HH-439: harden production artifact pipeline (#86)

* HH-439: harden production artifact pipeline

* fix(HH-439): address production compose review

* fix(HH-439): preserve previous JWT secrets in production

---------

Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
Rogee
2026-08-21 20:20:00 +08:00
committed by GitHub
co-authored by rogee
parent 7e3872170f
commit 7a9fec33c5
11 changed files with 436 additions and 153 deletions
-36
View File
@@ -1,36 +0,0 @@
# GoChat Production Environment Overrides
# Reference: Chatwoot config/environments/production.rb
server:
mode: "release"
cors:
# PRODUCTION: Must specify exact origins or wildcard patterns.
# NEVER leave empty in production — empty + non-debug = no CORS allowed.
allowed_origins:
- "https://app.yourdomain.com"
- "https://admin.yourdomain.com"
- "*.yourdomain.com" # matches any subdomain
allow_credentials: true # needed for JWT cookie-based auth
max_age: 86400
jwt:
allow_insecure_header_auth: false
database:
dsn: "postgres://gochat:CHANGE_ME@localhost:5432/gochat_production?sslmode=require"
pool_max: 20
log_level: "warn"
log:
level: "info"
format: "json"
worker:
concurrency: 10
redis_stream_prefix: "gochat:jobs"
redis_consumer_group: "gochat-workers"
redis_block_timeout_s: 5
redis_sweep_interval_s: 30
redis:
channel_prefix: "gochat_production"
+38
View File
@@ -0,0 +1,38 @@
# GoChat production overrides. Secrets and public origins must come from the environment.
server:
mode: "release"
cors:
allowed_origins: ["https://CHANGE_ME.example.com"]
allow_credentials: true
database:
dsn: "postgres://gochat:CHANGE_ME@postgres:5432/gochat_production?sslmode=disable"
run_migrations: true
migrations_path: "/app/migrations"
redis:
dsn: "redis://:CHANGE_ME@redis:6379"
jwt:
secret: "CHANGE_ME"
allow_insecure_header_auth: false
search:
engine: "meilisearch"
host: "http://meilisearch:7700"
api_key: "CHANGE_ME"
log:
level: "info"
format: "json"
worker:
concurrency: 10
redis_stream_prefix: "gochat:jobs"
redis_consumer_group: "gochat-workers"
redis_block_timeout_s: 5
redis_sweep_interval_s: 30
storage:
provider: "local"
local_path: "/app/storage/uploads"