Files
orca/cloud/dev/scripts/relay-repository.test.mjs
T
Jinwoo Hong 0746d82c01 chore(cloud): close the Workload Identity cutover onto stablyai/orca (#18509)
Mirrors stablyai/orca-cloud#470. The private relay workflows are retired, so
the dual accept has one live arm left. Add `github_workflow_file_prefix` for
the primary repository's workflow filenames, point `github_repo`/
`github_repo_id` at `stablyai/orca` (`1183888342`), and empty
`github_accepted_repositories` in both environments. Every relay provider goes
back to a single arm naming `cloud-` prefixed workflow refs.

`cloud/infra/terraform` stays byte-identical to the private branch. The two
identity tests diverge here as they already did, so they take the same change
rather than the same bytes: both now render the trusted ref head from the
Terraform variable instead of this checkout's own workflow filenames, which is
what lets the length pin be the same 791 characters in either repository.
2026-09-03 15:57:00 -04:00

40 lines
2.0 KiB
JavaScript

import assert from 'node:assert/strict'
import { readdirSync, readFileSync } from 'node:fs'
import test from 'node:test'
import { fileURLToPath } from 'node:url'
import {
RELAY_GITHUB_REPOSITORY,
RELAY_WORKFLOW_FILE_PREFIX,
prefixedRelayWorkflowPath,
readRelayWorkflow,
relayWorkflowFile,
relayWorkflowPath,
relayWorkflowUrl
} from './relay-repository.mjs'
const directory = fileURLToPath(new URL('.', import.meta.url))
// The Relay copy takes the scripts named for it. Everything else stays with the applications.
const relayScripts = readdirSync(directory)
.filter((name) => name.includes('relay') && name.endsWith('.mjs'))
.filter((name) => !name.startsWith('relay-repository.'))
test('workflow identity is derived, never restated', () => {
assert.equal(relayWorkflowFile('deploy-relay-staging.yml'), `${RELAY_WORKFLOW_FILE_PREFIX}deploy-relay-staging.yml`)
assert.equal(relayWorkflowPath('deploy-relay-staging.yml'), `.github/workflows/${relayWorkflowFile('deploy-relay-staging.yml')}`)
assert.ok(relayWorkflowUrl('deploy-relay-staging.yml').pathname.endsWith(relayWorkflowPath('deploy-relay-staging.yml')))
// A caller rendering Terraform's trusted ref supplies that prefix instead of this checkout's.
assert.equal(prefixedRelayWorkflowPath('cloud-', 'deploy-relay-staging.yml'), '.github/workflows/cloud-deploy-relay-staging.yml')
assert.match(readRelayWorkflow('deploy-relay-staging.yml'), /^name:/m)
assert.match(RELAY_GITHUB_REPOSITORY, /^[\w.-]+\/[\w.-]+$/)
})
// Why: the public-repo copy changes the owning repository, the workflow filenames, and the depth
// this tree sits at. Each has to be one edit here, so no Relay script may restate any of them.
test('no Relay script restates the repository or the workflow directory', () => {
for (const name of relayScripts) {
const text = readFileSync(`${directory}${name}`, 'utf8')
assert.doesNotMatch(text, /stablyai\//, `${name} restates the GitHub repository`)
assert.doesNotMatch(text, /\.github\/workflows/, `${name} restates the workflow directory`)
}
})