feat : 6 astra improve it
This commit is contained in:
@@ -14,7 +14,8 @@ not affiliated with or endorsed by HoYoverse.
|
||||
- Structured editors for overview, weapons, artifacts, constellations, teams,
|
||||
and custom sections with autosave and conflict recovery.
|
||||
- Better Auth email/password login with administrator-managed accounts.
|
||||
- Private S3-compatible media uploads with reference-aware same-origin delivery.
|
||||
- S3-compatible media uploads with reference-aware same-origin delivery for
|
||||
staged private objects.
|
||||
- PostgreSQL transactions and a retryable outbox.
|
||||
- Shared Redis cache invalidation and privacy-safe Server-Sent Events across
|
||||
replicas.
|
||||
@@ -35,7 +36,7 @@ formula fixtures. Their guide text and media are not imported or published.
|
||||
| `/admin` | Character and page overview |
|
||||
| `/admin/[character]/[page]` | Visual page editor |
|
||||
| `/admin/create` | Create a structured guide from the synced character catalog |
|
||||
| `/media/[id]` | Authorized same-origin media response |
|
||||
| `/media/[id]` | Same-origin media response with publication checks |
|
||||
| `/api/health` | Liveness response |
|
||||
| `/api/health?ready=1` | PostgreSQL and Redis readiness response |
|
||||
|
||||
@@ -49,7 +50,7 @@ Requirements:
|
||||
- Bun 1.3.14
|
||||
- PostgreSQL
|
||||
- Redis
|
||||
- Private S3-compatible object storage
|
||||
- S3-compatible object storage
|
||||
|
||||
Install dependencies and create your local environment file:
|
||||
|
||||
@@ -71,18 +72,6 @@ bun run db:migrate
|
||||
bun run dev
|
||||
```
|
||||
|
||||
### Fixture-only demo
|
||||
|
||||
The UI can be inspected without PostgreSQL, Redis, S3, or authentication
|
||||
credentials by running:
|
||||
|
||||
```bash
|
||||
BUZZ_DEMO_MODE=true bun run dev
|
||||
```
|
||||
|
||||
Demo mode uses sanitized local fixtures and bypasses production authorization
|
||||
and external services. Never enable it in a deployed environment.
|
||||
|
||||
## Commands
|
||||
|
||||
| Command | Purpose |
|
||||
@@ -92,6 +81,7 @@ and external services. Never enable it in a deployed environment.
|
||||
| `bun run test:coverage` | Produce V8 coverage output |
|
||||
| `bun run typecheck` | Run TypeScript without emitting files |
|
||||
| `bun run lint` | Run ESLint |
|
||||
| `bun run security:audit` | Check dependency advisories and time-limited exceptions |
|
||||
| `bun run build` | Compile the production application |
|
||||
| `bun run db:generate` | Generate a Drizzle migration from schema changes |
|
||||
| `bun run db:migrate` | Apply committed Drizzle migrations |
|
||||
@@ -122,9 +112,11 @@ Public guides use a shared Redis-backed Next.js cache. Admin routes remain
|
||||
dynamic. SSE streams send a 90-second heartbeat and close after 30 minutes so
|
||||
clients reconnect. Traefik buffering is disabled by the response headers.
|
||||
|
||||
Media objects remain private in S3. `/media/[id]` serves an object publicly only
|
||||
while a published guide references it; otherwise administrator authorization is
|
||||
required.
|
||||
Presigned staged uploads remain private in S3. `/media/[id]` serves a staged
|
||||
object publicly only while a published guide references it; otherwise
|
||||
administrator authorization is required. The direct upload path writes public
|
||||
CDN objects for guide images, so draft uploads on that path must not contain
|
||||
sensitive material.
|
||||
|
||||
## Verification
|
||||
|
||||
@@ -132,6 +124,7 @@ Run the complete host-safe verification set with:
|
||||
|
||||
```bash
|
||||
bun install --frozen-lockfile
|
||||
bun run security:audit
|
||||
bun run test
|
||||
bun run typecheck
|
||||
bun run lint
|
||||
@@ -190,6 +183,7 @@ Kustomize resources live in `k8s/` and define:
|
||||
- Web requests of 500m CPU/1 GiB and limits of 1 CPU/2 GiB.
|
||||
- HPA from 2 to 6 web replicas at 70% CPU or 75% memory and a PDB with one available.
|
||||
- Non-root, read-only containers with dropped capabilities and seccomp.
|
||||
- Ingress NetworkPolicy allowing the web pods only from Traefik in `kube-system`.
|
||||
- ARM64 scheduling constraints matching the production hosts and images.
|
||||
- A versioned migration Job and namespace-scoped CI deployer permissions.
|
||||
|
||||
@@ -205,19 +199,28 @@ Before the first rollout, a cluster administrator must provision a
|
||||
DATABASE_URL
|
||||
BETTER_AUTH_SECRET
|
||||
REDIS_URL
|
||||
CATALOG_SYNC_CONCURRENCY
|
||||
S3_ENDPOINT
|
||||
S3_PUBLIC_URL
|
||||
S3_BUCKET
|
||||
S3_ACCESS_KEY_ID
|
||||
S3_SECRET_ACCESS_KEY
|
||||
NEXT_SERVER_ACTIONS_ENCRYPTION_KEY
|
||||
TURNSTILE_SITE_KEY
|
||||
TURNSTILE_SECRET_KEY
|
||||
DISCORD_BOT_TOKEN
|
||||
DISCORD_CHANNEL_ID
|
||||
```
|
||||
|
||||
`NEXT_SERVER_ACTIONS_ENCRYPTION_KEY` must be generated once and remain stable
|
||||
across replicas and rolling deployments. Do not place secret values in the
|
||||
ConfigMap or commit them to this repository.
|
||||
|
||||
Traefik must overwrite `X-Real-Ip` for every request, and the web pods must be
|
||||
reachable only through Traefik before enabling the configured client IP based
|
||||
rate limits. The NetworkPolicy assumes Traefik runs in `kube-system` with the
|
||||
`app.kubernetes.io/name=traefik` pod label; verify those labels in the target
|
||||
cluster before applying it.
|
||||
|
||||
Every page also subscribes to `/api/active`. When a serving pod reports a newer
|
||||
deployment ID than the browser's current build, a persistent Thai notification
|
||||
offers a full reload into the new release.
|
||||
@@ -236,9 +239,11 @@ kubectl kustomize k8s/ >/dev/null
|
||||
|
||||
### Gitea Actions release
|
||||
|
||||
`.gitea/workflows/ci.yml` verifies every push and pull request. After the
|
||||
`.gitea/workflows/ci.yml` verifies pushes to `main` and scheduled runs, including a
|
||||
dependency audit and a Git history secret scan. A time-limited advisory
|
||||
exception is recorded in `security/audit-exceptions.json`. After the
|
||||
repository variable `DEPLOY_ENABLED` is explicitly set to `true`, a successful
|
||||
push to `main` builds multi-architecture images at:
|
||||
push to `main` builds and scans ARM64 images at:
|
||||
|
||||
```text
|
||||
registry.neko-piranha.ts.net/astral/buzz-sheet:<git-sha>
|
||||
@@ -250,7 +255,10 @@ Configure these Gitea secrets later:
|
||||
| Secret | Purpose |
|
||||
| --- | --- |
|
||||
| `KUBE_CONFIG_B64` | Base64 kubeconfig for the `ci-deployer` identity |
|
||||
| `REDIS_INTEGRATION_URL` | Optional isolated Redis endpoint for CI integration coverage |
|
||||
|
||||
The kubeconfig must contain a certificate-valid API server address and its CA.
|
||||
The workflow rejects `insecure-skip-tls-verify` and does not rewrite the
|
||||
cluster server address.
|
||||
|
||||
The deploy job creates a revision-named migration Job, waits for completion,
|
||||
updates `NEXT_DEPLOYMENT_ID`, and only then rolls out the immutable application
|
||||
|
||||
Reference in New Issue
Block a user