Alysia composition: compose stack, velocity, backend image, smoke
  • Shell 33.8%
  • Just 17.8%
  • Rust 17.2%
  • Dockerfile 15.9%
  • Java 15.3%
Find a file
yubo ac36bd1a1a
All checks were successful
CI / ci-freshness: vendored files match TEMPLATE_REV (push) Successful in 1s
CI / lint: shell scripts (POSIX sh) (push) Successful in 1s
CI / velocity: build the proxy image (push) Successful in 9s
CI / stack: ephemeral subset up + wait healthy (never the dev stack) (push) Successful in 1m11s
ci: weekly self-hosted Renovate via stored token
2026-10-08 17:59:47 +00:00
.github ci: weekly self-hosted Renovate via stored token 2026-10-08 17:59:47 +00:00
ci feat: extract platform composition from the monorepo 2026-10-08 17:53:17 +02:00
infra feat: extract platform composition from the monorepo 2026-10-08 17:53:17 +02:00
proxy/velocity-mover feat: extract platform composition from the monorepo 2026-10-08 17:53:17 +02:00
server feat: extract platform composition from the monorepo 2026-10-08 17:53:17 +02:00
.env.example feat: extract platform composition from the monorepo 2026-10-08 17:53:17 +02:00
.gitignore feat: extract platform composition from the monorepo 2026-10-08 17:53:17 +02:00
justfile feat: extract platform composition from the monorepo 2026-10-08 17:53:17 +02:00
justfile.ci feat: extract platform composition from the monorepo 2026-10-08 17:53:17 +02:00
README.md feat: extract platform composition from the monorepo 2026-10-08 17:53:17 +02:00

alysia-platform

The composition layer of the Alysia platform, extracted from the Alysia monorepo (infra/, proxy/velocity-mover/, server/ pins + scripts, .env.example, the ephemeral-stack half of the smoke job). This repo builds nothing on its own except two images — it wires together what the other repos publish.

Layout

Path Role
infra/docker-compose.yml The whole stack, images by digest via *_IMAGE vars (defaults :local)
infra/postgres/ infra/nats/ State: init.sql, nats.conf (pinned public images in compose)
infra/prometheus/ infra/loki/ infra/alloy/ infra/grafana/ Observability configs (pinned public images in compose)
infra/pumpkin/ Backend image: Dockerfile, Dockerfile.upstream, pumpkin.toml.in, slp-healthcheck.rs, ops.json
infra/velocity/ Proxy image: Dockerfile (jar pinned by sha256), entrypoint.sh, velocity.toml.in
infra/permissions/README.md Pointer: the seed lives in alysia-identity
infra/gateway/README.md Pointer: the policy lives in alysia-gateway, the PKI is generated
proxy/velocity-mover/ The mover plugin sources (Java, built inside the velocity image)
server/pins.toml Canonical Pumpkin pin (rev + version + flags)
server/build.sh Native host build of the pinned Pumpkin (just pumpkin-build)
server/entrypoint.sh Backend container entrypoint (renders pumpkin.toml, stages plugin + seed)
server/world-seed/maplab/ Staged maplab seed snapshot (see below)
.env.example Every variable, incl. *_IMAGE digests and ephemeral ports
justfile + justfile.ci + ci/ Repo recipes + vendored template contract at TEMPLATE_REV

Who publishes / who consumes

Image Published by Consumed here as
alysia/velocity this repo (just velocity-build, CI pushes velocity:<sha>) VELOCITY_IMAGE
alysia/pumpkin this repo (just image-build, needs the wasm below) PUMPKIN_IMAGE
alysia/identity alysia-identity IDENTITY_IMAGE
alysia/economy alysia-economy ECONOMY_IMAGE
alysia/social alysia-social SOCIAL_IMAGE
alysia/game alysia-game GAME_IMAGE
alysia/gateway alysia-gateway GATEWAY_IMAGE
alysia-core.wasm alysia-plugin (dist/, copied to plugins/dist/ for image-build) build input
map images alysia-maps (per-map images, digest = version) future COPY --from
shared Rust libs alysia-libs (lockstep tags) service repos

Until a service repo publishes, its compose entry resolves to the :local default and a full up of that service is not possible — the subset (just smoke) is the portable check.

PUMPKIN_REV: the canonical pin

server/pins.toml here is the single source of truth both build paths read (server/build.sh, infra/pumpkin/Dockerfile): exact commit, upstream version, cargo flags. Two mirrors trail it via their own vendor-freshness CI jobs — they must never lead:

  • alysia-plugin/pins.toml (the pumpkin-plugin-api rev: the guest WIT must be byte-identical to the pinned host's),
  • alysia-maps/server/pins.toml (the mapbake Pumpkin revs).

Bump the pin here first, then the mirrors.

Deploy order

  1. Publish the images (each repo's CI on main: services, gateway, velocity here, pumpkin here once the wasm handoff exists, maps).
  2. Pin the digests in the machine-local .env (*_IMAGE=...@sha256:… — .env is per machine, gitignored, never leaves it).
  3. just certs generate (dev PKI; staging/prod manage their own PKI outside this recipe).
  4. just compose-up (or compose up pinned to a git tag of this repo).

Lobbies/backends need the gateway healthy, the gateway needs the four services, everything needs postgres + nats — depends_on: service_healthy already encodes it; first boot takes minutes (world generation gates the lobby healthcheck).

Development

cp .env.example .env          # fill real values, stays on this machine
just certs generate           # dev PKI (gitignored)
just smoke                    # ephemeral subset: state + observability, 8/8 healthy
just velocity-build           # local proxy image
just compose-up               # full stack (needs the socle digests in .env)

just smoke never touches the dev stack: isolated project (alysia-platform-ci), ephemeral grafana port, disposable volumes.

Left behind on purpose

  • infra/services/Dockerfile (monorepo multi-binary image): superseded — each service repo owns its single-binary Dockerfile.
  • infra/permissions/seed.yaml → seed/permissions.yaml in alysia-identity (the repo that tests it).
  • infra/gateway/policies.cedar → alysia-gateway (the repo that enforces it).
  • The BotMark login smoke (.github/botmark-compat.patch, BOTMARK_REV, bot run + gateway-audit + stream assertions): stays in the monorepo until every socle image publishes — it needs the full stack. Tracked as the cutover of the deployment to these images, which is a separate workstream (M1 still deploys from the monorepo; nothing here changes that).
  • server/world-seed/maplab/: a 116 KiB staged snapshot so the backend image builds today. The planned handoff is the maps-image digest (COPY --from=…/plaza@sha256:<digest> /maps/plaza/ /opt/alysia/world-seed/maplab/, see alysia-maps README) — switch the Dockerfile when the first map digest is published and drop this directory.
  • server/tools/mapbake*: owned by alysia-maps now (server/tools/ there); the monorepo copies are stale references, not moved here.

CI

.github/workflows/ci.yml (runs on alysia-ci, model: template ci.yml.rust at TEMPLATE_REV=tpl-v0.1.1): freshness → shell lint → velocity build (+ push on main, needs REGISTRY_TOKEN) → ephemeral just smoke. No image is ever pushed by hand; no compose ever runs against staging from CI.