Pin delete-instance cross-instance safety (G4h: Alpha delete leaves Beta intact)
Summary
-
G4h mirrors G3h's
--purgecross-instance safety pin at the lower-leveldelete-instancecommand. Same destructive recursion logic (Path.GetDirectoryNameon cert path,Directory.Deleterecursive guarded byIsSafeInstanceDir); pinning both surfaces ensures any regression in the shared safety guard breaks at least one test. - Operator scenario: a host runs Alpha (decommissioned) + Beta (live production).
sudo squid-tentacle delete-instance --instance AlphaMUST leave Beta fully untouched — if Beta's cert dir gets nuked, polling silently breaks hours later.
Test mechanism
- Register Alpha + register Beta (no service install needed — keeps test scope tight on instance management)
delete-instance --instance Alpha- Assert Alpha artefacts gone (happy path)
- Assert Beta config + cert dir + registry entry SURVIVE
- Assert stdout logs Alpha's deletion specifically; Beta is never mentioned
Test plan
-
dotnet buildgreen (0 errors) -
CI passes G4h_DeleteInstanceAlpha_DoesNotDestroyBetaState -
G4h asserts: Alpha config + cert dir gone + Beta config + cert dir + registry entry SURVIVE + log "Instance '{Alpha}' deleted" present + log NOT containing "Instance '{Beta}' deleted" -
Existing 46 Linux E2E tests still pass