From 596909e2153e5949acf7ca5df17010ae2f0e0bb4 Mon Sep 17 00:00:00 2001 From: Nicklas Lundin Date: Thu, 1 Oct 2026 14:36:58 +0200 Subject: [PATCH] ci: verify Cloudflare memory preflight --- .github/workflows/ci.yml | 12 ++++++++++++ Dockerfile | 8 ++++++++ confidence-cloudflare-resolver/deployer/README.md | 2 +- .../deployer/memory-preflight-fixture.mjs | 15 +++++++++++++++ 4 files changed, 36 insertions(+), 1 deletion(-) create mode 100644 confidence-cloudflare-resolver/deployer/memory-preflight-fixture.mjs diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index dfcfbe13d..cb176e933 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -58,3 +58,15 @@ jobs: secret-files: | confidence_client_secret=/tmp/confidence_client_secret.txt confidence_client_encryption_key=/tmp/confidence_client_encryption_key.txt + + - name: Test Cloudflare deployer memory preflight + uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7 + with: + context: . + target: confidence-cloudflare-resolver.memory-preflight-test + platforms: linux/arm64 + push: false + cache-from: | + type=registry,ref=ghcr.io/${{ github.repository }}/cache:main + type=registry,ref=ghcr.io/${{ github.repository }}/cache:memory-preflight + cache-to: ${{ github.event_name == 'push' && format('type=registry,ref=ghcr.io/{0}/cache:memory-preflight,mode=max', github.repository) || '' }} diff --git a/Dockerfile b/Dockerfile index a87f05564..4167e3fa2 100644 --- a/Dockerfile +++ b/Dockerfile @@ -356,6 +356,14 @@ RUN chmod +x confidence-cloudflare-resolver/deployer/script.sh # Default command runs the deployer script CMD ["./confidence-cloudflare-resolver/deployer/script.sh"] +# Exercise the deployer's pinned workerd against a built Worker in CI. +FROM confidence-cloudflare-resolver.deployer AS confidence-cloudflare-resolver.memory-preflight-test +COPY data/resolver_state_current.pb /workspace/data/resolver_state_current.pb +WORKDIR /workspace/confidence-cloudflare-resolver +RUN node deployer/memory-preflight-fixture.mjs \ + && RUSTFLAGS='--cfg getrandom_backend="wasm_js"' worker-build --release \ + && MEMORY_PREFLIGHT_TEST_WORKER_DIR="$PWD" npm test --prefix deployer + # ============================================================================== # OpenFeature Provider (TypeScript) - Build and test # ============================================================================== diff --git a/confidence-cloudflare-resolver/deployer/README.md b/confidence-cloudflare-resolver/deployer/README.md index d2b107821..4fc97c5cc 100644 --- a/confidence-cloudflare-resolver/deployer/README.md +++ b/confidence-cloudflare-resolver/deployer/README.md @@ -226,7 +226,7 @@ For local validation (Node.js 22 or later), run `npm ci` in `deployer/`, build t node deployer/memory-preflight.mjs . ``` -Policy tests: `npm test --prefix deployer`. The probe does not upload or deploy the built artifact. Its temporary runtime directory is removed on completion. To also exercise initialization against a built Worker with a valid CDN envelope, set `MEMORY_PREFLIGHT_TEST_WORKER_DIR` to the component's absolute path when running the tests. The checked-in raw resolver-state fixture needs wrapping in a `ClientResolverState` envelope before it can be used for that integration test. +Policy tests: `npm test --prefix deployer`. The probe does not upload or deploy the built artifact. Its temporary runtime directory is removed on completion. A separate CI step builds the `confidence-cloudflare-resolver.memory-preflight-test` Docker target, which runs the built-Worker integration test in the deployer image using a test-only CDN envelope generated by `deployer/memory-preflight-fixture.mjs`. To run that test locally, generate the fixture in a disposable checkout, build with `worker-build --release`, and set `MEMORY_PREFLIGHT_TEST_WORKER_DIR` to the component's absolute path when running the tests. The Alpine deployer image includes a separate glibc loader and libraries solely for workerd; Node and Rust continue using musl. Dependencies are pinned in the npm lockfile. Builds using an authenticated npm mirror can pass their configuration with `docker build --secret id=npmrc,src="$HOME/.npmrc" ...`; the configuration is mounted only during dependency installation and is not stored in an image layer. diff --git a/confidence-cloudflare-resolver/deployer/memory-preflight-fixture.mjs b/confidence-cloudflare-resolver/deployer/memory-preflight-fixture.mjs new file mode 100644 index 000000000..b830023b0 --- /dev/null +++ b/confidence-cloudflare-resolver/deployer/memory-preflight-fixture.mjs @@ -0,0 +1,15 @@ +import { readFile, writeFile } from 'node:fs/promises'; + +// Wrap the checked-in raw ResolverState in the CDN ClientResolverState envelope. +const state = await readFile('../data/resolver_state_current.pb'); +const length = []; +let remaining = state.length; +while (remaining >= 128) { + length.push((remaining & 127) | 128); + remaining >>>= 7; +} +length.push(remaining); +await writeFile('../data/resolver_state_current.pb', Buffer.concat([ + Buffer.from([0x0a, ...length]), state, + Buffer.from([0x12, 0x0c]), Buffer.from('test-account'), +]));