Three beds give their fixtures names that are no catalogue module's (issue 074)

This commit is contained in:
2026-09-21 23:25:36 +02:00
parent e1739b1caf
commit 2e0f11dfc2
4 changed files with 19 additions and 23 deletions
+8 -8
View File
@@ -318,7 +318,7 @@ test("both machines join it, and the token is all they need", { skip, timeout: 9
test("a credential reaches both ends and the mesh holds neither", { skip, timeout: 900_000 }, async () => {
// The whole argument, on real machines: the two ends must hold the SAME password, and it must
// appear nowhere the mesh or the broker could read it.
await must("anchor", `printf %s '{"module":"postgres","version":"1",` +
await must("anchor", `printf %s '{"module":"a-store","version":"1",` +
`"provides":[{"name":"postgres-database","scope":"mesh"}],"serves":{"postgres-database":{"port":5432}},` +
`"grants":{"postgres-database":"/var/lib/mesh-host/grants"},` +
`"receives":{"postgres-database":"/var/lib/mesh-host/grants/mesh.json"},"resources":[]}' > /tmp/pg.json`);
@@ -342,7 +342,7 @@ test("a credential reaches both ends and the mesh holds neither", { skip, timeou
await mesh("overlay place anchor --hub --endpoint 192.0.2.10:51820 --site lab");
await mesh("overlay place laptop --site lab");
for (const node of ["anchor", "laptop"]) await mesh(`assign ${node} networking`);
await mesh("assign anchor postgres");
await mesh("assign anchor a-store");
await mesh("assign laptop meshboard");
for (const machine of ["anchor", "laptop"]) {
@@ -824,7 +824,7 @@ test("the builder is a module the mesh assigns, with a credential the mesh deliv
//
// So: the mesh issues a scoped account, seals it to the machine, and delivers it with the
// declaration. Nobody types it and the mesh cannot read it back.
await must("anchor", `mkdir -p /root/builder && printf %s '{"module":"builder","version":"1",` +
await must("anchor", `mkdir -p /root/builder && printf %s '{"module":"self-builder","version":"1",` +
`"requires":["artifact-store"],"capabilities":["container-runtime"],` +
`"claims":[{"name":"the-build-machine","scope":"node"}],` +
`"binds":{"artifact-store":"/var/lib/mesh/builder/artifact-store.json"},` +
@@ -865,7 +865,7 @@ test("the builder is a module the mesh assigns, with a credential the mesh deliv
assert.ok(!(await on("anchor", `pgrep -x mesh-builder`)).ok,
"the hand-started builder is still running, so this would test that one");
await mesh("assign anchor builder");
await mesh("assign anchor self-builder");
await mesh("push anchor");
await new Promise((r) => setTimeout(r, 20_000));
@@ -1671,7 +1671,7 @@ test("a third-party workload is adopted, with the credential it already had", {
const password = "the-password-it-already-had";
await must("anchor", `printf %s ${quote(JSON.stringify({
module: "umami",
module: "adopted-analytics",
version: "1",
capabilities: ["container-runtime"],
"own-secrets": {
@@ -1707,13 +1707,13 @@ test("a third-party workload is adopted, with the credential it already had", {
// seals it and cannot read it again. Given whole, as the environment lines the containers read.
await must("anchor",
`printf %s ${quote(`POSTGRES_PASSWORD=${password}`)} | ` +
`docker exec -i mesh-controller /mesh-controller secret accept anchor umami database --from -`);
`docker exec -i mesh-controller /mesh-controller secret accept anchor adopted-analytics database --from -`);
await must("anchor",
`printf %s ${quote(
`DATABASE_URL=postgresql://umami:${password}@umami-db:5432/umami`)} | ` +
`docker exec -i mesh-controller /mesh-controller secret accept anchor umami app --from -`);
`docker exec -i mesh-controller /mesh-controller secret accept anchor adopted-analytics app --from -`);
await mesh("assign anchor umami");
await mesh("assign anchor adopted-analytics");
await mesh("push anchor", 300_000);
// Both containers, and the network they share.