diff --git a/test/integration/one-node-mesh.test.ts b/test/integration/one-node-mesh.test.ts index 5b73a83..7785589 100644 --- a/test/integration/one-node-mesh.test.ts +++ b/test/integration/one-node-mesh.test.ts @@ -660,9 +660,25 @@ before(async () => { said.push(` plan every image pinned, no placeholders`); // And the catalogue, ASKED rather than observed. These five questions are what it exists for. + // **Asked as an operator would have to, which turns out to be nobody.** + // + // The obvious move — run the invoke inside the catalogue's own container — is refused by the + // broker: `User 'anchor-mesh-catalog' doesn't have permissions to queue 'amq.gen-…'`. A + // module's account is scoped to what it declares it emits and consumes, and calling a tool + // needs a temporary reply queue, which that scope does not cover. So a module can SERVE tools + // and cannot CALL them, and nothing issues an account to anyone who wants to ask (novox/hq + // issue 049). + // + // Until that is decided, the caller is the substrate's own admin account over the broker's + // loopback — the bootstrap case `mesh-tools` documents, reached the way genesis reaches a + // substrate container, by joining its network namespace. + const image = (await on(CONTROL, + `docker inspect -f '{{.Config.Image}}' mesh-catalog`)).out.trim(); const ask = async (tool: string, args = "{}") => - must(CONTROL, `docker exec mesh-catalog node /app/dist/main.js invoke mesh-catalog ` + - `${tool} ${quote(args)}`, + must(CONTROL, + `docker run --rm --network container:mesh-broker ` + + `-e MESH_BROKER_URL=amqp://guest:guest@127.0.0.1:5672/ ` + + `${image} invoke mesh-catalog ${tool} ${quote(args)}`, 120_000); const held = await ask("catalog_modules");