feat: add native Windows hierarchy test harness

This commit is contained in:
2026-09-09 16:48:54 +00:00
parent 8985457d37
commit 409b64a2fb
30 changed files with 1033 additions and 44 deletions
+11
View File
@@ -0,0 +1,11 @@
# Linux server native-test stack
This directory owns the Docker Compose stack for the Windows native E2E lane.
It runs on the current Linux controller and owns the Linux RVBox server, nginx
TLS proxy with a per-run matching-host self-signed leaf, SQLite/segment state,
control socket, and logs. The v1 client deliberately accepts this self-signed
leaf when no CA file is configured; it is encrypted transport, not server
authentication.
The Helium VM never hosts this stack. It receives only rvbox.exe and client
TOML through the Windows fixture controller.
+13
View File
@@ -0,0 +1,13 @@
#!/bin/sh
set -eu
test -f /pki/server.pem && test -f /pki/server-key.pem && exit 0
apk add --no-cache openssl
umask 077
openssl genrsa -out /pki/server-key.pem 2048
openssl req -x509 -new -key /pki/server-key.pem -sha256 -days 2 \
-subj "/CN=${RVBOX_NATIVE_ENDPOINT_HOST:?}" \
-addext "subjectAltName=DNS:${RVBOX_NATIVE_ENDPOINT_HOST}" \
-out /pki/server.pem
chmod 600 /pki/*key.pem
chmod 644 /pki/server.pem
+37
View File
@@ -0,0 +1,37 @@
# Per-run production-shaped Linux server/proxy fixture. It runs on the current
# controller; the Windows VM receives only its client bundle.
services:
server:
image: alpine:3.22
user: "${RVBOX_NATIVE_UID:-65532}:${RVBOX_NATIVE_GID:-65532}"
command: ["/opt/rvbox/rvbox-server", "--config", "/etc/rvbox/server.toml"]
volumes:
- ../../bin/rvbox-server:/opt/rvbox/rvbox-server:ro
- ../../bin/rvc:/opt/rvbox/rvc:ro
- "${RVBOX_NATIVE_RUNTIME_DIR}/server.toml:/etc/rvbox/server.toml:ro"
- "${RVBOX_NATIVE_RUNTIME_DIR}/state:/state"
- "${RVBOX_NATIVE_RUNTIME_DIR}/state/control:/run/rvbox"
networks: [native]
labels: { rvbox.native.run_id: "${RVBOX_NATIVE_RUN_ID}" }
nginx:
image: nginx:1.27-alpine
depends_on: [server]
ports: [ "${RVBOX_NATIVE_BIND:-0.0.0.0}:${RVBOX_NATIVE_PORT}:443" ]
volumes:
- ./nginx.conf:/etc/nginx/conf.d/default.conf:ro
- "${RVBOX_NATIVE_RUNTIME_DIR}/pki/server.pem:/etc/nginx/tls/server.pem:ro"
- "${RVBOX_NATIVE_RUNTIME_DIR}/pki/server-key.pem:/etc/nginx/tls/server-key.pem:ro"
networks: [native]
labels: { rvbox.native.run_id: "${RVBOX_NATIVE_RUN_ID}" }
certgen:
image: alpine:3.22
profiles: [tools]
environment:
RVBOX_NATIVE_ENDPOINT_HOST: "${RVBOX_NATIVE_ENDPOINT_HOST}"
volumes:
- "${RVBOX_NATIVE_RUNTIME_DIR}/pki:/pki"
- ./certgen.sh:/fixture/certgen.sh:ro
entrypoint: ["/bin/sh", "/fixture/certgen.sh"]
networks:
native:
labels: { rvbox.native.run_id: "${RVBOX_NATIVE_RUN_ID}" }
+21
View File
@@ -0,0 +1,21 @@
map $http_upgrade $connection_upgrade {
default upgrade;
'' close;
}
server {
listen 443 ssl;
server_name _;
ssl_certificate /etc/nginx/tls/server.pem;
ssl_certificate_key /etc/nginx/tls/server-key.pem;
ssl_protocols TLSv1.2 TLSv1.3;
location = /v1/agent {
proxy_pass http://server:6899;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_set_header Host $host;
proxy_read_timeout 75s;
proxy_send_timeout 15s;
}
location / { return 404; }
}