Repo-side rename only (Phases 1-3 of the migration plan); the live box (~/.castle, systemd units, /data/castle, domains) is a separate cutover. - Slug `castle` -> `wildpc`: CLI command, module names (wildpc_core/cli/api), dist names, entry point `wildpc = wildpc_cli.main:main`. - Identifiers: CastleConfig/NATSClient/DirError/MDNS -> Wildpc*. - Env/constants: CASTLE_* -> WILDPC_*; ~/.castle -> ~/.wildpc, castle.yaml -> wildpc.yaml, /data/castle -> /data/wildpc. - Systemd UNIT_PREFIX castle- -> wildpc-; own programs castle-api/gateway/etc. - Display prose "Castle" -> "Wild PC" in docs, agent-guide files, README, frontend. - Package dirs and bootstrap yaml renamed via git mv; lockfiles regenerated; redundant nested uv.lock files dropped (workspace root lock is authoritative). Tests: core 273, cli 47, wildpc-api 120 all pass. Frontend type-checks + builds. Fixed a stale test fixture (secret_env_path kind arg) broken pre-rename.
74 lines
2.6 KiB
Python
74 lines
2.6 KiB
Python
"""Tests for the pluggable secret backends (file default, OpenBao opt-in)."""
|
|
|
|
from __future__ import annotations
|
|
|
|
from pathlib import Path
|
|
|
|
from wildpc_core.secret_backends import (
|
|
FileSecretBackend,
|
|
OpenBaoBackend,
|
|
build_backend,
|
|
)
|
|
|
|
|
|
def test_file_backend_read_hit(tmp_path: Path) -> None:
|
|
(tmp_path / "MY_SECRET").write_text("value\n")
|
|
assert FileSecretBackend(tmp_path).read("MY_SECRET") == "value"
|
|
|
|
|
|
def test_file_backend_read_miss(tmp_path: Path) -> None:
|
|
assert FileSecretBackend(tmp_path).read("ABSENT") is None
|
|
|
|
|
|
def test_file_backend_write_read_list_delete(tmp_path: Path) -> None:
|
|
b = FileSecretBackend(tmp_path)
|
|
assert b.list_names() == []
|
|
b.write("A", "one")
|
|
b.write("B", "two")
|
|
assert b.read("A") == "one"
|
|
assert b.list_names() == ["A", "B"]
|
|
b.delete("A")
|
|
assert b.read("A") is None
|
|
assert b.list_names() == ["B"]
|
|
b.delete("ABSENT") # no error
|
|
|
|
|
|
def test_build_backend_defaults_to_file(tmp_path: Path, monkeypatch) -> None:
|
|
monkeypatch.delenv("WILDPC_SECRET_BACKEND", raising=False)
|
|
assert isinstance(build_backend(tmp_path), FileSecretBackend)
|
|
|
|
|
|
def test_build_backend_openbao_via_env(tmp_path: Path, monkeypatch) -> None:
|
|
monkeypatch.setenv("WILDPC_SECRET_BACKEND", "openbao")
|
|
assert isinstance(build_backend(tmp_path), OpenBaoBackend)
|
|
|
|
|
|
def test_build_backend_openbao_via_settings(tmp_path: Path, monkeypatch) -> None:
|
|
"""The wildpc.yaml `secrets:` block selects the backend (env still overrides)."""
|
|
monkeypatch.delenv("WILDPC_SECRET_BACKEND", raising=False)
|
|
settings = {"backend": "openbao", "addr": "https://vault:8200", "mount": "wildpc"}
|
|
assert isinstance(build_backend(tmp_path, settings), OpenBaoBackend)
|
|
|
|
|
|
def test_openbao_unreachable_returns_none_no_fallback(tmp_path: Path) -> None:
|
|
"""No file fallback: an unreachable vault returns None even if a file exists."""
|
|
(tmp_path / "ONLY_IN_FILE").write_text("from-file")
|
|
backend = OpenBaoBackend(addr="http://127.0.0.1:1", token="dummy", mount="wildpc")
|
|
assert backend.read("ONLY_IN_FILE") is None
|
|
assert backend.read("NOT_ANYWHERE") is None
|
|
|
|
|
|
def test_openbao_empty_token_returns_none(tmp_path: Path) -> None:
|
|
backend = OpenBaoBackend(addr="http://127.0.0.1:8200", token="", mount="wildpc")
|
|
assert backend.read("K") is None
|
|
|
|
|
|
def test_openbao_node_prefix_from_settings(tmp_path: Path, monkeypatch) -> None:
|
|
monkeypatch.delenv("WILDPC_SECRET_BACKEND", raising=False)
|
|
backend = build_backend(
|
|
tmp_path,
|
|
{"backend": "openbao", "addr": "http://x", "node_prefix": "nodes/primer"},
|
|
)
|
|
assert isinstance(backend, OpenBaoBackend)
|
|
assert backend._node_prefix == "nodes/primer"
|