The run rebuilds the module runtimes its beds stock (075); two mechanism beds read the catalogue's redis (074) #43

Merged
jschoubben merged 3 commits from feat/mesh-tests-and-runtimes into main 2026-09-21 17:36:44 +00:00
9 changed files with 286 additions and 109 deletions
+9 -4
View File
@@ -165,10 +165,15 @@ export MESH_LAB_ROUTE_PROXY=<somewhere>/route-proxy
`MESH_LAB_HOST_BINARY` and `MESH_LAB_MODULES` do double duty: the repository each sits in is what `MESH_LAB_HOST_BINARY` and `MESH_LAB_MODULES` do double duty: the repository each sits in is what
`suite` rebuilds and what the receipt claims. Point the run at a repository and it is built and `suite` rebuilds and what the receipt claims. Point the run at a repository and it is built and
claimed; leave it out and it is neither. `MESH_LAB_CATALOG` is claimed without being built: a bed claimed; leave it out and it is neither. `MESH_LAB_CATALOG` is claimed without being built as a
installs a catalogue module by reading its manifest from that checkout when it runs, so the repository: a bed installs a catalogue module by reading its manifest from that checkout when it
receipt names the catalogue's commit too, and a run taken before a manifest changed says so runs, so the receipt names the catalogue's commit too, and a run taken before a manifest changed
(novox/hq 04-ISSUES/073). says so (novox/hq 04-ISSUES/073). What IS built from it are the module runtimes the named beds'
scenarios stock (`mesh-runtime-<module>:development`): each is compared against the module's
source and the tool runtime and SDK it is built on (`MESH_TOOLS`, `MESH_SDK`, or the checkouts
beside this one — they need their `node_modules`), and rebuilt by `scripts/build-module-runtime.sh`
where the image is older, missing, or the source is uncommitted (novox/hq 04-ISSUES/075).
`--no-build` skips this too, and then the bed runs whatever image the store holds.
Check before running a long suite — it says which of these are missing rather than skipping Check before running a long suite — it says which of these are missing rather than skipping
quietly: quietly:
+3
View File
@@ -24,6 +24,9 @@ images:
# Redis's tool+provisioner runtime, built by scripts/build-module-runtime.sh redis into the local # Redis's tool+provisioner runtime, built by scripts/build-module-runtime.sh redis into the local
# daemon and loaded onto the machine, which holds it by its own image ID. # daemon and loaded onto the machine, which holds it by its own image ID.
- mesh-runtime-redis:development - mesh-runtime-redis:development
# The vault's, for the beds that install the catalogue's redis: its own password is a secret the
# vault provides (novox/hq ADR 0085).
- mesh-runtime-mesh-vault:development
place: place:
all: [host, runtime] all: [host, runtime]
+10 -3
View File
@@ -16,6 +16,7 @@
import { spawnSync } from "node:child_process"; import { spawnSync } from "node:child_process";
import { repositories } from "./repos.ts"; import { repositories } from "./repos.ts";
import { plannedRuntimes } from "./runtimes.ts";
export interface Build { export interface Build {
/** What it produces, for the log. */ /** What it produces, for the log. */
@@ -112,10 +113,16 @@ export function carriedImage(env: NodeJS.ProcessEnv = process.env): string {
return env["MESH_LAB_CARRIED_IMAGE"] ?? "mesh-builder:development"; return env["MESH_LAB_CARRIED_IMAGE"] ?? "mesh-builder:development";
} }
/** rebuild runs the plan, and throws on the first failure rather than testing a stale artifact. */ /**
export function rebuild(env: NodeJS.ProcessEnv = process.env): string[] { * rebuild runs the plan, and throws on the first failure rather than testing a stale artifact.
*
* The plan is what the run was pointed at, plus the module runtimes the named beds stock where
* those are older than their source (novox/hq 04-ISSUES/075) — so a bed never again passes against
* a runtime built two weeks before the manifest it serves.
*/
export function rebuild(env: NodeJS.ProcessEnv = process.env, testFiles: string[] = []): string[] {
const built: string[] = []; const built: string[] = [];
for (const build of planned(env)) { for (const build of [...planned(env), ...plannedRuntimes(testFiles, env)]) {
const [command, ...args] = build.argv; const [command, ...args] = build.argv;
const ran = spawnSync(command!, args, { const ran = spawnSync(command!, args, {
cwd: build.in, cwd: build.in,
+144
View File
@@ -0,0 +1,144 @@
/**
* The module runtimes a run stocks are rebuilt by the run, like everything else it tests.
*
* A per-module bed stocks the module's runtime image — the tool runtime carrying that module's
* code — from the workstation's image store, by tag. It was built by hand, by a script the suite
* never called, and on the day this was written the images for six modules about to run dated
* from two weeks before the manifests they were installed with (novox/hq 04-ISSUES/075). The
* suite's own rule, *the run rebuilds what it tests*, was held for the host and the control plane
* and not for these.
*
* So: for the beds about to run, every `mesh-runtime-<module>:development` their scenarios stock
* is compared against the source it is built from — the module in the catalogue, and the tool
* runtime and SDK it is built on — and rebuilt where the image is older, missing, or the source is
* uncommitted. A rebuild that fails stops the suite, the way a stale host binary would.
*/
import { readFileSync } from "node:fs";
import { tmpdir } from "node:os";
import { join, resolve } from "node:path";
import { spawnSync } from "node:child_process";
import { parse } from "yaml";
import type { Build } from "./rebuild.ts";
import { catalogueRoot } from "./repos.ts";
/** A runtime image a scenario stocks by tag, and the module it is built from. */
export interface StockedRuntime {
tag: string;
module: string;
}
/**
* Tags whose name is not the module's. The audit logger's runtime was the first, built before the
* script was generalised, and the scenario still stocks it under the module's slug.
*/
const NAMED_OTHERWISE: Record<string, string> = { "mesh-runtime-audit": "audit-logger" };
const RUNTIME_TAG = /^(mesh-runtime-[a-z0-9-]+):development$/;
/** The runtimes the scenarios of these beds stock, each named once. */
export function runtimesStockedBy(testFiles: string[], root: string = process.cwd()): StockedRuntime[] {
const seen = new Map<string, StockedRuntime>();
for (const file of testFiles) {
const text = readFileSync(resolve(root, file), "utf8");
const named = /const SCENARIO = "([^"]+)"/.exec(text);
if (!named) continue;
const scenario = parse(readFileSync(join(root, "scenarios", `${named[1]}.yml`), "utf8")) as { images?: unknown };
for (const image of Array.isArray(scenario.images) ? scenario.images : []) {
const m = RUNTIME_TAG.exec(String(image));
if (!m) continue;
const repository = m[1]!;
seen.set(repository, { tag: String(image), module: NAMED_OTHERWISE[repository] ?? repository.slice("mesh-runtime-".length) });
}
}
return [...seen.values()];
}
/** When an image was made and when its source last changed, in seconds; null for no image. */
export interface Ages {
image: number | null;
/** Infinity where the source has uncommitted changes: what is on disk is newer than any commit. */
source: number;
}
/** stale is whether the image predates its source, or is not there at all. */
export function isStale(a: Ages): boolean {
return a.image === null || a.image < a.source;
}
/** A command runner, for the two questions asked below; injected so the rules can be tested. */
export type Ask = (command: string, args: string[]) => { status: number | null; stdout: string };
const ask: Ask = (command, args) => {
const ran = spawnSync(command, args, { encoding: "utf8" });
return { status: ran.status, stdout: ran.stdout ?? "" };
};
/** ageOfImage is when the local image store made this tag, or null when it holds no such image. */
export function ageOfImage(tag: string, run: Ask = ask): number | null {
const ran = run("docker", ["image", "inspect", "--format", "{{.Created}}", tag]);
if (ran.status !== 0) return null;
const at = Date.parse(ran.stdout.trim());
return Number.isNaN(at) ? null : Math.floor(at / 1000);
}
/**
* ageOfSource is the newest commit touching what the runtime is built from: the module's directory
* in the catalogue, and the whole of each repository it is built on top of. Uncommitted changes in
* any of them are newer than every commit.
*/
export function ageOfSource(catalogue: string, module: string, builtOn: string[], run: Ask = ask): number {
let newest = 0;
const at = (dir: string, path?: string): number => {
const args = ["-C", dir, "log", "-1", "--format=%ct"];
if (path) args.push("--", path);
const ran = run("git", args);
const t = Number.parseInt(ran.stdout.trim(), 10);
return ran.status === 0 && Number.isFinite(t) ? t : 0;
};
const dirty = (dir: string, path?: string): boolean => {
const args = ["-C", dir, "status", "--porcelain"];
if (path) args.push("--", path);
const ran = run("git", args);
return ran.status === 0 && ran.stdout.trim() !== "";
};
if (dirty(catalogue, `modules/${module}`)) return Infinity;
newest = Math.max(newest, at(catalogue, `modules/${module}`));
for (const dir of builtOn) {
if (dirty(dir)) return Infinity;
newest = Math.max(newest, at(dir));
}
return newest;
}
/**
* plannedRuntimes is the runtime builds these beds need before they run, given where the run was
* pointed: nothing where no catalogue was named (the beds skip), one build per stale image
* otherwise. The repositories the runtime is built on are the siblings the build script itself
* reads (`MESH_TOOLS`, `MESH_SDK`, or the checkouts beside this one).
*/
export function plannedRuntimes(testFiles: string[], env: NodeJS.ProcessEnv = process.env,
root: string = process.cwd(), run: Ask = ask): Build[] {
const named = env["MESH_LAB_CATALOG"];
if (!named) return [];
const catalogue = catalogueRoot(named);
const builtOn = [
env["MESH_TOOLS"] ?? resolve(root, "..", "mesh-tools"),
env["MESH_SDK"] ?? resolve(root, "..", "mesh-sdk"),
];
const builds: Build[] = [];
for (const runtime of runtimesStockedBy(testFiles, root)) {
const ages: Ages = {
image: ageOfImage(runtime.tag, run),
source: ageOfSource(catalogue, runtime.module, builtOn, run),
};
if (!isStale(ages)) continue;
builds.push({
what: `runtime ${runtime.tag}`,
in: root,
argv: ["scripts/build-module-runtime.sh", runtime.module, join(tmpdir(), `mesh-lab-${runtime.module}.tar`)],
env: { MESH_CATALOG: catalogue, RUNTIME_TAG: runtime.tag },
});
}
return builds;
}
+1 -1
View File
@@ -40,7 +40,7 @@ export async function runSuite(args: string[]): Promise<number> {
if (!args.includes("--no-build")) { if (!args.includes("--no-build")) {
// Before the run, always. The artifacts are built from two other repositories, and a suite // Before the run, always. The artifacts are built from two other repositories, and a suite
// that tests yesterday's binary reports on code nobody is looking at (novox/hq 04-ISSUES/005). // that tests yesterday's binary reports on code nobody is looking at (novox/hq 04-ISSUES/005).
const built = rebuild(); const built = rebuild(process.env, files);
if (built.length > 0) console.log(`built: ${built.join(", ")}\n`); if (built.length > 0) console.log(`built: ${built.join(", ")}\n`);
} }
// Read now, while it is true. The receipt names these, and reading them when the run ends // Read now, while it is true. The receipt names these, and reading them when the run ends
+5 -4
View File
@@ -34,8 +34,11 @@ import { catalogueIsPresent, catalogueDir } from "./integration/harness.ts";
* WEARING the bed proves a mesh mechanism (a grant, a credential, a restart, a route) with a * WEARING the bed proves a mesh mechanism (a grant, a credential, a restart, a route) with a
* module cut down to the shape the mechanism needs — no upstream server, a secret in the * module cut down to the shape the mechanism needs — no upstream server, a secret in the
* environment, a requirement edge removed — and gives it a catalogue name. It is a mesh * environment, a requirement edge removed — and gives it a catalogue name. It is a mesh
* test wearing a catalogue module's name. It should carry a name of its own, or read the * test wearing a catalogue module's name. It cannot simply be renamed: a module's name
* catalogue and meet the module's real requirements. * is its tool namespace and its broker scope, so a fixture running the module's runtime
* must carry the module's name (novox/hq ADR 0093). It reads the catalogue and installs
* what the module requires — the vault for a secret, the route module for a route — or
* it runs no real runtime and carries a name of its own.
* DIFFERS a module bed whose copy differs from the catalogue in more than the lab may rewrite * DIFFERS a module bed whose copy differs from the catalogue in more than the lab may rewrite
* (an image, a port, an address). Reading the catalogue is the fix and needs a run. * (an image, a port, an address). Reading the catalogue is the fix and needs a run.
*/ */
@@ -55,10 +58,8 @@ const STILL_CARRIED: Record<string, { modules: string[]; why: string }> = {
"assigned-plex.test.ts": { modules: ["plex"], why: "WEARING: the sidecar alone, no Plex, the token in the environment" }, "assigned-plex.test.ts": { modules: ["plex"], why: "WEARING: the sidecar alone, no Plex, the token in the environment" },
"assigned-redis.test.ts": { modules: ["redis"], why: "WEARING: its own secret, a lab seal key in the environment" }, "assigned-redis.test.ts": { modules: ["redis"], why: "WEARING: its own secret, a lab seal key in the environment" },
"assigned-sonarr.test.ts": { modules: ["sonarr"], why: "WEARING: the sidecar alone against a forged config.xml" }, "assigned-sonarr.test.ts": { modules: ["sonarr"], why: "WEARING: the sidecar alone against a forged config.xml" },
"mesh-grant-end-to-end.test.ts": { modules: ["redis"], why: "WEARING: a grant mechanism test" },
"minio-grant-end-to-end.test.ts": { modules: ["minio"], why: "WEARING: a grant mechanism test, the root password by env-file" }, "minio-grant-end-to-end.test.ts": { modules: ["minio"], why: "WEARING: a grant mechanism test, the root password by env-file" },
"postgres-grant-end-to-end.test.ts": { modules: ["postgres"], why: "WEARING: a grant mechanism test, the superuser by env-file" }, "postgres-grant-end-to-end.test.ts": { modules: ["postgres"], why: "WEARING: a grant mechanism test, the superuser by env-file" },
"provider-on-backend-network.test.ts": { modules: ["redis"], why: "WEARING: a network mechanism test" },
"provider-uses-mesh-credential.test.ts": { modules: ["redis"], why: "WEARING: a credential mechanism test" }, "provider-uses-mesh-credential.test.ts": { modules: ["redis"], why: "WEARING: a credential mechanism test" },
"runtime-restart-on-config.test.ts": { modules: ["grafana"], why: "WEARING: a restart mechanism test" }, "runtime-restart-on-config.test.ts": { modules: ["grafana"], why: "WEARING: a restart mechanism test" },
"route-forwarding.test.ts": { modules: ["route-proxy", "hello-web"], "route-forwarding.test.ts": { modules: ["route-proxy", "hello-web"],
+15 -47
View File
@@ -23,7 +23,7 @@ import { loadScenario } from "../../src/declaration/parse.ts";
import { raise } from "../../src/lifecycle/raise.ts"; import { raise } from "../../src/lifecycle/raise.ts";
import { destroy, exec } from "../../src/lifecycle/operate.ts"; import { destroy, exec } from "../../src/lifecycle/operate.ts";
import { hostBinaryPath, HOST_PATH } from "../../src/lifecycle/place.ts"; import { hostBinaryPath, HOST_PATH } from "../../src/lifecycle/place.ts";
import { labIsUsable, destroyAll, foundationBundle, onTheMachine } from "./harness.ts"; import { labIsUsable, destroyAll, foundationBundle, onTheMachine, catalogueModule, catalogueIsPresent } from "./harness.ts";
import type { HeldImage } from "../../src/pinning.ts"; import type { HeldImage } from "../../src/pinning.ts";
const capability = await labIsUsable(); const capability = await labIsUsable();
@@ -36,7 +36,7 @@ const skip = !capability.usable
? "MESH_LAB_HOST_BINARY is not set to a built mesh-host" ? "MESH_LAB_HOST_BINARY is not set to a built mesh-host"
: !bundle || !existsSync(bundle) : !bundle || !existsSync(bundle)
? "MESH_LAB_BUNDLE is not set to a foundation bundle (mesh-host examples/)" ? "MESH_LAB_BUNDLE is not set to a foundation bundle (mesh-host examples/)"
: false; : catalogueIsPresent();
const SCENARIO = "redis-node"; const SCENARIO = "redis-node";
const MACHINE = "anchor"; const MACHINE = "anchor";
@@ -139,51 +139,12 @@ after(async () => {
test("the mesh grants a consumer redis's cache, and the credential it delivers authenticates", { test("the mesh grants a consumer redis's cache, and the credential it delivers authenticates", {
skip, timeout: 900_000, skip, timeout: 900_000,
}, async () => { }, async () => {
// The PROVIDER: redis in its committed shape — server and a broker-bound runtime on the private // The PROVIDER: the catalogue's redis (novox/hq 04-ISSUES/074) — server and a broker-bound
// redis network, the runtime running the provisioner. // runtime on the private redis network, the runtime running the provisioner. It requires a
const redisManifest = JSON.stringify({ // `secret` for its own password, so the vault that provides one is installed beside it, exactly
module: "redis", // as the vault bed does.
version: "1", const vaultManifest = catalogueModule("mesh-vault", held);
provides: [{ name: "redis-cache", scope: "mesh" }], const redisManifest = catalogueModule("redis", held);
serves: { "redis-cache": {} },
emits: ["module.redis.cache.provisioned", "module.redis.cache.deprovisioned"],
consumes: ["module.redis.cache.provisioned", "module.redis.cache.deprovisioned"],
receives: { "redis-cache": "/var/lib/redis-module/grants/mesh.json" },
grants: { "redis-cache": "/var/lib/redis-module/grants" },
"own-secrets": { default: "/var/lib/redis-module/default.secret", broker: "/var/lib/mesh/redis/broker" },
resources: [
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/redis", mode: "0700" },
{ id: "state", type: "directory", path: "/var/lib/redis-module", mode: "0700" },
{ id: "grants-dir", type: "directory", path: "/var/lib/redis-module/grants", mode: "0700" },
{ id: "data", type: "directory", path: "/services/redis/data", mode: "0700", owner: "999:999" },
{
id: "server-conf", type: "file", path: "/var/lib/redis-module/redis.conf", mode: "0644",
content: "requirepass ${secret:default}\nappendonly no\ndir /data\n",
},
{ id: "net", type: "network", name: "redis" },
{
id: "server", type: "container", name: "redis", image: pinned("redis"), network: "redis",
ports: ["6379"],
volumes: ["/services/redis/data:/data", "/var/lib/redis-module/redis.conf:/etc/redis/redis.conf:ro"],
args: ["/etc/redis/redis.conf"],
},
{
id: "runtime", type: "container", name: "mesh-redis", image: pinned("mesh-runtime-redis"),
network: "redis",
volumes: [
"/var/lib/mesh/redis/broker:/run/secrets/broker:ro",
"/var/lib/redis-module/grants:/var/lib/redis-module/grants:ro",
"/var/lib/redis-module/default.secret:/run/secrets/default:ro",
],
env: {
MESH_BROKER_FILE: "/run/secrets/broker",
MESH_RECEIVES: "/var/lib/redis-module/grants/mesh.json",
MESH_PROVISION_REDIS: "redis:6379",
MESH_PROVISION_PASSWORD_FILE: "/run/secrets/default",
},
},
],
});
// The CONSUMER: a module that requires redis-cache and no more. It runs no code here — the mesh // The CONSUMER: a module that requires redis-cache and no more. It runs no code here — the mesh
// delivers it a bound file (where redis is, and the login to present) and its sealed password, // delivers it a bound file (where redis is, and the login to present) and its sealed password,
@@ -191,6 +152,9 @@ test("the mesh grants a consumer redis's cache, and the credential it delivers a
const consumerManifest = JSON.stringify({ const consumerManifest = JSON.stringify({
module: "cacheuser", module: "cacheuser",
version: "1", version: "1",
// `mesh_anchor_cacheuser` is 21 characters, over the 20 a backend keeps (ADR 0049); the slug
// makes the consumer identity `mesh_anchor_cache`.
slug: "cache",
requires: ["redis-cache"], requires: ["redis-cache"],
// `contributes` (not just `requires`) is what makes a consumer *ask* — the grant forms from a // `contributes` (not just `requires`) is what makes a consumer *ask* — the grant forms from a
// contribution. It must be non-empty; redis's provisioner ignores the value (it uses the login // contribution. It must be non-empty; redis's provisioner ignores the value (it uses the login
@@ -201,6 +165,10 @@ test("the mesh grants a consumer redis's cache, and the credential it delivers a
resources: [{ id: "state", type: "directory", path: "/var/lib/cacheuser", mode: "0700" }], resources: [{ id: "state", type: "directory", path: "/var/lib/cacheuser", mode: "0700" }],
}); });
await must(`printf %s ${quote(vaultManifest)} > /tmp/mesh-vault.json && docker cp /tmp/mesh-vault.json mesh-controller:/mesh-vault.json`);
await mesh("module add /mesh-vault.json");
await mesh(`module issue mesh-vault --node ${MACHINE}`);
await mesh(`assign ${MACHINE} mesh-vault`);
await must(`printf %s ${quote(redisManifest)} > /tmp/redis.json && docker cp /tmp/redis.json mesh-controller:/redis.json`); await must(`printf %s ${quote(redisManifest)} > /tmp/redis.json && docker cp /tmp/redis.json mesh-controller:/redis.json`);
await mesh("module add /redis.json"); await mesh("module add /redis.json");
await mesh(`module issue redis --node ${MACHINE}`); await mesh(`module issue redis --node ${MACHINE}`);
@@ -20,7 +20,7 @@ import { loadScenario } from "../../src/declaration/parse.ts";
import { raise } from "../../src/lifecycle/raise.ts"; import { raise } from "../../src/lifecycle/raise.ts";
import { destroy, exec } from "../../src/lifecycle/operate.ts"; import { destroy, exec } from "../../src/lifecycle/operate.ts";
import { hostBinaryPath, HOST_PATH } from "../../src/lifecycle/place.ts"; import { hostBinaryPath, HOST_PATH } from "../../src/lifecycle/place.ts";
import { labIsUsable, destroyAll, foundationBundle, onTheMachine } from "./harness.ts"; import { labIsUsable, destroyAll, foundationBundle, onTheMachine, catalogueModule, catalogueIsPresent } from "./harness.ts";
import type { HeldImage } from "../../src/pinning.ts"; import type { HeldImage } from "../../src/pinning.ts";
const capability = await labIsUsable(); const capability = await labIsUsable();
@@ -33,7 +33,7 @@ const skip = !capability.usable
? "MESH_LAB_HOST_BINARY is not set to a built mesh-host" ? "MESH_LAB_HOST_BINARY is not set to a built mesh-host"
: !bundle || !existsSync(bundle) : !bundle || !existsSync(bundle)
? "MESH_LAB_BUNDLE is not set to a foundation bundle (mesh-host examples/)" ? "MESH_LAB_BUNDLE is not set to a foundation bundle (mesh-host examples/)"
: false; : catalogueIsPresent();
const SCENARIO = "redis-node"; const SCENARIO = "redis-node";
const MACHINE = "anchor"; const MACHINE = "anchor";
@@ -136,54 +136,15 @@ after(async () => {
test("redis's runtime, on the backend's private network, binds the broker and provisions with the mesh's credential", { test("redis's runtime, on the backend's private network, binds the broker and provisions with the mesh's credential", {
skip, timeout: 900_000, skip, timeout: 900_000,
}, async () => { }, async () => {
// Exactly the committed redis shape: a private `redis` network, the server on it with a published // The catalogue's redis (novox/hq 04-ISSUES/074): a private `redis` network, the server on it
// port, and the runtime on it too — reaching redis by name and the broker by NAT. // with a published port, and the runtime on it too — reaching redis by name and the broker by
const manifest = JSON.stringify({ // NAT. Its own password is a `secret` the vault provides, so the vault is installed beside it.
module: "redis", const vaultManifest = catalogueModule("mesh-vault", held);
version: "1", await must(`printf %s ${quote(vaultManifest)} > /tmp/mesh-vault.json && docker cp /tmp/mesh-vault.json mesh-controller:/mesh-vault.json`);
provides: [{ name: "redis-cache", scope: "mesh" }], await mesh("module add /mesh-vault.json");
serves: { "redis-cache": {} }, await mesh(`module issue mesh-vault --node ${MACHINE}`);
emits: ["module.redis.cache.provisioned", "module.redis.cache.deprovisioned"], await mesh(`assign ${MACHINE} mesh-vault`);
consumes: ["module.redis.cache.provisioned", "module.redis.cache.deprovisioned"], const manifest = catalogueModule("redis", held);
receives: { "redis-cache": "/var/lib/redis-module/grants/mesh.json" },
grants: { "redis-cache": "/var/lib/redis-module/grants" },
"own-secrets": { default: "/var/lib/redis-module/default.secret", broker: "/var/lib/mesh/redis/broker" },
resources: [
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/redis", mode: "0700" },
{ id: "state", type: "directory", path: "/var/lib/redis-module", mode: "0700" },
{ id: "grants-dir", type: "directory", path: "/var/lib/redis-module/grants", mode: "0700" },
{ id: "data", type: "directory", path: "/services/redis/data", mode: "0700", owner: "999:999" },
{
id: "server-conf", type: "file", path: "/var/lib/redis-module/redis.conf", mode: "0644",
content: "requirepass ${secret:default}\nappendonly no\ndir /data\n",
},
{ id: "net", type: "network", name: "redis" },
{
id: "server", type: "container", name: "redis", image: pinned("redis"), network: "redis",
ports: ["6379"],
volumes: [
"/services/redis/data:/data",
"/var/lib/redis-module/redis.conf:/etc/redis/redis.conf:ro",
],
args: ["/etc/redis/redis.conf"],
},
{
id: "runtime", type: "container", name: "mesh-redis", image: pinned("mesh-runtime-redis"),
network: "redis",
volumes: [
"/var/lib/mesh/redis/broker:/run/secrets/broker:ro",
"/var/lib/redis-module/grants:/var/lib/redis-module/grants:ro",
"/var/lib/redis-module/default.secret:/run/secrets/default:ro",
],
env: {
MESH_BROKER_FILE: "/run/secrets/broker",
MESH_RECEIVES: "/var/lib/redis-module/grants/mesh.json",
MESH_PROVISION_REDIS: "redis:6379",
MESH_PROVISION_PASSWORD_FILE: "/run/secrets/default",
},
},
],
});
await must(`printf %s ${quote(manifest)} > /tmp/redis.json && docker cp /tmp/redis.json mesh-controller:/redis.json`); await must(`printf %s ${quote(manifest)} > /tmp/redis.json && docker cp /tmp/redis.json mesh-controller:/redis.json`);
await mesh("module add /redis.json"); await mesh("module add /redis.json");
await mesh(`module issue redis --node ${MACHINE}`); await mesh(`module issue redis --node ${MACHINE}`);
+88
View File
@@ -0,0 +1,88 @@
import { test } from "node:test";
import assert from "node:assert/strict";
import { mkdtempSync, mkdirSync, writeFileSync, rmSync } from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { ageOfImage, ageOfSource, isStale, plannedRuntimes, runtimesStockedBy, type Ask } from "../src/runtimes.ts";
// The module runtimes a run stocks are rebuilt by the run (novox/hq 04-ISSUES/075): what a bed's
// scenario stocks is found, compared against its source, and built where older.
function aLabWith(beds: Record<string, string>, scenarios: Record<string, string[]>): { root: string; done: () => void } {
const root = mkdtempSync(join(tmpdir(), "mesh-lab-runtimes-"));
mkdirSync(join(root, "scenarios"));
mkdirSync(join(root, "test", "integration"), { recursive: true });
for (const [name, images] of Object.entries(scenarios)) {
writeFileSync(join(root, "scenarios", `${name}.yml`), `scenario: ${name}\nimages:\n${images.map((i) => ` - ${i}\n`).join("")}`);
}
for (const [file, scenario] of Object.entries(beds)) {
writeFileSync(join(root, "test", "integration", file), `const SCENARIO = "${scenario}";\n`);
}
return { root, done: () => rmSync(root, { recursive: true, force: true }) };
}
test("what a bed's scenario stocks is found, by module, once", () => {
const lab = aLabWith(
{ "a.test.ts": "one", "b.test.ts": "two", "c.test.ts": "one" },
{ one: ["mesh-controller:development", "mesh-runtime-gitlab:development", "postgres:16"],
two: ["mesh-runtime-gitlab:development", "mesh-runtime-audit:development"] });
try {
const found = runtimesStockedBy(["test/integration/a.test.ts", "test/integration/b.test.ts", "test/integration/c.test.ts"], lab.root);
assert.deepEqual(found, [
{ tag: "mesh-runtime-gitlab:development", module: "gitlab" },
// The audit logger's runtime is stocked under its slug, and the module is named for it.
{ tag: "mesh-runtime-audit:development", module: "audit-logger" },
]);
} finally { lab.done(); }
});
test("an image is stale when missing, older than its source, or when the source is uncommitted", () => {
assert.equal(isStale({ image: null, source: 0 }), true);
assert.equal(isStale({ image: 100, source: 200 }), true);
assert.equal(isStale({ image: 200, source: 100 }), false);
assert.equal(isStale({ image: 200, source: Infinity }), true);
});
test("the image's age comes from the store and the source's from the newest commit in any part", () => {
const answers: Ask = (command, args) => {
if (command === "docker") return { status: 0, stdout: "2026-09-21T12:00:00.000000000Z\n" };
if (args.includes("status")) return { status: 0, stdout: "" };
if (args.includes("modules/gitlab")) return { status: 0, stdout: "1000\n" };
return { status: 0, stdout: args[1] === "/tools" ? "3000\n" : "2000\n" };
};
assert.equal(ageOfImage("mesh-runtime-gitlab:development", answers), Date.parse("2026-09-21T12:00:00Z") / 1000);
assert.equal(ageOfSource("/catalogue", "gitlab", ["/tools", "/sdk"], answers), 3000);
// No such image is null, not zero: "never built" and "built at the epoch" are different answers.
assert.equal(ageOfImage("mesh-runtime-nothing:development", () => ({ status: 1, stdout: "" })), null);
// Uncommitted changes anywhere in the source are newer than every commit.
const dirtyTools: Ask = (command, args) =>
args.includes("status") && args[1] === "/tools" ? { status: 0, stdout: " M src/x.ts\n" } : answers(command, args);
assert.equal(ageOfSource("/catalogue", "gitlab", ["/tools", "/sdk"], dirtyTools), Infinity);
});
test("only a stale runtime is planned, built by the lab's own script under the tag the scenario stocks", () => {
const lab = aLabWith({ "a.test.ts": "one" },
{ one: ["mesh-runtime-gitlab:development", "mesh-runtime-audit:development"] });
try {
const answers: Ask = (command, args) => {
if (command === "docker") {
// gitlab's image is from yesterday; the audit logger has none.
return args.includes("mesh-runtime-gitlab:development")
? { status: 0, stdout: "2026-09-21T12:00:00Z\n" } : { status: 1, stdout: "" };
}
if (args.includes("status")) return { status: 0, stdout: "" };
return { status: 0, stdout: `${Date.parse("2026-09-20T00:00:00Z") / 1000}\n` };
};
const env = { MESH_LAB_CATALOG: "/catalogue/modules", MESH_TOOLS: "/tools", MESH_SDK: "/sdk" };
const builds = plannedRuntimes(["test/integration/a.test.ts"], env, lab.root, answers);
assert.equal(builds.length, 1);
assert.equal(builds[0]!.what, "runtime mesh-runtime-audit:development");
assert.equal(builds[0]!.argv[0], "scripts/build-module-runtime.sh");
assert.equal(builds[0]!.argv[1], "audit-logger");
assert.equal(builds[0]!.env?.["MESH_CATALOG"], "/catalogue");
assert.equal(builds[0]!.env?.["RUNTIME_TAG"], "mesh-runtime-audit:development");
// No catalogue named: nothing is planned, because no bed will read one either.
assert.deepEqual(plannedRuntimes(["test/integration/a.test.ts"], {}, lab.root, answers), []);
} finally { lab.done(); }
});