2a3bb6922d
Closes #46 once deployed. The headless browser leaves the API stack and becomes its own compose unit (`chrome/docker-compose.yml`) intended for the home machine, reached over the tailnet. No fallback sidecar is left on the VPS. The backend needs no code change — `BROWSER_WS_URL` was already the only coupling. Its default is now empty rather than a pinned Docker IP, so an unconfigured or unreachable browser degrades exactly as it always has: plain-TLS libraries unaffected, kagane/novelfull logged and skipped, stored covers still served. ### What shipped - `chrome/docker-compose.yml` + `chrome/.env.example` — the browser unit, with the CDP port bound to `${BROWSER_BIND_ADDR}` (no default) and the resource limits from the epic: 512 MiB / 1 GiB memory+swap, `oom_score_adj 800`, halved CPU weight, shm 1 GiB -> 128 MiB. - API stack drops the service, its `depends_on` and the `browser` network. - `bookmark-api` gains the `default` network. Dropping `browser` had left it on `db` alone, which is `internal: true` — no published port and, worse, no egress for the poller at all. Caught by actually bringing the stack up. - ADR-0006 for the topology; `DEPLOY.md` §7 for first-time setup of the browser machine; `REDEPLOY.md` §8 for its independent update cadence; architecture diagrams, config tables and troubleshooting rows across README/AGENTS/env. ### Verified locally - Browser unit builds and runs: Chrome 151, UA carries no `HeadlessChrome`, all limits applied as declared. - **Live smoke passes through the new unit**: `TestSmokeKaganeImage` fetched 56710 bytes of `image/webp`, `TestSmokeKaganeGet` got a 200 with a real chapter list. The challenge cleared under the reduced 128 MiB shm. - Bind isolation proven: refused on the host's non-loopback address, accepted on the configured one. - 321 MiB peak of the 512 MiB cap after a full solve; 0 restarts, no OOM kill. - API stack comes up clean, `/healthz` 200; egress confirmed present on `default` and absent on `db`. - `go test ./...`, `go vet`, `gofmt` clean. ### Left to the operator Provisioning the home machine, the Tailscale ACL, setting `BROWSER_WS_URL` in production, and observing acceptance criteria 5-7 (covers with the machine off, several days of zero OOM/restarts, VPS memory improvement). `DEPLOY.md` §7 now carries the before/after `free -m` reading those need. Reviewed-on: #52 Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com> Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
95 lines
3.0 KiB
Go
95 lines
3.0 KiB
Go
package latest
|
|
|
|
import (
|
|
"context"
|
|
"net/http"
|
|
"os"
|
|
"testing"
|
|
"time"
|
|
)
|
|
|
|
// TestSmokeKaganeImage is the live proof that the cover proxy's fetch actually
|
|
// clears Cloudflare and returns image bytes. It needs the real browser unit
|
|
// with outbound network, so it runs only when SMOKE_BROWSER_WS_URL is set:
|
|
//
|
|
// cd chrome && BROWSER_BIND_ADDR=127.0.0.1 docker compose up -d --build
|
|
// SMOKE_BROWSER_WS_URL=ws://127.0.0.1:9222 go test -run TestSmokeKaganeImage ./internal/latest
|
|
//
|
|
// Not chromedp/headless-shell: its challenge never clears (see chrome/Dockerfile),
|
|
// so a red run there proves nothing about kagane.
|
|
func TestSmokeKaganeImage(t *testing.T) {
|
|
ws := os.Getenv("SMOKE_BROWSER_WS_URL")
|
|
if ws == "" {
|
|
t.Skip("SMOKE_BROWSER_WS_URL unset")
|
|
}
|
|
const imageID = "019fe11a-84c3-7fc3-a84b-88787374b617" // SP Baby's cover
|
|
|
|
// The same URL through a plain client is what the web UI's <img> gets.
|
|
// Asserting on it keeps the test honest about why the browser is needed.
|
|
req, err := http.NewRequest(http.MethodGet,
|
|
"https://kagane.to/api/v2/image/"+imageID+"/compressed", nil)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if res, err := (&http.Client{Timeout: 15 * time.Second}).Do(req); err == nil {
|
|
res.Body.Close()
|
|
if res.StatusCode == http.StatusOK {
|
|
t.Log("note: kagane answered a plain request 200 — the challenge is not up right now")
|
|
}
|
|
}
|
|
|
|
f, err := NewBrowserFetcher(ws)
|
|
if err != nil {
|
|
t.Fatalf("NewBrowserFetcher: %v", err)
|
|
}
|
|
defer f.Close()
|
|
|
|
ctx, cancel := context.WithTimeout(context.Background(), 90*time.Second)
|
|
defer cancel()
|
|
body, contentType, err := f.Image(ctx, imageID)
|
|
if err != nil {
|
|
t.Fatalf("Image: %v", err)
|
|
}
|
|
if len(body) < 1000 {
|
|
t.Fatalf("body is %d bytes, want a real image", len(body))
|
|
}
|
|
if contentType != "image/webp" {
|
|
t.Fatalf("content type = %q, want image/webp", contentType)
|
|
}
|
|
// WebP files start with "RIFF....WEBP".
|
|
if string(body[:4]) != "RIFF" || string(body[8:12]) != "WEBP" {
|
|
t.Fatalf("body is not a WebP: % x", body[:12])
|
|
}
|
|
t.Logf("fetched %d bytes of %s", len(body), contentType)
|
|
|
|
if _, _, err := f.Image(ctx, "not-a-uuid"); err == nil {
|
|
t.Fatal("Image accepted a non-uuid id")
|
|
}
|
|
}
|
|
|
|
// Control for the test above: the poller's own kagane path, same sidecar. If
|
|
// this fails too, the sidecar is not clearing the challenge at all and the
|
|
// image result says nothing about Image itself.
|
|
func TestSmokeKaganeGet(t *testing.T) {
|
|
ws := os.Getenv("SMOKE_BROWSER_WS_URL")
|
|
if ws == "" {
|
|
t.Skip("SMOKE_BROWSER_WS_URL unset")
|
|
}
|
|
f, err := NewBrowserFetcher(ws)
|
|
if err != nil {
|
|
t.Fatalf("NewBrowserFetcher: %v", err)
|
|
}
|
|
defer f.Close()
|
|
|
|
ctx, cancel := context.WithTimeout(context.Background(), 90*time.Second)
|
|
defer cancel()
|
|
body, status, err := f.Get(ctx, "https://kagane.to/series/019fe11a-8670-7cf3-8343-0b02057d3787")
|
|
if err != nil {
|
|
t.Fatalf("Get: %v", err)
|
|
}
|
|
t.Logf("status=%d bytes=%d head=%.80q", status, len(body), body)
|
|
if status != 200 {
|
|
t.Fatalf("status = %d, want 200 — the sidecar is not clearing the challenge", status)
|
|
}
|
|
}
|