dorfteich/deploy/go-live.md
Claude Fable 5 28f05e270d
All checks were successful
CD / Build and push images (push) Successful in 1m5s
CD / Deploy to Test (push) Successful in 9s
CD / Smoke tests against Test (push) Successful in 1m6s
CD / Promote to Int (push) Successful in 10s
CI / Lint, typecheck, test (push) Successful in 3m33s
CI / Build container images (push) Has been skipped
Release / Build release images and notes (push) Successful in 1m1s
Prod deploy / Deploy the released images to Prod (push) Successful in 14s
CI / Auth e2e pack (push) Successful in 5m31s
CI / Import/export fidelity gate (push) Successful in 47s
Add the release pipeline with a tag-based manual gate and Prod stack (#89)
Pushing vX.Y.Z builds the four semver images and publishes a Gitea
release whose notes list the changes since the previous release with a
migration call-out derived from the migrations diff (the repo is
trunk-based — commit subjects stand in for PR titles). Deploying to Prod
is a separate human act: pushing prod-vX.Y.Z-<suffix> — Gitea 1.22 has
no environment approvals, so the tag push is the gate — verifies the
release images exist, pins TAG in the Prod .env, restarts the stack, and
waits for readiness; rollbacks are new suffix tags on the previous
release. The Prod stage is provisioned on ONE (ports 8120-8122, secrets
generated on the host, full backup profile); deploy/go-live.md carries
the executed mechanics and the operator checklist that blocks the DNS
switch (DNS, Caddy block, wizard/SMTP, legal texts, monitors, Prod
drill, BASEL mirror).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EwZ4jR4KFAPvpjWevfUGX1
2026-07-12 00:17:13 +02:00

3.4 KiB
Raw Blame History

Go-live checklist — dorfteich.online (issue #89)

The release pipeline and the Prod stack are ready; going live is the operator's call. Executed items carry their date; unchecked items block the DNS switch.

Release mechanics (in place)

  • 2026-07-12 — Release workflow: pushing vX.Y.Z builds the four semver images and publishes a Gitea release whose notes list the changes since the previous release and call out database migrations. (Notes derive from commit subjects — the repo is trunk-based without PRs; the issue's "PR titles" have no source here, documented deviation.)
  • 2026-07-12 — Manual gate + Prod deploy: pushing prod-vX.Y.Z-<suffix> (the human approval — Gitea 1.22 has no environment gates; revisit on 1.23+) verifies the release images exist, pins TAG in the Prod .env, pulls, restarts, and waits for readiness. Re-deploys/rollbacks are new suffix tags on the target release.
  • 2026-07-12 — Prod stack provisioned on ONE (/home/DOCKER/dorfteich-prod/, ports 81208122, secrets generated on the host, full backup profile: 30 d retention, failure mail). The host decision "ONE" is the working default — recorded here; if the owner picks different iron at go-live, the stack directory moves per the restore runbook's relocation procedure.
  • 2026-07-12 — Test release walked the full gate: v0.1.0 built and published → prod-v0.1.0-initial deployed → readyz green.
  • 2026-07-12 — Rollback tested on Prod: v0.1.1 deployed, then prod-v0.1.0-rollback1 returned the stack to v0.1.0, readyz green (one-release downgrade window per docs/self-hosting).

Operator items (block the DNS switch)

  • Prod host decision confirmed (working default: ONE, where Test/Int and the registry already live — one host, no BASEL yet).
  • DNS: point dorfteich.online at ONE (today it still points at the old VPS 188.245.116.44).
  • Caddy: activate the prepared dorfteich.online block in /etc/caddy/Caddyfile on ONE (ports 81208122) after DNS, systemctl reload caddy, verify the Let's Encrypt certificate — this also closes the #88 item "ACME exercised on a real domain".
  • First-run setup: run the wizard on the fresh instance (or set the SETUP_ADMIN_* preseed in the Prod .env before first boot) — creates the Site Admin.
  • Prod SMTP: configure a production relay (wizard step or .env); the Prod .env ships without SMTP on purpose.
  • Legal texts (#82): paste the real dorfteich.online imprint and privacy policy in Administration → Legal pages.
  • Monitors (#85): create the Prod monitor set from deploy/monitoring.md in Uptime-Kuma, with alerting; verify one test alert fires.
  • Backups verified on Prod (#87): switch the drill's DRILL_SOURCE_VOLUME to dorfteich-prod_backups and run one on-demand drill (drill-* tag) green.
  • Off-host mirror (#84): blocked on the ONE→BASEL WireGuard tunnel (Handoff-Wireguard.md) — going live without it is a conscious, temporary risk acceptance (local 30 d backups only).
  • Optional hygiene: a dedicated DEPLOY_SSH_KEY_PROD secret (the workflows currently reuse the host-wide deploy key stored as DEPLOY_SSH_KEY_TEST).