"""Locust load test for DocuVault — D-04, D-05, D-06. Strategy: self-bootstrapping (Option A) — on_start registers the load-test user (409 ignored if already exists), then logs in to get an access token. Run (headless, matches Phase 6 SLA gate): locust --headless --users 50 --spawn-rate 10 --run-time 5m \\ --host http://localhost:8000 \\ --csv backend/load_tests/results \\ -f backend/load_tests/locustfile.py Prerequisites: pip install -r backend/requirements-dev.txt docker compose up # backend, postgres, minio must be running Exit codes (enforced by check_sla listener): 0 — all SLA thresholds met 1 — p95 > 200 ms, OR p99 > 500 ms, OR fail_ratio > 1% Cleanup the load-test user: docker compose exec postgres psql -U docuvault -c \\ "DELETE FROM users WHERE email='loadtest@example.com';" """ import os from io import BytesIO from locust import HttpUser, between, events, task TEST_EMAIL = os.environ.get("LOAD_TEST_EMAIL", "loadtest@example.com") TEST_PASSWORD = os.environ.get("LOAD_TEST_PASSWORD", "Loadtest123!@#") TEST_HANDLE = "loadtestuser" # Minimal synthetic PDF — valid enough for the upload parser _FAKE_PDF = b"%PDF-1.4\n1 0 obj<>endobj\nxref\n0 2\ntrailer<>\n%%EOF" class DocuVaultUser(HttpUser): """Simulated DocuVault end-user exercising all authenticated endpoints. Task weights mirror a realistic read-heavy session per D-05: 5 — list documents (most common action) 3 — get single document 2 — upload a document 1 — refresh access token """ wait_time = between(0.5, 2.0) access_token: str = "" def on_start(self) -> None: self.client.post( "/api/auth/register", json={"handle": TEST_HANDLE, "email": TEST_EMAIL, "password": TEST_PASSWORD}, ) resp = self.client.post( "/api/auth/login", json={"email": TEST_EMAIL, "password": TEST_PASSWORD}, name="POST /api/auth/login", ) if resp.status_code == 200: self.access_token = resp.json().get("access_token", "") else: self.environment.runner.quit() def _auth_headers(self) -> dict: return {"Authorization": f"Bearer {self.access_token}"} @task(5) def list_documents(self) -> None: self.client.get("/api/documents/", headers=self._auth_headers(), name="GET /api/documents/") @task(3) def get_document(self) -> None: resp = self.client.get( "/api/documents/", headers=self._auth_headers(), name="GET /api/documents/ (for get_document)", ) if resp.status_code == 200: docs = resp.json() if docs: doc_id = docs[0]["id"] self.client.get( f"/api/documents/{doc_id}", headers=self._auth_headers(), name="GET /api/documents/{id}", ) @task(2) def upload_document(self) -> None: # Direct single-step upload to /api/documents/upload (confirmed against documents.py: # accepts UploadFile `file` + Form `target_backend` — simpler than the presigned flow). self.client.post( "/api/documents/upload", headers=self._auth_headers(), files={"file": ("load_test.pdf", BytesIO(_FAKE_PDF), "application/pdf")}, data={"target_backend": "minio"}, name="POST /api/documents/upload", ) @task(1) def refresh_token(self) -> None: self.client.post( "/api/auth/refresh", headers=self._auth_headers(), name="POST /api/auth/refresh", ) @events.quitting.add_listener def check_sla(environment, **kwargs) -> None: """Gate the Locust exit code on D-06 SLA thresholds.""" stats = environment.runner.stats.total p95 = stats.get_response_time_percentile(0.95) p99 = stats.get_response_time_percentile(0.99) fail_ratio = stats.fail_ratio if fail_ratio > 0.01: print(f"SLA FAIL: fail_ratio={fail_ratio:.2%} > 1%") environment.process_exit_code = 1 elif p95 > 200: print(f"SLA FAIL: p95={p95:.0f}ms > 200ms") environment.process_exit_code = 1 elif p99 > 500: print(f"SLA FAIL: p99={p99:.0f}ms > 500ms") environment.process_exit_code = 1 else: print(f"SLA PASS: p95={p95:.0f}ms p99={p99:.0f}ms fail_ratio={fail_ratio:.2%}")