towerops/config/config.exs
Graham McIntire 8682cdce55 fix: resolve session salts at runtime so prod release boots
The @session_options module attribute used Application.compile_env, which
baked compile-time placeholders into the endpoint while runtime.exs set
the real values from SESSION_SIGNING_SALT / SESSION_ENCRYPTION_SALT env
vars. Phoenix detected the mismatch and refused to start (failing migrate
Job in k8s).

- Remove hardcoded salts from config/config.exs (no compile-time binding)
- Add stable per-env salts in dev.exs / test.exs so local + CI don't need
  the env vars
- Split static cookie opts (@static_session_options) from runtime-resolved
  opts in endpoint.ex; expose session_options/0 as an MFA tuple in socket
  connect_info so LiveView decodes sessions with the same runtime salts
- New ToweropsWeb.Plugs.RuntimeSession wraps Plug.Session, fetches salts
  from app env on first request, and caches the initialized opts in
  :persistent_term (zero per-request overhead after warm-up)
2026-05-12 16:26:54 -05:00

176 lines
5.5 KiB
Elixir

# This file is responsible for configuring your application
# and its dependencies with the aid of the Config module.
#
# This configuration file is loaded before any dependency and
# is restricted to this project.
# General application configuration
import Config
# Configure time zone database to use tzdata for IANA timezone support
config :elixir, :time_zone_database, Tzdata.TimeZoneDatabase
config :error_tracker,
repo: Towerops.Repo,
otp_app: :towerops,
ignorer: Towerops.ErrorTrackerIgnorer
# Configure esbuild (the version is required)
config :esbuild,
version: "0.25.4",
towerops: [
args:
~w(js/app.ts --bundle --splitting --format=esm --target=es2022 --outdir=../priv/static/assets/js --external:/fonts/* --external:/images/* --alias:@=.),
cd: Path.expand("../assets", __DIR__),
env: %{"NODE_PATH" => [Path.expand("../deps", __DIR__), Mix.Project.build_path()]}
]
# Configure Elixir's Logger
config :logger, :default_formatter,
format: "$time $metadata[$level] $message\n",
metadata: [
:request_id,
:remote_ip,
:status,
:duration_ms,
:kind,
:reason,
:stacktrace,
:agent_token_id,
:device_id,
:error
]
# Filter out noisy errors from port scanners and bots
config :logger, :default_handler,
filters: [
# Suppress HTTP/0.9 and other invalid protocol errors from Bandit
# These are typically from port scanners and automated bots
bandit_invalid_http: {&Towerops.LogFilter.filter_bandit_errors/2, []},
# Suppress benign port_died and write_failed errors during K8s pod shutdown
shutdown_errors: {&Towerops.LoggerFilters.drop_shutdown_errors/2, []}
]
# Register protobuf MIME type for agent API
config :mime, :types, %{
"application/x-protobuf" => ["protobuf"]
}
# Filter sensitive parameters from logs
# These parameters will be replaced with "[FILTERED]" in Phoenix logs and error reports
config :phoenix, :filter_parameters, [
"password",
"snmp_community",
"community",
"secret",
"token",
"api_key",
# SNMPv3 credentials (for future use)
"auth_password",
"priv_password",
"auth_pass",
"priv_pass"
]
# Use Jason for JSON parsing in Phoenix
config :phoenix, :json_library, Jason
# Configure Req HTTP client to use our Finch pool with CA certs
config :req, default_options: [finch: Towerops.Finch]
# Configure tailwind (the version is required)
config :tailwind,
version: "4.1.12",
towerops: [
args: ~w(
--input=assets/css/app.css
--output=priv/static/assets/css/app.css
),
cd: Path.expand("..", __DIR__)
]
# Configure the mailer
#
# By default it uses the "Local" adapter which stores the emails
# locally. You can see the emails in your browser, at "/dev/mailbox".
#
# For production it's recommended to configure a different adapter
# at the `config/runtime.exs`.
config :towerops, Towerops.Mailer, adapter: Swoosh.Adapters.Local
# PromEx — Prometheus metrics exporter.
# Runs an isolated HTTP server on port 9568 so scrape traffic never traverses
# the public Traefik IngressRoute. The Pod template in k8s/deployment.yaml
# carries `prometheus.io/scrape` annotations so the external Prometheus
# (10.0.15.31) discovers it via the apiserver-proxy `kubernetes-pods` job.
config :towerops, Towerops.PromEx,
manual_metrics_start_delay: :no_delay,
drop_metrics_groups: [],
grafana: :disabled,
metrics_server: [
port: 9568,
path: "/metrics",
protocol: :http,
pool_size: 5,
cowboy_opts: [],
auth_strategy: :none
]
# Configure Ecto to use SQL structure dumps for faster test setup
# This allows CI to load the schema instantly instead of running 172+ migrations
config :towerops, Towerops.Repo,
dump_path: "priv/repo/structure.sql",
migration_timestamps: [type: :naive_datetime_usec],
types: Towerops.PostgrexTypes
# Configure the endpoint
config :towerops, ToweropsWeb.Endpoint,
url: [host: "localhost"],
adapter: Bandit.PhoenixAdapter,
render_errors: [
formats: [html: ToweropsWeb.ErrorHTML, json: ToweropsWeb.ErrorJSON],
layout: false
],
pubsub_server: Towerops.PubSub,
live_view: [signing_salt: "Uh1ABfdI"]
# Default coverage raster directory for dev/test. Production overrides this
# to "/data/coverage" (the shared NFS mount) in config/prod.exs so all
# replicas can serve the rasters and pod restarts don't lose them.
config :towerops, :coverage_storage_dir, {:towerops, "priv/static/coverage"}
config :towerops, :live_view_signing_salt, "Uh1ABfdI"
# SNMP MIB directories for production (in Docker image)
# MIB files are included in the release at /app/priv/mibs
# MibTranslator automatically expands these to include subdirectories
# Override in dev.exs for local development paths
config :towerops, :mib_dirs, [
"/app/priv/mibs",
"/usr/share/snmp/mibs"
]
config :towerops, :scopes,
user: [
default: true,
module: Towerops.Accounts.Scope,
assign_key: :current_scope,
access_path: [:user, :id],
schema_key: :user_id,
schema_type: :binary_id,
schema_table: :users,
test_data_fixture: Towerops.AccountsFixtures,
test_setup_helper: :register_and_log_in_user
]
# Agent Docker Image
# Override this in runtime.exs or environment-specific config
config :towerops,
agent_docker_image: "codeberg.org/towerops-agent/towerops-agent:latest"
# Import environment specific config. This must remain at the bottom
# of this file so it overrides the configuration defined above.
config :towerops,
ecto_repos: [Towerops.Repo],
generators: [timestamp_type: :utc_datetime, binary_id: true]
import_config "#{config_env()}.exs"