# Guía de Despliegue

## Desarrollo Local

```bash
# Clonar proyecto y entrar
cd swift-converter

# Crear y activar entorno virtual
python3.11 -m venv venv
source venv/bin/activate

# Instalar dependencias
pip install -r requirements.txt

# Configurar variables de entorno
cp .env.example .env
# Editar .env con valores reales

# Iniciar servidor con hot-reload
uvicorn app.main:app --reload --port 8000
```

## Variables de Entorno

| Variable | Descripción | Valor por defecto |
|---|---|---|
| `SECRET_KEY` | Clave secreta para firmar JWT (≥32 chars) | `dev-secret-key-...` |
| `ADMIN_SECRET` | Header requerido para endpoints admin | `dev-admin-secret-...` |
| `DATABASE_URL` | URL de SQLAlchemy | `sqlite:///./swift.db` |
| `JWT_ALGORITHM` | Algoritmo JWT | `HS256` |
| `JWT_EXPIRE_MINUTES` | Expiración del token en minutos | `15` |
| `RATE_LIMIT_DEFAULT` | Límite por defecto req/min | `100` |
| `API_VERSION` | Versión del prefijo de rutas | `v1` |
| `ENVIRONMENT` | `development` o `production` | `development` |

> ⚠️ En producción: cambiar `SECRET_KEY`, `ADMIN_SECRET` y usar PostgreSQL.

## Docker

### Build y Run

```bash
# Construir imagen
docker build -t swift-converter .

# Ejecutar con .env
docker run -p 8000:8000 --env-file .env swift-converter

# Con variables inline
docker run -p 8000:8000 \
  -e SECRET_KEY=mi-clave-secreta-produccion \
  -e ADMIN_SECRET=mi-admin-secret \
  -e DATABASE_URL=postgresql://user:pass@host:5432/swiftdb \
  -e ENVIRONMENT=production \
  swift-converter
```

### Docker Compose (ejemplo)

```yaml
version: "3.9"
services:
  api:
    build: .
    ports:
      - "8000:8000"
    environment:
      DATABASE_URL: postgresql://swift:secret@db:5432/swiftdb
      SECRET_KEY: ${SECRET_KEY}
      ADMIN_SECRET: ${ADMIN_SECRET}
      ENVIRONMENT: production
    depends_on:
      - db

  db:
    image: postgres:16-alpine
    environment:
      POSTGRES_DB: swiftdb
      POSTGRES_USER: swift
      POSTGRES_PASSWORD: secret
    volumes:
      - pgdata:/var/lib/postgresql/data

volumes:
  pgdata:
```

## Migración a PostgreSQL

1. Cambiar `DATABASE_URL` en `.env`:
   ```
   DATABASE_URL=postgresql://user:password@localhost:5432/swiftdb
   ```

2. Instalar driver:
   ```bash
   pip install psycopg2-binary
   ```

3. Las tablas se crean automáticamente al arrancar (via `create_tables()` en lifespan).

## Producción: Checklist

- [ ] `SECRET_KEY` con mínimo 32 caracteres aleatorios: `openssl rand -hex 32`
- [ ] `ADMIN_SECRET` diferente al de desarrollo
- [ ] `ENVIRONMENT=production` (restringe CORS)
- [ ] `DATABASE_URL` apuntando a PostgreSQL
- [ ] HTTPS via reverse proxy (nginx/caddy)
- [ ] Monitoreo de `/api/v1/health`
- [ ] Backup de la BD periódico
- [ ] Rate limiting configurado en el proxy también (defense in depth)

## Generar Claves Seguras

```bash
# SECRET_KEY
openssl rand -hex 32

# ADMIN_SECRET
openssl rand -base64 24
```

## Tests

```bash
source venv/bin/activate
pytest tests/ -v

# Con coverage
pytest tests/ -v --cov=app --cov-report=term-missing
```
