Files
go-caatsm/configs/config.prod.toml

157 lines
4.9 KiB
TOML

# Production Configuration for CAATSM
#
# This configuration is optimized for production environments.
# Key differences from dev config:
# - Uses JetStream mode (required for production)
# - Higher resource limits and connection pools
# - JSON logging (for log aggregation)
# - SSL/TLS enabled for secure connections
# - Higher stream replicas for HA (3+)
# - Longer retention periods
#
# IMPORTANT: Stream and Consumer must be created manually in production.
# The application does NOT auto-create them in production mode.
[nats]
url = "nats://nats.prod:4222"
# Production MUST use JetStream mode for message reliability
mode = "jetstream"
client = "caatsm-prod-client"
cluster = "prod-cluster"
stream = "TELEGRAM"
consumer = "telegram-consumer"
[nats.stream_limits]
# Production stream limits - adjust based on your requirements
# max_msgs: Maximum number of messages to keep in the stream (0 = unlimited)
max_msgs = 1000000
# max_bytes: Maximum total size of messages in bytes (1GB = 1073741824)
max_bytes = 1073741824
# max_age: Maximum age of messages before automatic deletion (7 days)
max_age = "168h"
# discard: What to do when limits are reached: "old" (delete oldest) or "new" (reject new)
discard = "old"
# storage: "file" (persistent to disk) - REQUIRED for production
storage = "file"
# replicas: Number of stream replicas for high availability (3+ for production cluster)
replicas = 3
[nats.consumer_rules]
# Consumer delivery rules (only applies when mode = "jetstream")
# max_deliver: Maximum number of delivery attempts before giving up
max_deliver = 3
# ack_wait: Time to wait for ACK before redelivering message
ack_wait = "30s"
# max_ack_pending: Maximum number of unacknowledged messages before pausing delivery
max_ack_pending = 1000
[nats.auth]
# NATS authentication configuration (REQUIRED for production)
# Only one authentication method can be used at a time:
# - token: Simple token authentication (suitable for service-to-service)
# - credentials_file: Path to NATS credentials file (recommended for production)
# - user/password: Username and password authentication
#
# Production examples:
#
# Option 1: Token authentication
# token = "your-nats-token-here"
#
# Option 2: Credentials file (recommended)
# credentials_file = "/etc/caatsm/nats.creds"
#
# Option 3: User/Password
# user = "caatsm-service"
# password = "secure-password-here"
#
# TLS configuration (REQUIRED for production)
# Enable TLS for encrypted communication
tls_enabled = true
# tls_cert_file = "/etc/caatsm/tls/client.crt" # Client certificate file path
# tls_key_file = "/etc/caatsm/tls/client.key" # Client private key file path
# tls_ca_file = "/etc/caatsm/tls/ca.crt" # CA certificate file for server verification
[subscription]
topic = "telegram.serial"
queue_group = "tele-queue"
[publisher]
topic = "telegram.json"
[timeouts]
server = "10s"
reconnect_wait = "5s"
close = "30s"
ack_wait = "30s"
[postgres]
# Production PostgreSQL connection - USE SSL/TLS
# Replace with your production database URL
url = "postgres://user:password@db.prod:5432/aviation?sslmode=require"
# Higher connection pool for production workloads
max_conns = 20
min_conns = 5
[app]
# Production batch processing configuration
# batch_size: Larger batch size for better throughput
batch_size = 100
# batch_timeout: Maximum time to wait when fetching a batch
batch_timeout = "2s"
# monitor_interval: How often to emit consumer statistics and metrics
monitor_interval = "30s"
[log]
# Production logging configuration
# level: Use "info" or "warn" in production (avoid "debug")
level = "info"
# format: "json" for log aggregation systems (ELK, Loki, etc.)
format = "json"
# output: Only stdout in production (let container/logging system handle file rotation)
output = ["stdout"]
# file: Not used in production (logging to stdout)
# file = "logs/caatsm.log"
# File rotation settings (not used when output = ["stdout"])
# max_size = 100 # MB
# max_backups = 7 # Keep 7 rotated files
# max_age = 30 # Keep logs for 30 days
# compress = true # Compress old log files
# Advanced options
disable_caller = false
disable_stacktrace = false
development = false
# Sampling configuration (optional, for high-volume scenarios)
# [log.sampling]
# initial = 100 # Log first 100 messages
# thereafter = 100 # Then log every 100th message
# tick = "1s" # Per second
[telemetry]
# Production telemetry configuration
enabled = true
# Replace with your production OTLP collector endpoint
endpoint = "otel-collector.prod:4318"
# Use TLS in production (set to false)
insecure = false
[monitoring]
# Production monitoring configuration
disabled = false
addr = ":2112"
enable_metrics = true
enable_health = true
read_timeout = "5s"
write_timeout = "5s"
health_timeout = "2s"
[dlq]
# Dead-Letter Queue configuration (REQUIRED for production)
# enabled: Enable DLQ routing for poison messages
enabled = true
# subject: NATS subject where failed messages will be published for manual inspection
subject = "caatsm.dlq"