10 Commits

Author SHA1 Message Date
Chever John
541dd5e4c8 fix: write envsubst output to /tmp to avoid read-only ConfigMap mount
The entrypoint.sh was writing the rendered config back to the same
directory as the source, which fails when the config is mounted from
a Kubernetes ConfigMap (read-only filesystem). Write to /tmp instead.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-18 09:29:18 +08:00
Chever John
a5b1b406ea security: remove hardcoded credentials and add envsubst for go-zero configs
- Clear default passwords in all service configs and local dev YAMLs
- Add entrypoint.sh with envsubst to resolve ${ENV} vars in go-zero YAML
- Update Dockerfiles to install gettext and use entrypoint
- Update docker-compose to pass secrets via environment and require via ${VAR:?...}
- Add .gitignore rules for .env files, add .env.example template

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-17 23:16:28 +08:00
Chever John
7a8df1f0d4 fix: use Aliyun Alpine mirror in Dockerfiles
Alpine CDN unreachable from DinD containers. Switch to
mirrors.aliyun.com for both builder and runtime stages.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-17 10:25:02 +08:00
Chever John
4547ce7fed fix: use Harbor base images and Chinese Go proxy for CI builds
Docker Hub and proxy.golang.org unreachable from k3s cluster (GFW).
Switch Dockerfiles to Harbor base images and goproxy.cn.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-17 10:17:39 +08:00
Chever John
a25acdc5e4 chore: sync codebase with upstream
Pull latest changes from upstream/main (GitHub) including:
- Purchase RPC service (proto, server, logic, models)
- Gateway route updates for purchase endpoints
- SQL migration and config updates

Excludes deploy/bin/ pre-compiled arm64 binaries (builds use
multi-stage Dockerfiles targeting amd64).
2026-06-15 09:20:56 +08:00
Chever John
379fb28d92 chore: sync codebase with upstream
Align origin/main with upstream/main (GitHub). The two branches
diverged due to pre-rebase vs post-rebase merge commits for the
k8s-amd64-dockerfiles feature.

Includes: multi-stage Go compilation Dockerfiles, pan-bolt
inventory features, CRM relations, Excel import tooling,
proto/gRPC updates, migration scripts, and tools/ directory.

Excludes deploy/bin/ pre-compiled binaries (arm64, not needed
for amd64 K3s cluster; builds use multi-stage Dockerfiles now).
2026-06-14 15:24:02 +08:00
Chenwei Jiang
c5ab2279c0 Merge pull request 'build(deploy): replace pre-compiled arm64 binaries with multi-stage Go compilation for amd64' (#2) from feat/k8s-amd64-dockerfiles into main
Reviewed-on: https://forgejo.cheverjohn.me/Business/muyuqingfeng-apiserver/pulls/2
2026-06-14 15:12:16 +08:00
Chever John
4144628cb6 build(deploy): replace pre-compiled arm64 binaries with multi-stage Go compilation for amd64
WHY: existing Dockerfiles copied pre-compiled arm64 binaries which cannot
run on the amd64 K3s cluster (exec format error). Also fixed port conflicts
when running muyu alongside iloom in docker-compose.

HOW:
- rewrite 3 Dockerfiles (system/inventory/gateway) to multi-stage builds
  using golang:1.24-alpine with CGO_ENABLED=0 GOARCH=amd64
- parameterize host ports in docker-compose to avoid conflicts (3306->13306,
  6379->16379, 8080->18080)
- fix inv_product unique key from product_name-only to composite
  (product_name, spec, color) to allow same-name products with different specs
- add X-Token to Authorization header middleware in gateway for
  iloom frontend compatibility

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-06-14 12:38:46 +08:00
Chever John
1f4ccfb54e feat: multi-tenant CRM with PostgreSQL graph, tenant isolation, and Casbin RBAC
- JWT claims extended with tenantId; login enforces strict tenant verification
- AuthorityMiddleware: tenant scope check + Casbin path permission + anti-spoofing
- CRM relation API (upstream/downstream one-hop, create/update/history, full graph)
- CrmRepo backed by PostgreSQL with $N placeholders
- gRPC tenant propagation via UnaryClientInterceptor (x-tenant-id metadata)
- All legacy tables (12) gain tenant_id column with indexes
- All model queries inject WHERE tenant_id filter
- Casbin gorm-adapter downgraded to v3.28.0 for v2 compatibility
- GraphSyncWorker (Kafka -> Neo4j) with idempotent MERGE
- Full graph API restricted to admin role only
- Database migrations for MySQL (CRM tables + tenant columns) and PostgreSQL (CRM init)
- Docker Compose: added postgres service to main stack, graph stack with Kafka/Debezium/Neo4j

Made-with: Cursor
2026-03-30 02:53:55 +00:00
Chever John
71a2d912e2 feat: initial commit for muyu-apiserver
Go service with gateway, RPC, model layers and k8s deploy configs.

Made-with: Cursor
2026-02-28 15:29:16 +08:00