boatramp_node/node.rs
1//! The node-graph assembly: given a built store (blobs + KV), a configured
2//! [`Auth`](boatramp_server::Auth), and resolved
3//! [`ServerOptions`](boatramp_server::ServerOptions), wire the deploy store,
4//! handler runtime, compute reconcile loop, and domain-verify reconcile loop
5//! into a [`RunningNode`] ready to hand to a transport (`serve_with` & friends).
6//!
7//! This is the headline extraction of `PLAN-node-library`: the binary's
8//! `serve::run` used to inline this wiring, so no embedder or in-process test
9//! could exercise the same graph the `boatramp serve` binary runs. `run` now
10//! resolves the *environment* (args -> backends -> store, signal handlers,
11//! migration, auth) and calls [`assemble`]; the cluster path keeps its own inline
12//! copy until a later step converges it here.
13
14use std::path::Path;
15use std::sync::Arc;
16
17use boatramp_core::deploy::DeployStore;
18use boatramp_core::kv::KvStore;
19use boatramp_core::Storage;
20
21use crate::config::ServerConfig;
22use crate::error::{Error, Result};
23
24/// How often the compute reconcile loop converges desired vs actual workloads.
25/// Defaults to 30s; override with `BOATRAMP_COMPUTE_RECONCILE_TICK_MS` (milliseconds)
26/// so compute-backed tests can converge in a fraction of a second instead of
27/// waiting a full tick for the launch/scale reconcile.
28pub fn compute_reconcile_tick() -> std::time::Duration {
29 std::env::var("BOATRAMP_COMPUTE_RECONCILE_TICK_MS")
30 .ok()
31 .and_then(|s| s.parse::<u64>().ok())
32 .filter(|&ms| ms > 0)
33 .map(std::time::Duration::from_millis)
34 .unwrap_or(std::time::Duration::from_secs(30))
35}
36/// How often the domain-verify reconcile loop re-checks pending challenges.
37pub const DOMAIN_VERIFY_RECONCILE_TICK: std::time::Duration = std::time::Duration::from_secs(60);
38/// How long a compute workload may be idle before scale-to-zero sleeps it.
39pub const COMPUTE_IDLE_TIMEOUT: std::time::Duration = std::time::Duration::from_secs(300);
40
41/// The built store + resolved config handed to [`assemble`]. Owns the blob/KV
42/// backends and the auth/options the caller already resolved; borrows the parsed
43/// config and data directory.
44pub struct NodeInput<'a> {
45 /// The full parsed server config (the handler + compute sections are read here).
46 pub config: &'a ServerConfig,
47 /// The node data directory (per-site SQL, handler state).
48 pub data_dir: &'a Path,
49 /// The object store built by [`crate::blobs::build_blobs`].
50 pub storage: Arc<dyn Storage>,
51 /// The metadata KV, already cache-fronted, built by [`crate::backends::build_kv`].
52 pub kv: Arc<dyn KvStore>,
53 /// The control-plane auth built by [`crate::auth::configure_auth`].
54 pub auth: boatramp_server::Auth,
55 /// Server options, already carrying the resolved posture, daemon runtime, and
56 /// (post-`configure_auth`/`configure_oidc`) issuer / OIDC verifier.
57 pub options: boatramp_server::ServerOptions,
58 /// The public HTTP serve bind address, if known — used (under
59 /// `allow_guest_self_egress`) to let a handler guest's `wasi:http` reach this
60 /// instance's own front door over loopback. `None` (an in-process embedder with no
61 /// listener) disables self-egress.
62 pub serve_addr: Option<std::net::SocketAddr>,
63 /// The cloud blob-change watch provider (FA-5b2), if the backend is a cloud one.
64 pub watch_provider: Option<Arc<dyn boatramp_core::blob_provision::WatchProvider>>,
65 /// The provisioning tier for the watch provider.
66 pub provision_tier: boatramp_core::blob_notify::ProvisionTier,
67 /// The `wasi:messaging` substrate override for the handler runtime. `None` uses
68 /// the single-node default (`LogMessaging` over the same backends); the cluster
69 /// path passes its Raft-backed coordinator.
70 pub messaging: Option<Arc<dyn boatramp_core::messaging::Messaging>>,
71 /// The single leader gate for cron firing + the compute / domain-verify reconcile
72 /// loops. Single-node passes an always-true gate (there is one node); the cluster
73 /// passes its Raft `is_leader` check so a single node drives each sweep.
74 pub is_leader: boatramp_server::CronLeaderGate,
75 /// This node's compute scheduler id (`0` single-node; the cluster node id in a
76 /// fleet, so replicas are tagged to the right node).
77 pub node_id: u64,
78 /// The binary the re-exec'd compute workers run as — the container backend's
79 /// `__sandbox` jailer and the microVM backends' `__vmm-run`/`__vz-run` VM hosts.
80 /// `None` uses this process's own executable (`current_exe`), which is what
81 /// `boatramp serve` wants (the child *is* boatramp). An **embedding harness**
82 /// whose own binary doesn't implement those subcommands should point this at a
83 /// built `boatramp` binary, so it can drive the real container/microVM backends
84 /// in-process (only the per-workload worker re-execs; the serving plane stays
85 /// embedded). The docker backend needs neither — it talks to a daemon.
86 pub worker_exe: Option<std::path::PathBuf>,
87}
88
89/// A fully wired node: the deploy store, handler runtime, auth, and options a
90/// transport consumes, plus the detached reconcile loops kept alive for the
91/// node's serving life. Destructure it and hold `reconcile` across the serve
92/// await so the loops outlive assembly.
93pub struct RunningNode {
94 /// The deploy store (blob + KV) the router serves from.
95 pub deploy: DeployStore,
96 /// The handler runtime for wasm handlers (a disabled build ⇒ a no-op runtime).
97 pub handlers: boatramp_server::HandlerRuntime,
98 /// The control-plane auth.
99 pub auth: boatramp_server::Auth,
100 /// The resolved server options.
101 pub options: boatramp_server::ServerOptions,
102 /// The detached reconcile loops (compute + domain-verify). Tokio `JoinHandle`s
103 /// do not abort on drop, so the loops run for the process life regardless; the
104 /// handles are retained so an embedder can join/abort them on shutdown.
105 pub reconcile: Vec<tokio::task::JoinHandle<()>>,
106}
107
108/// The instance's own serve socket(s) a guest self-call may reach, given the bind `addr` and
109/// whether the posture (`allow_guest_self_egress`) permits it. A wildcard bind
110/// (`0.0.0.0`/`::`) is reachable over loopback, so it normalizes to `127.0.0.1` **and** `::1`
111/// on the serve port; a specific bind is reachable at itself. Empty when disabled or no
112/// listener.
113fn self_egress_addrs(
114 addr: Option<std::net::SocketAddr>,
115 enabled: bool,
116) -> Vec<std::net::SocketAddr> {
117 use std::net::{IpAddr, Ipv4Addr, Ipv6Addr, SocketAddr};
118 let Some(addr) = addr.filter(|_| enabled) else {
119 return Vec::new();
120 };
121 if addr.ip().is_unspecified() {
122 let port = addr.port();
123 vec![
124 SocketAddr::new(IpAddr::V4(Ipv4Addr::LOCALHOST), port),
125 SocketAddr::new(IpAddr::V6(Ipv6Addr::LOCALHOST), port),
126 ]
127 } else {
128 vec![addr]
129 }
130}
131
132/// Wire [`NodeInput`] into a [`RunningNode`]: build the handler runtime, the
133/// deploy store (materializing the reserved `default` project), the compute
134/// backends + reconcile loop, and the domain-verify reconcile loop.
135///
136/// The caller has already built the store and configured auth/OIDC on `options`;
137/// this is the pure node-graph wiring, identical to what `boatramp serve` runs.
138pub async fn assemble(input: NodeInput<'_>) -> Result<RunningNode> {
139 let NodeInput {
140 config,
141 data_dir,
142 storage,
143 kv,
144 auth,
145 options,
146 serve_addr,
147 watch_provider,
148 provision_tier,
149 messaging,
150 is_leader,
151 node_id,
152 worker_exe,
153 } = input;
154 // Copy out the posture scalars up front so `options` can be moved into the
155 // returned `RunningNode` without a lingering borrow.
156 let max_handler_blob_bytes = options.posture.max_handler_blob_bytes;
157 let max_component_bytes = options.posture.max_component_bytes;
158 let allow_guest_private_egress = options.posture.allow_guest_private_egress;
159 let allow_env_secret_refs = options.posture.allow_env_secret_refs;
160 // The instance's own serve socket(s) a guest self-call may reach, when the posture allows
161 // it: a wildcard bind (`0.0.0.0`/`::`) is reachable on loopback, so normalize to
162 // `127.0.0.1`/`::1`; a specific bind is itself.
163 let self_egress_addrs = self_egress_addrs(serve_addr, options.posture.allow_guest_self_egress);
164 let allow_shared_kernel = options.posture.allow_shared_kernel_compute;
165 let domain_verify_allow_private = options.posture.domain_verify_allow_private;
166
167 // The deploy store the router serves from — built up front so the handler
168 // runtime's managed compute-backed `sql` binding can resolve DB endpoints from
169 // the same store the reconcile writes.
170 let compute_storage = storage.clone();
171 let deploy = DeployStore::new(storage, kv.clone());
172 // The `[secrets]` envelope (local KEK / Vault) that seals a managed SQL
173 // credential at rest. `None` ⇒ no wrapping (a managed DB then fails closed).
174 let secrets_envelope = build_secrets_envelope(config.secrets.as_ref(), data_dir)?;
175 // The project-scoped internal secret store, built from the same KV + `[secrets]`
176 // envelope that seal managed-DB credentials. Backs both the `boatramp:<name>`
177 // resolver (wired into the handler runtime below, when that feature is present)
178 // and the admin secrets API (threaded into `ServerOptions` unconditionally, so it
179 // works on a lean node too). `None` when no envelope is configured — the admin
180 // endpoints then fail closed with a clear 501, never a panic.
181 let secret_store = secrets_envelope.clone().map(|envelope| {
182 Arc::new(boatramp_core::secret_store::SecretStore::new(
183 kv.clone(),
184 envelope,
185 ))
186 });
187
188 // The handler runtime reuses the same blob/KV backends (per-site prefixed)
189 // for its wasi:blobstore/keyvalue bindings; the sql binding is selected by
190 // `[handlers.bindings.sql]` (default: per-site libsql files under <data-dir>).
191 let handlers = crate::handlers::build_handler_runtime(
192 kv.clone(),
193 compute_storage.clone(),
194 data_dir,
195 config.handlers.as_ref(),
196 messaging,
197 max_handler_blob_bytes,
198 max_component_bytes,
199 allow_guest_private_egress,
200 self_egress_addrs,
201 allow_env_secret_refs,
202 &deploy,
203 secrets_envelope.clone(),
204 )
205 .await?;
206 // Leader-gate cron firing (cluster: only the Raft leader fires; single-node: an
207 // always-true gate, equivalent to the unset default). The same gate drives the
208 // reconcile loops below, so all three converge on one leader per fleet. Only the
209 // handler runtime has a scheduler, so this is a no-op without the `handlers` feature.
210 #[cfg(feature = "handlers")]
211 handlers.set_cron_leader_gate(is_leader.clone());
212 // FA-5b2: on a cloud backend, wire the blob-change notification provisioner +
213 // its tier so adding a `blob` trigger provisions (and removing it retracts).
214 #[cfg(feature = "handlers")]
215 if let Some(provider) = watch_provider {
216 handlers.set_watch_provider(provider);
217 handlers.set_provision_tier(provision_tier);
218 }
219 #[cfg(not(feature = "handlers"))]
220 let _ = (watch_provider, provision_tier);
221
222 // Materialize the reserved `default` project so `project ls` / `project show
223 // default` reflect it on a fresh install, not only after a migration. Best
224 // effort: the reader backstop keeps listings correct even if this write can't
225 // land, so a transient failure must never block serving.
226 match deploy.ensure_default_project().await {
227 Ok(true) => tracing::info!("materialized the reserved `default` project record"),
228 Ok(false) => {}
229 Err(e) => tracing::warn!(
230 error = %e,
231 "could not materialize the `default` project record; readers use the synthesized default"
232 ),
233 }
234 // Wire the function-to-function invoke resolver now the deploy store exists,
235 // so a function granted `invoke` can call a sibling in-process (FI).
236 #[cfg(feature = "handlers")]
237 handlers.set_invoker(deploy.clone());
238
239 // Compute reconcile loop. Single-node is always the "leader". Backends are
240 // built from the `[compute]` config + capability detection; a no-op when none
241 // are registered. Detached for the server's life.
242 let (compute_backends, compute_node) = crate::compute::build_compute(
243 config.compute.as_ref(),
244 compute_storage,
245 data_dir,
246 node_id,
247 !allow_shared_kernel,
248 options.daemon_runtime.clone(),
249 worker_exe.as_deref(),
250 )
251 .await;
252 // Activate the compute sql-shim (PLAN-compute-bindings): bind its listener +
253 // build the resolver when a sql provider and `compute.sql_shim_url` are both present.
254 #[cfg(feature = "handlers")]
255 let sql_resolver = boatramp_server::sql_shim::spawn_sql_shim(
256 handlers.sql_backends(),
257 config.compute.as_ref().and_then(|c| c.sql_shim_url.clone()),
258 )
259 .await;
260 #[cfg(not(feature = "handlers"))]
261 let sql_resolver: Option<Arc<dyn boatramp_core::compute::ComputeBindingResolver>> = None;
262
263 // Managed compute-backed SQL (PLAN-managed-compute-sql P2-b): if the handler
264 // `sql` config declares any managed database, inject its `POSTGRES_*`/`MYSQL_*`
265 // server-init env into the DB workload at launch from the sealed credential.
266 // Reaching here with a managed DB implies an envelope (build_handler_runtime
267 // fails closed otherwise), so the credential store always has one to seal with.
268 // Keep a clone of the secrets envelope for the operator-SQL capability below
269 // (the managed_db_resolver match moves the original).
270 #[cfg(any(feature = "sql-postgres", feature = "sql-mysql"))]
271 let operator_envelope = secrets_envelope.clone();
272 // …and a second clone for the tenant-deprovision capability (drops a deleted
273 // tenant's managed DB/role/credential on project/site delete). It needs a real
274 // envelope to seal/unseal + delete per-tenant credentials, so it is wired only
275 // when one is present (same fail-closed gating as the managed-DB paths).
276 #[cfg(any(feature = "sql-postgres", feature = "sql-mysql"))]
277 let deprovision_envelope = secrets_envelope.clone();
278 // …and a third clone for the soft-delete tombstone reaper (the leader-gated task
279 // that hard-drops a Shared-Postgres tenant once its grace window elapses). It, too,
280 // needs a real envelope to unseal the superuser credential + delete the per-tenant
281 // one on hard-drop.
282 #[cfg(any(feature = "sql-postgres", feature = "sql-mysql"))]
283 let reaper_envelope = secrets_envelope.clone();
284 #[cfg(any(feature = "sql-postgres", feature = "sql-mysql"))]
285 let managed_db_resolver: Option<Arc<dyn boatramp_core::compute::ManagedDbEnvResolver>> = match (
286 config
287 .handlers
288 .as_ref()
289 .and_then(|h| h.bindings.sql.as_ref()),
290 secrets_envelope,
291 ) {
292 (Some(sql), Some(envelope)) if !sql.databases.is_empty() => {
293 let creds = crate::managed_sql::ManagedSqlCredentials::new(kv.clone(), envelope);
294 let privilege = config
295 .compute
296 .as_ref()
297 .map(|c| c.managed_db_privilege)
298 .unwrap_or_default();
299 let env =
300 crate::managed_sql::ManagedDbEnv::from_config(&sql.databases, creds, privilege);
301 (!env.is_empty()).then(|| Arc::new(env) as Arc<_>)
302 }
303 _ => None,
304 };
305 #[cfg(not(any(feature = "sql-postgres", feature = "sql-mysql")))]
306 let managed_db_resolver: Option<Arc<dyn boatramp_core::compute::ManagedDbEnvResolver>> = None;
307
308 // Turnkey managed DB: auto-register the compute workload backing each managed
309 // co-located database that has none yet, so declaring the `databases` binding is
310 // enough to boot the DB (no separate `compute set` / apply). Non-clobbering and
311 // idempotent; runs before the reconcile loop so its first tick can launch it.
312 #[cfg(any(feature = "sql-postgres", feature = "sql-mysql"))]
313 if let Some(sql) = config
314 .handlers
315 .as_ref()
316 .and_then(|h| h.bindings.sql.as_ref())
317 .filter(|sql| !sql.databases.is_empty())
318 {
319 crate::managed_sql::auto_register_managed_db_workloads(&deploy, &sql.databases).await;
320 }
321
322 // Operator SQL capability (managed-DB migrations/queries via the sealed
323 // credential, resolved server-side) — backs `POST /api/sql/{db}/{exec,query}`.
324 #[cfg(any(feature = "sql-postgres", feature = "sql-mysql"))]
325 let operator_sql: Option<Arc<dyn boatramp_core::sql::OperatorSql>> = config
326 .handlers
327 .as_ref()
328 .and_then(|h| h.bindings.sql.as_ref())
329 .filter(|sql| !sql.databases.is_empty())
330 .map(|sql| {
331 Arc::new(crate::managed_sql::NodeOperatorSql::new(
332 sql.databases.clone(),
333 kv.clone(),
334 operator_envelope,
335 deploy.clone(),
336 )) as Arc<_>
337 });
338 #[cfg(not(any(feature = "sql-postgres", feature = "sql-mysql")))]
339 let operator_sql: Option<Arc<dyn boatramp_core::sql::OperatorSql>> = None;
340
341 // Tenant-deprovision capability (drop a deleted tenant's managed DB/role/sealed
342 // credential on project/site delete). Wired only when a compute-backed managed
343 // database + a secrets envelope are both present — same gating as operator_sql,
344 // plus the envelope requirement (it must seal/unseal per-tenant credentials).
345 // The soft-delete grace window for a Shared-Postgres managed tenant
346 // (`handlers.bindings.sql.deprovision_grace_secs`, env-settable). Default 7 days;
347 // `0` disables the soft path (immediate hard drop). Threaded to the deprovisioner
348 // (which soft-deletes) and implicitly honored by the reaper (which only ever finds
349 // tombstones a >0 grace produced).
350 #[cfg(any(feature = "sql-postgres", feature = "sql-mysql"))]
351 let deprovision_grace_secs = config
352 .handlers
353 .as_ref()
354 .and_then(|h| h.bindings.sql.as_ref())
355 .and_then(|sql| sql.deprovision_grace_secs)
356 .unwrap_or(crate::tenant_sql::DEFAULT_DEPROVISION_GRACE_SECS);
357 #[cfg(any(feature = "sql-postgres", feature = "sql-mysql"))]
358 let tenant_deprovisioner: Option<Arc<dyn boatramp_core::sql::TenantDeprovisioner>> = config
359 .handlers
360 .as_ref()
361 .and_then(|h| h.bindings.sql.as_ref())
362 .filter(|sql| !sql.databases.is_empty())
363 .zip(deprovision_envelope)
364 .map(|(sql, envelope)| {
365 Arc::new(crate::tenant_sql::NodeTenantDeprovisioner::new(
366 deploy.clone(),
367 kv.clone(),
368 envelope,
369 sql.databases.clone(),
370 deprovision_grace_secs,
371 )) as Arc<_>
372 });
373 #[cfg(not(any(feature = "sql-postgres", feature = "sql-mysql")))]
374 let tenant_deprovisioner: Option<Arc<dyn boatramp_core::sql::TenantDeprovisioner>> = None;
375
376 // Operator compute-exec capability (run a command inside a running workload) —
377 // backs `POST /api/compute/{name}/exec`, gated by the `allow_compute_exec`
378 // posture. Clone the backend registry before the reconcile loop consumes it.
379 let compute_exec: Option<Arc<dyn boatramp_core::compute::ComputeExec>> = Some(Arc::new(
380 crate::compute::NodeComputeExec::new(compute_backends.clone(), deploy.clone()),
381 ) as Arc<_>);
382
383 // Operator volume-reclamation capability (list + remove persistent volumes) —
384 // backs `GET /api/compute/volumes` + `DELETE /api/compute/volumes/{name}`.
385 // Same admin-scoped `/api/compute/*` gate; clone the registry before the
386 // reconcile loop consumes the original below.
387 let compute_volumes: Option<Arc<dyn boatramp_core::compute::ComputeVolumes>> = Some(Arc::new(
388 crate::compute::NodeComputeVolumes::new(compute_backends.clone(), deploy.clone()),
389 )
390 as Arc<_>);
391
392 let compute_reconcile = boatramp_server::spawn_compute_reconcile(
393 deploy.clone(),
394 compute_backends,
395 vec![compute_node],
396 boatramp_core::compute::BackendPolicy::from_shared_kernel_allowed(allow_shared_kernel),
397 is_leader.clone(),
398 compute_reconcile_tick(),
399 COMPUTE_IDLE_TIMEOUT,
400 sql_resolver,
401 managed_db_resolver,
402 );
403
404 // Tenant tombstone reaper: leader-gated hard-drop of soft-deleted Shared-Postgres
405 // tenants past their grace window (safe deprovision — see `tenant_sql`). Wired only
406 // when a compute-backed managed database + a secrets envelope are both present
407 // (same gating as the deprovisioner); each tombstone carries its own server +
408 // superuser, so the reaper needs no per-binding config. A `0` grace never writes a
409 // tombstone, so the sweep is simply inert then.
410 #[cfg(any(feature = "sql-postgres", feature = "sql-mysql"))]
411 let tombstone_reaper: Option<tokio::task::JoinHandle<()>> = config
412 .handlers
413 .as_ref()
414 .and_then(|h| h.bindings.sql.as_ref())
415 .filter(|sql| !sql.databases.is_empty())
416 .zip(reaper_envelope)
417 .map(|(_sql, envelope)| {
418 crate::tenant_sql::spawn_tenant_tombstone_reaper(
419 deploy.clone(),
420 kv.clone(),
421 envelope,
422 is_leader.clone(),
423 crate::tenant_sql::TOMBSTONE_REAPER_TICK,
424 )
425 });
426 #[cfg(not(any(feature = "sql-postgres", feature = "sql-mysql")))]
427 let tombstone_reaper: Option<tokio::task::JoinHandle<()>> = None;
428
429 // Domain-verify auto-complete: periodically re-check every site's pending
430 // ownership challenges and attach any that now pass — a published token (e.g.
431 // via `domain add --provider`) converges without a manual `domain verify`.
432 let dv_reconcile = boatramp_server::spawn_domain_verify_reconcile(
433 deploy.clone(),
434 domain_verify_allow_private,
435 is_leader,
436 DOMAIN_VERIFY_RECONCILE_TICK,
437 );
438
439 // Wire the operator capabilities onto the options the router is built from.
440 let mut options = options;
441 options.operator_sql = operator_sql;
442 options.tenant_deprovisioner = tenant_deprovisioner;
443 options.compute_exec = compute_exec;
444 options.compute_volumes = compute_volumes;
445 // The internal secret store backs the admin secrets API (set/list/delete). Not
446 // handlers-gated — it must be reachable even on a lean node.
447 options.secret_store = secret_store;
448
449 // The detached reconcile loops: the always-present compute + domain-verify ones,
450 // plus the optional tenant-tombstone reaper (only when a managed DB is configured).
451 let mut reconcile = vec![compute_reconcile, dv_reconcile];
452 if let Some(reaper) = tombstone_reaper {
453 reconcile.push(reaper);
454 }
455
456 Ok(RunningNode {
457 deploy,
458 handlers,
459 auth,
460 options,
461 reconcile,
462 })
463}
464
465/// Build the `[secrets]` envelope (secrets-at-rest wrapping) from `boatramp.cfg`'s
466/// `[secrets]` section: `local` (a machine-local AES-256-GCM KEK) or `vault` (Vault
467/// Transit). `None`/empty ⇒ no wrapping. The Vault token is read from the
468/// environment (`token_env`), never a file. This seals a managed SQL credential at
469/// rest; a managed database fails closed without it.
470fn build_secrets_envelope(
471 secrets: Option<&crate::config::SecretsConfig>,
472 data_dir: &Path,
473) -> Result<Option<Arc<dyn boatramp_core::envelope::KeyEnvelope>>> {
474 use boatramp_server::envelope::{build_envelope, EnvelopeSpec};
475 let Some(cfg) = secrets else {
476 return Ok(None);
477 };
478 let spec = match cfg.envelope.as_str() {
479 "" => EnvelopeSpec::None,
480 "local" => EnvelopeSpec::Local {
481 kek_file: cfg
482 .kek_file
483 .clone()
484 .unwrap_or_else(|| data_dir.join("secrets/kek")),
485 },
486 "vault" => {
487 let v = cfg.vault.as_ref().ok_or_else(|| {
488 Error::Envelope(
489 "secrets.envelope = \"vault\" needs a [secrets.vault] section".into(),
490 )
491 })?;
492 let token = std::env::var(&v.token_env).map_err(|_| {
493 Error::Envelope(format!("Vault token env `{}` is not set", v.token_env))
494 })?;
495 EnvelopeSpec::Vault {
496 addr: v.addr.clone(),
497 key: v.key.clone(),
498 token,
499 }
500 }
501 other => {
502 return Err(Error::Envelope(format!(
503 "unknown secrets.envelope {other:?} (want \"local\" or \"vault\")"
504 )))
505 }
506 };
507 build_envelope(spec).map_err(|e| Error::Envelope(e.to_string()))
508}
509
510#[cfg(all(test, feature = "fs"))]
511mod tests {
512 use super::*;
513 use boatramp_core::kv::MemoryKv;
514 use boatramp_core::security::SecurityProfile;
515
516 /// The headline in-process fidelity check (PLAN-node-library N2b.3): `assemble`
517 /// over a temp `FsStorage` + `MemoryKv` produces a `RunningNode` whose deploy
518 /// store is live (the reserved `default` project was materialized during
519 /// assembly) and whose router — the exact one `boatramp serve` builds — answers
520 /// `/healthz`. No listener is bound: the request is driven through the router
521 /// via `tower::oneshot`, so the whole assembly runs in-process.
522 #[tokio::test]
523 async fn assemble_produces_a_serving_node_over_a_temp_store() {
524 use axum::body::Body;
525 use axum::http::{Request, StatusCode};
526 use tower::ServiceExt;
527
528 let tmp = tempfile::tempdir().unwrap();
529 let storage: Arc<dyn Storage> = Arc::new(boatramp_storage::FsStorage::new(tmp.path()));
530 let kv: Arc<dyn KvStore> = Arc::new(MemoryKv::new());
531 let config = ServerConfig::default();
532 let options = boatramp_server::ServerOptions {
533 // The strict `multi-tenant` posture, as an unconfigured `serve` resolves.
534 posture: SecurityProfile::MultiTenant.preset(),
535 ..Default::default()
536 };
537
538 let node = assemble(NodeInput {
539 config: &config,
540 data_dir: tmp.path(),
541 storage,
542 kv,
543 auth: boatramp_server::Auth::disabled(),
544 options,
545 serve_addr: None,
546 watch_provider: None,
547 provision_tier: boatramp_core::blob_notify::ProvisionTier::default(),
548 messaging: None,
549 is_leader: Arc::new(|| true),
550 node_id: 0,
551 worker_exe: None,
552 })
553 .await
554 .expect("assemble a node over a temp store");
555
556 // The deploy store is live: `assemble` already materialized the reserved
557 // `default` project, so a second ensure reports "already present" (`false`).
558 assert!(
559 !node
560 .deploy
561 .ensure_default_project()
562 .await
563 .expect("read the default project"),
564 "assemble should have materialized the default project"
565 );
566
567 // The assembled router (the same wiring `serve` binds) answers /healthz.
568 let router =
569 boatramp_server::router_with(node.deploy, node.auth, node.handlers, node.options);
570 let response = router
571 .oneshot(
572 Request::builder()
573 .uri("/healthz")
574 .body(Body::empty())
575 .unwrap(),
576 )
577 .await
578 .expect("route /healthz");
579 assert_eq!(response.status(), StatusCode::OK);
580 }
581}