Tier 1: ephemeral OpenStack staging host (boot → site.yml → smoke → destroy) #105

Öppen
öppnade 2026-07-18 15:01:09 +00:00 av supernaut · 1 kommentar
Ägare

Tier 1 — on-demand prod-parity staging, no standing cost. Reuse the existing throwaway-VM machinery (ephemeral-runner ADR 0021 tofu + cloud-init; restore-drill ADR 0027 boot→do→destroy flow) to:

  1. tofu apply a single staging VM on a dedicated network/SG (staging_count var, default 0 → $0 when idle).
  2. Run ansible-playbook site.yml against it with the staging inventory (from the layering task).
  3. Smoke-test (Tier 0 assertions, plus real TLS + real systemd + pasta networking that CI can't model).
  4. tofu destroy the VM.

Includes staging DNS + TLS: a staging domain (e.g. *.stg.gitborg.se or an nip.io fallback) and the Let's Encrypt staging ACME directory (caddy_acme_ca override in group_vars/staging) to avoid burning prod LE rate limits.

Run before prod for risky changes (socket/networking/capability/app.ini). A one-shot pnpm/make wrapper + optional CI trigger.

Epic: gitborg/gitborg-docs#37

**Tier 1 — on-demand prod-parity staging, no standing cost.** Reuse the existing throwaway-VM machinery (ephemeral-runner ADR 0021 tofu + cloud-init; restore-drill ADR 0027 boot→do→destroy flow) to: 1. `tofu apply` a single staging VM on a dedicated network/SG (`staging_count` var, default 0 → $0 when idle). 2. Run `ansible-playbook site.yml` against it with the `staging` inventory (from the layering task). 3. Smoke-test (Tier 0 assertions, plus real TLS + real systemd + pasta networking that CI can't model). 4. `tofu destroy` the VM. Includes staging DNS + TLS: a staging domain (e.g. `*.stg.gitborg.se` or an nip.io fallback) and the **Let's Encrypt staging** ACME directory (`caddy_acme_ca` override in `group_vars/staging`) to avoid burning prod LE rate limits. Run before prod for risky changes (socket/networking/capability/app.ini). A one-shot pnpm/make wrapper + optional CI trigger. Epic: gitborg/gitborg-docs#37
Upphovsperson
Ägare

Deferred per ADR 0030 — Tier-1 full staging and the prod/staging env split are last-ditch/optional: documented as the target shape but built only when a real-host-only failure actually demands it (the restore-drill clone covers the irreversible-upgrade case first). Kept in Backlog; not scheduled. See bitborg-docs/decisions/0030-environments-and-promotion.md.

**Deferred per ADR 0030** — Tier-1 full staging and the prod/staging env split are last-ditch/optional: documented as the target shape but built only when a real-host-only failure actually demands it (the restore-drill clone covers the irreversible-upgrade case first). Kept in Backlog; not scheduled. See `bitborg-docs/decisions/0030-environments-and-promotion.md`.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#105
Ingen beskrivning angiven.