master-zapier-plan-draft/packages/zapier-decisions/TODO.md
George Lambert 03f557203a
Some checks are pending
offline / test (push) Waiting to run
Sync docs, add verae-bootstrap, and run the full stack on NS1.
Docs match current modules: public portal is access-web /portal/,
IAM and keep are listed, edge is loopback. Bootstrap clones every
Forgejo repo and installs deps per server type. Fleet starts IAM
and staff-session. NS1 all-in-one uses edge :13000 because :3000
is taken; archive workers stay with keep.
2026-09-11 19:52:54 -04:00

1.1 KiB

Open todos

  • Live api.veraetime.net with MOCK_VERAE=false and admin bind credentials.
  • NATS nkeys/mTLS on a real three-node cluster (accounts file is the lab stand-in).
  • Exclusive JetStream consumer for verae.zapier.jobs.events on verae-jobs-events (JOBS_EVENTS_EXCLUSIVE=1; middleware skips the router).
  • Auth on CS/sales/accounting HTML via verae-staff-session (STAFF_AUTH=1).
  • Staff IAM: named users, roles, permissions (verae-staff-iam :3028).
  • Zapier Platform push of a private app.
  • Move portal static files fully into verae-access-web (/portal/ public door; API proxied to loopback edge).
  • Turn IAM on for the running lab (fleet STAFF_IAM_URL + restart).
  • IAM hardening: JSON sessions, login rate-limit, JSON 401 as well as HTML 302, credit principal = IAM username.
  • Host keep-alive (verae-keep) on NS1 with watch+guard; honors admin pause/stop.
  • Docs synced to IAM, public portal :3021, keep, bootstrap server types.
  • verae-bootstrap clones all module repos and installs deps per server type.