- Rust 90.2%
- Shell 7.1%
- Dockerfile 2.5%
- Just 0.2%
Standalone repo for services/identity (players, permission groups/ranks/nodes, snapshots, seed), following the alysia-economy extraction pattern: minimal workspace root + crate under crates/, scoped .sqlx/, deny.toml, justfile importing the vendored CI contract (alysia-ci-templates tpl-v0.1.1), service-model CI with ci-freshness, single-binary Dockerfile. alysia-* deps are exact-tag git deps on libs-v0.1.0, lockstep, never path nor vendor. The permission seed moves with the code that tests it: infra/permissions/seed.yaml -> seed/permissions.yaml (byte-identical), include_str! and DEFAULT_SEED_PATH rewritten to the local path (ALYSIA_PERMISSION_SEED still overrides in containers). Image pushes only via CI; REGISTRY_TOKEN is absent so the push step skips loudly, as on the economy pilot. |
||
|---|---|---|
| .github/workflows | ||
| .sqlx | ||
| ci | ||
| crates/identity | ||
| seed | ||
| .dockerignore | ||
| .gitignore | ||
| Cargo.lock | ||
| Cargo.toml | ||
| clippy.toml | ||
| deny.toml | ||
| Dockerfile | ||
| justfile | ||
| justfile.ci | ||
| README.md | ||
| rust-toolchain.toml | ||
| rustfmt.toml | ||
alysia-identity
The identity service of the Alysia platform, extracted from the
Alysia monorepo (services/identity/).
Owns the players table plus the permission model (groups,
group_parents, group_nodes, player_groups, player_nodes,
player_revs) and serves POST /v1/players/{uuid}/login (upsert in
Postgres, then a PlayerLoggedIn event acknowledged by JetStream) and
GET /v1/players/{uuid}/permissions (the resolved permission snapshot
for the requested context), plus the common surface every Alysia service
exposes (healthz, ping, gRPC Pinger + grpc.health.v1). The durable
JetStream stream (ALYSIA_IDENTITY) is ensured at boot; at boot the
service also converges the permission seed (seed/permissions.yaml,
GitOps — what the seed declares, the seed wins) before serving.
Layout
| Path | Role |
|---|---|
crates/identity/ |
The service crate (lib + binary + integration tests) |
crates/identity/migrations/ |
players + permission schema, run at startup |
seed/permissions.yaml |
The GitOps permission-groups skeleton converged at boot (moved from the monorepo's infra/permissions/seed.yaml — see below) |
.sqlx/ |
Committed offline query metadata, scoped to this service's queries |
Dockerfile |
Single-binary image (alysia/identity), built from this repo |
justfile.ci + ci/ |
Vendored from alysia-ci-templates at TEMPLATE_REV (see .github/workflows/ci.yml) — never patch locally |
The seed move
In the monorepo the seed lived at infra/permissions/seed.yaml while the
code that embeds it (src/seed.rs, the three integration tests) lives in
the service: the file now lives in the repo that tests it, at
seed/permissions.yaml, byte-identical. Only the paths moved:
src/main.rs:DEFAULT_SEED_PATHisseed/permissions.yaml(overridable per environment viaALYSIA_PERMISSION_SEED);src/seed.rs+tests/{login,permissions_sync,seed}.rs: theinclude_str!points at../../../seed/permissions.yaml.
The monorepo keeps its own copy until the compose stack reads the seed
from here (or via ALYSIA_PERMISSION_SEED); the two files must stay in
sync until then.
Dependencies
alysia-* crates come from the versioned libs release train as exact-tag
git dependencies — never a branch, never a vendored copy. All alysia-*
deps move together on a single tag (lockstep releases, currently
libs-v0.1.0):
alysia-service = { git = "https://git.zeto.fr/alysia/alysia-libs.git", tag = "libs-v0.1.0" }
Development
just ci-lint # fmt + clippy + machete + deny
just --set test_args "" ci-test # full suite (needs a container runtime for the integration tests)
just --set image "alysia/identity" ci-build # local image build (tag `local`); CI pushes `alysia/identity:<sha>` on main
The integration tests need Postgres/NATS containers (testcontainers):
DOCKER_HOST must point at a Docker-compatible socket.
Image push
ci-build produces alysia/identity:local. CI pushes
git.zeto.fr/alysia/alysia-identity/identity:<sha> on main/tags — but only
once a REGISTRY_TOKEN secret exists on this repo (it does not yet; the
push step skips loudly until then). No image is ever pushed by hand.