Skip to main content

Load Testing

Measure how a deployment handles token requests, pre-authorized issuance, OID4VP presentation requests and status-list reads with the k6 suite in scripts/load-test. The runner can start the repository's Compose stack or target a deployment that is already running.

Before you start​

  • k6 2.0 or newer
  • Docker, only if the runner should start the local stack
  • An OAuth client and a tenant with issuance and presentation configurations in the target deployment

Run against the local stack​

./scripts/load-test/run-all.sh --once

The runner starts deployment/docker-compose with the standard profile (COMPOSE_PROFILE, env file K6_ENV_FILE, default deployment/docker-compose/.env), waits for /health and runs every scenario once. Each scenario writes a JSON summary and a log with k6's end-of-run metrics to scripts/load-test/results/.

Run against a deployment​

--external does not start Docker and requires an explicit target. Start with --once before applying sustained load:

BASE_URL=https://eudiplo.example.com \
TENANT_ID=load-test \
CLIENT_ID=load-test-client \
CLIENT_SECRET=<secret> \
./scripts/load-test/run-all.sh --external --once

Use a dedicated test environment: the issuance and presentation scenarios create persistent sessions, and the load, stress and spike profiles generate substantial traffic. Use least-privilege client roles for the test client.

The runner waits for BASE_URL/health. Set HEALTH_URL if health checks are exposed elsewhere, or SKIP_HEALTH_CHECK=true if a gateway hides them; the first request then serves as the connectivity check. For private certificate authorities, K6_INSECURE_SKIP_TLS_VERIFY=true disables certificate checks; use it only in a controlled test environment.

Profiles and scenarios​

VariableDefaultMeaning
K6_PROFILEsmokeonce, smoke, load, stress or spike (--once forces once)
TENANT_IDdemoTenant used by the scenarios
CLIENT_ID, CLIENT_SECRETtest-client, test-client-secretOAuth client of that tenant
CREDENTIAL_CONFIG_IDpidCredential configuration offered by pre-auth-issuance
REQUEST_IDage-over-18Presentation configuration used by oid4vp-presentation
MAX_LISTS5Maximum number of status lists fetched per iteration
SUMMARY_DIRscripts/load-test/resultsOutput directory
CLEAN_RESULTStrueDelete earlier results before the run
PROMETHEUS_RW_URL-Also push k6 metrics to a Prometheus remote-write endpoint

Without scenario arguments the runner executes all four. Name scenarios to run a subset:

K6_PROFILE=load ./scripts/load-test/run-all.sh --external api-auth pre-auth-issuance
ScenarioExercises
api-authPOST /api/oauth2/token
pre-auth-issuanceOffer, token, nonce and credential request of the pre-authorized flow, with a generated holder key
oid4vp-presentationPresentation request creation and request object retrieval (no wallet response)
status-listStatus list downloads; needs at least one issued status-managed credential

To see the backend side of a run, start the monitoring stack and set PROMETHEUS_RW_URL=http://localhost:9090/api/v1/write.