Major Features: - ✅ Multi-tenant architecture (tenant isolation) - ✅ Employee CRUD with lifecycle management (onboarding/offboarding) - ✅ Department tree structure with email domain management - ✅ Company info management (single-record editing) - ✅ System functions CRUD (permission management) - ✅ Email account management (multi-account per employee) - ✅ Keycloak SSO integration (auth.lab.taipei) - ✅ Redis session storage (10.1.0.254:6379) - Solves Cookie 4KB limitation - Cross-system session sharing - Sliding expiration (8 hours) - Automatic token refresh Technical Stack: Backend: - FastAPI + SQLAlchemy - PostgreSQL 16 (10.1.0.20:5433) - Keycloak Admin API integration - Docker Mailserver integration (SSH) - Alembic migrations Frontend: - Next.js 14 (App Router) - NextAuth 4 with Keycloak Provider - Redis session storage (ioredis) - Tailwind CSS Infrastructure: - Redis 7 (10.1.0.254:6379) - Session + Cache - Keycloak 26.1.0 (auth.lab.taipei) - Docker Mailserver (10.1.0.254) Architecture Highlights: - Session管理由 Keycloak + Redis 統一控制 - 支援多系統 (HR/WebMail/Calendar/Drive/Office) 共享 session - Token 自動刷新,異質服務整合 - 未來可無縫遷移到雲端 Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
42 lines
1.0 KiB
YAML
42 lines
1.0 KiB
YAML
version: '3.8'
|
|
|
|
services:
|
|
# 後端 API (開發模式)
|
|
backend:
|
|
build:
|
|
context: ./backend
|
|
dockerfile: Dockerfile.dev
|
|
container_name: hr-portal-backend-dev
|
|
ports:
|
|
- "10181:10181"
|
|
environment:
|
|
- ENVIRONMENT=development
|
|
- DATABASE_URL=postgresql+psycopg://hr_admin:hr_dev_password_2026@10.1.0.20:5433/hr_portal
|
|
- API_BASE_URL=http://localhost:10181
|
|
- CORS_ORIGINS=http://localhost:10180,http://10.1.0.245:10180
|
|
networks:
|
|
- hr-network
|
|
restart: unless-stopped
|
|
|
|
# 前端應用 (開發模式)
|
|
frontend:
|
|
build:
|
|
context: ./frontend
|
|
dockerfile: Dockerfile.dev
|
|
container_name: hr-portal-frontend-dev
|
|
ports:
|
|
- "10180:10180"
|
|
environment:
|
|
- NEXT_PUBLIC_API_BASE_URL=http://localhost:10181/api/v1
|
|
- NEXTAUTH_URL=http://localhost:10180
|
|
- NEXTAUTH_SECRET=development-secret-key-change-in-production
|
|
networks:
|
|
- hr-network
|
|
depends_on:
|
|
- backend
|
|
restart: unless-stopped
|
|
|
|
networks:
|
|
hr-network:
|
|
driver: bridge
|