events: an e2e test — an emitted event reaches the audit trail over the mesh's broker #2

Merged
jschoubben merged 78 commits from events/audit-e2e into initialization 2026-09-05 01:07:06 +00:00
Showing only changes of commit cbd9b647ec - Show all commits
+13 -15
View File
@@ -27,21 +27,16 @@ const capability = await labIsUsable();
const binary = hostBinaryPath();
const bundle = process.env["MESH_LAB_BUNDLE"] ?? "";
// Blocked on novox/hq 04-ISSUES/010: the mesh derives `as` = mesh_<node>_<module> (e.g.
// `mesh_anchor_bucketuser`, 22 chars), and an S3 access key is capped at 20 — minio refuses to
// create the service account under it. This test is correct and will pass once the mesh's login
// fits S3's identifier rules; skipped (before hook and test both) until that is decided, rather than
// made to pass by working around the derivation. Remove `blocked ||` to run it once 010 is fixed.
const blocked = "blocked on 04-ISSUES/010 — the mesh's `as` exceeds minio's S3 access-key limit (3–20)";
const skip = blocked
|| (!capability.usable
? `lab not usable: ${capability.why}`
: !binary || !existsSync(binary)
? "MESH_LAB_HOST_BINARY is not set to a built mesh-host"
: !bundle || !existsSync(bundle)
? "MESH_LAB_BUNDLE is not set to a substrate bundle (mesh-host examples/)"
: false);
// 04-ISSUES/010 is fixed by ADR 0054: an S3 access key is capped at 20, and the mesh derives
// `mesh_<node>_<module>`, so `bucketuser` on `anchor` (22) would overflow — but a consumer declares a
// short `slug` and its identity fits. This bed's consumer does exactly that.
const skip = !capability.usable
? `lab not usable: ${capability.why}`
: !binary || !existsSync(binary)
? "MESH_LAB_HOST_BINARY is not set to a built mesh-host"
: !bundle || !existsSync(bundle)
? "MESH_LAB_BUNDLE is not set to a substrate bundle (mesh-host examples/)"
: false;
const SCENARIO = "minio-node";
const MACHINE = "anchor";
@@ -204,6 +199,9 @@ test("the mesh grants a consumer an S3 bucket, and the credential it delivers re
const consumerManifest = JSON.stringify({
module: "bucketuser",
version: "1",
// A short slug, so the derived identity `mesh_anchor_bkt` fits an S3 access key's 20 chars where
// `mesh_anchor_bucketuser` (22) would not (novox/hq ADR 0054, 04-ISSUES/010).
slug: "bkt",
requires: ["s3-bucket"],
contributes: { "s3-bucket": { name: "bucketuser" } },
binds: { "s3-bucket": "/var/lib/bucketuser/s3.json" },