Maps the 31-module plan onto the registry's 19 leaves as packages; the two edges the registry forbids (provider->httpclient, inbox->messaging) are replaced by application-owned ports. See docs/notification/module-mapping.md. Acceptance is not delivery: ProviderSubmissionResult refuses to carry a delivery outcome, and AMBIGUOUS is a first-class terminal state that blocks automatic retry and fallback until reconciliation resolves it. Providers: SES (SigV4 + SNS callback), Twilio (X-Twilio-Signature + reconciliation), FCM (FID-primary batch), APNs, Web Push (RFC 8030/8291/8292), SMTP and webhook. Contact points are AES-256-GCM encrypted with a separate HMAC lookup fingerprint; nothing raw reaches a log, metric tag or exception. Dispatch commits the attempt row, calls the provider with no transaction open, then records the outcome; the durable queue uses FOR UPDATE SKIP LOCKED. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
42 lines
1.6 KiB
Markdown
42 lines
1.6 KiB
Markdown
# Configuration reference
|
|
|
|
## Dispatch
|
|
|
|
| Property | Meaning | Bound |
|
|
|---|---|---|
|
|
| `claim-batch-size` | Rows claimed per scheduler tick | 1..1000 |
|
|
| `lease-duration` | How long a claimed job stays owned | positive, finite |
|
|
| `max-global-concurrency` | Ceiling across all providers | positive |
|
|
| `max-queue-age` | Age at which a job is escalated | positive |
|
|
| `max-retry-concurrency` | Ceiling for retry work | positive |
|
|
| `scheduler-poll-interval` | Queue poll cadence | positive |
|
|
| `callback-worker-concurrency` | Callback projection workers | positive |
|
|
|
|
Every value is bounded. "Unlimited" is not an accepted configuration.
|
|
|
|
## Provider profiles
|
|
|
|
A profile pins provider type, environment, credential profile, timeouts, concurrency, rate limit,
|
|
retry policy and callback profile. Sender identity and credential profile are separate concerns.
|
|
|
|
## Startup failures
|
|
|
|
Startup fails rather than degrading when:
|
|
|
|
- a payload or queue setting is unbounded
|
|
- a timeout is negative
|
|
- a TTL-required profile has no expiry source
|
|
- a callback signing secret is missing
|
|
- a production profile enables trust-all
|
|
- an APNs profile is missing its environment or topic
|
|
- a Web Push profile is missing its VAPID key
|
|
- two provider profiles share an id
|
|
- a route points only at disabled providers
|
|
- ambiguous fallback is enabled by default
|
|
|
|
## Secrets
|
|
|
|
All key material arrives through `SecretMaterialProvider`. Nothing is read from source, from a
|
|
committed file, or from a plaintext log. Contact point encryption and lookup HMAC keys must be
|
|
distinct, and the encryption key must be exactly 256 bits.
|