Fix fresh-clone dev environment onboarding - #1116
Conversation
Following the README from a clean clone fails before any dev server can boot.
This bundles the minimum fixes to make `docker compose up` + `pnpm setup-db`
+ `pnpm dev` work end-to-end.
docker-compose.yml
- Publish Redis on 127.0.0.1:6379 so host-side `pnpm dev` can reach it.
docker-compose.peerdb.yml
- Temporal: DYNAMIC_CONFIG_FILE_PATH pointed at development-sql.yaml, which
no longer exists in temporalio/auto-setup:1.29; switched to docker.yaml.
- Temporal: healthcheck used 127.0.0.1, but Temporal does not bind loopback
inside the container; switched to the peerdb-temporal hostname.
- MinIO: MINIO_ROOT_PASSWORD inherited the local POSTGRES_PASSWORD default
("health", 6 chars) which MinIO rejects; introduced a dedicated
MINIO_ROOT_PASSWORD env with an >=8-char default and updated the
flow-api S3 secret reference to match.
- Added peerdb-temporal-init: a one-shot container that registers the
MirrorName Temporal search attribute that PeerDB workflows depend on.
flow-api now waits for it (service_completed_successfully) so a fresh
stack works without manual `tctl admin cluster add-search-attributes`.
package.json
- Added `pnpm setup-db` -> `tsx src/db/run-migrate.ts` (the unified Postgres
+ ClickHouse runner that production's entrypoint.sh already uses).
`pnpm migrate` (drizzle-kit) only handles Postgres, so a fresh dev DB
was missing analytics.deduped_sensor / analytics.activity_summary and
the API server's bootstrap timed out waiting for them.
README.md
- Quick Start documents the .env.local block (CLICKHOUSE_URL, REDIS_URL,
POSTGRES_PASSWORD, CLICKHOUSE_PASSWORD), the required Infisical
CREDENTIAL_ENCRYPTION_KEY_BASE64 secret, and points at `pnpm setup-db`.
- Development section: PeerDB CDC stack moved out of "Optional" since
the API server's boot path waits for postgres_fitness.metric_stream;
notes that peerdb-temporal-init handles the search-attribute step.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| 32711125 | Triggered | Generic Password | 80c15d6 | docker-compose.peerdb.yml | View secret |
| 32711125 | Triggered | Generic Password | 80c15d6 | docker-compose.peerdb.yml | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secrets safely. Learn here the best practices.
- Revoke and rotate these secrets.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
📝 WalkthroughWalkthroughThis PR updates the local development environment setup by introducing a new ChangesLocal Development Environment Setup
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Tip 💬 Introducing Slack Agent: The best way for teams to turn conversations into code.Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.
Built for teams:
One agent for your entire SDLC. Right inside Slack. Comment |
|
Storybook previews for This comment updates automatically on each PR push. |
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
docker-compose.peerdb.yml (1)
3-3:⚠️ Potential issue | 🟡 Minor | ⚡ Quick winUpdate PeerDB image to latest stable version.
The coding guideline requires using the latest stable Docker image versions. PeerDB images should be updated from
stable-v0.36.18tostable-v0.36.19(currently the latest stable release). The postgres:18-alpine and temporalio versions (1.29) are already at their latest stable releases.Applies to: Lines 95, 128, 136, 144
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docker-compose.peerdb.yml` at line 3, Update the PeerDB Docker image tag from stable-v0.36.18 to stable-v0.36.19 where referenced in the compose file (replace every occurrence of "stable-v0.36.18" for the PeerDB image lines mentioned), leaving other images (postgres:18-alpine, temporalio 1.29) unchanged; search for the PeerDB image strings (e.g., the service image entries that currently contain "stable-v0.36.18") and change them to "stable-v0.36.19".
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@docker-compose.peerdb.yml`:
- Line 3: Update the PeerDB Docker image tag from stable-v0.36.18 to
stable-v0.36.19 where referenced in the compose file (replace every occurrence
of "stable-v0.36.18" for the PeerDB image lines mentioned), leaving other images
(postgres:18-alpine, temporalio 1.29) unchanged; search for the PeerDB image
strings (e.g., the service image entries that currently contain
"stable-v0.36.18") and change them to "stable-v0.36.19".
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 6c5e8a7d-eb57-4c6b-9181-c3da927669f4
📒 Files selected for processing (4)
README.mddocker-compose.peerdb.ymldocker-compose.ymlpackage.json
|
Review app is ready: This environment runs on a dedicated Hetzner server for PR #1116 and updates on each push. |
Summary
Following the README from a clean clone today fails before any dev server can boot. This bundles the minimum fixes to make
docker compose up+pnpm setup-db+pnpm devwork end-to-end on a fresh machine.I hit each of these in order while bringing up a dev environment for the first time; rather than file separate issues I packaged them into one onboarding-focused PR.
What was broken
docker-compose.ymlpnpm devcouldn't connect to RedisDYNAMIC_CONFIG_FILE_PATHpointed atdevelopment-sql.yaml, whichtemporalio/auto-setup:1.29no longer ships (onlydocker.yaml)peerdb-temporalcrashloop with "no such file or directory"127.0.0.1:7233; Temporal does not bind loopback inside the containerservice_started)MINIO_ROOT_PASSWORDinherited the localPOSTGRES_PASSWORDdefaulthealth(6 chars); MinIO requires ≥8pnpm clickhouse-cdcfailed with "connection refused" topeerdb-minio:9000MirrorNameTemporal search attribute had to be registered manually before any PeerDB workflow could runpnpm clickhouse-cdcfailed withNamespace default has no mapping defined for search attribute MirrorNamepnpm migrate(drizzle-kit only) didn't run the ClickHouse-side migrations on a fresh DBanalytics.deduped_sensor/analytics.activity_summary.env.localconnection strings or the requiredCREDENTIAL_ENCRYPTION_KEY_BASE64Infisical secretChanges
docker-compose.yml127.0.0.1:6379(override viaREDIS_PORT).docker-compose.peerdb.ymlDYNAMIC_CONFIG_FILE_PATHtoconfig/dynamicconfig/docker.yaml.peerdb-temporalservice hostname rather than127.0.0.1.POSTGRES_PASSWORD: introduceMINIO_ROOT_PASSWORDenv var (defaultpeerdblocaldev) and update the flow-api S3 secret reference to match.peerdb-temporal-initone-shot container that registers theMirrorNamesearch attribute idempotently (|| true) once Temporal is healthy.peerdb-flow-apinowdepends_onit viaservice_completed_successfully, so a fresh stack works without manualtctl admin cluster add-search-attributes.package.jsonpnpm setup-db->tsx src/db/run-migrate.ts. This is the unified Postgres + ClickHouse runner that production'sentrypoint.sh migratealready uses;pnpm migrate(drizzle-kit) is left intact for incremental schema work afterpnpm generate.README.md.env.localblock (CLICKHOUSE_URL,REDIS_URL,POSTGRES_PASSWORD,CLICKHOUSE_PASSWORD), the requiredCREDENTIAL_ENCRYPTION_KEY_BASE64Infisical secret, and points atpnpm setup-db.postgres_fitness.metric_stream. Notes thatpeerdb-temporal-inithandles the search-attribute step automatically.Test plan
docker compose -f docker-compose.yml -f docker-compose.peerdb.yml configparses with all changespeerdb-temporalhealthcheck transitions tohealthy(~15s)peerdb-temporal-initruns to completion against a healthy Temporal and exits cleanly (idempotent path returnsSearch attributes already exist.)pnpm clickhouse-cdcsucceeds end-to-end without manualtctlsteppnpm setup-dbapplies 20 Postgres + 8 ClickHouse migrations on a freshly-dropped DBcd packages/server && pnpm devboots and/healthzreturns{"status":"ok"}Notes / out of scope
pnpm migrateto invoke the unified runner — that switch would re-attempt migrations on existing dev DBs that drizzle-kit already tracked by hash, since the two runners use different tracking conventions. Adding a separatesetup-dbscript seemed safer; happy to restructure if maintainers prefer.peerdb-temporal-initcontainer usestctlrather than the newertemporalCLI to match the rest of the file. Easy follow-up to migrate once tctl's EOL date approaches.🤖 Generated with Claude Code
Summary by CodeRabbit
Documentation
New Features
setup-dbscript as the primary database bootstrap method.Chores