fix(acceptance): 阻断本地控制面漂移污染验收

本地 K3s 节点此前在 Kubelet 中登记为宿主机资源,负载可挤压 etcd 并在 server 重启后继续污染同一 Run。现在为三节点设置真实可调度预算、独立 etcd/数据卷和锁定依赖镜像,并持续核对 server 与 API/etcd 健康。\n\n每次验收生成独立 Run ID,报告使用独占或原子写入,负载错误记录具体阶段;数据库鉴权不可用返回带 Retry-After 的 503,避免基础设施故障被误报为 401。\n\n验证:Go 全量测试、go vet、gofmt、OpenAPI、bash -n、ShellCheck、报告测试和 k3d 配置解析均通过。
This commit is contained in:
2026-07-31 23:07:19 +08:00
parent 015ff8ea6c
commit a95184b5b6
20 changed files with 970 additions and 85 deletions
+30
View File
@@ -6,6 +6,7 @@ import (
"encoding/base64"
"encoding/hex"
"encoding/json"
"errors"
"fmt"
"net/http"
"net/http/httptest"
@@ -212,6 +213,35 @@ func TestAcceptanceReportErrorRedactsSecretsAndURLs(t *testing.T) {
}
}
func TestAcceptanceReportCannotOverwriteExistingRunArtifact(t *testing.T) {
path := filepath.Join(t.TempDir(), "load-report.json")
if err := writeReportExclusive(path, []byte(`{"runId":"first"}`)); err != nil {
t.Fatalf("write first report: %v", err)
}
if err := writeReportExclusive(path, []byte(`{"runId":"second"}`)); err == nil {
t.Fatal("second report unexpectedly overwrote the first report")
}
payload, err := os.ReadFile(path)
if err != nil {
t.Fatalf("read report: %v", err)
}
if string(payload) != "{\"runId\":\"first\"}\n" {
t.Fatalf("report changed after rejected overwrite: %s", payload)
}
}
func TestAcceptanceFailurePreservesOperationAndHTTPStatus(t *testing.T) {
err := withOperation("video_poll", &httpStatusError{Status: http.StatusUnauthorized, Body: "unauthorized"})
var operationErr *operationError
if !errors.As(err, &operationErr) || operationErr.Operation != "video_poll" {
t.Fatalf("operation error=%#v", operationErr)
}
var statusErr *httpStatusError
if !errors.As(err, &statusErr) || statusErr.Status != http.StatusUnauthorized {
t.Fatalf("HTTP status error=%#v", statusErr)
}
}
func TestAcceptanceGatewayTLSNameSetsHostHeader(t *testing.T) {
request := httptest.NewRequest(http.MethodGet, "https://127.0.0.1/api/v1/healthz", nil)
opts := options{