docs: record verified staging deployment
This commit is contained in:
parent
ae33fe3f53
commit
7671d6cd8f
|
|
@ -42,3 +42,22 @@ sudo rm -f /etc/nginx/sites-available/whoneedhelp.imalto.site
|
||||||
sudo nginx -t
|
sudo nginx -t
|
||||||
sudo systemctl reload nginx
|
sudo systemctl reload nginx
|
||||||
```
|
```
|
||||||
|
|
||||||
|
## Observed staging deployment
|
||||||
|
|
||||||
|
Verified on 2026-07-18:
|
||||||
|
|
||||||
|
- `whoneedhelp.imalto.site` resolves to the VPN gateway `77.110.101.144`.
|
||||||
|
- Plain HTTP redirects to HTTPS.
|
||||||
|
- HTTPS responds over HTTP/2 with a valid Let's Encrypt certificate whose SAN
|
||||||
|
is `whoneedhelp.imalto.site`; the observed expiry is 2026-10-16.
|
||||||
|
- `/healthz/live` and `/healthz/ready` return HTTP 200.
|
||||||
|
- The public homepage and fingerprinted CSS, JavaScript, and logo assets return
|
||||||
|
HTTP 200 with zero browser console errors or warnings.
|
||||||
|
- A direct WSS handshake through Nginx returns `101 Switching Protocols`.
|
||||||
|
- Nginx and `certbot.timer` are active.
|
||||||
|
|
||||||
|
The server also reports pre-existing protocol-option and duplicate-server-name
|
||||||
|
warnings in unrelated enabled vhosts. Its complete configuration test still
|
||||||
|
reports success. The staging domain publishes no AAAA record, so this bootstrap
|
||||||
|
vhost intentionally declares only the observed IPv4 listener.
|
||||||
|
|
|
||||||
|
|
@ -1,6 +1,5 @@
|
||||||
server {
|
server {
|
||||||
listen 80;
|
listen 80;
|
||||||
listen [::]:80;
|
|
||||||
server_name whoneedhelp.imalto.site;
|
server_name whoneedhelp.imalto.site;
|
||||||
|
|
||||||
location / {
|
location / {
|
||||||
|
|
|
||||||
|
|
@ -106,9 +106,25 @@ Exact production capacity, minimum CPU/RAM, and scaling thresholds are unknown:
|
||||||
there is no representative load dataset or target-environment measurement.
|
there is no representative load dataset or target-environment measurement.
|
||||||
The Helm chart therefore does not invent resource limits or an HPA policy.
|
The Helm chart therefore does not invent resource limits or an HPA policy.
|
||||||
|
|
||||||
|
## Public staging observation
|
||||||
|
|
||||||
|
On 2026-07-18, `whoneedhelp.imalto.site` was published through the existing
|
||||||
|
Ubuntu Nginx gateway and its OpenVPN path to the local Compose proxy. HTTP
|
||||||
|
redirected to HTTPS; the homepage, fingerprinted assets, and both health
|
||||||
|
endpoints returned HTTP 200. A headed Chrome session rendered the public page
|
||||||
|
with zero console errors or warnings. A complete WebSocket Upgrade request to
|
||||||
|
`/live/websocket` returned `101 Switching Protocols`.
|
||||||
|
|
||||||
|
The observed Let's Encrypt certificate had the correct
|
||||||
|
`DNS:whoneedhelp.imalto.site` SAN and an expiry of 2026-10-16. Nginx and the
|
||||||
|
Certbot renewal timer were active. This verifies the current staging path; it
|
||||||
|
does not make the workstation or gateway a production availability
|
||||||
|
environment.
|
||||||
|
|
||||||
## Known work before a public production launch
|
## Known work before a public production launch
|
||||||
|
|
||||||
- Configure a real public HTTPS origin and production-sign the Android app.
|
- Replace the temporary staging origin with the production-owned domain and
|
||||||
|
production-sign the Android app.
|
||||||
- Operate PostgreSQL/PostGIS with backups, recovery testing, and the required
|
- Operate PostgreSQL/PostGIS with backups, recovery testing, and the required
|
||||||
availability model.
|
availability model.
|
||||||
- Load-test representative data and traffic, then set measured pool, resource,
|
- Load-test representative data and traffic, then set measured pool, resource,
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue
Block a user