92ba527575
CI / changes (pull_request) Successful in 2s
CI / unit (pull_request) Successful in 11s
CI / integration (pull_request) Successful in 25s
CI / ui (pull_request) Successful in 1m17s
CI / conformance (pull_request) Successful in 10s
CI / gate (pull_request) Successful in 0s
CI / deploy (pull_request) Successful in 1m50s
Replace Robokassa with YooKassa as the RUB direct-rail provider. The wallet
model is untouched: one `direct` segment, the same spend wall, the same
per-channel merchant shops (D42) and `shop` on the order (D44).
The two providers are not shaped alike, and that drives the change:
- Opening a purchase is now an outbound API call (`POST /v3/payments`,
single-stage capture, redirect confirmation). The order id is both the
`Idempotence-Key` and `metadata.order_id`, so a retried create cannot mint a
second payment and a notification always resolves to its order.
- YooKassa does NOT sign notifications, so the body is never evidence: it only
names a payment, which is re-read with `GET /v3/payments/{id}`, and only that
answer is acted on. Two guards ride on it — the payment's metadata must name
the order, and its `test` flag must match the shop's, so a test-shop payment
can never credit real chips. The sender address is checked against YooKassa's
published ranges first, which stops a forger turning each fabricated
notification into an outbound call of ours.
- A notification lost for good would leave the money taken and the chips unowed,
silently. The existing pending-order reaper now asks the provider about each
order that reached its expiry age carrying a payment id, and credits the ones
really paid — one request per order over its whole life, not polling.
- `payment.canceled` records a `failed` event, so a declined payment is finally
surfaced to the customer as PAYMENTS.md §9 already specified.
- The admin refund moves the money through `POST /v3/refunds` before recording
anything; a failed call records nothing, so the ledger cannot claim a refund
that did not happen, and the recorded id is the provider's own.
- YooKassa has no cabinet-side generic receipt: «Чеки от ЮKassa» registers one
only if the request carries it, so every payment and refund now sends an
itemized `receipt` to the D36 confirmed email. The VAT rate code is a deploy
variable; the settlement subject and method are constants.
Robokassa is retired, not deleted: the direct rail falls back to it when no
YooKassa shop is configured and no deployment sets its credentials, so reviving
it is a credentials change rather than a code change. Its variables are removed
from compose, .env.example, write-prod-env.sh and the three workflows, and
recorded in backend/internal/robokassa/README.md together with the cabinet
configuration and the revival steps. Ledger rows keep `provider = 'robokassa'`;
that literal is load-bearing for the idempotency index.
No migration and no wire change: `orders.provider_payment_id` already existed,
and the client is rail-agnostic.
Decisions D47-D51 (revising D41) and stage E12 are baked into the docs.
103 lines
5.1 KiB
Bash
Executable File
103 lines
5.1 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Render the prod main-host runtime env.sh from the workflow job environment.
|
|
#
|
|
# Sourced identically by prod-deploy (deploy-main) and prod-rollback
|
|
# (rollback-main) so the two paths cannot drift: a rollback recreates the
|
|
# containers, so it must re-render the SAME runtime env a full deploy does —
|
|
# otherwise transactional email, VK login and Grafana alerts silently go dark
|
|
# after a rollback until the next full deploy.
|
|
#
|
|
# Usage: APP_VERSION=<tag> bash deploy/write-prod-env.sh <out-path>
|
|
#
|
|
# Every other value comes from the caller's environment (the job `env:` block,
|
|
# vars.* / secrets.*). Mirrors the compose interpolation contract in
|
|
# deploy/.env.example; keep in sync with deploy/docker-compose{,.prod}.yml.
|
|
out="${1:?usage: write-prod-env.sh <out-path>}"
|
|
|
|
# Derive the public URLs from the one canonical origin instead of storing each
|
|
# under its own variable. The path suffixes are structural (SPA routes / the
|
|
# Caddy /_gm sub-path), identical on every contour.
|
|
base="${PUBLIC_BASE_URL%/}"
|
|
TELEGRAM_MINIAPP_URL="$base/telegram/"
|
|
GRAFANA_ROOT_URL="$base/_gm/grafana/"
|
|
VITE_VK_ID_REDIRECT_URL="$base/app/"
|
|
|
|
# Grafana needs a BARE from-address (it rejects the "Name" <addr> form the backend
|
|
# go-mail accepts, and validates it even when SMTP is disabled — a bad value
|
|
# crash-loops Grafana). Split the display-format SERVICE From into address + name;
|
|
# the backend keeps the full form.
|
|
svc_from="${SMTP_RELAY_SERVICE_FROM:-}"
|
|
GRAFANA_SMTP_FROM_NAME=''
|
|
case "$svc_from" in
|
|
*"<"*">"*)
|
|
GRAFANA_SMTP_FROM_ADDRESS="$(printf '%s' "$svc_from" | sed -E 's/.*<([^>]+)>.*/\1/')"
|
|
GRAFANA_SMTP_FROM_NAME="$(printf '%s' "$svc_from" | sed -E 's/[[:space:]]*<[^>]*>.*$//; s/^"//; s/"$//')" ;;
|
|
*) GRAFANA_SMTP_FROM_ADDRESS="$svc_from" ;;
|
|
esac
|
|
|
|
cat > "$out" <<EOF
|
|
export REGISTRY='$REGISTRY'
|
|
export SCRABBLE_CONFIG_DIR='/opt/scrabble'
|
|
export POSTGRES_DB='${POSTGRES_DB:-scrabble}'
|
|
export POSTGRES_USER='${POSTGRES_USER:-scrabble}'
|
|
export POSTGRES_PASSWORD='$POSTGRES_PASSWORD'
|
|
export GM_BASICAUTH_USER='${GM_BASICAUTH_USER:-gm}'
|
|
export GM_BASICAUTH_HASH='$GM_BASICAUTH_HASH'
|
|
export GRAFANA_ADMIN_PASSWORD='$GRAFANA_ADMIN_PASSWORD'
|
|
export GRAFANA_ROOT_URL='$GRAFANA_ROOT_URL'
|
|
export CADDY_SITE_ADDRESS='$CADDY_SITE_ADDRESS'
|
|
export LOG_LEVEL='${LOG_LEVEL:-info}'
|
|
export DICT_VERSION='$DICT_VERSION'
|
|
export APP_VERSION='$APP_VERSION'
|
|
export GATEWAY_MIN_CLIENT_VERSION='$GATEWAY_MIN_CLIENT_VERSION'
|
|
export GATEWAY_RECOMMENDED_CLIENT_VERSION='$GATEWAY_RECOMMENDED_CLIENT_VERSION'
|
|
export TELEGRAM_BOT_TOKEN='$TELEGRAM_BOT_TOKEN'
|
|
export TELEGRAM_MINIAPP_URL='$TELEGRAM_MINIAPP_URL'
|
|
export GATEWAY_VK_APP_SECRET='$GATEWAY_VK_APP_SECRET'
|
|
export YOOKASSA_WEB_SHOP_ID='$YOOKASSA_WEB_SHOP_ID'
|
|
export YOOKASSA_WEB_SECRET_KEY='$YOOKASSA_WEB_SECRET_KEY'
|
|
export YOOKASSA_WEB_TEST='$YOOKASSA_WEB_TEST'
|
|
export YOOKASSA_ANDROID_SHOP_ID='$YOOKASSA_ANDROID_SHOP_ID'
|
|
export YOOKASSA_ANDROID_SECRET_KEY='$YOOKASSA_ANDROID_SECRET_KEY'
|
|
export YOOKASSA_ANDROID_TEST='$YOOKASSA_ANDROID_TEST'
|
|
export YOOKASSA_VAT_CODE='${YOOKASSA_VAT_CODE:-1}'
|
|
export VITE_VK_APP_ID='$VITE_VK_APP_ID'
|
|
export VITE_VK_ID_REDIRECT_URL='$VITE_VK_ID_REDIRECT_URL'
|
|
export GATEWAY_VK_ID_CLIENT_SECRET='$GATEWAY_VK_ID_CLIENT_SECRET'
|
|
export EXPORT_SIGN_KEY='$EXPORT_SIGN_KEY'
|
|
export SMTP_RELAY_HOST='$SMTP_RELAY_HOST'
|
|
export SMTP_RELAY_PORT='$SMTP_RELAY_PORT'
|
|
export SMTP_RELAY_TLS='$SMTP_RELAY_TLS'
|
|
export SMTP_RELAY_USER='$SMTP_RELAY_USER'
|
|
export SMTP_RELAY_PASS='$SMTP_RELAY_PASS'
|
|
export SMTP_RELAY_FROM='$SMTP_RELAY_FROM'
|
|
export SMTP_RELAY_ADMIN_FROM='$SMTP_RELAY_ADMIN_FROM'
|
|
export ADMIN_EMAIL='$ADMIN_EMAIL'
|
|
export SMTP_RELAY_SERVICE_FROM='$SMTP_RELAY_SERVICE_FROM'
|
|
export GRAFANA_SMTP_FROM_ADDRESS='$GRAFANA_SMTP_FROM_ADDRESS'
|
|
export GRAFANA_SMTP_FROM_NAME='$GRAFANA_SMTP_FROM_NAME'
|
|
export SERVICE_EMAIL='$SERVICE_EMAIL'
|
|
export GRAFANA_SMTP_PORT='$GRAFANA_SMTP_PORT'
|
|
export GF_SMTP_ENABLED='$GF_SMTP_ENABLED'
|
|
export PUBLIC_BASE_URL='$PUBLIC_BASE_URL'
|
|
export GATEWAY_HONEYTOKEN='$GATEWAY_HONEYTOKEN'
|
|
export GATEWAY_ABUSE_BAN_ENABLED='true'
|
|
# Community IP blocklist (Spamhaus DROP): opt-in — the operator enables it and sets the feed URL +
|
|
# allowlist via PROD_GATEWAY_BLOCKLIST_* vars once the feed is verified. Unset ⇒ off (safe).
|
|
export GATEWAY_BLOCKLIST_ENABLED='${GATEWAY_BLOCKLIST_ENABLED:-false}'
|
|
export GATEWAY_BLOCKLIST_URL='$GATEWAY_BLOCKLIST_URL'
|
|
export GATEWAY_BLOCKLIST_ALLOW='$GATEWAY_BLOCKLIST_ALLOW'
|
|
# Continuous WAL archiving (pgBackRest -> S3) for point-in-time recovery. The artifact
|
|
# ships disarmed: PGBACKREST_ARCHIVE_MODE defaults off, so archiving stays inert until the
|
|
# operator sets the S3 repository values + secrets, creates the stanza and flips the switch
|
|
# on (deploy/README.md). Empty repository values are harmless while the mode is off.
|
|
export PGBACKREST_ARCHIVE_MODE='${PGBACKREST_ARCHIVE_MODE:-off}'
|
|
export PGBACKREST_S3_ENDPOINT='$PGBACKREST_S3_ENDPOINT'
|
|
export PGBACKREST_S3_PORT='${PGBACKREST_S3_PORT:-443}'
|
|
export PGBACKREST_S3_BUCKET='$PGBACKREST_S3_BUCKET'
|
|
export PGBACKREST_S3_REGION='$PGBACKREST_S3_REGION'
|
|
export PGBACKREST_S3_KEY='$PGBACKREST_S3_KEY'
|
|
export PGBACKREST_S3_KEY_SECRET='$PGBACKREST_S3_KEY_SECRET'
|
|
export PGBACKREST_CIPHER_PASS='$PGBACKREST_CIPHER_PASS'
|
|
EOF
|