diff --git a/src/Server/ZB.MOM.WW.OtOpcUa.Host/Configuration/ConfigServeAuthInterceptor.cs b/src/Server/ZB.MOM.WW.OtOpcUa.Host/Configuration/ConfigServeAuthInterceptor.cs new file mode 100644 index 00000000..91aad7c7 --- /dev/null +++ b/src/Server/ZB.MOM.WW.OtOpcUa.Host/Configuration/ConfigServeAuthInterceptor.cs @@ -0,0 +1,157 @@ +using System.Security.Cryptography; +using System.Text; +using Grpc.Core; +using Grpc.Core.Interceptors; +using Microsoft.Extensions.Logging; +using Microsoft.Extensions.Options; +using ZB.MOM.WW.OtOpcUa.Cluster; + +namespace ZB.MOM.WW.OtOpcUa.Host.Configuration; + +/// +/// Gates the central config-serve artifact endpoint (per-cluster mesh Phase 3). The +/// DeploymentArtifactService streams a driver node the exact configuration it will boot +/// on; anything able to reach central's serve port could otherwise pull the whole deployed config +/// out-of-band. This interceptor is the ONLY inbound auth on that endpoint. +/// +/// +/// +/// Scoped by method path. Only calls under +/// /deployment_artifact.v1.DeploymentArtifactService/ are gated; every other method on +/// the shared gRPC pipeline (notably the LocalDb sync service) passes through untouched, so +/// this can share one AddGrpc registration with . +/// +/// +/// Fail-closed. With no ConfigServe:ApiKey configured, NO fetch is accepted, +/// authenticated or not. Treating "no key" as "no auth required" would expose the deployed +/// configuration on exactly the default shape most nodes ship with. The node dialing in must +/// present the same ConfigSource:ApiKey (the shared node key), so a key typo stops +/// config delivery outright rather than degrading to unauthenticated. +/// +/// +/// Comparison is over UTF-8 bytes, so a +/// wrong key cannot be recovered byte-by-byte from response timing. Length differences are +/// unavoidably observable and are not sensitive. +/// +/// +public sealed class ConfigServeAuthInterceptor : Interceptor +{ + private const string ServicePrefix = "/deployment_artifact.v1.DeploymentArtifactService/"; + private const string AuthorizationHeader = "authorization"; + private const string BearerPrefix = "Bearer "; + + private readonly IOptions _options; + private readonly ILogger _logger; + + /// Creates the interceptor. + /// Config-serve options; ApiKey is the expected bearer token. + /// Logger for denial diagnostics. + public ConfigServeAuthInterceptor( + IOptions options, + ILogger logger) + { + ArgumentNullException.ThrowIfNull(options); + ArgumentNullException.ThrowIfNull(logger); + + _options = options; + _logger = logger; + } + + /// + public override Task UnaryServerHandler( + TRequest request, + ServerCallContext context, + UnaryServerMethod continuation) + { + Authorize(context); + return continuation(request, context); + } + + /// + public override Task DuplexStreamingServerHandler( + IAsyncStreamReader requestStream, + IServerStreamWriter responseStream, + ServerCallContext context, + DuplexStreamingServerMethod continuation) + { + Authorize(context); + return continuation(requestStream, responseStream, context); + } + + /// + public override Task ClientStreamingServerHandler( + IAsyncStreamReader requestStream, + ServerCallContext context, + ClientStreamingServerMethod continuation) + { + Authorize(context); + return continuation(requestStream, context); + } + + /// + public override Task ServerStreamingServerHandler( + TRequest request, + IServerStreamWriter responseStream, + ServerCallContext context, + ServerStreamingServerMethod continuation) + { + Authorize(context); + return continuation(request, responseStream, context); + } + + /// + /// Throws with if this is + /// a config-serve call that does not carry the configured bearer token. Non-serve calls return + /// immediately. + /// + private void Authorize(ServerCallContext context) + { + if (!context.Method.StartsWith(ServicePrefix, StringComparison.Ordinal)) + return; + + var expected = _options.Value.ApiKey; + if (string.IsNullOrEmpty(expected)) + { + _logger.LogWarning( + "Rejected a config-serve call to {Method}: no ConfigServe:ApiKey is configured, so the " + + "artifact endpoint is closed. Configure the shared node key on central and every node.", + context.Method); + throw new RpcException(new Status( + StatusCode.Unauthenticated, + "Config-serve is not accepting connections: no API key is configured on this node.")); + } + + var presented = ExtractBearerToken(context.RequestHeaders); + if (presented is null || !FixedTimeEquals(presented, expected)) + { + _logger.LogWarning( + "Rejected a config-serve call to {Method}: {Reason}.", + context.Method, + presented is null ? "no bearer token presented" : "bearer token did not match"); + throw new RpcException(new Status( + StatusCode.Unauthenticated, + "Config-serve authentication failed.")); + } + } + + private static string? ExtractBearerToken(Metadata headers) + { + // gRPC lowercases header keys on the wire; compare case-insensitively anyway so a hand-built + // Metadata in a test behaves the same as a real request. + foreach (var entry in headers) + { + if (!string.Equals(entry.Key, AuthorizationHeader, StringComparison.OrdinalIgnoreCase)) + continue; + + var value = entry.Value; + if (value is not null && value.StartsWith(BearerPrefix, StringComparison.OrdinalIgnoreCase)) + return value[BearerPrefix.Length..]; + } + + return null; + } + + private static bool FixedTimeEquals(string presented, string expected) + => CryptographicOperations.FixedTimeEquals( + Encoding.UTF8.GetBytes(presented), Encoding.UTF8.GetBytes(expected)); +} diff --git a/src/Server/ZB.MOM.WW.OtOpcUa.Host/Program.cs b/src/Server/ZB.MOM.WW.OtOpcUa.Host/Program.cs index ef193f04..5dee7c3b 100644 --- a/src/Server/ZB.MOM.WW.OtOpcUa.Host/Program.cs +++ b/src/Server/ZB.MOM.WW.OtOpcUa.Host/Program.cs @@ -8,6 +8,7 @@ using Serilog.Events; using ZB.MOM.WW.OtOpcUa.AdminUI; using ZB.MOM.WW.OtOpcUa.AdminUI.Clients; using ZB.MOM.WW.OtOpcUa.AdminUI.Components; +using ZB.MOM.WW.OtOpcUa.AdminUI.Grpc; using ZB.MOM.WW.OtOpcUa.AdminUI.Hubs; using ZB.MOM.WW.OtOpcUa.AdminUI.ScriptAnalysis; using ZB.MOM.WW.OtOpcUa.Cluster; @@ -185,11 +186,9 @@ if (hasDriver) // (initiator) / LocalDb:SyncListenPort (listener) are set. See LocalDbRegistration. builder.Services.AddOtOpcUaLocalDb(builder.Configuration); - // gRPC server plumbing for the passive sync endpoint mapped below. Registered only under - // hasDriver so admin-only nodes expose no sync surface at all. The interceptor is the ONLY - // inbound auth on that endpoint — the replication library's LocalDbSyncService verifies - // nothing — and it fail-closes when no ApiKey is configured. - builder.Services.AddGrpc(o => o.Interceptors.Add()); + // gRPC server plumbing (AddGrpc + the two path-scoped auth interceptors) is registered once, + // below, for hasDriver || hasAdmin — the LocalDb passive sync endpoint (driver) and the + // ConfigServe artifact endpoint (admin) share one pipeline. // Config-gated server-side HistoryRead backend. When the ServerHistorian section is enabled this // overrides the NullHistorianDataSource default from AddOtOpcUaRuntime (last registration wins) with @@ -389,23 +388,46 @@ builder.Services.AddOtOpcUaSecrets(builder.Configuration); builder.Services.AddOtOpcUaHealth(); builder.Services.AddOtOpcUaObservability(builder.Configuration); +// gRPC server plumbing shared by two endpoints: the LocalDb passive sync endpoint (driver-role, +// mapped below on hasDriver && syncListenPort > 0) and the ConfigServe artifact endpoint +// (admin-role, mapped on hasAdmin && configServeGrpcPort > 0). Each interceptor is scoped strictly +// to its own service path, so both can share one pipeline and each is a harmless pass-through when +// its service is unmapped. Both fail-closed with no ApiKey configured — the interceptor is the ONLY +// inbound auth on either endpoint (the libraries verify nothing). Registered whenever either role is +// present so an admin-only node still serves config and a driver-only node still gates sync. +if (hasDriver || hasAdmin) +{ + builder.Services.AddGrpc(o => + { + if (hasDriver) + o.Interceptors.Add(); + if (hasAdmin) + o.Interceptors.Add(); + }); +} + // --------------------------------------------------------------------------------------------- -// LocalDb sync listener (default-OFF). +// Dedicated h2c listeners (both default-OFF): the LocalDb sync endpoint (driver) and the +// ConfigServe artifact endpoint (admin, per-cluster mesh Phase 3). // // DANGER: any explicit Kestrel Listen* call makes Kestrel IGNORE ASPNETCORE_URLS/urls ENTIRELY // (it logs "Overriding address(es)"). The host has no ConfigureKestrel today and binds solely via // that configuration, so adding a listener naively would silently unbind the AdminUI + deploy API // behind Traefik. Everything the host was already asked to serve is therefore re-bound explicitly -// in the same block. +// in the same block — and, critically, EXACTLY ONCE: a fused admin+driver node can have BOTH +// dedicated ports set, and re-applying the existing surface per-port would double-bind it and throw +// "address already in use". So the existing surface is computed and applied once, then whichever of +// the two dedicated ports are configured are added on top. // -// The listener is HTTP/2-ONLY on purpose: the sync client speaks prior-knowledge h2c, which a -// cleartext Http1AndHttp2 endpoint cannot negotiate (there is no ALPN without TLS). Hence a -// dedicated port rather than multiplexing onto the main one. +// Each listener is HTTP/2-ONLY on purpose: both clients speak prior-knowledge h2c, which a cleartext +// Http1AndHttp2 endpoint cannot negotiate (there is no ALPN without TLS). Hence dedicated ports +// rather than multiplexing onto the main one. // -// When LocalDb:SyncListenPort is 0 (the default) none of this runs and URL binding is untouched. +// When both ports are 0 (the default) none of this runs and URL binding is untouched. // --------------------------------------------------------------------------------------------- -var syncListenPort = LocalDbRegistration.SyncListenPort(builder.Configuration); -if (hasDriver && syncListenPort > 0) +var syncListenPort = hasDriver ? LocalDbRegistration.SyncListenPort(builder.Configuration) : 0; +var configServeGrpcPort = hasAdmin ? builder.Configuration.GetValue("ConfigServe:GrpcListenPort") : 0; +if (syncListenPort > 0 || configServeGrpcPort > 0) { // Mirror Kestrel's own source precedence: URLS wins; else the HTTP_PORTS/HTTPS_PORTS bare-port // vars; else Kestrel's localhost:5000 default. Missing the HTTP_PORTS leg is not academic — the @@ -428,8 +450,8 @@ if (hasDriver && syncListenPort > 0) ]; if (existingBindings.Count > 0) Log.Information( - "LocalDb sync listener enabled; re-binding the HTTP_PORTS surface ({HttpPorts}/{HttpsPorts}) " + - "alongside the sync port.", httpPorts, httpsPorts); + "Dedicated h2c listener(s) enabled; re-binding the HTTP_PORTS surface ({HttpPorts}/{HttpsPorts}) " + + "alongside the dedicated port(s).", httpPorts, httpsPorts); } // A driver-only Windows-service node gets NO URLS and NO *_PORTS (Install-Services.ps1 sets URLS @@ -440,38 +462,48 @@ if (hasDriver && syncListenPort > 0) { existingBindings = [new KestrelHttpBinding("localhost", 5000, IsSecure: false)]; Log.Information( - "LocalDb sync listener enabled with no URLs configured; re-binding Kestrel's default " + - "http://localhost:5000 alongside the sync port."); + "Dedicated h2c listener(s) enabled with no URLs configured; re-binding Kestrel's default " + + "http://localhost:5000 alongside the dedicated port(s)."); } // Re-binding an https endpoint would need its certificate configuration replayed too, which // this host does not model (TLS is terminated at Traefik). Rather than silently serve it // without TLS — or drop it — refuse to take over Kestrel at all and leave the existing // surface exactly as it was. The operator gets a loud, actionable error instead of an - // AdminUI that stopped answering. + // AdminUI that stopped answering. Disables BOTH dedicated ports (either would force the same + // Kestrel takeover). if (existingBindings.Any(b => b.IsSecure)) { Log.Error( - "LocalDb:SyncListenPort is set to {Port} but this host serves HTTPS endpoint(s) ({Urls}). " + - "Binding the sync listener requires re-binding every existing endpoint explicitly, and the " + - "HTTPS certificate configuration cannot be replayed safely. The sync listener is DISABLED; " + - "terminate TLS upstream (as the docker-dev rig does) or leave replication off on this node.", - syncListenPort, configuredUrls); + "A dedicated h2c listener is requested (LocalDb:SyncListenPort={SyncPort}, " + + "ConfigServe:GrpcListenPort={ConfigServePort}) but this host serves HTTPS endpoint(s) ({Urls}). " + + "Binding a dedicated listener requires re-binding every existing endpoint explicitly, and the " + + "HTTPS certificate configuration cannot be replayed safely. BOTH dedicated listeners are DISABLED; " + + "terminate TLS upstream (as the docker-dev rig does) or leave these features off on this node.", + syncListenPort, configServeGrpcPort, configuredUrls); syncListenPort = 0; + configServeGrpcPort = 0; } else { + // Capture locals so the ConfigureKestrel closure does not observe later reassignment. + var syncPortToBind = syncListenPort; + var configServePortToBind = configServeGrpcPort; builder.WebHost.ConfigureKestrel(kestrel => { foreach (var binding in existingBindings) binding.Apply(kestrel); - kestrel.ListenAnyIP(syncListenPort, o => o.Protocols = HttpProtocols.Http2); + if (syncPortToBind > 0) + kestrel.ListenAnyIP(syncPortToBind, o => o.Protocols = HttpProtocols.Http2); + if (configServePortToBind > 0) + kestrel.ListenAnyIP(configServePortToBind, o => o.Protocols = HttpProtocols.Http2); }); Log.Information( - "LocalDb sync listener bound on :{SyncPort} (h2c); re-bound existing endpoint(s) {Urls}.", - syncListenPort, configuredUrls ?? "http://localhost:5000 (Kestrel default)"); + "Dedicated h2c listener(s) bound (sync=:{SyncPort}, config-serve=:{ConfigServePort}); " + + "re-bound existing endpoint(s) {Urls}.", + syncListenPort, configServeGrpcPort, configuredUrls ?? "http://localhost:5000 (Kestrel default)"); } } @@ -514,6 +546,14 @@ if (hasDriver && syncListenPort > 0) app.MapZbLocalDbSync(); } +// Central config-serve artifact endpoint (per-cluster mesh Phase 3). Mapped only on admin-role +// nodes (which hold the central SQL connection) and only when a dedicated h2c port is bound. The +// ConfigServeAuthInterceptor is the ONLY inbound auth and fail-closes with no ConfigServe:ApiKey. +if (hasAdmin && configServeGrpcPort > 0) +{ + app.MapGrpcService(); +} + app.MapOtOpcUaHealth(); app.MapOtOpcUaMetrics(); diff --git a/tests/Server/ZB.MOM.WW.OtOpcUa.Host.IntegrationTests/ConfigServeAuthInterceptorTests.cs b/tests/Server/ZB.MOM.WW.OtOpcUa.Host.IntegrationTests/ConfigServeAuthInterceptorTests.cs new file mode 100644 index 00000000..333772d4 --- /dev/null +++ b/tests/Server/ZB.MOM.WW.OtOpcUa.Host.IntegrationTests/ConfigServeAuthInterceptorTests.cs @@ -0,0 +1,152 @@ +using Grpc.Core; +using Microsoft.Extensions.Logging.Abstractions; +using Microsoft.Extensions.Options; +using Shouldly; +using Xunit; +using ZB.MOM.WW.OtOpcUa.Cluster; +using ZB.MOM.WW.OtOpcUa.Host.Configuration; + +namespace ZB.MOM.WW.OtOpcUa.Host.IntegrationTests; + +/// +/// Per-cluster mesh Phase 3 (Task 3) — the config-serve artifact endpoint's inbound gate. +/// +/// +/// The DeploymentArtifactService streams a driver node the exact configuration it will +/// boot on. Anything able to reach central's serve port could otherwise pull the whole deployed +/// config, so the endpoint is gated by a shared bearer key, fail-closed, constant-time — the +/// same contract as , scoped to a different service path. +/// +public sealed class ConfigServeAuthInterceptorTests +{ + private const string FetchMethod = "/deployment_artifact.v1.DeploymentArtifactService/Fetch"; + private const string OtherMethod = "/localdb_sync.v1.LocalDbSync/Sync"; + + private static ConfigServeAuthInterceptor CreateInterceptor(string? apiKey) + => new( + Options.Create(new ConfigServeOptions { ApiKey = apiKey ?? string.Empty }), + NullLogger.Instance); + + private static ServerCallContext CreateContext(string method, string? authorizationHeader) + { + var headers = new Metadata(); + if (authorizationHeader is not null) + headers.Add("authorization", authorizationHeader); + + return new FakeServerCallContext(method, headers); + } + + /// Invokes the interceptor's server-streaming path (how Fetch actually runs). + private static Task Invoke(ConfigServeAuthInterceptor interceptor, ServerCallContext context) + => interceptor.ServerStreamingServerHandler( + "request", responseStream: null!, context, (_, _, _) => Task.CompletedTask); + + [Fact] + public async Task NonServeMethod_PassesThrough_EvenWithNoKeyConfigured() + { + // The interceptor shares the AddGrpc pipeline with the LocalDb sync interceptor, so it sees + // every call. It must be scoped strictly to the artifact service — a sync call is not its + // business. + var interceptor = CreateInterceptor(apiKey: null); + var context = CreateContext(OtherMethod, authorizationHeader: null); + + await Invoke(interceptor, context); // no throw + } + + [Fact] + public async Task FetchMethod_WithNoKeyConfigured_IsDenied_EvenWithABearerToken() + { + // Fail-closed. "No key configured" is the DEFAULT — treating it as "no auth required" would + // expose the deployed config on exactly the shape most nodes ship with. A token must not help. + var interceptor = CreateInterceptor(apiKey: null); + var context = CreateContext(FetchMethod, "Bearer anything-at-all"); + + var ex = await Should.ThrowAsync(() => Invoke(interceptor, context)); + ex.StatusCode.ShouldBe(StatusCode.Unauthenticated); + } + + [Fact] + public async Task FetchMethod_WithNoBearerToken_IsDenied() + { + var interceptor = CreateInterceptor("the-shared-key"); + var context = CreateContext(FetchMethod, authorizationHeader: null); + + var ex = await Should.ThrowAsync(() => Invoke(interceptor, context)); + ex.StatusCode.ShouldBe(StatusCode.Unauthenticated); + } + + [Fact] + public async Task FetchMethod_WithWrongBearerToken_IsDenied() + { + var interceptor = CreateInterceptor("the-shared-key"); + var context = CreateContext(FetchMethod, "Bearer the-wrong-key"); + + var ex = await Should.ThrowAsync(() => Invoke(interceptor, context)); + ex.StatusCode.ShouldBe(StatusCode.Unauthenticated); + } + + [Fact] + public async Task FetchMethod_WithCorrectBearerToken_PassesThrough() + { + var interceptor = CreateInterceptor("the-shared-key"); + var context = CreateContext(FetchMethod, "Bearer the-shared-key"); + + await Invoke(interceptor, context); // no throw + } + + [Fact] + public async Task FetchMethod_TokenComparison_IsNotAPrefixMatch() + { + // A prefix/StartsWith comparison would accept a truncated key and make the secret + // recoverable one character at a time. + var interceptor = CreateInterceptor("the-shared-key"); + var context = CreateContext(FetchMethod, "Bearer the-shared-ke"); + + var ex = await Should.ThrowAsync(() => Invoke(interceptor, context)); + ex.StatusCode.ShouldBe(StatusCode.Unauthenticated); + } + + [Fact] + public async Task UnaryPath_IsAlsoGated() + { + // Fetch is server-streaming today, but gating only that path would leave any future unary + // method on the same service open. Gate every handler shape. + var interceptor = CreateInterceptor("the-shared-key"); + var context = CreateContext(FetchMethod, "Bearer the-wrong-key"); + + var ex = await Should.ThrowAsync(() => + interceptor.UnaryServerHandler( + "request", context, (_, _) => Task.FromResult("ok"))); + + ex.StatusCode.ShouldBe(StatusCode.Unauthenticated); + } + + /// + /// Minimal carrying just a method name and request headers — + /// the only two things the interceptor reads. Hand-rolled because + /// Grpc.Core.Testing.TestServerCallContext ships only in the retired native package. + /// + private sealed class FakeServerCallContext(string method, Metadata requestHeaders) + : ServerCallContext + { + protected override string MethodCore => method; + protected override string HostCore => "localhost"; + protected override string PeerCore => "ipv4:127.0.0.1:12345"; + protected override DateTime DeadlineCore => DateTime.UtcNow.AddMinutes(1); + protected override Metadata RequestHeadersCore => requestHeaders; + protected override CancellationToken CancellationTokenCore => CancellationToken.None; + protected override Metadata ResponseTrailersCore { get; } = []; + protected override Status StatusCore { get; set; } + protected override WriteOptions? WriteOptionsCore { get; set; } + + protected override AuthContext AuthContextCore { get; } = + new(null, new Dictionary>()); + + protected override ContextPropagationToken CreatePropagationTokenCore( + ContextPropagationOptions? options) + => throw new NotSupportedException(); + + protected override Task WriteResponseHeadersAsyncCore(Metadata responseHeaders) + => Task.CompletedTask; + } +} diff --git a/tests/Server/ZB.MOM.WW.OtOpcUa.Host.IntegrationTests/ConfigServeListenerTests.cs b/tests/Server/ZB.MOM.WW.OtOpcUa.Host.IntegrationTests/ConfigServeListenerTests.cs new file mode 100644 index 00000000..0349f328 --- /dev/null +++ b/tests/Server/ZB.MOM.WW.OtOpcUa.Host.IntegrationTests/ConfigServeListenerTests.cs @@ -0,0 +1,99 @@ +using System.Net; +using Microsoft.AspNetCore.Builder; +using Microsoft.AspNetCore.Server.Kestrel.Core; +using Microsoft.Extensions.DependencyInjection; +using Microsoft.Extensions.Hosting; +using Shouldly; +using Xunit; +using ZB.MOM.WW.OtOpcUa.Host.Configuration; + +namespace ZB.MOM.WW.OtOpcUa.Host.IntegrationTests; + +/// +/// Per-cluster mesh Phase 3 (Task 3) — the coexistence of the ConfigServe artifact h2c listener +/// with the LocalDb-sync h2c listener on a fused admin+driver node. +/// +/// +/// +/// Why this is the load-bearing test. A fused central node can carry BOTH dedicated +/// h2c ports (LocalDb sync + ConfigServe). Any explicit Kestrel Listen* makes Kestrel +/// discard ASPNETCORE_URLS wholesale, so the existing HTTP surface must be re-bound +/// exactly ONCE alongside the two dedicated ports. Re-binding it twice (one block per h2c +/// port) throws "address already in use"; re-binding it zero times silently unbinds the +/// AdminUI behind Traefik. This test pins that all three answer simultaneously. +/// +/// +/// Like , this drives a minimal WebApplication +/// shaped exactly like Program.cs's merged listener block rather than booting the real +/// host (which needs SQL, an Akka mesh and LDAP). What is under test is the Kestrel binding +/// contract, fully reproduced here; the real end-to-end fetch is the Task 8 boundary test. +/// +/// +public sealed class ConfigServeListenerTests +{ + [Fact] + public async Task BothDedicatedH2cPorts_AndTheHttpSurface_AnswerSimultaneously() + { + var httpPort = GetFreePort(); + var syncPort = GetFreePort(); + var configServePort = GetFreePort(); + + var builder = WebApplication.CreateBuilder(); + builder.Environment.ApplicationName = typeof(ConfigServeListenerTests).Assembly.GetName().Name!; + builder.Services.AddGrpc(); + + // Exactly the shape Program.cs's merged block applies: compute the existing surface ONCE, + // apply it ONCE, then add each configured dedicated h2c port. + var existingBindings = KestrelHttpBinding.Parse($"http://localhost:{httpPort}"); + builder.WebHost.ConfigureKestrel(kestrel => + { + foreach (var binding in existingBindings) + binding.Apply(kestrel); + + kestrel.ListenAnyIP(syncPort, o => o.Protocols = HttpProtocols.Http2); + kestrel.ListenAnyIP(configServePort, o => o.Protocols = HttpProtocols.Http2); + }); + + await using var app = builder.Build(); + app.MapGet("/healthz", () => "ok"); + await app.StartAsync(TestContext.Current.CancellationToken); + + try + { + // The re-bound HTTP/1.1 surface still answers (the AdminUI/Traefik guarantee). + using var http1 = new HttpClient(); + (await http1.GetStringAsync( + $"http://localhost:{httpPort}/healthz", TestContext.Current.CancellationToken)) + .ShouldBe("ok"); + + // Both dedicated ports negotiate prior-knowledge h2c. A 404 is a fine result — it proves + // the HTTP/2 connection was established and routed, which is all that is in question. + using var http2 = new HttpClient + { + DefaultRequestVersion = HttpVersion.Version20, + DefaultVersionPolicy = HttpVersionPolicy.RequestVersionExact, + }; + + using var syncResponse = await http2.GetAsync( + $"http://localhost:{syncPort}/", TestContext.Current.CancellationToken); + syncResponse.Version.ShouldBe(HttpVersion.Version20); + + using var configServeResponse = await http2.GetAsync( + $"http://localhost:{configServePort}/", TestContext.Current.CancellationToken); + configServeResponse.Version.ShouldBe(HttpVersion.Version20); + } + finally + { + await app.StopAsync(TestContext.Current.CancellationToken); + } + } + + private static int GetFreePort() + { + using var listener = new System.Net.Sockets.TcpListener(IPAddress.Loopback, 0); + listener.Start(); + var port = ((IPEndPoint)listener.LocalEndpoint).Port; + listener.Stop(); + return port; + } +}