mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
## Summary - add one strict `BUZZ_S3_ADDRESSING_STYLE=path|virtual` setting shared by media and Git/CAS storage - preserve path-style defaults for bundled Compose/Helm MinIO while supporting Railway's virtual-hosted bucket contract - fail startup on invalid or non-Unicode values before dependency connection, and validate the Helm value with the same two choices - document operator mappings and why endpoint and bucket remain separate for routing and SigV4 signing ## Best-practice rationale AWS documents both URL forms and favors virtual-hosted addressing for S3, while compatibility endpoints such as the bundled MinIO deployment can require path style. `rust-s3` defaults to virtual/subdomain addressing and provides `with_path_style()` for the explicit compatibility case. Some providers buckets only support as virtual-hosted bucket styles. This PR therefore uses one explicit, provider-neutral switch rather than endpoint heuristics or fallback behavior, while retaining `path` as Buzz's backward-compatible default. Sources: - https://docs.aws.amazon.com/AmazonS3/latest/userguide/VirtualHosting.html - https://docs.rs/rust-s3/0.37.0/s3/bucket/struct.Bucket.html - https://docs.railway.com/storage-buckets#url-style - https://github.com/minio/minio/blob/master/docs/config/README.md#domain ## Validation - `cargo fmt --all` - `cargo check --workspace --all-targets` - targeted `buzz-media` and `buzz-relay` parsing/client-construction tests for defaults, strict errors, and both URL styles - Helm unittest: 45/45 passed - Compose config/render validation passed - local MinIO path-mode relay startup passed the Git A3 conformance probe and became ready - unreachable object storage failed startup and readiness never opened - push hooks completed the broader Rust and desktop suites successfully --------- Signed-off-by: npub122y0pqkertljmedu303rl0aqrj3w8pvu43t6jxm6875lzg6f2pwqegc3xc <5288f082d91aff2de5bc8be23fbfa01ca2e3859cac57a91b7a3fa9f12349505c@buzz.block.builderlab.xyz> Signed-off-by: Kalvin Chau <kalvin@block.xyz> Co-authored-by: npub122y0pqkertljmedu303rl0aqrj3w8pvu43t6jxm6875lzg6f2pwqegc3xc <5288f082d91aff2de5bc8be23fbfa01ca2e3859cac57a91b7a3fa9f12349505c@buzz.block.builderlab.xyz>
53 lines
1.9 KiB
Bash
53 lines
1.9 KiB
Bash
# Buzz production Docker Compose environment.
|
|
# Copy to .env and replace every CHANGE_ME value before running.
|
|
# The bootstrap script should generate this file for normal users.
|
|
|
|
# Image published by the public image pipeline. Use `:main` for pre-release testing. Pin `:sha-<7>` or a semver release tag for production.
|
|
BUZZ_IMAGE=ghcr.io/block/buzz:main
|
|
|
|
# Public host name. Used by compose.caddy.yml and URL-derived settings below.
|
|
BUZZ_DOMAIN=buzz.example.com
|
|
RELAY_URL=wss://buzz.example.com
|
|
BUZZ_MEDIA_BASE_URL=https://buzz.example.com/media
|
|
BUZZ_MEDIA_SERVER_DOMAIN=buzz.example.com
|
|
BUZZ_CORS_ORIGINS=https://buzz.example.com
|
|
|
|
# Production defaults. Closed relay mode requires RELAY_OWNER_PUBKEY and a stable relay key.
|
|
BUZZ_REQUIRE_AUTH_TOKEN=true
|
|
BUZZ_REQUIRE_RELAY_MEMBERSHIP=true
|
|
BUZZ_ALLOW_NIP_OA_AUTH=true
|
|
BUZZ_AUTO_MIGRATE=true
|
|
BUZZ_GIT_CONFORMANCE_PROBE=true
|
|
RUST_LOG=buzz_relay=info,buzz_db=info,buzz_auth=info,buzz_pubsub=info,tower_http=info
|
|
|
|
# Owner identity. Set to a 64-character hex Nostr pubkey.
|
|
RELAY_OWNER_PUBKEY=CHANGE_ME_OWNER_PUBKEY_HEX
|
|
|
|
# Stable secrets. Generate once, keep in .env, and back up securely.
|
|
BUZZ_RELAY_PRIVATE_KEY=CHANGE_ME_64_HEX_PRIVATE_KEY
|
|
BUZZ_GIT_HOOK_HMAC_SECRET=CHANGE_ME_RANDOM_64_HEX
|
|
POSTGRES_DB=buzz
|
|
POSTGRES_USER=buzz
|
|
POSTGRES_PASSWORD=CHANGE_ME_RANDOM_PASSWORD
|
|
REDIS_PASSWORD=CHANGE_ME_RANDOM_PASSWORD
|
|
BUZZ_S3_ACCESS_KEY=CHANGE_ME_RANDOM_ACCESS_KEY
|
|
BUZZ_S3_SECRET_KEY=CHANGE_ME_RANDOM_SECRET_KEY
|
|
BUZZ_S3_BUCKET=buzz-media
|
|
# Bundled MinIO uses path-style URLs; deploy/compose/compose.yml pins this.
|
|
BUZZ_S3_ADDRESSING_STYLE=path
|
|
|
|
# Optional host ports. Base compose publishes the relay directly on BUZZ_HTTP_PORT.
|
|
BUZZ_HTTP_PORT=3000
|
|
|
|
# Caddy host ports. Only used with compose.caddy.yml.
|
|
CADDY_HTTP_PORT=80
|
|
CADDY_HTTPS_PORT=443
|
|
|
|
# Dev override ports. Only used with compose.dev.yml.
|
|
POSTGRES_PORT=5432
|
|
REDIS_PORT=6379
|
|
MINIO_API_PORT=9000
|
|
MINIO_CONSOLE_PORT=9001
|
|
ADMINER_PORT=8082
|
|
PROMETHEUS_PORT=9090
|