Files
clawmates/ci/check-helm.sh
T
Omar SobhandClaude Fable 5 add4f79fed Rebrand: TeamClaw -> Clawmates (clawmates.work)
Full-depth rename per the approved plan; the 'claw' product vocabulary
(claws, /claws routes, clawId, Claw Chat) stays — it is now the brand.

- Display brand: Clawmates (manifest, titles, hero, login/rail logo
  'clawmates'); default host app.clawmates.work; registry
  ghcr.io/clawmates
- Crates tc-* -> cm-* (16 crates + all imports); binaries
  clawmates-server/broker/bundler; images clawmates/*; env prefix
  CLAWMATES_* (+ CM_TEST_DATABASE_URL / CM_LIVE_LLM); config
  clawmates.toml; helm chart deploy/helm/clawmates with clawmates-*
  resources; db names clawmates*; sockets /run/clawmates; cookie
  cm_session; kind cluster clawmates-test; seccomp node profile
  clawmates-agent-profile.json
- All 9 Playwright brand assertions updated in lockstep; historical
  spec document left untouched as the only remaining 'TeamClaw'
- Local env migrated: dev pg clawmates-dev-pg/clawmates_dev, shared
  test server clawmates-test-pg, kind cluster recreated with image +
  profile, compose images rebuilt under clawmates/*

Verified end to end: 161 Rust + 68 frontend tests, 29 Playwright
journeys, 4 live kind tests, helm/install/LOC/placeholder gates, and
the clean-room install rehearsal serving the clawmates login page from
a signed bundle of the rebuilt images.

Co-Authored-By: Claude Fable 5 <[email protected]>
2026-06-10 12:31:25 -05:00

62 lines
1.9 KiB
Bash
Executable File

#!/usr/bin/env bash
# Lints the chart and asserts the load-bearing rendered properties: the
# broker rides as a server sidecar sharing the socket volume, SSE is
# unbuffered at the ingress, and pods run hardened.
set -euo pipefail
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
CHART="$ROOT/deploy/helm/clawmates"
helm lint "$CHART" \
--set auth.issuerUrl=https://idp.example.com \
--set oauth.redirectBase=https://app.clawmates.work
RENDERED=$(helm template clawmates "$CHART" \
--set auth.issuerUrl=https://idp.example.com \
--set oauth.redirectBase=https://app.clawmates.work)
require() {
if ! grep -qF -- "$1" <<<"$RENDERED"; then
echo "FAIL: rendered chart is missing: $1"
exit 1
fi
}
# Broker sidecar shares the unix-socket emptyDir with the server.
require 'name: broker'
require 'value: /run/clawmates/broker.sock'
require 'mountPath: /run/clawmates'
# SSE must not buffer at the ingress.
require 'nginx.ingress.kubernetes.io/proxy-buffering: "off"'
# Hardened pods.
require 'runAsNonRoot: true'
require 'drop: ["ALL"]'
require 'readOnlyRootFilesystem: true'
# Config wired through the ConfigMap.
require 'socket_path = "/run/clawmates/broker.sock"'
# The chart-shipped seccomp profile must BE the Docker driver's profile.
if ! diff -q "$ROOT/images/seccomp/agent-profile.json" \
"$CHART/files/agent-profile.json" >/dev/null; then
echo "FAIL: chart seccomp profile diverged from images/seccomp"
exit 1
fi
HARDENED=$(helm template clawmates "$CHART" \
--set auth.issuerUrl=https://idp.example.com \
--set oauth.redirectBase=https://app.clawmates.work \
--set sandbox.seccomp=localhost \
--set server.autoscaling.enabled=true)
for needle in \
'kind: DaemonSet' \
'clawmates-agent-profile.json' \
'kind: HorizontalPodAutoscaler' \
'averageUtilization: 70'; do
if ! grep -qF -- "$needle" <<<"$HARDENED"; then
echo "FAIL: hardened render is missing: $needle"
exit 1
fi
done
echo "helm chart OK"