59 lines
3.2 KiB
Markdown
59 lines
3.2 KiB
Markdown
# Test-only deployment helpers
|
||
|
||
Nothing in this directory is installed by the production package.
|
||
|
||
## Dependency infrastructure
|
||
|
||
Use the existing Docker-backed target for RabbitMQ integration tests:
|
||
|
||
```sh
|
||
make mq-integration-local
|
||
```
|
||
|
||
It starts a disposable RabbitMQ container, waits for readiness, runs the
|
||
integration tests and removes the container. Do not install RabbitMQ as a
|
||
systemd service or add it to a production host.
|
||
|
||
## Native Asterisk validation
|
||
|
||
`nonprod-call-evidence.sh` is the mandatory capture-first wrapper for
|
||
non-production `mock`, `mixed` and explicit `nonprod-real` call checks. It runs on a validation
|
||
host with native Asterisk and required diagnostics; it is not an Asterisk or
|
||
Agent replacement and is not containerized. Run it explicitly with the current
|
||
call authorization and the approved target/trunk. It refuses production mode
|
||
and fails closed when its prerequisites are missing. Before any dial attempt it
|
||
checks the Asia/Shanghai 09:00–20:00 window twice (09:00 included, 20:00
|
||
excluded), the exact `enabled` + `active` Asterisk systemd state, the running
|
||
ARI module and HTTP `/ari/` route, the selected PJSIP endpoint, and SHA-256
|
||
of the installed binary and configuration. Missing facts fail the validation;
|
||
`--preflight-only` never authorizes a call. After capture, missing capture or
|
||
recording SHA-256, Asterisk journal, SIP summary, logger shutdown, timestamp, or
|
||
restricted evidence ownership is recorded in `diagnostic-errors.txt` and fails
|
||
the check; an already failed call keeps its nonzero result. Once live tcpdump
|
||
and the PJSIP logger are running, the script creates a root-owned, group-readable
|
||
`<call-id>.active` capture arm under `--proof-root` (default
|
||
`/run/sip-go-agent/nonprod-armed`). The real Agent must set `AGENT_EVIDENCE_ROOT`
|
||
to this directory; it checks the exact approved event ID, trunk, raw callee,
|
||
recent arm and live capture PID before origination. The script removes the arm
|
||
before stopping capture. Run one approved call per invocation, with
|
||
`--call-id` equal to that call's MQ `event_id`; never reuse a stale arm.
|
||
Isolated tests
|
||
replace host tools with fakes: they do not prove a real host or supplier is ready.
|
||
|
||
For the **nonproduction user-level Asterisk service only**, pass
|
||
`--asterisk-scope user` and explicitly set `ASTERISK_BIN` to its installed
|
||
native binary and `ASTERISK_CONFIG` to its user-owned `asterisk.conf`; the
|
||
native library directory defaults to the binary's sibling `../lib` and may be
|
||
set via `ASTERISK_LIBRARY_PATH`. This mode checks `go-sip-asterisk.service`
|
||
through `systemctl --user`, runs the CLI with the exact config and collects
|
||
the user journal. Missing settings or status fail closed; it neither skips
|
||
the installed-artifact checksum/capture requirements nor proves reboot
|
||
persistence when lingering is disabled. The default remains system scope.
|
||
|
||
The offline OSS environment file is a fixture for isolated tests only. It
|
||
contains no real credentials or production approval. The former
|
||
`ai-dental-meiba-v1.json` is archived at
|
||
[`docs/archive/deployment-examples/ai-dental-meiba-v1.json`](../../docs/archive/deployment-examples/ai-dental-meiba-v1.json),
|
||
with its original path and SHA-256 recorded in the archive README; it is not a
|
||
current AI configuration or an installable deployment input.
|