dorfteich/deploy/go-live.md
Claude Fable 5 203f7c98a5
All checks were successful
CD / Build and push images (push) Successful in 1m10s
CD / Deploy to Test (push) Successful in 10s
CD / Smoke tests against Test (push) Successful in 1m10s
CD / Promote to Int (push) Successful in 10s
CI / Lint, typecheck, test (push) Successful in 4m2s
CI / Build container images (push) Has been skipped
CI / Auth e2e pack (push) Successful in 5m36s
CI / Import/export fidelity gate (push) Successful in 46s
Tick the go-live mirror item: BASEL mirror live on Test, Prod prepared (#84)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EwZ4jR4KFAPvpjWevfUGX1
2026-07-12 12:33:00 +02:00

64 lines
3.5 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Go-live checklist — dorfteich.online (issue #89)
The release pipeline and the Prod stack are ready; going live is the
operator's call. Executed items carry their date; unchecked items block
the DNS switch.
## Release mechanics (in place)
- [x] 2026-07-12 — **Release workflow**: pushing `vX.Y.Z` builds the four
semver images and publishes a Gitea release whose notes list the
changes since the previous release and call out database
migrations. (Notes derive from commit subjects — the repo is
trunk-based without PRs; the issue's "PR titles" have no source
here, documented deviation.)
- [x] 2026-07-12 — **Manual gate + Prod deploy**: pushing
`prod-vX.Y.Z-<suffix>` (the human approval — Gitea 1.22 has no
environment gates; revisit on 1.23+) verifies the release images
exist, pins `TAG` in the Prod `.env`, pulls, restarts, and waits
for readiness. Re-deploys/rollbacks are new suffix tags on the
target release.
- [x] 2026-07-12 — **Prod stack provisioned** on ONE
(`/home/DOCKER/dorfteich-prod/`, ports 81208122, secrets generated
on the host, full backup profile: 30 d retention, failure mail).
The host decision "ONE" is the working default — recorded here; if
the owner picks different iron at go-live, the stack directory
moves per the restore runbook's relocation procedure.
- [x] 2026-07-12 — **Test release walked the full gate**: `v0.1.0` built
and published → `prod-v0.1.0-initial` deployed → readyz green.
- [x] 2026-07-12 — **Rollback tested on Prod**: `v0.1.1` deployed, then
`prod-v0.1.0-rollback1` returned the stack to `v0.1.0`, readyz
green (one-release downgrade window per docs/self-hosting).
## Operator items (block the DNS switch)
- [ ] **Prod host decision confirmed** (working default: ONE, where
Test/Int and the registry already live — one host, no BASEL yet).
- [ ] **DNS**: point `dorfteich.online` at ONE (today it still points at
the old VPS `188.245.116.44`).
- [ ] **Caddy**: activate the prepared `dorfteich.online` block in
`/etc/caddy/Caddyfile` on ONE (ports 81208122) after DNS,
`systemctl reload caddy`, verify the Let's Encrypt certificate —
this also closes the #88 item "ACME exercised on a real domain".
- [ ] **First-run setup**: run the wizard on the fresh instance (or set
the `SETUP_ADMIN_*` preseed in the Prod `.env` before first boot) —
creates the Site Admin.
- [ ] **Prod SMTP**: configure a production relay (wizard step or `.env`);
the Prod `.env` ships without SMTP on purpose.
- [ ] **Legal texts** (#82): paste the real dorfteich.online imprint and
privacy policy in Administration → Legal pages.
- [ ] **Monitors** (#85): create the Prod monitor set from
`deploy/monitoring.md` in Uptime-Kuma, with alerting; verify one
test alert fires.
- [ ] **Backups verified on Prod** (#87): switch the drill's
`DRILL_SOURCE_VOLUME` to `dorfteich-prod_backups` and run one
on-demand drill (`drill-*` tag) green.
- [x] **Off-host mirror** (#84, done 2026-07-12): tunnel fixed, BASEL
provisioned (`deploy/backup-basel.md`), mirror live on Test; the
Prod stack's `.env`/compose/key are already prepared — the mirror
activates automatically with the first release deploy that carries
the #84 sidecar (verify `status.json → mirror` afterwards).
- [ ] Optional hygiene: a dedicated `DEPLOY_SSH_KEY_PROD` secret (the
workflows currently reuse the host-wide deploy key stored as
`DEPLOY_SSH_KEY_TEST`).