Files
B2BCall-dialer/infrastructure/freeswitch/Dockerfile
Matheus c03c6d4eaa feat: implement Extensions with real FreeSWITCH directory integration
- extensions table (tenant-scoped, RLS): number, sip_password_enc
  (AES-256-GCM via packages/shared/src/crypto.ts), caller_id, context,
  sofia_profile, codecs, max_registrations
- apps/api/src/extensions: CRUD (POST/GET/GET:id/DELETE), protected by a
  new generic PermissionGuard (@RequirePermission decorator), tenant
  resolved only from the JWT (never trusted from the client)
- SIP password is returned in plaintext only once, in the create response;
  toPublicExtension() explicitly destructures the encrypted field out
  (not a spread) so it can't leak by accident
- b2bcall-fs-config now resolves real directory data: Tenant.telephonyDomain
  -> Extension.number, decrypts the password, builds proper directory XML
  including a dial-string param (missing it caused originate to fail with
  MANDATORY_IE_MISSING instead of the expected USER_NOT_REGISTERED)
- pinned FreeSWITCH's 357737{domain} to a stable value (b2bcall.local) via a
  vars.xml patch in the Dockerfile -- it previously used the container's
  dynamic IP, which could never match a stored telephony_domain
- added HTTP Basic auth between FreeSWITCH and fs-config
  (gateway-credentials, timingSafeEqual comparison) now that the service
  returns real secret data, closing the gap flagged as pending in the XML
  Curl phase instead of leaving it open
- found and fixed: PermissionGuard's constructor-injected Reflector came
  back undefined at runtime under tsx/esbuild (unreliable cross-file
  decorator metadata emission) -- fixed with an explicit @Inject(Reflector);
  worth watching for in future guards/services run via tsx
- verified end-to-end: create extension -> originate user/<ext> reports
  USER_NOT_REGISTERED (found, not registered) -> delete -> back to
  SUBSCRIBER_ABSENT (not found); password never reappears in any GET;
  unauthenticated fs-config requests get 401
- docs/EXTENSIONS.md
2026-08-28 07:39:19 -03:00

65 lines
3.1 KiB
Docker
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# syntax=docker/dockerfile:1.7
#
# Imagem própria/controlada do FreeSWITCH (agente.md secao 19), usando os
# pacotes pré-compilados do SignalWire em vez de compilar da fonte — build
# de C/C++ e´ pesado demais pra VM de laboratorio (1.9GB RAM).
FROM debian:trixie-slim
ENV DEBIAN_FRONTEND=noninteractive
RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates gnupg curl \
&& rm -rf /var/lib/apt/lists/*
# FREESWITCH_PAT só existe durante este RUN (BuildKit secret, nunca vira
# camada da imagem) e o arquivo de credenciais do apt é apagado antes do fim
# do MESMO RUN — agente.md secao 11: "a credencial nao devera permanecer na
# imagem runtime".
RUN --mount=type=secret,id=freeswitch_pat,required=true \
set -eu; \
FS_PAT="$(cat /run/secrets/freeswitch_pat)"; \
curl -fsSL -u "signalwire:${FS_PAT}" \
https://freeswitch.signalwire.com/repo/deb/debian-release/signalwire-freeswitch-repo.gpg \
-o /usr/share/keyrings/signalwire-freeswitch-repo.gpg; \
install -d -m 700 /etc/apt/auth.conf.d; \
printf 'machine freeswitch.signalwire.com\nlogin signalwire\npassword %s\n' "${FS_PAT}" \
> /etc/apt/auth.conf.d/freeswitch.conf; \
chmod 600 /etc/apt/auth.conf.d/freeswitch.conf; \
echo "deb [signed-by=/usr/share/keyrings/signalwire-freeswitch-repo.gpg] https://freeswitch.signalwire.com/repo/deb/debian-release/ trixie main" \
> /etc/apt/sources.list.d/freeswitch.list; \
apt-get update; \
apt-get install -y --no-install-recommends \
freeswitch-meta-vanilla \
freeswitch-conf-vanilla \
freeswitch-mod-xml-curl \
freeswitch-mod-callcenter \
freeswitch-mod-avmd \
freeswitch-mod-curl; \
rm -f /etc/apt/auth.conf.d/freeswitch.conf /etc/apt/sources.list.d/freeswitch.list; \
rm -rf /var/lib/apt/lists/*
# Overrides mínimos por cima da config vanilla (agente.md secao 15: "carregar
# somente o necessário"). Directory/dialplan/sip_profiles ficam na config
# vanilla padrão por enquanto — serão substituídos por mod_xml_curl na fase
# "Extensions/Trunks/Dialplan" (ver docs/FREESWITCH.md).
COPY overrides/autoload_configs/modules.conf.xml /etc/freeswitch/autoload_configs/modules.conf.xml
COPY overrides/autoload_configs/event_socket.conf.xml /etc/freeswitch/autoload_configs/event_socket.conf.xml
COPY overrides/autoload_configs/acl.conf.xml /etc/freeswitch/autoload_configs/acl.conf.xml
COPY overrides/autoload_configs/xml_curl.conf.xml /etc/freeswitch/autoload_configs/xml_curl.conf.xml
# Pino $${domain} num valor estavel em vez do IP dinamico do container
# (vars.xml vanilla usa "domain=$${local_ip_v4}", que muda a cada restart e
# nunca bateria com Tenant.telephonyDomain). Ver docs/EXTENSIONS.md.
ARG DEFAULT_SIP_DOMAIN=b2bcall.local
RUN sed -i "s/data=\"domain=\$\${local_ip_v4}\"/data=\"domain=${DEFAULT_SIP_DOMAIN}\"/" \
/etc/freeswitch/vars.xml \
&& grep -q "domain=${DEFAULT_SIP_DOMAIN}" /etc/freeswitch/vars.xml
COPY entrypoint.sh /usr/local/bin/entrypoint.sh
RUN chmod +x /usr/local/bin/entrypoint.sh
EXPOSE 8021
ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
CMD ["/usr/bin/freeswitch", "-nonat"]