test(mqtt): Mosquitto TLS+auth fixture + env-gated plain live suite
Adds the MQTT driver integration-test project: an eclipse-mosquitto fixture running auth AND TLS (allow_anonymous false on both listeners), a mosquitto_pub-based JSON publisher emitting retained messages, a cert/password generator script whose output is gitignored, and a live suite gated on MQTT_FIXTURE_ENDPOINT that skips clean offline. The fixture is never anonymous by design: an anonymous broker would let the driver's TLS/CA-pin and auth paths go untested, and those fail silently. The CA-pin leg carries its own falsifiability control (a foreign CA generated in-process must be rejected). Live gate on 10.100.0.35: 7/7 passed. It found a driver defect, reported not fixed here (src/ is out of this task's scope): MqttConnection.ConnectAsync RETURNS NORMALLY when Mosquitto rejects a CONNECT as not-authorized -- MQTTnet 5 does not throw on an unsuccessful CONNACK, so a wrong broker password yields DriverState.Healthy from InitializeAsync. The auth-negative test therefore asserts the invariant that holds either way (no session is ever established) and documents the finding. Claude-Session: https://claude.ai/code/session_01GASWkNEi68FSCtvr6rLoEW
This commit is contained in:
+77
@@ -0,0 +1,77 @@
|
||||
# MQTT integration-test fixture — Eclipse Mosquitto (auth + TLS) + a JSON publisher.
|
||||
#
|
||||
# PREREQUISITE — run this first, in this directory:
|
||||
#
|
||||
# MQTT_FIXTURE_PASSWORD='<pick-one>' ./gen-fixture-material.sh
|
||||
#
|
||||
# It writes ./secrets/ (password file + CA + server certificate/key), which is
|
||||
# gitignored and which both services below mount. Without it the broker will not
|
||||
# start: there is no anonymous fallback, by design.
|
||||
#
|
||||
# Bring up (on the shared Docker host — see infra/README.md §1):
|
||||
#
|
||||
# ssh dohertj2@10.100.0.35 'cd /opt/otopcua-mqtt \
|
||||
# && MQTT_FIXTURE_USERNAME=otopcua MQTT_FIXTURE_PASSWORD=<same> docker compose up -d'
|
||||
#
|
||||
# Endpoints: 10.100.0.35:8883 (TLS + auth) · 10.100.0.35:1883 (plaintext + auth, smoke)
|
||||
#
|
||||
# Unlike the Modbus / S7 fixtures there are no compose profiles: both services are
|
||||
# always wanted together (a broker with nothing publishing into it tests nothing), and
|
||||
# they bind different ports so nothing contends.
|
||||
services:
|
||||
mosquitto:
|
||||
image: eclipse-mosquitto:2.0.22
|
||||
container_name: otopcua-mosquitto
|
||||
restart: unless-stopped
|
||||
# Every lmxopcua fixture container carries this so the shared Docker host stays
|
||||
# discoverable with `docker ps --filter label=project=lmxopcua`.
|
||||
labels:
|
||||
project: lmxopcua
|
||||
ports:
|
||||
- "1883:1883"
|
||||
- "8883:8883"
|
||||
volumes:
|
||||
- ./mosquitto.conf:/mosquitto/config/mosquitto.conf:ro
|
||||
- ./secrets:/mosquitto/secrets:ro
|
||||
healthcheck:
|
||||
# Authenticated round-trip against the broker's own $SYS tree ($$ escapes the
|
||||
# compose variable syntax). Proves the password file loaded and the listener
|
||||
# accepts a real session — a bare port check would go green on a broker that
|
||||
# rejects every CONNECT.
|
||||
test:
|
||||
- CMD-SHELL
|
||||
- >-
|
||||
mosquitto_sub -h 127.0.0.1 -p 1883
|
||||
-u "$$MQTT_FIXTURE_USERNAME" -P "$$MQTT_FIXTURE_PASSWORD"
|
||||
-t '$$SYS/broker/uptime' -C 1 -W 3
|
||||
interval: 5s
|
||||
timeout: 8s
|
||||
retries: 12
|
||||
start_period: 5s
|
||||
environment:
|
||||
# Consumed only by the healthcheck above; the broker itself reads the hashed
|
||||
# password file. Supplied by the operator's environment at `docker compose up` —
|
||||
# never defaulted here, so a missing value fails loudly instead of silently
|
||||
# provisioning a known-password broker.
|
||||
MQTT_FIXTURE_USERNAME: ${MQTT_FIXTURE_USERNAME:?set MQTT_FIXTURE_USERNAME (must match gen-fixture-material.sh)}
|
||||
MQTT_FIXTURE_PASSWORD: ${MQTT_FIXTURE_PASSWORD:?set MQTT_FIXTURE_PASSWORD (must match gen-fixture-material.sh)}
|
||||
|
||||
publisher:
|
||||
image: eclipse-mosquitto:2.0.22
|
||||
container_name: otopcua-mqtt-publisher
|
||||
restart: unless-stopped
|
||||
labels:
|
||||
project: lmxopcua
|
||||
depends_on:
|
||||
mosquitto:
|
||||
condition: service_healthy
|
||||
volumes:
|
||||
- ./publisher/publish.sh:/publish.sh:ro
|
||||
environment:
|
||||
BROKER_HOST: mosquitto
|
||||
BROKER_PORT: "1883"
|
||||
TOPIC_PREFIX: ${MQTT_FIXTURE_TOPIC_PREFIX:-otopcua/fixture}
|
||||
PUBLISH_INTERVAL: ${MQTT_FIXTURE_PUBLISH_INTERVAL:-2}
|
||||
MQTT_FIXTURE_USERNAME: ${MQTT_FIXTURE_USERNAME:?set MQTT_FIXTURE_USERNAME}
|
||||
MQTT_FIXTURE_PASSWORD: ${MQTT_FIXTURE_PASSWORD:?set MQTT_FIXTURE_PASSWORD}
|
||||
entrypoint: ["/bin/sh", "/publish.sh"]
|
||||
Reference in New Issue
Block a user