feat: dev adoption - harden verify pipeline, pin compose project, align env examples - #5
Merged
Merged
Conversation
- wait loops (postgres/redis/backend/frontend) exit 1 with logs + down -v on timeout - health judgement reads the real response shape (checks.*.status == up) - generate compose env with DOCKER_HUB_USER guard and dev-abc123def -> develop tag - stop applying backend secret seds to frontend env (dead code)
- matrix environment: [dev] until prod tag scheme is decided - add env/** to push trigger paths - document the real CI tag scheme (develop / develop-<sha>) in example comments - note POSTGRES_PASSWORD must match backend.env DATABASE_URL
verify-images.sh became CRLF during editing and bash refused to run it (#!/usr/bin/env bash<CR> -> No such file or directory). Pin eol=lf for .sh (and .example files whose line-ending-anchored checks matter).
…ecrets - pull_request paths now match push paths (env/** added) - post-injection guards exit 1 when a secret is unset: empty KEY= (JWT), mid-line password loss (DATABASE_URL), empty POSTGRES_PASSWORD, or leftover placeholders
jq is not installed on local Windows hosts, so the DB/Redis check always degraded to the warning branch. Use jq when present, otherwise match checks.*.status == up with grep. Both paths verified against real and degraded health payloads.
local batch builds are not used by CI, verify pipeline, or compose; the mismatched booking-system-* naming made them unusable as-is.
- mount ./certs (host booking-deploy/certs) into backend container at /app/certs so SF_PRIVATE_KEY_PATH=certs/booking-integration.key resolves in-container - ignore certs/ : the real private key must never be committed (kept local only) - actual SF_*/INTEGRATION_TOKEN values live in env/dev/backend.env (gitignored)
…, HEAD refresh) - Known limitations 2/3 resolved: SF_SITE_URL baked via Dockerfile ARG + build-args (frontend #25/#26, develop=7e0f83a); certs mount + SF_*/INTEGRATION_TOKEN real values in backend.env (806512a) - HEAD/PR refreshed: backend 68d708e (PR #40), frontend 7e0f83a (PR #26), booking-deploy feat/dev-adoption 806512a (17 ahead of develop; PR #5 OPEN/REVIEW_REQUIRED/BLOCKED) - Step 3 G-6 marked unimplemented (compose example comments still stale); Step 7 dev leg proven by PR #5 CI; MAIL/NEXT_PUBLIC/G-15 rows de-staled - Line-number notes refreshed (cp/sed loop 33-61, generate_app_env 64-87, pull 103; 260 lines) and CRLF caveat added to 1.4
youdingtianzhaogeyinzuo
approved these changes
Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary(dev 適用手順 rev.6 の実装一式)
Step 1: verify-images.sh の修復
checks.*.status == "up")に修正し、jq 未 instal 環境では grep にフォールバックDOCKER_HUB_USERガード +developタグ置換を追加(ローカル実行可能化)Step 2: verify-images.yml
[dev]に限定(prod タグ体系確定まで)env/**を追加Step 3: compose
name: booking-devでプロジェクト名を固定(dev/prod 衝突防止)booking_uploads_dev:/app/uploadsボリューム(再作成でアップロード消失)Step 4: env examples
DB_*/LOG_*/HEALTHCHECK_TIMEOUT_MS)MAIL_*/INTEGRATION_TOKEN/RETENTION_*/SF_*追加、FRONTEND_URLSに 127.0.0.1NODE_ENV/未使用変数を削除しNEXT_PUBLIC_SF_SITE_URLを追加その他
.gitattributes:*.sh/*.exampleを LF 固定(CRLF によるシェバン破壊の再発防止)docs/handoff/dev-adoption-plan.html)を追加Test plan
develop)で seed 成功 → 実メール受信 → ログイン成功(booking-backend PR #40 とセット)