Issue 074 closed: the last WEARING fixtures renamed or retired; a stale delivery fixed #47
@@ -54,10 +54,6 @@ const STILL_CARRIED: Record<string, { modules: string[]; why: string }> = {
|
||||
why: "DIFFERS: redis mints its own secret, baserow drops its route requirement, letta drops its ports" },
|
||||
"lavinmq-bed.test.ts": { modules: ["lavinmq", "amqp-ping"],
|
||||
why: "BESIDE (lavinmq, with a bootstrap step and a data directory the catalogue has not got); DIFFERS (amqp-ping names its entrypoint)" },
|
||||
"provider-uses-mesh-credential.test.ts": { modules: ["redis"], why: "WEARING: a credential mechanism test" },
|
||||
"runtime-restart-on-config.test.ts": { modules: ["grafana"], why: "WEARING: a restart mechanism test" },
|
||||
"mesh.test.ts": { modules: ["postgres", "builder", "umami"],
|
||||
why: "WEARING: a postgres with no resources, a builder that builds itself, an umami that is another module of that name" },
|
||||
};
|
||||
|
||||
const beds = resolve(import.meta.dirname, "integration");
|
||||
|
||||
@@ -318,7 +318,7 @@ test("both machines join it, and the token is all they need", { skip, timeout: 9
|
||||
test("a credential reaches both ends and the mesh holds neither", { skip, timeout: 900_000 }, async () => {
|
||||
// The whole argument, on real machines: the two ends must hold the SAME password, and it must
|
||||
// appear nowhere the mesh or the broker could read it.
|
||||
await must("anchor", `printf %s '{"module":"postgres","version":"1",` +
|
||||
await must("anchor", `printf %s '{"module":"a-store","version":"1",` +
|
||||
`"provides":[{"name":"postgres-database","scope":"mesh"}],"serves":{"postgres-database":{"port":5432}},` +
|
||||
`"grants":{"postgres-database":"/var/lib/mesh-host/grants"},` +
|
||||
`"receives":{"postgres-database":"/var/lib/mesh-host/grants/mesh.json"},"resources":[]}' > /tmp/pg.json`);
|
||||
@@ -342,7 +342,7 @@ test("a credential reaches both ends and the mesh holds neither", { skip, timeou
|
||||
await mesh("overlay place anchor --hub --endpoint 192.0.2.10:51820 --site lab");
|
||||
await mesh("overlay place laptop --site lab");
|
||||
for (const node of ["anchor", "laptop"]) await mesh(`assign ${node} networking`);
|
||||
await mesh("assign anchor postgres");
|
||||
await mesh("assign anchor a-store");
|
||||
await mesh("assign laptop meshboard");
|
||||
|
||||
for (const machine of ["anchor", "laptop"]) {
|
||||
@@ -824,7 +824,7 @@ test("the builder is a module the mesh assigns, with a credential the mesh deliv
|
||||
//
|
||||
// So: the mesh issues a scoped account, seals it to the machine, and delivers it with the
|
||||
// declaration. Nobody types it and the mesh cannot read it back.
|
||||
await must("anchor", `mkdir -p /root/builder && printf %s '{"module":"builder","version":"1",` +
|
||||
await must("anchor", `mkdir -p /root/builder && printf %s '{"module":"self-builder","version":"1",` +
|
||||
`"requires":["artifact-store"],"capabilities":["container-runtime"],` +
|
||||
`"claims":[{"name":"the-build-machine","scope":"node"}],` +
|
||||
`"binds":{"artifact-store":"/var/lib/mesh/builder/artifact-store.json"},` +
|
||||
@@ -865,7 +865,7 @@ test("the builder is a module the mesh assigns, with a credential the mesh deliv
|
||||
assert.ok(!(await on("anchor", `pgrep -x mesh-builder`)).ok,
|
||||
"the hand-started builder is still running, so this would test that one");
|
||||
|
||||
await mesh("assign anchor builder");
|
||||
await mesh("assign anchor self-builder");
|
||||
await mesh("push anchor");
|
||||
await new Promise((r) => setTimeout(r, 20_000));
|
||||
|
||||
@@ -1671,7 +1671,7 @@ test("a third-party workload is adopted, with the credential it already had", {
|
||||
const password = "the-password-it-already-had";
|
||||
|
||||
await must("anchor", `printf %s ${quote(JSON.stringify({
|
||||
module: "umami",
|
||||
module: "adopted-analytics",
|
||||
version: "1",
|
||||
capabilities: ["container-runtime"],
|
||||
"own-secrets": {
|
||||
@@ -1707,13 +1707,13 @@ test("a third-party workload is adopted, with the credential it already had", {
|
||||
// seals it and cannot read it again. Given whole, as the environment lines the containers read.
|
||||
await must("anchor",
|
||||
`printf %s ${quote(`POSTGRES_PASSWORD=${password}`)} | ` +
|
||||
`docker exec -i mesh-controller /mesh-controller secret accept anchor umami database --from -`);
|
||||
`docker exec -i mesh-controller /mesh-controller secret accept anchor adopted-analytics database --from -`);
|
||||
await must("anchor",
|
||||
`printf %s ${quote(
|
||||
`DATABASE_URL=postgresql://umami:${password}@umami-db:5432/umami`)} | ` +
|
||||
`docker exec -i mesh-controller /mesh-controller secret accept anchor umami app --from -`);
|
||||
`docker exec -i mesh-controller /mesh-controller secret accept anchor adopted-analytics app --from -`);
|
||||
|
||||
await mesh("assign anchor umami");
|
||||
await mesh("assign anchor adopted-analytics");
|
||||
await mesh("push anchor", 300_000);
|
||||
|
||||
// Both containers, and the network they share.
|
||||
|
||||
@@ -145,7 +145,7 @@ test("redis creates a consumer's login with the password the mesh minted, sealin
|
||||
// (MESH_RECEIVES). There is NO MESH_SEAL_KEY — the whole point of ADR 0048 is that a provider
|
||||
// needs none.
|
||||
const manifest = JSON.stringify({
|
||||
module: "redis",
|
||||
module: "a-cache",
|
||||
version: "1",
|
||||
emits: ["module.redis.cache.provisioned", "module.redis.cache.deprovisioned"],
|
||||
consumes: ["module.redis.cache.provisioned", "module.redis.cache.deprovisioned"],
|
||||
@@ -184,10 +184,10 @@ test("redis creates a consumer's login with the password the mesh minted, sealin
|
||||
},
|
||||
],
|
||||
});
|
||||
await must(`printf %s ${quote(manifest)} > /tmp/redis.json && docker cp /tmp/redis.json mesh-controller:/redis.json`);
|
||||
await mesh("module add /redis.json");
|
||||
await mesh(`module issue redis --node ${MACHINE}`);
|
||||
await mesh(`assign ${MACHINE} redis`);
|
||||
await must(`printf %s ${quote(manifest)} > /tmp/a-cache.json && docker cp /tmp/a-cache.json mesh-controller:/a-cache.json`);
|
||||
await mesh("module add /a-cache.json");
|
||||
await mesh(`module issue a-cache --node ${MACHINE}`);
|
||||
await mesh(`assign ${MACHINE} a-cache`);
|
||||
await mesh(`push ${MACHINE}`);
|
||||
await settled();
|
||||
|
||||
|
||||
@@ -113,7 +113,7 @@ async function settled(withinMs = 480_000): Promise<void> {
|
||||
async function setToken(token: string): Promise<void> {
|
||||
const settings = JSON.stringify({ url: "http://127.0.0.1:3000", token });
|
||||
await must(`printf %s ${quote(settings)} > /tmp/s.json && docker cp /tmp/s.json mesh-controller:/s.json`);
|
||||
await mesh(`settings set grafana /s.json --node ${MACHINE}`);
|
||||
await mesh(`settings set a-runtime /s.json --node ${MACHINE}`);
|
||||
}
|
||||
|
||||
async function containerId(): Promise<string> {
|
||||
@@ -151,7 +151,7 @@ test("a running runtime is recreated when its settings change, and reads the new
|
||||
skip, timeout: 900_000,
|
||||
}, async () => {
|
||||
const manifest = JSON.stringify({
|
||||
module: "grafana",
|
||||
module: "a-runtime",
|
||||
version: "1",
|
||||
emits: ["module.grafana.alert.firing"],
|
||||
"own-secrets": { broker: "/var/lib/mesh/grafana/broker" },
|
||||
@@ -170,12 +170,12 @@ test("a running runtime is recreated when its settings change, and reads the new
|
||||
},
|
||||
],
|
||||
});
|
||||
await must(`printf %s ${quote(manifest)} > /tmp/grafana.json && docker cp /tmp/grafana.json mesh-controller:/grafana.json`);
|
||||
await mesh("module add /grafana.json");
|
||||
await must(`printf %s ${quote(manifest)} > /tmp/a-runtime.json && docker cp /tmp/a-runtime.json mesh-controller:/a-runtime.json`);
|
||||
await mesh("module add /a-runtime.json");
|
||||
|
||||
await setToken("token-alpha");
|
||||
await mesh(`module issue grafana --node ${MACHINE}`);
|
||||
await mesh(`assign ${MACHINE} grafana`);
|
||||
await mesh(`module issue a-runtime --node ${MACHINE}`);
|
||||
await mesh(`assign ${MACHINE} a-runtime`);
|
||||
await mesh(`push ${MACHINE}`);
|
||||
await settled();
|
||||
|
||||
|
||||
Reference in New Issue
Block a user