aprs.me/config/test.exs
Graham McIntire 0f2195ef9d
Some checks failed
Build and Push / Build and Push Docker Image (push) Failing after 2s
security: CSP nonces, RemoteIp CIDR gating, rate limiting, NetworkPolicies, deadlock fixes
- Content-Security-Policy: nonce-based per-request plug replacing unsafe-inline scripts
- RemoteIp: CIDR-based trust gating via InetCidr, skips forwarded headers from untrusted peers
- Rate limiting: auth pipeline (20/min), LiveView event handlers, existing mobile channel limits
- NetworkPolicy: 4 k8s policies (web ingress, cluster, metrics, egress) for least-privilege networking
- PartitionManager: deadlock retry with exponential backoff in drop_partition
- Tests: reduced parallelism (max_cases 4), packets_test async:false to prevent trigger contention
- k8s: APRS_PASSWORD -> APRS_PASSCODE secretRef, vendor/aprs submodule hardened
2026-07-26 14:04:56 -05:00

99 lines
3.4 KiB
Elixir

import Config
# Configure your database
#
# The MIX_TEST_PARTITION environment variable can be used
# to provide built-in test partitioning in CI environment.
# Run `mix help test` for more information.
# Reduce pool size when coverage is enabled to prevent file descriptor exhaustion
pool_size =
if System.get_env("MIX_TEST_COVERAGE") do
2
else
min(System.schedulers_online() * 2, 20)
end
# In test we don't send emails.
config :aprsme, Aprsme.Mailer, adapter: Swoosh.Adapters.Test
# Disable PromEx in test environment
config :aprsme, Aprsme.PromEx, disabled: true
config :aprsme, Aprsme.Repo,
username: "postgres",
password: "postgres",
hostname: "localhost",
database: "aprsme_test#{System.get_env("MIX_TEST_PARTITION")}",
pool: Ecto.Adapters.SQL.Sandbox,
pool_size: pool_size,
types: Aprsme.PostgresTypes,
ownership_timeout: 60_000,
timeout: 15_000,
queue_target: 50,
queue_interval: 100
# We don't run a server during test. If one is required,
# you can enable the server option below.
config :aprsme, AprsmeWeb.Endpoint,
adapter: Bandit.PhoenixAdapter,
http: [ip: {127, 0, 0, 1}, port: 4002],
secret_key_base: "IV9+ENaw9i8xjReRk4sULRvRgsmFVTGQwQGGrf4G+Q/SFMeHBCNWRlPXQ2YvT36R",
server: false
# RemoteIp plug: trust localhost so existing test behaviour is preserved.
# Tests that simulate untrusted peers override the trusted_proxies via init/1 opts.
config :aprsme, AprsmeWeb.Plugs.RemoteIp, trusted_proxies: ["127.0.0.0/8", "::1/128"]
# Disable cleanup scheduler in test environment
config :aprsme, :cleanup_scheduler, enabled: false
# Speed up ConnectionManager init in test environment
config :aprsme, :connection_manager_init_delay, 0
# Disable initialize replay delay in test environment
config :aprsme, :initialize_replay_delay, 0
# Configure the packets module to use the mock in tests
config :aprsme, :packets_module, Aprsme.PacketsMock
# Disable APRS-IS external connections and clustering in test environment
config :aprsme,
aprs_is_server: "mock.aprs.test",
aprs_is_port: 14_580,
aprs_is_default_filter: "r/33/-96/100",
aprs_is_login_id: "TEST",
aprs_is_password: "-1",
disable_aprs_connection: true,
cluster_enabled: false
# Disable automatic migrations during tests
config :aprsme, auto_migrate: false
config :aprsme, device_cache_initial_load_delay_ms: 0
# Short Req timeouts so HTTP calls fail fast without real network access.
# retry: false prevents Req's default exponential backoff (1s+2s+4s=7s).
config :aprsme, device_id_req_opts: [connect_options: [timeout: 50], receive_timeout: 50, retry: false]
config :aprsme, election_initial_delay_ms: 0
# Speed up time-sensitive delays in test environment
config :aprsme, is_call_timeout_ms: 100
config :aprsme, is_init_delay_ms: 0
# Only in tests, remove the complexity from the password hashing algorithm
config :bcrypt_elixir, :log_rounds, 1
# Disable ErrorTracker in test environment to avoid database ownership issues
config :error_tracker, enabled: false
# Configure Hammer for test environment
config :hammer,
backend: {Hammer.Backend.ETS, [expiry_ms: 60_000 * 60 * 4, cleanup_interval_ms: 60_000 * 10]}
# Disable logging during test for better performance
config :logger, level: :error
# Initialize plugs at runtime for faster test compilation
config :phoenix, :plug_init_mode, :runtime
# Disable swoosh api client as it is only required for production adapters.
config :swoosh, :api_client, false