# `checks.script-test-agent-bao-fetch` — runs the two agent units that log in # to the swarm secret store and fetch a secret, ../agent-modules/forge-token.nix # and ../agent-modules/queue-identity.nix, against a stub `bao`. The cases are # in ./agent-bao-fetch.sh. # # What runs is each unit's rendered `ExecStart`, on the unit's own `PATH` with # the stub in front. The one edit is the unit's `/run//` prefix, moved # under the build directory because the sandbox has no writable `/run`. { pkgs, lib, self, nixosSystem, }: let inherit (import ../module-eval/lib.nix { inherit pkgs lib self nixosSystem ; }) agentWith ; machine = agentWith { services.hyperhive.agent.bao.addr = "https://bao.t.local:8200"; }; unitEnv = prefix: name: let u = machine.systemd.services.${name}; in { "${prefix}_UNIT" = name; # `removeSuffix`, not `trim`: `trim` drops the string context, and with it # the script's store path from this check's inputs. "${prefix}_SCRIPT" = lib.removeSuffix " " u.serviceConfig.ExecStart; "${prefix}_PATH" = u.environment.PATH; "${prefix}_BAO_ADDR" = u.environment.BAO_ADDR; }; # Answers `login` and `kv get` from `FAKE_BAO_*` variables and logs every # call. A `kv` call without the token `login` printed fails, so a script that # drops `BAO_TOKEN` between the two cannot pass. fakeBao = pkgs.writeShellScriptBin "bao" '' echo "$*" >> "$FAKE_BAO_LOG" case "$1" in login) printf '%s' "$FAKE_BAO_LOGIN_ERR" >&2 printf '%s' "$FAKE_BAO_LOGIN_OUT" exit "$FAKE_BAO_LOGIN_RC" ;; kv) if [ "''${BAO_TOKEN-}" != "$FAKE_BAO_LOGIN_OUT" ]; then echo "fake bao: kv called without the login's token" >&2 exit 97 fi printf '%s' "$FAKE_BAO_KV_ERR" >&2 printf '%s' "$FAKE_BAO_KV_OUT" exit "$FAKE_BAO_KV_RC" ;; *) echo "fake bao: unexpected call: $*" >&2 exit 98 ;; esac ''; in pkgs.runCommand "hyperhive-script-test-agent-bao-fetch" ( unitEnv "FORGE" "hive-agent-forge-token" // unitEnv "QUEUE" "hive-agent-queue-credential" // { FAKE_BAO_BIN = "${fakeBao}/bin"; } ) '' ${pkgs.bash}/bin/bash ${./agent-bao-fetch.sh} touch "$out" ''