test(lab): add Asterisk lab — a fake PSTN for media validation
An Asterisk instance that answers calls, plays an IVR, holds with music and connects a "human", so the gateway has something real to dial that is not the PSTN: no charges, no strangers, no E911 exposure. Asterisk rather than Kamailio because the unproven risks are media risks. Kamailio is a proxy — it routes signalling and answers nothing, so it would forward the INVITE and find nobody home. Asterisk is a B2BUA: it answers, plays prompts and collects DTMF, which is the hold-slayer scenario itself. Kamailio remains the better model for trunk registration/digest auth later. No application changes are needed to use it. SIP_TRUNK_HOST is just an address, so the production code path runs unmodified — there is no test-only branch anywhere in the gateway. It also means safety is structural: while the trunk points at the lab there is no route to the PSTN at all, an absence of route rather than a policy that could be misconfigured. Nine scenarios (1001-1008 plus an echo test) cover the baseline call, the IVR/DTMF path, hold-then-human, long hold, busy, no-answer, remote hangup and silence. The image ships no sound files, so sounds/generate.py synthesises three fixtures from fixed seeds — byte-identical on every run, which is what makes a classifier regression distinguishable from noise. Verified against AudioClassifier: music→MUSIC 0.85, speech→LIVE_HUMAN 0.75, silence→SILENCE 1.00. The speech formants deliberately avoid the DTMF bands; the first version landed on a valid pair and classified as a keypress. Anonymous inbound calls are refused, and endpoint matching is by source address — Asterisk's default matches the From-header domain, which Hold Slayer populates from its SIP bind address (0.0.0.0 on a wildcard bind). Generated audio and the rendered per-host configs are gitignored: the former is reproducible from a fixed seed, the latter carry a host-specific IP and the lab password. Known limit, documented in the README: MediaPipeline.create_tap is a stub, so the classifier receives no audio on a live call. RTP flows and Asterisk plays audio, but the tap is never fed — the fixture results above were measured by feeding the classifier directly. This blocks scenarios 1002/1003/1004. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
28
tests/lab/docker-compose.lab.yml
Normal file
28
tests/lab/docker-compose.lab.yml
Normal file
@@ -0,0 +1,28 @@
|
||||
# Local Asterisk lab — for iterating on caliban before promoting to Virgo.
|
||||
#
|
||||
# This is the LOCAL variant: ports and credentials are concrete, not Jinja.
|
||||
# Ansible templates the same dialplan out to galatea with the estate's
|
||||
# variables (see virgo/ansible/asterisk/).
|
||||
#
|
||||
# Run: docker compose -f docker-compose.lab.yml up -d
|
||||
# CLI: docker compose -f docker-compose.lab.yml exec asterisk asterisk -rvvv
|
||||
#
|
||||
# host networking: SIP/RTP carry IP addresses *inside* the payload, so a
|
||||
# bridged network needs external_media_address set correctly or the call
|
||||
# connects with no audio. Host networking sidesteps that entirely for local
|
||||
# work. The Virgo deploy uses the same approach for the same reason.
|
||||
services:
|
||||
asterisk:
|
||||
image: andrius/asterisk:22.10.1_debian-trixie
|
||||
container_name: asterisk-lab
|
||||
network_mode: host
|
||||
volumes:
|
||||
- ./dialplan/extensions.conf:/etc/asterisk/extensions.conf:ro
|
||||
- ./dialplan/pjsip.local.conf:/etc/asterisk/pjsip.conf:ro
|
||||
- ./dialplan/rtp.local.conf:/etc/asterisk/rtp.conf:ro
|
||||
- ./dialplan/logger.conf:/etc/asterisk/logger.conf:ro
|
||||
# The image ships no sound files at all. These are generated by
|
||||
# sounds/generate.py; Asterisk resolves Playback(lab-music) to
|
||||
# lab-music.sln here (8kHz signed-linear, no transcoding).
|
||||
- ./sounds:/var/lib/asterisk/sounds/en:ro
|
||||
restart: unless-stopped
|
||||
Reference in New Issue
Block a user