Skip to content

Reference

Checks

Black-box checks prove an environment behaves the same on every target: services answer, logins work, blocked networks stay blocked.

Checks are scripts that test the environment from outside, the way a user would see it. They're what makes "same behavior on every target" verifiable.

checks:
  - checks/portal-answers.sh
  - checks/lan-is-blocked-from-outside.sh

Writing a check

A check is any executable script. It runs on the environment's networks, reaches machines by name, and exits 0 when the behavior holds:

#!/bin/sh
# The portal answers, and refuses a request without its API key.
set -eu
code=$(curl -s -o /dev/null -w '%{http_code}' http://web:8080/api/invoices/42)
[ "$code" = 401 ] || { echo "expected 401 without a key, got $code"; exit 1; }
curl -fsS -H "X-Api-Key: demo" http://web:8080/api/invoices/42 | grep -q amount
echo "portal answers and enforces its key"

Good checks test what should not happen too: a network that must stay unreachable, a service that must refuse anonymous access.

Where they run

Isoloom adds a small check runner to the targets it builds, attached to the environment's networks, so a project only ships the scripts. On Docker it's a check profile:

docker compose -f .isoloom/docker/compose.yml --profile check run --rm isoloom-check

In CI

The intended setup runs the checks on every change for the cheap target (Docker), and on the VM targets when the machines change. A target whose checks fail isn't offered.

Planned: the check runner for VM targets. On Vagrant today, run the scripts from one of the machines (vagrant ssh web -c 'cd /opt/isoloom && sh checks/…').