events: an e2e test — an emitted event reaches the audit trail over the mesh's broker #2

Merged
jschoubben merged 78 commits from events/audit-e2e into initialization 2026-09-05 01:07:06 +00:00
Showing only changes of commit 2c7e69f4db - Show all commits
+17 -6
View File
@@ -1710,16 +1710,31 @@ test("a third-party workload is adopted, with the credential it already had", {
// would live.
test("the real modules resolve together, and compose a declaration a host accepts", {
skip, timeout: 300_000,
}, async () => {
}, async (t) => {
const modules = ["postgres", "keycloak", "gitea", "minio", "mailu"];
for (const name of modules) {
const raw = readFileSync(
`${process.env["MESH_LAB_MODULES"]}/${name}.json`, "utf8");
await must("anchor", `printf %s ${quote(raw)} > /${name}.json`);
// Pointed at this scenario's registry before being added, exactly as the forge is.
//
// **Not cosmetic.** Some of these name an image the mesh builds, whose digest does not exist
// until it is built — so the file legitimately carries a placeholder, and composing a
// declaration from it is refused (novox/hq 04-ISSUES/025). Planning what could never run is
// what this test used to do.
const pinned = pinnedInto(raw, stocked);
await must("anchor", `printf %s ${quote(pinned)} > /${name}.json`);
await must("anchor", `docker cp /${name}.json mesh-control:/${name}.json`);
await mesh(`module add /${name}.json`);
}
// **Put the machine back whatever happens.** Tests here share one mesh, so what this one
// assigns is what the next one inherits. Written at the end of the body once, it was skipped
// the first time this test failed — and the next test's push was refused by a module this one
// had left behind, which reads as a fault in the test that was actually working.
t.after(async () => {
for (const name of modules) await mesh(`unassign anchor ${name}`).catch(() => {});
});
// Assigned one at a time, because assignment resolves the whole set and says so immediately.
// A refusal here is the graph rejecting something, which is the point of asking.
for (const name of modules) {
@@ -1802,10 +1817,6 @@ test("the real modules resolve together, and compose a declaration a host accept
}
}
// Put the machine back. **Tests here share one mesh**, so what this one assigns is what the
// next one inherits — and this one assigns five modules whose images are mostly not stocked.
// Planning them is harmless; leaving them assigned makes the next push try to start them.
for (const name of modules) await mesh(`unassign anchor ${name}`);
});
// The first of the real module descriptions to actually run.