test: gate unified compose deployment
This commit is contained in:
@@ -3,6 +3,35 @@
|
||||
> Starting-point snapshot for new sessions. Last updated: 2026-08-05 (portable deployment decoupled).
|
||||
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
|
||||
|
||||
## Unified deployment release gate — Task 13 (2026-08-05)
|
||||
|
||||
- **Release coverage.** `scripts/unified-deployment-smoke.sh` gates the two-service render/build,
|
||||
frontend-to-core routing, embedded pinned Pi, Git registry bootstrap, offline recreation, valid
|
||||
update, invalid-update retention, and the four persistent stores. `scripts/thothctl-update-smoke.sh`
|
||||
independently exercises the bad-Pi update and automatic rollback path.
|
||||
- **Isolation and disclosure boundary.** Every run generates a unique temporary root, Compose
|
||||
project, container/image names, transaction image tags, and run label. The rollback fixture uses
|
||||
an immutable public digest as a deliberately dead core rather than a host-local image registry.
|
||||
Cleanup checks ownership before removing exact containers, Compose resources, image references,
|
||||
control state, and temporary files. There is no global prune. Failure diagnostics are bounded
|
||||
and sanitized, and all credentials/endpoints used by the smokes are disposable fixtures rather
|
||||
than operator or repository secrets.
|
||||
- **Cross-platform CI contract.** `.github/workflows/deployment.yml` uses immutable action commits,
|
||||
pinned supported Node and Go versions, runs LF/Compose/secret/coupling/docs/TypeScript gates on
|
||||
Linux, runs each Docker smoke once under its own outer timeout, and builds/invokes native Windows
|
||||
`thothctl` after the PowerShell clone/LF/Compose contract. Native Windows execution remains an
|
||||
explicit manual release gate in addition to CI; no Windows Docker container startup is claimed
|
||||
by the static clone job.
|
||||
- **Validation status.** Deterministic Phase A gates, backend **434/434** plus TypeScript,
|
||||
frontend **386/386** plus TypeScript, and harness **862 passed / 5 L2 deselected** are green.
|
||||
The unified one-shot Docker run passed frontend/core/internal Pi, registry bootstrap, offline
|
||||
recreation, valid update, invalid-update retention, and persistence before Docker Desktop
|
||||
refused the daemon-to-host local-registry push; the update-only run reached the same boundary.
|
||||
Both exact run/project resource sets were independently proved absent. The local-registry
|
||||
fixture was then removed in favor of the immutable dead-core digest, but the requested no-retry
|
||||
rule leaves automatic rollback/preservation pending in CI or a fresh manual release run. Native
|
||||
Windows PowerShell execution is also still a manual release gate.
|
||||
|
||||
## Portable deployment decoupling — LIVE 2026-08-05
|
||||
|
||||
- **Mandatory stack.** The supported Compose stack is exactly `frontend` plus `core`; use the
|
||||
|
||||
Reference in New Issue
Block a user