Name ADR 0007 in the connectivity tests that defend it

Certificates, filtering, hub filtering and wildcard resolution were all
proven here without naming the decision they defend. novox/hq ADR 0017.
This commit is contained in:
2026-08-31 17:33:34 +02:00
parent 17e7132532
commit 61f864a274
+6
View File
@@ -482,6 +482,7 @@ test("the mesh runs its own artifact store", {
"the artifact store is not reachable from another machine, so nothing else can use it");
});
// Defends novox/hq ADR 0007: the mesh is its own certificate authority for internal names.
test("a machine serves its internal name with a certificate the mesh issued", {
skip, timeout: 900_000,
}, async () => {
@@ -525,6 +526,8 @@ test("a machine serves its internal name with a certificate the mesh issued", {
assert.match(shook.out, /Verification: OK/, shook.out);
});
// Defends novox/hq ADR 0007: what a machine exposes is what its modules declared, and nothing
// arrives at a port nobody asked for.
test("a machine filters exactly what its modules declared, and nothing else", {
skip, timeout: 900_000,
}, async () => {
@@ -1192,6 +1195,7 @@ test("the board names the machine that is not doing what it was told", {
await mesh("push laptop");
});
// Defends novox/hq ADR 0007: filtering the hub must not cut the overlay it carries.
test("the hub can be filtered without severing the mesh", {
skip, timeout: 900_000,
}, async () => {
@@ -1307,6 +1311,8 @@ test("a container reaches another machine by the name the mesh gave it", {
await mesh("push laptop");
});
// Defends novox/hq ADR 0007: a name under a machine is that machine, without the mesh being
// told each one.
test("every name under a machine resolves to that machine", {
skip, timeout: 900_000,
}, async () => {