The cloud portion of Nidus
  • Go 49.7%
  • Vue 22.7%
  • PLpgSQL 8.8%
  • Swift 6.3%
  • Python 5.9%
  • Other 6.6%
Find a file
Eli Ribble 093fbc6c3d
All checks were successful
/ golint (push) Successful in 2m7s
/ pnpm-build (push) Successful in 1m38s
/ gotest (push) Successful in 2m14s
/ pnpm-test (push) Successful in 10s
Merge pull request 'Mosquito check: admin-editable send message, off-property save fix, closer geocode, solution copy updates' (#211) from mosquito-check-updates into main
Reviewed-on: #211
Reviewed-by: Eli Ribble <eli@gleipnir.technology>
2026-09-05 00:27:49 +00:00
.forgejo Move sqlcheck build artifact into repo-local tmp/ 2026-09-04 20:47:38 +00:00
align planet align: parallelize the strip warp in warp_tile 2026-08-26 21:13:51 +00:00
api Restructure sudo Background into sections; add job statistics and history 2026-09-04 23:04:35 +00:00
arcgis-go@d4aa822a99 Update to latest arcgis-go 2026-08-26 15:04:39 +00:00
auth Change sign-up page to tell people to reach out to sales 2026-07-29 13:44:52 +00:00
cmd Add durable job run history and retry cursor columns 2026-09-04 23:04:35 +00:00
comms Fix duplicate SMS on Voip.MS timeout 2026-08-27 19:43:43 +00:00
config api: per-host maintenance gates with status + sudo maintenance endpoints 2026-09-03 14:35:24 +00:00
container nemish: discrete image build entry points + docs 2026-08-27 11:02:09 -07:00
db mosquito-check: drop habitat wording columns from habitat_type 2026-09-04 23:32:44 +00:00
debug Begin work on debugging user behavior in early setup 2026-01-06 14:46:31 +00:00
deploy paseo-host-router: send per-daemon password on route poll 2026-09-04 20:24:22 +00:00
doc docs: explain district/phone tokens in habitat solutions copy 2026-09-04 23:52:09 +00:00
etc Report pool risk from newest medium-res detection everywhere 2026-09-04 03:37:06 +00:00
geomutil Fix: set SRID 4326 on point geometry for CSV import 2026-07-12 03:11:48 +00:00
go-geojson2h3@c2ff1a96ab Add mocks for data entry 2025-12-10 17:06:27 +00:00
go-shp@6759ac7e08 Fix broken go-shp release 2026-08-13 14:01:21 +00:00
h3utils style: lowercase error strings across the codebase 2026-07-09 18:46:41 +00:00
html Stop looking for embedded RMO templates 2026-07-21 05:25:52 +00:00
http Show more information or error with status when printing 2026-06-08 22:12:38 +00:00
internal/testutil Show parcel/situs on site detail page; fix test util fixtures 2026-08-26 00:17:08 +00:00
label-studio Fix unused import 2026-07-09 14:20:56 -05:00
lint platform: stop logging client-disconnect write errors on transform tiles 2026-08-27 19:42:53 +00:00
llm style: lowercase error strings across the codebase 2026-07-09 18:46:41 +00:00
lob Fix API compatibility with resty.dev/v3 v3.0.0-rc.1 upgrade 2026-07-15 18:17:57 +00:00
local: Add sticky ground-truth layer design port to medres 2026-08-21 01:24:56 +00:00
mapvision-go@63ed070c29 Update mapvision to include ctx in requests 2026-08-27 04:08:41 +00:00
medres Wire pool-condition backfill job end to end 2026-09-04 16:47:57 +00:00
middleware lint: remove unused code across api, comms, h3utils, html, middleware, minio, platform, rmo 2026-05-09 14:47:56 +00:00
minio style: lowercase error strings across the codebase 2026-07-09 18:46:41 +00:00
nemish vision/training: regression test for writable shard tensors 2026-08-30 03:21:23 +00:00
Nidus-iOS docs(nidus-notes): design on-device extraction + knowledge-graph persistence & sync 2026-09-03 08:13:16 -07:00
nir Route cache writes through an atomic write helper 2026-09-04 17:20:00 +00:00
nixos-modules Move tegola service into nidus-sync 2026-09-02 00:24:05 +00:00
orgtransfer org-import: hint to grant/revoke superuser when FK-trigger disable is denied 2026-09-01 01:39:56 +00:00
placer-mysql-feed@0b67b0a802 Update placer-mysql-feed 2026-08-24 22:54:43 +00:00
planet Route cache writes through an atomic write helper 2026-09-04 17:20:00 +00:00
planet-go@d52be758ac Avoid OOM when reading native TIFF tiles 2026-08-15 00:22:31 +00:00
platform mosquito-check: org identity drives send copy and resident state 2026-09-04 23:42:35 +00:00
postgrid/cmd/send-pdf Save experiment in postgred integration 2026-04-03 15:25:15 +00:00
resource mosquito-check: admin-editable message for mosquito check send (backend) 2026-09-04 23:13:50 +00:00
rmo Add short links with click tracking and campaign inspections 2026-09-04 21:19:33 +00:00
scripts Handle setting the paseo env with non-daemon managed environment 2026-09-04 23:01:12 +00:00
scss RMO frontend checkpoint 2026-04-09 17:21:35 +00:00
stadia Update files 2026-08-18 18:18:14 +00:00
static Show the MapVision logo for data synchronized from MapVision 2026-08-22 18:28:42 +00:00
svg Add avatar placeholer when avatar is empty 2026-04-01 14:48:31 +00:00
sync Fix compilation: update all db.ExecuteOne/ExecuteOneTx callers for *T return type 2026-07-10 01:31:51 +00:00
tools situs override: per-org field-level correction of municipal situs data 2026-09-03 21:55:45 +00:00
ts mosquito: substitute runtime org identity at render 2026-09-04 23:48:44 +00:00
vastai-go@4d5b14ba70 Move to latest vastai, initial release v0.0.1 2026-08-25 01:19:38 +00:00
vectorsurv-go@2534efcb08 Update files 2026-08-25 23:38:46 +00:00
version Move to setting version info explicitly in linker flags 2026-05-19 19:46:05 +00:00
vite Add short links with click tracking and campaign inspections 2026-09-04 21:19:33 +00:00
.air.toml Don't stop the server if there is a build error 2026-02-13 19:18:48 +00:00
.containerignore Initial creation of container image for opencode to run nidus-sync 2026-07-12 23:52:51 +00:00
.gitattributes Add a basic main page with login 2025-11-03 22:13:19 +00:00
.gitignore Move sqlcheck build artifact into repo-local tmp/ 2026-09-04 20:47:38 +00:00
.gitmodules Register swift-h3 as nested submodule of nidus-sync; drop stale Nidus-iOS/.gitmodules 2026-09-03 07:53:04 -07:00
.golangci.yml add golangci-lint to dev toolchain and enforce in CI and lefthook 2026-08-26 20:44:14 +00:00
.prettierrc Update prettier config with latest flake update 2026-06-24 11:21:45 -05:00
AGENTS-WORKSPACE.md paseo: seed workspace-specific AGENTS.md from AGENTS-WORKSPACE.md at worktree creation 2026-08-28 19:44:39 +00:00
AGENTS.md Document anti-wait operating principles in AGENTS.md 2026-09-02 04:23:27 +00:00
default.nix Fix stale pnpm deps hash for nix build 2026-09-03 20:31:33 +00:00
fake-xdg-open Initial creation of container image for opencode to run nidus-sync 2026-07-12 23:52:51 +00:00
flake.lock Use local nemish source to build containers 2026-08-13 21:59:52 +00:00
flake.nix Update paseo host router hash 2026-09-02 13:47:25 +00:00
generate-icons.js Fix build: add mkdirSync and generate-icons step 2026-07-10 20:13:56 +00:00
go.mod mapvision: cancel in-flight sync requests on shutdown 2026-08-26 21:37:14 +00:00
go.sum mapvision: cancel in-flight sync requests on shutdown 2026-08-26 21:37:14 +00:00
HISTORY.md Test of agent capabilities: 2026-05-09 00:54:39 +00:00
lefthook.yml chore: block large binaries and compiled programs in pre-commit 2026-08-29 23:19:50 +00:00
LICENSE Initial commit 2025-11-03 05:12:02 -07:00
main.go Fix worker logs, auto-scale SSE events, and event reliability 2026-08-25 14:59:08 +00:00
package-lock.json Add histogram of tasks instead of a table of tasks 2026-07-26 16:39:01 +00:00
package.json review/transcripts: Phase 4+5 — transcript review API + UI cutover 2026-09-02 15:25:42 +00:00
paseo.json Try new config for generating titles, commits, and PRs 2026-08-29 21:25:30 +00:00
pnpm-lock.yaml review/transcripts: Phase 4+5 — transcript review API + UI cutover 2026-09-02 15:25:42 +00:00
pnpm-workspace.yaml feat: integrate maplibre-gl-terradraw with UI drawing playground 2026-07-24 17:08:35 +00:00
README.md file: split first-order files from derivative cache storage 2026-08-29 20:21:56 +00:00
result-align Retry transient nidus-sync failures with bounded backoff 2026-08-26 16:28:13 +00:00
run-backend.sh Add NIR flood-irrigation mosquito-risk pipeline 2026-08-19 02:59:14 +00:00
sqlcheck.baseline Quiet canceled-context DB collect warnings and early-bail worker handlers 2026-09-01 20:24:51 +00:00
start-air.sh Load secrets from shared nidus-sync-env file 2026-08-20 00:55:59 +00:00
start-flogo.sh Load secrets from shared nidus-sync-env file 2026-08-20 00:55:59 +00:00
start-nidus-sync.sh Load secrets from shared nidus-sync-env file 2026-08-20 00:55:59 +00:00
start-nix-built.sh Load secrets from shared nidus-sync-env file 2026-08-20 00:55:59 +00:00
start-opencode.sh Set up container build using nix flake 2026-07-13 00:34:44 +00:00
TEST-PLAN.md Add test plan, update cleanup 2026-05-12 14:37:47 +00:00
tsconfig.json TypeScript checking is clean. 2026-03-22 02:55:17 +00:00
vitest.config.ts review/transcripts: Phase 4+5 — transcript review API + UI cutover 2026-09-02 15:25:42 +00:00

Nidus Sync

This is the software that powers Nidus Cloud Sync.

Administration

Password resets

If you need to manually reset a password you can do so with:

$ nix-shell -p genpass
$ genpass 12
abc123abc123
# this is from nidus, installed on deployment servers at the system layer
$ passwordgen
Please enter your password: abc123abc123
Password: abc123abc123
Hash: $2a$14$hdtoAtP7joczutY3bxaFqemBApH8xc5NbXLvDQqBfdzWV3jGSy4zi
$ psql -d nidus-sync
nidus-sync=> update user set password_hash='$2a$14$hdtoAtP7joczutY3bxaFqemBApH8xc5NbXLvDQqBfdzWV3jGSy4zi' where id=<something>;

Building from source

First, you'll need Nix.

Then:

nix develop
go build .

Building Custom Theme

We're using a customized Bootstrap theme for this site. You'll need to build the SCSS into CSS:

nix develop
sass --style=compressed --trace "$SASS_SRC_DIR/custom.scss":"$CSS_OUTPUT_DIR/bootstrap.css"

Running

You'll need a number of environment variables for configuring things;

Required

Variable Description
ARCGIS_CLIENT_ID Client ID for ArcGIS OAuth, configured with Esri
ARCGIS_CLIENT_SECRET Client secret for ArcGIS OAuth, configured with Esri
BIND Address and port to bind to. Use :9001 for any address, port 9001 (default)
DOMAIN_NIDUS Domain for the Nidus Cloud Sync site, used for forming callback URLs — e.g. sync.nidus.cloud
DOMAIN_RMO Domain for the RMO site — e.g. rmo.nidus.cloud
DOMAIN_TEGOLA Domain for the Tegola tile server — e.g. tegola.nidus.cloud
ENVIRONMENT Either PRODUCTION or DEVELOPMENT. Controls behaviour like OAuth token length
FIELDSEEKER_SCHEMA_DIRECTORY Directory to write FieldSeeker schema files for debugging
FILES_DIRECTORY Directory for writing first-order (backed-up) content: uploaded user data (audio, images), avatars, logos, CSVs, KML/KMZ, planet orders, public images, vision models
CACHE_DIRECTORY Directory for second-order, derivative content that is rebuilt in disaster recovery (normalized/transcoded audio, planet TIFs, tile caches, vision masks). Map to a separate, non-backed-up drive. Defaults to FILES_DIRECTORY if unset
FORWARDEMAIL_API_TOKEN API token for forwardemail.net
FORWARDEMAIL_RMO_ADDRESS Forward email address for RMO
FORWARDEMAIL_RMO_USERNAME Forward email SMTP username for RMO
FORWARDEMAIL_RMO_PASSWORD Forward email SMTP password for RMO
FORWARDEMAIL_NIDUS_ADDRESS Forward email address for Nidus
FORWARDEMAIL_NIDUS_USERNAME Forward email SMTP username for Nidus
FORWARDEMAIL_NIDUS_PASSWORD Forward email SMTP password for Nidus
LOB_API_KEY Lob.com API key for letter mailing services
PHONE_NUMBER_RMO RMO phone number used for reports (format: +1XXXXXXXXXX)
PHONE_NUMBER_SUPPORT Support phone number (format: +1XXXXXXXXXX)
POSTGRES_DSN DSN for connecting to the PostgreSQL database
SENTRY_DSN Sentry DSN for backend error tracking
SENTRY_DSN_FRONTEND Sentry DSN for frontend error tracking
STADIA_MAPS_API_KEY Stadia Maps API key used for geocoding and tile rendering
TEXT_PROVIDER SMS/MMS provider — must be twilio or voipms
TWILIO_ACCOUNT_SID Twilio Account SID
TWILIO_AUTH_TOKEN Twilio Auth Token
TWILIO_MESSAGING_SERVICE_SID Twilio Messaging Service SID
TWILIO_RCS_SENDER_RMO Twilio RCS sender identity for RMO
VOIPMS_NUMBER VoIP.ms phone number
VOIPMS_PASSWORD VoIP.ms password
VOIPMS_USERNAME VoIP.ms username

Optional

Variable Description
PLANET_API_TOKEN API key for the Planet Data API. If unset, Planet integration is skipped at startup
PLANET_CATALOG_CLIENT_ID OAuth2 client ID for the Planet Catalog API (requires PLANET_CATALOG_CLIENT_SECRET)
PLANET_CATALOG_CLIENT_SECRET OAuth2 client secret for the Planet Catalog API
DIGITAL_OCEAN_ACCESS_TOKEN Digital Ocean API token for vision worker auto-scaling
LAMBDA_LABS_API_KEY Lambda Labs API key for vision worker auto-scaling
VAST_AI_API_KEY Vast.ai API key for vision worker auto-scaling
VISION_WORKER_CONTAINER_IMAGE Container image URL (in the Forgejo registry) that auto-scaled instances run as the vision worker. The container defines the full worker software stack; connection and auth are injected as environment variables at instance creation. Required for auto-scaling on container-native providers (Novita AI, Vast.ai); scale-up fails before provisioning when unset
SSH_AUTHORIZED_KEYS SSH public keys to install on vision worker instances for developer debugging access. Content is appended to /root/.ssh/authorized_keys during the software install job
VERBOSE Set to any non-empty value to enable debug-level logging
PPROF_BIND Address and port for the pprof HTTP server (e.g. :6060). If unset, pprof is disabled
> DOMAIN_NIDUS=sync.nidus.cloud DOMAIN_RMO=rmo.nidus.cloud DOMAIN_TEGOLA=tegola.nidus.cloud \
  ARCGIS_CLIENT_ID=foo ARCGIS_CLIENT_SECRET=bar \
  POSTGRES_DSN='postgresql://?host=/var/run/postgresql&dbname=nidus-sync' \
  ./nidus-sync

Tile endpoint

The preferred tile endpoint is GET /api/tile/{provider}/{type}/{z}/{x}/{y}. It accepts either an operator session or a worker Bearer secret.

provider is one of:

Provider Description
stadia Stadia Maps raster basemap
planet Planet imagery (mosaics and scene items)

type depends on the provider:

Provider Type Meaning
stadia alidade_satellite Satellite imagery + labels (JPEG)
stadia alidade_smooth Muted basemap designed for overlays (PNG)
planet mosaic A Planet basemap mosaic
planet pelican Pelican constellation scene items
planet skysat SkySat constellation scene items
planet any Any Planet constellation — highest-resolution item auto-selected

The ?source= query argument narrows the underlying source:

  • stadia: ignored — the type alone selects the style.
  • planet/mosaic: a mosaic ID. When omitted, the most recent downloadable mosaic is used.
  • planet/pelican, planet/skysat, and planet/any: an item ID. When omitted, the most recent item intersecting the tile is auto-selected (constellation-filtered for pelican/skysat; highest-resolution across all constellations for any).

Planet types honor the same rendering query arguments as the legacy vision tile endpoint:

Argument Applies to Description
asset_type pelican, skysat, any Planet asset type (default ortho_analytic_sr)
transform mosaic, pelican, skysat, any blue-excess, ndwi, blue-v-red, pixel-variation
band mosaic, pelican, skysat, any Single band (1-based)
bands mosaic, pelican, skysat, any r,g,b band indices (0 = skip)
brightness mosaic, pelican, skysat, any Brightness multiplier
clip pelican, skysat, any Pass through to the item tile renderer
offset stadia, pelican, skysat, any Half-pixel-offset tile

pelican, skysat, and any also support multipart output via Accept: multipart/x-mixed-replace.

Access constraints

Tiles are area-restricted for operator sessions by organization:

  • Users of the catch-all organization are unrestricted.
  • Other users are limited to tiles intersecting their organization's service area bounding box for stadia and planet/mosaic requests, and their satellite surveillance area bounding box for planet/pelican, planet/skysat, and planet/any requests. Requests outside the applicable bounds return 403.
  • Worker requests (Bearer secret) are unrestricted.

Hacking

air

This project uses air for fast compile-and-test loops. You can run it with:

> DOMAIN_NIDUS=sync.nidus.cloud DOMAIN_RMO=rmo.nidus.cloud DOMAIN_TEGOLA=tegola.nidus.cloud \
  ARCGIS_CLIENT_ID=foo ARCGIS_CLIENT_SECRET=bar \
  POSTGRES_DSN='postgresql://?host=/var/run/postgresql&dbname=nidus-sync' air

bob

This uses the bob query framework. You can regenerate the models for bob with:

PSQL_DSN="postgresql://dbname?host=/var/run/postgresql&sslmode=disable" go run github.com/stephenafamo/bob/gen/bobgen-psql@latest"
PSQL_DSN="postgresql://?host=/var/run/postgresql&sslmode=disable&dbname=nidus-sync" go run github.com/stephenafamo/bob/gen/bobgen-psql@latest

This will generate a bunch of files. They're already committed, you only need this if you change the database schema in some way.

goose

This uses goose. You can use the goose command line to check status and make changes

> cd migrations
> GOOSE_DRIVER=postgres GOOSE_DBSTRING="dbname=nidus-sync sslmode=disable" goose status
> GOOSE_DRIVER=postgres GOOSE_DBSTRING="dbname=nidus-sync sslmode=disable" goose down
> GOOSE_DRIVER=postgres GOOSE_DBSTRING="dbname=nidus-sync sslmode=disable" goose up

svg icons

These icons are generated as part of the build system. You can generate them manually with:

pnpm generate-icons

This will produce an scss file at ts/gen/custom-icons.scss

typescript

In order to work on the TypeScript code you'll need to install the dependencies locally in your dev environment:

nix develop
pnpm install

You can then generate the TypeScript with:

pnpm watch

The only page that works right now is https://sync.nidus.cloud/template-test

watchexec

For iterating on styles

watchexec -e scss sass scss/custom.scss:static/gen/css/bootstrap.css

testing

Run integration tests (with the actual database) with something like:

POSTGRES_DSN='postgresql://?host=/var/run/postgresql&dbname=nidus-sync-test' go test -tags integration ./db/query/comms