Task group 1 of federation-hardening. Fedify was configured with `InProcessMessageQueue`, so every queued outbound delivery, its pending retry state, and inbox processing task was lost on a container restart (routine here: deploys, OOM history) — directly contradicting the social-federation spec's promise that fan-out survives a deploy. - `federation-queue.server.ts`: `PgBossMessageQueue` implementing Fedify's `MessageQueue` over the pg-boss instance the journal already runs, mirroring the `PostgresKvStore` adapter. `nativeRetrial = false` keeps Fedify the retry-policy owner; pg-boss supplies durability + delayed jobs (delay → whole-second `startAfter`, `retryLimit: 0`). - Swap it in for `InProcessMessageQueue` in `federation.server.ts`; document the two intentional queueing layers (our fan-out jobs feed Fedify; Fedify's sends now durable underneath). - `server.ts`: create the durable queue at startup when federation is on. - Broaden the structural `BossLike` in `boss.server.ts` with the work/offWork/createQueue/getQueue methods the adapter needs. - Tests: enqueue maps retry/delay correctly, consume roundtrip, restart durability (fresh listener drains a prior instance's backlog), abort stops the worker, depth reports ready vs delayed. Verified: journal typecheck + lint clean, 7/7 new unit tests pass. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1.8 KiB
1.8 KiB
1. Durable queue
- 1.1 Implement
federation-queue.server.ts: FedifyMessageQueueover pg-boss (enqueue with delay, listen loop), mirroring thePostgresKvStoreadapter pattern - 1.2 Swap
InProcessMessageQueuefor it infederation.server.ts; document the two-layer queueing (fan-out jobs + Fedify queue) in a code comment - 1.3 Tests: enqueue/delay/consume roundtrip; simulated restart (new listener picks up previously enqueued messages)
2. Replay defense
- 2.1 Add
federation_processed_activitiestable (activity IRI PK, received_at) + migration; insert-or-drop check in inbox handlers before side effects - 2.2 30-day TTL sweep in the jobs worker
- 2.3 Tests: duplicate Like/Delete/Update dropped as no-ops; Create double-delivery still covered by remoteOriginIri constraint
3. Blocklist
- 3.1 Add
federation_blocked_instancestable + migration; exact-host check helper - 3.2 Enforce at inbox (silent 202 drop + counter), delivery enqueue (filter recipients), and outbox poll/actor fetch (refuse)
- 3.3 Document the operator procedure (SQL insert/delete) in the ops docs; tests for all three boundaries
4. Protocol doc & observability
- 4.1 Write
FEDERATION.md(repo root): NodeInfo, actors/WebFinger, object + activity types with JSON examples, addressing, signatures + dedup expectations, retry policy, moderation semantics; link from README and docs - 4.2 Add
federation_delivery_total{outcome},federation_queue_depth,federation_inbox_dropped_total{reason}metrics + journal dashboard row
5. Verification
- 5.1 Staging check: queue a fan-out, restart the journal container, confirm deliveries complete; block a test domain and verify both directions
- 5.2 Run
pnpm typecheck && pnpm lint && pnpm test && pnpm test:e2e