Files
copilotkit__copilotkit/showcase/bin/spec/test_promote_p3.rb
Jordan Ritter c03270135e fix(showcase): promote resolves staging tag to GHCR digest before pinning prod
The showcase deploy model is STAGING = mutable :latest tag, PROD = immutable
@sha256: digest (P6 enforces both shapes). SnapshotCommand#build_snapshot
stored the raw serviceInstance.source.image, so for staging svc["image"] was
the :latest TAG. execute_promotion was pinning THAT mutable tag to prod via
serviceInstanceUpdate, defeating the immutable-prod invariant before
pin_and_verify raised on the nil expected_digest.

Fix: add PromoteCommand#resolved_prod_image — returns the staging svc as
@sha256:-pinned (pass-through if already pinned; resolves the tag via the
shared GHCR client otherwise; returns nil if the tag cannot be resolved).
execute_promotion now refuses (P0) rather than pin a mutable tag, and
check_p1_ghcr_digests verifies the resolved digest (it previously SKIPPED
tag-form images entirely, so :latest was never P1-checked).

Also:
- P2 race-check guards latest["meta"] when Railway returns a JSON String
  (deserialized as Ruby String, not Hash) — .dig used to crash with
  NoMethodError. SUCCESS status remains the real gate.
- Remove dead --include-startcommand flag (never read; doubly inert because
  P6 REFUSEs on any startCommand divergence).
- Spec hygiene: P3 skip-test raises if probe runs under --no-require-staging-
  green; P6 warn-proceed stubs execute_promotion to isolate the gate and
  asserts rc==0; test_ghcr_token teardown unconditionally deletes
  GITHUB_TOKEN/GHCR_TOKEN/RAILWAY_TOKEN before restoring priors.

70 runs, 204 assertions, 0 failures (up from 66/188 baseline).
2026-05-29 11:45:13 -07:00

67 lines
3.2 KiB
Ruby

# frozen_string_literal: true
require_relative "spec_helper"
class PromoteP3Test < Minitest::Test
def make_cmd(probe_result:, flag:)
argv = ["--non-interactive", "--yes"]
argv << flag if flag
c = Railway::PromoteCommand.new(argv)
# run_with_preflight_only skips parser.parse!; parse eagerly so the
# --no-require-staging-green / --confirm-divergence flags land.
c.parser.parse!(c.argv)
c.instance_variable_set(:@staging_snapshot, {
"services" => [{
"name" => "x", "service_id" => "svc-1",
"image" => "ghcr.io/copilotkit/x:latest", "digest" => "sha256:abc",
"env_keys" => [],
"start_command" => "node server.js", "healthcheck_path" => "/health",
"region" => "us-west", "replicas" => 1, "restart_policy" => "ON_FAILURE",
}],
})
c.instance_variable_set(:@prod_snapshot, {
"services" => [{
"name" => "x", "service_id" => "svc-1",
"image" => "ghcr.io/copilotkit/x@sha256:abc", "digest" => "sha256:abc",
"env_keys" => [],
"start_command" => "node server.js", "healthcheck_path" => "/health",
"region" => "us-west", "replicas" => 1, "restart_policy" => "ON_FAILURE",
}],
})
c.instance_variable_set(:@gql, Object.new.tap { |o| def o.query(*); { "deployments" => { "edges" => [{ "node" => { "id" => "d", "status" => "SUCCESS", "meta" => { "image" => "ghcr.io/copilotkit/x@sha256:abc" } } }] } }; end })
c.instance_variable_set(:@ghcr, Object.new.tap do |o|
def o.manifest_exists(_); :exists; end
def o.resolve_digest(ref); ref.include?("@sha256:") ? ref.split("@", 2).last : "sha256:abc"; end
def o.parse_image_ref(ref); Railway::GHCR.allocate.parse_image_ref(ref); end
end)
# Inject the probe result as a stub.
c.define_singleton_method(:run_staging_probe) { |services:| probe_result }
c
end
def test_refuses_on_red_probe_when_flag_default_on
cmd = make_cmd(probe_result: { ok: false, summary: "x: HTTP 502 from docs.staging.copilotkit.ai" }, flag: nil)
out, _ = capture_io { @rc = cmd.run_with_preflight_only }
assert_equal 1, @rc
assert_match(/REFUSE: P3.*staging.*not green.*HTTP 502/i, out)
end
def test_skips_probe_when_no_require_staging_green
cmd = make_cmd(probe_result: { ok: false, summary: "would have failed" }, flag: "--no-require-staging-green")
# Fail LOUD if the skip path ever calls the probe — the probe stub
# must be unreachable under --no-require-staging-green.
cmd.define_singleton_method(:run_staging_probe) do |services:|
raise "probe must not run under --no-require-staging-green"
end
out, _ = capture_io { cmd.run_with_preflight_only }
refute_match(/REFUSE: P3/, out)
assert_match(/P3 SKIPPED.*--no-require-staging-green/, out)
end
def test_passes_p3_on_green_probe
cmd = make_cmd(probe_result: { ok: true, summary: "all green" }, flag: nil)
out, _ = capture_io { cmd.run_with_preflight_only }
refute_match(/REFUSE: P3/, out)
end
end