# zriz > zriz runs end-to-end tests of your own app: HTTP calls and database checks, from pipeline files in your repo. The CLI is `zz`. Each command prints one JSON object. Its `hints` name the next command. **Start.** Run these in the folder of your service: curl -fsSL https://zriz.io/install | sh ~/.local/bin/zz login ~/.local/bin/zz init --url http://localhost:3000 ~/.local/bin/zz run hello **Done** is a run with status `pass`. Nothing less. ## Rules - `zz` is right. If a page and `zz` differ, do what `zz` says. - Run `zz guide` before you write a pipeline. Do not guess the format. - Keep secrets out of resource files. Put them in the environment file and list them in `sensitive`. - `zz:` at the top of a page is the lowest version the page is true for. `zz version` shows yours. `zz upgrade` updates it. - `draft` means not tested or not approved. Tell your user before you use it. - `Your user must` marks a step you cannot do. Ask your user. - If a step fails and `If not` does not name what you see, stop and tell your user. - A list of supported items is complete. What is not in it is not supported. - A failed run names a reason. Read `https://zriz.io/docs/errors.md#`. - In a code block, `` is text you replace. `sh` and `sql` are things to run. `json` and `yaml` are files. - Compare `You should see` with the output line by line, in order. The output can have more lines. `` there matches any text. ## Pages and questions - [zriz quick start](https://zriz.io/docs.md): Install zz, log in, make a project, and run the sample test in four commands. The work is done when the run has status pass. The commands need zz 0.4.0 or later. (draft) - [What zriz tests and what it does not](https://zriz.io/docs/supported.md): zriz tests HTTP APIs, Postgres, and MySQL. On a deployed runner it also tests browser flows and command-line tools. It tests nothing else. - [Which resource types does zriz have?](https://zriz.io/docs/supported.md#resource-types): Four: http, sql, browser, and cli. There is no other type. Each run needs a runner. - [Can zriz test an HTTP API?](https://zriz.io/docs/supported.md#http): Yes. A step calls an action of an http resource. A check reads the status and the body of the reply. - [Can zriz test a Postgres database?](https://zriz.io/docs/supported.md#postgres): Yes. A step runs a query of an sql resource. A check reads rows and row-count. - [Can zriz test a MySQL database?](https://zriz.io/docs/supported.md#mysql): Yes. A step runs a query of an sql resource. A check reads rows and row-count. - [Can zriz test a different database?](https://zriz.io/docs/supported.md#other-databases): No. zriz tests Postgres and MySQL. It tests no other database. - [Can zriz test a browser flow?](https://zriz.io/docs/supported.md#browser): Yes. The runner needs the worker, a second container. zz runners init adds the worker to compose.yml when the project has a browser resource. - [Can zriz test a command-line tool?](https://zriz.io/docs/supported.md#cli): Yes. The runner needs the worker. The runner runs only the commands that its config permits. - [Which operating systems does zz run on?](https://zriz.io/docs/supported.md#operating-systems): macOS and Linux, on arm64 and x86_64. The install script stops on each other system. There is no install for Windows. - [Can zriz run in CI?](https://zriz.io/docs/supported.md#ci): Yes. zz asks no question, and each command prints one JSON object. zz run ends with exit code 0 only when the status is pass. - [Limits of the zriz free tier](https://zriz.io/docs/limits.md): The free tier gives each org one run at a time and 50 runs a day. The count starts again at 00:00 UTC. zriz is in open beta. (draft) - [How many runs a day does the free tier give?](https://zriz.io/docs/limits.md#runs-a-day): 50 runs a day for each org. All the projects of the org share the count. (draft) - [How many runs can I do at the same time?](https://zriz.io/docs/limits.md#at-a-time): One. A second start at the same time gets 429 with the error too-many-runs and the scope org. (draft) - [When does the count start again?](https://zriz.io/docs/limits.md#reset): At 00:00 UTC, each day. (draft) - [What happens at the limit?](https://zriz.io/docs/limits.md#at-the-limit): The cloud refuses the run. zz run prints the error too-many-runs with the number of seconds to wait, and ends with exit code 5. (draft) - [Where do I see the count?](https://zriz.io/docs/limits.md#count): On the runs page of the web app, at the path /app/runs. Sign in first. (draft) - [How do I read the limits of my org?](https://zriz.io/docs/limits.md#org): GET /api/org shows the tier, the limits and the runs of today. Send your API key in the header x-api-key. Each role can read it. (draft) - [Does the free tier include each resource type?](https://zriz.io/docs/limits.md#resource-types): Yes. The free tier includes http, sql, browser, and cli resources. There is no other type. (draft) - [Words that zriz uses](https://zriz.io/docs/words.md): Each word of zriz has one meaning: org, project, pipeline, step, check, resource, environment, runner, run. - [End-to-end tests an AI agent can write](https://zriz.io/docs/agent-e2e-tests.md): Give your coding agent one instruction. It installs the zriz CLI, writes one test for a flow of your service, and runs it. The work is done when the run has status pass. (draft) - [Test an API call and the database row](https://zriz.io/docs/api-and-database-test.md): Write one zriz pipeline with two calls: a POST to your API, then a select of the new row. A check compares the row with the value that the test sent. (draft) - [Write your first zriz test](https://zriz.io/docs/first-test.md): Add one HTTP call of your own service to the project, write one pipeline with one check, and run it. The work is done when the run has status pass. (draft) - [zriz pipelines](https://zriz.io/docs/pipelines.md): zriz runs API tests: a pipeline calls HTTP endpoints and SQL queries, then checks the replies. zz runs pipelines. - [Errors of zriz](https://zriz.io/docs/errors.md): A run that does not pass has a cause. This page has one entry for each of the 60 reason words. 52 are for a run, 5 are for zz and 3 are op words. - [Deploy a zriz runner with Docker](https://zriz.io/docs/runner.md): Build the runner image from its source, give it a token and a config file, and start it with Docker. The work is done when a run has status pass on this runner. (draft) - [Test a database in a private network](https://zriz.io/docs/test-private-database.md): Put a zriz runner inside the network. It makes outbound connections only, so you open no port. The work is done when a run on the runner has status pass. (draft) - [Create a read-only Postgres user](https://zriz.io/docs/postgres-read-only-user.md): Create a role with login. Grant it connect on the database, usage on the schema, and select on the tables. The role can read each table and can write to none of them. - [Run end-to-end tests in GitHub Actions](https://zriz.io/docs/github-actions-e2e-tests.md): Start the service and a runner in the job. Then run the tests against localhost. A job has no browser, so the login is an API key from a secret. (draft) - [zriz notifications of run results](https://zriz.io/docs/notify.md): zriz sends no email for a run result now. It records a notice for a run that a deployed runner did. Each member sets a choice for these notices on the page Notifications of the web app. (draft) - [Members and roles of a zriz org](https://zriz.io/docs/team.md): An admin invites a person by email with zz members invite. An org has three roles: admin, member, and viewer. There is no other role. - [How do I invite a person?](https://zriz.io/docs/team.md#invite): An admin does zz members invite . The invite gives the role member and stays open for 7 days. - [What can each role do?](https://zriz.io/docs/team.md#roles): An admin can do each action. A member can start runs but cannot manage members or runner tokens. A viewer can only read. - [Where do I see the members and my role?](https://zriz.io/docs/team.md#list): zz members lists the members with their roles, and the open invites. Each role can do this command. - [How do I change the role of a member?](https://zriz.io/docs/team.md#change-role): An admin does zz members role . The role is admin, member, or viewer. - [How do I remove a member?](https://zriz.io/docs/team.md#remove): An admin does zz members remove . The person is no longer a member, and the cloud ends the web sessions of the person. - [How do I cancel an invite?](https://zriz.io/docs/team.md#cancel-invite): An admin does zz members uninvite . The id is the field id of the invite in the reply of zz members. - [What does an invited person see?](https://zriz.io/docs/team.md#join): The join link opens a page with the heading Join . The page shows the address and asks for a new password. - [How do I work in two orgs?](https://zriz.io/docs/team.md#two-orgs): Use two emails. One email is one account in one org. - [Is zriz safe? Security and your data](https://zriz.io/docs/security.md): zriz is built so that database passwords and connection strings stay in your network. A value that you do not list in sensitive goes to the cloud. (draft) - [Does the cloud see my database password?](https://zriz.io/docs/security.md#database-password): No, for a database connection. zriz is built so that zz or the runner holds the connection string, and the cloud has no database driver. (draft) - [What never leaves my network?](https://zriz.io/docs/security.md#never-leaves): zriz is built so that the connection and the base-url of a resource stay in your network. Each value in sensitive stays too. (draft) - [What goes to zriz.io?](https://zriz.io/docs/security.md#goes-to-zriz): The pipeline file and the resource files, without base-url and connection. Also each value that is not in sensitive, and the results that the checks need. (draft) - [Which connections does the runner make?](https://zriz.io/docs/security.md#outbound): Outbound connections only: to zriz.io, and to the resources in its config. zriz is built so that nothing listens. You open no port. (draft) - [What can the runner do?](https://zriz.io/docs/security.md#runner-may): Only what the allowlist in its own config file permits. zriz is built so that a pipeline cannot make the runner call a different target. (draft) - [Can a zriz test change my data?](https://zriz.io/docs/security.md#change-data): Yes, when a step writes. An HTTP step can change data. An SQL step on a resource with read-only cannot. (draft) - [Is my data kept apart from other orgs?](https://zriz.io/docs/security.md#data-scope): Yes. zriz is built so that each record in the cloud belongs to one org. Each query reads the records of one org only. (draft) - [What do the logs of zriz hold?](https://zriz.io/docs/security.md#logs): zriz is built so that its logs hold ids, kinds, reasons, and times. They hold no request body and no reply body. (draft) - [Does zz hold a runner?](https://zriz.io/docs/security.md#one-interpreter): No. zriz is built so that zz and a runner are two programs. zz holds no runner and makes no call to your service. (draft) - [Where is the code?](https://zriz.io/docs/security.md#where-is-the-code): The runner is open source. You can read the code that holds your secrets on a deployed runner. zz is not open source. (draft) ## Learn - [Learn API testing](https://zriz.io/learn.md): Short lessons on API and database tests. Each lesson solves one test problem with one zriz pipeline that you can copy.