Skip to main content

systemprompt_cloud/
constants.rs

1//! Compile-time constants for the cloud layer: container paths, callback ports
2//! and timeouts, API endpoints, deploy regions, and on-disk file/profile names.
3//!
4//! Grouped into submodules by concern (`oauth`, `credentials`, `docker`,
5//! `api`, `paths`, `profile`, `env_vars`); path-name and storage constants
6//! are re-exported from `systemprompt_models`.
7//!
8//! Copyright (c) systemprompt.io — Business Source License 1.1.
9//! See <https://systemprompt.io> for licensing details.
10
11pub use systemprompt_models::paths::constants::{build, dir_names, file_names, storage};
12
13pub mod container {
14    use systemprompt_models::paths::constants::cloud_container;
15
16    pub const APP: &str = cloud_container::APP_ROOT;
17    pub const APP_ROOT: &str = cloud_container::APP_ROOT;
18    pub const BIN: &str = cloud_container::BIN;
19    pub const LOGS: &str = cloud_container::LOGS;
20    pub const SERVICES: &str = cloud_container::SERVICES;
21    pub const STORAGE: &str = cloud_container::STORAGE;
22    pub const WEB: &str = cloud_container::WEB;
23    pub const WEB_DIST: &str = cloud_container::WEB_DIST;
24    pub const WEB_CONFIG: &str = cloud_container::WEB_CONFIG;
25    pub const PROFILES: &str = cloud_container::PROFILES;
26    pub const TEMPLATES: &str = cloud_container::TEMPLATES;
27    pub const ASSETS: &str = cloud_container::ASSETS;
28}
29
30pub const CALLBACK_TIMEOUT_SECS: u64 = 300;
31
32pub mod oauth {
33    pub const CALLBACK_PORT: u16 = 8765;
34    pub const CALLBACK_TIMEOUT_SECS: u64 = super::CALLBACK_TIMEOUT_SECS;
35}
36
37pub mod credentials {
38    use super::{dir_names, file_names};
39
40    pub const DEFAULT_DIR_NAME: &str = dir_names::SYSTEMPROMPT;
41    pub const DEFAULT_FILE_NAME: &str = file_names::CREDENTIALS;
42
43    pub const VALIDATION_TTL_SECS: i64 = 900;
44}
45
46pub mod tenants {
47    use super::{dir_names, file_names};
48
49    pub const DEFAULT_DIR_NAME: &str = dir_names::SYSTEMPROMPT;
50    pub const DEFAULT_FILE_NAME: &str = file_names::TENANTS;
51}
52
53pub mod cli_session {
54    use super::{dir_names, file_names};
55
56    pub const DEFAULT_DIR_NAME: &str = dir_names::SYSTEMPROMPT;
57    pub const DEFAULT_FILE_NAME: &str = file_names::SESSION;
58}
59
60pub mod docker {
61    pub const CONTAINER_NAME_PREFIX: &str = "systemprompt-postgres";
62    pub const COMPOSE_PATH: &str = "infrastructure/docker";
63
64    pub fn container_name(env_name: &str) -> String {
65        format!("{}-{}", CONTAINER_NAME_PREFIX, env_name)
66    }
67}
68
69pub mod api {
70    pub const PRODUCTION_URL: &str = "https://api.systemprompt.io";
71    pub const SANDBOX_URL: &str = "https://api-sandbox.systemprompt.io";
72}
73
74pub mod paths {
75    use super::{dir_names, file_names};
76
77    pub const ROOT_DIR: &str = dir_names::SYSTEMPROMPT;
78    pub const PROFILES_DIR: &str = dir_names::PROFILES;
79    pub const DOCKER_DIR: &str = dir_names::DOCKER;
80    pub const STORAGE_DIR: &str = dir_names::STORAGE;
81    pub const DOCKERFILE: &str = file_names::DOCKERFILE;
82    pub const PROFILE_CONFIG: &str = file_names::PROFILE_CONFIG;
83    pub const PROFILE_SECRETS: &str = file_names::PROFILE_SECRETS;
84    pub const CREDENTIALS_FILE: &str = file_names::CREDENTIALS;
85    pub const TENANTS_FILE: &str = file_names::TENANTS;
86    pub const SESSION_FILE: &str = file_names::SESSION;
87    pub const PROFILE_DOCKER_DIR: &str = dir_names::DOCKER;
88    pub const ENTRYPOINT: &str = file_names::ENTRYPOINT;
89    pub const DOCKERIGNORE: &str = file_names::DOCKERIGNORE;
90    pub const COMPOSE_FILE: &str = file_names::COMPOSE;
91}
92
93pub mod profile {
94    use super::container;
95
96    pub const DEFAULT_DB_TYPE: &str = "postgres";
97    pub const DEFAULT_PORT: u16 = 8080;
98    pub const LOCAL_HOST: &str = "127.0.0.1";
99    pub const CLOUD_HOST: &str = "0.0.0.0";
100    pub const DEFAULT_CLOUD_URL: &str = "https://cloud.systemprompt.io";
101    pub const LOCAL_ISSUER: &str = "systemprompt-local";
102    pub const CLOUD_ISSUER: &str = "systemprompt";
103    pub const ACCESS_TOKEN_EXPIRATION: i64 = 2_592_000;
104    pub const REFRESH_TOKEN_EXPIRATION: i64 = 15_552_000;
105    pub const CLOUD_APP_PATH: &str = container::APP_ROOT;
106    pub const CREDENTIALS_PATH: &str = "../../credentials.json";
107    pub const TENANTS_PATH: &str = "../../tenants.json";
108}
109
110pub mod proxies {
111    pub const PRIVATE_RANGES: &[&str] = &[
112        "127.0.0.0/8",
113        "::1/128",
114        "10.0.0.0/8",
115        "172.16.0.0/12",
116        "192.168.0.0/16",
117    ];
118
119    pub const FLY_PRIVATE_RANGES: &[&str] = &["fc00::/7"];
120
121    pub const FLY_PUBLIC_RANGES: &[&str] = &["66.241.64.0/18"];
122
123    pub const CLOUDFLARE_RANGES: &[&str] = &[
124        "173.245.48.0/20",
125        "103.21.244.0/22",
126        "103.22.200.0/22",
127        "103.31.4.0/22",
128        "141.101.64.0/18",
129        "108.162.192.0/18",
130        "190.93.240.0/20",
131        "188.114.96.0/20",
132        "197.234.240.0/22",
133        "198.41.128.0/17",
134        "162.158.0.0/15",
135        "104.16.0.0/13",
136        "104.24.0.0/14",
137        "172.64.0.0/13",
138        "131.0.72.0/22",
139        "2400:cb00::/32",
140        "2606:4700::/32",
141        "2803:f800::/32",
142        "2405:b500::/32",
143        "2405:8100::/32",
144        "2a06:98c0::/29",
145        "2c0f:f248::/32",
146    ];
147}
148
149pub mod env_vars {
150    pub use systemprompt_models::paths::constants::env_vars::CUSTOM_SECRETS;
151
152    pub const SYSTEM_MANAGED: &[&str] = &["FLY_APP_NAME", "FLY_MACHINE_ID"];
153
154    pub const CLI_SYNCED: &[&str] = &[
155        "SYSTEMPROMPT_API_TOKEN",
156        "SYSTEMPROMPT_USER_EMAIL",
157        "SYSTEMPROMPT_CLI_REMOTE",
158        "SYSTEMPROMPT_PROFILE",
159    ];
160
161    pub fn is_system_managed(key: &str) -> bool {
162        SYSTEM_MANAGED.iter().any(|&k| k.eq_ignore_ascii_case(key))
163    }
164}