157 lines
6.4 KiB
Markdown
157 lines
6.4 KiB
Markdown
# taler-monitoring
|
|
|
|
Report for the **GOA** stack with clear severity tags and **per-area test IDs**:
|
|
|
|
| Tag | Meaning |
|
|
|-----|---------|
|
|
| `[OK]` | check passed |
|
|
| `[INFO]` | inside status (container, ports, log noise) |
|
|
| `[WARN]` | degraded but maybe not fatal |
|
|
| `[ERROR]` | component problem |
|
|
| `[BLOCKER]` | **withdraw/pay path cannot complete** because of this |
|
|
|
|
IDs: **`www-001`**, **`inside-001`**, **`versions-001`**, **`sanity-001`**, **`server-001`**, **`e2e-001`** …
|
|
Catalog: **[TESTS.md](./TESTS.md)**.
|
|
|
|
```text
|
|
[OK] www-001 exchange /config https://exchange…/config
|
|
[BLOCKER] e2e-015 prereq: merchant HTTP 502
|
|
```
|
|
|
|
End of each phase: totals + list of **BLOCKERS** and **ERRORS**.
|
|
|
|
## Commands
|
|
|
|
```bash
|
|
# Local GOA stack (may use SSH for inside/e2e)
|
|
./taler-monitoring.sh # urls + inside + versions + e2e
|
|
./taler-monitoring.sh inside # containers on koopa
|
|
./taler-monitoring.sh versions # deb.taler.net + package versions vs trixie
|
|
./taler-monitoring.sh sanity
|
|
./taler-monitoring.sh e2e
|
|
|
|
# Other domains — public HTTPS only, never SSH
|
|
./taler-monitoring.sh -d taler.net
|
|
./taler-monitoring.sh --domain taler-ops.ch
|
|
./taler-monitoring.sh -d my.taler-ops.ch urls
|
|
./taler-monitoring.sh -d demo.taler.net urls
|
|
./taler-monitoring.sh taler.net # bare domain = same as -d
|
|
|
|
# Explicit endpoints (any mix; override profile or skip -d)
|
|
./taler-monitoring.sh --bank https://bank.demo.taler.net \
|
|
--exchange https://exchange.demo.taler.net \
|
|
--merchant https://backend.demo.taler.net --currency KUDOS urls
|
|
```
|
|
|
|
## Domain profiles (`domains.conf`)
|
|
|
|
Each monitored stack must say **what is bank, exchange, and merchant-backend**.
|
|
|
|
Edit **[domains.conf](./domains.conf)** (or set `TALER_DOMAINS_CONF=`):
|
|
|
|
```text
|
|
# name bank exchange merchant-backend currency local [canonical]
|
|
taler-ops.ch bank.taler-ops.ch exchange.taler-ops.ch my.taler-ops.ch CHF 0
|
|
```
|
|
|
|
| Field | Meaning |
|
|
|-------|---------|
|
|
| **name** | `-d NAME` / `TALER_DOMAIN` match (add alias lines as needed) |
|
|
| **bank** | libeufin/bank public host or `https://…` |
|
|
| **exchange** | exchange public host or URL |
|
|
| **merchant** | merchant **backend** (SPA/API), e.g. `my.taler-ops.ch` |
|
|
| **currency** | `GOA` / `KUDOS` / `CHF` / … |
|
|
| **local** | `1` = koopa SSH stack; `0` = public only |
|
|
| **landing** | `1` = check `/intro` landings + assets; `0` = skip (TOPS / mytops) |
|
|
| **canonical** | optional label after alias (e.g. `my.taler-ops.ch` → `taler-ops.ch`) |
|
|
|
|
Then:
|
|
|
|
```bash
|
|
./taler-monitoring.sh -d taler-ops.ch urls
|
|
```
|
|
|
|
Overrides (always win after profile load):
|
|
|
|
```bash
|
|
./taler-monitoring.sh -d taler-ops.ch \
|
|
--merchant https://my.taler-ops.ch \
|
|
--exchange https://exchange.taler-ops.ch \
|
|
--bank https://bank.taler-ops.ch urls
|
|
```
|
|
|
|
Helpers in `lib.sh`: `set_taler_stack`, `load_domain_profile`, `apply_taler_domain`.
|
|
|
|
### Built-in profiles (see `domains.conf`)
|
|
|
|
| Domain / alias | Bank | Exchange | Merchant | Currency |
|
|
|----------------|------|----------|----------|----------|
|
|
| `hacktivism.ch` / `koopa` | bank.hacktivism.ch | exchange.hacktivism.ch | taler.hacktivism.ch | GOA |
|
|
| `taler.net` / `demo.taler.net` | bank.demo.taler.net | exchange.demo.taler.net | backend.demo.taler.net | KUDOS |
|
|
| `test.taler.net` | bank.test… | exchange.test… | backend.test… | **TESTKUDOS** · no landings |
|
|
| `lefrancpaysan.ch` | bank.… | exchange.… | **monnaie.…** (merchant) | report-only · no landings |
|
|
| `taler-ops.ch` / `my.taler-ops.ch` | bank.taler-ops.ch | exchange.taler-ops.ch | **my.taler-ops.ch** | CHF · **no landings** |
|
|
| `stage.taler-ops.ch` | bank.stage… | exchange.stage… | **my.stage…** | CHF · **no landings** |
|
|
| unknown | bank.DOMAIN | exchange.DOMAIN | my.DOMAIN then probe | any · no landings |
|
|
|
|
**Landings:** only GOA (and optionally demo) use public `/intro` pages. **taler-ops.ch does not** — `CHECK_LANDING=0` in the profile skips intro crawl, shop assets, and demo-withdraw checks.
|
|
|
|
**SSH only for koopa** (`hacktivism.ch` / `-d koopa`).
|
|
|
|
Other domains: never SSH. Optional **e2e** aborts cleanly on login/KYC.
|
|
|
|
### E2E amounts (variable)
|
|
|
|
| | Local (koopa) | Remote |
|
|
|--|---------------|--------|
|
|
| **ATM withdraw** | 20 · 50 · 100 · 200 · **4200** (paivana) | 10 · 20 · 50 |
|
|
| **Pay ladder** | 0.01 … 10 | 0.01 … 1 |
|
|
| **Paivana** | HTTP paywall + template pay **GOA:4200** (`goa-shop` / `paivana`) | skipped |
|
|
|
|
```bash
|
|
./taler-monitoring.sh e2e
|
|
./taler-monitoring.sh -d taler.net urls e2e
|
|
# customize:
|
|
E2E_WITHDRAW_VALUES="20 50 100" E2E_PAY_VALUES="0.05 1 5" ./taler-monitoring.sh e2e
|
|
E2E_VARIABLE=0 WITHDRAW_AMT=GOA:50 PAY_AMT=GOA:1 ./taler-monitoring.sh e2e # single fixed
|
|
# GOA shop catalog (local hacktivism): full list in E2E_SHOP_PRODUCTS; each run
|
|
# shuffles and pays E2E_SHOP_PICK_N products (default 2).
|
|
# E2E_SHOP_PRODUCTS lines: id|Product name|GOA:amount
|
|
# E2E_SHOP_PICK_N=2
|
|
# (landing QR = taler://pay-template/…/{id}; popup = live taler://pay after POST templates/{id})
|
|
# Paivana paywall (local GOA only):
|
|
# E2E_PAIVANA=1 (default) PAIVANA_PUBLIC=https://paivana.hacktivism.ch
|
|
# E2E_PAIVANA_TEMPLATE=paivana E2E_PAIVANA_AMOUNT=GOA:4200 E2E_PAIVANA_INSTANCE=goa-shop
|
|
# E2E_PAIVANA=0 # skip
|
|
# remote secrets:
|
|
# E2E_BANK_ADMIN_PASS=… E2E_MERCHANT_TOKEN=…
|
|
```
|
|
|
|
## Phases
|
|
|
|
| Phase | What |
|
|
|-------|------|
|
|
| **inside** | SSH koopa: processes, postgres, local /config,/keys, wirewatch, recent log ERRORs |
|
|
| **versions** | `deb.taler.net` reachable (InRelease/Packages/pool `.deb`); containers can reach it + have apt source; installed Taler packages vs **trixie** |
|
|
| **sanity** | bank · exchange · merchant sections (public + server) |
|
|
| **e2e** | account → credit → withdraw → wallet → confirm → order → pay |
|
|
|
|
```bash
|
|
# package suite (default trixie on deb.taler.net)
|
|
TALER_APT_SUITE=trixie ./taler-monitoring.sh versions
|
|
TALER_PKG_BEHIND=error ./taler-monitoring.sh versions # any behind = ERROR
|
|
```
|
|
|
|
E2E maps failures to blockers, e.g.:
|
|
|
|
- `bank-confirm HTTP 409` → wallet did not select exchange
|
|
- `no GOA balance` → wirewatch / transfer
|
|
- `create order failed` → merchant auth/instance
|
|
- `Alarm clock` during pay → usually missing `handle-uri --yes` or wrong pay URI (must be `…/instances/{inst}/{oid}/?c={token}` from merchant `taler_pay_uri`)
|
|
- `insufficient balance` → withdraw incomplete
|
|
|
|
## Needs
|
|
|
|
- SSH `koopa` (inside/sanity server bits)
|
|
- secrets under `koopa-admin-secrets/...` for e2e
|
|
- `taler-wallet-cli` for e2e
|