test(e2e): one-shot PPE deploy+E2E resume script
Runs the whole §9 PPE stage non-interactively after the operator's gcloud reauth: bot-token-seed the PPE repos -> ensure E2E secret -> deploy -> wait for health=0.52.0 + bdd-collection sync -> run metadata.spec.js against the deployed host. Idempotent; secrets fetched from SM, never echoed. Test/ops infra (not in the deployed artifact). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Executable
+86
@@ -0,0 +1,86 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
# One-shot resume for the §9 PPE deployed-environment E2E stage.
|
||||||
|
#
|
||||||
|
# PRECONDITION: the operator has run the interactive Workspace reauth:
|
||||||
|
# gcloud auth login && gcloud auth application-default login
|
||||||
|
# (Only they can — the gcloud CLI creds expire under the Workspace session
|
||||||
|
# policy even when ADC is valid.)
|
||||||
|
#
|
||||||
|
# This script then runs the whole pipeline non-interactively:
|
||||||
|
# 1. read the bot token from Secret Manager (never echoed) and use it to
|
||||||
|
# create + seed the dedicated PPE registry + content repos;
|
||||||
|
# 2. ensure the E2E test-auth shared secret exists (generates one if not);
|
||||||
|
# 3. deploy rfc-app-ppe via flotilla-core (pins .rfc-app-version.ppe=0.52.0);
|
||||||
|
# 4. wait for /api/health to report the expected version, then for the
|
||||||
|
# reconciler to sync the seeded bdd collection into the cache;
|
||||||
|
# 5. run metadata.spec.js (SLICE-3/4/5) against the deployed PPE host.
|
||||||
|
#
|
||||||
|
# Idempotent: re-running re-seeds (RESEED=1 restores SLICE-4/5 preconditions),
|
||||||
|
# reuses the existing E2E secret, and redeploys.
|
||||||
|
|
||||||
|
REPO_ROOT="$HOME/git/wiggleverse.org/ben.stull/rfc-app"
|
||||||
|
FLOTILLA="$HOME/git/wiggleverse.org/wiggleverse/flotilla-core/.venv/bin/flotilla-core"
|
||||||
|
PPE_HOST="https://rfc-ppe.wiggleverse.org"
|
||||||
|
EXPECT_VERSION="0.52.0"
|
||||||
|
BOT_SECRET_PROJECT="wiggleverse-ohm"
|
||||||
|
BOT_SECRET_ID="ohm-rfc-app-gitea-bot-token"
|
||||||
|
E2E_SECRET_PROJECT="rfc-app-ppe"
|
||||||
|
E2E_SECRET_ID="rfc-app-ppe-e2e-test-auth-secret"
|
||||||
|
E2E_EMAIL="e2e-owner@example.test"
|
||||||
|
export CLOUDSDK_ACTIVE_CONFIG_NAME="rfc-app-ppe"
|
||||||
|
|
||||||
|
echo "== 0. precheck gcloud reauth =="
|
||||||
|
if ! gcloud secrets list --project="$E2E_SECRET_PROJECT" --limit=1 >/dev/null 2>&1; then
|
||||||
|
echo "gcloud is not reauthed. Run: gcloud auth login && gcloud auth application-default login" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "gcloud OK"
|
||||||
|
|
||||||
|
echo "== 1. create + seed PPE repos (bot token; never echoed) =="
|
||||||
|
GITEA_TOKEN="$(gcloud secrets versions access latest --secret="$BOT_SECRET_ID" --project="$BOT_SECRET_PROJECT")" \
|
||||||
|
RESEED="${RESEED:-1}" \
|
||||||
|
bash "$REPO_ROOT/testing/seed-ppe.sh"
|
||||||
|
|
||||||
|
echo "== 2. ensure E2E test-auth secret exists =="
|
||||||
|
if gcloud secrets describe "$E2E_SECRET_ID" --project="$E2E_SECRET_PROJECT" >/dev/null 2>&1; then
|
||||||
|
echo "E2E secret already exists; ensuring binding"
|
||||||
|
"$FLOTILLA" secret bind rfc-app-ppe E2E_TEST_AUTH_SECRET "$E2E_SECRET_PROJECT/$E2E_SECRET_ID@latest"
|
||||||
|
else
|
||||||
|
echo "creating E2E secret (random, via stdin — bytes never echoed)"
|
||||||
|
openssl rand -hex 32 | "$FLOTILLA" secret set rfc-app-ppe E2E_TEST_AUTH_SECRET
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "== 3. deploy rfc-app-ppe =="
|
||||||
|
"$FLOTILLA" deploy rfc-app-ppe
|
||||||
|
|
||||||
|
echo "== 4a. verify /api/health reports $EXPECT_VERSION =="
|
||||||
|
ok=0
|
||||||
|
for _ in $(seq 1 24); do
|
||||||
|
body="$(curl -s "$PPE_HOST/api/health" || true)"
|
||||||
|
echo " health: $body"
|
||||||
|
if printf '%s' "$body" | grep -q "\"version\":\"$EXPECT_VERSION\""; then ok=1; break; fi
|
||||||
|
sleep 5
|
||||||
|
done
|
||||||
|
[ "$ok" = 1 ] || { echo "health never reported $EXPECT_VERSION" >&2; exit 1; }
|
||||||
|
|
||||||
|
echo "== 4b. wait for the seeded bdd collection to sync into the cache =="
|
||||||
|
ok=0
|
||||||
|
for _ in $(seq 1 40); do
|
||||||
|
body="$(curl -s "$PPE_HOST/api/projects/ohm/collections/bdd/rfcs" || true)"
|
||||||
|
n="$(printf '%s' "$body" | grep -o 'checkout-guest\|checkout-returning\|search-facets' | sort -u | wc -l | tr -d ' ')"
|
||||||
|
echo " synced entries: $n/3"
|
||||||
|
if [ "$n" = 3 ]; then ok=1; break; fi
|
||||||
|
sleep 6
|
||||||
|
done
|
||||||
|
[ "$ok" = 1 ] || { echo "bdd collection never synced 3 entries" >&2; exit 1; }
|
||||||
|
|
||||||
|
echo "== 5. run metadata.spec.js against PPE =="
|
||||||
|
E2E_SECRET="$(gcloud secrets versions access latest --secret="$E2E_SECRET_ID" --project="$E2E_SECRET_PROJECT")"
|
||||||
|
cd "$REPO_ROOT/e2e"
|
||||||
|
BASE_URL="$PPE_HOST" \
|
||||||
|
E2E_TEST_AUTH_SECRET="$E2E_SECRET" \
|
||||||
|
E2E_OWNER_EMAIL="$E2E_EMAIL" \
|
||||||
|
npx playwright test metadata.spec.js
|
||||||
|
echo "== DONE: PPE E2E complete =="
|
||||||
Reference in New Issue
Block a user