P6: S3 blob store, Helm chart, air-gapped installer verify loop

- S3BlobStore (object_store, path-style) behind the same BlobStore trait,
  tested against a REAL MinIO container (round trip, overwrite, NotFound
  on get and delete, nested keys); [storage] backend=local|s3 config with
  validation + server-side selection (S3 creds via env overlay)
- Helm chart: server pod with the secret broker as a SIDECAR sharing a
  private emptyDir unix socket (no network hop carries credentials),
  frontend, optional local PVC vs S3, OIDC/oauth values, unbuffered-SSE
  ingress annotations, NetworkPolicies (frontend->server only), hardened
  securityContexts; ci/check-helm.sh lints AND asserts the rendered
  topology properties
- deploy/airgapped/install.sh: offline signature+checksum verification via
  the bundled teamclaw-bundler BEFORE any docker load; --verify-only mode;
  ci/test-install.sh rehearses clean/tampered/wrong-key paths with the
  real binary
- CI: helm gate + installer rehearsal wired in

149 Rust tests; helm lint + rendered assertions green; installer
verify-path rehearsal green.

Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
Omar Sobh
2026-06-10 08:19:43 -05:00
co-authored by Claude Fable 5
parent ccf96053e6
commit 70ec39f696
20 changed files with 851 additions and 3 deletions
+91
View File
@@ -0,0 +1,91 @@
//! The cloud-target blob store against a REAL S3-compatible server
//! (MinIO in a container) — same contract the local store satisfies.
use testcontainers_modules::testcontainers::core::{ExecCommand, IntoContainerPort, WaitFor};
use testcontainers_modules::testcontainers::runners::AsyncRunner;
use testcontainers_modules::testcontainers::{GenericImage, ImageExt};
use tc_files::{BlobError, BlobStore, S3BlobStore};
async fn minio_store() -> (
S3BlobStore,
testcontainers_modules::testcontainers::ContainerAsync<GenericImage>,
) {
let container = GenericImage::new("minio/minio", "latest")
.with_exposed_port(9000.tcp())
.with_wait_for(WaitFor::message_on_either_std("API:"))
.with_env_var("MINIO_ROOT_USER", "tc-access")
.with_env_var("MINIO_ROOT_PASSWORD", "tc-secret-key")
.with_cmd(["server", "/data"])
.start()
.await
.expect("minio starts");
// Create the bucket with the bundled mc client.
container
.exec(ExecCommand::new([
"sh",
"-c",
"mc alias set local http://127.0.0.1:9000 tc-access tc-secret-key && mc mb local/teamclaw",
]))
.await
.expect("bucket created");
let port = container.get_host_port_ipv4(9000).await.unwrap();
// The bucket is created asynchronously after boot; retry connect+probe.
let store = S3BlobStore::connect(
&format!("http://127.0.0.1:{port}"),
"teamclaw",
"tc-access",
"tc-secret-key",
)
.expect("client builds");
for _ in 0..50 {
if store.put("probe", b"x").await.is_ok() {
store.delete("probe").await.ok();
return (store, container);
}
tokio::time::sleep(std::time::Duration::from_millis(200)).await;
}
panic!("minio bucket never became writable");
}
#[tokio::test]
async fn s3_round_trip_overwrite_and_missing_keys() {
let (store, _container) = minio_store().await;
store
.put("ws1/documents/agent1/report.md", b"# Q2 Report")
.await
.unwrap();
assert_eq!(
store.get("ws1/documents/agent1/report.md").await.unwrap(),
b"# Q2 Report"
);
// Overwrite replaces.
store
.put("ws1/documents/agent1/report.md", b"# Q3 Report")
.await
.unwrap();
assert_eq!(
store.get("ws1/documents/agent1/report.md").await.unwrap(),
b"# Q3 Report"
);
// Delete then NotFound on both get and delete.
store
.delete("ws1/documents/agent1/report.md")
.await
.unwrap();
assert!(matches!(
store.get("ws1/documents/agent1/report.md").await,
Err(BlobError::NotFound)
));
assert!(matches!(
store.delete("ws1/documents/agent1/report.md").await,
Err(BlobError::NotFound)
));
// Nested keys work without directory semantics.
store.put("a/b/c/deep.txt", b"deep").await.unwrap();
assert_eq!(store.get("a/b/c/deep.txt").await.unwrap(), b"deep");
}