Gateway: README with env vars, deploy, security #11
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Context
Gateway service (see #18). The README is what the owner and other agents
use to deploy.
Task
README.mdcovering:docker runexample with-evars, a volume for the SQLite DB,a reverse proxy (Caddy/Traefik) for HTTPS — the registered MusicKit
redirect URI must be https
/login, click Connect, done/api/v1/status,/playlists,/playlists/{id}/tracks,DELETE /api/v1/login,/healthz) with bearer authSERVICE_TOKENand the.p8key are secrets; token stored inowner-only SQLite; callback query strings are never logged
coop/beets-appleplaylists) as the intendedclient
Acceptance criteria
questions.
Done.
README.mdrewritten (commit460219c) and verified against the implementation:GATEWAY_DB_PATH), names + purpose + required flagdocker runexample with-evars, a named volume for the SQLite DB (GATEWAY_DB_PATH), unprivileged container, healthcheck note; reverse-proxy section (Caddy example) making the redirect URI https/login, click Connect Apple Music, sign in, "Linked" page/healthz,/login,/callback,/api/v1/status,/api/v1/playlists,/api/v1/playlists/{id}/tracks,DELETE /api/v1/login— with bearer-auth requirement and the Apple 401/403 -> 502 re-login hintSERVICE_TOKEN+.p8are secrets, owner-only SQLite, query strings never logged (access-log scrubber)coop/beets-appleplaylistsas the intended clientThe README documents the pipeline-built image (
git.sams.wtf/coop/apple-music-gateway:<version>/latest), matchingpipeline.yamland the Dockerfile.