diff --git a/.gitignore b/.gitignore index 3198076..1e9c4b0 100644 --- a/.gitignore +++ b/.gitignore @@ -1,5 +1,4 @@ # Claude Code -CLAUDE.md .claude/ # Environment files (contain secrets) diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..0b292d9 --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,68 @@ +# Barazo Deploy -- Self-Hosting Templates + + + +MIT | Part of [github.com/barazo-forum](https://github.com/barazo-forum) + +Docker Compose templates and documentation for self-hosting a Barazo forum instance. + +## What This Repo Does + +- Docker Compose files for deploying the full Barazo stack (AppView + frontend + PostgreSQL + Valkey) +- Environment variable templates and configuration examples +- Installation and admin documentation +- Upgrade guides + +## Stack (Deployed) + +| Service | Image | +|---------|-------| +| AppView | barazo-api | +| Frontend | barazo-web | +| Database | PostgreSQL 16 | +| Cache | Valkey | +| Reverse proxy | Caddy (automatic SSL) | + +## Deploy-Specific Standards + +- Documentation-first -- every configuration option documented with defaults and examples +- Secure defaults -- no open ports beyond 80/443, secrets via env vars (never in compose files), non-root containers +- Minimal requirements -- target a single VPS (2 vCPU, 4GB RAM) as minimum spec +- One command deploy -- `docker compose up` must work for a basic setup + +--- + +## Project-Wide Standards + +### About Barazo + +Federated forum built on the [AT Protocol](https://atproto.com/). Portable identity, user-owned data, cross-community reputation. + +- **Organization:** [github.com/barazo-forum](https://github.com/barazo-forum) +- **License:** AGPL-3.0 (backend) / MIT (frontend, lexicons, deploy, website) +- **Contributing:** See [CONTRIBUTING.md](https://github.com/barazo-forum/.github/blob/main/CONTRIBUTING.md) + +### Coding Standards + +1. **Test-Driven Development** -- write tests before implementation (Vitest). +2. **Strict TypeScript** -- `strict: true`, no `any`, no `@ts-ignore`. +3. **Conventional commits** -- `type(scope): description`. +4. **CI must pass** -- lint, typecheck, tests, security scan on every PR. +5. **Input validation** -- Zod schemas on all API inputs and firehose records. +6. **Output sanitization** -- DOMPurify on all user-generated content. +7. **No raw SQL** -- Drizzle ORM with parameterized queries only. +8. **Structured logging** -- Pino logger, never `console.log`. +9. **Accessibility** -- WCAG 2.2 AA, semantic HTML, keyboard navigable. + +### Git Workflow + +All changes go through Pull Requests -- never commit directly to `main`. Branch naming: `type/short-description` (e.g., `feat/add-reactions`, `fix/xss-sanitization`). + +### AT Protocol Context + +- Users own their data (stored on their Personal Data Server) +- The AppView (barazo-api) indexes data from the AT Protocol firehose +- Lexicons (`forum.barazo.*`) define the data schema contract +- Identity is portable via DIDs -- no vendor lock-in +- All record types are validated against lexicon schemas