EN · ÖZGÜN DEPO BELGESİ
Kalıcı yerel ortam
Özgün İngilizce metin. Komutlar ve kanıtlar, belgede belirtilen revizyona ve ortama aittir.
product/local/README.md
Bu sayfada
Persistent local website and Go backend
The existing Astro frontend and Go licensing service run on loopback:
- Astro development website:
http://127.0.0.1:8765/tr/and/en/. - Built website and Go backend:
http://127.0.0.1:8766/tr/and/en/. - Operator console: a private, unlinked, noindex address defined in
product/site/src/lib/admin-path.ts(this README is published in the website reference library, so the address is intentionally not repeated here). The old/tr/admin/and/en/admin/routes return 404. Customer account:/tr/account/or/en/account/. - Backend health:
http://127.0.0.1:8766/healthz.
The Astro development bridge forwards /portal/* to Go with the existing
session, exact-Origin and CSRF checks. All mutations use the Go API. The built
site is served directly by Go; rebuilding it requires restarting the backend
because its public manifest is snapshotted at startup.
Start (PowerShell, from repository root)
npm --prefix product/site run build
docker compose -f product/local/compose.yaml up -d --wait --wait-timeout 180
npm --prefix product/site run dev
The final command stays in the foreground. Open another terminal for lifecycle
commands. Node dependencies must already be installed (npm ci in product/site);
Docker uses the existing golang:1.27.1-bookworm image. Go has no external module
dependencies; network module fetching is disabled.
This remains the default development workflow. The Go bridge reuses upstream
connections and copy buffers. Public HTML/CSS/JS/SVG/XML representations are
gzipped once at server startup when compression makes them smaller. Authenticated
API responses and downloads remain uncached and uncompressed. Slow request bodies
and response writes no longer hold the shared portal state mutex. Go 1.27 follows
container CPU quotas through GODEBUG, without fixing a machine-specific CPU count.
Both configurations default to GOGC=200 to reduce collection CPU overhead at the
cost of a larger heap. Set LOCAL_GOGC=100 in product/local/.env and recreate the
service to restore Go’s standard collection frequency on a memory-constrained
machine. This is a tunable allocation threshold, not a memory limit; measurements
include the memory trade-off.
Optional prebuilt Docker image
The optional configuration builds Astro and both existing Go binaries into one runtime image. The same Go bridge serves the frontend and API; no extra web server or database is introduced. Its runtime contains only the binaries and public site, with a read-only root filesystem. Node, npm, Go and a shell are build-stage tools and are absent from this image. The default configuration above remains available for source-driven development and shell-based diagnostics.
docker compose -f product/local/compose.optimized.yaml up -d --build --wait --wait-timeout 180
Both compose files intentionally use project object-cache-local, service
backend, port 8766 and the same existing object-cache-local_data volume.
Run one configuration at a time. This command recreates the service, retains its
accounts/licenses/orders and invalidates process-local sessions. Rebuild the image
after changing source or documentation. The 8765 Astro development command still
supports live updates and proxies to the same backend.
Return to the default configuration with:
npm --prefix product/site run build
docker compose -f product/local/compose.yaml up -d --force-recreate --wait --wait-timeout 180
The optional build context is explicitly filtered by Dockerfile.dockerignore:
private state, .env, Git data, dependencies and review ZIPs are not baked into
the image. An optional review ZIP still comes from the existing read-only build
mount and LOCAL_REVIEW_MANIFEST. SITE_URL and SITE_INDEXING are optional build
arguments; their local defaults retain noindex and an empty sitemap.
Use the matching compose filename for lifecycle and credential commands. The
/tmp/local-runtime credentials and health subcommands work with either image.
No CPU or memory cap is imposed on normal local use; benchmark CPU caps are only
measurement controls. Measurements and their limits are in
product/local/PERFORMANCE.md.
The old disposable ocp-astro-browser test fixture also uses port 8766. If you
started it separately, stop that specific container before starting this setup.
Local accounts and state
The first start creates two local test identities, admin (local-admin) and
customer (local-customer), with random passwords and recovery codes. No
business licenses or paid orders are seeded. Display the local credentials with:
docker compose -f product/local/compose.yaml exec -T backend /tmp/local-runtime credentials
This is an explicit local bootstrap using the existing test provisioning command; it is not public registration or an email service. Initial credentials are stored only in the private Docker data volume. Passwords used by authentication are salted hashes. After password recovery, the bootstrap credential copy is stale.
The object-cache-local_data volume retains RSA/HMAC keys, licenses.json,
identities.json and test-orders.json. These are private Linux files using the
existing JSON, file locking and atomic-write approach. Container recreation does
not reset them. Partial/corrupt state is not silently replaced. Accounts and
licenses can be verified by signing in again after restarting.
docker compose -f product/local/compose.yaml restart backend
docker compose -f product/local/compose.yaml ps
docker compose -f product/local/compose.yaml down
down retains the named volumes. Do not use down -v unless you intend to erase
the local data. Back up this volume before any intentional reset. Browser
sessions and service traffic observations remain process-local; sign in again
after a restart. Test orders survive when this compose configuration is used.
No test payment creates a license or charges money.
Optional private review ZIP
Copy .env.example to .env in this directory and set LOCAL_REVIEW_MANIFEST to
the exact existing review manifest’s container path, for example
/workspace/build/<review-package>.manifest.json. The launcher checks the ZIP’s
SHA-256 against that manifest before starting Go. This serves the existing private
review artifact only to authorized local accounts. It does not build a release,
download a package, or treat the candidate as production approved.
After changing .env, run docker compose -f product/local/compose.yaml up -d --force-recreate --wait. Without a configured manifest, the portal accurately
reports that no downloadable package is configured.
SEO and domain
No domain is selected. Local builds intentionally emit noindex, follow, an
empty sitemap and no invented canonical origin. See product/site/SEO.md for
the build-time domain settings and reproducible SEO checks. This setup never
publishes a site, installs certificates or changes DNS.