Update production deploy safeguards
This commit is contained in:
+8
-11
@@ -19,13 +19,11 @@ bash deploy.sh
|
|||||||
|
|
||||||
`bash sync.sh` remains as a legacy alias for the same flow.
|
`bash sync.sh` remains as a legacy alias for the same flow.
|
||||||
|
|
||||||
Production deploys require a reproducible Git source tree by default
|
Deploys allow intentional test changes in the working tree by default. For a
|
||||||
(`REQUIRE_CLEAN_GIT=1`). The preflight inspects staged, tracked, and
|
reproducible release, opt in with `--require-clean-git` or
|
||||||
deployable untracked files; untracked paths excluded by rsync are ignored.
|
`REQUIRE_CLEAN_GIT=1`; that mode inspects staged, tracked, and deployable
|
||||||
The local Vite build may refresh the tracked generated SSR bundle under
|
untracked files and aborts on changes. The local Git `HEAD` is still captured
|
||||||
`bootstrap/ssr/`, but source/config/deploy changes made during preparation
|
before build and checked through rsync when clean-git mode is enabled.
|
||||||
abort before the release is switched. The local Git `HEAD` is captured before
|
|
||||||
build and must remain unchanged through rsync.
|
|
||||||
|
|
||||||
Run the local-only guard when validating a release without creating a remote
|
Run the local-only guard when validating a release without creating a remote
|
||||||
release or running rsync:
|
release or running rsync:
|
||||||
@@ -34,10 +32,9 @@ release or running rsync:
|
|||||||
bash sync.sh --preflight-only
|
bash sync.sh --preflight-only
|
||||||
```
|
```
|
||||||
|
|
||||||
`--skip-build` is rejected for a clean production deploy unless
|
`--skip-build` is allowed for working-tree test deploys. For clean-git mode it
|
||||||
`deploy.cmd` has just completed the Windows build and exported
|
is accepted only when `deploy.cmd` has just completed the Windows build and
|
||||||
`WINDOWS_FRONTEND_BUILT=1`. An explicit `REQUIRE_CLEAN_GIT=0` is reserved for
|
exported `WINDOWS_FRONTEND_BUILT=1`.
|
||||||
non-production/custom workflows and is not the production default.
|
|
||||||
|
|
||||||
`deploy.cmd` runs `npm.cmd run build` on Windows first, then enters WSL for rsync/ssh. That is required when the Ubuntu distro cannot execute Windows `.exe` files (`Exec format error` on `powershell.exe`). If WSL interop does work, `bash deploy.sh` can still launch `npm.cmd` through PowerShell. Local Linux `php`/`composer` are not required for a normal deploy; Artisan and Composer run on the production server. `--with-tests` uses WSL `php` when present, otherwise Windows `php.exe`.
|
`deploy.cmd` runs `npm.cmd run build` on Windows first, then enters WSL for rsync/ssh. That is required when the Ubuntu distro cannot execute Windows `.exe` files (`Exec format error` on `powershell.exe`). If WSL interop does work, `bash deploy.sh` can still launch `npm.cmd` through PowerShell. Local Linux `php`/`composer` are not required for a normal deploy; Artisan and Composer run on the production server. `--with-tests` uses WSL `php` when present, otherwise Windows `php.exe`.
|
||||||
|
|
||||||
|
|||||||
@@ -57,10 +57,9 @@ php_fpm_service="${PHP_FPM_SERVICE:-php8.4-fpm}"
|
|||||||
ssr_supervisor_program="${SSR_SUPERVISOR_PROGRAM:-skinbase-ssr}"
|
ssr_supervisor_program="${SSR_SUPERVISOR_PROGRAM:-skinbase-ssr}"
|
||||||
# SSH login user stays klevze@...; remote file/composer/artisan work runs as this app user.
|
# SSH login user stays klevze@...; remote file/composer/artisan work runs as this app user.
|
||||||
remote_app_user="${REMOTE_APP_USER:-skinbase}"
|
remote_app_user="${REMOTE_APP_USER:-skinbase}"
|
||||||
# Production deploys must originate from a clean, reproducible source tree.
|
# Test deploys may intentionally originate from the working tree. Use
|
||||||
# An explicit REQUIRE_CLEAN_GIT=0 remains available for non-production/custom
|
# --require-clean-git or REQUIRE_CLEAN_GIT=1 when reproducibility is required.
|
||||||
# workflows, but is intentionally not the default.
|
require_clean_git="${REQUIRE_CLEAN_GIT:-0}"
|
||||||
require_clean_git="${REQUIRE_CLEAN_GIT:-1}"
|
|
||||||
required_git_branch="${REQUIRED_GIT_BRANCH:-}"
|
required_git_branch="${REQUIRED_GIT_BRANCH:-}"
|
||||||
db_sync_remote_maintenance=0
|
db_sync_remote_maintenance=0
|
||||||
preflight_only=0
|
preflight_only=0
|
||||||
@@ -110,7 +109,7 @@ Options:
|
|||||||
--no-rollback Disable automatic rollback to the previous release when the switched release fails before health/safe point.
|
--no-rollback Disable automatic rollback to the previous release when the switched release fails before health/safe point.
|
||||||
--reload-php-fpm Try to reload PHP-FPM after release switch. Uses PHP_FPM_SERVICE, default php8.4-fpm.
|
--reload-php-fpm Try to reload PHP-FPM after release switch. Uses PHP_FPM_SERVICE, default php8.4-fpm.
|
||||||
--no-php-fpm-reload Explicitly skip PHP-FPM reload.
|
--no-php-fpm-reload Explicitly skip PHP-FPM reload.
|
||||||
--require-clean-git Refuse deploy when the local Git working tree has uncommitted deployable changes (default).
|
--require-clean-git Refuse deploy when the local Git working tree has uncommitted deployable changes (opt-in).
|
||||||
--required-branch BRANCH
|
--required-branch BRANCH
|
||||||
Refuse deploy unless the local Git branch matches BRANCH.
|
Refuse deploy unless the local Git branch matches BRANCH.
|
||||||
--no-rsync-progress Disable rsync transfer progress output.
|
--no-rsync-progress Disable rsync transfer progress output.
|
||||||
|
|||||||
Reference in New Issue
Block a user