feat : 6 astra improve it
CI / Verify and audit (push) Successful in 2m33s
CI / Build, scan and deploy immutable images (push) Failing after 1m29s

This commit is contained in:
2026-09-22 18:28:18 +07:00 Unverified
parent 88afa8e947
commit 87e6bcd96f
56 changed files with 1351 additions and 511 deletions
+30 -22
View File
@@ -14,7 +14,8 @@ not affiliated with or endorsed by HoYoverse.
- Structured editors for overview, weapons, artifacts, constellations, teams,
and custom sections with autosave and conflict recovery.
- Better Auth email/password login with administrator-managed accounts.
- Private S3-compatible media uploads with reference-aware same-origin delivery.
- S3-compatible media uploads with reference-aware same-origin delivery for
staged private objects.
- PostgreSQL transactions and a retryable outbox.
- Shared Redis cache invalidation and privacy-safe Server-Sent Events across
replicas.
@@ -35,7 +36,7 @@ formula fixtures. Their guide text and media are not imported or published.
| `/admin` | Character and page overview |
| `/admin/[character]/[page]` | Visual page editor |
| `/admin/create` | Create a structured guide from the synced character catalog |
| `/media/[id]` | Authorized same-origin media response |
| `/media/[id]` | Same-origin media response with publication checks |
| `/api/health` | Liveness response |
| `/api/health?ready=1` | PostgreSQL and Redis readiness response |
@@ -49,7 +50,7 @@ Requirements:
- Bun 1.3.14
- PostgreSQL
- Redis
- Private S3-compatible object storage
- S3-compatible object storage
Install dependencies and create your local environment file:
@@ -71,18 +72,6 @@ bun run db:migrate
bun run dev
```
### Fixture-only demo
The UI can be inspected without PostgreSQL, Redis, S3, or authentication
credentials by running:
```bash
BUZZ_DEMO_MODE=true bun run dev
```
Demo mode uses sanitized local fixtures and bypasses production authorization
and external services. Never enable it in a deployed environment.
## Commands
| Command | Purpose |
@@ -92,6 +81,7 @@ and external services. Never enable it in a deployed environment.
| `bun run test:coverage` | Produce V8 coverage output |
| `bun run typecheck` | Run TypeScript without emitting files |
| `bun run lint` | Run ESLint |
| `bun run security:audit` | Check dependency advisories and time-limited exceptions |
| `bun run build` | Compile the production application |
| `bun run db:generate` | Generate a Drizzle migration from schema changes |
| `bun run db:migrate` | Apply committed Drizzle migrations |
@@ -122,9 +112,11 @@ Public guides use a shared Redis-backed Next.js cache. Admin routes remain
dynamic. SSE streams send a 90-second heartbeat and close after 30 minutes so
clients reconnect. Traefik buffering is disabled by the response headers.
Media objects remain private in S3. `/media/[id]` serves an object publicly only
while a published guide references it; otherwise administrator authorization is
required.
Presigned staged uploads remain private in S3. `/media/[id]` serves a staged
object publicly only while a published guide references it; otherwise
administrator authorization is required. The direct upload path writes public
CDN objects for guide images, so draft uploads on that path must not contain
sensitive material.
## Verification
@@ -132,6 +124,7 @@ Run the complete host-safe verification set with:
```bash
bun install --frozen-lockfile
bun run security:audit
bun run test
bun run typecheck
bun run lint
@@ -190,6 +183,7 @@ Kustomize resources live in `k8s/` and define:
- Web requests of 500m CPU/1 GiB and limits of 1 CPU/2 GiB.
- HPA from 2 to 6 web replicas at 70% CPU or 75% memory and a PDB with one available.
- Non-root, read-only containers with dropped capabilities and seccomp.
- Ingress NetworkPolicy allowing the web pods only from Traefik in `kube-system`.
- ARM64 scheduling constraints matching the production hosts and images.
- A versioned migration Job and namespace-scoped CI deployer permissions.
@@ -205,19 +199,28 @@ Before the first rollout, a cluster administrator must provision a
DATABASE_URL
BETTER_AUTH_SECRET
REDIS_URL
CATALOG_SYNC_CONCURRENCY
S3_ENDPOINT
S3_PUBLIC_URL
S3_BUCKET
S3_ACCESS_KEY_ID
S3_SECRET_ACCESS_KEY
NEXT_SERVER_ACTIONS_ENCRYPTION_KEY
TURNSTILE_SITE_KEY
TURNSTILE_SECRET_KEY
DISCORD_BOT_TOKEN
DISCORD_CHANNEL_ID
```
`NEXT_SERVER_ACTIONS_ENCRYPTION_KEY` must be generated once and remain stable
across replicas and rolling deployments. Do not place secret values in the
ConfigMap or commit them to this repository.
Traefik must overwrite `X-Real-Ip` for every request, and the web pods must be
reachable only through Traefik before enabling the configured client IP based
rate limits. The NetworkPolicy assumes Traefik runs in `kube-system` with the
`app.kubernetes.io/name=traefik` pod label; verify those labels in the target
cluster before applying it.
Every page also subscribes to `/api/active`. When a serving pod reports a newer
deployment ID than the browser's current build, a persistent Thai notification
offers a full reload into the new release.
@@ -236,9 +239,11 @@ kubectl kustomize k8s/ >/dev/null
### Gitea Actions release
`.gitea/workflows/ci.yml` verifies every push and pull request. After the
`.gitea/workflows/ci.yml` verifies pushes to `main` and scheduled runs, including a
dependency audit and a Git history secret scan. A time-limited advisory
exception is recorded in `security/audit-exceptions.json`. After the
repository variable `DEPLOY_ENABLED` is explicitly set to `true`, a successful
push to `main` builds multi-architecture images at:
push to `main` builds and scans ARM64 images at:
```text
registry.neko-piranha.ts.net/astral/buzz-sheet:<git-sha>
@@ -250,7 +255,10 @@ Configure these Gitea secrets later:
| Secret | Purpose |
| --- | --- |
| `KUBE_CONFIG_B64` | Base64 kubeconfig for the `ci-deployer` identity |
| `REDIS_INTEGRATION_URL` | Optional isolated Redis endpoint for CI integration coverage |
The kubeconfig must contain a certificate-valid API server address and its CA.
The workflow rejects `insecure-skip-tls-verify` and does not rewrite the
cluster server address.
The deploy job creates a revision-named migration Job, waits for completion,
updates `NEXT_DEPLOYMENT_ID`, and only then rolls out the immutable application