Skip to content

feat(backend): harden config, backups, quality, and database TLS - #171

Merged
heymariam merged 3 commits into
Dorisio:mainfrom
mandyslovestories-sudo:feat/drips-backend-hardening
Oct 1, 2026
Merged

heymariam merged 3 commits into
Dorisio:mainfrom
mandyslovestories-sudo:feat/drips-backend-hardening

Conversation

@mandyslovestories-sudo

Copy link
Copy Markdown
Contributor

Summary

This PR resolves the four assigned Stellar Wave backend issues:

  • Closes Database Connection Encryption (TLS for Database) #152 — encrypt PostgreSQL connections with configurable TLS modes, mounted PEM certificate support, hostname validation, and production/staging fail-fast enforcement.
  • Closes Automated Database Backup Verification #153 — add encrypted multi-target backup restore verification with checksum validation, secondary-target failover, staging/critical-query hooks, restore-time SLOs, append-only history, and a weekly/manual GitHub Actions runner.
  • Closes Environment-Specific Configuration Management #154 — complete environment-specific configuration management, repair the corrupted compatibility shim, centralize legacy runtime/cache settings, document all keys, and validate configuration before startup.
  • Closes Code Quality Metrics Dashboard and Reporting #155 — add code-quality metric collection for SLOC, coverage, duplication, and complexity, publish JSON/Markdown/HTML dashboards and history, detect regressions, and enforce CI quality gates while tracking pre-existing debt separately.

Implementation details

Database TLS (#152)

  • Added DB_SSL_MODE, certificate/key/CA configuration, and server-name support.
  • verify-ca and verify-full require certificate validation in staging and production.
  • Both the application pool and standalone migration pool use the same TLS builder.
  • PEM values can be supplied directly or through mounted file paths.

Backup verification (#153)

  • Existing AES-256-GCM encrypted backups remain the source of truth.
  • Restore now tries all configured targets when a copy is missing or fails integrity checks.
  • BackupVerificationService selects the newest backup, runs restore and critical-data callbacks, measures restore time, and records JSONL history.
  • pnpm verify-backup and .github/workflows/backup-verification.yml provide scheduled/manual verification. The workflow fails on verification errors so repository alerts can notify operators.

Configuration management (#154)

  • Replaced the malformed src/config/env.ts implementation with a compatibility shim over the validated loader.
  • Added the missing HTTP/response/document-storage/cache settings to the schema, templates, and docs.
  • Preserved legacy cache environment aliases while routing reads through validated config.

Quality dashboard (#155)

  • pnpm quality:report creates current.json, dashboard.md, index.html, and historical JSON output.
  • pnpm quality:check runs tests with V8 coverage and enforces coverage/duplication/complexity thresholds.
  • CI uploads the dashboard and reports; existing debt is visible and tracked while new regressions fail the job.

Validation

  • Focused backup tests: 4 passed.
  • Focused configuration + backup suite: 37 passed, 1 pre-existing environment bootstrap failure because the interrupted local dependency install did not create node_modules/.bin/tsx; the failure is ENOENT before application startup, not a test assertion or implementation failure.
  • TypeScript 5.4 targeted diagnostics: no errors in changed config, database, backup, or script files. The repository still has unrelated baseline Prisma/client and application diagnostics because Prisma postinstall could not complete in the sandbox.
  • Package lock updated with the coverage provider; formatting and git diff --check completed successfully.

No production data, backup contents, secrets, or credentials are included in this PR. Maintainers should configure the backup directories/key and database CA through deployment secrets before enabling the scheduled workflow.

@drips-wave

drips-wave Bot commented Sep 30, 2026

Copy link
Copy Markdown

@mandyslovestories-sudo Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@heymariam

Copy link
Copy Markdown
Contributor

@mandyslovestories-sudo well done and thanks for contributing, resolve the conflicts so we can check and merge

@heymariam
heymariam merged commit c6cc8e7 into Dorisio:main Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants