Luigit
repositories / will

will

owned by admin

docs/deployment.md

Raw
Rendered preview

Deployment

Production deploys are platform-owned; this repo contributes configuration, the revision envelope, and conformance expectations.

Envelope

deploy/revision.schema.json binds commit + two image digests + green gates

  • build identity, issued by Luci. The platform rejects or holds a candidate whose compatibility baseline no longer matches production.

Local verification

  • mise run images builds both final images from the recorded bases.
  • mise run boot-test runs the two-container pod with fake providers and asserts readiness within 60 seconds (exits 77 without podman).

Quadlet templates

deploy/quadlet/ holds the pod + container templates the platform repins: service drops all capabilities and mounts only its data volume; agent mounts only its volume and scoped secrets, never host sockets.

Open platform work

Luci extensions and the host deploy API are tracked in deploy/contract.md; until they exist, deployment-related client calls fail closed with clear errors (see src/agent/deploy-client.ts).

# Deployment

Production deploys are platform-owned; this repo contributes configuration,
the revision envelope, and conformance expectations.

## Envelope

`deploy/revision.schema.json` binds commit + two image digests + green gates
+ build identity, issued by Luci. The platform rejects or holds a candidate
whose compatibility baseline no longer matches production.

## Local verification

- `mise run images` builds both final images from the recorded bases.
- `mise run boot-test` runs the two-container pod with fake providers and
  asserts readiness within 60 seconds (exits 77 without podman).

## Quadlet templates

`deploy/quadlet/` holds the pod + container templates the platform repins:
service drops all capabilities and mounts only its data volume; agent mounts
only its volume and scoped secrets, never host sockets.

## Open platform work

Luci extensions and the host deploy API are tracked in `deploy/contract.md`;
until they exist, deployment-related client calls fail closed with clear
errors (see `src/agent/deploy-client.ts`).