chore(iios): production Dockerfile + migrate entrypoint + env/secrets contract

Adds a multi-stage Dockerfile for iios-service (build → pnpm deploy prune →
slim non-root runtime), a docker-entrypoint that runs `prisma migrate deploy`
then starts the server as PID 1, a .dockerignore, a fully-commented
.env.example config contract, and docs/DEPLOYMENT.md (topology, scaling,
release strategy, prod-readiness gaps). Moves prisma to dependencies so the
CLI ships in the prod bundle. Image builds, migrates, and serves /health 200.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-07-03 19:19:13 +05:30
parent 5bd1f646ca
commit a520b26398
7 changed files with 241 additions and 4 deletions
+48
View File
@@ -0,0 +1,48 @@
# ─────────────────────────────────────────────────────────────────────────────
# iios-service configuration contract.
# Copy to `.env` for local dev; in prod, inject via your secrets manager / orchestrator.
# 🔒 = secret (never commit a real value). ⚠️ = must be set correctly for prod safety.
# ─────────────────────────────────────────────────────────────────────────────
# ── Core ─────────────────────────────────────────────────────────────────────
DATABASE_URL=postgresql://iios:iios@localhost:5434/iios?schema=public # 🔒 Postgres connection
PORT=3200
# NODE_ENV=production # set by the Docker image
# ── Secrets ──────────────────────────────────────────────────────────────────
# JSON map of appId → HS256 signing secret used to verify session JWTs (SessionVerifier).
APP_SECRETS={"portal-demo":"dev-secret"} # 🔒
# JSON map of channelType → inbound webhook HMAC secret (adapter signature check).
ADAPTER_SECRETS={"WEBHOOK":"dev-adapter-secret"} # 🔒
# Default scope an unauthenticated adapter webhook ingests into.
ADAPTER_APP=portal-demo
ADAPTER_ORG=org_demo
# ── ⚠️ Production-safety flags ────────────────────────────────────────────────
# Enables /v1/dev/* (token mint, webhook inject, chaos, retention sweep). MUST be unset
# or 0 in production — leaving it on exposes unauthenticated token minting.
IIOS_DEV_TOKENS=0
# Skip `prisma migrate deploy` at boot (set to 1 when a separate migration job runs).
IIOS_SKIP_MIGRATE=0
# ── Tenant isolation ─────────────────────────────────────────────────────────
IIOS_CELL_ID=cell-default # physical cell this instance serves (blast-radius partition)
# ── Background workers ───────────────────────────────────────────────────────
IIOS_RELAY_INTERVAL_MS=500 # outbox relay tick; 0 disables the timer
IIOS_OUTBOX_MAX_ATTEMPTS=5 # relay dead-letters an event after N failed publishes
IIOS_RETENTION_SWEEP_INTERVAL_MS=0 # retention sweep tick; 0 disables (run via job instead)
IIOS_RETENTION_POLICY_VERSION=v1
IIOS_RETENTION_ARCHIVE_DAYS=90 # default archive window (per-class override: _INTERNAL/_RESTRICTED/_CONFIDENTIAL/_REGULATED)
IIOS_RETENTION_DELETE_DAYS=365 # default delete (redact) window; same per-class overrides
# ── Rate limits / quotas / budgets ───────────────────────────────────────────
IIOS_OUTBOUND_LIMIT=5 # per-(channel,target) sends per window
IIOS_OUTBOUND_WINDOW_MS=60000
IIOS_TENANT_OUTBOUND_LIMIT=10000 # per-tenant egress cap per window (noisy-neighbor guard)
IIOS_TENANT_OUTBOUND_WINDOW_MS=60000
IIOS_AI_BUDGET_UNITS=100000 # per-scope AI cost-unit budget (KG-12)
# ── Capability providers (governed egress targets) ───────────────────────────
# Per-channel provider endpoint the CapabilityBroker calls, e.g.:
# IIOS_PROVIDER_URL_EMAIL=https://provider.internal/email
+54
View File
@@ -0,0 +1,54 @@
# syntax=docker/dockerfile:1
# Production image for @insignia/iios-service (the single IIOS backend).
# Build context MUST be the monorepo ROOT (it needs the workspace + lockfile):
# docker build -f packages/iios-service/Dockerfile -t iios-service:latest .
#
# Multi-stage: (1) build the service + its workspace deps and prune to a
# self-contained prod bundle via `pnpm deploy`; (2) a slim runtime that only
# carries that bundle. Migrations run at container start (see docker-entrypoint.sh).
ARG NODE_VERSION=22-bookworm-slim
ARG PNPM_VERSION=10.6.2
# ── build ───────────────────────────────────────────────────────────────────
FROM node:${NODE_VERSION} AS build
ARG PNPM_VERSION
ENV PNPM_HOME=/pnpm PATH=/pnpm:$PATH
# openssl + ca-certificates are required by Prisma's engine on debian-slim.
RUN apt-get update && apt-get install -y --no-install-recommends openssl ca-certificates \
&& rm -rf /var/lib/apt/lists/*
RUN corepack enable && corepack prepare pnpm@${PNPM_VERSION} --activate
WORKDIR /repo
COPY . .
# Full install (needs devDeps to compile), then build ONLY the service + its
# workspace dependencies, generate the Prisma client, and emit a pruned prod bundle.
RUN --mount=type=cache,id=pnpm-store,target=/pnpm/store \
pnpm install --frozen-lockfile
# Generate the Prisma client BEFORE compiling — nest build (tsc) needs its types,
# otherwise Prisma results are `any` and noImplicitAny fails the build.
RUN pnpm --filter @insignia/iios-service exec prisma generate \
&& pnpm --filter "@insignia/iios-service..." build \
&& pnpm --filter @insignia/iios-service --prod --legacy deploy /app
# ── runtime ──────────────────────────────────────────────────────────────────
FROM node:${NODE_VERSION} AS runtime
ENV NODE_ENV=production
# Prisma engine needs openssl at runtime too.
RUN apt-get update && apt-get install -y --no-install-recommends openssl ca-certificates \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /app
COPY --from=build /app ./
# Regenerate the Prisma client against the final filesystem (deterministic).
RUN node_modules/.bin/prisma generate
# Run as the built-in non-root `node` user.
RUN chmod +x docker-entrypoint.sh && chown -R node:node /app
USER node
EXPOSE 3200
ENV PORT=3200
# migrate deploy → start; see docker-entrypoint.sh.
ENTRYPOINT ["./docker-entrypoint.sh"]
@@ -0,0 +1,19 @@
#!/bin/sh
# Container entrypoint for iios-service.
# 1) Apply pending DB migrations (idempotent; safe to run on every boot).
# 2) Exec the server as PID 1 so signals (SIGTERM) reach Node for graceful shutdown.
#
# NOTE: at higher replica counts, prefer running `prisma migrate deploy` ONCE as a
# separate pre-deploy job/init-container and set IIOS_SKIP_MIGRATE=1 here, so N
# replicas don't race the migration on rollout.
set -e
if [ "${IIOS_SKIP_MIGRATE:-0}" != "1" ]; then
echo "[entrypoint] applying migrations (prisma migrate deploy)…"
node_modules/.bin/prisma migrate deploy
else
echo "[entrypoint] IIOS_SKIP_MIGRATE=1 — skipping migrations"
fi
echo "[entrypoint] starting iios-service on :${PORT:-3200}"
exec node dist/main.js
+1 -1
View File
@@ -20,6 +20,7 @@
"@nestjs/platform-socket.io": "^11.1.27",
"@nestjs/websockets": "^11.1.27",
"@prisma/client": "^6.2.1",
"prisma": "^6.2.1",
"socket.io": "^4.8.3",
"class-transformer": "^0.5.1",
"class-validator": "^0.15.1",
@@ -35,7 +36,6 @@
"@types/express": "^5.0.6",
"@types/jsonwebtoken": "^9.0.10",
"@types/node": "^26.0.1",
"prisma": "^6.2.1",
"socket.io-client": "^4.8.3",
"typescript": "^5.7.3"
}