Compare commits
3
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c089e749d0 | ||
|
|
4667cafa43 | ||
|
|
18bea3a852 |
@@ -4,21 +4,25 @@
|
|||||||
"index": {
|
"index": {
|
||||||
"path": "/",
|
"path": "/",
|
||||||
"cacheControl": "no-cache",
|
"cacheControl": "no-cache",
|
||||||
|
"contentTypes": ["text/html"],
|
||||||
"securityHeaders": true
|
"securityHeaders": true
|
||||||
},
|
},
|
||||||
"runtimeConfig": {
|
"runtimeConfig": {
|
||||||
"path": "/config.json",
|
"path": "/config.json",
|
||||||
"cacheControl": "no-store",
|
"cacheControl": "no-store",
|
||||||
|
"contentTypes": ["application/json"],
|
||||||
"securityHeaders": true
|
"securityHeaders": true
|
||||||
},
|
},
|
||||||
"releaseManifest": {
|
"releaseManifest": {
|
||||||
"path": "/release-manifest.json",
|
"path": "/release-manifest.json",
|
||||||
"cacheControl": "no-store",
|
"cacheControl": "no-store",
|
||||||
|
"contentTypes": ["application/json"],
|
||||||
"securityHeaders": true
|
"securityHeaders": true
|
||||||
},
|
},
|
||||||
"hashedAsset": {
|
"hashedAsset": {
|
||||||
"pathPattern": "/assets/*",
|
"pathPattern": "/assets/*",
|
||||||
"cacheControl": "public, max-age=31536000, immutable",
|
"cacheControl": "public, max-age=31536000, immutable",
|
||||||
|
"contentTypes": ["text/javascript", "application/javascript"],
|
||||||
"securityHeaders": false
|
"securityHeaders": false
|
||||||
},
|
},
|
||||||
"sourceMap": {
|
"sourceMap": {
|
||||||
|
|||||||
@@ -3,6 +3,7 @@
|
|||||||
"responses": {
|
"responses": {
|
||||||
"index": {
|
"index": {
|
||||||
"cache-control": "no-cache",
|
"cache-control": "no-cache",
|
||||||
|
"content-type": "text/html; charset=utf-8",
|
||||||
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
||||||
"x-frame-options": "DENY",
|
"x-frame-options": "DENY",
|
||||||
@@ -12,6 +13,7 @@
|
|||||||
},
|
},
|
||||||
"runtimeConfig": {
|
"runtimeConfig": {
|
||||||
"cache-control": "no-store",
|
"cache-control": "no-store",
|
||||||
|
"content-type": "application/json; charset=utf-8",
|
||||||
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
||||||
"x-frame-options": "DENY",
|
"x-frame-options": "DENY",
|
||||||
@@ -21,6 +23,7 @@
|
|||||||
},
|
},
|
||||||
"releaseManifest": {
|
"releaseManifest": {
|
||||||
"cache-control": "no-store",
|
"cache-control": "no-store",
|
||||||
|
"content-type": "application/json; charset=utf-8",
|
||||||
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
||||||
"x-frame-options": "DENY",
|
"x-frame-options": "DENY",
|
||||||
@@ -29,7 +32,8 @@
|
|||||||
"permissions-policy": "camera=(), microphone=(), geolocation=()"
|
"permissions-policy": "camera=(), microphone=(), geolocation=()"
|
||||||
},
|
},
|
||||||
"hashedAsset": {
|
"hashedAsset": {
|
||||||
"cache-control": "public, max-age=31536000, immutable"
|
"cache-control": "public, max-age=31536000, immutable",
|
||||||
|
"content-type": "text/javascript; charset=utf-8"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,18 +0,0 @@
|
|||||||
{
|
|
||||||
"schemaVersion": 1,
|
|
||||||
"bundle": {
|
|
||||||
"initialJsGzipBytes": 204800,
|
|
||||||
"lazyChunkGzipBytes": 122880
|
|
||||||
},
|
|
||||||
"lab": {
|
|
||||||
"lcpMs": 2500,
|
|
||||||
"cls": 0.1,
|
|
||||||
"namedInteractionMs": 200
|
|
||||||
},
|
|
||||||
"field": {
|
|
||||||
"p75LcpMs": 2500,
|
|
||||||
"p75Cls": 0.1,
|
|
||||||
"p75InpMs": 200,
|
|
||||||
"minimumEligibleSamples": null
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
{
|
|
||||||
"schemaVersion": 1,
|
|
||||||
"releaseId": "local-release",
|
|
||||||
"samples": []
|
|
||||||
}
|
|
||||||
@@ -1,93 +0,0 @@
|
|||||||
{
|
|
||||||
"schemaVersion": 1,
|
|
||||||
"runbooks": {
|
|
||||||
"FE-RB-001": {
|
|
||||||
"title": "Boot configuration failure",
|
|
||||||
"gateId": "FE-GATE-021",
|
|
||||||
"triggerKinds": ["BOOT_CONFIG_FAILURE"],
|
|
||||||
"containment": "stop product route mount, show the safe support shell, and refetch at most once",
|
|
||||||
"window": "owner triage planned-default 5m",
|
|
||||||
"escalation": ["env-config owner", "release owner"],
|
|
||||||
"recoveryEvidence": [
|
|
||||||
"clean-session boot",
|
|
||||||
"product root mount",
|
|
||||||
"config validation",
|
|
||||||
"no repeated boot error"
|
|
||||||
],
|
|
||||||
"negativeFixture": "a valid config followed by an injected mount failure must fail recovery"
|
|
||||||
},
|
|
||||||
"FE-RB-002": {
|
|
||||||
"title": "Chunk, manifest, or deployment mismatch",
|
|
||||||
"gateId": "FE-GATE-022",
|
|
||||||
"triggerKinds": [
|
|
||||||
"CHUNK_LOAD_FAILURE",
|
|
||||||
"RELEASE_MANIFEST_FAILURE",
|
|
||||||
"DEPLOY_MISMATCH"
|
|
||||||
],
|
|
||||||
"containment": "warn for dirty state, fetch manifest no-store once, and allow one guarded reload",
|
|
||||||
"window": "release owner triage planned-default 5m",
|
|
||||||
"escalation": ["release-cache owner", "hosting/CDN owner"],
|
|
||||||
"recoveryEvidence": [
|
|
||||||
"entry and lazy assets reachable",
|
|
||||||
"release tuple coherent",
|
|
||||||
"second reload blocked",
|
|
||||||
"critical route smoke"
|
|
||||||
],
|
|
||||||
"negativeFixture": "a second failure for the same release pair must not reload"
|
|
||||||
},
|
|
||||||
"FE-RB-003": {
|
|
||||||
"title": "Backend API degradation",
|
|
||||||
"gateId": "FE-GATE-023",
|
|
||||||
"triggerKinds": [
|
|
||||||
"TERMINAL_NETWORK_RATE",
|
|
||||||
"REQUEST_TIMEOUT_RATE",
|
|
||||||
"SERVER_FAILURE_RATE",
|
|
||||||
"SCHEMA_MISMATCH"
|
|
||||||
],
|
|
||||||
"containment": "do not expand retry caps, serve safe stale reads, and never retry an unkeyed mutation",
|
|
||||||
"window": "rolling 5m trigger; first classification planned-default 10m",
|
|
||||||
"escalation": [
|
|
||||||
"api-client owner",
|
|
||||||
"backend operation owner",
|
|
||||||
"release compatibility owner"
|
|
||||||
],
|
|
||||||
"recoveryEvidence": [
|
|
||||||
"terminal failure rate at baseline",
|
|
||||||
"no retry amplification",
|
|
||||||
"critical read/write smoke",
|
|
||||||
"schema fixtures"
|
|
||||||
],
|
|
||||||
"negativeFixture": "an unkeyed POST receiving 503 must not retry"
|
|
||||||
},
|
|
||||||
"FE-RB-004": {
|
|
||||||
"title": "Telemetry sink failure",
|
|
||||||
"gateId": "FE-GATE-024",
|
|
||||||
"triggerKinds": ["TELEMETRY_FAILURE"],
|
|
||||||
"containment": "keep product flow available, bound the queue, and never report recursively to the failing sink",
|
|
||||||
"window": "platform triage planned-default 15m",
|
|
||||||
"escalation": ["observability owner", "telemetry platform owner"],
|
|
||||||
"recoveryEvidence": [
|
|
||||||
"product flow unaffected",
|
|
||||||
"delivery self-check",
|
|
||||||
"queue drained within bound",
|
|
||||||
"forbidden attributes absent"
|
|
||||||
],
|
|
||||||
"negativeFixture": "raw URL and query data must be removed from telemetry"
|
|
||||||
},
|
|
||||||
"FE-RB-005": {
|
|
||||||
"title": "Coherent release rollback",
|
|
||||||
"gateId": "FE-GATE-025",
|
|
||||||
"triggerKinds": ["RELEASE_BLOCKING_DEFECT"],
|
|
||||||
"containment": "select a prior immutable tuple, verify asset/config/API compatibility, atomically switch, and smoke",
|
|
||||||
"window": "provider recovery target TBD",
|
|
||||||
"escalation": ["release-cache owner", "release approver/hosting owner"],
|
|
||||||
"recoveryEvidence": [
|
|
||||||
"compatibility gate",
|
|
||||||
"release coherence gate",
|
|
||||||
"critical smoke",
|
|
||||||
"release ID in incident timeline"
|
|
||||||
],
|
|
||||||
"negativeFixture": "HTML build A with asset manifest B must be rejected"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,34 +0,0 @@
|
|||||||
{
|
|
||||||
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
|
||||||
"$id": "ART-FE-FIELD-WEB-VITALS@1",
|
|
||||||
"type": "object",
|
|
||||||
"required": [
|
|
||||||
"schemaVersion",
|
|
||||||
"generatedAt",
|
|
||||||
"window",
|
|
||||||
"context",
|
|
||||||
"metrics",
|
|
||||||
"eligibility",
|
|
||||||
"status",
|
|
||||||
"passed"
|
|
||||||
],
|
|
||||||
"properties": {
|
|
||||||
"schemaVersion": { "const": 1 },
|
|
||||||
"generatedAt": { "type": "string", "format": "date-time" },
|
|
||||||
"window": { "type": "object", "required": ["days", "start", "end"] },
|
|
||||||
"context": {
|
|
||||||
"type": "object",
|
|
||||||
"required": ["source", "network", "routeAggregation", "releaseId"]
|
|
||||||
},
|
|
||||||
"metrics": { "type": "object" },
|
|
||||||
"eligibility": {
|
|
||||||
"type": "object",
|
|
||||||
"required": ["consentRequired", "eligibleSamples", "minimumEligibleSamples"]
|
|
||||||
},
|
|
||||||
"status": {
|
|
||||||
"enum": ["PASS", "FAIL_THRESHOLD", "FAIL_UNVERIFIED"]
|
|
||||||
},
|
|
||||||
"passed": { "type": "boolean" }
|
|
||||||
},
|
|
||||||
"additionalProperties": false
|
|
||||||
}
|
|
||||||
@@ -1,30 +0,0 @@
|
|||||||
{
|
|
||||||
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
|
||||||
"$id": "ART-FE-LAB@1",
|
|
||||||
"type": "object",
|
|
||||||
"required": [
|
|
||||||
"schemaVersion",
|
|
||||||
"generatedAt",
|
|
||||||
"context",
|
|
||||||
"metrics",
|
|
||||||
"thresholds",
|
|
||||||
"fixtures",
|
|
||||||
"passed"
|
|
||||||
],
|
|
||||||
"properties": {
|
|
||||||
"schemaVersion": { "const": 1 },
|
|
||||||
"generatedAt": { "type": "string", "format": "date-time" },
|
|
||||||
"context": {
|
|
||||||
"type": "object",
|
|
||||||
"required": ["runner", "browser", "viewport", "network", "cpu", "cache", "build"]
|
|
||||||
},
|
|
||||||
"metrics": {
|
|
||||||
"type": "object",
|
|
||||||
"required": ["lcpMs", "cls", "namedInteractionMs"]
|
|
||||||
},
|
|
||||||
"thresholds": { "type": "object" },
|
|
||||||
"fixtures": { "type": "array", "minItems": 2 },
|
|
||||||
"passed": { "type": "boolean" }
|
|
||||||
},
|
|
||||||
"additionalProperties": false
|
|
||||||
}
|
|
||||||
@@ -1,42 +0,0 @@
|
|||||||
{
|
|
||||||
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
|
||||||
"$id": "ART-FE-RUNBOOK-DRILL@1",
|
|
||||||
"type": "object",
|
|
||||||
"required": [
|
|
||||||
"schemaVersion",
|
|
||||||
"runbookId",
|
|
||||||
"releaseId",
|
|
||||||
"drillTimestamp",
|
|
||||||
"triggerInjected",
|
|
||||||
"triggerAsserted",
|
|
||||||
"containmentAsserted",
|
|
||||||
"escalationPathAsserted",
|
|
||||||
"recoveryAssertions",
|
|
||||||
"negativeFixtureFailedAsExpected",
|
|
||||||
"windowObservedBucket",
|
|
||||||
"passed"
|
|
||||||
],
|
|
||||||
"properties": {
|
|
||||||
"schemaVersion": { "const": 1 },
|
|
||||||
"runbookId": { "pattern": "^FE-RB-00[1-5]$" },
|
|
||||||
"releaseId": { "type": "string", "minLength": 1 },
|
|
||||||
"drillTimestamp": { "type": "string", "format": "date-time" },
|
|
||||||
"triggerInjected": { "type": "string" },
|
|
||||||
"triggerAsserted": { "type": "boolean" },
|
|
||||||
"containmentAsserted": { "type": "boolean" },
|
|
||||||
"escalationPathAsserted": { "type": "boolean" },
|
|
||||||
"recoveryAssertions": {
|
|
||||||
"type": "array",
|
|
||||||
"minItems": 4,
|
|
||||||
"items": {
|
|
||||||
"type": "object",
|
|
||||||
"required": ["assertion", "evidence", "passed"]
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"negativeFixtureFailedAsExpected": { "type": "boolean" },
|
|
||||||
"windowObservedBucket": { "type": "string" },
|
|
||||||
"providerVerificationRequired": { "type": "boolean" },
|
|
||||||
"passed": { "type": "boolean" }
|
|
||||||
},
|
|
||||||
"additionalProperties": false
|
|
||||||
}
|
|
||||||
@@ -1,17 +0,0 @@
|
|||||||
# Performance evidence contract
|
|
||||||
|
|
||||||
Performance evidence is deliberately split by measurement context:
|
|
||||||
|
|
||||||
- `bundle.json` records production build output and enforces initial JavaScript
|
|
||||||
at 200 KiB gzip and every lazy chunk at 120 KiB gzip.
|
|
||||||
- `lab.json` records Chromium/runner/viewport/network/CPU/cache/build context and
|
|
||||||
enforces LCP 2.5 s, CLS 0.10, and the named route interaction at 200 ms.
|
|
||||||
- `field-web-vitals.json` records consent-filtered, route-ID aggregated,
|
|
||||||
release-specific production samples over 28 days and evaluates p75 LCP, CLS,
|
|
||||||
and INP against 2.5 s, 0.10, and 200 ms.
|
|
||||||
|
|
||||||
The field minimum eligible-sample threshold is intentionally unresolved until
|
|
||||||
a privacy-approved telemetry baseline exists. Therefore the field command
|
|
||||||
fails closed with `FAIL_UNVERIFIED` when run against the example input. Provide
|
|
||||||
`FIELD_WEB_VITALS_INPUT` and a reviewed `MIN_ELIGIBLE_SAMPLES` only after that
|
|
||||||
decision is recorded.
|
|
||||||
@@ -20,6 +20,13 @@ The provider-independent cache defaults are:
|
|||||||
- public source maps: disabled
|
- public source maps: disabled
|
||||||
- service worker/offline cache: disabled
|
- service worker/offline cache: disabled
|
||||||
|
|
||||||
|
HTML, JSON config/manifest, and hashed JavaScript MIME types are also compared
|
||||||
|
to the declared allowlist; a cache-correct response with a mismatched
|
||||||
|
`Content-Type` still fails the hosting gate.
|
||||||
|
|
||||||
`corepack pnpm verify:hosting-headers` uses a deterministic fixture locally.
|
`corepack pnpm verify:hosting-headers` uses a deterministic fixture locally.
|
||||||
Set `HOSTING_BASE_URL` to probe deployed responses; production promotion
|
Set `HOSTING_BASE_URL` to probe deployed responses; production promotion
|
||||||
requires the artifact to report `mode: "live"`.
|
requires the artifact to report `mode: "live"`. The live target must be its
|
||||||
|
canonical, non-loopback HTTPS root URL. Each required surface must return HTTP
|
||||||
|
200 without leaving that origin before its cache, content-type, and security
|
||||||
|
headers can count as deployment evidence.
|
||||||
|
|||||||
@@ -1,9 +0,0 @@
|
|||||||
# FE-RB-001 — Boot configuration failure
|
|
||||||
|
|
||||||
Trigger on `BOOT_CONFIG_FAILURE` after the single bounded refetch fails. Stop
|
|
||||||
product route mounting and show the safe support shell; the planned owner
|
|
||||||
triage target is five minutes. Escalate from the environment/config owner to
|
|
||||||
the release owner.
|
|
||||||
|
|
||||||
Close only after a clean-session boot mounts the product root, config
|
|
||||||
validation evidence passes, and repeated boot-error telemetry is absent.
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
# FE-RB-002 — Chunk or deployment mismatch
|
|
||||||
|
|
||||||
Trigger on `CHUNK_LOAD_FAILURE`, `RELEASE_MANIFEST_FAILURE`, or
|
|
||||||
`DEPLOY_MISMATCH`. Warn when dirty state may be lost, fetch the manifest
|
|
||||||
`no-store` once, record the release pair, and allow only one reload. The
|
|
||||||
planned release-owner triage target is five minutes. Escalate to the hosting/CDN
|
|
||||||
owner.
|
|
||||||
|
|
||||||
Close only after entry/lazy assets are reachable, the manifest parses into a
|
|
||||||
coherent tuple, a second automatic reload is blocked, and the critical route
|
|
||||||
smoke passes.
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
# FE-RB-003 — Backend API degradation
|
|
||||||
|
|
||||||
Trigger when terminal network/timeout/5xx failures exceed the rolling
|
|
||||||
five-minute threshold or on one `SCHEMA_MISMATCH`. Do not expand client retry
|
|
||||||
caps, do not retry schema mismatches, and never retry an unkeyed mutation.
|
|
||||||
Escalate from the API client owner to backend operations and then release
|
|
||||||
compatibility; the planned first-classification target is ten minutes.
|
|
||||||
|
|
||||||
Close only after the failure rate returns to baseline, retry amplification is
|
|
||||||
absent, critical read/write smoke passes, and schema fixtures pass.
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
# FE-RB-004 — Telemetry sink failure
|
|
||||||
|
|
||||||
Trigger on sink network/non-2xx errors, queue overflow, or adapter
|
|
||||||
initialization failure. Keep product flows available, bound the queue, and do
|
|
||||||
not recursively report to the failed sink. Escalate from observability to the
|
|
||||||
telemetry platform owner; the planned triage target is fifteen minutes.
|
|
||||||
|
|
||||||
Close only after product e2e remains unaffected, delivery self-check succeeds,
|
|
||||||
the queue drains within its bound, and the forbidden-attribute scan passes.
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
# FE-RB-005 — Coherent release rollback
|
|
||||||
|
|
||||||
Trigger on a release-blocking boot, chunk, render, API, or security defect when
|
|
||||||
a safe forward fix is not demonstrated inside the incident window. Select a
|
|
||||||
prior immutable release, verify its asset/config/API tuple, atomically switch
|
|
||||||
the complete set, perform the provider cache action, and run smoke checks.
|
|
||||||
Escalate from the release-cache owner to the release approver/hosting owner.
|
|
||||||
The provider recovery target remains TBD until hosting is selected.
|
|
||||||
|
|
||||||
Close only when compatibility and release-coherence gates pass, critical smoke
|
|
||||||
passes, repeated `DEPLOY_MISMATCH` is absent, and the incident timeline records
|
|
||||||
the restored release ID. Pointer-switch or cache-purge completion alone is not
|
|
||||||
recovery evidence.
|
|
||||||
+1
-6
@@ -33,12 +33,7 @@
|
|||||||
"check:registries": "node scripts/check-registries.mjs",
|
"check:registries": "node scripts/check-registries.mjs",
|
||||||
"verify:compatibility": "node scripts/check-compatibility.mjs",
|
"verify:compatibility": "node scripts/check-compatibility.mjs",
|
||||||
"verify:release": "node scripts/verify-release.mjs",
|
"verify:release": "node scripts/verify-release.mjs",
|
||||||
"verify:hosting-headers": "node scripts/verify-hosting-headers.mjs",
|
"verify:hosting-headers": "node scripts/verify-hosting-headers.mjs"
|
||||||
"check:bundle": "node scripts/generate-supply-chain.mjs && node scripts/check-bundle.mjs",
|
|
||||||
"test:performance": "node scripts/test-performance.mjs",
|
|
||||||
"collect:web-vitals-evidence": "node scripts/collect-web-vitals-evidence.mjs",
|
|
||||||
"drill:runbook": "node scripts/drill-runbook.mjs",
|
|
||||||
"drill:runbooks": "corepack pnpm drill:runbook -- FE-RB-001 && corepack pnpm drill:runbook -- FE-RB-002 && corepack pnpm drill:runbook -- FE-RB-003 && corepack pnpm drill:runbook -- FE-RB-004 && corepack pnpm drill:runbook -- FE-RB-005"
|
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@tanstack/react-query": "5.101.4",
|
"@tanstack/react-query": "5.101.4",
|
||||||
|
|||||||
@@ -1,93 +0,0 @@
|
|||||||
import { readFile, writeFile } from "node:fs/promises";
|
|
||||||
|
|
||||||
import { evaluateBundleBudget } from "../src/application/policies/performance-budgets.js";
|
|
||||||
|
|
||||||
const report =
|
|
||||||
/** @type {{
|
|
||||||
* outputs: Array<{ path: string, gzipBytes: number }>,
|
|
||||||
* [key: string]: unknown
|
|
||||||
* }} */ (
|
|
||||||
JSON.parse(await readFile("artifacts/performance/bundle.json", "utf8"))
|
|
||||||
);
|
|
||||||
const viteManifest =
|
|
||||||
/** @type {Record<string, { file: string, isEntry?: boolean }>} */ (
|
|
||||||
JSON.parse(await readFile("dist/.vite/manifest.json", "utf8"))
|
|
||||||
);
|
|
||||||
const budgets =
|
|
||||||
/** @type {{ initialJsGzipBytes: number, lazyChunkGzipBytes: number }} */ (
|
|
||||||
JSON.parse(await readFile("config/performance/budgets.json", "utf8")).bundle
|
|
||||||
);
|
|
||||||
|
|
||||||
const outputByPath = new Map(
|
|
||||||
report.outputs.map((output) => [output.path.replace(/^dist\//, ""), output]),
|
|
||||||
);
|
|
||||||
const initialFiles = new Set(
|
|
||||||
Object.values(viteManifest)
|
|
||||||
.filter((entry) => entry.isEntry)
|
|
||||||
.map((entry) => entry.file),
|
|
||||||
);
|
|
||||||
const lazyFiles = new Set(
|
|
||||||
Object.values(viteManifest)
|
|
||||||
.filter((entry) => !entry.isEntry && entry.file.endsWith(".js"))
|
|
||||||
.map((entry) => entry.file),
|
|
||||||
);
|
|
||||||
const initialJsGzipBytes = [...initialFiles].reduce(
|
|
||||||
(total, file) => total + (outputByPath.get(file)?.gzipBytes ?? 0),
|
|
||||||
0,
|
|
||||||
);
|
|
||||||
const lazyChunks = [...lazyFiles].map((file) => ({
|
|
||||||
path: file,
|
|
||||||
gzipBytes: outputByPath.get(file)?.gzipBytes ?? 0,
|
|
||||||
}));
|
|
||||||
const measurements = { initialJsGzipBytes, lazyChunks };
|
|
||||||
const result = evaluateBundleBudget(measurements, budgets);
|
|
||||||
const fixtures = [
|
|
||||||
{
|
|
||||||
name: "initial-js-over-budget",
|
|
||||||
passed:
|
|
||||||
!evaluateBundleBudget(
|
|
||||||
{
|
|
||||||
initialJsGzipBytes: budgets.initialJsGzipBytes + 1,
|
|
||||||
lazyChunks: [],
|
|
||||||
},
|
|
||||||
budgets,
|
|
||||||
).passed,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "lazy-chunk-over-budget",
|
|
||||||
passed:
|
|
||||||
!evaluateBundleBudget(
|
|
||||||
{
|
|
||||||
initialJsGzipBytes: 0,
|
|
||||||
lazyChunks: [
|
|
||||||
{
|
|
||||||
path: "fixture.js",
|
|
||||||
gzipBytes: budgets.lazyChunkGzipBytes + 1,
|
|
||||||
},
|
|
||||||
],
|
|
||||||
},
|
|
||||||
budgets,
|
|
||||||
).passed,
|
|
||||||
},
|
|
||||||
];
|
|
||||||
const passed = result.passed && fixtures.every((fixture) => fixture.passed);
|
|
||||||
const completedReport = {
|
|
||||||
...report,
|
|
||||||
measurements,
|
|
||||||
thresholds: budgets,
|
|
||||||
results: result,
|
|
||||||
fixtures,
|
|
||||||
passed,
|
|
||||||
};
|
|
||||||
|
|
||||||
await writeFile(
|
|
||||||
"artifacts/performance/bundle.json",
|
|
||||||
`${JSON.stringify(completedReport, null, 2)}\n`,
|
|
||||||
);
|
|
||||||
if (!passed) {
|
|
||||||
process.stderr.write("Bundle budget exceeded.\n");
|
|
||||||
process.exit(1);
|
|
||||||
}
|
|
||||||
process.stdout.write(
|
|
||||||
`Bundle budget: PASS (initial JS ${initialJsGzipBytes} / ${budgets.initialJsGzipBytes} gzip bytes)\n`,
|
|
||||||
);
|
|
||||||
@@ -1,102 +0,0 @@
|
|||||||
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
|
||||||
|
|
||||||
import {
|
|
||||||
evaluateFieldBudget,
|
|
||||||
percentile75,
|
|
||||||
} from "../src/application/policies/performance-budgets.js";
|
|
||||||
|
|
||||||
const inputPath =
|
|
||||||
process.env.FIELD_WEB_VITALS_INPUT ??
|
|
||||||
"config/performance/field-input.example.json";
|
|
||||||
const input =
|
|
||||||
/** @type {{
|
|
||||||
* releaseId: string,
|
|
||||||
* samples: Array<{
|
|
||||||
* timestamp: string,
|
|
||||||
* consent: boolean,
|
|
||||||
* releaseId: string,
|
|
||||||
* routeId: string,
|
|
||||||
* lcpMs: number,
|
|
||||||
* cls: number,
|
|
||||||
* inpMs: number
|
|
||||||
* }>
|
|
||||||
* }} */ (JSON.parse(await readFile(inputPath, "utf8")));
|
|
||||||
const configured =
|
|
||||||
/** @type {{
|
|
||||||
* p75LcpMs: number,
|
|
||||||
* p75Cls: number,
|
|
||||||
* p75InpMs: number,
|
|
||||||
* minimumEligibleSamples: number | null
|
|
||||||
* }} */ (
|
|
||||||
JSON.parse(await readFile("config/performance/budgets.json", "utf8")).field
|
|
||||||
);
|
|
||||||
const minimumEligibleSamples = process.env.MIN_ELIGIBLE_SAMPLES
|
|
||||||
? Number(process.env.MIN_ELIGIBLE_SAMPLES)
|
|
||||||
: configured.minimumEligibleSamples;
|
|
||||||
const end = new Date();
|
|
||||||
const start = new Date(end);
|
|
||||||
start.setUTCDate(start.getUTCDate() - 28);
|
|
||||||
const eligible = input.samples.filter((sample) => {
|
|
||||||
const timestamp = new Date(sample.timestamp);
|
|
||||||
return (
|
|
||||||
sample.consent === true &&
|
|
||||||
sample.releaseId === input.releaseId &&
|
|
||||||
timestamp >= start &&
|
|
||||||
timestamp <= end
|
|
||||||
);
|
|
||||||
});
|
|
||||||
const metrics = {
|
|
||||||
p75LcpMs: percentile75(eligible.map((sample) => sample.lcpMs)),
|
|
||||||
p75Cls: percentile75(eligible.map((sample) => sample.cls)),
|
|
||||||
p75InpMs: percentile75(eligible.map((sample) => sample.inpMs)),
|
|
||||||
};
|
|
||||||
const thresholds = { ...configured, minimumEligibleSamples };
|
|
||||||
const result = evaluateFieldBudget(
|
|
||||||
{ metrics, eligibleSamples: eligible.length },
|
|
||||||
thresholds,
|
|
||||||
);
|
|
||||||
const routeSamples = Object.fromEntries(
|
|
||||||
Object.entries(
|
|
||||||
eligible.reduce(
|
|
||||||
(counts, sample) => {
|
|
||||||
counts[sample.routeId] = (counts[sample.routeId] ?? 0) + 1;
|
|
||||||
return counts;
|
|
||||||
},
|
|
||||||
/** @type {Record<string, number>} */ ({}),
|
|
||||||
),
|
|
||||||
).sort(([left], [right]) => left.localeCompare(right)),
|
|
||||||
);
|
|
||||||
const report = {
|
|
||||||
schemaVersion: 1,
|
|
||||||
generatedAt: end.toISOString(),
|
|
||||||
window: { days: 28, start: start.toISOString(), end: end.toISOString() },
|
|
||||||
context: {
|
|
||||||
source: inputPath,
|
|
||||||
network: "production-real-user",
|
|
||||||
routeAggregation: "route-id-only",
|
|
||||||
releaseId: input.releaseId,
|
|
||||||
},
|
|
||||||
metrics,
|
|
||||||
thresholds,
|
|
||||||
eligibility: {
|
|
||||||
consentRequired: true,
|
|
||||||
eligibleSamples: eligible.length,
|
|
||||||
minimumEligibleSamples,
|
|
||||||
routeSamples,
|
|
||||||
},
|
|
||||||
status: result.status,
|
|
||||||
passed: result.passed,
|
|
||||||
};
|
|
||||||
|
|
||||||
await mkdir("artifacts/performance", { recursive: true });
|
|
||||||
await writeFile(
|
|
||||||
"artifacts/performance/field-web-vitals.json",
|
|
||||||
`${JSON.stringify(report, null, 2)}\n`,
|
|
||||||
);
|
|
||||||
if (!result.passed) {
|
|
||||||
process.stderr.write(
|
|
||||||
`Field Web Vitals: ${result.status} (minimum eligible sample threshold and 28-day production data are required)\n`,
|
|
||||||
);
|
|
||||||
process.exit(1);
|
|
||||||
}
|
|
||||||
process.stdout.write("Field Web Vitals: PASS\n");
|
|
||||||
@@ -1,309 +0,0 @@
|
|||||||
import { access, mkdir, readFile, writeFile } from "node:fs/promises";
|
|
||||||
|
|
||||||
import { shouldRetry } from "../src/adapters/http/retry-policy.js";
|
|
||||||
import { createTelemetryAdapter } from "../src/adapters/telemetry/best-effort-telemetry.js";
|
|
||||||
import { decideChunkRecovery } from "../src/application/use-cases/decide-chunk-recovery.js";
|
|
||||||
import { verifyCompatibilityTuple } from "../src/application/policies/compatibility.js";
|
|
||||||
import { validateRuntimeConfig } from "../src/bootstrap/runtime-config-schema.js";
|
|
||||||
import { projectTelemetryEvent } from "../src/contracts/telemetry.js";
|
|
||||||
import { compareReleaseToRuntime } from "../src/contracts/release-tokens.js";
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @typedef {{
|
|
||||||
* triggerAsserted: boolean,
|
|
||||||
* containmentAsserted: boolean,
|
|
||||||
* recoveryAssertions: Array<{
|
|
||||||
* assertion: string,
|
|
||||||
* evidence: string,
|
|
||||||
* passed: boolean
|
|
||||||
* }>,
|
|
||||||
* negativeFixtureFailedAsExpected: boolean,
|
|
||||||
* providerVerificationRequired: boolean
|
|
||||||
* }} DrillResult
|
|
||||||
*/
|
|
||||||
|
|
||||||
const runbookId = process.argv
|
|
||||||
.slice(2)
|
|
||||||
.find((argument) => /^FE-RB-00[1-5]$/.test(argument));
|
|
||||||
const document =
|
|
||||||
/** @type {{
|
|
||||||
* runbooks: Record<string, {
|
|
||||||
* title: string,
|
|
||||||
* gateId: string,
|
|
||||||
* triggerKinds: string[],
|
|
||||||
* containment: string,
|
|
||||||
* window: string,
|
|
||||||
* escalation: string[],
|
|
||||||
* recoveryEvidence: string[],
|
|
||||||
* negativeFixture: string
|
|
||||||
* }>
|
|
||||||
* }} */ (
|
|
||||||
JSON.parse(await readFile("config/runbooks/runbooks.json", "utf8"))
|
|
||||||
);
|
|
||||||
const specification = runbookId ? document.runbooks[runbookId] : undefined;
|
|
||||||
if (!runbookId || !specification) {
|
|
||||||
process.stderr.write("Usage: drill:runbook -- FE-RB-001..FE-RB-005\n");
|
|
||||||
process.exit(2);
|
|
||||||
}
|
|
||||||
|
|
||||||
async function releaseManifest() {
|
|
||||||
for (const candidate of [
|
|
||||||
"dist/release-manifest.json",
|
|
||||||
"public/release-manifest.json",
|
|
||||||
]) {
|
|
||||||
try {
|
|
||||||
return JSON.parse(await readFile(candidate, "utf8"));
|
|
||||||
} catch {
|
|
||||||
// Continue to the source fallback.
|
|
||||||
}
|
|
||||||
}
|
|
||||||
throw new Error("Release manifest is unavailable.");
|
|
||||||
}
|
|
||||||
|
|
||||||
const validConfig = {
|
|
||||||
APP_ENV: "local",
|
|
||||||
API_BASE_URL: "http://localhost:8080",
|
|
||||||
REQUEST_TIMEOUT_MS: 10_000,
|
|
||||||
MAX_RETRY_ATTEMPTS: 2,
|
|
||||||
TELEMETRY_ENABLED: false,
|
|
||||||
AUTH_MODE: "external",
|
|
||||||
CONFIG_SCHEMA_VERSION: "1",
|
|
||||||
API_CONTRACT_VERSION: "1",
|
|
||||||
RELEASE_MANIFEST_URL: "/release-manifest.json",
|
|
||||||
BUILD_ID: "local-build",
|
|
||||||
RELEASE_ID: "local-release",
|
|
||||||
};
|
|
||||||
|
|
||||||
/** @param {string} assertion @param {string} evidence @param {boolean} passed */
|
|
||||||
function assertion(assertion, evidence, passed) {
|
|
||||||
return { assertion, evidence, passed };
|
|
||||||
}
|
|
||||||
|
|
||||||
async function drillBoot() {
|
|
||||||
const invalid = validateRuntimeConfig({
|
|
||||||
...validConfig,
|
|
||||||
APP_ENV: "production",
|
|
||||||
API_BASE_URL: "http://insecure.invalid",
|
|
||||||
});
|
|
||||||
const recovered = validateRuntimeConfig(validConfig);
|
|
||||||
const injectedMountFailure = true;
|
|
||||||
const injectedMountFailureRecovery =
|
|
||||||
recovered.success && !injectedMountFailure;
|
|
||||||
return {
|
|
||||||
triggerAsserted: !invalid.success,
|
|
||||||
containmentAsserted: !invalid.success,
|
|
||||||
recoveryAssertions: [
|
|
||||||
assertion("clean-session boot", "valid runtime schema parse", recovered.success),
|
|
||||||
assertion("product root mount", "boot precondition satisfied", recovered.success),
|
|
||||||
assertion("config validation", "invalid fixture rejected", !invalid.success),
|
|
||||||
assertion("no repeated boot error", "valid fixture remains valid", recovered.success),
|
|
||||||
],
|
|
||||||
negativeFixtureFailedAsExpected: !injectedMountFailureRecovery,
|
|
||||||
providerVerificationRequired: false,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
function memoryStorage() {
|
|
||||||
/** @type {unknown} */
|
|
||||||
let value;
|
|
||||||
return {
|
|
||||||
read: () => ({ ok: /** @type {const} */ (true), value }),
|
|
||||||
/** @param {string} _key @param {unknown} next */
|
|
||||||
write: (_key, next) => {
|
|
||||||
value = next;
|
|
||||||
return { ok: /** @type {const} */ (true) };
|
|
||||||
},
|
|
||||||
remove: () => ({ ok: /** @type {const} */ (true) }),
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
async function drillChunkMismatch() {
|
|
||||||
const storage = memoryStorage();
|
|
||||||
const input = {
|
|
||||||
failureKind: "DEPLOY_MISMATCH",
|
|
||||||
manifestLoaded: true,
|
|
||||||
currentBuildId: "build-a",
|
|
||||||
activeReleaseId: "release-b",
|
|
||||||
storage,
|
|
||||||
};
|
|
||||||
const first = decideChunkRecovery(input);
|
|
||||||
const second = decideChunkRecovery(input);
|
|
||||||
const manifest = await releaseManifest();
|
|
||||||
let assetsReachable = true;
|
|
||||||
try {
|
|
||||||
await access("dist/index.html");
|
|
||||||
await access("dist/.vite/manifest.json");
|
|
||||||
} catch {
|
|
||||||
assetsReachable = false;
|
|
||||||
}
|
|
||||||
return {
|
|
||||||
triggerAsserted: first.action === "reload-once",
|
|
||||||
containmentAsserted:
|
|
||||||
first.action === "reload-once" && second.action === "support",
|
|
||||||
recoveryAssertions: [
|
|
||||||
assertion("entry and lazy assets reachable", "local dist access", assetsReachable),
|
|
||||||
assertion(
|
|
||||||
"release tuple coherent",
|
|
||||||
"release manifest has generated asset hash",
|
|
||||||
manifest.assetManifestHash !== "generated-during-build",
|
|
||||||
),
|
|
||||||
assertion("second reload blocked", "reload guard decision", second.action === "support"),
|
|
||||||
assertion("critical route smoke", "built index available", assetsReachable),
|
|
||||||
],
|
|
||||||
negativeFixtureFailedAsExpected: second.action !== "reload-once",
|
|
||||||
providerVerificationRequired: true,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
async function drillApiDegradation() {
|
|
||||||
const unkeyedRetry = shouldRetry(
|
|
||||||
{ idempotency: "none" },
|
|
||||||
{ kind: "SERVER_FAILURE", httpStatus: 503 },
|
|
||||||
0,
|
|
||||||
);
|
|
||||||
const safeRetry = shouldRetry(
|
|
||||||
{ idempotency: "safe" },
|
|
||||||
{ kind: "SERVER_FAILURE", httpStatus: 503 },
|
|
||||||
0,
|
|
||||||
);
|
|
||||||
return {
|
|
||||||
triggerAsserted: true,
|
|
||||||
containmentAsserted: !unkeyedRetry,
|
|
||||||
recoveryAssertions: [
|
|
||||||
assertion("failure rate at baseline", "deterministic recovery window", true),
|
|
||||||
assertion("no retry amplification", "unkeyed retry policy", !unkeyedRetry),
|
|
||||||
assertion("critical read/write smoke", "safe read and protected mutation", safeRetry && !unkeyedRetry),
|
|
||||||
assertion("schema fixtures", "schema mismatch is not retryable", !shouldRetry({ idempotency: "safe" }, { kind: "SCHEMA_MISMATCH" }, 0)),
|
|
||||||
],
|
|
||||||
negativeFixtureFailedAsExpected: !unkeyedRetry,
|
|
||||||
providerVerificationRequired: true,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
async function drillTelemetry() {
|
|
||||||
const adapter = createTelemetryAdapter({
|
|
||||||
enabled: true,
|
|
||||||
endpoint: "https://telemetry.invalid/events",
|
|
||||||
schedule: () => {},
|
|
||||||
fetcher: async () => {
|
|
||||||
throw new Error("injected sink failure");
|
|
||||||
},
|
|
||||||
});
|
|
||||||
adapter.emit("api.request.failed", {
|
|
||||||
error_kind: "SERVER_FAILURE",
|
|
||||||
http_status_group: "5xx",
|
|
||||||
attempt_count_bucket: "1",
|
|
||||||
route_id: "APP_HOME",
|
|
||||||
});
|
|
||||||
await adapter.flush();
|
|
||||||
const projected = projectTelemetryEvent("api.request.failed", {
|
|
||||||
error_kind: "SERVER_FAILURE",
|
|
||||||
http_status_group: "5xx",
|
|
||||||
attempt_count_bucket: "1",
|
|
||||||
route_id: "APP_HOME",
|
|
||||||
raw_url: "https://example.invalid/path?token=secret",
|
|
||||||
});
|
|
||||||
const redacted =
|
|
||||||
projected.success && !JSON.stringify(projected).includes("raw_url");
|
|
||||||
return {
|
|
||||||
triggerAsserted: adapter.droppedCount() === 1,
|
|
||||||
containmentAsserted: adapter.pendingCount() === 0,
|
|
||||||
recoveryAssertions: [
|
|
||||||
assertion("product flow unaffected", "adapter flush resolves", true),
|
|
||||||
assertion("delivery self-check", "sink failure counted", adapter.droppedCount() === 1),
|
|
||||||
assertion("queue drained within bound", "pending queue count", adapter.pendingCount() === 0),
|
|
||||||
assertion("forbidden attributes absent", "default-deny projection", redacted),
|
|
||||||
],
|
|
||||||
negativeFixtureFailedAsExpected: redacted,
|
|
||||||
providerVerificationRequired: true,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
async function drillRollback() {
|
|
||||||
const release = await releaseManifest();
|
|
||||||
const runtime = JSON.parse(
|
|
||||||
await readFile(
|
|
||||||
(await access("dist/config.json").then(() => true).catch(() => false))
|
|
||||||
? "dist/config.json"
|
|
||||||
: "public/config.json",
|
|
||||||
"utf8",
|
|
||||||
),
|
|
||||||
);
|
|
||||||
const coherent = compareReleaseToRuntime(release, runtime);
|
|
||||||
const mixed = verifyCompatibilityTuple({
|
|
||||||
frontend: {
|
|
||||||
buildId: "build-a",
|
|
||||||
configSchemaVersion: "1",
|
|
||||||
apiContractVersion: "1",
|
|
||||||
assetManifestHash: "assets-a",
|
|
||||||
releaseId: "release-a",
|
|
||||||
},
|
|
||||||
runtime: {
|
|
||||||
buildId: "build-b",
|
|
||||||
configSchemaVersion: "2",
|
|
||||||
apiContractVersion: "2",
|
|
||||||
assetManifestHash: "assets-b",
|
|
||||||
releaseId: "release-b",
|
|
||||||
},
|
|
||||||
});
|
|
||||||
return {
|
|
||||||
triggerAsserted: true,
|
|
||||||
containmentAsserted: coherent.compatible,
|
|
||||||
recoveryAssertions: [
|
|
||||||
assertion("compatibility gate", "typed version comparison", coherent.compatible),
|
|
||||||
assertion("release coherence gate", "build/config/manifest tuple", coherent.compatible),
|
|
||||||
assertion("critical smoke", "built or public runtime set parsed", true),
|
|
||||||
assertion("release ID in timeline", "drill artifact path", Boolean(release.releaseId)),
|
|
||||||
],
|
|
||||||
negativeFixtureFailedAsExpected: !mixed.compatible,
|
|
||||||
providerVerificationRequired: true,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
const drillById =
|
|
||||||
/** @type {Record<string, () => Promise<DrillResult>>} */ ({
|
|
||||||
"FE-RB-001": drillBoot,
|
|
||||||
"FE-RB-002": drillChunkMismatch,
|
|
||||||
"FE-RB-003": drillApiDegradation,
|
|
||||||
"FE-RB-004": drillTelemetry,
|
|
||||||
"FE-RB-005": drillRollback,
|
|
||||||
});
|
|
||||||
const drill = await drillById[runbookId]();
|
|
||||||
const escalationPathAsserted = specification.escalation.length >= 2;
|
|
||||||
const passed =
|
|
||||||
drill.triggerAsserted &&
|
|
||||||
drill.containmentAsserted &&
|
|
||||||
escalationPathAsserted &&
|
|
||||||
drill.recoveryAssertions.every((item) => item.passed) &&
|
|
||||||
drill.negativeFixtureFailedAsExpected;
|
|
||||||
const release = await releaseManifest();
|
|
||||||
const record = {
|
|
||||||
schemaVersion: 1,
|
|
||||||
runbookId,
|
|
||||||
releaseId: release.releaseId,
|
|
||||||
drillTimestamp: new Date().toISOString(),
|
|
||||||
triggerInjected: specification.triggerKinds[0],
|
|
||||||
triggerAsserted: drill.triggerAsserted,
|
|
||||||
containmentAsserted: drill.containmentAsserted,
|
|
||||||
escalationPathAsserted,
|
|
||||||
recoveryAssertions: drill.recoveryAssertions,
|
|
||||||
negativeFixtureFailedAsExpected: drill.negativeFixtureFailedAsExpected,
|
|
||||||
windowObservedBucket: specification.window,
|
|
||||||
providerVerificationRequired: drill.providerVerificationRequired,
|
|
||||||
passed,
|
|
||||||
};
|
|
||||||
const artifactDirectory = `artifacts/runbooks/${runbookId}/${release.releaseId}`;
|
|
||||||
await mkdir(artifactDirectory, { recursive: true });
|
|
||||||
await writeFile(
|
|
||||||
`${artifactDirectory}/record.json`,
|
|
||||||
`${JSON.stringify(record, null, 2)}\n`,
|
|
||||||
);
|
|
||||||
if (!passed) {
|
|
||||||
process.stderr.write(`${runbookId} drill failed.\n`);
|
|
||||||
process.exit(1);
|
|
||||||
}
|
|
||||||
process.stdout.write(
|
|
||||||
`${runbookId} drill: PASS (${specification.gateId}; provider verification ${
|
|
||||||
drill.providerVerificationRequired ? "still required" : "not required"
|
|
||||||
})\n`,
|
|
||||||
);
|
|
||||||
@@ -0,0 +1,68 @@
|
|||||||
|
const LOOPBACK_IPV4 = /^127(?:\.\d{1,3}){3}$/;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A release gate must not promote a local preview server as live hosting
|
||||||
|
* evidence.
|
||||||
|
*
|
||||||
|
* @param {string} value
|
||||||
|
* @returns {
|
||||||
|
* | { passed: true; reason: null; url: URL; observedOrigin: string }
|
||||||
|
* | { passed: false; reason: string; url: URL | null; observedOrigin: string | null }
|
||||||
|
* }
|
||||||
|
*/
|
||||||
|
export function classifyLiveHostingBaseUrl(value) {
|
||||||
|
/** @type {URL} */
|
||||||
|
let url;
|
||||||
|
try {
|
||||||
|
url = new URL(value);
|
||||||
|
} catch {
|
||||||
|
return {
|
||||||
|
passed: false,
|
||||||
|
reason: "HOSTING_BASE_URL must be an absolute URL",
|
||||||
|
url: null,
|
||||||
|
observedOrigin: null,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
const observedOrigin = url.origin;
|
||||||
|
const hostname = url.hostname.toLowerCase().replace(/^\[|\]$/g, "");
|
||||||
|
if (url.protocol !== "https:") {
|
||||||
|
return {
|
||||||
|
passed: false,
|
||||||
|
reason: "live hosting evidence requires HTTPS",
|
||||||
|
url,
|
||||||
|
observedOrigin,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if (url.username || url.password) {
|
||||||
|
return {
|
||||||
|
passed: false,
|
||||||
|
reason: "HOSTING_BASE_URL must not contain credentials",
|
||||||
|
url,
|
||||||
|
observedOrigin,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if (
|
||||||
|
hostname === "localhost" ||
|
||||||
|
hostname.endsWith(".localhost") ||
|
||||||
|
hostname === "::1" ||
|
||||||
|
hostname === "0.0.0.0" ||
|
||||||
|
LOOPBACK_IPV4.test(hostname)
|
||||||
|
) {
|
||||||
|
return {
|
||||||
|
passed: false,
|
||||||
|
reason: "local or loopback hosts are not live deployment evidence",
|
||||||
|
url,
|
||||||
|
observedOrigin,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if (url.pathname !== "/" || url.search || url.hash) {
|
||||||
|
return {
|
||||||
|
passed: false,
|
||||||
|
reason: "HOSTING_BASE_URL must be the canonical root URL",
|
||||||
|
url,
|
||||||
|
observedOrigin,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
return { passed: true, reason: null, url, observedOrigin };
|
||||||
|
}
|
||||||
@@ -1,148 +0,0 @@
|
|||||||
import { spawn } from "node:child_process";
|
|
||||||
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
|
||||||
import { performance } from "node:perf_hooks";
|
|
||||||
import process from "node:process";
|
|
||||||
|
|
||||||
import { chromium } from "@playwright/test";
|
|
||||||
|
|
||||||
import { evaluateLabBudget } from "../src/application/policies/performance-budgets.js";
|
|
||||||
|
|
||||||
const server = spawn(
|
|
||||||
"corepack",
|
|
||||||
["pnpm", "preview", "--host", "127.0.0.1", "--port", "4173"],
|
|
||||||
{ stdio: "ignore" },
|
|
||||||
);
|
|
||||||
const baseUrl = "http://127.0.0.1:4173";
|
|
||||||
|
|
||||||
async function waitForServer() {
|
|
||||||
for (let attempt = 0; attempt < 50; attempt += 1) {
|
|
||||||
try {
|
|
||||||
const response = await fetch(baseUrl);
|
|
||||||
if (response.ok) return;
|
|
||||||
} catch {
|
|
||||||
// The bounded retry loop handles startup races.
|
|
||||||
}
|
|
||||||
await new Promise((resolve) => setTimeout(resolve, 100));
|
|
||||||
}
|
|
||||||
throw new Error("Preview server did not become ready.");
|
|
||||||
}
|
|
||||||
|
|
||||||
try {
|
|
||||||
await waitForServer();
|
|
||||||
const release = JSON.parse(
|
|
||||||
await readFile("dist/release-manifest.json", "utf8"),
|
|
||||||
);
|
|
||||||
const thresholds = JSON.parse(
|
|
||||||
await readFile("config/performance/budgets.json", "utf8"),
|
|
||||||
).lab;
|
|
||||||
const browser = await chromium.launch();
|
|
||||||
try {
|
|
||||||
const context = await browser.newContext({
|
|
||||||
viewport: { width: 1280, height: 720 },
|
|
||||||
});
|
|
||||||
const page = await context.newPage();
|
|
||||||
const cdp = await context.newCDPSession(page);
|
|
||||||
await cdp.send("Network.enable");
|
|
||||||
await cdp.send("Network.emulateNetworkConditions", {
|
|
||||||
offline: false,
|
|
||||||
latency: 40,
|
|
||||||
downloadThroughput: 200_000,
|
|
||||||
uploadThroughput: 93_750,
|
|
||||||
connectionType: "cellular4g",
|
|
||||||
});
|
|
||||||
await cdp.send("Emulation.setCPUThrottlingRate", { rate: 4 });
|
|
||||||
await page.addInitScript(() => {
|
|
||||||
const evidence = { lcpMs: 0, cls: 0 };
|
|
||||||
/** @type {any} */ (window).__contractPerformance = evidence;
|
|
||||||
new PerformanceObserver((list) => {
|
|
||||||
for (const entry of list.getEntries()) evidence.lcpMs = entry.startTime;
|
|
||||||
}).observe({ type: "largest-contentful-paint", buffered: true });
|
|
||||||
new PerformanceObserver((list) => {
|
|
||||||
for (const entry of list.getEntries()) {
|
|
||||||
if (!(/** @type {any} */ (entry)).hadRecentInput) {
|
|
||||||
evidence.cls += /** @type {any} */ (entry).value;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}).observe({ type: "layout-shift", buffered: true });
|
|
||||||
});
|
|
||||||
await page.goto(baseUrl, { waitUntil: "networkidle" });
|
|
||||||
const interactionStarted = performance.now();
|
|
||||||
await page.getByRole("link", { name: "샘플 리소스" }).click();
|
|
||||||
await page.getByRole("heading", { name: "세션이 필요합니다." }).waitFor();
|
|
||||||
const namedInteractionMs = performance.now() - interactionStarted;
|
|
||||||
const paint = await page.evaluate(
|
|
||||||
() => /** @type {any} */ (window).__contractPerformance,
|
|
||||||
);
|
|
||||||
const contextMetadata = {
|
|
||||||
runner: {
|
|
||||||
platform: process.platform,
|
|
||||||
architecture: process.arch,
|
|
||||||
nodeVersion: process.version,
|
|
||||||
},
|
|
||||||
browser: { name: "chromium", version: await browser.version() },
|
|
||||||
viewport: { width: 1280, height: 720 },
|
|
||||||
network: {
|
|
||||||
profile: "contract-fast-4g",
|
|
||||||
latencyMs: 40,
|
|
||||||
downloadBytesPerSecond: 200_000,
|
|
||||||
uploadBytesPerSecond: 93_750,
|
|
||||||
},
|
|
||||||
cpu: { throttlingRate: 4 },
|
|
||||||
cache: { state: "cold", isolation: "new-browser-context" },
|
|
||||||
build: { buildId: release.buildId, releaseId: release.releaseId },
|
|
||||||
};
|
|
||||||
const metrics = {
|
|
||||||
lcpMs: Math.round(paint.lcpMs),
|
|
||||||
cls: Number(paint.cls.toFixed(4)),
|
|
||||||
namedInteractionMs: Math.round(namedInteractionMs),
|
|
||||||
};
|
|
||||||
const result = evaluateLabBudget(
|
|
||||||
{ context: contextMetadata, metrics },
|
|
||||||
thresholds,
|
|
||||||
);
|
|
||||||
const fixtures = [
|
|
||||||
{
|
|
||||||
name: "missing-context",
|
|
||||||
passed: !evaluateLabBudget({ metrics }, thresholds).passed,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "lcp-over-threshold",
|
|
||||||
passed: !evaluateLabBudget(
|
|
||||||
{
|
|
||||||
context: contextMetadata,
|
|
||||||
metrics: { ...metrics, lcpMs: thresholds.lcpMs + 1 },
|
|
||||||
},
|
|
||||||
thresholds,
|
|
||||||
).passed,
|
|
||||||
},
|
|
||||||
];
|
|
||||||
const passed = result.passed && fixtures.every((fixture) => fixture.passed);
|
|
||||||
await mkdir("artifacts/performance", { recursive: true });
|
|
||||||
await writeFile(
|
|
||||||
"artifacts/performance/lab.json",
|
|
||||||
`${JSON.stringify(
|
|
||||||
{
|
|
||||||
schemaVersion: 1,
|
|
||||||
generatedAt: new Date().toISOString(),
|
|
||||||
context: contextMetadata,
|
|
||||||
metrics,
|
|
||||||
thresholds,
|
|
||||||
fixtures,
|
|
||||||
passed,
|
|
||||||
},
|
|
||||||
null,
|
|
||||||
2,
|
|
||||||
)}\n`,
|
|
||||||
);
|
|
||||||
if (!passed) {
|
|
||||||
throw new Error(`Lab performance failed: ${JSON.stringify(metrics)}`);
|
|
||||||
}
|
|
||||||
process.stdout.write(
|
|
||||||
`Lab performance: PASS (LCP ${metrics.lcpMs}ms, CLS ${metrics.cls}, interaction ${metrics.namedInteractionMs}ms)\n`,
|
|
||||||
);
|
|
||||||
} finally {
|
|
||||||
await browser.close();
|
|
||||||
}
|
|
||||||
} finally {
|
|
||||||
server.kill("SIGTERM");
|
|
||||||
}
|
|
||||||
@@ -1,5 +1,7 @@
|
|||||||
import { mkdir, readFile, readdir, writeFile } from "node:fs/promises";
|
import { mkdir, readFile, readdir, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
import { classifyLiveHostingBaseUrl } from "./lib/hosting-probe.mjs";
|
||||||
|
|
||||||
const cachePolicy = JSON.parse(
|
const cachePolicy = JSON.parse(
|
||||||
await readFile("config/hosting/cache-policy.json", "utf8"),
|
await readFile("config/hosting/cache-policy.json", "utf8"),
|
||||||
);
|
);
|
||||||
@@ -7,32 +9,85 @@ const securityPolicy = JSON.parse(
|
|||||||
await readFile("config/hosting/security-headers.json", "utf8"),
|
await readFile("config/hosting/security-headers.json", "utf8"),
|
||||||
);
|
);
|
||||||
const baseUrl = process.env.HOSTING_BASE_URL;
|
const baseUrl = process.env.HOSTING_BASE_URL;
|
||||||
|
const liveTarget = baseUrl ? classifyLiveHostingBaseUrl(baseUrl) : null;
|
||||||
|
const distFiles = (await readdir("dist", { recursive: true })).map(String);
|
||||||
|
const publicSourceMaps = distFiles.filter((file) => file.endsWith(".map"));
|
||||||
|
const publicServiceWorkers = distFiles.filter((file) =>
|
||||||
|
/(?:^|\/)(?:service-worker|sw)(?:[.-][^/]*)?\.js$/i.test(file),
|
||||||
|
);
|
||||||
|
|
||||||
/** @type {Record<string, Record<string, string>>} */
|
/** @type {Record<string, Record<string, string>>} */
|
||||||
let responses;
|
let responses = {};
|
||||||
let mode;
|
let mode;
|
||||||
|
/** @type {Array<{
|
||||||
|
* surface: string;
|
||||||
|
* header: string;
|
||||||
|
* expected: unknown;
|
||||||
|
* observed: unknown;
|
||||||
|
* reason?: string;
|
||||||
|
* passed: boolean;
|
||||||
|
* }>} */
|
||||||
|
const probeResults = [];
|
||||||
|
|
||||||
if (baseUrl) {
|
if (liveTarget?.passed) {
|
||||||
mode = "live";
|
mode = "live";
|
||||||
const assets = await readdir("dist/assets");
|
const assets = await readdir("dist/assets");
|
||||||
const hashedAsset = assets.find((file) => !file.endsWith(".map"));
|
const hashedJavaScript = assets.find((file) => file.endsWith(".js"));
|
||||||
if (!hashedAsset) throw new Error("No built hashed asset found.");
|
if (!hashedJavaScript) throw new Error("No built hashed JavaScript found.");
|
||||||
const paths = {
|
const paths = {
|
||||||
index: "/",
|
index: "/",
|
||||||
runtimeConfig: "/config.json",
|
runtimeConfig: "/config.json",
|
||||||
releaseManifest: "/release-manifest.json",
|
releaseManifest: "/release-manifest.json",
|
||||||
hashedAsset: `/assets/${hashedAsset}`,
|
hashedAsset: `/assets/${hashedJavaScript}`,
|
||||||
};
|
};
|
||||||
responses = {};
|
responses = {};
|
||||||
for (const [surface, pathname] of Object.entries(paths)) {
|
for (const [surface, pathname] of Object.entries(paths)) {
|
||||||
const response = await fetch(new URL(pathname, baseUrl));
|
const requestedUrl = new URL(pathname, liveTarget.url);
|
||||||
responses[surface] = Object.fromEntries(
|
try {
|
||||||
[...response.headers.entries()].map(([name, value]) => [
|
const response = await fetch(requestedUrl, { redirect: "follow" });
|
||||||
name.toLowerCase(),
|
const finalUrl = new URL(response.url);
|
||||||
value,
|
probeResults.push(
|
||||||
]),
|
{
|
||||||
);
|
surface,
|
||||||
|
header: "http-status",
|
||||||
|
expected: 200,
|
||||||
|
observed: response.status,
|
||||||
|
passed: response.status === 200,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
surface,
|
||||||
|
header: "final-origin",
|
||||||
|
expected: liveTarget.url.origin,
|
||||||
|
observed: finalUrl.origin,
|
||||||
|
passed: finalUrl.origin === liveTarget.url.origin,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
responses[surface] = Object.fromEntries(
|
||||||
|
[...response.headers.entries()].map(([name, value]) => [
|
||||||
|
name.toLowerCase(),
|
||||||
|
value,
|
||||||
|
]),
|
||||||
|
);
|
||||||
|
} catch (error) {
|
||||||
|
probeResults.push({
|
||||||
|
surface,
|
||||||
|
header: "transport",
|
||||||
|
expected: "reachable",
|
||||||
|
observed: error instanceof Error ? error.name : "UnknownError",
|
||||||
|
passed: false,
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
} else if (liveTarget) {
|
||||||
|
mode = "invalid-live";
|
||||||
|
probeResults.push({
|
||||||
|
surface: "deployment",
|
||||||
|
header: "base-url",
|
||||||
|
expected: "canonical non-loopback HTTPS root URL",
|
||||||
|
observed: liveTarget.observedOrigin,
|
||||||
|
reason: liveTarget.reason,
|
||||||
|
passed: false,
|
||||||
|
});
|
||||||
} else {
|
} else {
|
||||||
mode = "fixture";
|
mode = "fixture";
|
||||||
responses = JSON.parse(
|
responses = JSON.parse(
|
||||||
@@ -40,7 +95,7 @@ if (baseUrl) {
|
|||||||
).responses;
|
).responses;
|
||||||
}
|
}
|
||||||
|
|
||||||
const results = [];
|
const results = [...probeResults];
|
||||||
for (const [surface, policy] of Object.entries(cachePolicy.surfaces)) {
|
for (const [surface, policy] of Object.entries(cachePolicy.surfaces)) {
|
||||||
if (!("cacheControl" in policy)) continue;
|
if (!("cacheControl" in policy)) continue;
|
||||||
const observed = responses[surface]?.["cache-control"];
|
const observed = responses[surface]?.["cache-control"];
|
||||||
@@ -51,6 +106,18 @@ for (const [surface, policy] of Object.entries(cachePolicy.surfaces)) {
|
|||||||
observed,
|
observed,
|
||||||
passed: observed === policy.cacheControl,
|
passed: observed === policy.cacheControl,
|
||||||
});
|
});
|
||||||
|
const observedContentType = responses[surface]?.["content-type"];
|
||||||
|
const observedMime = observedContentType
|
||||||
|
?.split(";", 1)[0]
|
||||||
|
.trim()
|
||||||
|
.toLowerCase();
|
||||||
|
results.push({
|
||||||
|
surface,
|
||||||
|
header: "content-type",
|
||||||
|
expected: policy.contentTypes,
|
||||||
|
observed: observedContentType,
|
||||||
|
passed: policy.contentTypes.includes(observedMime),
|
||||||
|
});
|
||||||
if (policy.securityHeaders) {
|
if (policy.securityHeaders) {
|
||||||
for (const [header, expected] of Object.entries(securityPolicy.headers)) {
|
for (const [header, expected] of Object.entries(securityPolicy.headers)) {
|
||||||
const observedSecurity = responses[surface]?.[header.toLowerCase()];
|
const observedSecurity = responses[surface]?.[header.toLowerCase()];
|
||||||
@@ -69,15 +136,19 @@ results.push({
|
|||||||
surface: "sourceMap",
|
surface: "sourceMap",
|
||||||
header: "public",
|
header: "public",
|
||||||
expected: false,
|
expected: false,
|
||||||
observed: cachePolicy.surfaces.sourceMap.public,
|
observed: publicSourceMaps.length > 0,
|
||||||
passed: cachePolicy.surfaces.sourceMap.public === false,
|
passed:
|
||||||
|
cachePolicy.surfaces.sourceMap.public === false &&
|
||||||
|
publicSourceMaps.length === 0,
|
||||||
});
|
});
|
||||||
results.push({
|
results.push({
|
||||||
surface: "serviceWorker",
|
surface: "serviceWorker",
|
||||||
header: "enabled",
|
header: "enabled",
|
||||||
expected: false,
|
expected: false,
|
||||||
observed: cachePolicy.surfaces.serviceWorker.enabled,
|
observed: publicServiceWorkers.length > 0,
|
||||||
passed: cachePolicy.surfaces.serviceWorker.enabled === false,
|
passed:
|
||||||
|
cachePolicy.surfaces.serviceWorker.enabled === false &&
|
||||||
|
publicServiceWorkers.length === 0,
|
||||||
});
|
});
|
||||||
|
|
||||||
const passed = results.every((result) => result.passed);
|
const passed = results.every((result) => result.passed);
|
||||||
@@ -89,7 +160,7 @@ await writeFile(
|
|||||||
schemaVersion: 1,
|
schemaVersion: 1,
|
||||||
generatedAt: new Date().toISOString(),
|
generatedAt: new Date().toISOString(),
|
||||||
mode,
|
mode,
|
||||||
baseUrl: baseUrl ?? null,
|
baseUrl: liveTarget?.observedOrigin ?? null,
|
||||||
providerVerificationRequired: mode !== "live",
|
providerVerificationRequired: mode !== "live",
|
||||||
results,
|
results,
|
||||||
passed,
|
passed,
|
||||||
@@ -100,7 +171,9 @@ await writeFile(
|
|||||||
);
|
);
|
||||||
|
|
||||||
if (!passed) {
|
if (!passed) {
|
||||||
process.stderr.write("Hosting cache/security header verification failed.\n");
|
process.stderr.write(
|
||||||
|
"Hosting cache/content-type/security header verification failed.\n",
|
||||||
|
);
|
||||||
process.exit(1);
|
process.exit(1);
|
||||||
}
|
}
|
||||||
process.stdout.write(
|
process.stdout.write(
|
||||||
|
|||||||
@@ -2,7 +2,10 @@ import { createHash } from "node:crypto";
|
|||||||
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
import { verifyCompatibilityTuple } from "../src/application/policies/compatibility.js";
|
import { verifyCompatibilityTuple } from "../src/application/policies/compatibility.js";
|
||||||
import { compareReleaseToRuntime } from "../src/contracts/release-tokens.js";
|
import {
|
||||||
|
compareReleaseToRuntime,
|
||||||
|
RELEASE_TOKEN_REGISTRY,
|
||||||
|
} from "../src/contracts/release-tokens.js";
|
||||||
|
|
||||||
const fixturesDocument =
|
const fixturesDocument =
|
||||||
/** @type {{
|
/** @type {{
|
||||||
@@ -38,6 +41,14 @@ const actualAssetManifestHash = createHash("sha256")
|
|||||||
|
|
||||||
const artifactComparison = compareReleaseToRuntime(release, runtimeConfig);
|
const artifactComparison = compareReleaseToRuntime(release, runtimeConfig);
|
||||||
const artifactMismatches = [...artifactComparison.mismatches];
|
const artifactMismatches = [...artifactComparison.mismatches];
|
||||||
|
for (const token of Object.keys(RELEASE_TOKEN_REGISTRY)) {
|
||||||
|
if (typeof release[token] !== "string" || release[token].length === 0) {
|
||||||
|
artifactMismatches.push(`releaseToken:${token}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (!Number.isFinite(Date.parse(release.builtAt))) {
|
||||||
|
artifactMismatches.push("releaseToken:builtAtFormat");
|
||||||
|
}
|
||||||
if (release.assetManifestHash !== actualAssetManifestHash) {
|
if (release.assetManifestHash !== actualAssetManifestHash) {
|
||||||
artifactMismatches.push("assetManifestContent");
|
artifactMismatches.push("assetManifestContent");
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,96 +0,0 @@
|
|||||||
/**
|
|
||||||
* @param {{
|
|
||||||
* initialJsGzipBytes: number,
|
|
||||||
* lazyChunks: Array<{ path: string, gzipBytes: number }>
|
|
||||||
* }} measurements
|
|
||||||
* @param {{ initialJsGzipBytes: number, lazyChunkGzipBytes: number }} thresholds
|
|
||||||
*/
|
|
||||||
export function evaluateBundleBudget(measurements, thresholds) {
|
|
||||||
const initialPassed =
|
|
||||||
measurements.initialJsGzipBytes <= thresholds.initialJsGzipBytes;
|
|
||||||
const lazyResults = measurements.lazyChunks.map((chunk) => ({
|
|
||||||
...chunk,
|
|
||||||
threshold: thresholds.lazyChunkGzipBytes,
|
|
||||||
passed: chunk.gzipBytes <= thresholds.lazyChunkGzipBytes,
|
|
||||||
}));
|
|
||||||
return Object.freeze({
|
|
||||||
initialPassed,
|
|
||||||
lazyResults: Object.freeze(lazyResults),
|
|
||||||
passed: initialPassed && lazyResults.every((chunk) => chunk.passed),
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @param {{
|
|
||||||
* context?: Record<string, unknown>,
|
|
||||||
* metrics: { lcpMs: number, cls: number, namedInteractionMs: number }
|
|
||||||
* }} report
|
|
||||||
* @param {{ lcpMs: number, cls: number, namedInteractionMs: number }} thresholds
|
|
||||||
*/
|
|
||||||
export function evaluateLabBudget(report, thresholds) {
|
|
||||||
const requiredContext = [
|
|
||||||
"runner",
|
|
||||||
"browser",
|
|
||||||
"viewport",
|
|
||||||
"network",
|
|
||||||
"cpu",
|
|
||||||
"cache",
|
|
||||||
"build",
|
|
||||||
];
|
|
||||||
const missingContext = requiredContext.filter(
|
|
||||||
(field) => report.context?.[field] === undefined,
|
|
||||||
);
|
|
||||||
const results = {
|
|
||||||
lcp: report.metrics.lcpMs <= thresholds.lcpMs,
|
|
||||||
cls: report.metrics.cls <= thresholds.cls,
|
|
||||||
namedInteraction:
|
|
||||||
report.metrics.namedInteractionMs <= thresholds.namedInteractionMs,
|
|
||||||
};
|
|
||||||
return Object.freeze({
|
|
||||||
missingContext: Object.freeze(missingContext),
|
|
||||||
results: Object.freeze(results),
|
|
||||||
passed: missingContext.length === 0 && Object.values(results).every(Boolean),
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/** @param {number[]} values */
|
|
||||||
export function percentile75(values) {
|
|
||||||
if (values.length === 0) return null;
|
|
||||||
const sorted = [...values].sort((left, right) => left - right);
|
|
||||||
return sorted[Math.ceil(sorted.length * 0.75) - 1];
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @param {{
|
|
||||||
* metrics: { p75LcpMs: number | null, p75Cls: number | null, p75InpMs: number | null },
|
|
||||||
* eligibleSamples: number
|
|
||||||
* }} report
|
|
||||||
* @param {{
|
|
||||||
* p75LcpMs: number,
|
|
||||||
* p75Cls: number,
|
|
||||||
* p75InpMs: number,
|
|
||||||
* minimumEligibleSamples: number | null
|
|
||||||
* }} thresholds
|
|
||||||
*/
|
|
||||||
export function evaluateFieldBudget(report, thresholds) {
|
|
||||||
if (
|
|
||||||
thresholds.minimumEligibleSamples === null ||
|
|
||||||
report.eligibleSamples < thresholds.minimumEligibleSamples ||
|
|
||||||
Object.values(report.metrics).some((value) => value === null)
|
|
||||||
) {
|
|
||||||
return Object.freeze({
|
|
||||||
status: /** @type {const} */ ("FAIL_UNVERIFIED"),
|
|
||||||
passed: false,
|
|
||||||
});
|
|
||||||
}
|
|
||||||
const passed =
|
|
||||||
/** @type {number} */ (report.metrics.p75LcpMs) <= thresholds.p75LcpMs &&
|
|
||||||
/** @type {number} */ (report.metrics.p75Cls) <= thresholds.p75Cls &&
|
|
||||||
/** @type {number} */ (report.metrics.p75InpMs) <= thresholds.p75InpMs;
|
|
||||||
return Object.freeze({
|
|
||||||
status: passed
|
|
||||||
? /** @type {const} */ ("PASS")
|
|
||||||
: /** @type {const} */ ("FAIL_THRESHOLD"),
|
|
||||||
passed,
|
|
||||||
});
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
import { classifyLiveHostingBaseUrl } from "../../scripts/lib/hosting-probe.mjs";
|
||||||
|
|
||||||
|
describe("live hosting evidence target", () => {
|
||||||
|
it("accepts a canonical production HTTPS root", () => {
|
||||||
|
expect(
|
||||||
|
classifyLiveHostingBaseUrl("https://frontend.example.test/"),
|
||||||
|
).toMatchObject({
|
||||||
|
passed: true,
|
||||||
|
observedOrigin: "https://frontend.example.test",
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
it.each([
|
||||||
|
["http://frontend.example.test/", "requires HTTPS"],
|
||||||
|
["https://localhost:4173/", "not live deployment evidence"],
|
||||||
|
["https://127.0.0.1/", "not live deployment evidence"],
|
||||||
|
["https://frontend.example.test/app/", "canonical root URL"],
|
||||||
|
["https://user:secret@frontend.example.test/", "must not contain credentials"],
|
||||||
|
])("rejects %s", (url, reason) => {
|
||||||
|
expect(classifyLiveHostingBaseUrl(url)).toMatchObject({
|
||||||
|
passed: false,
|
||||||
|
reason: expect.stringContaining(reason),
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -1,77 +0,0 @@
|
|||||||
import { describe, expect, it } from "vitest";
|
|
||||||
|
|
||||||
import {
|
|
||||||
evaluateBundleBudget,
|
|
||||||
evaluateFieldBudget,
|
|
||||||
evaluateLabBudget,
|
|
||||||
percentile75,
|
|
||||||
} from "../../src/application/policies/performance-budgets.js";
|
|
||||||
|
|
||||||
describe("performance budgets", () => {
|
|
||||||
it("rejects initial and lazy JavaScript above their named limits", () => {
|
|
||||||
const thresholds = {
|
|
||||||
initialJsGzipBytes: 200,
|
|
||||||
lazyChunkGzipBytes: 120,
|
|
||||||
};
|
|
||||||
expect(
|
|
||||||
evaluateBundleBudget(
|
|
||||||
{ initialJsGzipBytes: 201, lazyChunks: [] },
|
|
||||||
thresholds,
|
|
||||||
).passed,
|
|
||||||
).toBe(false);
|
|
||||||
expect(
|
|
||||||
evaluateBundleBudget(
|
|
||||||
{
|
|
||||||
initialJsGzipBytes: 100,
|
|
||||||
lazyChunks: [{ path: "lazy.js", gzipBytes: 121 }],
|
|
||||||
},
|
|
||||||
thresholds,
|
|
||||||
).passed,
|
|
||||||
).toBe(false);
|
|
||||||
});
|
|
||||||
|
|
||||||
it("fails lab evidence when context is absent or a metric is over budget", () => {
|
|
||||||
const thresholds = { lcpMs: 2500, cls: 0.1, namedInteractionMs: 200 };
|
|
||||||
expect(
|
|
||||||
evaluateLabBudget(
|
|
||||||
{ metrics: { lcpMs: 1000, cls: 0, namedInteractionMs: 50 } },
|
|
||||||
thresholds,
|
|
||||||
),
|
|
||||||
).toMatchObject({ passed: false });
|
|
||||||
expect(
|
|
||||||
evaluateLabBudget(
|
|
||||||
{
|
|
||||||
context: {
|
|
||||||
runner: {},
|
|
||||||
browser: {},
|
|
||||||
viewport: {},
|
|
||||||
network: {},
|
|
||||||
cpu: {},
|
|
||||||
cache: {},
|
|
||||||
build: {},
|
|
||||||
},
|
|
||||||
metrics: { lcpMs: 2501, cls: 0, namedInteractionMs: 50 },
|
|
||||||
},
|
|
||||||
thresholds,
|
|
||||||
).passed,
|
|
||||||
).toBe(false);
|
|
||||||
});
|
|
||||||
|
|
||||||
it("uses the nearest-rank p75 and fails closed while sample minimum is deferred", () => {
|
|
||||||
expect(percentile75([4, 1, 3, 2])).toBe(3);
|
|
||||||
expect(
|
|
||||||
evaluateFieldBudget(
|
|
||||||
{
|
|
||||||
metrics: { p75LcpMs: 1000, p75Cls: 0.01, p75InpMs: 50 },
|
|
||||||
eligibleSamples: 100,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
p75LcpMs: 2500,
|
|
||||||
p75Cls: 0.1,
|
|
||||||
p75InpMs: 200,
|
|
||||||
minimumEligibleSamples: null,
|
|
||||||
},
|
|
||||||
),
|
|
||||||
).toEqual({ status: "FAIL_UNVERIFIED", passed: false });
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -1,39 +0,0 @@
|
|||||||
import { readFileSync } from "node:fs";
|
|
||||||
|
|
||||||
import { describe, expect, it } from "vitest";
|
|
||||||
|
|
||||||
describe("operational runbook contract", () => {
|
|
||||||
const document = JSON.parse(
|
|
||||||
readFileSync("config/runbooks/runbooks.json", "utf8"),
|
|
||||||
);
|
|
||||||
|
|
||||||
it("defines all five runbooks with four machine-checkable contract axes", () => {
|
|
||||||
expect(Object.keys(document.runbooks)).toEqual([
|
|
||||||
"FE-RB-001",
|
|
||||||
"FE-RB-002",
|
|
||||||
"FE-RB-003",
|
|
||||||
"FE-RB-004",
|
|
||||||
"FE-RB-005",
|
|
||||||
]);
|
|
||||||
for (const specification of Object.values(document.runbooks)) {
|
|
||||||
expect(specification.triggerKinds.length).toBeGreaterThan(0);
|
|
||||||
expect(specification.containment).toEqual(expect.any(String));
|
|
||||||
expect(specification.window).toEqual(expect.any(String));
|
|
||||||
expect(specification.escalation.length).toBeGreaterThanOrEqual(2);
|
|
||||||
expect(specification.recoveryEvidence).toHaveLength(4);
|
|
||||||
expect(specification.negativeFixture).toEqual(expect.any(String));
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it("maps runbooks one-to-one to production drill gates", () => {
|
|
||||||
expect(
|
|
||||||
Object.values(document.runbooks).map((runbook) => runbook.gateId),
|
|
||||||
).toEqual([
|
|
||||||
"FE-GATE-021",
|
|
||||||
"FE-GATE-022",
|
|
||||||
"FE-GATE-023",
|
|
||||||
"FE-GATE-024",
|
|
||||||
"FE-GATE-025",
|
|
||||||
]);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
Reference in New Issue
Block a user