3.3 KiB
SCUM Companion One-Shot Smoke
This plugin-owned fixture proves the Platform Client Manager and Game Client Bridge integration without adding SCUM behavior to Run. The command registers the deployed component, sends one heartbeat, claims at most one command, processes only companion.diagnostics, and uploads one typed companion.health snapshot.
Use it only with a dedicated non-production server instance whose bridge queue contains no shared or production work. The claim API cannot filter by command type, so this smoke command must never target a shared or production queue.
Before starting it, confirm that the isolated queue is otherwise empty and queue exactly one companion.diagnostics command through the Platform SCUM operations page. Use the bounded payload includeWindowState=false and maxEntries=1. Do not pass an operator session or API token to the companion process.
Package
Build the one-shot command from this directory:
go build -o scum-companion-smoke ./cmd/scum-companion-smoke
Place the generated config.yaml beside the executable. The command intentionally has no --config flag and reads only that sidecar filename from its working directory. config.yaml.example documents the generated shape; deployed identity and generation values must come from the fenced Client Manager lifecycle input.
The Platform base URL must be a trusted HTTPS origin. The client uses host system certificate roots, requires TLS 1.2 or newer, and does not follow redirects. Local acceptance therefore needs a hostname and certificate already trusted by the machine account running the package. The certificate SAN must cover the configured hostname or IP; a certificate for localhost does not cover 127.0.0.1 unless that IP is also present. Do not use HTTP fallback, certificate-skip flags, custom root overrides, or other verification bypasses for local testing.
The supervisor supplies the component proof through the environment variable named by proof.materialEnv. Bind it from the protected component package at process start. Do not place the proof in config.yaml, command arguments, command-line environment assignments, shell history, documentation, or logs.
The process environment must also set SCUM_COMPANION_SMOKE_SCOPE to isolated-non-production. This value is a non-secret safety acknowledgement; configure it in the supervisor rather than placing component proof material on a command line.
Run the executable from the package working directory:
./scum-companion-smoke
The JSON output contains only claimed/completed/unsupported counts, command IDs, and the accepted snapshot ID. It never prints the component proof, component session, command payloads, host paths, or transport details. The run proceeds only when exactly one live companion.diagnostics command with a valid bounded payload is claimed. Zero, multiple, expired, malformed, or unsupported commands stop the smoke immediately; they are not acknowledged, completed, or executed, and no snapshot is uploaded. Platform lease fencing remains authoritative.
Each invocation uploads health to a fresh bounded smoke-<random> stream with sequence 1. This avoids reusing production stream state and remains safe across process restarts without storing a host path or local sequence file.