feat: missing required setting fails startup with a field-specific error (E00-S04-T02)
- packages/config: add src/startup.ts exposing assertValidConfig (builds on the T01 TypeBox/Ajv schema) and the field-specific startup errors (MissingRequiredSettingError names the missing field; ConfigStartupError names each violating field); re-export from the package boundary - apps/server: validate the startup configuration (including the required EPPP_SESSION_SECRET) before the server binds, so a missing required setting crashes the process at startup naming the field; depends on @personal-blog/config - compose.yaml: provide EPPP_SESSION_SECRET for the app service (dev-only >= 32 char default; override via .env / shell) - Dockerfile: ship the compiled packages/config in the image (build source + runtime dist), matching the server's new workspace dependency - pnpm-lock.yaml: apps/server importer gains @personal-blog/config
This commit is contained in:
@@ -18,11 +18,22 @@
|
||||
* E00-S01-T06) there are no migrations to run, so the app reports ready
|
||||
* immediately.
|
||||
*
|
||||
* [E00-S04-T02] field-specific startup error: the required settings are
|
||||
* validated before the server binds, so a deployment missing a required
|
||||
* setting (the admin-session secret `EPPP_SESSION_SECRET` — the schema's
|
||||
* required field, Security-and-Operations §32/§26) fails fast at startup
|
||||
* with an error naming the missing field instead of booting with an invalid
|
||||
* configuration. The parsed config keeps the committed defaults for
|
||||
* `host`/`port`/`databaseUrl` (the `process.env` adapter that centralizes
|
||||
* these reads is E00-S04-T04 and lands later); `assertValidConfig` throws
|
||||
* `MissingRequiredSettingError` naming the missing field.
|
||||
*
|
||||
* The Fastify 5 application shell (and the real HTTP API) lands in a later
|
||||
* story; this bootstrap keeps the application health-checkable until then.
|
||||
*/
|
||||
|
||||
import { createServer, type IncomingMessage, type ServerResponse } from 'node:http';
|
||||
import { assertValidConfig } from '@personal-blog/config';
|
||||
import { Pool } from '@personal-blog/database-postgres';
|
||||
import { MigrationLedger, MigrationRunner } from '@personal-blog/database-postgres';
|
||||
import type { Migration } from '@personal-blog/database-postgres';
|
||||
@@ -30,6 +41,17 @@ import type { Migration } from '@personal-blog/database-postgres';
|
||||
/** Port the server listens on; `PORT` overrides the container default (3000). */
|
||||
const PORT = resolvePort(process.env.PORT);
|
||||
|
||||
// [E00-S04-T02] field-specific startup error: validate the startup
|
||||
// configuration before anything else, so a missing required setting (e.g.
|
||||
// EPPP_SESSION_SECRET) crashes the process at startup with an error naming
|
||||
// the missing field — never boots with an invalid configuration.
|
||||
assertValidConfig({
|
||||
host: '0.0.0.0',
|
||||
port: PORT,
|
||||
databaseUrl: process.env.DATABASE_URL,
|
||||
sessionSecret: process.env.EPPP_SESSION_SECRET,
|
||||
});
|
||||
|
||||
/** Health payload — reported once the startup migration run completes. */
|
||||
const HEALTH_PAYLOAD = JSON.stringify({ status: 'ok' });
|
||||
|
||||
|
||||
Reference in New Issue
Block a user