Files
go-sip/deploys/test/README.md
T

59 lines
3.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Test-only deployment helpers
Nothing in this directory is installed by the production package.
## Dependency infrastructure
Use the existing Docker-backed target for RabbitMQ integration tests:
```sh
make mq-integration-local
```
It starts a disposable RabbitMQ container, waits for readiness, runs the
integration tests and removes the container. Do not install RabbitMQ as a
systemd service or add it to a production host.
## Native Asterisk validation
`nonprod-call-evidence.sh` is the mandatory capture-first wrapper for
non-production `mock`, `mixed` and explicit `nonprod-real` call checks. It runs on a validation
host with native Asterisk and required diagnostics; it is not an Asterisk or
Agent replacement and is not containerized. Run it explicitly with the current
call authorization and the approved target/trunk. It refuses production mode
and fails closed when its prerequisites are missing. Before any dial attempt it
checks the Asia/Shanghai 09:00–20:00 window twice (09:00 included, 20:00
excluded), the exact `enabled` + `active` Asterisk systemd state, the running
ARI module and HTTP `/ari/` route, the selected PJSIP endpoint, and SHA-256
of the installed binary and configuration. Missing facts fail the validation;
`--preflight-only` never authorizes a call. After capture, missing capture or
recording SHA-256, Asterisk journal, SIP summary, logger shutdown, timestamp, or
restricted evidence ownership is recorded in `diagnostic-errors.txt` and fails
the check; an already failed call keeps its nonzero result. Once live tcpdump
and the PJSIP logger are running, the script creates a root-owned, group-readable
`<call-id>.active` capture arm under `--proof-root` (default
`/run/sip-go-agent/nonprod-armed`). The real Agent must set `AGENT_EVIDENCE_ROOT`
to this directory; it checks the exact approved event ID, trunk, raw callee,
recent arm and live capture PID before origination. The script removes the arm
before stopping capture. Run one approved call per invocation, with
`--call-id` equal to that call's MQ `event_id`; never reuse a stale arm.
Isolated tests
replace host tools with fakes: they do not prove a real host or supplier is ready.
For the **nonproduction user-level Asterisk service only**, pass
`--asterisk-scope user` and explicitly set `ASTERISK_BIN` to its installed
native binary and `ASTERISK_CONFIG` to its user-owned `asterisk.conf`; the
native library directory defaults to the binary's sibling `../lib` and may be
set via `ASTERISK_LIBRARY_PATH`. This mode checks `go-sip-asterisk.service`
through `systemctl --user`, runs the CLI with the exact config and collects
the user journal. Missing settings or status fail closed; it neither skips
the installed-artifact checksum/capture requirements nor proves reboot
persistence when lingering is disabled. The default remains system scope.
The offline OSS environment file is a fixture for isolated tests only. It
contains no real credentials or production approval. The former
`ai-dental-meiba-v1.json` is archived at
[`docs/archive/deployment-examples/ai-dental-meiba-v1.json`](../../docs/archive/deployment-examples/ai-dental-meiba-v1.json),
with its original path and SHA-256 recorded in the archive README; it is not a
current AI configuration or an installable deployment input.