refactor: rename environment variables and update related configurations
- Updated environment variable names from JERAPAH_FLOW_* to JFLOW_* for consistency and clarity. - Adjusted database path handling in knexfile.js to reflect the new variable naming. - Modified logging and retention days configurations to use the new variable names. - Ensured that the JWT secret and secrets key checks are aligned with the new naming convention. - Updated workflow test storage prefix to match the new project branding. This refactor enhances the clarity of environment variable usage and aligns with the project's rebranding efforts.
This commit is contained in:
@@ -61,12 +61,12 @@ Optional `script.meta.reads = "ctx"` documents expression hosts. `meta.input` /
|
|||||||
|
|
||||||
| Variable | Default | Notes |
|
| Variable | Default | Notes |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| `JERAPAH_FLOW_JWT_SECRET` | `scrunner-dev-secret` (dev only) | **Required in production**. `SCRUNNER_JWT_SECRET` is still accepted. |
|
| `JFLOW_JWT_SECRET` | `jflow-dev-secret` (dev only) | **Required in production**. |
|
||||||
| `JERAPAH_FLOW_SECRETS_KEY` | `scrunner-dev-secrets-key` (dev only) | Master key for named secrets. **Required in production**. Changing it makes existing secrets unreadable. 64 hex chars are used as a raw AES-256 key; any other string is derived with scrypt. `SCRUNNER_SECRETS_KEY` is still accepted. |
|
| `JFLOW_SECRETS_KEY` | `jflow-dev-secrets-key` (dev only) | Master key for named secrets. **Required in production**. Changing it makes existing secrets unreadable. 64 hex chars are used as a raw AES-256 key; any other string is derived with scrypt. |
|
||||||
| `JERAPAH_FLOW_DB_PATH` | `packages/server/data/jerapah-flow.db` (or existing `scrunner.db`) | SQLite file. `SCRUNNER_DB_PATH` is still accepted. |
|
| `JFLOW_DB_PATH` | `packages/server/data/jerapah-flow.db` | SQLite file. |
|
||||||
| `JERAPAH_FLOW_LOG_LEVEL` | `debug` | Pino level |
|
| `JFLOW_LOG_LEVEL` | `debug` | Pino level |
|
||||||
| `JERAPAH_FLOW_RETENTION_DAYS` | `30` | Run history prune |
|
| `JFLOW_RETENTION_DAYS` | `30` | Run history prune |
|
||||||
| `JERAPAH_FLOW_CORS_ORIGIN` | `http://localhost:5173` | Vite origin in dev |
|
| `JFLOW_CORS_ORIGIN` | `http://localhost:5173` | Vite origin in dev |
|
||||||
| `PORT` | `9000` | HTTP port |
|
| `PORT` | `9000` | HTTP port |
|
||||||
| `NODE_ENV` | — | Set `production` for secure cookies |
|
| `NODE_ENV` | — | Set `production` for secure cookies |
|
||||||
|
|
||||||
@@ -75,7 +75,7 @@ Optional `script.meta.reads = "ctx"` documents expression hosts. `meta.input` /
|
|||||||
```bash
|
```bash
|
||||||
pnpm install
|
pnpm install
|
||||||
pnpm build
|
pnpm build
|
||||||
JERAPAH_FLOW_JWT_SECRET=... JERAPAH_FLOW_SECRETS_KEY=... NODE_ENV=production pnpm start
|
JFLOW_JWT_SECRET=... JFLOW_SECRETS_KEY=... NODE_ENV=production pnpm start
|
||||||
```
|
```
|
||||||
|
|
||||||
The server serves `packages/web/dist` when that folder exists.
|
The server serves `packages/web/dist` when that folder exists.
|
||||||
|
|||||||
@@ -2,12 +2,8 @@ import fs from "fs";
|
|||||||
import path from "path";
|
import path from "path";
|
||||||
import { DATA_DIR, SERVER_ROOT } from "./paths.js";
|
import { DATA_DIR, SERVER_ROOT } from "./paths.js";
|
||||||
|
|
||||||
const defaultNew = path.join(DATA_DIR, "jerapah-flow.db");
|
|
||||||
const defaultLegacy = path.join(DATA_DIR, "scrunner.db");
|
|
||||||
const dbPath =
|
const dbPath =
|
||||||
process.env.JERAPAH_FLOW_DB_PATH ??
|
process.env.JFLOW_DB_PATH ?? path.join(DATA_DIR, "jerapah-flow.db");
|
||||||
process.env.SCRUNNER_DB_PATH ??
|
|
||||||
(fs.existsSync(defaultLegacy) && !fs.existsSync(defaultNew) ? defaultLegacy : defaultNew);
|
|
||||||
fs.mkdirSync(path.dirname(dbPath), { recursive: true });
|
fs.mkdirSync(path.dirname(dbPath), { recursive: true });
|
||||||
|
|
||||||
/** @type {import("knex").Knex.Config} */
|
/** @type {import("knex").Knex.Config} */
|
||||||
|
|||||||
@@ -113,7 +113,7 @@ const rollingFile = pino.transport({
|
|||||||
});
|
});
|
||||||
|
|
||||||
export const log = pino(
|
export const log = pino(
|
||||||
{ level: process.env.JERAPAH_FLOW_LOG_LEVEL ?? process.env.SCRUNNER_LOG_LEVEL ?? "debug" },
|
{ level: process.env.JFLOW_LOG_LEVEL ?? "debug" },
|
||||||
pino.multistream([
|
pino.multistream([
|
||||||
{ level: "debug", stream: redactStream(process.stdout) },
|
{ level: "debug", stream: redactStream(process.stdout) },
|
||||||
{ level: "debug", stream: redactStream(rollingFile) },
|
{ level: "debug", stream: redactStream(rollingFile) },
|
||||||
|
|||||||
@@ -323,7 +323,7 @@ export function createRegistry(server) {
|
|||||||
pruneTask.destroy();
|
pruneTask.destroy();
|
||||||
pruneTask = null;
|
pruneTask = null;
|
||||||
}
|
}
|
||||||
const days = Number(process.env.JERAPAH_FLOW_RETENTION_DAYS ?? process.env.SCRUNNER_RETENTION_DAYS ?? 30);
|
const days = Number(process.env.JFLOW_RETENTION_DAYS ?? 30);
|
||||||
pruneTask = cron.schedule(
|
pruneTask = cron.schedule(
|
||||||
"0 0 * * *",
|
"0 0 * * *",
|
||||||
async () => {
|
async () => {
|
||||||
|
|||||||
@@ -27,12 +27,11 @@ await migrate();
|
|||||||
enableLogPersistence();
|
enableLogPersistence();
|
||||||
|
|
||||||
const jwtSecret =
|
const jwtSecret =
|
||||||
process.env.JERAPAH_FLOW_JWT_SECRET ??
|
process.env.JFLOW_JWT_SECRET ??
|
||||||
process.env.SCRUNNER_JWT_SECRET ??
|
(process.env.NODE_ENV === "production" ? "" : "jflow-dev-secret");
|
||||||
(process.env.NODE_ENV === "production" ? "" : "scrunner-dev-secret");
|
|
||||||
|
|
||||||
if (!jwtSecret) {
|
if (!jwtSecret) {
|
||||||
log.error("JERAPAH_FLOW_JWT_SECRET is required in production");
|
log.error("JFLOW_JWT_SECRET is required in production");
|
||||||
process.exit(1);
|
process.exit(1);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -54,7 +53,7 @@ await server.register(jwt, {
|
|||||||
},
|
},
|
||||||
});
|
});
|
||||||
await server.register(cors, {
|
await server.register(cors, {
|
||||||
origin: process.env.JERAPAH_FLOW_CORS_ORIGIN ?? process.env.SCRUNNER_CORS_ORIGIN ?? "http://localhost:5173",
|
origin: process.env.JFLOW_CORS_ORIGIN ?? "http://localhost:5173",
|
||||||
credentials: true,
|
credentials: true,
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
import { createCipheriv, createDecipheriv, randomBytes, scryptSync } from "node:crypto";
|
import { createCipheriv, createDecipheriv, randomBytes, scryptSync } from "node:crypto";
|
||||||
|
|
||||||
const DEV_DEFAULT = "scrunner-dev-secrets-key";
|
const DEV_DEFAULT = "jflow-dev-secrets-key";
|
||||||
const SCRYPT_SALT = Buffer.from("scrunner-secrets-v1");
|
const SCRYPT_SALT = Buffer.from("jflow-secrets-v1");
|
||||||
const KEY_LEN = 32;
|
const KEY_LEN = 32;
|
||||||
const IV_LEN = 12;
|
const IV_LEN = 12;
|
||||||
const AUTH_TAG_LEN = 16;
|
const AUTH_TAG_LEN = 16;
|
||||||
@@ -11,11 +11,10 @@ const AUTH_TAG_LEN = 16;
|
|||||||
*/
|
*/
|
||||||
export function resolveSecretsKeyMaterial() {
|
export function resolveSecretsKeyMaterial() {
|
||||||
const raw =
|
const raw =
|
||||||
process.env.JERAPAH_FLOW_SECRETS_KEY ??
|
process.env.JFLOW_SECRETS_KEY ??
|
||||||
process.env.SCRUNNER_SECRETS_KEY ??
|
|
||||||
(process.env.NODE_ENV === "production" ? "" : DEV_DEFAULT);
|
(process.env.NODE_ENV === "production" ? "" : DEV_DEFAULT);
|
||||||
if (!raw) {
|
if (!raw) {
|
||||||
throw new Error("JERAPAH_FLOW_SECRETS_KEY is required in production");
|
throw new Error("JFLOW_SECRETS_KEY is required in production");
|
||||||
}
|
}
|
||||||
return raw;
|
return raw;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
const PREFIX = "scrunner.workflowTestData:";
|
const PREFIX = "jerapah-flow.workflowTestData:";
|
||||||
|
|
||||||
export function workflowTestStorageKey(owner, file) {
|
export function workflowTestStorageKey(owner, file) {
|
||||||
return `${PREFIX}${owner}/${file}`;
|
return `${PREFIX}${owner}/${file}`;
|
||||||
|
|||||||
Reference in New Issue
Block a user