panels-origin/api/scripts/verify-storage.ts
Cursor Agent 42bba34469
api: --allow-sys para el SDK de AWS/R2 en Deno
El cliente S3 lee osRelease; sin --allow-sys el ping a R2 falla
con NotCapable aunque endpoint y bucket estén bien.

Co-authored-by: alberto.martinez <alberto.martinez@mrdev.mx>
2026-09-03 05:49:14 +00:00

36 lines
1.4 KiB
TypeScript

/**
* Sonda S3/R2: ListObjects (o put/get/delete). HeadBucket no se usa:
* R2 suele devolver 403 con tokens acotados al bucket.
*
* Desde api/:
* deno run --allow-net --allow-env --allow-read --allow-write --allow-sys scripts/verify-storage.ts
*
* Requiere S3_ENDPOINT, S3_BUCKET, S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY.
* Si REQUIRE_S3=1 y no hay credenciales, sale con error (staging/prod).
* Si no están, sale 0 y avisa (dev local con disco).
*/
import { config } from "../config.ts";
import { pingStorage, probeStorageReadWrite, s3Configured } from "../storage.ts";
const requireS3 = ["1", "true", "yes"].includes((Deno.env.get("REQUIRE_S3") ?? "").toLowerCase());
if (!s3Configured()) {
const msg =
"S3 no configurado (S3_ENDPOINT / S3_BUCKET / S3_ACCESS_KEY_ID / S3_SECRET_ACCESS_KEY).";
if (requireS3) {
console.error(`FAIL - ${msg} Obligatorio en staging/producción.`);
Deno.exit(1);
}
console.log(`SKIP - ${msg} En este ambiente se usará disco local.`);
Deno.exit(0);
}
console.log(`S3 endpoint=${config.s3Endpoint} bucket=${config.s3Bucket} region=${config.s3Region}`);
const ping = await pingStorage();
if (!ping.ok) {
console.error(`FAIL - ping bucket: ${ping.error ?? "sin detalle"}`);
Deno.exit(1);
}
console.log("OK - ping bucket (ListObjects o sonda write)");
await probeStorageReadWrite();
console.log("OK - put/get/delete de objeto sonda");