All checks were successful
CD / Build and push images (push) Successful in 1m8s
CD / Deploy to Test (push) Successful in 9s
CD / Smoke tests against Test (push) Successful in 1m11s
CD / Promote to Int (push) Successful in 10s
CI / Lint, typecheck, test (push) Successful in 4m3s
CI / Build container images (push) Has been skipped
CI / Auth e2e pack (push) Successful in 5m34s
CI / Import/export fidelity gate (push) Successful in 47s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EwZ4jR4KFAPvpjWevfUGX1
3.4 KiB
3.4 KiB
Go-live checklist — dorfteich.online (issue #89)
The release pipeline and the Prod stack are ready; going live is the operator's call. Executed items carry their date; unchecked items block the DNS switch.
Release mechanics (in place)
- 2026-07-12 — Release workflow: pushing
vX.Y.Zbuilds the four semver images and publishes a Gitea release whose notes list the changes since the previous release and call out database migrations. (Notes derive from commit subjects — the repo is trunk-based without PRs; the issue's "PR titles" have no source here, documented deviation.) - 2026-07-12 — Manual gate + Prod deploy: pushing
prod-vX.Y.Z-<suffix>(the human approval — Gitea 1.22 has no environment gates; revisit on 1.23+) verifies the release images exist, pinsTAGin the Prod.env, pulls, restarts, and waits for readiness. Re-deploys/rollbacks are new suffix tags on the target release. - 2026-07-12 — Prod stack provisioned on ONE
(
/home/DOCKER/dorfteich-prod/, ports 8120–8122, secrets generated on the host, full backup profile: 30 d retention, failure mail). The host decision "ONE" is the working default — recorded here; if the owner picks different iron at go-live, the stack directory moves per the restore runbook's relocation procedure. - 2026-07-12 — Test release walked the full gate:
v0.1.0built and published →prod-v0.1.0-initialdeployed → readyz green. - 2026-07-12 — Rollback tested on Prod:
v0.1.1deployed, thenprod-v0.1.0-rollback1returned the stack tov0.1.0, readyz green (one-release downgrade window per docs/self-hosting).
Operator items (block the DNS switch)
- Prod host decision confirmed (working default: ONE, where Test/Int and the registry already live — one host, no BASEL yet).
- DNS: point
dorfteich.onlineat ONE (today it still points at the old VPS188.245.116.44). - Caddy: activate the prepared
dorfteich.onlineblock in/etc/caddy/Caddyfileon ONE (ports 8120–8122) after DNS,systemctl reload caddy, verify the Let's Encrypt certificate — this also closes the #88 item "ACME exercised on a real domain". - First-run setup: run the wizard on the fresh instance (or set
the
SETUP_ADMIN_*preseed in the Prod.envbefore first boot) — creates the Site Admin. - Prod SMTP: configure a production relay (wizard step or
.env); the Prod.envships without SMTP on purpose. - Legal texts (#82): paste the real dorfteich.online imprint and privacy policy in Administration → Legal pages.
- Monitors (#85): create the Prod monitor set from
deploy/monitoring.mdin Uptime-Kuma, with alerting; verify one test alert fires. - Backups verified on Prod (#87): switch the drill's
DRILL_SOURCE_VOLUMEtodorfteich-prod_backupsand run one on-demand drill (drill-*tag) green. - Off-host mirror (#84, done 2026-07-12): tunnel fixed, BASEL
provisioned (
deploy/backup-basel.md), mirror live on Test AND on Prod since the v0.2.0 deploy (first run verified: all sets on BASEL,status.json → mirror.lastRun = succeeded). - Optional hygiene: a dedicated
DEPLOY_SSH_KEY_PRODsecret (the workflows currently reuse the host-wide deploy key stored asDEPLOY_SSH_KEY_TEST).