This PR contains the work done to introduce a _Fluent_-based persistence layer for the Website service, selectable at runtime alongside the existing in-memory default, plus the local dev tooling and docs to support it. To provide further details about the work: * Persistence package * The `Driver` and `TLS` enumerations * The `Configuration` type * The `Service` factory that builds the service * `PrepareDB` for migrations registration * The `Probe` for readiness checks. * App integration * Builds the driver, registers migrations, and attaches `Fluent` to the service lifecycle so it starts/stops with the HTTP server. * Migrate-on-boot is gated to the in-memory backend; MySQL/MariaDB is migrated out of band via --database-migrate so shared databases never race on startup. * The `ConfigReader+Properties` extension maps database.* config keys onto the driver. * Library * Added database configuration constants. * The `HealthController` controller gains a readiness probe: `GET /health/ready` checks whether the database is reachable, separate from the existing liveness check. * Others * Updated the `docker-compose` files to support a database service behind a database profile, and hardened for local development * New database targets on the `Makefile` file and overall documentation updated * Updated the `.env.local`, `Dockerfile`, and `README` files to document the persistence workflow, config keys, and local DB commands Reviewed-on: rock-n-code/loud-amsterdam#13 Co-authored-by: Javier Cicchelli <javier@rock-n-code.com> Co-committed-by: Javier Cicchelli <javier@rock-n-code.com>
53 lines
2.8 KiB
Swift
53 lines
2.8 KiB
Swift
extension String {
|
|
/// A namespace for the persistence's default configuration values and recognized tokens.
|
|
public enum Database {
|
|
/// The default persistence driver: in-memory SQLite, which needs no external infrastructure.
|
|
public static let driver = "inMemory"
|
|
/// The driver token selecting the MySQL/MariaDB backend.
|
|
public static let driverMySQL = "mysql"
|
|
/// The default MySQL/MariaDB host.
|
|
public static let host = "localhost"
|
|
/// The default database name.
|
|
public static let name = "loud"
|
|
/// The default database username.
|
|
public static let username = "loud"
|
|
/// The default TLS posture token.
|
|
public static let tls = "prefer"
|
|
/// The TLS token disabling TLS.
|
|
public static let tlsOff = "off"
|
|
/// The TLS token requiring TLS.
|
|
public static let tlsRequire = "require"
|
|
}
|
|
/// A namespace for well-known path string constants.
|
|
public enum Path {
|
|
/// The directory, relative to the working directory, that the website's static files are served from.
|
|
public static let staticResources = "Resources/Static"
|
|
}
|
|
/// A namespace for the security headers' default configuration values.
|
|
///
|
|
/// `Strict-Transport-Security` is intentionally absent: it is only safe over HTTPS and is
|
|
/// "sticky" in browsers, so it stays off unless explicitly configured in production.
|
|
public enum Security {
|
|
/// The default `Content-Security-Policy`.
|
|
///
|
|
/// Restricts every resource to the site's own origin (`default-src 'self'`), blocks plugins
|
|
/// (`object-src 'none'`), pins the document base URL (`base-uri 'self'`), and forbids framing
|
|
/// (`frame-ancestors 'none'`). Both pages link external stylesheets, so no inline-style
|
|
/// exception is required.
|
|
public static let contentSecurityPolicy = "default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'"
|
|
/// The default `X-Content-Type-Options` (disables MIME sniffing).
|
|
public static let contentTypeOptions = "nosniff"
|
|
/// The default `X-Frame-Options` (forbids framing the page).
|
|
public static let frameOptions = "DENY"
|
|
/// The default `Referrer-Policy`.
|
|
public static let referrerPolicy = "strict-origin-when-cross-origin"
|
|
/// The default `Permissions-Policy` (denies access to powerful browser features the site does not use).
|
|
public static let permissionsPolicy = "accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()"
|
|
}
|
|
/// A namespace for the server string constants.
|
|
public enum Server {
|
|
/// The website server's name.
|
|
public static let name = "LoudWebsite"
|
|
}
|
|
}
|