phase-0: foundation, both apps boot end to end

Monorepo (pnpm workspaces) with two deployable apps and three pure packages.

apps/api (Hono on Node): Zod validated env that fails fast and names the problem,
Kysely factories for SQLite and Postgres chosen by DATABASE_URL scheme, portable
migrations covering the whole SPEC section 5 schema, Better Auth with the four
roles and seeded demo accounts, localized error envelope, /healthz and /readyz,
graceful SIGTERM drain. Dialect specific SQL is confined to the two factories.

apps/web (Next.js App Router): locale routed shell in es and en with a language
switcher, sign in screen, and a runtime /api proxy so the browser only ever sees
one origin and cookies stay first party.

packages/i18n ships both catalogs complete; es is generated from COPY.md and a
test re-derives it from the document on every run so it cannot drift.
packages/contracts holds the Zod schemas and the typed client the web app uses.

Verified: 43 vitest tests, 14 Playwright tests on mobile and desktop, typecheck
and lint clean, migrate and seed from a clean database, sign in through the proxy
with CSRF rejection of foreign origins.

Not verified here: docker compose. This user has no access to the docker socket.

RULES.md is absent from docs/, so packages/rules exports only RULES_VERSION and
no tax rule, check digit or deadline was invented. See DECISIONS.md.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Michilis
2026-09-03 21:46:35 +00:00
co-authored by Claude Opus 5
commit ae2ea20b7e
106 changed files with 11541 additions and 0 deletions
+65
View File
@@ -0,0 +1,65 @@
import { serve } from '@hono/node-server';
import { createAuth } from './auth/options';
import { createDb } from './db/index';
import { pendingMigrations } from './db/migrator';
import { createApp } from './http/app';
import type { AppDeps } from './http/context';
import { loadEnv } from './lib/env';
import { createOtpSender } from './modules/notifications/mailer';
const DRAIN_TIMEOUT_MS = 25_000;
const env = loadEnv();
const handle = createDb(env.DATABASE_URL);
const auth = createAuth({
db: handle.db,
dialect: handle.dialect,
env,
sendOtp: createOtpSender(env),
});
const deps: AppDeps = { env, handle, auth };
const { app, startDraining, inFlight } = createApp(deps);
const pending = await pendingMigrations(handle).catch(() => ['<database unreachable>']);
if (pending.length > 0) {
console.warn(`[boot] pending migrations: ${pending.join(', ')}. Run pnpm db:migrate.`);
}
if (env.ROLE === 'worker') {
// The worker shares this image and this bootstrap. It serves only the health
// endpoints; the job poller is wired in with the jobs module.
console.info('[boot] role=worker');
}
const server = serve({ fetch: app.fetch, port: env.PORT, hostname: '0.0.0.0' }, (info) => {
console.info(`[boot] role=${env.ROLE} dialect=${handle.dialect} listening on :${info.port}`);
});
let shuttingDown = false;
async function shutdown(signal: string): Promise<void> {
if (shuttingDown) return;
shuttingDown = true;
console.info(`[shutdown] ${signal}: draining`);
// Fail readiness first so the load balancer stops routing here, then stop accepting.
startDraining();
server.close();
const deadline = Date.now() + DRAIN_TIMEOUT_MS;
while (inFlight() > 0 && Date.now() < deadline) {
await new Promise((resolve) => setTimeout(resolve, 100));
}
if (inFlight() > 0) {
console.warn(`[shutdown] ${inFlight()} requests still in flight after drain timeout`);
if ('closeAllConnections' in server) server.closeAllConnections();
}
await handle.close();
console.info('[shutdown] done');
process.exit(0);
}
process.on('SIGTERM', () => void shutdown('SIGTERM'));
process.on('SIGINT', () => void shutdown('SIGINT'));