From aba2017273d02b236bfc9daf37e2c0047499df6d Mon Sep 17 00:00:00 2001 From: test Date: Sun, 30 Aug 2026 12:02:25 +0200 Subject: [PATCH] Update production deploy safeguards --- docs/deployment.md | 19 ++++++++----------- scripts/sync-safe-updated.sh | 9 ++++----- 2 files changed, 12 insertions(+), 16 deletions(-) diff --git a/docs/deployment.md b/docs/deployment.md index 6dd366a4..8ce2eb20 100644 --- a/docs/deployment.md +++ b/docs/deployment.md @@ -19,13 +19,11 @@ bash deploy.sh `bash sync.sh` remains as a legacy alias for the same flow. -Production deploys require a reproducible Git source tree by default -(`REQUIRE_CLEAN_GIT=1`). The preflight inspects staged, tracked, and -deployable untracked files; untracked paths excluded by rsync are ignored. -The local Vite build may refresh the tracked generated SSR bundle under -`bootstrap/ssr/`, but source/config/deploy changes made during preparation -abort before the release is switched. The local Git `HEAD` is captured before -build and must remain unchanged through rsync. +Deploys allow intentional test changes in the working tree by default. For a +reproducible release, opt in with `--require-clean-git` or +`REQUIRE_CLEAN_GIT=1`; that mode inspects staged, tracked, and deployable +untracked files and aborts on changes. The local Git `HEAD` is still captured +before build and checked through rsync when clean-git mode is enabled. Run the local-only guard when validating a release without creating a remote release or running rsync: @@ -34,10 +32,9 @@ release or running rsync: bash sync.sh --preflight-only ``` -`--skip-build` is rejected for a clean production deploy unless -`deploy.cmd` has just completed the Windows build and exported -`WINDOWS_FRONTEND_BUILT=1`. An explicit `REQUIRE_CLEAN_GIT=0` is reserved for -non-production/custom workflows and is not the production default. +`--skip-build` is allowed for working-tree test deploys. For clean-git mode it +is accepted only when `deploy.cmd` has just completed the Windows build and +exported `WINDOWS_FRONTEND_BUILT=1`. `deploy.cmd` runs `npm.cmd run build` on Windows first, then enters WSL for rsync/ssh. That is required when the Ubuntu distro cannot execute Windows `.exe` files (`Exec format error` on `powershell.exe`). If WSL interop does work, `bash deploy.sh` can still launch `npm.cmd` through PowerShell. Local Linux `php`/`composer` are not required for a normal deploy; Artisan and Composer run on the production server. `--with-tests` uses WSL `php` when present, otherwise Windows `php.exe`. diff --git a/scripts/sync-safe-updated.sh b/scripts/sync-safe-updated.sh index bbdb546e..30d52dfe 100644 --- a/scripts/sync-safe-updated.sh +++ b/scripts/sync-safe-updated.sh @@ -57,10 +57,9 @@ php_fpm_service="${PHP_FPM_SERVICE:-php8.4-fpm}" ssr_supervisor_program="${SSR_SUPERVISOR_PROGRAM:-skinbase-ssr}" # SSH login user stays klevze@...; remote file/composer/artisan work runs as this app user. remote_app_user="${REMOTE_APP_USER:-skinbase}" -# Production deploys must originate from a clean, reproducible source tree. -# An explicit REQUIRE_CLEAN_GIT=0 remains available for non-production/custom -# workflows, but is intentionally not the default. -require_clean_git="${REQUIRE_CLEAN_GIT:-1}" +# Test deploys may intentionally originate from the working tree. Use +# --require-clean-git or REQUIRE_CLEAN_GIT=1 when reproducibility is required. +require_clean_git="${REQUIRE_CLEAN_GIT:-0}" required_git_branch="${REQUIRED_GIT_BRANCH:-}" db_sync_remote_maintenance=0 preflight_only=0 @@ -110,7 +109,7 @@ Options: --no-rollback Disable automatic rollback to the previous release when the switched release fails before health/safe point. --reload-php-fpm Try to reload PHP-FPM after release switch. Uses PHP_FPM_SERVICE, default php8.4-fpm. --no-php-fpm-reload Explicitly skip PHP-FPM reload. - --require-clean-git Refuse deploy when the local Git working tree has uncommitted deployable changes (default). + --require-clean-git Refuse deploy when the local Git working tree has uncommitted deployable changes (opt-in). --required-branch BRANCH Refuse deploy unless the local Git branch matches BRANCH. --no-rsync-progress Disable rsync transfer progress output.