From 2e0f11dfc2106b56980e8cedb062dd2472e90412 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 21 Sep 2026 23:25:36 +0200 Subject: [PATCH] Three beds give their fixtures names that are no catalogue module's (issue 074) --- test/beds-read-the-catalogue.test.ts | 4 ---- test/integration/mesh.test.ts | 16 ++++++++-------- .../provider-uses-mesh-credential.test.ts | 10 +++++----- .../runtime-restart-on-config.test.ts | 12 ++++++------ 4 files changed, 19 insertions(+), 23 deletions(-) diff --git a/test/beds-read-the-catalogue.test.ts b/test/beds-read-the-catalogue.test.ts index 39bfcdf..d1d7cfd 100644 --- a/test/beds-read-the-catalogue.test.ts +++ b/test/beds-read-the-catalogue.test.ts @@ -54,10 +54,6 @@ const STILL_CARRIED: Record = { why: "DIFFERS: redis mints its own secret, baserow drops its route requirement, letta drops its ports" }, "lavinmq-bed.test.ts": { modules: ["lavinmq", "amqp-ping"], why: "BESIDE (lavinmq, with a bootstrap step and a data directory the catalogue has not got); DIFFERS (amqp-ping names its entrypoint)" }, - "provider-uses-mesh-credential.test.ts": { modules: ["redis"], why: "WEARING: a credential mechanism test" }, - "runtime-restart-on-config.test.ts": { modules: ["grafana"], why: "WEARING: a restart mechanism test" }, - "mesh.test.ts": { modules: ["postgres", "builder", "umami"], - why: "WEARING: a postgres with no resources, a builder that builds itself, an umami that is another module of that name" }, }; const beds = resolve(import.meta.dirname, "integration"); diff --git a/test/integration/mesh.test.ts b/test/integration/mesh.test.ts index 46487cd..c78b762 100644 --- a/test/integration/mesh.test.ts +++ b/test/integration/mesh.test.ts @@ -318,7 +318,7 @@ test("both machines join it, and the token is all they need", { skip, timeout: 9 test("a credential reaches both ends and the mesh holds neither", { skip, timeout: 900_000 }, async () => { // The whole argument, on real machines: the two ends must hold the SAME password, and it must // appear nowhere the mesh or the broker could read it. - await must("anchor", `printf %s '{"module":"postgres","version":"1",` + + await must("anchor", `printf %s '{"module":"a-store","version":"1",` + `"provides":[{"name":"postgres-database","scope":"mesh"}],"serves":{"postgres-database":{"port":5432}},` + `"grants":{"postgres-database":"/var/lib/mesh-host/grants"},` + `"receives":{"postgres-database":"/var/lib/mesh-host/grants/mesh.json"},"resources":[]}' > /tmp/pg.json`); @@ -342,7 +342,7 @@ test("a credential reaches both ends and the mesh holds neither", { skip, timeou await mesh("overlay place anchor --hub --endpoint 192.0.2.10:51820 --site lab"); await mesh("overlay place laptop --site lab"); for (const node of ["anchor", "laptop"]) await mesh(`assign ${node} networking`); - await mesh("assign anchor postgres"); + await mesh("assign anchor a-store"); await mesh("assign laptop meshboard"); for (const machine of ["anchor", "laptop"]) { @@ -824,7 +824,7 @@ test("the builder is a module the mesh assigns, with a credential the mesh deliv // // So: the mesh issues a scoped account, seals it to the machine, and delivers it with the // declaration. Nobody types it and the mesh cannot read it back. - await must("anchor", `mkdir -p /root/builder && printf %s '{"module":"builder","version":"1",` + + await must("anchor", `mkdir -p /root/builder && printf %s '{"module":"self-builder","version":"1",` + `"requires":["artifact-store"],"capabilities":["container-runtime"],` + `"claims":[{"name":"the-build-machine","scope":"node"}],` + `"binds":{"artifact-store":"/var/lib/mesh/builder/artifact-store.json"},` + @@ -865,7 +865,7 @@ test("the builder is a module the mesh assigns, with a credential the mesh deliv assert.ok(!(await on("anchor", `pgrep -x mesh-builder`)).ok, "the hand-started builder is still running, so this would test that one"); - await mesh("assign anchor builder"); + await mesh("assign anchor self-builder"); await mesh("push anchor"); await new Promise((r) => setTimeout(r, 20_000)); @@ -1671,7 +1671,7 @@ test("a third-party workload is adopted, with the credential it already had", { const password = "the-password-it-already-had"; await must("anchor", `printf %s ${quote(JSON.stringify({ - module: "umami", + module: "adopted-analytics", version: "1", capabilities: ["container-runtime"], "own-secrets": { @@ -1707,13 +1707,13 @@ test("a third-party workload is adopted, with the credential it already had", { // seals it and cannot read it again. Given whole, as the environment lines the containers read. await must("anchor", `printf %s ${quote(`POSTGRES_PASSWORD=${password}`)} | ` + - `docker exec -i mesh-controller /mesh-controller secret accept anchor umami database --from -`); + `docker exec -i mesh-controller /mesh-controller secret accept anchor adopted-analytics database --from -`); await must("anchor", `printf %s ${quote( `DATABASE_URL=postgresql://umami:${password}@umami-db:5432/umami`)} | ` + - `docker exec -i mesh-controller /mesh-controller secret accept anchor umami app --from -`); + `docker exec -i mesh-controller /mesh-controller secret accept anchor adopted-analytics app --from -`); - await mesh("assign anchor umami"); + await mesh("assign anchor adopted-analytics"); await mesh("push anchor", 300_000); // Both containers, and the network they share. diff --git a/test/integration/provider-uses-mesh-credential.test.ts b/test/integration/provider-uses-mesh-credential.test.ts index c5bffb8..6bad589 100644 --- a/test/integration/provider-uses-mesh-credential.test.ts +++ b/test/integration/provider-uses-mesh-credential.test.ts @@ -145,7 +145,7 @@ test("redis creates a consumer's login with the password the mesh minted, sealin // (MESH_RECEIVES). There is NO MESH_SEAL_KEY — the whole point of ADR 0048 is that a provider // needs none. const manifest = JSON.stringify({ - module: "redis", + module: "a-cache", version: "1", emits: ["module.redis.cache.provisioned", "module.redis.cache.deprovisioned"], consumes: ["module.redis.cache.provisioned", "module.redis.cache.deprovisioned"], @@ -184,10 +184,10 @@ test("redis creates a consumer's login with the password the mesh minted, sealin }, ], }); - await must(`printf %s ${quote(manifest)} > /tmp/redis.json && docker cp /tmp/redis.json mesh-controller:/redis.json`); - await mesh("module add /redis.json"); - await mesh(`module issue redis --node ${MACHINE}`); - await mesh(`assign ${MACHINE} redis`); + await must(`printf %s ${quote(manifest)} > /tmp/a-cache.json && docker cp /tmp/a-cache.json mesh-controller:/a-cache.json`); + await mesh("module add /a-cache.json"); + await mesh(`module issue a-cache --node ${MACHINE}`); + await mesh(`assign ${MACHINE} a-cache`); await mesh(`push ${MACHINE}`); await settled(); diff --git a/test/integration/runtime-restart-on-config.test.ts b/test/integration/runtime-restart-on-config.test.ts index 5dc1bcb..1b5659f 100644 --- a/test/integration/runtime-restart-on-config.test.ts +++ b/test/integration/runtime-restart-on-config.test.ts @@ -113,7 +113,7 @@ async function settled(withinMs = 480_000): Promise { async function setToken(token: string): Promise { const settings = JSON.stringify({ url: "http://127.0.0.1:3000", token }); await must(`printf %s ${quote(settings)} > /tmp/s.json && docker cp /tmp/s.json mesh-controller:/s.json`); - await mesh(`settings set grafana /s.json --node ${MACHINE}`); + await mesh(`settings set a-runtime /s.json --node ${MACHINE}`); } async function containerId(): Promise { @@ -151,7 +151,7 @@ test("a running runtime is recreated when its settings change, and reads the new skip, timeout: 900_000, }, async () => { const manifest = JSON.stringify({ - module: "grafana", + module: "a-runtime", version: "1", emits: ["module.grafana.alert.firing"], "own-secrets": { broker: "/var/lib/mesh/grafana/broker" }, @@ -170,12 +170,12 @@ test("a running runtime is recreated when its settings change, and reads the new }, ], }); - await must(`printf %s ${quote(manifest)} > /tmp/grafana.json && docker cp /tmp/grafana.json mesh-controller:/grafana.json`); - await mesh("module add /grafana.json"); + await must(`printf %s ${quote(manifest)} > /tmp/a-runtime.json && docker cp /tmp/a-runtime.json mesh-controller:/a-runtime.json`); + await mesh("module add /a-runtime.json"); await setToken("token-alpha"); - await mesh(`module issue grafana --node ${MACHINE}`); - await mesh(`assign ${MACHINE} grafana`); + await mesh(`module issue a-runtime --node ${MACHINE}`); + await mesh(`assign ${MACHINE} a-runtime`); await mesh(`push ${MACHINE}`); await settled();