From 42bba3446981bd3dcd5953642210f180add4dcf7 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Thu, 3 Sep 2026 05:49:14 +0000 Subject: [PATCH] api: --allow-sys para el SDK de AWS/R2 en Deno MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit El cliente S3 lee osRelease; sin --allow-sys el ping a R2 falla con NotCapable aunque endpoint y bucket estén bien. Co-authored-by: alberto.martinez --- .github/workflows/ci.yml | 2 +- Dockerfile.api | 3 ++- api/deno.json | 6 +++--- api/scripts/verify-storage.ts | 2 +- db/provision/verify-connectivity.sh | 2 +- 5 files changed, 8 insertions(+), 7 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8428850..62c870b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -103,7 +103,7 @@ jobs: working-directory: api env: DATABASE_URL_CORE_OWNER: postgresql://panels_core_owner:ci-core-owner@localhost:5432/panels_product - run: deno test --allow-net --allow-read --allow-write --allow-env + run: deno test --allow-net --allow-read --allow-write --allow-env --allow-sys web: runs-on: ubuntu-latest diff --git a/Dockerfile.api b/Dockerfile.api index bb2b92d..9405e81 100644 --- a/Dockerfile.api +++ b/Dockerfile.api @@ -20,4 +20,5 @@ EXPOSE 8000 HEALTHCHECK --interval=30s --timeout=5s --start-period=15s --retries=3 \ CMD ["deno", "eval", "const r=await fetch('http://127.0.0.1:'+(Deno.env.get('PORT')||'8000')+'/v1/health'); if(!r.ok) Deno.exit(1)"] -CMD ["deno", "run", "--allow-net", "--allow-read", "--allow-write", "--allow-env", "main.ts"] +# --allow-sys: AWS SDK v3 (R2) lee osRelease; sin esto Deno lanza NotCapable. +CMD ["deno", "run", "--allow-net", "--allow-read", "--allow-write", "--allow-env", "--allow-sys", "main.ts"] diff --git a/api/deno.json b/api/deno.json index 0dd5e86..c8a08e3 100644 --- a/api/deno.json +++ b/api/deno.json @@ -2,11 +2,11 @@ "name": "panel-obra-api", "exports": "./main.ts", "tasks": { - "dev": "deno run --allow-net --allow-read --allow-write --allow-env --env-file=../.env main.ts", - "start": "deno run --allow-net --allow-read --allow-write --allow-env main.ts", + "dev": "deno run --allow-net --allow-read --allow-write --allow-env --allow-sys --env-file=../.env main.ts", + "start": "deno run --allow-net --allow-read --allow-write --allow-env --allow-sys main.ts", "migrate": "cd .. && ./db/update.sh all", "check": "deno check main.ts", - "test": "deno test --allow-net --allow-read --allow-write --allow-env" + "test": "deno test --allow-net --allow-read --allow-write --allow-env --allow-sys" }, "imports": { "hono": "jsr:@hono/hono@4", diff --git a/api/scripts/verify-storage.ts b/api/scripts/verify-storage.ts index d2c2c81..e2ec966 100644 --- a/api/scripts/verify-storage.ts +++ b/api/scripts/verify-storage.ts @@ -3,7 +3,7 @@ * R2 suele devolver 403 con tokens acotados al bucket. * * Desde api/: - * deno run --allow-net --allow-env --allow-read --allow-write scripts/verify-storage.ts + * deno run --allow-net --allow-env --allow-read --allow-write --allow-sys scripts/verify-storage.ts * * Requiere S3_ENDPOINT, S3_BUCKET, S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY. * Si REQUIRE_S3=1 y no hay credenciales, sale con error (staging/prod). diff --git a/db/provision/verify-connectivity.sh b/db/provision/verify-connectivity.sh index cd74dda..990f9a0 100755 --- a/db/provision/verify-connectivity.sh +++ b/db/provision/verify-connectivity.sh @@ -60,7 +60,7 @@ need REDIS_URL_CORE && check "core redis PING" redis-cli -u "$REDIS_URL_CORE" PI echo "== Contabo (S3) ==" if command -v deno >/dev/null 2>&1; then - if (cd "$ROOT/api" && REQUIRE_S3="${REQUIRE_S3:-}" deno run --allow-net --allow-env --allow-read --allow-write scripts/verify-storage.ts); then + if (cd "$ROOT/api" && REQUIRE_S3="${REQUIRE_S3:-}" deno run --allow-net --allow-env --allow-read --allow-write --allow-sys scripts/verify-storage.ts); then : else fail=1