Document isolated development SMTP verification

This commit is contained in:
SimpleTest 2026-07-23 22:22:28 +03:00
parent ca766dc1d3
commit 27bcb7188e

View File

@ -16,6 +16,23 @@ edit, branch, or tag was made during this audit.
and all 341 ExUnit tests. The configured image scans reported zero and all 341 ExUnit tests. The configured image scans reported zero
vulnerabilities, and the run left no project-scoped quality containers, vulnerabilities, and the run left no project-scoped quality containers,
networks, volumes, or one-run image tags. networks, volumes, or one-run image tags.
- A dedicated Brevo SMTP key and verified sender
`Who Need Help Development <dev@whoneedhelp.com>` were configured only in the
ignored local development `.env`. Brevo reported the sender domain as
authenticated with DKIM and DMARC. A release-container delivery probe sent one
non-authentication verification message to the operator inbox without
creating application or database data; Brevo's transactional log recorded
`Sent`, `Delivered`, and `First opening` for that exact subject and sender.
The disposable probe container was removed, and no test or production sender,
key, environment, container, or deployment was changed. The running dev
replicas deliberately still use their earlier runtime environment until the
remaining Google/Firebase credentials are ready for one controlled rebuild.
- `./scripts/check-environment-readiness.sh .env` now reports external SMTP,
the support inbox, application secrets, browser VAPID, Android App Links, and
Android signing inputs as ready. Its three remaining development blockers are
the Google OAuth client pair, the four public Firebase Android values, and the
FCM service-account credential. No release-readiness claim is made until those
credentials are imported and provider/device behavior is exercised.
- Two web and two worker replicas, PostGIS, Mailpit, Traefik, and the scoped - Two web and two worker replicas, PostGIS, Mailpit, Traefik, and the scoped
Docker socket proxy were running after the audit. Both web replicas and both Docker socket proxy were running after the audit. Both web replicas and both
workers were healthy; public liveness and readiness returned `ok` and workers were healthy; public liveness and readiness returned `ok` and
@ -1310,9 +1327,11 @@ None of the observations below describe the current delivery path.
been registered. been registered.
- Operate PostgreSQL/PostGIS with off-site backups, recovery testing, monitoring, - Operate PostgreSQL/PostGIS with off-site backups, recovery testing, monitoring,
and the availability model selected for real usage. and the availability model selected for real usage.
- After provider approval, verify that delivered MIME contains neither open nor - The development Brevo SMTP transport and sender have completed an external
link tracking and omits the unsubscribe block, then exercise registration and delivery probe. After the controlled dev rebuild, exercise registration and
magic-link delivery through the deployed application to a real mailbox. magic-link delivery through the deployed application itself and inspect the
received message. Repeat the same post-deploy application flow for production
only after the final release scope is reviewed and explicitly approved.
- Exercise registration, sign-in, and settings linking against the production - Exercise registration, sign-in, and settings linking against the production
Google OAuth client on its exact HTTPS callback origin after the tested Google OAuth client on its exact HTTPS callback origin after the tested
release is explicitly promoted. The test client and callback have already release is explicitly promoted. The test client and callback have already