fix(14-02): parity:upstream writes its sidecar on interrupt or SIGTERM

- the command context had no signal handling, so stopping the proxy
  killed it before Flush and no sidecar was ever written
- a background proxy (SIGINT ignored by the shell) now stops on SIGTERM
This commit is contained in:
Jakub Zych
2026-10-03 20:06:42 +02:00
parent 43b869d613
commit 0a7635b12a
3 changed files with 10 additions and 2 deletions

View File

@@ -4,8 +4,10 @@ import (
"context"
"fmt"
"os"
"os/signal"
"path/filepath"
"strings"
"syscall"
"time"
"git.golem15.com/golem15/summercms/modules/bonfire"
@@ -140,6 +142,12 @@ func runParityUpstream(ctx context.Context, in bonfire.Input, out bonfire.Output
out.Info(fmt.Sprintf("upstream proxy listening on %s", listen))
out.Info(fmt.Sprintf("parity CA certificate: %s", certPath))
out.Info(fmt.Sprintf("point the reference backend at it: HTTPS_PROXY=http://%s, curl.cainfo and openssl.cafile=%s", listen, certPath))
// The sidecar is written only after the proxy stops, so an interrupt or
// SIGTERM must end serving gracefully instead of killing the process. A
// shell starts background jobs with SIGINT ignored; NotifyContext
// re-enables it.
ctx, stop := signal.NotifyContext(ctx, os.Interrupt, syscall.SIGTERM)
defer stop()
if err := proxy.ListenAndServe(ctx); err != nil {
return err
}

View File

@@ -161,7 +161,7 @@ summer parity:upstream --ca-dir /tmp/parity/ca --vars /tmp/parity/vars.yaml \
--out testdata/parity/routes/POST_items_jwt__ok.upstream.yaml
```
It prints the path of its CA certificate. Start the reference backend with `HTTPS_PROXY=http://127.0.0.1:8425` and that certificate as its curl and OpenSSL CA file, run the case, then interrupt the command to write the sidecar. In the default `script` mode each request is answered from the script file, a list of `responses` entries (`tide.UpstreamScriptResponse`: `method`, `host`, `path` and the `response` to send), so recording needs no real vendor and no real credential; a request no entry matches is answered with status 599 and the sidecar is not written. `--mode forward` sends each request once to the real vendor through a guarded client instead. Use it only by hand, never in CI.
It prints the path of its CA certificate. Start the reference backend with `HTTPS_PROXY=http://127.0.0.1:8425` and that certificate as its curl and OpenSSL CA file, run the case, then interrupt the command (Ctrl-C, or SIGTERM when it runs in the background) to write the sidecar. In the default `script` mode each request is answered from the script file, a list of `responses` entries (`tide.UpstreamScriptResponse`: `method`, `host`, `path` and the `response` to send), so recording needs no real vendor and no real credential; a request no entry matches is answered with status 599 and the sidecar is not written. `--mode forward` sends each request once to the real vendor through a guarded client instead. Use it only by hand, never in CI.
The rules match the other recorders: the proxy listens on loopback only, the CA key is kept with mode 0600 in `--ca-dir` outside the fixtures tree, and every value from the variables file is replaced by its `{{name}}` placeholder. `tide.WriteUpstream` refuses to write an Authorization or X-Api-Key header that no variable masks.

View File

@@ -181,7 +181,7 @@ summer parity:upstream \
--out testdata/parity/routes/POST_items_jwt__ok.upstream.yaml
```
`--listen` defaults to `127.0.0.1:8425` and `--mode` to `script`. The command prints the CA certificate path; run the reference backend with `HTTPS_PROXY` pointing at the proxy and that certificate as its CA file, then interrupt the command to write the sidecar. Security rules: the proxy listens on loopback only; the CA key stays mode 0600 in `--ca-dir`, outside the fixtures tree; the vars file is outside the sidecar's directory and every value in it is masked; an unmasked Authorization or X-Api-Key value refuses the write; `--mode forward` reaches the real vendor and is for hand recording only, never CI.
`--listen` defaults to `127.0.0.1:8425` and `--mode` to `script`. The command prints the CA certificate path; run the reference backend with `HTTPS_PROXY` pointing at the proxy and that certificate as its CA file, then interrupt the command (Ctrl-C, or SIGTERM when it runs in the background) to write the sidecar. Security rules: the proxy listens on loopback only; the CA key stays mode 0600 in `--ca-dir`, outside the fixtures tree; the vars file is outside the sidecar's directory and every value in it is masked; an unmasked Authorization or X-Api-Key value refuses the write; `--mode forward` reaches the real vendor and is for hand recording only, never CI.
## Dependencies