OpenClaw EnterpriseDOCSGitHub

ChatGPT service-account tests

Verify real ChatGPT service-account creation, credential delivery, and a Codex model turn. Prepare the Kubernetes runtime setup and private credential file first.

ChatGPT service accounts

Use the linked Kubernetes setup for a disposable cluster, migrated database, and immutable runtime images. Supply a protected admin-key file and the exact authorized workspace ID; the test creates a real provider account and issues its model credential. For a direct local node --test run, import approved gateway and Agent images first and export their immutable image@sha256:<digest> references as shown in Kubernetes model turns and Secrets.

The test uses stock local-path RWO storage in the disposable k3d cluster and grants its controller identities the production worker's volume and Pod observation permissions. The worker remains unable to read Secrets.

The protected provider-account GitHub Actions lane builds the checked-in runtime image and imports it into the run-owned k3d cluster when either OCC_TEST_KUBERNETES_GATEWAY_IMAGE or OCC_TEST_KUBERNETES_AGENT_IMAGE is unset. If both image variables are set, the lane uses those explicit references after validating that each is immutable.

sh
(  unset OCC_TEST_CHATGPT_ADMIN_KEY  export OCC_TEST_CHATGPT_ADMIN_KEY_PATH=/absolute/path/to/private/chatgpt-admin-key  export OCC_TEST_CHATGPT_WORKSPACE_ID='<authorized-workspace-id>'  OCC_TEST_CHATGPT_SERVICE_ACCOUNT_REAL=1 \    node --env-file="$TEST_ENV_FILE" --test tests/integration/service-account-driver-real.test.mjs)

Keep OCC_TEST_CHATGPT_ADMIN_KEY out of that environment file as well: a nonempty environment key takes precedence over the file-path option. Protect the supplied key file with mode 0600. OPENAI_API_KEY is not required. Set the supported model explicitly with OCC_TEST_OPENAI_MODEL. The test attempts provider-account deletion and scoped resource cleanup; investigate any reported cleanup failure before rerunning.

ChatGPT service-account integration test environment

service-account-driver-real.test.mjs creates an actual ChatGPT service account, issues its credential, deploys the associated dedicated Codex Agent, and requires one genuine provider-backed model turn. Set OCC_TEST_CHATGPT_SERVICE_ACCOUNT_REAL=1 to opt in; missing prerequisites then fail rather than skip.

Variable Requirement
OCC_TEST_CHATGPT_SERVICE_ACCOUNT_REAL Set to 1 to enable the real provider-backed account and model-turn test.
OCC_TEST_CHATGPT_ADMIN_KEY Explicit admin key; takes precedence over the path when set.
OCC_TEST_CHATGPT_ADMIN_KEY_PATH Protected 0600 admin-key file read only when OCC_TEST_CHATGPT_ADMIN_KEY is unset.
OCC_TEST_CHATGPT_WORKSPACE_ID ChatGPT workspace authorized for account and credential creation.
OCC_TEST_KUBERNETES_KUBECONFIG Absolute kubeconfig path for the dedicated disposable local cluster.
OCC_TEST_KUBERNETES_CONTEXT Explicit k3d-* context with a verified loopback HTTPS API.
OCC_TEST_KUBERNETES_GATEWAY_IMAGE Imported immutable real OpenClaw gateway image.
OCC_TEST_KUBERNETES_CODEX_IMAGE Imported immutable real Codex image; OCC_TEST_KUBERNETES_AGENT_IMAGE is also accepted.
OCC_TEST_DATABASE_URL Migrated disposable loopback PostgreSQL database named openclaw_k8s_*.

This scenario uses its newly issued access token, not OPENAI_API_KEY. Its optional OCC_TEST_OPENAI_MODEL defaults to gpt-6-astra; select a model available to the issued ChatGPT account's Codex credentials. API-key model availability does not establish support for this authentication mode. When using the file path, unset OCC_TEST_CHATGPT_ADMIN_KEY first so the test actually reads the protected file. See the ChatGPT service-account testing guide for the complete setup.

Local and provider coverage

tests/integration/occ-api.test.mjs covers native references, immutable revision snapshots, and Namespace-scoped access. tests/conformance/service-account-driver.test.mjs covers authorized lifecycle, transaction-failure compensation, and execution-mode admission. These checks do not exercise a live provider or Kubernetes cluster.

tests/integration/postgres-service-account-deletion.test.mjs uses the PostgreSQL test setup to verify deletion rejection before Driver effects for queued, claimed, and active revisions after draft detachment. It also checks that completed cutover and permanently failed work release account references. The shared storage contract covers active and historical revisions in both storage adapters. These are persistence and controller checks, not live credential-revocation or model-turn proof.

The real account suite above creates a provider account and runs dedicated Codex with its issued credential. The ordinary Kubernetes runtime suite separately covers native API-key Codex and embedded OpenClaw execution.

Search documentation