Sign inSign up

ghga/fis

Sponsored OSS

File Ingest Service - A service to liaise between Central File Services and Data Hubs for file inspe

Image
0

100K+

ghga/fis repository overview

⁠File Ingest Service

A service to liaise between Central File Services and Data Hubs for file inspection.

⁠Description

The File Ingest Service provides an endpoint to populate the Encryption Key Store, Internal File Registry and Download Controller with output metadata from the S3 upload script at https://github.com/ghga-de/data-steward-scripts/blob/main/src/s3_upload.py⁠.

⁠Installation

We recommend using the provided Docker container.

A pre-built version is available at docker hub⁠:

docker pull ghga/file-ingest-service:12.1.0

Or you can build the container yourself from the ./Dockerfile⁠:

# Execute in the repo's root dir:
docker build -t ghga/file-ingest-service:12.1.0 .

For production-ready deployment, we recommend using Kubernetes, however, for simple use cases, you could execute the service using docker on a single server:

# The entrypoint is preconfigured:
docker run -p 8080:8080 ghga/file-ingest-service:12.1.0 --help

If you prefer not to use containers, you may install the service from source:

# Execute in the repo's root dir:
pip install .

# To run the service:
fis --help

⁠Configuration

⁠Parameters

The service requires the following configuration parameters:

  • client_exponential_backoff_max (integer): Maximum number of seconds to wait between retries when using exponential backoff retry strategies. The client timeout might need to be adjusted accordingly. Minimum: 0. Default: 60.

  • client_num_retries (integer): Number of times to retry failed API calls. Minimum: 0. Default: 3.

  • client_retry_status_codes (array): List of status codes that should trigger retrying a request. Default: [408, 429, 500, 502, 503, 504].

    • Items (integer): Minimum: 0.
  • client_reraise_from_retry_error (boolean): Specifies if the exception wrapped in the final RetryError is reraised or the RetryError is returned as is. Default: true.

  • per_request_jitter (number): Max amount of jitter (in seconds) to add to each request. Minimum: 0. Default: 0.0.

  • retry_after_applicable_for_num_requests (integer): Amount of requests after which the stored delay from a 429 response is ignored again. Can be useful to adjust if concurrent requests are fired in quick succession. Exclusive minimum: 0. Default: 1.

  • http_request_timeout_seconds (number): Request timeout setting in seconds. Default: 60.0.

  • ekss_api_url (string, format: uri, required): The base URL for the EKSS API. Length must be between 1 and 2083 (inclusive).

    Examples:

    "http://127.0.0.1/ekss"
    
  • file_upload_topic (string, required): Topic containing published FileUpload outbox events.

    Examples:

    "file-uploads"
    
    "file-upload-topic"
    
  • enable_opentelemetry (boolean): If set to true, this will run necessary setup code.If set to false, no setup code is run, which leaves tracing disabled. Default: false.

  • otel_trace_sampling_rate (number): Determines which proportion of spans should be sampled. A value of 1.0 means all and is equivalent to the previous behaviour. Setting this to 0 will result in no spans being sampled, but this does not automatically set enable_opentelemetry to False. Minimum: 0. Maximum: 1. Default: 1.0.

  • log_level (string): The minimum log level to capture. Must be one of: "CRITICAL", "ERROR", "WARNING", "INFO", "DEBUG", or "TRACE". Default: "INFO".

  • service_name (string): Default: "fis".

  • service_instance_id (string, required): A string that uniquely identifies this instance across all instances of this service. A globally unique Kafka client ID will be created by concatenating the service_name and the service_instance_id.

    Examples:

    "germany-bw-instance-001"
    
  • log_format: If set, will replace JSON formatting with the specified string format. If not set, has no effect. In addition to the standard attributes, the following can also be specified: timestamp, service, instance, level, correlation_id, and details. Default: null.

    • Any of

      • string

      • null

    Examples:

    "%(timestamp)s - %(service)s - %(level)s - %(message)s"
    
    "%(asctime)s - Severity: %(levelno)s - %(msg)s"
    
  • log_traceback (boolean): Whether to include exception tracebacks in log messages. Default: true.

  • file_interrogations_topic (string, required): The name of the topic use to publish file interrogation outcome events.

    Examples:

    "file-interrogations"
    
  • interrogation_success_type (string, required): The type used for events informing about successful file validations.

    Examples:

    "interrogation_success"
    
  • interrogation_failure_type (string, required): The type used for events informing about failed file validations.

    Examples:

    "interrogation_failed"
    
  • host (string): IP of the host. Default: "127.0.0.1".

  • port (integer): Port to expose the server on the specified host. Default: 8080.

  • auto_reload (boolean): A development feature. Set to True to automatically reload the server upon code changes. Default: false.

  • workers (integer): Number of workers processes to run. Default: 1.

  • timeout_keep_alive (integer): The time in seconds to keep an idle connection open for subsequent requests before closing it. This value should be higher than the timeout used by any client or reverse proxy to avoid premature connection closures. Default: 90.

    Examples:

    5
    
    90
    
    5400
    
  • api_root_path (string): Root path at which the API is reachable. This is relative to the specified host and port. Default: "".

  • openapi_url (string): Path to get the openapi specification in JSON format. This is relative to the specified host and port. Default: "/openapi.json".

  • docs_url (string): Path to host the swagger documentation. This is relative to the specified host and port. Default: "/docs".

  • cors_allowed_origins: A list of origins that should be permitted to make cross-origin requests. By default, cross-origin requests are not allowed. You can use ['*'] to allow any origin. Default: null.

    • Any of

      • array

        • Items (string)
      • null

    Examples:

    [
        "https://example.org",
        "https://www.example.org"
    ]
    
  • cors_allow_credentials: Indicate that cookies should be supported for cross-origin requests. Defaults to False. Also, cors_allowed_origins cannot be set to ['*'] for credentials to be allowed. The origins must be explicitly specified. Default: null.

    • Any of

      • boolean

      • null

    Examples:

    [
        "https://example.org",
        "https://www.example.org"
    ]
    
  • cors_allowed_methods: A list of HTTP methods that should be allowed for cross-origin requests. Defaults to ['GET']. You can use ['*'] to allow all standard methods. Default: null.

    • Any of

      • array

        • Items (string)
      • null

    Examples:

    [
        "*"
    ]
    
  • cors_allowed_headers: A list of HTTP request headers that should be supported for cross-origin requests. Defaults to []. You can use ['*'] to allow all request headers. The Accept, Accept-Language, Content-Language, Content-Type and some are always allowed for CORS requests. Default: null.

    • Any of

      • array

        • Items (string)
      • null

    Examples:

    []
    
  • cors_exposed_headers: A list of HTTP response headers that should be exposed for cross-origin responses. Defaults to []. Note that you can NOT use ['*'] to expose all response headers. The Cache-Control, Content-Language, Content-Length, Content-Type, Expires, Last-Modified and Pragma headers are always exposed for CORS responses. Default: null.

    • Any of

      • array

        • Items (string)
      • null

    Examples:

    []
    
  • generate_correlation_id (boolean): A flag, which, if False, will result in an error when trying to publish an event without a valid correlation ID set for the context. If True, a new correlation ID will be generated and used in the event header. Default: true.

    Examples:

    true
    
    false
    
  • kafka_servers (array, required): A list of connection strings to connect to Kafka bootstrap servers.

    • Items (string)

    Examples:

    [
        "localhost:9092"
    ]
    
  • kafka_security_protocol (string): Protocol used to communicate with brokers. Valid values are: PLAINTEXT, SSL. Must be one of: "PLAINTEXT" or "SSL". Default: "PLAINTEXT".

  • kafka_ssl_cafile (string): Certificate Authority file path containing certificates used to sign broker certificates. If a CA is not specified, the default system CA will be used if found by OpenSSL. Default: "".

  • kafka_ssl_certfile (string): Optional filename of client certificate, as well as any CA certificates needed to establish the certificate's authenticity. Default: "".

  • kafka_ssl_keyfile (string): Optional filename containing the client private key. Default: "".

  • kafka_ssl_password (string, format: password, write-only): Optional password to be used for the client private key. Default: "".

  • kafka_max_message_size (integer): The largest message size that can be transmitted, in bytes, before compression. Only services that have a need to send/receive larger messages should set this. When used alongside compression, this value can be set to something greater than the broker's message.max.bytes field, which effectively concerns the compressed message size. Exclusive minimum: 0. Default: 1048576.

    Examples:

    1048576
    
    16777216
    
  • kafka_compression_type: The compression type used for messages. Valid values are: None, gzip, snappy, lz4, and zstd. If None, no compression is applied. This setting is only relevant for the producer and has no effect on the consumer. If set to a value, the producer will compress messages before sending them to the Kafka broker. If unsure, zstd provides a good balance between speed and compression ratio. Default: null.

    • Any of

      • string: Must be one of: "gzip", "snappy", "lz4", or "zstd".

      • null

    Examples:

    null
    
    "gzip"
    
    "snappy"
    
    "lz4"
    
    "zstd"
    
  • kafka_max_retries (integer): The maximum number of times to immediately retry consuming an event upon failure. Works independently of the dead letter queue. Minimum: 0. Default: 0.

    Examples:

    0
    
    1
    
    2
    
    3
    
    5
    
  • kafka_enable_dlq (boolean): A flag to toggle the dead letter queue. If set to False, the service will crash upon exhausting retries instead of publishing events to the DLQ. If set to True, the service will publish events to the DLQ topic after exhausting all retries. Default: false.

    Examples:

    true
    
    false
    
  • kafka_dlq_topic (string): The name of the topic used to resolve error-causing events. Default: "dlq".

    Examples:

    "dlq"
    
  • kafka_retry_backoff (integer): The number of seconds to wait before retrying a failed event. The backoff time is doubled for each retry attempt. Minimum: 0. Default: 0.

    Examples:

    0
    
    1
    
    2
    
    3
    
    5
    
  • mongo_dsn (string, format: multi-host-uri, required): MongoDB connection string. Might include credentials. For more information see: https://naiveskill.com/mongodb-connection-string/⁠. Length must be at least 1.

    Examples:

    "mongodb://localhost:27017"
    
  • db_name (string, required): Name of the database located on the MongoDB server.

    Examples:

    "my-database"
    
  • mongo_timeout: Timeout in seconds for API calls to MongoDB. The timeout applies to all steps needed to complete the operation, including server selection, connection checkout, serialization, and server-side execution. When the timeout expires, PyMongo raises a timeout exception. If set to None, the operation will not time out (default MongoDB behavior). Default: null.

    • Any of

      • integer: Exclusive minimum: 0.

      • null

    Examples:

    300
    
    600
    
    null
    
  • db_version_collection (string, required): The name of the collection containing DB version information for this service.

    Examples:

    "ifrsDbVersions"
    
  • migration_wait_sec (integer, required): The number of seconds to wait before checking the DB version again.

    Examples:

    5
    
    30
    
    180
    
  • migration_max_wait_sec: The maximum number of seconds to wait for migrations to complete before raising an error. Default: null.

    • Any of

      • integer

      • null

    Examples:

    null
    
    300
    
    600
    
    3600
    
  • data_hub_auth_keys (object, required): Mapping of storage (data hub) aliases to their public token signature validation keys. Can contain additional properties.

    • Additional properties (string)

    Examples:

    {
        "HD": "{\"crv\": \"P-256\", \"kty\": \"EC\", \"x\": \"...\", \"y\": \"...\"}",
        "TU": "{\"crv\": \"P-256\", \"kty\": \"EC\", \"x\": \"...\", \"y\": \"...\"}"
    }
    
  • dhfs_version_constraint (string, required): A PEP 440 version specifier controlling which DHFS client versions are accepted. Requests where the reported version does not satisfy this specifier will be rejected with a 426 error.

    Examples:

    ">=1.0.0,<2.0.0"
    
    "~=2.0"
    
⁠Usage:

A template YAML for configuring the service can be found at ./example-config.yaml⁠. Please adapt it, rename it to .fis.yaml, and place it in one of the following locations:

  • in the current working directory where you execute the service (on Linux: ./.fis.yaml)
  • in your home directory (on Linux: ~/.fis.yaml)

The config yaml will be automatically parsed by the service.

Important: If you are using containers, the locations refer to paths within the container.

All parameters mentioned in the ./example-config.yaml⁠ could also be set using environment variables or file secrets.

For naming the environment variables, just prefix the parameter name with fis_, e.g. for the host set an environment variable named fis_host (you may use both upper or lower cases, however, it is standard to define all env variables in upper cases).

To use file secrets, please refer to the corresponding section⁠ of the pydantic documentation.

⁠HTTP API

An OpenAPI specification for this service can be found here⁠.

⁠Architecture and Design:

This is a Python-based service following the Triple Hexagonal Architecture pattern. It uses protocol/provider pairs and dependency injection mechanisms provided by the hexkit⁠ library.

⁠Development

For setting up the development environment, we rely on the devcontainer feature⁠ of VS Code in combination with Docker Compose.

To use it, you have to have Docker Compose as well as VS Code with its "Remote - Containers" extension (ms-vscode-remote.remote-containers) installed. Then open this repository in VS Code and run the command Remote-Containers: Reopen in Container from the VS Code "Command Palette".

This will give you a full-fledged, pre-configured development environment including:

  • infrastructural dependencies of the service (databases, etc.)
  • all relevant VS Code extensions pre-installed
  • pre-configured linting and auto-formatting
  • a pre-configured debugger
  • automatic license-header insertion

Moreover, inside the devcontainer, a command dev_install is available for convenience. It installs the service with all development dependencies, and it installs pre-commit.

The installation is performed automatically when you build the devcontainer. However, if you update dependencies in the ./pyproject.toml⁠ or the ./requirements-dev.txt⁠, please run it again.

⁠License

This repository is free to use and modify according to the Apache 2.0 License⁠.

⁠README Generation

This README file is auto-generated, please see readme_generation.md⁠ for details.

Tag summary

Content type

Image

Digest

sha256:87916ee49…

Size

76.8 MB

Last updated

1 day ago

docker pull ghga/fis:15.3.1

This week's pulls

Pulls:

775

Last week