events: an e2e test — an emitted event reaches the audit trail over the mesh's broker #2
@@ -192,13 +192,13 @@ test("a credential reaches both ends and the mesh holds neither", { skip, timeou
|
||||
// The whole argument, on real machines: the two ends must hold the SAME password, and it must
|
||||
// appear nowhere the mesh or the broker could read it.
|
||||
await must("anchor", `printf %s '{"module":"postgres","version":"1",` +
|
||||
`"provides":[{"name":"database","scope":"mesh"}],"serves":{"database":{"port":5432}},` +
|
||||
`"grants":{"database":"/var/lib/mesh-host/grants"},` +
|
||||
`"receives":{"database":"/var/lib/mesh-host/grants/mesh.json"},"resources":[]}' > /tmp/pg.json`);
|
||||
`"provides":[{"name":"postgres-database","scope":"mesh"}],"serves":{"postgres-database":{"port":5432}},` +
|
||||
`"grants":{"postgres-database":"/var/lib/mesh-host/grants"},` +
|
||||
`"receives":{"postgres-database":"/var/lib/mesh-host/grants/mesh.json"},"resources":[]}' > /tmp/pg.json`);
|
||||
await must("anchor", `printf %s '{"module":"meshboard","version":"1",` +
|
||||
`"requires":["database"],"contributes":{"database":{"name":"meshboard"}},` +
|
||||
`"binds":{"database":"/etc/meshboard/database.json"},` +
|
||||
`"secrets":{"database":"/etc/meshboard/database.password"},"resources":[]}' > /tmp/app.json`);
|
||||
`"requires":["postgres-database"],"contributes":{"postgres-database":{"name":"meshboard"}},` +
|
||||
`"binds":{"postgres-database":"/etc/meshboard/database.json"},` +
|
||||
`"secrets":{"postgres-database":"/etc/meshboard/database.password"},"resources":[]}' > /tmp/app.json`);
|
||||
await must("anchor", `docker cp /tmp/pg.json mesh-control:/pg.json`);
|
||||
await must("anchor", `docker cp /tmp/app.json mesh-control:/app.json`);
|
||||
await mesh("module add /pg.json");
|
||||
@@ -771,21 +771,21 @@ test("rotating a credential moves both ends, and the old one stops working", {
|
||||
// holding a matching string proves they agree; only an authentication proves they are right.
|
||||
const store = "/var/lib/mesh/postgres";
|
||||
await must("anchor", `printf %s '{"module":"realstore","version":"1",` +
|
||||
`"provides":[{"name":"realdatabase","scope":"mesh"}],` +
|
||||
`"provides":[{"name":"realpostgres-database","scope":"mesh"}],` +
|
||||
`"capabilities":["container-runtime"],` +
|
||||
`"serves":{"realdatabase":{"port":5433}},` +
|
||||
`"serves":{"realpostgres-database":{"port":5433}},` +
|
||||
`"own-secrets":{"superuser":"${store}/superuser"},` +
|
||||
`"grants":{"realdatabase":"${store}/grants"},` +
|
||||
`"grants":{"realpostgres-database":"${store}/grants"},` +
|
||||
// Both halves. `grants` is where each consumer's sealed password lands; `receives` is the
|
||||
// manifest saying who asked and for what. Without the second the provisioner finds a
|
||||
// directory of unexplained secrets and says nothing has been granted — which is true, and
|
||||
// reads exactly like a credential that was never delivered.
|
||||
`"receives":{"realdatabase":"${store}/grants/mesh.json"},` +
|
||||
`"receives":{"realpostgres-database":"${store}/grants/mesh.json"},` +
|
||||
`"listens":[{"port":5433,"from":"mesh","why":"a database the mesh provisions"}],` +
|
||||
`"resources":[` +
|
||||
`{"id":"state","type":"directory","path":"${store}","mode":"0755"},` +
|
||||
`{"id":"grants","type":"directory","path":"${store}/grants","mode":"0755"},` +
|
||||
`{"id":"database","type":"container","name":"real-store",` +
|
||||
`{"id":"postgres-database","type":"container","name":"real-store",` +
|
||||
`"image":"${pinned("postgres")}",` +
|
||||
`"ports":["5433:5432"],` +
|
||||
`"volumes":["${store}/superuser:/run/superuser:ro"],` +
|
||||
@@ -798,9 +798,9 @@ test("rotating a credential moves both ends, and the old one stops working", {
|
||||
`"MESH_PROVISION_POSTGRES":"postgres://postgres@127.0.0.1:5433/postgres?sslmode=disable"}}]}' ` +
|
||||
`> /tmp/realstore.json`);
|
||||
await must("anchor", `printf %s '{"module":"realapp","version":"1",` +
|
||||
`"requires":["realdatabase"],"contributes":{"realdatabase":{"name":"realapp"}},` +
|
||||
`"binds":{"realdatabase":"/etc/realapp/where.json"},` +
|
||||
`"secrets":{"realdatabase":"/etc/realapp/password"},` +
|
||||
`"requires":["realpostgres-database"],"contributes":{"realpostgres-database":{"name":"realapp"}},` +
|
||||
`"binds":{"realpostgres-database":"/etc/realapp/where.json"},` +
|
||||
`"secrets":{"realpostgres-database":"/etc/realapp/password"},` +
|
||||
`"resources":[{"id":"dir","type":"directory","path":"/etc/realapp","mode":"0755"}]}' ` +
|
||||
`> /tmp/realapp.json`);
|
||||
for (const f of ["realstore", "realapp"]) {
|
||||
|
||||
@@ -75,7 +75,7 @@ async function meshWrote(
|
||||
): Promise<void> {
|
||||
const manifest = {
|
||||
contributions: 1,
|
||||
requirement: "database",
|
||||
requirement: "postgres-database",
|
||||
generated: "by the mesh",
|
||||
given: consumers.map((c) => ({
|
||||
from: c.module,
|
||||
@@ -247,7 +247,7 @@ test("a manifest naming a credential that was never written is refused", { skip,
|
||||
// report until something tried to connect.
|
||||
await meshWrote([]);
|
||||
await must(
|
||||
`printf %s '{"contributions":1,"requirement":"database","given":[` +
|
||||
`printf %s '{"contributions":1,"requirement":"postgres-database","given":[` +
|
||||
`{"from":"meshboard","node":"ghost","secret":"${GRANTS}/ghost.secret","values":{"name":"ghost"}}` +
|
||||
`]}' > ${GRANTS}/mesh.json`,
|
||||
);
|
||||
|
||||
Reference in New Issue
Block a user