0003: Opt-in live tests against real Telnyx S3 and Cloudflare¶
Date: 2026-10-07 · Status: accepted
Context¶
CLAUDE.md said tests never touch Cloudflare or Telnyx. The owner has since provided credentials and asked for the
real services to be tested too, using the Cloudflare zone the-republic.net (never republic.global).
Decision¶
make test-allstays hermetic: MinIO (incl. a path-style SigV4 config identical to Telnyx), mocked Cloudflare API and Access. It needs no credentials and is what gates merges.- Separate opt-in targets run against real services and fail (not skip) when their configuration is missing:
make test-live-s3: envKEEPER_LIVE_S3_ENDPOINT,KEEPER_LIVE_S3_REGION,KEEPER_LIVE_S3_BUCKET,TELNYX_API_KEY(access key id = secret). Writes only underkeeper-test/<run-id>/and deletes it afterwards.make test-live-cloudflare: envCLOUDFLARE_API_TOKEN,KEEPER_LIVE_CF_ZONE(e.g.the-republic.net), optionalCLOUDFLARE_ACCOUNT_ID(discovered from the token otherwise). Creates a throwaway tunnel, DNS records, an Access app and a service token, all namedkeeper-test-<run-id>*, and deletes them afterwards.- Safety guards in the test helpers refuse any S3 key outside
keeper-test/and any DNS name or Cloudflare object not prefixedkeeper-test-. A cleanup step also removeskeeper-test-*leftovers older than 24 h. - Tunnel data-path traffic (cloudflared to the edge on port 7844) may be impossible from the build environment; it is covered by the mocked e2e and by the rollout checklist.
Consequences¶
CLAUDE.md's testing rule is updated: the default suites never touch real services; the live suites do, only through these guarded targets.