Skip to content

Go SDK: CI never runs the example program, so it can break unnoticed #1124

Description

@coderdan

Background

The Go SDK ships a runnable example at languages/golang/encrypt/example (mise run go:encrypt:example). It connects to ZeroKMS, the CipherStash key service, so it needs real credentials. No CI job runs it.

Problem

The example broke without anyone noticing. It encrypted rows through a cipher with Extend("tenant-42") and decrypted them through the Client, which refuses rows sealed with an extension. So it failed at its last step. #1094 fixed the call, but nothing stops the same kind of break from happening again. Examples that work as written matter a lot: developers copy them.

The tests use a deterministic test build of the guest (NewDeterministicClient) that needs no ZeroKMS. But that constructor lives in encrypt/export_test.go, so only package encrypt's own tests can call it. The example is package main in another directory, so it cannot reach it.

Proposal

  1. Make the example's run take a *encrypt.Client, so a test can pass one in.
  2. Make a deterministic client available to tests outside package encrypt, for example from an internal test-support package that reads the deterministic guest build.
  3. Add encrypt/example/main_test.go, which calls run with that client. Then tests-golang.yml runs the example on every pull request.

Found in the review of #1094.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    SDKgithub-actionsPull request modifies GitHub Actions

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions