fix(deploy): ship tested AI service
This commit is contained in:
@@ -155,6 +155,7 @@ jobs:
|
|||||||
git reset --hard ${{ github.sha }}
|
git reset --hard ${{ github.sha }}
|
||||||
git clean -fd
|
git clean -fd
|
||||||
chmod +x deploy/deploy.sh
|
chmod +x deploy/deploy.sh
|
||||||
|
DEPLOY_BUILD_AI_SERVICE=true \
|
||||||
APP_VERSION=${{ github.run_number }} \
|
APP_VERSION=${{ github.run_number }} \
|
||||||
APP_COMMIT_SHA=${{ github.sha }} \
|
APP_COMMIT_SHA=${{ github.sha }} \
|
||||||
APP_BUILD_STAMP="$(date -u +'%Y-%m-%d %H:%M UTC')" \
|
APP_BUILD_STAMP="$(date -u +'%Y-%m-%d %H:%M UTC')" \
|
||||||
|
|||||||
@@ -3,10 +3,12 @@
|
|||||||
Production runs the frontend/nginx, ASP.NET API, AI sidecar, and configured database through Docker
|
Production runs the frontend/nginx, ASP.NET API, AI sidecar, and configured database through Docker
|
||||||
Compose. The backend is not published directly; nginx proxies `/api`. `deploy/deploy.sh` validates
|
Compose. The backend is not published directly; nginx proxies `/api`. `deploy/deploy.sh` validates
|
||||||
configuration, takes and verifies a provider-appropriate backup before replacement, builds/restarts the
|
configuration, takes and verifies a provider-appropriate backup before replacement, builds/restarts the
|
||||||
stack, and performs health checks.
|
stack, and performs health checks. The protected production workflow explicitly rebuilds the AI sidecar
|
||||||
|
so application and AI contracts always come from the same tested commit.
|
||||||
|
|
||||||
Production commands explicitly select `docker-compose.yml`; it publishes no application ports.
|
Production commands explicitly select `docker-compose.yml`. The operator-owned reverse proxy still
|
||||||
Traefik reaches frontend/nginx over `jobtracker_shared`, must match the canonical Host exactly, and
|
targets frontend/nginx through compatibility port 3000; the host firewall blocks direct external access.
|
||||||
|
Traefik must match the canonical Host exactly and
|
||||||
must replace `X-Forwarded-For` and `X-Forwarded-Proto`. Nginx passes those sanitized values to the
|
must replace `X-Forwarded-For` and `X-Forwarded-Proto`. Nginx passes those sanitized values to the
|
||||||
backend over the dedicated `WEB_PROXY_SUBNET`; nginx also derives its only application server name
|
backend over the dedicated `WEB_PROXY_SUBNET`; nginx also derives its only application server name
|
||||||
from `APP_PUBLIC_BASE_URL` and rejects unknown Hosts except its liveness endpoint. The backend trusts
|
from `APP_PUBLIC_BASE_URL` and rejects unknown Hosts except its liveness endpoint. The backend trusts
|
||||||
|
|||||||
Reference in New Issue
Block a user