diff --git a/.gitea/actions/quickstack-oci/deploy.test.mjs b/.gitea/actions/quickstack-oci/deploy.test.mjs index 77cacb4..27b4486 100644 --- a/.gitea/actions/quickstack-oci/deploy.test.mjs +++ b/.gitea/actions/quickstack-oci/deploy.test.mjs @@ -6,6 +6,7 @@ import { deployExactImage, expandTokens, mergeEnvironment, + resolveSecretEnvironment, orderApplications, resolveDeploymentBranch, resolvePullRequestHeadBranch, @@ -170,6 +171,24 @@ test("preserves response-only fields and existing environment secrets safely", ( assert.equal(mergeEnvironment(app().envVars, { ENVIRONMENT: "new" }), "SECRET=preserved\nENVIRONMENT=new"); }); +test("maps only explicitly declared Actions secrets into runtime environment", () => { + assert.deepEqual( + resolveSecretEnvironment( + { MINIO_ENDPOINT: "MINIO_ENDPOINT", MINIO_REGION: "MINIO_REGION" }, + { MINIO_ENDPOINT: "https://minio.example.test", MINIO_REGION: "us-east-1" }, + ), + { MINIO_ENDPOINT: "https://minio.example.test", MINIO_REGION: "us-east-1" }, + ); + assert.throws( + () => resolveSecretEnvironment({ MINIO_ENDPOINT: "MINIO_ENDPOINT" }, {}), + /Missing Actions secret MINIO_ENDPOINT/, + ); + assert.throws( + () => resolveSecretEnvironment({ "INVALID-KEY": "MINIO_ENDPOINT" }, { MINIO_ENDPOINT: "value" }), + /Invalid secret environment key/, + ); +}); + test("postflight waits for the exact expected identity", async () => { let attempt = 0; const result = await verifyEndpoint(