Skip to content

Fix fresh-clone dev environment onboarding - #1116

Merged
spencermcnamara merged 1 commit into
mainfrom
fix/dev-onboarding-compose-and-readme
May 10, 2026
Merged

spencermcnamara merged 1 commit into
mainfrom
fix/dev-onboarding-compose-and-readme

Conversation

@spencermcnamara

@spencermcnamara spencermcnamara commented May 10, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Following the README from a clean clone today fails before any dev server can boot. This bundles the minimum fixes to make docker compose up + pnpm setup-db + pnpm dev work end-to-end on a fresh machine.

I hit each of these in order while bringing up a dev environment for the first time; rather than file separate issues I packaged them into one onboarding-focused PR.

What was broken

Issue Symptom on a fresh clone
1 Redis port wasn't published in docker-compose.yml Host-side pnpm dev couldn't connect to Redis
2 Temporal DYNAMIC_CONFIG_FILE_PATH pointed at development-sql.yaml, which temporalio/auto-setup:1.29 no longer ships (only docker.yaml) peerdb-temporal crashloop with "no such file or directory"
3 Temporal healthcheck used 127.0.0.1:7233; Temporal does not bind loopback inside the container Healthcheck never passed (didn't matter previously since dependents used service_started)
4 MINIO_ROOT_PASSWORD inherited the local POSTGRES_PASSWORD default health (6 chars); MinIO requires ≥8 MinIO crashloop, pnpm clickhouse-cdc failed with "connection refused" to peerdb-minio:9000
5 The MirrorName Temporal search attribute had to be registered manually before any PeerDB workflow could run pnpm clickhouse-cdc failed with Namespace default has no mapping defined for search attribute MirrorName
6 pnpm migrate (drizzle-kit only) didn't run the ClickHouse-side migrations on a fresh DB API server boot timed out waiting for analytics.deduped_sensor / analytics.activity_summary
7 Quick Start didn't mention .env.local connection strings or the required CREDENTIAL_ENCRYPTION_KEY_BASE64 Infisical secret App refused to boot with no clear pointer in the docs

Changes

docker-compose.yml

  • Publish Redis on 127.0.0.1:6379 (override via REDIS_PORT).

docker-compose.peerdb.yml

  • Switch Temporal DYNAMIC_CONFIG_FILE_PATH to config/dynamicconfig/docker.yaml.
  • Fix Temporal healthcheck to use the peerdb-temporal service hostname rather than 127.0.0.1.
  • Decouple MinIO password from POSTGRES_PASSWORD: introduce MINIO_ROOT_PASSWORD env var (default peerdblocaldev) and update the flow-api S3 secret reference to match.
  • New peerdb-temporal-init one-shot container that registers the MirrorName search attribute idempotently (|| true) once Temporal is healthy. peerdb-flow-api now depends_on it via service_completed_successfully, so a fresh stack works without manual tctl admin cluster add-search-attributes.

package.json

  • New pnpm setup-db -> tsx src/db/run-migrate.ts. This is the unified Postgres + ClickHouse runner that production's entrypoint.sh migrate already uses; pnpm migrate (drizzle-kit) is left intact for incremental schema work after pnpm generate.

README.md

  • Quick Start documents the .env.local block (CLICKHOUSE_URL, REDIS_URL, POSTGRES_PASSWORD, CLICKHOUSE_PASSWORD), the required CREDENTIAL_ENCRYPTION_KEY_BASE64 Infisical secret, and points at pnpm setup-db.
  • Development section: removed the "Optional" framing on the PeerDB CDC stack since the API server's boot waits for postgres_fitness.metric_stream. Notes that peerdb-temporal-init handles the search-attribute step automatically.

Test plan

  • docker compose -f docker-compose.yml -f docker-compose.peerdb.yml config parses with all changes
  • After fix: peerdb-temporal healthcheck transitions to healthy (~15s)
  • After fix: peerdb-temporal-init runs to completion against a healthy Temporal and exits cleanly (idempotent path returns Search attributes already exist.)
  • After fix: pnpm clickhouse-cdc succeeds end-to-end without manual tctl step
  • After fix: pnpm setup-db applies 20 Postgres + 8 ClickHouse migrations on a freshly-dropped DB
  • After fix: cd packages/server && pnpm dev boots and /healthz returns {"status":"ok"}
  • Verified on a brand-new clone (I tested incrementally on my working tree; fresh-clone replay would be ideal before merge)

Notes / out of scope

  • I deliberately did not change pnpm migrate to invoke the unified runner — that switch would re-attempt migrations on existing dev DBs that drizzle-kit already tracked by hash, since the two runners use different tracking conventions. Adding a separate setup-db script seemed safer; happy to restructure if maintainers prefer.
  • The peerdb-temporal-init container uses tctl rather than the newer temporal CLI to match the rest of the file. Easy follow-up to migrate once tctl's EOL date approaches.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Documentation

    • Updated Quick Start and Development setup instructions in README with improved clarity on local environment configuration and database initialization steps.
  • New Features

    • Added setup-db script as the primary database bootstrap method.
    • Redis now exposed on host loopback interface.
  • Chores

    • Updated Docker Compose configuration for improved Temporal bootstrapping and MinIO credential management.

Review Change Stack

Following the README from a clean clone fails before any dev server can boot.
This bundles the minimum fixes to make `docker compose up` + `pnpm setup-db`
+ `pnpm dev` work end-to-end.

docker-compose.yml
- Publish Redis on 127.0.0.1:6379 so host-side `pnpm dev` can reach it.

docker-compose.peerdb.yml
- Temporal: DYNAMIC_CONFIG_FILE_PATH pointed at development-sql.yaml, which
  no longer exists in temporalio/auto-setup:1.29; switched to docker.yaml.
- Temporal: healthcheck used 127.0.0.1, but Temporal does not bind loopback
  inside the container; switched to the peerdb-temporal hostname.
- MinIO: MINIO_ROOT_PASSWORD inherited the local POSTGRES_PASSWORD default
  ("health", 6 chars) which MinIO rejects; introduced a dedicated
  MINIO_ROOT_PASSWORD env with an >=8-char default and updated the
  flow-api S3 secret reference to match.
- Added peerdb-temporal-init: a one-shot container that registers the
  MirrorName Temporal search attribute that PeerDB workflows depend on.
  flow-api now waits for it (service_completed_successfully) so a fresh
  stack works without manual `tctl admin cluster add-search-attributes`.

package.json
- Added `pnpm setup-db` -> `tsx src/db/run-migrate.ts` (the unified Postgres
  + ClickHouse runner that production's entrypoint.sh already uses).
  `pnpm migrate` (drizzle-kit) only handles Postgres, so a fresh dev DB
  was missing analytics.deduped_sensor / analytics.activity_summary and
  the API server's bootstrap timed out waiting for them.

README.md
- Quick Start documents the .env.local block (CLICKHOUSE_URL, REDIS_URL,
  POSTGRES_PASSWORD, CLICKHOUSE_PASSWORD), the required Infisical
  CREDENTIAL_ENCRYPTION_KEY_BASE64 secret, and points at `pnpm setup-db`.
- Development section: PeerDB CDC stack moved out of "Optional" since
  the API server's boot path waits for postgres_fitness.metric_stream;
  notes that peerdb-temporal-init handles the search-attribute step.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@gitguardian

gitguardian Bot commented May 10, 2026

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 2 secrets following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secrets in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
32711125 Triggered Generic Password 80c15d6 docker-compose.peerdb.yml View secret
32711125 Triggered Generic Password 80c15d6 docker-compose.peerdb.yml View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@coderabbitai

coderabbitai Bot commented May 10, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

This PR updates the local development environment setup by introducing a new setup-db npm script, refactoring Docker Compose services for Temporal bootstrapping with automatic search attribute registration, isolating MinIO credentials from Postgres password, exposing Redis to the host, and clarifying setup documentation in the README.

Changes

Local Development Environment Setup

Layer / File(s) Summary
Setup Script Definition
package.json
New setup-db script added to run database migrations via src/db/run-migrate.ts with environment wrapper.
Temporal Service Bootstrap
docker-compose.peerdb.yml
Temporal service switched to Docker dynamic config; healthcheck updated to use peerdb-temporal:7233 hostname; new peerdb-temporal-init service registers MirrorName search attribute after Temporal becomes healthy.
Service Credentials and Dependencies
docker-compose.peerdb.yml
MinIO root password isolated to MINIO_ROOT_PASSWORD environment variable; flow-api's ClickHouse S3 secret now derives from MinIO credentials instead of Postgres password; flow-api startup gated on peerdb-temporal-init completion.
Infrastructure Exposure
docker-compose.yml
Redis service exposed on host loopback interface via configurable REDIS_PORT.
Development Documentation
README.md
Quick Start sequence updated to document .env.local creation, CREDENTIAL_ENCRYPTION_KEY_BASE64 setup, idempotent pnpm setup-db bootstrap, and optional sync. Development Docker Compose section reorganized to clarify required stacks and sequencing of pnpm setup-db and pnpm clickhouse-cdc.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

  • Asherlc/dofek#1087: Modifies Temporal bootstrap and healthcheck behavior with idempotent MirrorName search-attribute registration.
  • Asherlc/dofek#1088: Modifies PeerDB Docker Compose stack including peerdb-temporal service and MinIO/flow-api credential wiring.
  • Asherlc/dofek#1081: Modifies MinIO and ClickHouse S3 credential propagation between services.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change: fixing fresh-clone dev environment onboarding. It directly reflects the PR's core objective of addressing seven onboarding failures when setting up from a clean checkout.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/dev-onboarding-compose-and-readme

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

Copy link
Copy Markdown
Contributor

Storybook previews for 63e2a8af are ready:

This comment updates automatically on each PR push.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
docker-compose.peerdb.yml (1)

3-3: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Update PeerDB image to latest stable version.

The coding guideline requires using the latest stable Docker image versions. PeerDB images should be updated from stable-v0.36.18 to stable-v0.36.19 (currently the latest stable release). The postgres:18-alpine and temporalio versions (1.29) are already at their latest stable releases.

Applies to: Lines 95, 128, 136, 144

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docker-compose.peerdb.yml` at line 3, Update the PeerDB Docker image tag from
stable-v0.36.18 to stable-v0.36.19 where referenced in the compose file (replace
every occurrence of "stable-v0.36.18" for the PeerDB image lines mentioned),
leaving other images (postgres:18-alpine, temporalio 1.29) unchanged; search for
the PeerDB image strings (e.g., the service image entries that currently contain
"stable-v0.36.18") and change them to "stable-v0.36.19".
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@docker-compose.peerdb.yml`:
- Line 3: Update the PeerDB Docker image tag from stable-v0.36.18 to
stable-v0.36.19 where referenced in the compose file (replace every occurrence
of "stable-v0.36.18" for the PeerDB image lines mentioned), leaving other images
(postgres:18-alpine, temporalio 1.29) unchanged; search for the PeerDB image
strings (e.g., the service image entries that currently contain
"stable-v0.36.18") and change them to "stable-v0.36.19".

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 6c5e8a7d-eb57-4c6b-9181-c3da927669f4

📥 Commits

Reviewing files that changed from the base of the PR and between 46df264 and 80c15d6.

📒 Files selected for processing (4)
  • README.md
  • docker-compose.peerdb.yml
  • docker-compose.yml
  • package.json

@github-actions

Copy link
Copy Markdown
Contributor

Review app is ready:

This environment runs on a dedicated Hetzner server for PR #1116 and updates on each push.

@spencermcnamara
spencermcnamara merged commit 6abdb09 into main May 10, 2026
61 of 62 checks passed
@spencermcnamara
spencermcnamara deleted the fix/dev-onboarding-compose-and-readme branch May 10, 2026 21:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant