033b3700c4
Adds the MQTT driver integration-test project: an eclipse-mosquitto fixture running auth AND TLS (allow_anonymous false on both listeners), a mosquitto_pub-based JSON publisher emitting retained messages, a cert/password generator script whose output is gitignored, and a live suite gated on MQTT_FIXTURE_ENDPOINT that skips clean offline. The fixture is never anonymous by design: an anonymous broker would let the driver's TLS/CA-pin and auth paths go untested, and those fail silently. The CA-pin leg carries its own falsifiability control (a foreign CA generated in-process must be rejected). Live gate on 10.100.0.35: 7/7 passed. It found a driver defect, reported not fixed here (src/ is out of this task's scope): MqttConnection.ConnectAsync RETURNS NORMALLY when Mosquitto rejects a CONNECT as not-authorized -- MQTTnet 5 does not throw on an unsuccessful CONNACK, so a wrong broker password yields DriverState.Healthy from InitializeAsync. The auth-negative test therefore asserts the invariant that holds either way (no session is ever established) and documents the finding. Claude-Session: https://claude.ai/code/session_01GASWkNEi68FSCtvr6rLoEW
78 lines
3.2 KiB
YAML
78 lines
3.2 KiB
YAML
# MQTT integration-test fixture — Eclipse Mosquitto (auth + TLS) + a JSON publisher.
|
|
#
|
|
# PREREQUISITE — run this first, in this directory:
|
|
#
|
|
# MQTT_FIXTURE_PASSWORD='<pick-one>' ./gen-fixture-material.sh
|
|
#
|
|
# It writes ./secrets/ (password file + CA + server certificate/key), which is
|
|
# gitignored and which both services below mount. Without it the broker will not
|
|
# start: there is no anonymous fallback, by design.
|
|
#
|
|
# Bring up (on the shared Docker host — see infra/README.md §1):
|
|
#
|
|
# ssh dohertj2@10.100.0.35 'cd /opt/otopcua-mqtt \
|
|
# && MQTT_FIXTURE_USERNAME=otopcua MQTT_FIXTURE_PASSWORD=<same> docker compose up -d'
|
|
#
|
|
# Endpoints: 10.100.0.35:8883 (TLS + auth) · 10.100.0.35:1883 (plaintext + auth, smoke)
|
|
#
|
|
# Unlike the Modbus / S7 fixtures there are no compose profiles: both services are
|
|
# always wanted together (a broker with nothing publishing into it tests nothing), and
|
|
# they bind different ports so nothing contends.
|
|
services:
|
|
mosquitto:
|
|
image: eclipse-mosquitto:2.0.22
|
|
container_name: otopcua-mosquitto
|
|
restart: unless-stopped
|
|
# Every lmxopcua fixture container carries this so the shared Docker host stays
|
|
# discoverable with `docker ps --filter label=project=lmxopcua`.
|
|
labels:
|
|
project: lmxopcua
|
|
ports:
|
|
- "1883:1883"
|
|
- "8883:8883"
|
|
volumes:
|
|
- ./mosquitto.conf:/mosquitto/config/mosquitto.conf:ro
|
|
- ./secrets:/mosquitto/secrets:ro
|
|
healthcheck:
|
|
# Authenticated round-trip against the broker's own $SYS tree ($$ escapes the
|
|
# compose variable syntax). Proves the password file loaded and the listener
|
|
# accepts a real session — a bare port check would go green on a broker that
|
|
# rejects every CONNECT.
|
|
test:
|
|
- CMD-SHELL
|
|
- >-
|
|
mosquitto_sub -h 127.0.0.1 -p 1883
|
|
-u "$$MQTT_FIXTURE_USERNAME" -P "$$MQTT_FIXTURE_PASSWORD"
|
|
-t '$$SYS/broker/uptime' -C 1 -W 3
|
|
interval: 5s
|
|
timeout: 8s
|
|
retries: 12
|
|
start_period: 5s
|
|
environment:
|
|
# Consumed only by the healthcheck above; the broker itself reads the hashed
|
|
# password file. Supplied by the operator's environment at `docker compose up` —
|
|
# never defaulted here, so a missing value fails loudly instead of silently
|
|
# provisioning a known-password broker.
|
|
MQTT_FIXTURE_USERNAME: ${MQTT_FIXTURE_USERNAME:?set MQTT_FIXTURE_USERNAME (must match gen-fixture-material.sh)}
|
|
MQTT_FIXTURE_PASSWORD: ${MQTT_FIXTURE_PASSWORD:?set MQTT_FIXTURE_PASSWORD (must match gen-fixture-material.sh)}
|
|
|
|
publisher:
|
|
image: eclipse-mosquitto:2.0.22
|
|
container_name: otopcua-mqtt-publisher
|
|
restart: unless-stopped
|
|
labels:
|
|
project: lmxopcua
|
|
depends_on:
|
|
mosquitto:
|
|
condition: service_healthy
|
|
volumes:
|
|
- ./publisher/publish.sh:/publish.sh:ro
|
|
environment:
|
|
BROKER_HOST: mosquitto
|
|
BROKER_PORT: "1883"
|
|
TOPIC_PREFIX: ${MQTT_FIXTURE_TOPIC_PREFIX:-otopcua/fixture}
|
|
PUBLISH_INTERVAL: ${MQTT_FIXTURE_PUBLISH_INTERVAL:-2}
|
|
MQTT_FIXTURE_USERNAME: ${MQTT_FIXTURE_USERNAME:?set MQTT_FIXTURE_USERNAME}
|
|
MQTT_FIXTURE_PASSWORD: ${MQTT_FIXTURE_PASSWORD:?set MQTT_FIXTURE_PASSWORD}
|
|
entrypoint: ["/bin/sh", "/publish.sh"]
|