# Test-only deployment helpers Nothing in this directory is installed by the production package. ## Dependency infrastructure Use the existing Docker-backed target for RabbitMQ integration tests: ```sh make mq-integration-local ``` It starts a disposable RabbitMQ container, waits for readiness, runs the integration tests and removes the container. Do not install RabbitMQ as a systemd service or add it to a production host. ## Native Asterisk validation `nonprod-call-evidence.sh` is the mandatory capture-first wrapper for non-production `mock`, `mixed` and explicit `nonprod-real` call checks. It runs on a validation host with native Asterisk and required diagnostics; it is not an Asterisk or Agent replacement and is not containerized. Run it explicitly with the current call authorization and the approved target/trunk. It refuses production mode and fails closed when its prerequisites are missing. Before any dial attempt it checks the Asia/Shanghai 09:00–20:00 window twice (09:00 included, 20:00 excluded), the exact `enabled` + `active` Asterisk systemd state, the running ARI module and HTTP `/ari/` route, the selected PJSIP endpoint, and SHA-256 of the installed binary and configuration. Missing facts fail the validation; `--preflight-only` never authorizes a call. After capture, missing capture or recording SHA-256, Asterisk journal, SIP summary, logger shutdown, timestamp, or restricted evidence ownership is recorded in `diagnostic-errors.txt` and fails the check; an already failed call keeps its nonzero result. Once live tcpdump and the PJSIP logger are running, the script creates a root-owned, group-readable `.active` capture arm under `--proof-root` (default `/run/sip-go-agent/nonprod-armed`). The real Agent must set `AGENT_EVIDENCE_ROOT` to this directory; it checks the exact approved event ID, trunk, raw callee, recent arm and live capture PID before origination. The script removes the arm before stopping capture. Run one approved call per invocation, with `--call-id` equal to that call's MQ `event_id`; never reuse a stale arm. Isolated tests replace host tools with fakes: they do not prove a real host or supplier is ready. For the **nonproduction user-level Asterisk service only**, pass `--asterisk-scope user` and explicitly set `ASTERISK_BIN` to its installed native binary and `ASTERISK_CONFIG` to its user-owned `asterisk.conf`; the native library directory defaults to the binary's sibling `../lib` and may be set via `ASTERISK_LIBRARY_PATH`. This mode checks `go-sip-asterisk.service` through `systemctl --user`, runs the CLI with the exact config and collects the user journal. Missing settings or status fail closed; it neither skips the installed-artifact checksum/capture requirements nor proves reboot persistence when lingering is disabled. The default remains system scope. The offline OSS environment file is a fixture for isolated tests only. It contains no real credentials or production approval. The former `ai-dental-meiba-v1.json` is archived at [`docs/archive/deployment-examples/ai-dental-meiba-v1.json`](../../docs/archive/deployment-examples/ai-dental-meiba-v1.json), with its original path and SHA-256 recorded in the archive README; it is not a current AI configuration or an installable deployment input.