Compare commits

...

2 Commits

Author SHA1 Message Date
agent-company a0620ea391 docs: add Step 10 rapidapi-proxy-secret to secrets-checklist.md
Add checklist item 10 and full detail section for the rapidapi-proxy-secret
Kubernetes secret that must be created in each API namespace (zip-enrichment,
holidays, air-quality) before the Phase 3 server middleware can validate
incoming RapidAPI requests.

Includes:
- Checklist item 10 in the summary list
- Full detail section with kubectl commands for all 3 namespaces
- Note about placeholder ExternalSecret manifests and ESO (issue #61)
- Updated dependency-order diagram

Closes leeworks-agents/api-company#60
2026-05-27 15:04:45 +00:00
AI-Manager 13ce96e07e Merge pull request 'docs: add secrets-checklist items 8 & 9 (gitea-registry + gitea-image-automation-token)' (#59) from feature/secrets-checklist-items-8-9 into main
Build Docs Site / Aggregate OpenAPI Specs (push) Failing after 55s
2026-05-27 10:03:09 +00:00
+40
View File
@@ -18,6 +18,7 @@ Follow this list top-to-bottom; each step unblocks the next.
- [ ] 7. Add api-company Flux source + kustomization to 0xWheatyz/Talos — unblocks all GitOps reconciliation - [ ] 7. Add api-company Flux source + kustomization to 0xWheatyz/Talos — unblocks all GitOps reconciliation
- [ ] 8. `gitea-registry` (zip-enrichment, holidays, air-quality, docs-site) — imagePullSecret for pods pulling from `registry.leeworks.dev` - [ ] 8. `gitea-registry` (zip-enrichment, holidays, air-quality, docs-site) — imagePullSecret for pods pulling from `registry.leeworks.dev`
- [ ] 9. `gitea-image-automation-token` (flux-system) — write-scoped token for Flux ImageUpdateAutomation to push image-tag commits - [ ] 9. `gitea-image-automation-token` (flux-system) — write-scoped token for Flux ImageUpdateAutomation to push image-tag commits
- [ ] 10. `rapidapi-proxy-secret` (zip-enrichment, holidays, air-quality) — RapidAPI Proxy Secret for server-side request validation
--- ---
@@ -155,6 +156,44 @@ Unblocks: Issue #2 (Flux reconciliation of all `flux/` manifests in this repo).
--- ---
---
### 10. `rapidapi-proxy-secret` — RapidAPI Proxy Secret (per API namespace)
| Field | Value |
|-----------|-------|
| Name | `rapidapi-proxy-secret` |
| Namespaces | `zip-enrichment`, `holidays`, `air-quality` |
| Purpose | Every API service validates the `X-RapidAPI-Proxy-Secret` header on every route. Requests without a valid secret return HTTP 403. |
| Source | RapidAPI dashboard → API Settings → Security → **Proxy Secret** (generated after each API listing is created) |
| Unblocks | Phase 3 server middleware; API services will start but reject all traffic without this secret |
```bash
for NS in zip-enrichment holidays air-quality; do
kubectl create secret generic rapidapi-proxy-secret \
--namespace=$NS \
--from-literal=X-RapidAPI-Proxy-Secret=<value-from-rapidapi-dashboard>
done
```
**Source:** RapidAPI dashboard → select your API → Settings → Security → Proxy Secret
> **Note:** Placeholder `ExternalSecret` manifests are committed at
> `flux/zip-enrichment/externalsecret.yaml`, `flux/holidays/externalsecret.yaml`,
> and `flux/air-quality/externalsecret.yaml`. These will auto-sync this secret
> from the configured backend once the External Secrets Operator (ESO) is
> deployed (see issue #61). Until then, create manually using the commands above.
Verify:
```bash
for NS in zip-enrichment holidays air-quality; do
echo -n "$NS: "
kubectl get secret rapidapi-proxy-secret -n $NS -o jsonpath='{.data.X-RapidAPI-Proxy-Secret}' | base64 -d | wc -c
echo " chars"
done
```
## Dependency Order ## Dependency Order
``` ```
@@ -166,6 +205,7 @@ Unblocks: Issue #2 (Flux reconciliation of all `flux/` manifests in this repo).
5 + 6 (GITEA_TOKEN + registry packages) → CI pushes images → API services deploy 5 + 6 (GITEA_TOKEN + registry packages) → CI pushes images → API services deploy
8 (gitea-registry) → pods can pull images from registry.leeworks.dev → services start 8 (gitea-registry) → pods can pull images from registry.leeworks.dev → services start
9 (gitea-image-automation-token) → Flux ImageUpdateAutomation pushes tag-update commits 9 (gitea-image-automation-token) → Flux ImageUpdateAutomation pushes tag-update commits
10 (rapidapi-proxy-secret × 3) → API server middleware validates RapidAPI requests → revenue enabled
``` ```
Once all nine items are complete, the full stack (runner, registry, Prometheus, Grafana, Gatus, docs-site, three API services) reconciles automatically via FluxCD with no further manual steps. Once all nine items are complete, the full stack (runner, registry, Prometheus, Grafana, Gatus, docs-site, three API services) reconciles automatically via FluxCD with no further manual steps.