## What & why S-18c, the **final** slice of the S-18 (#19) split (after S-18a #142, S-18b #143). Defines the **RegisterRecord** objecttype — the schema S-19 (#20) will write canonical register records against on approval — and registers it in the Objecttypen API at startup. Closes #141 ### What - **Schema** (`infra/objecttypen-registerrecord/registerrecord.schema.json`): public-safe by construction — `id`, `status` (enum `INGEDIEND`/`INGESCHREVEN`), `reference` only, `additionalProperties: false`, `dataClassification: open`. Mirrors the BFF's `OpenbaarEntry` — **no `bsn`/`naam`** (ADR-0027). - **Registration**: a `registerrecord-init` compose one-shot (stdlib Python on the stack network) POSTs the objecttype + a **published** version over the API once Objecttypen is healthy. The Objecttypen `setup_configuration` (3.4.2) only provisions tokens — no declarative objecttype step — so this follows the ADR-0020 self-seed pattern. **Idempotent**: if a `RegisterRecord` with a version already exists it is a no-op. - **Wiring**: schema + `register.py` streamed into the external `rr-registerrecord-config` volume by `seed-config.sh registerrecord` (main) / bind-mounted (local); added to `SEED`, `CFG_VOLS`, and the CI log-dump. `registerrecord-init` is a one-shot (not in `WAIT_SVCS`). - **Smoke**: `verify-registerrecord` (`run-registerrecord-check.sh` + `registerrecord-check.py`) asserts the objecttype exists, has a **published** version, and that version's schema carries `id`/`status`/`reference`; added as a verify-stack step + a row in the #136 summary. - **ADR-0027**: records the public-safe schema decision (mirror the BFF public view, not the internal projection; API-seeded one-shot). The slice issue #141 flagged the schema as ADR-worthy, so no separate adr-proposal issue was opened. ## Verified locally (end to end, real compose) Seeded `rr-registerrecord-config`, brought Objecttypen up, ran `registerrecord-init` → `registered RegisterRecord <uuid> v1 (published)`. `make verify-registerrecord` → **OK — RegisterRecord v1 published, fields=['id', 'reference', 'status']**. Re-running the one-shot → **no-op** (idempotent). `docker compose config` clean on both files; schema + script + ci.yaml validated. ## Definition of Done - [x] Failing smoke committed first (`test(infra): …`, "no objecttype named RegisterRecord"); implementation makes it pass. - [x] Conventional Commits referencing #141. - [x] CI green (verify-stack registerrecord step — validated locally; runner already unstarved by #145). - [x] `docker compose up` reaches health (one-shot registers after Objecttypen healthy). - [x] Docs: ADR-0027 + demo note. - [x] Closed by the merging PR (`closes #141`). This closes out the S-18 (#19) split — Objecttypen (S-18a) + Objecten (S-18b) + RegisterRecord (S-18c) are all up. Next: **S-19 (#20)** — ACL writes the register record to Objecten on approval, against this schema. 🤖 Generated with [Claude Code](https://claude.com/claude-code)Reviewed-on: #146
59 lines
3.0 KiB
Bash
Executable File
59 lines
3.0 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
#
|
|
# Populate the external named *config* volumes that the upstream services mount,
|
|
# by `docker cp`-ing files into a throwaway helper container that mounts each one.
|
|
#
|
|
# Why: the compose stack uses the upstream images verbatim (no build). On Gitea's
|
|
# containerized runner, `docker compose` starts the stack as SIBLING containers
|
|
# via the host daemon, so a workspace bind mount resolves to a path the daemon
|
|
# can't see and is mounted empty. `docker cp` instead streams bytes over the
|
|
# Docker API, so the files reach the volume regardless of where the daemon runs.
|
|
# We use plain docker primitives (volume create / run / cp / rm) rather than
|
|
# `docker compose create`, because podman-compose (local dev) lacks that
|
|
# subcommand. Fixed-name `external` volumes keep the names deterministic across
|
|
# both runtimes. See docs/runbooks/gitea-actions-gotchas.md.
|
|
#
|
|
# Usage: seed-config.sh <key> [<key> ...] where key ∈ { oz, nrc, kc, fl, objecttypen, objecten, registerrecord }
|
|
set -euo pipefail
|
|
|
|
here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
HELPER="${SEED_HELPER_IMAGE:-docker.io/library/busybox:stable}"
|
|
|
|
populate() { # volume source(file or dir/.)
|
|
local vol="$1" src="$2" cid
|
|
docker volume rm -f "$vol" >/dev/null 2>&1 || true
|
|
docker volume create "$vol" >/dev/null
|
|
# A *created* (never started) helper is enough: the volume is attached at create
|
|
# time, `docker cp` writes through to it, and `docker rm` is instant (nothing to
|
|
# stop). `docker create` is a container subcommand both docker and podman have —
|
|
# unlike `docker compose create`, which podman-compose lacks.
|
|
cid="$(docker create -v "$vol:/dest" "$HELPER" true)"
|
|
docker cp "$src" "$cid:/dest/"
|
|
docker rm "$cid" >/dev/null
|
|
echo " seeded $vol"
|
|
}
|
|
|
|
[ "$#" -gt 0 ] || { echo "usage: seed-config.sh <oz|nrc|kc|fl|objecttypen|objecten|registerrecord> ..." >&2; exit 2; }
|
|
|
|
# The registratie process (BPMN) and its diploma-eligibility DMN are deployed as SEPARATE Flowable
|
|
# deployments — the process engine and the DMN engine each own theirs (S-13, ADR-0016). flowable-rest
|
|
# does not cascade a .dmn bundled in a process .bar into the DMN engine, so we seed both raw files and
|
|
# let flowable-init deploy each via its own REST app. We stage them in a temp dir and copy its contents.
|
|
stage_flowable_workflows() {
|
|
local dir="$1"
|
|
cp "$here/../workflows/registratie.bpmn" "$here/../workflows/diploma-eligibility.dmn" "$dir/"
|
|
}
|
|
|
|
for key in "$@"; do
|
|
case "$key" in
|
|
oz) populate rr-oz-config "$here/openzaak/setup_configuration/." ;;
|
|
nrc) populate rr-nrc-config "$here/opennotificaties/setup_configuration/." ;;
|
|
kc) populate rr-kc-realms "$here/keycloak/realms/." ;;
|
|
objecttypen) populate rr-objecttypen-config "$here/objecttypen/setup_configuration/." ;;
|
|
objecten) populate rr-objecten-config "$here/objecten/setup_configuration/." ;;
|
|
registerrecord) populate rr-registerrecord-config "$here/objecttypen-registerrecord/." ;;
|
|
fl) d="$(mktemp -d)"; stage_flowable_workflows "$d"; populate rr-fl-bpmn "$d/." ;;
|
|
*) echo "unknown seed key: $key" >&2; exit 2 ;;
|
|
esac
|
|
done
|