Infrastructure (H3 CI gate, H5 KMS): - Gitea Actions enabled (GITEA__actions__ENABLED=true) - act_runner: Docker-outside-of-Docker for deploy job - Vault Transit RSA-2048 signing keys (casan-audit-key, casan-policy-key) Vault KMS scripts (H5 governance): - .specify/scripts/bash/vault-kms.sh — sign/verify/pubkey/ensure-key - .specify/scripts/bash/sign-audit-head.sh — sign audit chain via Vault - Updated sign-policy-bundle.sh — Vault path + local fallback - Updated security-gate.sh — KMS gate added (PASS=11 FAIL=0) OKR app deployment (port 80/3001): - Dockerfile.backend — node:22-slim (node:sqlite requires Node 22) - Dockerfile.frontend — node:20-alpine build + nginx:alpine runtime - nginx/nginx.conf — React SPA + /api/v1/* proxy to okr-backend:3001 - backend/entrypoint.sh — auto init DB on first run + seed - .dockerignore CI pipeline (.gitea/workflows/ci.yml): - Job 1: Vitest frontend tests (H3) - Job 2: CASAN security gate + Vault KMS signing (H4/H5) - Job 3: Deploy OKR → port 80 (runs on push to main after tests pass) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
22 lines
648 B
Bash
22 lines
648 B
Bash
#!/bin/sh
|
|
# OKR backend container entrypoint.
|
|
# - First run: creates SQLite schema via setup-sqlite.mjs + seeds initial data.
|
|
# - Subsequent runs: DB already exists, skip init.
|
|
# WORKDIR expected: /app/backend (set in Dockerfile)
|
|
set -e
|
|
|
|
# Hoisted node_modules/.bin (workspace root) must be in PATH for tsx + prisma CLI
|
|
export PATH="/app/node_modules/.bin:$PATH"
|
|
|
|
mkdir -p /data
|
|
|
|
if [ ! -f "/data/okr.db" ]; then
|
|
echo "[OKR] First run — initializing database at /data/okr.db"
|
|
node scripts/setup-sqlite.mjs
|
|
npx prisma db seed
|
|
echo "[OKR] Database initialized"
|
|
fi
|
|
|
|
echo "[OKR] Starting backend on port ${PORT:-3001}"
|
|
exec node dist/main.js
|