hackforla / hackforla/devops

Tables: 1Password Vault Access API

未关闭
#163 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
complexity: large feature: incubator move: incubator role: DevOps Engineer size: 8pt
主要语言
PowerShell
星标
8
派生
10
平均合并
7 小时 30 分钟
30 天内合并 PR
22

描述

### Overview
We need to deploy a Node.js REST API to the HFLA Incubator that automates 1Password vault access management. This API is used by our Google Apps Script onboarding system to automatically grant/revoke vault access when members join or leave projects.
Related Issue: https://github.com/hackforla/tables/issues/137

#### Application Stack

| Component | Details |
|-----------|---------|
| Runtime | Node.js 18 |
| Framework | Express.js |
| Dependencies | 1Password CLI v2 (must be installed in container) |
| Port | 3000 |
| Health Check | `GET /health` |

#### Resource Requirements

| Resource | Value | Notes |
|----------|-------|-------|
| CPU | 256 (0.25 vCPU) | Minimal, mostly I/O bound |
| Memory | 512 MB | Should be sufficient |
| Instances | 1 | No scaling needed |
| Storage | None | Stateless |

#### Secrets Required

We need to store these secrets in AWS Secrets Manager:

| Secret Name | Description |
|-------------|-------------|
| `API_KEY` | API authentication key |
| `OP_BOT_PASSWORD` | 1Password bot account password |
| `OP_BOT_SECRET_KEY` | 1Password secret key (A3-XXXXX format) |

### Questions
1.What's the deployment workflow? Do we need to create a separate repo?
2.Is there a standard pattern for API-only deployments in the Incubator?

### Action Items

### Resources/Instructions

贡献指南

打开贡献指南

调研方向

首先审查相关 issue #137 以及 hackforla/devops repository 中现有的 API-only 部署模式。确定是否需要单独的 repository,以及 Node.js 18、Express.js、1Password CLI、health check 和 AWS Secrets Manager 的要求如何适配部署工作流。当工作流和标准部署模式已完成文档记录或达成一致时,即视为完成。

由索引模型根据 Issue 内容生成。

评估

技术栈
aws, express, node.js
领域
api, cloud, devops
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
停滞
描述清晰度
需要澄清
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。