feat(billing): deploy the billing service, inert until enabled #507
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!507
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/billing-service-deploy"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
Deploys the billing service. Inert until
billing_enabled: true, so merging and applying changes nothing that runs.billing: Quadlet container from the org registry, pinned tag with a Renovate annotation, no auto-update. Read-only rootfs, all caps dropped, no-new-privileges, memory caps, healthcheck on/healthz. Env file mode 0600, rendered withno_log. Asserts every vault value exists when enabled.billing_payments_enabled(default false) rendersPAYMENTS_ENABLED. Enabling the role alone moves no money.ExecStartPrerunsnode dist/src/migrate.jsfrom the same image. Idempotent, and a failed migration fails the start.bitborgpodman network, no published port. The portal reaches/trpcwith a bearer token.POST /webhooks/mollieonwww.bitborg.sereaches the service, in its own rate-limit zone (60/min per IP, private ranges exempt). Every other/webhooks/*request returns 404./trpcis never routed publicly.PUBLICloses access to the database.bitborg-billingis entry manager oftier_proand nothing else. No person reads: the portal passes display name and email.overwriteMembersstays false.BILLING_API_URLandBILLING_API_TOKENonly when enabled. The unit renders byte-identical when disabled.pg_restore --list, and the drill restores it and asserts at least one table. All guarded on the file existing.monitoring_core_unitswhen enabled, so the existing unit-down, unhealthy and flapping alerts cover it.No webhook secret. Mollie does not sign webhooks. The service re-fetches each payment by id and trusts only that, so the issue's "webhook secret" item does not apply.
Verified
POST /webhooks/molliereached billing.GETand other paths returned 404, and/trpc/xwent to the portal.entryManagedBy: bitborg-billingontier_pro).--check, billing disabled:changed=3 failed=0. The backup, verify and drill scripts gain billing blocks that do nothing while billing is off.--check -e billing_enabled=truefails at the vault assert with a clear message.Not verified until first enable
entry_managed_bygrants member write ontier_pro. It is a runbook verify step.bitborg_billing_image_tagis a placeholderv0.2.0.First enable
bitborg_billing_image_tagto it.bitborg-billingKanidm service account and a read-write API token.vault_payments_mollie_api_key_test(test_only),vault_billing_db_password,vault_billing_api_token,vault_kanidm_billing_token.billing_enabled: true, dry-run, apply--tags kanidm,billing,web,caddy,backup,monitoring-agent.billing_payments_enabled: trueand run a test checkout.Refs #496. It closes once a test payment grants the paid tier end to end and the drill restores the billing database.