mirror of
https://github.com/kellymichels/zscripts-token-savers
synced 2026-10-07 07:18:18 +00:00
Part of #26. The toolkit had no automated tests at all - including for the functions that decide what goes into a deploy zip, which is where a dev .env reached production (#23). Phase 1 - the seam. Get-ZConfig read a hardcoded $PSScriptRoot\zconfig.json, so nothing config-dependent could be tested without touching the real config. Adds Get-ZConfigPath honoring $env:ZCONFIG (the bash port has always had this, so it also closes a parity gap) and Reset-ZConfigCache to drop the memoised config between fixtures. Deliberately did NOT convert the exit 1 paths to throw: that changes observed CLI output, and the pure functions don't need it. Phase 2 - 61 tests over the functions with no side effects: Get-ArchiveExcludes (common/python/vite/nextjs lists, deploy.exclude merging, dedupe, array shape), Get-ZConfig / Get-ZConfigPath / Get-ZProjectKeys / Get-ZProject (dash tolerance, underscore-key filtering, memoisation), Get-ZEdgeProject, Get-RemoteComposeDir, Get-Ec2Target / Get-Ec2Home, Get-LabelFromBuildJsonObj, Read-JsonBuildVersion. The suite is verified by mutation testing rather than assumed useful - six deliberate regressions were each introduced and confirmed to turn it red, including reintroducing the exact #23 bug and its inverse (backups silently dropping .env/uploads, which would produce restore points that cannot restore). Runs off a fixture config injected via ZCONFIG, so it never reads a real zconfig.json and passes on a machine that has never been configured.
5.6 KiB
5.6 KiB
Changelog
Notable changes to the Evomedia.net Token Savers.
Unreleased
Fixed
zdeployno longer deletes operator-managed files on deploy (#2) — the project-directory replacement preserved only./.env, silently destroying every other server-side file (.env.db, staged signing keys, certs) on every deploy. All.env*files at the project root are now preserved by default, plus anything listed in the newdeploy.preservearray (files or directories); the vite kind, which previously preserved nothing, gets the same protection. Found the hard way: a first production deploy of an auth service wiped its staged DB credentials and RSA signing keys.
Added
- Test suite (Pester) — the toolkit now has automated coverage of its own
pure logic:
Get-ArchiveExcludes(including the deploy-vs-backup rule that keeps.env/uploadsout of deploys but in backups), config and project lookups,remote.composeDirfallback, EC2 target composition, and build-label formatting. Run withInvoke-Pester .\tests(Pester 5+). Verified by mutation testing — reintroducing each historical bug turns the suite red. ZCONFIGenvironment variable (PowerShell) — overrides the path tozconfig.json, matching the bash port, which has always honored it. Closes a parity gap and gives the test suite a seam for injecting a fixture config.zec2_rotatekeys— safely rotate/reset server-side secrets — a new tool for when a secret leaks or a deploy overwrites a production.envwith dev values.-Rotate KEYregenerates a key on the server (openssl rand -hex 32) so the new value never leaves the box;-Set KEYtakes an operator-known value (e.g.DATABASE_URL,ADMIN_EMAIL) from a masked prompt and streams it over SSH stdin — never a command argument, never echoed. Backs the server.envup to a timestamped.bakfirst, updates the key atomically (matches or appends), auto-detectsbackend/.envfromdeploy.preserve, and with-Restartrecreates the container (up -d --force-recreate, so the new values actually load — a plain restart keeps the old environment).-WhatIfpreviews the plan without touching anything.zkill all—zkillnow acceptsall, stopping the dev server of every project that has aports.dev(edge/docker stacks with no local dev server are skipped). Brings it in line withzdeploy all/zbackup all; the one-shot "stop everything I've got running locally". Ported to both the PowerShell and bash versions.zdeployserver-side health verification (verifyblock) — projects not published through the edge proxy can declare"verify": { "port": ..., "path": "/health", "expect": "..." }and the deploy is checked from the server itself (curl localhost:<port><path>over SSH) instead of hitting the public IP. Fixes a false PASS where the proxy's default vhost answered for apps that never started; projects with neitherdomainnorverifyare now reported as NOT verified.zdeployoptionaldeploy.gitPull—git pull --ff-onlyin the project root before zipping.zdeployzips the working tree and doesn't otherwise pull, so a checkout left behindoriginafter a merged PR would deploy stale code while still bumping the build number — success that changes nothing. A failed pull aborts the deploy instead.- Per-project
startconfig block —zstarthonors optional pre-start steps fromzconfig.json:"gitPull": truerunsgit pull --ff-onlyin the project root before starting (never boot a stale checkout), and"env": { ... }sets environment variables for the dev-server process. Example added tozconfig.example.json. - Switch-style argument tolerance — a leading dash on a project key is
ignored everywhere (
zdeploy -myapp==zdeploy myapp), for hands that grew up on per-project switches.
Changed
zbackup/zbackup_and_syncrequire an explicit target — running them bare now shows usage instead of quietly backing up every project;alldoes what bare invocation used to (matchingzdeploy). The scheduled task created bysetup_backup_schedule.ps1passesall— re-run it if your task was registered before this change.zbackupparses moreDATABASE_URLstyles — double/single-quoted values (Prisma convention),postgres://andpostgresql+driver://schemes, and URLs without an explicit port (defaults to 5432) all work; previously these skipped the Postgres dump with "Could not parse DATABASE_URL".zkill/ port cleanup kills the whole process tree — listeners on a project's port are now terminated children-first. Auto-reloading servers (uvicorn/watchfiles, nodemon) spawn workers that inherit the listening socket; killing only the parent left orphans serving stale code.zbackupfindsDATABASE_URLinbackend\.envtoo — projects with a frontend/backend split get their Postgres dump bundled without needing a root-level.env.
1.0.0
Initial public release: zstart / zkill / zrestart (local dev servers),
zdeploy (zip → upload → compose build → live build-version verification,
with handlers for python / vite / nextjs / edge / docker project kinds),
zec2 / zec2online / zrepair (health checks and recovery), zbackup /
zbackup_ec2 / zsync (local, server-side, and offsite backups), all driven
by a single gitignored zconfig.json.