Skip to content

Release candidate: this page describes 410fbfb, which is separate from main. See version and availability.

Provider test endpoints, sandboxes and local verification

Researched on 2026-09-10 against official provider/project documentation and CPRa source candidate 370a60b22dcbea3b7552de987ca6a2c5bfaaf671.

This reference covers the complete inventory: 14 health checks, five recovery drivers and 14 notification drivers. It records available testing approaches and their compatibility with the current source. No new provider test, account creation, fixture download or external operation was performed for this research. The existing six passing live local cases remain the only such evidence recorded in evidence/local/final-370a60b; a documented testing option is not a passing result.

Findings

The inventory does not require 33 production accounts. Based on the implementations and sources below, 22 driver types have a local verification route without a hosted provider account: all 14 health checks; Docker, webhook, Kubernetes and systemd recovery; and log, email, webhook and Mattermost notifications. Some require local fixture implementation, images, system permissions or configuration changes. These routes verify the operations CPRa actually implements, within the coverage limits in the matrix.

Other providers offer useful alternatives: Twilio's test credentials suppress real delivery, Telegram has a separate test environment, Slack offers developer sandboxes, and Microsoft offers eligible developers a Microsoft 365 sandbox. Moto provides a third-party EC2 mock. These options have different account requirements and establish different evidence; none should silently become a live delivery or real EC2 reboot result.

For negative availability findings, "not found" means no suitable public option was located in the official documentation reviewed. It is not proof that a provider has no private partner environment. A provider's button for testing an outgoing webhook does not verify CPRa's incoming event submission path.

Evidence categories for a future verification update

Category Meaning
Local integration Production CPRa driver communicates with an actual local service or protocol endpoint; the observer checks the operation at that boundary.
Mock contract A controlled server validates the documented request and supplies scripted replies/faults. This exercises serialization and error handling, not the provider backend.
Provider sandbox The provider's designated test service/account validates behavior within its documented sandbox scope. Delivery may be suppressed.
Live account A designated real resource or destination independently confirms the actual requested effect. This is specific evidence, not formal vendor certification.

These categories are recommendations, not fields already implemented in the live runner. internal/verification/runner.go currently reports pass/fail/not_configured and a single all_providers_verified flag; it requires an independently observed effect. Do not use a fabricated observer to force Twilio test credentials or an EC2 mock through that gate.

The practical next implementation is to record evidence type and observed boundary explicitly, add missing isolated endpoint selection where necessary, and run real local services alongside strict HTTP contract fixtures. Retain provider-account results separately. This research does not change the agreed release gate or claim that the missing live campaign has passed.

Health checks: 14 of 14 researched

CPRa check / build tag Current operation in CPRa Official documentation and usable local endpoint / fixture Account and configuration requirements What a passing case establishes; applicability limits
http / default Sends the configured HTTP method, headers and body; checks configured status codes, otherwise any 2xx. Go's official httptest.NewServer starts a real loopback HTTP server. Script successful status, unexpected status, delayed response, redirects and dropped connections while leaving CPRa's HTTP transport intact. This is an official Go test facility, not a mock of a named SaaS provider. No external account. Set url to the loopback URL and configure the expected response. Existing fixture already exercises this route. Independent handler request count/method/body receipt plus CPRa result establish the actual HTTP exchange. No assertion about any particular Internet service follows. NewServer works with Go 1.25; do not require the newer NewTestServer API.
tcp / default Opens and closes a TCP connection; no application payload. Official Go net.Listen and Listener.Accept provide a real local TCP endpoint. A listener that is opened, closed, or deliberately left unresponsive supports reachability/failure cases. No account. Loopback host and an available port. Accepted-connection counters plus CPRa results prove TCP reachability. This check cannot establish application-level health.
icmp / default Sends ICMP echo requests and requires at least one response. Linux uses the dependency's unprivileged ping mode. The exact dependency's first-party pro-bing documentation documents ICMP echo behavior and Linux ping_group_range prerequisites. Use loopback or a disposable network namespace with a real kernel ICMP responder. No account. Local OS permission for ping sockets; inspect the existing Linux configuration first. CPRa selects unprivileged mode on Linux, so a raw-socket mock alone does not exercise that path. Kernel replies and independently observed echo request/reply counts establish actual ICMP behavior. Block or isolate only the dedicated test target for negative cases.
dns / default Calls LookupHost for A/AAAA address resolution; a configured resolver is dialed on port 53. CoreDNS's official hosts plugin serves controlled A/AAAA records from an inline Corefile or hosts file; the CoreDNS manual documents its Docker image. CoreDNS is an actual open-source DNS implementation. No account or registered domain needed. Use a reserved test name with a controlled DNS server. Bind isolated loopback/container port 53 because current CPRa server cannot specify a custom port. Avoid overriding the machine's normal resolver. Query logs plus positive lookup, NXDOMAIN and unavailable-server cases establish resolver behavior. CPRa currently tests successful resolution, not equality to an expected address or an SRV record.
udp / default Sends a required nonempty configured payload and waits for a nonempty datagram reply. Official Go net.ListenPacket provides a real local UDP socket; implement an echo responder and a no-reply mode. This is a custom protocol fixture using the official standard library, not a provider emulator. No account. Loopback host, free port, nonempty payload. Server-side received payload/reply counters plus result prove a round trip. CPRa does not compare response contents with an expected value; a successful UDP connect alone is insufficient.
grpc / default Only TCP reachability, despite the type name and accepted service setting. No RPC is sent. gRPC publishes the standard health service and an official Go health server example, which can run locally. No account. Local host/port; use the real example server to expose the current boundary. The present job can only prove its port is listening. Switching the example service from SERVING to NOT_SERVING while retaining the listening socket will not make CPRa fail. A full grpc.health.v1.Health/Check test requires an actual driver enhancement; a mock cannot supply the missing behavior.
docker / default Calls daemon ContainerInspect and requires State.Running; does not inspect Docker HEALTHCHECK status. Docker documents docker container inspect. Use a real installed daemon with an isolated running/stopped disposable container, and inspect it independently. No hosted account. Access to the local daemon and an available container image; daemon address/credentials use the normal Docker environment. Match CPRa outcomes to independently inspected running/stopped state. This path already has live local passing evidence in the candidate. It is Docker daemon integration, not an HTTP mock.
tls / default Completes TLS handshake and reports leaf-certificate expiration; optional warning/critical day thresholds. Official OpenSSL s_server supplies a real TLS endpoint accepting chosen certificate/key material. Go's httptest.NewTLSServer is another official local test facility. No account. Generate test CA/leaf certificates and configure host, port, server_name and thresholds. To prove trust/name validation, make the test CA trusted by the isolated test process; insecure_skip_verify cases only establish the explicitly insecure mode. Server handshake logs and known certificate dates establish handshake/expiration results; include valid, expired, untrusted and wrong-name cases. No public certificate purchase or live third-party endpoint is required.
redis / redis Connects using optional username/password and selected DB, then issues RESP PING. Redis's official Docker instructions use redis:<version>; the official PING reference describes its response. Existing compose profile is redis:7.4. No hosted account. Local fixture credentials, addr, optional username/password/db; enable the redis build tag. Observe actual PING/response on the dedicated server or via an auditing relay and verify wrong-password and offline failures. Current schema does not configure Redis TLS; this local route validates the supported plain RESP path.
postgres / postgres Authenticates through pgx and runs its ping operation (current pgx sends the SQL comment -- ping, not a business query). PostgreSQL's official pg_ctl can initialize/start/stop a disposable cluster. postgres Docker Official Image is maintained by the PostgreSQL Docker Community and documents initialization credentials; current compose profile is postgres:17. No hosted account. Local database/user/password, DSN or discrete fields, sslmode; enable postgres. Successful protocol ping plus server/relay evidence establishes connectivity/authentication and query round trip. Include bad credentials and shutdown. It does not establish arbitrary SQL correctness or managed-service compatibility.
mysql / mysql Uses database/sql.PingContext with go-sql-driver/mysql, issuing COM_PING after connection/authentication. Oracle's official MySQL 8.4 Docker instructions provide container-registry.oracle.com/mysql/community-server:8.4. The separate mysql Docker Official Image documents fixture environment variables; current compose uses mysql:8.4. Community server needs no hosted database account; configure local user/password/database and DSN or discrete fields; enable mysql. Oracle's Enterprise image is a different subscription/login route and is unnecessary here. Observe real connection/COM_PING request and response plus success/failure results; wrong credentials and server shutdown are negative cases. No business data write is performed by CPRa's check.
mongo / mongo MongoDB driver connects and sends ping using primary read preference; explicitly rejects mongodb+srv:. MongoDB's own Community Docker guide provides the vendor-maintained mongodb/mongodb-community-server image, and ping documentation defines the command. The current compose's mongo:8.0 is a separate Docker Official Image, not MongoDB's vendor-maintained image. No Atlas/cloud account. Direct mongodb://127.0.0.1:<port> URI, local credentials if enabled; build tag mongo. Check host CPU requirements for the selected server version (MongoDB 5+ images require AVX). Observe actual command traffic and ping result; stop the local server for failure. Using the vendor image is possible with fixture adjustment and version/digest recording. This does not remove or test support for SRV discovery.
rabbitmq / rabbitmq Opens an AMQP 0-9-1 connection and channel, then closes both; does not publish/consume. RabbitMQ's official installation page recommends the community-maintained rabbitmq:4-management Docker image for workstation experiments. The official Go tutorial shows connection/channel operations with the same amqp091-go client family. Current compose pins rabbitmq:4.1-management. No hosted account. Dedicated local user/password/vhost in the AMQP URL; enable rabbitmq. Use an explicit fixture user rather than depending on guest's remote-login restrictions. Observe successful authentication/channel open, wrong-password rejection and stopped-broker failure. A message round trip could validate the fixture independently, but cannot be claimed as CPRa check behavior because this driver sends no messages.
kafka / kafka franz-go Ping sends a broker-only Metadata request and succeeds when a broker responds; no produce/consume. Apache's official quickstart offers a local server and Apache-maintained apache/kafka / apache/kafka-native Docker images. Current compose uses apache/kafka:3.9.1 in single-node KRaft mode. No Confluent/cloud account. Reachable broker addresses and matching advertised listener configuration; enable kafka. Current CPRa schema only exposes brokers/retries, so a local PLAINTEXT listener matches the implemented configuration; SASL/TLS account modes are not configured by this driver. Broker/relay traffic and successful metadata response prove supported protocol reachability. Wrong address/stopped broker establishes failure. This is not producer/consumer delivery evidence.

Recovery drivers: 5 of 5 researched

These are documented testing options, not newly executed verification results. Source inspected: CPRa 370a60b.

Driver Test endpoint, local implementation or mock Hosted account needed? CPRa applicability and evidence boundary
docker Real local Docker Engine with a disposable container. Docker documents the restart API. A local HTTP server can also implement that API contract for failure tests. No hosted account; daemon access and an available image are required. Existing production driver uses DOCKER_HOST and API negotiation. Existing docker_local.py verifies a changed container start time. A mocked 204 response alone cannot demonstrate process replacement.
webhook Isolated local HTTP receiver with a state change and receipt endpoint; Go supplies HTTP test servers. This is a CPRa-owned protocol fixture, not a vendor sandbox. No. Configurable URL, method, headers and body already work with the production driver. Existing local.py exercises this path. Independently inspect the receiver's state and test a lost response after applying the effect.
kubernetes Kubernetes SIGs' kind runs actual Kubernetes nodes in containers. envtest starts an API server and etcd but omits kubelet and built-in controllers. No cloud account; local runtime, images and resources are required. Use kind and a dedicated Deployment for completed rollout/scale evidence. Existing driver accepts a designated kubeconfig with token/certificate credentials. envtest is appropriate for API validation, not proof that Pods were replaced. Current exec-credential restriction remains.
aws AWS RebootInstances DryRun checks permission without rebooting. Third-party Moto documents reboot_instances support and server mode for non-Python clients. LocalStack is another third-party emulator with mock/Docker EC2 backends. AWS DryRun needs AWS credentials and designated resources; Moto can use fake local credentials without an AWS account. LocalStack has its own account/licensing requirements. Candidate already uses AWS SDK v2 endpoint configuration: AWS_ENDPOINT_URL_EC2 can target Moto without replacing the production HTTP transport. This was confirmed in the pinned SDK source and AWS endpoint documentation. Candidate does not expose or set DryRun. Add a separate validation path if wanted. Moto establishes emulated request/response behavior, not real EC2 reboot. AWS success itself only queues a reboot.
systemd A dedicated local service managed by actual systemd. Upstream documents transient service creation and the D-Bus RestartUnit interface. No hosted account; system bus and permission to manage the dedicated unit are required. Existing driver uses the system bus, so a user-bus-only fixture would not exercise it. Observe a changed invocation/process identity and active state after restart; current observe_effect.py systemd does this. D-Bus mocks can separately exercise job completion/failure without proving a real restart.

AWS mock selection

Moto is the simpler candidate for account-free EC2 contract testing because its support list explicitly includes reboot_instances. Support documentation does not establish that the chosen Moto version models a reboot side effect; pin it and verify the exact behavior. The current runner's guest-boot observer must not pass against a mock response. Introduce an explicit emulated-evidence mode before reporting these results.

LocalStack's current EC2 operation table omits RebootInstances and states that unlisted Docker-backend operations use its mock manager. Do not claim a Docker-backed guest actually rebooted. Its current licensing documentation describes an authenticated Hobby option and separately approved OSS sponsorship; it should not be described as universally account-free.

Code references

  • internal/jobs/intervention_aws.go: LoadDefaultConfig, ec2.NewFromConfig, and the reboot call without DryRun.
  • go.mod: AWS config v1.32.38, EC2 v1.322.0; pinned EC2 endpoints.go reads AWS_ENDPOINT_URL_EC2.
  • internal/jobs/intervention_kubernetes.go: Deployment patch/scale and exec-credential rejection.
  • internal/jobs/intervention_systemd.go: system-bus connection and completed job outcome.
  • internal/jobs/intervention_webhook.go: configurable HTTP target and ambiguous-outcome handling.
  • internal/jobs/jobs.go: Docker inspection and restart.
  • scripts/verification/{local.py,docker_local.py,observe_effect.py} and examples/verification/{kubernetes.yaml,cpra-verification.service}.

The freedesktop HTML manual returned HTTP 403 to the research reader; the corresponding systemd-owned manual source was read instead.

Notifications: 14 of 14 researched

Driver Documented test option and classification Account, delivery, and CPRa fit
log Real local filesystem, no vendor or mock needed. CPRa appends JSON lines to the configured file. No account. Configure file under a disposable directory and independently read the result. This exercises the actual implementation, including directory creation and append errors. Code: internal/jobs/jobs.go:1019. High confidence.
slack First-party developer sandbox through the Slack Developer Program. A dedicated normal test workspace/channel also works. Developer sandboxes, incoming webhooks. Enrollment is open, but provisioning needs qualifying paid-workspace membership or payment-method identity verification; the verification is not charged. Enterprise policy can require approval. Sandbox webhooks deliver real messages inside that sandbox; this is not a no-send API. CPRa’s hook URL already supports a sandbox webhook or our own local HTTP protocol mock. Code: jobs.go:1155. High confidence for documented sandbox; account eligibility remains untested.
pagerduty Real trial/test account and service using Events API v2; alternatively an independently implemented local protocol mock. No public no-send Events API sandbox or provider-hosted mock was found in the reviewed docs. Trial onboarding, Events integration setup. Trial signup currently requires a work email. Events require a service integration/routing key and may create actual incidents/notifications according to its configuration. CPRa’s url already permits a local mock or regional endpoint. PagerDuty’s outbound webhook “Send Test Event” tests the opposite direction and does not verify CPRa’s Events API integration. Code: jobs.go:1112. High confidence for trial/API path; moderate confidence for absence of a dedicated sandbox.
email / SMTP Mailpit SMTP capture fixture, an open-source test service, not a Gmail/Exchange/provider emulator. Its maintainers document SMTP, optional STARTTLS, intercepted-message UI/API, and configurable SMTP error injection. Mailpit features, official Docker images. No hosted account. CPRa’s configurable server can send through its actual SMTP implementation; verify the captured message through Mailpit’s independent API. Use trusted local allow_insecure for plain local SMTP, or configure trusted STARTTLS. CPRa currently does not perform SMTP AUTH, so an unauthenticated local relay fits its current path. Avoid enabling Mailpit forwarding/relaying. This validates SMTP acceptance/content, not Internet mailbox deliverability. Code: notifications.go:56, schema groups.go:69. High confidence.
webhook Real local HTTP receiver / protocol fixture. There is no specific external provider for this driver. Go’s standard library provides local HTTP test servers. Go httptest. No account. Configure url, method and headers to a dedicated receiver; assert the request independently and inject rejection, timeout, disconnect, and delayed-response scenarios. An arbitrary success-returning public URL would not establish payload correctness. Code: jobs.go:1214, groups.go:90. High confidence.
telegram First-party dedicated test environment, with https://api.telegram.org/bot<token>/test/METHOD_NAME. Alternatively use a separate normal bot for testing. Testing your bot / dedicated test environment. Requires a separate test-environment user and bot created through BotFather. Messages are real within the isolated test environment; production users are separate. Flood limits are not lifted. CPRa currently hardcodes /bot<token>/sendMessage, so proper test-mode/base-URL configuration is needed; do not hide /test inside a credential string. A local Bot API server is a Telegram gateway, not an offline mock of Telegram. Code: jobs.go:1254, schema manifest.go:725. High confidence.
discord Dedicated test server/channel with incoming webhook, or our own local protocol mock. No dedicated public no-send webhook sandbox was found in the reviewed API docs. Discord webhook resource. A Discord user/server with permission is needed to create the webhook; executing it needs the webhook URL/token, not a bot account. Messages really appear in the selected channel. CPRa’s webhook_url supports local mocks and a real test channel. Use ?wait=true for provider confirmation: the docs warn that with the default false, an unsaved message need not return an error. Independent channel observation is stronger than HTTP acceptance. Code: jobs.go:1290. High confidence for API; moderate for no sandbox found.
opsgenie Local protocol mock, or an existing designated Opsgenie account/integration. Atlassian’s migration demo is a limited migration trial for existing Opsgenie owners, not a general no-account alert sandbox. Alert API, migration demo, end-of-sales/support notice. url already configurable for a local mock/EU endpoint. Real calls require integration API keys; HTTP 202 means asynchronous acceptance, so the observer must check request status/created alert. New sales ended June 4, 2025; support ends April 5, 2027. No public no-send alert endpoint/mock was found. Code: jobs.go:1332. High confidence for API/lifecycle; moderate for no alternative found.
mattermost First-party local Docker Preview / self-hosted Mattermost, i.e. the actual server rather than an API imitation. Container deployment, incoming webhooks. No cloud account or purchase needed for the documented local evaluation route; create fixture-local users/channel/webhook. The preview is self-contained and disables email by default. Messages appear in the local Mattermost channel, enabling independent read-back. CPRa’s webhook_url already accepts that server or a simpler local protocol mock. Preview is disposable and not a production deployment. Code: code_mattermost.go:28. High confidence.
victorops / Splunk On-Call Local protocol mock. If an account already exists, message_type: INFO is a documented lighter real operation: it adds a timeline event without triggering an incident. REST endpoint integration. Real calls need an enabled integration endpoint key and routing key. INFO still writes real account data and does not test critical-alert escalation. CPRa supports message_type but hardcodes the provider URL; a full URL override is needed for a normal local network mock. No first-party no-send sandbox/mock or authoritative On-Call retirement date was found in the reviewed docs; do not conflate other Splunk products’ end-of-life notices. Code: code_victorops.go:30 and :40. High confidence for INFO/API; moderate for absence/lifecycle search.
pushover First-party credential/user validation endpoint POST /1/users/validate.json, plus our own local message-API mock. Pushover API / user validation. Validation requires a real app token and user/group key; it checks a usable user/device without posting a notification. It does not exercise CPRa’s /1/messages.json production send operation. Quiet/lowest-priority sends are still real delivery, not a sandbox. The sample token in docs is explicitly nonfunctional. CPRa hardcodes the message host, so a URL override is needed for a normal local mock. No documented send-message sandbox was found. Code: code_pushover.go:91. High confidence for validation boundary; moderate for no sandbox found.
datadog First-party API-key validation endpoint GET /api/v1/validate, plus our own local Events API mock. API-key validation, posting events. Key validation needs an organization API key and checks authentication only. CPRa posts real v1 events; validation does not prove ingestion. No documented no-send sandbox for this operation was found. site selects https://api.<site>/api/v1/events; it is not a general local base-URL field. Add an explicit endpoint override for a local network mock; do not treat a local Datadog Agent as an Events API emulator. Code: code_datadog.go:66. High confidence for endpoints; moderate for absence. The web reader rejected these pages’ content type, so their current page HTML was also retrieved read-only directly.
teams Microsoft 365 E5 developer sandbox for qualifying members, with a real Workflows/Power Automate webhook; or a local JSON/Adaptive Card protocol mock. Developer sandbox setup, Teams incoming webhooks, connector retirement. The sandbox requires qualification and, in current docs, a valid billing account; the sandbox itself is not charged. Messages sent to a real workflow are delivered inside its tenant/channel, not suppressed. CPRa already supports configurable webhook_url and an Adaptive Card under the teams build tag. Test workflow permissions/authentication and completed channel delivery, not just request acceptance. Legacy Office 365 connector shutdown was scheduled for May 18–22, 2026; use Workflows. High confidence for documented alternatives; user eligibility untested.
twilio First-party test credentials and magic phone numbers for the exact SMS Messages API used by CPRa. Twilio test credentials. Account required to obtain the test Account SID/Auth Token, but no purchased sending number is needed for these tests. Requests use the normal host with the test SID; From: +15005550006 selects success and documented magic inputs exercise failures. No charges, real SMS, production-account mutations, or delivery status callbacks occur. This works through current CPRa configuration and twilio build tag; a local network mock would separately need endpoint configurability. It verifies provider-side validation and synchronous outcomes, not carrier/device delivery. Code: code_twilio.go:54. High confidence.

Changes implied by an account-free test suite

Seven HTTP notification drivers already have configurable endpoint URLs: Slack, PagerDuty, generic webhook, Discord, Opsgenie, Mattermost, Teams. They can exercise their real network code against a local receiver whose responses and independently stored receipts follow the provider’s published contract. Local-target settings must agree with CPRa’s configured SSRF policy; this is a deliberate isolated fixture setup, not a reason to weaken production defaults.

Five currently fix the host/path or expose only a site selector: Telegram, VictorOps, Pushover, Datadog, Twilio. Existing unit contract tests replace the transport (internal/jobs/provider_contract_test.go:19, tagged_notification_contract_test.go:14), so fast mock testing is already possible. To include these in a configuration-driven external network suite, add explicit endpoint configuration while preserving default production URLs, credential redaction, and conservative replay behavior. Telegram additionally needs a genuine test-mode path. Twilio’s official test credentials require no code change.

Use separate evidence labels: local protocol contract passed, actual local service passed, provider sandbox/test API passed, and real destination effect observed. No tests were executed during this documentation research, so these findings do not increase the current passing-provider count.

Existing repository coverage and the next practical step

The source already contains sequential real-server fixtures for Redis, PostgreSQL, MySQL, MongoDB, RabbitMQ and Kafka in examples/verification/fixtures.compose.yaml, with the database_local.py runner. It starts one server at a time and forwards the unmodified production protocol through a byte-counting TCP relay. Its physical-disk prerequisite applies before starting or pulling those fixtures. The relay currently proves fresh connections and bidirectional traffic; a decoded command trace or target-side operation counter is stronger proof of the named operation. Do not overstate byte counts alone as command-level evidence.

The historical local final-370a60b campaign summary recorded six local passes across all driver categories, with HTTP and Docker being the two health-check passes. Prepared database/broker profiles are not new passing results. The full account-free health-check campaign can be expanded with loopback TCP/UDP/TLS, kernel ICMP, a controlled CoreDNS server, and the official gRPC example; the last must retain the explicit TCP-only coverage label.

For regression testing, local protocol responders can deliberately send malformed frames, delayed replies, or disconnects. Those supplement actual server tests. No official cloud sandbox is needed for these 14 checks, and no hosted-account evidence should be asserted from the local campaign. Container versions/digests and account-free test scope should be recorded in the resulting matrix; examples above describe the current fixtures and documented alternatives rather than asserting that all listed version tags are newly validated.

Local code grounding

Configuration gaps exposed by this research

  • The example DNS case uses server: 127.0.0.1:15353, but the current driver appends port 53 itself. This configuration will not work as written. A host-only server on an isolated port 53 or explicit custom-port support is needed before that case can pass.
  • Telegram needs a real test-environment selector. A credential string must remain a credential, not an implicit way to insert /test/ into an API path.
  • Twilio's existing credential fields can call its official test API, but the live runner's delivery observer is unsuitable for intentionally undelivered SMS. Record provider-side validation separately.
  • AWS supports local SDK endpoint selection already, but a mock needs its own contract observer/evidence class. AWS DryRun is not currently exposed by CPRa and does not prove a reboot.
  • For fixed notification URLs, add explicit isolated-test endpoint configuration before claiming that the external mock suite uses an unchanged production transport. Existing in-process transport stubs remain unit contract tests.

Research recommendations should be implemented and measured before any matrix row is marked passed. Public release documentation remains tied to the candidate's completed evidence, not this list of available tools.

Implemented verification tooling since this research

This research is the dated design background. The reviewed candidate now includes notification contract fixtures, protocol listeners, actual database-service fixtures, local Mattermost, Moto and isolated cluster checks. Use provider test environments for current commands, supported endpoint overrides and evidence fields. Historical local passes are not refreshed provider-account certification.