🔧 e2e mock: address review — clarify backend flag, move ignore to root

- Document the --backend-addr flag: it is the stub upstream service Traefik
  proxies allowed requests to (the traefik/whoami equivalent), not AppSec.
- Move the .cache/ ignore rule from the per-suite .gitignore to the repo root
  .gitignore, and make the wording accurate: the cache persists across local
  runs but is recreated on every (fresh-runner) CI run.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
mhx
2026-06-06 12:03:19 +02:00
co-authored by Claude Opus 4.8
parent b201143844
commit 8580a085b9
5 changed files with 13 additions and 7 deletions
+4
View File
@@ -5,3 +5,7 @@ conf
db
logs
docker-compose.dev.yml
# Binary e2e suite working cache: Traefik binary + compiled mock. Persisted
# across local runs; CI runs on fresh runners so it is recreated every time.
tests/e2e/mock/.cache/
-2
View File
@@ -1,2 +0,0 @@
# Cached Traefik binary and compiled mock, produced on first run.
.cache/
+4 -3
View File
@@ -28,7 +28,7 @@ returns whatever decisions the test tells it to.
| Component | How |
|-----------|-----|
| Traefik | Binary `v3.7.1`, downloaded once and cached under `.cache/` |
| Traefik | Binary `v3.7.1`, downloaded into `.cache/` (reused across local runs; re-downloaded on fresh CI runners) |
| Plugin | Loaded via `experimental.localPlugins` from the repo root (symlinked into `plugins-local/`) |
| LAPI | `mocklapi` — a stdlib-only Go command (its own nested module), compiled and cached under `.cache/`, driven through `/admin` endpoints instead of `cscli` |
| Backend | A plain HTTP responder built into the mock |
@@ -38,8 +38,9 @@ backend `8091`.
## Running locally
Prerequisites: `bash`, `curl`, `go`, `tar`. The Traefik binary is fetched and
the mock is compiled automatically on first run (both cached under `.cache/`).
Prerequisites: `bash`, `curl`, `go`, `tar`. On first use the Traefik binary is
fetched and the mock is compiled into `.cache/`. That cache is reused across
local runs; CI runs on fresh runners, so both are recreated on every CI run.
```bash
# one scenario
+2 -1
View File
@@ -7,7 +7,8 @@
# IPs, ban / captcha rendering), NOT Crowdsec or AppSec correctness.
#
# Dependencies: bash, curl, go, tar. The Traefik binary is downloaded and the
# mock is compiled on first run (both cached), so local and CI behave the same.
# mock is compiled into .cache/ on first use. That cache persists across local
# runs; CI runs on fresh runners, so both are recreated on every CI run.
set -euo pipefail
+3 -1
View File
@@ -213,7 +213,9 @@ func backendHandler() http.Handler {
func main() {
lapiAddr := flag.String("lapi-addr", "127.0.0.1:8090", "address for the LAPI mock")
backendAddr := flag.String("backend-addr", "127.0.0.1:8091", "address for the backend responder")
// The stub upstream service Traefik proxies allowed requests to — the
// binary-suite equivalent of the traefik/whoami container. Not AppSec.
backendAddr := flag.String("backend-addr", "127.0.0.1:8091", "address of the stub upstream service Traefik proxies allowed requests to")
apiKey := flag.String("api-key", "e2e-mock-key", "expected X-Api-Key value")
flag.Parse()