feat(mcpedia): Phase 4 — operability + correctness hardening
Reinterpreted from the plan's YAGNI 'Scale-out' (OpenSearch/object-storage /multi-tenant deferred at KB scale). Phase 4 = make the Phase 3 async + revision system correct, secure, observable, deployable. - T1 (correctness bug): restoreRevision now rebuilds semantic chunks via new @mcpedia/core reindexChunks(slug) so semantic/hybrid search stay consistent after a restore (previously document_chunks held the NEW body while documents.body held the restored OLD body -> stale search). - T2 (security): /hooks/* git-sync webhooks now require x-webhook-secret header matching WEBHOOK_SECRET (401 otherwise); API fails fast at startup if unset. Added WEBHOOK_SECRET to @mcpedia/config + .env.example; set real secret in .env. - T3 (UX): web doc page shows a History panel (revision no/reason/date/length) with per-revision Restore; app/api/revisions/restore/route.ts calls restoreRevision + revalidatePath (server-component only, no client JS). - T4: listRevisions gains offset paging; summary never includes body. - T5 (ops): deploy/mcpedia-api.service + deploy/mcpedia-worker.service systemd units (Restart=on-failure, EnvironmentFile=.env). Not auto-enabled on host. Verified against live imrnes Redis + Postgres: turbo typecheck+build green; restore-rebuilds-chunks (marker present -> gone after restore); webhook 401/200; web restore route redirects to doc + reverts body; revisions API returns summary (no body); systemd-analyze verify passes.
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
[Unit]
|
||||
Description=MCPedia API (tRPC/Hono + git-sync webhooks)
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
WorkingDirectory=/home/code/mcpedia
|
||||
# Loads DATABASE_URL, REDIS_*, EMBED_*, WEBHOOK_SECRET from the repo .env
|
||||
# (.env is gitignored; for prod, point this at a deployed secret file).
|
||||
EnvironmentFile=/home/code/mcpedia/.env
|
||||
ExecStart=/usr/bin/env bun run api
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
User=code
|
||||
Group=code
|
||||
# The API needs WEBHOOK_SECRET; fail-fast is built into the app if it's missing.
|
||||
NoNewPrivileges=true
|
||||
PrivateTmp=true
|
||||
MemoryMax=512M
|
||||
TasksMax=256
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -0,0 +1,23 @@
|
||||
[Unit]
|
||||
Description=MCPedia indexing/embedding worker (BullMQ)
|
||||
After=network-online.target redis.service
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
WorkingDirectory=/home/code/mcpedia
|
||||
# Loads DATABASE_URL, REDIS_*, EMBED_* from the repo .env
|
||||
# (.env is gitignored; for prod, point this at a deployed secret file).
|
||||
EnvironmentFile=/home/code/mcpedia/.env
|
||||
ExecStart=/usr/bin/env bun run worker
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
User=code
|
||||
Group=code
|
||||
NoNewPrivileges=true
|
||||
PrivateTmp=true
|
||||
MemoryMax=1G
|
||||
TasksMax=256
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Reference in New Issue
Block a user