mirror of
https://github.com/turnstonelabs/turnstone.git
synced 2026-08-12 23:12:23 -06:00
2b58c127b1
* Add pluggable storage backend (SQLite + PostgreSQL) and deployment packaging Database abstraction: StorageBackend protocol with 21 methods, SQLAlchemy Core schema, SQLite backend (FTS5), PostgreSQL backend (tsvector/ILIKE), Alembic migrations, singleton registry. memory.py reduced to thin facade. Session.py open_db() calls replaced with generic KV methods. [database] config section with env var support. Deployment: Docker Compose production profile with PostgreSQL, Dockerfile with postgres extras and migration entrypoint, Helm chart with bitnami subcharts, Terraform AWS ECS/Fargate module with RDS + ElastiCache + ALB. 39 new storage tests (934 total). mypy strict clean. Docs and diagrams updated. * Address PR #20 review feedback (16 items) - Backends only call create_all() when Alembic migrations are disabled - Helm configmap uses correct TURNSTONE_DB_BACKEND env var; DB URL constructed via env expansion with secret reference instead of ConfigMap - Migration errors fail fast for PostgreSQL (only non-fatal for SQLite) - save_memory/delete_memory wrapped in exception handling like other facade fns - pool_size passed through from config/env to init_storage() in cli + server - Terraform: DB URL moved to Secrets Manager, auth enabled flag set, optional TLS listeners with certificate_arn, Redis transit encryption on - Docker entrypoint no longer suppresses migration output - Diagram fixes: removed StaticPool claim, removed non-existent migration ref - compose.yaml/README: clarified production profile requires DB env vars
43 lines
1.1 KiB
Terraform
43 lines
1.1 KiB
Terraform
# ---------- Random Password ----------
|
|
|
|
resource "random_password" "db" {
|
|
length = 32
|
|
special = false
|
|
}
|
|
|
|
# ---------- DB Subnet Group ----------
|
|
|
|
resource "aws_db_subnet_group" "this" {
|
|
name = "${var.name_prefix}-${var.environment}"
|
|
subnet_ids = var.private_subnet_ids
|
|
tags = local.common_tags
|
|
}
|
|
|
|
# ---------- RDS PostgreSQL ----------
|
|
|
|
resource "aws_db_instance" "this" {
|
|
identifier = "${var.name_prefix}-${var.environment}"
|
|
|
|
engine = "postgres"
|
|
engine_version = "17"
|
|
instance_class = var.db_instance_class
|
|
allocated_storage = 20
|
|
storage_type = "gp3"
|
|
storage_encrypted = true
|
|
deletion_protection = true
|
|
skip_final_snapshot = false
|
|
final_snapshot_identifier = "${var.name_prefix}-${var.environment}-final"
|
|
|
|
db_name = "turnstone"
|
|
username = "turnstone"
|
|
password = random_password.db.result
|
|
|
|
db_subnet_group_name = aws_db_subnet_group.this.name
|
|
vpc_security_group_ids = [aws_security_group.rds.id]
|
|
|
|
backup_retention_period = 7
|
|
multi_az = false
|
|
|
|
tags = local.common_tags
|
|
}
|