diff --git a/test/integration/mesh.test.ts b/test/integration/mesh.test.ts index c11cba9..f48f905 100644 --- a/test/integration/mesh.test.ts +++ b/test/integration/mesh.test.ts @@ -1714,12 +1714,34 @@ test("the real modules resolve together, and compose a declaration a host accept assert.match(JSON.stringify(bound), /postgres/, "keycloak's binding does not name what answered its requirement"); + // The password, alone in a file and sealed. It is a password and nothing else, so nothing reads + // it as configuration — novox/hq 04-ISSUES/023 and the playbook both turn on that distinction. const credential = [...byId.values()].find((r) => - r.type === "file" && r.path === "/var/lib/keycloak/database.env"); - assert.ok(credential, "keycloak was given no credential for its database"); + r.type === "file" && r.path === "/var/lib/keycloak/database.secret"); + assert.ok(credential, `keycloak was given no credential for its database: ${ids.join(", ")}`); assert.ok(credential.sealed, "keycloak's credential is not sealed, so the mesh can read it"); assert.ok(!credential.content, "a credential arrived as content rather than sealed"); + // And the connection itself, which keycloak could not have written: the address and port come + // from what the provider serves, and the user name from what the mesh decided both ends would + // call this consumer (novox/hq 04-ISSUES/023). + const connection = [...byId.values()].find((r) => + r.type === "file" && r.path === "/var/lib/keycloak/database.env"); + assert.ok(connection, "keycloak was given no database configuration"); + assert.match(connection.content, /KC_DB_USERNAME=mesh_[a-z0-9_]+_keycloak/, + `keycloak was not told what name to present:\n${connection.content}`); + assert.doesNotMatch(connection.content, /\$\{bound:/, + `a placeholder reached the machine as a value:\n${connection.content}`); + + // The password is the one hole left open, and the sealed value travels beside it. The mesh + // discarded the plaintext, so the host is the only thing that can close it. + assert.match(connection.content, /KC_DB_PASSWORD=\$\{secret:postgres-database\}/, + `the password was not left for the host to fill:\n${connection.content}`); + assert.ok(connection.secrets?.["postgres-database"], + "the sealed credential did not travel with the file that needs it"); + assert.doesNotMatch(JSON.stringify(connection.content), /postgres-database":"[A-Za-z0-9+/]{24,}/, + "the credential was written into the configuration in the clear"); + // And the provider was told who asked, which is what its provisioner reconciles against. const grants = [...byId.values()].find((r) => r.type === "file" && String(r.path).startsWith("/var/lib/postgres/grants"));