Vendor OpenClaw source as Adolf fork baseline
Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
This commit is contained in:
144
test/scripts/k8s-manifests.test.ts
Normal file
144
test/scripts/k8s-manifests.test.ts
Normal file
@@ -0,0 +1,144 @@
|
||||
// K8s manifest tests cover the deployable Kubernetes bundle shape.
|
||||
import { readFileSync } from "node:fs";
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { parse } from "yaml";
|
||||
|
||||
type Manifest = Record<string, unknown>;
|
||||
|
||||
function readManifest(name: string): Manifest {
|
||||
const parsed = parse(readFileSync(`scripts/k8s/manifests/${name}`, "utf8")) as unknown;
|
||||
expect(parsed).toBeTypeOf("object");
|
||||
expect(parsed).not.toBeNull();
|
||||
expect(Array.isArray(parsed)).toBe(false);
|
||||
return parsed as Manifest;
|
||||
}
|
||||
|
||||
function asRecord(value: unknown, label: string): Record<string, unknown> {
|
||||
expect(value, label).toBeTypeOf("object");
|
||||
expect(value, label).not.toBeNull();
|
||||
expect(Array.isArray(value), label).toBe(false);
|
||||
return value as Record<string, unknown>;
|
||||
}
|
||||
|
||||
function asRecords(value: unknown, label: string): Record<string, unknown>[] {
|
||||
expect(Array.isArray(value), label).toBe(true);
|
||||
return value as Record<string, unknown>[];
|
||||
}
|
||||
|
||||
function asStrings(value: unknown, label: string): string[] {
|
||||
expect(Array.isArray(value), label).toBe(true);
|
||||
for (const entry of value as unknown[]) {
|
||||
expect(entry, label).toBeTypeOf("string");
|
||||
}
|
||||
return value as string[];
|
||||
}
|
||||
|
||||
function findNamed(records: Record<string, unknown>[], name: string): Record<string, unknown> {
|
||||
const record = records.find((entry) => entry.name === name);
|
||||
expect(record, name).toBeDefined();
|
||||
return record as Record<string, unknown>;
|
||||
}
|
||||
|
||||
describe("k8s manifests", () => {
|
||||
it("keeps kustomization resources aligned with shipped manifests", () => {
|
||||
const kustomization = readManifest("kustomization.yaml");
|
||||
|
||||
expect(kustomization).toMatchObject({
|
||||
apiVersion: "kustomize.config.k8s.io/v1beta1",
|
||||
kind: "Kustomization",
|
||||
});
|
||||
expect(asStrings(kustomization.resources, "kustomization resources").sort()).toEqual([
|
||||
"configmap.yaml",
|
||||
"deployment.yaml",
|
||||
"pvc.yaml",
|
||||
"service.yaml",
|
||||
]);
|
||||
});
|
||||
|
||||
it("keeps gateway service selectors and ports aligned with deployment labels", () => {
|
||||
const deployment = readManifest("deployment.yaml");
|
||||
const service = readManifest("service.yaml");
|
||||
const deploymentSpec = asRecord(deployment.spec, "deployment spec");
|
||||
const selector = asRecord(deploymentSpec.selector, "deployment selector");
|
||||
const matchLabels = asRecord(selector.matchLabels, "deployment match labels");
|
||||
const template = asRecord(deploymentSpec.template, "deployment template");
|
||||
const templateMetadata = asRecord(template.metadata, "deployment template metadata");
|
||||
const templateLabels = asRecord(templateMetadata.labels, "deployment template labels");
|
||||
const serviceSpec = asRecord(service.spec, "service spec");
|
||||
const serviceSelector = asRecord(serviceSpec.selector, "service selector");
|
||||
const ports = asRecords(serviceSpec.ports, "service ports");
|
||||
|
||||
expect(deployment).toMatchObject({
|
||||
apiVersion: "apps/v1",
|
||||
kind: "Deployment",
|
||||
metadata: { name: "openclaw" },
|
||||
});
|
||||
expect(matchLabels).toEqual({ app: "openclaw" });
|
||||
expect(templateLabels).toMatchObject(matchLabels);
|
||||
expect(serviceSelector).toEqual(matchLabels);
|
||||
expect(ports).toContainEqual({
|
||||
name: "gateway",
|
||||
port: 18789,
|
||||
protocol: "TCP",
|
||||
targetPort: 18789,
|
||||
});
|
||||
});
|
||||
|
||||
it("keeps deployment mounts, secrets, and security posture deployable", () => {
|
||||
const deployment = readManifest("deployment.yaml");
|
||||
const spec = asRecord(deployment.spec, "deployment spec");
|
||||
const template = asRecord(spec.template, "deployment template");
|
||||
const podSpec = asRecord(template.spec, "pod spec");
|
||||
const containers = asRecords(podSpec.containers, "containers");
|
||||
const gateway = findNamed(containers, "gateway");
|
||||
const env = asRecords(gateway.env, "gateway env");
|
||||
const volumes = asRecords(podSpec.volumes, "pod volumes");
|
||||
const securityContext = asRecord(gateway.securityContext, "gateway security context");
|
||||
|
||||
expect(gateway.command).toEqual(["node", "/app/dist/index.js", "gateway", "run"]);
|
||||
expect(findNamed(env, "HOME")).toMatchObject({ value: "/home/node" });
|
||||
expect(findNamed(env, "OPENCLAW_CONFIG_DIR")).toMatchObject({ value: "/home/node/.openclaw" });
|
||||
expect(findNamed(env, "OPENCLAW_GATEWAY_TOKEN")).toMatchObject({
|
||||
valueFrom: { secretKeyRef: { key: "OPENCLAW_GATEWAY_TOKEN", name: "openclaw-secrets" } },
|
||||
});
|
||||
expect(findNamed(volumes, "openclaw-home")).toMatchObject({
|
||||
persistentVolumeClaim: { claimName: "openclaw-home-pvc" },
|
||||
});
|
||||
expect(findNamed(volumes, "config")).toMatchObject({ configMap: { name: "openclaw-config" } });
|
||||
expect(securityContext).toMatchObject({
|
||||
allowPrivilegeEscalation: false,
|
||||
readOnlyRootFilesystem: true,
|
||||
runAsNonRoot: true,
|
||||
});
|
||||
});
|
||||
|
||||
it("keeps config and persistence manifests aligned with the gateway", () => {
|
||||
const configMap = readManifest("configmap.yaml");
|
||||
const pvc = readManifest("pvc.yaml");
|
||||
const data = asRecord(configMap.data, "configmap data");
|
||||
const config = JSON.parse(String(data["openclaw.json"])) as Record<string, unknown>;
|
||||
const gateway = asRecord(config.gateway, "openclaw config gateway");
|
||||
const auth = asRecord(gateway.auth, "openclaw config auth");
|
||||
const agents = asRecord(config.agents, "openclaw config agents");
|
||||
const defaults = asRecord(agents.defaults, "openclaw config agent defaults");
|
||||
const pvcSpec = asRecord(pvc.spec, "pvc spec");
|
||||
const resources = asRecord(pvcSpec.resources, "pvc resources");
|
||||
const requests = asRecord(resources.requests, "pvc resource requests");
|
||||
|
||||
expect(configMap).toMatchObject({
|
||||
apiVersion: "v1",
|
||||
kind: "ConfigMap",
|
||||
metadata: { name: "openclaw-config" },
|
||||
});
|
||||
expect(gateway).toMatchObject({ mode: "local", port: 18789 });
|
||||
expect(auth).toMatchObject({ mode: "token" });
|
||||
expect(defaults).toMatchObject({ workspace: "~/.openclaw/workspace" });
|
||||
expect(data["AGENTS.md"]).toContain("OpenClaw Assistant");
|
||||
expect(pvc).toMatchObject({
|
||||
apiVersion: "v1",
|
||||
kind: "PersistentVolumeClaim",
|
||||
metadata: { name: "openclaw-home-pvc" },
|
||||
});
|
||||
expect(requests).toMatchObject({ storage: "10Gi" });
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user