Context
Spike #854 proposed a 7-case compatibility-test matrix for validating
complyctl's consumption of bundles published by grcli. The cross-repo
integration tests (tests/cross-repo/) currently test against
complytime-providers, not against grcli-published bundles.
Problem
There is no test infrastructure that validates complyctl against bundles
produced by the upstream grcli toolchain. As the Gemara bundle format
evolves, complyctl needs regression coverage for bundle consumption
compatibility.
Proposed Compatibility Matrix
| Test Case |
Bundle Source |
Verification |
Expected Behavior |
| Flat single-artifact bundle |
grcli Pack |
keyless |
get syncs, scan resolves graph |
| Multi-artifact bundle (policy + catalog + guidance) |
grcli Pack |
keyless |
Full DependencyGraph resolved |
| Bundle with embedded imports |
grcli Pack + Assemble |
keyless |
Imports resolved from cached OCI Layout |
| Bundle with external mapping refs |
Future (Smart Bundling) |
keyless |
TBD (depends on grc-store-clientkit#2) |
| Private registry bundle |
grcli to private registry |
keyed (PEM) |
Auth via docker cred helpers |
| Legacy split-layer artifact |
pre-v0.10 publisher |
optional |
Backward compat via DetectManifestShape |
| Version-skewed bundle |
grcli on go-gemara v0.9.2 |
keyless |
Unpack on v0.10.0 succeeds |
Implementation Notes
- Requires a test fixture pipeline using
grcli (or bundle.Pack() directly)
to produce artifacts in a test registry (e.g., zot, as used in acceptance tests)
- The "external mapping refs" case is blocked on grc-store-clientkit#2
(Smart Bundling spec)
- Consider extending the existing acceptance test infrastructure
(tests/acceptance/) rather than building a separate stack
Related
Context
Spike #854 proposed a 7-case compatibility-test matrix for validating
complyctl's consumption of bundles published by
grcli. The cross-repointegration tests (
tests/cross-repo/) currently test againstcomplytime-providers, not againstgrcli-published bundles.Problem
There is no test infrastructure that validates complyctl against bundles
produced by the upstream
grclitoolchain. As the Gemara bundle formatevolves, complyctl needs regression coverage for bundle consumption
compatibility.
Proposed Compatibility Matrix
grcliPackgetsyncs,scanresolves graphgrcliPackgrcliPack + Assemblegrclito private registryDetectManifestShapegrclion go-gemara v0.9.2Unpackon v0.10.0 succeedsImplementation Notes
grcli(orbundle.Pack()directly)to produce artifacts in a test registry (e.g., zot, as used in acceptance tests)
(Smart Bundling spec)
(
tests/acceptance/) rather than building a separate stackRelated
grc-store-clientkitAdoption for Bundle Consumption #854 (spike assessment, section 8)