Alysia identity and permissions service
  • Rust 90.2%
  • Shell 7.1%
  • Dockerfile 2.5%
  • Just 0.2%
Find a file
alysia-ci 636adb6091
All checks were successful
CI / ci-freshness: vendored files match TEMPLATE_REV (push) Successful in 1s
CI / ci: lint, test, build (push) Successful in 2m24s
feat: extract identity service from the monorepo
Standalone repo for services/identity (players, permission
groups/ranks/nodes, snapshots, seed), following the alysia-economy
extraction pattern: minimal workspace root + crate under crates/,
scoped .sqlx/, deny.toml, justfile importing the vendored CI contract
(alysia-ci-templates tpl-v0.1.1), service-model CI with ci-freshness,
single-binary Dockerfile.

alysia-* deps are exact-tag git deps on libs-v0.1.0, lockstep, never
path nor vendor. The permission seed moves with the code that tests
it: infra/permissions/seed.yaml -> seed/permissions.yaml
(byte-identical), include_str! and DEFAULT_SEED_PATH rewritten to the
local path (ALYSIA_PERMISSION_SEED still overrides in containers).

Image pushes only via CI; REGISTRY_TOKEN is absent so the push step
skips loudly, as on the economy pilot.
2026-10-08 17:12:59 +02:00
.github/workflows feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
.sqlx feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
ci feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
crates/identity feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
seed feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
.dockerignore feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
.gitignore feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
Cargo.lock feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
Cargo.toml feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
clippy.toml feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
deny.toml feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
Dockerfile feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
justfile feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
justfile.ci feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
README.md feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
rust-toolchain.toml feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00
rustfmt.toml feat: extract identity service from the monorepo 2026-10-08 17:12:59 +02:00

alysia-identity

The identity service of the Alysia platform, extracted from the Alysia monorepo (services/identity/). Owns the players table plus the permission model (groups, group_parents, group_nodes, player_groups, player_nodes, player_revs) and serves POST /v1/players/{uuid}/login (upsert in Postgres, then a PlayerLoggedIn event acknowledged by JetStream) and GET /v1/players/{uuid}/permissions (the resolved permission snapshot for the requested context), plus the common surface every Alysia service exposes (healthz, ping, gRPC Pinger + grpc.health.v1). The durable JetStream stream (ALYSIA_IDENTITY) is ensured at boot; at boot the service also converges the permission seed (seed/permissions.yaml, GitOps — what the seed declares, the seed wins) before serving.

Layout

Path Role
crates/identity/ The service crate (lib + binary + integration tests)
crates/identity/migrations/ players + permission schema, run at startup
seed/permissions.yaml The GitOps permission-groups skeleton converged at boot (moved from the monorepo's infra/permissions/seed.yaml — see below)
.sqlx/ Committed offline query metadata, scoped to this service's queries
Dockerfile Single-binary image (alysia/identity), built from this repo
justfile.ci + ci/ Vendored from alysia-ci-templates at TEMPLATE_REV (see .github/workflows/ci.yml) — never patch locally

The seed move

In the monorepo the seed lived at infra/permissions/seed.yaml while the code that embeds it (src/seed.rs, the three integration tests) lives in the service: the file now lives in the repo that tests it, at seed/permissions.yaml, byte-identical. Only the paths moved:

  • src/main.rs: DEFAULT_SEED_PATH is seed/permissions.yaml (overridable per environment via ALYSIA_PERMISSION_SEED);
  • src/seed.rs + tests/{login,permissions_sync,seed}.rs: the include_str! points at ../../../seed/permissions.yaml.

The monorepo keeps its own copy until the compose stack reads the seed from here (or via ALYSIA_PERMISSION_SEED); the two files must stay in sync until then.

Dependencies

alysia-* crates come from the versioned libs release train as exact-tag git dependencies — never a branch, never a vendored copy. All alysia-* deps move together on a single tag (lockstep releases, currently libs-v0.1.0):

alysia-service = { git = "https://git.zeto.fr/alysia/alysia-libs.git", tag = "libs-v0.1.0" }

Development

just ci-lint                              # fmt + clippy + machete + deny
just --set test_args "" ci-test           # full suite (needs a container runtime for the integration tests)
just --set image "alysia/identity" ci-build # local image build (tag `local`); CI pushes `alysia/identity:<sha>` on main

The integration tests need Postgres/NATS containers (testcontainers): DOCKER_HOST must point at a Docker-compatible socket.

Image push

ci-build produces alysia/identity:local. CI pushes git.zeto.fr/alysia/alysia-identity/identity:<sha> on main/tags — but only once a REGISTRY_TOKEN secret exists on this repo (it does not yet; the push step skips loudly until then). No image is ever pushed by hand.