diff --git a/test/integration/mesh.test.ts b/test/integration/mesh.test.ts index 571476d..4cc9e1d 100644 --- a/test/integration/mesh.test.ts +++ b/test/integration/mesh.test.ts @@ -482,6 +482,7 @@ test("the mesh runs its own artifact store", { "the artifact store is not reachable from another machine, so nothing else can use it"); }); +// Defends novox/hq ADR 0007: the mesh is its own certificate authority for internal names. test("a machine serves its internal name with a certificate the mesh issued", { skip, timeout: 900_000, }, async () => { @@ -525,6 +526,8 @@ test("a machine serves its internal name with a certificate the mesh issued", { assert.match(shook.out, /Verification: OK/, shook.out); }); +// Defends novox/hq ADR 0007: what a machine exposes is what its modules declared, and nothing +// arrives at a port nobody asked for. test("a machine filters exactly what its modules declared, and nothing else", { skip, timeout: 900_000, }, async () => { @@ -1192,6 +1195,7 @@ test("the board names the machine that is not doing what it was told", { await mesh("push laptop"); }); +// Defends novox/hq ADR 0007: filtering the hub must not cut the overlay it carries. test("the hub can be filtered without severing the mesh", { skip, timeout: 900_000, }, async () => { @@ -1307,6 +1311,8 @@ test("a container reaches another machine by the name the mesh gave it", { await mesh("push laptop"); }); +// Defends novox/hq ADR 0007: a name under a machine is that machine, without the mesh being +// told each one. test("every name under a machine resolves to that machine", { skip, timeout: 900_000, }, async () => {