feat: align LegacyHUB with TeamHUB platform contract (D2/D4, assets, security)
Close 12 audit-driven platform-compliance gaps on a single branch. - D4 dispatch: app/integrations/dispatch_client.py participant `legacyhub`, emits LegacyhubDocumentIndexed + AssetDerivativeReady after the indexing commit (idempotent uuid5), http_inbox route (reindex/tombstone) with audit-based dedupe; docs/dispatch-contract.md. Celery+Redis stays intra-module. - D2 SSO: app/integrations/identity.py validates X-TeamHub-* + role/scope mapper; security.py adds trusted-header enforcement (AUTH_REQUIRE_IDENTITY) and a scope check on /search; docker-compose.teamhub.yml (external teamhub_net + internal db net, api not host-published); RUNBOOK network/firewall section. - Asset standard: SearchHit/Citation carry asset_id/owner_module; buckets renamed teamhub-legacyhub-* (+quarantine/tmp/exports); purge-by-asset_id with legal-hold guard (app/indexing/projection.py); OCR-markdown derivative event. - audit_log model + Alembic 0003 + record_audit on writes (same transaction). - Secret masking: app/common/json_logger.py recursive mask wired into structlog (+ensure_ascii=False); event payloads redacted before persistence. - Service X-API-Key mandatory on ingest endpoints (defence-in-depth). - Port: host API 8000->8050 (collision with SalesHUB/MailHUB resolved), container still listens on 8000. - Config: no plaintext secret defaults; fail-loud in non-dev (no value leak). - Docs drift: README PG 5440, layered-auth note, 5173 removed from CORS; ingest/folder gated by ENABLE_FOLDER_INGEST (410 by default). - ADRs: layers mapping, shared-core extraction, UI locale (RU-first). Tests: 78 passing (ruff, compileall, pytest, tsc, vite build, compose config). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
53
docker-compose.teamhub.yml
Normal file
53
docker-compose.teamhub.yml
Normal file
@@ -0,0 +1,53 @@
|
||||
# Federation overlay: run LegacyHUB behind the TeamHUB gateway on the shared
|
||||
# `teamhub_net`. Compared with the standalone dev compose this overlay:
|
||||
# - moves every backing service onto an internal-only network (no host ports);
|
||||
# - reaches the api ONLY via `teamhub_net` (the gateway upstream), never
|
||||
# directly from the host - so spoofing `X-TeamHub-*` is blocked by the network;
|
||||
# - turns on trusted-header identity enforcement (AUTH_REQUIRE_IDENTITY).
|
||||
#
|
||||
# The shared network must exist first (created by TeamHUB-Platform infra):
|
||||
# docker network create teamhub_net
|
||||
#
|
||||
# Usage (compose with prod hardening + this federation overlay):
|
||||
# docker compose -f docker-compose.yml -f docker-compose.prod.yml \
|
||||
# -f docker-compose.teamhub.yml --env-file .env.prod up -d --build
|
||||
#
|
||||
# See RUNBOOK.md "Network model & firewall" for the matching firewall rules.
|
||||
|
||||
networks:
|
||||
teamhub_net:
|
||||
external: true
|
||||
name: teamhub_net
|
||||
legacyhub_db:
|
||||
internal: true
|
||||
|
||||
services:
|
||||
postgres:
|
||||
ports: !reset []
|
||||
networks: [legacyhub_db]
|
||||
|
||||
minio:
|
||||
ports: !reset []
|
||||
networks: [legacyhub_db]
|
||||
|
||||
opensearch:
|
||||
ports: !reset []
|
||||
networks: [legacyhub_db]
|
||||
|
||||
qdrant:
|
||||
ports: !reset []
|
||||
networks: [legacyhub_db]
|
||||
|
||||
redis:
|
||||
ports: !reset []
|
||||
networks: [legacyhub_db]
|
||||
|
||||
api:
|
||||
# Not published to the host: the gateway reaches the api over teamhub_net.
|
||||
ports: !reset []
|
||||
networks: [legacyhub_db, teamhub_net]
|
||||
environment:
|
||||
AUTH_REQUIRE_IDENTITY: "true"
|
||||
|
||||
worker:
|
||||
networks: [legacyhub_db, teamhub_net]
|
||||
Reference in New Issue
Block a user