docs(deploy): runbook style — one command per line, session style

This commit is contained in:
Bastien Chanot
2026-07-05 15:31:10 +02:00
parent 395c77b597
commit bd7f6e4984
+9 -5
View File
@@ -5,15 +5,19 @@
# Static site baked into the nginx image (COPY whitelist): any content or
# infra change needs a rebuild; docs/.claude-only deltas skip it.
# Front: VPS native nginx (TLS, HSTS) → proxy_pass 127.0.0.1:$PORT → container.
# Style: one command per line, as typed in an interactive session — step 1 opens
# the ssh session, later steps run ON the box; local steps say "(from your machine)".
# 1) pull the desired branch on the VPS (fixed)
ssh "$DEPLOY_HOST" "cd \$APP_DIR && git pull" # VERIFY: HEAD == target sha
# 1) connect + pull the desired branch (fixed)
ssh "$DEPLOY_HOST"
cd "$APP_DIR"
git pull # VERIFY: HEAD == target sha
# @delta:rebuild when=index.html,CV_Bastien_Chanot.*,favicon*,apple-touch-icon.png,Dockerfile,docker-compose*.yml,nginx*.conf
# 2) rebuild + restart the container (content is baked into the image)
ssh "$DEPLOY_HOST" "cd \$APP_DIR && docker compose up -d --build" # VERIFY: docker compose ps → healthy
docker compose up -d --build # VERIFY: docker compose ps → healthy
# 3) smoke test (fixed)
# 3) smoke test (from your machine)
curl -fsS -o /dev/null -w '%{http_code}\n' https://bchanot.fr/ # VERIFY: 200
curl -sI https://bchanot.fr/ | grep -i 'x-content-type-options' # VERIFY: nosniff
# ROLLBACK: ssh "$DEPLOY_HOST" "cd \$APP_DIR && git checkout deploy/<date-précédent> && docker compose up -d --build"
# ROLLBACK: on the VPS — git checkout deploy/<date-précédent> && docker compose up -d --build