From 5fe8b4119b33e77c27b35eedc37b1ae7962a5070 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Sun, 5 Jul 2026 15:17:00 +0200 Subject: [PATCH] feat(deploy): bootstrap runbook --- .claude/deploy/INCIDENTS.md | 10 ++++++++++ .claude/deploy/PROCEDURE.md | 19 +++++++++++++++++++ 2 files changed, 29 insertions(+) create mode 100644 .claude/deploy/INCIDENTS.md create mode 100644 .claude/deploy/PROCEDURE.md diff --git a/.claude/deploy/INCIDENTS.md b/.claude/deploy/INCIDENTS.md new file mode 100644 index 0000000..76c4680 --- /dev/null +++ b/.claude/deploy/INCIDENTS.md @@ -0,0 +1,10 @@ +# Deploy incidents (append-only) — DEP-NNN + + + + diff --git a/.claude/deploy/PROCEDURE.md b/.claude/deploy/PROCEDURE.md new file mode 100644 index 0000000..7c8ecd1 --- /dev/null +++ b/.claude/deploy/PROCEDURE.md @@ -0,0 +1,19 @@ +#!/usr/bin/env bash +# === deploy runbook (reference) — NOT run directly. Instantiated to NEXT.sh per delta. === +# Fixed steps run every deploy; # @delta: steps re-instantiate from the delta. +# @config push_deploy_tags=false +# Static site baked into the nginx image (COPY whitelist): any content or +# infra change needs a rebuild; docs/.claude-only deltas skip it. +# Front: VPS native nginx (TLS, HSTS) → proxy_pass 127.0.0.1:$PORT → container. + +# 1) pull the desired branch on the VPS (fixed) +ssh "$DEPLOY_HOST" "cd \$APP_DIR && git pull" # VERIFY: HEAD == target sha + +# @delta:rebuild when=index.html,CV_Bastien_Chanot.*,favicon*,apple-touch-icon.png,Dockerfile,docker-compose*.yml,nginx*.conf +# 2) rebuild + restart the container (content is baked into the image) +ssh "$DEPLOY_HOST" "cd \$APP_DIR && docker compose up -d --build" # VERIFY: docker compose ps → healthy + +# 3) smoke test (fixed) +curl -fsS -o /dev/null -w '%{http_code}\n' https://bchanot.fr/ # VERIFY: 200 +curl -sI https://bchanot.fr/ | grep -i 'x-content-type-options' # VERIFY: nosniff +# ROLLBACK: ssh "$DEPLOY_HOST" "cd \$APP_DIR && git checkout deploy/ && docker compose up -d --build"