feat: improve API keys and build workflows

This commit is contained in:
2026-10-04 20:05:13 +00:00 Unverified
parent 62f2362a2e
commit e4623efe86
27 changed files with 2080 additions and 235 deletions
+33
View File
@@ -1,6 +1,7 @@
import { afterEach, describe, expect, mock, spyOn, test } from "bun:test";
import type { ComposeSpecification, Service } from "../../schema/docker.d";
import {
DatabaseReconciliationError,
buildDatabaseUrl,
buildPostgresEnvironment,
getComposePostgresClaims,
@@ -152,6 +153,38 @@ describe("managed PostgreSQL claims", () => {
]);
});
test("reports database apply phase and claim without exposing provider credentials", async () => {
const claim = {
service: "app",
username: "app_role",
database: "app_db",
secretName: "postgres-app_role",
};
spyOn(objectApi, "read").mockImplementation(async (resource) => {
if (resource.kind === "Secret") {
return { ...resource, data: { password: Buffer.from("private-value").toString("base64") } } as never;
}
return { ...resource, spec: { managed: { roles: [] } } } as never;
});
spyOn(objectApi, "patch").mockImplementation(async (resource) => {
if (resource.kind === "Database") {
throw Object.assign(new Error("Forbidden: password=private-value"), { code: 403 });
}
return resource as never;
});
let failure: unknown;
try {
await reconcilePostgresClaim("project", claim);
} catch (error) {
failure = error;
}
expect(failure).toBeInstanceOf(DatabaseReconciliationError);
expect((failure as Error).message).toBe(
"Database reconciliation failed during database apply for database app_db (service app, role app_role): Forbidden (HTTP 403)",
);
expect((failure as Error).message).not.toContain("private-value");
});
test("reconciles a CNPG cluster returned with managed fields without sending them back", async () => {
const claim = {
service: "app",