feat(ops): add integrity-checked backups and isolated restore drills
CI / check (push) Successful in 4m12s
CI / deploy (push) Failing after 2m8s
CI / publish-container (push) Skipped

This commit is contained in:
Simo committed 2026-09-13 20:29:18 +02:00
1 parent 7867bf6b72
commit 46f7ad6571
10 files changed
+1309 -1

No files matched your search

+43
View File
@@ -0,0 +1,43 @@
import { expect, it } from "vitest";
import {
credentialOptions,
dockerEnvironment,
validateDatabase,
} from "./database.mjs";
it("quotes credentials without permitting option-file injection", () => {
const config = {
host: "127.0.0.1",
port: 3306,
user: "backup",
password: 'quote"slash\\secret',
database: "cms",
};
expect(credentialOptions(config)).toContain(
'password="quote\\"slash\\\\secret"',
);
expect(() =>
credentialOptions({ ...config, password: "secret\n[client]" }),
).toThrow();
expect(() => validateDatabase({ ...config, database: "mysql" })).toThrow();
expect(() =>
validateDatabase({ ...config, database: "cms; DROP DATABASE other" }),
).toThrow();
});
it("passes only explicit Docker runtime variables to subprocesses", () => {
expect(
dockerEnvironment({
PATH: "/bin",
DOCKER_HOST: "unix:///run/docker.sock",
DATABASE_URL: "private",
MARIADB_PWD: "secret",
NODE_OPTIONS: "--inspect",
HOME: "/operator",
}),
).toEqual({
PATH: "/bin",
DOCKER_HOST: "unix:///run/docker.sock",
HOME: "/operator",
});
});