import test from 'node:test'; import assert from 'node:assert/strict'; import { readFileSync } from 'node:fs'; const compose = readFileSync(new URL('../deploy/vikunja/compose.yaml', import.meta.url), 'utf8'); const runbook = readFileSync(new URL('../../../docs/guides/slice-1-identities.md', import.meta.url), 'utf8'); const lines = compose.split('\n').filter((l) => !/^\s*#/.test(l)); // REQ-TASK-3: the upstream image by digest, the same one the runbook and the probes used. test('the bundled Vikunja is the pinned upstream image the runbook names', () => { const images = lines.filter((l) => /^\s*image:/.test(l)).map((l) => l.split('image:')[1].trim()); assert.equal(images.length, 1); assert.match(images[0], /^vikunja\/vikunja@sha256:[0-9a-f]{64}$/); assert.ok(runbook.includes(images[0]), 'the runbook pins another digest'); assert.equal(lines.some((l) => /^\s*build:/.test(l)), false); }); test('every published port is on 127.0.0.1, and no secret is in the file', () => { const at = lines.findIndex((l) => /^\s*ports:/.test(l)); const ports = []; for (let i = at + 1; i < lines.length && /^\s*-/.test(lines[i]); i++) ports.push(lines[i]); assert.ok(ports.length > 0); for (const p of ports) assert.match(p, /^\s*- "127\.0\.0\.1:/); assert.equal(lines.some((l) => /network_mode:\s*host/.test(l)), false); assert.equal(/SERVICE_SECRET|JWTSECRET|PASSWORD/i.test(lines.join('\n')), false); assert.match(compose, /VIKUNJA_SERVICE_ENABLEREGISTRATION: "false"/); });