@@ -155,6 +155,25 @@ def imported_provider_profile(
155155 _delete_provider_profile (stub , profile .id )
156156
157157
158+ def _endpointless_credential_profile (profile_id : str ) -> openshell_pb2 .ProviderProfile :
159+ """Build an endpointless credential profile without a platform adapter."""
160+ return openshell_pb2 .ProviderProfile (
161+ id = profile_id ,
162+ display_name = f"{ profile_id } display" ,
163+ category = openshell_pb2 .PROVIDER_PROFILE_CATEGORY_OTHER ,
164+ credentials = [
165+ openshell_pb2 .ProviderProfileCredential (
166+ name = "api_token" ,
167+ description = "E2E endpointless credential" ,
168+ env_vars = ["E2E_ENDPOINTLESS_TOKEN" ],
169+ required = True ,
170+ auth_style = "bearer" ,
171+ header_name = "authorization" ,
172+ )
173+ ],
174+ )
175+
176+
158177def _native_inference_profile (
159178 * ,
160179 profile_id : str ,
@@ -344,24 +363,33 @@ def test_endpointless_profile_credentials_fail_closed_without_policy_binding(
344363 sandbox_client : SandboxClient ,
345364) -> None :
346365 """Endpointless profile credentials are withheld without an explicit binding."""
347- with provider (
348- sandbox_client ._stub ,
349- name = "e2e-test-google-cloud-without-policy-binding" ,
350- provider_type = "google-cloud" ,
351- credentials = {"GCP_ADC_ACCESS_TOKEN" : "gcp-e2e-token" },
352- ) as provider_name :
366+ profile_id = "e2e-endpointless-without-policy-binding"
367+ with (
368+ imported_provider_profile (
369+ sandbox_client ._stub ,
370+ profile = _endpointless_credential_profile (profile_id ),
371+ source = f"{ profile_id } .yaml" ,
372+ ),
373+ provider (
374+ sandbox_client ._stub ,
375+ name = "e2e-test-endpointless-without-policy-binding" ,
376+ provider_type = profile_id ,
377+ credentials = {"E2E_ENDPOINTLESS_TOKEN" : "e2e-token" },
378+ profile_workspace = "default" ,
379+ ) as provider_name ,
380+ ):
353381 spec = datamodel_pb2 .SandboxSpec (
354382 policy = _default_policy (),
355383 providers = [provider_name ],
356384 )
357385
358- def read_gcp_token () -> str :
386+ def read_token () -> str :
359387 import os
360388
361- return os .environ .get ("GCP_ADC_ACCESS_TOKEN " , "NOT_SET" )
389+ return os .environ .get ("E2E_ENDPOINTLESS_TOKEN " , "NOT_SET" )
362390
363391 with sandbox (spec = spec , delete_on_exit = True ) as sb :
364- result = sb .exec_python (read_gcp_token )
392+ result = sb .exec_python (read_token )
365393 assert result .exit_code == 0 , result .stderr
366394 assert result .stdout .strip () == "NOT_SET"
367395
@@ -371,19 +399,28 @@ def test_endpointless_profile_credentials_use_explicit_policy_binding(
371399 sandbox_client : SandboxClient ,
372400) -> None :
373401 """An endpointless profile emits credentials only with an explicit binding."""
374- with provider (
375- sandbox_client ._stub ,
376- name = "e2e-test-google-cloud-policy-binding" ,
377- provider_type = "google-cloud" ,
378- credentials = {"GCP_ADC_ACCESS_TOKEN" : "gcp-e2e-token" },
379- ) as provider_name :
402+ profile_id = "e2e-endpointless-policy-binding"
403+ with (
404+ imported_provider_profile (
405+ sandbox_client ._stub ,
406+ profile = _endpointless_credential_profile (profile_id ),
407+ source = f"{ profile_id } .yaml" ,
408+ ),
409+ provider (
410+ sandbox_client ._stub ,
411+ name = "e2e-test-endpointless-policy-binding" ,
412+ provider_type = profile_id ,
413+ credentials = {"E2E_ENDPOINTLESS_TOKEN" : "e2e-token" },
414+ profile_workspace = "default" ,
415+ ) as provider_name ,
416+ ):
380417 policy = _default_policy ()
381- policy .network_policies ["gcp_storage " ].CopyFrom (
418+ policy .network_policies ["endpointless_api " ].CopyFrom (
382419 sandbox_pb2 .NetworkPolicyRule (
383- name = "gcp_storage " ,
420+ name = "endpointless_api " ,
384421 endpoints = [
385422 sandbox_pb2 .NetworkEndpoint (
386- host = "storage.googleapis .com" ,
423+ host = "api.example .com" ,
387424 port = 443 ,
388425 protocol = "rest" ,
389426 access = sandbox_pb2 .NETWORK_ACCESS_PRESET_FULL ,
@@ -399,16 +436,16 @@ def test_endpointless_profile_credentials_use_explicit_policy_binding(
399436 providers = [provider_name ],
400437 )
401438
402- def read_gcp_token () -> str :
439+ def read_token () -> str :
403440 import os
404441
405- return os .environ .get ("GCP_ADC_ACCESS_TOKEN " , "NOT_SET" )
442+ return os .environ .get ("E2E_ENDPOINTLESS_TOKEN " , "NOT_SET" )
406443
407444 with sandbox (spec = spec , delete_on_exit = True ) as sb :
408- result = sb .exec_python (read_gcp_token )
445+ result = sb .exec_python (read_token )
409446 assert result .exit_code == 0 , result .stderr
410447 assert _is_placeholder_for_env_key (
411- result .stdout .strip (), "GCP_ADC_ACCESS_TOKEN "
448+ result .stdout .strip (), "E2E_ENDPOINTLESS_TOKEN "
412449 )
413450
414451
0 commit comments