events: an e2e test — an emitted event reaches the audit trail over the mesh's broker #2
@@ -1714,12 +1714,34 @@ test("the real modules resolve together, and compose a declaration a host accept
|
||||
assert.match(JSON.stringify(bound), /postgres/,
|
||||
"keycloak's binding does not name what answered its requirement");
|
||||
|
||||
// The password, alone in a file and sealed. It is a password and nothing else, so nothing reads
|
||||
// it as configuration — novox/hq 04-ISSUES/023 and the playbook both turn on that distinction.
|
||||
const credential = [...byId.values()].find((r) =>
|
||||
r.type === "file" && r.path === "/var/lib/keycloak/database.env");
|
||||
assert.ok(credential, "keycloak was given no credential for its database");
|
||||
r.type === "file" && r.path === "/var/lib/keycloak/database.secret");
|
||||
assert.ok(credential, `keycloak was given no credential for its database: ${ids.join(", ")}`);
|
||||
assert.ok(credential.sealed, "keycloak's credential is not sealed, so the mesh can read it");
|
||||
assert.ok(!credential.content, "a credential arrived as content rather than sealed");
|
||||
|
||||
// And the connection itself, which keycloak could not have written: the address and port come
|
||||
// from what the provider serves, and the user name from what the mesh decided both ends would
|
||||
// call this consumer (novox/hq 04-ISSUES/023).
|
||||
const connection = [...byId.values()].find((r) =>
|
||||
r.type === "file" && r.path === "/var/lib/keycloak/database.env");
|
||||
assert.ok(connection, "keycloak was given no database configuration");
|
||||
assert.match(connection.content, /KC_DB_USERNAME=mesh_[a-z0-9_]+_keycloak/,
|
||||
`keycloak was not told what name to present:\n${connection.content}`);
|
||||
assert.doesNotMatch(connection.content, /\$\{bound:/,
|
||||
`a placeholder reached the machine as a value:\n${connection.content}`);
|
||||
|
||||
// The password is the one hole left open, and the sealed value travels beside it. The mesh
|
||||
// discarded the plaintext, so the host is the only thing that can close it.
|
||||
assert.match(connection.content, /KC_DB_PASSWORD=\$\{secret:postgres-database\}/,
|
||||
`the password was not left for the host to fill:\n${connection.content}`);
|
||||
assert.ok(connection.secrets?.["postgres-database"],
|
||||
"the sealed credential did not travel with the file that needs it");
|
||||
assert.doesNotMatch(JSON.stringify(connection.content), /postgres-database":"[A-Za-z0-9+/]{24,}/,
|
||||
"the credential was written into the configuration in the clear");
|
||||
|
||||
// And the provider was told who asked, which is what its provisioner reconciles against.
|
||||
const grants = [...byId.values()].find((r) =>
|
||||
r.type === "file" && String(r.path).startsWith("/var/lib/postgres/grants"));
|
||||
|
||||
Reference in New Issue
Block a user