flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/services/runner/src/workflow-hosts.test.ts

44 lines2,406 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Fast pages, required checks on the branch, self-hosted runners, honest incidents1import assert from "node:assert/strict";
2import { test } from "node:test";
3
4import type { WorkflowDomain } from "@g1t/contracts";
5
6import { SANDBOX_BINDINGS, jobHosts, sandboxNamespace } from "./egress.ts";
7
8const domains: WorkflowDomain[] = [
9 { domain: "api.cloudflare.com", workflows: ["deploy.yml"], environments: ["production"] },
10 { domain: "*.example.com", workflows: [], environments: [] },
11];
12const policy = { workflowDomains: domains };
13const deploy = { workflow: ".g1t/workflows/deploy.yml", environment: "production", trusted: true };
14
15test("a trusted workflow job reaches the workflow-only domains that name it", () => {
16 assert.deepEqual(jobHosts(policy, "actions", deploy), ["api.cloudflare.com", "*.example.com"]);
17 assert.deepEqual(jobHosts(policy, "actions", { ...deploy, workflow: "DEPLOY.yml", environment: "Production" }), [
18 "api.cloudflare.com",
19 "*.example.com",
20 ]);
21 // Another environment, none, or another workflow: only the open entry.
22 assert.deepEqual(jobHosts(policy, "actions", { ...deploy, environment: "staging" }), ["*.example.com"]);
23 assert.deepEqual(jobHosts(policy, "actions", { ...deploy, environment: null }), ["*.example.com"]);
24 assert.deepEqual(jobHosts(policy, "actions", { ...deploy, workflow: ".g1t/workflows/ci.yml" }), ["*.example.com"]);
25});
26
27test("nothing else ever reaches them: forks, deploy builds, unknown jobs", () => {
28 assert.deepEqual(jobHosts(policy, "actions", { ...deploy, trusted: false }), []);
29 assert.deepEqual(jobHosts(policy, "deploy", deploy), []);
30 assert.deepEqual(jobHosts(policy, "actions", null), []);
31 assert.deepEqual(jobHosts(policy, "actions", { ...deploy, workflow: null }), []);
32 // Guardrails from before the list existed.
33 assert.deepEqual(jobHosts({}, "actions", deploy), []);
34});
35
36test("each sandbox class reports to its own namespace", () => {
37 const env = { SANDBOX: "standard", SANDBOX_2CORE: "two", SANDBOX_4CORE: "four" } as unknown as object;
38 assert.equal(sandboxNamespace(env, "AttemptSandbox"), "standard");
39 assert.equal(sandboxNamespace(env, "Sandbox4Core"), "four");
40 assert.equal(sandboxNamespace(env, "Sandbox2Core"), "two");
41 assert.equal(sandboxNamespace(env, undefined), "standard");
42 assert.equal(sandboxNamespace({ SANDBOX: "standard" }, "Sandbox4Core"), "standard");
43 assert.deepEqual(Object.keys(SANDBOX_BINDINGS), ["AttemptSandbox", "Sandbox2Core", "Sandbox4Core"]);
44});