fix(deploy): align runtime identity and ingress
This commit is contained in:
@@ -19,11 +19,13 @@ describe("production deployment contract", () => {
|
||||
/requests:\s+cpu: 500m\s+memory: 512Mi\s+limits:\s+cpu: "1"\s+memory: 1Gi/u,
|
||||
);
|
||||
expect(deployment).toContain("runAsNonRoot: true");
|
||||
expect(deployment).toContain("runAsUser: 1000");
|
||||
expect(deployment).toContain("runAsGroup: 1000");
|
||||
expect(deployment).toContain("readOnlyRootFilesystem: true");
|
||||
expect(deployment).toContain('drop: ["ALL"]');
|
||||
});
|
||||
|
||||
it("exposes only the app through the requested service and TLS host", async () => {
|
||||
it("exposes only the app through the requested edge-TLS host", async () => {
|
||||
const [service, ingress] = await Promise.all([
|
||||
repositoryFile("k8s/base/service.yaml"),
|
||||
repositoryFile("k8s/base/ingress.yaml"),
|
||||
@@ -34,7 +36,8 @@ describe("production deployment contract", () => {
|
||||
expect(service).toContain("targetPort: http");
|
||||
expect(ingress).toContain("ingressClassName: traefik");
|
||||
expect(ingress).toContain("host: sheet.sudloh.com");
|
||||
expect(ingress).toContain("secretName: sheet-sudloh-com-tls");
|
||||
expect(ingress).not.toContain("secretName:");
|
||||
expect(ingress).not.toContain("router.tls");
|
||||
});
|
||||
|
||||
it("keeps availability and scaling bounds explicit", async () => {
|
||||
@@ -78,7 +81,7 @@ describe("production deployment contract", () => {
|
||||
|
||||
expect(dockerfile).toContain("FROM dependencies AS migration");
|
||||
expect(dockerfile).toContain("FROM oven/bun:${BUN_VERSION} AS app");
|
||||
expect(dockerfile.match(/^USER bun$/gmu)).toHaveLength(2);
|
||||
expect(dockerfile.match(/^USER 1000:1000$/gmu)).toHaveLength(2);
|
||||
expect(dockerfile).toContain('ENTRYPOINT ["bun", "scripts/migrate.ts"]');
|
||||
expect(dockerfile).toContain('CMD ["bun", "server.js"]');
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user