Project pinned digest-safe retention tool through existing GitOps resources
All checks were successful
CI Smoke / host-smoke (push) Successful in 3s
CI Smoke / container-smoke (push) Successful in 14s
Build and Publish Container Image / build-and-push (push) Successful in 27s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
tegwick 2026-09-27 16:04:30 +02:00
parent 942059a6fe
commit a12f1169f9
6 changed files with 988 additions and 2 deletions

View file

@ -72,3 +72,16 @@ def test_frontend_projection_checks_content_and_pin(tmp_path):
renderer.verify_frontend(tmp_path)
(tmp_path/'frontend-patterns-daily.md').write_text('tampered')
with pytest.raises(ValueError): renderer.verify_frontend(tmp_path)
def test_retention_projection_is_pinned_and_mounted(tmp_path):
renderer=load('render_gitops')
docs=list(yaml.safe_load_all(renderer.render()))
cm=next(d for d in docs if d['metadata']['name']=='actcore-ops-service-inventory')
source=tmp_path/'prune.py';source.write_text(cm['data']['forgejo_package_prune.py'])
renderer.verify_platform(source)
worker=next(d for d in docs if d['metadata']['name']=='actcore-worker')
mounts=worker['spec']['template']['spec']['containers'][0]['volumeMounts']
assert any(m.get('subPath')=='forgejo_package_prune.py' and m['readOnly'] is True for m in mounts)
source.write_text('tampered')
with pytest.raises(ValueError):renderer.verify_platform(source)