koopa-admin-log/scripts/taler-monitoring/README.md
2026-07-17 11:42:41 +02:00

6.3 KiB

taler-monitoring

Report for the GOA stack with clear severity tags and per-area test IDs:

Tag Meaning
[OK] check passed
[INFO] inside status (container, ports, log noise)
[WARN] degraded but maybe not fatal
[ERROR] component problem
[BLOCKER] withdraw/pay path cannot complete because of this

IDs: www-001, inside-001, versions-001, sanity-001, server-001, e2e-001
Catalog: TESTS.md.

[OK]    www-001  exchange /config https://exchange…/config
[BLOCKER] e2e-015  prereq: merchant HTTP 502

End of each phase: totals + list of BLOCKERS and ERRORS.

Commands

# Local GOA stack (may use SSH for inside/e2e)
./taler-monitoring.sh              # urls + inside + versions + e2e
./taler-monitoring.sh inside       # containers on koopa
./taler-monitoring.sh versions     # deb.taler.net + package versions vs trixie
./taler-monitoring.sh sanity
./taler-monitoring.sh e2e

# Other domains — public HTTPS only, never SSH
./taler-monitoring.sh -d taler.net
./taler-monitoring.sh --domain taler-ops.ch
./taler-monitoring.sh -d my.taler-ops.ch urls
./taler-monitoring.sh -d demo.taler.net urls
./taler-monitoring.sh taler.net    # bare domain = same as -d

# Explicit endpoints (any mix; override profile or skip -d)
./taler-monitoring.sh --bank https://bank.demo.taler.net \
  --exchange https://exchange.demo.taler.net \
  --merchant https://backend.demo.taler.net --currency KUDOS urls

Domain profiles (domains.conf)

Each monitored stack must say what is bank, exchange, and merchant-backend.

Edit domains.conf (or set TALER_DOMAINS_CONF=):

# name   bank   exchange   merchant-backend   currency   local   [canonical]
taler-ops.ch  bank.taler-ops.ch  exchange.taler-ops.ch  my.taler-ops.ch  CHF  0
Field Meaning
name -d NAME / TALER_DOMAIN match (add alias lines as needed)
bank libeufin/bank public host or https://…
exchange exchange public host or URL
merchant merchant backend (SPA/API), e.g. my.taler-ops.ch
currency GOA / KUDOS / CHF / …
local 1 = koopa SSH stack; 0 = public only
landing 1 = check /intro landings + assets; 0 = skip (TOPS / mytops)
canonical optional label after alias (e.g. my.taler-ops.chtaler-ops.ch)

Then:

./taler-monitoring.sh -d taler-ops.ch urls

Overrides (always win after profile load):

./taler-monitoring.sh -d taler-ops.ch \
  --merchant https://my.taler-ops.ch \
  --exchange https://exchange.taler-ops.ch \
  --bank https://bank.taler-ops.ch urls

Helpers in lib.sh: set_taler_stack, load_domain_profile, apply_taler_domain.

Built-in profiles (see domains.conf)

Domain / alias Bank Exchange Merchant Currency
hacktivism.ch / koopa bank.hacktivism.ch exchange.hacktivism.ch taler.hacktivism.ch GOA
taler.net / demo.taler.net bank.demo.taler.net exchange.demo.taler.net backend.demo.taler.net KUDOS
test.taler.net bank.test… exchange.test… backend.test… TESTKUDOS · no landings
taler-ops.ch / my.taler-ops.ch bank.taler-ops.ch exchange.taler-ops.ch my.taler-ops.ch CHF · no landings
stage.taler-ops.ch bank.stage… exchange.stage… my.stage… CHF · no landings
unknown bank.DOMAIN exchange.DOMAIN my.DOMAIN then probe any · no landings

Landings: only GOA (and optionally demo) use public /intro pages. taler-ops.ch does notCHECK_LANDING=0 in the profile skips intro crawl, shop assets, and demo-withdraw checks.

SSH only for koopa (hacktivism.ch / -d koopa).

Other domains: never SSH. Optional e2e aborts cleanly on login/KYC.

E2E amounts (variable)

Local (koopa) Remote
ATM withdraw 20 · 50 · 100 · 200 · 4200 (paivana) 10 · 20 · 50
Pay ladder 0.01 … 10 0.01 … 1
Paivana HTTP paywall + template pay GOA:4200 (goa-shop / paivana) skipped
./taler-monitoring.sh e2e
./taler-monitoring.sh -d taler.net urls e2e
# customize:
E2E_WITHDRAW_VALUES="20 50 100" E2E_PAY_VALUES="0.05 1 5" ./taler-monitoring.sh e2e
E2E_VARIABLE=0 WITHDRAW_AMT=GOA:50 PAY_AMT=GOA:1 ./taler-monitoring.sh e2e   # single fixed
# GOA shop catalog (local hacktivism): full list in E2E_SHOP_PRODUCTS; each run
#   shuffles and pays E2E_SHOP_PICK_N products (default 2).
#   E2E_SHOP_PRODUCTS lines: id|Product name|GOA:amount
#   E2E_SHOP_PICK_N=2
#   (landing QR = taler://pay-template/…/{id}; popup = live taler://pay after POST templates/{id})
# Paivana paywall (local GOA only):
#   E2E_PAIVANA=1 (default)  PAIVANA_PUBLIC=https://paivana.hacktivism.ch
#   E2E_PAIVANA_TEMPLATE=paivana  E2E_PAIVANA_AMOUNT=GOA:4200  E2E_PAIVANA_INSTANCE=goa-shop
#   E2E_PAIVANA=0            # skip
# remote secrets:
#   E2E_BANK_ADMIN_PASS=…  E2E_MERCHANT_TOKEN=…

Phases

Phase What
inside SSH koopa: processes, postgres, local /config,/keys, wirewatch, recent log ERRORs
versions deb.taler.net reachable (InRelease/Packages/pool .deb); containers can reach it + have apt source; installed Taler packages vs trixie
sanity bank · exchange · merchant sections (public + server)
e2e account → credit → withdraw → wallet → confirm → order → pay
# package suite (default trixie on deb.taler.net)
TALER_APT_SUITE=trixie ./taler-monitoring.sh versions
TALER_PKG_BEHIND=error ./taler-monitoring.sh versions   # any behind = ERROR

E2E maps failures to blockers, e.g.:

  • bank-confirm HTTP 409 → wallet did not select exchange
  • no GOA balance → wirewatch / transfer
  • create order failed → merchant auth/instance
  • Alarm clock during pay → usually missing handle-uri --yes or wrong pay URI (must be …/instances/{inst}/{oid}/?c={token} from merchant taler_pay_uri)
  • insufficient balance → withdraw incomplete

Needs

  • SSH koopa (inside/sanity server bits)
  • secrets under koopa-admin-secrets/... for e2e
  • taler-wallet-cli for e2e