Update production deploy safeguards

This commit is contained in:
test
2026-08-30 12:02:25 +02:00
parent 937f484cc9
commit aba2017273
2 changed files with 12 additions and 16 deletions
+4 -5
View File
@@ -57,10 +57,9 @@ php_fpm_service="${PHP_FPM_SERVICE:-php8.4-fpm}"
ssr_supervisor_program="${SSR_SUPERVISOR_PROGRAM:-skinbase-ssr}"
# SSH login user stays klevze@...; remote file/composer/artisan work runs as this app user.
remote_app_user="${REMOTE_APP_USER:-skinbase}"
# Production deploys must originate from a clean, reproducible source tree.
# An explicit REQUIRE_CLEAN_GIT=0 remains available for non-production/custom
# workflows, but is intentionally not the default.
require_clean_git="${REQUIRE_CLEAN_GIT:-1}"
# Test deploys may intentionally originate from the working tree. Use
# --require-clean-git or REQUIRE_CLEAN_GIT=1 when reproducibility is required.
require_clean_git="${REQUIRE_CLEAN_GIT:-0}"
required_git_branch="${REQUIRED_GIT_BRANCH:-}"
db_sync_remote_maintenance=0
preflight_only=0
@@ -110,7 +109,7 @@ Options:
--no-rollback Disable automatic rollback to the previous release when the switched release fails before health/safe point.
--reload-php-fpm Try to reload PHP-FPM after release switch. Uses PHP_FPM_SERVICE, default php8.4-fpm.
--no-php-fpm-reload Explicitly skip PHP-FPM reload.
--require-clean-git Refuse deploy when the local Git working tree has uncommitted deployable changes (default).
--require-clean-git Refuse deploy when the local Git working tree has uncommitted deployable changes (opt-in).
--required-branch BRANCH
Refuse deploy unless the local Git branch matches BRANCH.
--no-rsync-progress Disable rsync transfer progress output.