NODEDC_PLATFORM/docs/LOCAL_TESTING_SYSTEM.md

175 lines
4.6 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# NODE.DC Local Testing System
Цель: тестировать новые функции на локально запущенных репозиториях без переписывания адресов перед деплоем и без случайных обращений в production-приложения.
## Canon
Локальный профиль:
```text
NODEDC_ENV=local
```
В `local` все product apps являются локальными:
```text
Launcher/Auth/HUB UI -> local
Engine -> local
Ops/Gateway/Tasker -> local
AI Workspace Assistant -> local
DB/fixtures -> local
```
Единственное разрешенное deployed-звено в этом профиле:
```text
AI Hub relay -> https://ai-hub.nodedc.ru
```
Этот Hub используется только как транспорт для удаленного Codex worker. Он не должен быть downstream app, не должен владеть доступами пользователя и не должен сам читать/писать Launcher, Engine или Ops.
## Remote Worker Local Flow
```text
local Engine / local Ops UI
-> local AI Workspace Assistant
-> deployed AI Hub relay
-> remote Codex worker
-> deployed AI Hub assistant action relay
-> local AI Workspace Assistant
-> local Launcher / local Engine / local Ops
```
Worker получает только relay URL и scoped run profile. Product app URL остаются на стороне локального Assistant.
## Required Local Guardrails
Local Platform env:
```text
NODEDC_ENV=local
AI_WORKSPACE_HUB_PUBLIC_URL=wss://ai-hub.nodedc.ru/api/ai-workspace/hub
AI_WORKSPACE_HUB_INTERNAL_URL=https://ai-hub.nodedc.ru
AI_WORKSPACE_ASSISTANT_ACTION_RELAY_ENABLED=true
AI_WORKSPACE_ASSISTANT_ACTION_RELAY_ID=local-dev
```
Local Engine env:
```text
NODEDC_ENV=local
NODEDC_AI_WORKSPACE_ASSISTANT_URL=http://127.0.0.1:18082
NODEDC_LAUNCHER_INTERNAL_URL=http://127.0.0.1:5173
NODEDC_LAUNCHER_ORIGIN=http://launcher.local.nodedc
AUTHENTIK_PUBLIC_BASE_URL=http://auth.local.nodedc
```
Production app URLs are forbidden in local config:
```text
https://hub.nodedc.ru
https://engine.nodedc.ru
https://ops.nodedc.ru
https://id.nodedc.ru
https://ops-agents.nodedc.ru
```
Tunnel/private URLs are also forbidden in `local`. If Tailscale/ngrok is deliberately needed, switch to:
```text
NODEDC_ENV=tunnel-local-e2e
```
## Standard Check
Run this before UI testing and before deploy preparation:
```sh
cd /Users/dcconstructions/Downloads/mnt/NODEDC/platform
sh infra/scripts/check-local-test-system.sh
```
This command:
- checks Node and shell syntax;
- checks local env safety;
- checks AI Workspace config contract;
- renders local Docker Compose config without starting containers;
- checks that local Compose does not inject the full `.env` into every service;
- runs run-profile and ontology assistant caller smoke tests;
- classifies the current runtime topology;
- checks diff whitespace hygiene.
It does not deploy, restart containers, mutate databases, or write production config.
## Runtime Modes
`contract-only`
Static contracts are testable, but no runtime path is proven.
`local-ui-only`
Some local UI/backend endpoints respond, but AI write path is not proven.
`local-ops-vertical`
Local Ops/Gateway/Tasker vertical path is reachable, but remote worker action path is not proven.
`local-remote-worker-relay`
Expected current target for this workstation:
```text
local product apps + local Assistant + deployed AI Hub relay + remote Codex worker
```
This is valid only when Assistant action relay is configured. A successful UI request must show that `assistant_action_call` routes through the relay back to local Assistant.
`true-local-e2e`
Everything, including Hub and worker reachability, is local.
`tunnel-local-e2e`
Explicit Tailscale/ngrok profile. This must never happen by accidental URL fallback.
## Strict Runtime Checks
Require a live local/relay runtime:
```sh
REQUIRE_RUNTIME=1 sh infra/scripts/check-local-test-system.sh
```
Require specifically the remote-worker relay mode:
```sh
REQUIRE_REMOTE_WORKER_RELAY=1 sh infra/scripts/check-local-test-system.sh
```
## Deploy Rule
Deploy is allowed only after:
```sh
sh infra/scripts/check-local-test-system.sh
sh infra/scripts/check-ai-workspace-release-gates.sh
```
Runtime bugs must be fixed in the local profile first. Do not deploy product app changes just to test whether the local AI Workspace path works.
## Audit And Test Map
Current audit report:
```text
docs/AI_WORKSPACE_SECURITY_AUDIT_2026-06-20.md
```
Current horizontal, vertical, and security test matrix:
```text
docs/AI_WORKSPACE_TEST_MATRIX.md
```