- DatabaseConfig: Host/Port/User/Password/Name/DBName/SSLMode → 单个 DSN 字段 - RedisConfig: Host/Port/Password/DB/URL → 单个 DSN 字段 - 环境变量: GOCHAT_DATABASE_* (7个) → GOCHAT_DATABASE_DSN, GOCHAT_REDIS_* (5个) → GOCHAT_REDIS_DSN - validator.go: DSN URL 解析校验 (scheme + host) - redis.go: redis.ParseURL(cfg.DSN) 直连 - 所有 docker-compose / CI / shell 脚本 / .env 同步更新 - 删除 deploy/helm/ 整个目录 (20个文件) - CI 删除 helm-validate / deploy-staging / deploy-production 三个 job - 文档同步更新 (README, 架构设计, PRD, 滚动升级)
65 lines
2.7 KiB
YAML
65 lines
2.7 KiB
YAML
server:
|
|
host: "0.0.0.0"
|
|
port: 3000
|
|
mode: "debug" # debug, release, test
|
|
cors:
|
|
allowed_origins: [] # empty = Allow-Origin:* in debug mode; production must list exact origins
|
|
# Examples:
|
|
# - "https://app.example.com"
|
|
# - "*.example.com"
|
|
allowed_methods: ["GET", "POST", "PUT", "DELETE", "PATCH", "OPTIONS"]
|
|
allowed_headers: ["Origin", "Content-Type", "Accept", "Authorization", "X-Account-ID", "access-token", "client", "uid", "token-type", "expiry"]
|
|
expose_headers: ["Content-Length", "access-token", "client", "uid", "token-type", "expiry"]
|
|
allow_credentials: false # set to true only if you need cookies/auth headers
|
|
max_age: 86400 # preflight cache duration in seconds
|
|
|
|
database:
|
|
dsn: "postgres://postgres:xiha02@localhost:5444/gochat_dev?sslmode=disable"
|
|
max_idle_conns: 10
|
|
max_open_conns: 100
|
|
conn_max_lifetime: 3600 # seconds
|
|
run_migrations: true # auto-run migrations on startup (dev convenience)
|
|
migrations_path: "migrations"
|
|
|
|
redis:
|
|
dsn: "redis://:xiha02@localhost:6397/0"
|
|
pool_size: 50
|
|
|
|
jwt:
|
|
secret: "gochat_dev_secret_change_in_production"
|
|
expiry_hours: 72
|
|
|
|
log:
|
|
level: "debug" # debug, info, warn, error
|
|
format: "json" # json, text
|
|
|
|
rate_limit:
|
|
enabled: true
|
|
requests_per_minute: 100 # max requests per client IP per window
|
|
window_seconds: 60 # sliding window duration in seconds
|
|
|
|
search:
|
|
# Chatwoot parity target. Use "db" only for explicit local fallback.
|
|
engine: "meilisearch"
|
|
host: "http://localhost:7700"
|
|
api_key: ""
|
|
index_prefix: "gochat_"
|
|
timeout_seconds: 5
|
|
|
|
saml:
|
|
enabled: false # SAML 2.0 SSO — enable for enterprise IdP integration
|
|
# IdP metadata: provide URL or inline XML (URL preferred for auto-refresh)
|
|
idp_metadata_url: "" # e.g. "https://idp.example.com/metadata"
|
|
idp_metadata_xml: "" # fallback: paste IdP metadata XML here
|
|
sp_entity_id: "https://gochat.example.com/saml" # our SP entity ID
|
|
acs_url: "https://gochat.example.com/api/v1/saml/acs" # Assertion Consumer Service URL
|
|
# SP key/certificate: PEM format (required for signed AuthnRequest + response validation)
|
|
sp_private_key: "" # path or inline PEM — generate with: openssl genrsa -out sp.key 2048
|
|
sp_certificate: "" # path or inline PEM — generate with: openssl req -new -x509 -key sp.key -out sp.crt
|
|
clock_drift_tolerance: 180 # seconds of allowed clock drift for NotOnOrAfter validation
|
|
attribute_map:
|
|
email: "email" # SAML attribute → GoChat email field
|
|
display_name: "displayName" # SAML attribute → GoChat display name field
|
|
first_name: "firstName" # SAML attribute → first name component
|
|
last_name: "lastName" # SAML attribute → last name component
|