|
| 1 | +# Viceroy local server configuration template for integration tests — |
| 2 | +# EdgeZero entry-point variant. |
| 3 | +# |
| 4 | +# Identical to `viceroy-template.toml` but adds the `trusted_server_config` |
| 5 | +# config store with `edgezero_enabled = "true"`, so the same WASM binary routes |
| 6 | +# requests through the EdgeZero entry point instead of the legacy path. Used by |
| 7 | +# the `integration-tests-edgezero` CI job (via `VICEROY_CONFIG_PATH`) to exercise |
| 8 | +# Fastly request conversion, config-store dispatch, and end-to-end EC wiring on |
| 9 | +# the EdgeZero path. Keep the shared stores in sync with `viceroy-template.toml`. |
| 10 | +# |
| 11 | +# This configures the Viceroy runtime itself (backends, KV stores, etc.), |
| 12 | +# separate from the application config (trusted-server.toml). |
| 13 | + |
| 14 | +[local_server] |
| 15 | + |
| 16 | + [local_server.backends] |
| 17 | + |
| 18 | + [local_server.kv_stores] |
| 19 | + # These inline placeholders satisfy Viceroy's local KV configuration |
| 20 | + # requirements without exercising KV-backed application behavior. |
| 21 | + [[local_server.kv_stores.counter_store]] |
| 22 | + key = "placeholder" |
| 23 | + data = "placeholder" |
| 24 | + |
| 25 | + [[local_server.kv_stores.opid_store]] |
| 26 | + key = "placeholder" |
| 27 | + data = "placeholder" |
| 28 | + |
| 29 | + [[local_server.kv_stores.creative_store]] |
| 30 | + key = "placeholder" |
| 31 | + data = "placeholder" |
| 32 | + |
| 33 | + [[local_server.kv_stores.ec_identity_store]] |
| 34 | + key = "placeholder" |
| 35 | + data = "placeholder" |
| 36 | + |
| 37 | + # Pre-seeded EC rows for KV-backed EC lifecycle tests. Each scenario |
| 38 | + # uses a separate row so withdrawal tombstones do not leak across |
| 39 | + # sequential scenario execution in the same Viceroy instance. |
| 40 | + [[local_server.kv_stores.ec_identity_store]] |
| 41 | + key = "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.test01" |
| 42 | + data = '{"v":1,"created":1700000000,"consent":{"ok":true,"updated":1700000000},"geo":{"country":"US","region":"CA"}}' |
| 43 | + |
| 44 | + [[local_server.kv_stores.ec_identity_store]] |
| 45 | + key = "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb.test02" |
| 46 | + data = '{"v":1,"created":1700000000,"consent":{"ok":true,"updated":1700000000},"geo":{"country":"US","region":"CA"}}' |
| 47 | + |
| 48 | + [[local_server.kv_stores.ec_identity_store]] |
| 49 | + key = "cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc.test03" |
| 50 | + data = '{"v":1,"created":1700000000,"consent":{"ok":true,"updated":1700000000},"geo":{"country":"US","region":"CA"}}' |
| 51 | + |
| 52 | + [[local_server.kv_stores.ec_identity_store]] |
| 53 | + key = "dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd.test04" |
| 54 | + data = '{"v":1,"created":1700000000,"consent":{"ok":true,"updated":1700000000},"geo":{"country":"US","region":"CA"}}' |
| 55 | + |
| 56 | + [[local_server.kv_stores.ec_identity_store]] |
| 57 | + key = "eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee.test05" |
| 58 | + data = '{"v":1,"created":1700000000,"consent":{"ok":true,"updated":1700000000},"geo":{"country":"US","region":"CA"}}' |
| 59 | + |
| 60 | + [[local_server.kv_stores.ec_partner_store]] |
| 61 | + key = "placeholder" |
| 62 | + data = "placeholder" |
| 63 | + |
| 64 | + # These are generated test-only key pairs, not production credentials. |
| 65 | + # The Ed25519 private key (data) and its matching public key (x in jwks_store below) |
| 66 | + # exist solely for signing and verifying tokens in the integration test environment. |
| 67 | + # They were generated specifically for testing and are safe to commit — they |
| 68 | + # have never been used in any production or staging environment. |
| 69 | + [local_server.secret_stores] |
| 70 | + [[local_server.secret_stores.signing_keys]] |
| 71 | + key = "ts-2025-10-A" |
| 72 | + data = "NVnTYrw5xoyTJDOwoUWoPJO3A6UCCXOJJUzgGTxxx7k=" |
| 73 | + |
| 74 | + [[local_server.secret_stores.api-keys]] |
| 75 | + key = "api_key" |
| 76 | + data = "test-api-key" |
| 77 | + |
| 78 | + [local_server.config_stores] |
| 79 | + # Routes requests through the EdgeZero entry point. `is_edgezero_enabled` |
| 80 | + # in the Fastly adapter reads this key at runtime; `"true"` (or `"1"`) |
| 81 | + # enables EdgeZero, anything else falls back to the legacy path. |
| 82 | + [local_server.config_stores.trusted_server_config] |
| 83 | + format = "inline-toml" |
| 84 | + [local_server.config_stores.trusted_server_config.contents] |
| 85 | + edgezero_enabled = "true" |
| 86 | + |
| 87 | + [local_server.config_stores.jwks_store] |
| 88 | + format = "inline-toml" |
| 89 | + [local_server.config_stores.jwks_store.contents] |
| 90 | + ts-2025-10-A = "{\"kty\":\"OKP\",\"crv\":\"Ed25519\",\"kid\":\"ts-2025-10-A\",\"use\":\"sig\",\"x\":\"UVTi04QLrIuB7jXpVfHjUTVN5aIdcbPNr50umTtN8pw\"}" |
| 91 | + ts-2025-10-B = "{\"kty\":\"OKP\",\"crv\":\"Ed25519\",\"kid\":\"ts-2025-10-B\",\"use\":\"sig\",\"x\":\"HVTi04QLrIuB7jXpVfHjUTVN5aIdcbPNr50umTtN8pw\"}" |
| 92 | + current-kid = "ts-2025-10-A" |
| 93 | + active-kids = "ts-2025-10-A,ts-2025-10-B" |
0 commit comments