WAL-1321 - #47
Draft
JakeFernandes98 wants to merge 24 commits into
Draft
Conversation
`docker compose up -d --wait mongodb` always failed. mongodb declared `depends_on: - init-keyfile`, which means condition service_started, but init-keyfile is a one-shot container that generates the keyfile and exits. --wait treats that clean exit as a failure: container init_keyfile exited (0) It is now declared as service_completed_successfully, which is what it actually is. Waiting for MongoDB matters because the container needs 10-20s on a fresh volume to create the root user, and connecting during that window fails with MongoSecurityException / AuthenticationFailed. The published MongoDB and mongo-express ports are now overridable via MONGO_PORT and MONGO_EXPRESS_PORT, so a host that already runs either service can still start the stack. Only host access is affected; the Enterprise API always reaches MongoDB as mongo:27017 on the compose network.
…llation generates its own
`docker compose up -d --wait mongodb` always failed. mongodb declared `depends_on: - init-keyfile`, which means condition service_started, but init-keyfile is a one-shot container that generates the keyfile and exits. --wait treats that clean exit as a failure: container init_keyfile exited (0) It is now declared as service_completed_successfully, which is what it actually is. Waiting for MongoDB matters because the container needs 10-20s on a fresh volume to create the root user, and connecting during that window fails with MongoSecurityException / AuthenticationFailed. The published MongoDB and mongo-express ports are now overridable via MONGO_PORT and MONGO_EXPRESS_PORT, so a host that already runs either service can still start the stack. Only host access is affected; the Enterprise API always reaches MongoDB as mongo:27017 on the compose network.
…llation generates its own
…key does not stop the pod
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This aligns the Enterprise quickstart compose stack with generated license-state secrets so a local install can activate without a published shared encryption key, and it fixes the compose networking and Mongo startup conditions that blocked a licensed stack from coming up cleanly.
LICENSE_STATE_ENCRYPTION_KEYis left unset. The Enterprise API on walt-id/waltid-identity-enterprise#642 then generates a per-installation secret. The previous example value is removed because a secret that ships in the repository protects nothing. Compose Mongo now waits for the keyfile init container to finish, host ports are configurable, Caddy keepsenterprise.localhost, and the API no longer advertises that hostname on port 80.Ticket: WAL-1321.
Related PRs:
What Changed
License configuration
.envleavesLICENSE_STATE_ENCRYPTION_KEYempty and documents why a shared example must not return.config/license.confdescribes the key as optional and drops the redundantLICENSE_SERVER_URLoverride. The compiled defaulthttps://license.walt.idis the correct production endpoint.Compose runtime
MONGO_PORT,MONGO_EXPRESS_PORT). The API still reaches Mongo asmongo:27017on the compose network.init-keyfileisservice_completed_successfullysodocker compose up --waitdoes not treat the one-shot container's exit as a failure.enterprise.localhostaliases are removed from the API service. Caddy owns those names; declaring them on both containers made callbacks round-robin onto the API's port 80, where nothing listens.basePortis 80 so self-callbacks go through Caddy. Use 7500 only when running the API without Caddy.Architecture Notes
waltid-enterprise-license/state-encryption-key. The optional-key path is the compose quickstart, not Kubernetes.Caveats and Follow-Ups
LICENSE_STATE_ENCRYPTION_KEYfails startup closed. That is stale once enterprise #642 treats blank as unset.Breaking
LICENSE_STATE_ENCRYPTION_KEY. Leaving it empty requires the enterprise #642 runtime.basePortchanging from 7500 to 80 changes generated public URLs in the Caddy-fronted quickstart. That matches how the stack is actually reached.