Skip to content

test(bdd): single-cluster PKI feature with a secured LLM invoke #1076

Description

@along-2017

Parent

Relates to #1019

What to build

A new single-cluster PKI feature file with its own live entry point
and wiring test. It reuses the existing fixtures and overlays the LLM
PKI add-on enabled and the stargate QUIC tunnel secure in its
Background, so the default fixtures and every existing feature stay
untouched. Scenarios: render check with PKI enabled; install
asserting the PKI release deployed and the issuer and router
certificate Ready; a trust-distribution helper script that reads the
root CA and fingerprint after install and writes them into the
compute-plane environment as the agent config merge fragment (no CLI
profile dependency); the LLM function scenario invoking over the
secured tunnel.

Acceptance criteria

  • PKI release, issuer, and router certificate asserted Ready
  • Trust bundle distributed by script, no secrets in command logs
  • LLM chat completion and 401 checks pass over the secured tunnel
  • Existing features and fixtures unchanged
  • Wiring test and short suite green; live run green

Blocked by

None — can start immediately (reuses the landed single-cluster LLM
scenario shape).

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions