- orchestrator: per mutating tier, run optional pre-op seed hook (ops.py pre_<op>) → perform the op
ONCE (harness-owned) → run generic assertion (unless opted out) AND overlay assertion, both against
the shared post-op deployment. Op results passed op→assertion via run-scoped CCCI_OP_STATE_FILE.
- opt-out: CCCI_SKIP_GENERIC / CCCI_SKIP_GENERIC_<OP> / recipe_meta.SKIP_GENERIC (declarative).
- generic.py: split do_* into op primitives (perform_upgrade/backup/restore) + assertions
(assert_upgraded/backup_artifact/restore_healthy) reading op_state(); deployed_identity now returns
{version,image,chaos} (chaos label ready for HC1).
- generic test_<op>.py + all 6 recipe overlays migrated to assertion-only; pre-op seeding moved to
per-recipe ops.py (pre_upgrade/pre_backup/pre_restore). install overlays unchanged (no op).
- deploy-count stays 1 (op primitives never call deploy_app). lint PASS; 8 unit tests PASS on cc-ci.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
34 lines
1.3 KiB
Python
34 lines
1.3 KiB
Python
"""keycloak — pre-op seed hooks (Phase 1e HC3). The orchestrator runs these BEFORE the op; the
|
|
matching test_<op>.py asserts post-op (assertion-only). The data marker is a realm in mariadb,
|
|
written via the keycloak admin API (kc_admin)."""
|
|
|
|
import os
|
|
import sys
|
|
|
|
sys.path.insert(0, os.path.join(os.path.dirname(__file__), "..", "..", "runner"))
|
|
import kc_admin # noqa: E402
|
|
from harness import generic # noqa: E402
|
|
|
|
|
|
def _token(domain):
|
|
return kc_admin.admin_token(domain, kc_admin.admin_password(domain))
|
|
|
|
|
|
def pre_upgrade(domain, meta):
|
|
# create the marker realm (DB data) before the upgrade so the overlay can prove it survives
|
|
assert kc_admin.create_marker_realm(domain, _token(domain)) in (201, 409)
|
|
|
|
|
|
def pre_backup(domain, meta):
|
|
# establish the marker realm before the backup op captures mariadb
|
|
assert kc_admin.create_marker_realm(domain, _token(domain)) in (201, 409)
|
|
|
|
|
|
def pre_restore(domain, meta):
|
|
# backup-bot-two cycles the keycloak container during backup → wait for serving, re-auth, then
|
|
# delete the realm (diverge from the backup) so a successful restore is observable
|
|
generic.assert_serving(domain, meta)
|
|
tok = _token(domain)
|
|
assert kc_admin.delete_marker_realm(domain, tok) in (204, 200)
|
|
assert not kc_admin.marker_realm_exists(domain, tok), "delete did not take"
|