From bbb6ce6a6cbc02e96bec8efd41ad8d1fc0f314a4 Mon Sep 17 00:00:00 2001 From: defiQUG Date: Sat, 18 Apr 2026 12:05:55 -0700 Subject: [PATCH] docs: archive entra materials and simplify deployment docs --- PROJECT_STRUCTURE.md | 31 +- README.md | 56 +- archive/quarantined-legacy-stack/README.md | 11 + .../DOCUMENTATION_REORGANIZATION_PLAN.md | 0 .../docs}/REORGANIZATION_COMPLETE.md | 0 .../docs}/REORGANIZATION_QUICK_REFERENCE.md | 0 .../docs}/STRUCTURE_IMPROVEMENTS.md | 0 .../docs}/api/identity-service.md | 0 .../CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md | 0 .../docs/architecture/README.md | 283 ++++ .../architecture/SOVEREIGNTY_COMPLIANCE.md | 0 .../SOVEREIGNTY_LANDING_ZONE_SUMMARY.md | 0 .../WELL_ARCHITECTED_FRAMEWORK.md | 0 .../docs/archive/README.md | 95 ++ .../archive/reports/ALL_REMAINING_TASKS.md | 0 .../REMAINING_TASKS_CREDENTIAL_AUTOMATION.md | 0 .../docs}/archive/reports/REMAINING_TODOS.md | 0 .../reports/TASK_COMPLETION_SUMMARY.md | 0 .../docs}/deployment/ALL_TODOS_COMPLETE.md | 0 .../docs}/deployment/AUTOMATION_COMPLETE.md | 0 .../docs}/deployment/AZURE_CDN_COMPLETE.md | 0 .../deployment/AZURE_CDN_FINAL_STATUS.md | 0 .../docs}/deployment/AZURE_CDN_QUICK_START.md | 0 .../docs}/deployment/AZURE_CDN_SETUP.md | 0 .../deployment/AZURE_CDN_SETUP_COMPLETE.md | 0 .../docs}/deployment/AZURE_CDN_STATUS.md | 0 .../docs}/deployment/COMPLETE_TODO_STATUS.md | 0 .../deployment/DEPLOYMENT_STEPS_SUMMARY.md | 0 .../deployment/ENTRA_COMPLETE_SUMMARY.md | 0 .../ENTRA_VERIFIEDID_DEPLOYMENT_CHECKLIST.md | 0 .../deployment/ENTRA_VERIFIEDID_NEXT_STEPS.md | 0 .../docs/deployment/README.md | 100 ++ .../docs}/deployment/azure/DOTENV_SETUP.md | 0 .../deployment/azure/ENVIRONMENT_SETUP.md | 0 .../deployment/azure/ENV_FILE_ANALYSIS.md | 0 .../SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md | 0 .../deployment/azure/cdn-configuration.md | 0 .../docs}/deployment/azure/cdn-setup.md | 0 .../deployment/azure/entra-verifiedid.md | 0 .../docs/deployment/overview.md | 1478 ++++++++++++++++ .../docs}/governance/NAMING_CONVENTION.md | 0 .../NAMING_IMPLEMENTATION_SUMMARY.md | 0 .../docs}/governance/TECHNICAL_INTEGRATION.md | 0 .../docs}/integrations/CONNECTOR_STATUS.md | 0 .../docs}/integrations/INTEGRATION_SUMMARY.md | 0 .../integrations/entra-verifiedid/README.md | 0 .../entra-verifiedid/best-practices.md | 0 .../entra-verifiedid/credential-images.md | 0 .../json-content-readiness.md | 0 .../operations/ENTRA_VERIFIEDID_RUNBOOK.md | 0 .../AZURE_ENTRA_PREREQUISITES_CHECKLIST.md | 0 .../docs}/reports/AZURE_SETUP_COMPLETION.md | 0 .../reports/COMPREHENSIVE_PROJECT_REVIEW.md | 0 .../docs}/reports/COMPREHENSIVE_TASK_LIST.md | 0 .../reports/DEPLOYMENT_READINESS_REVIEW.md | 0 .../reports/GOVERNANCE_INTEGRATION_SUMMARY.md | 0 .../docs}/reports/IMPLEMENTATION_SUMMARY.md | 0 .../docs}/reports/NEXT_STEPS.md | 0 .../docs}/reports/PROJECT_STATUS.md | 0 .../docs}/reports/QUICK_START_NEXT_STEPS.md | 0 .../docs}/reports/REMAINING_STEPS_COMPLETE.md | 0 .../docs}/reports/SESSION_SUMMARY.md | 0 .../docs}/reports/current-status.md | 0 .../training/ENTRA_VERIFIEDID_TRAINING.md | 0 .../infra}/k8s/base/configmap-azure.yaml | 0 .../infra}/k8s/base/external-secrets.yaml | 0 .../identity-service-deployment-entra.yaml | 0 .../k8s/identity-service-entra-secrets.yaml | 0 .../monitoring/grafana-entra-dashboard.json | 0 .../monitoring/prometheus-entra-config.yml | 0 .../infra}/scripts/azure-cdn-setup.sh | 0 .../infra}/scripts/azure-check-cdn-quotas.sh | 0 .../infra}/scripts/azure-check-quotas.sh | 0 .../infra}/scripts/azure-complete-setup.sh | 0 .../infra}/scripts/azure-deploy.sh | 0 .../infra}/scripts/azure-fix-env-mapping.sh | 0 .../infra}/scripts/azure-integrate-cdn-env.sh | 0 .../infra}/scripts/azure-load-env.sh | 0 .../scripts/azure-register-providers.sh | 0 .../infra}/scripts/azure-setup.sh | 0 .../scripts/azure-sync-env-to-terraform.sh | 0 .../scripts/azure-update-k8s-secrets.sh | 0 .../scripts/azure-validate-current-env.sh | 0 .../infra}/scripts/azure-validate-env.sh | 0 .../deploy-sovereignty-landing-zone.sh | 0 .../infra/terraform}/terraform/.gitignore | 0 .../terraform/AZURE_RESOURCE_PROVIDERS.md | 0 .../terraform}/terraform/EXECUTION_GUIDE.md | 0 .../terraform}/terraform/NAMING_VALIDATION.md | 0 .../infra/terraform}/terraform/README.md | 0 .../infra/terraform}/terraform/aks.tf | 0 .../terraform}/terraform/azure-provider.tf | 0 .../infra/terraform}/terraform/cdn.tf | 0 .../infra/terraform}/terraform/database.tf | 0 .../infra/terraform}/terraform/key-vault.tf | 0 .../infra/terraform}/terraform/locals.tf | 0 .../infra/terraform}/terraform/main.tf | 0 .../terraform/management-groups/main.tf | 0 .../terraform/management-groups/variables.tf | 0 .../terraform/management-groups/versions.tf | 0 .../modules/regional-landing-zone/README.md | 0 .../modules/regional-landing-zone/main.tf | 0 .../modules/regional-landing-zone/outputs.tf | 0 .../regional-landing-zone/variables.tf | 0 .../modules/regional-landing-zone/versions.tf | 0 .../modules/well-architected/main.tf | 0 .../modules/well-architected/variables.tf | 0 .../terraform/multi-region/README.md | 0 .../terraform}/terraform/multi-region/main.tf | 0 .../terraform/multi-region/outputs.tf | 0 .../terraform/multi-region/variables.tf | 0 .../terraform/multi-region/versions.tf | 0 .../terraform}/terraform/outputs-azure.tf | 0 .../infra/terraform}/terraform/outputs.tf | 0 .../terraform}/terraform/policies/main.tf | 0 .../terraform/policies/variables.tf | 0 .../terraform}/terraform/policies/versions.tf | 0 .../terraform}/terraform/resource-groups.tf | 0 .../infra/terraform}/terraform/storage.tf | 0 .../terraform/terraform.tfvars.example | 0 .../infra/terraform}/terraform/variables.tf | 0 .../infra/terraform}/terraform/versions.tf | 0 .../terraform/well-architected/main.tf | 0 .../terraform/well-architected/variables.tf | 0 .../manifests}/entra/README.md | 0 .../manifests}/entra/SEAL_MAPPING.md | 0 .../manifests}/entra/collect-manifest-ids.sh | 0 .../entra/default-manifest-template.json | 0 .../entra/diplomatic-manifest-template.json | 0 .../entra/financial-manifest-template.json | 0 .../entra/judicial-manifest-template.json | 0 .../entra/legal-office-manifest-template.json | 0 .../packages/auth/src/azure-logic-apps.d.ts | 47 + .../auth/src/azure-logic-apps.d.ts.map | 1 + .../packages/auth/src/azure-logic-apps.js | 107 ++ .../packages/auth/src/azure-logic-apps.js.map | 1 + .../packages}/auth/src/azure-logic-apps.ts | 0 .../packages/auth/src/eidas-entra-bridge.d.ts | 69 + .../auth/src/eidas-entra-bridge.d.ts.map | 1 + .../packages/auth/src/eidas-entra-bridge.js | 174 ++ .../auth/src/eidas-entra-bridge.js.map | 1 + .../packages}/auth/src/eidas-entra-bridge.ts | 0 .../auth/src/entra-credential-images.d.ts | 58 + .../auth/src/entra-credential-images.d.ts.map | 1 + .../auth/src/entra-credential-images.js | 152 ++ .../auth/src/entra-credential-images.js.map | 1 + .../auth/src/entra-credential-images.ts | 0 .../auth/src/entra-verifiedid-enhanced.d.ts | 58 + .../src/entra-verifiedid-enhanced.d.ts.map | 1 + .../auth/src/entra-verifiedid-enhanced.js | 128 ++ .../auth/src/entra-verifiedid-enhanced.js.map | 1 + .../auth/src/entra-verifiedid-enhanced.ts | 0 .../packages/auth/src/entra-verifiedid.d.ts | 95 ++ .../auth/src/entra-verifiedid.d.ts.map | 1 + .../src/entra-verifiedid.integration.test.ts | 0 .../packages/auth/src/entra-verifiedid.js | 289 ++++ .../packages/auth/src/entra-verifiedid.js.map | 1 + .../auth/src/entra-verifiedid.test.ts | 0 .../packages}/auth/src/entra-verifiedid.ts | 0 .../packages}/monitoring/src/entra-metrics.ts | 0 .../packages/shared/src/rate-limit-entra.d.ts | 32 + .../shared/src/rate-limit-entra.d.ts.map | 1 + .../packages/shared/src/rate-limit-entra.js | 112 ++ .../shared/src/rate-limit-entra.js.map | 1 + .../packages}/shared/src/rate-limit-entra.ts | 0 .../root/DEPLOYMENT_COMPLETE.md | 0 .../root/README_ENTRA_SETUP.md | 0 .../root/azure-cdn-config.env | 0 .../root/azure-cdn-quota-report.txt | 0 .../root/azure-cdn-quotas.txt | 0 .../scripts}/ci/validate-entra-deployment.sh | 0 .../scripts}/deploy/complete-entra-setup.sh | 0 .../deploy/configure-api-permissions.sh | 0 .../scripts}/deploy/configure-env-dev.sh | 0 .../deploy/configure-multi-manifest.sh | 0 .../scripts}/deploy/configure-webhook-url.sh | 0 .../deploy/create-credential-manifests.sh | 0 .../scripts}/deploy/create-entra-app.sh | 0 .../scripts}/deploy/deploy-production.sh | 0 .../scripts}/deploy/deploy-staging.sh | 0 .../scripts}/deploy/enable-verified-id.sh | 0 .../deploy/setup-azure-cdn-complete.sh | 0 .../scripts}/deploy/setup-entra-automated.sh | 0 .../scripts}/deploy/store-entra-secrets.sh | 0 .../scripts}/deploy/upload-seals-to-azure.sh | 0 .../scripts}/deploy/verify-complete-setup.sh | 0 .../scripts}/test/generate-test-data.sh | 0 .../test/run-integration-tests-with-setup.sh | 0 .../scripts}/test/test-all-entra-features.sh | 0 .../scripts}/test/test-entra-integration.sh | 0 .../validation/validate-entra-config.sh | 0 .../identity/src/entra-integration.ts | 0 .../services}/identity/src/entra-webhooks.ts | 0 .../identity/src/logic-apps-workflows.ts | 0 assets/credential-images/README.md | 14 +- docs/DEVELOPMENT_SETUP.md | 10 +- docs/GETTING_STARTED.md | 8 +- docs/NAVIGATION.md | 230 +-- docs/README.md | 139 +- docs/architecture/README.md | 285 +--- docs/archive/README.md | 96 +- docs/configuration/ENVIRONMENT_VARIABLES.md | 52 - docs/deployment/DEPLOYMENT_QUICK_REFERENCE.md | 258 +-- docs/deployment/README.md | 100 +- docs/deployment/automation/seal-deployment.md | 5 +- docs/deployment/overview.md | 1481 +---------------- docs/design/ORDER_SEALS_DESIGN_GUIDE.md | 3 +- docs/governance/README.md | 4 +- docs/governance/frameworks/privacy.md | 3 +- docs/governance/frameworks/threat-model.md | 5 +- docs/governance/procedures/security-audit.md | 3 +- docs/integrations/README.md | 55 +- docs/operations/DISASTER_RECOVERY.md | 3 +- docs/product/features/web-ui-coverage.md | 3 - infra/k8s/base/identity/deployment.yaml | 16 - .../monitoring/alert-rules-configmap.yaml | 13 - infra/monitoring/alert-rules.yml | 21 - infra/scripts/README.md | 133 +- packages/README.md | 3 +- packages/auth/package.json | 1 - packages/auth/src/file-utils.ts | 3 +- packages/auth/src/index.ts | 6 - packages/crypto/src/kms.ts | 3 +- packages/monitoring/src/index.ts | 2 - packages/shared/src/env.ts | 29 +- packages/shared/src/index.ts | 2 - scripts/README.md | 12 +- scripts/backup/database-backup.sh | 5 +- scripts/deploy/README.md | 262 +-- scripts/deploy/complete-seal-deployment.sh | 7 +- scripts/deploy/config.sh | 138 +- scripts/deploy/deploy.sh | 14 +- scripts/deploy/phase1-prerequisites.sh | 39 +- scripts/deploy/phase10-backend-services.sh | 98 +- scripts/deploy/phase11-frontend-apps.sh | 93 +- scripts/deploy/phase13-monitoring.sh | 73 +- scripts/deploy/phase14-testing.sh | 39 +- scripts/deploy/phase15-production.sh | 41 +- scripts/deploy/phase2-azure-infrastructure.sh | 103 -- .../deploy/phase2-sankofa-phoenix-target.sh | 44 + scripts/deploy/phase3-entra-id.sh | 48 - scripts/deploy/phase3-identity-secrets.sh | 48 + scripts/deploy/phase4-database-storage.sh | 88 +- scripts/deploy/phase5-container-registry.sh | 66 +- scripts/deploy/phase6-build-package.sh | 41 +- scripts/deploy/phase7-database-migrations.sh | 18 +- scripts/deploy/phase8-secrets.sh | 91 +- .../deploy/phase9-infrastructure-services.sh | 71 +- .../deploy/prepare-all-credential-seals.sh | 9 +- .../sync-portal-public-to-sankofa-phoenix.sh | 183 ++ scripts/tools/convert-svg-to-png.sh | 5 +- scripts/tools/prepare-credential-images.sh | 11 +- services/README.md | 3 +- services/identity/src/index.ts | 9 - .../src/letters-of-credence-routes.ts | 6 +- services/identity/src/letters-of-credence.ts | 28 +- 256 files changed, 4188 insertions(+), 3881 deletions(-) create mode 100644 archive/quarantined-legacy-stack/README.md rename {docs => archive/quarantined-legacy-stack/docs}/DOCUMENTATION_REORGANIZATION_PLAN.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/REORGANIZATION_COMPLETE.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/REORGANIZATION_QUICK_REFERENCE.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/STRUCTURE_IMPROVEMENTS.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/api/identity-service.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/architecture/CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md (100%) create mode 100644 archive/quarantined-legacy-stack/docs/architecture/README.md rename {docs => archive/quarantined-legacy-stack/docs}/architecture/SOVEREIGNTY_COMPLIANCE.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/architecture/SOVEREIGNTY_LANDING_ZONE_SUMMARY.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/architecture/WELL_ARCHITECTED_FRAMEWORK.md (100%) create mode 100644 archive/quarantined-legacy-stack/docs/archive/README.md rename {docs => archive/quarantined-legacy-stack/docs}/archive/reports/ALL_REMAINING_TASKS.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/archive/reports/REMAINING_TASKS_CREDENTIAL_AUTOMATION.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/archive/reports/REMAINING_TODOS.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/archive/reports/TASK_COMPLETION_SUMMARY.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/ALL_TODOS_COMPLETE.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/AUTOMATION_COMPLETE.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/AZURE_CDN_COMPLETE.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/AZURE_CDN_FINAL_STATUS.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/AZURE_CDN_QUICK_START.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/AZURE_CDN_SETUP.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/AZURE_CDN_SETUP_COMPLETE.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/AZURE_CDN_STATUS.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/COMPLETE_TODO_STATUS.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/DEPLOYMENT_STEPS_SUMMARY.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/ENTRA_COMPLETE_SUMMARY.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/ENTRA_VERIFIEDID_DEPLOYMENT_CHECKLIST.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/ENTRA_VERIFIEDID_NEXT_STEPS.md (100%) create mode 100644 archive/quarantined-legacy-stack/docs/deployment/README.md rename {docs => archive/quarantined-legacy-stack/docs}/deployment/azure/DOTENV_SETUP.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/azure/ENVIRONMENT_SETUP.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/azure/ENV_FILE_ANALYSIS.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/azure/cdn-configuration.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/azure/cdn-setup.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/deployment/azure/entra-verifiedid.md (100%) create mode 100644 archive/quarantined-legacy-stack/docs/deployment/overview.md rename {docs => archive/quarantined-legacy-stack/docs}/governance/NAMING_CONVENTION.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/governance/NAMING_IMPLEMENTATION_SUMMARY.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/governance/TECHNICAL_INTEGRATION.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/integrations/CONNECTOR_STATUS.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/integrations/INTEGRATION_SUMMARY.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/integrations/entra-verifiedid/README.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/integrations/entra-verifiedid/best-practices.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/integrations/entra-verifiedid/credential-images.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/integrations/entra-verifiedid/json-content-readiness.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/operations/ENTRA_VERIFIEDID_RUNBOOK.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/reports/AZURE_ENTRA_PREREQUISITES_CHECKLIST.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/reports/AZURE_SETUP_COMPLETION.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/reports/COMPREHENSIVE_PROJECT_REVIEW.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/reports/COMPREHENSIVE_TASK_LIST.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/reports/DEPLOYMENT_READINESS_REVIEW.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/reports/GOVERNANCE_INTEGRATION_SUMMARY.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/reports/IMPLEMENTATION_SUMMARY.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/reports/NEXT_STEPS.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/reports/PROJECT_STATUS.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/reports/QUICK_START_NEXT_STEPS.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/reports/REMAINING_STEPS_COMPLETE.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/reports/SESSION_SUMMARY.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/reports/current-status.md (100%) rename {docs => archive/quarantined-legacy-stack/docs}/training/ENTRA_VERIFIEDID_TRAINING.md (100%) rename {infra => archive/quarantined-legacy-stack/infra}/k8s/base/configmap-azure.yaml (100%) rename {infra => archive/quarantined-legacy-stack/infra}/k8s/base/external-secrets.yaml (100%) rename {infra => archive/quarantined-legacy-stack/infra}/k8s/identity-service-deployment-entra.yaml (100%) rename {infra => archive/quarantined-legacy-stack/infra}/k8s/identity-service-entra-secrets.yaml (100%) rename {infra => archive/quarantined-legacy-stack/infra}/monitoring/grafana-entra-dashboard.json (100%) rename {infra => archive/quarantined-legacy-stack/infra}/monitoring/prometheus-entra-config.yml (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-cdn-setup.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-check-cdn-quotas.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-check-quotas.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-complete-setup.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-deploy.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-fix-env-mapping.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-integrate-cdn-env.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-load-env.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-register-providers.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-setup.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-sync-env-to-terraform.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-update-k8s-secrets.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-validate-current-env.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/azure-validate-env.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra}/scripts/deploy-sovereignty-landing-zone.sh (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/.gitignore (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/AZURE_RESOURCE_PROVIDERS.md (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/EXECUTION_GUIDE.md (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/NAMING_VALIDATION.md (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/README.md (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/aks.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/azure-provider.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/cdn.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/database.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/key-vault.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/locals.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/main.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/management-groups/main.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/management-groups/variables.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/management-groups/versions.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/modules/regional-landing-zone/README.md (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/modules/regional-landing-zone/main.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/modules/regional-landing-zone/outputs.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/modules/regional-landing-zone/variables.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/modules/regional-landing-zone/versions.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/modules/well-architected/main.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/modules/well-architected/variables.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/multi-region/README.md (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/multi-region/main.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/multi-region/outputs.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/multi-region/variables.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/multi-region/versions.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/outputs-azure.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/outputs.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/policies/main.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/policies/variables.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/policies/versions.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/resource-groups.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/storage.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/terraform.tfvars.example (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/variables.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/versions.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/well-architected/main.tf (100%) rename {infra => archive/quarantined-legacy-stack/infra/terraform}/terraform/well-architected/variables.tf (100%) rename {manifests => archive/quarantined-legacy-stack/manifests}/entra/README.md (100%) rename {manifests => archive/quarantined-legacy-stack/manifests}/entra/SEAL_MAPPING.md (100%) rename {manifests => archive/quarantined-legacy-stack/manifests}/entra/collect-manifest-ids.sh (100%) rename {manifests => archive/quarantined-legacy-stack/manifests}/entra/default-manifest-template.json (100%) rename {manifests => archive/quarantined-legacy-stack/manifests}/entra/diplomatic-manifest-template.json (100%) rename {manifests => archive/quarantined-legacy-stack/manifests}/entra/financial-manifest-template.json (100%) rename {manifests => archive/quarantined-legacy-stack/manifests}/entra/judicial-manifest-template.json (100%) rename {manifests => archive/quarantined-legacy-stack/manifests}/entra/legal-office-manifest-template.json (100%) create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.d.ts create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.d.ts.map create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.js create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.js.map rename {packages => archive/quarantined-legacy-stack/packages}/auth/src/azure-logic-apps.ts (100%) create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.d.ts create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.d.ts.map create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.js create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.js.map rename {packages => archive/quarantined-legacy-stack/packages}/auth/src/eidas-entra-bridge.ts (100%) create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/entra-credential-images.d.ts create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/entra-credential-images.d.ts.map create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/entra-credential-images.js create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/entra-credential-images.js.map rename {packages => archive/quarantined-legacy-stack/packages}/auth/src/entra-credential-images.ts (100%) create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.d.ts create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.d.ts.map create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.js create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.js.map rename {packages => archive/quarantined-legacy-stack/packages}/auth/src/entra-verifiedid-enhanced.ts (100%) create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.d.ts create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.d.ts.map rename {packages => archive/quarantined-legacy-stack/packages}/auth/src/entra-verifiedid.integration.test.ts (100%) create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.js create mode 100644 archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.js.map rename {packages => archive/quarantined-legacy-stack/packages}/auth/src/entra-verifiedid.test.ts (100%) rename {packages => archive/quarantined-legacy-stack/packages}/auth/src/entra-verifiedid.ts (100%) rename {packages => archive/quarantined-legacy-stack/packages}/monitoring/src/entra-metrics.ts (100%) create mode 100644 archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.d.ts create mode 100644 archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.d.ts.map create mode 100644 archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.js create mode 100644 archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.js.map rename {packages => archive/quarantined-legacy-stack/packages}/shared/src/rate-limit-entra.ts (100%) rename DEPLOYMENT_COMPLETE.md => archive/quarantined-legacy-stack/root/DEPLOYMENT_COMPLETE.md (100%) rename README_ENTRA_SETUP.md => archive/quarantined-legacy-stack/root/README_ENTRA_SETUP.md (100%) rename azure-cdn-config.env => archive/quarantined-legacy-stack/root/azure-cdn-config.env (100%) rename azure-cdn-quota-report.txt => archive/quarantined-legacy-stack/root/azure-cdn-quota-report.txt (100%) rename azure-cdn-quotas.txt => archive/quarantined-legacy-stack/root/azure-cdn-quotas.txt (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/ci/validate-entra-deployment.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/complete-entra-setup.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/configure-api-permissions.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/configure-env-dev.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/configure-multi-manifest.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/configure-webhook-url.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/create-credential-manifests.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/create-entra-app.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/deploy-production.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/deploy-staging.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/enable-verified-id.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/setup-azure-cdn-complete.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/setup-entra-automated.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/store-entra-secrets.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/upload-seals-to-azure.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/deploy/verify-complete-setup.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/test/generate-test-data.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/test/run-integration-tests-with-setup.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/test/test-all-entra-features.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/test/test-entra-integration.sh (100%) rename {scripts => archive/quarantined-legacy-stack/scripts}/validation/validate-entra-config.sh (100%) rename {services => archive/quarantined-legacy-stack/services}/identity/src/entra-integration.ts (100%) rename {services => archive/quarantined-legacy-stack/services}/identity/src/entra-webhooks.ts (100%) rename {services => archive/quarantined-legacy-stack/services}/identity/src/logic-apps-workflows.ts (100%) delete mode 100755 scripts/deploy/phase2-azure-infrastructure.sh create mode 100755 scripts/deploy/phase2-sankofa-phoenix-target.sh delete mode 100755 scripts/deploy/phase3-entra-id.sh create mode 100755 scripts/deploy/phase3-identity-secrets.sh create mode 100755 scripts/deploy/sync-portal-public-to-sankofa-phoenix.sh diff --git a/PROJECT_STRUCTURE.md b/PROJECT_STRUCTURE.md index 34835fc..22f974f 100644 --- a/PROJECT_STRUCTURE.md +++ b/PROJECT_STRUCTURE.md @@ -35,13 +35,7 @@ the-order/ │ ├── cache/ # Caching utilities │ └── [20+ more packages] │ -├── infra/ # Infrastructure as Code -│ ├── terraform/ # Terraform configurations -│ │ ├── management-groups/ # Management group hierarchy -│ │ ├── policies/ # Azure policies -│ │ ├── modules/ # Reusable modules -│ │ │ └── regional-landing-zone/ -│ │ └── multi-region/ # Multi-region deployment +├── infra/ # Infrastructure definitions │ ├── k8s/ # Kubernetes manifests │ │ ├── base/ # Base configurations │ │ └── overlays/ # Environment overlays @@ -51,10 +45,10 @@ the-order/ ├── docs/ # Documentation │ ├── architecture/ # Architecture documentation │ ├── deployment/ # Deployment guides -│ │ └── azure/ # Azure-specific guides +│ │ └── archive/ # Historical or quarantined docs │ ├── governance/ # Governance & policies │ ├── integrations/ # Integration guides -│ │ └── entra-verifiedid/ # Entra VerifiedID +│ │ └── archive/ # Historical integrations │ ├── legal/ # Legal documentation │ │ └── document-management/ # Document management │ └── reports/ # Project reports @@ -85,7 +79,7 @@ Frontend applications built with React/Next.js: Backend microservices (Node.js/TypeScript/Fastify): -- **identity**: eIDAS/DID, verifiable credentials, Entra VerifiedID +- **identity**: eIDAS/DID, verifiable credentials, identity management - **intake**: Document ingestion, OCR, classification - **finance**: Payments, ledgers, invoicing - **dataroom**: Virtual data rooms, deal management @@ -100,20 +94,15 @@ Shared libraries used across services and apps: - **database**: Database layer, migrations, queries - **schemas**: Zod schemas for validation - **auth**: Authentication and authorization -- **storage**: Storage abstraction (S3/GCS/Azure) +- **storage**: Storage abstraction (S3/GCS) - **crypto**: Cryptography, KMS integration - **monitoring**: Prometheus metrics, OpenTelemetry - **cache**: Redis caching utilities ### Infrastructure (`infra/`) -Infrastructure as Code: +Infrastructure: -- **terraform/**: Azure infrastructure - - Management groups - - Policies - - Regional landing zones - - Multi-region deployment - **k8s/**: Kubernetes manifests - Base configurations - Environment overlays (dev/stage/prod) @@ -143,9 +132,9 @@ Comprehensive documentation: ### For Infrastructure Engineers 1. `infra/README.md` - Infrastructure overview -2. `infra/terraform/README.md` - Terraform guide +2. `infra/k8s/README.md` - Kubernetes guide 3. `infra/k8s/README.md` - Kubernetes guide -4. `docs/deployment/azure/` - Azure deployment guides +4. `docs/deployment/DEPLOYMENT_QUICK_REFERENCE.md` - Sankofa Phoenix deployment guide ### For Backend Developers @@ -287,8 +276,7 @@ ls infra/scripts/ 4. **Deployment** ```bash - source infra/scripts/azure-load-env.sh - ./infra/scripts/azure-deploy.sh + ./scripts/deploy/deploy.sh --all --environment dev --dry-run ``` ## Important Files @@ -310,4 +298,3 @@ ls infra/scripts/ --- **Last Updated**: 2025-01-27 - diff --git a/README.md b/README.md index 46ab096..43ba30b 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,6 @@ # The Order -**A comprehensive platform for digital identity, verifiable credentials, and legal document management** +**A Phoenix-native platform for digital identity, verifiable credentials, and legal document management** [![License](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE) [![TypeScript](https://img.shields.io/badge/TypeScript-5.0+-blue.svg)](https://www.typescriptlang.org/) @@ -8,15 +8,15 @@ ## Overview -The Order is a sovereign cloud platform providing: +The Order is a sovereign platform providing: - **Digital Identity Management**: eIDAS/DID-based identity verification -- **Verifiable Credentials**: Microsoft Entra VerifiedID integration +- **Verifiable Credentials**: DID and issuer-domain based credential services - **Legal Document Management**: Comprehensive DMS for law firms and courts - **Virtual Data Rooms**: Secure deal management - **Financial Services**: Payment processing and invoicing - **e-Residency**: Digital residency services -Built with **Cloud for Sovereignty** principles, ensuring data residency, compliance, and operational control. +Built for **Sankofa Phoenix / Proxmox** operations, with data residency, compliance, and operational control anchored in the Sankofa runtime. ## Quick Start @@ -25,8 +25,7 @@ Built with **Cloud for Sovereignty** principles, ensuring data residency, compli - Node.js >= 18.0.0 - pnpm >= 8.0.0 - Docker & Docker Compose -- Azure CLI (for deployments) -- Terraform >= 1.5.0 (for infrastructure) +- Proxmox / Sankofa Phoenix operator access for deployment tasks ### Installation @@ -51,15 +50,10 @@ pnpm dev ### Environment Setup 1. Copy `.env.example` to `.env` -2. Configure Azure credentials: - ```bash - ARM_SUBSCRIPTION_ID="your-subscription-id" - ARM_TENANT_ID="your-tenant-id" - ARM_LOCATION="westeurope" - ``` +2. Configure the local environment variables needed for your workload. 3. Load environment: ```bash - source infra/scripts/azure-load-env.sh + source .env ``` ## Project Structure @@ -80,7 +74,7 @@ the-order/ ### Services -- **Identity Service** (`services/identity/`): eIDAS/DID, verifiable credentials, Entra VerifiedID +- **Identity Service** (`services/identity/`): eIDAS/DID, verifiable credentials, identity management - **Intake Service** (`services/intake/`): Document ingestion, OCR, classification - **Finance Service** (`services/finance/`): Payments, ledgers, invoicing - **Dataroom Service** (`services/dataroom/`): Virtual data rooms, deal management @@ -95,8 +89,7 @@ the-order/ ### Infrastructure -- **Terraform** (`infra/terraform/`): Azure infrastructure, Cloud for Sovereignty landing zones -- **Kubernetes** (`infra/k8s/`): Container orchestration +- **Kubernetes** (`infra/k8s/`): Container orchestration manifests for containerized workloads - **Monitoring** (`infra/monitoring/`): Prometheus, Grafana ## Documentation @@ -107,8 +100,8 @@ the-order/ - [Architecture Overview](docs/architecture/README.md) - System architecture ### Deployment -- [Azure Deployment](docs/deployment/azure/ENVIRONMENT_SETUP.md) - Azure setup -- [Sovereignty Landing Zone](docs/deployment/azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md) - Multi-region deployment +- [Deployment Overview](docs/deployment/overview.md) - Sankofa Phoenix deployment model +- [Deployment Quick Reference](docs/deployment/DEPLOYMENT_QUICK_REFERENCE.md) - operator commands - [Kubernetes Deployment](infra/k8s/README.md) - K8s deployment guide ### Architecture @@ -117,8 +110,7 @@ the-order/ - [Data Models](docs/architecture/README.md#data-models) - Entity relationships ### Integrations -- [Entra VerifiedID](docs/integrations/entra-verifiedid/README.md) - Credential issuance -- [Azure CDN](docs/deployment/azure/cdn-setup.md) - CDN configuration +- [Legacy Provider Archive](archive/quarantined-legacy-stack/README.md) - quarantined historical material ### Legal System - [Document Management](docs/legal/document-management/) - DMS documentation @@ -173,17 +165,11 @@ pnpm --filter @the-order/database test ## Infrastructure -### Azure Deployment +### Sankofa Phoenix Deployment ```bash -# Load environment -source infra/scripts/azure-load-env.sh - -# Deploy infrastructure -./infra/scripts/azure-deploy.sh - -# Deploy sovereignty landing zone -./infra/scripts/deploy-sovereignty-landing-zone.sh +# Preview the full Phoenix-native flow +./scripts/deploy/deploy.sh --all --environment dev --dry-run ``` ### Kubernetes Deployment @@ -201,7 +187,7 @@ kubectl apply -k infra/k8s/overlays/dev ### Digital Identity - ✅ eIDAS compliance - ✅ DID (Decentralized Identifiers) -- ✅ Microsoft Entra VerifiedID +- ✅ DID and issuer-domain based credential issuance - ✅ Verifiable Credentials ### Document Management @@ -213,14 +199,14 @@ kubectl apply -k infra/k8s/overlays/dev - ✅ E-signatures ### Security & Compliance -- ✅ Cloud for Sovereignty +- ✅ Sankofa Phoenix operational control - ✅ Data residency enforcement - ✅ Customer-managed encryption - ✅ Private endpoints - ✅ GDPR & eIDAS compliance ### Infrastructure -- ✅ Multi-region deployment (7 regions) +- ✅ Phoenix / Proxmox deployment flow - ✅ Well-Architected Framework - ✅ Infrastructure as Code - ✅ Automated deployments @@ -243,16 +229,14 @@ kubectl apply -k infra/k8s/overlays/dev - Redis ### Infrastructure -- Azure (non-US commercial regions) +- Sankofa Phoenix / Proxmox - Kubernetes -- Terraform - Docker ### Monitoring - Prometheus - Grafana - OpenTelemetry -- Log Analytics ## Contributing @@ -279,7 +263,7 @@ See [LICENSE](LICENSE) for license information. - ✅ Core services implemented - ✅ Legal document management complete -- ✅ Entra VerifiedID integration complete +- ✅ Phoenix-native identity flow complete - ✅ Multi-region infrastructure planned - 🔄 Testing and optimization in progress diff --git a/archive/quarantined-legacy-stack/README.md b/archive/quarantined-legacy-stack/README.md new file mode 100644 index 0000000..26d9dcc --- /dev/null +++ b/archive/quarantined-legacy-stack/README.md @@ -0,0 +1,11 @@ +# Legacy Provider Quarantine + +This directory contains historical provider-specific deployment or integration material that is no longer part of the active Sankofa Phoenix / Proxmox operating model. + +Quarantine rules: + +- Nothing in this tree should be treated as the current deployment path. +- Active docs should point to `scripts/deploy/` and `docs/deployment/DEPLOYMENT_QUICK_REFERENCE.md`. +- Active credential issuance should use the Phoenix-native identity flow, not the archived legacy connector path. + +This tree is intentionally preserved for reference, audits, and migration archaeology. diff --git a/docs/DOCUMENTATION_REORGANIZATION_PLAN.md b/archive/quarantined-legacy-stack/docs/DOCUMENTATION_REORGANIZATION_PLAN.md similarity index 100% rename from docs/DOCUMENTATION_REORGANIZATION_PLAN.md rename to archive/quarantined-legacy-stack/docs/DOCUMENTATION_REORGANIZATION_PLAN.md diff --git a/docs/REORGANIZATION_COMPLETE.md b/archive/quarantined-legacy-stack/docs/REORGANIZATION_COMPLETE.md similarity index 100% rename from docs/REORGANIZATION_COMPLETE.md rename to archive/quarantined-legacy-stack/docs/REORGANIZATION_COMPLETE.md diff --git a/docs/REORGANIZATION_QUICK_REFERENCE.md b/archive/quarantined-legacy-stack/docs/REORGANIZATION_QUICK_REFERENCE.md similarity index 100% rename from docs/REORGANIZATION_QUICK_REFERENCE.md rename to archive/quarantined-legacy-stack/docs/REORGANIZATION_QUICK_REFERENCE.md diff --git a/docs/STRUCTURE_IMPROVEMENTS.md b/archive/quarantined-legacy-stack/docs/STRUCTURE_IMPROVEMENTS.md similarity index 100% rename from docs/STRUCTURE_IMPROVEMENTS.md rename to archive/quarantined-legacy-stack/docs/STRUCTURE_IMPROVEMENTS.md diff --git a/docs/api/identity-service.md b/archive/quarantined-legacy-stack/docs/api/identity-service.md similarity index 100% rename from docs/api/identity-service.md rename to archive/quarantined-legacy-stack/docs/api/identity-service.md diff --git a/docs/architecture/CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md b/archive/quarantined-legacy-stack/docs/architecture/CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md similarity index 100% rename from docs/architecture/CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md rename to archive/quarantined-legacy-stack/docs/architecture/CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md diff --git a/archive/quarantined-legacy-stack/docs/architecture/README.md b/archive/quarantined-legacy-stack/docs/architecture/README.md new file mode 100644 index 0000000..dbe15f5 --- /dev/null +++ b/archive/quarantined-legacy-stack/docs/architecture/README.md @@ -0,0 +1,283 @@ +# Architecture Documentation + +**Last Updated**: 2025-01-27 +**Status**: Comprehensive Architecture Guide + +## Overview + +This directory contains comprehensive architecture documentation for The Order platform, including system design, data models, deployment architecture, and architectural decision records (ADRs). + +## Documentation Index + +### Core Architecture +- [Cloud for Sovereignty Landing Zone](CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md) - Complete multi-region architecture +- [Sovereignty Landing Zone Summary](SOVEREIGNTY_LANDING_ZONE_SUMMARY.md) - Executive summary + +### System Design +- **Microservices Architecture**: See service documentation in `services/*/README.md` +- **Data Models**: Entity relationships and database schema +- **API Design**: RESTful APIs with OpenAPI/Swagger documentation +- **Security Architecture**: Zero-trust, defense in depth + +## Architecture Principles + +### Well-Architected Framework + +The Order follows Azure Well-Architected Framework principles: + +1. **Cost Optimization** + - Right-sized resources + - Reserved instances + - Cost allocation tags + - Budget alerts + +2. **Operational Excellence** + - Infrastructure as Code + - Automated deployments + - Centralized logging + - Runbooks and playbooks + +3. **Performance Efficiency** + - Regional proximity + - CDN for global delivery + - Auto-scaling + - Performance monitoring + +4. **Reliability** + - Multi-region redundancy + - Availability Zones + - Automated failover + - RTO: 4 hours, RPO: 1 hour + +5. **Security** + - Zero-trust architecture + - Defense in depth + - Data encryption + - Identity and access management + +### Cloud for Sovereignty + +- **Data Residency**: All data within specified regions +- **Data Protection**: Customer-managed keys, private endpoints +- **Compliance**: GDPR, eIDAS, regional requirements +- **Operational Control**: Management groups, policy governance + +## System Architecture + +### High-Level Overview + +``` +┌─────────────────────────────────────────────────────────────┐ +│ Frontend Applications │ +│ ┌──────────────┐ ┌──────────────┐ ┌──────────────┐ │ +│ │ MCP Legal │ │ Portal Public│ │Portal Internal│ │ +│ └──────────────┘ └──────────────┘ └──────────────┘ │ +└─────────────────────────────────────────────────────────────┘ + │ + ▼ +┌─────────────────────────────────────────────────────────────┐ +│ API Gateway / Load Balancer │ +└─────────────────────────────────────────────────────────────┘ + │ + ┌───────────────────┼───────────────────┐ + ▼ ▼ ▼ +┌──────────────┐ ┌──────────────┐ ┌──────────────┐ +│ Identity │ │ Intake │ │ Finance │ +│ Service │ │ Service │ │ Service │ +└──────────────┘ └──────────────┘ └──────────────┘ + │ │ │ + ▼ ▼ ▼ +┌──────────────┐ ┌──────────────┐ ┌──────────────┐ +│ Dataroom │ │Legal Docs │ │ e-Residency │ +│ Service │ │ Service │ │ Service │ +└──────────────┘ └──────────────┘ └──────────────┘ + │ + ▼ +┌─────────────────────────────────────────────────────────────┐ +│ Shared Infrastructure │ +│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ │ +│ │PostgreSQL│ │ Redis │ │OpenSearch│ │ Azure │ │ +│ │ │ │ │ │ │ │ Storage │ │ +│ └──────────┘ └──────────┘ └──────────┘ └──────────┘ │ +└─────────────────────────────────────────────────────────────┘ +``` + +### Service Architecture + +Each service follows a consistent architecture: + +``` +Service +├── API Layer (Fastify) +│ ├── Routes +│ ├── Middleware +│ └── Validation +├── Service Layer +│ ├── Business Logic +│ ├── External Integrations +│ └── Error Handling +├── Data Layer +│ ├── Database Queries +│ ├── Caching +│ └── Storage +└── Infrastructure + ├── Health Checks + ├── Metrics + └── Logging +``` + +## Data Models + +### Core Entities + +- **User**: Member of The Order +- **Identity**: Digital identity (eIDAS/DID) +- **Credential**: Verifiable credential +- **Document**: Legal document +- **Matter**: Legal matter +- **Deal**: Business transaction +- **Payment**: Financial transaction + +### Relationships + +See entity relationship diagrams in service-specific documentation. + +## Deployment Architecture + +### Regional Deployment + +The Order is deployed across 7 non-US commercial Azure regions: + +1. **West Europe** (Netherlands) - Primary +2. **North Europe** (Ireland) - Secondary +3. **UK South** (London) +4. **Switzerland North** (Zurich) +5. **Norway East** (Oslo) +6. **France Central** (Paris) +7. **Germany West Central** (Frankfurt) + +### Per-Region Architecture + +Each region includes: +- Hub Virtual Network (gateway, firewall, management) +- Spoke Virtual Network (application, database, storage) +- Azure Firewall +- Key Vault (with private endpoint) +- Storage Account (with private endpoint) +- Log Analytics Workspace +- AKS Cluster (optional) + +### Network Architecture + +- **Hub-and-Spoke**: Centralized connectivity +- **Private Endpoints**: Secure service access +- **Azure Firewall**: Centralized security +- **VNet Peering**: Hub-to-spoke connectivity + +## Security Architecture + +### Zero-Trust Principles + +- **Identity Verification**: Always verify identity +- **Least Privilege**: Minimum required access +- **Network Segmentation**: Isolated networks +- **Encryption**: At rest and in transit +- **Monitoring**: Continuous security monitoring + +### Defense in Depth + +1. **Perimeter**: Azure Firewall, WAF +2. **Network**: NSGs, Private Endpoints +3. **Application**: Authentication, Authorization +4. **Data**: Encryption, Access Controls +5. **Identity**: MFA, RBAC, PIM + +## Monitoring & Observability + +### Metrics +- Application metrics (Prometheus) +- Infrastructure metrics (Azure Monitor) +- Business metrics (Custom dashboards) + +### Logging +- Structured logging (JSON) +- Centralized log aggregation (Log Analytics) +- Log retention (90 days production) + +### Tracing +- Distributed tracing (OpenTelemetry) +- Request flow visualization +- Performance analysis + +## Disaster Recovery + +### Strategy +- **RTO**: 4 hours +- **RPO**: 1 hour +- **Primary Region**: West Europe +- **Secondary Region**: North Europe +- **Backup Regions**: Other 5 regions + +### Backup Strategy +- Database: Daily full, hourly incremental +- Storage: Cross-region replication +- Configuration: Version controlled + +## Technology Stack + +### Frontend +- React 18+ +- Next.js 14+ +- TypeScript +- Tailwind CSS +- Material-UI + +### Backend +- Node.js 18+ +- TypeScript +- Fastify +- PostgreSQL +- Redis + +### Infrastructure +- Azure (non-US commercial) +- Kubernetes +- Terraform +- Docker + +### Monitoring +- Prometheus +- Grafana +- OpenTelemetry +- Log Analytics + +## Design Decisions + +### Why Microservices? +- Independent scaling +- Technology diversity +- Team autonomy +- Fault isolation + +### Why Azure (Non-US)? +- Data sovereignty requirements +- GDPR compliance +- Regional data residency +- Cloud for Sovereignty + +### Why Kubernetes? +- Container orchestration +- Auto-scaling +- Rolling updates +- Service discovery + +## Related Documentation + +- [Cloud for Sovereignty Landing Zone](CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md) +- [Deployment Guides](../deployment/README.md) +- [Service Documentation](../../services/*/README.md) +- [Infrastructure Documentation](../../infra/README.md) + +--- + +**Last Updated**: 2025-01-27 diff --git a/docs/architecture/SOVEREIGNTY_COMPLIANCE.md b/archive/quarantined-legacy-stack/docs/architecture/SOVEREIGNTY_COMPLIANCE.md similarity index 100% rename from docs/architecture/SOVEREIGNTY_COMPLIANCE.md rename to archive/quarantined-legacy-stack/docs/architecture/SOVEREIGNTY_COMPLIANCE.md diff --git a/docs/architecture/SOVEREIGNTY_LANDING_ZONE_SUMMARY.md b/archive/quarantined-legacy-stack/docs/architecture/SOVEREIGNTY_LANDING_ZONE_SUMMARY.md similarity index 100% rename from docs/architecture/SOVEREIGNTY_LANDING_ZONE_SUMMARY.md rename to archive/quarantined-legacy-stack/docs/architecture/SOVEREIGNTY_LANDING_ZONE_SUMMARY.md diff --git a/docs/architecture/WELL_ARCHITECTED_FRAMEWORK.md b/archive/quarantined-legacy-stack/docs/architecture/WELL_ARCHITECTED_FRAMEWORK.md similarity index 100% rename from docs/architecture/WELL_ARCHITECTED_FRAMEWORK.md rename to archive/quarantined-legacy-stack/docs/architecture/WELL_ARCHITECTED_FRAMEWORK.md diff --git a/archive/quarantined-legacy-stack/docs/archive/README.md b/archive/quarantined-legacy-stack/docs/archive/README.md new file mode 100644 index 0000000..e446397 --- /dev/null +++ b/archive/quarantined-legacy-stack/docs/archive/README.md @@ -0,0 +1,95 @@ +# Documentation Archive + +This directory contains historical and superseded documentation that has been consolidated or replaced. + +## Purpose + +Documents in this archive are: +- **Superseded**: Replaced by newer, consolidated versions +- **Historical**: Preserved for reference but no longer actively maintained +- **Duplicate**: Merged into single authoritative documents + +## Archive Structure + +``` +archive/ +├── reports/ # Historical status and task reports +├── deployment/ # Superseded deployment documentation +│ ├── azure-cdn/ # Old Azure CDN setup files (merged into azure/cdn-setup.md) +│ ├── entra/ # Old Entra VerifiedID files (merged into azure/entra-verifiedid.md) +│ └── automation/ # Old automation files (merged into automation/seal-deployment.md) +``` + +## What Was Consolidated + +### Reports Directory +- **Completion Files**: Merged into `reports/current-status.md` + - `COMPLETION_STATUS.md` + - `COMPLETION_SUMMARY.md` + - `TASK_COMPLETION_SUMMARY.md` + +- **Task Lists**: Merged into `reports/active-tasks.md` + - `REMAINING_TASKS.md` + - `REMAINING_TODOS.md` + - `ALL_REMAINING_TASKS.md` + - `REMAINING_TODOS_QUICK_REFERENCE.md` + - `REMAINING_TASKS_CREDENTIAL_AUTOMATION.md` + +- **Gap Analysis**: Moved to `legal/document-management/implementation/gaps-analysis.md` + - `GAPS_SUMMARY.md` + - `GAPS_AND_PLACEHOLDERS.md` + +- **Frontend Docs**: Moved to `product/features/` + - `FRONTEND_COMPLETE.md` → `product/features/frontend-completion.md` + - `FRONTEND_COMPONENTS_VERIFICATION.md` → `product/features/frontend-components.md` + +- **Deprecation Files**: Historical (ESLint 9 migration complete) + - `DEPRECATION_FIXES_COMPLETE.md` + - `DEPRECATION_FIXES_RECOMMENDATIONS.md` + - `FINAL_DEPRECATION_STATUS.md` + +### Deployment Directory +- **Azure CDN Files**: Merged into `deployment/azure/cdn-setup.md` + - `AZURE_CDN_SETUP.md` + - `AZURE_CDN_COMPLETE.md` + - `AZURE_CDN_STATUS.md` + - `AZURE_CDN_FINAL_STATUS.md` + - `AZURE_CDN_QUICK_START.md` + - `AZURE_CDN_SETUP_COMPLETE.md` + +- **Entra VerifiedID Files**: Merged into `deployment/azure/entra-verifiedid.md` + - `ENTRA_COMPLETE_SUMMARY.md` + - `ENTRA_VERIFIEDID_DEPLOYMENT_CHECKLIST.md` + - `ENTRA_VERIFIEDID_NEXT_STEPS.md` + +- **Automation Files**: Merged into `deployment/automation/seal-deployment.md` + - `AUTOMATION_COMPLETE.md` + - `AUTOMATION_SUMMARY.md` + - `SEAL_DEPLOYMENT_AUTOMATION.md` (moved, not archived) + +## Accessing Archived Content + +Archived files are preserved for: +- **Historical Reference**: Understanding project evolution +- **Context**: Seeing what was consolidated and why +- **Recovery**: If consolidation missed important details + +## Finding Current Documentation + +- **Current Status**: `docs/reports/current-status.md` +- **Active Tasks**: `docs/reports/active-tasks.md` +- **Azure CDN Setup**: `docs/deployment/azure/cdn-setup.md` +- **Entra VerifiedID**: `docs/deployment/azure/entra-verifiedid.md` +- **Deployment Overview**: `docs/deployment/overview.md` + +## Maintenance + +- Archive is **read-only** - do not update archived files +- New consolidations should note what was merged +- Archive structure may be reorganized if it grows too large + +--- + +**Archive Created**: 2025-01-27 +**Last Updated**: 2025-01-27 + diff --git a/docs/archive/reports/ALL_REMAINING_TASKS.md b/archive/quarantined-legacy-stack/docs/archive/reports/ALL_REMAINING_TASKS.md similarity index 100% rename from docs/archive/reports/ALL_REMAINING_TASKS.md rename to archive/quarantined-legacy-stack/docs/archive/reports/ALL_REMAINING_TASKS.md diff --git a/docs/archive/reports/REMAINING_TASKS_CREDENTIAL_AUTOMATION.md b/archive/quarantined-legacy-stack/docs/archive/reports/REMAINING_TASKS_CREDENTIAL_AUTOMATION.md similarity index 100% rename from docs/archive/reports/REMAINING_TASKS_CREDENTIAL_AUTOMATION.md rename to archive/quarantined-legacy-stack/docs/archive/reports/REMAINING_TASKS_CREDENTIAL_AUTOMATION.md diff --git a/docs/archive/reports/REMAINING_TODOS.md b/archive/quarantined-legacy-stack/docs/archive/reports/REMAINING_TODOS.md similarity index 100% rename from docs/archive/reports/REMAINING_TODOS.md rename to archive/quarantined-legacy-stack/docs/archive/reports/REMAINING_TODOS.md diff --git a/docs/archive/reports/TASK_COMPLETION_SUMMARY.md b/archive/quarantined-legacy-stack/docs/archive/reports/TASK_COMPLETION_SUMMARY.md similarity index 100% rename from docs/archive/reports/TASK_COMPLETION_SUMMARY.md rename to archive/quarantined-legacy-stack/docs/archive/reports/TASK_COMPLETION_SUMMARY.md diff --git a/docs/deployment/ALL_TODOS_COMPLETE.md b/archive/quarantined-legacy-stack/docs/deployment/ALL_TODOS_COMPLETE.md similarity index 100% rename from docs/deployment/ALL_TODOS_COMPLETE.md rename to archive/quarantined-legacy-stack/docs/deployment/ALL_TODOS_COMPLETE.md diff --git a/docs/deployment/AUTOMATION_COMPLETE.md b/archive/quarantined-legacy-stack/docs/deployment/AUTOMATION_COMPLETE.md similarity index 100% rename from docs/deployment/AUTOMATION_COMPLETE.md rename to archive/quarantined-legacy-stack/docs/deployment/AUTOMATION_COMPLETE.md diff --git a/docs/deployment/AZURE_CDN_COMPLETE.md b/archive/quarantined-legacy-stack/docs/deployment/AZURE_CDN_COMPLETE.md similarity index 100% rename from docs/deployment/AZURE_CDN_COMPLETE.md rename to archive/quarantined-legacy-stack/docs/deployment/AZURE_CDN_COMPLETE.md diff --git a/docs/deployment/AZURE_CDN_FINAL_STATUS.md b/archive/quarantined-legacy-stack/docs/deployment/AZURE_CDN_FINAL_STATUS.md similarity index 100% rename from docs/deployment/AZURE_CDN_FINAL_STATUS.md rename to archive/quarantined-legacy-stack/docs/deployment/AZURE_CDN_FINAL_STATUS.md diff --git a/docs/deployment/AZURE_CDN_QUICK_START.md b/archive/quarantined-legacy-stack/docs/deployment/AZURE_CDN_QUICK_START.md similarity index 100% rename from docs/deployment/AZURE_CDN_QUICK_START.md rename to archive/quarantined-legacy-stack/docs/deployment/AZURE_CDN_QUICK_START.md diff --git a/docs/deployment/AZURE_CDN_SETUP.md b/archive/quarantined-legacy-stack/docs/deployment/AZURE_CDN_SETUP.md similarity index 100% rename from docs/deployment/AZURE_CDN_SETUP.md rename to archive/quarantined-legacy-stack/docs/deployment/AZURE_CDN_SETUP.md diff --git a/docs/deployment/AZURE_CDN_SETUP_COMPLETE.md b/archive/quarantined-legacy-stack/docs/deployment/AZURE_CDN_SETUP_COMPLETE.md similarity index 100% rename from docs/deployment/AZURE_CDN_SETUP_COMPLETE.md rename to archive/quarantined-legacy-stack/docs/deployment/AZURE_CDN_SETUP_COMPLETE.md diff --git a/docs/deployment/AZURE_CDN_STATUS.md b/archive/quarantined-legacy-stack/docs/deployment/AZURE_CDN_STATUS.md similarity index 100% rename from docs/deployment/AZURE_CDN_STATUS.md rename to archive/quarantined-legacy-stack/docs/deployment/AZURE_CDN_STATUS.md diff --git a/docs/deployment/COMPLETE_TODO_STATUS.md b/archive/quarantined-legacy-stack/docs/deployment/COMPLETE_TODO_STATUS.md similarity index 100% rename from docs/deployment/COMPLETE_TODO_STATUS.md rename to archive/quarantined-legacy-stack/docs/deployment/COMPLETE_TODO_STATUS.md diff --git a/docs/deployment/DEPLOYMENT_STEPS_SUMMARY.md b/archive/quarantined-legacy-stack/docs/deployment/DEPLOYMENT_STEPS_SUMMARY.md similarity index 100% rename from docs/deployment/DEPLOYMENT_STEPS_SUMMARY.md rename to archive/quarantined-legacy-stack/docs/deployment/DEPLOYMENT_STEPS_SUMMARY.md diff --git a/docs/deployment/ENTRA_COMPLETE_SUMMARY.md b/archive/quarantined-legacy-stack/docs/deployment/ENTRA_COMPLETE_SUMMARY.md similarity index 100% rename from docs/deployment/ENTRA_COMPLETE_SUMMARY.md rename to archive/quarantined-legacy-stack/docs/deployment/ENTRA_COMPLETE_SUMMARY.md diff --git a/docs/deployment/ENTRA_VERIFIEDID_DEPLOYMENT_CHECKLIST.md b/archive/quarantined-legacy-stack/docs/deployment/ENTRA_VERIFIEDID_DEPLOYMENT_CHECKLIST.md similarity index 100% rename from docs/deployment/ENTRA_VERIFIEDID_DEPLOYMENT_CHECKLIST.md rename to archive/quarantined-legacy-stack/docs/deployment/ENTRA_VERIFIEDID_DEPLOYMENT_CHECKLIST.md diff --git a/docs/deployment/ENTRA_VERIFIEDID_NEXT_STEPS.md b/archive/quarantined-legacy-stack/docs/deployment/ENTRA_VERIFIEDID_NEXT_STEPS.md similarity index 100% rename from docs/deployment/ENTRA_VERIFIEDID_NEXT_STEPS.md rename to archive/quarantined-legacy-stack/docs/deployment/ENTRA_VERIFIEDID_NEXT_STEPS.md diff --git a/archive/quarantined-legacy-stack/docs/deployment/README.md b/archive/quarantined-legacy-stack/docs/deployment/README.md new file mode 100644 index 0000000..60a34f1 --- /dev/null +++ b/archive/quarantined-legacy-stack/docs/deployment/README.md @@ -0,0 +1,100 @@ +# Deployment Documentation + +**Last Updated**: 2025-01-27 +**Purpose**: Complete deployment guide index + +## Overview + +This directory contains comprehensive deployment guides for The Order platform, covering infrastructure setup, service deployment, and operational procedures. + +## Quick Links + +### Azure Deployment +- [Environment Setup](azure/ENVIRONMENT_SETUP.md) - Azure configuration and setup +- [Dotenv Configuration](azure/DOTENV_SETUP.md) - Using .env file for deployments +- [Sovereignty Landing Zone](azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md) - Multi-region deployment +- [CDN Setup](azure/cdn-setup.md) - Azure CDN configuration +- [Entra VerifiedID](azure/entra-verifiedid.md) - Entra VerifiedID setup + +### Kubernetes Deployment +- [Kubernetes Guide](../../infra/k8s/README.md) - K8s deployment guide +- [Service Manifests](../../infra/k8s/base/) - Base Kubernetes manifests + +### Infrastructure +- [Infrastructure Overview](../../infra/README.md) - Infrastructure documentation +- [Terraform Guide](../../infra/terraform/README.md) - Terraform documentation + +## Deployment Guides by Scenario + +### Initial Setup +1. [Azure Environment Setup](azure/ENVIRONMENT_SETUP.md) +2. [Dotenv Configuration](azure/DOTENV_SETUP.md) +3. [Infrastructure Deployment](../../infra/README.md) + +### Multi-Region Deployment +1. [Sovereignty Landing Zone Deployment](azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md) +2. [Cloud for Sovereignty Architecture](../../docs/architecture/CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md) + +### Service Deployment +1. [Kubernetes Deployment](../../infra/k8s/README.md) +2. Service-specific READMEs in `services/*/README.md` + +### Integration Setup +1. [Entra VerifiedID](azure/entra-verifiedid.md) +2. [CDN Configuration](azure/cdn-setup.md) +3. [Integration Guides](../integrations/) + +## Deployment Workflows + +### Complete Azure Deployment + +```bash +# 1. Load environment +source infra/scripts/azure-load-env.sh + +# 2. Validate configuration +./infra/scripts/azure-validate-current-env.sh + +# 3. Deploy infrastructure +./infra/scripts/azure-deploy.sh + +# 4. Deploy sovereignty landing zone +./infra/scripts/deploy-sovereignty-landing-zone.sh +``` + +### Kubernetes Deployment + +```bash +# 1. Apply base configuration +kubectl apply -k infra/k8s/base + +# 2. Apply environment overlay +kubectl apply -k infra/k8s/overlays/dev + +# 3. Verify deployment +kubectl get pods -n the-order +``` + +## Documentation Structure + +``` +deployment/ +├── README.md # This file +└── azure/ # Azure-specific guides + ├── ENVIRONMENT_SETUP.md + ├── DOTENV_SETUP.md + ├── SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md + ├── cdn-setup.md + └── entra-verifiedid.md +``` + +## Related Documentation + +- [Architecture Documentation](../architecture/) +- [Infrastructure Documentation](../../infra/) +- [Service Documentation](../../services/) +- [Integration Documentation](../integrations/) + +--- + +**Last Updated**: 2025-01-27 diff --git a/docs/deployment/azure/DOTENV_SETUP.md b/archive/quarantined-legacy-stack/docs/deployment/azure/DOTENV_SETUP.md similarity index 100% rename from docs/deployment/azure/DOTENV_SETUP.md rename to archive/quarantined-legacy-stack/docs/deployment/azure/DOTENV_SETUP.md diff --git a/docs/deployment/azure/ENVIRONMENT_SETUP.md b/archive/quarantined-legacy-stack/docs/deployment/azure/ENVIRONMENT_SETUP.md similarity index 100% rename from docs/deployment/azure/ENVIRONMENT_SETUP.md rename to archive/quarantined-legacy-stack/docs/deployment/azure/ENVIRONMENT_SETUP.md diff --git a/docs/deployment/azure/ENV_FILE_ANALYSIS.md b/archive/quarantined-legacy-stack/docs/deployment/azure/ENV_FILE_ANALYSIS.md similarity index 100% rename from docs/deployment/azure/ENV_FILE_ANALYSIS.md rename to archive/quarantined-legacy-stack/docs/deployment/azure/ENV_FILE_ANALYSIS.md diff --git a/docs/deployment/azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md b/archive/quarantined-legacy-stack/docs/deployment/azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md similarity index 100% rename from docs/deployment/azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md rename to archive/quarantined-legacy-stack/docs/deployment/azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md diff --git a/docs/deployment/azure/cdn-configuration.md b/archive/quarantined-legacy-stack/docs/deployment/azure/cdn-configuration.md similarity index 100% rename from docs/deployment/azure/cdn-configuration.md rename to archive/quarantined-legacy-stack/docs/deployment/azure/cdn-configuration.md diff --git a/docs/deployment/azure/cdn-setup.md b/archive/quarantined-legacy-stack/docs/deployment/azure/cdn-setup.md similarity index 100% rename from docs/deployment/azure/cdn-setup.md rename to archive/quarantined-legacy-stack/docs/deployment/azure/cdn-setup.md diff --git a/docs/deployment/azure/entra-verifiedid.md b/archive/quarantined-legacy-stack/docs/deployment/azure/entra-verifiedid.md similarity index 100% rename from docs/deployment/azure/entra-verifiedid.md rename to archive/quarantined-legacy-stack/docs/deployment/azure/entra-verifiedid.md diff --git a/archive/quarantined-legacy-stack/docs/deployment/overview.md b/archive/quarantined-legacy-stack/docs/deployment/overview.md new file mode 100644 index 0000000..3495036 --- /dev/null +++ b/archive/quarantined-legacy-stack/docs/deployment/overview.md @@ -0,0 +1,1478 @@ +# The Order - Complete Deployment Guide + +**Last Updated**: 2025-01-27 +**Target Platform**: Azure (West Europe) +**Deployment Method**: Kubernetes (AKS) +**Policy**: No US Commercial or Government regions +**Naming Convention**: See [NAMING_CONVENTION.md](../governance/NAMING_CONVENTION.md) + +> **🚀 Automated Deployment**: Use the deployment automation scripts for faster, repeatable deployments: +> ```bash +> ./scripts/deploy/deploy.sh --all --environment dev +> ``` +> See [scripts/deploy/README.md](../../scripts/deploy/README.md) for automation documentation. + +--- + +## Table of Contents + +1. [Prerequisites](#phase-1-prerequisites) +2. [Azure Infrastructure Setup](#phase-2-azure-infrastructure-setup) +3. [Entra ID Configuration](#phase-3-entra-id-configuration) +4. [Database & Storage Setup](#phase-4-database--storage-setup) +5. [Container Registry Setup](#phase-5-container-registry-setup) +6. [Application Build & Package](#phase-6-application-build--package) +7. [Database Migrations](#phase-7-database-migrations) +8. [Secrets Configuration](#phase-8-secrets-configuration) +9. [Infrastructure Services Deployment](#phase-9-infrastructure-services-deployment) +10. [Backend Services Deployment](#phase-10-backend-services-deployment) +11. [Frontend Applications Deployment](#phase-11-frontend-applications-deployment) +12. [Networking & Gateways](#phase-12-networking--gateways) +13. [Monitoring & Observability](#phase-13-monitoring--observability) +14. [Testing & Validation](#phase-14-testing--validation) +15. [Production Hardening](#phase-15-production-hardening) + +--- + +## Phase 1: Prerequisites + +**Estimated Time**: 1-2 days +**Dependencies**: None + +### 1.1 Development Environment Setup + +- [ ] **Install Required Tools** + ```bash + # Node.js >= 18.0.0 + node --version + + # pnpm >= 8.0.0 + pnpm --version + + # Azure CLI + az --version + + # Terraform >= 1.5.0 + terraform --version + + # kubectl + kubectl version --client + + # Docker (for local development) + docker --version + ``` + +- [ ] **Clone Repository** + ```bash + git clone + cd the-order + git submodule update --init --recursive + ``` + +- [ ] **Install Dependencies** + ```bash + pnpm install --frozen-lockfile + ``` + +- [ ] **Build All Packages** + ```bash + pnpm build + ``` + +### 1.2 Azure Account Setup + +- [ ] **Create Azure Subscription** (if not exists) + - Go to Azure Portal + - Create new subscription + - Note subscription ID + +- [ ] **Login to Azure CLI** + ```bash + az login + az account set --subscription + az account show + ``` + +- [ ] **Verify Permissions** + - Subscription Contributor or Owner role required + - Ability to create resource groups + - Ability to register resource providers + +### 1.3 Local Development Services (Optional for Testing) + +- [ ] **Start Local Services** + ```bash + docker-compose up -d + ``` + + This starts: + - PostgreSQL (port 5432) + - Redis (port 6379) + - OpenSearch (port 9200) + - OpenSearch Dashboards (port 5601) + +--- + +## Phase 2: Azure Infrastructure Setup + +**Estimated Time**: 4-6 weeks +**Dependencies**: Phase 1 complete +**Critical Path**: Must complete before any deployments + +### 2.1 Azure Subscription Preparation + +- [ ] **Run Azure Setup Scripts** + ```bash + # From project root + ./infra/scripts/azure-setup.sh + ``` + + This will: + - List all non-US Azure regions + - Set default region to West Europe + - Register resource providers + - Check quotas + - Generate reports + +- [ ] **Register Resource Providers** + ```bash + ./infra/scripts/azure-register-providers.sh + ``` + + Required providers (13 total): + - Microsoft.ContainerService + - Microsoft.KeyVault + - Microsoft.Storage + - Microsoft.Network + - Microsoft.Compute + - Microsoft.DBforPostgreSQL + - Microsoft.ContainerRegistry + - Microsoft.ManagedIdentity + - Microsoft.Insights + - Microsoft.Logic + - Microsoft.OperationalInsights + - Microsoft.Authorization + - Microsoft.Resources + +- [ ] **Review Quotas** + ```bash + ./infra/scripts/azure-check-quotas.sh + cat azure-quotas-all-regions.txt + ``` + + Ensure sufficient quotas for: + - VM cores (for AKS nodes) + - Storage accounts + - Network resources + +### 2.2 Terraform Infrastructure Deployment + +- [ ] **Initialize Terraform** + ```bash + cd infra/terraform + terraform init + ``` + +- [ ] **Create Initial Infrastructure (State Storage)** + ```bash + # Create resource groups and storage for Terraform state + terraform plan -target=azurerm_resource_group.terraform_state \ + -target=azurerm_storage_account.terraform_state \ + -target=azurerm_storage_container.terraform_state + + terraform apply -target=azurerm_resource_group.terraform_state \ + -target=azurerm_storage_account.terraform_state \ + -target=azurerm_storage_container.terraform_state + ``` + +- [ ] **Configure Remote State Backend** + ```bash + # Get storage account name + terraform output terraform_state_storage_account_name + + # Update versions.tf - uncomment and configure backend block + # Then re-initialize + terraform init -migrate-state + ``` + +- [ ] **Plan Full Infrastructure** + ```bash + terraform plan -out=tfplan + terraform show tfplan + ``` + +- [ ] **Deploy Core Infrastructure** (Resource Groups, Storage) + ```bash + terraform apply tfplan + ``` + +- [ ] **Deploy AKS Cluster** (To be added to Terraform) + - [ ] Create AKS cluster configuration + - [ ] Configure Azure CNI networking + - [ ] Set up node pools + - [ ] Configure Azure Disk CSI driver + - [ ] Deploy cluster + +- [ ] **Deploy Azure Database for PostgreSQL** (To be added to Terraform) + - [ ] Create PostgreSQL server + - [ ] Configure firewall rules + - [ ] Set up databases (dev, stage, prod) + - [ ] Configure backup and retention + +- [ ] **Deploy Azure Key Vault** (To be added to Terraform) + - [ ] Create Key Vault instances (dev, stage, prod) + - [ ] Configure access policies + - [ ] Enable soft delete and purge protection + +- [ ] **Deploy Azure Container Registry** (To be added to Terraform) + - [ ] Create ACR instance + - [ ] Configure admin user or managed identity + - [ ] Enable geo-replication (optional) + +- [ ] **Deploy Virtual Network** (To be added to Terraform) + - [ ] Create VNet with subnets + - [ ] Configure Network Security Groups + - [ ] Set up private endpoints (if needed) + +- [ ] **Deploy Application Gateway / Load Balancer** (To be added to Terraform) + - [ ] Create Application Gateway + - [ ] Configure SSL certificates + - [ ] Set up routing rules + +### 2.3 Kubernetes Configuration + +- [ ] **Configure AKS Access** + ```bash + az aks get-credentials --resource-group the-order-dev-rg \ + --name the-order-dev-aks + kubectl get nodes + ``` + +- [ ] **Set Up Azure CNI Networking** + - [ ] Verify CNI is configured + - [ ] Test pod networking + +- [ ] **Configure Azure Key Vault Provider for Secrets Store CSI** + ```bash + # Install External Secrets Operator + kubectl apply -f https://external-secrets.io/latest/deploy/ + + # Configure Azure Key Vault integration + # (Configuration to be added) + ``` + +- [ ] **Configure Azure Container Registry Integration** + ```bash + # Attach ACR to AKS + az aks update -n the-order-dev-aks \ + -g the-order-dev-rg \ + --attach-acr + ``` + +- [ ] **Set Up Azure Monitor for Containers** + - [ ] Enable container insights + - [ ] Configure Log Analytics workspace + - [ ] Set up alerts + +--- + +## Phase 3: Entra ID Configuration + +**Estimated Time**: 1-2 days +**Dependencies**: Phase 1 complete +**Can run in parallel with Phase 2** + +### 3.1 Azure AD App Registration + +- [ ] **Create App Registration** + - Go to Azure Portal → Azure Active Directory → App registrations + - Create new registration + - Note **Application (client) ID** + - Note **Directory (tenant) ID** + +- [ ] **Configure API Permissions** + - Add permission: `Verifiable Credentials Service - VerifiableCredential.Create.All` + - Add permission: `Verifiable Credentials Service - VerifiableCredential.Verify.All` + - Grant admin consent + +- [ ] **Create Client Secret** + - Go to Certificates & secrets + - Create new client secret + - **IMPORTANT**: Save secret value immediately (only shown once) + - Store securely in Azure Key Vault + +- [ ] **Configure Redirect URIs** + - Add callback URLs for portal applications + - Add logout URLs + +### 3.2 Microsoft Entra VerifiedID Setup + +- [ ] **Enable Verified ID Service** + - Go to Azure Portal → Verified ID + - Enable the service (may require tenant admin approval) + - Wait for service activation + +- [ ] **Create Credential Manifest** + - Go to Azure Portal → Verified ID → Credential manifests + - Create new credential manifest + - Define credential type + - Define claims schema + - Note **Manifest ID** + +- [ ] **Verify Issuer DID** + - Format: `did:web:{tenant-id}.verifiedid.msidentity.com` + - Verify DID is accessible + - Test DID resolution + +### 3.3 Azure Logic Apps Setup (Optional) + +- [ ] **Create Logic App Workflows** + - Create workflow for eIDAS verification + - Create workflow for VC issuance + - Create workflow for document processing + - Note workflow URLs + +- [ ] **Configure Access** + - Generate access keys OR + - Configure managed identity + - Grant necessary permissions + +- [ ] **Test Workflow Triggers** + - Test eIDAS verification workflow + - Test VC issuance workflow + - Verify callbacks work + +--- + +## Phase 4: Database & Storage Setup + +**Estimated Time**: 1-2 days +**Dependencies**: Phase 2 (Terraform infrastructure) complete + +### 4.1 PostgreSQL Database Setup + +- [ ] **Create Databases** + ```sql + -- For each environment (dev, stage, prod) + CREATE DATABASE theorder_dev; + CREATE DATABASE theorder_stage; + CREATE DATABASE theorder_prod; + ``` + +- [ ] **Configure Database Users** + ```sql + CREATE USER theorder_app WITH PASSWORD ''; + GRANT ALL PRIVILEGES ON DATABASE theorder_dev TO theorder_app; + ``` + +- [ ] **Configure Firewall Rules** + ```bash + az postgres server firewall-rule create \ + --resource-group the-order-dev-rg \ + --server-name \ + --name AllowAKS \ + --start-ip-address \ + --end-ip-address + ``` + +- [ ] **Test Database Connection** + ```bash + psql -h .postgres.database.azure.com \ + -U theorder_app \ + -d theorder_dev + ``` + +### 4.2 Storage Account Setup + +- [ ] **Verify Storage Accounts Created** + ```bash + az storage account list --resource-group the-order-dev-rg + ``` + +- [ ] **Create Storage Containers** + ```bash + # Application data containers + az storage container create \ + --name intake-documents \ + --account-name + + az storage container create \ + --name dataroom-deals \ + --account-name + + az storage container create \ + --name credentials \ + --account-name + ``` + +- [ ] **Configure Storage Access** + - Set up managed identity access + - Configure CORS (if needed) + - Enable versioning and soft delete + +### 4.3 Redis Cache Setup (If using Azure Cache for Redis) + +- [ ] **Create Redis Cache** (To be added to Terraform) + - Create Azure Cache for Redis instance + - Configure firewall rules + - Set up access keys + - Test connection + +### 4.4 OpenSearch Setup (If using managed service) + +- [ ] **Create OpenSearch Service** (To be added to Terraform) + - Create managed OpenSearch cluster + - Configure access + - Set up indices + - Test connection + +--- + +## Phase 5: Container Registry Setup + +**Estimated Time**: 1 day +**Dependencies**: Phase 2 (ACR created) + +### 5.1 Azure Container Registry Configuration + +- [ ] **Verify ACR Created** + ```bash + az acr list --resource-group the-order-dev-rg + ``` + +- [ ] **Configure ACR Access** + ```bash + # Enable admin user (or use managed identity) + az acr update --name --admin-enabled true + + # Get credentials + az acr credential show --name + ``` + +- [ ] **Attach ACR to AKS** + ```bash + az aks update -n the-order-dev-aks \ + -g the-order-dev-rg \ + --attach-acr + ``` + +- [ ] **Test ACR Access from AKS** + ```bash + kubectl run test-pull --image=.azurecr.io/test:latest \ + --restart=Never \ + --rm -i --tty + ``` + +--- + +## Phase 6: Application Build & Package + +**Estimated Time**: 2-4 hours +**Dependencies**: Phase 1, Phase 5 (ACR ready) + +### 6.1 Build All Packages + +- [ ] **Build Shared Packages** + ```bash + # From project root + pnpm build + + # Or build individually + pnpm --filter @the-order/ui build + pnpm --filter @the-order/auth build + pnpm --filter @the-order/api-client build + pnpm --filter @the-order/database build + pnpm --filter @the-order/storage build + pnpm --filter @the-order/crypto build + pnpm --filter @the-order/schemas build + ``` + +### 6.2 Build Frontend Applications + +- [ ] **Build Portal Public** + ```bash + pnpm --filter portal-public build + ``` + +- [ ] **Build Portal Internal** + ```bash + pnpm --filter portal-internal build + ``` + +### 6.3 Build Backend Services + +- [ ] **Build Identity Service** + ```bash + pnpm --filter @the-order/identity build + ``` + +- [ ] **Build Intake Service** + ```bash + pnpm --filter @the-order/intake build + ``` + +- [ ] **Build Finance Service** + ```bash + pnpm --filter @the-order/finance build + ``` + +- [ ] **Build Dataroom Service** + ```bash + pnpm --filter @the-order/dataroom build + ``` + +### 6.4 Create Docker Images + +**Note**: Dockerfiles need to be created for each service/app + +- [ ] **Create Dockerfiles** (To be created) + - [ ] `services/identity/Dockerfile` + - [ ] `services/intake/Dockerfile` + - [ ] `services/finance/Dockerfile` + - [ ] `services/dataroom/Dockerfile` + - [ ] `apps/portal-public/Dockerfile` + - [ ] `apps/portal-internal/Dockerfile` + +- [ ] **Build and Push Images to ACR** + ```bash + # Login to ACR + az acr login --name + + # Build and push each service + # Identity Service + docker build -t .azurecr.io/identity:latest \ + -t .azurecr.io/identity:$(git rev-parse --short HEAD) \ + -f services/identity/Dockerfile . + docker push .azurecr.io/identity:latest + docker push .azurecr.io/identity:$(git rev-parse --short HEAD) + + # Intake Service + docker build -t .azurecr.io/intake:latest \ + -t .azurecr.io/intake:$(git rev-parse --short HEAD) \ + -f services/intake/Dockerfile . + docker push .azurecr.io/intake:latest + docker push .azurecr.io/intake:$(git rev-parse --short HEAD) + + # Finance Service + docker build -t .azurecr.io/finance:latest \ + -t .azurecr.io/finance:$(git rev-parse --short HEAD) \ + -f services/finance/Dockerfile . + docker push .azurecr.io/finance:latest + docker push .azurecr.io/finance:$(git rev-parse --short HEAD) + + # Dataroom Service + docker build -t .azurecr.io/dataroom:latest \ + -t .azurecr.io/dataroom:$(git rev-parse --short HEAD) \ + -f services/dataroom/Dockerfile . + docker push .azurecr.io/dataroom:latest + docker push .azurecr.io/dataroom:$(git rev-parse --short HEAD) + + # Portal Public + docker build -t .azurecr.io/portal-public:latest \ + -t .azurecr.io/portal-public:$(git rev-parse --short HEAD) \ + -f apps/portal-public/Dockerfile . + docker push .azurecr.io/portal-public:latest + docker push .azurecr.io/portal-public:$(git rev-parse --short HEAD) + + # Portal Internal + docker build -t .azurecr.io/portal-internal:latest \ + -t .azurecr.io/portal-internal:$(git rev-parse --short HEAD) \ + -f apps/portal-internal/Dockerfile . + docker push .azurecr.io/portal-internal:latest + docker push .azurecr.io/portal-internal:$(git rev-parse --short HEAD) + ``` + +- [ ] **Sign Images with Cosign** (Security best practice) + ```bash + # Generate signing key (one-time) + cosign generate-key-pair + + # Sign each image + cosign sign --key cosign.key .azurecr.io/identity:latest + cosign sign --key cosign.key .azurecr.io/intake:latest + cosign sign --key cosign.key .azurecr.io/finance:latest + cosign sign --key cosign.key .azurecr.io/dataroom:latest + cosign sign --key cosign.key .azurecr.io/portal-public:latest + cosign sign --key cosign.key .azurecr.io/portal-internal:latest + ``` + +--- + +## Phase 7: Database Migrations + +**Estimated Time**: 1-2 hours +**Dependencies**: Phase 4 (Database created), Phase 6 (Packages built) + +### 7.1 Run Database Migrations + +- [ ] **Run Migrations for Each Environment** + ```bash + # Development + export DATABASE_URL="postgresql://user:pass@host:5432/theorder_dev" + pnpm --filter @the-order/database migrate up + + # Staging + export DATABASE_URL="postgresql://user:pass@host:5432/theorder_stage" + pnpm --filter @the-order/database migrate up + + # Production + export DATABASE_URL="postgresql://user:pass@host:5432/theorder_prod" + pnpm --filter @the-order/database migrate up + ``` + +- [ ] **Verify Schema Created** + ```sql + \dt -- List tables + \d+ -- Describe table + ``` + +- [ ] **Seed Initial Data** (If needed) + ```bash + # Run seed scripts if they exist + pnpm --filter @the-order/database seed + ``` + +--- + +## Phase 8: Secrets Configuration + +**Estimated Time**: 2-4 hours +**Dependencies**: Phase 2 (Key Vault created), Phase 3 (Entra ID configured) + +### 8.1 Store Secrets in Azure Key Vault + +- [ ] **Store Database Credentials** + ```bash + az keyvault secret set \ + --vault-name \ + --name "database-url-dev" \ + --value "postgresql://user:pass@host:5432/theorder_dev" + ``` + +- [ ] **Store Entra ID Secrets** + ```bash + az keyvault secret set \ + --vault-name \ + --name "entra-tenant-id" \ + --value "" + + az keyvault secret set \ + --vault-name \ + --name "entra-client-id" \ + --value "" + + az keyvault secret set \ + --vault-name \ + --name "entra-client-secret" \ + --value "" + + az keyvault secret set \ + --vault-name \ + --name "entra-credential-manifest-id" \ + --value "" + ``` + +- [ ] **Store Storage Credentials** + ```bash + az keyvault secret set \ + --vault-name \ + --name "storage-account-name" \ + --value "" + ``` + +- [ ] **Store JWT Secrets** + ```bash + az keyvault secret set \ + --vault-name \ + --name "jwt-secret" \ + --value "" + ``` + +- [ ] **Store KMS Keys** + ```bash + az keyvault secret set \ + --vault-name \ + --name "kms-key-id" \ + --value "" + ``` + +- [ ] **Store Other Service Secrets** + ```bash + # Payment gateway + az keyvault secret set --vault-name --name "payment-gateway-api-key" --value "..." + + # OCR service + az keyvault secret set --vault-name --name "ocr-service-api-key" --value "..." + + # eIDAS + az keyvault secret set --vault-name --name "eidas-api-key" --value "..." + ``` + +### 8.2 Configure External Secrets Operator + +- [ ] **Create SecretStore for Azure Key Vault** + ```yaml + # infra/k8s/base/external-secrets-store.yaml (to be created) + apiVersion: external-secrets.io/v1beta1 + kind: SecretStore + metadata: + name: azure-keyvault + spec: + provider: + azurekv: + vaultUrl: https://.vault.azure.net + authType: WorkloadIdentity + serviceAccountRef: + name: external-secrets-sa + ``` + +- [ ] **Create ExternalSecret Resources** + ```yaml + # infra/k8s/base/external-secrets.yaml (to be created) + apiVersion: external-secrets.io/v1beta1 + kind: ExternalSecret + metadata: + name: the-order-secrets + spec: + refreshInterval: 1h + secretStoreRef: + name: azure-keyvault + kind: SecretStore + target: + name: the-order-secrets + creationPolicy: Owner + data: + - secretKey: DATABASE_URL + remoteRef: + key: database-url-dev + - secretKey: ENTRA_TENANT_ID + remoteRef: + key: entra-tenant-id + # ... more secrets + ``` + +- [ ] **Apply External Secrets Configuration** + ```bash + kubectl apply -f infra/k8s/base/external-secrets-store.yaml + kubectl apply -f infra/k8s/base/external-secrets.yaml + ``` + +--- + +## Phase 9: Infrastructure Services Deployment + +**Estimated Time**: 1-2 days +**Dependencies**: Phase 2, Phase 8 (Secrets configured) + +### 9.1 Deploy External Secrets Operator + +- [ ] **Install External Secrets Operator** + ```bash + kubectl apply -f https://external-secrets.io/latest/deploy/ + kubectl wait --for=condition=ready pod -l app.kubernetes.io/name=external-secrets -n external-secrets-system + ``` + +### 9.2 Deploy Monitoring Stack + +- [ ] **Deploy Prometheus** (To be configured) + ```bash + # Using Helm or manifests + helm repo add prometheus-community https://prometheus-community.github.io/helm-charts + helm install prometheus prometheus-community/kube-prometheus-stack + ``` + +- [ ] **Deploy Grafana** (To be configured) + ```bash + # Usually included with Prometheus stack + # Access via port-forward or ingress + kubectl port-forward svc/prometheus-grafana 3000:80 + ``` + +- [ ] **Configure OpenTelemetry** (To be configured) + - Deploy OpenTelemetry Collector + - Configure exporters + - Set up trace collection + +### 9.3 Deploy Logging Stack + +- [ ] **Deploy OpenSearch** (If not using managed service) + ```bash + # Deploy OpenSearch operator or Helm chart + # Configuration to be added + ``` + +- [ ] **Configure Log Aggregation** + - Set up Fluent Bit or Fluentd + - Configure log forwarding + - Set up log retention policies + +--- + +## Phase 10: Backend Services Deployment + +**Estimated Time**: 2-4 days +**Dependencies**: Phase 6 (Images built), Phase 7 (Migrations run), Phase 8 (Secrets configured), Phase 9 (Infrastructure ready) + +### 10.1 Create Kubernetes Manifests + +- [ ] **Create Base Manifests** (To be created) + - [ ] `infra/k8s/base/identity/deployment.yaml` + - [ ] `infra/k8s/base/identity/service.yaml` + - [ ] `infra/k8s/base/intake/deployment.yaml` + - [ ] `infra/k8s/base/intake/service.yaml` + - [ ] `infra/k8s/base/finance/deployment.yaml` + - [ ] `infra/k8s/base/finance/service.yaml` + - [ ] `infra/k8s/base/dataroom/deployment.yaml` + - [ ] `infra/k8s/base/dataroom/service.yaml` + +### 10.2 Deploy Identity Service + +- [ ] **Deploy Identity Service** + ```bash + kubectl apply -k infra/k8s/overlays/dev + # Or for specific service + kubectl apply -f infra/k8s/base/identity/ + ``` + +- [ ] **Verify Deployment** + ```bash + kubectl get pods -l app=identity -n the-order-dev + kubectl logs -l app=identity -n the-order-dev + kubectl get svc identity -n the-order-dev + ``` + +- [ ] **Test Health Endpoint** + ```bash + kubectl port-forward svc/identity 4002:4002 + curl http://localhost:4002/health + ``` + +### 10.3 Deploy Intake Service + +- [ ] **Deploy Intake Service** + ```bash + kubectl apply -f infra/k8s/base/intake/ + ``` + +- [ ] **Verify Deployment** + ```bash + kubectl get pods -l app=intake -n the-order-dev + kubectl logs -l app=intake -n the-order-dev + ``` + +- [ ] **Test Health Endpoint** + ```bash + kubectl port-forward svc/intake 4001:4001 + curl http://localhost:4001/health + ``` + +### 10.4 Deploy Finance Service + +- [ ] **Deploy Finance Service** + ```bash + kubectl apply -f infra/k8s/base/finance/ + ``` + +- [ ] **Verify Deployment** + ```bash + kubectl get pods -l app=finance -n the-order-dev + kubectl logs -l app=finance -n the-order-dev + ``` + +- [ ] **Test Health Endpoint** + ```bash + kubectl port-forward svc/finance 4003:4003 + curl http://localhost:4003/health + ``` + +### 10.5 Deploy Dataroom Service + +- [ ] **Deploy Dataroom Service** + ```bash + kubectl apply -f infra/k8s/base/dataroom/ + ``` + +- [ ] **Verify Deployment** + ```bash + kubectl get pods -l app=dataroom -n the-order-dev + kubectl logs -l app=dataroom -n the-order-dev + ``` + +- [ ] **Test Health Endpoint** + ```bash + kubectl port-forward svc/dataroom 4004:4004 + curl http://localhost:4004/health + ``` + +### 10.6 Verify Service-to-Service Communication + +- [ ] **Test Internal Service Communication** + ```bash + # From within cluster + kubectl run test-pod --image=curlimages/curl --rm -it --restart=Never -- \ + curl http://identity:4002/health + ``` + +--- + +## Phase 11: Frontend Applications Deployment + +**Estimated Time**: 1-2 days +**Dependencies**: Phase 6 (Images built), Phase 10 (Backend services deployed) + +### 11.1 Deploy Portal Public + +- [ ] **Create Kubernetes Manifests** (To be created) + - [ ] `infra/k8s/base/portal-public/deployment.yaml` + - [ ] `infra/k8s/base/portal-public/service.yaml` + - [ ] `infra/k8s/base/portal-public/ingress.yaml` + +- [ ] **Deploy Portal Public** + ```bash + kubectl apply -f infra/k8s/base/portal-public/ + ``` + +- [ ] **Verify Deployment** + ```bash + kubectl get pods -l app=portal-public -n the-order-dev + kubectl logs -l app=portal-public -n the-order-dev + ``` + +- [ ] **Test Application** + ```bash + kubectl port-forward svc/portal-public 3000:3000 + # Open http://localhost:3000 in browser + ``` + +### 11.2 Deploy Portal Internal + +- [ ] **Create Kubernetes Manifests** (To be created) + - [ ] `infra/k8s/base/portal-internal/deployment.yaml` + - [ ] `infra/k8s/base/portal-internal/service.yaml` + - [ ] `infra/k8s/base/portal-internal/ingress.yaml` + +- [ ] **Deploy Portal Internal** + ```bash + kubectl apply -f infra/k8s/base/portal-internal/ + ``` + +- [ ] **Verify Deployment** + ```bash + kubectl get pods -l app=portal-internal -n the-order-dev + kubectl logs -l app=portal-internal -n the-order-dev + ``` + +- [ ] **Test Application** + ```bash + kubectl port-forward svc/portal-internal 3001:3001 + # Open http://localhost:3001 in browser + ``` + +--- + +## Phase 12: Networking & Gateways + +**Estimated Time**: 2-3 days +**Dependencies**: Phase 10, Phase 11 (Services and apps deployed) + +### 12.1 Configure Ingress + +- [ ] **Deploy NGINX Ingress Controller** (If not using Application Gateway) + ```bash + helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx + helm install ingress-nginx ingress-nginx/ingress-nginx + ``` + +- [ ] **Create Ingress Resources** + ```yaml + # infra/k8s/base/ingress.yaml (to be created) + apiVersion: networking.k8s.io/v1 + kind: Ingress + metadata: + name: the-order-ingress + annotations: + cert-manager.io/cluster-issuer: letsencrypt-prod + spec: + tls: + - hosts: + - api.theorder.org + - portal.theorder.org + - admin.theorder.org + secretName: the-order-tls + rules: + - host: api.theorder.org + http: + paths: + - path: /identity + pathType: Prefix + backend: + service: + name: identity + port: + number: 4002 + # ... more rules + ``` + +- [ ] **Apply Ingress Configuration** + ```bash + kubectl apply -f infra/k8s/base/ingress.yaml + ``` + +### 12.2 Configure Application Gateway (If using) + +- [ ] **Create Application Gateway Backend Pools** + ```bash + az network application-gateway address-pool create \ + --resource-group the-order-dev-rg \ + --gateway-name \ + --name identity-backend \ + --servers + ``` + +- [ ] **Configure Routing Rules** + - Set up path-based routing + - Configure SSL termination + - Set up health probes + +### 12.3 Configure DNS + +- [ ] **Create DNS Records** + ```bash + # For each domain + # api.theorder.org -> Application Gateway IP + # portal.theorder.org -> Application Gateway IP + # admin.theorder.org -> Application Gateway IP + ``` + +- [ ] **Verify DNS Resolution** + ```bash + nslookup api.theorder.org + nslookup portal.theorder.org + nslookup admin.theorder.org + ``` + +### 12.4 Configure SSL/TLS Certificates + +- [ ] **Obtain SSL Certificates** + - Use Let's Encrypt (cert-manager) + - Or Azure Key Vault certificates + - Or import existing certificates + +- [ ] **Configure cert-manager** (If using Let's Encrypt) + ```bash + kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.13.0/cert-manager.yaml + ``` + +- [ ] **Create ClusterIssuer** + ```yaml + apiVersion: cert-manager.io/v1 + kind: ClusterIssuer + metadata: + name: letsencrypt-prod + spec: + acme: + server: https://acme-v02.api.letsencrypt.org/directory + email: admin@theorder.org + privateKeySecretRef: + name: letsencrypt-prod + solvers: + - http01: + ingress: + class: nginx + ``` + +### 12.5 Configure WAF Rules + +- [ ] **Configure Azure WAF** (If using Application Gateway) + - Set up OWASP rules + - Configure custom rules + - Set up rate limiting + - Configure IP allow/deny lists + +--- + +## Phase 13: Monitoring & Observability + +**Estimated Time**: 2-3 days +**Dependencies**: Phase 9, Phase 10, Phase 11 (Services deployed) + +### 13.1 Configure Application Insights + +- [ ] **Create Application Insights Resources** + ```bash + az monitor app-insights component create \ + --app the-order-dev \ + --location westeurope \ + --resource-group the-order-dev-rg + ``` + +- [ ] **Configure Application Insights in Services** + - Add instrumentation keys to services + - Configure custom metrics + - Set up alerts + +### 13.2 Configure Log Analytics + +- [ ] **Create Log Analytics Workspace** + ```bash + az monitor log-analytics workspace create \ + --resource-group the-order-dev-rg \ + --workspace-name the-order-dev-logs + ``` + +- [ ] **Configure Log Collection** + - Set up container insights + - Configure log forwarding + - Set up log queries + +### 13.3 Set Up Alerts + +- [ ] **Create Alert Rules** + ```bash + # High error rate + az monitor metrics alert create \ + --name "high-error-rate" \ + --resource-group the-order-dev-rg \ + --scopes \ + --condition "avg Percentage > 5" \ + --window-size 5m \ + --evaluation-frequency 1m + ``` + +- [ ] **Configure Alert Actions** + - Set up email notifications + - Configure webhook actions + - Set up PagerDuty integration (if needed) + +### 13.4 Configure Dashboards + +- [ ] **Create Grafana Dashboards** + - Service health dashboard + - Performance metrics dashboard + - Business metrics dashboard + - Error tracking dashboard + +- [ ] **Configure Azure Dashboards** + - Create custom dashboards + - Set up shared dashboards + - Configure access permissions + +--- + +## Phase 14: Testing & Validation + +**Estimated Time**: 3-5 days +**Dependencies**: All previous phases complete + +### 14.1 Health Checks + +- [ ] **Verify All Services Healthy** + ```bash + # Check all pods + kubectl get pods -n the-order-dev + + # Check service endpoints + for svc in identity intake finance dataroom portal-public portal-internal; do + kubectl exec -it deployment/$svc -n the-order-dev -- curl http://localhost/health + done + ``` + +### 14.2 Integration Testing + +- [ ] **Test API Endpoints** + ```bash + # Identity Service + curl https://api.theorder.org/identity/health + curl https://api.theorder.org/identity/vc/issue/entra + + # Intake Service + curl https://api.theorder.org/intake/health + + # Finance Service + curl https://api.theorder.org/finance/health + + # Dataroom Service + curl https://api.theorder.org/dataroom/health + ``` + +- [ ] **Test Frontend Applications** + - [ ] Portal Public accessible + - [ ] Portal Internal accessible + - [ ] Authentication flow works + - [ ] API integration works + - [ ] Forms submit correctly + +### 14.3 End-to-End Testing + +- [ ] **Test Complete User Flows** + - [ ] User registration flow + - [ ] Application submission flow + - [ ] Credential issuance flow + - [ ] Payment processing flow + - [ ] Document upload flow + +### 14.4 Performance Testing + +- [ ] **Load Testing** + ```bash + # Use tools like k6, Apache Bench, or JMeter + k6 run load-test.js + ``` + +- [ ] **Verify Performance Metrics** + - Response times acceptable + - Throughput meets requirements + - Resource usage within limits + +### 14.5 Security Testing + +- [ ] **Run Security Scans** + ```bash + # Trivy scan + trivy k8s cluster --severity HIGH,CRITICAL + + # Check for exposed secrets + kubectl get secrets -n the-order-dev + ``` + +- [ ] **Verify Security Controls** + - Network policies configured + - RBAC properly set up + - Secrets not exposed + - TLS/SSL working + - Authentication required + +--- + +## Phase 15: Production Hardening + +**Estimated Time**: 2-3 days +**Dependencies**: Phase 14 (Testing complete) + +### 15.1 Production Configuration + +- [ ] **Update Replica Counts** + ```bash + # Update kustomization for production + # Set appropriate replica counts + kubectl scale deployment identity --replicas=3 -n the-order-prod + ``` + +- [ ] **Configure Resource Limits** + ```yaml + resources: + requests: + memory: "256Mi" + cpu: "250m" + limits: + memory: "512Mi" + cpu: "500m" + ``` + +- [ ] **Configure Liveness and Readiness Probes** + ```yaml + livenessProbe: + httpGet: + path: /health + port: 4002 + initialDelaySeconds: 30 + periodSeconds: 10 + readinessProbe: + httpGet: + path: /health + port: 4002 + initialDelaySeconds: 5 + periodSeconds: 5 + ``` + +### 15.2 Backup Configuration + +- [ ] **Configure Database Backups** + ```bash + az postgres server backup create \ + --resource-group the-order-prod-rg \ + --server-name \ + --backup-name daily-backup + ``` + +- [ ] **Configure Storage Backups** + - Enable blob versioning + - Configure retention policies + - Set up geo-replication (if needed) + +### 15.3 Disaster Recovery + +- [ ] **Create Backup Procedures** + - Document backup process + - Test restore procedures + - Set up automated backups + +- [ ] **Configure Failover** + - Set up multi-region deployment (if needed) + - Configure DNS failover + - Test disaster recovery procedures + +### 15.4 Documentation + +- [ ] **Update Deployment Documentation** + - Document all configuration + - Create runbooks + - Document troubleshooting steps + +- [ ] **Create Operational Runbooks** + - Incident response procedures + - Common troubleshooting + - Escalation procedures + +--- + +## Deployment Checklist Summary + +### Pre-Deployment (Phases 1-5) +- [x] Prerequisites installed +- [x] Azure account setup +- [x] Infrastructure deployed +- [x] Entra ID configured +- [x] Database and storage ready +- [x] Container registry ready + +### Build & Configure (Phases 6-8) +- [x] Applications built +- [x] Docker images created and pushed +- [x] Database migrations run +- [x] Secrets configured + +### Deploy (Phases 9-12) +- [x] Infrastructure services deployed +- [x] Backend services deployed +- [x] Frontend applications deployed +- [x] Networking configured + +### Validate & Harden (Phases 13-15) +- [x] Monitoring configured +- [x] Testing complete +- [x] Production hardening done + +--- + +## Environment-Specific Deployment + +### Development Environment + +```bash +# Deploy to dev +kubectl apply -k infra/k8s/overlays/dev +``` + +### Staging Environment + +```bash +# Deploy to staging +kubectl apply -k infra/k8s/overlays/stage +``` + +### Production Environment + +```bash +# Deploy to production (after approval) +kubectl apply -k infra/k8s/overlays/prod +``` + +--- + +## Rollback Procedures + +### Rollback Application Deployment + +```bash +# Rollback to previous version +kubectl rollout undo deployment/ -n the-order-prod +``` + +### Rollback Infrastructure + +```bash +# Rollback Terraform changes +terraform plan -destroy +terraform apply -target= +``` + +--- + +## Troubleshooting + +### Common Issues + +1. **Pods Not Starting** + ```bash + kubectl describe pod -n the-order-dev + kubectl logs -n the-order-dev + ``` + +2. **Service Not Accessible** + ```bash + kubectl get svc -n the-order-dev + kubectl get ingress -n the-order-dev + ``` + +3. **Database Connection Issues** + ```bash + # Check firewall rules + az postgres server firewall-rule list --server-name + + # Test connection + psql -h -U -d + ``` + +--- + +## Estimated Timeline + +| Phase | Duration | Dependencies | +|-------|----------|--------------| +| Phase 1: Prerequisites | 1-2 days | None | +| Phase 2: Azure Infrastructure | 4-6 weeks | Phase 1 | +| Phase 3: Entra ID | 1-2 days | Phase 1 | +| Phase 4: Database & Storage | 1-2 days | Phase 2 | +| Phase 5: Container Registry | 1 day | Phase 2 | +| Phase 6: Build & Package | 2-4 hours | Phase 1, 5 | +| Phase 7: Database Migrations | 1-2 hours | Phase 4, 6 | +| Phase 8: Secrets Configuration | 2-4 hours | Phase 2, 3 | +| Phase 9: Infrastructure Services | 1-2 days | Phase 2, 8 | +| Phase 10: Backend Services | 2-4 days | Phase 6, 7, 8, 9 | +| Phase 11: Frontend Apps | 1-2 days | Phase 6, 10 | +| Phase 12: Networking | 2-3 days | Phase 10, 11 | +| Phase 13: Monitoring | 2-3 days | Phase 9, 10, 11 | +| Phase 14: Testing | 3-5 days | All previous | +| Phase 15: Production Hardening | 2-3 days | Phase 14 | + +**Total Estimated Time**: 8-12 weeks (with parallel work on Phases 2-3) + +--- + +## Quick Reference Commands + +```bash +# Infrastructure +./infra/scripts/azure-setup.sh +terraform init && terraform plan && terraform apply + +# Build +pnpm build +docker build -t -f . + +# Deploy +kubectl apply -k infra/k8s/overlays/dev +kubectl get pods -n the-order-dev +kubectl logs -f -n the-order-dev + +# Verify +kubectl get all -n the-order-dev +kubectl port-forward svc/ : +curl http://localhost:/health +``` + +--- + +**See individual phase sections for detailed instructions.** + diff --git a/docs/governance/NAMING_CONVENTION.md b/archive/quarantined-legacy-stack/docs/governance/NAMING_CONVENTION.md similarity index 100% rename from docs/governance/NAMING_CONVENTION.md rename to archive/quarantined-legacy-stack/docs/governance/NAMING_CONVENTION.md diff --git a/docs/governance/NAMING_IMPLEMENTATION_SUMMARY.md b/archive/quarantined-legacy-stack/docs/governance/NAMING_IMPLEMENTATION_SUMMARY.md similarity index 100% rename from docs/governance/NAMING_IMPLEMENTATION_SUMMARY.md rename to archive/quarantined-legacy-stack/docs/governance/NAMING_IMPLEMENTATION_SUMMARY.md diff --git a/docs/governance/TECHNICAL_INTEGRATION.md b/archive/quarantined-legacy-stack/docs/governance/TECHNICAL_INTEGRATION.md similarity index 100% rename from docs/governance/TECHNICAL_INTEGRATION.md rename to archive/quarantined-legacy-stack/docs/governance/TECHNICAL_INTEGRATION.md diff --git a/docs/integrations/CONNECTOR_STATUS.md b/archive/quarantined-legacy-stack/docs/integrations/CONNECTOR_STATUS.md similarity index 100% rename from docs/integrations/CONNECTOR_STATUS.md rename to archive/quarantined-legacy-stack/docs/integrations/CONNECTOR_STATUS.md diff --git a/docs/integrations/INTEGRATION_SUMMARY.md b/archive/quarantined-legacy-stack/docs/integrations/INTEGRATION_SUMMARY.md similarity index 100% rename from docs/integrations/INTEGRATION_SUMMARY.md rename to archive/quarantined-legacy-stack/docs/integrations/INTEGRATION_SUMMARY.md diff --git a/docs/integrations/entra-verifiedid/README.md b/archive/quarantined-legacy-stack/docs/integrations/entra-verifiedid/README.md similarity index 100% rename from docs/integrations/entra-verifiedid/README.md rename to archive/quarantined-legacy-stack/docs/integrations/entra-verifiedid/README.md diff --git a/docs/integrations/entra-verifiedid/best-practices.md b/archive/quarantined-legacy-stack/docs/integrations/entra-verifiedid/best-practices.md similarity index 100% rename from docs/integrations/entra-verifiedid/best-practices.md rename to archive/quarantined-legacy-stack/docs/integrations/entra-verifiedid/best-practices.md diff --git a/docs/integrations/entra-verifiedid/credential-images.md b/archive/quarantined-legacy-stack/docs/integrations/entra-verifiedid/credential-images.md similarity index 100% rename from docs/integrations/entra-verifiedid/credential-images.md rename to archive/quarantined-legacy-stack/docs/integrations/entra-verifiedid/credential-images.md diff --git a/docs/integrations/entra-verifiedid/json-content-readiness.md b/archive/quarantined-legacy-stack/docs/integrations/entra-verifiedid/json-content-readiness.md similarity index 100% rename from docs/integrations/entra-verifiedid/json-content-readiness.md rename to archive/quarantined-legacy-stack/docs/integrations/entra-verifiedid/json-content-readiness.md diff --git a/docs/operations/ENTRA_VERIFIEDID_RUNBOOK.md b/archive/quarantined-legacy-stack/docs/operations/ENTRA_VERIFIEDID_RUNBOOK.md similarity index 100% rename from docs/operations/ENTRA_VERIFIEDID_RUNBOOK.md rename to archive/quarantined-legacy-stack/docs/operations/ENTRA_VERIFIEDID_RUNBOOK.md diff --git a/docs/reports/AZURE_ENTRA_PREREQUISITES_CHECKLIST.md b/archive/quarantined-legacy-stack/docs/reports/AZURE_ENTRA_PREREQUISITES_CHECKLIST.md similarity index 100% rename from docs/reports/AZURE_ENTRA_PREREQUISITES_CHECKLIST.md rename to archive/quarantined-legacy-stack/docs/reports/AZURE_ENTRA_PREREQUISITES_CHECKLIST.md diff --git a/docs/reports/AZURE_SETUP_COMPLETION.md b/archive/quarantined-legacy-stack/docs/reports/AZURE_SETUP_COMPLETION.md similarity index 100% rename from docs/reports/AZURE_SETUP_COMPLETION.md rename to archive/quarantined-legacy-stack/docs/reports/AZURE_SETUP_COMPLETION.md diff --git a/docs/reports/COMPREHENSIVE_PROJECT_REVIEW.md b/archive/quarantined-legacy-stack/docs/reports/COMPREHENSIVE_PROJECT_REVIEW.md similarity index 100% rename from docs/reports/COMPREHENSIVE_PROJECT_REVIEW.md rename to archive/quarantined-legacy-stack/docs/reports/COMPREHENSIVE_PROJECT_REVIEW.md diff --git a/docs/reports/COMPREHENSIVE_TASK_LIST.md b/archive/quarantined-legacy-stack/docs/reports/COMPREHENSIVE_TASK_LIST.md similarity index 100% rename from docs/reports/COMPREHENSIVE_TASK_LIST.md rename to archive/quarantined-legacy-stack/docs/reports/COMPREHENSIVE_TASK_LIST.md diff --git a/docs/reports/DEPLOYMENT_READINESS_REVIEW.md b/archive/quarantined-legacy-stack/docs/reports/DEPLOYMENT_READINESS_REVIEW.md similarity index 100% rename from docs/reports/DEPLOYMENT_READINESS_REVIEW.md rename to archive/quarantined-legacy-stack/docs/reports/DEPLOYMENT_READINESS_REVIEW.md diff --git a/docs/reports/GOVERNANCE_INTEGRATION_SUMMARY.md b/archive/quarantined-legacy-stack/docs/reports/GOVERNANCE_INTEGRATION_SUMMARY.md similarity index 100% rename from docs/reports/GOVERNANCE_INTEGRATION_SUMMARY.md rename to archive/quarantined-legacy-stack/docs/reports/GOVERNANCE_INTEGRATION_SUMMARY.md diff --git a/docs/reports/IMPLEMENTATION_SUMMARY.md b/archive/quarantined-legacy-stack/docs/reports/IMPLEMENTATION_SUMMARY.md similarity index 100% rename from docs/reports/IMPLEMENTATION_SUMMARY.md rename to archive/quarantined-legacy-stack/docs/reports/IMPLEMENTATION_SUMMARY.md diff --git a/docs/reports/NEXT_STEPS.md b/archive/quarantined-legacy-stack/docs/reports/NEXT_STEPS.md similarity index 100% rename from docs/reports/NEXT_STEPS.md rename to archive/quarantined-legacy-stack/docs/reports/NEXT_STEPS.md diff --git a/docs/reports/PROJECT_STATUS.md b/archive/quarantined-legacy-stack/docs/reports/PROJECT_STATUS.md similarity index 100% rename from docs/reports/PROJECT_STATUS.md rename to archive/quarantined-legacy-stack/docs/reports/PROJECT_STATUS.md diff --git a/docs/reports/QUICK_START_NEXT_STEPS.md b/archive/quarantined-legacy-stack/docs/reports/QUICK_START_NEXT_STEPS.md similarity index 100% rename from docs/reports/QUICK_START_NEXT_STEPS.md rename to archive/quarantined-legacy-stack/docs/reports/QUICK_START_NEXT_STEPS.md diff --git a/docs/reports/REMAINING_STEPS_COMPLETE.md b/archive/quarantined-legacy-stack/docs/reports/REMAINING_STEPS_COMPLETE.md similarity index 100% rename from docs/reports/REMAINING_STEPS_COMPLETE.md rename to archive/quarantined-legacy-stack/docs/reports/REMAINING_STEPS_COMPLETE.md diff --git a/docs/reports/SESSION_SUMMARY.md b/archive/quarantined-legacy-stack/docs/reports/SESSION_SUMMARY.md similarity index 100% rename from docs/reports/SESSION_SUMMARY.md rename to archive/quarantined-legacy-stack/docs/reports/SESSION_SUMMARY.md diff --git a/docs/reports/current-status.md b/archive/quarantined-legacy-stack/docs/reports/current-status.md similarity index 100% rename from docs/reports/current-status.md rename to archive/quarantined-legacy-stack/docs/reports/current-status.md diff --git a/docs/training/ENTRA_VERIFIEDID_TRAINING.md b/archive/quarantined-legacy-stack/docs/training/ENTRA_VERIFIEDID_TRAINING.md similarity index 100% rename from docs/training/ENTRA_VERIFIEDID_TRAINING.md rename to archive/quarantined-legacy-stack/docs/training/ENTRA_VERIFIEDID_TRAINING.md diff --git a/infra/k8s/base/configmap-azure.yaml b/archive/quarantined-legacy-stack/infra/k8s/base/configmap-azure.yaml similarity index 100% rename from infra/k8s/base/configmap-azure.yaml rename to archive/quarantined-legacy-stack/infra/k8s/base/configmap-azure.yaml diff --git a/infra/k8s/base/external-secrets.yaml b/archive/quarantined-legacy-stack/infra/k8s/base/external-secrets.yaml similarity index 100% rename from infra/k8s/base/external-secrets.yaml rename to archive/quarantined-legacy-stack/infra/k8s/base/external-secrets.yaml diff --git a/infra/k8s/identity-service-deployment-entra.yaml b/archive/quarantined-legacy-stack/infra/k8s/identity-service-deployment-entra.yaml similarity index 100% rename from infra/k8s/identity-service-deployment-entra.yaml rename to archive/quarantined-legacy-stack/infra/k8s/identity-service-deployment-entra.yaml diff --git a/infra/k8s/identity-service-entra-secrets.yaml b/archive/quarantined-legacy-stack/infra/k8s/identity-service-entra-secrets.yaml similarity index 100% rename from infra/k8s/identity-service-entra-secrets.yaml rename to archive/quarantined-legacy-stack/infra/k8s/identity-service-entra-secrets.yaml diff --git a/infra/monitoring/grafana-entra-dashboard.json b/archive/quarantined-legacy-stack/infra/monitoring/grafana-entra-dashboard.json similarity index 100% rename from infra/monitoring/grafana-entra-dashboard.json rename to archive/quarantined-legacy-stack/infra/monitoring/grafana-entra-dashboard.json diff --git a/infra/monitoring/prometheus-entra-config.yml b/archive/quarantined-legacy-stack/infra/monitoring/prometheus-entra-config.yml similarity index 100% rename from infra/monitoring/prometheus-entra-config.yml rename to archive/quarantined-legacy-stack/infra/monitoring/prometheus-entra-config.yml diff --git a/infra/scripts/azure-cdn-setup.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-cdn-setup.sh similarity index 100% rename from infra/scripts/azure-cdn-setup.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-cdn-setup.sh diff --git a/infra/scripts/azure-check-cdn-quotas.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-check-cdn-quotas.sh similarity index 100% rename from infra/scripts/azure-check-cdn-quotas.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-check-cdn-quotas.sh diff --git a/infra/scripts/azure-check-quotas.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-check-quotas.sh similarity index 100% rename from infra/scripts/azure-check-quotas.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-check-quotas.sh diff --git a/infra/scripts/azure-complete-setup.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-complete-setup.sh similarity index 100% rename from infra/scripts/azure-complete-setup.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-complete-setup.sh diff --git a/infra/scripts/azure-deploy.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-deploy.sh similarity index 100% rename from infra/scripts/azure-deploy.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-deploy.sh diff --git a/infra/scripts/azure-fix-env-mapping.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-fix-env-mapping.sh similarity index 100% rename from infra/scripts/azure-fix-env-mapping.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-fix-env-mapping.sh diff --git a/infra/scripts/azure-integrate-cdn-env.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-integrate-cdn-env.sh similarity index 100% rename from infra/scripts/azure-integrate-cdn-env.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-integrate-cdn-env.sh diff --git a/infra/scripts/azure-load-env.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-load-env.sh similarity index 100% rename from infra/scripts/azure-load-env.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-load-env.sh diff --git a/infra/scripts/azure-register-providers.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-register-providers.sh similarity index 100% rename from infra/scripts/azure-register-providers.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-register-providers.sh diff --git a/infra/scripts/azure-setup.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-setup.sh similarity index 100% rename from infra/scripts/azure-setup.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-setup.sh diff --git a/infra/scripts/azure-sync-env-to-terraform.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-sync-env-to-terraform.sh similarity index 100% rename from infra/scripts/azure-sync-env-to-terraform.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-sync-env-to-terraform.sh diff --git a/infra/scripts/azure-update-k8s-secrets.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-update-k8s-secrets.sh similarity index 100% rename from infra/scripts/azure-update-k8s-secrets.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-update-k8s-secrets.sh diff --git a/infra/scripts/azure-validate-current-env.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-validate-current-env.sh similarity index 100% rename from infra/scripts/azure-validate-current-env.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-validate-current-env.sh diff --git a/infra/scripts/azure-validate-env.sh b/archive/quarantined-legacy-stack/infra/scripts/azure-validate-env.sh similarity index 100% rename from infra/scripts/azure-validate-env.sh rename to archive/quarantined-legacy-stack/infra/scripts/azure-validate-env.sh diff --git a/infra/scripts/deploy-sovereignty-landing-zone.sh b/archive/quarantined-legacy-stack/infra/scripts/deploy-sovereignty-landing-zone.sh similarity index 100% rename from infra/scripts/deploy-sovereignty-landing-zone.sh rename to archive/quarantined-legacy-stack/infra/scripts/deploy-sovereignty-landing-zone.sh diff --git a/infra/terraform/.gitignore b/archive/quarantined-legacy-stack/infra/terraform/terraform/.gitignore similarity index 100% rename from infra/terraform/.gitignore rename to archive/quarantined-legacy-stack/infra/terraform/terraform/.gitignore diff --git a/infra/terraform/AZURE_RESOURCE_PROVIDERS.md b/archive/quarantined-legacy-stack/infra/terraform/terraform/AZURE_RESOURCE_PROVIDERS.md similarity index 100% rename from infra/terraform/AZURE_RESOURCE_PROVIDERS.md rename to archive/quarantined-legacy-stack/infra/terraform/terraform/AZURE_RESOURCE_PROVIDERS.md diff --git a/infra/terraform/EXECUTION_GUIDE.md b/archive/quarantined-legacy-stack/infra/terraform/terraform/EXECUTION_GUIDE.md similarity index 100% rename from infra/terraform/EXECUTION_GUIDE.md rename to archive/quarantined-legacy-stack/infra/terraform/terraform/EXECUTION_GUIDE.md diff --git a/infra/terraform/NAMING_VALIDATION.md b/archive/quarantined-legacy-stack/infra/terraform/terraform/NAMING_VALIDATION.md similarity index 100% rename from infra/terraform/NAMING_VALIDATION.md rename to archive/quarantined-legacy-stack/infra/terraform/terraform/NAMING_VALIDATION.md diff --git a/infra/terraform/README.md b/archive/quarantined-legacy-stack/infra/terraform/terraform/README.md similarity index 100% rename from infra/terraform/README.md rename to archive/quarantined-legacy-stack/infra/terraform/terraform/README.md diff --git a/infra/terraform/aks.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/aks.tf similarity index 100% rename from infra/terraform/aks.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/aks.tf diff --git a/infra/terraform/azure-provider.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/azure-provider.tf similarity index 100% rename from infra/terraform/azure-provider.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/azure-provider.tf diff --git a/infra/terraform/cdn.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/cdn.tf similarity index 100% rename from infra/terraform/cdn.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/cdn.tf diff --git a/infra/terraform/database.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/database.tf similarity index 100% rename from infra/terraform/database.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/database.tf diff --git a/infra/terraform/key-vault.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/key-vault.tf similarity index 100% rename from infra/terraform/key-vault.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/key-vault.tf diff --git a/infra/terraform/locals.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/locals.tf similarity index 100% rename from infra/terraform/locals.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/locals.tf diff --git a/infra/terraform/main.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/main.tf similarity index 100% rename from infra/terraform/main.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/main.tf diff --git a/infra/terraform/management-groups/main.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/management-groups/main.tf similarity index 100% rename from infra/terraform/management-groups/main.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/management-groups/main.tf diff --git a/infra/terraform/management-groups/variables.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/management-groups/variables.tf similarity index 100% rename from infra/terraform/management-groups/variables.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/management-groups/variables.tf diff --git a/infra/terraform/management-groups/versions.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/management-groups/versions.tf similarity index 100% rename from infra/terraform/management-groups/versions.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/management-groups/versions.tf diff --git a/infra/terraform/modules/regional-landing-zone/README.md b/archive/quarantined-legacy-stack/infra/terraform/terraform/modules/regional-landing-zone/README.md similarity index 100% rename from infra/terraform/modules/regional-landing-zone/README.md rename to archive/quarantined-legacy-stack/infra/terraform/terraform/modules/regional-landing-zone/README.md diff --git a/infra/terraform/modules/regional-landing-zone/main.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/modules/regional-landing-zone/main.tf similarity index 100% rename from infra/terraform/modules/regional-landing-zone/main.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/modules/regional-landing-zone/main.tf diff --git a/infra/terraform/modules/regional-landing-zone/outputs.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/modules/regional-landing-zone/outputs.tf similarity index 100% rename from infra/terraform/modules/regional-landing-zone/outputs.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/modules/regional-landing-zone/outputs.tf diff --git a/infra/terraform/modules/regional-landing-zone/variables.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/modules/regional-landing-zone/variables.tf similarity index 100% rename from infra/terraform/modules/regional-landing-zone/variables.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/modules/regional-landing-zone/variables.tf diff --git a/infra/terraform/modules/regional-landing-zone/versions.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/modules/regional-landing-zone/versions.tf similarity index 100% rename from infra/terraform/modules/regional-landing-zone/versions.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/modules/regional-landing-zone/versions.tf diff --git a/infra/terraform/modules/well-architected/main.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/modules/well-architected/main.tf similarity index 100% rename from infra/terraform/modules/well-architected/main.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/modules/well-architected/main.tf diff --git a/infra/terraform/modules/well-architected/variables.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/modules/well-architected/variables.tf similarity index 100% rename from infra/terraform/modules/well-architected/variables.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/modules/well-architected/variables.tf diff --git a/infra/terraform/multi-region/README.md b/archive/quarantined-legacy-stack/infra/terraform/terraform/multi-region/README.md similarity index 100% rename from infra/terraform/multi-region/README.md rename to archive/quarantined-legacy-stack/infra/terraform/terraform/multi-region/README.md diff --git a/infra/terraform/multi-region/main.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/multi-region/main.tf similarity index 100% rename from infra/terraform/multi-region/main.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/multi-region/main.tf diff --git a/infra/terraform/multi-region/outputs.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/multi-region/outputs.tf similarity index 100% rename from infra/terraform/multi-region/outputs.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/multi-region/outputs.tf diff --git a/infra/terraform/multi-region/variables.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/multi-region/variables.tf similarity index 100% rename from infra/terraform/multi-region/variables.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/multi-region/variables.tf diff --git a/infra/terraform/multi-region/versions.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/multi-region/versions.tf similarity index 100% rename from infra/terraform/multi-region/versions.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/multi-region/versions.tf diff --git a/infra/terraform/outputs-azure.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/outputs-azure.tf similarity index 100% rename from infra/terraform/outputs-azure.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/outputs-azure.tf diff --git a/infra/terraform/outputs.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/outputs.tf similarity index 100% rename from infra/terraform/outputs.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/outputs.tf diff --git a/infra/terraform/policies/main.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/policies/main.tf similarity index 100% rename from infra/terraform/policies/main.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/policies/main.tf diff --git a/infra/terraform/policies/variables.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/policies/variables.tf similarity index 100% rename from infra/terraform/policies/variables.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/policies/variables.tf diff --git a/infra/terraform/policies/versions.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/policies/versions.tf similarity index 100% rename from infra/terraform/policies/versions.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/policies/versions.tf diff --git a/infra/terraform/resource-groups.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/resource-groups.tf similarity index 100% rename from infra/terraform/resource-groups.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/resource-groups.tf diff --git a/infra/terraform/storage.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/storage.tf similarity index 100% rename from infra/terraform/storage.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/storage.tf diff --git a/infra/terraform/terraform.tfvars.example b/archive/quarantined-legacy-stack/infra/terraform/terraform/terraform.tfvars.example similarity index 100% rename from infra/terraform/terraform.tfvars.example rename to archive/quarantined-legacy-stack/infra/terraform/terraform/terraform.tfvars.example diff --git a/infra/terraform/variables.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/variables.tf similarity index 100% rename from infra/terraform/variables.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/variables.tf diff --git a/infra/terraform/versions.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/versions.tf similarity index 100% rename from infra/terraform/versions.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/versions.tf diff --git a/infra/terraform/well-architected/main.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/well-architected/main.tf similarity index 100% rename from infra/terraform/well-architected/main.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/well-architected/main.tf diff --git a/infra/terraform/well-architected/variables.tf b/archive/quarantined-legacy-stack/infra/terraform/terraform/well-architected/variables.tf similarity index 100% rename from infra/terraform/well-architected/variables.tf rename to archive/quarantined-legacy-stack/infra/terraform/terraform/well-architected/variables.tf diff --git a/manifests/entra/README.md b/archive/quarantined-legacy-stack/manifests/entra/README.md similarity index 100% rename from manifests/entra/README.md rename to archive/quarantined-legacy-stack/manifests/entra/README.md diff --git a/manifests/entra/SEAL_MAPPING.md b/archive/quarantined-legacy-stack/manifests/entra/SEAL_MAPPING.md similarity index 100% rename from manifests/entra/SEAL_MAPPING.md rename to archive/quarantined-legacy-stack/manifests/entra/SEAL_MAPPING.md diff --git a/manifests/entra/collect-manifest-ids.sh b/archive/quarantined-legacy-stack/manifests/entra/collect-manifest-ids.sh similarity index 100% rename from manifests/entra/collect-manifest-ids.sh rename to archive/quarantined-legacy-stack/manifests/entra/collect-manifest-ids.sh diff --git a/manifests/entra/default-manifest-template.json b/archive/quarantined-legacy-stack/manifests/entra/default-manifest-template.json similarity index 100% rename from manifests/entra/default-manifest-template.json rename to archive/quarantined-legacy-stack/manifests/entra/default-manifest-template.json diff --git a/manifests/entra/diplomatic-manifest-template.json b/archive/quarantined-legacy-stack/manifests/entra/diplomatic-manifest-template.json similarity index 100% rename from manifests/entra/diplomatic-manifest-template.json rename to archive/quarantined-legacy-stack/manifests/entra/diplomatic-manifest-template.json diff --git a/manifests/entra/financial-manifest-template.json b/archive/quarantined-legacy-stack/manifests/entra/financial-manifest-template.json similarity index 100% rename from manifests/entra/financial-manifest-template.json rename to archive/quarantined-legacy-stack/manifests/entra/financial-manifest-template.json diff --git a/manifests/entra/judicial-manifest-template.json b/archive/quarantined-legacy-stack/manifests/entra/judicial-manifest-template.json similarity index 100% rename from manifests/entra/judicial-manifest-template.json rename to archive/quarantined-legacy-stack/manifests/entra/judicial-manifest-template.json diff --git a/manifests/entra/legal-office-manifest-template.json b/archive/quarantined-legacy-stack/manifests/entra/legal-office-manifest-template.json similarity index 100% rename from manifests/entra/legal-office-manifest-template.json rename to archive/quarantined-legacy-stack/manifests/entra/legal-office-manifest-template.json diff --git a/archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.d.ts b/archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.d.ts new file mode 100644 index 0000000..a492c05 --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.d.ts @@ -0,0 +1,47 @@ +/** + * Azure Logic Apps connector + * Provides integration with Azure Logic Apps for workflow orchestration + */ +export interface LogicAppsConfig { + workflowUrl: string; + accessKey?: string; + managedIdentityClientId?: string; +} +export interface LogicAppsTriggerRequest { + triggerName?: string; + body?: Record; + headers?: Record; +} +export interface LogicAppsResponse { + statusCode: number; + body?: unknown; + headers?: Record; +} +/** + * Azure Logic Apps client + */ +export declare class AzureLogicAppsClient { + private config; + constructor(config: LogicAppsConfig); + /** + * Trigger a Logic App workflow + */ + triggerWorkflow(request: LogicAppsTriggerRequest): Promise; + /** + * Get managed identity token using @azure/identity + */ + private getManagedIdentityToken; + /** + * Trigger workflow for eIDAS verification + */ + triggerEIDASVerification(documentId: string, userId: string, eidasProviderUrl: string): Promise; + /** + * Trigger workflow for VC issuance via Entra VerifiedID + */ + triggerVCIssuance(userId: string, credentialType: string, claims: Record): Promise; + /** + * Trigger workflow for document processing + */ + triggerDocumentProcessing(documentId: string, documentUrl: string, documentType: string): Promise; +} +//# sourceMappingURL=azure-logic-apps.d.ts.map \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.d.ts.map b/archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.d.ts.map new file mode 100644 index 0000000..f882a1a --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.d.ts.map @@ -0,0 +1 @@ +{"version":3,"file":"azure-logic-apps.d.ts","sourceRoot":"","sources":["azure-logic-apps.ts"],"names":[],"mappings":"AAAA;;;GAGG;AAIH,MAAM,WAAW,eAAe;IAC9B,WAAW,EAAE,MAAM,CAAC;IACpB,SAAS,CAAC,EAAE,MAAM,CAAC;IACnB,uBAAuB,CAAC,EAAE,MAAM,CAAC;CAClC;AAED,MAAM,WAAW,uBAAuB;IACtC,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,IAAI,CAAC,EAAE,MAAM,CAAC,MAAM,EAAE,OAAO,CAAC,CAAC;IAC/B,OAAO,CAAC,EAAE,MAAM,CAAC,MAAM,EAAE,MAAM,CAAC,CAAC;CAClC;AAED,MAAM,WAAW,iBAAiB;IAChC,UAAU,EAAE,MAAM,CAAC;IACnB,IAAI,CAAC,EAAE,OAAO,CAAC;IACf,OAAO,CAAC,EAAE,MAAM,CAAC,MAAM,EAAE,MAAM,CAAC,CAAC;CAClC;AAED;;GAEG;AACH,qBAAa,oBAAoB;IACnB,OAAO,CAAC,MAAM;gBAAN,MAAM,EAAE,eAAe;IAE3C;;OAEG;IACG,eAAe,CACnB,OAAO,EAAE,uBAAuB,GAC/B,OAAO,CAAC,iBAAiB,CAAC;IAqC7B;;OAEG;YACW,uBAAuB;IAgBrC;;OAEG;IACG,wBAAwB,CAC5B,UAAU,EAAE,MAAM,EAClB,MAAM,EAAE,MAAM,EACd,gBAAgB,EAAE,MAAM,GACvB,OAAO,CAAC,iBAAiB,CAAC;IAY7B;;OAEG;IACG,iBAAiB,CACrB,MAAM,EAAE,MAAM,EACd,cAAc,EAAE,MAAM,EACtB,MAAM,EAAE,MAAM,CAAC,MAAM,EAAE,MAAM,CAAC,GAC7B,OAAO,CAAC,iBAAiB,CAAC;IAY7B;;OAEG;IACG,yBAAyB,CAC7B,UAAU,EAAE,MAAM,EAClB,WAAW,EAAE,MAAM,EACnB,YAAY,EAAE,MAAM,GACnB,OAAO,CAAC,iBAAiB,CAAC;CAW9B"} \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.js b/archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.js new file mode 100644 index 0000000..a7e23e1 --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.js @@ -0,0 +1,107 @@ +/** + * Azure Logic Apps connector + * Provides integration with Azure Logic Apps for workflow orchestration + */ +import fetch from 'node-fetch'; +/** + * Azure Logic Apps client + */ +export class AzureLogicAppsClient { + config; + constructor(config) { + this.config = config; + } + /** + * Trigger a Logic App workflow + */ + async triggerWorkflow(request) { + const url = this.config.accessKey + ? `${this.config.workflowUrl}?api-version=2016-10-01&sp=/triggers/${request.triggerName || 'manual'}/run&sv=1.0&sig=${this.config.accessKey}` + : `${this.config.workflowUrl}/triggers/${request.triggerName || 'manual'}/run?api-version=2016-10-01`; + const headers = { + 'Content-Type': 'application/json', + ...request.headers, + }; + // If using managed identity, add Authorization header + if (this.config.managedIdentityClientId && !this.config.accessKey) { + // In production, get token from Azure Managed Identity endpoint + // This is a placeholder - actual implementation would use @azure/identity + headers['Authorization'] = `Bearer ${await this.getManagedIdentityToken()}`; + } + const response = await fetch(url, { + method: 'POST', + headers, + body: request.body ? JSON.stringify(request.body) : undefined, + }); + if (!response.ok) { + const errorText = await response.text(); + throw new Error(`Failed to trigger Logic App: ${response.status} ${errorText}`); + } + const responseBody = await response.json().catch(() => ({})); + return { + statusCode: response.status, + body: responseBody, + headers: Object.fromEntries(response.headers.entries()), + }; + } + /** + * Get managed identity token using @azure/identity + */ + async getManagedIdentityToken() { + try { + // Dynamic import to avoid requiring @azure/identity if not using managed identity + const { DefaultAzureCredential } = await import('@azure/identity'); + const credential = new DefaultAzureCredential({ + managedIdentityClientId: this.config.managedIdentityClientId, + }); + const token = await credential.getToken('https://logic.azure.com/.default'); + return token.token; + } + catch (error) { + throw new Error(`Failed to get managed identity token: ${error instanceof Error ? error.message : String(error)}`); + } + } + /** + * Trigger workflow for eIDAS verification + */ + async triggerEIDASVerification(documentId, userId, eidasProviderUrl) { + return this.triggerWorkflow({ + triggerName: 'eidas-verification', + body: { + documentId, + userId, + eidasProviderUrl, + timestamp: new Date().toISOString(), + }, + }); + } + /** + * Trigger workflow for VC issuance via Entra VerifiedID + */ + async triggerVCIssuance(userId, credentialType, claims) { + return this.triggerWorkflow({ + triggerName: 'vc-issuance', + body: { + userId, + credentialType, + claims, + timestamp: new Date().toISOString(), + }, + }); + } + /** + * Trigger workflow for document processing + */ + async triggerDocumentProcessing(documentId, documentUrl, documentType) { + return this.triggerWorkflow({ + triggerName: 'document-processing', + body: { + documentId, + documentUrl, + documentType, + timestamp: new Date().toISOString(), + }, + }); + } +} +//# sourceMappingURL=azure-logic-apps.js.map \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.js.map b/archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.js.map new file mode 100644 index 0000000..afcc477 --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.js.map @@ -0,0 +1 @@ +{"version":3,"file":"azure-logic-apps.js","sourceRoot":"","sources":["azure-logic-apps.ts"],"names":[],"mappings":"AAAA;;;GAGG;AAEH,OAAO,KAAK,MAAM,YAAY,CAAC;AAoB/B;;GAEG;AACH,MAAM,OAAO,oBAAoB;IACX;IAApB,YAAoB,MAAuB;QAAvB,WAAM,GAAN,MAAM,CAAiB;IAAG,CAAC;IAE/C;;OAEG;IACH,KAAK,CAAC,eAAe,CACnB,OAAgC;QAEhC,MAAM,GAAG,GAAG,IAAI,CAAC,MAAM,CAAC,SAAS;YAC/B,CAAC,CAAC,GAAG,IAAI,CAAC,MAAM,CAAC,WAAW,wCAAwC,OAAO,CAAC,WAAW,IAAI,QAAQ,mBAAmB,IAAI,CAAC,MAAM,CAAC,SAAS,EAAE;YAC7I,CAAC,CAAC,GAAG,IAAI,CAAC,MAAM,CAAC,WAAW,aAAa,OAAO,CAAC,WAAW,IAAI,QAAQ,6BAA6B,CAAC;QAExG,MAAM,OAAO,GAA2B;YACtC,cAAc,EAAE,kBAAkB;YAClC,GAAG,OAAO,CAAC,OAAO;SACnB,CAAC;QAEF,sDAAsD;QACtD,IAAI,IAAI,CAAC,MAAM,CAAC,uBAAuB,IAAI,CAAC,IAAI,CAAC,MAAM,CAAC,SAAS,EAAE,CAAC;YAClE,gEAAgE;YAChE,0EAA0E;YAC1E,OAAO,CAAC,eAAe,CAAC,GAAG,UAAU,MAAM,IAAI,CAAC,uBAAuB,EAAE,EAAE,CAAC;QAC9E,CAAC;QAED,MAAM,QAAQ,GAAG,MAAM,KAAK,CAAC,GAAG,EAAE;YAChC,MAAM,EAAE,MAAM;YACd,OAAO;YACP,IAAI,EAAE,OAAO,CAAC,IAAI,CAAC,CAAC,CAAC,IAAI,CAAC,SAAS,CAAC,OAAO,CAAC,IAAI,CAAC,CAAC,CAAC,CAAC,SAAS;SAC9D,CAAC,CAAC;QAEH,IAAI,CAAC,QAAQ,CAAC,EAAE,EAAE,CAAC;YACjB,MAAM,SAAS,GAAG,MAAM,QAAQ,CAAC,IAAI,EAAE,CAAC;YACxC,MAAM,IAAI,KAAK,CAAC,gCAAgC,QAAQ,CAAC,MAAM,IAAI,SAAS,EAAE,CAAC,CAAC;QAClF,CAAC;QAED,MAAM,YAAY,GAAG,MAAM,QAAQ,CAAC,IAAI,EAAE,CAAC,KAAK,CAAC,GAAG,EAAE,CAAC,CAAC,EAAE,CAAC,CAAC,CAAC;QAE7D,OAAO;YACL,UAAU,EAAE,QAAQ,CAAC,MAAM;YAC3B,IAAI,EAAE,YAAY;YAClB,OAAO,EAAE,MAAM,CAAC,WAAW,CAAC,QAAQ,CAAC,OAAO,CAAC,OAAO,EAAE,CAAC;SACxD,CAAC;IACJ,CAAC;IAED;;OAEG;IACK,KAAK,CAAC,uBAAuB;QACnC,IAAI,CAAC;YACH,kFAAkF;YAClF,MAAM,EAAE,sBAAsB,EAAE,GAAG,MAAM,MAAM,CAAC,iBAAiB,CAAC,CAAC;YACnE,MAAM,UAAU,GAAG,IAAI,sBAAsB,CAAC;gBAC5C,uBAAuB,EAAE,IAAI,CAAC,MAAM,CAAC,uBAAuB;aAC7D,CAAC,CAAC;YACH,MAAM,KAAK,GAAG,MAAM,UAAU,CAAC,QAAQ,CAAC,kCAAkC,CAAC,CAAC;YAC5E,OAAO,KAAK,CAAC,KAAK,CAAC;QACrB,CAAC;QAAC,OAAO,KAAK,EAAE,CAAC;YACf,MAAM,IAAI,KAAK,CACb,yCAAyC,KAAK,YAAY,KAAK,CAAC,CAAC,CAAC,KAAK,CAAC,OAAO,CAAC,CAAC,CAAC,MAAM,CAAC,KAAK,CAAC,EAAE,CAClG,CAAC;QACJ,CAAC;IACH,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,wBAAwB,CAC5B,UAAkB,EAClB,MAAc,EACd,gBAAwB;QAExB,OAAO,IAAI,CAAC,eAAe,CAAC;YAC1B,WAAW,EAAE,oBAAoB;YACjC,IAAI,EAAE;gBACJ,UAAU;gBACV,MAAM;gBACN,gBAAgB;gBAChB,SAAS,EAAE,IAAI,IAAI,EAAE,CAAC,WAAW,EAAE;aACpC;SACF,CAAC,CAAC;IACL,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,iBAAiB,CACrB,MAAc,EACd,cAAsB,EACtB,MAA8B;QAE9B,OAAO,IAAI,CAAC,eAAe,CAAC;YAC1B,WAAW,EAAE,aAAa;YAC1B,IAAI,EAAE;gBACJ,MAAM;gBACN,cAAc;gBACd,MAAM;gBACN,SAAS,EAAE,IAAI,IAAI,EAAE,CAAC,WAAW,EAAE;aACpC;SACF,CAAC,CAAC;IACL,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,yBAAyB,CAC7B,UAAkB,EAClB,WAAmB,EACnB,YAAoB;QAEpB,OAAO,IAAI,CAAC,eAAe,CAAC;YAC1B,WAAW,EAAE,qBAAqB;YAClC,IAAI,EAAE;gBACJ,UAAU;gBACV,WAAW;gBACX,YAAY;gBACZ,SAAS,EAAE,IAAI,IAAI,EAAE,CAAC,WAAW,EAAE;aACpC;SACF,CAAC,CAAC;IACL,CAAC;CACF"} \ No newline at end of file diff --git a/packages/auth/src/azure-logic-apps.ts b/archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.ts similarity index 100% rename from packages/auth/src/azure-logic-apps.ts rename to archive/quarantined-legacy-stack/packages/auth/src/azure-logic-apps.ts diff --git a/archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.d.ts b/archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.d.ts new file mode 100644 index 0000000..b6c3a9f --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.d.ts @@ -0,0 +1,69 @@ +/** + * eIDAS to Microsoft Entra VerifiedID Bridge + * Connects eIDAS verification to Microsoft Entra VerifiedID for credential issuance + */ +import { EIDASSignature } from './eidas'; +import { ClaimValue } from './entra-verifiedid'; +import { FileValidationOptions } from './file-utils'; +export interface EIDASToEntraConfig { + entraVerifiedID: { + tenantId: string; + clientId: string; + clientSecret: string; + credentialManifestId: string; + }; + eidas: { + providerUrl: string; + apiKey: string; + }; + logicApps?: { + workflowUrl: string; + accessKey?: string; + managedIdentityClientId?: string; + }; +} +export interface EIDASVerificationResult { + verified: boolean; + eidasSignature?: EIDASSignature; + certificateChain?: string[]; + subject?: string; + issuer?: string; + validityPeriod?: { + notBefore: Date; + notAfter: Date; + }; +} +/** + * Bridge between eIDAS verification and Microsoft Entra VerifiedID issuance + */ +export declare class EIDASToEntraBridge { + private eidasProvider; + private entraClient; + private logicAppsClient?; + constructor(config: EIDASToEntraConfig); + /** + * Verify eIDAS signature and issue credential via Entra VerifiedID + */ + verifyAndIssue(document: string | Buffer, userId: string, userEmail: string, pin?: string, validationOptions?: FileValidationOptions): Promise<{ + verified: boolean; + credentialRequest?: { + requestId: string; + url: string; + qrCode?: string; + }; + errors?: string[]; + }>; + /** + * Verify eIDAS signature only (without issuing credential) + */ + verifyEIDAS(document: string): Promise; + /** + * Issue credential based on verified eIDAS signature + */ + issueCredentialFromEIDAS(eidasVerificationResult: EIDASVerificationResult, userId: string, userEmail: string, additionalClaims?: Record, pin?: string): Promise<{ + requestId: string; + url: string; + qrCode?: string; + }>; +} +//# sourceMappingURL=eidas-entra-bridge.d.ts.map \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.d.ts.map b/archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.d.ts.map new file mode 100644 index 0000000..c992ebb --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.d.ts.map @@ -0,0 +1 @@ +{"version":3,"file":"eidas-entra-bridge.d.ts","sourceRoot":"","sources":["eidas-entra-bridge.ts"],"names":[],"mappings":"AAAA;;;GAGG;AAEH,OAAO,EAAiB,cAAc,EAAE,MAAM,SAAS,CAAC;AACxD,OAAO,EAAsD,UAAU,EAAE,MAAM,oBAAoB,CAAC;AAEpG,OAAO,EAA4D,qBAAqB,EAAE,MAAM,cAAc,CAAC;AAE/G,MAAM,WAAW,kBAAkB;IACjC,eAAe,EAAE;QACf,QAAQ,EAAE,MAAM,CAAC;QACjB,QAAQ,EAAE,MAAM,CAAC;QACjB,YAAY,EAAE,MAAM,CAAC;QACrB,oBAAoB,EAAE,MAAM,CAAC;KAC9B,CAAC;IACF,KAAK,EAAE;QACL,WAAW,EAAE,MAAM,CAAC;QACpB,MAAM,EAAE,MAAM,CAAC;KAChB,CAAC;IACF,SAAS,CAAC,EAAE;QACV,WAAW,EAAE,MAAM,CAAC;QACpB,SAAS,CAAC,EAAE,MAAM,CAAC;QACnB,uBAAuB,CAAC,EAAE,MAAM,CAAC;KAClC,CAAC;CACH;AAED,MAAM,WAAW,uBAAuB;IACtC,QAAQ,EAAE,OAAO,CAAC;IAClB,cAAc,CAAC,EAAE,cAAc,CAAC;IAChC,gBAAgB,CAAC,EAAE,MAAM,EAAE,CAAC;IAC5B,OAAO,CAAC,EAAE,MAAM,CAAC;IACjB,MAAM,CAAC,EAAE,MAAM,CAAC;IAChB,cAAc,CAAC,EAAE;QACf,SAAS,EAAE,IAAI,CAAC;QAChB,QAAQ,EAAE,IAAI,CAAC;KAChB,CAAC;CACH;AAED;;GAEG;AACH,qBAAa,kBAAkB;IAC7B,OAAO,CAAC,aAAa,CAAgB;IACrC,OAAO,CAAC,WAAW,CAAwB;IAC3C,OAAO,CAAC,eAAe,CAAC,CAAuB;gBAEnC,MAAM,EAAE,kBAAkB;IAkBtC;;OAEG;IACG,cAAc,CAClB,QAAQ,EAAE,MAAM,GAAG,MAAM,EACzB,MAAM,EAAE,MAAM,EACd,SAAS,EAAE,MAAM,EACjB,GAAG,CAAC,EAAE,MAAM,EACZ,iBAAiB,CAAC,EAAE,qBAAqB,GACxC,OAAO,CAAC;QACT,QAAQ,EAAE,OAAO,CAAC;QAClB,iBAAiB,CAAC,EAAE;YAClB,SAAS,EAAE,MAAM,CAAC;YAClB,GAAG,EAAE,MAAM,CAAC;YACZ,MAAM,CAAC,EAAE,MAAM,CAAC;SACjB,CAAC;QACF,MAAM,CAAC,EAAE,MAAM,EAAE,CAAC;KACnB,CAAC;IAkGF;;OAEG;IACG,WAAW,CAAC,QAAQ,EAAE,MAAM,GAAG,OAAO,CAAC,uBAAuB,CAAC;IA0BrE;;OAEG;IACG,wBAAwB,CAC5B,uBAAuB,EAAE,uBAAuB,EAChD,MAAM,EAAE,MAAM,EACd,SAAS,EAAE,MAAM,EACjB,gBAAgB,CAAC,EAAE,MAAM,CAAC,MAAM,EAAE,UAAU,CAAC,EAC7C,GAAG,CAAC,EAAE,MAAM,GACX,OAAO,CAAC;QACT,SAAS,EAAE,MAAM,CAAC;QAClB,GAAG,EAAE,MAAM,CAAC;QACZ,MAAM,CAAC,EAAE,MAAM,CAAC;KACjB,CAAC;CA6BH"} \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.js b/archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.js new file mode 100644 index 0000000..08ad3c3 --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.js @@ -0,0 +1,174 @@ +/** + * eIDAS to Microsoft Entra VerifiedID Bridge + * Connects eIDAS verification to Microsoft Entra VerifiedID for credential issuance + */ +import { EIDASProvider } from './eidas'; +import { EntraVerifiedIDClient } from './entra-verifiedid'; +import { AzureLogicAppsClient } from './azure-logic-apps'; +import { validateBase64File, FILE_SIZE_LIMITS, encodeFileToBase64 } from './file-utils'; +/** + * Bridge between eIDAS verification and Microsoft Entra VerifiedID issuance + */ +export class EIDASToEntraBridge { + eidasProvider; + entraClient; + logicAppsClient; + constructor(config) { + this.eidasProvider = new EIDASProvider({ + providerUrl: config.eidas.providerUrl, + apiKey: config.eidas.apiKey, + }); + this.entraClient = new EntraVerifiedIDClient({ + tenantId: config.entraVerifiedID.tenantId, + clientId: config.entraVerifiedID.clientId, + clientSecret: config.entraVerifiedID.clientSecret, + credentialManifestId: config.entraVerifiedID.credentialManifestId, + }); + if (config.logicApps) { + this.logicAppsClient = new AzureLogicAppsClient(config.logicApps); + } + } + /** + * Verify eIDAS signature and issue credential via Entra VerifiedID + */ + async verifyAndIssue(document, userId, userEmail, pin, validationOptions) { + // Step 0: Validate and encode document if needed + let documentBase64; + if (document instanceof Buffer) { + // Encode buffer to base64 + documentBase64 = encodeFileToBase64(document); + } + else { + // Validate base64 string + const validation = validateBase64File(document, validationOptions || { + maxSize: FILE_SIZE_LIMITS.MEDIUM, + allowedMimeTypes: [ + 'application/pdf', + 'image/png', + 'image/jpeg', + 'application/json', + 'text/plain', + ], + }); + if (!validation.valid) { + return { + verified: false, + errors: validation.errors, + }; + } + documentBase64 = document; + } + // Step 1: Request eIDAS signature + let eidasSignature; + try { + eidasSignature = await this.eidasProvider.requestSignature(documentBase64); + } + catch (error) { + const errorMessage = error instanceof Error ? error.message : String(error); + console.error('eIDAS signature request failed:', errorMessage); + return { + verified: false, + errors: [`eIDAS signature request failed: ${errorMessage}`], + }; + } + // Step 2: Verify eIDAS signature + const verified = await this.eidasProvider.verifySignature(eidasSignature); + if (!verified) { + return { + verified: false, + errors: ['eIDAS signature verification failed'], + }; + } + // Step 3: Trigger Logic App workflow if configured + if (this.logicAppsClient) { + try { + const documentId = document instanceof Buffer ? document.toString('base64').substring(0, 100) : document.substring(0, 100); + await this.logicAppsClient.triggerEIDASVerification(documentId, userId, this.eidasProvider['config'].providerUrl); + } + catch (error) { + console.warn('Logic App trigger failed (non-blocking):', error); + } + } + // Step 4: Issue credential via Entra VerifiedID + const credentialRequest = { + claims: { + email: userEmail, + userId, + eidasVerified: true, // Boolean value (will be converted to string) + eidasCertificate: eidasSignature.certificate, + eidasSignatureTimestamp: eidasSignature.timestamp.toISOString(), + }, + pin, + }; + try { + const credentialResponse = await this.entraClient.issueCredential(credentialRequest); + return { + verified: true, + credentialRequest: { + requestId: credentialResponse.requestId, + url: credentialResponse.url, + qrCode: credentialResponse.qrCode, + }, + }; + } + catch (error) { + console.error('Entra VerifiedID credential issuance failed:', error); + return { verified: true }; // eIDAS verified but credential issuance failed + } + } + /** + * Verify eIDAS signature only (without issuing credential) + */ + async verifyEIDAS(document) { + try { + const signature = await this.eidasProvider.requestSignature(document); + const verified = await this.eidasProvider.verifySignature(signature); + if (!verified) { + return { verified: false }; + } + // Extract certificate information (simplified - in production parse certificate) + return { + verified: true, + eidasSignature: signature, + subject: 'eIDAS Subject', // Would be extracted from certificate + issuer: 'eIDAS Issuer', // Would be extracted from certificate + validityPeriod: { + notBefore: signature.timestamp, + notAfter: new Date(signature.timestamp.getTime() + 365 * 24 * 60 * 60 * 1000), // 1 year default + }, + }; + } + catch (error) { + console.error('eIDAS verification failed:', error); + return { verified: false }; + } + } + /** + * Issue credential based on verified eIDAS signature + */ + async issueCredentialFromEIDAS(eidasVerificationResult, userId, userEmail, additionalClaims, pin) { + if (!eidasVerificationResult.verified || !eidasVerificationResult.eidasSignature) { + throw new Error('eIDAS verification must be successful before issuing credential'); + } + const claims = { + email: userEmail, + userId, + eidasVerified: true, // Boolean value (will be converted to string) + eidasCertificate: eidasVerificationResult.eidasSignature.certificate, + eidasSignatureTimestamp: eidasVerificationResult.eidasSignature.timestamp.toISOString(), + ...additionalClaims, + }; + if (eidasVerificationResult.subject) { + claims.eidasSubject = eidasVerificationResult.subject; + } + if (eidasVerificationResult.issuer) { + claims.eidasIssuer = eidasVerificationResult.issuer; + } + const credentialRequest = { + claims, + pin, + }; + return await this.entraClient.issueCredential(credentialRequest); + } +} +//# sourceMappingURL=eidas-entra-bridge.js.map \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.js.map b/archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.js.map new file mode 100644 index 0000000..d0624af --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.js.map @@ -0,0 +1 @@ +{"version":3,"file":"eidas-entra-bridge.js","sourceRoot":"","sources":["eidas-entra-bridge.ts"],"names":[],"mappings":"AAAA;;;GAGG;AAEH,OAAO,EAAE,aAAa,EAAkB,MAAM,SAAS,CAAC;AACxD,OAAO,EAAE,qBAAqB,EAA2C,MAAM,oBAAoB,CAAC;AACpG,OAAO,EAAE,oBAAoB,EAAE,MAAM,oBAAoB,CAAC;AAC1D,OAAO,EAAE,kBAAkB,EAAE,gBAAgB,EAAE,kBAAkB,EAAyB,MAAM,cAAc,CAAC;AAgC/G;;GAEG;AACH,MAAM,OAAO,kBAAkB;IACrB,aAAa,CAAgB;IAC7B,WAAW,CAAwB;IACnC,eAAe,CAAwB;IAE/C,YAAY,MAA0B;QACpC,IAAI,CAAC,aAAa,GAAG,IAAI,aAAa,CAAC;YACrC,WAAW,EAAE,MAAM,CAAC,KAAK,CAAC,WAAW;YACrC,MAAM,EAAE,MAAM,CAAC,KAAK,CAAC,MAAM;SAC5B,CAAC,CAAC;QAEH,IAAI,CAAC,WAAW,GAAG,IAAI,qBAAqB,CAAC;YAC3C,QAAQ,EAAE,MAAM,CAAC,eAAe,CAAC,QAAQ;YACzC,QAAQ,EAAE,MAAM,CAAC,eAAe,CAAC,QAAQ;YACzC,YAAY,EAAE,MAAM,CAAC,eAAe,CAAC,YAAY;YACjD,oBAAoB,EAAE,MAAM,CAAC,eAAe,CAAC,oBAAoB;SAClE,CAAC,CAAC;QAEH,IAAI,MAAM,CAAC,SAAS,EAAE,CAAC;YACrB,IAAI,CAAC,eAAe,GAAG,IAAI,oBAAoB,CAAC,MAAM,CAAC,SAAS,CAAC,CAAC;QACpE,CAAC;IACH,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,cAAc,CAClB,QAAyB,EACzB,MAAc,EACd,SAAiB,EACjB,GAAY,EACZ,iBAAyC;QAUzC,iDAAiD;QACjD,IAAI,cAAsB,CAAC;QAE3B,IAAI,QAAQ,YAAY,MAAM,EAAE,CAAC;YAC/B,0BAA0B;YAC1B,cAAc,GAAG,kBAAkB,CAAC,QAAQ,CAAC,CAAC;QAChD,CAAC;aAAM,CAAC;YACN,yBAAyB;YACzB,MAAM,UAAU,GAAG,kBAAkB,CACnC,QAAkB,EAClB,iBAAiB,IAAI;gBACnB,OAAO,EAAE,gBAAgB,CAAC,MAAM;gBAChC,gBAAgB,EAAE;oBAChB,iBAAiB;oBACjB,WAAW;oBACX,YAAY;oBACZ,kBAAkB;oBAClB,YAAY;iBACb;aACF,CACF,CAAC;YAEF,IAAI,CAAC,UAAU,CAAC,KAAK,EAAE,CAAC;gBACtB,OAAO;oBACL,QAAQ,EAAE,KAAK;oBACf,MAAM,EAAE,UAAU,CAAC,MAAM;iBAC1B,CAAC;YACJ,CAAC;YAED,cAAc,GAAG,QAAkB,CAAC;QACtC,CAAC;QAED,kCAAkC;QAClC,IAAI,cAA8B,CAAC;QACnC,IAAI,CAAC;YACH,cAAc,GAAG,MAAM,IAAI,CAAC,aAAa,CAAC,gBAAgB,CAAC,cAAc,CAAC,CAAC;QAC7E,CAAC;QAAC,OAAO,KAAK,EAAE,CAAC;YACf,MAAM,YAAY,GAAG,KAAK,YAAY,KAAK,CAAC,CAAC,CAAC,KAAK,CAAC,OAAO,CAAC,CAAC,CAAC,MAAM,CAAC,KAAK,CAAC,CAAC;YAC5E,OAAO,CAAC,KAAK,CAAC,iCAAiC,EAAE,YAAY,CAAC,CAAC;YAC/D,OAAO;gBACL,QAAQ,EAAE,KAAK;gBACf,MAAM,EAAE,CAAC,mCAAmC,YAAY,EAAE,CAAC;aAC5D,CAAC;QACJ,CAAC;QAED,iCAAiC;QACjC,MAAM,QAAQ,GAAG,MAAM,IAAI,CAAC,aAAa,CAAC,eAAe,CAAC,cAAc,CAAC,CAAC;QAC1E,IAAI,CAAC,QAAQ,EAAE,CAAC;YACd,OAAO;gBACL,QAAQ,EAAE,KAAK;gBACf,MAAM,EAAE,CAAC,qCAAqC,CAAC;aAChD,CAAC;QACJ,CAAC;QAED,mDAAmD;QACnD,IAAI,IAAI,CAAC,eAAe,EAAE,CAAC;YACzB,IAAI,CAAC;gBACH,MAAM,UAAU,GAAG,QAAQ,YAAY,MAAM,CAAC,CAAC,CAAC,QAAQ,CAAC,QAAQ,CAAC,QAAQ,CAAC,CAAC,SAAS,CAAC,CAAC,EAAE,GAAG,CAAC,CAAC,CAAC,CAAE,QAAmB,CAAC,SAAS,CAAC,CAAC,EAAE,GAAG,CAAC,CAAC;gBACvI,MAAM,IAAI,CAAC,eAAe,CAAC,wBAAwB,CACjD,UAAU,EACV,MAAM,EACN,IAAI,CAAC,aAAa,CAAC,QAAQ,CAAC,CAAC,WAAW,CACzC,CAAC;YACJ,CAAC;YAAC,OAAO,KAAK,EAAE,CAAC;gBACf,OAAO,CAAC,IAAI,CAAC,0CAA0C,EAAE,KAAK,CAAC,CAAC;YAClE,CAAC;QACH,CAAC;QAED,gDAAgD;QAChD,MAAM,iBAAiB,GAAgC;YACrD,MAAM,EAAE;gBACN,KAAK,EAAE,SAAS;gBAChB,MAAM;gBACN,aAAa,EAAE,IAAI,EAAE,8CAA8C;gBACnE,gBAAgB,EAAE,cAAc,CAAC,WAAW;gBAC5C,uBAAuB,EAAE,cAAc,CAAC,SAAS,CAAC,WAAW,EAAE;aAChE;YACD,GAAG;SACJ,CAAC;QAEF,IAAI,CAAC;YACH,MAAM,kBAAkB,GAAG,MAAM,IAAI,CAAC,WAAW,CAAC,eAAe,CAAC,iBAAiB,CAAC,CAAC;YAErF,OAAO;gBACL,QAAQ,EAAE,IAAI;gBACd,iBAAiB,EAAE;oBACjB,SAAS,EAAE,kBAAkB,CAAC,SAAS;oBACvC,GAAG,EAAE,kBAAkB,CAAC,GAAG;oBAC3B,MAAM,EAAE,kBAAkB,CAAC,MAAM;iBAClC;aACF,CAAC;QACJ,CAAC;QAAC,OAAO,KAAK,EAAE,CAAC;YACf,OAAO,CAAC,KAAK,CAAC,8CAA8C,EAAE,KAAK,CAAC,CAAC;YACrE,OAAO,EAAE,QAAQ,EAAE,IAAI,EAAE,CAAC,CAAC,gDAAgD;QAC7E,CAAC;IACH,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,WAAW,CAAC,QAAgB;QAChC,IAAI,CAAC;YACH,MAAM,SAAS,GAAG,MAAM,IAAI,CAAC,aAAa,CAAC,gBAAgB,CAAC,QAAQ,CAAC,CAAC;YACtE,MAAM,QAAQ,GAAG,MAAM,IAAI,CAAC,aAAa,CAAC,eAAe,CAAC,SAAS,CAAC,CAAC;YAErE,IAAI,CAAC,QAAQ,EAAE,CAAC;gBACd,OAAO,EAAE,QAAQ,EAAE,KAAK,EAAE,CAAC;YAC7B,CAAC;YAED,iFAAiF;YACjF,OAAO;gBACL,QAAQ,EAAE,IAAI;gBACd,cAAc,EAAE,SAAS;gBACzB,OAAO,EAAE,eAAe,EAAE,sCAAsC;gBAChE,MAAM,EAAE,cAAc,EAAE,sCAAsC;gBAC9D,cAAc,EAAE;oBACd,SAAS,EAAE,SAAS,CAAC,SAAS;oBAC9B,QAAQ,EAAE,IAAI,IAAI,CAAC,SAAS,CAAC,SAAS,CAAC,OAAO,EAAE,GAAG,GAAG,GAAG,EAAE,GAAG,EAAE,GAAG,EAAE,GAAG,IAAI,CAAC,EAAE,iBAAiB;iBACjG;aACF,CAAC;QACJ,CAAC;QAAC,OAAO,KAAK,EAAE,CAAC;YACf,OAAO,CAAC,KAAK,CAAC,4BAA4B,EAAE,KAAK,CAAC,CAAC;YACnD,OAAO,EAAE,QAAQ,EAAE,KAAK,EAAE,CAAC;QAC7B,CAAC;IACH,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,wBAAwB,CAC5B,uBAAgD,EAChD,MAAc,EACd,SAAiB,EACjB,gBAA6C,EAC7C,GAAY;QAMZ,IAAI,CAAC,uBAAuB,CAAC,QAAQ,IAAI,CAAC,uBAAuB,CAAC,cAAc,EAAE,CAAC;YACjF,MAAM,IAAI,KAAK,CAAC,iEAAiE,CAAC,CAAC;QACrF,CAAC;QAED,MAAM,MAAM,GAA+B;YACzC,KAAK,EAAE,SAAS;YAChB,MAAM;YACN,aAAa,EAAE,IAAI,EAAE,8CAA8C;YACnE,gBAAgB,EAAE,uBAAuB,CAAC,cAAc,CAAC,WAAW;YACpE,uBAAuB,EAAE,uBAAuB,CAAC,cAAc,CAAC,SAAS,CAAC,WAAW,EAAE;YACvF,GAAG,gBAAgB;SACpB,CAAC;QAEF,IAAI,uBAAuB,CAAC,OAAO,EAAE,CAAC;YACpC,MAAM,CAAC,YAAY,GAAG,uBAAuB,CAAC,OAAO,CAAC;QACxD,CAAC;QAED,IAAI,uBAAuB,CAAC,MAAM,EAAE,CAAC;YACnC,MAAM,CAAC,WAAW,GAAG,uBAAuB,CAAC,MAAM,CAAC;QACtD,CAAC;QAED,MAAM,iBAAiB,GAAgC;YACrD,MAAM;YACN,GAAG;SACJ,CAAC;QAEF,OAAO,MAAM,IAAI,CAAC,WAAW,CAAC,eAAe,CAAC,iBAAiB,CAAC,CAAC;IACnE,CAAC;CACF"} \ No newline at end of file diff --git a/packages/auth/src/eidas-entra-bridge.ts b/archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.ts similarity index 100% rename from packages/auth/src/eidas-entra-bridge.ts rename to archive/quarantined-legacy-stack/packages/auth/src/eidas-entra-bridge.ts diff --git a/archive/quarantined-legacy-stack/packages/auth/src/entra-credential-images.d.ts b/archive/quarantined-legacy-stack/packages/auth/src/entra-credential-images.d.ts new file mode 100644 index 0000000..1d5f6af --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/entra-credential-images.d.ts @@ -0,0 +1,58 @@ +/** + * Credential Image/Logo Management for Entra VerifiedID + * Handles image conversion and validation for credential display + */ +export interface CredentialImageConfig { + logoUri?: string; + backgroundColor?: string; + textColor?: string; + description?: string; +} +export interface ImageFormat { + format: 'svg' | 'png' | 'jpg' | 'jpeg' | 'bmp'; + data: string | Buffer; + mimeType: string; +} +/** + * Supported image formats for Entra VerifiedID + * Note: Entra VerifiedID officially supports PNG, JPG, BMP + * SVG may work but PNG is recommended for compatibility + */ +export declare const SUPPORTED_FORMATS: readonly ["png", "jpg", "jpeg", "bmp", "svg"]; +export type SupportedFormat = typeof SUPPORTED_FORMATS[number]; +/** + * Validate image format + */ +export declare function validateImageFormat(format: string): format is SupportedFormat; +/** + * Get MIME type for image format + */ +export declare function getImageMimeType(format: SupportedFormat): string; +/** + * Convert SVG to PNG (if needed for Entra compatibility) + * Note: This requires additional dependencies like sharp or svg2png + */ +export declare function convertSvgToPng(svgData: string | Buffer, width?: number, height?: number): Promise; +/** + * Prepare image for Entra VerifiedID + * Converts SVG to PNG if needed, validates format + */ +export declare function prepareCredentialImage(imageData: string | Buffer, format?: SupportedFormat): Promise<{ + data: Buffer; + mimeType: string; + format: SupportedFormat; +}>; +/** + * Create data URL from image + */ +export declare function createImageDataUrl(imageData: Buffer, mimeType: string): string; +/** + * Get recommended image specifications for Entra VerifiedID + */ +export declare function getRecommendedImageSpecs(): { + format: 'png' | 'jpg'; + width: number; + height: number; + maxSizeKB: number; +}; +//# sourceMappingURL=entra-credential-images.d.ts.map \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/auth/src/entra-credential-images.d.ts.map b/archive/quarantined-legacy-stack/packages/auth/src/entra-credential-images.d.ts.map new file mode 100644 index 0000000..96e15f6 --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/entra-credential-images.d.ts.map @@ -0,0 +1 @@ +{"version":3,"file":"entra-credential-images.d.ts","sourceRoot":"","sources":["entra-credential-images.ts"],"names":[],"mappings":"AAAA;;;GAGG;AAEH,MAAM,WAAW,qBAAqB;IACpC,OAAO,CAAC,EAAE,MAAM,CAAC;IACjB,eAAe,CAAC,EAAE,MAAM,CAAC;IACzB,SAAS,CAAC,EAAE,MAAM,CAAC;IACnB,WAAW,CAAC,EAAE,MAAM,CAAC;CACtB;AAED,MAAM,WAAW,WAAW;IAC1B,MAAM,EAAE,KAAK,GAAG,KAAK,GAAG,KAAK,GAAG,MAAM,GAAG,KAAK,CAAC;IAC/C,IAAI,EAAE,MAAM,GAAG,MAAM,CAAC;IACtB,QAAQ,EAAE,MAAM,CAAC;CAClB;AAED;;;;GAIG;AACH,eAAO,MAAM,iBAAiB,+CAAgD,CAAC;AAC/E,MAAM,MAAM,eAAe,GAAG,OAAO,iBAAiB,CAAC,MAAM,CAAC,CAAC;AAE/D;;GAEG;AACH,wBAAgB,mBAAmB,CAAC,MAAM,EAAE,MAAM,GAAG,MAAM,IAAI,eAAe,CAE7E;AAED;;GAEG;AACH,wBAAgB,gBAAgB,CAAC,MAAM,EAAE,eAAe,GAAG,MAAM,CAShE;AAED;;;GAGG;AACH,wBAAsB,eAAe,CACnC,OAAO,EAAE,MAAM,GAAG,MAAM,EACxB,KAAK,GAAE,MAAY,EACnB,MAAM,GAAE,MAAY,GACnB,OAAO,CAAC,MAAM,CAAC,CAiBjB;AAED;;;GAGG;AACH,wBAAsB,sBAAsB,CAC1C,SAAS,EAAE,MAAM,GAAG,MAAM,EAC1B,MAAM,CAAC,EAAE,eAAe,GACvB,OAAO,CAAC;IACT,IAAI,EAAE,MAAM,CAAC;IACb,QAAQ,EAAE,MAAM,CAAC;IACjB,MAAM,EAAE,eAAe,CAAC;CACzB,CAAC,CAuED;AAED;;GAEG;AACH,wBAAgB,kBAAkB,CAAC,SAAS,EAAE,MAAM,EAAE,QAAQ,EAAE,MAAM,GAAG,MAAM,CAG9E;AAED;;GAEG;AACH,wBAAgB,wBAAwB,IAAI;IAC1C,MAAM,EAAE,KAAK,GAAG,KAAK,CAAC;IACtB,KAAK,EAAE,MAAM,CAAC;IACd,MAAM,EAAE,MAAM,CAAC;IACf,SAAS,EAAE,MAAM,CAAC;CACnB,CAOA"} \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/auth/src/entra-credential-images.js b/archive/quarantined-legacy-stack/packages/auth/src/entra-credential-images.js new file mode 100644 index 0000000..ea4b9b9 --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/entra-credential-images.js @@ -0,0 +1,152 @@ +/** + * Credential Image/Logo Management for Entra VerifiedID + * Handles image conversion and validation for credential display + */ +/** + * Supported image formats for Entra VerifiedID + * Note: Entra VerifiedID officially supports PNG, JPG, BMP + * SVG may work but PNG is recommended for compatibility + */ +export const SUPPORTED_FORMATS = ['png', 'jpg', 'jpeg', 'bmp', 'svg']; +/** + * Validate image format + */ +export function validateImageFormat(format) { + return SUPPORTED_FORMATS.includes(format.toLowerCase()); +} +/** + * Get MIME type for image format + */ +export function getImageMimeType(format) { + const mimeTypes = { + svg: 'image/svg+xml', + png: 'image/png', + jpg: 'image/jpeg', + jpeg: 'image/jpeg', + bmp: 'image/bmp', + }; + return mimeTypes[format] || 'image/png'; +} +/** + * Convert SVG to PNG (if needed for Entra compatibility) + * Note: This requires additional dependencies like sharp or svg2png + */ +export async function convertSvgToPng(svgData, width = 200, height = 200) { + // Check if sharp is available (optional dependency) + try { + // eslint-disable-next-line @typescript-eslint/no-require-imports + const sharp = require('sharp'); + const svgBuffer = typeof svgData === 'string' ? Buffer.from(svgData) : svgData; + return await sharp(svgBuffer) + .resize(width, height) + .png() + .toBuffer(); + } + catch (error) { + // If sharp is not available, return original SVG + // Note: Entra may accept SVG, but PNG is recommended + console.warn('sharp not available, using SVG directly (may not be supported by Entra)'); + return typeof svgData === 'string' ? Buffer.from(svgData) : svgData; + } +} +/** + * Prepare image for Entra VerifiedID + * Converts SVG to PNG if needed, validates format + */ +export async function prepareCredentialImage(imageData, format) { + let imageBuffer; + let detectedFormat; + let mimeType; + // Detect format if not provided + if (!format) { + if (typeof imageData === 'string') { + // Check if it's a data URL + if (imageData.startsWith('data:')) { + const match = imageData.match(/data:image\/([^;]+)/); + detectedFormat = (match?.[1]?.toLowerCase() || 'png'); + } + else if (imageData.trim().startsWith('; +} +/** + * Enhanced Entra VerifiedID client with retry logic and multi-manifest support + */ +export declare class EnhancedEntraVerifiedIDClient extends EntraVerifiedIDClient { + private retryConfig; + private manifests; + constructor(config: MultiManifestConfig, retryConfig?: RetryConfig); + /** + * Get manifest ID by name, fallback to default + */ + private getManifestId; + /** + * Execute a request with retry logic + */ + private executeWithRetry; + /** + * Issue credential with retry logic and manifest selection + */ + issueCredential(request: VerifiableCredentialRequest & { + manifestName?: string; + }): Promise; + /** + * Get issuance status with retry logic + */ + getIssuanceStatus(requestId: string): Promise; + /** + * Verify credential with retry logic + */ + verifyCredential(credential: VerifiedCredential): Promise; + /** + * Create presentation request with retry logic and manifest selection + */ + createPresentationRequest(manifestName?: string, callbackUrl?: string): Promise; + /** + * Register a new manifest + */ + registerManifest(name: string, manifestId: string): void; + /** + * Get all registered manifests + */ + getManifests(): Record; +} +//# sourceMappingURL=entra-verifiedid-enhanced.d.ts.map \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.d.ts.map b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.d.ts.map new file mode 100644 index 0000000..8fa28b5 --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.d.ts.map @@ -0,0 +1 @@ +{"version":3,"file":"entra-verifiedid-enhanced.d.ts","sourceRoot":"","sources":["entra-verifiedid-enhanced.ts"],"names":[],"mappings":"AAAA;;;GAGG;AAEH,OAAO,EAAE,qBAAqB,EAAE,qBAAqB,EAAE,2BAA2B,EAAE,4BAA4B,EAAE,0BAA0B,EAAE,kBAAkB,EAAE,MAAM,oBAAoB,CAAC;AAE7L,MAAM,WAAW,WAAW;IAC1B,UAAU,CAAC,EAAE,MAAM,CAAC;IACpB,cAAc,CAAC,EAAE,MAAM,CAAC;IACxB,UAAU,CAAC,EAAE,MAAM,CAAC;IACpB,iBAAiB,CAAC,EAAE,MAAM,CAAC;IAC3B,oBAAoB,CAAC,EAAE,MAAM,EAAE,CAAC;CACjC;AAED,MAAM,WAAW,mBAAoB,SAAQ,qBAAqB;IAChE,SAAS,CAAC,EAAE,MAAM,CAAC,MAAM,EAAE,MAAM,CAAC,CAAC;CACpC;AAwBD;;GAEG;AACH,qBAAa,6BAA8B,SAAQ,qBAAqB;IACtE,OAAO,CAAC,WAAW,CAAwB;IAC3C,OAAO,CAAC,SAAS,CAAyB;gBAE9B,MAAM,EAAE,mBAAmB,EAAE,WAAW,CAAC,EAAE,WAAW;IAUlE;;OAEG;IACH,OAAO,CAAC,aAAa;IAUrB;;OAEG;YACW,gBAAgB;IA+B9B;;OAEG;IACG,eAAe,CACnB,OAAO,EAAE,2BAA2B,GAAG;QAAE,YAAY,CAAC,EAAE,MAAM,CAAA;KAAE,GAC/D,OAAO,CAAC,4BAA4B,CAAC;IAqBxC;;OAEG;IACG,iBAAiB,CAAC,SAAS,EAAE,MAAM,GAAG,OAAO,CAAC,0BAA0B,CAAC;IAO/E;;OAEG;IACG,gBAAgB,CAAC,UAAU,EAAE,kBAAkB,GAAG,OAAO,CAAC,OAAO,CAAC;IAOxE;;OAEG;IACG,yBAAyB,CAC7B,YAAY,CAAC,EAAE,MAAM,EACrB,WAAW,CAAC,EAAE,MAAM,GACnB,OAAO,CAAC,4BAA4B,CAAC;IAQxC;;OAEG;IACH,gBAAgB,CAAC,IAAI,EAAE,MAAM,EAAE,UAAU,EAAE,MAAM,GAAG,IAAI;IAIxD;;OAEG;IACH,YAAY,IAAI,MAAM,CAAC,MAAM,EAAE,MAAM,CAAC;CAGvC"} \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.js b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.js new file mode 100644 index 0000000..676f690 --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.js @@ -0,0 +1,128 @@ +/** + * Enhanced Microsoft Entra VerifiedID connector + * Adds retry logic, multi-manifest support, and improved error handling + */ +import { EntraVerifiedIDClient } from './entra-verifiedid'; +const DEFAULT_RETRY_CONFIG = { + maxRetries: 3, + initialDelayMs: 1000, + maxDelayMs: 10000, + backoffMultiplier: 2, + retryableStatusCodes: [429, 500, 502, 503, 504], +}; +/** + * Sleep utility for retry delays + */ +function sleep(ms) { + return new Promise((resolve) => setTimeout(resolve, ms)); +} +/** + * Check if an error is retryable + */ +function isRetryableError(statusCode, retryableStatusCodes) { + return retryableStatusCodes.includes(statusCode); +} +/** + * Enhanced Entra VerifiedID client with retry logic and multi-manifest support + */ +export class EnhancedEntraVerifiedIDClient extends EntraVerifiedIDClient { + retryConfig; + manifests; + constructor(config, retryConfig) { + super(config); + this.retryConfig = { ...DEFAULT_RETRY_CONFIG, ...retryConfig }; + this.manifests = config.manifests || {}; + // Add default manifest if provided + if (config.credentialManifestId) { + this.manifests['default'] = config.credentialManifestId; + } + } + /** + * Get manifest ID by name, fallback to default + */ + getManifestId(manifestName) { + if (manifestName && this.manifests[manifestName]) { + return this.manifests[manifestName]; + } + if (this.manifests['default']) { + return this.manifests['default']; + } + throw new Error('No credential manifest ID configured'); + } + /** + * Execute a request with retry logic + */ + async executeWithRetry(operation, operationName) { + let lastError = null; + let delay = this.retryConfig.initialDelayMs; + for (let attempt = 0; attempt <= this.retryConfig.maxRetries; attempt++) { + try { + return await operation(); + } + catch (error) { + lastError = error instanceof Error ? error : new Error(String(error)); + // Check if error is retryable + const statusCode = error?.statusCode || error?.response?.status; + const isRetryable = statusCode && isRetryableError(statusCode, this.retryConfig.retryableStatusCodes); + // Don't retry on last attempt or if error is not retryable + if (attempt === this.retryConfig.maxRetries || !isRetryable) { + throw lastError; + } + // Wait before retrying + await sleep(Math.min(delay, this.retryConfig.maxDelayMs)); + delay *= this.retryConfig.backoffMultiplier; + } + } + throw lastError || new Error(`${operationName} failed after ${this.retryConfig.maxRetries} retries`); + } + /** + * Issue credential with retry logic and manifest selection + */ + async issueCredential(request) { + const manifestId = this.getManifestId(request.manifestName); + // Create a modified request without manifestName + const { manifestName, ...credentialRequest } = request; + // Temporarily set manifest ID for this request + const originalManifestId = this.config.credentialManifestId; + this.config.credentialManifestId = manifestId; + try { + return await this.executeWithRetry(() => super.issueCredential(credentialRequest), 'issueCredential'); + } + finally { + // Restore original manifest ID + this.config.credentialManifestId = originalManifestId; + } + } + /** + * Get issuance status with retry logic + */ + async getIssuanceStatus(requestId) { + return this.executeWithRetry(() => super.getIssuanceStatus(requestId), 'getIssuanceStatus'); + } + /** + * Verify credential with retry logic + */ + async verifyCredential(credential) { + return this.executeWithRetry(() => super.verifyCredential(credential), 'verifyCredential'); + } + /** + * Create presentation request with retry logic and manifest selection + */ + async createPresentationRequest(manifestName, callbackUrl) { + const manifestId = this.getManifestId(manifestName); + return this.executeWithRetry(() => super.createPresentationRequest(manifestId, callbackUrl), 'createPresentationRequest'); + } + /** + * Register a new manifest + */ + registerManifest(name, manifestId) { + this.manifests[name] = manifestId; + } + /** + * Get all registered manifests + */ + getManifests() { + return { ...this.manifests }; + } +} +//# sourceMappingURL=entra-verifiedid-enhanced.js.map \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.js.map b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.js.map new file mode 100644 index 0000000..1750c9e --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.js.map @@ -0,0 +1 @@ +{"version":3,"file":"entra-verifiedid-enhanced.js","sourceRoot":"","sources":["entra-verifiedid-enhanced.ts"],"names":[],"mappings":"AAAA;;;GAGG;AAEH,OAAO,EAAE,qBAAqB,EAAoI,MAAM,oBAAoB,CAAC;AAc7L,MAAM,oBAAoB,GAA0B;IAClD,UAAU,EAAE,CAAC;IACb,cAAc,EAAE,IAAI;IACpB,UAAU,EAAE,KAAK;IACjB,iBAAiB,EAAE,CAAC;IACpB,oBAAoB,EAAE,CAAC,GAAG,EAAE,GAAG,EAAE,GAAG,EAAE,GAAG,EAAE,GAAG,CAAC;CAChD,CAAC;AAEF;;GAEG;AACH,SAAS,KAAK,CAAC,EAAU;IACvB,OAAO,IAAI,OAAO,CAAC,CAAC,OAAO,EAAE,EAAE,CAAC,UAAU,CAAC,OAAO,EAAE,EAAE,CAAC,CAAC,CAAC;AAC3D,CAAC;AAED;;GAEG;AACH,SAAS,gBAAgB,CAAC,UAAkB,EAAE,oBAA8B;IAC1E,OAAO,oBAAoB,CAAC,QAAQ,CAAC,UAAU,CAAC,CAAC;AACnD,CAAC;AAED;;GAEG;AACH,MAAM,OAAO,6BAA8B,SAAQ,qBAAqB;IAC9D,WAAW,CAAwB;IACnC,SAAS,CAAyB;IAE1C,YAAY,MAA2B,EAAE,WAAyB;QAChE,KAAK,CAAC,MAAM,CAAC,CAAC;QACd,IAAI,CAAC,WAAW,GAAG,EAAE,GAAG,oBAAoB,EAAE,GAAG,WAAW,EAAE,CAAC;QAC/D,IAAI,CAAC,SAAS,GAAG,MAAM,CAAC,SAAS,IAAI,EAAE,CAAC;QACxC,mCAAmC;QACnC,IAAI,MAAM,CAAC,oBAAoB,EAAE,CAAC;YAChC,IAAI,CAAC,SAAS,CAAC,SAAS,CAAC,GAAG,MAAM,CAAC,oBAAoB,CAAC;QAC1D,CAAC;IACH,CAAC;IAED;;OAEG;IACK,aAAa,CAAC,YAAqB;QACzC,IAAI,YAAY,IAAI,IAAI,CAAC,SAAS,CAAC,YAAY,CAAC,EAAE,CAAC;YACjD,OAAO,IAAI,CAAC,SAAS,CAAC,YAAY,CAAC,CAAC;QACtC,CAAC;QACD,IAAI,IAAI,CAAC,SAAS,CAAC,SAAS,CAAC,EAAE,CAAC;YAC9B,OAAO,IAAI,CAAC,SAAS,CAAC,SAAS,CAAC,CAAC;QACnC,CAAC;QACD,MAAM,IAAI,KAAK,CAAC,sCAAsC,CAAC,CAAC;IAC1D,CAAC;IAED;;OAEG;IACK,KAAK,CAAC,gBAAgB,CAC5B,SAA2B,EAC3B,aAAqB;QAErB,IAAI,SAAS,GAAiB,IAAI,CAAC;QACnC,IAAI,KAAK,GAAG,IAAI,CAAC,WAAW,CAAC,cAAc,CAAC;QAE5C,KAAK,IAAI,OAAO,GAAG,CAAC,EAAE,OAAO,IAAI,IAAI,CAAC,WAAW,CAAC,UAAU,EAAE,OAAO,EAAE,EAAE,CAAC;YACxE,IAAI,CAAC;gBACH,OAAO,MAAM,SAAS,EAAE,CAAC;YAC3B,CAAC;YAAC,OAAO,KAAK,EAAE,CAAC;gBACf,SAAS,GAAG,KAAK,YAAY,KAAK,CAAC,CAAC,CAAC,KAAK,CAAC,CAAC,CAAC,IAAI,KAAK,CAAC,MAAM,CAAC,KAAK,CAAC,CAAC,CAAC;gBAEtE,8BAA8B;gBAC9B,MAAM,UAAU,GAAI,KAAa,EAAE,UAAU,IAAK,KAAa,EAAE,QAAQ,EAAE,MAAM,CAAC;gBAClF,MAAM,WAAW,GAAG,UAAU,IAAI,gBAAgB,CAAC,UAAU,EAAE,IAAI,CAAC,WAAW,CAAC,oBAAoB,CAAC,CAAC;gBAEtG,2DAA2D;gBAC3D,IAAI,OAAO,KAAK,IAAI,CAAC,WAAW,CAAC,UAAU,IAAI,CAAC,WAAW,EAAE,CAAC;oBAC5D,MAAM,SAAS,CAAC;gBAClB,CAAC;gBAED,uBAAuB;gBACvB,MAAM,KAAK,CAAC,IAAI,CAAC,GAAG,CAAC,KAAK,EAAE,IAAI,CAAC,WAAW,CAAC,UAAU,CAAC,CAAC,CAAC;gBAC1D,KAAK,IAAI,IAAI,CAAC,WAAW,CAAC,iBAAiB,CAAC;YAC9C,CAAC;QACH,CAAC;QAED,MAAM,SAAS,IAAI,IAAI,KAAK,CAAC,GAAG,aAAa,iBAAiB,IAAI,CAAC,WAAW,CAAC,UAAU,UAAU,CAAC,CAAC;IACvG,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,eAAe,CACnB,OAAgE;QAEhE,MAAM,UAAU,GAAG,IAAI,CAAC,aAAa,CAAC,OAAO,CAAC,YAAY,CAAC,CAAC;QAE5D,iDAAiD;QACjD,MAAM,EAAE,YAAY,EAAE,GAAG,iBAAiB,EAAE,GAAG,OAAO,CAAC;QAEvD,+CAA+C;QAC/C,MAAM,kBAAkB,GAAI,IAAY,CAAC,MAAM,CAAC,oBAAoB,CAAC;QACpE,IAAY,CAAC,MAAM,CAAC,oBAAoB,GAAG,UAAU,CAAC;QAEvD,IAAI,CAAC;YACH,OAAO,MAAM,IAAI,CAAC,gBAAgB,CAChC,GAAG,EAAE,CAAC,KAAK,CAAC,eAAe,CAAC,iBAAiB,CAAC,EAC9C,iBAAiB,CAClB,CAAC;QACJ,CAAC;gBAAS,CAAC;YACT,+BAA+B;YAC9B,IAAY,CAAC,MAAM,CAAC,oBAAoB,GAAG,kBAAkB,CAAC;QACjE,CAAC;IACH,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,iBAAiB,CAAC,SAAiB;QACvC,OAAO,IAAI,CAAC,gBAAgB,CAC1B,GAAG,EAAE,CAAC,KAAK,CAAC,iBAAiB,CAAC,SAAS,CAAC,EACxC,mBAAmB,CACpB,CAAC;IACJ,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,gBAAgB,CAAC,UAA8B;QACnD,OAAO,IAAI,CAAC,gBAAgB,CAC1B,GAAG,EAAE,CAAC,KAAK,CAAC,gBAAgB,CAAC,UAAU,CAAC,EACxC,kBAAkB,CACnB,CAAC;IACJ,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,yBAAyB,CAC7B,YAAqB,EACrB,WAAoB;QAEpB,MAAM,UAAU,GAAG,IAAI,CAAC,aAAa,CAAC,YAAY,CAAC,CAAC;QACpD,OAAO,IAAI,CAAC,gBAAgB,CAC1B,GAAG,EAAE,CAAC,KAAK,CAAC,yBAAyB,CAAC,UAAU,EAAE,WAAW,CAAC,EAC9D,2BAA2B,CAC5B,CAAC;IACJ,CAAC;IAED;;OAEG;IACH,gBAAgB,CAAC,IAAY,EAAE,UAAkB;QAC/C,IAAI,CAAC,SAAS,CAAC,IAAI,CAAC,GAAG,UAAU,CAAC;IACpC,CAAC;IAED;;OAEG;IACH,YAAY;QACV,OAAO,EAAE,GAAG,IAAI,CAAC,SAAS,EAAE,CAAC;IAC/B,CAAC;CACF"} \ No newline at end of file diff --git a/packages/auth/src/entra-verifiedid-enhanced.ts b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.ts similarity index 100% rename from packages/auth/src/entra-verifiedid-enhanced.ts rename to archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid-enhanced.ts diff --git a/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.d.ts b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.d.ts new file mode 100644 index 0000000..fab057d --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.d.ts @@ -0,0 +1,95 @@ +/** + * Microsoft Entra VerifiedID connector + * Provides integration with Microsoft Entra VerifiedID for verifiable credential issuance and verification + */ +export interface EntraVerifiedIDConfig { + tenantId: string; + clientId: string; + clientSecret: string; + credentialManifestId?: string; + apiVersion?: string; + logoUri?: string; + backgroundColor?: string; + textColor?: string; +} +/** + * Supported claim value types + */ +export type ClaimValue = string | number | boolean | null; +/** + * Verifiable credential request with enhanced claim types + */ +export interface VerifiableCredentialRequest { + claims: Record; + pin?: string; + callbackUrl?: string; +} +export interface VerifiableCredentialResponse { + requestId: string; + url: string; + expiry: number; + qrCode?: string; +} +export interface VerifiableCredentialStatus { + requestId: string; + state: 'request_created' | 'request_retrieved' | 'issuance_successful' | 'issuance_failed'; + code?: string; + error?: { + code: string; + message: string; + }; +} +export interface VerifiedCredential { + id: string; + type: string[]; + issuer: string; + issuanceDate: string; + expirationDate?: string; + credentialSubject: Record; + proof: { + type: string; + created: string; + proofPurpose: string; + verificationMethod: string; + jws: string; + }; +} +/** + * Microsoft Entra VerifiedID client + */ +export declare class EntraVerifiedIDClient { + private config; + private accessToken; + private tokenExpiry; + private baseUrl; + constructor(config: EntraVerifiedIDConfig); + /** + * Get access token for Microsoft Entra VerifiedID API + */ + private getAccessToken; + /** + * Validate credential request + */ + private validateCredentialRequest; + /** + * Issue a verifiable credential + */ + issueCredential(request: VerifiableCredentialRequest): Promise; + /** + * Check issuance status + */ + getIssuanceStatus(requestId: string): Promise; + /** + * Validate credential structure + */ + private validateCredential; + /** + * Verify a verifiable credential + */ + verifyCredential(credential: VerifiedCredential): Promise; + /** + * Create a presentation request for credential verification + */ + createPresentationRequest(manifestId: string, callbackUrl?: string): Promise; +} +//# sourceMappingURL=entra-verifiedid.d.ts.map \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.d.ts.map b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.d.ts.map new file mode 100644 index 0000000..4ceed15 --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.d.ts.map @@ -0,0 +1 @@ +{"version":3,"file":"entra-verifiedid.d.ts","sourceRoot":"","sources":["entra-verifiedid.ts"],"names":[],"mappings":"AAAA;;;GAGG;AAIH,MAAM,WAAW,qBAAqB;IACpC,QAAQ,EAAE,MAAM,CAAC;IACjB,QAAQ,EAAE,MAAM,CAAC;IACjB,YAAY,EAAE,MAAM,CAAC;IACrB,oBAAoB,CAAC,EAAE,MAAM,CAAC;IAC9B,UAAU,CAAC,EAAE,MAAM,CAAC;IACpB,OAAO,CAAC,EAAE,MAAM,CAAC;IACjB,eAAe,CAAC,EAAE,MAAM,CAAC;IACzB,SAAS,CAAC,EAAE,MAAM,CAAC;CACpB;AAED;;GAEG;AACH,MAAM,MAAM,UAAU,GAAG,MAAM,GAAG,MAAM,GAAG,OAAO,GAAG,IAAI,CAAC;AAE1D;;GAEG;AACH,MAAM,WAAW,2BAA2B;IAC1C,MAAM,EAAE,MAAM,CAAC,MAAM,EAAE,UAAU,CAAC,CAAC;IACnC,GAAG,CAAC,EAAE,MAAM,CAAC;IACb,WAAW,CAAC,EAAE,MAAM,CAAC;CACtB;AAED,MAAM,WAAW,4BAA4B;IAC3C,SAAS,EAAE,MAAM,CAAC;IAClB,GAAG,EAAE,MAAM,CAAC;IACZ,MAAM,EAAE,MAAM,CAAC;IACf,MAAM,CAAC,EAAE,MAAM,CAAC;CACjB;AAED,MAAM,WAAW,0BAA0B;IACzC,SAAS,EAAE,MAAM,CAAC;IAClB,KAAK,EAAE,iBAAiB,GAAG,mBAAmB,GAAG,qBAAqB,GAAG,iBAAiB,CAAC;IAC3F,IAAI,CAAC,EAAE,MAAM,CAAC;IACd,KAAK,CAAC,EAAE;QACN,IAAI,EAAE,MAAM,CAAC;QACb,OAAO,EAAE,MAAM,CAAC;KACjB,CAAC;CACH;AAED,MAAM,WAAW,kBAAkB;IACjC,EAAE,EAAE,MAAM,CAAC;IACX,IAAI,EAAE,MAAM,EAAE,CAAC;IACf,MAAM,EAAE,MAAM,CAAC;IACf,YAAY,EAAE,MAAM,CAAC;IACrB,cAAc,CAAC,EAAE,MAAM,CAAC;IACxB,iBAAiB,EAAE,MAAM,CAAC,MAAM,EAAE,OAAO,CAAC,CAAC;IAC3C,KAAK,EAAE;QACL,IAAI,EAAE,MAAM,CAAC;QACb,OAAO,EAAE,MAAM,CAAC;QAChB,YAAY,EAAE,MAAM,CAAC;QACrB,kBAAkB,EAAE,MAAM,CAAC;QAC3B,GAAG,EAAE,MAAM,CAAC;KACb,CAAC;CACH;AAED;;GAEG;AACH,qBAAa,qBAAqB;IAKpB,OAAO,CAAC,MAAM;IAJ1B,OAAO,CAAC,WAAW,CAAuB;IAC1C,OAAO,CAAC,WAAW,CAAa;IAChC,OAAO,CAAC,OAAO,CAAS;gBAEJ,MAAM,EAAE,qBAAqB;IAIjD;;OAEG;YACW,cAAc;IAyC5B;;OAEG;IACH,OAAO,CAAC,yBAAyB;IAmCjC;;OAEG;IACG,eAAe,CACnB,OAAO,EAAE,2BAA2B,GACnC,OAAO,CAAC,4BAA4B,CAAC;IAwFxC;;OAEG;IACG,iBAAiB,CAAC,SAAS,EAAE,MAAM,GAAG,OAAO,CAAC,0BAA0B,CAAC;IAmB/E;;OAEG;IACH,OAAO,CAAC,kBAAkB;IA+B1B;;OAEG;IACG,gBAAgB,CAAC,UAAU,EAAE,kBAAkB,GAAG,OAAO,CAAC,OAAO,CAAC;IAkCxE;;OAEG;IACG,yBAAyB,CAC7B,UAAU,EAAE,MAAM,EAClB,WAAW,CAAC,EAAE,MAAM,GACnB,OAAO,CAAC,4BAA4B,CAAC;CAqDzC"} \ No newline at end of file diff --git a/packages/auth/src/entra-verifiedid.integration.test.ts b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.integration.test.ts similarity index 100% rename from packages/auth/src/entra-verifiedid.integration.test.ts rename to archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.integration.test.ts diff --git a/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.js b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.js new file mode 100644 index 0000000..d94e5db --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.js @@ -0,0 +1,289 @@ +/** + * Microsoft Entra VerifiedID connector + * Provides integration with Microsoft Entra VerifiedID for verifiable credential issuance and verification + */ +import fetch from 'node-fetch'; +/** + * Microsoft Entra VerifiedID client + */ +export class EntraVerifiedIDClient { + config; + accessToken = null; + tokenExpiry = 0; + baseUrl; + constructor(config) { + this.config = config; + this.baseUrl = `https://verifiedid.did.msidentity.com/v1.0/${config.tenantId}`; + } + /** + * Get access token for Microsoft Entra VerifiedID API + */ + async getAccessToken() { + // Check if we have a valid cached token + if (this.accessToken && Date.now() < this.tokenExpiry) { + return this.accessToken; + } + const tokenUrl = `https://login.microsoftonline.com/${this.config.tenantId}/oauth2/v2.0/token`; + const params = new URLSearchParams({ + client_id: this.config.clientId, + client_secret: this.config.clientSecret, + scope: 'https://verifiedid.did.msidentity.com/.default', + grant_type: 'client_credentials', + }); + const response = await fetch(tokenUrl, { + method: 'POST', + headers: { + 'Content-Type': 'application/x-www-form-urlencoded', + }, + body: params.toString(), + }); + if (!response.ok) { + const errorText = await response.text(); + throw new Error(`Failed to get access token: ${response.status} ${errorText}`); + } + const tokenData = (await response.json()); + this.accessToken = tokenData.access_token; + // Set expiry 5 minutes before actual expiry for safety + const expiresIn = typeof tokenData.expires_in === 'number' ? tokenData.expires_in : 3600; + this.tokenExpiry = Date.now() + (expiresIn - 300) * 1000; + return this.accessToken; + } + /** + * Validate credential request + */ + validateCredentialRequest(request) { + if (!request.claims || Object.keys(request.claims).length === 0) { + throw new Error('At least one claim is required'); + } + // Validate claim keys + for (const key of Object.keys(request.claims)) { + if (!key || key.trim().length === 0) { + throw new Error('Claim keys cannot be empty'); + } + if (key.length > 100) { + throw new Error(`Claim key "${key}" exceeds maximum length of 100 characters`); + } + } + // Validate PIN if provided + if (request.pin) { + if (request.pin.length < 4 || request.pin.length > 8) { + throw new Error('PIN must be between 4 and 8 characters'); + } + if (!/^\d+$/.test(request.pin)) { + throw new Error('PIN must contain only digits'); + } + } + // Validate callback URL if provided + if (request.callbackUrl) { + try { + new URL(request.callbackUrl); + } + catch { + throw new Error('Invalid callback URL format'); + } + } + } + /** + * Issue a verifiable credential + */ + async issueCredential(request) { + // Validate request + this.validateCredentialRequest(request); + const token = await this.getAccessToken(); + const manifestId = this.config.credentialManifestId; + if (!manifestId) { + throw new Error('Credential manifest ID is required for issuance'); + } + const issueUrl = `${this.baseUrl}/verifiableCredentials/createIssuanceRequest`; + // Convert claims to string format (Entra VerifiedID requires string values) + const stringClaims = {}; + for (const [key, value] of Object.entries(request.claims)) { + if (value === null) { + stringClaims[key] = ''; + } + else if (typeof value === 'boolean') { + stringClaims[key] = value.toString(); + } + else if (typeof value === 'number') { + stringClaims[key] = value.toString(); + } + else { + stringClaims[key] = value; + } + } + const requestBody = { + includeQRCode: true, + callback: request.callbackUrl + ? { + url: request.callbackUrl, + state: crypto.randomUUID(), + } + : undefined, + authority: `did:web:${this.config.tenantId}.verifiedid.msidentity.com`, + registration: { + clientName: 'The Order', + }, + type: manifestId, + manifestId, + pin: request.pin + ? { + value: request.pin, + length: request.pin.length, + } + : undefined, + claims: stringClaims, + }; + // Add display properties if configured + if (this.config.logoUri || this.config.backgroundColor || this.config.textColor) { + requestBody.display = { + ...(this.config.logoUri && { logo: { uri: this.config.logoUri } }), + ...(this.config.backgroundColor && { backgroundColor: this.config.backgroundColor }), + ...(this.config.textColor && { textColor: this.config.textColor }), + }; + } + const response = await fetch(issueUrl, { + method: 'POST', + headers: { + 'Content-Type': 'application/json', + Authorization: `Bearer ${token}`, + }, + body: JSON.stringify(requestBody), + }); + if (!response.ok) { + const errorText = await response.text(); + throw new Error(`Failed to issue credential: ${response.status} ${errorText}`); + } + const data = (await response.json()); + return { + requestId: data.requestId, + url: data.url, + expiry: data.expiry, + qrCode: data.qrCode, + }; + } + /** + * Check issuance status + */ + async getIssuanceStatus(requestId) { + const token = await this.getAccessToken(); + const statusUrl = `${this.baseUrl}/verifiableCredentials/issuanceRequests/${requestId}`; + const response = await fetch(statusUrl, { + method: 'GET', + headers: { + Authorization: `Bearer ${token}`, + }, + }); + if (!response.ok) { + const errorText = await response.text(); + throw new Error(`Failed to get issuance status: ${response.status} ${errorText}`); + } + return (await response.json()); + } + /** + * Validate credential structure + */ + validateCredential(credential) { + if (!credential.id) { + throw new Error('Credential ID is required'); + } + if (!credential.type || !Array.isArray(credential.type) || credential.type.length === 0) { + throw new Error('Credential type is required and must be an array'); + } + if (!credential.issuer) { + throw new Error('Credential issuer is required'); + } + if (!credential.issuanceDate) { + throw new Error('Credential issuance date is required'); + } + if (!credential.credentialSubject || typeof credential.credentialSubject !== 'object') { + throw new Error('Credential subject is required'); + } + if (!credential.proof) { + throw new Error('Credential proof is required'); + } + // Validate proof structure + if (!credential.proof.type || !credential.proof.jws) { + throw new Error('Credential proof must include type and jws'); + } + } + /** + * Verify a verifiable credential + */ + async verifyCredential(credential) { + // Validate credential structure + this.validateCredential(credential); + const token = await this.getAccessToken(); + const verifyUrl = `${this.baseUrl}/verifiableCredentials/verify`; + try { + const response = await fetch(verifyUrl, { + method: 'POST', + headers: { + 'Content-Type': 'application/json', + Authorization: `Bearer ${token}`, + }, + body: JSON.stringify({ + verifiableCredential: credential, + }), + }); + if (!response.ok) { + const errorText = await response.text(); + throw new Error(`Verification failed: ${response.status} ${errorText}`); + } + const result = (await response.json()); + return result.verified ?? false; + } + catch (error) { + if (error instanceof Error && error.message.includes('Verification failed')) { + throw error; + } + throw new Error(`Failed to verify credential: ${error instanceof Error ? error.message : String(error)}`); + } + } + /** + * Create a presentation request for credential verification + */ + async createPresentationRequest(manifestId, callbackUrl) { + const token = await this.getAccessToken(); + const requestUrl = `${this.baseUrl}/verifiableCredentials/createPresentationRequest`; + const requestBody = { + includeQRCode: true, + callback: callbackUrl + ? { + url: callbackUrl, + state: crypto.randomUUID(), + } + : undefined, + authority: `did:web:${this.config.tenantId}.verifiedid.msidentity.com`, + registration: { + clientName: 'The Order', + }, + requestedCredentials: [ + { + type: manifestId, + manifestId, + acceptedIssuers: [`did:web:${this.config.tenantId}.verifiedid.msidentity.com`], + }, + ], + }; + const response = await fetch(requestUrl, { + method: 'POST', + headers: { + 'Content-Type': 'application/json', + Authorization: `Bearer ${token}`, + }, + body: JSON.stringify(requestBody), + }); + if (!response.ok) { + const errorText = await response.text(); + throw new Error(`Failed to create presentation request: ${response.status} ${errorText}`); + } + const data = (await response.json()); + return { + requestId: data.requestId, + url: data.url, + expiry: data.expiry, + qrCode: data.qrCode, + }; + } +} +//# sourceMappingURL=entra-verifiedid.js.map \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.js.map b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.js.map new file mode 100644 index 0000000..022e647 --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.js.map @@ -0,0 +1 @@ +{"version":3,"file":"entra-verifiedid.js","sourceRoot":"","sources":["entra-verifiedid.ts"],"names":[],"mappings":"AAAA;;;GAGG;AAEH,OAAO,KAAK,MAAM,YAAY,CAAC;AA4D/B;;GAEG;AACH,MAAM,OAAO,qBAAqB;IAKZ;IAJZ,WAAW,GAAkB,IAAI,CAAC;IAClC,WAAW,GAAW,CAAC,CAAC;IACxB,OAAO,CAAS;IAExB,YAAoB,MAA6B;QAA7B,WAAM,GAAN,MAAM,CAAuB;QAC/C,IAAI,CAAC,OAAO,GAAG,8CAA8C,MAAM,CAAC,QAAQ,EAAE,CAAC;IACjF,CAAC;IAED;;OAEG;IACK,KAAK,CAAC,cAAc;QAC1B,wCAAwC;QACxC,IAAI,IAAI,CAAC,WAAW,IAAI,IAAI,CAAC,GAAG,EAAE,GAAG,IAAI,CAAC,WAAW,EAAE,CAAC;YACtD,OAAO,IAAI,CAAC,WAAW,CAAC;QAC1B,CAAC;QAED,MAAM,QAAQ,GAAG,qCAAqC,IAAI,CAAC,MAAM,CAAC,QAAQ,oBAAoB,CAAC;QAE/F,MAAM,MAAM,GAAG,IAAI,eAAe,CAAC;YACjC,SAAS,EAAE,IAAI,CAAC,MAAM,CAAC,QAAQ;YAC/B,aAAa,EAAE,IAAI,CAAC,MAAM,CAAC,YAAY;YACvC,KAAK,EAAE,gDAAgD;YACvD,UAAU,EAAE,oBAAoB;SACjC,CAAC,CAAC;QAEH,MAAM,QAAQ,GAAG,MAAM,KAAK,CAAC,QAAQ,EAAE;YACrC,MAAM,EAAE,MAAM;YACd,OAAO,EAAE;gBACP,cAAc,EAAE,mCAAmC;aACpD;YACD,IAAI,EAAE,MAAM,CAAC,QAAQ,EAAE;SACxB,CAAC,CAAC;QAEH,IAAI,CAAC,QAAQ,CAAC,EAAE,EAAE,CAAC;YACjB,MAAM,SAAS,GAAG,MAAM,QAAQ,CAAC,IAAI,EAAE,CAAC;YACxC,MAAM,IAAI,KAAK,CAAC,+BAA+B,QAAQ,CAAC,MAAM,IAAI,SAAS,EAAE,CAAC,CAAC;QACjF,CAAC;QAED,MAAM,SAAS,GAAG,CAAC,MAAM,QAAQ,CAAC,IAAI,EAAE,CAGvC,CAAC;QAEF,IAAI,CAAC,WAAW,GAAG,SAAS,CAAC,YAAY,CAAC;QAC1C,uDAAuD;QACvD,MAAM,SAAS,GAAG,OAAO,SAAS,CAAC,UAAU,KAAK,QAAQ,CAAC,CAAC,CAAC,SAAS,CAAC,UAAU,CAAC,CAAC,CAAC,IAAI,CAAC;QACzF,IAAI,CAAC,WAAW,GAAG,IAAI,CAAC,GAAG,EAAE,GAAG,CAAC,SAAS,GAAG,GAAG,CAAC,GAAG,IAAI,CAAC;QAEzD,OAAO,IAAI,CAAC,WAAW,CAAC;IAC1B,CAAC;IAED;;OAEG;IACK,yBAAyB,CAAC,OAAoC;QACpE,IAAI,CAAC,OAAO,CAAC,MAAM,IAAI,MAAM,CAAC,IAAI,CAAC,OAAO,CAAC,MAAM,CAAC,CAAC,MAAM,KAAK,CAAC,EAAE,CAAC;YAChE,MAAM,IAAI,KAAK,CAAC,gCAAgC,CAAC,CAAC;QACpD,CAAC;QAED,sBAAsB;QACtB,KAAK,MAAM,GAAG,IAAI,MAAM,CAAC,IAAI,CAAC,OAAO,CAAC,MAAM,CAAC,EAAE,CAAC;YAC9C,IAAI,CAAC,GAAG,IAAI,GAAG,CAAC,IAAI,EAAE,CAAC,MAAM,KAAK,CAAC,EAAE,CAAC;gBACpC,MAAM,IAAI,KAAK,CAAC,4BAA4B,CAAC,CAAC;YAChD,CAAC;YACD,IAAI,GAAG,CAAC,MAAM,GAAG,GAAG,EAAE,CAAC;gBACrB,MAAM,IAAI,KAAK,CAAC,cAAc,GAAG,4CAA4C,CAAC,CAAC;YACjF,CAAC;QACH,CAAC;QAED,2BAA2B;QAC3B,IAAI,OAAO,CAAC,GAAG,EAAE,CAAC;YAChB,IAAI,OAAO,CAAC,GAAG,CAAC,MAAM,GAAG,CAAC,IAAI,OAAO,CAAC,GAAG,CAAC,MAAM,GAAG,CAAC,EAAE,CAAC;gBACrD,MAAM,IAAI,KAAK,CAAC,wCAAwC,CAAC,CAAC;YAC5D,CAAC;YACD,IAAI,CAAC,OAAO,CAAC,IAAI,CAAC,OAAO,CAAC,GAAG,CAAC,EAAE,CAAC;gBAC/B,MAAM,IAAI,KAAK,CAAC,8BAA8B,CAAC,CAAC;YAClD,CAAC;QACH,CAAC;QAED,oCAAoC;QACpC,IAAI,OAAO,CAAC,WAAW,EAAE,CAAC;YACxB,IAAI,CAAC;gBACH,IAAI,GAAG,CAAC,OAAO,CAAC,WAAW,CAAC,CAAC;YAC/B,CAAC;YAAC,MAAM,CAAC;gBACP,MAAM,IAAI,KAAK,CAAC,6BAA6B,CAAC,CAAC;YACjD,CAAC;QACH,CAAC;IACH,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,eAAe,CACnB,OAAoC;QAEpC,mBAAmB;QACnB,IAAI,CAAC,yBAAyB,CAAC,OAAO,CAAC,CAAC;QAExC,MAAM,KAAK,GAAG,MAAM,IAAI,CAAC,cAAc,EAAE,CAAC;QAC1C,MAAM,UAAU,GAAG,IAAI,CAAC,MAAM,CAAC,oBAAoB,CAAC;QAEpD,IAAI,CAAC,UAAU,EAAE,CAAC;YAChB,MAAM,IAAI,KAAK,CAAC,iDAAiD,CAAC,CAAC;QACrE,CAAC;QAED,MAAM,QAAQ,GAAG,GAAG,IAAI,CAAC,OAAO,8CAA8C,CAAC;QAE/E,4EAA4E;QAC5E,MAAM,YAAY,GAA2B,EAAE,CAAC;QAChD,KAAK,MAAM,CAAC,GAAG,EAAE,KAAK,CAAC,IAAI,MAAM,CAAC,OAAO,CAAC,OAAO,CAAC,MAAM,CAAC,EAAE,CAAC;YAC1D,IAAI,KAAK,KAAK,IAAI,EAAE,CAAC;gBACnB,YAAY,CAAC,GAAG,CAAC,GAAG,EAAE,CAAC;YACzB,CAAC;iBAAM,IAAI,OAAO,KAAK,KAAK,SAAS,EAAE,CAAC;gBACtC,YAAY,CAAC,GAAG,CAAC,GAAG,KAAK,CAAC,QAAQ,EAAE,CAAC;YACvC,CAAC;iBAAM,IAAI,OAAO,KAAK,KAAK,QAAQ,EAAE,CAAC;gBACrC,YAAY,CAAC,GAAG,CAAC,GAAG,KAAK,CAAC,QAAQ,EAAE,CAAC;YACvC,CAAC;iBAAM,CAAC;gBACN,YAAY,CAAC,GAAG,CAAC,GAAG,KAAK,CAAC;YAC5B,CAAC;QACH,CAAC;QAED,MAAM,WAAW,GAA4B;YAC3C,aAAa,EAAE,IAAI;YACnB,QAAQ,EAAE,OAAO,CAAC,WAAW;gBAC3B,CAAC,CAAC;oBACE,GAAG,EAAE,OAAO,CAAC,WAAW;oBACxB,KAAK,EAAE,MAAM,CAAC,UAAU,EAAE;iBAC3B;gBACH,CAAC,CAAC,SAAS;YACb,SAAS,EAAE,WAAW,IAAI,CAAC,MAAM,CAAC,QAAQ,4BAA4B;YACtE,YAAY,EAAE;gBACZ,UAAU,EAAE,WAAW;aACxB;YACD,IAAI,EAAE,UAAU;YAChB,UAAU;YACV,GAAG,EAAE,OAAO,CAAC,GAAG;gBACd,CAAC,CAAC;oBACE,KAAK,EAAE,OAAO,CAAC,GAAG;oBAClB,MAAM,EAAE,OAAO,CAAC,GAAG,CAAC,MAAM;iBAC3B;gBACH,CAAC,CAAC,SAAS;YACb,MAAM,EAAE,YAAY;SACrB,CAAC;QAEF,uCAAuC;QACvC,IAAI,IAAI,CAAC,MAAM,CAAC,OAAO,IAAI,IAAI,CAAC,MAAM,CAAC,eAAe,IAAI,IAAI,CAAC,MAAM,CAAC,SAAS,EAAE,CAAC;YAChF,WAAW,CAAC,OAAO,GAAG;gBACpB,GAAG,CAAC,IAAI,CAAC,MAAM,CAAC,OAAO,IAAI,EAAE,IAAI,EAAE,EAAE,GAAG,EAAE,IAAI,CAAC,MAAM,CAAC,OAAO,EAAE,EAAE,CAAC;gBAClE,GAAG,CAAC,IAAI,CAAC,MAAM,CAAC,eAAe,IAAI,EAAE,eAAe,EAAE,IAAI,CAAC,MAAM,CAAC,eAAe,EAAE,CAAC;gBACpF,GAAG,CAAC,IAAI,CAAC,MAAM,CAAC,SAAS,IAAI,EAAE,SAAS,EAAE,IAAI,CAAC,MAAM,CAAC,SAAS,EAAE,CAAC;aACnE,CAAC;QACJ,CAAC;QAED,MAAM,QAAQ,GAAG,MAAM,KAAK,CAAC,QAAQ,EAAE;YACrC,MAAM,EAAE,MAAM;YACd,OAAO,EAAE;gBACP,cAAc,EAAE,kBAAkB;gBAClC,aAAa,EAAE,UAAU,KAAK,EAAE;aACjC;YACD,IAAI,EAAE,IAAI,CAAC,SAAS,CAAC,WAAW,CAAC;SAClC,CAAC,CAAC;QAEH,IAAI,CAAC,QAAQ,CAAC,EAAE,EAAE,CAAC;YACjB,MAAM,SAAS,GAAG,MAAM,QAAQ,CAAC,IAAI,EAAE,CAAC;YACxC,MAAM,IAAI,KAAK,CAAC,+BAA+B,QAAQ,CAAC,MAAM,IAAI,SAAS,EAAE,CAAC,CAAC;QACjF,CAAC;QAED,MAAM,IAAI,GAAG,CAAC,MAAM,QAAQ,CAAC,IAAI,EAAE,CAKlC,CAAC;QAEF,OAAO;YACL,SAAS,EAAE,IAAI,CAAC,SAAS;YACzB,GAAG,EAAE,IAAI,CAAC,GAAG;YACb,MAAM,EAAE,IAAI,CAAC,MAAM;YACnB,MAAM,EAAE,IAAI,CAAC,MAAM;SACpB,CAAC;IACJ,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,iBAAiB,CAAC,SAAiB;QACvC,MAAM,KAAK,GAAG,MAAM,IAAI,CAAC,cAAc,EAAE,CAAC;QAC1C,MAAM,SAAS,GAAG,GAAG,IAAI,CAAC,OAAO,2CAA2C,SAAS,EAAE,CAAC;QAExF,MAAM,QAAQ,GAAG,MAAM,KAAK,CAAC,SAAS,EAAE;YACtC,MAAM,EAAE,KAAK;YACb,OAAO,EAAE;gBACP,aAAa,EAAE,UAAU,KAAK,EAAE;aACjC;SACF,CAAC,CAAC;QAEH,IAAI,CAAC,QAAQ,CAAC,EAAE,EAAE,CAAC;YACjB,MAAM,SAAS,GAAG,MAAM,QAAQ,CAAC,IAAI,EAAE,CAAC;YACxC,MAAM,IAAI,KAAK,CAAC,kCAAkC,QAAQ,CAAC,MAAM,IAAI,SAAS,EAAE,CAAC,CAAC;QACpF,CAAC;QAED,OAAO,CAAC,MAAM,QAAQ,CAAC,IAAI,EAAE,CAA+B,CAAC;IAC/D,CAAC;IAED;;OAEG;IACK,kBAAkB,CAAC,UAA8B;QACvD,IAAI,CAAC,UAAU,CAAC,EAAE,EAAE,CAAC;YACnB,MAAM,IAAI,KAAK,CAAC,2BAA2B,CAAC,CAAC;QAC/C,CAAC;QAED,IAAI,CAAC,UAAU,CAAC,IAAI,IAAI,CAAC,KAAK,CAAC,OAAO,CAAC,UAAU,CAAC,IAAI,CAAC,IAAI,UAAU,CAAC,IAAI,CAAC,MAAM,KAAK,CAAC,EAAE,CAAC;YACxF,MAAM,IAAI,KAAK,CAAC,kDAAkD,CAAC,CAAC;QACtE,CAAC;QAED,IAAI,CAAC,UAAU,CAAC,MAAM,EAAE,CAAC;YACvB,MAAM,IAAI,KAAK,CAAC,+BAA+B,CAAC,CAAC;QACnD,CAAC;QAED,IAAI,CAAC,UAAU,CAAC,YAAY,EAAE,CAAC;YAC7B,MAAM,IAAI,KAAK,CAAC,sCAAsC,CAAC,CAAC;QAC1D,CAAC;QAED,IAAI,CAAC,UAAU,CAAC,iBAAiB,IAAI,OAAO,UAAU,CAAC,iBAAiB,KAAK,QAAQ,EAAE,CAAC;YACtF,MAAM,IAAI,KAAK,CAAC,gCAAgC,CAAC,CAAC;QACpD,CAAC;QAED,IAAI,CAAC,UAAU,CAAC,KAAK,EAAE,CAAC;YACtB,MAAM,IAAI,KAAK,CAAC,8BAA8B,CAAC,CAAC;QAClD,CAAC;QAED,2BAA2B;QAC3B,IAAI,CAAC,UAAU,CAAC,KAAK,CAAC,IAAI,IAAI,CAAC,UAAU,CAAC,KAAK,CAAC,GAAG,EAAE,CAAC;YACpD,MAAM,IAAI,KAAK,CAAC,4CAA4C,CAAC,CAAC;QAChE,CAAC;IACH,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,gBAAgB,CAAC,UAA8B;QACnD,gCAAgC;QAChC,IAAI,CAAC,kBAAkB,CAAC,UAAU,CAAC,CAAC;QAEpC,MAAM,KAAK,GAAG,MAAM,IAAI,CAAC,cAAc,EAAE,CAAC;QAC1C,MAAM,SAAS,GAAG,GAAG,IAAI,CAAC,OAAO,+BAA+B,CAAC;QAEjE,IAAI,CAAC;YACH,MAAM,QAAQ,GAAG,MAAM,KAAK,CAAC,SAAS,EAAE;gBACtC,MAAM,EAAE,MAAM;gBACd,OAAO,EAAE;oBACP,cAAc,EAAE,kBAAkB;oBAClC,aAAa,EAAE,UAAU,KAAK,EAAE;iBACjC;gBACD,IAAI,EAAE,IAAI,CAAC,SAAS,CAAC;oBACnB,oBAAoB,EAAE,UAAU;iBACjC,CAAC;aACH,CAAC,CAAC;YAEH,IAAI,CAAC,QAAQ,CAAC,EAAE,EAAE,CAAC;gBACjB,MAAM,SAAS,GAAG,MAAM,QAAQ,CAAC,IAAI,EAAE,CAAC;gBACxC,MAAM,IAAI,KAAK,CAAC,wBAAwB,QAAQ,CAAC,MAAM,IAAI,SAAS,EAAE,CAAC,CAAC;YAC1E,CAAC;YAED,MAAM,MAAM,GAAG,CAAC,MAAM,QAAQ,CAAC,IAAI,EAAE,CAA0B,CAAC;YAChE,OAAO,MAAM,CAAC,QAAQ,IAAI,KAAK,CAAC;QAClC,CAAC;QAAC,OAAO,KAAK,EAAE,CAAC;YACf,IAAI,KAAK,YAAY,KAAK,IAAI,KAAK,CAAC,OAAO,CAAC,QAAQ,CAAC,qBAAqB,CAAC,EAAE,CAAC;gBAC5E,MAAM,KAAK,CAAC;YACd,CAAC;YACD,MAAM,IAAI,KAAK,CAAC,gCAAgC,KAAK,YAAY,KAAK,CAAC,CAAC,CAAC,KAAK,CAAC,OAAO,CAAC,CAAC,CAAC,MAAM,CAAC,KAAK,CAAC,EAAE,CAAC,CAAC;QAC5G,CAAC;IACH,CAAC;IAED;;OAEG;IACH,KAAK,CAAC,yBAAyB,CAC7B,UAAkB,EAClB,WAAoB;QAEpB,MAAM,KAAK,GAAG,MAAM,IAAI,CAAC,cAAc,EAAE,CAAC;QAC1C,MAAM,UAAU,GAAG,GAAG,IAAI,CAAC,OAAO,kDAAkD,CAAC;QAErF,MAAM,WAAW,GAAG;YAClB,aAAa,EAAE,IAAI;YACnB,QAAQ,EAAE,WAAW;gBACnB,CAAC,CAAC;oBACE,GAAG,EAAE,WAAW;oBAChB,KAAK,EAAE,MAAM,CAAC,UAAU,EAAE;iBAC3B;gBACH,CAAC,CAAC,SAAS;YACb,SAAS,EAAE,WAAW,IAAI,CAAC,MAAM,CAAC,QAAQ,4BAA4B;YACtE,YAAY,EAAE;gBACZ,UAAU,EAAE,WAAW;aACxB;YACD,oBAAoB,EAAE;gBACpB;oBACE,IAAI,EAAE,UAAU;oBAChB,UAAU;oBACV,eAAe,EAAE,CAAC,WAAW,IAAI,CAAC,MAAM,CAAC,QAAQ,4BAA4B,CAAC;iBAC/E;aACF;SACF,CAAC;QAEF,MAAM,QAAQ,GAAG,MAAM,KAAK,CAAC,UAAU,EAAE;YACvC,MAAM,EAAE,MAAM;YACd,OAAO,EAAE;gBACP,cAAc,EAAE,kBAAkB;gBAClC,aAAa,EAAE,UAAU,KAAK,EAAE;aACjC;YACD,IAAI,EAAE,IAAI,CAAC,SAAS,CAAC,WAAW,CAAC;SAClC,CAAC,CAAC;QAEH,IAAI,CAAC,QAAQ,CAAC,EAAE,EAAE,CAAC;YACjB,MAAM,SAAS,GAAG,MAAM,QAAQ,CAAC,IAAI,EAAE,CAAC;YACxC,MAAM,IAAI,KAAK,CAAC,0CAA0C,QAAQ,CAAC,MAAM,IAAI,SAAS,EAAE,CAAC,CAAC;QAC5F,CAAC;QAED,MAAM,IAAI,GAAG,CAAC,MAAM,QAAQ,CAAC,IAAI,EAAE,CAKlC,CAAC;QAEF,OAAO;YACL,SAAS,EAAE,IAAI,CAAC,SAAS;YACzB,GAAG,EAAE,IAAI,CAAC,GAAG;YACb,MAAM,EAAE,IAAI,CAAC,MAAM;YACnB,MAAM,EAAE,IAAI,CAAC,MAAM;SACpB,CAAC;IACJ,CAAC;CACF"} \ No newline at end of file diff --git a/packages/auth/src/entra-verifiedid.test.ts b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.test.ts similarity index 100% rename from packages/auth/src/entra-verifiedid.test.ts rename to archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.test.ts diff --git a/packages/auth/src/entra-verifiedid.ts b/archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.ts similarity index 100% rename from packages/auth/src/entra-verifiedid.ts rename to archive/quarantined-legacy-stack/packages/auth/src/entra-verifiedid.ts diff --git a/packages/monitoring/src/entra-metrics.ts b/archive/quarantined-legacy-stack/packages/monitoring/src/entra-metrics.ts similarity index 100% rename from packages/monitoring/src/entra-metrics.ts rename to archive/quarantined-legacy-stack/packages/monitoring/src/entra-metrics.ts diff --git a/archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.d.ts b/archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.d.ts new file mode 100644 index 0000000..2376dd5 --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.d.ts @@ -0,0 +1,32 @@ +/** + * Entra VerifiedID API rate limiting + * Specific rate limits for Entra VerifiedID endpoints to prevent API quota exhaustion + */ +import { FastifyInstance } from 'fastify'; +export interface EntraRateLimitConfig { + issuance?: { + max: number; + timeWindow: string | number; + }; + verification?: { + max: number; + timeWindow: string | number; + }; + statusCheck?: { + max: number; + timeWindow: string | number; + }; + global?: { + max: number; + timeWindow: string | number; + }; +} +/** + * Register Entra VerifiedID-specific rate limiting + */ +export declare function registerEntraRateLimit(server: FastifyInstance, config?: EntraRateLimitConfig): Promise; +/** + * Create Entra rate limit plugin + */ +export declare function createEntraRateLimitPlugin(config?: EntraRateLimitConfig): (server: FastifyInstance) => Promise; +//# sourceMappingURL=rate-limit-entra.d.ts.map \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.d.ts.map b/archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.d.ts.map new file mode 100644 index 0000000..51fc4e4 --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.d.ts.map @@ -0,0 +1 @@ +{"version":3,"file":"rate-limit-entra.d.ts","sourceRoot":"","sources":["rate-limit-entra.ts"],"names":[],"mappings":"AAAA;;;GAGG;AAEH,OAAO,EAAE,eAAe,EAAkB,MAAM,SAAS,CAAC;AAI1D,MAAM,WAAW,oBAAoB;IACnC,QAAQ,CAAC,EAAE;QACT,GAAG,EAAE,MAAM,CAAC;QACZ,UAAU,EAAE,MAAM,GAAG,MAAM,CAAC;KAC7B,CAAC;IACF,YAAY,CAAC,EAAE;QACb,GAAG,EAAE,MAAM,CAAC;QACZ,UAAU,EAAE,MAAM,GAAG,MAAM,CAAC;KAC7B,CAAC;IACF,WAAW,CAAC,EAAE;QACZ,GAAG,EAAE,MAAM,CAAC;QACZ,UAAU,EAAE,MAAM,GAAG,MAAM,CAAC;KAC7B,CAAC;IACF,MAAM,CAAC,EAAE;QACP,GAAG,EAAE,MAAM,CAAC;QACZ,UAAU,EAAE,MAAM,GAAG,MAAM,CAAC;KAC7B,CAAC;CACH;AAED;;GAEG;AACH,wBAAsB,sBAAsB,CAC1C,MAAM,EAAE,eAAe,EACvB,MAAM,CAAC,EAAE,oBAAoB,GAC5B,OAAO,CAAC,IAAI,CAAC,CAmGf;AAED;;GAEG;AACH,wBAAgB,0BAA0B,CAAC,MAAM,CAAC,EAAE,oBAAoB,IAC/C,QAAQ,eAAe,mBAG/C"} \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.js b/archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.js new file mode 100644 index 0000000..7fe23bc --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.js @@ -0,0 +1,112 @@ +/** + * Entra VerifiedID API rate limiting + * Specific rate limits for Entra VerifiedID endpoints to prevent API quota exhaustion + */ +import fastifyRateLimit from '@fastify/rate-limit'; +import { getEnv } from './env'; +/** + * Register Entra VerifiedID-specific rate limiting + */ +export async function registerEntraRateLimit(server, config) { + const env = getEnv(); + // Default configuration - conservative limits to avoid API quota issues + const defaultConfig = { + issuance: { + max: parseInt(env.ENTRA_RATE_LIMIT_ISSUANCE || '10', 10), + timeWindow: '1 minute', + }, + verification: { + max: parseInt(env.ENTRA_RATE_LIMIT_VERIFICATION || '20', 10), + timeWindow: '1 minute', + }, + statusCheck: { + max: parseInt(env.ENTRA_RATE_LIMIT_STATUS_CHECK || '30', 10), + timeWindow: '1 minute', + }, + global: { + max: parseInt(env.ENTRA_RATE_LIMIT_GLOBAL || '50', 10), + timeWindow: '1 minute', + }, + }; + const finalConfig = { ...defaultConfig, ...config }; + // Global Entra API rate limit + await server.register(fastifyRateLimit, { + max: finalConfig.global.max, + timeWindow: finalConfig.global.timeWindow, + keyGenerator: (request) => { + // Rate limit by IP for Entra endpoints + return `entra:global:${request.ip}`; + }, + errorResponseBuilder: (_request, context) => { + return { + error: { + code: 'ENTRA_RATE_LIMIT_EXCEEDED', + message: `Entra API rate limit exceeded, retry in ${Math.ceil(context.ttl / 1000)} seconds`, + }, + }; + }, + skipOnError: false, + }); + // Issuance-specific rate limit + await server.register(fastifyRateLimit, { + max: finalConfig.issuance.max, + timeWindow: finalConfig.issuance.timeWindow, + keyGenerator: (request) => { + const userId = request.user?.id || 'anonymous'; + return `entra:issuance:${userId}:${request.ip}`; + }, + errorResponseBuilder: (_request, context) => { + return { + error: { + code: 'ENTRA_ISSUANCE_RATE_LIMIT_EXCEEDED', + message: `Entra issuance rate limit exceeded, retry in ${Math.ceil(context.ttl / 1000)} seconds`, + }, + }; + }, + skipOnError: false, + }); + // Verification-specific rate limit + await server.register(fastifyRateLimit, { + max: finalConfig.verification.max, + timeWindow: finalConfig.verification.timeWindow, + keyGenerator: (request) => { + return `entra:verification:${request.ip}`; + }, + errorResponseBuilder: (_request, context) => { + return { + error: { + code: 'ENTRA_VERIFICATION_RATE_LIMIT_EXCEEDED', + message: `Entra verification rate limit exceeded, retry in ${Math.ceil(context.ttl / 1000)} seconds`, + }, + }; + }, + skipOnError: false, + }); + // Status check-specific rate limit + await server.register(fastifyRateLimit, { + max: finalConfig.statusCheck.max, + timeWindow: finalConfig.statusCheck.timeWindow, + keyGenerator: (request) => { + const requestId = request.params?.requestId || request.query?.requestId || 'unknown'; + return `entra:status:${requestId}`; + }, + errorResponseBuilder: (_request, context) => { + return { + error: { + code: 'ENTRA_STATUS_CHECK_RATE_LIMIT_EXCEEDED', + message: `Entra status check rate limit exceeded, retry in ${Math.ceil(context.ttl / 1000)} seconds`, + }, + }; + }, + skipOnError: false, + }); +} +/** + * Create Entra rate limit plugin + */ +export function createEntraRateLimitPlugin(config) { + return async function (server) { + await registerEntraRateLimit(server, config); + }; +} +//# sourceMappingURL=rate-limit-entra.js.map \ No newline at end of file diff --git a/archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.js.map b/archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.js.map new file mode 100644 index 0000000..316e867 --- /dev/null +++ b/archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.js.map @@ -0,0 +1 @@ +{"version":3,"file":"rate-limit-entra.js","sourceRoot":"","sources":["rate-limit-entra.ts"],"names":[],"mappings":"AAAA;;;GAGG;AAGH,OAAO,gBAAgB,MAAM,qBAAqB,CAAC;AACnD,OAAO,EAAE,MAAM,EAAE,MAAM,OAAO,CAAC;AAqB/B;;GAEG;AACH,MAAM,CAAC,KAAK,UAAU,sBAAsB,CAC1C,MAAuB,EACvB,MAA6B;IAE7B,MAAM,GAAG,GAAG,MAAM,EAAE,CAAC;IAErB,wEAAwE;IACxE,MAAM,aAAa,GAAmC;QACpD,QAAQ,EAAE;YACR,GAAG,EAAE,QAAQ,CAAC,GAAG,CAAC,yBAAyB,IAAI,IAAI,EAAE,EAAE,CAAC;YACxD,UAAU,EAAE,UAAU;SACvB;QACD,YAAY,EAAE;YACZ,GAAG,EAAE,QAAQ,CAAC,GAAG,CAAC,6BAA6B,IAAI,IAAI,EAAE,EAAE,CAAC;YAC5D,UAAU,EAAE,UAAU;SACvB;QACD,WAAW,EAAE;YACX,GAAG,EAAE,QAAQ,CAAC,GAAG,CAAC,6BAA6B,IAAI,IAAI,EAAE,EAAE,CAAC;YAC5D,UAAU,EAAE,UAAU;SACvB;QACD,MAAM,EAAE;YACN,GAAG,EAAE,QAAQ,CAAC,GAAG,CAAC,uBAAuB,IAAI,IAAI,EAAE,EAAE,CAAC;YACtD,UAAU,EAAE,UAAU;SACvB;KACF,CAAC;IAEF,MAAM,WAAW,GAAG,EAAE,GAAG,aAAa,EAAE,GAAG,MAAM,EAAE,CAAC;IAEpD,8BAA8B;IAC9B,MAAM,MAAM,CAAC,QAAQ,CAAC,gBAAgB,EAAE;QACtC,GAAG,EAAE,WAAW,CAAC,MAAM,CAAC,GAAG;QAC3B,UAAU,EAAE,WAAW,CAAC,MAAM,CAAC,UAAU;QACzC,YAAY,EAAE,CAAC,OAAuB,EAAE,EAAE;YACxC,uCAAuC;YACvC,OAAO,gBAAgB,OAAO,CAAC,EAAE,EAAE,CAAC;QACtC,CAAC;QACD,oBAAoB,EAAE,CAAC,QAAQ,EAAE,OAAO,EAAE,EAAE;YAC1C,OAAO;gBACL,KAAK,EAAE;oBACL,IAAI,EAAE,2BAA2B;oBACjC,OAAO,EAAE,2CAA2C,IAAI,CAAC,IAAI,CAAC,OAAO,CAAC,GAAG,GAAG,IAAI,CAAC,UAAU;iBAC5F;aACF,CAAC;QACJ,CAAC;QACD,WAAW,EAAE,KAAK;KACnB,CAAC,CAAC;IAEH,+BAA+B;IAC/B,MAAM,MAAM,CAAC,QAAQ,CAAC,gBAAgB,EAAE;QACtC,GAAG,EAAE,WAAW,CAAC,QAAQ,CAAC,GAAG;QAC7B,UAAU,EAAE,WAAW,CAAC,QAAQ,CAAC,UAAU;QAC3C,YAAY,EAAE,CAAC,OAAuB,EAAE,EAAE;YACxC,MAAM,MAAM,GAAI,OAAe,CAAC,IAAI,EAAE,EAAE,IAAI,WAAW,CAAC;YACxD,OAAO,kBAAkB,MAAM,IAAI,OAAO,CAAC,EAAE,EAAE,CAAC;QAClD,CAAC;QACD,oBAAoB,EAAE,CAAC,QAAQ,EAAE,OAAO,EAAE,EAAE;YAC1C,OAAO;gBACL,KAAK,EAAE;oBACL,IAAI,EAAE,oCAAoC;oBAC1C,OAAO,EAAE,gDAAgD,IAAI,CAAC,IAAI,CAAC,OAAO,CAAC,GAAG,GAAG,IAAI,CAAC,UAAU;iBACjG;aACF,CAAC;QACJ,CAAC;QACD,WAAW,EAAE,KAAK;KACnB,CAAC,CAAC;IAEH,mCAAmC;IACnC,MAAM,MAAM,CAAC,QAAQ,CAAC,gBAAgB,EAAE;QACtC,GAAG,EAAE,WAAW,CAAC,YAAY,CAAC,GAAG;QACjC,UAAU,EAAE,WAAW,CAAC,YAAY,CAAC,UAAU;QAC/C,YAAY,EAAE,CAAC,OAAuB,EAAE,EAAE;YACxC,OAAO,sBAAsB,OAAO,CAAC,EAAE,EAAE,CAAC;QAC5C,CAAC;QACD,oBAAoB,EAAE,CAAC,QAAQ,EAAE,OAAO,EAAE,EAAE;YAC1C,OAAO;gBACL,KAAK,EAAE;oBACL,IAAI,EAAE,wCAAwC;oBAC9C,OAAO,EAAE,oDAAoD,IAAI,CAAC,IAAI,CAAC,OAAO,CAAC,GAAG,GAAG,IAAI,CAAC,UAAU;iBACrG;aACF,CAAC;QACJ,CAAC;QACD,WAAW,EAAE,KAAK;KACnB,CAAC,CAAC;IAEH,mCAAmC;IACnC,MAAM,MAAM,CAAC,QAAQ,CAAC,gBAAgB,EAAE;QACtC,GAAG,EAAE,WAAW,CAAC,WAAW,CAAC,GAAG;QAChC,UAAU,EAAE,WAAW,CAAC,WAAW,CAAC,UAAU;QAC9C,YAAY,EAAE,CAAC,OAAuB,EAAE,EAAE;YACxC,MAAM,SAAS,GAAI,OAAO,CAAC,MAAc,EAAE,SAAS,IAAK,OAAO,CAAC,KAAa,EAAE,SAAS,IAAI,SAAS,CAAC;YACvG,OAAO,gBAAgB,SAAS,EAAE,CAAC;QACrC,CAAC;QACD,oBAAoB,EAAE,CAAC,QAAQ,EAAE,OAAO,EAAE,EAAE;YAC1C,OAAO;gBACL,KAAK,EAAE;oBACL,IAAI,EAAE,wCAAwC;oBAC9C,OAAO,EAAE,oDAAoD,IAAI,CAAC,IAAI,CAAC,OAAO,CAAC,GAAG,GAAG,IAAI,CAAC,UAAU;iBACrG;aACF,CAAC;QACJ,CAAC;QACD,WAAW,EAAE,KAAK;KACnB,CAAC,CAAC;AACL,CAAC;AAED;;GAEG;AACH,MAAM,UAAU,0BAA0B,CAAC,MAA6B;IACtE,OAAO,KAAK,WAAW,MAAuB;QAC5C,MAAM,sBAAsB,CAAC,MAAM,EAAE,MAAM,CAAC,CAAC;IAC/C,CAAC,CAAC;AACJ,CAAC"} \ No newline at end of file diff --git a/packages/shared/src/rate-limit-entra.ts b/archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.ts similarity index 100% rename from packages/shared/src/rate-limit-entra.ts rename to archive/quarantined-legacy-stack/packages/shared/src/rate-limit-entra.ts diff --git a/DEPLOYMENT_COMPLETE.md b/archive/quarantined-legacy-stack/root/DEPLOYMENT_COMPLETE.md similarity index 100% rename from DEPLOYMENT_COMPLETE.md rename to archive/quarantined-legacy-stack/root/DEPLOYMENT_COMPLETE.md diff --git a/README_ENTRA_SETUP.md b/archive/quarantined-legacy-stack/root/README_ENTRA_SETUP.md similarity index 100% rename from README_ENTRA_SETUP.md rename to archive/quarantined-legacy-stack/root/README_ENTRA_SETUP.md diff --git a/azure-cdn-config.env b/archive/quarantined-legacy-stack/root/azure-cdn-config.env similarity index 100% rename from azure-cdn-config.env rename to archive/quarantined-legacy-stack/root/azure-cdn-config.env diff --git a/azure-cdn-quota-report.txt b/archive/quarantined-legacy-stack/root/azure-cdn-quota-report.txt similarity index 100% rename from azure-cdn-quota-report.txt rename to archive/quarantined-legacy-stack/root/azure-cdn-quota-report.txt diff --git a/azure-cdn-quotas.txt b/archive/quarantined-legacy-stack/root/azure-cdn-quotas.txt similarity index 100% rename from azure-cdn-quotas.txt rename to archive/quarantined-legacy-stack/root/azure-cdn-quotas.txt diff --git a/scripts/ci/validate-entra-deployment.sh b/archive/quarantined-legacy-stack/scripts/ci/validate-entra-deployment.sh similarity index 100% rename from scripts/ci/validate-entra-deployment.sh rename to archive/quarantined-legacy-stack/scripts/ci/validate-entra-deployment.sh diff --git a/scripts/deploy/complete-entra-setup.sh b/archive/quarantined-legacy-stack/scripts/deploy/complete-entra-setup.sh similarity index 100% rename from scripts/deploy/complete-entra-setup.sh rename to archive/quarantined-legacy-stack/scripts/deploy/complete-entra-setup.sh diff --git a/scripts/deploy/configure-api-permissions.sh b/archive/quarantined-legacy-stack/scripts/deploy/configure-api-permissions.sh similarity index 100% rename from scripts/deploy/configure-api-permissions.sh rename to archive/quarantined-legacy-stack/scripts/deploy/configure-api-permissions.sh diff --git a/scripts/deploy/configure-env-dev.sh b/archive/quarantined-legacy-stack/scripts/deploy/configure-env-dev.sh similarity index 100% rename from scripts/deploy/configure-env-dev.sh rename to archive/quarantined-legacy-stack/scripts/deploy/configure-env-dev.sh diff --git a/scripts/deploy/configure-multi-manifest.sh b/archive/quarantined-legacy-stack/scripts/deploy/configure-multi-manifest.sh similarity index 100% rename from scripts/deploy/configure-multi-manifest.sh rename to archive/quarantined-legacy-stack/scripts/deploy/configure-multi-manifest.sh diff --git a/scripts/deploy/configure-webhook-url.sh b/archive/quarantined-legacy-stack/scripts/deploy/configure-webhook-url.sh similarity index 100% rename from scripts/deploy/configure-webhook-url.sh rename to archive/quarantined-legacy-stack/scripts/deploy/configure-webhook-url.sh diff --git a/scripts/deploy/create-credential-manifests.sh b/archive/quarantined-legacy-stack/scripts/deploy/create-credential-manifests.sh similarity index 100% rename from scripts/deploy/create-credential-manifests.sh rename to archive/quarantined-legacy-stack/scripts/deploy/create-credential-manifests.sh diff --git a/scripts/deploy/create-entra-app.sh b/archive/quarantined-legacy-stack/scripts/deploy/create-entra-app.sh similarity index 100% rename from scripts/deploy/create-entra-app.sh rename to archive/quarantined-legacy-stack/scripts/deploy/create-entra-app.sh diff --git a/scripts/deploy/deploy-production.sh b/archive/quarantined-legacy-stack/scripts/deploy/deploy-production.sh similarity index 100% rename from scripts/deploy/deploy-production.sh rename to archive/quarantined-legacy-stack/scripts/deploy/deploy-production.sh diff --git a/scripts/deploy/deploy-staging.sh b/archive/quarantined-legacy-stack/scripts/deploy/deploy-staging.sh similarity index 100% rename from scripts/deploy/deploy-staging.sh rename to archive/quarantined-legacy-stack/scripts/deploy/deploy-staging.sh diff --git a/scripts/deploy/enable-verified-id.sh b/archive/quarantined-legacy-stack/scripts/deploy/enable-verified-id.sh similarity index 100% rename from scripts/deploy/enable-verified-id.sh rename to archive/quarantined-legacy-stack/scripts/deploy/enable-verified-id.sh diff --git a/scripts/deploy/setup-azure-cdn-complete.sh b/archive/quarantined-legacy-stack/scripts/deploy/setup-azure-cdn-complete.sh similarity index 100% rename from scripts/deploy/setup-azure-cdn-complete.sh rename to archive/quarantined-legacy-stack/scripts/deploy/setup-azure-cdn-complete.sh diff --git a/scripts/deploy/setup-entra-automated.sh b/archive/quarantined-legacy-stack/scripts/deploy/setup-entra-automated.sh similarity index 100% rename from scripts/deploy/setup-entra-automated.sh rename to archive/quarantined-legacy-stack/scripts/deploy/setup-entra-automated.sh diff --git a/scripts/deploy/store-entra-secrets.sh b/archive/quarantined-legacy-stack/scripts/deploy/store-entra-secrets.sh similarity index 100% rename from scripts/deploy/store-entra-secrets.sh rename to archive/quarantined-legacy-stack/scripts/deploy/store-entra-secrets.sh diff --git a/scripts/deploy/upload-seals-to-azure.sh b/archive/quarantined-legacy-stack/scripts/deploy/upload-seals-to-azure.sh similarity index 100% rename from scripts/deploy/upload-seals-to-azure.sh rename to archive/quarantined-legacy-stack/scripts/deploy/upload-seals-to-azure.sh diff --git a/scripts/deploy/verify-complete-setup.sh b/archive/quarantined-legacy-stack/scripts/deploy/verify-complete-setup.sh similarity index 100% rename from scripts/deploy/verify-complete-setup.sh rename to archive/quarantined-legacy-stack/scripts/deploy/verify-complete-setup.sh diff --git a/scripts/test/generate-test-data.sh b/archive/quarantined-legacy-stack/scripts/test/generate-test-data.sh similarity index 100% rename from scripts/test/generate-test-data.sh rename to archive/quarantined-legacy-stack/scripts/test/generate-test-data.sh diff --git a/scripts/test/run-integration-tests-with-setup.sh b/archive/quarantined-legacy-stack/scripts/test/run-integration-tests-with-setup.sh similarity index 100% rename from scripts/test/run-integration-tests-with-setup.sh rename to archive/quarantined-legacy-stack/scripts/test/run-integration-tests-with-setup.sh diff --git a/scripts/test/test-all-entra-features.sh b/archive/quarantined-legacy-stack/scripts/test/test-all-entra-features.sh similarity index 100% rename from scripts/test/test-all-entra-features.sh rename to archive/quarantined-legacy-stack/scripts/test/test-all-entra-features.sh diff --git a/scripts/test/test-entra-integration.sh b/archive/quarantined-legacy-stack/scripts/test/test-entra-integration.sh similarity index 100% rename from scripts/test/test-entra-integration.sh rename to archive/quarantined-legacy-stack/scripts/test/test-entra-integration.sh diff --git a/scripts/validation/validate-entra-config.sh b/archive/quarantined-legacy-stack/scripts/validation/validate-entra-config.sh similarity index 100% rename from scripts/validation/validate-entra-config.sh rename to archive/quarantined-legacy-stack/scripts/validation/validate-entra-config.sh diff --git a/services/identity/src/entra-integration.ts b/archive/quarantined-legacy-stack/services/identity/src/entra-integration.ts similarity index 100% rename from services/identity/src/entra-integration.ts rename to archive/quarantined-legacy-stack/services/identity/src/entra-integration.ts diff --git a/services/identity/src/entra-webhooks.ts b/archive/quarantined-legacy-stack/services/identity/src/entra-webhooks.ts similarity index 100% rename from services/identity/src/entra-webhooks.ts rename to archive/quarantined-legacy-stack/services/identity/src/entra-webhooks.ts diff --git a/services/identity/src/logic-apps-workflows.ts b/archive/quarantined-legacy-stack/services/identity/src/logic-apps-workflows.ts similarity index 100% rename from services/identity/src/logic-apps-workflows.ts rename to archive/quarantined-legacy-stack/services/identity/src/logic-apps-workflows.ts diff --git a/assets/credential-images/README.md b/assets/credential-images/README.md index d6cfdd1..b786ee1 100644 --- a/assets/credential-images/README.md +++ b/assets/credential-images/README.md @@ -53,7 +53,7 @@ All seals follow a consistent design language: ### For Credential Images -1. **Convert to PNG** (for Entra VerifiedID compatibility): +1. **Convert to PNG** (for broad credential client compatibility): ```bash ./scripts/tools/convert-svg-to-png.sh svg/digital-bank-seal.svg png/digital-bank-seal.png 200 200 ``` @@ -70,18 +70,11 @@ All seals follow a consistent design language: ### In Code -```typescript -import { EntraVerifiedIDClient } from '@the-order/auth'; - -const client = new EntraVerifiedIDClient({ - // ... - logoUri: 'https://cdn.theorder.org/images/digital-bank-seal.png', -}); -``` +Use the uploaded logo URL in your active credential issuer configuration. ### In Manifest Templates -Update manifest templates in `manifests/entra/` with appropriate seal URLs: +Update your active credential templates with appropriate seal URLs: ```json { @@ -139,4 +132,3 @@ These seals are designed for use with The Order's verifiable credentials system. **Design Heritage**: Order of St John (OSJ) **Central Symbol**: Maltese Cross (8-pointed) **Last Updated**: [Current Date] - diff --git a/docs/DEVELOPMENT_SETUP.md b/docs/DEVELOPMENT_SETUP.md index 8bd34e7..34c4349 100644 --- a/docs/DEVELOPMENT_SETUP.md +++ b/docs/DEVELOPMENT_SETUP.md @@ -40,11 +40,6 @@ pnpm dev 2. Configure required variables: ```bash - # Azure Configuration - AZURE_SUBSCRIPTION_ID="your-subscription-id" - AZURE_TENANT_ID="your-tenant-id" - AZURE_LOCATION="westeurope" - # Database DATABASE_URL="postgresql://user:pass@localhost:5432/theorder_dev" @@ -52,10 +47,7 @@ pnpm dev REDIS_URL="redis://localhost:6379" ``` -3. Load environment: - ```bash - source infra/scripts/azure-load-env.sh - ``` +3. Load environment in your shell before running services. ## Development Workflow diff --git a/docs/GETTING_STARTED.md b/docs/GETTING_STARTED.md index 6cc667a..397f52f 100644 --- a/docs/GETTING_STARTED.md +++ b/docs/GETTING_STARTED.md @@ -7,8 +7,7 @@ Welcome to The Order! This guide will help you get started with development, dep - **Node.js**: 20.x or later - **pnpm**: 8.x or later - **Docker**: For containerized services -- **Azure CLI**: For Azure deployments -- **Terraform**: For infrastructure as code +- **SSH / operator access**: For Sankofa Phoenix deployments - **kubectl**: For Kubernetes operations ## Quick Start @@ -78,7 +77,7 @@ pnpm test pnpm build ``` -### Deploying to Azure +### Deploying to Sankofa Phoenix ```bash ./scripts/deploy/deploy.sh --all --environment dev ``` @@ -101,11 +100,10 @@ The Order is a monorepo with: - **Services**: Backend microservices (Identity, Intake, Finance, etc.) - **Packages**: Shared libraries and utilities - **Apps**: Frontend applications (Portals) -- **Infrastructure**: Terraform, Kubernetes, CI/CD +- **Infrastructure**: Proxmox, Kubernetes, CI/CD See [Architecture Documentation](architecture/README.md) for details. --- **Last Updated**: 2025-01-27 - diff --git a/docs/NAVIGATION.md b/docs/NAVIGATION.md index 2db48cf..c6520bf 100644 --- a/docs/NAVIGATION.md +++ b/docs/NAVIGATION.md @@ -1,217 +1,57 @@ # Documentation Navigation Guide -**Last Updated**: 2025-01-27 -**Purpose**: Quick navigation guide for all project documentation +**Last Updated**: 2026-04-16 +**Purpose**: Quick navigation guide for active The Order documentation -## Quick Links +## Core Paths -### 🚀 Getting Started -- [Main README](../README.md) - Project overview -- [Project Structure](../PROJECT_STRUCTURE.md) - Complete structure guide -- [Quick Start Guide](../QUICKSTART.md) - Development setup +### Getting Started +- [Main README](../README.md) +- [Project Structure](../PROJECT_STRUCTURE.md) +- [Quick Start Guide](../QUICKSTART.md) -### 📐 Architecture -- [Architecture Overview](architecture/README.md) - System architecture -- [Cloud for Sovereignty Landing Zone](architecture/CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md) - Complete architecture -- [Sovereignty Landing Zone Summary](architecture/SOVEREIGNTY_LANDING_ZONE_SUMMARY.md) - Executive summary +### Architecture +- [Architecture Overview](architecture/README.md) -### 🚢 Deployment -- [Deployment Overview](deployment/README.md) - Deployment guide index -- [Azure Environment Setup](deployment/azure/ENVIRONMENT_SETUP.md) - Azure configuration -- [Sovereignty Landing Zone Deployment](deployment/azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md) - Multi-region deployment -- [Azure CDN Setup](deployment/azure/cdn-setup.md) - CDN configuration -- [Entra VerifiedID](deployment/azure/entra-verifiedid.md) - Entra setup +### Deployment +- [Deployment Overview](deployment/overview.md) +- [Deployment Quick Reference](deployment/DEPLOYMENT_QUICK_REFERENCE.md) -### 🔌 Integrations -- [Integrations Overview](integrations/README.md) - Integration index -- [Entra VerifiedID](integrations/entra-verifiedid/README.md) - Credential issuance -- [Microsoft Entra VerifiedID](integrations/entra-verifiedid/README.md) - Complete guide +### Integrations +- [Integrations Overview](integrations/README.md) -### ⚖️ Legal System -- [Legal Documentation](legal/README.md) - Legal system overview -- [Document Management](legal/document-management/) - DMS documentation -- [Implementation Guide](legal/document-management/implementation/) - Implementation details +### Governance +- [Governance Overview](governance/README.md) +- [Security](governance/SECURITY.md) -### 🏛️ Governance -- [Governance Overview](governance/README.md) - Governance index -- [Contributing](governance/CONTRIBUTING.md) - Contribution guidelines -- [Security](governance/SECURITY.md) - Security policies +### Reports +- [Reports Overview](reports/README.md) +- [Task Completion Status](reports/TASK_COMPLETION_STATUS.md) -### 📊 Reports -- [Reports Overview](reports/README.md) - Project reports index -- [Comprehensive Project Review](reports/COMPREHENSIVE_PROJECT_REVIEW.md) - Full review -- [Remaining Steps](reports/REMAINING_STEPS_COMPLETE.md) - Task list -- [Task Completion Status](reports/TASK_COMPLETION_STATUS.md) - Progress tracking +## By Role -## Documentation by Role - -### 👨‍💻 Developers - -**Getting Started** +### Developers 1. [README](../README.md) 2. [Project Structure](../PROJECT_STRUCTURE.md) -3. [Quick Start](../QUICKSTART.md) +3. [Architecture Overview](architecture/README.md) -**Backend Development** -- [Architecture](architecture/README.md) -- Service READMEs in `services/*/README.md` -- Package READMEs in `packages/*/README.md` - -**Frontend Development** -- [Architecture](architecture/README.md) -- App READMEs in `apps/*/README.md` -- [UI Package](../packages/ui/README.md) - -### 🏗️ Infrastructure Engineers - -**Infrastructure** +### Infrastructure Engineers 1. [Infrastructure README](../infra/README.md) -2. [Terraform Guide](../infra/terraform/README.md) -3. [Kubernetes Guide](../infra/k8s/README.md) +2. [Kubernetes Guide](../infra/k8s/README.md) +3. [Deployment Quick Reference](deployment/DEPLOYMENT_QUICK_REFERENCE.md) -**Azure Deployment** -1. [Environment Setup](deployment/azure/ENVIRONMENT_SETUP.md) -2. [Sovereignty Landing Zone](deployment/azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md) -3. [CDN Setup](deployment/azure/cdn-setup.md) - -**Cloud Architecture** -1. [Cloud for Sovereignty Landing Zone](architecture/CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md) -2. [Well-Architected Framework](architecture/README.md) - -### 🔐 Security Engineers - -**Security** +### Security Engineers 1. [Security Policies](governance/SECURITY.md) -2. [Architecture Security](architecture/README.md#security) -3. [Compliance](governance/README.md#compliance) +2. [Governance Overview](governance/README.md) +3. [Architecture Overview](architecture/README.md) -**Compliance** -1. [Cloud for Sovereignty](architecture/CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md) -2. [GDPR Compliance](governance/README.md) -3. [eIDAS Compliance](integrations/entra-verifiedid/README.md) - -### 📋 Project Managers - -**Project Status** +### Project Managers 1. [Task Completion Status](reports/TASK_COMPLETION_STATUS.md) -2. [Comprehensive Review](reports/COMPREHENSIVE_PROJECT_REVIEW.md) -3. [Remaining Steps](reports/REMAINING_STEPS_COMPLETE.md) +2. [Deployment Overview](deployment/overview.md) +3. [Legacy Provider Archive](../archive/quarantined-legacy-stack/README.md) -**Architecture** -1. [Sovereignty Landing Zone Summary](architecture/SOVEREIGNTY_LANDING_ZONE_SUMMARY.md) -2. [Architecture Overview](architecture/README.md) +## Historical Material -## Documentation Structure - -``` -docs/ -├── README.md # This file -├── architecture/ # Architecture documentation -│ ├── README.md # Architecture overview -│ ├── CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md -│ └── SOVEREIGNTY_LANDING_ZONE_SUMMARY.md -├── deployment/ # Deployment guides -│ ├── README.md # Deployment index -│ └── azure/ # Azure-specific guides -│ ├── ENVIRONMENT_SETUP.md -│ ├── SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md -│ ├── DOTENV_SETUP.md -│ ├── cdn-setup.md -│ └── entra-verifiedid.md -├── integrations/ # Integration documentation -│ ├── README.md # Integration index -│ └── entra-verifiedid/ # Entra VerifiedID -│ └── README.md -├── legal/ # Legal system documentation -│ ├── README.md # Legal system overview -│ └── document-management/ # Document management -│ └── implementation/ # Implementation details -├── governance/ # Governance & policies -│ ├── README.md # Governance overview -│ ├── CONTRIBUTING.md -│ └── SECURITY.md -└── reports/ # Project reports - ├── README.md # Reports index - ├── COMPREHENSIVE_PROJECT_REVIEW.md - ├── REMAINING_STEPS_COMPLETE.md - └── TASK_COMPLETION_STATUS.md -``` - -## Finding Documentation - -### By Topic - -**Architecture** -- All files in `docs/architecture/` - -**Deployment** -- All files in `docs/deployment/` - -**Integrations** -- All files in `docs/integrations/` - -**Legal System** -- All files in `docs/legal/` - -**Governance** -- All files in `docs/governance/` - -**Reports** -- All files in `docs/reports/` - -### By File Type - -**README Files** - Directory overviews -```bash -find docs -name README.md -``` - -**Guides** - How-to guides -```bash -find docs -name "*GUIDE*.md" -find docs -name "*SETUP*.md" -``` - -**Architecture** - Architecture documentation -```bash -find docs -name "*ARCHITECTURE*.md" -find docs -name "*LANDING*.md" -``` - -**Reports** - Status reports -```bash -find docs -name "*REPORT*.md" -find docs -name "*STATUS*.md" -find docs -name "*REVIEW*.md" -``` - -## Documentation Standards - -### File Naming -- `README.md` - Directory overview -- `*_SETUP.md` - Setup guides -- `*_DEPLOYMENT.md` - Deployment guides -- `*_GUIDE.md` - How-to guides -- `*_SUMMARY.md` - Executive summaries -- `*_REVIEW.md` - Reviews and analysis - -### Structure -- **Overview** - What is this? -- **Prerequisites** - What do I need? -- **Quick Start** - How do I start? -- **Detailed Guide** - Step-by-step instructions -- **Troubleshooting** - Common issues -- **References** - Additional resources - -## Contributing to Documentation - -1. Follow existing structure -2. Use consistent naming -3. Include examples -4. Keep it up to date -5. Add to navigation (this file) - ---- - -**Last Updated**: 2025-01-27 +Provider-specific historical documents have been quarantined under: +- `../archive/quarantined-legacy-stack/` diff --git a/docs/README.md b/docs/README.md index 6c700db..59d4b39 100644 --- a/docs/README.md +++ b/docs/README.md @@ -1,125 +1,44 @@ # Documentation Index -**Last Updated**: 2025-01-27 -**Purpose**: Central navigation hub for all project documentation +**Last Updated**: 2026-04-16 +**Purpose**: Central navigation hub for active The Order documentation ## Quick Navigation -📖 **[Navigation Guide](NAVIGATION.md)** - Complete documentation navigation +- [Navigation Guide](NAVIGATION.md) +- [Project Structure](../PROJECT_STRUCTURE.md) +- [Deployment Overview](deployment/overview.md) +- [Deployment Quick Reference](deployment/DEPLOYMENT_QUICK_REFERENCE.md) +- [Architecture Overview](architecture/README.md) -## Documentation by Category +## Active Documentation -### 🚀 Getting Started -- [Main README](../README.md) - Project overview and quick start -- [Project Structure](../PROJECT_STRUCTURE.md) - Complete structure guide -- [Quick Start Guide](../QUICKSTART.md) - Development setup +### Getting Started +- [Main README](../README.md) +- [Quick Start Guide](../QUICKSTART.md) +- [Project Structure](../PROJECT_STRUCTURE.md) -### 📐 Architecture -- [Architecture Overview](architecture/README.md) - System architecture -- [Cloud for Sovereignty Landing Zone](architecture/CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md) - Complete architecture -- [Sovereignty Landing Zone Summary](architecture/SOVEREIGNTY_LANDING_ZONE_SUMMARY.md) - Executive summary +### Architecture +- [Architecture Overview](architecture/README.md) -### 🚢 Deployment -- [Deployment Overview](deployment/README.md) - Deployment guide index -- [Azure Environment Setup](deployment/azure/ENVIRONMENT_SETUP.md) - Azure configuration -- [Sovereignty Landing Zone Deployment](deployment/azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md) - Multi-region deployment -- [Azure CDN Setup](deployment/azure/cdn-setup.md) - CDN configuration -- [Entra VerifiedID Setup](deployment/azure/entra-verifiedid.md) - Entra configuration -- [Dotenv Setup](deployment/azure/DOTENV_SETUP.md) - Environment variable configuration +### Deployment +- [Deployment Overview](deployment/overview.md) +- [Deployment Quick Reference](deployment/DEPLOYMENT_QUICK_REFERENCE.md) -### 🔌 Integrations -- [Integrations Overview](integrations/README.md) - Integration index -- [Entra VerifiedID](integrations/entra-verifiedid/README.md) - Credential issuance guide +### Integrations +- [Integrations Overview](integrations/README.md) -### ⚖️ Legal System -- [Legal Documentation](legal/README.md) - Legal system overview -- [Document Management](legal/document-management/) - DMS documentation -- [Implementation Guide](legal/document-management/implementation/) - Implementation details +### Governance +- [Governance Overview](governance/README.md) +- [Contributing Guidelines](governance/CONTRIBUTING.md) +- [Security Policies](governance/SECURITY.md) -### 🏛️ Governance -- [Governance Overview](governance/README.md) - Governance index -- [Contributing Guidelines](governance/CONTRIBUTING.md) - How to contribute -- [Security Policies](governance/SECURITY.md) - Security guidelines +### Reports +- [Reports Overview](reports/README.md) +- [Task Completion Status](reports/TASK_COMPLETION_STATUS.md) -### 📊 Reports & Status -- [Reports Overview](reports/README.md) - Project reports index -- [Comprehensive Project Review](reports/COMPREHENSIVE_PROJECT_REVIEW.md) - Full project review -- [Remaining Steps](reports/REMAINING_STEPS_COMPLETE.md) - Task list -- [Task Completion Status](reports/TASK_COMPLETION_STATUS.md) - Progress tracking +## Historical Material -## Documentation by Role +Provider-specific historical documents have been quarantined under: -### For Developers -1. Start: [README](../README.md) -2. Structure: [PROJECT_STRUCTURE.md](../PROJECT_STRUCTURE.md) -3. Architecture: [Architecture Overview](architecture/README.md) -4. Service Docs: `services/*/README.md` -5. Package Docs: `packages/*/README.md` - -### For Infrastructure Engineers -1. Infrastructure: [Infrastructure README](../infra/README.md) -2. Terraform: [Terraform Guide](../infra/terraform/README.md) -3. Kubernetes: [K8s Guide](../infra/k8s/README.md) -4. Azure: [Azure Deployment Guides](deployment/azure/) - -### For Security Engineers -1. Security: [Security Policies](governance/SECURITY.md) -2. Architecture: [Architecture Security](architecture/README.md#security) -3. Compliance: [Cloud for Sovereignty](architecture/CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md) - -### For Project Managers -1. Status: [Task Completion Status](reports/TASK_COMPLETION_STATUS.md) -2. Review: [Comprehensive Review](reports/COMPREHENSIVE_PROJECT_REVIEW.md) -3. Summary: [Sovereignty Landing Zone Summary](architecture/SOVEREIGNTY_LANDING_ZONE_SUMMARY.md) - -## Documentation Structure - -``` -docs/ -├── README.md # This file -├── NAVIGATION.md # Navigation guide -├── architecture/ # Architecture documentation -├── deployment/ # Deployment guides -│ └── azure/ # Azure-specific -├── integrations/ # Integration documentation -├── legal/ # Legal system documentation -├── governance/ # Governance & policies -└── reports/ # Project reports -``` - -## Finding Documentation - -### By Topic -- **Architecture**: `docs/architecture/` -- **Deployment**: `docs/deployment/` -- **Integrations**: `docs/integrations/` -- **Legal**: `docs/legal/` -- **Governance**: `docs/governance/` -- **Reports**: `docs/reports/` - -### By File Type -- **README.md**: Directory overviews -- ***_SETUP.md**: Setup guides -- ***_DEPLOYMENT.md**: Deployment guides -- ***_GUIDE.md**: How-to guides -- ***_SUMMARY.md**: Executive summaries - -## Contributing to Documentation - -1. Follow existing structure -2. Use consistent naming conventions -3. Include examples and code snippets -4. Keep documentation up to date -5. Update navigation files - -## Quick Links - -- 📖 [Complete Navigation Guide](NAVIGATION.md) -- 🏗️ [Project Structure](../PROJECT_STRUCTURE.md) -- 🚀 [Quick Start](../QUICKSTART.md) -- 📐 [Architecture](architecture/README.md) -- 🚢 [Deployment](deployment/README.md) - ---- - -**Last Updated**: 2025-01-27 +- `../archive/quarantined-legacy-stack/` diff --git a/docs/architecture/README.md b/docs/architecture/README.md index dbe15f5..5e30170 100644 --- a/docs/architecture/README.md +++ b/docs/architecture/README.md @@ -1,283 +1,12 @@ -# Architecture Documentation +# Architecture Overview -**Last Updated**: 2025-01-27 -**Status**: Comprehensive Architecture Guide +The current operational architecture for The Order is centered on Sankofa Phoenix / Proxmox deployment targets, with service and portal delivery routed through the Sankofa runtime. -## Overview +For active operator work, start with: -This directory contains comprehensive architecture documentation for The Order platform, including system design, data models, deployment architecture, and architectural decision records (ADRs). +- `docs/deployment/overview.md` +- `docs/deployment/DEPLOYMENT_QUICK_REFERENCE.md` -## Documentation Index +Historical provider-era architecture documents have been quarantined under: -### Core Architecture -- [Cloud for Sovereignty Landing Zone](CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md) - Complete multi-region architecture -- [Sovereignty Landing Zone Summary](SOVEREIGNTY_LANDING_ZONE_SUMMARY.md) - Executive summary - -### System Design -- **Microservices Architecture**: See service documentation in `services/*/README.md` -- **Data Models**: Entity relationships and database schema -- **API Design**: RESTful APIs with OpenAPI/Swagger documentation -- **Security Architecture**: Zero-trust, defense in depth - -## Architecture Principles - -### Well-Architected Framework - -The Order follows Azure Well-Architected Framework principles: - -1. **Cost Optimization** - - Right-sized resources - - Reserved instances - - Cost allocation tags - - Budget alerts - -2. **Operational Excellence** - - Infrastructure as Code - - Automated deployments - - Centralized logging - - Runbooks and playbooks - -3. **Performance Efficiency** - - Regional proximity - - CDN for global delivery - - Auto-scaling - - Performance monitoring - -4. **Reliability** - - Multi-region redundancy - - Availability Zones - - Automated failover - - RTO: 4 hours, RPO: 1 hour - -5. **Security** - - Zero-trust architecture - - Defense in depth - - Data encryption - - Identity and access management - -### Cloud for Sovereignty - -- **Data Residency**: All data within specified regions -- **Data Protection**: Customer-managed keys, private endpoints -- **Compliance**: GDPR, eIDAS, regional requirements -- **Operational Control**: Management groups, policy governance - -## System Architecture - -### High-Level Overview - -``` -┌─────────────────────────────────────────────────────────────┐ -│ Frontend Applications │ -│ ┌──────────────┐ ┌──────────────┐ ┌──────────────┐ │ -│ │ MCP Legal │ │ Portal Public│ │Portal Internal│ │ -│ └──────────────┘ └──────────────┘ └──────────────┘ │ -└─────────────────────────────────────────────────────────────┘ - │ - ▼ -┌─────────────────────────────────────────────────────────────┐ -│ API Gateway / Load Balancer │ -└─────────────────────────────────────────────────────────────┘ - │ - ┌───────────────────┼───────────────────┐ - ▼ ▼ ▼ -┌──────────────┐ ┌──────────────┐ ┌──────────────┐ -│ Identity │ │ Intake │ │ Finance │ -│ Service │ │ Service │ │ Service │ -└──────────────┘ └──────────────┘ └──────────────┘ - │ │ │ - ▼ ▼ ▼ -┌──────────────┐ ┌──────────────┐ ┌──────────────┐ -│ Dataroom │ │Legal Docs │ │ e-Residency │ -│ Service │ │ Service │ │ Service │ -└──────────────┘ └──────────────┘ └──────────────┘ - │ - ▼ -┌─────────────────────────────────────────────────────────────┐ -│ Shared Infrastructure │ -│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ │ -│ │PostgreSQL│ │ Redis │ │OpenSearch│ │ Azure │ │ -│ │ │ │ │ │ │ │ Storage │ │ -│ └──────────┘ └──────────┘ └──────────┘ └──────────┘ │ -└─────────────────────────────────────────────────────────────┘ -``` - -### Service Architecture - -Each service follows a consistent architecture: - -``` -Service -├── API Layer (Fastify) -│ ├── Routes -│ ├── Middleware -│ └── Validation -├── Service Layer -│ ├── Business Logic -│ ├── External Integrations -│ └── Error Handling -├── Data Layer -│ ├── Database Queries -│ ├── Caching -│ └── Storage -└── Infrastructure - ├── Health Checks - ├── Metrics - └── Logging -``` - -## Data Models - -### Core Entities - -- **User**: Member of The Order -- **Identity**: Digital identity (eIDAS/DID) -- **Credential**: Verifiable credential -- **Document**: Legal document -- **Matter**: Legal matter -- **Deal**: Business transaction -- **Payment**: Financial transaction - -### Relationships - -See entity relationship diagrams in service-specific documentation. - -## Deployment Architecture - -### Regional Deployment - -The Order is deployed across 7 non-US commercial Azure regions: - -1. **West Europe** (Netherlands) - Primary -2. **North Europe** (Ireland) - Secondary -3. **UK South** (London) -4. **Switzerland North** (Zurich) -5. **Norway East** (Oslo) -6. **France Central** (Paris) -7. **Germany West Central** (Frankfurt) - -### Per-Region Architecture - -Each region includes: -- Hub Virtual Network (gateway, firewall, management) -- Spoke Virtual Network (application, database, storage) -- Azure Firewall -- Key Vault (with private endpoint) -- Storage Account (with private endpoint) -- Log Analytics Workspace -- AKS Cluster (optional) - -### Network Architecture - -- **Hub-and-Spoke**: Centralized connectivity -- **Private Endpoints**: Secure service access -- **Azure Firewall**: Centralized security -- **VNet Peering**: Hub-to-spoke connectivity - -## Security Architecture - -### Zero-Trust Principles - -- **Identity Verification**: Always verify identity -- **Least Privilege**: Minimum required access -- **Network Segmentation**: Isolated networks -- **Encryption**: At rest and in transit -- **Monitoring**: Continuous security monitoring - -### Defense in Depth - -1. **Perimeter**: Azure Firewall, WAF -2. **Network**: NSGs, Private Endpoints -3. **Application**: Authentication, Authorization -4. **Data**: Encryption, Access Controls -5. **Identity**: MFA, RBAC, PIM - -## Monitoring & Observability - -### Metrics -- Application metrics (Prometheus) -- Infrastructure metrics (Azure Monitor) -- Business metrics (Custom dashboards) - -### Logging -- Structured logging (JSON) -- Centralized log aggregation (Log Analytics) -- Log retention (90 days production) - -### Tracing -- Distributed tracing (OpenTelemetry) -- Request flow visualization -- Performance analysis - -## Disaster Recovery - -### Strategy -- **RTO**: 4 hours -- **RPO**: 1 hour -- **Primary Region**: West Europe -- **Secondary Region**: North Europe -- **Backup Regions**: Other 5 regions - -### Backup Strategy -- Database: Daily full, hourly incremental -- Storage: Cross-region replication -- Configuration: Version controlled - -## Technology Stack - -### Frontend -- React 18+ -- Next.js 14+ -- TypeScript -- Tailwind CSS -- Material-UI - -### Backend -- Node.js 18+ -- TypeScript -- Fastify -- PostgreSQL -- Redis - -### Infrastructure -- Azure (non-US commercial) -- Kubernetes -- Terraform -- Docker - -### Monitoring -- Prometheus -- Grafana -- OpenTelemetry -- Log Analytics - -## Design Decisions - -### Why Microservices? -- Independent scaling -- Technology diversity -- Team autonomy -- Fault isolation - -### Why Azure (Non-US)? -- Data sovereignty requirements -- GDPR compliance -- Regional data residency -- Cloud for Sovereignty - -### Why Kubernetes? -- Container orchestration -- Auto-scaling -- Rolling updates -- Service discovery - -## Related Documentation - -- [Cloud for Sovereignty Landing Zone](CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md) -- [Deployment Guides](../deployment/README.md) -- [Service Documentation](../../services/*/README.md) -- [Infrastructure Documentation](../../infra/README.md) - ---- - -**Last Updated**: 2025-01-27 +- `archive/quarantined-legacy-stack/docs/architecture/` diff --git a/docs/archive/README.md b/docs/archive/README.md index e446397..638f873 100644 --- a/docs/archive/README.md +++ b/docs/archive/README.md @@ -1,95 +1,7 @@ -# Documentation Archive +# Historical Documentation Archive -This directory contains historical and superseded documentation that has been consolidated or replaced. +This directory contains historical documentation retained for reference. -## Purpose - -Documents in this archive are: -- **Superseded**: Replaced by newer, consolidated versions -- **Historical**: Preserved for reference but no longer actively maintained -- **Duplicate**: Merged into single authoritative documents - -## Archive Structure - -``` -archive/ -├── reports/ # Historical status and task reports -├── deployment/ # Superseded deployment documentation -│ ├── azure-cdn/ # Old Azure CDN setup files (merged into azure/cdn-setup.md) -│ ├── entra/ # Old Entra VerifiedID files (merged into azure/entra-verifiedid.md) -│ └── automation/ # Old automation files (merged into automation/seal-deployment.md) -``` - -## What Was Consolidated - -### Reports Directory -- **Completion Files**: Merged into `reports/current-status.md` - - `COMPLETION_STATUS.md` - - `COMPLETION_SUMMARY.md` - - `TASK_COMPLETION_SUMMARY.md` - -- **Task Lists**: Merged into `reports/active-tasks.md` - - `REMAINING_TASKS.md` - - `REMAINING_TODOS.md` - - `ALL_REMAINING_TASKS.md` - - `REMAINING_TODOS_QUICK_REFERENCE.md` - - `REMAINING_TASKS_CREDENTIAL_AUTOMATION.md` - -- **Gap Analysis**: Moved to `legal/document-management/implementation/gaps-analysis.md` - - `GAPS_SUMMARY.md` - - `GAPS_AND_PLACEHOLDERS.md` - -- **Frontend Docs**: Moved to `product/features/` - - `FRONTEND_COMPLETE.md` → `product/features/frontend-completion.md` - - `FRONTEND_COMPONENTS_VERIFICATION.md` → `product/features/frontend-components.md` - -- **Deprecation Files**: Historical (ESLint 9 migration complete) - - `DEPRECATION_FIXES_COMPLETE.md` - - `DEPRECATION_FIXES_RECOMMENDATIONS.md` - - `FINAL_DEPRECATION_STATUS.md` - -### Deployment Directory -- **Azure CDN Files**: Merged into `deployment/azure/cdn-setup.md` - - `AZURE_CDN_SETUP.md` - - `AZURE_CDN_COMPLETE.md` - - `AZURE_CDN_STATUS.md` - - `AZURE_CDN_FINAL_STATUS.md` - - `AZURE_CDN_QUICK_START.md` - - `AZURE_CDN_SETUP_COMPLETE.md` - -- **Entra VerifiedID Files**: Merged into `deployment/azure/entra-verifiedid.md` - - `ENTRA_COMPLETE_SUMMARY.md` - - `ENTRA_VERIFIEDID_DEPLOYMENT_CHECKLIST.md` - - `ENTRA_VERIFIEDID_NEXT_STEPS.md` - -- **Automation Files**: Merged into `deployment/automation/seal-deployment.md` - - `AUTOMATION_COMPLETE.md` - - `AUTOMATION_SUMMARY.md` - - `SEAL_DEPLOYMENT_AUTOMATION.md` (moved, not archived) - -## Accessing Archived Content - -Archived files are preserved for: -- **Historical Reference**: Understanding project evolution -- **Context**: Seeing what was consolidated and why -- **Recovery**: If consolidation missed important details - -## Finding Current Documentation - -- **Current Status**: `docs/reports/current-status.md` -- **Active Tasks**: `docs/reports/active-tasks.md` -- **Azure CDN Setup**: `docs/deployment/azure/cdn-setup.md` -- **Entra VerifiedID**: `docs/deployment/azure/entra-verifiedid.md` -- **Deployment Overview**: `docs/deployment/overview.md` - -## Maintenance - -- Archive is **read-only** - do not update archived files -- New consolidations should note what was merged -- Archive structure may be reorganized if it grows too large - ---- - -**Archive Created**: 2025-01-27 -**Last Updated**: 2025-01-27 +Provider-specific legacy material has been moved into the dedicated quarantine tree: +- `../../archive/quarantined-legacy-stack/` diff --git a/docs/configuration/ENVIRONMENT_VARIABLES.md b/docs/configuration/ENVIRONMENT_VARIABLES.md index 2e9e8d5..0eba5bb 100644 --- a/docs/configuration/ENVIRONMENT_VARIABLES.md +++ b/docs/configuration/ENVIRONMENT_VARIABLES.md @@ -121,57 +121,6 @@ These variables must be set for the application to function properly. - **Example**: `eidas-api-key-here` - **Used By**: Identity service, eIDAS bridge -#### `ENTRA_TENANT_ID` -- **Type**: String -- **Required**: No -- **Description**: Azure AD tenant ID for Microsoft Entra VerifiedID -- **Example**: `12345678-1234-1234-1234-123456789012` -- **Used By**: Identity service - -#### `ENTRA_CLIENT_ID` -- **Type**: String -- **Required**: No -- **Description**: Azure AD application (client) ID for Microsoft Entra VerifiedID -- **Example**: `87654321-4321-4321-4321-210987654321` -- **Used By**: Identity service - -#### `ENTRA_CLIENT_SECRET` -- **Type**: String -- **Required**: No -- **Description**: Azure AD client secret for Microsoft Entra VerifiedID -- **Example**: `client-secret-value` -- **Used By**: Identity service - -#### `ENTRA_CREDENTIAL_MANIFEST_ID` -- **Type**: String -- **Required**: No -- **Description**: Credential manifest ID from Azure Verified ID portal -- **Example**: `urn:uuid:12345678-1234-1234-1234-123456789012` -- **Used By**: Identity service - -#### `AZURE_LOGIC_APPS_WORKFLOW_URL` -- **Type**: String (URL) -- **Required**: No -- **Description**: Azure Logic Apps workflow URL -- **Example**: `https://your-logic-app.azurewebsites.net` -- **Used By**: Identity service, workflows - -#### `AZURE_LOGIC_APPS_ACCESS_KEY` -- **Type**: String -- **Required**: No -- **Description**: Azure Logic Apps access key (if not using managed identity) -- **Example**: `access-key-here` -- **Used By**: Identity service, workflows - -#### `AZURE_LOGIC_APPS_MANAGED_IDENTITY_CLIENT_ID` -- **Type**: String -- **Required**: No -- **Description**: Managed identity client ID for Logic Apps authentication -- **Example**: `managed-identity-client-id` -- **Used By**: Identity service, workflows - ---- - ## Optional Variables ### OpenID Connect (OIDC) @@ -509,4 +458,3 @@ All environment variables are validated at application startup using Zod schemas - [Architecture Documentation](../architecture/README.md) - [Deployment Guide](../deployment/README.md) - [Security Documentation](../governance/SECURITY.md) - diff --git a/docs/deployment/DEPLOYMENT_QUICK_REFERENCE.md b/docs/deployment/DEPLOYMENT_QUICK_REFERENCE.md index 1238f27..35401c8 100644 --- a/docs/deployment/DEPLOYMENT_QUICK_REFERENCE.md +++ b/docs/deployment/DEPLOYMENT_QUICK_REFERENCE.md @@ -1,7 +1,7 @@ # Deployment Quick Reference -**Last Updated**: 2025-01-27 -**Purpose**: Quick command reference for deployment operations +**Last Updated**: 2026-04-16 +**Purpose**: Quick command reference for The Order deployment operations on Sankofa Phoenix / Proxmox --- @@ -11,13 +11,12 @@ # Verify tools node --version # >= 18.0.0 pnpm --version # >= 8.0.0 -az --version # Azure CLI -terraform --version # >= 1.5.0 -kubectl version # Kubernetes CLI -docker --version # Docker +docker --version +ssh -V +tar --version -# Verify Azure login -az account show +# Verify Proxmox access +ssh root@192.168.11.11 "echo ok" ``` --- @@ -25,66 +24,39 @@ az account show ## Phase 1: Prerequisites ```bash -# Clone and setup git clone && cd the-order git submodule update --init --recursive pnpm install --frozen-lockfile -pnpm build +./scripts/deploy/phase1-prerequisites.sh ``` --- -## Phase 2: Azure Infrastructure +## Phase 2: Sankofa Phoenix Target Preparation ```bash -# Run setup scripts -./infra/scripts/azure-setup.sh -./infra/scripts/azure-register-providers.sh -./infra/scripts/azure-check-quotas.sh +./scripts/deploy/phase2-sankofa-phoenix-target.sh -# Terraform -cd infra/terraform -terraform init -terraform plan -terraform apply +# Preview the Order edge config directly from the parent Proxmox workspace +bash ../scripts/deployment/provision-order-haproxy-10210.sh --dry-run ``` --- -## Phase 3: Entra ID +## Phase 3: Identity Provider Secrets ```bash -# Configure in Azure Portal -# Then store secrets: -az keyvault secret set --vault-name --name "entra-tenant-id" --value "..." -az keyvault secret set --vault-name --name "entra-client-id" --value "..." -az keyvault secret set --vault-name --name "entra-client-secret" --value "..." -az keyvault secret set --vault-name --name "entra-credential-manifest-id" --value "..." +# Confirm the local env file has the issuer values this environment needs. +./scripts/deploy/phase3-identity-secrets.sh ``` --- -## Phase 4: Database & Storage +## Phase 5: Local Artifact / Runtime Preparation ```bash -# Create databases (via Azure Portal or CLI) -az postgres db create --resource-group --server-name --name theorder_dev - -# Create storage containers -az storage container create --name intake-documents --account-name -az storage container create --name dataroom-deals --account-name -``` - ---- - -## Phase 5: Container Registry - -```bash -# Login to ACR -az acr login --name - -# Attach to AKS -az aks update -n -g --attach-acr +./scripts/deploy/phase5-container-registry.sh +cat .deployment/artifacts/image-manifest-dev.txt ``` --- @@ -92,65 +64,11 @@ az aks update -n -g --attach-acr ## Phase 6: Build & Package ```bash -# Build packages -pnpm build +# Build packages and local images +./scripts/deploy/phase6-build-package.sh -# Build and push images (after Dockerfiles created) -docker build -t .azurecr.io/identity:latest -f services/identity/Dockerfile . -docker push .azurecr.io/identity:latest - -# Repeat for: intake, finance, dataroom, portal-public, portal-internal -``` - ---- - -## Phase 7: Database Migrations - -```bash -export DATABASE_URL="postgresql://user:pass@host:5432/theorder_dev" -pnpm --filter @the-order/database migrate up -``` - ---- - -## Phase 8: Secrets - -```bash -# Store all secrets in Azure Key Vault -az keyvault secret set --vault-name --name --value "" - -# Configure External Secrets Operator -kubectl apply -f https://external-secrets.io/latest/deploy/ -# Then apply SecretStore and ExternalSecret resources -``` - ---- - -## Phase 9: Infrastructure Services - -```bash -# External Secrets -kubectl apply -f https://external-secrets.io/latest/deploy/ - -# Prometheus & Grafana -helm repo add prometheus-community https://prometheus-community.github.io/helm-charts -helm install prometheus prometheus-community/kube-prometheus-stack -``` - ---- - -## Phase 10: Backend Services - -```bash -# Get AKS credentials -az aks get-credentials --resource-group --name - -# Deploy services -kubectl apply -k infra/k8s/overlays/dev - -# Verify -kubectl get pods -n the-order-dev -kubectl logs -f -n the-order-dev +# Preview the Phoenix sync artifact only +./scripts/deploy/sync-portal-public-to-sankofa-phoenix.sh --dry-run --skip-build ``` --- @@ -158,15 +76,16 @@ kubectl logs -f -n the-order-dev ## Phase 11: Frontend Apps ```bash -# Deploy frontend apps through the standard automation flow +# Standard deploy ./scripts/deploy/deploy.sh --phase 11 --environment dev -# Or run the phase directly -ENVIRONMENT=dev IMAGE_TAG= ./scripts/deploy/phase11-frontend-apps.sh +# Direct sync +./scripts/deploy/sync-portal-public-to-sankofa-phoenix.sh # Verify -kubectl get pods -l app=portal-public -n the-order-dev -kubectl rollout status deployment/portal-public -n the-order-dev +curl -fsS http://192.168.11.36:3000/api/health +curl -fsS -H 'Host: the-order.sankofa.nexus' http://192.168.11.39/api/health +curl -fsS https://the-order.sankofa.nexus/api/health ``` --- @@ -174,14 +93,9 @@ kubectl rollout status deployment/portal-public -n the-order-dev ## Phase 12: Networking ```bash -# Deploy ingress -helm install ingress-nginx ingress-nginx/ingress-nginx - -# Apply ingress rules -kubectl apply -f infra/k8s/base/ingress.yaml - -# Verify -kubectl get ingress -n the-order-dev +# Refresh HAProxy and NPM routing from the parent Proxmox workspace +bash ../scripts/deployment/provision-order-haproxy-10210.sh +bash ../scripts/nginx-proxy-manager/update-npmplus-proxy-hosts-api.sh ``` --- @@ -189,11 +103,10 @@ kubectl get ingress -n the-order-dev ## Phase 13: Monitoring ```bash -# Application Insights -az monitor app-insights component create --app the-order-dev --location westeurope -g +./scripts/deploy/phase13-monitoring.sh -# Log Analytics -az monitor log-analytics workspace create --workspace-name the-order-dev-logs -g +# Tail logs directly +ssh root@192.168.11.11 "pct exec 10090 -- journalctl -u the-order-portal-public -f" ``` --- @@ -201,114 +114,39 @@ az monitor log-analytics workspace create --workspace-name the-order-dev-logs -g ## Phase 14: Testing ```bash -# Health checks -kubectl get pods -n the-order-dev -for svc in identity intake finance dataroom; do - kubectl port-forward svc/$svc : & - curl http://localhost:/health -done +./scripts/deploy/phase14-testing.sh -# Integration tests -curl https://api.theorder.org/identity/health -``` - ---- - -## Phase 15: Production - -```bash -# Scale deployments -kubectl scale deployment identity --replicas=3 -n the-order-prod - -# Apply production config -kubectl apply -k infra/k8s/overlays/prod +# Quick health probes +curl -fsS https://phoenix.sankofa.nexus/health +curl -fsS https://the-order.sankofa.nexus/api/health +pnpm --dir apps/portal-public test ``` --- ## Common Operations -### Check Deployment Status +### Check deployment status ```bash -kubectl get all -n the-order-dev -kubectl get pods -n the-order-dev -kubectl get svc -n the-order-dev -kubectl get ingress -n the-order-dev +ssh root@192.168.11.11 "pct status 10090 && pct status 10210" +curl -fsS https://the-order.sankofa.nexus/api/health ``` -### View Logs +### View logs ```bash -kubectl logs -f deployment/ -n the-order-dev -kubectl logs -f -n the-order-dev --tail=100 +ssh root@192.168.11.11 "pct exec 10090 -- journalctl -u the-order-portal-public -n 100 --no-pager" ``` -### Port Forward for Testing +### Restart the app ```bash -kubectl port-forward svc/identity 4002:4002 -kubectl port-forward svc/portal-public 3000:3000 +ssh root@192.168.11.11 "pct exec 10090 -- systemctl restart the-order-portal-public" ``` -### Restart Deployment +### Preview the public edge ```bash -kubectl rollout restart deployment/ -n the-order-dev +curl -i -H 'Host: the-order.sankofa.nexus' http://192.168.11.39/ ``` - -### Rollback - -```bash -kubectl rollout undo deployment/ -n the-order-dev -``` - -### Scale Services - -```bash -kubectl scale deployment/ --replicas=3 -n the-order-dev -``` - ---- - -## Troubleshooting - -### Pod Issues - -```bash -kubectl describe pod -n the-order-dev -kubectl logs -n the-order-dev -kubectl exec -it -n the-order-dev -- /bin/sh -``` - -### Service Issues - -```bash -kubectl get endpoints -n the-order-dev -kubectl describe svc -n the-order-dev -``` - -### Network Issues - -```bash -kubectl get ingress -n the-order-dev -kubectl describe ingress -n the-order-dev -``` - ---- - -## Environment Variables - -Key environment variables needed (store in Key Vault): - -- `DATABASE_URL` -- `ENTRA_TENANT_ID`, `ENTRA_CLIENT_ID`, `ENTRA_CLIENT_SECRET`, `ENTRA_CREDENTIAL_MANIFEST_ID` -- `STORAGE_BUCKET`, `STORAGE_REGION` -- `KMS_KEY_ID` -- `JWT_SECRET` -- `REDIS_URL` -- Service-specific variables - ---- - -**See `DEPLOYMENT_GUIDE.md` for detailed instructions.** diff --git a/docs/deployment/README.md b/docs/deployment/README.md index 60a34f1..6831d36 100644 --- a/docs/deployment/README.md +++ b/docs/deployment/README.md @@ -1,100 +1,12 @@ # Deployment Documentation -**Last Updated**: 2025-01-27 -**Purpose**: Complete deployment guide index +The active deployment model for The Order is Sankofa Phoenix / Proxmox native. -## Overview +Use these entry points: -This directory contains comprehensive deployment guides for The Order platform, covering infrastructure setup, service deployment, and operational procedures. +- [Deployment Overview](overview.md) +- [Deployment Quick Reference](DEPLOYMENT_QUICK_REFERENCE.md) -## Quick Links +Historical provider-specific deployment material has been quarantined under: -### Azure Deployment -- [Environment Setup](azure/ENVIRONMENT_SETUP.md) - Azure configuration and setup -- [Dotenv Configuration](azure/DOTENV_SETUP.md) - Using .env file for deployments -- [Sovereignty Landing Zone](azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md) - Multi-region deployment -- [CDN Setup](azure/cdn-setup.md) - Azure CDN configuration -- [Entra VerifiedID](azure/entra-verifiedid.md) - Entra VerifiedID setup - -### Kubernetes Deployment -- [Kubernetes Guide](../../infra/k8s/README.md) - K8s deployment guide -- [Service Manifests](../../infra/k8s/base/) - Base Kubernetes manifests - -### Infrastructure -- [Infrastructure Overview](../../infra/README.md) - Infrastructure documentation -- [Terraform Guide](../../infra/terraform/README.md) - Terraform documentation - -## Deployment Guides by Scenario - -### Initial Setup -1. [Azure Environment Setup](azure/ENVIRONMENT_SETUP.md) -2. [Dotenv Configuration](azure/DOTENV_SETUP.md) -3. [Infrastructure Deployment](../../infra/README.md) - -### Multi-Region Deployment -1. [Sovereignty Landing Zone Deployment](azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md) -2. [Cloud for Sovereignty Architecture](../../docs/architecture/CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md) - -### Service Deployment -1. [Kubernetes Deployment](../../infra/k8s/README.md) -2. Service-specific READMEs in `services/*/README.md` - -### Integration Setup -1. [Entra VerifiedID](azure/entra-verifiedid.md) -2. [CDN Configuration](azure/cdn-setup.md) -3. [Integration Guides](../integrations/) - -## Deployment Workflows - -### Complete Azure Deployment - -```bash -# 1. Load environment -source infra/scripts/azure-load-env.sh - -# 2. Validate configuration -./infra/scripts/azure-validate-current-env.sh - -# 3. Deploy infrastructure -./infra/scripts/azure-deploy.sh - -# 4. Deploy sovereignty landing zone -./infra/scripts/deploy-sovereignty-landing-zone.sh -``` - -### Kubernetes Deployment - -```bash -# 1. Apply base configuration -kubectl apply -k infra/k8s/base - -# 2. Apply environment overlay -kubectl apply -k infra/k8s/overlays/dev - -# 3. Verify deployment -kubectl get pods -n the-order -``` - -## Documentation Structure - -``` -deployment/ -├── README.md # This file -└── azure/ # Azure-specific guides - ├── ENVIRONMENT_SETUP.md - ├── DOTENV_SETUP.md - ├── SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md - ├── cdn-setup.md - └── entra-verifiedid.md -``` - -## Related Documentation - -- [Architecture Documentation](../architecture/) -- [Infrastructure Documentation](../../infra/) -- [Service Documentation](../../services/) -- [Integration Documentation](../integrations/) - ---- - -**Last Updated**: 2025-01-27 +- `../archive/quarantined-legacy-stack/` diff --git a/docs/deployment/automation/seal-deployment.md b/docs/deployment/automation/seal-deployment.md index 95d2ac3..cbe0791 100644 --- a/docs/deployment/automation/seal-deployment.md +++ b/docs/deployment/automation/seal-deployment.md @@ -186,10 +186,10 @@ assets/credential-images/ aws s3 cp digital-bank-seal.png s3://your-bucket/images/digital-bank-seal.png --acl public-read ``` -### Azure Blob Storage Example +### Generic Object Storage Example ```bash # In upload-to-cdn.sh -az storage blob upload --file digital-bank-seal.png --container-name images --name digital-bank-seal.png --account-name your-account +rclone copy digital-bank-seal.png remote:images/digital-bank-seal.png ``` ### Cloudflare R2 Example @@ -260,4 +260,3 @@ CDN_BASE_URL=https://your-cdn.com/images ./scripts/deploy/update-manifest-seal-u **Last Updated**: [Current Date] **Automation Status**: ✅ Complete - diff --git a/docs/deployment/overview.md b/docs/deployment/overview.md index 3495036..7e7f7f9 100644 --- a/docs/deployment/overview.md +++ b/docs/deployment/overview.md @@ -1,1478 +1,13 @@ -# The Order - Complete Deployment Guide +# Deployment Overview -**Last Updated**: 2025-01-27 -**Target Platform**: Azure (West Europe) -**Deployment Method**: Kubernetes (AKS) -**Policy**: No US Commercial or Government regions -**Naming Convention**: See [NAMING_CONVENTION.md](../governance/NAMING_CONVENTION.md) +The active deployment model for The Order is Sankofa Phoenix / Proxmox native. -> **🚀 Automated Deployment**: Use the deployment automation scripts for faster, repeatable deployments: -> ```bash -> ./scripts/deploy/deploy.sh --all --environment dev -> ``` -> See [scripts/deploy/README.md](../../scripts/deploy/README.md) for automation documentation. +Primary operator entry points: ---- +- `scripts/deploy/deploy.sh` +- `scripts/deploy/sync-portal-public-to-sankofa-phoenix.sh` +- `docs/deployment/DEPLOYMENT_QUICK_REFERENCE.md` -## Table of Contents - -1. [Prerequisites](#phase-1-prerequisites) -2. [Azure Infrastructure Setup](#phase-2-azure-infrastructure-setup) -3. [Entra ID Configuration](#phase-3-entra-id-configuration) -4. [Database & Storage Setup](#phase-4-database--storage-setup) -5. [Container Registry Setup](#phase-5-container-registry-setup) -6. [Application Build & Package](#phase-6-application-build--package) -7. [Database Migrations](#phase-7-database-migrations) -8. [Secrets Configuration](#phase-8-secrets-configuration) -9. [Infrastructure Services Deployment](#phase-9-infrastructure-services-deployment) -10. [Backend Services Deployment](#phase-10-backend-services-deployment) -11. [Frontend Applications Deployment](#phase-11-frontend-applications-deployment) -12. [Networking & Gateways](#phase-12-networking--gateways) -13. [Monitoring & Observability](#phase-13-monitoring--observability) -14. [Testing & Validation](#phase-14-testing--validation) -15. [Production Hardening](#phase-15-production-hardening) - ---- - -## Phase 1: Prerequisites - -**Estimated Time**: 1-2 days -**Dependencies**: None - -### 1.1 Development Environment Setup - -- [ ] **Install Required Tools** - ```bash - # Node.js >= 18.0.0 - node --version - - # pnpm >= 8.0.0 - pnpm --version - - # Azure CLI - az --version - - # Terraform >= 1.5.0 - terraform --version - - # kubectl - kubectl version --client - - # Docker (for local development) - docker --version - ``` - -- [ ] **Clone Repository** - ```bash - git clone - cd the-order - git submodule update --init --recursive - ``` - -- [ ] **Install Dependencies** - ```bash - pnpm install --frozen-lockfile - ``` - -- [ ] **Build All Packages** - ```bash - pnpm build - ``` - -### 1.2 Azure Account Setup - -- [ ] **Create Azure Subscription** (if not exists) - - Go to Azure Portal - - Create new subscription - - Note subscription ID - -- [ ] **Login to Azure CLI** - ```bash - az login - az account set --subscription - az account show - ``` - -- [ ] **Verify Permissions** - - Subscription Contributor or Owner role required - - Ability to create resource groups - - Ability to register resource providers - -### 1.3 Local Development Services (Optional for Testing) - -- [ ] **Start Local Services** - ```bash - docker-compose up -d - ``` - - This starts: - - PostgreSQL (port 5432) - - Redis (port 6379) - - OpenSearch (port 9200) - - OpenSearch Dashboards (port 5601) - ---- - -## Phase 2: Azure Infrastructure Setup - -**Estimated Time**: 4-6 weeks -**Dependencies**: Phase 1 complete -**Critical Path**: Must complete before any deployments - -### 2.1 Azure Subscription Preparation - -- [ ] **Run Azure Setup Scripts** - ```bash - # From project root - ./infra/scripts/azure-setup.sh - ``` - - This will: - - List all non-US Azure regions - - Set default region to West Europe - - Register resource providers - - Check quotas - - Generate reports - -- [ ] **Register Resource Providers** - ```bash - ./infra/scripts/azure-register-providers.sh - ``` - - Required providers (13 total): - - Microsoft.ContainerService - - Microsoft.KeyVault - - Microsoft.Storage - - Microsoft.Network - - Microsoft.Compute - - Microsoft.DBforPostgreSQL - - Microsoft.ContainerRegistry - - Microsoft.ManagedIdentity - - Microsoft.Insights - - Microsoft.Logic - - Microsoft.OperationalInsights - - Microsoft.Authorization - - Microsoft.Resources - -- [ ] **Review Quotas** - ```bash - ./infra/scripts/azure-check-quotas.sh - cat azure-quotas-all-regions.txt - ``` - - Ensure sufficient quotas for: - - VM cores (for AKS nodes) - - Storage accounts - - Network resources - -### 2.2 Terraform Infrastructure Deployment - -- [ ] **Initialize Terraform** - ```bash - cd infra/terraform - terraform init - ``` - -- [ ] **Create Initial Infrastructure (State Storage)** - ```bash - # Create resource groups and storage for Terraform state - terraform plan -target=azurerm_resource_group.terraform_state \ - -target=azurerm_storage_account.terraform_state \ - -target=azurerm_storage_container.terraform_state - - terraform apply -target=azurerm_resource_group.terraform_state \ - -target=azurerm_storage_account.terraform_state \ - -target=azurerm_storage_container.terraform_state - ``` - -- [ ] **Configure Remote State Backend** - ```bash - # Get storage account name - terraform output terraform_state_storage_account_name - - # Update versions.tf - uncomment and configure backend block - # Then re-initialize - terraform init -migrate-state - ``` - -- [ ] **Plan Full Infrastructure** - ```bash - terraform plan -out=tfplan - terraform show tfplan - ``` - -- [ ] **Deploy Core Infrastructure** (Resource Groups, Storage) - ```bash - terraform apply tfplan - ``` - -- [ ] **Deploy AKS Cluster** (To be added to Terraform) - - [ ] Create AKS cluster configuration - - [ ] Configure Azure CNI networking - - [ ] Set up node pools - - [ ] Configure Azure Disk CSI driver - - [ ] Deploy cluster - -- [ ] **Deploy Azure Database for PostgreSQL** (To be added to Terraform) - - [ ] Create PostgreSQL server - - [ ] Configure firewall rules - - [ ] Set up databases (dev, stage, prod) - - [ ] Configure backup and retention - -- [ ] **Deploy Azure Key Vault** (To be added to Terraform) - - [ ] Create Key Vault instances (dev, stage, prod) - - [ ] Configure access policies - - [ ] Enable soft delete and purge protection - -- [ ] **Deploy Azure Container Registry** (To be added to Terraform) - - [ ] Create ACR instance - - [ ] Configure admin user or managed identity - - [ ] Enable geo-replication (optional) - -- [ ] **Deploy Virtual Network** (To be added to Terraform) - - [ ] Create VNet with subnets - - [ ] Configure Network Security Groups - - [ ] Set up private endpoints (if needed) - -- [ ] **Deploy Application Gateway / Load Balancer** (To be added to Terraform) - - [ ] Create Application Gateway - - [ ] Configure SSL certificates - - [ ] Set up routing rules - -### 2.3 Kubernetes Configuration - -- [ ] **Configure AKS Access** - ```bash - az aks get-credentials --resource-group the-order-dev-rg \ - --name the-order-dev-aks - kubectl get nodes - ``` - -- [ ] **Set Up Azure CNI Networking** - - [ ] Verify CNI is configured - - [ ] Test pod networking - -- [ ] **Configure Azure Key Vault Provider for Secrets Store CSI** - ```bash - # Install External Secrets Operator - kubectl apply -f https://external-secrets.io/latest/deploy/ - - # Configure Azure Key Vault integration - # (Configuration to be added) - ``` - -- [ ] **Configure Azure Container Registry Integration** - ```bash - # Attach ACR to AKS - az aks update -n the-order-dev-aks \ - -g the-order-dev-rg \ - --attach-acr - ``` - -- [ ] **Set Up Azure Monitor for Containers** - - [ ] Enable container insights - - [ ] Configure Log Analytics workspace - - [ ] Set up alerts - ---- - -## Phase 3: Entra ID Configuration - -**Estimated Time**: 1-2 days -**Dependencies**: Phase 1 complete -**Can run in parallel with Phase 2** - -### 3.1 Azure AD App Registration - -- [ ] **Create App Registration** - - Go to Azure Portal → Azure Active Directory → App registrations - - Create new registration - - Note **Application (client) ID** - - Note **Directory (tenant) ID** - -- [ ] **Configure API Permissions** - - Add permission: `Verifiable Credentials Service - VerifiableCredential.Create.All` - - Add permission: `Verifiable Credentials Service - VerifiableCredential.Verify.All` - - Grant admin consent - -- [ ] **Create Client Secret** - - Go to Certificates & secrets - - Create new client secret - - **IMPORTANT**: Save secret value immediately (only shown once) - - Store securely in Azure Key Vault - -- [ ] **Configure Redirect URIs** - - Add callback URLs for portal applications - - Add logout URLs - -### 3.2 Microsoft Entra VerifiedID Setup - -- [ ] **Enable Verified ID Service** - - Go to Azure Portal → Verified ID - - Enable the service (may require tenant admin approval) - - Wait for service activation - -- [ ] **Create Credential Manifest** - - Go to Azure Portal → Verified ID → Credential manifests - - Create new credential manifest - - Define credential type - - Define claims schema - - Note **Manifest ID** - -- [ ] **Verify Issuer DID** - - Format: `did:web:{tenant-id}.verifiedid.msidentity.com` - - Verify DID is accessible - - Test DID resolution - -### 3.3 Azure Logic Apps Setup (Optional) - -- [ ] **Create Logic App Workflows** - - Create workflow for eIDAS verification - - Create workflow for VC issuance - - Create workflow for document processing - - Note workflow URLs - -- [ ] **Configure Access** - - Generate access keys OR - - Configure managed identity - - Grant necessary permissions - -- [ ] **Test Workflow Triggers** - - Test eIDAS verification workflow - - Test VC issuance workflow - - Verify callbacks work - ---- - -## Phase 4: Database & Storage Setup - -**Estimated Time**: 1-2 days -**Dependencies**: Phase 2 (Terraform infrastructure) complete - -### 4.1 PostgreSQL Database Setup - -- [ ] **Create Databases** - ```sql - -- For each environment (dev, stage, prod) - CREATE DATABASE theorder_dev; - CREATE DATABASE theorder_stage; - CREATE DATABASE theorder_prod; - ``` - -- [ ] **Configure Database Users** - ```sql - CREATE USER theorder_app WITH PASSWORD ''; - GRANT ALL PRIVILEGES ON DATABASE theorder_dev TO theorder_app; - ``` - -- [ ] **Configure Firewall Rules** - ```bash - az postgres server firewall-rule create \ - --resource-group the-order-dev-rg \ - --server-name \ - --name AllowAKS \ - --start-ip-address \ - --end-ip-address - ``` - -- [ ] **Test Database Connection** - ```bash - psql -h .postgres.database.azure.com \ - -U theorder_app \ - -d theorder_dev - ``` - -### 4.2 Storage Account Setup - -- [ ] **Verify Storage Accounts Created** - ```bash - az storage account list --resource-group the-order-dev-rg - ``` - -- [ ] **Create Storage Containers** - ```bash - # Application data containers - az storage container create \ - --name intake-documents \ - --account-name - - az storage container create \ - --name dataroom-deals \ - --account-name - - az storage container create \ - --name credentials \ - --account-name - ``` - -- [ ] **Configure Storage Access** - - Set up managed identity access - - Configure CORS (if needed) - - Enable versioning and soft delete - -### 4.3 Redis Cache Setup (If using Azure Cache for Redis) - -- [ ] **Create Redis Cache** (To be added to Terraform) - - Create Azure Cache for Redis instance - - Configure firewall rules - - Set up access keys - - Test connection - -### 4.4 OpenSearch Setup (If using managed service) - -- [ ] **Create OpenSearch Service** (To be added to Terraform) - - Create managed OpenSearch cluster - - Configure access - - Set up indices - - Test connection - ---- - -## Phase 5: Container Registry Setup - -**Estimated Time**: 1 day -**Dependencies**: Phase 2 (ACR created) - -### 5.1 Azure Container Registry Configuration - -- [ ] **Verify ACR Created** - ```bash - az acr list --resource-group the-order-dev-rg - ``` - -- [ ] **Configure ACR Access** - ```bash - # Enable admin user (or use managed identity) - az acr update --name --admin-enabled true - - # Get credentials - az acr credential show --name - ``` - -- [ ] **Attach ACR to AKS** - ```bash - az aks update -n the-order-dev-aks \ - -g the-order-dev-rg \ - --attach-acr - ``` - -- [ ] **Test ACR Access from AKS** - ```bash - kubectl run test-pull --image=.azurecr.io/test:latest \ - --restart=Never \ - --rm -i --tty - ``` - ---- - -## Phase 6: Application Build & Package - -**Estimated Time**: 2-4 hours -**Dependencies**: Phase 1, Phase 5 (ACR ready) - -### 6.1 Build All Packages - -- [ ] **Build Shared Packages** - ```bash - # From project root - pnpm build - - # Or build individually - pnpm --filter @the-order/ui build - pnpm --filter @the-order/auth build - pnpm --filter @the-order/api-client build - pnpm --filter @the-order/database build - pnpm --filter @the-order/storage build - pnpm --filter @the-order/crypto build - pnpm --filter @the-order/schemas build - ``` - -### 6.2 Build Frontend Applications - -- [ ] **Build Portal Public** - ```bash - pnpm --filter portal-public build - ``` - -- [ ] **Build Portal Internal** - ```bash - pnpm --filter portal-internal build - ``` - -### 6.3 Build Backend Services - -- [ ] **Build Identity Service** - ```bash - pnpm --filter @the-order/identity build - ``` - -- [ ] **Build Intake Service** - ```bash - pnpm --filter @the-order/intake build - ``` - -- [ ] **Build Finance Service** - ```bash - pnpm --filter @the-order/finance build - ``` - -- [ ] **Build Dataroom Service** - ```bash - pnpm --filter @the-order/dataroom build - ``` - -### 6.4 Create Docker Images - -**Note**: Dockerfiles need to be created for each service/app - -- [ ] **Create Dockerfiles** (To be created) - - [ ] `services/identity/Dockerfile` - - [ ] `services/intake/Dockerfile` - - [ ] `services/finance/Dockerfile` - - [ ] `services/dataroom/Dockerfile` - - [ ] `apps/portal-public/Dockerfile` - - [ ] `apps/portal-internal/Dockerfile` - -- [ ] **Build and Push Images to ACR** - ```bash - # Login to ACR - az acr login --name - - # Build and push each service - # Identity Service - docker build -t .azurecr.io/identity:latest \ - -t .azurecr.io/identity:$(git rev-parse --short HEAD) \ - -f services/identity/Dockerfile . - docker push .azurecr.io/identity:latest - docker push .azurecr.io/identity:$(git rev-parse --short HEAD) - - # Intake Service - docker build -t .azurecr.io/intake:latest \ - -t .azurecr.io/intake:$(git rev-parse --short HEAD) \ - -f services/intake/Dockerfile . - docker push .azurecr.io/intake:latest - docker push .azurecr.io/intake:$(git rev-parse --short HEAD) - - # Finance Service - docker build -t .azurecr.io/finance:latest \ - -t .azurecr.io/finance:$(git rev-parse --short HEAD) \ - -f services/finance/Dockerfile . - docker push .azurecr.io/finance:latest - docker push .azurecr.io/finance:$(git rev-parse --short HEAD) - - # Dataroom Service - docker build -t .azurecr.io/dataroom:latest \ - -t .azurecr.io/dataroom:$(git rev-parse --short HEAD) \ - -f services/dataroom/Dockerfile . - docker push .azurecr.io/dataroom:latest - docker push .azurecr.io/dataroom:$(git rev-parse --short HEAD) - - # Portal Public - docker build -t .azurecr.io/portal-public:latest \ - -t .azurecr.io/portal-public:$(git rev-parse --short HEAD) \ - -f apps/portal-public/Dockerfile . - docker push .azurecr.io/portal-public:latest - docker push .azurecr.io/portal-public:$(git rev-parse --short HEAD) - - # Portal Internal - docker build -t .azurecr.io/portal-internal:latest \ - -t .azurecr.io/portal-internal:$(git rev-parse --short HEAD) \ - -f apps/portal-internal/Dockerfile . - docker push .azurecr.io/portal-internal:latest - docker push .azurecr.io/portal-internal:$(git rev-parse --short HEAD) - ``` - -- [ ] **Sign Images with Cosign** (Security best practice) - ```bash - # Generate signing key (one-time) - cosign generate-key-pair - - # Sign each image - cosign sign --key cosign.key .azurecr.io/identity:latest - cosign sign --key cosign.key .azurecr.io/intake:latest - cosign sign --key cosign.key .azurecr.io/finance:latest - cosign sign --key cosign.key .azurecr.io/dataroom:latest - cosign sign --key cosign.key .azurecr.io/portal-public:latest - cosign sign --key cosign.key .azurecr.io/portal-internal:latest - ``` - ---- - -## Phase 7: Database Migrations - -**Estimated Time**: 1-2 hours -**Dependencies**: Phase 4 (Database created), Phase 6 (Packages built) - -### 7.1 Run Database Migrations - -- [ ] **Run Migrations for Each Environment** - ```bash - # Development - export DATABASE_URL="postgresql://user:pass@host:5432/theorder_dev" - pnpm --filter @the-order/database migrate up - - # Staging - export DATABASE_URL="postgresql://user:pass@host:5432/theorder_stage" - pnpm --filter @the-order/database migrate up - - # Production - export DATABASE_URL="postgresql://user:pass@host:5432/theorder_prod" - pnpm --filter @the-order/database migrate up - ``` - -- [ ] **Verify Schema Created** - ```sql - \dt -- List tables - \d+ -- Describe table - ``` - -- [ ] **Seed Initial Data** (If needed) - ```bash - # Run seed scripts if they exist - pnpm --filter @the-order/database seed - ``` - ---- - -## Phase 8: Secrets Configuration - -**Estimated Time**: 2-4 hours -**Dependencies**: Phase 2 (Key Vault created), Phase 3 (Entra ID configured) - -### 8.1 Store Secrets in Azure Key Vault - -- [ ] **Store Database Credentials** - ```bash - az keyvault secret set \ - --vault-name \ - --name "database-url-dev" \ - --value "postgresql://user:pass@host:5432/theorder_dev" - ``` - -- [ ] **Store Entra ID Secrets** - ```bash - az keyvault secret set \ - --vault-name \ - --name "entra-tenant-id" \ - --value "" - - az keyvault secret set \ - --vault-name \ - --name "entra-client-id" \ - --value "" - - az keyvault secret set \ - --vault-name \ - --name "entra-client-secret" \ - --value "" - - az keyvault secret set \ - --vault-name \ - --name "entra-credential-manifest-id" \ - --value "" - ``` - -- [ ] **Store Storage Credentials** - ```bash - az keyvault secret set \ - --vault-name \ - --name "storage-account-name" \ - --value "" - ``` - -- [ ] **Store JWT Secrets** - ```bash - az keyvault secret set \ - --vault-name \ - --name "jwt-secret" \ - --value "" - ``` - -- [ ] **Store KMS Keys** - ```bash - az keyvault secret set \ - --vault-name \ - --name "kms-key-id" \ - --value "" - ``` - -- [ ] **Store Other Service Secrets** - ```bash - # Payment gateway - az keyvault secret set --vault-name --name "payment-gateway-api-key" --value "..." - - # OCR service - az keyvault secret set --vault-name --name "ocr-service-api-key" --value "..." - - # eIDAS - az keyvault secret set --vault-name --name "eidas-api-key" --value "..." - ``` - -### 8.2 Configure External Secrets Operator - -- [ ] **Create SecretStore for Azure Key Vault** - ```yaml - # infra/k8s/base/external-secrets-store.yaml (to be created) - apiVersion: external-secrets.io/v1beta1 - kind: SecretStore - metadata: - name: azure-keyvault - spec: - provider: - azurekv: - vaultUrl: https://.vault.azure.net - authType: WorkloadIdentity - serviceAccountRef: - name: external-secrets-sa - ``` - -- [ ] **Create ExternalSecret Resources** - ```yaml - # infra/k8s/base/external-secrets.yaml (to be created) - apiVersion: external-secrets.io/v1beta1 - kind: ExternalSecret - metadata: - name: the-order-secrets - spec: - refreshInterval: 1h - secretStoreRef: - name: azure-keyvault - kind: SecretStore - target: - name: the-order-secrets - creationPolicy: Owner - data: - - secretKey: DATABASE_URL - remoteRef: - key: database-url-dev - - secretKey: ENTRA_TENANT_ID - remoteRef: - key: entra-tenant-id - # ... more secrets - ``` - -- [ ] **Apply External Secrets Configuration** - ```bash - kubectl apply -f infra/k8s/base/external-secrets-store.yaml - kubectl apply -f infra/k8s/base/external-secrets.yaml - ``` - ---- - -## Phase 9: Infrastructure Services Deployment - -**Estimated Time**: 1-2 days -**Dependencies**: Phase 2, Phase 8 (Secrets configured) - -### 9.1 Deploy External Secrets Operator - -- [ ] **Install External Secrets Operator** - ```bash - kubectl apply -f https://external-secrets.io/latest/deploy/ - kubectl wait --for=condition=ready pod -l app.kubernetes.io/name=external-secrets -n external-secrets-system - ``` - -### 9.2 Deploy Monitoring Stack - -- [ ] **Deploy Prometheus** (To be configured) - ```bash - # Using Helm or manifests - helm repo add prometheus-community https://prometheus-community.github.io/helm-charts - helm install prometheus prometheus-community/kube-prometheus-stack - ``` - -- [ ] **Deploy Grafana** (To be configured) - ```bash - # Usually included with Prometheus stack - # Access via port-forward or ingress - kubectl port-forward svc/prometheus-grafana 3000:80 - ``` - -- [ ] **Configure OpenTelemetry** (To be configured) - - Deploy OpenTelemetry Collector - - Configure exporters - - Set up trace collection - -### 9.3 Deploy Logging Stack - -- [ ] **Deploy OpenSearch** (If not using managed service) - ```bash - # Deploy OpenSearch operator or Helm chart - # Configuration to be added - ``` - -- [ ] **Configure Log Aggregation** - - Set up Fluent Bit or Fluentd - - Configure log forwarding - - Set up log retention policies - ---- - -## Phase 10: Backend Services Deployment - -**Estimated Time**: 2-4 days -**Dependencies**: Phase 6 (Images built), Phase 7 (Migrations run), Phase 8 (Secrets configured), Phase 9 (Infrastructure ready) - -### 10.1 Create Kubernetes Manifests - -- [ ] **Create Base Manifests** (To be created) - - [ ] `infra/k8s/base/identity/deployment.yaml` - - [ ] `infra/k8s/base/identity/service.yaml` - - [ ] `infra/k8s/base/intake/deployment.yaml` - - [ ] `infra/k8s/base/intake/service.yaml` - - [ ] `infra/k8s/base/finance/deployment.yaml` - - [ ] `infra/k8s/base/finance/service.yaml` - - [ ] `infra/k8s/base/dataroom/deployment.yaml` - - [ ] `infra/k8s/base/dataroom/service.yaml` - -### 10.2 Deploy Identity Service - -- [ ] **Deploy Identity Service** - ```bash - kubectl apply -k infra/k8s/overlays/dev - # Or for specific service - kubectl apply -f infra/k8s/base/identity/ - ``` - -- [ ] **Verify Deployment** - ```bash - kubectl get pods -l app=identity -n the-order-dev - kubectl logs -l app=identity -n the-order-dev - kubectl get svc identity -n the-order-dev - ``` - -- [ ] **Test Health Endpoint** - ```bash - kubectl port-forward svc/identity 4002:4002 - curl http://localhost:4002/health - ``` - -### 10.3 Deploy Intake Service - -- [ ] **Deploy Intake Service** - ```bash - kubectl apply -f infra/k8s/base/intake/ - ``` - -- [ ] **Verify Deployment** - ```bash - kubectl get pods -l app=intake -n the-order-dev - kubectl logs -l app=intake -n the-order-dev - ``` - -- [ ] **Test Health Endpoint** - ```bash - kubectl port-forward svc/intake 4001:4001 - curl http://localhost:4001/health - ``` - -### 10.4 Deploy Finance Service - -- [ ] **Deploy Finance Service** - ```bash - kubectl apply -f infra/k8s/base/finance/ - ``` - -- [ ] **Verify Deployment** - ```bash - kubectl get pods -l app=finance -n the-order-dev - kubectl logs -l app=finance -n the-order-dev - ``` - -- [ ] **Test Health Endpoint** - ```bash - kubectl port-forward svc/finance 4003:4003 - curl http://localhost:4003/health - ``` - -### 10.5 Deploy Dataroom Service - -- [ ] **Deploy Dataroom Service** - ```bash - kubectl apply -f infra/k8s/base/dataroom/ - ``` - -- [ ] **Verify Deployment** - ```bash - kubectl get pods -l app=dataroom -n the-order-dev - kubectl logs -l app=dataroom -n the-order-dev - ``` - -- [ ] **Test Health Endpoint** - ```bash - kubectl port-forward svc/dataroom 4004:4004 - curl http://localhost:4004/health - ``` - -### 10.6 Verify Service-to-Service Communication - -- [ ] **Test Internal Service Communication** - ```bash - # From within cluster - kubectl run test-pod --image=curlimages/curl --rm -it --restart=Never -- \ - curl http://identity:4002/health - ``` - ---- - -## Phase 11: Frontend Applications Deployment - -**Estimated Time**: 1-2 days -**Dependencies**: Phase 6 (Images built), Phase 10 (Backend services deployed) - -### 11.1 Deploy Portal Public - -- [ ] **Create Kubernetes Manifests** (To be created) - - [ ] `infra/k8s/base/portal-public/deployment.yaml` - - [ ] `infra/k8s/base/portal-public/service.yaml` - - [ ] `infra/k8s/base/portal-public/ingress.yaml` - -- [ ] **Deploy Portal Public** - ```bash - kubectl apply -f infra/k8s/base/portal-public/ - ``` - -- [ ] **Verify Deployment** - ```bash - kubectl get pods -l app=portal-public -n the-order-dev - kubectl logs -l app=portal-public -n the-order-dev - ``` - -- [ ] **Test Application** - ```bash - kubectl port-forward svc/portal-public 3000:3000 - # Open http://localhost:3000 in browser - ``` - -### 11.2 Deploy Portal Internal - -- [ ] **Create Kubernetes Manifests** (To be created) - - [ ] `infra/k8s/base/portal-internal/deployment.yaml` - - [ ] `infra/k8s/base/portal-internal/service.yaml` - - [ ] `infra/k8s/base/portal-internal/ingress.yaml` - -- [ ] **Deploy Portal Internal** - ```bash - kubectl apply -f infra/k8s/base/portal-internal/ - ``` - -- [ ] **Verify Deployment** - ```bash - kubectl get pods -l app=portal-internal -n the-order-dev - kubectl logs -l app=portal-internal -n the-order-dev - ``` - -- [ ] **Test Application** - ```bash - kubectl port-forward svc/portal-internal 3001:3001 - # Open http://localhost:3001 in browser - ``` - ---- - -## Phase 12: Networking & Gateways - -**Estimated Time**: 2-3 days -**Dependencies**: Phase 10, Phase 11 (Services and apps deployed) - -### 12.1 Configure Ingress - -- [ ] **Deploy NGINX Ingress Controller** (If not using Application Gateway) - ```bash - helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx - helm install ingress-nginx ingress-nginx/ingress-nginx - ``` - -- [ ] **Create Ingress Resources** - ```yaml - # infra/k8s/base/ingress.yaml (to be created) - apiVersion: networking.k8s.io/v1 - kind: Ingress - metadata: - name: the-order-ingress - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - spec: - tls: - - hosts: - - api.theorder.org - - portal.theorder.org - - admin.theorder.org - secretName: the-order-tls - rules: - - host: api.theorder.org - http: - paths: - - path: /identity - pathType: Prefix - backend: - service: - name: identity - port: - number: 4002 - # ... more rules - ``` - -- [ ] **Apply Ingress Configuration** - ```bash - kubectl apply -f infra/k8s/base/ingress.yaml - ``` - -### 12.2 Configure Application Gateway (If using) - -- [ ] **Create Application Gateway Backend Pools** - ```bash - az network application-gateway address-pool create \ - --resource-group the-order-dev-rg \ - --gateway-name \ - --name identity-backend \ - --servers - ``` - -- [ ] **Configure Routing Rules** - - Set up path-based routing - - Configure SSL termination - - Set up health probes - -### 12.3 Configure DNS - -- [ ] **Create DNS Records** - ```bash - # For each domain - # api.theorder.org -> Application Gateway IP - # portal.theorder.org -> Application Gateway IP - # admin.theorder.org -> Application Gateway IP - ``` - -- [ ] **Verify DNS Resolution** - ```bash - nslookup api.theorder.org - nslookup portal.theorder.org - nslookup admin.theorder.org - ``` - -### 12.4 Configure SSL/TLS Certificates - -- [ ] **Obtain SSL Certificates** - - Use Let's Encrypt (cert-manager) - - Or Azure Key Vault certificates - - Or import existing certificates - -- [ ] **Configure cert-manager** (If using Let's Encrypt) - ```bash - kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.13.0/cert-manager.yaml - ``` - -- [ ] **Create ClusterIssuer** - ```yaml - apiVersion: cert-manager.io/v1 - kind: ClusterIssuer - metadata: - name: letsencrypt-prod - spec: - acme: - server: https://acme-v02.api.letsencrypt.org/directory - email: admin@theorder.org - privateKeySecretRef: - name: letsencrypt-prod - solvers: - - http01: - ingress: - class: nginx - ``` - -### 12.5 Configure WAF Rules - -- [ ] **Configure Azure WAF** (If using Application Gateway) - - Set up OWASP rules - - Configure custom rules - - Set up rate limiting - - Configure IP allow/deny lists - ---- - -## Phase 13: Monitoring & Observability - -**Estimated Time**: 2-3 days -**Dependencies**: Phase 9, Phase 10, Phase 11 (Services deployed) - -### 13.1 Configure Application Insights - -- [ ] **Create Application Insights Resources** - ```bash - az monitor app-insights component create \ - --app the-order-dev \ - --location westeurope \ - --resource-group the-order-dev-rg - ``` - -- [ ] **Configure Application Insights in Services** - - Add instrumentation keys to services - - Configure custom metrics - - Set up alerts - -### 13.2 Configure Log Analytics - -- [ ] **Create Log Analytics Workspace** - ```bash - az monitor log-analytics workspace create \ - --resource-group the-order-dev-rg \ - --workspace-name the-order-dev-logs - ``` - -- [ ] **Configure Log Collection** - - Set up container insights - - Configure log forwarding - - Set up log queries - -### 13.3 Set Up Alerts - -- [ ] **Create Alert Rules** - ```bash - # High error rate - az monitor metrics alert create \ - --name "high-error-rate" \ - --resource-group the-order-dev-rg \ - --scopes \ - --condition "avg Percentage > 5" \ - --window-size 5m \ - --evaluation-frequency 1m - ``` - -- [ ] **Configure Alert Actions** - - Set up email notifications - - Configure webhook actions - - Set up PagerDuty integration (if needed) - -### 13.4 Configure Dashboards - -- [ ] **Create Grafana Dashboards** - - Service health dashboard - - Performance metrics dashboard - - Business metrics dashboard - - Error tracking dashboard - -- [ ] **Configure Azure Dashboards** - - Create custom dashboards - - Set up shared dashboards - - Configure access permissions - ---- - -## Phase 14: Testing & Validation - -**Estimated Time**: 3-5 days -**Dependencies**: All previous phases complete - -### 14.1 Health Checks - -- [ ] **Verify All Services Healthy** - ```bash - # Check all pods - kubectl get pods -n the-order-dev - - # Check service endpoints - for svc in identity intake finance dataroom portal-public portal-internal; do - kubectl exec -it deployment/$svc -n the-order-dev -- curl http://localhost/health - done - ``` - -### 14.2 Integration Testing - -- [ ] **Test API Endpoints** - ```bash - # Identity Service - curl https://api.theorder.org/identity/health - curl https://api.theorder.org/identity/vc/issue/entra - - # Intake Service - curl https://api.theorder.org/intake/health - - # Finance Service - curl https://api.theorder.org/finance/health - - # Dataroom Service - curl https://api.theorder.org/dataroom/health - ``` - -- [ ] **Test Frontend Applications** - - [ ] Portal Public accessible - - [ ] Portal Internal accessible - - [ ] Authentication flow works - - [ ] API integration works - - [ ] Forms submit correctly - -### 14.3 End-to-End Testing - -- [ ] **Test Complete User Flows** - - [ ] User registration flow - - [ ] Application submission flow - - [ ] Credential issuance flow - - [ ] Payment processing flow - - [ ] Document upload flow - -### 14.4 Performance Testing - -- [ ] **Load Testing** - ```bash - # Use tools like k6, Apache Bench, or JMeter - k6 run load-test.js - ``` - -- [ ] **Verify Performance Metrics** - - Response times acceptable - - Throughput meets requirements - - Resource usage within limits - -### 14.5 Security Testing - -- [ ] **Run Security Scans** - ```bash - # Trivy scan - trivy k8s cluster --severity HIGH,CRITICAL - - # Check for exposed secrets - kubectl get secrets -n the-order-dev - ``` - -- [ ] **Verify Security Controls** - - Network policies configured - - RBAC properly set up - - Secrets not exposed - - TLS/SSL working - - Authentication required - ---- - -## Phase 15: Production Hardening - -**Estimated Time**: 2-3 days -**Dependencies**: Phase 14 (Testing complete) - -### 15.1 Production Configuration - -- [ ] **Update Replica Counts** - ```bash - # Update kustomization for production - # Set appropriate replica counts - kubectl scale deployment identity --replicas=3 -n the-order-prod - ``` - -- [ ] **Configure Resource Limits** - ```yaml - resources: - requests: - memory: "256Mi" - cpu: "250m" - limits: - memory: "512Mi" - cpu: "500m" - ``` - -- [ ] **Configure Liveness and Readiness Probes** - ```yaml - livenessProbe: - httpGet: - path: /health - port: 4002 - initialDelaySeconds: 30 - periodSeconds: 10 - readinessProbe: - httpGet: - path: /health - port: 4002 - initialDelaySeconds: 5 - periodSeconds: 5 - ``` - -### 15.2 Backup Configuration - -- [ ] **Configure Database Backups** - ```bash - az postgres server backup create \ - --resource-group the-order-prod-rg \ - --server-name \ - --backup-name daily-backup - ``` - -- [ ] **Configure Storage Backups** - - Enable blob versioning - - Configure retention policies - - Set up geo-replication (if needed) - -### 15.3 Disaster Recovery - -- [ ] **Create Backup Procedures** - - Document backup process - - Test restore procedures - - Set up automated backups - -- [ ] **Configure Failover** - - Set up multi-region deployment (if needed) - - Configure DNS failover - - Test disaster recovery procedures - -### 15.4 Documentation - -- [ ] **Update Deployment Documentation** - - Document all configuration - - Create runbooks - - Document troubleshooting steps - -- [ ] **Create Operational Runbooks** - - Incident response procedures - - Common troubleshooting - - Escalation procedures - ---- - -## Deployment Checklist Summary - -### Pre-Deployment (Phases 1-5) -- [x] Prerequisites installed -- [x] Azure account setup -- [x] Infrastructure deployed -- [x] Entra ID configured -- [x] Database and storage ready -- [x] Container registry ready - -### Build & Configure (Phases 6-8) -- [x] Applications built -- [x] Docker images created and pushed -- [x] Database migrations run -- [x] Secrets configured - -### Deploy (Phases 9-12) -- [x] Infrastructure services deployed -- [x] Backend services deployed -- [x] Frontend applications deployed -- [x] Networking configured - -### Validate & Harden (Phases 13-15) -- [x] Monitoring configured -- [x] Testing complete -- [x] Production hardening done - ---- - -## Environment-Specific Deployment - -### Development Environment - -```bash -# Deploy to dev -kubectl apply -k infra/k8s/overlays/dev -``` - -### Staging Environment - -```bash -# Deploy to staging -kubectl apply -k infra/k8s/overlays/stage -``` - -### Production Environment - -```bash -# Deploy to production (after approval) -kubectl apply -k infra/k8s/overlays/prod -``` - ---- - -## Rollback Procedures - -### Rollback Application Deployment - -```bash -# Rollback to previous version -kubectl rollout undo deployment/ -n the-order-prod -``` - -### Rollback Infrastructure - -```bash -# Rollback Terraform changes -terraform plan -destroy -terraform apply -target= -``` - ---- - -## Troubleshooting - -### Common Issues - -1. **Pods Not Starting** - ```bash - kubectl describe pod -n the-order-dev - kubectl logs -n the-order-dev - ``` - -2. **Service Not Accessible** - ```bash - kubectl get svc -n the-order-dev - kubectl get ingress -n the-order-dev - ``` - -3. **Database Connection Issues** - ```bash - # Check firewall rules - az postgres server firewall-rule list --server-name - - # Test connection - psql -h -U -d - ``` - ---- - -## Estimated Timeline - -| Phase | Duration | Dependencies | -|-------|----------|--------------| -| Phase 1: Prerequisites | 1-2 days | None | -| Phase 2: Azure Infrastructure | 4-6 weeks | Phase 1 | -| Phase 3: Entra ID | 1-2 days | Phase 1 | -| Phase 4: Database & Storage | 1-2 days | Phase 2 | -| Phase 5: Container Registry | 1 day | Phase 2 | -| Phase 6: Build & Package | 2-4 hours | Phase 1, 5 | -| Phase 7: Database Migrations | 1-2 hours | Phase 4, 6 | -| Phase 8: Secrets Configuration | 2-4 hours | Phase 2, 3 | -| Phase 9: Infrastructure Services | 1-2 days | Phase 2, 8 | -| Phase 10: Backend Services | 2-4 days | Phase 6, 7, 8, 9 | -| Phase 11: Frontend Apps | 1-2 days | Phase 6, 10 | -| Phase 12: Networking | 2-3 days | Phase 10, 11 | -| Phase 13: Monitoring | 2-3 days | Phase 9, 10, 11 | -| Phase 14: Testing | 3-5 days | All previous | -| Phase 15: Production Hardening | 2-3 days | Phase 14 | - -**Total Estimated Time**: 8-12 weeks (with parallel work on Phases 2-3) - ---- - -## Quick Reference Commands - -```bash -# Infrastructure -./infra/scripts/azure-setup.sh -terraform init && terraform plan && terraform apply - -# Build -pnpm build -docker build -t -f . - -# Deploy -kubectl apply -k infra/k8s/overlays/dev -kubectl get pods -n the-order-dev -kubectl logs -f -n the-order-dev - -# Verify -kubectl get all -n the-order-dev -kubectl port-forward svc/ : -curl http://localhost:/health -``` - ---- - -**See individual phase sections for detailed instructions.** +Historical provider-specific deployment material has been quarantined under: +- `archive/quarantined-legacy-stack/` diff --git a/docs/design/ORDER_SEALS_DESIGN_GUIDE.md b/docs/design/ORDER_SEALS_DESIGN_GUIDE.md index 09487a3..ddca383 100644 --- a/docs/design/ORDER_SEALS_DESIGN_GUIDE.md +++ b/docs/design/ORDER_SEALS_DESIGN_GUIDE.md @@ -166,7 +166,7 @@ For digital credentials, you can create color variations: ## Usage Guidelines ### For Credential Images -1. Use PNG format for Entra VerifiedID (convert from SVG) +1. Use PNG format for credential clients (convert from SVG) 2. Ensure images are publicly accessible via HTTPS 3. Use CDN for fast delivery 4. Maintain aspect ratio (1:1, square) @@ -211,4 +211,3 @@ For digital credentials, you can create color variations: **Design Heritage**: Order of St John (OSJ) **Central Symbol**: Maltese Cross (8-pointed, V-shaped arms) **Last Updated**: [Current Date] - diff --git a/docs/governance/README.md b/docs/governance/README.md index a57f53e..22fa0cb 100644 --- a/docs/governance/README.md +++ b/docs/governance/README.md @@ -43,8 +43,8 @@ This directory contains governance documentation, including contribution guideli ## Related Documentation - [Architecture Security](../architecture/README.md#security) -- [Cloud for Sovereignty](../architecture/CLOUD_FOR_SOVEREIGNTY_LANDING_ZONE.md) -- [Deployment Security](../deployment/azure/SOVEREIGNTY_LANDING_ZONE_DEPLOYMENT.md#security-features) +- [Architecture Overview](../architecture/README.md) +- [Deployment Overview](../deployment/overview.md) --- diff --git a/docs/governance/frameworks/privacy.md b/docs/governance/frameworks/privacy.md index 2de9b7d..dbd24dd 100644 --- a/docs/governance/frameworks/privacy.md +++ b/docs/governance/frameworks/privacy.md @@ -107,7 +107,7 @@ This document provides the privacy and data governance framework for the DSB, in **Providers:** * KYC providers (Veriff) * Sanctions providers (ComplyAdvantage) -* Cloud providers (AWS, Azure) +* Cloud providers (AWS, GCP, private infrastructure) * Email/SMS providers * Analytics providers @@ -277,4 +277,3 @@ This document provides the privacy and data governance framework for the DSB, in **Chancellor:** _________________ Date: _________ **Founding Council:** _________________ Date: _________ - diff --git a/docs/governance/frameworks/threat-model.md b/docs/governance/frameworks/threat-model.md index 30a2f85..05abecc 100644 --- a/docs/governance/frameworks/threat-model.md +++ b/docs/governance/frameworks/threat-model.md @@ -117,7 +117,7 @@ This document outlines the threat model for The Order monorepo, identifying pote - **Mitigation**: - Hardware Security Modules (HSM) - Key rotation policies - - Secure key storage (AWS KMS, Azure Key Vault) + - Secure key storage (AWS KMS, GCP KMS, or HSM-backed stores) - Access controls on key operations - Audit logging of key usage @@ -273,6 +273,5 @@ This document outlines the threat model for The Order monorepo, identifying pote ## References - [OWASP Threat Modeling](https://owasp.org/www-community/Threat_Modeling) -- [STRIDE Threat Model](https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-threats) +- [STRIDE Threat Model](https://en.wikipedia.org/wiki/STRIDE_(security)) - [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework) - diff --git a/docs/governance/procedures/security-audit.md b/docs/governance/procedures/security-audit.md index 40f20cb..beac665 100644 --- a/docs/governance/procedures/security-audit.md +++ b/docs/governance/procedures/security-audit.md @@ -18,7 +18,7 @@ This document provides a comprehensive security audit checklist for The Order mo ## Secrets Management - [ ] No hardcoded secrets in code -- [ ] Secrets are stored in AWS Secrets Manager or Azure Key Vault +- [ ] Secrets are stored in an approved secret manager or HSM-backed store - [ ] Secrets are rotated regularly - [ ] Secret access is logged and audited - [ ] Secrets are encrypted at rest and in transit @@ -197,4 +197,3 @@ This document provides a comprehensive security audit checklist for The Order mo **Audit Date**: _______________ **Auditor**: _______________ **Next Review Date**: _______________ - diff --git a/docs/integrations/README.md b/docs/integrations/README.md index fb81c8c..7ef6961 100644 --- a/docs/integrations/README.md +++ b/docs/integrations/README.md @@ -1,53 +1,26 @@ # Integration Documentation -**Last Updated**: 2025-01-27 -**Purpose**: Integration guide index +**Last Updated**: 2026-04-16 +**Purpose**: Integration guide index for active The Order integrations ## Overview -This directory contains documentation for all external integrations used by The Order platform. +This directory covers active integrations used by The Order platform. -## Available Integrations +## Active Areas -### Microsoft Entra VerifiedID -- [Entra VerifiedID Guide](entra-verifiedid/README.md) - Complete integration guide -- Credential issuance and verification -- Multi-manifest support -- Webhook handling -- Rate limiting and metrics +### Identity +- DID and issuer-domain based credential services +- OIDC where configured for operator and portal flows -### Azure Services -- [Azure CDN](../deployment/azure/cdn-setup.md) - CDN configuration -- [Azure Key Vault](../../infra/terraform/key-vault.tf) - Secrets management -- [Azure Storage](../deployment/azure/cdn-setup.md) - Object storage +### Payments +- Finance service integrations live under `services/finance/` -### Payment Gateways -- Stripe integration (see `services/finance/`) -- Additional providers (planned) +### Legal and Documents +- Legal and document-management integrations live under `docs/legal/` -### E-Signature Providers -- DocuSign (planned) -- Adobe Sign (planned) +## Historical Material -### Court E-Filing -- Federal court systems (planned) -- State court systems (planned) +Legacy provider integration guides have been quarantined under: -## Integration Documentation Structure - -``` -integrations/ -├── README.md # This file -└── entra-verifiedid/ # Entra VerifiedID integration - └── README.md # Complete guide -``` - -## Quick Links - -- [Entra VerifiedID](entra-verifiedid/README.md) - Credential issuance -- [Azure Deployment](../deployment/azure/) - Azure service integration -- [Service Documentation](../../services/) - Service-specific integrations - ---- - -**Last Updated**: 2025-01-27 +- `../archive/quarantined-legacy-stack/` diff --git a/docs/operations/DISASTER_RECOVERY.md b/docs/operations/DISASTER_RECOVERY.md index 366123e..d28f198 100644 --- a/docs/operations/DISASTER_RECOVERY.md +++ b/docs/operations/DISASTER_RECOVERY.md @@ -32,7 +32,7 @@ This document outlines disaster recovery (DR) procedures for The Order platform, ### Configuration Backups - **Infrastructure**: Version controlled in Git -- **Secrets**: Stored in Azure Key Vault with backup +- **Secrets**: Stored in an approved secret manager with backup - **Kubernetes Manifests**: Version controlled ## Recovery Procedures @@ -138,4 +138,3 @@ This document outlines disaster recovery (DR) procedures for The Order platform, --- **Last Updated**: 2025-01-27 - diff --git a/docs/product/features/web-ui-coverage.md b/docs/product/features/web-ui-coverage.md index 9d0e512..85736a2 100644 --- a/docs/product/features/web-ui-coverage.md +++ b/docs/product/features/web-ui-coverage.md @@ -55,8 +55,6 @@ The Order monorepo currently has **minimal web-based UI/UX implementation**. The - `POST /vc/issue/batch` - Batch credential issuance - `POST /vc/revoke` - Revoke credential - `POST /sign` - Sign document - - `POST /vc/issue/entra` - Microsoft Entra VerifiedID issuance - - `POST /vc/verify/entra` - Microsoft Entra VerifiedID verification - `POST /eidas/verify-and-issue` - eIDAS verification and issuance - `GET/POST /templates` - Credential template management - `GET /metrics` - Credential metrics @@ -297,4 +295,3 @@ To make the system user-friendly and accessible to non-technical users, signific **Last Updated**: 2025-01-27 **Analysis Based On**: Current codebase state as of commit `9e46f3f` - diff --git a/infra/k8s/base/identity/deployment.yaml b/infra/k8s/base/identity/deployment.yaml index e5f9611..229d5c9 100644 --- a/infra/k8s/base/identity/deployment.yaml +++ b/infra/k8s/base/identity/deployment.yaml @@ -36,21 +36,6 @@ spec: secretKeyRef: name: the-order-secrets key: database-url - - name: ENTRA_TENANT_ID - valueFrom: - secretKeyRef: - name: the-order-secrets - key: entra-tenant-id - - name: ENTRA_CLIENT_ID - valueFrom: - secretKeyRef: - name: the-order-secrets - key: entra-client-id - - name: ENTRA_CLIENT_SECRET - valueFrom: - secretKeyRef: - name: the-order-secrets - key: entra-client-secret resources: requests: memory: "256Mi" @@ -126,4 +111,3 @@ spec: target: type: Utilization averageUtilization: 80 - diff --git a/infra/k8s/base/monitoring/alert-rules-configmap.yaml b/infra/k8s/base/monitoring/alert-rules-configmap.yaml index 987d3e7..91f4303 100644 --- a/infra/k8s/base/monitoring/alert-rules-configmap.yaml +++ b/infra/k8s/base/monitoring/alert-rules-configmap.yaml @@ -71,16 +71,3 @@ data: annotations: summary: "Database connection pool nearly exhausted" description: "{{ $value }}% of connections in use" - - - name: azure - interval: 30s - rules: - - alert: EntraAPIRateLimit - expr: rate(entra_api_requests_total{status="429"}[5m]) > 0 - for: 1m - labels: - severity: warning - annotations: - summary: "Entra API rate limit hit" - description: "Rate limit errors detected for Entra VerifiedID API" - diff --git a/infra/monitoring/alert-rules.yml b/infra/monitoring/alert-rules.yml index 352b2b9..dfb8d2a 100644 --- a/infra/monitoring/alert-rules.yml +++ b/infra/monitoring/alert-rules.yml @@ -82,24 +82,3 @@ groups: annotations: summary: "Slow database queries detected" description: "Average query time is {{ $value }} seconds" - - - name: azure - interval: 30s - rules: - - alert: EntraAPIRateLimit - expr: rate(entra_api_requests_total{status="429"}[5m]) > 0 - for: 1m - labels: - severity: warning - annotations: - summary: "Entra API rate limit hit" - description: "Rate limit errors detected for Entra VerifiedID API" - - - alert: AzureStorageErrors - expr: rate(azure_storage_errors_total[5m]) > 0.01 - for: 5m - labels: - severity: warning - annotations: - summary: "Azure Storage errors detected" - description: "Storage error rate is {{ $value }} errors per second" diff --git a/infra/scripts/README.md b/infra/scripts/README.md index c895cf4..43c7d61 100644 --- a/infra/scripts/README.md +++ b/infra/scripts/README.md @@ -1,130 +1,13 @@ -# Azure Setup Scripts +# Infrastructure Scripts -This directory contains scripts for setting up Azure infrastructure prerequisites for The Order. +This directory contains supporting infrastructure scripts for the active Sankofa Phoenix / Proxmox deployment model. -## Scripts +Use these active entry points: -### 1. `azure-setup.sh` - Complete Azure Setup +- `scripts/deploy/deploy.sh` +- `docs/deployment/overview.md` +- `docs/deployment/DEPLOYMENT_QUICK_REFERENCE.md` -Comprehensive setup script that: -- Lists all available Azure Commercial regions (excluding US) -- Sets default region to West Europe -- Checks and registers required resource providers -- Checks quotas for primary regions -- Generates reports - -**Usage:** -```bash -./infra/scripts/azure-setup.sh -``` - -**Output Files:** -- `azure-regions.txt` - List of all non-US regions -- `azure-quotas.txt` - Quota information for primary regions - -### 2. `azure-register-providers.sh` - Register Resource Providers - -Registers all required Azure Resource Providers for The Order. - -**Usage:** -```bash -./infra/scripts/azure-register-providers.sh -``` - -**What it does:** -- Checks registration status of all required providers -- Registers unregistered providers -- Waits for registration to complete -- Reports final status - -### 3. `azure-check-quotas.sh` - Check Quotas for All Regions - -Checks quotas for all non-US Azure regions. - -**Usage:** -```bash -./infra/scripts/azure-check-quotas.sh -``` - -**Output:** -- `azure-quotas-all-regions.txt` - Detailed quota information for all regions - -## Prerequisites - -1. **Azure CLI installed** - ```bash - # Check if installed - az --version - - # Install if needed - # https://docs.microsoft.com/en-us/cli/azure/install-azure-cli - ``` - -2. **Azure CLI logged in** - ```bash - az login - az account show - ``` - -3. **Required permissions** - - Subscription Contributor or Owner role - - Ability to register resource providers - - Ability to check quotas - -## Quick Start - -1. **Login to Azure** - ```bash - az login - ``` - -2. **Run complete setup** - ```bash - ./infra/scripts/azure-setup.sh - ``` - -3. **Verify providers are registered** - ```bash - ./infra/scripts/azure-register-providers.sh - ``` - -4. **Check quotas** - ```bash - ./infra/scripts/azure-check-quotas.sh - ``` - -## Required Resource Providers - -See `infra/terraform/AZURE_RESOURCE_PROVIDERS.md` for complete list. - -## Default Region - -**West Europe (westeurope)** is the default region. US Commercial and Government regions are **not used**. - -## Troubleshooting - -### Script fails with "not logged in" -```bash -az login -az account set --subscription -``` - -### Provider registration fails -- Check subscription permissions -- Verify subscription is active -- Wait 5-10 minutes and retry - -### Quota check fails -- Some regions may not support all quota types -- Check individual regions manually if needed - -## Output Files - -All scripts generate output files in the current directory: - -- `azure-regions.txt` - List of available regions -- `azure-quotas.txt` - Quotas for primary regions -- `azure-quotas-all-regions.txt` - Quotas for all regions - -Review these files to understand available resources and limits. +Historical provider setup scripts have been quarantined under: +- `archive/quarantined-legacy-stack/infra/scripts/` diff --git a/packages/README.md b/packages/README.md index 0a95391..2a04f7e 100644 --- a/packages/README.md +++ b/packages/README.md @@ -41,7 +41,7 @@ This directory contains shared libraries and packages used across services and a ### Infrastructure #### `storage/` -- **Purpose**: Storage abstraction (S3/GCS/Azure) +- **Purpose**: Storage abstraction (S3/GCS) - **Used By**: Intake, Dataroom, Legal Documents services - **Key Features**: WORM storage, object lifecycle @@ -142,4 +142,3 @@ Packages can depend on other packages: --- **Last Updated**: 2025-01-27 - diff --git a/packages/auth/package.json b/packages/auth/package.json index 953dccf..4f18657 100644 --- a/packages/auth/package.json +++ b/packages/auth/package.json @@ -12,7 +12,6 @@ "type-check": "tsc --noEmit" }, "dependencies": { - "@azure/identity": "^4.0.1", "@noble/ed25519": "^2.0.0", "@types/node-fetch": "^2.6.11", "base58-universal": "^2.0.0", diff --git a/packages/auth/src/file-utils.ts b/packages/auth/src/file-utils.ts index 33d9494..f310bff 100644 --- a/packages/auth/src/file-utils.ts +++ b/packages/auth/src/file-utils.ts @@ -1,5 +1,5 @@ /** - * File handling utilities for Entra VerifiedID and other integrations + * File handling utilities for credential and document integrations * Provides base64 encoding/decoding, validation, and content type detection */ @@ -375,4 +375,3 @@ export function calculateFileHash(data: Buffer | string, algorithm: 'sha256' | ' return createHash(algorithm).update(buffer).digest('hex'); } - diff --git a/packages/auth/src/index.ts b/packages/auth/src/index.ts index 7ca9234..5faa838 100644 --- a/packages/auth/src/index.ts +++ b/packages/auth/src/index.ts @@ -5,10 +5,4 @@ export * from './oidc'; export * from './did'; export * from './eidas'; -export * from './entra-verifiedid'; -export * from './entra-verifiedid-enhanced'; -export * from './entra-credential-images'; -export * from './azure-logic-apps'; -export * from './eidas-entra-bridge'; export * from './file-utils'; - diff --git a/packages/crypto/src/kms.ts b/packages/crypto/src/kms.ts index 6e990ab..aa1dd10 100644 --- a/packages/crypto/src/kms.ts +++ b/packages/crypto/src/kms.ts @@ -11,7 +11,7 @@ import { } from '@aws-sdk/client-kms'; export interface KMSConfig { - provider: 'aws' | 'gcp' | 'azure' | 'hsm'; + provider: 'aws' | 'gcp' | 'hsm'; keyId: string; region?: string; } @@ -83,4 +83,3 @@ export class KMSClient { return response.SignatureValid ?? false; } } - diff --git a/packages/monitoring/src/index.ts b/packages/monitoring/src/index.ts index 3109a84..f5c72e7 100644 --- a/packages/monitoring/src/index.ts +++ b/packages/monitoring/src/index.ts @@ -5,11 +5,9 @@ export * from './otel'; export * from './metrics'; export * from './business-metrics'; -export * from './entra-metrics'; // Re-export business metrics with explicit names to avoid conflicts export { documentsProcessed, paymentsProcessed, } from './business-metrics'; - diff --git a/packages/shared/src/env.ts b/packages/shared/src/env.ts index c52fc89..644f1be 100644 --- a/packages/shared/src/env.ts +++ b/packages/shared/src/env.ts @@ -44,31 +44,10 @@ const envSchema = z.object({ EIDAS_PROVIDER_URL: z.string().url().optional(), EIDAS_API_KEY: z.string().optional(), - // Microsoft Entra VerifiedID - ENTRA_TENANT_ID: z.string().optional(), - ENTRA_CLIENT_ID: z.string().optional(), - ENTRA_CLIENT_SECRET: z.string().optional(), - ENTRA_CREDENTIAL_MANIFEST_ID: z.string().optional(), - ENTRA_MANIFESTS: z.string().optional(), // JSON object mapping manifest names to IDs - // Entra Rate Limiting - ENTRA_RATE_LIMIT_ISSUANCE: z.string().optional(), - ENTRA_RATE_LIMIT_VERIFICATION: z.string().optional(), - ENTRA_RATE_LIMIT_STATUS_CHECK: z.string().optional(), - ENTRA_RATE_LIMIT_GLOBAL: z.string().optional(), - // Credential Display/Images - ENTRA_CREDENTIAL_LOGO_URI: z.string().url().optional(), - ENTRA_CREDENTIAL_BG_COLOR: z.string().optional(), - ENTRA_CREDENTIAL_TEXT_COLOR: z.string().optional(), - // Credential Rate Limiting CREDENTIAL_RATE_LIMIT_PER_USER: z.string().optional(), CREDENTIAL_RATE_LIMIT_PER_IP: z.string().optional(), - // Azure Logic Apps - AZURE_LOGIC_APPS_WORKFLOW_URL: z.string().url().optional(), - AZURE_LOGIC_APPS_ACCESS_KEY: z.string().optional(), - AZURE_LOGIC_APPS_MANAGED_IDENTITY_CLIENT_ID: z.string().optional(), - // CORS CORS_ORIGIN: z.string().optional(), @@ -135,12 +114,7 @@ const envSchema = z.object({ DSB_SCHEMA_REGISTRY_URL: z.string().url().optional(), // Secrets Management - SECRETS_PROVIDER: z.enum(['aws', 'azure', 'env']).optional(), - AZURE_KEY_VAULT_URL: z.string().url().optional(), - AZURE_TENANT_ID: z.string().optional(), - AZURE_CLIENT_ID: z.string().optional(), - AZURE_CLIENT_SECRET: z.string().optional(), - AZURE_MANAGED_IDENTITY_CLIENT_ID: z.string().optional(), + SECRETS_PROVIDER: z.enum(['aws', 'gcp', 'env']).optional(), SECRETS_CACHE_TTL: z.string().transform(Number).pipe(z.number().int().positive()).optional(), }); @@ -175,4 +149,3 @@ export function getEnv(): Env { * Validate environment variables on module load */ getEnv(); - diff --git a/packages/shared/src/index.ts b/packages/shared/src/index.ts index c72344d..c678f37 100644 --- a/packages/shared/src/index.ts +++ b/packages/shared/src/index.ts @@ -12,7 +12,6 @@ export * from './auth'; export * from './rate-limit-credential'; export * from './rate-limiting'; export * from './graceful-shutdown'; -export * from './rate-limit-entra'; export * from './authorization'; export * from './compliance'; export * from './retry'; @@ -22,4 +21,3 @@ export * from './timeout'; // Re-export types export type { AuthUser } from './auth'; - diff --git a/scripts/README.md b/scripts/README.md index 7054d3d..bf6cf71 100644 --- a/scripts/README.md +++ b/scripts/README.md @@ -10,8 +10,7 @@ This directory contains utility scripts organized by purpose. ## Script Categories ### Deployment (`deploy/`) -- Azure deployment scripts -- CDN setup scripts +- Sankofa Phoenix / Proxmox deployment scripts - Seal deployment scripts - Monitoring setup @@ -30,8 +29,7 @@ This directory contains utility scripts organized by purpose. - Compliance checking ### Infrastructure (`infra/scripts/`) -- Azure infrastructure scripts -- Terraform automation +- Supporting infrastructure scripts - Environment management ## Usage @@ -41,10 +39,9 @@ This directory contains utility scripts organized by purpose. ./scripts/dev/setup-dev.sh ``` -### Azure Deployment +### Sankofa Phoenix Deployment ```bash -source infra/scripts/azure-load-env.sh -./infra/scripts/azure-deploy.sh +./scripts/deploy/deploy.sh --all --environment dev --dry-run ``` ### Security Scanning @@ -77,4 +74,3 @@ scripts/ --- **Last Updated**: 2025-01-27 - diff --git a/scripts/backup/database-backup.sh b/scripts/backup/database-backup.sh index 70451bf..1d2df6f 100755 --- a/scripts/backup/database-backup.sh +++ b/scripts/backup/database-backup.sh @@ -38,10 +38,9 @@ if [ -n "$BACKUP_STORAGE_BUCKET" ]; then echo "Uploading backup to cloud storage..." if command -v aws &> /dev/null; then aws s3 cp "$BACKUP_FILE" "s3://$BACKUP_STORAGE_BUCKET/$(basename $BACKUP_FILE)" || true - elif command -v az &> /dev/null; then - az storage blob upload --file "$BACKUP_FILE" --container-name backups --name "$(basename $BACKUP_FILE)" --account-name "$AZURE_STORAGE_ACCOUNT" || true + elif [ -n "${BACKUP_CLOUD_SYNC_CMD:-}" ]; then + sh -c "$BACKUP_CLOUD_SYNC_CMD \"$BACKUP_FILE\" \"$BACKUP_STORAGE_BUCKET\"" || true fi fi echo "✅ Backup complete!" - diff --git a/scripts/deploy/README.md b/scripts/deploy/README.md index 1bebe2b..e5642cd 100644 --- a/scripts/deploy/README.md +++ b/scripts/deploy/README.md @@ -1,272 +1,180 @@ # Deployment Automation Scripts -Automated deployment scripts for The Order following the deployment guide. +Automated deployment scripts for The Order using the Sankofa Phoenix / Proxmox runtime. ## Overview -This directory contains automated scripts for deploying The Order to Azure/Kubernetes. The scripts follow the 15-phase deployment guide and can be run individually or as a complete deployment. +The active deployment path is now Sankofa Phoenix / Proxmox-native. The scripts in this directory now: + +- build The Order locally +- package the `portal-public` Next.js standalone bundle +- sync it to the Order public CT on Proxmox +- refresh the Order HAProxy edge +- verify direct, edge, and public health endpoints + +The default topology is: + +- `order-portal-public` CT `10090` at `192.168.11.36:3000` +- `order-haproxy` CT `10210` at `192.168.11.39:80` +- public URL `https://the-order.sankofa.nexus` +- Phoenix public URL `https://phoenix.sankofa.nexus` ## Quick Start ```bash -# Deploy all phases for dev environment +# Deploy the frontend to the default dev target +./scripts/deploy/deploy.sh --phase 11 --environment dev + +# Run the direct sync script +./scripts/deploy/sync-portal-public-to-sankofa-phoenix.sh + +# Full phase flow ./scripts/deploy/deploy.sh --all --environment dev - -# Deploy specific phases -./scripts/deploy/deploy.sh --phase 1 --phase 2 --phase 6 - -# Continue from last saved state -./scripts/deploy/deploy.sh --continue - -# Deploy with auto-apply (no Terraform review) -./scripts/deploy/deploy.sh --all --auto-apply ``` ## Configuration -Configuration is managed in `config.sh`. Key variables: +Configuration is managed in `config.sh`. The most important variables are: -- `ENVIRONMENT`: Deployment environment (dev, stage, prod) -- `AZURE_REGION`: Azure region (default: westeurope) -- `ACR_NAME`: Azure Container Registry name -- `AKS_NAME`: AKS cluster name -- `KEY_VAULT_NAME`: Azure Key Vault name +- `PROXMOX_HOST` +- `ORDER_PORTAL_PUBLIC_VMID` +- `ORDER_PORTAL_PUBLIC_IP` +- `ORDER_HAPROXY_VMID` +- `ORDER_HAPROXY_IP` +- `SANKOFA_PHOENIX_URL` +- `THE_ORDER_PUBLIC_URL` +- `IMAGE_REGISTRY` +- `IMAGE_TAG` -Set via environment variables or edit `config.sh`: +Example: ```bash export ENVIRONMENT=prod -export AZURE_REGION=westeurope -export ACR_NAME=theorderacr -./scripts/deploy/deploy.sh --all +export PROXMOX_HOST=192.168.11.11 +export ORDER_PORTAL_PUBLIC_VMID=10090 +export ORDER_HAPROXY_VMID=10210 +./scripts/deploy/deploy.sh --phase 11 ``` ## Phase Scripts ### Phase 1: Prerequisites -- Checks all required tools -- Verifies Azure login -- Installs dependencies -- Builds packages + +- verifies local tooling +- verifies SSH access to Proxmox +- records the Sankofa / Order runtime targets ```bash ./scripts/deploy/phase1-prerequisites.sh ``` -### Phase 2: Azure Infrastructure -- Runs Azure setup scripts -- Registers resource providers -- Deploys Terraform infrastructure -- Configures Kubernetes access +### Phase 2: Sankofa Phoenix Target Preparation + +- confirms the Order public CT and HAProxy CT are reachable +- previews the HAProxy config for `the-order.sankofa.nexus` +- probes Phoenix public health ```bash -./scripts/deploy/phase2-azure-infrastructure.sh +./scripts/deploy/phase2-sankofa-phoenix-target.sh ``` -### Phase 3: Entra ID Configuration -- **Manual steps required** (Azure Portal) -- Helper script to store secrets: `store-entra-secrets.sh` - ### Phase 6: Build & Package -- Builds all packages and applications -- Creates Docker images -- Pushes to Azure Container Registry -- Signs images with Cosign (if available) + +- builds all packages and applications +- creates local Docker images for services and apps +- previews the Phoenix deployment artifact ```bash ./scripts/deploy/phase6-build-package.sh ``` -### Phase 7: Database Migrations -- Runs database schema migrations -- Verifies database connection +### Phase 11: Frontend Applications Deployment + +- builds `portal-public` +- syncs the standalone bundle to CT `10090` +- installs or refreshes the `the-order-portal-public` systemd service +- reprovisions the Order HAProxy edge on `10210` +- verifies LAN and public health endpoints ```bash -./scripts/deploy/phase7-database-migrations.sh -``` - -### Phase 10: Backend Services -- Deploys backend services to Kubernetes -- Verifies deployments -- Tests health endpoints - -```bash -./scripts/deploy/phase10-backend-services.sh +./scripts/deploy/phase11-frontend-apps.sh ``` ## Usage Examples -### Full Deployment +### Frontend deployment ```bash -# Development environment -./scripts/deploy/deploy.sh --all --environment dev - -# Staging environment -./scripts/deploy/deploy.sh --all --environment stage - -# Production (with confirmation) -./scripts/deploy/deploy.sh --all --environment prod +./scripts/deploy/deploy.sh --phase 11 --environment dev ``` -### Incremental Deployment +### Build only ```bash -# Run prerequisites and infrastructure -./scripts/deploy/deploy.sh --phase 1 --phase 2 - -# Build and package -./scripts/deploy/deploy.sh --phase 6 - -# Deploy services -./scripts/deploy/deploy.sh --phase 10 --phase 11 +./scripts/deploy/deploy.sh --phase 6 --environment dev ``` -### Skip Phases +### Continue from the last saved state ```bash -# Skip build (if already built) -./scripts/deploy/deploy.sh --all --skip-build - -# Skip specific phase -./scripts/deploy/deploy.sh --all --skip 3 --skip 8 -``` - -### Continue from Failure - -```bash -# If deployment fails, continue from last state ./scripts/deploy/deploy.sh --continue ``` ## State Management -Deployment state is saved in `.deployment/${ENVIRONMENT}.state`. This allows: +Deployment state is saved in `.deployment/${ENVIRONMENT}.state`. -- Resuming from last completed phase -- Tracking deployment progress -- Debugging failed deployments +Artifacts and image manifests are written under `.deployment/artifacts/`. ## Logging All deployment logs are saved to `logs/deployment-YYYYMMDD-HHMMSS.log`. -View logs: ```bash tail -f logs/deployment-*.log ``` ## Manual Steps -Some phases require manual steps: +Some phases still require external operator work: -- **Phase 3**: Entra ID configuration (Azure Portal) -- **Phase 8**: Secrets configuration (use helper scripts) -- **Phase 12**: DNS configuration -- **Phase 13**: Monitoring dashboard setup - -See `docs/deployment/DEPLOYMENT_GUIDE.md` for detailed instructions. - -## Helper Scripts - -### Store Entra ID Secrets - -After completing Entra ID setup in Azure Portal: - -```bash -./scripts/deploy/store-entra-secrets.sh -``` - -This will prompt for: -- Tenant ID -- Client ID -- Client Secret -- Credential Manifest ID - -And store them in Azure Key Vault. +- `Phase 3`: identity-provider / Entra setup +- `Phase 8`: secret injection into the chosen backend +- `Phase 12`: DNS / NPM updates if you are changing routing +- `Phase 13`: central monitoring / alert wiring ## Troubleshooting -### Check Deployment State +### Check deployment state ```bash cat .deployment/dev.state ``` -### View Logs +### Verify Order runtime access ```bash -tail -f logs/deployment-*.log +ssh root@192.168.11.11 "pct status 10090 && pct status 10210" +curl -fsS http://192.168.11.36:3000/api/health +curl -fsS -H 'Host: the-order.sankofa.nexus' http://192.168.11.39/api/health +curl -fsS https://the-order.sankofa.nexus/api/health ``` -### Verify Kubernetes Access +### Verify Phoenix public access ```bash -kubectl cluster-info -kubectl get nodes +curl -fsS https://phoenix.sankofa.nexus/health ``` -### Verify Azure Access +### View CT service logs ```bash -az account show -az aks list -``` - -### Re-run Failed Phase - -```bash -./scripts/deploy/deploy.sh --phase -``` - -## Environment-Specific Configuration - -Create environment-specific config files: - -```bash -# .deployment/dev.env -export ENVIRONMENT=dev -export AKS_NAME=the-order-dev-aks -export KEY_VAULT_NAME=the-order-dev-kv -``` - -Source before deployment: - -```bash -source .deployment/dev.env -./scripts/deploy/deploy.sh --all -``` - -## Integration with CI/CD - -The scripts can be integrated into CI/CD pipelines: - -```yaml -# .github/workflows/deploy.yml -- name: Deploy to Dev - run: | - ./scripts/deploy/deploy.sh --all --environment dev --auto-apply - env: - AZURE_CREDENTIALS: ${{ secrets.AZURE_CREDENTIALS }} +ssh root@192.168.11.11 "pct exec 10090 -- journalctl -u the-order-portal-public -n 100 --no-pager" ``` ## Security Notes -- Never commit secrets to repository -- Use Azure Key Vault for all secrets -- Enable RBAC for all resources -- Review Terraform plans before applying -- Use managed identities where possible - -## Next Steps - -After deployment: - -1. Verify all services are running: `kubectl get pods -n the-order-${ENV}` -2. Test health endpoints -3. Configure monitoring dashboards -4. Set up alerts -5. Review security settings - -See `docs/deployment/DEPLOYMENT_GUIDE.md` for complete deployment instructions. - +- never commit secrets to the repository +- keep Proxmox SSH access limited to operator hosts +- review CT and HAProxy targets before applying changes +- prefer the documented `10090 -> 10210 -> public` path over ad hoc edits diff --git a/scripts/deploy/complete-seal-deployment.sh b/scripts/deploy/complete-seal-deployment.sh index 2ce792f..fcfcff9 100755 --- a/scripts/deploy/complete-seal-deployment.sh +++ b/scripts/deploy/complete-seal-deployment.sh @@ -77,7 +77,7 @@ cat > "assets/credential-images/DEPLOYMENT_CHECKLIST.md" << 'EOF' - [ ] Development environment variables set - [ ] Staging environment variables set - [ ] Production environment variables set -- [ ] ENTRA_CREDENTIAL_LOGO_URI configured per credential type +- [ ] Credential logo URL configured per credential type ## Testing @@ -144,11 +144,11 @@ $(find assets/credential-images/png -name "*.png" -type f | wc -l) PNG files gen - Ensure HTTPS and public access 3. **Update Manifest Templates** - - Update CDN URLs in \`manifests/entra/*-manifest-template.json\` + - Update CDN URLs in your active credential templates - Verify all credential types have correct seal references 4. **Configure Environment** - - Set \`ENTRA_CREDENTIAL_LOGO_URI\` per credential type + - Set the credential logo URL per credential type - Update staging/production configurations 5. **Test** @@ -204,4 +204,3 @@ echo "3. Update manifest templates with CDN URLs" echo "4. Test credential issuance" echo "" log_success "Ready for CDN deployment!" - diff --git a/scripts/deploy/config.sh b/scripts/deploy/config.sh index dc5e193..2eacbce 100755 --- a/scripts/deploy/config.sh +++ b/scripts/deploy/config.sh @@ -22,24 +22,13 @@ readonly SCRIPTS_DIR="${PROJECT_ROOT}/scripts" readonly INFRA_DIR="${PROJECT_ROOT}/infra" readonly TERRAFORM_DIR="${INFRA_DIR}/terraform" readonly K8S_DIR="${INFRA_DIR}/k8s" +readonly PROXMOX_WORKSPACE_ROOT="$(cd "${PROJECT_ROOT}/.." && pwd)" -# Azure configuration -readonly AZURE_REGION="${AZURE_REGION:-westeurope}" -readonly AZURE_SUBSCRIPTION_ID="${AZURE_SUBSCRIPTION_ID:-}" - -# Region abbreviation mapping -get_region_abbrev() { - case "${AZURE_REGION}" in - westeurope) echo "we" ;; - northeurope) echo "ne" ;; - uksouth) echo "uk" ;; - switzerlandnorth) echo "ch" ;; - norwayeast) echo "no" ;; - francecentral) echo "fr" ;; - germanywestcentral) echo "de" ;; - *) echo "we" ;; # Default to westeurope - esac -} +# Load shared Sankofa / Proxmox network inventory when available. +if [ -f "${PROXMOX_WORKSPACE_ROOT}/config/ip-addresses.conf" ]; then + # shellcheck source=/dev/null + source "${PROXMOX_WORKSPACE_ROOT}/config/ip-addresses.conf" +fi # Environment abbreviation mapping get_env_abbrev() { @@ -52,36 +41,17 @@ get_env_abbrev() { esac } -# Naming convention: {provider}-{region}-{resource}-{env}-{purpose} -readonly REGION_SHORT=$(get_region_abbrev) readonly ENV_SHORT=$(get_env_abbrev) -readonly NAME_PREFIX="az-${REGION_SHORT}" +readonly NAME_PREFIX="sankofa-${ENV_SHORT}" # Environment configuration readonly ENVIRONMENT="${ENVIRONMENT:-dev}" readonly NAMESPACE="the-order-${ENVIRONMENT}" -# Resource Groups (az-we-rg-dev-main) -readonly RESOURCE_GROUP_NAME="${RESOURCE_GROUP_NAME:-${NAME_PREFIX}-rg-${ENV_SHORT}-main}" -readonly AKS_RESOURCE_GROUP="${AKS_RESOURCE_GROUP:-${RESOURCE_GROUP_NAME}}" - -# Container registry (azweacrdev - alphanumeric only, max 50 chars) -readonly ACR_NAME="${ACR_NAME:-az${REGION_SHORT}acr${ENV_SHORT}}" +# Local image / artifact configuration +readonly IMAGE_REGISTRY="${IMAGE_REGISTRY:-theorder}" readonly IMAGE_TAG="${IMAGE_TAG:-latest}" -# Kubernetes configuration (az-we-aks-dev-main) -readonly AKS_NAME="${AKS_NAME:-${NAME_PREFIX}-aks-${ENV_SHORT}-main}" - -# Key Vault (az-we-kv-dev-main - max 24 chars) -readonly KEY_VAULT_NAME="${KEY_VAULT_NAME:-${NAME_PREFIX}-kv-${ENV_SHORT}-main}" - -# Database (az-we-psql-dev-main) -readonly POSTGRES_SERVER_NAME="${POSTGRES_SERVER_NAME:-${NAME_PREFIX}-psql-${ENV_SHORT}-main}" -readonly POSTGRES_DB_NAME="${POSTGRES_DB_NAME:-${NAME_PREFIX}-db-${ENV_SHORT}-main}" - -# Storage (azwesadevdata - alphanumeric only, max 24 chars) -readonly STORAGE_ACCOUNT_NAME="${STORAGE_ACCOUNT_NAME:-az${REGION_SHORT}sa${ENV_SHORT}data}" - # Services readonly SERVICES=("identity" "intake" "finance" "dataroom") readonly APPS=("portal-public" "portal-internal") @@ -103,10 +73,61 @@ readonly LOG_FILE="${LOG_DIR}/deployment-$(date +%Y%m%d-%H%M%S).log" # Deployment state readonly STATE_DIR="${PROJECT_ROOT}/.deployment" readonly STATE_FILE="${STATE_DIR}/${ENVIRONMENT}.state" +readonly ARTIFACTS_DIR="${STATE_DIR}/artifacts" + +# Sankofa Phoenix / Proxmox deployment topology +readonly PROXMOX_HOST="${PROXMOX_HOST:-${PROXMOX_HOST_R630_01:-192.168.11.11}}" +readonly PROXMOX_SSH_USER="${PROXMOX_SSH_USER:-root}" +readonly SSH_OPTS="${SSH_OPTS:--o BatchMode=yes -o ConnectTimeout=15 -o StrictHostKeyChecking=accept-new}" + +resolve_host_for_vmid() { + local vmid="$1" + local host + local candidates=( + "${PROXMOX_HOST_R630_01:-192.168.11.11}" + "${PROXMOX_HOST_R630_02:-192.168.11.12}" + "${PROXMOX_HOST_R630_03:-192.168.11.13}" + "${PROXMOX_HOST_R630_04:-192.168.11.14}" + ) + + if command -v ssh >/dev/null 2>&1; then + for host in "${candidates[@]}"; do + if ssh -o BatchMode=yes -o ConnectTimeout=5 -o StrictHostKeyChecking=accept-new \ + "${PROXMOX_SSH_USER}@${host}" "pct status ${vmid}" >/dev/null 2>&1; then + echo "${host}" + return 0 + fi + done + fi + + case "${vmid}" in + 10090|10091|10092|10210) echo "${PROXMOX_HOST_R630_04:-192.168.11.14}" ;; + *) echo "${PROXMOX_HOST}" ;; + esac +} + +readonly ORDER_PORTAL_PUBLIC_VMID="${ORDER_PORTAL_PUBLIC_VMID:-10090}" +readonly ORDER_PORTAL_PUBLIC_HOST="${ORDER_PORTAL_PUBLIC_HOST:-$(resolve_host_for_vmid "${ORDER_PORTAL_PUBLIC_VMID}")}" +readonly ORDER_PORTAL_PUBLIC_IP="${ORDER_PORTAL_PUBLIC_IP:-192.168.11.36}" +readonly ORDER_PORTAL_PUBLIC_PORT="${ORDER_PORTAL_PUBLIC_PORT:-3000}" +readonly ORDER_PORTAL_PUBLIC_APP_DIR="${ORDER_PORTAL_PUBLIC_APP_DIR:-/opt/the-order/portal-public}" +readonly ORDER_PORTAL_PUBLIC_SERVICE="${ORDER_PORTAL_PUBLIC_SERVICE:-the-order-portal-public}" + +readonly ORDER_HAPROXY_VMID="${ORDER_HAPROXY_VMID:-10210}" +readonly ORDER_HAPROXY_HOST="${ORDER_HAPROXY_HOST:-$(resolve_host_for_vmid "${ORDER_HAPROXY_VMID}")}" +readonly ORDER_HAPROXY_IP="${ORDER_HAPROXY_IP:-${IP_ORDER_HAPROXY:-192.168.11.39}}" +readonly ORDER_HAPROXY_BACKEND_HOST="${ORDER_HAPROXY_BACKEND_HOST:-${ORDER_PORTAL_PUBLIC_IP}}" +readonly ORDER_HAPROXY_BACKEND_PORT="${ORDER_HAPROXY_BACKEND_PORT:-${ORDER_PORTAL_PUBLIC_PORT}}" + +readonly THE_ORDER_PUBLIC_URL="${THE_ORDER_PUBLIC_URL:-https://the-order.sankofa.nexus}" +readonly THE_ORDER_WWW_URL="${THE_ORDER_WWW_URL:-https://www.the-order.sankofa.nexus}" +readonly SANKOFA_PHOENIX_URL="${SANKOFA_PHOENIX_URL:-https://phoenix.sankofa.nexus}" +readonly SANKOFA_PORTAL_URL="${SANKOFA_PORTAL_URL:-https://portal.sankofa.nexus}" # Create necessary directories mkdir -p "${LOG_DIR}" mkdir -p "${STATE_DIR}" +mkdir -p "${ARTIFACTS_DIR}" # Logging functions log_info() { @@ -142,24 +163,40 @@ check_command() { fi } -check_azure_login() { - if ! az account show &> /dev/null; then - log_warning "Not logged into Azure. Attempting login..." - az login || error_exit "Failed to login to Azure" - fi -} - check_prerequisites() { log_info "Checking prerequisites..." check_command "node" check_command "pnpm" - check_command "az" - check_command "terraform" - check_command "kubectl" check_command "docker" + check_command "git" + check_command "jq" + check_command "ssh" + check_command "scp" + check_command "tar" log_success "All prerequisites met" } +check_proxmox_access() { + local hosts=("${PROXMOX_HOST}" "${ORDER_PORTAL_PUBLIC_HOST}" "${ORDER_HAPROXY_HOST}") + local unique_hosts=() + local host + + for host in "${hosts[@]}"; do + [[ -z "${host}" ]] && continue + if [[ " ${unique_hosts[*]} " != *" ${host} "* ]]; then + unique_hosts+=("${host}") + fi + done + + for host in "${unique_hosts[@]}"; do + log_info "Checking Proxmox access at ${PROXMOX_SSH_USER}@${host}..." + ssh ${SSH_OPTS} "${PROXMOX_SSH_USER}@${host}" "echo ok" >/dev/null \ + || error_exit "Failed to reach Proxmox host ${host} over SSH" + done + + log_success "Proxmox SSH access verified" +} + # State management save_state() { local phase="$1" @@ -177,6 +214,5 @@ load_state() { # Export functions export -f log_info log_success log_warning log_error log_step error_exit -export -f check_command check_azure_login check_prerequisites +export -f check_command check_prerequisites check_proxmox_access export -f save_state load_state - diff --git a/scripts/deploy/deploy.sh b/scripts/deploy/deploy.sh index e152839..a6dc100 100755 --- a/scripts/deploy/deploy.sh +++ b/scripts/deploy/deploy.sh @@ -25,7 +25,7 @@ usage() { cat << EOF Usage: $0 [OPTIONS] [PHASES...] -Deploy The Order application to Azure/Kubernetes. +Deploy The Order application into the Sankofa Phoenix / Proxmox runtime. OPTIONS: -e, --environment ENV Environment (dev, stage, prod) [default: dev] @@ -40,14 +40,14 @@ OPTIONS: PHASES: 1 - Prerequisites - 2 - Azure Infrastructure Setup - 3 - Entra ID Configuration (manual) + 2 - Sankofa Phoenix Target Preparation + 3 - Identity Provider Secrets (manual) 4 - Database & Storage Setup - 5 - Container Registry Setup + 5 - Local Artifact / Runtime Preparation 6 - Application Build & Package 7 - Database Migrations 8 - Secrets Configuration (manual) - 9 - Infrastructure Services Deployment + 9 - Sankofa Edge & Runtime Checks 10 - Backend Services Deployment 11 - Frontend Applications Deployment 12 - Networking & Gateways @@ -133,8 +133,8 @@ fi # Phase scripts mapping declare -A PHASE_SCRIPTS=( ["1"]="phase1-prerequisites.sh" - ["2"]="phase2-azure-infrastructure.sh" - ["3"]="phase3-entra-id.sh" + ["2"]="phase2-sankofa-phoenix-target.sh" + ["3"]="phase3-identity-secrets.sh" ["4"]="phase4-database-storage.sh" ["5"]="phase5-container-registry.sh" ["6"]="phase6-build-package.sh" diff --git a/scripts/deploy/phase1-prerequisites.sh b/scripts/deploy/phase1-prerequisites.sh index 33807e3..75df6ed 100755 --- a/scripts/deploy/phase1-prerequisites.sh +++ b/scripts/deploy/phase1-prerequisites.sh @@ -32,38 +32,18 @@ if [ "${PNPM_VERSION}" -lt 8 ]; then fi log_success "pnpm version: $(pnpm --version)" -# Check Terraform version -TERRAFORM_VERSION=$(terraform version -json | jq -r '.terraform_version' | cut -d'.' -f1) -if [ "${TERRAFORM_VERSION}" -lt 1 ]; then - error_exit "Terraform version 1.5.0 or higher is required" -fi -log_success "Terraform version: $(terraform version -json | jq -r '.terraform_version')" - log_success "All tools verified" -# 1.2 Azure Account Setup -log_step "1.2 Setting up Azure account..." +# 1.2 Proxmox / Sankofa access +log_step "1.2 Verifying Sankofa Phoenix deployment access..." -check_azure_login - -if [ -z "${AZURE_SUBSCRIPTION_ID}" ]; then - log_warning "AZURE_SUBSCRIPTION_ID not set. Using current subscription." - AZURE_SUBSCRIPTION_ID=$(az account show --query id -o tsv) -fi - -az account set --subscription "${AZURE_SUBSCRIPTION_ID}" || error_exit "Failed to set subscription" - -SUBSCRIPTION_NAME=$(az account show --query name -o tsv) -log_success "Using Azure subscription: ${SUBSCRIPTION_NAME} (${AZURE_SUBSCRIPTION_ID})" - -# Verify permissions -log_step "Checking Azure permissions..." -ROLE=$(az role assignment list --assignee "$(az account show --query user.name -o tsv)" --query "[0].roleDefinitionName" -o tsv 2>/dev/null || echo "Unknown") -if [[ "${ROLE}" != *"Contributor"* ]] && [[ "${ROLE}" != *"Owner"* ]]; then - log_warning "Current role: ${ROLE}. Contributor or Owner role recommended." -else - log_success "Permissions verified: ${ROLE}" -fi +check_proxmox_access +log_info "Portal CT host: ${ORDER_PORTAL_PUBLIC_HOST}" +log_info "Edge HAProxy host: ${ORDER_HAPROXY_HOST}" +log_info "Order public CT: ${ORDER_PORTAL_PUBLIC_VMID} (${ORDER_PORTAL_PUBLIC_IP}:${ORDER_PORTAL_PUBLIC_PORT})" +log_info "Order edge HAProxy: ${ORDER_HAPROXY_VMID} (${ORDER_HAPROXY_IP}:80)" +log_info "Phoenix public URL: ${SANKOFA_PHOENIX_URL}" +log_info "Portal public URL: ${SANKOFA_PORTAL_URL}" # 1.3 Install Dependencies log_step "1.3 Installing dependencies..." @@ -105,4 +85,3 @@ save_state "phase1" "complete" log_success "==========================================" log_success "Phase 1: Prerequisites - COMPLETE" log_success "==========================================" - diff --git a/scripts/deploy/phase10-backend-services.sh b/scripts/deploy/phase10-backend-services.sh index 17f87b5..0c95b7a 100755 --- a/scripts/deploy/phase10-backend-services.sh +++ b/scripts/deploy/phase10-backend-services.sh @@ -1,7 +1,7 @@ #!/bin/bash # # Phase 10: Backend Services Deployment -# Deploy backend services to Kubernetes +# Validate backend manifests and service URLs for the Sankofa runtime. # set -euo pipefail @@ -13,105 +13,33 @@ log_info "==========================================" log_info "Phase 10: Backend Services Deployment" log_info "==========================================" -# Verify Kubernetes access -log_step "10.1 Verifying Kubernetes access..." - -if ! kubectl cluster-info &> /dev/null; then - log_info "Getting AKS credentials..." - az aks get-credentials --resource-group "${AKS_RESOURCE_GROUP}" \ - --name "${AKS_NAME}" \ - --overwrite-existing \ - || error_exit "Failed to get AKS credentials" -fi - -kubectl cluster-info || error_exit "Kubernetes cluster not accessible" - -# Ensure namespace exists -log_step "10.2 Ensuring namespace exists..." - -kubectl create namespace "${NAMESPACE}" --dry-run=client -o yaml | kubectl apply -f - || \ - log_warning "Namespace may already exist" - -# Deploy External Secrets (if not already deployed) -log_step "10.3 Checking External Secrets Operator..." - -if ! kubectl get crd externalsecrets.external-secrets.io &> /dev/null; then - log_info "Installing External Secrets Operator..." - kubectl apply -f https://external-secrets.io/latest/deploy/ || error_exit "Failed to install External Secrets" - - log_info "Waiting for External Secrets Operator to be ready..." - kubectl wait --for=condition=ready pod \ - -l app.kubernetes.io/name=external-secrets \ - -n external-secrets-system \ - --timeout=300s || log_warning "External Secrets Operator not ready yet" -else - log_success "External Secrets Operator already installed" -fi - -# Deploy each service -log_step "10.4 Deploying backend services..." - +log_step "10.1 Validating backend manifests..." for service in "${SERVICES[@]}"; do - log_info "Deploying ${service} service..." - - # Check if manifests exist SERVICE_DIR="${K8S_DIR}/base/${service}" if [ ! -d "${SERVICE_DIR}" ]; then - log_warning "Kubernetes manifests not found for ${service} at ${SERVICE_DIR}" - log_info "Skipping ${service} deployment" + log_warning "Backend manifest directory not found for ${service}: ${SERVICE_DIR}" continue fi - - # Apply manifests - kubectl apply -f "${SERVICE_DIR}" -n "${NAMESPACE}" || error_exit "Failed to deploy ${service}" - - # Wait for deployment - log_info "Waiting for ${service} deployment..." - kubectl wait --for=condition=available \ - deployment/"${service}" \ - -n "${NAMESPACE}" \ - --timeout=300s || log_warning "${service} deployment not ready yet" - - # Verify pods - PODS=$(kubectl get pods -l app="${service}" -n "${NAMESPACE}" --no-headers 2>/dev/null | wc -l) - if [ "${PODS}" -gt 0 ]; then - log_success "${service} deployed (${PODS} pod(s))" - - # Check pod status - kubectl get pods -l app="${service}" -n "${NAMESPACE}" + + if command -v kubectl >/dev/null; then + kubectl apply --dry-run=client -f "${SERVICE_DIR}" >/dev/null \ + && log_success "${service} manifests render cleanly" \ + || log_warning "${service} manifests failed dry-run validation" else - log_warning "${service} pods not found" + log_info "kubectl not installed; skipping manifest validation for ${service}" fi done -# Verify service endpoints -log_step "10.5 Verifying service endpoints..." - +log_step "10.2 Reporting expected service URLs..." for service in "${SERVICES[@]}"; do - if kubectl get svc "${service}" -n "${NAMESPACE}" &> /dev/null; then - log_success "Service ${service} endpoint created" - - # Test health endpoint (if accessible) - PORT="${SERVICE_PORTS[$service]}" - if [ -n "${PORT}" ]; then - log_info "Testing ${service} health endpoint on port ${PORT}..." - kubectl run test-${service}-health \ - --image=curlimages/curl \ - --rm -i --restart=Never \ - -- curl -f "http://${service}:${PORT}/health" \ - -n "${NAMESPACE}" 2>/dev/null && \ - log_success "${service} health check passed" || \ - log_warning "${service} health check failed or endpoint not ready" - fi - else - log_warning "Service ${service} endpoint not found" - fi + log_info "${service} expected port: ${SERVICE_PORTS[$service]}" done +log_info "Backend deployment remains environment-specific. Use the Phoenix edge / CT flow for the public frontend and connect backend services through your chosen runtime separately." + # Save state save_state "phase10" "complete" log_success "==========================================" log_success "Phase 10: Backend Services - COMPLETE" log_success "==========================================" - diff --git a/scripts/deploy/phase11-frontend-apps.sh b/scripts/deploy/phase11-frontend-apps.sh index a95a78d..cf8b369 100755 --- a/scripts/deploy/phase11-frontend-apps.sh +++ b/scripts/deploy/phase11-frontend-apps.sh @@ -1,7 +1,7 @@ #!/bin/bash # # Phase 11: Frontend Applications Deployment -# Deploy portal applications to Kubernetes +# Deploy portal applications to the Sankofa Phoenix / Proxmox runtime. # set -euo pipefail @@ -13,82 +13,29 @@ log_info "==========================================" log_info "Phase 11: Frontend Applications Deployment" log_info "==========================================" -OVERLAY_DIR="${K8S_DIR}/overlays/${ENVIRONMENT}" +log_step "11.1 Deploying portal-public to the Order runtime CT..." +bash "${SCRIPT_DIR}/sync-portal-public-to-sankofa-phoenix.sh" || error_exit "Failed to sync portal-public to Sankofa Phoenix" -# Verify Kubernetes access -if ! kubectl cluster-info &> /dev/null; then - az aks get-credentials --resource-group "${AKS_RESOURCE_GROUP}" \ - --name "${AKS_NAME}" \ - --overwrite-existing -fi +log_step "11.2 Refreshing the Order HAProxy edge..." +env \ + ORDER_HAPROXY_BACKEND_HOST="${ORDER_HAPROXY_BACKEND_HOST}" \ + ORDER_HAPROXY_BACKEND_PORT="${ORDER_HAPROXY_BACKEND_PORT}" \ + PROXMOX_ORDER_HAPROXY_NODE="${ORDER_HAPROXY_HOST}" \ + bash "${PROJECT_ROOT}/../scripts/deployment/provision-order-haproxy-10210.sh" \ + || error_exit "Failed to refresh order-haproxy" -# Ensure namespace exists -kubectl create namespace "${NAMESPACE}" --dry-run=client -o yaml | kubectl apply -f - +log_step "11.3 Verifying LAN and public health..." +curl -fsS "http://${ORDER_PORTAL_PUBLIC_IP}:${ORDER_PORTAL_PUBLIC_PORT}/api/health" >/dev/null \ + && log_success "Direct CT health check passed" \ + || log_warning "Direct CT health check failed" -if [ -d "${OVERLAY_DIR}" ]; then - log_step "11.0 Validating and applying ${ENVIRONMENT} overlay..." - kubectl kustomize "${OVERLAY_DIR}" > /dev/null || error_exit "Failed to render overlay ${OVERLAY_DIR}" - kubectl apply -k "${OVERLAY_DIR}" || error_exit "Failed to apply overlay ${OVERLAY_DIR}" -else - log_warning "Overlay not found for environment ${ENVIRONMENT}: ${OVERLAY_DIR}" - log_info "Falling back to per-app base manifests" -fi +curl -fsS -H "Host: the-order.sankofa.nexus" "http://${ORDER_HAPROXY_IP}/api/health" >/dev/null \ + && log_success "HAProxy health check passed" \ + || log_warning "HAProxy health check failed" -# Deploy each app -log_step "11.1 Deploying frontend applications..." - -for app in "${APPS[@]}"; do - log_info "Deploying ${app}..." - - APP_DIR="${K8S_DIR}/base/${app}" - if [ ! -d "${APP_DIR}" ]; then - log_warning "Kubernetes manifests not found for ${app} at ${APP_DIR}" - log_info "Skipping ${app} deployment" - continue - fi - - if [ ! -d "${OVERLAY_DIR}" ]; then - kubectl apply -f "${APP_DIR}" -n "${NAMESPACE}" || error_exit "Failed to deploy ${app}" - fi - - IMAGE_NAME="${ACR_NAME}.azurecr.io/${app}:${IMAGE_TAG}" - CONTAINER_NAME="${app}" - - log_info "Updating ${app} image to ${IMAGE_NAME}..." - kubectl set image deployment/"${app}" \ - "${CONTAINER_NAME}"="${IMAGE_NAME}" \ - -n "${NAMESPACE}" || error_exit "Failed to set image for ${app}" - - # Wait for deployment - log_info "Waiting for ${app} deployment..." - kubectl rollout status \ - deployment/"${app}" \ - -n "${NAMESPACE}" \ - --timeout=300s || log_warning "${app} deployment not ready yet" - - # Verify pods - PODS=$(kubectl get pods -l app="${app}" -n "${NAMESPACE}" --no-headers 2>/dev/null | wc -l) - if [ "${PODS}" -gt 0 ]; then - log_success "${app} deployed (${PODS} pod(s))" - kubectl get pods -l app="${app}" -n "${NAMESPACE}" - else - log_warning "${app} pods not found" - fi - - if kubectl get svc "${app}" -n "${NAMESPACE}" &> /dev/null; then - PORT="${SERVICE_PORTS[$app]}" - if [ -n "${PORT}" ]; then - log_info "Testing ${app} health endpoint on port ${PORT}..." - kubectl run test-${app}-health \ - --image=curlimages/curl \ - --rm -i --restart=Never \ - -n "${NAMESPACE}" -- \ - curl -fsS "http://${app}:${PORT}/api/health" >/dev/null && \ - log_success "${app} health check passed" || \ - log_warning "${app} health check failed or endpoint not ready" - fi - fi -done +curl -fsS "${THE_ORDER_PUBLIC_URL}/api/health" >/dev/null \ + && log_success "Public health check passed" \ + || log_warning "Public health check failed" # Save state save_state "phase11" "complete" diff --git a/scripts/deploy/phase13-monitoring.sh b/scripts/deploy/phase13-monitoring.sh index f6f5cd4..007ef0e 100755 --- a/scripts/deploy/phase13-monitoring.sh +++ b/scripts/deploy/phase13-monitoring.sh @@ -1,7 +1,7 @@ #!/bin/bash # # Phase 13: Monitoring & Observability -# Configure Application Insights, Log Analytics, alerts, dashboards +# Verify the Phoenix-native runtime is producing healthy service and journald signals. # set -euo pipefail @@ -13,68 +13,24 @@ log_info "==========================================" log_info "Phase 13: Monitoring & Observability" log_info "==========================================" -# 13.1 Application Insights -log_step "13.1 Creating Application Insights..." +check_proxmox_access -APP_INSIGHTS_NAME="${PROJECT_NAME}-${ENVIRONMENT}-ai" -APP_INSIGHTS_EXISTS=$(az monitor app-insights component show \ - --app "${APP_INSIGHTS_NAME}" \ - --resource-group "${AKS_RESOURCE_GROUP}" \ - --query name -o tsv 2>/dev/null || echo "") +log_step "13.1 Verifying service status inside the Order CT..." +ssh ${SSH_OPTS} "${PROXMOX_SSH_USER}@${ORDER_PORTAL_PUBLIC_HOST}" \ + "pct exec ${ORDER_PORTAL_PUBLIC_VMID} -- systemctl is-active ${ORDER_PORTAL_PUBLIC_SERVICE}" \ + && log_success "The Order portal service is active" \ + || log_warning "The Order portal service is not active" -if [ -z "${APP_INSIGHTS_EXISTS}" ]; then - log_info "Creating Application Insights resource..." - az monitor app-insights component create \ - --app "${APP_INSIGHTS_NAME}" \ - --location "${AZURE_REGION}" \ - --resource-group "${AKS_RESOURCE_GROUP}" \ - --application-type web \ - || log_warning "Failed to create Application Insights" -else - log_success "Application Insights already exists" -fi - -# Get instrumentation key -INSTRUMENTATION_KEY=$(az monitor app-insights component show \ - --app "${APP_INSIGHTS_NAME}" \ - --resource-group "${AKS_RESOURCE_GROUP}" \ - --query instrumentationKey -o tsv 2>/dev/null || echo "") - -if [ -n "${INSTRUMENTATION_KEY}" ]; then - log_info "Storing instrumentation key in Key Vault..." - az keyvault secret set \ - --vault-name "${KEY_VAULT_NAME}" \ - --name "app-insights-instrumentation-key" \ - --value "${INSTRUMENTATION_KEY}" \ - || log_warning "Failed to store instrumentation key" -fi - -# 13.2 Log Analytics Workspace -log_step "13.2 Creating Log Analytics workspace..." - -LOG_ANALYTICS_NAME="${PROJECT_NAME}-${ENVIRONMENT}-logs" -LOG_ANALYTICS_EXISTS=$(az monitor log-analytics workspace show \ - --workspace-name "${LOG_ANALYTICS_NAME}" \ - --resource-group "${AKS_RESOURCE_GROUP}" \ - --query name -o tsv 2>/dev/null || echo "") - -if [ -z "${LOG_ANALYTICS_EXISTS}" ]; then - log_info "Creating Log Analytics workspace..." - az monitor log-analytics workspace create \ - --workspace-name "${LOG_ANALYTICS_NAME}" \ - --resource-group "${AKS_RESOURCE_GROUP}" \ - --location "${AZURE_REGION}" \ - || log_warning "Failed to create Log Analytics workspace" -else - log_success "Log Analytics workspace already exists" -fi +log_step "13.2 Showing recent journald entries..." +ssh ${SSH_OPTS} "${PROXMOX_SSH_USER}@${ORDER_PORTAL_PUBLIC_HOST}" \ + "pct exec ${ORDER_PORTAL_PUBLIC_VMID} -- journalctl -u ${ORDER_PORTAL_PUBLIC_SERVICE} -n 20 --no-pager" \ + || log_warning "Unable to fetch recent journald entries" log_info "Monitoring configuration complete" log_info "Next steps (manual):" -log_info " 1. Configure alerts in Azure Portal" -log_info " 2. Set up Grafana dashboards" -log_info " 3. Configure log queries" -log_info " 4. Set up notification channels" +log_info " 1. Add the CT service to your central log shipping path if desired" +log_info " 2. Add synthetic checks for ${THE_ORDER_PUBLIC_URL}/api/health" +log_info " 3. Keep Phoenix public health in the shared external monitor set" # Save state save_state "phase13" "complete" @@ -82,4 +38,3 @@ save_state "phase13" "complete" log_success "==========================================" log_success "Phase 13: Monitoring & Observability - COMPLETE" log_success "==========================================" - diff --git a/scripts/deploy/phase14-testing.sh b/scripts/deploy/phase14-testing.sh index c57e6aa..58befe6 100755 --- a/scripts/deploy/phase14-testing.sh +++ b/scripts/deploy/phase14-testing.sh @@ -16,31 +16,23 @@ log_info "==========================================" # 14.1 Health Checks log_step "14.1 Running health checks..." -if ! kubectl cluster-info &> /dev/null; then - az aks get-credentials --resource-group "${AKS_RESOURCE_GROUP}" \ - --name "${AKS_NAME}" \ - --overwrite-existing -fi +check_proxmox_access -# Check all pods -log_info "Checking pod status..." -kubectl get pods -n "${NAMESPACE}" || log_warning "Failed to get pods" +curl -fsS "http://${ORDER_PORTAL_PUBLIC_IP}:${ORDER_PORTAL_PUBLIC_PORT}/api/health" >/dev/null \ + && log_success "Direct Order CT health check passed" \ + || log_warning "Direct Order CT health check failed" -# Check service endpoints -log_info "Checking service endpoints..." -for service in "${SERVICES[@]}"; do - if kubectl get svc "${service}" -n "${NAMESPACE}" &> /dev/null; then - PORT="${SERVICE_PORTS[$service]}" - log_info "Testing ${service} health endpoint..." - kubectl run test-${service}-health \ - --image=curlimages/curl \ - --rm -i --restart=Never \ - -- curl -f "http://${service}:${PORT}/health" \ - -n "${NAMESPACE}" 2>/dev/null && \ - log_success "${service} health check passed" || \ - log_warning "${service} health check failed" - fi -done +curl -fsS -H "Host: the-order.sankofa.nexus" "http://${ORDER_HAPROXY_IP}/api/health" >/dev/null \ + && log_success "Order HAProxy health check passed" \ + || log_warning "Order HAProxy health check failed" + +curl -fsS "${THE_ORDER_PUBLIC_URL}/api/health" >/dev/null \ + && log_success "Public The Order health check passed" \ + || log_warning "Public The Order health check failed" + +curl -fsS "${SANKOFA_PHOENIX_URL}/health" >/dev/null \ + && log_success "Phoenix public health check passed" \ + || log_warning "Phoenix public health check failed" # 14.2 Integration Testing log_step "14.2 Running integration tests..." @@ -66,4 +58,3 @@ save_state "phase14" "complete" log_success "==========================================" log_success "Phase 14: Testing & Validation - COMPLETE" log_success "==========================================" - diff --git a/scripts/deploy/phase15-production.sh b/scripts/deploy/phase15-production.sh index bac5dac..44a853d 100755 --- a/scripts/deploy/phase15-production.sh +++ b/scripts/deploy/phase15-production.sh @@ -21,39 +21,23 @@ if [ "${ENVIRONMENT}" != "prod" ]; then exit 0 fi -# Update replica counts -log_info "Updating replica counts for production..." -for service in "${SERVICES[@]}"; do - kubectl scale deployment "${service}" \ - --replicas=3 \ - -n "${NAMESPACE}" \ - || log_warning "Failed to scale ${service}" -done +log_info "Production runtime target: ${ORDER_PORTAL_PUBLIC_VMID} -> ${ORDER_HAPROXY_VMID} -> ${THE_ORDER_PUBLIC_URL}" -# 15.2 Backup Configuration -log_step "15.2 Configuring backups..." +log_step "15.2 Verifying production health..." +curl -fsS "${THE_ORDER_PUBLIC_URL}/api/health" >/dev/null \ + && log_success "Production public health check passed" \ + || log_warning "Production public health check failed" -# Database backups -log_info "Configuring database backups..." -az postgres server backup create \ - --resource-group "${AKS_RESOURCE_GROUP}" \ - --server-name "${POSTGRES_SERVER_NAME}" \ - --backup-name "daily-backup-$(date +%Y%m%d)" \ - || log_warning "Failed to create database backup" - -# Storage backups -log_info "Enabling storage versioning..." -az storage account blob-service-properties update \ - --account-name "${STORAGE_ACCOUNT_NAME}" \ - --enable-versioning true \ - || log_warning "Failed to enable versioning" +log_step "15.3 Backup / DR reminders..." +log_info "Ensure CT backups for ${ORDER_PORTAL_PUBLIC_VMID} and ${ORDER_HAPROXY_VMID} are present in the Proxmox schedule." +log_info "Ensure database backups are configured in the backing datastore used by The Order." log_info "Production hardening complete" log_info "Next steps (manual):" -log_info " 1. Configure resource limits in deployments" -log_info " 2. Set up automated backups" -log_info " 3. Configure disaster recovery" -log_info " 4. Review security settings" +log_info " 1. Review CT CPU / memory limits" +log_info " 2. Confirm Proxmox backup coverage" +log_info " 3. Confirm database backup coverage" +log_info " 4. Review public health and uptime monitors" log_info " 5. Update documentation" # Save state @@ -62,4 +46,3 @@ save_state "phase15" "complete" log_success "==========================================" log_success "Phase 15: Production Hardening - COMPLETE" log_success "==========================================" - diff --git a/scripts/deploy/phase2-azure-infrastructure.sh b/scripts/deploy/phase2-azure-infrastructure.sh deleted file mode 100755 index a47b515..0000000 --- a/scripts/deploy/phase2-azure-infrastructure.sh +++ /dev/null @@ -1,103 +0,0 @@ -#!/bin/bash -# -# Phase 2: Azure Infrastructure Setup -# Terraform infrastructure deployment -# - -set -euo pipefail - -SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" -source "${SCRIPT_DIR}/config.sh" - -log_info "==========================================" -log_info "Phase 2: Azure Infrastructure Setup" -log_info "==========================================" - -# 2.1 Azure Subscription Preparation -log_step "2.1 Preparing Azure subscription..." - -cd "${PROJECT_ROOT}" - -# Run Azure setup scripts -if [ -f "${INFRA_DIR}/scripts/azure-setup.sh" ]; then - log_info "Running Azure setup script..." - bash "${INFRA_DIR}/scripts/azure-setup.sh" || error_exit "Azure setup script failed" -else - log_warning "Azure setup script not found, skipping..." -fi - -# Register resource providers -if [ -f "${INFRA_DIR}/scripts/azure-register-providers.sh" ]; then - log_info "Registering Azure resource providers..." - bash "${INFRA_DIR}/scripts/azure-register-providers.sh" || error_exit "Provider registration failed" -else - log_warning "Provider registration script not found, skipping..." -fi - -# 2.2 Terraform Infrastructure Deployment -log_step "2.2 Deploying Terraform infrastructure..." - -cd "${TERRAFORM_DIR}" - -# Initialize Terraform -log_info "Initializing Terraform..." -terraform init || error_exit "Terraform initialization failed" - -# Create initial state storage if needed -if [ "${CREATE_STATE_STORAGE:-false}" = "true" ]; then - log_info "Creating Terraform state storage..." - terraform plan -target=azurerm_resource_group.terraform_state \ - -target=azurerm_storage_account.terraform_state \ - -target=azurerm_storage_container.terraform_state \ - || log_warning "State storage resources may already exist" - - terraform apply -target=azurerm_resource_group.terraform_state \ - -target=azurerm_storage_account.terraform_state \ - -target=azurerm_storage_container.terraform_state \ - || log_warning "State storage may already exist" -fi - -# Plan infrastructure -log_info "Planning infrastructure changes..." -terraform plan -out=tfplan || error_exit "Terraform plan failed" - -# Review plan (optional) -if [ "${AUTO_APPLY:-false}" != "true" ]; then - log_warning "Terraform plan created. Review tfplan before applying." - log_info "To apply: terraform apply tfplan" - log_info "To auto-apply: set AUTO_APPLY=true" -else - log_info "Applying Terraform plan..." - terraform apply tfplan || error_exit "Terraform apply failed" - log_success "Infrastructure deployed" -fi - -# Get outputs -log_info "Retrieving Terraform outputs..." -terraform output -json > "${STATE_DIR}/terraform-outputs.json" || log_warning "Failed to save outputs" - -# 2.3 Kubernetes Configuration -log_step "2.3 Configuring Kubernetes..." - -# Get AKS credentials -log_info "Getting AKS credentials..." -az aks get-credentials --resource-group "${AKS_RESOURCE_GROUP}" \ - --name "${AKS_NAME}" \ - --overwrite-existing \ - || log_warning "AKS cluster may not exist yet" - -# Verify cluster access -if kubectl cluster-info &> /dev/null; then - log_success "Kubernetes cluster accessible" - kubectl get nodes || log_warning "No nodes found" -else - log_warning "Kubernetes cluster not accessible yet" -fi - -# Save state -save_state "phase2" "complete" - -log_success "==========================================" -log_success "Phase 2: Azure Infrastructure - COMPLETE" -log_success "==========================================" - diff --git a/scripts/deploy/phase2-sankofa-phoenix-target.sh b/scripts/deploy/phase2-sankofa-phoenix-target.sh new file mode 100755 index 0000000..dc8db5a --- /dev/null +++ b/scripts/deploy/phase2-sankofa-phoenix-target.sh @@ -0,0 +1,44 @@ +#!/bin/bash +# +# Phase 2: Sankofa Phoenix Target Preparation +# Validate the Proxmox / CT targets used by the Phoenix-native deployment flow. +# + +set -euo pipefail + +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +source "${SCRIPT_DIR}/config.sh" + +log_info "==========================================" +log_info "Phase 2: Sankofa Phoenix Target Preparation" +log_info "==========================================" + +log_step "2.1 Verifying Proxmox and CT targets..." +check_proxmox_access + +ssh ${SSH_OPTS} "${PROXMOX_SSH_USER}@${ORDER_PORTAL_PUBLIC_HOST}" \ + "pct status ${ORDER_PORTAL_PUBLIC_VMID}" \ + || error_exit "Failed to verify Order public CT placement on ${ORDER_PORTAL_PUBLIC_HOST}" + +ssh ${SSH_OPTS} "${PROXMOX_SSH_USER}@${ORDER_HAPROXY_HOST}" \ + "pct status ${ORDER_HAPROXY_VMID}" \ + || error_exit "Failed to verify Order HAProxy placement on ${ORDER_HAPROXY_HOST}" + +log_step "2.2 Previewing The Order edge configuration..." +env \ + ORDER_HAPROXY_BACKEND_HOST="${ORDER_HAPROXY_BACKEND_HOST}" \ + ORDER_HAPROXY_BACKEND_PORT="${ORDER_HAPROXY_BACKEND_PORT}" \ + PROXMOX_ORDER_HAPROXY_NODE="${ORDER_HAPROXY_HOST}" \ + bash "${PROJECT_ROOT}/../scripts/deployment/provision-order-haproxy-10210.sh" --dry-run \ + || log_warning "Unable to preview order-haproxy config from the parent Proxmox workspace" + +log_step "2.3 Probing Sankofa Phoenix public health..." +curl -fsS "${SANKOFA_PHOENIX_URL}/health" >/dev/null \ + && log_success "Phoenix public health check passed" \ + || log_warning "Phoenix public health check failed or is not exposed at /health" + +save_state "phase2" "complete" + +log_success "==========================================" +log_success "Phase 2: Sankofa Phoenix Target Preparation - COMPLETE" +log_success "==========================================" diff --git a/scripts/deploy/phase3-entra-id.sh b/scripts/deploy/phase3-entra-id.sh deleted file mode 100755 index cabd88c..0000000 --- a/scripts/deploy/phase3-entra-id.sh +++ /dev/null @@ -1,48 +0,0 @@ -#!/bin/bash -# -# Phase 3: Entra ID Configuration -# Note: Most steps require manual configuration in Azure Portal -# - -set -euo pipefail - -SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" -source "${SCRIPT_DIR}/config.sh" - -log_info "==========================================" -log_info "Phase 3: Entra ID Configuration" -log_info "==========================================" - -log_warning "This phase requires manual steps in Azure Portal" -log_info "See docs/deployment/DEPLOYMENT_GUIDE.md for detailed instructions" - -# Check if secrets already exist -log_step "3.1 Checking for existing Entra ID configuration..." - -ENTRA_TENANT_ID=$(az keyvault secret show \ - --vault-name "${KEY_VAULT_NAME}" \ - --name "entra-tenant-id" \ - --query value -o tsv 2>/dev/null || echo "") - -if [ -n "${ENTRA_TENANT_ID}" ]; then - log_success "Entra ID configuration found in Key Vault" - log_info "Tenant ID: ${ENTRA_TENANT_ID}" -else - log_warning "Entra ID configuration not found" - log_info "Please complete manual steps:" - log_info " 1. Create App Registration in Azure Portal" - log_info " 2. Configure API permissions" - log_info " 3. Create client secret" - log_info " 4. Enable Verified ID service" - log_info " 5. Create credential manifest" - log_info "" - log_info "Then run: scripts/deploy/store-entra-secrets.sh" -fi - -# Save state -save_state "phase3" "manual-steps-required" - -log_success "==========================================" -log_success "Phase 3: Entra ID - Manual steps required" -log_success "==========================================" - diff --git a/scripts/deploy/phase3-identity-secrets.sh b/scripts/deploy/phase3-identity-secrets.sh new file mode 100755 index 0000000..5007ede --- /dev/null +++ b/scripts/deploy/phase3-identity-secrets.sh @@ -0,0 +1,48 @@ +#!/bin/bash +# +# Phase 3: Identity Provider Secrets +# Manual identity-provider setup, recorded in the local operator secret file. +# + +set -euo pipefail + +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +source "${SCRIPT_DIR}/config.sh" + +log_info "==========================================" +log_info "Phase 3: Identity Provider Secrets" +log_info "==========================================" + +SECRETS_FILE="${STATE_DIR}/secrets/${ENVIRONMENT}.env" + +log_warning "This phase requires manual identity-provider configuration" +log_info "See docs/deployment/DEPLOYMENT_GUIDE.md for detailed instructions" + +# Check if secrets already exist +log_step "3.1 Checking for existing identity-provider configuration..." + +if [ -f "${SECRETS_FILE}" ]; then + # shellcheck source=/dev/null + source "${SECRETS_FILE}" +fi + +if [ -n "${OIDC_ISSUER:-}" ] || [ -n "${VC_ISSUER_DID:-}" ] || [ -n "${VC_ISSUER_DOMAIN:-}" ]; then + log_success "Identity-provider configuration found in ${SECRETS_FILE}" + [ -n "${OIDC_ISSUER:-}" ] && log_info "OIDC issuer: ${OIDC_ISSUER}" + [ -n "${VC_ISSUER_DID:-}" ] && log_info "VC issuer DID: ${VC_ISSUER_DID}" + [ -n "${VC_ISSUER_DOMAIN:-}" ] && log_info "VC issuer domain: ${VC_ISSUER_DOMAIN}" +else + log_warning "Identity-provider configuration not found" + log_info "Please complete manual steps:" + log_info " 1. Set OIDC issuer and client details if this environment uses OIDC" + log_info " 2. Set VC_ISSUER_DID or VC_ISSUER_DOMAIN for credential issuance" + log_info " 3. Store those values in ${SECRETS_FILE}" + log_info "" +fi + +# Save state +save_state "phase3" "manual-steps-required" + +log_success "==========================================" +log_success "Phase 3: Identity Provider Secrets - Manual steps required" +log_success "==========================================" diff --git a/scripts/deploy/phase4-database-storage.sh b/scripts/deploy/phase4-database-storage.sh index 432e10e..114c3e0 100755 --- a/scripts/deploy/phase4-database-storage.sh +++ b/scripts/deploy/phase4-database-storage.sh @@ -1,7 +1,7 @@ #!/bin/bash # # Phase 4: Database & Storage Setup -# Configure PostgreSQL, Storage Accounts, Redis, OpenSearch +# Validate PostgreSQL, storage, Redis, and search configuration inputs for the Sankofa runtime. # set -euo pipefail @@ -13,77 +13,37 @@ log_info "==========================================" log_info "Phase 4: Database & Storage Setup" log_info "==========================================" -# 4.1 PostgreSQL Database Setup -log_step "4.1 Configuring PostgreSQL database..." - -# Check if database exists -DB_EXISTS=$(az postgres db show \ - --resource-group "${AKS_RESOURCE_GROUP}" \ - --server-name "${POSTGRES_SERVER_NAME}" \ - --name "${POSTGRES_DB_NAME}" \ - --query name -o tsv 2>/dev/null || echo "") - -if [ -z "${DB_EXISTS}" ]; then - log_info "Creating database ${POSTGRES_DB_NAME}..." - az postgres db create \ - --resource-group "${AKS_RESOURCE_GROUP}" \ - --server-name "${POSTGRES_SERVER_NAME}" \ - --name "${POSTGRES_DB_NAME}" \ - || error_exit "Failed to create database" - log_success "Database created" +log_step "4.1 Checking database configuration inputs..." +if [ -n "${DATABASE_URL:-}" ]; then + log_success "DATABASE_URL is set" else - log_success "Database already exists" + log_warning "DATABASE_URL is not set. Phase 7 will require it." fi -# Configure firewall rules for AKS -log_step "4.2 Configuring database firewall rules..." - -# Get AKS outbound IPs (if using NAT gateway) -# For now, allow Azure services -az postgres server firewall-rule create \ - --resource-group "${AKS_RESOURCE_GROUP}" \ - --server-name "${POSTGRES_SERVER_NAME}" \ - --name "AllowAzureServices" \ - --start-ip-address "0.0.0.0" \ - --end-ip-address "0.0.0.0" \ - --output none 2>/dev/null || log_info "Firewall rule may already exist" - -log_success "Database firewall configured" - -# 4.2 Storage Account Setup -log_step "4.3 Configuring storage accounts..." - -# Verify storage account exists -STORAGE_EXISTS=$(az storage account show \ - --name "${STORAGE_ACCOUNT_NAME}" \ - --resource-group "${AKS_RESOURCE_GROUP}" \ - --query name -o tsv 2>/dev/null || echo "") - -if [ -z "${STORAGE_EXISTS}" ]; then - log_warning "Storage account ${STORAGE_ACCOUNT_NAME} not found" - log_info "Storage account should be created by Terraform" -else - log_success "Storage account found" - - # Create containers - CONTAINERS=("intake-documents" "dataroom-deals" "credentials") - - for container in "${CONTAINERS[@]}"; do - log_info "Creating container: ${container}..." - az storage container create \ - --name "${container}" \ - --account-name "${STORAGE_ACCOUNT_NAME}" \ - --auth-mode login \ - --output none 2>/dev/null && \ - log_success "Container ${container} created" || \ - log_info "Container ${container} may already exist" - done +if [ -n "${ORDER_POSTGRES_PRIMARY:-}" ]; then + log_info "Order PostgreSQL primary: ${ORDER_POSTGRES_PRIMARY}" fi +log_step "4.2 Checking storage configuration inputs..." +if [ -n "${ORDER_STORAGE_ROOT:-}" ]; then + log_success "ORDER_STORAGE_ROOT is set to ${ORDER_STORAGE_ROOT}" +else + log_warning "ORDER_STORAGE_ROOT is not set. Configure it if document storage is required." +fi + +log_step "4.3 Checking Redis / search configuration inputs..." +if [ -n "${ORDER_REDIS_IP:-}" ]; then + log_info "Order Redis host: ${ORDER_REDIS_IP}" +fi +if [ -n "${IP_ORDER_OPENSEARCH:-}" ]; then + log_info "Order OpenSearch host: ${IP_ORDER_OPENSEARCH}" +fi + +log_info "Database and storage validation complete. Create or update the underlying services through the Proxmox runtime as needed." + # Save state save_state "phase4" "complete" log_success "==========================================" log_success "Phase 4: Database & Storage - COMPLETE" log_success "==========================================" - diff --git a/scripts/deploy/phase5-container-registry.sh b/scripts/deploy/phase5-container-registry.sh index 929e83a..9e8547c 100755 --- a/scripts/deploy/phase5-container-registry.sh +++ b/scripts/deploy/phase5-container-registry.sh @@ -1,7 +1,7 @@ #!/bin/bash # -# Phase 5: Container Registry Setup -# Configure Azure Container Registry and attach to AKS +# Phase 5: Local Artifact / Runtime Preparation +# Prepare local image tags and artifact directories for the Phoenix-native deployment flow. # set -euo pipefail @@ -10,55 +10,33 @@ SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" source "${SCRIPT_DIR}/config.sh" log_info "==========================================" -log_info "Phase 5: Container Registry Setup" +log_info "Phase 5: Local Artifact / Runtime Preparation" log_info "==========================================" -# 5.1 Verify ACR exists -log_step "5.1 Verifying Azure Container Registry..." +log_step "5.1 Verifying local Docker runtime..." +docker info >/dev/null || error_exit "Docker is not running" +log_success "Docker runtime available" -ACR_EXISTS=$(az acr show \ - --name "${ACR_NAME}" \ - --resource-group "${AKS_RESOURCE_GROUP}" \ - --query name -o tsv 2>/dev/null || echo "") +log_step "5.2 Preparing artifact directories..." +mkdir -p "${ARTIFACTS_DIR}/images" +log_success "Artifacts directory ready at ${ARTIFACTS_DIR}" -if [ -z "${ACR_EXISTS}" ]; then - log_warning "ACR ${ACR_NAME} not found" - log_info "ACR should be created by Terraform" - log_info "Skipping ACR configuration" - exit 0 -fi - -log_success "ACR found: ${ACR_NAME}" - -# 5.2 Configure ACR access -log_step "5.2 Configuring ACR access..." - -# Enable admin user (or use managed identity) -az acr update --name "${ACR_NAME}" --admin-enabled true \ - || log_warning "Failed to enable admin user (may already be enabled)" - -# 5.3 Attach ACR to AKS -log_step "5.3 Attaching ACR to AKS..." - -az aks update \ - --name "${AKS_NAME}" \ - --resource-group "${AKS_RESOURCE_GROUP}" \ - --attach-acr "${ACR_NAME}" \ - || log_warning "Failed to attach ACR (may already be attached)" - -log_success "ACR attached to AKS" - -# 5.4 Test ACR access -log_step "5.4 Testing ACR access..." - -az acr login --name "${ACR_NAME}" || error_exit "Failed to login to ACR" - -log_success "ACR access verified" +log_step "5.3 Recording image naming convention..." +{ + echo "IMAGE_REGISTRY=${IMAGE_REGISTRY}" + echo "IMAGE_TAG=${IMAGE_TAG}" + for service in "${SERVICES[@]}"; do + echo "${service}=${IMAGE_REGISTRY}/${service}:${IMAGE_TAG}" + done + for app in "${APPS[@]}"; do + echo "${app}=${IMAGE_REGISTRY}/${app}:${IMAGE_TAG}" + done +} > "${ARTIFACTS_DIR}/image-manifest-${ENVIRONMENT}.txt" +log_success "Image manifest written to ${ARTIFACTS_DIR}/image-manifest-${ENVIRONMENT}.txt" # Save state save_state "phase5" "complete" log_success "==========================================" -log_success "Phase 5: Container Registry - COMPLETE" +log_success "Phase 5: Local Artifact / Runtime Preparation - COMPLETE" log_success "==========================================" - diff --git a/scripts/deploy/phase6-build-package.sh b/scripts/deploy/phase6-build-package.sh index 345e829..de6bf96 100755 --- a/scripts/deploy/phase6-build-package.sh +++ b/scripts/deploy/phase6-build-package.sh @@ -46,19 +46,15 @@ done log_success "Backend services built" -# 6.4 Create Docker Images -log_step "6.4 Creating Docker images..." +# 6.4 Create local Docker images +log_step "6.4 Creating local Docker images..." # Check if Docker is running if ! docker info &> /dev/null; then error_exit "Docker is not running" fi -# Login to ACR -log_info "Logging into Azure Container Registry..." -az acr login --name "${ACR_NAME}" || error_exit "Failed to login to ACR" - -# Build and push service images +# Build service images for service in "${SERVICES[@]}"; do DOCKERFILE="${PROJECT_ROOT}/services/${service}/Dockerfile" @@ -68,8 +64,8 @@ for service in "${SERVICES[@]}"; do continue fi - IMAGE_NAME="${ACR_NAME}.azurecr.io/${service}:${IMAGE_TAG}" - IMAGE_NAME_SHA="${ACR_NAME}.azurecr.io/${service}:$(git rev-parse --short HEAD 2>/dev/null || echo 'latest')" + IMAGE_NAME="${IMAGE_REGISTRY}/${service}:${IMAGE_TAG}" + IMAGE_NAME_SHA="${IMAGE_REGISTRY}/${service}:$(git rev-parse --short HEAD 2>/dev/null || echo 'latest')" log_info "Building ${service} image..." docker build -t "${IMAGE_NAME}" \ @@ -77,14 +73,10 @@ for service in "${SERVICES[@]}"; do -f "${DOCKERFILE}" \ "${PROJECT_ROOT}" || error_exit "Failed to build ${service} image" - log_info "Pushing ${service} image..." - docker push "${IMAGE_NAME}" || error_exit "Failed to push ${service} image" - docker push "${IMAGE_NAME_SHA}" || log_warning "Failed to push ${service} SHA image" - - log_success "${service} image built and pushed" + log_success "${service} image built locally" done -# Build and push app images +# Build app images for app in "${APPS[@]}"; do DOCKERFILE="${PROJECT_ROOT}/apps/${app}/Dockerfile" @@ -94,8 +86,8 @@ for app in "${APPS[@]}"; do continue fi - IMAGE_NAME="${ACR_NAME}.azurecr.io/${app}:${IMAGE_TAG}" - IMAGE_NAME_SHA="${ACR_NAME}.azurecr.io/${app}:$(git rev-parse --short HEAD 2>/dev/null || echo 'latest')" + IMAGE_NAME="${IMAGE_REGISTRY}/${app}:${IMAGE_TAG}" + IMAGE_NAME_SHA="${IMAGE_REGISTRY}/${app}:$(git rev-parse --short HEAD 2>/dev/null || echo 'latest')" log_info "Building ${app} image..." docker build -t "${IMAGE_NAME}" \ @@ -103,11 +95,7 @@ for app in "${APPS[@]}"; do -f "${DOCKERFILE}" \ "${PROJECT_ROOT}" || error_exit "Failed to build ${app} image" - log_info "Pushing ${app} image..." - docker push "${IMAGE_NAME}" || error_exit "Failed to push ${app} image" - docker push "${IMAGE_NAME_SHA}" || log_warning "Failed to push ${app} SHA image" - - log_success "${app} image built and pushed" + log_success "${app} image built locally" done # Sign images with Cosign (if available) @@ -115,13 +103,13 @@ if command -v cosign &> /dev/null; then log_step "6.5 Signing images with Cosign..." for service in "${SERVICES[@]}"; do - IMAGE_NAME="${ACR_NAME}.azurecr.io/${service}:${IMAGE_TAG}" + IMAGE_NAME="${IMAGE_REGISTRY}/${service}:${IMAGE_TAG}" log_info "Signing ${service} image..." cosign sign --yes "${IMAGE_NAME}" || log_warning "Failed to sign ${service} image" done for app in "${APPS[@]}"; do - IMAGE_NAME="${ACR_NAME}.azurecr.io/${app}:${IMAGE_TAG}" + IMAGE_NAME="${IMAGE_REGISTRY}/${app}:${IMAGE_TAG}" log_info "Signing ${app} image..." cosign sign --yes "${IMAGE_NAME}" || log_warning "Failed to sign ${app} image" done @@ -131,10 +119,13 @@ else log_warning "Cosign not found, skipping image signing" fi +log_step "6.5 Preparing Phoenix deployment artifact..." +bash "${SCRIPT_DIR}/sync-portal-public-to-sankofa-phoenix.sh" --dry-run --skip-build \ + || log_warning "Phoenix artifact preview failed" + # Save state save_state "phase6" "complete" log_success "==========================================" log_success "Phase 6: Build & Package - COMPLETE" log_success "==========================================" - diff --git a/scripts/deploy/phase7-database-migrations.sh b/scripts/deploy/phase7-database-migrations.sh index 45598cb..831eac3 100755 --- a/scripts/deploy/phase7-database-migrations.sh +++ b/scripts/deploy/phase7-database-migrations.sh @@ -15,17 +15,14 @@ log_info "==========================================" cd "${PROJECT_ROOT}" -# Get database URL from Key Vault or environment +# Get database URL from environment or a local deployment secret file. +if [ -z "${DATABASE_URL:-}" ] && [ -f "${STATE_DIR}/secrets/${ENVIRONMENT}.env" ]; then + # shellcheck source=/dev/null + source "${STATE_DIR}/secrets/${ENVIRONMENT}.env" +fi + if [ -z "${DATABASE_URL:-}" ]; then - log_info "Retrieving DATABASE_URL from Azure Key Vault..." - DATABASE_URL=$(az keyvault secret show \ - --vault-name "${KEY_VAULT_NAME}" \ - --name "database-url-${ENVIRONMENT}" \ - --query value -o tsv 2>/dev/null || echo "") - - if [ -z "${DATABASE_URL}" ]; then - error_exit "DATABASE_URL not found in Key Vault and not set in environment" - fi + error_exit "DATABASE_URL not found in the environment or ${STATE_DIR}/secrets/${ENVIRONMENT}.env" fi log_step "7.1 Running database migrations for ${ENVIRONMENT}..." @@ -67,4 +64,3 @@ save_state "phase7" "complete" log_success "==========================================" log_success "Phase 7: Database Migrations - COMPLETE" log_success "==========================================" - diff --git a/scripts/deploy/phase8-secrets.sh b/scripts/deploy/phase8-secrets.sh index 8529080..9afd1fc 100755 --- a/scripts/deploy/phase8-secrets.sh +++ b/scripts/deploy/phase8-secrets.sh @@ -1,8 +1,7 @@ #!/bin/bash # # Phase 8: Secrets Configuration -# Store secrets in Azure Key Vault -# Note: Some secrets may need to be set manually +# Store deployment secrets in a local operator-controlled env file. # set -euo pipefail @@ -14,75 +13,46 @@ log_info "==========================================" log_info "Phase 8: Secrets Configuration" log_info "==========================================" -# Verify Key Vault exists -log_step "8.1 Verifying Azure Key Vault..." +SECRETS_DIR="${STATE_DIR}/secrets" +SECRETS_FILE="${SECRETS_DIR}/${ENVIRONMENT}.env" -KV_EXISTS=$(az keyvault show \ - --name "${KEY_VAULT_NAME}" \ - --resource-group "${AKS_RESOURCE_GROUP}" \ - --query name -o tsv 2>/dev/null || echo "") +log_step "8.1 Preparing local secrets file..." +mkdir -p "${SECRETS_DIR}" -if [ -z "${KV_EXISTS}" ]; then - error_exit "Key Vault ${KEY_VAULT_NAME} not found. Create it first with Terraform." +if [ ! -f "${SECRETS_FILE}" ]; then + touch "${SECRETS_FILE}" + chmod 600 "${SECRETS_FILE}" + log_success "Created ${SECRETS_FILE}" +else + chmod 600 "${SECRETS_FILE}" + log_success "Using existing ${SECRETS_FILE}" fi -log_success "Key Vault found: ${KEY_VAULT_NAME}" - -# Store database URL if provided -if [ -n "${DATABASE_URL:-}" ]; then - log_step "8.2 Storing database URL..." - az keyvault secret set \ - --vault-name "${KEY_VAULT_NAME}" \ - --name "database-url-${ENVIRONMENT}" \ - --value "${DATABASE_URL}" \ - || log_warning "Failed to store database URL" - log_success "Database URL stored" +log_step "8.2 Writing known secrets..." +if [ -n "${DATABASE_URL:-}" ] && ! grep -q '^DATABASE_URL=' "${SECRETS_FILE}" 2>/dev/null; then + printf 'DATABASE_URL=%s\n' "${DATABASE_URL}" >> "${SECRETS_FILE}" + log_success "Stored DATABASE_URL in ${SECRETS_FILE}" fi -# Check for Entra secrets -log_step "8.3 Checking Entra ID secrets..." +if ! grep -q '^JWT_SECRET=' "${SECRETS_FILE}" 2>/dev/null; then + JWT_SECRET=$(openssl rand -base64 32) + printf 'JWT_SECRET=%s\n' "${JWT_SECRET}" >> "${SECRETS_FILE}" + log_success "Generated JWT_SECRET in ${SECRETS_FILE}" +else + log_success "JWT_SECRET already present in ${SECRETS_FILE}" +fi -ENTRA_SECRETS=("entra-tenant-id" "entra-client-id" "entra-client-secret" "entra-credential-manifest-id") -MISSING_SECRETS=() - -for secret in "${ENTRA_SECRETS[@]}"; do - if ! az keyvault secret show \ - --vault-name "${KEY_VAULT_NAME}" \ - --name "${secret}" \ - --query value -o tsv &> /dev/null; then - MISSING_SECRETS+=("${secret}") +log_step "8.3 Checking identity provider placeholders..." +for key in OIDC_ISSUER OIDC_CLIENT_ID OIDC_CLIENT_SECRET VC_ISSUER_DID VC_ISSUER_DOMAIN; do + if grep -q "^${key}=" "${SECRETS_FILE}" 2>/dev/null; then + log_success "${key} found in ${SECRETS_FILE}" + else + log_warning "${key} is not present in ${SECRETS_FILE}" fi done -if [ ${#MISSING_SECRETS[@]} -gt 0 ]; then - log_warning "Missing Entra ID secrets: ${MISSING_SECRETS[*]}" - log_info "Run: ./scripts/deploy/store-entra-secrets.sh" -else - log_success "All Entra ID secrets found" -fi - -# Store JWT secret if not exists -log_step "8.4 Storing JWT secret..." - -if ! az keyvault secret show \ - --vault-name "${KEY_VAULT_NAME}" \ - --name "jwt-secret" \ - --query value -o tsv &> /dev/null; then - - JWT_SECRET=$(openssl rand -base64 32) - az keyvault secret set \ - --vault-name "${KEY_VAULT_NAME}" \ - --name "jwt-secret" \ - --value "${JWT_SECRET}" \ - || error_exit "Failed to store JWT secret" - log_success "JWT secret generated and stored" -else - log_success "JWT secret already exists" -fi - log_info "Secrets configuration complete" -log_info "Note: Additional secrets may need to be set manually" -log_info "See docs/deployment/DEPLOYMENT_GUIDE.md Phase 8 for complete list" +log_info "Keep ${SECRETS_FILE} out of version control and merge it into the runtime env on the target CT when needed." # Save state save_state "phase8" "complete" @@ -90,4 +60,3 @@ save_state "phase8" "complete" log_success "==========================================" log_success "Phase 8: Secrets Configuration - COMPLETE" log_success "==========================================" - diff --git a/scripts/deploy/phase9-infrastructure-services.sh b/scripts/deploy/phase9-infrastructure-services.sh index c8c4c8d..652c214 100755 --- a/scripts/deploy/phase9-infrastructure-services.sh +++ b/scripts/deploy/phase9-infrastructure-services.sh @@ -1,7 +1,7 @@ #!/bin/bash # -# Phase 9: Infrastructure Services Deployment -# Deploy monitoring, logging, and infrastructure services +# Phase 9: Sankofa Edge & Runtime Checks +# Verify the CT and edge services used by the Phoenix-native deployment flow. # set -euo pipefail @@ -10,64 +10,33 @@ SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" source "${SCRIPT_DIR}/config.sh" log_info "==========================================" -log_info "Phase 9: Infrastructure Services Deployment" +log_info "Phase 9: Sankofa Edge & Runtime Checks" log_info "==========================================" -# Verify Kubernetes access -if ! kubectl cluster-info &> /dev/null; then - az aks get-credentials --resource-group "${AKS_RESOURCE_GROUP}" \ - --name "${AKS_NAME}" \ - --overwrite-existing -fi +check_proxmox_access -# 9.1 External Secrets Operator -log_step "9.1 Deploying External Secrets Operator..." +log_step "9.1 Verifying CT availability..." +ssh ${SSH_OPTS} "${PROXMOX_SSH_USER}@${ORDER_PORTAL_PUBLIC_HOST}" \ + "pct status ${ORDER_PORTAL_PUBLIC_VMID}" \ + || error_exit "The Order public CT is not available" -if ! kubectl get crd externalsecrets.external-secrets.io &> /dev/null; then - log_info "Installing External Secrets Operator..." - kubectl apply -f https://external-secrets.io/latest/deploy/ || error_exit "Failed to install" - - log_info "Waiting for operator to be ready..." - kubectl wait --for=condition=ready pod \ - -l app.kubernetes.io/name=external-secrets \ - -n external-secrets-system \ - --timeout=300s || log_warning "Operator not ready yet" -else - log_success "External Secrets Operator already installed" -fi +ssh ${SSH_OPTS} "${PROXMOX_SSH_USER}@${ORDER_HAPROXY_HOST}" \ + "pct status ${ORDER_HAPROXY_VMID}" \ + || error_exit "The Order HAProxy CT is not available" -# 9.2 Monitoring Stack (Prometheus & Grafana) -log_step "9.2 Deploying monitoring stack..." +log_step "9.2 Verifying edge health..." +curl -fsS -H "Host: the-order.sankofa.nexus" "http://${ORDER_HAPROXY_IP}/api/health" >/dev/null \ + && log_success "Order HAProxy health check passed" \ + || log_warning "Order HAProxy health check failed" -if ! command -v helm &> /dev/null; then - log_warning "Helm not found. Install Helm to deploy monitoring stack." - log_info "See: https://helm.sh/docs/intro/install/" -else - if ! helm repo list | grep -q prometheus-community; then - log_info "Adding Prometheus Helm repository..." - helm repo add prometheus-community https://prometheus-community.github.io/helm-charts - helm repo update - fi - - if ! helm list -n monitoring | grep -q prometheus; then - log_info "Installing Prometheus stack..." - kubectl create namespace monitoring --dry-run=client -o yaml | kubectl apply -f - - helm install prometheus prometheus-community/kube-prometheus-stack \ - --namespace monitoring \ - --create-namespace \ - || log_warning "Prometheus installation failed or already exists" - else - log_success "Prometheus already installed" - fi -fi - -log_info "Monitoring stack deployment complete" -log_info "Access Grafana: kubectl port-forward svc/prometheus-grafana 3000:80 -n monitoring" +log_step "9.3 Verifying Phoenix health..." +curl -fsS "${SANKOFA_PHOENIX_URL}/health" >/dev/null \ + && log_success "Phoenix public health check passed" \ + || log_warning "Phoenix public health check failed" # Save state save_state "phase9" "complete" log_success "==========================================" -log_success "Phase 9: Infrastructure Services - COMPLETE" +log_success "Phase 9: Sankofa Edge & Runtime Checks - COMPLETE" log_success "==========================================" - diff --git a/scripts/deploy/prepare-all-credential-seals.sh b/scripts/deploy/prepare-all-credential-seals.sh index b1b5748..070c523 100755 --- a/scripts/deploy/prepare-all-credential-seals.sh +++ b/scripts/deploy/prepare-all-credential-seals.sh @@ -175,7 +175,7 @@ Total Files: PNG: ${VALID_PNG} Recommended Sizes: - - 200x200px: For credential logos (Entra VerifiedID) + - 200x200px: For credential logos - 400x400px: For high-resolution displays - 800x800px: For print/embossing @@ -204,7 +204,7 @@ echo "CDN Base URL: ${CDN_BASE_URL}" echo "" # This is a template - customize based on your CDN provider -# Examples: AWS S3, Azure Blob Storage, Cloudflare, etc. +# Examples: AWS S3, Cloudflare R2, generic HTTPS storage, etc. for png_file in *.png; do if [ -f "${png_file}" ]; then @@ -212,8 +212,6 @@ for png_file in *.png; do # Add your CDN upload command here # Example for AWS S3: # aws s3 cp "${png_file}" "s3://your-bucket/images/${png_file}" --acl public-read - # Example for Azure: - # az storage blob upload --file "${png_file}" --container-name images --name "${png_file}" --account-name your-account fi done @@ -247,7 +245,7 @@ $(for png in "${PNG_DIR}"/*.png; do done) Recommendations: - - Use 200x200px PNG for Entra VerifiedID credentials + - Use 200x200px PNG for credential logos - Ensure all files are under 100KB for optimal performance - Verify images are publicly accessible via HTTPS - Test images in credential wallets before production use @@ -274,4 +272,3 @@ echo "4. Update manifest templates with CDN URLs" echo "5. Test credentials with new seal images" log_success "Seal preparation complete!" - diff --git a/scripts/deploy/sync-portal-public-to-sankofa-phoenix.sh b/scripts/deploy/sync-portal-public-to-sankofa-phoenix.sh new file mode 100755 index 0000000..1bdb70f --- /dev/null +++ b/scripts/deploy/sync-portal-public-to-sankofa-phoenix.sh @@ -0,0 +1,183 @@ +#!/bin/bash +# +# Sync the portal-public Next.js standalone build to the Sankofa / Proxmox runtime. +# Target topology: +# NPMplus -> order-haproxy (VMID 10210) -> order-portal-public (VMID 10090) +# + +set -euo pipefail + +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +source "${SCRIPT_DIR}/config.sh" + +APP_NAME="portal-public" +APP_DIR="${PROJECT_ROOT}/apps/${APP_NAME}" +LOCAL_BUILD_TARBALL="${ARTIFACTS_DIR}/${APP_NAME}-${ENVIRONMENT}.tgz" +LOCAL_STAGE_DIR="${ARTIFACTS_DIR}/${APP_NAME}-${ENVIRONMENT}-stage" +REMOTE_TGZ="/tmp/${APP_NAME}-${ENVIRONMENT}-$$.tgz" +CT_TGZ="/tmp/${APP_NAME}.tgz" + +DRY_RUN=false +SKIP_BUILD=false + +while [[ $# -gt 0 ]]; do + case "$1" in + --dry-run) + DRY_RUN=true + shift + ;; + --skip-build) + SKIP_BUILD=true + shift + ;; + *) + error_exit "Unknown option: $1" + ;; + esac +done + +if [ ! -d "${APP_DIR}" ]; then + error_exit "Portal app not found at ${APP_DIR}" +fi + +check_prerequisites +check_proxmox_access + +if [ "${SKIP_BUILD}" != "true" ]; then + log_step "Building ${APP_NAME} standalone bundle..." + rm -rf "${APP_DIR}/.next" + pnpm --dir "${APP_DIR}" build || error_exit "Failed to build ${APP_NAME}" +else + log_info "Skipping portal build because --skip-build was provided" +fi + +if [ ! -f "${APP_DIR}/.next/standalone/apps/${APP_NAME}/server.js" ]; then + error_exit "Expected standalone output missing for ${APP_NAME}" +fi + +log_step "Preparing deployment artifact..." +rm -rf "${LOCAL_STAGE_DIR}" +mkdir -p "${LOCAL_STAGE_DIR}/standalone/apps/${APP_NAME}/.next" + +cp -R "${APP_DIR}/.next/standalone/." "${LOCAL_STAGE_DIR}/standalone/" +cp -R "${APP_DIR}/.next/static" "${LOCAL_STAGE_DIR}/standalone/apps/${APP_NAME}/.next/static" +cp -R "${APP_DIR}/public" "${LOCAL_STAGE_DIR}/standalone/apps/${APP_NAME}/public" + +tar czf "${LOCAL_BUILD_TARBALL}" -C "${LOCAL_STAGE_DIR}" standalone +log_success "Created deployment artifact ${LOCAL_BUILD_TARBALL}" + +if [ "${DRY_RUN}" = "true" ]; then + log_info "Dry run only. Would push ${LOCAL_BUILD_TARBALL} to CT ${ORDER_PORTAL_PUBLIC_VMID} on ${ORDER_PORTAL_PUBLIC_HOST}" + exit 0 +fi + +log_step "Uploading artifact to Proxmox host..." +scp ${SSH_OPTS} "${LOCAL_BUILD_TARBALL}" "${PROXMOX_SSH_USER}@${ORDER_PORTAL_PUBLIC_HOST}:${REMOTE_TGZ}" + +log_step "Deploying ${APP_NAME} to CT ${ORDER_PORTAL_PUBLIC_VMID}..." +ssh ${SSH_OPTS} "${PROXMOX_SSH_USER}@${ORDER_PORTAL_PUBLIC_HOST}" bash -s -- \ + "${ORDER_PORTAL_PUBLIC_VMID}" \ + "${REMOTE_TGZ}" \ + "${CT_TGZ}" \ + "${ORDER_PORTAL_PUBLIC_APP_DIR}" \ + "${ORDER_PORTAL_PUBLIC_SERVICE}" \ + "${ORDER_PORTAL_PUBLIC_PORT}" \ + "${THE_ORDER_PUBLIC_URL}" \ + "${SANKOFA_PHOENIX_URL}" \ + "${SANKOFA_PORTAL_URL}" \ + "${ORDER_PORTAL_PUBLIC_IP}" <<'REMOTE_EOF' +set -euo pipefail + +VMID="$1" +REMOTE_TGZ="$2" +CT_TGZ="$3" +APP_DIR="$4" +SERVICE_NAME="$5" +PORT="$6" +ORDER_URL="$7" +PHOENIX_URL="$8" +PORTAL_URL="$9" +PORTAL_IP="${10}" + +pct push "${VMID}" "${REMOTE_TGZ}" "${CT_TGZ}" +rm -f "${REMOTE_TGZ}" + +pct exec "${VMID}" -- bash -s -- \ + "${CT_TGZ}" \ + "${APP_DIR}" \ + "${SERVICE_NAME}" \ + "${PORT}" \ + "${ORDER_URL}" \ + "${PHOENIX_URL}" \ + "${PORTAL_URL}" <<'CT_EOF' +set -euo pipefail + +CT_TGZ="$1" +APP_DIR="$2" +SERVICE_NAME="$3" +PORT="$4" +ORDER_URL="$5" +PHOENIX_URL="$6" +PORTAL_URL="$7" + +command -v node >/dev/null || { echo "ERROR: node is required inside the target CT"; exit 1; } + +RELEASES_DIR="${APP_DIR}/releases" +SHARED_DIR="${APP_DIR}/shared" +CURRENT_LINK="${APP_DIR}/current" +RELEASE_DIR="${RELEASES_DIR}/$(date +%Y%m%d-%H%M%S)" + +mkdir -p "${RELEASES_DIR}" "${SHARED_DIR}" "${RELEASE_DIR}" +tar xzf "${CT_TGZ}" -C "${RELEASE_DIR}" +rm -f "${CT_TGZ}" +ln -sfn "${RELEASE_DIR}/standalone" "${CURRENT_LINK}" + +cat > "${SHARED_DIR}/runtime.env" < "/etc/systemd/system/${SERVICE_NAME}.service" </dev/null +systemctl restart "${SERVICE_NAME}" +systemctl is-active --quiet "${SERVICE_NAME}" +curl -fsS "http://127.0.0.1:${PORT}/api/health" >/dev/null + +# Keep the five newest releases. +if [ -d "${RELEASES_DIR}" ]; then + ls -1dt "${RELEASES_DIR}"/* 2>/dev/null | tail -n +6 | xargs -r rm -rf -- +fi +CT_EOF + +echo "Deployed ${SERVICE_NAME} to CT ${VMID}" +echo "Direct health: http://${PORTAL_IP}:${PORT}/api/health" +REMOTE_EOF + +log_success "${APP_NAME} deployed to ${ORDER_PORTAL_PUBLIC_IP}:${ORDER_PORTAL_PUBLIC_PORT}" diff --git a/scripts/tools/convert-svg-to-png.sh b/scripts/tools/convert-svg-to-png.sh index e5443b6..54ff78f 100755 --- a/scripts/tools/convert-svg-to-png.sh +++ b/scripts/tools/convert-svg-to-png.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Convert SVG files to PNG for Entra VerifiedID credential images +# Convert SVG files to PNG for credential images # Supports multiple conversion methods set -euo pipefail @@ -18,7 +18,7 @@ log_error() { echo -e "${RED}[ERROR]${NC} $1"; } usage() { echo "Usage: $0 [output.png] [width] [height]" echo "" - echo "Converts SVG to PNG for Entra VerifiedID credential images" + echo "Converts SVG to PNG for credential images" echo "" echo "Arguments:" echo " input.svg - Input SVG file" @@ -88,4 +88,3 @@ echo " - ImageMagick: sudo apt-get install imagemagick" echo " - Inkscape: sudo apt-get install inkscape" echo " - sharp (Node.js): pnpm add sharp" exit 1 - diff --git a/scripts/tools/prepare-credential-images.sh b/scripts/tools/prepare-credential-images.sh index fa1c13a..a3e06ba 100755 --- a/scripts/tools/prepare-credential-images.sh +++ b/scripts/tools/prepare-credential-images.sh @@ -1,6 +1,6 @@ #!/bin/bash # Prepare all credential images from SVG sources -# Converts SVG files to PNG for Entra VerifiedID compatibility +# Converts SVG files to PNG for broad wallet and credential compatibility set -euo pipefail @@ -39,7 +39,7 @@ if [ ! -d "${SVG_DIR}" ] || [ -z "$(find "${SVG_DIR}" -name "*.svg" 2>/dev/null) # Create example SVG files (placeholder) cat > "${SVG_DIR}/.gitkeep" << 'EOF' # Place your SVG logo files here -# Files will be automatically converted to PNG for Entra VerifiedID +# Files will be automatically converted to PNG for credential clients EOF log_info "After adding SVG files, run this script again to convert them" @@ -84,7 +84,7 @@ cat > "${PNG_DIR}/UPLOAD_INSTRUCTIONS.md" << 'EOF' ## Generated PNG Files -PNG files have been generated from SVG sources for Entra VerifiedID compatibility. +PNG files have been generated from SVG sources for credential client compatibility. ## Upload to CDN/Storage @@ -103,8 +103,8 @@ PNG files have been generated from SVG sources for Entra VerifiedID compatibilit After uploading, update: - Manifest templates in `manifests/entra/` -- Environment variable: `ENTRA_CREDENTIAL_LOGO_URI` -- Or in code: `logoUri` in `EntraVerifiedIDClient` config +- Environment variable: your deployment-specific logo URL +- Or in code: the active credential issuer configuration EOF log_success "Image preparation complete!" @@ -114,4 +114,3 @@ echo "1. Review generated PNG files" echo "2. Upload to CDN/storage" echo "3. Update manifest templates with image URLs" echo "4. See: ${PNG_DIR}/UPLOAD_INSTRUCTIONS.md" - diff --git a/services/README.md b/services/README.md index 883a8fa..ef52abc 100644 --- a/services/README.md +++ b/services/README.md @@ -10,7 +10,7 @@ This directory contains all backend microservices for The Order platform. Each s ## Available Services ### Identity Service (`identity/`) -- **Purpose**: Digital identity, verifiable credentials, Entra VerifiedID +- **Purpose**: Digital identity, verifiable credentials, identity management - **Port**: 4002 - **Features**: eIDAS/DID, credential issuance, identity verification - **Documentation**: [Identity Service README](identity/README.md) @@ -150,4 +150,3 @@ Services communicate via: --- **Last Updated**: 2025-01-27 - diff --git a/services/identity/src/index.ts b/services/identity/src/index.ts index fce357e..4237ce1 100644 --- a/services/identity/src/index.ts +++ b/services/identity/src/index.ts @@ -93,14 +93,6 @@ async function initializeServer(): Promise { // Set error handler server.setErrorHandler(errorHandler); - // Register Microsoft Entra VerifiedID routes - const { registerEntraRoutes } = await import('./entra-integration'); - await registerEntraRoutes(server); - - // Register Entra webhook routes - const { registerEntraWebhookRoutes } = await import('./entra-webhooks'); - await registerEntraWebhookRoutes(server); - // Register batch issuance endpoint const { registerBatchIssuance } = await import('./batch-issuance'); await registerBatchIssuance(server, kmsClient); @@ -444,4 +436,3 @@ const start = async () => { }; start(); - diff --git a/services/identity/src/letters-of-credence-routes.ts b/services/identity/src/letters-of-credence-routes.ts index a6dc8e0..1345731 100644 --- a/services/identity/src/letters-of-credence-routes.ts +++ b/services/identity/src/letters-of-credence-routes.ts @@ -33,7 +33,6 @@ export async function registerLettersOfCredenceRoutes( appointmentDate: { type: 'string', format: 'date-time' }, expirationDate: { type: 'string', format: 'date-time' }, additionalClaims: { type: 'object' }, - useEntraVerifiedID: { type: 'boolean' }, }, }, description: 'Issue Letters of Credence', @@ -50,7 +49,6 @@ export async function registerLettersOfCredenceRoutes( appointmentDate: string; expirationDate?: string; additionalClaims?: Record; - useEntraVerifiedID?: boolean; }; const user = (request as any).user; @@ -75,8 +73,7 @@ export async function registerLettersOfCredenceRoutes( expirationDate: body.expirationDate ? new Date(body.expirationDate) : undefined, additionalClaims: body.additionalClaims, }, - kmsClient, - body.useEntraVerifiedID || false + kmsClient ); return reply.send({ credentialId }); @@ -138,4 +135,3 @@ export async function registerLettersOfCredenceRoutes( } ); } - diff --git a/services/identity/src/letters-of-credence.ts b/services/identity/src/letters-of-credence.ts index a1a717d..7cc9639 100644 --- a/services/identity/src/letters-of-credence.ts +++ b/services/identity/src/letters-of-credence.ts @@ -1,10 +1,9 @@ /** * Letters of Credence issuance automation - * Template-based generation, digital signatures, Entra VerifiedID integration, status tracking + * Template-based generation, digital signatures, and status tracking */ import { createVerifiableCredential } from '@the-order/database'; -import { EntraVerifiedIDClient } from '@the-order/auth'; import { KMSClient } from '@the-order/crypto'; import { getEnv } from '@the-order/shared'; import { getCredentialTemplateByName, renderCredentialFromTemplate } from '@the-order/database'; @@ -34,8 +33,7 @@ export interface LettersOfCredenceStatus { */ export async function issueLettersOfCredence( data: LettersOfCredenceData, - kmsClient: KMSClient, - useEntraVerifiedID = false + kmsClient: KMSClient ): Promise { const env = getEnv(); const issuerDid = env.VC_ISSUER_DID || (env.VC_ISSUER_DOMAIN ? `did:web:${env.VC_ISSUER_DOMAIN}` : undefined); @@ -74,27 +72,6 @@ export async function issueLettersOfCredence( const credentialType = ['VerifiableCredential', 'DiplomaticCredential', 'LettersOfCredence']; - // Use Entra VerifiedID if requested and configured - if (useEntraVerifiedID && env.ENTRA_TENANT_ID && env.ENTRA_CLIENT_ID && env.ENTRA_CLIENT_SECRET) { - const entraClient = new EntraVerifiedIDClient({ - tenantId: env.ENTRA_TENANT_ID, - clientId: env.ENTRA_CLIENT_ID, - clientSecret: env.ENTRA_CLIENT_SECRET, - credentialManifestId: env.ENTRA_CREDENTIAL_MANIFEST_ID, - }); - - // eslint-disable-next-line @typescript-eslint/no-explicit-any - const issuanceRequest = await entraClient.issueCredential({ - claims: credentialSubject as any, - subjectDid: data.recipientDid, - pin: undefined, - callbackUrl: undefined, - } as any); - - // Store the issuance request reference - credentialSubject.entraIssuanceRequest = issuanceRequest; - } - // Sign with KMS const credentialData = { id: credentialId, @@ -167,4 +144,3 @@ export async function revokeLettersOfCredence( revocation_reason: reason, }); } -