Manual-promotion workflow + post-apply prod health gate #107

Stängd
öppnade 2026-07-18 15:01:10 +00:00 av supernaut · 1 kommentar
Ägare

Tier 2 — process + a safety net on prod itself.

  • Document the promotion flow in the runbook: trunk-based, merge to main → apply + smoke on ephemeral staging (for risky changes) → human-approved prod apply. No env branches.
  • Add a post-apply health gate to the prod apply flow: after site.yml, assert containers are active + public endpoints serve (extend the existing running-image verify into a real smoke check), and halt loudly / auto-recover if not — so a bad apply is caught in seconds, not by users. (The #94 verify failed after the outage; this makes the check block the failure mode earlier and pairs with the migration choreography.)
  • Bake "stage risky infra changes before prod" into the infra-apply skill + runbook, with a short checklist of what counts as risky (socket/port/capability/network/app.ini/image-tag).

Depends on Tier 0 (smoke assertions) and Tier 1 (staging target).

Epic: gitborg/gitborg-docs#37

**Tier 2 — process + a safety net on prod itself.** - Document the promotion flow in the runbook: trunk-based, merge to `main` → apply + smoke on ephemeral staging (for risky changes) → **human-approved** prod apply. No env branches. - Add a **post-apply health gate** to the prod apply flow: after `site.yml`, assert containers are `active` + public endpoints serve (extend the existing running-image verify into a real smoke check), and **halt loudly / auto-recover** if not — so a bad apply is caught in seconds, not by users. (The #94 verify failed *after* the outage; this makes the check block the failure mode earlier and pairs with the migration choreography.) - Bake "stage risky infra changes before prod" into the `infra-apply` skill + runbook, with a short checklist of what counts as risky (socket/port/capability/network/app.ini/image-tag). Depends on Tier 0 (smoke assertions) and Tier 1 (staging target). Epic: gitborg/gitborg-docs#37
Upphovsperson
Ägare

Scope confirmed by ADR 0030 (accepted) — this is the near-term build (Tier-2). Three parts:

  1. Post-apply health gate — a final play in site.yml, host-scoped core-liveness: bitborg host = forgejo/postgres/caddy/kanidm/web containers active + www/git/auth serve + node_textfile_scrape_error==0; monitoring host = its containers + health endpoints. Halt + alert on any miss; no auto-rollback (fix-forward). Excludes the standing monitoring alert set (backup volume/drill) to avoid false-fails. Skipped under --check.
  2. main branch protection — require the ci workflow green before merge (review soft — solo operator).
  3. Runbook — the rehearse-first rule for major Postgres/Forgejo upgrades (restore-drill clone first), and the trunk-based/gated-promotion note.

(The Tier-1 staging + env-layering pieces this issue used to imply are deferred — see #103/#105/#106.)

Scope confirmed by ADR 0030 (accepted) — this is the near-term build (Tier-2). Three parts: 1. **Post-apply health gate** — a final play in `site.yml`, **host-scoped core-liveness**: bitborg host = `forgejo`/`postgres`/`caddy`/`kanidm`/`web` containers `active` + www/git/auth serve + `node_textfile_scrape_error==0`; monitoring host = its containers + health endpoints. **Halt + alert on any miss; no auto-rollback** (fix-forward). Excludes the standing monitoring alert set (backup volume/drill) to avoid false-fails. Skipped under `--check`. 2. **`main` branch protection** — require the `ci` workflow green before merge (review soft — solo operator). 3. **Runbook** — the rehearse-first rule for major Postgres/Forgejo upgrades (restore-drill clone first), and the trunk-based/gated-promotion note. (The Tier-1 staging + env-layering pieces this issue used to imply are deferred — see #103/#105/#106.)
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#107
Ingen beskrivning angiven.