Cloud Smoke Tests
This document records the manual real-cloud verification performed before each Rivet release. It is the operator-discipline counterpart to the automated PR CI matrix described in reliability-matrix.md.
Per-PR CI uses MinIO (S3-compatible) and fake-gcs containers. Real S3 / GCS / Azure endpoints are exercised manually here — too expensive and too credential-sensitive to run on every push.
Last manually verified
| Backend | Auth mode | Date verified | Verified by |
|---|---|---|---|
| Local FS | path | continuous (CI) | PR CI |
| S3 | env access key | 2026-05-22 | maintainer |
| S3 | session token (STS) | 2026-05-22 | maintainer |
| S3 | AWS profile | 2026-05-22 | maintainer |
| GCS | ADC / service account | 2026-08-19 | maintainer + assistant (0.24.5 pre-tag) |
| Azure Blob | account key env | 2026-05-21 | maintainer |
| Azure Blob | SAS token env | 2026-05-22 | maintainer |
Update this table as part of the release checklist.
Tested scenarios
For each backend, the smoke run covers:
- Fresh export to an empty prefix —
rivet runproduces parts +manifest.json+_SUCCESS. - Manifest fingerprint round-trip —
_SUCCESSbody matches the xxh3 ofmanifest.jsonbytes. -
rivet validateon the just-finished run — exits 0. -
rivet validate --date YYYY-MM-DDagainst a previous-day prefix — exits 0 (historical anchor). -
rivet validate --prefix <abs-prefix>— bypasses placeholder resolution, exits 0 against the same physical prefix. -
rivet validate --run-id <RID>— re-checks a specific run. - Failed source auth → no URL password in stderr /
summary.json/summary.md/manifest.json/ journal events / log lines. - Failed destination auth → no credential in the same artifact set.
- Cleanup: probe object
.rivet_doctor_proberemoved; no orphaned parts under the test prefix.
Per-backend results
S3 — 2026-05-22
| Scenario | Result | Notes |
|---|---|---|
| Fresh export | ✅ | MinIO + real AWS S3 (us-east-1) |
validate | ✅ | — |
validate --date (historical) | ✅ | Anchor lifts the implicit “today” assumption (v0.7.2) |
validate --prefix | ✅ | — |
| Manifest fingerprint match | ✅ | M2 |
| Auth-failure secret-leak audit | ✅ | URL password redacted; access keys not echoed |
GCS — 2026-08-19 (0.24.5 pre-tag)
Scope decision, recorded rather than implied: this release’s real-cloud smoke
was deliberately LIMITED to GCS. S3 and Azure keep their 2026-05-22/21 dates —
their sessions were expired at smoke time and the release rides the emulator
(MinIO / Azurite) coverage plus the shared CloudDestination path, which this
GCS run exercises for real.
| Scenario | Result | Notes |
|---|---|---|
| Fresh export | ✅ | real GCS bucket rivet-matrix-smoke-…, ADC; release binary |
validate | ✅ | — |
validate --date (historical) | ✅ | — |
validate --prefix | ✅ | prefix taken from validate’s own JSON report |
validate --run-id | ✅ | re-check of the smoke run |
| Auth-failure secret-leak audit | ✅ | probe password absent from stderr + every run artifact |
GCS — 2026-05-22
| Scenario | Result | Notes |
|---|---|---|
| Fresh export | ✅ | fake-gcs + real GCS bucket |
validate | ✅ | — |
validate --date (historical) | ✅ | — |
validate --prefix | ✅ | — |
| Manifest fingerprint match | ✅ | M2 |
ADC vs explicit credentials_file | ✅ | Both paths exercised |
| Auth-failure secret-leak audit | ✅ | Service-account JSON path is logged but contents are not |
Azure Blob — 2026-05-21 (account key) / 2026-05-22 (SAS)
| Scenario | Result | Notes |
|---|---|---|
| Fresh export (account key) | ✅ | RIVET_AZURE_KEY env var |
| Fresh export (SAS token) | ✅ | AZURE_STORAGE_SAS_TOKEN env var; v0.7.2 path |
validate | ✅ | — |
validate --date (historical) | ✅ | — |
validate --prefix | ✅ | — |
Endpoint auto-derive from account_name | ✅ | Regression caught 2026-05-21; covered by azure_destination_auto_derives_endpoint_from_account_name unit test |
| SAS-expiry preflight | ✅ | v0.7.4 — doctor warns when se= is < 60 min; fails when expired |
| Auth-failure secret-leak audit | ✅ | Account key + SAS token redacted |
What is not covered
Manual smoke tests intentionally skip:
- Long-running SAS-expiry mid-export. The preflight catches near-expiry tokens before extraction starts; we do not run a many-hour export against a deliberately short SAS.
- Cross-region network instability. Toxiproxy chaos coverage exists
in PR CI (
live_chaos) but only against MinIO and fake-gcs. - Provider outage or throttling. Documented as a known limitation in cloud-destinations.md § Known limitations.
- Multipart upload interruption beyond what
live_chunked_recoveryexercises against MinIO. - Full IAM permission matrix. Minimum-required permissions are documented in cloud-permissions.md; a systematic least-privilege matrix is roadmap.
- Bucket / container lifecycle policies, encryption-at-rest, replication. Out of scope for Rivet (the operator manages these out-of-band).
How to reproduce
The smoke runner expects environment variables matching each backend’s auth mode (see the per-backend pages under docs/destinations/). At minimum:
# S3 (real AWS bucket, region us-east-1)
export AWS_ACCESS_KEY_ID=AKIA...
export AWS_SECRET_ACCESS_KEY=wJa...
export RIVET_SMOKE_S3_BUCKET=rivet-smoke-${USER}
# Copy an example config to a scratch path and point it at the smoke bucket
cp examples/pg_chunked_s3.yaml /tmp/smoke-s3.yaml
# edit /tmp/smoke-s3.yaml: set `bucket:` to $RIVET_SMOKE_S3_BUCKET
rivet doctor --config /tmp/smoke-s3.yaml
rivet run --config /tmp/smoke-s3.yaml
rivet validate --config /tmp/smoke-s3.yaml
rivet validate --config /tmp/smoke-s3.yaml --date "$(date -u +%Y-%m-%d)"
# The resolved prefix comes from validate's own JSON report — the run
# summary (.rivet/runs/<id>/summary.json) does not record it.
rivet validate --config /tmp/smoke-s3.yaml --prefix "$(rivet validate --config /tmp/smoke-s3.yaml --format json | jq -r '.exports[0].resolved_prefix')"
Equivalent recipes for GCS and Azure live under
examples/ (pg_full_azure_sas.yaml,
mysql_full_azure_sas.yaml, etc.).
Reporting smoke-run failures
If a smoke run regresses on a clean checkout, file an issue tagged
smoke-regression and include:
- The exact backend / auth mode that failed.
- The release tag or commit SHA.
- The
rivet doctorandrivet runoutput (with credentials redacted — Rivet’s own output should already be clean). - The resolved prefix from the run summary.
Trust-contract violations (manifest fingerprint drift, missing parts under
_SUCCESS, credentials in artifacts) follow the
security disclosure path, not
the public issue tracker.