feat(journal): durable Fedify message queue over pg-boss

Task group 1 of federation-hardening. Fedify was configured with
`InProcessMessageQueue`, so every queued outbound delivery, its pending
retry state, and inbox processing task was lost on a container restart
(routine here: deploys, OOM history) — directly contradicting the
social-federation spec's promise that fan-out survives a deploy.

- `federation-queue.server.ts`: `PgBossMessageQueue` implementing Fedify's
  `MessageQueue` over the pg-boss instance the journal already runs,
  mirroring the `PostgresKvStore` adapter. `nativeRetrial = false` keeps
  Fedify the retry-policy owner; pg-boss supplies durability + delayed
  jobs (delay → whole-second `startAfter`, `retryLimit: 0`).
- Swap it in for `InProcessMessageQueue` in `federation.server.ts`;
  document the two intentional queueing layers (our fan-out jobs feed
  Fedify; Fedify's sends now durable underneath).
- `server.ts`: create the durable queue at startup when federation is on.
- Broaden the structural `BossLike` in `boss.server.ts` with the
  work/offWork/createQueue/getQueue methods the adapter needs.
- Tests: enqueue maps retry/delay correctly, consume roundtrip, restart
  durability (fresh listener drains a prior instance's backlog), abort
  stops the worker, depth reports ready vs delayed.

Verified: journal typecheck + lint clean, 7/7 new unit tests pass.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Ullrich Schäfer 2026-07-13 21:46:46 +02:00
parent 1ea2559246
commit b8fc8fadff
No known key found for this signature in database
GPG key ID: A32FF691A0F752D9
6 changed files with 252 additions and 12 deletions

View file

@ -165,6 +165,12 @@ server.listen(port, async () => {
// users get keys before any federation traffic). Each run only
// touches users whose public_key IS NULL, so repeats are no-ops.
if (process.env.FEDERATION_ENABLED === "true") {
// Create the durable queue backing Fedify's message queue before any
// federation traffic can enqueue/consume on it. pg-boss requires queues
// to exist explicitly (v10+); createQueue is idempotent.
const { FEDERATION_QUEUE_NAME } = await import("./app/lib/federation-queue.server.ts");
await boss.createQueue(FEDERATION_QUEUE_NAME);
await enqueue("backfill-user-keypairs", {});
logger.info("federation keypair backfill enqueued");
}