Skip to content

0003: Opt-in live tests against real Telnyx S3 and Cloudflare

Date: 2026-10-07 · Status: accepted

Context

CLAUDE.md said tests never touch Cloudflare or Telnyx. The owner has since provided credentials and asked for the real services to be tested too, using the Cloudflare zone the-republic.net (never republic.global).

Decision

  • make test-all stays hermetic: MinIO (incl. a path-style SigV4 config identical to Telnyx), mocked Cloudflare API and Access. It needs no credentials and is what gates merges.
  • Separate opt-in targets run against real services and fail (not skip) when their configuration is missing:
  • make test-live-s3: env KEEPER_LIVE_S3_ENDPOINT, KEEPER_LIVE_S3_REGION, KEEPER_LIVE_S3_BUCKET, TELNYX_API_KEY (access key id = secret). Writes only under keeper-test/<run-id>/ and deletes it afterwards.
  • make test-live-cloudflare: env CLOUDFLARE_API_TOKEN, KEEPER_LIVE_CF_ZONE (e.g. the-republic.net), optional CLOUDFLARE_ACCOUNT_ID (discovered from the token otherwise). Creates a throwaway tunnel, DNS records, an Access app and a service token, all named keeper-test-<run-id>*, and deletes them afterwards.
  • Safety guards in the test helpers refuse any S3 key outside keeper-test/ and any DNS name or Cloudflare object not prefixed keeper-test-. A cleanup step also removes keeper-test-* leftovers older than 24 h.
  • Tunnel data-path traffic (cloudflared to the edge on port 7844) may be impossible from the build environment; it is covered by the mocked e2e and by the rollout checklist.

Consequences

CLAUDE.md's testing rule is updated: the default suites never touch real services; the live suites do, only through these guarded targets.