[AZ-505] AC-5 fix: enable TLS for HTTP/2 via ALPN
ci/woodpecker/push/01-test Pipeline was successful
ci/woodpecker/push/02-build-push Pipeline was successful

Kestrel with HttpProtocols.Http1AndHttp2 on a plaintext listener
silently downgrades to HTTP/1.1-only (logs "HTTP/2 is not enabled
... TLS is not enabled"), so AC-5's multiplexed-GET test failed
with HTTP_1_1_REQUIRED. ALPN cannot run over plaintext, so the
fix switches the dev listener to TLS on https://+:8080:

- scripts/run-tests.sh generates a self-signed dev cert idempotently
  (./certs/api.pfx + api.crt) via openssl in an alpine container;
  certs/ is gitignored.
- docker-compose.yml binds Kestrel to ASPNETCORE_URLS=https://+:8080
  with Kestrel__Certificates__Default__Path bound to the .pfx.
- docker-compose.tests.yml mounts api.crt into the integration-tests
  container's CA store and runs update-ca-certificates so HttpClient
  trusts the cert transparently; default API_URL is now https://api:8080.
- Drop the obsolete Http2UnencryptedSupport AppContext switch from
  Http2MultiplexingTests; ALPN over TLS handles negotiation.

Test-data fixes caught on the post-TLS rerun (independent of the TLS
switch but surfaced together):

- Http2MultiplexingTests: switch slippy coords from (154321, 95812)
  -- which Google Maps returns 404 for -- to (158485, 91707), the
  slippy projection of (47.461747, 37.647063) already exercised by
  JwtIntegrationTests.
- TileInventoryTests + LeafletPathIndexOnlyTests: SpecifyKind to
  Unspecified at the binding site for raw Npgsql seed paths writing
  into tiles.captured_at / created_at / updated_at (TIMESTAMP without
  tz). Npgsql v6+ refuses Kind=Utc into plain timestamp columns;
  production goes through Dapper and never hits this code path.
- MigrationTests Az503NewUniqueIndexCoversIntegerKeyAndFlightId:
  accept either idx_tiles_location_hash (migration 014) or its
  AZ-505 successor tiles_leaflet_path (migration 015) -- both have
  location_hash as the leading column, which is the AC-9 intent.

Docs updated to reflect the TLS+ALPN path: tile-inventory.md
Non-Goals, modules/api_program.md, module-layout.md, the AZ-505
task spec's Risk 3, and the cycle 6 implementation + completeness
reports. The full integration test suite passes (mode=full, exit 0).

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Oleksandr Bezdieniezhnykh
2026-05-12 22:19:26 +03:00
parent da40534b49
commit c74a2339aa
17 changed files with 148 additions and 42 deletions
@@ -3,15 +3,15 @@ using System.Net.Http.Headers;
namespace SatelliteProvider.IntegrationTests;
// AZ-505 AC-5: HTTP/2 multiplexed responses on the dev plaintext endpoint.
// AZ-505 AC-5: HTTP/2 multiplexed responses.
//
// Kestrel is configured with `HttpProtocols.Http1AndHttp2` (Program.cs); the
// .NET HttpClient supports HTTP/2 over plaintext (h2c, prior-knowledge) when
// the `System.Net.SocketsHttpHandler.Http2UnencryptedSupport` AppContext switch
// is on. Browsers cannot use h2c — that's documented in the AZ-505 risk
// section and in `tile-inventory.md` v1.0.0. This test exercises the
// programmatic-client path the onboard `TileDownloader` (httpx http2=True)
// uses in production.
// Kestrel is configured with `HttpProtocols.Http1AndHttp2` over TLS
// (docker-compose.yml mounts the dev cert; ASPNETCORE_URLS=https://+:8080).
// ALPN negotiates HTTP/2 with HTTP/2-capable clients and falls back to
// HTTP/1.1 for browsers and legacy callers. The integration-tests
// container trusts the dev cert via /usr/local/share/ca-certificates,
// so HttpClient negotiates HTTP/2 transparently — no h2c / unencrypted
// support switch is needed.
public static class Http2MultiplexingTests
{
private const int ConcurrentRequestCount = 20;
@@ -20,11 +20,6 @@ public static class Http2MultiplexingTests
{
RouteTestHelpers.PrintTestHeader("Test: HTTP/2 multiplexing on /tiles/{z}/{x}/{y} (AZ-505)");
// The Http2UnencryptedSupport switch is process-wide on the client.
// Setting it more than once is a no-op, so it's safe to call here even
// though other tests in the same runner do not need it.
AppContext.SetSwitch("System.Net.SocketsHttpHandler.Http2UnencryptedSupport", true);
var apiUri = new Uri(apiUrl);
using var handler = new SocketsHttpHandler
{
@@ -48,9 +43,14 @@ public static class Http2MultiplexingTests
// Pick a single (z, x, y) — caching means all 20 calls hit the same
// tile, which is exactly what we want: prove the responses come back
// over HTTP/2 with their CDN-style headers preserved.
//
// Coords (158485, 91707) at z=18 are the slippy projection of
// (47.461747, 37.647063), the same lat/lon JwtIntegrationTests hits
// — confirmed to have Google Maps satellite coverage by every prior
// cycle's run, so the warmup download is reliable.
const int z = 18;
const int x = 154321;
const int y = 95812;
const int x = 158485;
const int y = 91707;
var path = $"/tiles/{z}/{x}/{y}";
// Prime the cache with a single warm-up call so the 20 concurrent