feat(core): single-source data_dir/repos_dir via castle.yaml

The `castle` CLI and the `castle-api` service are two independent in-process
drivers of `castle_core`. Each resolved DATA_DIR/REPOS_DIR at import time from
its own process env (default /data/castle), persisted nowhere — so they silently
diverged, and `apply`/dashboard-apply crashed on a non-existent /data.

Make the loaded CastleConfig the single source of truth:
- Resolve data_dir/repos_dir only in load_config (env > castle.yaml > default),
  anchored to the config root; drop the DATA_DIR/REPOS_DIR module globals and the
  import-time file read entirely — no global twin that can disagree with the file.
- Thread config.data_dir/repos_dir through ensure_dirs, _env_context, tls_dir_for
  (now unified — deploy no longer inlines the tls path), and create/add/clone.
- ensure_dirs raises an actionable CastleDirError instead of a bare PermissionError;
  the api surfaces it as 422.
- doctor: "data dir writable" check + WARN when CASTLE_DATA_DIR/REPOS_DIR env
  overrides the file (the one remaining cross-process divergence vector).
- install.sh persists data_dir/repos_dir into castle.yaml (idempotent, non-default).
- Docs: registry.md globals + AGENTS.md roots.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-07-06 23:02:33 -07:00
parent b28645f2f4
commit 340f469b3d
16 changed files with 417 additions and 88 deletions

View File

@@ -329,3 +329,141 @@ class TestConfigRoundTrip:
assert g.public_domain == "pub.io"
assert g.tunnel_id == "uuid-123"
assert g.cert_hook is True
class TestConfigurableRoots:
"""data_dir / repos_dir: env > castle.yaml > default. The single source of truth
that keeps the CLI and the api service from resolving different data dirs."""
@pytest.fixture(autouse=True)
def _no_root_env(self, monkeypatch: pytest.MonkeyPatch) -> None:
# The test host may export CASTLE_DATA_DIR (that's the bug we're fixing);
# clear it so yaml/default precedence is exercised deterministically.
monkeypatch.delenv("CASTLE_DATA_DIR", raising=False)
monkeypatch.delenv("CASTLE_REPOS_DIR", raising=False)
def test_resolve_precedence_env_over_yaml(
self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch
) -> None:
from castle_core.config import _DEFAULT_DATA_DIR, _resolve_root_path
monkeypatch.setenv("X_ROOT_ENV", "/from/env")
p = _resolve_root_path("X_ROOT_ENV", "/from/yaml", tmp_path, _DEFAULT_DATA_DIR)
assert p == Path("/from/env")
def test_resolve_yaml_over_default(self, tmp_path: Path) -> None:
from castle_core.config import _DEFAULT_DATA_DIR, _resolve_root_path
p = _resolve_root_path(
"UNSET_ROOT_ENV", "/from/yaml", tmp_path, _DEFAULT_DATA_DIR
)
assert p == Path("/from/yaml")
def test_resolve_default_when_neither(self, tmp_path: Path) -> None:
from castle_core.config import _DEFAULT_DATA_DIR, _resolve_root_path
p = _resolve_root_path("UNSET_ROOT_ENV", None, tmp_path, _DEFAULT_DATA_DIR)
assert p == _DEFAULT_DATA_DIR # returned as-is so save_config can compare equal
def test_resolve_expanduser(
self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch
) -> None:
from castle_core.config import _DEFAULT_DATA_DIR, _resolve_root_path
monkeypatch.setenv("X_ROOT_ENV", "~/box")
p = _resolve_root_path("X_ROOT_ENV", None, tmp_path, _DEFAULT_DATA_DIR)
assert p == (Path.home() / "box").resolve()
def test_resolve_relative_anchored_to_anchor_not_cwd(self, tmp_path: Path) -> None:
"""A relative root is anchored to the dir holding castle.yaml — never cwd, or
the CLI (shell cwd) and api (unit cwd) would diverge again."""
from castle_core.config import _DEFAULT_DATA_DIR, _resolve_root_path
p = _resolve_root_path(
"UNSET_ROOT_ENV", "sub/data", tmp_path, _DEFAULT_DATA_DIR
)
assert p == (tmp_path / "sub" / "data").resolve()
def test_load_config_reads_data_dir_from_yaml(self, tmp_path: Path) -> None:
(tmp_path / "castle.yaml").write_text(
yaml.dump({"gateway": {"port": 9000}, "data_dir": "/srv/box/data"})
)
config = load_config(tmp_path)
assert config.data_dir == Path("/srv/box/data")
def test_load_config_data_dir_defaults(self, tmp_path: Path) -> None:
from castle_core.config import _DEFAULT_DATA_DIR
(tmp_path / "castle.yaml").write_text(yaml.dump({"gateway": {"port": 9000}}))
config = load_config(tmp_path)
assert config.data_dir == _DEFAULT_DATA_DIR
def test_save_round_trips_nondefault_roots(self, tmp_path: Path) -> None:
from castle_core.config import GatewayConfig
cfg = CastleConfig(
root=tmp_path,
gateway=GatewayConfig(port=9000),
repo=None,
programs={},
data_dir=Path("/srv/box/data"),
repos_dir=Path("/srv/box/repos"),
)
save_config(cfg)
text = (tmp_path / "castle.yaml").read_text()
assert "data_dir: /srv/box/data" in text
assert "repos_dir: /srv/box/repos" in text
reloaded = load_config(tmp_path)
assert reloaded.data_dir == Path("/srv/box/data")
assert reloaded.repos_dir == Path("/srv/box/repos")
def test_save_omits_default_roots(self, tmp_path: Path) -> None:
from castle_core.config import (
_DEFAULT_DATA_DIR,
_DEFAULT_REPOS_DIR,
GatewayConfig,
)
cfg = CastleConfig(
root=tmp_path,
gateway=GatewayConfig(port=9000),
repo=None,
programs={},
data_dir=_DEFAULT_DATA_DIR,
repos_dir=_DEFAULT_REPOS_DIR,
)
save_config(cfg)
text = (tmp_path / "castle.yaml").read_text()
assert "data_dir" not in text
assert "repos_dir" not in text
def test_ensure_dirs_raises_actionable_error(
self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch
) -> None:
"""An uncreatable data dir yields a CastleDirError with a fix, not a bare OSError."""
import castle_core.config as C
from castle_core.config import GatewayConfig
# Redirect the in-$HOME dirs to tmp so the test never touches the real ~/.castle.
for name in (
"CASTLE_HOME",
"CODE_DIR",
"SPECS_DIR",
"CONTENT_DIR",
"SECRETS_DIR",
):
monkeypatch.setattr(C, name, tmp_path / name.lower())
# data_dir whose parent is a FILE → mkdir raises NotADirectoryError (OSError),
# deterministically, even if the suite runs as root.
blocker = tmp_path / "afile"
blocker.write_text("x")
cfg = CastleConfig(
root=tmp_path,
gateway=GatewayConfig(port=9000),
repo=None,
programs={},
data_dir=blocker / "sub",
)
with pytest.raises(C.CastleDirError) as ei:
C.ensure_dirs(cfg)
assert "data_dir" in str(ei.value)

View File

@@ -20,21 +20,27 @@ def _write_wildcard(xdg: Path, domain: str, tag: str, acme_dir: str) -> None:
@pytest.fixture
def tls_env(tmp_path: Path, monkeypatch: pytest.MonkeyPatch):
"""Isolate Caddy's cert store (XDG_DATA_HOME, read live) and DATA_DIR (patched
on the tls module) to a temp dir — no importlib.reload, so no global leak."""
"""Isolate Caddy's cert store (XDG_DATA_HOME, read live) to a temp dir. The data
dir is carried on the config (config.data_dir)the single source of truth — and
returned so tests can locate materialized certs via tls_dir_for(data_dir, ...)."""
domain = "civil.payne.io"
xdg = tmp_path / "xdg"
_write_wildcard(xdg, domain, "PROD", "acme-v02.api.letsencrypt.org-directory")
_write_wildcard(xdg, domain, "STAGING", "acme-staging-v02.api.letsencrypt.org-directory")
_write_wildcard(
xdg, domain, "STAGING", "acme-staging-v02.api.letsencrypt.org-directory"
)
monkeypatch.setenv("XDG_DATA_HOME", str(xdg))
monkeypatch.setattr(T, "DATA_DIR", tmp_path / "data") # tls_dir_for reads this
return T, C, domain
return T, C, domain, tmp_path / "data"
def _cfg(C, domain, dep):
def _cfg(C, domain, dep, data_dir):
return C.CastleConfig(
root=None, gateway=C.GatewayConfig(port=9000, domain=domain), repo=None,
programs={}, deployments={"postgres": dep},
root=None,
gateway=C.GatewayConfig(port=9000, domain=domain),
repo=None,
programs={},
data_dir=data_dir,
deployments={"postgres": dep},
)
@@ -51,31 +57,33 @@ def _pg(material: str):
def test_prefers_prod_over_staging(tls_env) -> None:
T, _, domain = tls_env
T, _, domain, _dd = tls_env
crt, _ = T.wildcard_cert(domain)
assert crt.read_text().strip() == "CERT-PROD"
def test_pair_material_and_idempotency(tls_env) -> None:
T, C, domain = tls_env
T, C, domain, dd = tls_env
pg = _pg("pair")
cfg = _cfg(C, domain, pg)
assert T.materialize_tls(cfg, "postgres", pg) is True # first write
cfg = _cfg(C, domain, pg, dd)
assert T.materialize_tls(cfg, "postgres", pg) is True # first write
assert T.materialize_tls(cfg, "postgres", pg) is False # idempotent
td = T.tls_dir_for("postgres")
td = T.tls_dir_for(dd, "postgres")
assert sorted(p.name for p in td.iterdir()) == ["cert.pem", "chain.pem", "key.pem"]
assert (td / "cert.pem").read_text().strip() == "CERT-PROD"
assert oct((td / "key.pem").stat().st_mode)[-3:] == "600" # secret
assert oct((td / "key.pem").stat().st_mode)[-3:] == "600" # secret
assert oct((td / "cert.pem").stat().st_mode)[-3:] == "644" # public
def test_material_switch_cleans_stale(tls_env) -> None:
T, C, domain = tls_env
T, C, domain, dd = tls_env
pair = _pg("pair")
T.materialize_tls(_cfg(C, domain, pair), "postgres", pair)
T.materialize_tls(_cfg(C, domain, pair, dd), "postgres", pair)
combined = _pg("combined")
assert T.materialize_tls(_cfg(C, domain, combined), "postgres", combined) is True
td = T.tls_dir_for("postgres")
assert (
T.materialize_tls(_cfg(C, domain, combined, dd), "postgres", combined) is True
)
td = T.tls_dir_for(dd, "postgres")
assert sorted(p.name for p in td.iterdir()) == ["chain.pem", "combined.pem"]
assert (td / "combined.pem").read_text() == "KEY-PROD\nCERT-PROD\n" # key + cert
assert oct((td / "combined.pem").stat().st_mode)[-3:] == "600"
@@ -85,28 +93,36 @@ def test_pair_chain_is_issuer_not_leaf(tls_env, tmp_path) -> None:
"""`chain.pem` (${tls_ca}) is the issuer chain — the intermediates only, leaf
stripped — so it's a real CA bundle distinct from the leaf-bearing cert.pem
(regression: they used to be byte-identical)."""
T, C, domain = tls_env
T, C, domain, dd = tls_env
leaf = b"-----BEGIN CERTIFICATE-----\nLEAF\n-----END CERTIFICATE-----\n"
inter = b"-----BEGIN CERTIFICATE-----\nINTERMEDIATE\n-----END CERTIFICATE-----\n"
crt_dir = (
Path(tmp_path) / "xdg" / "caddy" / "certificates"
/ "acme-v02.api.letsencrypt.org-directory" / f"wildcard_.{domain}"
Path(tmp_path)
/ "xdg"
/ "caddy"
/ "certificates"
/ "acme-v02.api.letsencrypt.org-directory"
/ f"wildcard_.{domain}"
)
(crt_dir / f"wildcard_.{domain}.crt").write_bytes(leaf + inter)
pg = _pg("pair")
assert T.materialize_tls(_cfg(C, domain, pg), "postgres", pg) is True
td = T.tls_dir_for("postgres")
assert T.materialize_tls(_cfg(C, domain, pg, dd), "postgres", pg) is True
td = T.tls_dir_for(dd, "postgres")
assert (td / "cert.pem").read_bytes() == leaf + inter # server presents leaf+chain
assert (td / "chain.pem").read_bytes() == inter # CA bundle = intermediates
assert (td / "chain.pem").read_bytes() == inter # CA bundle = intermediates
assert (td / "cert.pem").read_bytes() != (td / "chain.pem").read_bytes()
def test_material_off_is_noop(tls_env) -> None:
T, C, domain = tls_env
T, C, domain, dd = tls_env
off = SystemdDeployment.model_validate(
{"manager": "systemd", "program": "postgres",
"run": {"launcher": "container", "image": "postgres:17"},
"reach": "internal", "expose": {"tcp": {"port": 5432}}}
{
"manager": "systemd",
"program": "postgres",
"run": {"launcher": "container", "image": "postgres:17"},
"reach": "internal",
"expose": {"tcp": {"port": 5432}},
}
)
assert T.materialize_tls(_cfg(C, domain, off), "postgres", off) is False
assert not T.tls_dir_for("postgres").exists()
assert T.materialize_tls(_cfg(C, domain, off, dd), "postgres", off) is False
assert not T.tls_dir_for(dd, "postgres").exists()