## What & why S-18b, second of the S-18 (#19) split (after S-18a #139/#142). Stands up the upstream Maykin **Objecten API** in the compose stack and wires it to the Objecttypen API — the authoritative object store the ACL will write register records to (S-19). Closes #140 ### What - **Compose** (main + local): `objecten-db` (**PostGIS** — objects carry geometry), `objecten-redis`, `objecten-init` (RUN_SETUP_CONFIG → migrate + provision token + register the Objecttypen service), `objecten` web (health on `/admin/`, host `:8021`). Verbatim upstream image `maykinmedia/objects-api` pinned to `3.4.0` (nearest release to objecttypes-api `3.4.2`; the two speak over the stable Objecttypes API v2). - **Seed**: `infra/seed-config.sh objecten` streams `infra/objecten/setup_configuration/data.yaml` into the external `rr-objecten-config` volume — same pattern as S-18a. The data.yaml (1) registers **Objecttypen** as a trusted `zgw_consumers` service (`api_type: orc`, api-key auth with the S-18a dev token) so an object can reference its objecttype, and (2) provisions a dev **static API token** so peers (the ACL, S-19) can write objects. - **Wiring**: added to `WAIT_SVCS`, `CFG_VOLS`, the `SEED` invocations, `seed-config.sh`, and the CI log-dump. `objecten-init` waits on `objecttypen` being healthy so the service registration is meaningful end to end. - **Smoke**: `verify-objecten` (`infra/run-objecten-check.sh` + `objecten-check.py`) asserts unauth → 401, token → 200 on `/api/v2/objects`; added as a verify-stack step + a row in the #136 check-summary table. ## Verified locally (end to end, real compose) Seeded + brought up the real `infra/docker-compose.yml` objecten chain (pulls in objecttypen via `depends_on`): `objecten-init` ran setup_configuration — `token_configuration_success` **and** "Successfully executed step: Configuration to connect with external services" — the web reached healthy, and `make verify-objecten` → **"OK — no-auth 401, token 200"**. Confirmed the registered service via the Objecten django shell: ``` objecttypen | orc | http://objecttypen:8000/api/v2/ | api_key ``` YAML (both compose files + ci.yaml) + shell + python all validated; `docker compose config` clean on both files. ## Definition of Done - [x] Failing smoke committed first (`test(infra): …`, "no running objecten container"); implementation makes it pass. - [x] Conventional Commits referencing #140. - [ ] CI green (verify-stack objecten step). - [x] `docker compose up` reaches health (objecten healthy on first poll locally). - [x] Demo note in `docs/demo-script.md`. - [x] Closed by the merging PR (`closes #140`). No new ADR: follows the established verbatim-image + seed-config CG-module pattern (S-18a/ADR-0023-era). 🤖 Generated with [Claude Code](https://claude.com/claude-code)Reviewed-on: #143
This commit was merged in pull request #143.
This commit is contained in:
@@ -621,12 +621,76 @@ services:
|
||||
condition: service_completed_successfully
|
||||
networks: [cg]
|
||||
|
||||
# ── Objecten API (S-18b) — bind-mounted config (local variant) ─────────────
|
||||
objecten-db:
|
||||
image: docker.io/postgis/postgis:17-3.5
|
||||
environment:
|
||||
POSTGRES_USER: objects
|
||||
POSTGRES_PASSWORD: objects
|
||||
POSTGRES_DB: objects
|
||||
volumes:
|
||||
- objecten-db:/var/lib/postgresql/data
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "pg_isready -U objects"]
|
||||
interval: 5s
|
||||
timeout: 3s
|
||||
retries: 10
|
||||
networks: [cg]
|
||||
|
||||
objecten-redis:
|
||||
image: docker.io/library/redis:7
|
||||
networks: [cg]
|
||||
|
||||
objecten-init:
|
||||
image: docker.io/maykinmedia/objects-api:${OBJECTS_TAG:-3.4.0}
|
||||
environment: &objecten-env-local
|
||||
DJANGO_SETTINGS_MODULE: objects.conf.docker
|
||||
SECRET_KEY: ${OBJECTS_SECRET_KEY:-dev-only-not-for-production}
|
||||
DB_HOST: objecten-db
|
||||
DB_NAME: objects
|
||||
DB_USER: objects
|
||||
DB_PASSWORD: objects
|
||||
ALLOWED_HOSTS: "*"
|
||||
CACHE_DEFAULT: objecten-redis:6379/0
|
||||
CACHE_AXES: objecten-redis:6379/0
|
||||
DISABLE_2FA: "true"
|
||||
OTEL_SDK_DISABLED: "true"
|
||||
RUN_SETUP_CONFIG: "true"
|
||||
command: /setup_configuration.sh
|
||||
volumes:
|
||||
- ./objecten/setup_configuration:/app/setup_configuration:ro,z
|
||||
depends_on:
|
||||
objecten-db:
|
||||
condition: service_healthy
|
||||
objecten-redis:
|
||||
condition: service_started
|
||||
objecttypen:
|
||||
condition: service_healthy
|
||||
networks: [cg]
|
||||
|
||||
objecten:
|
||||
image: docker.io/maykinmedia/objects-api:${OBJECTS_TAG:-3.4.0}
|
||||
environment: *objecten-env-local
|
||||
healthcheck:
|
||||
test: ["CMD", "python", "-c", "import requests,sys; sys.exit(0 if requests.head('http://localhost:8000/admin/').status_code in (200,302) else 1)"]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 10
|
||||
start_period: 30s
|
||||
ports:
|
||||
- "8021:8000"
|
||||
depends_on:
|
||||
objecten-init:
|
||||
condition: service_completed_successfully
|
||||
networks: [cg]
|
||||
|
||||
volumes:
|
||||
oz-db:
|
||||
nrc-db:
|
||||
flowable-db:
|
||||
projection-db:
|
||||
objecttypen-db:
|
||||
objecten-db:
|
||||
# Carries the seed-generated acl.env (server-assigned zaaktype URLs) from local-seed to the ACL.
|
||||
seed-env:
|
||||
|
||||
|
||||
@@ -635,6 +635,76 @@ services:
|
||||
condition: service_completed_successfully
|
||||
networks: [cg]
|
||||
|
||||
# ── Objecten API (S-18b) — upstream Maykin image, verbatim ─────────────────
|
||||
# The authoritative object store. Same shape as Objecttypen (own DB + redis, an `-init` that runs
|
||||
# setup_configuration from the external config volume, a health-checked web). Two differences: the
|
||||
# DB is PostGIS (objects carry geometry), and setup_configuration registers the Objecttypen API
|
||||
# (S-18a) as a trusted service so an object can reference its objecttype.
|
||||
objecten-db:
|
||||
image: docker.io/postgis/postgis:17-3.5
|
||||
environment:
|
||||
POSTGRES_USER: objects
|
||||
POSTGRES_PASSWORD: objects
|
||||
POSTGRES_DB: objects
|
||||
volumes:
|
||||
- objecten-db:/var/lib/postgresql/data
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "pg_isready -U objects"]
|
||||
interval: 5s
|
||||
timeout: 3s
|
||||
retries: 10
|
||||
networks: [cg]
|
||||
|
||||
objecten-redis:
|
||||
image: docker.io/library/redis:7
|
||||
networks: [cg]
|
||||
|
||||
objecten-init:
|
||||
image: docker.io/maykinmedia/objects-api:${OBJECTS_TAG:-3.4.0}
|
||||
environment: &objecten-env
|
||||
DJANGO_SETTINGS_MODULE: objects.conf.docker
|
||||
SECRET_KEY: ${OBJECTS_SECRET_KEY:-dev-only-not-for-production}
|
||||
DB_HOST: objecten-db
|
||||
DB_NAME: objects
|
||||
DB_USER: objects
|
||||
DB_PASSWORD: objects
|
||||
ALLOWED_HOSTS: "*"
|
||||
CACHE_DEFAULT: objecten-redis:6379/0
|
||||
CACHE_AXES: objecten-redis:6379/0
|
||||
DISABLE_2FA: "true"
|
||||
OTEL_SDK_DISABLED: "true"
|
||||
RUN_SETUP_CONFIG: "true"
|
||||
command: /setup_configuration.sh
|
||||
# data.yaml is streamed into this external volume by infra/seed-config.sh before start.
|
||||
volumes:
|
||||
- objecten-config:/app/setup_configuration:ro
|
||||
depends_on:
|
||||
objecten-db:
|
||||
condition: service_healthy
|
||||
objecten-redis:
|
||||
condition: service_started
|
||||
# Objecten's setup_configuration registers the Objecttypen service; that service only needs to
|
||||
# exist as config, but wait for Objecttypen to be up so the register is meaningful end to end.
|
||||
objecttypen:
|
||||
condition: service_healthy
|
||||
networks: [cg]
|
||||
|
||||
objecten:
|
||||
image: docker.io/maykinmedia/objects-api:${OBJECTS_TAG:-3.4.0}
|
||||
environment: *objecten-env
|
||||
healthcheck:
|
||||
test: ["CMD", "python", "-c", "import requests,sys; sys.exit(0 if requests.head('http://localhost:8000/admin/').status_code in (200,302) else 1)"]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 10
|
||||
start_period: 30s
|
||||
ports:
|
||||
- "8021:8000"
|
||||
depends_on:
|
||||
objecten-init:
|
||||
condition: service_completed_successfully
|
||||
networks: [cg]
|
||||
|
||||
# ── Observability backplane (S-16a, ADR-0023) ──────────────────────────────
|
||||
# Grafana-native stack: Tempo ingests OTLP traces (the .NET services export
|
||||
# straight to it — no collector hop, S-16b), Prometheus scrapes service
|
||||
@@ -685,6 +755,7 @@ volumes:
|
||||
flowable-db:
|
||||
projection-db:
|
||||
objecttypen-db:
|
||||
objecten-db:
|
||||
# Config volumes — created and populated out-of-band by infra/seed-config.sh
|
||||
# (docker cp), because bind mounts don't reach sibling containers on the CI
|
||||
# runner. `external` keeps the names deterministic; the seed step manages them.
|
||||
@@ -703,6 +774,9 @@ volumes:
|
||||
objecttypen-config:
|
||||
external: true
|
||||
name: rr-objecttypen-config
|
||||
objecten-config:
|
||||
external: true
|
||||
name: rr-objecten-config
|
||||
|
||||
networks:
|
||||
cg:
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
#!/usr/bin/env python3
|
||||
"""S-18b (#140): prove the Objecten API is up and its static token authenticates.
|
||||
|
||||
Assert an unauthenticated call to /api/v2/objects is 401 and an authenticated one (the seeded dev
|
||||
token) is 200 — i.e. the service migrated, booted, and setup_configuration provisioned the token
|
||||
and the Objecttypen service it trusts. Stdlib only so it runs in a bare python:3-slim container on
|
||||
the compose network.
|
||||
"""
|
||||
import os
|
||||
import sys
|
||||
import time
|
||||
import urllib.error
|
||||
import urllib.request
|
||||
|
||||
BASE = os.environ["OBJECTEN"] # http://<ip>:8000
|
||||
TOKEN = os.environ["OBJECTEN_TOKEN"]
|
||||
TIMEOUT = int(os.environ.get("OBJECTEN_TIMEOUT", "60"))
|
||||
|
||||
|
||||
def status(url, token=None):
|
||||
req = urllib.request.Request(url)
|
||||
if token:
|
||||
req.add_header("Authorization", f"Token {token}")
|
||||
try:
|
||||
with urllib.request.urlopen(req, timeout=10) as r:
|
||||
return r.status
|
||||
except urllib.error.HTTPError as e:
|
||||
return e.code
|
||||
except Exception:
|
||||
return 0
|
||||
|
||||
|
||||
def main():
|
||||
url = f"{BASE}/api/v2/objects"
|
||||
deadline = time.time() + TIMEOUT
|
||||
while time.time() < deadline:
|
||||
unauth = status(url)
|
||||
authed = status(url, TOKEN)
|
||||
if unauth == 401 and authed == 200:
|
||||
print(f"OK — {url}: no-auth {unauth}, token {authed}")
|
||||
return 0
|
||||
time.sleep(3)
|
||||
print(f"FAIL — {url}: expected no-auth 401 + token 200, got {status(url)} / {status(url, TOKEN)}",
|
||||
file=sys.stderr)
|
||||
return 1
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
@@ -0,0 +1,31 @@
|
||||
# Objecten API setup_configuration (S-18b). Streamed into the external rr-objecten-config volume by
|
||||
# infra/seed-config.sh and applied by objecten-init (RUN_SETUP_CONFIG). Declarative + idempotent.
|
||||
#
|
||||
# Two things: (1) register the Objecttypen API (S-18a) as a trusted service so an object can
|
||||
# reference its objecttype — authenticating with the dev static token Objecttypen provisioned; and
|
||||
# (2) a dev static token so peers (the ACL, S-19) can write objects here. Dev-only, not for prod.
|
||||
|
||||
# (1) Trust the Objecttypen API. `orc` = overige RESTful component (how zgw_consumers classifies the
|
||||
# Objecttypen API). The RegisterRecord objecttype (S-18c) will reference an objecttype under this
|
||||
# service by uuid.
|
||||
zgw_consumers_config_enable: true
|
||||
zgw_consumers:
|
||||
services:
|
||||
- identifier: objecttypen
|
||||
label: Objecttypen API
|
||||
api_type: orc
|
||||
api_root: http://objecttypen:8000/api/v2/
|
||||
auth_type: api_key
|
||||
header_key: Authorization
|
||||
header_value: Token 0123456789abcdef0123456789abcdef01234567
|
||||
|
||||
# (2) Static API token peers use to write/read objects.
|
||||
tokenauth_config_enable: true
|
||||
tokenauth:
|
||||
items:
|
||||
- identifier: register-referentie
|
||||
token: 1234567890abcdef1234567890abcdef12345678
|
||||
contact_person: Register Referentie
|
||||
email: admin@localhost
|
||||
organization: Respellion
|
||||
is_superuser: true
|
||||
Executable
+28
@@ -0,0 +1,28 @@
|
||||
#!/usr/bin/env bash
|
||||
#
|
||||
# S-18b (#140): assert the Objecten API is healthy + its static token authenticates, against an
|
||||
# ALREADY-RUNNING stack. Runs the check in a python:3-slim container on the stack network (the
|
||||
# service is reached by container IP; the runner can't reach published ports — gitea-actions-gotchas.md
|
||||
# §5/§6). Does NOT manage the stack lifecycle.
|
||||
set -euo pipefail
|
||||
|
||||
here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
|
||||
# The dev token provisioned by infra/objecten/setup_configuration/data.yaml.
|
||||
TOKEN="${OBJECTEN_TOKEN:-1234567890abcdef1234567890abcdef12345678}"
|
||||
|
||||
ot="$(docker ps -q --filter 'name=objecten' --filter 'health=healthy' | head -1)"
|
||||
[ -n "$ot" ] || ot="$(docker ps -q --filter 'name=[-_]objecten[-_]' | head -1)"
|
||||
[ -n "$ot" ] || { echo "ERROR: no running objecten container — bring the stack up first" >&2; exit 1; }
|
||||
net="$(docker inspect -f '{{range $k,$_ := .NetworkSettings.Networks}}{{$k}}{{"\n"}}{{end}}' "$ot" | head -1)"
|
||||
ip="$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' "$ot")"
|
||||
echo ">> network=$net objecten=$ip"
|
||||
|
||||
cid="$(docker create --network "$net" \
|
||||
-e "OBJECTEN=http://$ip:8000" -e "OBJECTEN_TOKEN=$TOKEN" \
|
||||
-e "OBJECTEN_TIMEOUT=${OBJECTEN_TIMEOUT:-60}" \
|
||||
python:3-slim python /objecten-check.py)"
|
||||
docker cp "$here/objecten-check.py" "$cid:/objecten-check.py" >/dev/null
|
||||
rc=0; docker start -a "$cid" || rc=$?
|
||||
docker rm -f "$cid" >/dev/null
|
||||
exit $rc
|
||||
@@ -13,7 +13,7 @@
|
||||
# subcommand. Fixed-name `external` volumes keep the names deterministic across
|
||||
# both runtimes. See docs/runbooks/gitea-actions-gotchas.md.
|
||||
#
|
||||
# Usage: seed-config.sh <key> [<key> ...] where key ∈ { oz, kc, fl }
|
||||
# Usage: seed-config.sh <key> [<key> ...] where key ∈ { oz, nrc, kc, fl, objecttypen, objecten }
|
||||
set -euo pipefail
|
||||
|
||||
here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
@@ -33,7 +33,7 @@ populate() { # volume source(file or dir/.)
|
||||
echo " seeded $vol"
|
||||
}
|
||||
|
||||
[ "$#" -gt 0 ] || { echo "usage: seed-config.sh <oz|nrc|kc|fl|objecttypen> ..." >&2; exit 2; }
|
||||
[ "$#" -gt 0 ] || { echo "usage: seed-config.sh <oz|nrc|kc|fl|objecttypen|objecten> ..." >&2; exit 2; }
|
||||
|
||||
# The registratie process (BPMN) and its diploma-eligibility DMN are deployed as SEPARATE Flowable
|
||||
# deployments — the process engine and the DMN engine each own theirs (S-13, ADR-0016). flowable-rest
|
||||
@@ -50,6 +50,7 @@ for key in "$@"; do
|
||||
nrc) populate rr-nrc-config "$here/opennotificaties/setup_configuration/." ;;
|
||||
kc) populate rr-kc-realms "$here/keycloak/realms/." ;;
|
||||
objecttypen) populate rr-objecttypen-config "$here/objecttypen/setup_configuration/." ;;
|
||||
objecten) populate rr-objecten-config "$here/objecten/setup_configuration/." ;;
|
||||
fl) d="$(mktemp -d)"; stage_flowable_workflows "$d"; populate rr-fl-bpmn "$d/." ;;
|
||||
*) echo "unknown seed key: $key" >&2; exit 2 ;;
|
||||
esac
|
||||
|
||||
Reference in New Issue
Block a user