feat: missing required setting fails startup with a field-specific error (E00-S04-T02)

- packages/config: add src/startup.ts exposing assertValidConfig (builds on
  the T01 TypeBox/Ajv schema) and the field-specific startup errors
  (MissingRequiredSettingError names the missing field; ConfigStartupError
  names each violating field); re-export from the package boundary
- apps/server: validate the startup configuration (including the required
  EPPP_SESSION_SECRET) before the server binds, so a missing required
  setting crashes the process at startup naming the field; depends on
  @personal-blog/config
- compose.yaml: provide EPPP_SESSION_SECRET for the app service (dev-only
  >= 32 char default; override via .env / shell)
- Dockerfile: ship the compiled packages/config in the image (build source +
  runtime dist), matching the server's new workspace dependency
- pnpm-lock.yaml: apps/server importer gains @personal-blog/config
This commit is contained in:
implementer
2026-08-30 03:00:40 +00:00
parent ecc945ce65
commit 0ce790fca3
9 changed files with 200 additions and 23 deletions
+9
View File
@@ -50,6 +50,11 @@
#
# All values have defaults so `docker compose up -d` works from a clean clone
# without a .env file (a committed .env.example template lands in E00-S04).
# Since E00-S04-T02 the app validates its required settings at startup: the
# admin-session secret `EPPP_SESSION_SECRET` (the schema's required field,
# Security-and-Operations §32/§26) is provided here with a dev-only default —
# override it via a `.env` file / shell environment for anything beyond local
# development.
services:
db:
@@ -93,6 +98,10 @@ services:
- linux/arm64
environment:
DATABASE_URL: postgres://eppp:eppp@db:5432/eppp
# E00-S04-T02: the app's required admin-session secret (the schema's
# required field, EPPP_SESSION_SECRET per Security-and-Operations
# §32/§26) — dev-only default (>= 32 chars), override via .env / shell.
EPPP_SESSION_SECRET: ${EPPP_SESSION_SECRET:-eppp-local-session-secret-change-me-0123456789}
ports:
- "${APP_PORT:-3000}:3000"
# T02: start only once the database reports healthy (service_healthy), so