Compare commits

..
Author SHA1 Message Date
github-action[bot]andgithub-action[bot] 5b51812991 Create Flex endpoint 2026-09-14 14:38:47 +00:00
3 changed files with 152 additions and 140 deletions
+149
View File
@@ -0,0 +1,149 @@
{
"manifests": {
"fyrst/shopware-cd": {
"manifest": {
"copy-from-package": {
"overlay/": ""
},
"bundles": {
"Fyrst\\ShopwareCd\\FyrstShopwareCdBundle": [
"all"
]
},
"env": {
"SHOPWARE_SHOP_ID": "",
"SHOPWARE_DEPLOY_ENV": "live",
"SHOPWARE_DATA_BASE": "/var/lib/shopware/data"
},
"post-install-output": [
" * <fg=blue>fyrst/shopware-cd</>",
" Flex copied CD files from the package",
" <comment>overlay/</comment> into the shop root: CI,",
" <comment>deploy/</comment> (including CD Compose), <comment>.dockerignore</comment>,",
" and <comment>.env.example</comment>",
" (same idea as <comment>shopware/docker</comment> copying <comment>docker/Dockerfile</comment>).",
"",
" <comment>compose.yaml</comment>, <comment>.gitignore</comment>, and",
" <comment>.shopware-project.yml</comment> (create\u2019s default;",
" <comment>.shopware-project.yaml</comment> is also accepted \u2014 do not rename)",
" are owned by",
" <comment>shopware-cli project create</comment> / the CLI \u2014 not this recipe.",
"",
" Local: <comment>shopware-cli project dev</comment> and the CLI-managed",
" shop-root <comment>compose.yaml</comment>.",
" VPS/CD: files under <comment>deploy/</comment>",
" (<comment>deploy/compose.yaml</comment>, <comment>deploy/compose.prod.yaml</comment>,",
" <comment>deploy/compose.vps.yaml</comment>).",
" Runtime DB/bind-mount copy between VPS hosts:",
" <comment>fyrst-cli shopware sync pull</comment>",
" (see <comment>deploy/sync-runtime.md</comment>).",
" DB snapshots use <comment>shopware-cli project dump</comment>",
" (fyrst-cli never dumps; restore is",
" <comment>fyrst-cli shopware db import</comment>).",
" Live backups (not sync):",
" <comment>fyrst-cli shopware backup create</comment>",
" (see <comment>deploy/backup-runtime.md</comment>).",
" Rollback:",
" <comment>IMAGE_TAG=$(cat .previous-tag) fyrst-cli shopware deploy rollback</comment>.",
" Each VPS needs <comment>fyrst-cli</comment> 0.1.0+",
" (<comment>https://github.com/fyrst-dev/cli</comment>).",
" CI runs <comment>fyrst-cli shopware deploy release</comment>",
" with <comment>IMAGE</comment> / <comment>IMAGE_TAG</comment> /",
" <comment>COMPOSE_DIR</comment>.",
" TLS edge: <comment>deploy/edge/Caddyfile</comment>.",
" Live \u2192 local project dev rsync (no DB):",
" <comment>fyrst-cli shopware sync local</comment>",
" (reads <comment>SHOPWARE_SHOP_ID</comment> from local <comment>.env</comment>;",
" remote root <comment>/var/lib/shopware/data/${SHOPWARE_SHOP_ID}/live</comment>;",
" <comment>--data all</comment> is refused).",
"",
" Flex may append a <comment>###> fyrst/shopware-cd ###</comment>",
" block to shop-root <comment>.env</comment> (empty",
" <comment>SHOPWARE_SHOP_ID</comment>, <comment>SHOPWARE_DEPLOY_ENV=live</comment>,",
" <comment>SHOPWARE_DATA_BASE=/var/lib/shopware/data</comment>).",
" It does not overwrite create\u2019s whole <comment>.env</comment>",
" and does not put secrets in that block. Then run",
" <comment>fyrst-cli shopware env init --shop-id \u2026</comment>",
" (see <comment>deploy/README</comment>).",
" VPS <comment>.env</comment> source of truth (required):",
" <comment>SHOPWARE_SHOP_ID</comment> (same slug on live + staging + laptop),",
" <comment>SHOPWARE_DEPLOY_ENV</comment> (live|staging|playground|dev).",
" Compose derives project name",
" (<comment>${SHOPWARE_SHOP_ID}-${SHOPWARE_DEPLOY_ENV}</comment>)",
" and bind-mount paths from those two plus optional",
" <comment>SHOPWARE_DATA_BASE</comment> (default",
" <comment>/var/lib/shopware/data</comment>) \u2014 three separate interpolations,",
" no nested defaults. It does not require",
" <comment>COMPOSE_PROJECT_NAME</comment> or <comment>SHOPWARE_DATA_ROOT</comment>",
" (optional for scripts/docs; fyrst-cli derives when unset and prefers them",
" when set \u2014 do not assign them empty).",
" WARNING: <comment>shopware-cli project create</comment> writes",
" <comment>COMPOSE_PROJECT_NAME=sw-shop-\u2026</comment> into shop-root",
" <comment>.env</comment> for local <comment>project dev</comment>. That env var",
" overrides Compose <comment>name:</comment>",
" (<comment>${SHOPWARE_SHOP_ID}-${SHOPWARE_DEPLOY_ENV}</comment>).",
" On the VPS, comment out that line",
" (<comment>fyrst-cli shopware env init --vps</comment> or by hand).",
" Flex does not delete it on <comment>composer require</comment>",
" (create owns the local flow).",
" Bootstrap:",
" <comment>DATA=\"${SHOPWARE_DATA_BASE:-/var/lib/shopware/data}/${SHOPWARE_SHOP_ID}/${SHOPWARE_DEPLOY_ENV}\"</comment>",
" then <comment>mkdir -p \"${DATA}\"/{files,media,thumbnail,theme,sitemap}</comment>",
" then <comment>chown -R 82:82 \"${DATA}\"</comment>.",
" Live profiles: uncomment",
" <comment>COMPOSE_PROFILES=redis,worker,scheduler</comment>",
" in <comment>.env</comment> (worker + scheduler; redis if used). Staging leaves",
" this unset unless you need async tasks.",
" <comment>fyrst-cli shopware deploy release</comment> warns on live when it is empty; it does",
" not auto-enable.",
" Same-host tag-and-load / air-gap: <comment>PULL_POLICY=never</comment>",
" and <comment>SKIP_PULL=1</comment> (or",
" <comment>fyrst-cli shopware deploy release --skip-pull</comment>). Default",
" <comment>pull_policy</comment> is <comment>always</comment> for CI/VPS.",
" Several shops or live+staging on one VPS share the host; shop id + env",
" keep stacks isolated.",
"",
" You MUST require <comment>shopware/docker</comment> in the same Composer command as",
" this package. That recipe copies <comment>docker/Dockerfile</comment>, which CI and",
" CD Compose require (default <comment>DOCKERFILE=docker/Dockerfile</comment>). This recipe",
" does not ship a root Dockerfile. A missing <comment>docker/Dockerfile</comment>",
" means <comment>shopware/docker</comment> was skipped.",
"",
" Flex may append SoT keys to <comment>.env</comment>; it does not",
" overwrite create\u2019s whole <comment>.env</comment>. Then run",
" <comment>fyrst-cli shopware env init --shop-id \u2026</comment>",
" (VPS: add <comment>--vps</comment>; see <comment>deploy/README</comment>).",
" If <comment>.env</comment> is missing, that command copies",
" <comment>.env.example</comment> first. Commit the copied files;",
" <comment>vendor/</comment> is gitignored.",
"",
" shopware-cli project create writes <comment>.shopware-project.yml</comment>",
" (that extension is fine). shopware-cli accepts both",
" <comment>.yml</comment> and <comment>.yaml</comment>; do not rename.",
" GitHub Actions picks up",
" <comment>.github/workflows/cd.yaml</comment>. GitLab still defaults to",
" <comment>.gitlab-ci.yml</comment>: set Settings \u2192 CI/CD \u2192 CI/CD configuration file",
" to <comment>.gitlab-ci.yaml</comment> (or copy/symlink that name).",
"",
" Flex registers",
" <comment>Fyrst\\ShopwareCd\\FyrstShopwareCdBundle</comment>",
" in <comment>config/bundles.php</comment>.",
" Post-restore sales-channel URL rewrite uses",
" <comment>APP_URL</comment> in shop-root <comment>.env</comment>;",
" sync calls",
" <comment>bin/console fyrst:sales-channel:rewrite-urls</comment>.",
" Laptop SSH (<comment>SHOPWARE_SSH_*</comment>) belongs in",
" <comment>.env.local</comment>.",
" Shops need <comment>composer update fyrst/shopware-cd</comment>",
" so the command and bundle exist, then",
" <comment>composer recipes:update fyrst/shopware-cd</comment>.",
"",
" Refresh later with <comment>composer recipes:update fyrst/shopware-cd</comment>.",
" See https://github.com/fyrst-dev/shopware-cd"
]
},
"files": [],
"ref": "b31466bc7861d30c0b1f128d8dc226e0efa3b5e6"
}
}
}
+3 -3
View File
@@ -1,7 +1,7 @@
{ {
"aliases": [], "aliases": [],
"recipes": { "recipes": {
"sulu/mcp-bundle": [ "fyrst/shopware-cd": [
"1.0" "1.0"
] ]
}, },
@@ -12,9 +12,9 @@
"_links": { "_links": {
"repository": "github.com/symfony/recipes-contrib", "repository": "github.com/symfony/recipes-contrib",
"origin_template": "{package}:{version}@github.com/symfony/recipes-contrib:main", "origin_template": "{package}:{version}@github.com/symfony/recipes-contrib:main",
"recipe_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2034/{package_dotted}.{version}.json", "recipe_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2049/{package_dotted}.{version}.json",
"recipe_template_relative": "{package_dotted}.{version}.json", "recipe_template_relative": "{package_dotted}.{version}.json",
"archived_recipes_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2034/archived/{package_dotted}/{ref}.json", "archived_recipes_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2049/archived/{package_dotted}/{ref}.json",
"archived_recipes_template_relative": "archived/{package_dotted}/{ref}.json" "archived_recipes_template_relative": "archived/{package_dotted}/{ref}.json"
} }
} }
-137
View File
@@ -1,137 +0,0 @@
{
"manifests": {
"sulu/mcp-bundle": {
"manifest": {
"bundles": {
"Symfony\\AI\\McpBundle\\McpBundle": [
"all"
],
"Sulu\\Mcp\\Infrastructure\\Symfony\\HttpKernel\\SuluMcpBundle": [
"all"
]
},
"copy-from-recipe": {
"config/": "%CONFIG_DIR%/"
},
"env": {
"SULU_MCP_SERVER_URL": "https://localhost"
},
"gitignore": [
"/config/jwt/*.pem"
],
"post-install-output": [
" <bg=blue;fg=white> </>",
" <bg=blue;fg=white> What's next? </>",
" <bg=blue;fg=white> </>",
"",
" * Set <comment>SULU_MCP_SERVER_URL</> in <comment>.env.local</> to the public base URL of this installation.",
"",
" * Generate the RSA key pair league/oauth2-server-bundle signs its tokens with,",
" and point the OAUTH_* variables at it. Without it every MCP request fails with",
" \"Invalid key supplied\":",
"",
" mkdir -p config/jwt",
" openssl genrsa -aes128 -out config/jwt/private.pem 4096",
" openssl rsa -in config/jwt/private.pem -pubout -out config/jwt/public.pem",
"",
" * The password and implicit grants of <comment>league/oauth2-server-bundle</> are deprecated while unset",
" and MCP does not use them. Turn them off in <comment>config/packages/league_oauth2_server.yaml</>:",
"",
" league_oauth2_server:",
" authorization_server:",
" enable_password_grant: false",
" enable_implicit_grant: false",
"",
" * Create the OAuth tables: <comment>bin/console doctrine:migrations:diff</> and <comment>migrate</>",
"",
" * Declare the MCP firewall in <comment>config/packages/security.yaml</> BEFORE the admin firewall.",
" Both patterns match /admin/mcp and Symfony applies the first one in declaration order:",
"",
" firewalls:",
" mcp:",
" pattern: ^/admin/mcp/?$",
" provider: sulu",
" stateless: true",
" entry_point: sulu_mcp.authentication_entry_point",
" oauth2: true",
" admin:",
" pattern: ^/admin(\\/|$)",
" # ...existing admin firewall...",
"",
" The pattern is anchored on purpose: /admin/mcp/authorize and /admin/mcp/consent/...",
" need the logged-in Sulu user and must fall through to the admin firewall.",
" Let the client-authenticated endpoints through in <comment>access_control</>:",
"",
" - { path: ^/\\.well-known/oauth-, roles: PUBLIC_ACCESS }",
" - { path: ^/admin/mcp/register$, roles: PUBLIC_ACCESS }",
" - { path: ^/admin/mcp/token$, roles: PUBLIC_ACCESS }",
" - { path: ^/admin/mcp/?$, roles: IS_AUTHENTICATED_FULLY }",
"",
" * Create an OAuth client for hosted clients such as Claude.ai or ChatGPT:",
" <comment>bin/console sulu:mcp:create-client \"Claude.ai Production\"</>",
" Claude Code registers itself dynamically and needs no client up front.",
"",
" * Full guide: <comment>https://github.com/sulu/SuluMcpBundle/blob/1.0/docs/configuration.md</>"
]
},
"files": {
"config/packages/sulu_mcp.yaml": {
"contents": [
"sulu_mcp:",
" # Publicly reachable base URL of this Sulu installation. Together with mcp_path",
" # it forms the OAuth issuer and the resource identifier of the discovery documents.",
" server_url: '%env(SULU_MCP_SERVER_URL)%'",
"",
"# The two sections below configure other bundles. They live in this file rather than in",
"# their own so they merge with whatever those bundles' recipes wrote, instead of taking",
"# ownership of a file that is not ours.",
"",
"mcp:",
" http:",
" # DNS rebinding protection. Left unset it accepts localhost only, so a server",
" # reachable under its own domain answers every request with \"403 Forbidden:",
" # Invalid Host header.\" after the OAuth handshake already succeeded, and without",
" # writing anything to the log. Hosts carry no port.",
" allowed_hosts:",
" - '%env(key:host:url:SULU_MCP_SERVER_URL)%'",
" - localhost",
" - 127.0.0.1",
" - '[::1]'",
"",
"league_oauth2_server:",
" scopes:",
" # `available` is contributed by SuluMcpBundle. `default` applies to clients that",
" # request no scope of their own, and league leaves it to the project. Scope lists",
" # are appended across files, so the entries the league recipe wrote stay; drop",
" # them there if the project does not use them.",
" default: ['mcp:tools', 'mcp:resources']",
""
],
"executable": false
},
"config/routes/sulu_mcp.yaml": {
"contents": [
"# MCP transport endpoint, registered by symfony/mcp-bundle at the path configured",
"# in config/packages/sulu_mcp.yaml. Declare it only once - a second \"type: mcp\"",
"# entry makes the route loader fail.",
"mcp:",
" resource: .",
" type: mcp",
"",
"# OAuth endpoints behind the admin prefix. The prefix must match mcp_path.",
"sulu_mcp_admin:",
" resource: '@SuluMcpBundle/config/routing_admin.yaml'",
" prefix: /admin",
"",
"# RFC 8414 / RFC 9728 discovery documents, unprefixed in the host's /.well-known/ namespace.",
"sulu_mcp_website:",
" resource: '@SuluMcpBundle/config/routing_website.yaml'",
""
],
"executable": false
}
},
"ref": "82ffa93812d4dff9e9d5673751749ddc8f65b46c"
}
}
}