044 provider runtime completion (pre-staged workstream): capacity/operator stores, provider ops/protocol/reconciler/dispatch revalidation, exploration sandbox runtime, alembic 0014-0016, live canary evidence (browser provider 6/6 against the live stand). 050 Phases 0-2: RBAC FastMCP server with a 45-tool explicit catalog, OAuth/DCR transport guards with bounded bodies, per-call provenance (McpToolInvocationRecord), durable ActionApprovalGate + CAS decide + leased/fenced poller, authoring workspace ops, bounded-response discipline, hidden-vs-gated matrices. Parity domains (T012-T014): gated git/deploy/migration/backup/llm tools with reviewed dispatch adapters in explicit poll chains; Superset reads/writes with a dedicated plugin:superset_sql risk class (terminal PROD denial via the canonical execution-policy criterion, hardened danger-SQL guard covering INTO/CALL/SET/REFRESH/file primitives/multi-statement); baseline 037 tools over the shared REST-surface services. Evidence (T016/T023/T028): REST-vs-MCP field parity on shared 037 fixtures; vertical E2E from tools/list through registry revision activation with real scenario:EDIT RBAC; sandbox-to-revision promotion E2E with unsafe-payload and caller-digest rejection; dispatcher soak (three poll cycles, exactly-once). Orthogonal QA+security audit hardening: enforced response_limit fail-closed envelope, poisoned-exploration fail-closed (EXPLORATION_TARGET_UNRESOLVED), sha256 exploration evidence digests, actor-UUID task ownership, is_active guard on baseline consume, 038 resolver description=None selector fix. Phase 3/4 decommission: HandoffSurface behind the MCP_DECOMMISSION flag, then unconditional removal — agent/ service tree, chat components/models/ stores/types, gradio proxies (vite + nginx), agent service in run.sh, docker-compose profiles, build.sh bundles; /agent renders the handoff only. Docs: AGENTS.md/INSTALL.md two-service rewrite; 036-047 drift amendments marked done; WORKSTATE checkpoints with all evidence. Suites: backend 11199 passed / 240 skipped / 1 xpassed; frontend 3454 passed (197 files), lint 0 errors, build OK; browser E2E login+handoff 6/6 twice on the isolated compose stack (no 7860); ruff/compileall clean. Misc: gitignore hardening (tmp/, tool model cache); E2E selector repairs (nav strict-mode, invalid-credentials passthrough detail).
59 lines
2.9 KiB
Markdown
59 lines
2.9 KiB
Markdown
## @{ Doc.Architecture.DocArchitecture [C:3] [TYPE Module]
|
||
# @BRIEF: Placeholder architecture document reserved for future normalized project architecture guidance.
|
||
# @RELATION: DEPENDS_ON -> [Std:Architecture]
|
||
|
||
Architecture guidance currently lives in `.ai/standards/architecture.md` and `.ai/MODULE_MAP.md`.
|
||
|
||
---
|
||
|
||
## Интеграционное тестирование с Testcontainers
|
||
|
||
Проект использует [Testcontainers](https://testcontainers-python.readthedocs.io/) для интеграционных тестов, требующих реальных сервисов (PostgreSQL, ClickHouse, Apache Superset).
|
||
|
||
### Принцип
|
||
|
||
Каждая тестовая сессия получает изолированные Docker-контейнеры на случайных портах. Контейнеры уничтожаются после завершения сессии. Это гарантирует отсутствие утечек состояния между запусками.
|
||
|
||
### Поддерживаемые сервисы
|
||
|
||
| Сервис | Образ | Scope | Конфигурация |
|
||
|--------|-------|-------|-------------|
|
||
| PostgreSQL | `postgres:16-alpine` | session | `backend/tests/integration/conftest.py` |
|
||
| ClickHouse | `clickhouse/clickhouse-server:24.3` | module | `test_translate_clickhouse.py` |
|
||
| Apache Superset | `apache/superset:4.1.2` | session | `backend/tests/integration/conftest.py` |
|
||
|
||
### Apache Superset Testcontainers
|
||
|
||
**Решение:** [ADR-0012 — Superset Testcontainers](./adr/ADR-0012-superset-testcontainers.md)
|
||
|
||
**Архитектура:**
|
||
```
|
||
Test Session
|
||
├── PostgresContainer (общий) # DB: superset_meta
|
||
├── Init Container (краткоживущий) # db upgrade → create-admin → init
|
||
└── Web Container (на всю сессию) # superset run -p 8088
|
||
```
|
||
|
||
**Запуск:**
|
||
```bash
|
||
cd backend && source .venv/bin/activate
|
||
python -m pytest tests/integration/test_superset_integration.py -v
|
||
# 8 passed in ~25s
|
||
```
|
||
|
||
**Доступные fixtures:**
|
||
- `superset_db_url` — PostgreSQL URI для метаданных Superset
|
||
- `superset_container` — запущенный веб-сервер Superset
|
||
- `superset_url` — `http://host:port`
|
||
- `superset_admin_headers` — авторизованная сессия (admin:admin123)
|
||
|
||
**Ограничения:**
|
||
- Для REST API используйте fixture `superset_jwt_headers`: JWT-авторизация
|
||
(`/api/v1/security/login`) настроена в тестовом контейнере; session cookie
|
||
предназначена для form-login сценариев.
|
||
- Метаданные Superset хранятся в отдельной PostgreSQL БД `superset_meta`.
|
||
Fixture устанавливает `psycopg2-binary`, передаёт URI через
|
||
`SUPERSET_CONFIG_PATH` и использует Docker bridge IP; подробности в ADR-0012.
|
||
|
||
## @} Doc.Architecture.DocArchitecture
|