diff --git a/pkg/plan/node_identity_boot_test.go b/pkg/plan/node_identity_boot_test.go index f44c688..0b1129f 100644 --- a/pkg/plan/node_identity_boot_test.go +++ b/pkg/plan/node_identity_boot_test.go @@ -72,6 +72,22 @@ func TestIdentityFailureAndRetry(t *testing.T) { if err := run("1"); err != nil { t.Fatal("completed setup should not reset passwords", err) } + // Re-injection into a previously booted image must not trust its old marker. + if err := os.WriteFile(filepath.Join(etc, "node-identity.pending"), []byte("pending"), 0600); err != nil { + t.Fatal(err) + } + if err := os.WriteFile(envPath, []byte(synthetic), 0600); err != nil { + t.Fatal(err) + } + if run("1") == nil { + t.Fatal("old marker suppressed newly injected credentials") + } + if err := run("0"); err != nil { + t.Fatal(err) + } + if _, err := os.Stat(filepath.Join(etc, "node-identity.pending")); !os.IsNotExist(err) { + t.Fatal("successful identity left a pending marker") + } } func TestIdentityEnabledWithoutCloudInit(t *testing.T) {