test: add production compose smoke harness

This commit is contained in:
2026-09-11 06:28:11 +00:00
parent 110a329652
commit 248c41c7e1
9 changed files with 259 additions and 12 deletions
+40
View File
@@ -54,3 +54,43 @@ func TestNativeFixtureAssets_HP_HARNESS_20(t *testing.T) {
t.Fatal("fixture-only context faults are not separated from release builds")
}
}
// TestProductionComposeAssets_HP_OPS_01 guards the deployment properties that
// a syntax-only Compose check cannot prove: private server reachability through
// nginx, non-root state initialization, and a repository-local smoke cleanup.
func TestProductionComposeAssets_HP_OPS_01(t *testing.T) {
t.Parallel()
root := filepath.Clean(filepath.Join("..", ".."))
read := func(relative string) string {
t.Helper()
data, err := os.ReadFile(filepath.Join(root, relative))
if err != nil {
t.Fatalf("read %s: %v", relative, err)
}
return string(data)
}
compose := read("deploy/production/compose.yaml")
for _, required := range []string{
"RVBOX_SERVER_CONFIG:-./server.toml",
"RVBOX_HTTPS_BIND:-0.0.0.0",
"condition: service_completed_successfully",
"condition: service_healthy",
"NET_BIND_SERVICE", "DAC_OVERRIDE", "CHOWN", "SETUID", "SETGID",
} {
if !strings.Contains(compose, required) {
t.Fatalf("production Compose is missing %q", required)
}
}
config := read("deploy/production/server.toml.example")
for _, required := range []string{"agent_listen = \"0.0.0.0:6899\"", "listen = \"0.0.0.0:6901\"", "enabled = false"} {
if !strings.Contains(config, required) {
t.Fatalf("production server example is missing %q", required)
}
}
runner := read("scripts/test-production-compose")
for _, required := range []string{".test-runs/$run_id/production-compose", "RVBOX_HTTPS_BIND=127.0.0.1", "curl --fail", "compose exec -T server", "clean --purge --yes"} {
if !strings.Contains(runner, required) {
t.Fatalf("production smoke runner is missing %q", required)
}
}
}