Skip to content

Commit 7f491c1

Browse files
committed
Add real setup CLI deployment and AI configuration end-to-end tests
1 parent 0564ef8 commit 7f491c1

5 files changed

Lines changed: 467 additions & 0 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
99

1010
### Added
1111
- Added privacy-scoped setup wizard funnel telemetry with deployment identity handoff and Node 24 support. [#1653](https://github.com/sourcebot-dev/sourcebot/pull/1653)
12+
- Added isolated live setup CLI deployment tests covering public code hosts, local clones, AI configuration, search, and restart identity; repaired cross-platform test-runner cleanup. [#1653](https://github.com/sourcebot-dev/sourcebot/pull/1653)
1213

1314
## [5.1.13] - 2026-09-12
1415

‎packages/setupWizard/telemetry.html‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1743,6 +1743,7 @@ <h3>Reo coexistence</h3>
17431743
<p>The release notes and telemetry documentation should state that setup-wizard PostHog telemetry is always on when its code executes, list the categories collected, explain that PostHog creates a Person profile keyed only by a random pseudonymous session/deployment ID, explain the new-deployment ID handoff, and distinguish PostHog from Reo’s separate tracking and variable. They must not describe the project ingestion token as a secret.</p>
17441744
<h2>Testing plan</h2>
17451745
<h3>Implementation verification status</h3>
1746+
<p><strong>Live deployment suite:</strong> <code>tests/e2e/liveDeployment.mjs</code> builds and installs the npm tarball, drives the real interactive CLI, and starts the released Sourcebot <code>v5.1.13</code> image with real PostgreSQL, Redis, migrations, backend, and web processes. It exercises public GitHub repository/organization/user scopes, GitLab projects, Gitea repositories, Gerrit projects, generic Git URLs, three local-clone layouts, automatic startup/interruption, and AI configuration. Each deployment uses an isolated Compose project and loopback port; only the test Compose networking/image settings and deployment telemetry opt-out are changed. Generated configuration, environment values, local mounts, and install-ID handoff remain intact. See <code>tests/e2e/liveDeployment.md</code> for reproduction and limits. A final clean rerun of all thirteen live scenarios is in progress; this does not replace the still-required full scenario/branch-coverage accounting.</p>
17461747
<p><strong>Live AI validation scope (user clarification):</strong> verify that the packaged wizard writes the selected provider/model configuration and credential references correctly, that the generated environment values reach the resulting Sourcebot container unchanged, and that Sourcebot starts successfully. Do not invoke Ask or make model-inference requests. A Pro license is not required for this test scope. Use available development credentials without printing them; where credentials are unavailable, distinguish configuration/startup coverage with synthetic values from actual credential validation. Continue real repository discovery, indexing, search, browser access, and restart tests independently.</p>
17471748
<p>The feature is not release-complete until the full completion gate below is satisfied. Executable tests cover packed-package collectors, terminal paths, real SDK payloads, Docker branches, and actual container identity continuity. CI definitions are not evidence that Windows or other remote jobs have run.</p>
17481749
<p>Implementation-discovered changes for the behavioral baseline allowlist: status 130 for Ctrl+C; cancellation-aware readiness cleanup; explicit final process exit after bounded telemetry shutdown; recoverable autocomplete fallback on network/decode failure with an 8-second timeout; and fixed, credential-free SDK shutdown-timeout diagnostics where PostHog itself emits them. Do not patch SDK internals or silence the global console. Empty search/catalog results are not failures; actual infrastructure errors can emit recoverable diagnostics while retaining manual fallback.</p>
Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
# Live deployment verification
2+
3+
Run `liveDeployment.mjs` with Node 24 on macOS or Linux with Docker available.
4+
It builds and installs the actual npm tarball in a disposable directory, drives
5+
the interactive CLI through a PTY, starts the real Sourcebot/Postgres/Redis stack,
6+
onboards a synthetic owner through Chromium, verifies indexing and authenticated
7+
search, then verifies health, search, and install-ID continuity after restart.
8+
9+
Pull `docker.sourcebot.dev/sourcebot-dev/sourcebot:v5.1.13`, `postgres:16`, and
10+
`redis:8` first. The default scenario is `github_repo`. For the public/configuration
11+
matrix, set:
12+
13+
```sh
14+
SETUP_TEST_LIVE_CASES=github_repo,github_org,github_user,gitlab_project,gitea_repo,gerrit_project,remote_git,local_root,local_wildcard,local_nested,auto_start,ai_all \
15+
SETUP_TEST_LIVE_OUTPUT=/absolute/path/outside/the/repository \
16+
node packages/setupWizard/tests/e2e/liveDeployment.mjs
17+
```
18+
19+
The optional `anthropic` scenario reads `ANTHROPIC_API_KEY` from development env
20+
files under `SETUP_TEST_CREDENTIAL_DIR`. Never pass the credential as a command
21+
argument. `ai_all` configures all twelve providers with synthetic values. Neither
22+
scenario calls Ask or an inference endpoint; neither proves credential validity
23+
or requires a Pro license. The tests check generated model configuration,
24+
credential references, container environment propagation, and successful startup.
25+
26+
Every deployment uses a unique Compose project, random loopback HTTP port, and
27+
unpublished database/Redis ports. The Compose download is intercepted only to
28+
apply these isolation settings, pin the image, and disable deployment telemetry.
29+
The wizard's generated config, `.env`, identity, and local-repository override
30+
remain intact. Wizard PostHog requests use the real SDK and are routed to the
31+
local TLS collector; live public autocomplete/model-catalog requests remain real.
32+
This suite does not forward to production or dev PostHog. The separate dev smoke
33+
test provides actual ingestion/query evidence.
34+
35+
Public fixtures are bounded: one explicit repository/project per host, the
36+
small `chalk` organization, and the `octocat` user. Organization/user tests obtain
37+
the expected repository count before starting and require all repositories to
38+
be discovered and indexed. Multi-local tests clone two distinct origins because
39+
Sourcebot deduplicates multiple local clones of the same origin.
40+
41+
Each scenario records success/failure and removes its containers, volumes,
42+
network, generated secrets, and temporary files in cleanup. Only redacted reports
43+
and browser screenshots remain when an output directory is supplied. Task-owned
44+
image downloads should be removed by the operator afterward without removing
45+
images that existed before the run. Do not commit generated artifacts.
46+
47+
This live matrix supplements, not replaces, the deterministic collector, fault,
48+
transport, lifecycle, and platform suites. It does not establish live access to
49+
private/GHE/GitLab self-managed, Azure DevOps, or Bitbucket deployments, and does
50+
not claim every possible code-host scope or credential mode has live coverage.
51+
Unavailable integrations must remain explicitly unverified in the completion
52+
report rather than being inferred from fixture-based coverage.

0 commit comments

Comments
 (0)