mirror of
https://github.com/simstudioai/sim.git
synced 2026-09-24 15:45:35 +08:00
* feat(secrets): ingest env secrets at container runtime instead of fanning into ECS taskdef The app/socket ECS taskdefs were ~42KB, ~93% of which was the secrets[] array: 268 pointer entries each restating the full ~78-char secret ARN, marching toward the 64KB taskdef limit and growing ~150 bytes per hosted key added. The secret blob itself is only ~18KB/268 keys. Move secret delivery to container boot: new @sim/runtime-secrets loadRuntimeSecrets() reads SIM_ENV_SECRET_ID, fetches the combined secret once, and hydrates process.env (no-clobber, no-op when unset, fail-fast). Bootstrap entrypoints for app + realtime await it before importing the real server (env-flags reads env at module load). The app bootstrap is bun-bundled in the Dockerfile builder stage since it runs outside the Next standalone bundle; realtime keeps full node_modules and runs the TS entry. Backward-compatible: with the current fan-out taskdef the loader no-ops and the app reads the injected env vars unchanged. The matching infra change (empty secrets[] + SIM_ENV_SECRET_ID) ships separately, after this image is live. * fix(runtime-secrets): address review feedback - Move the binary-secret guard outside the retry loop (sendWithRetry) so a missing SecretString throws immediately instead of burning 3 attempts + backoff. - Bound each Secrets Manager request with AbortSignal.timeout(5s) so a stalled response can't hang boot indefinitely. - Drop the redundant @aws-sdk/client-secrets-manager pin from apps/realtime; it resolves transitively via @sim/runtime-secrets. - Add a test for the non-retriable binary-secret path.
14 lines
614 B
TypeScript
14 lines
614 B
TypeScript
/**
|
|
* Container entrypoint. Hydrates `process.env` from the runtime secret before
|
|
* loading the Next.js standalone server, so application modules that read env at
|
|
* import time see the full configuration. See `@sim/runtime-secrets`.
|
|
*/
|
|
import { loadRuntimeSecrets } from '@sim/runtime-secrets'
|
|
|
|
await loadRuntimeSecrets()
|
|
// `server.js` is the Next standalone build artifact, a sibling of this file in
|
|
// the image; it does not exist at type-check time, so the specifier is held in a
|
|
// variable to keep it out of static module resolution.
|
|
const standaloneServer = './server.js'
|
|
await import(standaloneServer)
|