read it to replace it: secret rotate now works on it, and a value given through secret accept is replaced on its own after the module's first good start under the mesh. Only a value an outside party issues (own-secrets "issued-by": "outside") or one the module applies stays as given, refused with the reason.
51 lines
2.3 KiB
Go
51 lines
2.3 KiB
Go
package broker_test
|
|
|
|
import (
|
|
"slices"
|
|
"testing"
|
|
|
|
"github.com/novox/mesh-controller/internal/broker"
|
|
"github.com/novox/mesh-controller/internal/catalogue"
|
|
"github.com/novox/mesh-controller/internal/conditions"
|
|
"github.com/novox/mesh-controller/internal/link"
|
|
)
|
|
|
|
// The facts the control plane states are named twice — in the grant that permits them and in the code
|
|
// that states them — because `link` imports `broker` and the dependency cannot go the other way. So a
|
|
// test keeps them agreeing: a subject the grant omits is refused at the moment the mesh has something
|
|
// to say, and one the grant adds that nothing states is authority nobody uses.
|
|
//
|
|
// An external test package, because it may import both while neither imports the other.
|
|
func TestTheFactsTheGrantPermitsAreTheFactsTheMeshStates(t *testing.T) {
|
|
if broker.ControllerSeat != link.MeshControllerSeat {
|
|
t.Fatalf("the grant is written for the %q seat and the mesh states its facts under %q",
|
|
broker.ControllerSeat, link.MeshControllerSeat)
|
|
}
|
|
// And what is wrong, as it changes, and the self-check's heartbeat (novox/hq to-be 45 §2, §4).
|
|
states := append([]string{link.KeyApplied, link.KeyRefused, link.KeyBuiltBefore}, conditions.Events...)
|
|
states = append(states, conditions.HeartbeatEvent)
|
|
// And a value given by hand, replaced after its module's first good start (novox/hq ADR 0228).
|
|
states = append(states, link.KeySecretReplaced)
|
|
for _, event := range states {
|
|
if !slices.Contains(broker.ControllerStates, event) {
|
|
t.Errorf("the mesh states %q and its account may not publish it", event)
|
|
}
|
|
}
|
|
if len(broker.ControllerStates) != len(states) {
|
|
t.Errorf("the grant permits %v, which is more than the mesh states", broker.ControllerStates)
|
|
}
|
|
// **And the seat says it.** A seat carries the protocol of its role (novox/hq ADR 0129), so the
|
|
// facts the control plane states are the seat's `emits` — which is what lets anything else declare
|
|
// that it consumes them, and what the subject-agreement check reads to know they have an owner.
|
|
var declared []string
|
|
for _, seat := range catalogue.SeatsWithAProtocol() {
|
|
if seat.Name == broker.ControllerSeat {
|
|
declared = seat.Emits
|
|
}
|
|
}
|
|
if !slices.Equal(declared, broker.ControllerStates) {
|
|
t.Errorf("the %s seat emits %v and the grant permits %v", broker.ControllerSeat,
|
|
declared, broker.ControllerStates)
|
|
}
|
|
}
|