Skip to content

Hardening: nightly base images in prod Dockerfiles, mis-nested Production mail config, early-return provisioning wait in tests #1412

Description

@iammukeshm

Three small hardening items that came up while reviewing #1406 and #1409. Each is small; they're grouped so they don't get lost.

  1. Production Dockerfiles use nightly base images. src/Host/FSH.Starter.Api/Dockerfile and src/Host/FSH.Starter.DbMigrator/Dockerfile use FROM mcr.microsoft.com/dotnet/nightly/aspnet:10.0-noble-chiseled. That line came in with 59b513e ("bump bases off preview"), when .NET 10 was still in preview. Nightly images are unsupported and can change under you. Move to mcr.microsoft.com/dotnet/aspnet:10.0-noble-chiseled. While at it, note the drift: the csproj ContainerFamily (SDK container publish, used for AWS) is noble, while the Dockerfiles (compose) are noble-chiseled. Pick one on purpose and document why.
  2. appsettings.Production.json mail keys are nested at the wrong level. Host/Port/UserName/Password sit directly under MailOptions instead of MailOptions:Smtp, so they bind to nothing (reported in fix(deploy): working e-mail in the compose stack (Mailpit + MailOptions:Smtp:Security) and no GSS load noise #1409).
  3. The tenant-provisioning wait helper in integration tests returns early. Several tenant-isolation tests treat the word "Completed" anywhere in the provisioning status body as done. That matches as soon as the first step completes, before the tenant admin is seeded, which is a likely flake source. fix(identity): run session cleanup inside each tenant's context #1406 introduced a correct version that checks the overall Status field. Extract it into the shared test infrastructure and use it everywhere.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions