feat(multi-site): auto-derive site slug; wire proxy/jump service integrations
Two real gaps found while fixing the Directory's Multi-Site modal:
1. SITE_SLUG was never set anywhere -- site_config.js's own fallback
("site-default") was all a fresh master could ever show, since
nothing in setup.sh/docker-compose.yml passed it a value and
bootstrap.js never generated one. Derived from CFG_SITE_NAME (same
source jump-host's default exit node name already uses) with the
same slugify rule bootstrap.js's own site Resource slug uses,
formatted to match site_config.js's own "site-default" convention.
Only a first-run default -- a real join/promote's persisted
site.json value always wins.
2. PROXY_INTERNAL_URL and JUMP_INTERNAL_URL -- the env vars
utils/proxy_client.js (no-inbound relay automation) and the new
utils/jump_client.js (real gateway-mesh count on the modal) read to
find each service -- were never actually set anywhere in
docker-compose.yml. Both features existed in sso-manager-node's
code but were completely unreachable in every real deployment,
always hitting their "not configured" fallback. Wired both to the
docker network hostnames.
Also documents how to mint + store the two integration API tokens
those features need (self-service tokens each app already has, not a
new credential type -- same reasoning as the relay automation).
This commit is contained in:
@@ -78,6 +78,20 @@ CFG_DOMAIN=example.com
|
||||
#CFG_SPOKE_NO_INBOUND=true
|
||||
#CFG_SPOKE_PUBLIC_HOST=sso-branch2.master-domain.example.com
|
||||
|
||||
# Two service-to-service integrations the Directory uses (both reuse each
|
||||
# app's existing self-service API token system -- see MULTI_SITE_SPEC.md's
|
||||
# "service-to-service auth" note -- not a new credential type each):
|
||||
# - No-inbound relay automation (above) needs a theta-proxy API token so
|
||||
# sso-manager can create/update the relay Host route on its own.
|
||||
# - The Multi-Site modal's real gateway-mesh count needs a jump-host API
|
||||
# token (minted by a jump-admin user) to read GET /api/mesh/gateways.
|
||||
# Neither is required for the rest of the stack to work -- both features
|
||||
# just report "not configured" until you mint a token in each app's own web
|
||||
# UI (Settings -> API Tokens) and store it in OpenBao, from inside the
|
||||
# sso-manager container (VAULT_ADDR/VAULT_TOKEN are already set there):
|
||||
# docker compose exec sso-manager node -e "require('@simpleworkjs/bao-conf').set('integrations/theta-proxy', {token: 'prx_...'})"
|
||||
# docker compose exec sso-manager node -e "require('@simpleworkjs/bao-conf').set('integrations/theta-jump', {token: 'jmp_...'})"
|
||||
|
||||
# ── Optional outbound HTTP(S) proxy ──────────────────────────────────────────
|
||||
# For an isolated/offline/corporate-network test host that only reaches the
|
||||
# internet through an upstream HTTP proxy — NOT the theta42 "proxy" app.
|
||||
|
||||
Reference in New Issue
Block a user