Skip to content

Latest commit

 

History

History
69 lines (55 loc) · 2.91 KB

File metadata and controls

69 lines (55 loc) · 2.91 KB

Nexora platform API

This module is the Spring Boot modular-monolith boundary for Nexora domain APIs. It defaults to the deterministic local profile: it exposes process health, readiness, metrics, OpenAPI and a small /api/v1/platform vertical slice, but does not connect to a database.

Run locally

Use Java 25 (the repository toolchain line) and Maven 3.9+:

Set-Location apps/platform-api
mvn spring-boot:run

The local endpoints are:

  • GET /actuator/health/liveness
  • GET /actuator/health/readiness
  • GET /actuator/metrics
  • GET /v3/api-docs
  • GET /api/v1/platform

The server binds to 127.0.0.1 by default. A reviewed deployment that needs a non-loopback listener must explicitly set NEXORA_BIND_ADDRESS (for example, to its approved private address or 0.0.0.0). That override alone does not establish a deployment, network policy, or production-readiness claim.

X-Trace-Id is returned on every HTTP response. A caller may supply a printable 1–128 character value; all other values are replaced with a new opaque identifier.

Database profile

The database profile is deliberately opt-in. The baseline defines nexora_runtime as NOLOGIN, so JDBC must use a separately managed LOGIN credential that is a member of that non-owner role. Hikari runs SET ROLE nexora_runtime for each connection. Flyway uses a distinct approved migrator LOGIN to read the authoritative migration train. No credential is stored in this repository.

$env:SPRING_PROFILES_ACTIVE = 'database'
$env:NEXORA_RUNTIME_DATABASE_URL = 'jdbc:postgresql://127.0.0.1:5432/postgres'
$env:NEXORA_RUNTIME_DATABASE_USERNAME = '<LOGIN member of nexora_runtime>'
$env:NEXORA_RUNTIME_DATABASE_PASSWORD = '<runtime LOGIN credential>'
$env:NEXORA_MIGRATION_DATABASE_URL = $env:NEXORA_RUNTIME_DATABASE_URL
$env:NEXORA_MIGRATION_DATABASE_USERNAME = '<approved migrator login>'
$env:NEXORA_MIGRATION_DATABASE_PASSWORD = '<migrator credential>'
$env:NEXORA_MIGRATIONS_LOCATION = 'C:/absolute/path/to/ordered-flyway-migrations'
$env:NEXORA_REALTIME_JWT_SECRET = '<at least 32 random characters from secret storage>'
mvn spring-boot:run

NEXORA_MIGRATIONS_LOCATION must contain only ordered VNNN__description.sql migration files. The repository's disposable verification fixture is intentionally outside that runtime scan path; the application keeps Flyway filename validation enabled.

NEXORA_REALTIME_JWT_SECRET signs short-lived private-channel descriptors. It has no repository or runtime fallback and must come from approved secret storage. The default local profile does not load this database-only adapter.

In this profile, readiness includes the database check. The integration test uses a disposable local PostgreSQL container to prove this configuration only; it is not provider or production evidence. The local profile does not claim database availability, migration application, tenant authorization, or production readiness.