3.2 KiB
Test-only deployment helpers
Nothing in this directory is installed by the production package.
Dependency infrastructure
Use the existing Docker-backed target for RabbitMQ integration tests:
make mq-integration-local
It starts a disposable RabbitMQ container, waits for readiness, runs the integration tests and removes the container. Do not install RabbitMQ as a systemd service or add it to a production host.
Native Asterisk validation
nonprod-call-evidence.sh is the mandatory capture-first wrapper for
non-production mock, mixed and explicit nonprod-real call checks. It runs on a validation
host with native Asterisk and required diagnostics; it is not an Asterisk or
Agent replacement and is not containerized. Run it explicitly with the current
call authorization and the approved target/trunk. It refuses production mode
and fails closed when its prerequisites are missing. Before any dial attempt it
checks the Asia/Shanghai 09:00–20:00 window twice (09:00 included, 20:00
excluded), the exact enabled + active Asterisk systemd state, the running
ARI module and HTTP /ari/ route, the selected PJSIP endpoint, and SHA-256
of the installed binary and configuration. Missing facts fail the validation;
--preflight-only never authorizes a call. After capture, missing capture or
recording SHA-256, Asterisk journal, SIP summary, logger shutdown, timestamp, or
restricted evidence ownership is recorded in diagnostic-errors.txt and fails
the check; an already failed call keeps its nonzero result. Once live tcpdump
and the PJSIP logger are running, the script creates a root-owned, group-readable
<call-id>.active capture arm under --proof-root (default
/run/sip-go-agent/nonprod-armed). The real Agent must set AGENT_EVIDENCE_ROOT
to this directory; it checks the exact approved event ID, trunk, raw callee,
recent arm and live capture PID before origination. The script removes the arm
before stopping capture. Run one approved call per invocation, with
--call-id equal to that call's MQ event_id; never reuse a stale arm.
Isolated tests
replace host tools with fakes: they do not prove a real host or supplier is ready.
For the nonproduction user-level Asterisk service only, pass
--asterisk-scope user and explicitly set ASTERISK_BIN to its installed
native binary and ASTERISK_CONFIG to its user-owned asterisk.conf; the
native library directory defaults to the binary's sibling ../lib and may be
set via ASTERISK_LIBRARY_PATH. This mode checks go-sip-asterisk.service
through systemctl --user, runs the CLI with the exact config and collects
the user journal. Missing settings or status fail closed; it neither skips
the installed-artifact checksum/capture requirements nor proves reboot
persistence when lingering is disabled. The default remains system scope.
The offline OSS environment file is a fixture for isolated tests only. It
contains no real credentials or production approval. The former
ai-dental-meiba-v1.json is archived at
docs/archive/deployment-examples/ai-dental-meiba-v1.json,
with its original path and SHA-256 recorded in the archive README; it is not a
current AI configuration or an installable deployment input.