docs(adr-0019): amend for readiness-gated start and automatic rollback #102
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-docs!102
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "work/62"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
ADR 0019 records the deploy mechanism: CI builds and pushes an image, the services host pulls it via
podman auto-update, CI never touches production. Still true. The mechanism has since gained two properties the ADR did not describe, and both change what a deploy means.The amendment records:
Notify=healthywith a healthcheck against/healthz, which checks the Node process is up and Postgres answersselect 1. A start that never becomes ready fails instead of silently serving a broken container.podman auto-update.podman auto-updateexits 0 whether it deployed or rolled back, so a successful run can mean nothing shipped; a rollback reverts the image but not a migration; web start now depends on Postgres answering, and fails closed during a Postgres outage.Two Consequences bullets updated to point at it.
Verified against source, not against the issue body:
roles/web/templates/bitborg-web.container.j2forNotify=healthyand the healthcheck,bitborg-web/src/lib/health.tsandsrc/pages/healthz.tsfor what/healthzchecks.The issue's caveat is stale. It said the rollback was verified on podman 5.8.3 but not rehearsed on production's 5.4.2. The runbook's recorded-results table now carries both rows, dated 2026-08-01, and names the 5.4.2 row the load-bearing one. The amendment describes the rollback as rehearsed on a throwaway VM matching production's version, never on production itself.
The post-deploy probe and the Grafana deploy annotation are observability, not mechanism, and are left out.
Closes #62
a2903698346be7b993f5