Skip to content

Opt-in real-OCI verification harness for describe/observe/validate/plan - #12

Merged
sinkog merged 3 commits into
mainfrom
devel
Aug 2, 2026
Merged

Opt-in real-OCI verification harness for describe/observe/validate/plan#12
sinkog merged 3 commits into
mainfrom
devel

Conversation

@sinkog

@sinkog sinkog commented Aug 2, 2026

Copy link
Copy Markdown
Member

Summary

  • Adds module/manual_real_oci_test.go: calls the module's own handler functions (Describe/Observe/Validate/Plan) against a real OCI tenancy, using the real API-key signing scheme — covers what the existing mock-host tests (relay_integration_test.go, module_loadtest_test.go) cannot: whether the request/response logic actually works against live OCI.
  • Double-gated so it never runs by default: absent without the manual_real_oci build tag, and skips without REAL_OCI_TEST=1 even when built with the tag.
  • Adds docs/design/manual-verification.md: coverage table (describe/observe/validate/plan verified; poll blocked on no live work-request found; execute/invoke/destroy out of scope, mutating), plus a concrete finding — describe()'s required_capabilities.egress_hosts is *.oraclecloud.com only, but this was verified against an EU Sovereign realm tenancy whose real host is oraclecloud.eu.
  • Adds a golang.test.manual-real-oci Makefile target mirroring the existing golang.test docker pattern (not verified in this environment — no docker available here; flagged in the target's own output that OCI_KEY_PATH needs to be reachable inside the builder container, which the current docker-compose.yml doesn't mount).
  • Regenerates MANIFEST.sha256.

Test plan

  • go vet ./... (no tags) — file invisible, unaffected
  • go test -tags manual_real_oci ./... without REAL_OCI_TEST — all gated tests SKIP cleanly
  • go test -tags manual_real_oci -run TestManualRealOCI -v ./... with real OCI credentials — Describe/Observe (Vcn + Subnet)/Validate/Plan (noop + update) all PASS against a live tenancy
  • CI green on devel (lint_and_test, including the WASM build/host-load steps, unaffected by the new file)

Gábor Z Sinkó added 3 commits July 19, 2026 22:05
Makes provider errors actionable and adds the concurrency guard the spec's error
model and concurrency sections call for — both on the shared actuateSigned core.

- ociError(status, body): parses OCI's {code, message} response and maps the HTTP
  status to a CIC-canonical class (400→validation, 401/403→permission, 404→
  not-found, 409/412→conflict, 429→transport+retryable, 5xx→provider+retryable),
  preserving the native provider_code for evidence. execute/observe/destroy/
  invoke/poll now return the mapped error instead of a bare "HTTP N"; execution
  steps carry error_class + provider_code.
- If-Match: execBinding.revision (the observed etag) is sent as an unsigned
  If-Match header on mutations (execute/destroy/invoke), so a concurrent change
  yields 412 → conflict, never a silent overwrite. GET ops (observe/poll) send
  none. actuateSigned gained the ifMatch arg.
- destroy now also surfaces async Work Requests (accepted + work_request_id).

TestExecuteErrorAndIfMatch covers 409→conflict/IncorrectState and the If-Match
header. Full local CI green (golang.quality, wasm.build/integrity/test full suite,
check, verify-release, manifest, pytest).

---
[signing-metadata]
key = cic-my-sign-key
signature = vault:v1:MEQCIC6gmifyvg7N9N/CATFeTL2vDGis+DBr+MZw13zyb6rfAiAGKAPRa9fYy4XtckQJ6d8mpNg2kVewagedIJUd7wSsdQ==
hash-algorithm = sha256
digest = 4JiAp43EAMeycbJtvE+0SM+Fmt5WwVTCWLFFVXhgrUc=

[certificate]
-----BEGIN CERTIFICATE-----
MIICBjCCAaygAwIBAgIUSnRMR6RPnEbg296XWPOqq/u5PCwwCgYIKoZIzj0EAwIw
QzELMAkGA1UEBhMCSFUxGTAXBgNVBAoMEENlbnRyYWxJbmZyYUNvcmUxGTAXBgNV
BAMMEENJQyBEZXZlbG9wZXIgQ0EwHhcNMjYwMzIwMTMyMjU5WhcNMjYxMjMxMTMy
MjU5WjBFMQswCQYDVQQGEwJIVTEZMBcGA1UECgwQQ2VudHJhbEluZnJhQ29yZTEb
MBkGA1UEAwwSR2Fib3IgWm9sdGFuIFNpbmtvMFkwEwYHKoZIzj0CAQYIKoZIzj0D
AQcDQgAEIG2CVmTfmLB9pLLclj7YmP2eedAjklpy4LGrU2ijoiy6Xqpuybv7OgJe
i+ez31s65NEV8+X/ByeX1cstR988z6N8MHowCQYDVR0TBAIwADAdBgNVHQ4EFgQU
yZN6AIX/TNnIJ9GwAa/NRN3ujHAwHwYDVR0jBBgwFoAUXn6CHYzPUqU4JVP8g+OS
WeDYjhcwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEF
BQcDBDAKBggqhkjOPQQDAgNIADBFAiEA+bFzXRoJ4PCQbhAAtpkcMjt0vNj5rEW0
lOMBGDNyaWkCIB1vmM7PcZzv/c9bIrxF5kqv6QXomouhByUfeNUTbpKW
-----END CERTIFICATE-----
…ve/validate/plan

Adds manual_real_oci_test.go, gated behind a manual_real_oci build tag plus a
REAL_OCI_TEST=1 runtime opt-in, so it never runs in a plain `go test ./...` or
`make golang.test`. It calls the module's own handler functions against a real
OCI tenancy using the real API-key signing scheme, to cover what the existing
mock-host tests (relay_integration_test.go, module_loadtest_test.go) cannot:
whether the request/response logic actually works against live OCI.

Documents current coverage and known gaps (poll needs a live work-request;
execute/invoke/destroy are mutating and out of scope for this harness) in
docs/design/manual-verification.md, including a capability-manifest/realm
mismatch found via describe() (egress_hosts declares *.oraclecloud.com only;
this tenancy's real host is the EU Sovereign realm's oraclecloud.eu).

---
[signing-metadata]
key = cic-my-sign-key
signature = vault:v1:MEQCICjWxcWKF1io8wtKpL50iMCRJR84M/WJBKxaFcz+hDqyAiA/6eL2/sCZQsNUqwez/ceZctydinxdxe9KaYfMRi142Q==
hash-algorithm = sha256
digest = Ivzn5N8QEdyxivv1s42gSjy8++NNm8ngVnb9uMCt1jk=

[certificate]
-----BEGIN CERTIFICATE-----
MIICBjCCAaygAwIBAgIUSnRMR6RPnEbg296XWPOqq/u5PCwwCgYIKoZIzj0EAwIw
QzELMAkGA1UEBhMCSFUxGTAXBgNVBAoMEENlbnRyYWxJbmZyYUNvcmUxGTAXBgNV
BAMMEENJQyBEZXZlbG9wZXIgQ0EwHhcNMjYwMzIwMTMyMjU5WhcNMjYxMjMxMTMy
MjU5WjBFMQswCQYDVQQGEwJIVTEZMBcGA1UECgwQQ2VudHJhbEluZnJhQ29yZTEb
MBkGA1UEAwwSR2Fib3IgWm9sdGFuIFNpbmtvMFkwEwYHKoZIzj0CAQYIKoZIzj0D
AQcDQgAEIG2CVmTfmLB9pLLclj7YmP2eedAjklpy4LGrU2ijoiy6Xqpuybv7OgJe
i+ez31s65NEV8+X/ByeX1cstR988z6N8MHowCQYDVR0TBAIwADAdBgNVHQ4EFgQU
yZN6AIX/TNnIJ9GwAa/NRN3ujHAwHwYDVR0jBBgwFoAUXn6CHYzPUqU4JVP8g+OS
WeDYjhcwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEF
BQcDBDAKBggqhkjOPQQDAgNIADBFAiEA+bFzXRoJ4PCQbhAAtpkcMjt0vNj5rEW0
lOMBGDNyaWkCIB1vmM7PcZzv/c9bIrxF5kqv6QXomouhByUfeNUTbpKW
-----END CERTIFICATE-----
Missed in the previous commit — CI's manifest-verify step caught it.

---
[signing-metadata]
key = cic-my-sign-key
signature = vault:v1:MEUCIDptg4k9W3It7Ku1btZ2X3y6JpchqL8aCwmMBN5/AQJSAiEAv5duRUitGffpL3L4mbKnuL81A/NiTH5wN0UGRh88yV8=
hash-algorithm = sha256
digest = jSpHVe1UcYHMuqY13EF2P5FgLQJIWcSJ3rhXKyp02Hk=

[certificate]
-----BEGIN CERTIFICATE-----
MIICBjCCAaygAwIBAgIUSnRMR6RPnEbg296XWPOqq/u5PCwwCgYIKoZIzj0EAwIw
QzELMAkGA1UEBhMCSFUxGTAXBgNVBAoMEENlbnRyYWxJbmZyYUNvcmUxGTAXBgNV
BAMMEENJQyBEZXZlbG9wZXIgQ0EwHhcNMjYwMzIwMTMyMjU5WhcNMjYxMjMxMTMy
MjU5WjBFMQswCQYDVQQGEwJIVTEZMBcGA1UECgwQQ2VudHJhbEluZnJhQ29yZTEb
MBkGA1UEAwwSR2Fib3IgWm9sdGFuIFNpbmtvMFkwEwYHKoZIzj0CAQYIKoZIzj0D
AQcDQgAEIG2CVmTfmLB9pLLclj7YmP2eedAjklpy4LGrU2ijoiy6Xqpuybv7OgJe
i+ez31s65NEV8+X/ByeX1cstR988z6N8MHowCQYDVR0TBAIwADAdBgNVHQ4EFgQU
yZN6AIX/TNnIJ9GwAa/NRN3ujHAwHwYDVR0jBBgwFoAUXn6CHYzPUqU4JVP8g+OS
WeDYjhcwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEF
BQcDBDAKBggqhkjOPQQDAgNIADBFAiEA+bFzXRoJ4PCQbhAAtpkcMjt0vNj5rEW0
lOMBGDNyaWkCIB1vmM7PcZzv/c9bIrxF5kqv6QXomouhByUfeNUTbpKW
-----END CERTIFICATE-----
@sinkog
sinkog merged commit c445a97 into main Aug 2, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant