Repository navigation
Expand file tree
/
Copy pathdocker-compose.test.yml
More file actions
134 lines (129 loc) · 4.27 KB
/
Copy pathdocker-compose.test.yml
File metadata and controls
134 lines (129 loc) · 4.27 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
# c2c sealed test environment — docker compose configuration.
#
# Network: isolated bridge (c2c-test-net) — containers cannot reach each
# other's broker ports. Host broker ports also unreachable from inside.
#
# Broker state: ephemeral anonymous volume (fresh on each `docker compose up`).
# Auth files: mounted at runtime (see .env.example for paths).
#
# Resource limits: memory cap, pids limit, no privileged.
# These limits are applied ENFORCEMENT-side (Docker daemon, not container).
# A runaway process inside the container hits the limit and is killed;
# it CANNOT affect the host.
#
# Usage:
# cp .env.example .env # fill in auth file paths
# docker compose -f docker-compose.test.yml up -d --build
# docker compose -f docker-compose.test.yml run --rm test-env pytest tests/
# docker compose -f docker-compose.test.yml down -v # wipe ephemeral state
services:
test-env:
build:
context: .
dockerfile: Dockerfile.test
container_name: c2c-test-env
# Ephemeral broker state — anonymous volume, fresh each run.
# Wipes on `docker compose down -v`.
volumes:
- c2c-test-broker:/var/lib/c2c
- c2c-test-home:/home/testagent
# Auth files (optional — comment out if not needed):
# - ${KIMI_AUTH:-/dev/null}:/home/testagent/.kimi:ro
# - ${KIMI_CONFIG:-/dev/null}:/home/testagent/.config/kimi:ro
networks:
- c2c-test-net
# Resource enforcement limits — runaway slice hits these, not host.
deploy:
resources:
limits:
memory: 512m
pids: 100
reservations:
memory: 128m
# Security: no privileged, no new privileges, cgroup namespace isolated.
security_opt:
- no-new-privileges:true
# Prevent container from loading other Docker sockets (anti-collateral).
# read_only: true # careful — may break some test scenarios
# tmpfs for /tmp to prevent disk-based attacks
tmpfs:
- /tmp:rw,noexec,nosuid,size=64m
environment:
# Broker root inside container
C2C_MCP_BROKER_ROOT: /var/lib/c2c
# Disable relay auto-discovery to stay sealed
C2C_RELAY_CONNECTOR_BACKEND: ""
# Docker cross-container liveness via file-based lease
C2C_IN_DOCKER: "1"
# Healthcheck — verifies binary accepts --help, NOT that relay is healthy.
# In sealed mode C2C_RELAY_CONNECTOR_BACKEND="" so relay is not used;
# this check only confirms the binary is present and runnable.
healthcheck:
test: ["CMD", "sh", "-c", "c2c relay serve --help > /dev/null 2>&1"]
interval: 5s
timeout: 3s
retries: 3
start_period: 5s
# Kimi integration test environment.
# Mounts kimi auth files from host at runtime.
test-kimi:
build:
context: .
dockerfile: Dockerfile.test
container_name: c2c-test-kimi
volumes:
- c2c-test-broker:/var/lib/c2c
- c2c-test-home:/home/testagent
networks:
- c2c-test-net
deploy:
resources:
limits:
memory: 768m
pids: 100
reservations:
memory: 256m
security_opt:
- no-new-privileges:true
tmpfs:
- /tmp:rw,noexec,nosuid,size=64m
environment:
C2C_MCP_BROKER_ROOT: /var/lib/c2c
C2C_RELAY_CONNECTOR_BACKEND: ""
C2C_IN_DOCKER: "1"
command: ["sh", "-c", "echo 'kimi test env ready; run tests manually' && sleep 3600"]
# Claude integration test environment.
# Claude binary may not be in PATH inside container — tests skip gracefully.
test-claude:
build:
context: .
dockerfile: Dockerfile.test
container_name: c2c-test-claude
volumes:
- c2c-test-broker:/var/lib/c2c
- c2c-test-home:/home/testagent
networks:
- c2c-test-net
deploy:
resources:
limits:
memory: 768m
pids: 100
reservations:
memory: 256m
security_opt:
- no-new-privileges:true
tmpfs:
- /tmp:rw,noexec,nosuid,size=64m
environment:
C2C_MCP_BROKER_ROOT: /var/lib/c2c
C2C_RELAY_CONNECTOR_BACKEND: ""
C2C_IN_DOCKER: "1"
command: ["sh", "-c", "echo 'claude test env ready; run tests manually' && sleep 3600"]
networks:
c2c-test-net:
driver: bridge
volumes:
# Ephemeral broker state — wiped on `docker compose down -v`.
c2c-test-broker:
c2c-test-home: