OPS-FIXES-1: AR-3 Data Protection Key-Persistenz + AR-4 AI-Env-Korrekte
AR-3 (P1): PersistKeysToFileSystem + persistentes Volume
Program.cs: AddDataProtection().PersistKeysToFileSystem(keyRingPath).SetApplicationName(GerbilManager)
Pfad konfigurierbar via DataProtection:KeyRingPath (env DataProtection__KeyRingPath);
Fallback = ContentRoot/.data-protection-keys (Aspire-Dev-ephemeral, ok).
compose.yaml: DataProtection__KeyRingPath: /data/keys + Volume-Mount keys:/data/keys.
Volumes: neues 'keys' Volume (Bind-Mount auf NAS-Dataset KEYS_PATH=/mnt/SSD/gerbil/keys).
.gitignore: .data-protection-keys/ ignoriert (Dev-only ephemeral keys).
Verhindert: Gmail-App-Passwort wird nach Image-Redeploy unlesbar (bisher stilles inbox-fail).
AR-4 (P1): compose.yaml + .env.example: AI__* statt ANTHROPIC_API_KEY
compose.yaml: ANTHROPIC_API_KEY entfernt (Code liest es nicht). Korrekte Vars:
AI__BaseUrl: ${AI__BaseUrl:-}
AI__ApiKey: ${AI__ApiKey:-}
AI__Model: ${AI__Model:-gemini-2.0-flash}
.env.example: AI__BaseUrl/ApiKey/Model + KEYS_PATH hinzugefuegt; ANTHROPIC_API_KEY entfernt.
Quelle: docs/ai-provider.md (war korrekt, compose war falsch).
Verhindert: alle 4 KI-Features (Verkaufstext, Inbox-Entwurf) blieben in prod stumm.
GATE: 139/139 C#-Tests, build gruen (using Microsoft.AspNetCore.DataProtection; framework-included).
This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
using System.Text.Json.Serialization;
|
||||
using GerbilManagerWebAPI.Endpoints;
|
||||
using Microsoft.AspNetCore.DataProtection;
|
||||
using Microsoft.EntityFrameworkCore;
|
||||
using Scalar.AspNetCore;
|
||||
|
||||
@@ -46,7 +47,17 @@ builder.Services.AddHttpClient<GerbilManagerWebAPI.Inbox.DraftReplyService>(
|
||||
http => http.Timeout = TimeSpan.FromSeconds(60));
|
||||
|
||||
// INBOX-0: Gmail inbox. App Password encrypted at rest via Data Protection.
|
||||
builder.Services.AddDataProtection();
|
||||
// AR-3: persist the key ring so encrypted passwords survive image redeployments.
|
||||
// In prod the path is mounted to a persistent volume (compose DataProtection__KeyRingPath).
|
||||
// In dev (Aspire) keys live in the content root — ephemeral, which is fine there.
|
||||
{
|
||||
var keyRingPath = builder.Configuration["DataProtection:KeyRingPath"]
|
||||
?? Path.Combine(builder.Environment.ContentRootPath, ".data-protection-keys");
|
||||
Directory.CreateDirectory(keyRingPath);
|
||||
builder.Services.AddDataProtection()
|
||||
.PersistKeysToFileSystem(new DirectoryInfo(keyRingPath))
|
||||
.SetApplicationName("GerbilManager");
|
||||
}
|
||||
builder.Services.AddScoped<GerbilManagerWebAPI.Inbox.MailSettingsService>();
|
||||
builder.Services.AddScoped<GerbilManagerWebAPI.Inbox.IGmailMailReader, GerbilManagerWebAPI.Inbox.GmailMailReader>();
|
||||
builder.Services.AddScoped<GerbilManagerWebAPI.Inbox.RequestSyncService>();
|
||||
|
||||
Reference in New Issue
Block a user