405a2cfc0f
Enforce mTLS and least-privilege runtime boundaries while adding repeatable MySQL 8.4 and Docker smoke checks that require no production secrets.
29 lines
1.1 KiB
Markdown
29 lines
1.1 KiB
Markdown
# Local Docker smoke verification
|
|
|
|
Run from any directory:
|
|
|
|
```bash
|
|
/Users/rocky/Documents/OSGAccountServer/deploy/smoke-local.sh
|
|
```
|
|
|
|
Requirements: Docker with Compose v2, `curl`, `openssl`, and Python 3.
|
|
|
|
The runner builds the current checkout, creates an isolated MySQL 8.4 project,
|
|
generates one-time keys and administrator credentials, and uses an internal
|
|
Docker network. Apple, DeepSeek, and Volcengine endpoints point to the
|
|
container's closed loopback port, so no provider request can leave the project.
|
|
|
|
The checks cover:
|
|
|
|
- successful Flyway V1-V8 history and `/health/ready`;
|
|
- hidden admin routes without the trusted edge header;
|
|
- TOTP login, cookies, CSRF, role denial, core reads, grants, and logout;
|
|
- a 101-row ledger fixture that requires a second cursor page;
|
|
- an exact per-table runtime grant matrix;
|
|
- denied `UPDATE` and `DELETE` on ledger, audit, and grant history.
|
|
|
|
Containers, the named volume, the local smoke image, cookie jars, generated
|
|
keys, and administrator credentials are removed on exit. On failure, only
|
|
recent container status and logs remain in the printed temporary diagnostics
|
|
path.
|