Add Secrets Manager resolution to probod-bootstrap
Introduce a Resolver that owns env lookup and typed parsing for probod-bootstrap. Env values prefixed with aws://<secret-id> are fetched from AWS Secrets Manager (plaintext SecretString); each secret ID is cached per run. Builder now takes a Resolver only. Prefix every probod-bootstrap input with PROBOD_ so bootstrap config does not collide with unrelated process environment (for example AWS_* used by other tooling). Secrets Manager authentication uses the standard AWS SDK default chain (AWS_REGION, IAM role, profile); PROBOD_AWS_* vars configure S3 in the generated config only. Update Helm deployment env names, GNUmakefile dev-config, Lima provision, e2e testutil, compose.prod.yaml, and docs. Deployments must rename bootstrap env vars to PROBOD_* (e.g. AUTH_COOKIE_SECRET → PROBOD_AUTH_COOKIE_SECRET). BREAKING CHANGE: all env vars are now prefixed by `PROBOD_`. Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
@@ -2,10 +2,28 @@
|
||||
|
||||
E2E tests live in `e2e/console/` (package `console_test`) and run against a live `bin/probod` instance. The test infrastructure handles server lifecycle, authentication, and test data creation.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
E2e uses the local [Pebble](https://github.com/letsencrypt/pebble) ACME server over HTTPS. Pebble’s TLS certificate is minted with [mkcert](https://github.com/FiloSottile/mkcert); register mkcert’s root CA in your system trust store once per machine:
|
||||
|
||||
```bash
|
||||
mkcert -install
|
||||
```
|
||||
|
||||
Without this step, probod cannot verify Pebble’s HTTPS endpoint when it registers an ACME account at startup.
|
||||
|
||||
You also need the Docker stack running and `bin/probod` built. `make stack-up` generates Pebble TLS material under `compose/pebble/certs/` (via mkcert):
|
||||
|
||||
```bash
|
||||
make stack-up
|
||||
make build
|
||||
```
|
||||
|
||||
E2e config is built at test startup in `e2e/internal/testutil/testutil.go` (`generateConfig` → `probod-bootstrap`). It points ACME at Pebble but does not set `PROBOD_ACME_ROOT_CA`; local runs rely on the system trust store populated by `mkcert -install`. CI passes `PROBOD_ACME_ROOT_CA` in the workflow instead.
|
||||
|
||||
## Running tests
|
||||
|
||||
```bash
|
||||
make build # Build the binary (backend only)
|
||||
make test-e2e # Run all e2e tests
|
||||
```
|
||||
|
||||
|
||||
Reference in New Issue
Block a user