diff --git a/test/integration/assigned-catalogue-apps.test.ts b/test/integration/assigned-catalogue-apps.test.ts index 8391c5e..a264809 100644 --- a/test/integration/assigned-catalogue-apps.test.ts +++ b/test/integration/assigned-catalogue-apps.test.ts @@ -215,6 +215,8 @@ test("the mesh assigns mongodb, unifi, marrytts and postgres to one node in one receives: { "mongodb-database": "/var/lib/mongodb/grants/mesh.json" }, grants: { "mongodb-database": "/var/lib/mongodb/grants" }, "own-secrets": { root: "/var/lib/mongodb/root.secret", broker: "/var/lib/mesh/mongodb/broker" }, + // The image drops to its own user before it reads the password file (ADR 0086; as the catalogue's). + "secrets-owner": "999:999", resources: [ { id: "mesh-state", type: "directory", path: "/var/lib/mesh/mongodb", mode: "0700" }, { id: "state", type: "directory", path: "/var/lib/mongodb", mode: "0700" }, @@ -413,7 +415,9 @@ test("the mesh assigns mongodb, unifi, marrytts and postgres to one node in one assert.doesNotMatch(mongoRes.out, /authentication failed/i, `mongodb delivered a credential that does not authenticate:\n${mongoRes.out}\n---runtime log---\n${(await on(`docker logs mesh-mongodb 2>&1 | tail -30`)).out}`); assert.match(mongoRes.out, /MONGO_OK/, - `the consumer could not use its granted database as ${mongoAs}:\n${mongoRes.out}`); + `the consumer could not use its granted database as ${mongoAs}:\n${mongoRes.out}\n---containers---\n` + + `${(await on(`docker ps -a --format '{{.Names}} {{.Status}}'`)).out}\n---mongo log---\n` + + `${(await on(`docker logs mongo 2>&1 | tail -15`)).out}`); // --- mongodb and unifi serve their tools over their scoped accounts ------------------------------- let served = "";