Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion .github/workflows/test-solution.yml
Original file line number Diff line number Diff line change
Expand Up @@ -73,9 +73,11 @@ jobs:
dotnet-sonarscanner begin /k:"DFE-Digital_flexforms-api" /o:"dfe-digital" /d:sonar.token="${{ secrets.SONAR_TOKEN }}" /d:sonar.host.url="https://sonarcloud.io" /d:sonar.coverageReportPaths=CoverageReport/SonarQube.xml
dotnet build GovUK.Dfe.FlexForms.Api.sln --no-restore -p:CI=${CI}

- name: Run Tests
- name: Run Tests
env:
CI: true
ASPNETCORE_DATAPROTECTION_PROVIDER: NONE
DOTNET_SYSTEM_GLOBALIZATION_INVARIANT: 1
run: dotnet test GovUK.Dfe.FlexForms.Api.sln --no-build --verbosity normal --collect:"XPlat Code Coverage"

- name: Generate Code Coverage Report
Expand Down
3 changes: 2 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -185,4 +185,5 @@ uploads/

Directory.Build.targets.user
/src/LocalPackages
Comment thread
FrostyApeOne marked this conversation as resolved.
.cursor
.cursor
/encryption-keys
40 changes: 40 additions & 0 deletions Dockerfile.dev
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
# See https://aka.ms/customizecontainer to learn how to customize your debug container and how Visual Studio uses this Dockerfile to build your images for faster debugging.

# This stage is used when running from VS in fast mode (Default for Debug configuration)
FROM mcr.microsoft.com/dotnet/aspnet:10.0 AS base
USER root
WORKDIR /app
EXPOSE 8080
EXPOSE 8081

# This stage is used to build the service project
FROM mcr.microsoft.com/dotnet/sdk:10.0 AS build
ENV CI=true
ARG BUILD_CONFIGURATION=Debug
WORKDIR /src
COPY ["Directory.Build.props", "."]
COPY ["src/GovUK.Dfe.FlexForms.Api/GovUK.Dfe.FlexForms.Api.csproj", "src/GovUK.Dfe.FlexForms.Api/"]
COPY ["src/GovUK.Dfe.FlexForms.Application/GovUK.Dfe.FlexForms.Application.csproj", "src/GovUK.Dfe.FlexForms.Application/"]
COPY ["src/GovUK.Dfe.FlexForms.Domain/GovUK.Dfe.FlexForms.Domain.csproj", "src/GovUK.Dfe.FlexForms.Domain/"]
COPY ["src/GovUK.Dfe.FlexForms.Utils/GovUK.Dfe.FlexForms.Utils.csproj", "src/GovUK.Dfe.FlexForms.Utils/"]
COPY ["src/GovUK.Dfe.FlexForms.Infrastructure/GovUK.Dfe.FlexForms.Infrastructure.csproj", "src/GovUK.Dfe.FlexForms.Infrastructure/"]
RUN dotnet restore "./src/GovUK.Dfe.FlexForms.Api/GovUK.Dfe.FlexForms.Api.csproj"
COPY . .
WORKDIR "/src/src/GovUK.Dfe.FlexForms.Api"
RUN dotnet build "./GovUK.Dfe.FlexForms.Api.csproj" -c $BUILD_CONFIGURATION -p:SkipDockerCompose=true -o /app/build

# This stage is used to publish the service project to be copied to the final stage
FROM build AS publish
ARG BUILD_CONFIGURATION=Debug
RUN dotnet publish "./GovUK.Dfe.FlexForms.Api.csproj" -c $BUILD_CONFIGURATION -p:SkipDockerCompose=true -o /app/publish /p:UseAppHost=false

# This stage is used in production or when running from VS in regular mode (Default when not using the Debug configuration)
FROM base AS final
WORKDIR /app
COPY --from=publish /app/publish .

COPY script/dev-api-docker-entrypoint.sh /app/docker-entrypoint.sh
RUN sed -i 's/\r$//' /app/docker-entrypoint.sh
RUN chmod +x /app/docker-entrypoint.sh

ENTRYPOINT ["/app/docker-entrypoint.sh"]
47 changes: 47 additions & 0 deletions docker-compose.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
name: dfe-flexforms

networks:
dfe-flexforms-network:
name: dfe-flexforms-network
driver: bridge
external: true
dfe-shared-network:
name: dfe-shared-network
external: true

services:
ea_api:
container_name: ea-flexforms-api
cap_add:
- SYS_PTRACE
security_opt:
- seccomp:unconfined
build:
context: ${REPO_PATH}
dockerfile: Dockerfile.dev
ports:
- 5277:8080
- 7089:8081
restart: unless-stopped
environment:
- ConnectionStrings__DefaultConnection=Server=sql,1433;Database=ExternalApplications;User Id=SA;Password=Pa55w0rd!;TrustServerCertificate=True;
- ConnectionStrings__TenantConfigDatabase=Server=sql,1433;Database=TenantConfig;User Id=SA;Password=Pa55w0rd!;TrustServerCertificate=True;
- ConnectionStrings__Redis=redis:6379
- CacheSettings__Redis__ConnectionString=redis:6379
- DataProtection__UseAzure=false
- DataProtection__UseStorageSas=false
- DataProtection__ApplicationName=GovUK.Dfe.FlexForms.Api
- DataProtection__LocalKeysPath=/home/app/.aspnet/DataProtection-Keys
- Tenants__CodeGeneration__ConnectionStrings__Redis=redis:6379
- ASPNETCORE_URLS=https://+:8081;http://+:8080
- ASPNETCORE_ENVIRONMENT=Development
- ASPNETCORE_Kestrel__Certificates__Default__Password=Pa55w0rd
- ASPNETCORE_Kestrel__Certificates__Default__Path=/https/docker_dev_cert.pfx
volumes:
- ${APPDATA}/dev-certs/docker_dev_cert.pfx:/https/docker_dev_cert.pfx:ro
- ${APPDATA}/Microsoft/UserSecrets/f714ca7a-fc08-46ff-b0cc-373d6f04cf4c:/home/app/.microsoft/usersecrets/f714ca7a-fc08-46ff-b0cc-373d6f04cf4c:ro
- ${APPDATA}/mkcert/rootCA.pem:/usr/local/share/ca-certificates/mkcert-rootCA.crt:ro
- ${APPDATA}/DataProtection-Keys:/home/app/.aspnet/DataProtection-Keys:rw
networks:
- dfe-flexforms-network
- dfe-shared-network
7 changes: 7 additions & 0 deletions script/dev-api-docker-entrypoint.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
#!/bin/sh
set -e

#apt-get update
#update-ca-certificates

exec su app -s /bin/sh -c "dotnet GovUK.Dfe.FlexForms.Api.dll"
4 changes: 4 additions & 0 deletions src/GovUK.Dfe.FlexForms.Api.Client/Directory.Build.targets
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
<Project>
<Import Project="Directory.Build.targets.user"
Condition="Exists('Directory.Build.targets.user')" />
</Project>
4 changes: 4 additions & 0 deletions src/GovUK.Dfe.FlexForms.Api/Directory.Build.targets
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
<Project>
<Import Project="Directory.Build.targets.user"
Condition="Exists('Directory.Build.targets.user')" />
</Project>
10 changes: 10 additions & 0 deletions src/GovUK.Dfe.FlexForms.Api/Security/DataProtectionSettings.cs
Original file line number Diff line number Diff line change
Expand Up @@ -42,4 +42,14 @@ public sealed class DataProtectionSettings
/// Always accessed with managed identity / DefaultAzureCredential.
/// </summary>
public string? KeyVaultKeyId { get; set; }

/// <summary>
/// Directory for the local file-system key ring (for example
/// <c>/home/app/.aspnet/DataProtection-Keys</c> in the API container).
/// Bind-mount the host key directory to this path (read-only is fine).
/// When the path is not writable, XML keys are copied to a temp directory
/// and automatic key generation is disabled so the container only decrypts.
/// Leave empty to use the ASP.NET default key location.
/// </summary>
public string LocalKeysPath { get; set; } = "/home/app/.aspnet/DataProtection-Keys";
}
Original file line number Diff line number Diff line change
Expand Up @@ -27,10 +27,18 @@ public static IDataProtectionBuilder AddTenantSettingsDataProtection(

// Local/Development without Azure opt-in: default key ring only (no SetApplicationName)
// so existing locally encrypted TenantSettings remain decryptable.
var builder = services.AddDataProtection();

IDataProtectionBuilder builder;
if (ShouldUseLocalKeyRing(environment, settings))
{
Console.WriteLine("Using local key ring for Data Protection (no Azure).");
Console.WriteLine(settings.LocalKeysPath);
builder = services.AddDataProtection().PersistKeysToFileSystem(new DirectoryInfo(settings.LocalKeysPath)).SetApplicationName(settings.ApplicationName);
return builder;
}
else
{
builder = services.AddDataProtection();
}

var applicationName = string.IsNullOrWhiteSpace(settings.ApplicationName)
? "GovUK.Dfe.FlexForms.Api"
Expand Down
3 changes: 2 additions & 1 deletion src/GovUK.Dfe.FlexForms.Api/appsettings.CodeGeneration.json
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,8 @@
"UseStorageSas": false,
"ApplicationName": "GovUK.Dfe.FlexForms.Api",
"BlobUri": "",
"KeyVaultKeyId": ""
"KeyVaultKeyId": "",
"LocalKeysPath": "/home/app/.aspnet/DataProtection-Keys"
},
"GlobalConfiguration": {
"FileStorage": {
Expand Down
3 changes: 2 additions & 1 deletion src/GovUK.Dfe.FlexForms.Api/appsettings.json
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,8 @@
"UseStorageSas": false,
"ApplicationName": "GovUK.Dfe.FlexForms.Api",
"BlobUri": "",
"KeyVaultKeyId": ""
"KeyVaultKeyId": "",
"LocalKeysPath": "/home/app/.aspnet/DataProtection-Keys"
},
"GlobalConfiguration": {
"ApplicationInsights": {
Expand Down
Loading