fix(api): editable-spec detail + PATCH-merge saves + shared gateway parser

Deployment/program edits could silently drop spec fields:

- GET /deployments/{name} served the runtime view (no reach/program/root/expose)
  for deployed deployments, so the dashboard round-tripped a lossy manifest and
  stripped fields on save (broke astro). Now serves the editable castle.yaml spec
  when the deployment is in config.
- _save_deployment and save_program replaced the whole object with client input.
  Now shallow-merge over the existing spec (omit = preserve, null = clear), so a
  partial/lossy save can't drop untouched fields.
- save_yaml rebuilt GatewayConfig from `port` only, wiping tls/domain/tunnel/
  cert_hook on a whole-file save. Now uses a shared parse_gateway() (also used by
  load_config) so gateway fields can't drift between the two.

Dashboard forms (ServiceFields/StaticFields) send explicit null to clear, per the
merge contract; adds exposure host-label helpers. Coverage: detail-serves-spec,
save round-trip, partial-patch-preserves, null-clears, program partial-patch,
parse_gateway, and config save/load round-trip.
This commit is contained in:
2026-07-05 23:23:59 -07:00
parent eeaa65f7ce
commit 07c02aa151
10 changed files with 309 additions and 72 deletions

View File

@@ -0,0 +1,78 @@
"""Edit-safety tests for the deployment detail + save endpoints.
These guard the regression that broke astro (and postgres): the detail endpoint
served the *runtime view* (no reach/program/root/expose) for a deployed deployment,
so the dashboard edit form round-tripped a lossy manifest and stripped spec-only
fields on save. The fixtures already have `test-svc` deployed AND defined in
castle.yaml (with legacy `proxy: true` → `reach: internal`) — exactly that case.
"""
from __future__ import annotations
from fastapi.testclient import TestClient
class TestDeploymentEditSafety:
def test_detail_serves_editable_spec_not_runtime(self, client: TestClient) -> None:
"""A deployed deployment that's in castle.yaml serves its EDITABLE SPEC —
the shape the edit form consumes (launcher nested under `run`, plus
reach/expose) — not the flat runtime view (`run_cmd`, top-level launcher)."""
m = client.get("/deployments/test-svc").json()["manifest"]
assert m["run"]["launcher"] == "python" # spec shape (nested)
assert "run_cmd" not in m # runtime-only key absent
assert m.get("reach") == "internal" # normalized from proxy:true
assert m["expose"]["http"]["internal"]["port"] == 19000
def test_save_roundtrip_preserves_spec_fields(self, client: TestClient) -> None:
"""GET a deployment's manifest → PUT it back unchanged → GET again: no
spec field may be lost. This is the exact round-trip the dashboard does on
an edit, and the exact thing that dropped astro's program/root."""
before = client.get("/deployments/test-svc").json()["manifest"]
resp = client.put("/config/deployments/test-svc", json={"config": before})
assert resp.status_code == 200, resp.text
after = client.get("/deployments/test-svc").json()["manifest"]
for key in ("reach", "expose", "run", "program"):
assert after.get(key) == before.get(key), f"{key} lost on save round-trip"
def test_partial_patch_preserves_untouched_fields(self, client: TestClient) -> None:
"""PATCH semantics: sending ONLY the changed field must not drop the rest.
This is what makes the astro-class regression structurally impossible —
even a client that sends a lossy payload can't nuke fields it omitted."""
before = client.get("/deployments/test-svc").json()["manifest"]
resp = client.put("/config/deployments/test-svc", json={"config": {"reach": "off"}})
assert resp.status_code == 200, resp.text
after = client.get("/deployments/test-svc").json()["manifest"]
assert after["reach"] == "off" # the change applied
assert after["program"] == before["program"] # untouched → preserved
assert after["run"] == before["run"]
assert after["expose"] == before["expose"]
def test_explicit_null_clears_a_field(self, client: TestClient) -> None:
"""An explicit null clears a field — so a form can still *remove* exposure
under merge semantics (omit = preserve, null = clear). Removing the port
goes with reach: off (a port-only process), which is what ServiceFields
sends when the port is cleared."""
resp = client.put(
"/config/deployments/test-svc",
json={"config": {"expose": None, "reach": "off"}},
)
assert resp.status_code == 200, resp.text
after = client.get("/deployments/test-svc").json()["manifest"]
assert after.get("expose") is None # cleared
assert after["reach"] == "off"
assert after["program"] == "test-svc-comp" # rest preserved
class TestProgramEditSafety:
def test_program_partial_patch_preserves(self, client: TestClient) -> None:
"""save_program is the same footgun: a partial edit must not drop
source/commands. Send only a description; the rest survives."""
resp = client.put(
"/config/programs/wired-in",
json={"config": {"description": "renamed"}},
)
assert resp.status_code == 200, resp.text
m = client.get("/programs/wired-in").json()["manifest"]
assert m["description"] == "renamed" # change applied
assert m["source"].endswith("wired-in") # source preserved
assert m["commands"]["lint"] == [["make", "lint"]] # commands preserved