The no-fake multi-node gate: built-store-cross-node #34

Merged
jschoubben merged 12 commits from bed/built-store-cross-node into main 2026-09-17 23:00:49 +00:00
Showing only changes of commit d3a6dc9784 - Show all commits
+10 -12
View File
@@ -126,8 +126,13 @@ async function buildAndAssign(module: string, node: string, opts?: { build?: boo
assert.doesNotMatch(built, /failed/i, built);
}
const manifest = (await on(CONTROL, `docker exec mesh-controller cat /${module}.json`)).out;
if (manifest.includes("MESH_BROKER_FILE")) await mesh(`module issue ${module} --node ${node}`);
if (manifest.includes("MESH_BROKER_FILE")) {
const issued = await mesh(`module issue ${module} --node ${node}`);
assert.match(issued, /scoped to what it (emits and consumes|consumes and emits)/,
`the broker account for ${module} was not issued:\n${issued}`);
}
await mesh(`assign ${node} ${module}`);
await mesh(`push ${node}`, 600_000);
}
async function waitForContainer(node: string, container: string, seconds = 300): Promise<string> {
@@ -205,18 +210,11 @@ test("a joined node's consumers open the store and broker the mesh built and ado
const base = await mesh(`build ${forgeUrl(BASE.repo)} --ref ${refFor(BASE.repo)} --wait 1200s`, 1_500_000);
assert.doesNotMatch(base, /failed/i, base);
// Adopt the foundation store and broker as the postgres and lavinmq modules, BUILT by the mesh.
// The store's superuser is the foundation's, made at genesis — carried in through `secret accept`
// before the push, or the module mints one the running store does not know.
await buildAndAssign("nftables", CONTROL, { build: false });
await buildAndAssign("postgres", CONTROL);
const superPw = (await must(CONTROL,
`docker inspect mesh-store --format '{{range .Config.Env}}{{println .}}{{end}}' | sed -n 's/^POSTGRES_PASSWORD=//p'`)).trim();
await must(CONTROL, `printf %s ${quote(superPw)} > /tmp/superuser && docker cp /tmp/superuser mesh-controller:/superuser`);
await mesh(`secret accept ${CONTROL} postgres superuser --from /superuser`);
// Genesis already adopted the store as the postgres module (superuser accepted), and installed
// nftables and the catalogue — verified rather than redone. The broker is the one foundation
// half genesis leaves to the mesh proper: adopt it here, BUILT by the mesh's own builder.
await waitForContainer(CONTROL, "mesh-postgres", 120);
await buildAndAssign("lavinmq", CONTROL);
await mesh(`push ${CONTROL}`, 600_000);
await waitForContainer(CONTROL, "mesh-postgres", 600);
await waitForContainer(CONTROL, "mesh-lavinmq", 600);
// The consumers on the joined node — built by the mesh, delivered from its registry.