chore: harden Docker base images, Production mail config, and the provisioning wait in tests - #1414
Merged
Merged
Conversation
Both production Dockerfiles pulled mcr.microsoft.com/dotnet/nightly/aspnet, left over from when .NET 10 was in preview. Nightly images are unsupported and can change under you. Use the supported aspnet:10.0-noble-chiseled. Also document the deliberate drift: the Dockerfiles (docker compose) stay chiseled, while the csproj ContainerFamily (SDK publish, AWS deploy) is full noble because chiseled strips libgssapi_krb5 and Npgsql's GSSAPI probe then logs a noisy load error. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Host/Port/UserName/Password sat directly under MailOptions, where nothing binds them (SmtpOptions lives at MailOptions:Smtp). Move them into the Smtp section so Production overrides actually apply. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…l Status 27 test classes carried their own copy of WaitForProvisioningAsync, and 26 treated "Completed" anywhere in the status body as done. The body lists each step, so that matched as soon as the first step finished, before the tenant admin was seeded - a likely flake source. Extract the correct wait from #1406 (reads TenantProvisioningStatusDto and trusts only its Status field, throws on Failed with the step and error) into Infrastructure/TenantProvisioningWait and use it everywhere. The timeout message now reports the last status and step. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The keys now bind, so a Port of 0 would override the base 587 and break an operator who only sets the host. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Three hardening items from #1412, one commit each.
1. Docker: off nightly base images (
chore(docker))src/Host/FSH.Starter.Api/Dockerfileandsrc/Host/FSH.Starter.DbMigrator/Dockerfilenow use the supportedmcr.microsoft.com/dotnet/aspnet:10.0-noble-chiseledinstead ofdotnet/nightly/aspnet. No otherdotnet/nightlyrefs in the repo (SDK build stages were already onsdk:10.0;clients/don't use .NET images).ContainerFamily(SDK publish, AWS deploy) stays noble because chiseled stripslibgssapi_krb5and Npgsql's GSSAPI probe then logs a noisy (benign) load error (changed in 23df90c).ContainerFamilyis untouched.2. Config: Production SMTP keys (
fix(config))appsettings.Production.jsonhadHost/Port/UserName/Passworddirectly underMailOptions;SmtpOptionsbinds fromMailOptions:Smtp, so they bound to nothing. Moved them intoSmtp.appsettings.json/appsettings.Development.jsonalready nest underSMTP(binding is case-insensitive); AppHost env vars already useMailOptions__Smtp__*. The DbMigrator has no appsettings files.smtp.ethereal.email:587; now the Production blanks actually apply, so SMTP must be configured for prod (mail fails at send time, not at startup, since there is no startup validation).3. Tests: shared provisioning wait (
test(integration))src/Tests/Integration.Tests/Infrastructure/TenantProvisioningWait.cs, extracted from fix(identity): run session cleanup inside each tenant's context #1406: readsTenantProvisioningStatusDto, trusts only the overallStatus, throws onFailedwith the step and error, and the timeout message includes the last status/step.Statusfield and return the DTO for assertions (PollUntilTerminalAsyncetc.) are unchanged.Verification
dotnet build src/FSH.Starter.slnx: 0 warnings, 0 errors.docker buildof both the API and DbMigrator Dockerfiles from the repo root (the compose build context) succeeded; API image runs as user 1654 on runtime 10.0.12.Closes #1412
🤖 Generated with Claude Code