Document Google provider environments
This commit is contained in:
parent
72fd99e09a
commit
a9b78ec374
|
|
@ -788,6 +788,7 @@ and no fallback provider. Recommendations require a human moderator action.
|
||||||
- [Architecture](docs/architecture.md)
|
- [Architecture](docs/architecture.md)
|
||||||
- [Trust and safety](docs/trust-safety.md)
|
- [Trust and safety](docs/trust-safety.md)
|
||||||
- [Operations runbook](docs/operations.md)
|
- [Operations runbook](docs/operations.md)
|
||||||
|
- [Google provider inventory for Dev, Test, and Prod](docs/google-provider-inventory.md)
|
||||||
- [Performance measurement](docs/performance.md)
|
- [Performance measurement](docs/performance.md)
|
||||||
- [Implementation verification and known limits](docs/verification.md)
|
- [Implementation verification and known limits](docs/verification.md)
|
||||||
- [Verified dependency baseline](docs/dependency-baseline.md)
|
- [Verified dependency baseline](docs/dependency-baseline.md)
|
||||||
|
|
|
||||||
135
docs/google-provider-inventory.md
Normal file
135
docs/google-provider-inventory.md
Normal file
|
|
@ -0,0 +1,135 @@
|
||||||
|
# Google provider inventory
|
||||||
|
|
||||||
|
Verified read-only on 2026-08-28 against the authenticated Google Cloud and
|
||||||
|
Firebase consoles, the local Dev `.env`, the installed Test and Prod `.env`
|
||||||
|
files over SSH, and the repository environment validators. No secret values
|
||||||
|
were read into this document. This is an inventory, not a source of secrets.
|
||||||
|
|
||||||
|
## Environment contract
|
||||||
|
|
||||||
|
Who Need Help has exactly three deployment environments:
|
||||||
|
|
||||||
|
| Environment | Public origin | Android build/package | Google project |
|
||||||
|
| --- | --- | --- | --- |
|
||||||
|
| Dev | `https://whoneedhelp.imalto.site` | `development` / `org.whoneedhelp.mobile.development` | `Who Need Help Development` / `who-need-help-development` / `299749044449` |
|
||||||
|
| Test | `https://test.whoneedhelp.com` | `staging` / `org.whoneedhelp.mobile.staging` | `Who Need Help Staging` / `who-need-help-staging` / `340523338913` |
|
||||||
|
| Prod | `https://whoneedhelp.com` | `release` / `org.whoneedhelp.mobile` | `Who Need Help Production` / `who-need-help-production` / `184178014037` |
|
||||||
|
|
||||||
|
`staging` is only the existing Google display name and Android build/package
|
||||||
|
label for **Test**. It is not a fourth environment. Reuse the three project IDs
|
||||||
|
above; do not create another Google Cloud or Firebase project for these
|
||||||
|
environments.
|
||||||
|
|
||||||
|
The repository enforces this mapping in
|
||||||
|
[`scripts/validate-android-environment.sh`](../scripts/validate-android-environment.sh).
|
||||||
|
|
||||||
|
The installed runtime identifiers match the table: Dev points to
|
||||||
|
`who-need-help-development`, Prod points to `who-need-help-production`, and
|
||||||
|
Test has its own Web OAuth client while all Firebase/FCM values remain empty.
|
||||||
|
|
||||||
|
## Current registrations
|
||||||
|
|
||||||
|
### Dev
|
||||||
|
|
||||||
|
- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-development)
|
||||||
|
- Web: `Who Need Help Development Web`
|
||||||
|
(`299749044449-j364ndp46h83r6mmtrj2qrlleas05an0.apps.googleusercontent.com`)
|
||||||
|
- origin: `https://whoneedhelp.imalto.site`
|
||||||
|
- callback: `https://whoneedhelp.imalto.site/auth/google/callback`
|
||||||
|
- Android: `Who Need Help Development Android`
|
||||||
|
(`299749044449-e39l1h560kot97bj2mjjat70or2sn00n.apps.googleusercontent.com`)
|
||||||
|
- [Firebase project](https://console.firebase.google.com/project/who-need-help-development/settings/general):
|
||||||
|
Spark, shown as `No-cost ($0/month)` at verification time.
|
||||||
|
- Firebase Android app: `Who Need Help Development`, package
|
||||||
|
`org.whoneedhelp.mobile.development`, app ID
|
||||||
|
`1:299749044449:android:284bfd48e072ca29e307a0`.
|
||||||
|
- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-development):
|
||||||
|
- `wnh-dev-fcm-sender@who-need-help-development.iam.gserviceaccount.com`
|
||||||
|
is enabled for FCM HTTP v1;
|
||||||
|
- the Firebase Admin SDK service account exists and has no user-managed key.
|
||||||
|
|
||||||
|
### Test
|
||||||
|
|
||||||
|
- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-staging)
|
||||||
|
- Web: `Who Need Help Staging Web`
|
||||||
|
(`340523338913-8qjj8vtnamq44mtl7eg5fv60o8cfnts5.apps.googleusercontent.com`)
|
||||||
|
- origin: `https://test.whoneedhelp.com`
|
||||||
|
- callback: `https://test.whoneedhelp.com/auth/google/callback`
|
||||||
|
- Android: `Who Need Help Staging Android`
|
||||||
|
(`340523338913-4634ev1onnv8a5q092pncpocj9smfvvg.apps.googleusercontent.com`),
|
||||||
|
package `org.whoneedhelp.mobile.staging`.
|
||||||
|
- Firebase is not connected to `who-need-help-staging`; the current Firebase
|
||||||
|
project list contains only Dev and Prod.
|
||||||
|
- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-staging):
|
||||||
|
no service accounts were present, so Test has no FCM sender registration.
|
||||||
|
- The Google Cloud project has a billing account linked. The console showed
|
||||||
|
`$0.00` estimated charges for 2026-08-01 through 2026-08-28; this observation
|
||||||
|
is not a pricing guarantee.
|
||||||
|
- The Web OAuth client also contains the old callback
|
||||||
|
`https://staging.whoneedhelp.com/auth/google/callback`. It is not part of the
|
||||||
|
three-environment contract. Do not rely on or remove it until the owner
|
||||||
|
explicitly chooses the cleanup.
|
||||||
|
|
||||||
|
### Prod
|
||||||
|
|
||||||
|
- [Google OAuth clients](https://console.cloud.google.com/auth/clients?project=who-need-help-production)
|
||||||
|
- Web: `Who Need Help Production Web`
|
||||||
|
(`184178014037-elt40fdgum1umln6440fgmb6h7o7dskr.apps.googleusercontent.com`)
|
||||||
|
- origin: `https://whoneedhelp.com`
|
||||||
|
- callback: `https://whoneedhelp.com/auth/google/callback`
|
||||||
|
- Android clients: `Who Need Help Android Upload`,
|
||||||
|
`Who Need Help Android Play RSA 1`, `Who Need Help Android Play RSA 2`, and
|
||||||
|
`Who Need Help Android Play ML-DSA`.
|
||||||
|
- [Firebase project](https://console.firebase.google.com/project/who-need-help-production/settings/general):
|
||||||
|
Spark, shown as `No-cost ($0/month)` at verification time.
|
||||||
|
- Firebase Android app: `Who Need Help Production`, package
|
||||||
|
`org.whoneedhelp.mobile`, app ID
|
||||||
|
`1:184178014037:android:18b3996444c3bebce361dc`.
|
||||||
|
- [IAM service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts?project=who-need-help-production):
|
||||||
|
- `who-need-help-fcm@who-need-help-production.iam.gserviceaccount.com` is
|
||||||
|
enabled for FCM HTTP v1;
|
||||||
|
- the Firebase Admin SDK service account exists and has no user-managed key.
|
||||||
|
- [Google Play app](https://play.google.com/console/u/0/developers/5283023225403815420/app/4972430103169452589/app-dashboard)
|
||||||
|
is the production Android application.
|
||||||
|
- Four Android OAuth clients currently exist while the local Play identity
|
||||||
|
inventory records three Play signing identities. The purpose of the fourth
|
||||||
|
client has not been verified; do not delete or merge any of them based only
|
||||||
|
on their similar names.
|
||||||
|
|
||||||
|
## Configuration ownership
|
||||||
|
|
||||||
|
Each checkout keeps one ignored `.env`. Provider secrets must remain there or
|
||||||
|
in the ignored provider files consumed by the import scripts; never copy them
|
||||||
|
into this document or commit them.
|
||||||
|
|
||||||
|
| Capability | Runtime configuration |
|
||||||
|
| --- | --- |
|
||||||
|
| Web Google sign-in | `GOOGLE_OAUTH_CLIENT_ID`, `GOOGLE_OAUTH_CLIENT_SECRET` |
|
||||||
|
| Android Google sign-in | `GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS` |
|
||||||
|
| Public Firebase Android config | four `WNH_FIREBASE_*` values |
|
||||||
|
| Server-side FCM | `FCM_PROJECT_ID` and exactly one service-account source |
|
||||||
|
| Android App Links | `ANDROID_APP_LINKS_PACKAGE_NAME`, `ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS` |
|
||||||
|
|
||||||
|
Relevant validated importers:
|
||||||
|
|
||||||
|
- [`scripts/import-firebase-android-config.sh`](../scripts/import-firebase-android-config.sh)
|
||||||
|
- [`scripts/import-fcm-service-account.sh`](../scripts/import-fcm-service-account.sh)
|
||||||
|
- [`scripts/import-play-android-config.sh`](../scripts/import-play-android-config.sh)
|
||||||
|
|
||||||
|
The Dev and Prod FCM sender accounts being present proves registration only;
|
||||||
|
delivery still requires the matching environment configuration and an actual
|
||||||
|
device smoke test. Test currently has OAuth but no Firebase/FCM registration.
|
||||||
|
|
||||||
|
The ignored `tmp/environment-access/*.env` files are historical snapshots, not
|
||||||
|
live configuration. In particular, its old Dev snapshot still references the
|
||||||
|
historical `who-need-help-dev-firebase` setup and must not be used to recreate or
|
||||||
|
overwrite the current Dev configuration.
|
||||||
|
|
||||||
|
## Do not recreate
|
||||||
|
|
||||||
|
- Do not create a fourth environment called Staging.
|
||||||
|
- Do not create another Firebase project for Dev or Prod.
|
||||||
|
- Do not place OAuth client secrets, Firebase API keys, service-account JSON,
|
||||||
|
private keys, or key IDs in documentation.
|
||||||
|
- Do not delete an OAuth client, callback, Firebase app, fingerprint, or service
|
||||||
|
account until its active environment and signing identity have been verified.
|
||||||
Loading…
Reference in New Issue
Block a user