feat: live deployment with automated acceptance checklist (phase 13)
- APP_INTERNAL_URL: in-network base URL for §5.2 callbacks and signed attachment URLs handed to the external services (compose: http://app:8787) - work-performer image runs as the node user with ~/.claude mounted into /home/node — the claude CLI refuses --dangerously-skip-permissions as root - scripts/acceptance.sh: re-run-safe live verification of the §13 checklist (demo import within one poll, subdivide sum=1 + editable, extend sibling, publish/bounty math, decline/claim/approve, changes-requested loop, approval award in metrics, unassign, AI job through real Claude Code with signed idempotent callback, breaker independence between the two services) - README/DECISIONS: sudo HOME gotcha, internal URL, non-root performer Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -36,7 +36,11 @@ func (o OIDC) Enabled() bool {
|
||||
}
|
||||
|
||||
type Config struct {
|
||||
AppBaseURL string
|
||||
AppBaseURL string
|
||||
// AppInternalURL is how the external services reach the app from inside
|
||||
// the compose network (callback URLs, signed attachment URLs). Defaults
|
||||
// to AppBaseURL.
|
||||
AppInternalURL string
|
||||
TrustedProxyCIDRs []netip.Prefix
|
||||
AppPort int
|
||||
MongoURI string
|
||||
@@ -132,6 +136,7 @@ func Load() (*Config, error) {
|
||||
CookieSecureMode: getenv("COOKIE_SECURE", "auto"),
|
||||
AtomizeMaxConcurrency: atoi("ATOMIZE_MAX_CONCURRENCY", "3"),
|
||||
}
|
||||
c.AppInternalURL = strings.TrimRight(getenv("APP_INTERNAL_URL", c.AppBaseURL), "/")
|
||||
c.AtomizerTimeout = time.Duration(atoi("ATOMIZER_TIMEOUT_SEC", "120")) * time.Second
|
||||
c.WorkPerformerHTTPTimeout = time.Duration(atoi("WORK_PERFORMER_HTTP_TIMEOUT_SEC", "30")) * time.Second
|
||||
|
||||
|
||||
Reference in New Issue
Block a user