feat: add native Windows hierarchy test harness
This commit is contained in:
@@ -0,0 +1,11 @@
|
||||
# Linux server native-test stack
|
||||
|
||||
This directory owns the Docker Compose stack for the Windows native E2E lane.
|
||||
It runs on the current Linux controller and owns the Linux RVBox server, nginx
|
||||
TLS proxy with a per-run matching-host self-signed leaf, SQLite/segment state,
|
||||
control socket, and logs. The v1 client deliberately accepts this self-signed
|
||||
leaf when no CA file is configured; it is encrypted transport, not server
|
||||
authentication.
|
||||
|
||||
The Helium VM never hosts this stack. It receives only rvbox.exe and client
|
||||
TOML through the Windows fixture controller.
|
||||
Executable
+13
@@ -0,0 +1,13 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
|
||||
test -f /pki/server.pem && test -f /pki/server-key.pem && exit 0
|
||||
apk add --no-cache openssl
|
||||
umask 077
|
||||
openssl genrsa -out /pki/server-key.pem 2048
|
||||
openssl req -x509 -new -key /pki/server-key.pem -sha256 -days 2 \
|
||||
-subj "/CN=${RVBOX_NATIVE_ENDPOINT_HOST:?}" \
|
||||
-addext "subjectAltName=DNS:${RVBOX_NATIVE_ENDPOINT_HOST}" \
|
||||
-out /pki/server.pem
|
||||
chmod 600 /pki/*key.pem
|
||||
chmod 644 /pki/server.pem
|
||||
@@ -0,0 +1,37 @@
|
||||
# Per-run production-shaped Linux server/proxy fixture. It runs on the current
|
||||
# controller; the Windows VM receives only its client bundle.
|
||||
services:
|
||||
server:
|
||||
image: alpine:3.22
|
||||
user: "${RVBOX_NATIVE_UID:-65532}:${RVBOX_NATIVE_GID:-65532}"
|
||||
command: ["/opt/rvbox/rvbox-server", "--config", "/etc/rvbox/server.toml"]
|
||||
volumes:
|
||||
- ../../bin/rvbox-server:/opt/rvbox/rvbox-server:ro
|
||||
- ../../bin/rvc:/opt/rvbox/rvc:ro
|
||||
- "${RVBOX_NATIVE_RUNTIME_DIR}/server.toml:/etc/rvbox/server.toml:ro"
|
||||
- "${RVBOX_NATIVE_RUNTIME_DIR}/state:/state"
|
||||
- "${RVBOX_NATIVE_RUNTIME_DIR}/state/control:/run/rvbox"
|
||||
networks: [native]
|
||||
labels: { rvbox.native.run_id: "${RVBOX_NATIVE_RUN_ID}" }
|
||||
nginx:
|
||||
image: nginx:1.27-alpine
|
||||
depends_on: [server]
|
||||
ports: [ "${RVBOX_NATIVE_BIND:-0.0.0.0}:${RVBOX_NATIVE_PORT}:443" ]
|
||||
volumes:
|
||||
- ./nginx.conf:/etc/nginx/conf.d/default.conf:ro
|
||||
- "${RVBOX_NATIVE_RUNTIME_DIR}/pki/server.pem:/etc/nginx/tls/server.pem:ro"
|
||||
- "${RVBOX_NATIVE_RUNTIME_DIR}/pki/server-key.pem:/etc/nginx/tls/server-key.pem:ro"
|
||||
networks: [native]
|
||||
labels: { rvbox.native.run_id: "${RVBOX_NATIVE_RUN_ID}" }
|
||||
certgen:
|
||||
image: alpine:3.22
|
||||
profiles: [tools]
|
||||
environment:
|
||||
RVBOX_NATIVE_ENDPOINT_HOST: "${RVBOX_NATIVE_ENDPOINT_HOST}"
|
||||
volumes:
|
||||
- "${RVBOX_NATIVE_RUNTIME_DIR}/pki:/pki"
|
||||
- ./certgen.sh:/fixture/certgen.sh:ro
|
||||
entrypoint: ["/bin/sh", "/fixture/certgen.sh"]
|
||||
networks:
|
||||
native:
|
||||
labels: { rvbox.native.run_id: "${RVBOX_NATIVE_RUN_ID}" }
|
||||
@@ -0,0 +1,21 @@
|
||||
map $http_upgrade $connection_upgrade {
|
||||
default upgrade;
|
||||
'' close;
|
||||
}
|
||||
server {
|
||||
listen 443 ssl;
|
||||
server_name _;
|
||||
ssl_certificate /etc/nginx/tls/server.pem;
|
||||
ssl_certificate_key /etc/nginx/tls/server-key.pem;
|
||||
ssl_protocols TLSv1.2 TLSv1.3;
|
||||
location = /v1/agent {
|
||||
proxy_pass http://server:6899;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection $connection_upgrade;
|
||||
proxy_set_header Host $host;
|
||||
proxy_read_timeout 75s;
|
||||
proxy_send_timeout 15s;
|
||||
}
|
||||
location / { return 404; }
|
||||
}
|
||||
Reference in New Issue
Block a user