diff --git a/test/integration/mesh.test.ts b/test/integration/mesh.test.ts index 63f42fc..571476d 100644 --- a/test/integration/mesh.test.ts +++ b/test/integration/mesh.test.ts @@ -192,13 +192,13 @@ test("a credential reaches both ends and the mesh holds neither", { skip, timeou // The whole argument, on real machines: the two ends must hold the SAME password, and it must // appear nowhere the mesh or the broker could read it. await must("anchor", `printf %s '{"module":"postgres","version":"1",` + - `"provides":[{"name":"database","scope":"mesh"}],"serves":{"database":{"port":5432}},` + - `"grants":{"database":"/var/lib/mesh-host/grants"},` + - `"receives":{"database":"/var/lib/mesh-host/grants/mesh.json"},"resources":[]}' > /tmp/pg.json`); + `"provides":[{"name":"postgres-database","scope":"mesh"}],"serves":{"postgres-database":{"port":5432}},` + + `"grants":{"postgres-database":"/var/lib/mesh-host/grants"},` + + `"receives":{"postgres-database":"/var/lib/mesh-host/grants/mesh.json"},"resources":[]}' > /tmp/pg.json`); await must("anchor", `printf %s '{"module":"meshboard","version":"1",` + - `"requires":["database"],"contributes":{"database":{"name":"meshboard"}},` + - `"binds":{"database":"/etc/meshboard/database.json"},` + - `"secrets":{"database":"/etc/meshboard/database.password"},"resources":[]}' > /tmp/app.json`); + `"requires":["postgres-database"],"contributes":{"postgres-database":{"name":"meshboard"}},` + + `"binds":{"postgres-database":"/etc/meshboard/database.json"},` + + `"secrets":{"postgres-database":"/etc/meshboard/database.password"},"resources":[]}' > /tmp/app.json`); await must("anchor", `docker cp /tmp/pg.json mesh-control:/pg.json`); await must("anchor", `docker cp /tmp/app.json mesh-control:/app.json`); await mesh("module add /pg.json"); @@ -771,21 +771,21 @@ test("rotating a credential moves both ends, and the old one stops working", { // holding a matching string proves they agree; only an authentication proves they are right. const store = "/var/lib/mesh/postgres"; await must("anchor", `printf %s '{"module":"realstore","version":"1",` + - `"provides":[{"name":"realdatabase","scope":"mesh"}],` + + `"provides":[{"name":"realpostgres-database","scope":"mesh"}],` + `"capabilities":["container-runtime"],` + - `"serves":{"realdatabase":{"port":5433}},` + + `"serves":{"realpostgres-database":{"port":5433}},` + `"own-secrets":{"superuser":"${store}/superuser"},` + - `"grants":{"realdatabase":"${store}/grants"},` + + `"grants":{"realpostgres-database":"${store}/grants"},` + // Both halves. `grants` is where each consumer's sealed password lands; `receives` is the // manifest saying who asked and for what. Without the second the provisioner finds a // directory of unexplained secrets and says nothing has been granted — which is true, and // reads exactly like a credential that was never delivered. - `"receives":{"realdatabase":"${store}/grants/mesh.json"},` + + `"receives":{"realpostgres-database":"${store}/grants/mesh.json"},` + `"listens":[{"port":5433,"from":"mesh","why":"a database the mesh provisions"}],` + `"resources":[` + `{"id":"state","type":"directory","path":"${store}","mode":"0755"},` + `{"id":"grants","type":"directory","path":"${store}/grants","mode":"0755"},` + - `{"id":"database","type":"container","name":"real-store",` + + `{"id":"postgres-database","type":"container","name":"real-store",` + `"image":"${pinned("postgres")}",` + `"ports":["5433:5432"],` + `"volumes":["${store}/superuser:/run/superuser:ro"],` + @@ -798,9 +798,9 @@ test("rotating a credential moves both ends, and the old one stops working", { `"MESH_PROVISION_POSTGRES":"postgres://postgres@127.0.0.1:5433/postgres?sslmode=disable"}}]}' ` + `> /tmp/realstore.json`); await must("anchor", `printf %s '{"module":"realapp","version":"1",` + - `"requires":["realdatabase"],"contributes":{"realdatabase":{"name":"realapp"}},` + - `"binds":{"realdatabase":"/etc/realapp/where.json"},` + - `"secrets":{"realdatabase":"/etc/realapp/password"},` + + `"requires":["realpostgres-database"],"contributes":{"realpostgres-database":{"name":"realapp"}},` + + `"binds":{"realpostgres-database":"/etc/realapp/where.json"},` + + `"secrets":{"realpostgres-database":"/etc/realapp/password"},` + `"resources":[{"id":"dir","type":"directory","path":"/etc/realapp","mode":"0755"}]}' ` + `> /tmp/realapp.json`); for (const f of ["realstore", "realapp"]) { diff --git a/test/integration/provisioner.test.ts b/test/integration/provisioner.test.ts index 0ffa6c3..e65f4a8 100644 --- a/test/integration/provisioner.test.ts +++ b/test/integration/provisioner.test.ts @@ -75,7 +75,7 @@ async function meshWrote( ): Promise { const manifest = { contributions: 1, - requirement: "database", + requirement: "postgres-database", generated: "by the mesh", given: consumers.map((c) => ({ from: c.module, @@ -247,7 +247,7 @@ test("a manifest naming a credential that was never written is refused", { skip, // report until something tried to connect. await meshWrote([]); await must( - `printf %s '{"contributions":1,"requirement":"database","given":[` + + `printf %s '{"contributions":1,"requirement":"postgres-database","given":[` + `{"from":"meshboard","node":"ghost","secret":"${GRANTS}/ghost.secret","values":{"name":"ghost"}}` + `]}' > ${GRANTS}/mesh.json`, );