diff --git a/docker/tests/test-pg17-upgrade.sh b/docker/tests/test-pg17-upgrade.sh index 6ac7ff9f091..a4e2bfa45ea 100644 --- a/docker/tests/test-pg17-upgrade.sh +++ b/docker/tests/test-pg17-upgrade.sh @@ -112,6 +112,37 @@ pre_checksum=$(run_sql -A -t -c "SELECT md5(string_agg(name || value::text, ',' echo " Rows: $pre_count" echo " Checksum: $pre_checksum" +# --- Seed a Vault secret --------------------------------------------------- +# Verifies the pgsodium root key survives the volume swap/chown AND that Vault +# secrets still decrypt on Postgres 17. For legacy (key_id-based) secrets this +# also exercises complete.sh's pgsodium->Vault re-encryption; on a stock +# self-hosted stack the secret is already pgsodium-less, so this confirms the +# round-trip and the post-upgrade invariant (key_id IS NULL). +VAULT_SECRET_NAME="upgrade_test_secret" +VAULT_SECRET_VALUE="upgrade-test-secret-value-42" +vault_available="f" +if [ "$(run_sql -A -t -c "SELECT EXISTS (SELECT 1 FROM pg_available_extensions WHERE name = 'supabase_vault');" | tr -d '[:space:]')" = "t" ]; then + echo "" + echo "Seeding Vault secret on Postgres 15..." + run_sql <&2 + fi + vault_available="t" +else + echo "" + echo "Skipping Vault seed: supabase_vault extension not available." +fi + # --- Run upgrade ----------------------------------------------------------- echo "" @@ -127,11 +158,37 @@ echo "" echo "Running pgTAP verification..." echo "" -# Use a non-quoted heredoc so $pre_count and $pre_checksum are interpolated +# Optional Vault assertions, only when a secret was seeded above. +vault_plan=0 +vault_tests="" +if [ "$vault_available" = "t" ]; then + vault_plan=3 + vault_tests=$(cat <