## What & why The host-browser stack (`make local`) had drifted behind three slices, so a fresh bring-up couldn't complete the flow: registrations stuck at `OpenZaakAanmaken`, the behandel werkbak stayed empty, and the openbaar register showed nothing. The `verify-*` scripts do this setup for CI at test time; `make local` had no equivalent. This makes the local stack **self-seed at bring-up** so it just works in a browser: - **DMN** — `flowable-init` now also deploys `diploma-eligibility.dmn` (was BPMN-only), so completing `WachtOpDocumenten` routes through the DMN to `Beoordelen` instead of 404ing. - **Zaaktype + ACL** — a `local-seed` one-shot publishes the BIG zaaktype (whose UUID is server-assigned, hence not static in the compose file) and writes the real URLs to `seed-env:/acl.env`; the ACL sources it on startup via an entrypoint override. - **NRC abonnement** — an `nrc-subscribe` one-shot registers the `zaken` subscription at the event-subscriber callback, so notifications reach the projection/openbaar register. Both one-shots reach OpenZaak/NRC by **container IP** (a single-label host fails their Django URLValidator), mirroring the CI verify scripts. Design + trade-offs in **ADR-0020**. Closes #110 ## Definition of Done - [x] Linked Gitea issue (#110). - [x] Failing test committed before the implementation — `test(infra): …` adds `infra/run-local-flow-check.sh` / `make verify-local`; the three gaps' failures were observed live on a fresh `make local` (red), and the fix turns it green. - [x] Implementation makes the test pass; docs commit follows. - [x] Conventional Commits referencing the issue (`refs #110`). - [ ] CI green — running on the restored runner. Infra-only change; the CI `verify-stack` job uses `docker-compose.yml` (untouched). Also validated locally: `make verify-local` passes against a fresh `make local` (see below). - [x] `docker compose up` from a fresh clone reaches green health checks — verified: `make local` healthy in ~2m20s, then `make verify-local` green. - [x] Docs updated — ADR-0020 + demo-script note. - [x] ADR added in `docs/architecture/` — ADR-0020. - [x] Demo note in `docs/demo-script.md`. ## Notes for reviewers - **Infra-only** — no service code changes; the ACL image and the CI stack (`docker-compose.yml`) are untouched. - **Verified end-to-end on a fresh stack** (`make local-down && make local && make verify-local`): ``` >> 2. zaak opened (zaaktype seeded + wired) >> 3. documents accepted 204 (DMN deployed) >> 4. in the werkbak (DMN routing → Beoordelen) >> 5. visible in the openbaar register (NRC abonnement) OK — a fresh local stack completed the flow with no manual seeding ``` - **Follow-up:** the cleaner design — ACL resolving its zaaktype by `identificatie` instead of a pinned server-assigned URL — is split out as **S-27 (#113)**; landing it would remove the `acl.env` injection here. ADR-0020 records this. - The `seed-env` volume carries the generated `acl.env` from `local-seed` to the ACL; a `down --volumes` (as `make local-down` does) resets it cleanly. Reviewed-on: #114
36 lines
1.9 KiB
Bash
Executable File
36 lines
1.9 KiB
Bash
Executable File
#!/bin/sh
|
|
# Local-stack bootstrap (S-B04, #110, ADR-0020) — the "seed zaaktype + wire the ACL" step.
|
|
#
|
|
# Runs as the `local-seed` init container of infra/docker-compose.local.yml. It seeds + publishes
|
|
# the BIG zaaktype (and the Diploma informatieobjecttype) into OpenZaak, then writes the resulting
|
|
# **server-assigned** URLs into /out/acl.env, which the ACL entrypoint sources before starting. This
|
|
# is the local-stack equivalent of what infra/run-domain-check.sh does for CI: the zaaktype UUID is
|
|
# assigned by OpenZaak at creation, so it can't be a static value in the compose file.
|
|
#
|
|
# Why the container IP and not the `openzaak` service name: OpenZaak validates URL query params
|
|
# (e.g. ?catalogus=) with Django's URLValidator, which rejects a single-label host like `openzaak`.
|
|
# Seeding against the resolved IP keeps the seeded URLs valid AND host-consistent with the ACL, which
|
|
# we point at the same IP below. See docs/runbooks/gitea-actions-gotchas.md and ADR-0020.
|
|
set -eu
|
|
|
|
oz_ip="$(python3 -c "import socket;print(socket.gethostbyname('openzaak'))")"
|
|
OZ_BASE="http://${oz_ip}:8000"
|
|
export OZ_BASE OZ_PUBLISH=1
|
|
|
|
echo ">> seeding + publishing the BIG zaaktype at ${OZ_BASE} (idempotent)"
|
|
out="$(python3 /work/seed_catalogus.py)"
|
|
echo "$out"
|
|
|
|
zt="$(printf '%s\n' "$out" | sed -n 's/^ZAAKTYPE_URL //p' | head -1)"
|
|
iot="$(printf '%s\n' "$out" | sed -n 's/^INFORMATIEOBJECTTYPE_URL //p' | head -1)"
|
|
[ -n "$zt" ] || { echo "ERROR: seed did not report a ZAAKTYPE_URL" >&2; exit 1; }
|
|
[ -n "$iot" ] || { echo "ERROR: seed did not report an INFORMATIEOBJECTTYPE_URL" >&2; exit 1; }
|
|
|
|
# The ACL entrypoint sources this; these keys override the placeholder defaults in the compose file.
|
|
cat > /out/acl.env <<EOF
|
|
Acl__OpenZaak__BaseUrl=${OZ_BASE}/
|
|
Acl__Defaults__ZaaktypeUrl=${zt}
|
|
Acl__Defaults__InformatieobjecttypeUrl=${iot}
|
|
EOF
|
|
echo ">> wrote /out/acl.env (base=${OZ_BASE}/ zaaktype=${zt})"
|