Test-only deployment helpers
Nothing in this directory is installed by the production package.
Dependency infrastructure
Use the existing Docker-backed target for RabbitMQ integration tests:
make mq-integration-local
It starts a disposable RabbitMQ container, waits for readiness, runs the integration tests and removes the container. Do not install RabbitMQ as a systemd service or add it to a production host.
Native Asterisk validation
nonprod-call-evidence.sh is the mandatory capture-first wrapper for
non-production mock, mixed and explicit nonprod-real call checks. It runs on a validation
host with native Asterisk and required diagnostics; it is not an Asterisk or
Agent replacement and is not containerized. Run it explicitly with the current
call authorization and the approved target/trunk. It refuses production mode
and fails closed when its prerequisites are missing. Before any dial attempt it
checks the Asia/Shanghai 09:00–20:00 window twice (09:00 included, 20:00
excluded), the exact enabled + active Asterisk systemd state, the running
ARI module and HTTP /ari/ route, the selected PJSIP endpoint, and SHA-256
of the installed binary and configuration. Missing facts fail the validation;
--preflight-only never authorizes a call. After capture, missing capture or
recording SHA-256, Asterisk journal, SIP summary, logger shutdown, timestamp, or
restricted evidence ownership is recorded in diagnostic-errors.txt and fails
the check; an already failed call keeps its nonzero result. Once live tcpdump
and the PJSIP logger are running, the script creates a root-owned, group-readable
<call-id>.active capture arm under --proof-root (default
/run/sip-go-agent/nonprod-armed). The real Agent must set AGENT_EVIDENCE_ROOT
to this directory; it checks the exact approved event ID, trunk, raw callee,
recent arm and live capture PID before origination. The script removes the arm
before stopping capture. Run one approved call per invocation, with
--call-id equal to that call's MQ event_id; never reuse a stale arm.
Isolated tests
replace host tools with fakes: they do not prove a real host or supplier is ready.
For the nonproduction user-level Asterisk service only, pass
--asterisk-scope user and explicitly set ASTERISK_BIN to its installed
native binary and ASTERISK_CONFIG to its user-owned asterisk.conf; the
native library directory defaults to the binary's sibling ../lib and may be
set via ASTERISK_LIBRARY_PATH. This mode checks go-sip-asterisk.service
through systemctl --user, runs the CLI with the exact config and collects
the user journal. Missing settings or status fail closed; it neither skips
the installed-artifact checksum/capture requirements nor proves reboot
persistence when lingering is disabled. The default remains system scope.
For nonproduction real calls, additionally configure the on-host Asterisk HEP
mirror as described in cell/README.md, with
AGENT_HEP_LISTEN_ADDR=127.0.0.1:<port> matching capture_address in the
private hep.conf. Confirm res_hep and res_hep_pjsip are running and the
Agent's UDP listener is bound before any explicitly authorized trial. The
capture-first wrapper remains mandatory; HEP is not a replacement for pcap,
PJSIP logger, call-window checks, or caller approval. Verify the same
call.execute.result is present in Dispatcher outbox and the SaaS Mock's
restricted result store; inspect full raw only there and do not place it in
logs, source, chat, or long-term evidence. A missing mirror produces a clear
sip_capture_error but does not undo a proven call end or release. This setup
by itself neither places a real call nor establishes that one was answered.
The offline OSS environment file is a fixture for isolated tests only. It
contains no real credentials or production approval. The former
ai-dental-meiba-v1.json is archived at
docs/archive/deployment-examples/ai-dental-meiba-v1.json,
with its original path and SHA-256 recorded in the archive README; it is not a
current AI configuration or an installable deployment input.