Repository navigation
test(deploy): start serve with the OIDC profile and ask it over HTTP - #1057
Merged
Merged
Conversation
The plumbing tests check files. This starts the real serve command in its own process with an issuer, an audience, an administrator and REQUIRE_OWN_PROVIDER_CREDENTIAL, then checks /healthz is 200, the other routes are 401 without a token, and an incomplete profile exits. Refs #992 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
yeongseon
approved these changes
Oct 6, 2026
yeongseon
left a comment
Collaborator
There was a problem hiding this comment.
diff 를 읽고 승인합니다. 테스트 한 파일과 CHANGELOG 한 줄입니다.
- 실제
serve를 별도 프로세스로 띄우고, 테스트 실행 환경의DEV_MODE·API_KEY·CREDENTIAL_MASTER_KEY·OIDC_*를 빼고 프로필만 넣습니다 — CI 러너의 변수에 기대지 않습니다. - 뜨지 않으면 프로세스 출력을 붙여 실패하고, 60초 한도가 있고, 끝나면 terminate → kill 로 정리합니다.
- 부정 2건(audience 없음, 관리자 없음)이 "refusing to start" 로 끝나는 것을 봅니다.
본문이 적은 한계에 동의합니다 — 이것은 "뜨고 닫혀 있다" 이지 "로그인이 된다" 가 아니고, #992 는 Refs 로 열어 둡니다. 남은 항목(실 Keycloak 토큰)은 kpubdata#812 §4 의 배포 대상·realm 결정을 기다립니다.
알아 둘 것 (막지 않음): 포트를 잡았다 놓고 다시 여는 방식이라 그 사이에 다른 프로세스가 같은 포트를 잡을 수 있습니다. 불안정해지면 그때 serve 가 포트 0 을 받아 실제 포트를 알려 주게 바꾸면 됩니다.
yeongseon
pushed a commit
that referenced
this pull request
Oct 6, 2026
…token (#1058) ## 무엇을 `OIDC_ISSUER` 가 설정되고 `KPUBDATA_BUILDER_API_KEY` 가 없는 배포(다중 사용자 프로필)에서, 토큰 없는 요청의 401 문구를 고칩니다. - 전: `{"error": "api key not configured", "code": "unauthorized"}` - 후: `{"error": "sign-in required: send a bearer token", "code": "unauthorized"}` ## 왜 #1057 의 기동 스모크를 손으로 띄워 보다가 봤습니다. 그 배포에는 설정할 API 키가 없는데, 문구는 읽는 사람을 키 설정 쪽으로 보냅니다. `authenticate()` 가 Bearer 가 없으면 그대로 API 키 경로로 내려가기 때문입니다. ## 바뀌지 않는 것 - 상태 코드(401)와 `code`(`unauthorized`). Studio 는 `code` 로 분기합니다. 문구에 의존하는 곳은 Builder 계약·테스트·문서와 Studio `src` 에서 찾지 못했습니다(`grep "api key not configured"`). - OIDC 와 API 키를 함께 쓰는 배포: 키 경로가 그대로 판정합니다. - OIDC 가 없는 배포: `api key not configured` 그대로. - 인증 실패 집계(#1035)에는 손대지 않았습니다. ## 테스트 `tests/unit/test_oidc_auth.py::TestRequestWithoutAToken` 4건 — OIDC 전용에서 새 문구, API 키를 보내도 같은 답, 부정 2건(키도 받는 배포 / OIDC 없는 배포는 종전대로). ## 검증 - `test_oidc_auth.py`, `test_auth_throttle.py`, `test_signup_ledger.py`, `test_ephemeral_credentials.py` 124건 통과 - `ruff`, `mypy src` 통과 - 전체 단위 스위트는 로컬에서 돌리지 않았습니다. CI 에 맡깁니다. 인증 응답의 문구를 바꾸는 것이라 직접 머지하지 않고 리뷰를 기다립니다. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Eomdahyeon <213566566+Eomdahyeon@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
yeongseon
pushed a commit
that referenced
this pull request
Oct 6, 2026
## 무엇을 #1057 리뷰에서 "막지 않음"으로 남기신 것 — 스모크 테스트가 포트를 잡았다 놓고 다시 여는 사이의 경합 — 을 없앱니다. - `serve --port 0`: 운영체제가 포트를 고르고, `serve` 가 `listening on http://<host>:<port>` 를 한 줄 출력합니다. 다른 포트 값의 동작과 출력은 그대로입니다. - `tests/unit/test_oidc_start_smoke.py`: 미리 포트를 고르지 않고 `--port 0` 으로 띄운 뒤 그 줄에서 포트를 읽습니다. 60초 안에 그 줄이 없거나 프로세스가 먼저 끝나면 그때까지의 출력을 붙여 실패합니다. ## 알아 둘 것 - `--port 0` 일 때 CLI 가 먼저 찍는 `serving kpubdata-builder on http://…:0` 줄은 그대로 `:0` 입니다. 실제 포트는 그 다음 줄에 나옵니다. 그 줄까지 바꾸려면 바인드를 CLI 쪽으로 옮겨야 해서 손대지 않았습니다. - 배포 설정(compose, Dockerfile)은 바꾸지 않았습니다. 기본 포트는 8000 그대로입니다. ## 검증 - 스모크 5건을 3회 연속 통과 (각 약 5초) - `ruff`, `mypy src` 통과 - 전체 단위 스위트는 로컬에서 돌리지 않았습니다. CI 에 맡깁니다. Refs #992 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Eomdahyeon <213566566+Eomdahyeon@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
71 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
무엇을
#992 의 남은 항목 가운데 "OIDC 설정으로
serve기동 →/healthz200" 스모크를 더합니다. 테스트 파일 하나와 CHANGELOG 뿐이고, 서비스 코드는 바꾸지 않았습니다.어떻게
tests/unit/test_oidc_start_smoke.py가 실제serve명령을 별도 프로세스로 띄웁니다. 환경은 다중 사용자 프로필입니다.DEV_MODE,API_KEY,CREDENTIAL_MASTER_KEY는 테스트 실행 환경에 있더라도 빼고 띄웁니다.GET /healthz→ 200{"status": "ok"}/providers,/builds,/version→ 401unauthorizedauth_unavailable(통과시키지 않음)OIDC_AUDIENCE가 없거나ADMIN_SUBJECTS가 없으면 "refusing to start" 로 종료kpubdata 0.9.0 pin(#1050) 덕에 가능해졌습니다 —
REQUIRE_OWN_PROVIDER_CREDENTIAL이 켜져 있으면serve는env_keys를 모르는 kpubdata 에서 기동을 거부합니다(#990).한계
idp.invalid). 서비스가 뜨고 닫혀 있다는 것만 보이고, 로그인이 된다는 것은 보이지 않습니다. 수용 기준의 "실 Keycloak 토큰으로GET /providers200" 은 실제 realm 이 정해진 뒤의 일입니다.test_prod_oidc_plumbing.py가 파일로 확인합니다.api key not configured입니다. 동작은 맞고 문구만 어색합니다. 이 PR 에서는 건드리지 않았습니다.#992 수용 기준 대조
import jwt— fix(deploy): let the production image and compose run OIDC #1020, fix(deploy): build the CUBRID-profile image with the auth extra #1033GET /providers200 — 배포 대상·realm 결정 필요검증
ruff,mypy통과Refs #992 (닫지 않습니다)
🤖 Generated with Claude Code