Testing, coverage, and E2E
Choose the cheapest faithful tier, preserve coverage gates, and place every real-cluster test in exactly one CI bucket.
Gameplane’s test suite spans three tiers: unit tests and Vitest (cheapest), envtest for Kubernetes integration (moderate cost), and kind E2E for full-cluster validation (most expensive). Every real-cluster test lives in exactly one CI bucket to prevent login rate-limiter starvation.
kubectl port-forward tunnels through the kubelet, bypassing NetworkPolicy entirely. It cannot prove real in-cluster game connectivity. Use a live E2E run on a kind cluster instead.
Go test tiers
Unit, envtest, and kind E2E cover progressively more infrastructure at progressively higher cost.
Web and coverage
Vitest/MSW and Playwright mock/live modes cover browser behavior; merged profiles enforce component thresholds.
E2E discipline
Every test belongs to one disjoint CI bucket; real game probes run as in-cluster Jobs and failures retain diagnostics.
The 11 buckets partition tests by login pressure, not feature area. The API rate limiter is per-IP (burst 10, 5/min) and per-username (burst 6, 3/min). Each bucket keeps within its login budget (~7 admin logins):
operator— zero logins; runs parallel and wide.api-auth,api-roles,api-rbac,api-agent,api-mods— API-specific tests, carefully metered.ratelimit— deliberately exhausts the shared limiter; runs last as a separate invocation.bot-fast,bot-heavy— game bot harness tests.multicluster— requires two kind clusters (one per node, setGAMEPLANE_E2E_CLUSTER_B).upgrade— helm upgrade and state persistence.
Use BUCKET=<name> make test-e2e-bucket to run a single bucket locally against a live cluster.
The separate ingress-nginx smoke (kind) CI job boots a Kind cluster with the node config make dev-up uses, applies the dev ingress-nginx manifest pinned in deploy/kind/up.sh and waits for the controller rollout. It runs only when deploy/kind/** or the CI workflow file changes.