Skip to content

test: smoke-test the running stack in CI - #308

Closed
sabinem wants to merge 3 commits into
mainfrom
test/ci-smoke-suite
Closed

sabinem wants to merge 3 commits into
mainfrom
test/ci-smoke-suite

Conversation

@sabinem

@sabinem sabinem commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator

CI already started Postgres, Keycloak and the backend to run the seed, then tore the whole thing down without asking it a single question. The suites under internal/** run on in-memory SQLite behind a mock keyfunc over bufconn, so three things production depends on were never exercised anywhere: the Postgres schema the migration actually produces, the token exchange with Keycloak, and the gRPC server on a real port.

Six specs now run against that stack before it is discarded: health over the socket, a genuine Keycloak token resolving to the seeded user, the seeded fixture read back out of Postgres, a hackathon written and read back, and two refusals asserted on the code rather than merely on failure — PERMISSION_DENIED is a clean 403 in the frontend, INTERNAL is a 500, and a test that accepts any error cannot tell them apart.

The stack boot was already paid for, so this adds well under a second.

@sabinem
sabinem marked this pull request as draft September 15, 2026 08:08
CI already started Postgres, Keycloak and the backend to run the seed, then
tore the whole thing down without asking it a single question. The suites
under internal/** run on in-memory SQLite behind a mock keyfunc over bufconn,
so three things production depends on were never exercised anywhere: the
Postgres schema the migration actually produces, the token exchange with
Keycloak, and the gRPC server on a real port.

Six specs now run against that stack before it is discarded: health over the
socket, a genuine Keycloak token resolving to the seeded user, the seeded
fixture read back out of Postgres, a hackathon written and read back, and two
refusals asserted on the code rather than merely on failure — PERMISSION_DENIED
is a clean 403 in the frontend, INTERNAL is a 500, and a test that accepts any
error cannot tell them apart.

The stack boot was already paid for, so this adds well under a second.
Both recipes returned as soon as they had asked for the backend to be
scaled back up, so dev could still be starting, or failing to start,
when they reported success. _backend-up, the counterpart to
_backend-down, now scales up and waits for the rollout, and its
failure fails the recipe even from the EXIT trap, which otherwise
keeps the exit status it found.
check::smoke defaults to the local stack. cluster::smoke points it at
dev: it waits for the backend, port-forwards svc/hackagon-backend, and
takes the Keycloak address and realm from the backend's own issuerurl,
so tokens always come from the issuer the backend trusts. A failure
names the usual causes on dev: an unseeded database, missing fixture
users or a different password, or direct access grants switched off.
@sabinem
sabinem force-pushed the test/ci-smoke-suite branch from b2ec2dd to b2e7cad Compare October 8, 2026 12:38
@sabinem

sabinem commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator Author

close for now.

@sabinem sabinem closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant