docs: document HOST validation and bind control (E00-S04-T04)
CI / Frozen lockfile install (pull_request) Successful in 54s
CI / Secrets not embedded (E00-S02-T08) (pull_request) Successful in 34s
CI / Database-postgres import isolation (E00-S03-T02) (pull_request) Successful in 30s
CI / Migration ledger (E00-S03-T03) (pull_request) Successful in 1m16s
CI / Migration advisory lock (E00-S03-T04) (pull_request) Successful in 54s
CI / Migration failure diagnostic (E00-S03-T05) (pull_request) Successful in 46s
CI / App readiness after migrations (E00-S03-T06) (pull_request) Successful in 1m6s
CI / Field-specific startup errors (E00-S04-T02) (pull_request) Successful in 1m2s
CI / Secret redaction from logs (E00-S04-T03) (pull_request) Successful in 1m1s
CI / TypeBox/Ajv config schema (E00-S04-T01) (pull_request) Successful in 50s
CI / Env adapter owns process.env (E00-S04-T04) (pull_request) Successful in 1m5s
CI / Compose config (E00-S03-T01) (pull_request) Successful in 26s
CI / Frozen lockfile install (pull_request) Successful in 54s
CI / Secrets not embedded (E00-S02-T08) (pull_request) Successful in 34s
CI / Database-postgres import isolation (E00-S03-T02) (pull_request) Successful in 30s
CI / Migration ledger (E00-S03-T03) (pull_request) Successful in 1m16s
CI / Migration advisory lock (E00-S03-T04) (pull_request) Successful in 54s
CI / Migration failure diagnostic (E00-S03-T05) (pull_request) Successful in 46s
CI / App readiness after migrations (E00-S03-T06) (pull_request) Successful in 1m6s
CI / Field-specific startup errors (E00-S04-T02) (pull_request) Successful in 1m2s
CI / Secret redaction from logs (E00-S04-T03) (pull_request) Successful in 1m1s
CI / TypeBox/Ajv config schema (E00-S04-T01) (pull_request) Successful in 50s
CI / Env adapter owns process.env (E00-S04-T04) (pull_request) Successful in 1m5s
CI / Compose config (E00-S03-T01) (pull_request) Successful in 26s
The non-container guide now notes that HOST is validated at the adapter boundary as a hostname/IP (invalid values fail startup naming the field) and that the server passes config.host to server.listen, so a configured HOST binds exactly that interface and the startup log reflects the actual bind. The config-env-adapter CI job comment is refreshed to describe the extended suite (HOST validation + loopback-only boot probe).
This commit is contained in:
@@ -233,11 +233,15 @@ jobs:
|
||||
# validated config) with a comment-stripped workspace scan, mutation probes
|
||||
# (injecting a direct process.env read into any other module fails the scan),
|
||||
# a deterministic boundary probe (full env mapping, defaults, bad-PORT
|
||||
# fallback, missing required secret -> MissingRequiredSettingError) and
|
||||
# server-boot probes (a PORT/HOST override shows up in the resolved
|
||||
# configuration; a missing required secret still fails startup). The job
|
||||
# installs the frozen workspace and builds the config and database-postgres
|
||||
# packages because the probes boot the committed server which imports them.
|
||||
# fallback, HOST validated as hostname/IP with invalid values throwing a
|
||||
# field-specific startup error, missing required secret ->
|
||||
# MissingRequiredSettingError) and server-boot probes (a PORT/HOST override
|
||||
# shows up in the resolved configuration; HOST=127.0.0.1 binds loopback only
|
||||
# and the startup log reflects the actual bind; an invalid HOST fails startup
|
||||
# naming the field without echoing the raw value; a missing required secret
|
||||
# still fails startup). The job installs the frozen workspace and builds the
|
||||
# config and database-postgres packages because the probes boot the committed
|
||||
# server which imports them.
|
||||
config-env-adapter:
|
||||
name: Env adapter owns process.env (E00-S04-T04)
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
Reference in New Issue
Block a user