Skip to content

WAL-1321 - #47

Draft
JakeFernandes98 wants to merge 24 commits into
mainfrom
feat/wal-1321
Draft

WAL-1321#47
JakeFernandes98 wants to merge 24 commits into
mainfrom
feat/wal-1321

Conversation

@JakeFernandes98

Copy link
Copy Markdown
Contributor

Summary

This aligns the Enterprise quickstart compose stack with generated license-state secrets so a local install can activate without a published shared encryption key, and it fixes the compose networking and Mongo startup conditions that blocked a licensed stack from coming up cleanly.

LICENSE_STATE_ENCRYPTION_KEY is left unset. The Enterprise API on walt-id/waltid-identity-enterprise#642 then generates a per-installation secret. The previous example value is removed because a secret that ships in the repository protects nothing. Compose Mongo now waits for the keyfile init container to finish, host ports are configurable, Caddy keeps enterprise.localhost, and the API no longer advertises that hostname on port 80.

Ticket: WAL-1321.

Related PRs:

What Changed

License configuration

  • .env leaves LICENSE_STATE_ENCRYPTION_KEY empty and documents why a shared example must not return.
  • config/license.conf describes the key as optional and drops the redundant LICENSE_SERVER_URL override. The compiled default https://license.walt.id is the correct production endpoint.

Compose runtime

  • Mongo and Mongo Express host ports are configurable (MONGO_PORT, MONGO_EXPRESS_PORT). The API still reaches Mongo as mongo:27017 on the compose network.
  • init-keyfile is service_completed_successfully so docker compose up --wait does not treat the one-shot container's exit as a failure.
  • The API waits for a healthy Mongo.
  • enterprise.localhost aliases are removed from the API service. Caddy owns those names; declaring them on both containers made callbacks round-robin onto the API's port 80, where nothing listens.
  • basePort is 80 so self-callbacks go through Caddy. Use 7500 only when running the API without Caddy.

Architecture Notes

  • This repository does not generate the secret. It only stops publishing one. Generation and blank-as-unset live in enterprise #642.
  • Helm still expects Secret waltid-enterprise-license / state-encryption-key. The optional-key path is the compose quickstart, not Kubernetes.

Caveats and Follow-Ups

  • A compose comment still says an empty LICENSE_STATE_ENCRYPTION_KEY fails startup closed. That is stale once enterprise #642 treats blank as unset.
  • Published docs are not updated in this repository.

Breaking

  • Existing compose users who kept the old example key can keep setting LICENSE_STATE_ENCRYPTION_KEY. Leaving it empty requires the enterprise #642 runtime.
  • basePort changing from 7500 to 80 changes generated public URLs in the Caddy-fronted quickstart. That matches how the stack is actually reached.

waltkb added 10 commits August 24, 2026 13:47
`docker compose up -d --wait mongodb` always failed. mongodb declared `depends_on: - init-keyfile`,
which means condition service_started, but init-keyfile is a one-shot container that generates the
keyfile and exits. --wait treats that clean exit as a failure:

  container init_keyfile exited (0)

It is now declared as service_completed_successfully, which is what it actually is.

Waiting for MongoDB matters because the container needs 10-20s on a fresh volume to create the root
user, and connecting during that window fails with MongoSecurityException / AuthenticationFailed.

The published MongoDB and mongo-express ports are now overridable via MONGO_PORT and
MONGO_EXPRESS_PORT, so a host that already runs either service can still start the stack. Only host
access is affected; the Enterprise API always reaches MongoDB as mongo:27017 on the compose network.
`docker compose up -d --wait mongodb` always failed. mongodb declared `depends_on: - init-keyfile`,
which means condition service_started, but init-keyfile is a one-shot container that generates the
keyfile and exits. --wait treats that clean exit as a failure:

  container init_keyfile exited (0)

It is now declared as service_completed_successfully, which is what it actually is.

Waiting for MongoDB matters because the container needs 10-20s on a fresh volume to create the root
user, and connecting during that window fails with MongoSecurityException / AuthenticationFailed.

The published MongoDB and mongo-express ports are now overridable via MONGO_PORT and
MONGO_EXPRESS_PORT, so a host that already runs either service can still start the stack. Only host
access is affected; the Enterprise API always reaches MongoDB as mongo:27017 on the compose network.
@linear-code

linear-code Bot commented Sep 1, 2026

Copy link
Copy Markdown

WAL-1321

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants