From eb02b8fe6bbb8816ae0ccdfef14d009746c6fe4e Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 1 Sep 2026 03:06:59 +0200 Subject: [PATCH] Assert the whole of what keycloak is given, not one file's name MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The credential moved: the sealed password is a password alone, at `.secret`, and `database.env` is now the connection keycloak could not have written — address and port from what the provider serves, user name from what the mesh decided both ends would call this consumer. So the test asks for both, and for the seam between them: the password is still a hole, the sealed value travels beside the file that needs it, and no ${bound:...} survives as a value. That last one matters most — a placeholder written through would be read as a hostname, and the failure would name neither the module nor the mesh. --- test/integration/mesh.test.ts | 26 ++++++++++++++++++++++++-- 1 file changed, 24 insertions(+), 2 deletions(-) diff --git a/test/integration/mesh.test.ts b/test/integration/mesh.test.ts index c11cba9..f48f905 100644 --- a/test/integration/mesh.test.ts +++ b/test/integration/mesh.test.ts @@ -1714,12 +1714,34 @@ test("the real modules resolve together, and compose a declaration a host accept assert.match(JSON.stringify(bound), /postgres/, "keycloak's binding does not name what answered its requirement"); + // The password, alone in a file and sealed. It is a password and nothing else, so nothing reads + // it as configuration — novox/hq 04-ISSUES/023 and the playbook both turn on that distinction. const credential = [...byId.values()].find((r) => - r.type === "file" && r.path === "/var/lib/keycloak/database.env"); - assert.ok(credential, "keycloak was given no credential for its database"); + r.type === "file" && r.path === "/var/lib/keycloak/database.secret"); + assert.ok(credential, `keycloak was given no credential for its database: ${ids.join(", ")}`); assert.ok(credential.sealed, "keycloak's credential is not sealed, so the mesh can read it"); assert.ok(!credential.content, "a credential arrived as content rather than sealed"); + // And the connection itself, which keycloak could not have written: the address and port come + // from what the provider serves, and the user name from what the mesh decided both ends would + // call this consumer (novox/hq 04-ISSUES/023). + const connection = [...byId.values()].find((r) => + r.type === "file" && r.path === "/var/lib/keycloak/database.env"); + assert.ok(connection, "keycloak was given no database configuration"); + assert.match(connection.content, /KC_DB_USERNAME=mesh_[a-z0-9_]+_keycloak/, + `keycloak was not told what name to present:\n${connection.content}`); + assert.doesNotMatch(connection.content, /\$\{bound:/, + `a placeholder reached the machine as a value:\n${connection.content}`); + + // The password is the one hole left open, and the sealed value travels beside it. The mesh + // discarded the plaintext, so the host is the only thing that can close it. + assert.match(connection.content, /KC_DB_PASSWORD=\$\{secret:postgres-database\}/, + `the password was not left for the host to fill:\n${connection.content}`); + assert.ok(connection.secrets?.["postgres-database"], + "the sealed credential did not travel with the file that needs it"); + assert.doesNotMatch(JSON.stringify(connection.content), /postgres-database":"[A-Za-z0-9+/]{24,}/, + "the credential was written into the configuration in the clear"); + // And the provider was told who asked, which is what its provisioner reconciles against. const grants = [...byId.values()].find((r) => r.type === "file" && String(r.path).startsWith("/var/lib/postgres/grants"));