427396653f
Adds an opt-in RedisIoAdapter (wired in main.ts when REDIS_URL is set) so socket.io room emits fan out across instances via Redis pub/sub — a client on replica B now receives messages emitted by replica A. Without REDIS_URL the in-memory adapter is kept (single-instance dev unchanged). Adds redis to docker-compose, REDIS_URL to the env contract, and smoke-realtime-cluster.mjs which proves cross-instance delivery fails without Redis and passes with it. Delivery is at-least-once at N>1; clients dedupe by message id (documented). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
52 lines
4.1 KiB
Bash
52 lines
4.1 KiB
Bash
# ─────────────────────────────────────────────────────────────────────────────
|
|
# iios-service configuration contract.
|
|
# Copy to `.env` for local dev; in prod, inject via your secrets manager / orchestrator.
|
|
# 🔒 = secret (never commit a real value). ⚠️ = must be set correctly for prod safety.
|
|
# ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
# ── Core ─────────────────────────────────────────────────────────────────────
|
|
DATABASE_URL=postgresql://iios:iios@localhost:5434/iios?schema=public # 🔒 Postgres connection
|
|
PORT=3200
|
|
# NODE_ENV=production # set by the Docker image
|
|
# Realtime fan-out across replicas (socket.io Redis adapter). REQUIRED when running
|
|
# more than one instance with live chat; omit for a single instance (in-memory adapter).
|
|
# REDIS_URL=redis://localhost:6379 # 🔒
|
|
|
|
# ── Secrets ──────────────────────────────────────────────────────────────────
|
|
# JSON map of appId → HS256 signing secret used to verify session JWTs (SessionVerifier).
|
|
APP_SECRETS={"portal-demo":"dev-secret"} # 🔒
|
|
# JSON map of channelType → inbound webhook HMAC secret (adapter signature check).
|
|
ADAPTER_SECRETS={"WEBHOOK":"dev-adapter-secret"} # 🔒
|
|
# Default scope an unauthenticated adapter webhook ingests into.
|
|
ADAPTER_APP=portal-demo
|
|
ADAPTER_ORG=org_demo
|
|
|
|
# ── ⚠️ Production-safety flags ────────────────────────────────────────────────
|
|
# Enables /v1/dev/* (token mint, webhook inject, chaos, retention sweep). MUST be unset
|
|
# or 0 in production — leaving it on exposes unauthenticated token minting.
|
|
IIOS_DEV_TOKENS=0
|
|
# Skip `prisma migrate deploy` at boot (set to 1 when a separate migration job runs).
|
|
IIOS_SKIP_MIGRATE=0
|
|
|
|
# ── Tenant isolation ─────────────────────────────────────────────────────────
|
|
IIOS_CELL_ID=cell-default # physical cell this instance serves (blast-radius partition)
|
|
|
|
# ── Background workers ───────────────────────────────────────────────────────
|
|
IIOS_RELAY_INTERVAL_MS=500 # outbox relay tick; 0 disables the timer
|
|
IIOS_OUTBOX_MAX_ATTEMPTS=5 # relay dead-letters an event after N failed publishes
|
|
IIOS_RETENTION_SWEEP_INTERVAL_MS=0 # retention sweep tick; 0 disables (run via job instead)
|
|
IIOS_RETENTION_POLICY_VERSION=v1
|
|
IIOS_RETENTION_ARCHIVE_DAYS=90 # default archive window (per-class override: _INTERNAL/_RESTRICTED/_CONFIDENTIAL/_REGULATED)
|
|
IIOS_RETENTION_DELETE_DAYS=365 # default delete (redact) window; same per-class overrides
|
|
|
|
# ── Rate limits / quotas / budgets ───────────────────────────────────────────
|
|
IIOS_OUTBOUND_LIMIT=5 # per-(channel,target) sends per window
|
|
IIOS_OUTBOUND_WINDOW_MS=60000
|
|
IIOS_TENANT_OUTBOUND_LIMIT=10000 # per-tenant egress cap per window (noisy-neighbor guard)
|
|
IIOS_TENANT_OUTBOUND_WINDOW_MS=60000
|
|
IIOS_AI_BUDGET_UNITS=100000 # per-scope AI cost-unit budget (KG-12)
|
|
|
|
# ── Capability providers (governed egress targets) ───────────────────────────
|
|
# Per-channel provider endpoint the CapabilityBroker calls, e.g.:
|
|
# IIOS_PROVIDER_URL_EMAIL=https://provider.internal/email
|