Compare commits

3 Commits
3 changed files with 39 additions and 0 deletions
+10
View File
@@ -0,0 +1,10 @@
# Deploy incidents (append-only) — DEP-NNN
<!-- One entry per incident. Next ID = grep '^## DEP-' | max+1. Mirrors blockers.md. -->
<!-- Resolution = the commit that adds this entry (atomic patch+incident). Recover: git log -S 'DEP-NNN' -- .claude/deploy/INCIDENTS.md -->
<!-- ## DEP-NNN — <step> failed
- date: YYYY-MM-DD
- step: <runbook step + label>
- error: `<verbatim error>`
- cause: <root cause>
- fix: <what changed in PROCEDURE.md> -->
+23
View File
@@ -0,0 +1,23 @@
#!/usr/bin/env bash
# === deploy runbook (reference) — NOT run directly. Instantiated to NEXT.sh per delta. ===
# Fixed steps run every deploy; # @delta: steps re-instantiate from the delta.
# @config push_deploy_tags=false
# Static site baked into the nginx image (COPY whitelist): any content or
# infra change needs a rebuild; docs/.claude-only deltas skip it.
# Front: VPS native nginx (TLS, HSTS) → proxy_pass 127.0.0.1:$PORT → container.
# Style: one command per line, as typed in an interactive session — step 1 opens
# the ssh session, later steps run ON the box; local steps say "(from your machine)".
# 1) connect + pull the desired branch (fixed)
ssh "$DEPLOY_HOST"
cd "$APP_DIR"
git pull # VERIFY: HEAD == target sha
# @delta:rebuild when=index.html,CV_Bastien_Chanot.*,favicon*,apple-touch-icon.png,Dockerfile,docker-compose*.yml,nginx*.conf
# 2) rebuild + restart the container (content is baked into the image)
docker compose up -d --build # VERIFY: docker compose ps → healthy
# 3) smoke test (from your machine)
curl -fsS -o /dev/null -w '%{http_code}\n' https://bchanot.fr/ # VERIFY: 200
curl -sI https://bchanot.fr/ | grep -i 'x-content-type-options' # VERIFY: nosniff
# ROLLBACK: on the VPS — git checkout deploy/<date-précédent> && docker compose up -d --build
+6
View File
@@ -0,0 +1,6 @@
{
"deployed_sha": "5fe8b4119b33e77c27b35eedc37b1ae7962a5070",
"deployed_at": "2026-07-05T15:24:00+02:00",
"outcome": "ok",
"tag": "deploy/2026-07-05"
}