Files
shelfmark/tests/e2e/platform/env/dns-doh.env
T

18 lines
807 B
Bash

# Profile: dns-doh (config cluster — in-stack DNS-over-HTTPS, end to end)
#
# Proves the app's DoH path resolves a name over real HTTPS:
# * system resolver = coredns-blocked, which NXDOMAINs aa.mock.test, so the host
# can ONLY be resolved via DoH;
# * CUSTOM_DNS=cloudflare + USE_DOH=true => the app queries the cloudflare DoH
# endpoint, which docker-compose `extra_hosts` redirects to the in-stack
# mock-doh (HTTPS, self-signed). CERTIFICATE_VALIDATION=disabled accepts it.
# * mock-doh maps aa.mock.test -> mock-aa, so the search reaches AA — only
# possible if DoH resolution worked.
COMPOSE_PROFILES=dns-doh,dns-blocked
SM_AA_URL=http://aa.mock.test
SM_SYSTEM_DNS=172.30.0.22
SM_CUSTOM_DNS=cloudflare
SM_USE_DOH=true
SM_CERTIFICATE_VALIDATION=disabled
E2E_PROFILE=dns-doh