Security-first ecommerce rebuild for Zevlin Bike.
apps/old_website: legacy reference (read-only source for migration)apps/landing: public marketing websiteapps/store: customer storefront and checkoutapps/admin: operations and backofficeapps/customer: customer account portalapps/b2b: wholesale and quote portalapps/team: cycling team community hub
Shared packages:
packages/db: Postgres schema, migrations, and runtime persistence helperspackages/auth: Authentik-backed authentication and authorization guardspackages/security: encryption, hashing, and audit event APIpackages/contracts: Zod request/response contractspackages/integrations: Stripe/Shippo + Directus/MinIO/SMTP adapterspackages/observability: telemetry and log correlation helperspackages/config: environment loading and validationpackages/ui: shared design primitives
Self-hosted on Coolify for Dev/Staging/Prod with:
- PostgreSQL
- Authentik
- Directus
- MinIO
- Redis
- Grafana/Loki/Prometheus/Tempo
Allowed external vendors: Stripe, Shippo, managed SMTP.
pnpm install
pnpm typecheck
pnpm lint
pnpm testpnpm dev runs an environment bootstrap wizard before starting Turborepo.
- Ensures required keys exist in root
.env.local - Prompts for optional integration keys
- Syncs environment values to app-level
.env.localfiles
Useful variants:
pnpm dev:wizard # run wizard only (even if required keys already exist)
pnpm dev:raw # skip wizard and run turbo directlyStart the self-hosted local stack first:
cp ops/coolify/.env.compose.example ops/coolify/.env.compose.local
pnpm platform:up
pnpm test:block:8Stop the stack:
pnpm platform:downpnpm securityThis repository tracks SOC2 controls for Security, Availability, and Confidentiality. See docs/compliance and docs/policies.
Use checkpoint scripts while building to avoid late integration failures:
pnpm test:blocksRuntime smoke checks are separate:
STORE_BASE_URL=http://localhost:3002 ADMIN_BASE_URL=http://localhost:3003 pnpm test:block:4See docs/testing/testing-blocks.md for block definitions.