Mechanical, semantics-preserving cleanup so the codebase passes the new lint stage:
- ruff format: all 32 Python files (wraps long signatures, normalizes quotes/blank lines).
- nixpkgs-fmt: modules/drone-runner.nix.
- shfmt (-i 2 -ci): scripts/*.sh.
Lint fixes (reviewed, behavior-preserving — no test weakened):
- ruff SIM105: try/except-pass -> contextlib.suppress (abra.py app_config rm; lifecycle.py janitor).
- ruff SIM115: open().read() -> with open() (run_recipe_ci.py redaction-values + gitea-token).
- statix: merge repeated sops `secrets.*` keys into one `secrets = { ... }` (comments kept);
empty fn pattern `{ ... }:` -> `_:` (packages.nix).
- deadnix: drop unused lambda args (flake `self`; configuration.nix `lib`; overlay `final` -> `_`).
Verified on cc-ci: `scripts/lint.sh` -> lint: PASS; nixosConfigurations.cc-ci evaluates;
all Python byte-compiles. The deployed bridge/dashboard/runner source changes hash (reformat),
so cc-ci will be rebuilt to the new closure in W2 before the cold D1-D10 re-verification.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
33 lines
1.2 KiB
Python
33 lines
1.2 KiB
Python
"""keycloak — backup/restore stage (D2): create a realm, backup, delete it (mutate), restore,
|
|
assert the realm is back (mariadb restored to the backed-up state)."""
|
|
|
|
import os
|
|
import sys
|
|
|
|
sys.path.insert(0, os.path.join(os.path.dirname(__file__), "..", "..", "runner"))
|
|
import kc_admin # noqa: E402
|
|
from harness import lifecycle # noqa: E402
|
|
|
|
|
|
def test_backup_mutate_restore(deployed):
|
|
domain = deployed
|
|
pw = kc_admin.admin_password(domain)
|
|
tok = kc_admin.admin_token(domain, pw)
|
|
|
|
# 1) create the marker realm, then back up
|
|
assert kc_admin.create_marker_realm(domain, tok) in (201, 409)
|
|
assert kc_admin.marker_realm_exists(domain, tok)
|
|
lifecycle.backup_app(domain)
|
|
|
|
# 2) mutate: delete the realm
|
|
assert kc_admin.delete_marker_realm(domain, tok) in (204, 200)
|
|
assert not kc_admin.marker_realm_exists(domain, tok), "delete did not take"
|
|
|
|
# 3) restore -> realm returns
|
|
lifecycle.restore_app(domain)
|
|
lifecycle.wait_healthy(
|
|
domain, path="/realms/master", ok_codes=(200,), deploy_timeout=600, http_timeout=600
|
|
)
|
|
tok2 = kc_admin.admin_token(domain, pw)
|
|
assert kc_admin.marker_realm_exists(domain, tok2), "restore did not bring back the realm"
|