Skip to content

chore(deploy): T2 2026 deploy and dev stack updates - #43

Open
Clupai8o0 wants to merge 2 commits into
thoth-tech:11.0.xfrom
ontrack-features-t2-2026:upstream-pr/deploy
Open

Clupai8o0 wants to merge 2 commits into
thoth-tech:11.0.xfrom
ontrack-features-t2-2026:upstream-pr/deploy

Conversation

@Clupai8o0

@Clupai8o0 Clupai8o0 commented Sep 27, 2026 •

Copy link
Copy Markdown

What this is

This updates the deploy repo for the 11.0.x release with the T2 2026 features. It adds local run guides and dev compose changes for notifications, and hardens the production compose so a deploy stops when config is missing. It also removes TLS keys and config files that were committed under production/ and replaces them with example files.

What is in it

  • RUNNING-LOCALLY.md, DESKTOP-PWA.md, docs/ONTRACK_PODMAN_SETUP.md and production/UPLOAD-LIMITS.md are new guides. DEPLOYING.md, MIGRATING.md, RELEASING.md and README.md are updated.
  • development/: Mailpit and a Sidekiq worker, local path and Podman overrides, a notifications test database script and verify-notifications.sh.
  • production/docker-compose.yml: internal networks, a migrate step, a Docker socket proxy, and required settings that stop start-up when unset. The proxy nginx config becomes a template.
  • production/validate.sh, verify.sh, verify-pwa.py, deploy.sh, compose.sh and publish-release.sh, with tests in production/tests/.
  • tools/audit-vapid-secret.py and docs/vapid-secret-audit.md: a check the release owner can run to confirm the push notification private key is not in old commits, image layers or logs.
  • Removes production/CAkeys/*, localhost.key, localhost.crt, .env.production, msmtprc and aliases, adds .example versions, and ignores the real files in .gitignore.
  • Two new workflows check the production compose and the secret audit tool. build-dev-container.yml pins actions to commit SHAs and fixes a wrong steps.meta reference.
  • Update, 28 Sep 2026: one more commit. Brings feat: land Unit Hub packaging, Teams settings and the demo database guard (#36) ontrack-features-t2-2026/doubtfire-deploy#41. It adds the Unit Hub Teams settings to the production example env and compose file, a check for the Teams channel mappings in validate.sh with tests, and development/verify-unit-hub.py. It also brings the .devcontainer files. Their AAF settings are now blank and come from an ignored .devcontainer/.env, which the secret check in production/tests/validate_test.sh needs to pass on this branch.

How this set of PRs works

This is one of 24 PRs from the Thoth Tech T2 2026 Features team (9 api, 14 web, 1 deploy), one per feature per repo. Each one carries that feature's files, taken from our team org's 11.0.x branch, and applied straight onto thoth-tech 11.0.x. Every file is in exactly one PR. Some files are shared between features, so a PR on its own may not build. The demo PR in each repo (api #127, web #544) is imported by earlier PRs too, so it has to go in with the rest, not be dropped. Merged in the order below, the set equals our org 11.0.x minus team docs, evidence files, org-only CI and dev setup files. No app code or tests are left out.

On 28 Sep 2026 the set was brought up to our org's latest merges (api ontrack-features-t2-2026/doubtfire-api#178, web ontrack-features-t2-2026/doubtfire-web#281 and ontrack-features-t2-2026/doubtfire-web#282, deploy ontrack-features-t2-2026#41). Most PRs got one more commit for that. Two web PRs are new, panels (thoth-tech/doubtfire-web#546) and celebrate (thoth-tech/doubtfire-web#547), for files that were in no PR before.

Merge order, api first, then web, then deploy. In web, panels goes before the pages that use it, and celebrate goes after a11y, whose confetti service it needs.

Built against

  • api: thoth-tech 11.0.x @ dc76a5a0e, taken from org 11.0.x @ a9589b302
  • web: thoth-tech 11.0.x @ 20d1f380c, taken from org 11.0.x @ 0b8a20344
  • deploy: thoth-tech 11.0.x @ 58905969e, taken from org 11.0.x @ 8e560f7e0

Testing

Checked on 28 Sep 2026 with all the branches merged together. This PR was not tested on its own, see above.

  • web: with all 14 web branches merged onto thoth-tech 11.0.x, npm run test:ci runs 2603 tests in 290 files, all passing, and npm run lint and ng build pass. The merged set's app code is the same as our org 11.0.x after fix(profile): save a changed summary email cadence ontrack-features-t2-2026/doubtfire-web#282, where CI passed test, lint (22) and build (22).
  • api: the full Minitest suite passes on the nine api PRs merged onto thoth-tech 11.0.x. 1799 tests, 20182 assertions, 0 failures, 0 errors, 0 skips. It ran through our CI on branch check/upstream-combined-28sep (run), and the database schema check and RuboCop pass there too. The set differs from our org 11.0.x only by the left-out docs, evidence, CI and dev setup files, none of them app code.
  • deploy: production/tests/validate_test.sh, verify_pwa_test.py, publish_release_test.py and nginx_upload_test.py pass. The production compose file loads with docker compose config against .env.production.example, and the development and .devcontainer ones load as they are.

Contributors

Samridh Limbu, Maple Fox, UmedaRanuluge, jerickson

This was referenced Sep 27, 2026
@Clupai8o0
Clupai8o0 force-pushed the upstream-pr/deploy branch 2 times, most recently from 3232534 to 314dff4 Compare September 27, 2026 10:04
Brings the T2 2026 deploy work from ontrack-features-t2-2026 11.0.x (reviewed and merged work) onto thoth-tech 11.0.x.

Co-authored-by: maplefoxgit <s223932052@deakin.edu.au>
Co-authored-by: UmedaRanuluge <umedakr@gmail.com>
Co-authored-by: Maple 'Ryan' Fox <s223932052@deakin.edu.au>
Co-authored-by: jerickson <joshuae.data@gmail.com>
Brings #41 to the files this
PR already carries, so every file stays in exactly one PR. It adds the
Unit Hub Teams settings to the production example env and compose file,
a check for the Teams channel mappings in validate.sh with tests, and
development/verify-unit-hub.py.

It also brings the .devcontainer files. Their AAF settings are now blank
and come from an ignored .devcontainer/.env, which the secret check in
production/tests/validate_test.sh needs to pass on this branch.

Co-authored-by: Maple Fox <s223932052@deakin.edu.au>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants