Major Features: - ✅ Multi-tenant architecture (tenant isolation) - ✅ Employee CRUD with lifecycle management (onboarding/offboarding) - ✅ Department tree structure with email domain management - ✅ Company info management (single-record editing) - ✅ System functions CRUD (permission management) - ✅ Email account management (multi-account per employee) - ✅ Keycloak SSO integration (auth.lab.taipei) - ✅ Redis session storage (10.1.0.254:6379) - Solves Cookie 4KB limitation - Cross-system session sharing - Sliding expiration (8 hours) - Automatic token refresh Technical Stack: Backend: - FastAPI + SQLAlchemy - PostgreSQL 16 (10.1.0.20:5433) - Keycloak Admin API integration - Docker Mailserver integration (SSH) - Alembic migrations Frontend: - Next.js 14 (App Router) - NextAuth 4 with Keycloak Provider - Redis session storage (ioredis) - Tailwind CSS Infrastructure: - Redis 7 (10.1.0.254:6379) - Session + Cache - Keycloak 26.1.0 (auth.lab.taipei) - Docker Mailserver (10.1.0.254) Architecture Highlights: - Session管理由 Keycloak + Redis 統一控制 - 支援多系統 (HR/WebMail/Calendar/Drive/Office) 共享 session - Token 自動刷新,異質服務整合 - 未來可無縫遷移到雲端 Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
45 lines
1.0 KiB
YAML
45 lines
1.0 KiB
YAML
version: '3.8'
|
|
|
|
services:
|
|
postgres:
|
|
image: postgres:16
|
|
container_name: hr-portal-db-test
|
|
environment:
|
|
POSTGRES_DB: hr_portal
|
|
POSTGRES_USER: hr_admin
|
|
POSTGRES_PASSWORD: hr_dev_password_2026
|
|
POSTGRES_INITDB_ARGS: "--encoding=UTF8 --locale=C"
|
|
ports:
|
|
- "5433:5432" # 使用 5433 避免與其他 PostgreSQL 實例衝突
|
|
volumes:
|
|
- hr_portal_db_data:/var/lib/postgresql/data
|
|
networks:
|
|
- hr-portal-network
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U hr_admin -d hr_portal"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
|
|
pgadmin:
|
|
image: dpage/pgadmin4:latest
|
|
container_name: hr-portal-pgadmin
|
|
environment:
|
|
PGADMIN_DEFAULT_EMAIL: admin@lab.taipei
|
|
PGADMIN_DEFAULT_PASSWORD: admin
|
|
PGADMIN_CONFIG_SERVER_MODE: 'False'
|
|
ports:
|
|
- "5050:80"
|
|
depends_on:
|
|
- postgres
|
|
networks:
|
|
- hr-portal-network
|
|
|
|
volumes:
|
|
hr_portal_db_data:
|
|
driver: local
|
|
|
|
networks:
|
|
hr-portal-network:
|
|
driver: bridge
|