117 lines
4.9 KiB
Bash
Executable File
117 lines
4.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
umask 077
|
|
|
|
ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd)
|
|
K6_IMAGE="grafana/k6@sha256:65c920dc067d5e2e00befbf982af6ad6ad0117034e8b1c65817c7975c52d4669"
|
|
temporary_directory=$(mktemp -d "${TMPDIR:-/tmp}/wnh-production-load-drill.XXXXXX")
|
|
|
|
cleanup() {
|
|
trap - EXIT HUP INT TERM
|
|
rm -rf "$temporary_directory"
|
|
}
|
|
trap cleanup EXIT HUP INT TERM
|
|
|
|
mkdir -p "$temporary_directory/bin"
|
|
# The single-quoted text below is intentionally written into the SSH stub and
|
|
# expands only when that generated script runs.
|
|
# shellcheck disable=SC2016
|
|
printf '%s\n' \
|
|
'#!/bin/sh' \
|
|
'if [ "${WNH_LOAD_STUB_MODE:-good}" = bad ]; then' \
|
|
' printf "%s\n" "commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" "project=unexpected" "deployment_env=test" "phx_host=invalid.example" "base_url=https://invalid.example" "containers=invalid-app-1" "cpu_count=1" "mem_total_kib=1" "mem_available_kib=1" "load_average=0 0 0"' \
|
|
'else' \
|
|
' printf "%s\n" "commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" "project=who_need_help_production" "deployment_env=production" "phx_host=whoneedhelp.com" "base_url=https://whoneedhelp.com" "containers=who_need_help_production-app-1" "cpu_count=2" "mem_total_kib=4000000" "mem_available_kib=1000000" "load_average=0.1 0.1 0.1"' \
|
|
'fi' >"$temporary_directory/bin/ssh"
|
|
chmod +x "$temporary_directory/bin/ssh"
|
|
|
|
export PATH="$temporary_directory/bin:$PATH"
|
|
export WNH_PRODUCTION_LOAD_HTTP_VUS=1
|
|
export WNH_PRODUCTION_LOAD_WS_VUS=1
|
|
export WNH_PRODUCTION_LOAD_DURATION=1s
|
|
export WNH_PRODUCTION_LOAD_HTTP_THINK_SECONDS=1
|
|
export WNH_PRODUCTION_LOAD_WS_HOLD_MS=1000
|
|
export WNH_PRODUCTION_LOAD_WS_CONNECT_TIMEOUT_MS=3000
|
|
|
|
"$ROOT/scripts/production-readonly-load.sh" plan drill \
|
|
>"$temporary_directory/plan.txt"
|
|
grep -F 'URL: https://whoneedhelp.com' "$temporary_directory/plan.txt" >/dev/null
|
|
grep -F 'No POST, login attempt, registration, email, support request' \
|
|
"$temporary_directory/plan.txt" >/dev/null
|
|
grep -F \
|
|
"WNH_PRODUCTION_LOAD_CONFIRM='whoneedhelp.com:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa:http=1:ws=1:duration=1s'" \
|
|
"$temporary_directory/plan.txt" >/dev/null
|
|
|
|
if WNH_LOAD_STUB_MODE=bad \
|
|
"$ROOT/scripts/production-readonly-load.sh" plan drill-bad-target \
|
|
>"$temporary_directory/bad-target.txt" 2>&1; then
|
|
echo "Production runner accepted an unexpected deployment identity." >&2
|
|
exit 1
|
|
fi
|
|
grep -F 'does not match the pinned production identity' \
|
|
"$temporary_directory/bad-target.txt" >/dev/null
|
|
|
|
if WNH_PRODUCTION_LOAD_CONFIRM=wrong \
|
|
"$ROOT/scripts/production-readonly-load.sh" run drill-refusal \
|
|
>"$temporary_directory/refusal.txt" 2>&1; then
|
|
echo "Production runner accepted an incorrect confirmation." >&2
|
|
exit 1
|
|
fi
|
|
grep -F 'does not match this verified plan' \
|
|
"$temporary_directory/refusal.txt" >/dev/null
|
|
test ! -e "$ROOT/output/performance/drill-refusal"
|
|
|
|
printf '%s\n' \
|
|
'{"observed_at":"2026-07-28T00:00:00Z","host":{"load_1":0.5,"mem_total_kib":4000000,"mem_available_kib":1000000,"host_postgres_rss_kib":200000},"containers":[{"Name":"app-1","CPUPerc":"10.0%","MemUsage":"200MiB / 4GiB","PIDs":"25"}]}' \
|
|
'{"observed_at":"2026-07-28T00:00:01Z","host":{"load_1":0.7,"mem_total_kib":4000000,"mem_available_kib":900000,"host_postgres_rss_kib":210000},"containers":[{"Name":"app-1","CPUPerc":"20.0%","MemUsage":"210MiB / 4GiB","PIDs":"26"}]}' \
|
|
>"$temporary_directory/server-stats.jsonl"
|
|
"$ROOT/scripts/summarize-production-load.py" \
|
|
"$temporary_directory/server-stats.jsonl" \
|
|
"$temporary_directory/server-stats-summary.json"
|
|
jq -e '
|
|
.sample_count == 2 and
|
|
.host.load_1.average == 0.6 and
|
|
.host.mem_available_kib.minimum == 900000 and
|
|
.host.host_postgres_rss_kib.maximum == 210000 and
|
|
.containers[0].memory_bytes.first_to_last_delta == 10485760
|
|
' "$temporary_directory/server-stats-summary.json" >/dev/null
|
|
|
|
docker run --rm \
|
|
--volume "$ROOT/load/k6:/scripts:ro" \
|
|
"$K6_IMAGE" inspect \
|
|
-e BASE_URL=https://whoneedhelp.com \
|
|
-e HTTP_VUS=1 \
|
|
-e WS_VUS=1 \
|
|
-e DURATION=1s \
|
|
-e HTTP_THINK_SECONDS=1 \
|
|
-e WS_HOLD_MS=1000 \
|
|
-e WS_CONNECT_TIMEOUT_MS=3000 \
|
|
/scripts/production-readonly.js \
|
|
>"$temporary_directory/k6-inspect.json"
|
|
jq -e '
|
|
.scenarios.public_http.vus == 1 and
|
|
.scenarios.phoenix_websocket.vus == 1 and
|
|
.thresholds.http_req_failed[0].threshold == "rate==0"
|
|
' "$temporary_directory/k6-inspect.json" >/dev/null
|
|
|
|
docker run --rm \
|
|
--volume "$ROOT/load/k6:/scripts:ro" \
|
|
"$K6_IMAGE" inspect \
|
|
-e BASE_URL=https://whoneedhelp.com \
|
|
-e HTTP_VUS=0 \
|
|
-e WS_VUS=1 \
|
|
-e DURATION=1s \
|
|
-e HTTP_THINK_SECONDS=1 \
|
|
-e WS_HOLD_MS=1000 \
|
|
-e WS_CONNECT_TIMEOUT_MS=3000 \
|
|
/scripts/production-readonly.js \
|
|
>"$temporary_directory/k6-websocket-only-inspect.json"
|
|
jq -e '
|
|
(.scenarios | has("public_http") | not) and
|
|
.scenarios.phoenix_websocket.vus == 1 and
|
|
(.thresholds | has("checks") | not) and
|
|
(.thresholds | has("http_req_failed") | not)
|
|
' "$temporary_directory/k6-websocket-only-inspect.json" >/dev/null
|
|
|
|
echo "Production read-only load safety drill passed."
|