53221c91
feat(cmd): wire server with /healthz /readyz /metrics + authed /api/v1
Phase 9 of lethe-server: thin main.go that loads config, registers every steward asset, and orchestrates Inject -> Init -> Start -> wait -> Stop -> Destroy. Compensates for the Phase 4 finding (steward.Manager does not unwind on Init failure) by tracking destroyer-implementing assets in a parallel slice and invoking Destroy in reverse registration order with a per-call timeout when Init or Start fails. Server.Start now opens its TCP listener synchronously and exposes the bound address via Addr(), so the e2e smoke can bind to 127.0.0.1:0 and discover the kernel-assigned port. Adds an end-to-end smoke test that drives the real steward graph (in-memory SQLite, real loopback listener, forward-auth) through ingest + sessions list/detail for two users with the same composite session key, proving owner isolation reaches all the way through the trust boundary. Deletes internal/platform/health/steward_unwind_test.go: the canary's purpose was to surface the unwind gap so Phase 9 could compensate, which it now does. README updated with consolidated curl quickstart (forward-auth + OIDC bearer variants), trust-chain diagram and the proxy-must-strip-Remote-* spoofing note, response-shape documentation for the API surface, and an operational notes section covering health, metrics, lifecycle and logs.
Eugene Blikh <bigbes@gmail.com> — 2026-04-25 20:46:44 UTC
Commit 53221c915cf9f4ce373ee0192e58898d660bdbfd —
view raw patch
Parent(s):
e108b3e0
| File | Status | + | − |
|---|---|---|---|
README.md
|
M | +96 | -16 |
cmd/lethe/main.go
|
M | +180 | -5 |
cmd/lethe/main_e2e_test.go
|
A | +338 | |
internal/platform/health/steward_unwind_test.go
|
D | -77 | |
internal/server/server.go
|
M | +23 | -6 |