Payments: deploy the billing service #496

Öppen
öppnade 2026-09-24 13:03:35 +00:00 av supernaut · 2 kommentarer
Ägare

Problem

The billing service has no deployment. Paid checkout needs it running before launch.

Scope

  • A Quadlet container for the service, pulled from the org registry, with the same image-update path as the portal.
  • Its own Postgres database and role, least privilege.
  • Secrets in Ansible Vault: the payment provider API key and webhook secret.
  • A Kanidm service account that may only change membership of the paid tier group (ADR 0017: tier changes flow through Kanidm and the reconciler, never straight into Forgejo).
  • A Caddy route for the provider's webhook, reachable from the internet, everything else internal only.
  • Backups of the new database included in the existing backup and drill.
  • Runbook section: deploy, rotate secrets, roll back.

Done when

The service runs in production against the provider's test mode, a test payment grants the paid tier end to end, and the backup drill restores its database.

Blocked on the service having an HTTP entry point.

Epic: bitborg/bitborg-docs#5

## Problem The billing service has no deployment. Paid checkout needs it running before launch. ## Scope - A Quadlet container for the service, pulled from the org registry, with the same image-update path as the portal. - Its own Postgres database and role, least privilege. - Secrets in Ansible Vault: the payment provider API key and webhook secret. - A Kanidm service account that may only change membership of the paid tier group (ADR 0017: tier changes flow through Kanidm and the reconciler, never straight into Forgejo). - A Caddy route for the provider's webhook, reachable from the internet, everything else internal only. - Backups of the new database included in the existing backup and drill. - Runbook section: deploy, rotate secrets, roll back. ## Done when The service runs in production against the provider's test mode, a test payment grants the paid tier end to end, and the backup drill restores its database. Blocked on the service having an HTTP entry point. Epic: bitborg/bitborg-docs#5
Upphovsperson
Ägare

Status 2026-10-01: the role is merged (#507), pinned to the first published image v0.2.1 (#508) and applied. Production runs it disabled: billing_enabled: false. A second --check gave changed=0.

No webhook secret: Mollie does not sign webhooks, so the service re-fetches each payment by id.

Left before this closes, in order (runbook "Billing service"):

  1. Create the bitborg-billing Kanidm service account and a read-write API token.
  2. Add vault_payments_mollie_api_key_test, vault_billing_db_password, vault_billing_api_token, vault_kanidm_billing_token.
  3. Set billing_enabled: true, dry-run, apply. Verify, including that entry_managed_by on an account grants member write on tier_pro.
  4. Set billing_payments_enabled: true, run a test payment, confirm the paid tier reaches Forgejo.
  5. Take a backup and let the drill restore the billing database.
Status 2026-10-01: the role is merged (#507), pinned to the first published image `v0.2.1` (#508) and applied. Production runs it disabled: `billing_enabled: false`. A second `--check` gave `changed=0`. No webhook secret: Mollie does not sign webhooks, so the service re-fetches each payment by id. Left before this closes, in order (runbook "Billing service"): 1. Create the `bitborg-billing` Kanidm service account and a read-write API token. 2. Add `vault_payments_mollie_api_key_test`, `vault_billing_db_password`, `vault_billing_api_token`, `vault_kanidm_billing_token`. 3. Set `billing_enabled: true`, dry-run, apply. Verify, including that `entry_managed_by` on an account grants member write on `tier_pro`. 4. Set `billing_payments_enabled: true`, run a test payment, confirm the paid tier reaches Forgejo. 5. Take a backup and let the drill restore the billing database.
Upphovsperson
Ägare

One more step for the enable checklist, from #510: after billing_enabled: true is applied and the bitborg-billing container logs to Loki, confirm the BillingReconcileManualReview alert fires on one matching line. For example, log [reconcile] test is paid at the provider with no settled local charge; needs manual review from inside the container to stdout, then check Alertmanager. The rule needs the monitoring tag applied first.

One more step for the enable checklist, from #510: after `billing_enabled: true` is applied and the `bitborg-billing` container logs to Loki, confirm the `BillingReconcileManualReview` alert fires on one matching line. For example, log `[reconcile] test is paid at the provider with no settled local charge; needs manual review` from inside the container to stdout, then check Alertmanager. The rule needs the `monitoring` tag applied first.
supernaut refererade till detta ärende från en incheckning 2026-10-01 21:45:18 +00:00
supernaut refererade till detta ärende från en incheckning 2026-10-02 17:56:58 +00:00
supernaut refererade till detta ärende från en incheckning 2026-10-02 20:09:05 +00:00
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#496
Ingen beskrivning angiven.