Full-depth rename per the approved plan; the 'claw' product vocabulary (claws, /claws routes, clawId, Claw Chat) stays — it is now the brand. - Display brand: Clawmates (manifest, titles, hero, login/rail logo 'clawmates'); default host app.clawmates.work; registry ghcr.io/clawmates - Crates tc-* -> cm-* (16 crates + all imports); binaries clawmates-server/broker/bundler; images clawmates/*; env prefix CLAWMATES_* (+ CM_TEST_DATABASE_URL / CM_LIVE_LLM); config clawmates.toml; helm chart deploy/helm/clawmates with clawmates-* resources; db names clawmates*; sockets /run/clawmates; cookie cm_session; kind cluster clawmates-test; seccomp node profile clawmates-agent-profile.json - All 9 Playwright brand assertions updated in lockstep; historical spec document left untouched as the only remaining 'TeamClaw' - Local env migrated: dev pg clawmates-dev-pg/clawmates_dev, shared test server clawmates-test-pg, kind cluster recreated with image + profile, compose images rebuilt under clawmates/* Verified end to end: 161 Rust + 68 frontend tests, 29 Playwright journeys, 4 live kind tests, helm/install/LOC/placeholder gates, and the clean-room install rehearsal serving the clawmates login page from a signed bundle of the rebuilt images. Co-Authored-By: Claude Fable 5 <[email protected]>
62 lines
1.9 KiB
Bash
Executable File
62 lines
1.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Lints the chart and asserts the load-bearing rendered properties: the
|
|
# broker rides as a server sidecar sharing the socket volume, SSE is
|
|
# unbuffered at the ingress, and pods run hardened.
|
|
set -euo pipefail
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
|
|
CHART="$ROOT/deploy/helm/clawmates"
|
|
|
|
helm lint "$CHART" \
|
|
--set auth.issuerUrl=https://idp.example.com \
|
|
--set oauth.redirectBase=https://app.clawmates.work
|
|
|
|
RENDERED=$(helm template clawmates "$CHART" \
|
|
--set auth.issuerUrl=https://idp.example.com \
|
|
--set oauth.redirectBase=https://app.clawmates.work)
|
|
|
|
require() {
|
|
if ! grep -qF -- "$1" <<<"$RENDERED"; then
|
|
echo "FAIL: rendered chart is missing: $1"
|
|
exit 1
|
|
fi
|
|
}
|
|
|
|
# Broker sidecar shares the unix-socket emptyDir with the server.
|
|
require 'name: broker'
|
|
require 'value: /run/clawmates/broker.sock'
|
|
require 'mountPath: /run/clawmates'
|
|
# SSE must not buffer at the ingress.
|
|
require 'nginx.ingress.kubernetes.io/proxy-buffering: "off"'
|
|
# Hardened pods.
|
|
require 'runAsNonRoot: true'
|
|
require 'drop: ["ALL"]'
|
|
require 'readOnlyRootFilesystem: true'
|
|
# Config wired through the ConfigMap.
|
|
require 'socket_path = "/run/clawmates/broker.sock"'
|
|
|
|
# The chart-shipped seccomp profile must BE the Docker driver's profile.
|
|
if ! diff -q "$ROOT/images/seccomp/agent-profile.json" \
|
|
"$CHART/files/agent-profile.json" >/dev/null; then
|
|
echo "FAIL: chart seccomp profile diverged from images/seccomp"
|
|
exit 1
|
|
fi
|
|
|
|
HARDENED=$(helm template clawmates "$CHART" \
|
|
--set auth.issuerUrl=https://idp.example.com \
|
|
--set oauth.redirectBase=https://app.clawmates.work \
|
|
--set sandbox.seccomp=localhost \
|
|
--set server.autoscaling.enabled=true)
|
|
for needle in \
|
|
'kind: DaemonSet' \
|
|
'clawmates-agent-profile.json' \
|
|
'kind: HorizontalPodAutoscaler' \
|
|
'averageUtilization: 70'; do
|
|
if ! grep -qF -- "$needle" <<<"$HARDENED"; then
|
|
echo "FAIL: hardened render is missing: $needle"
|
|
exit 1
|
|
fi
|
|
done
|
|
|
|
echo "helm chart OK"
|