Close 12 audit-driven platform-compliance gaps on a single branch. - D4 dispatch: app/integrations/dispatch_client.py participant `legacyhub`, emits LegacyhubDocumentIndexed + AssetDerivativeReady after the indexing commit (idempotent uuid5), http_inbox route (reindex/tombstone) with audit-based dedupe; docs/dispatch-contract.md. Celery+Redis stays intra-module. - D2 SSO: app/integrations/identity.py validates X-TeamHub-* + role/scope mapper; security.py adds trusted-header enforcement (AUTH_REQUIRE_IDENTITY) and a scope check on /search; docker-compose.teamhub.yml (external teamhub_net + internal db net, api not host-published); RUNBOOK network/firewall section. - Asset standard: SearchHit/Citation carry asset_id/owner_module; buckets renamed teamhub-legacyhub-* (+quarantine/tmp/exports); purge-by-asset_id with legal-hold guard (app/indexing/projection.py); OCR-markdown derivative event. - audit_log model + Alembic 0003 + record_audit on writes (same transaction). - Secret masking: app/common/json_logger.py recursive mask wired into structlog (+ensure_ascii=False); event payloads redacted before persistence. - Service X-API-Key mandatory on ingest endpoints (defence-in-depth). - Port: host API 8000->8050 (collision with SalesHUB/MailHUB resolved), container still listens on 8000. - Config: no plaintext secret defaults; fail-loud in non-dev (no value leak). - Docs drift: README PG 5440, layered-auth note, 5173 removed from CORS; ingest/folder gated by ENABLE_FOLDER_INGEST (410 by default). - ADRs: layers mapping, shared-core extraction, UI locale (RU-first). Tests: 78 passing (ruff, compileall, pytest, tsc, vite build, compose config). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
54 lines
1.5 KiB
YAML
54 lines
1.5 KiB
YAML
# Federation overlay: run LegacyHUB behind the TeamHUB gateway on the shared
|
|
# `teamhub_net`. Compared with the standalone dev compose this overlay:
|
|
# - moves every backing service onto an internal-only network (no host ports);
|
|
# - reaches the api ONLY via `teamhub_net` (the gateway upstream), never
|
|
# directly from the host - so spoofing `X-TeamHub-*` is blocked by the network;
|
|
# - turns on trusted-header identity enforcement (AUTH_REQUIRE_IDENTITY).
|
|
#
|
|
# The shared network must exist first (created by TeamHUB-Platform infra):
|
|
# docker network create teamhub_net
|
|
#
|
|
# Usage (compose with prod hardening + this federation overlay):
|
|
# docker compose -f docker-compose.yml -f docker-compose.prod.yml \
|
|
# -f docker-compose.teamhub.yml --env-file .env.prod up -d --build
|
|
#
|
|
# See RUNBOOK.md "Network model & firewall" for the matching firewall rules.
|
|
|
|
networks:
|
|
teamhub_net:
|
|
external: true
|
|
name: teamhub_net
|
|
legacyhub_db:
|
|
internal: true
|
|
|
|
services:
|
|
postgres:
|
|
ports: !reset []
|
|
networks: [legacyhub_db]
|
|
|
|
minio:
|
|
ports: !reset []
|
|
networks: [legacyhub_db]
|
|
|
|
opensearch:
|
|
ports: !reset []
|
|
networks: [legacyhub_db]
|
|
|
|
qdrant:
|
|
ports: !reset []
|
|
networks: [legacyhub_db]
|
|
|
|
redis:
|
|
ports: !reset []
|
|
networks: [legacyhub_db]
|
|
|
|
api:
|
|
# Not published to the host: the gateway reaches the api over teamhub_net.
|
|
ports: !reset []
|
|
networks: [legacyhub_db, teamhub_net]
|
|
environment:
|
|
AUTH_REQUIRE_IDENTITY: "true"
|
|
|
|
worker:
|
|
networks: [legacyhub_db, teamhub_net]
|