forked from bchanot/claude
feat(skills): /deploy NEXT.sh session style + inline hand-back print
First-real-run UX feedback (EVAL-016): one command per line as typed in an interactive session (ssh opens the box, following lines run on it, local steps flagged), never folded ssh compounds; the hand-back prints the full checklist in the conversation (and every re-hand-back reprints it). Step defined as a block (header + command lines to next blank line), @delta governs the block. Template restyled to match.
This commit is contained in:
@@ -1,5 +1,19 @@
|
|||||||
# TODO
|
# TODO
|
||||||
|
|
||||||
|
## 2026-07-05 — /deploy UX patch (feature/deploy-next-style)
|
||||||
|
Feedback user au 1er run réel (bchanot-cv, [[EVAL-016]]) : NEXT.sh une commande
|
||||||
|
par ligne (style session — ssh ouvre la box, la suite s'exécute dessus, local =
|
||||||
|
"(from your machine)") + hand-back AFFICHE la checklist inline (aussi aux
|
||||||
|
re-hand-back). Step = bloc (header + lignes jusqu'à ligne vide), @delta
|
||||||
|
gouverne le bloc entier.
|
||||||
|
- [x] skills/deploy/SKILL.md — grammaire bloc-étape + shape rule + print inline
|
||||||
|
- [x] templates/deploy/PROCEDURE.md — restylé session
|
||||||
|
- [x] bchanot-cv runbook restylé, committé, pushé (bd7f6e4, develop sync)
|
||||||
|
- [x] settings.json +inputNeededNotifEnabled (layout committé inchangé)
|
||||||
|
- [x] Capitalize EVAL-016 + journal
|
||||||
|
- [ ] Re-dogfood au prochain /deploy réel (edit de skill non re-testé par run —
|
||||||
|
dette Iron Law assumée, même statut que la note d'authoring du skill)
|
||||||
|
|
||||||
## 2026-07-05 — impeccable install chain (feature/impeccable-install)
|
## 2026-07-05 — impeccable install chain (feature/impeccable-install)
|
||||||
Décision (user a délégué) : COMPLÉMENTAIRES → les deux. frontend-design garde
|
Décision (user a délégué) : COMPLÉMENTAIRES → les deux. frontend-design garde
|
||||||
la direction esthétique au build ; impeccable (pbakaus, 43.6k⭐, Apache-2.0,
|
la direction esthétique au build ; impeccable (pbakaus, 43.6k⭐, Apache-2.0,
|
||||||
|
|||||||
@@ -6,6 +6,10 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
|||||||
|
|
||||||
## [Unreleased]
|
## [Unreleased]
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- `/deploy` NEXT.sh reshaped on first-real-run feedback: runbook steps are **one command per line, interactive-session style** (an early step opens the ssh session; later lines run on the box; local steps say "from your machine") instead of folded `ssh host "cd … && …"` one-liners, and the **hand-back prints the full checklist inline** in the conversation (also on every re-hand-back) so the user never has to open `NEXT.sh` to know what to run. Step = comment header + command lines up to the next blank line; a `@delta:` directive governs the whole block. Template `templates/deploy/PROCEDURE.md` restyled to match.
|
||||||
|
- `settings.json`: `inputNeededNotifEnabled: true` adopted (harness notification toggle); committed layout otherwise unchanged.
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
- **impeccable** (pbakaus, Apache-2.0) wired into the toolchain as the design counterpart of semgrep: the `/impeccable` skill (23 verbs under one command: audit, polish, bolder, quieter…) plus the 45-rule deterministic anti-pattern detector (`npx impeccable detect`, exit 0/2, `--json`). Complementary to `frontend-design` (kept — aesthetic direction at build time); impeccable adds the deterministic audit floor and per-project design context (`/impeccable init`). CLI pinned in `plugins.lock.json` (3.2.0 — a silent rules update would change audit output on unchanged code); dist is machine-owned under `skills-external/impeccable/` (gitignored, ctx7 pattern), staged-installed by `install-plugins.sh` Step 8d, refreshed pin-honored by `update-all.sh`, symlinked by `link.sh`, listed in the design/web/web-full/full profiles and the design-work routing. Requires Node ≥ 24: the install baseline is bumped from 22 to 24 LTS (NodeSource `setup_24.x` / brew `node@24`), so `make plugin` upgrades a too-old host in place; the impeccable steps still skip gracefully if Node stays below 24. Not in the design gate's GATE-BLOCK list yet — promotion deliberate, after first dogfood.
|
- **impeccable** (pbakaus, Apache-2.0) wired into the toolchain as the design counterpart of semgrep: the `/impeccable` skill (23 verbs under one command: audit, polish, bolder, quieter…) plus the 45-rule deterministic anti-pattern detector (`npx impeccable detect`, exit 0/2, `--json`). Complementary to `frontend-design` (kept — aesthetic direction at build time); impeccable adds the deterministic audit floor and per-project design context (`/impeccable init`). CLI pinned in `plugins.lock.json` (3.2.0 — a silent rules update would change audit output on unchanged code); dist is machine-owned under `skills-external/impeccable/` (gitignored, ctx7 pattern), staged-installed by `install-plugins.sh` Step 8d, refreshed pin-honored by `update-all.sh`, symlinked by `link.sh`, listed in the design/web/web-full/full profiles and the design-work routing. Requires Node ≥ 24: the install baseline is bumped from 22 to 24 LTS (NodeSource `setup_24.x` / brew `node@24`), so `make plugin` upgrades a too-old host in place; the impeccable steps still skip gracefully if Node stays below 24. Not in the design gate's GATE-BLOCK list yet — promotion deliberate, after first dogfood.
|
||||||
- `/tour` skill — grouped all-axes sweep over one or several projects: security (pinned-semgrep `security-auditor` agent + `/cso` posture when gstack is ON) → cleanup → re-verify → reconcile (report-only, never edits the target TODO/registries) → doc sync, looping until a full pass applies zero fixes (bounded at 3 iterations). Fixes land on a `chore/tour-<date>` branch the skill never merges; each project gets an append-only `.claude/audits/TOUR.md` report with BREAKING tags on contract-changing security fixes. Built TDD (superpowers:writing-skills): baseline run showed silent TODO rewrites, autonomous registry writes, grep-as-security-pass, no persistent report, scope creep and an unbounded loop — each countered and verified on a seeded fixture.
|
- `/tour` skill — grouped all-axes sweep over one or several projects: security (pinned-semgrep `security-auditor` agent + `/cso` posture when gstack is ON) → cleanup → re-verify → reconcile (report-only, never edits the target TODO/registries) → doc sync, looping until a full pass applies zero fixes (bounded at 3 iterations). Fixes land on a `chore/tour-<date>` branch the skill never merges; each project gets an append-only `.claude/audits/TOUR.md` report with BREAKING tags on contract-changing security fixes. Built TDD (superpowers:writing-skills): baseline run showed silent TODO rewrites, autonomous registry writes, grep-as-security-pass, no persistent report, scope creep and an unbounded loop — each countered and verified on a seeded fixture.
|
||||||
|
|||||||
+18
-2
@@ -99,6 +99,14 @@ A directive sits on the comment line **above** the step it governs; patterns are
|
|||||||
matched against the delta file list. Un-annotated step = **fixed**, always
|
matched against the delta file list. Un-annotated step = **fixed**, always
|
||||||
emitted verbatim.
|
emitted verbatim.
|
||||||
|
|
||||||
|
**A step is a block**: its `# n)` comment header plus every command line below
|
||||||
|
it, up to the next blank line. A directive governs the whole block. Steps are
|
||||||
|
written **one command per line, interactive-session style** — an early fixed
|
||||||
|
step opens the box (`ssh "$DEPLOY_HOST"`), the lines after it run *on* the box
|
||||||
|
as you would type them; a step that runs locally says `(from your machine)` in
|
||||||
|
its header. Never fold `ssh host "cd … && …"` compounds: the user copy-pastes
|
||||||
|
line by line. Each `# VERIFY:` sits at the end of the command line it gates.
|
||||||
|
|
||||||
| Directive | Meaning | Instantiation |
|
| Directive | Meaning | Instantiation |
|
||||||
|-----------|---------|---------------|
|
|-----------|---------|---------------|
|
||||||
| `# @delta:<kind> glob=<pat>:each` | per-file command | repeat the command once **per** matching delta file (file substituted in) |
|
| `# @delta:<kind> glob=<pat>:each` | per-file command | repeat the command once **per** matching delta file (file substituted in) |
|
||||||
@@ -275,7 +283,9 @@ Set the base, compute the changed-file list, capture the target.
|
|||||||
prepend `# PRE-WARN: DEP-NNN <one-line summary>` above it.
|
prepend `# PRE-WARN: DEP-NNN <one-line summary>` above it.
|
||||||
3. Keep every `# VERIFY:` gate. Header the file: *"Run by hand, step by step.
|
3. Keep every `# VERIFY:` gate. Header the file: *"Run by hand, step by step.
|
||||||
Never `bash NEXT.sh` unattended."*
|
Never `bash NEXT.sh` unattended."*
|
||||||
4. Write `.claude/deploy/NEXT.sh`.
|
4. Preserve the runbook's shape: one command per line, session style (see the
|
||||||
|
`@delta:` grammar section) — instantiation never re-folds lines.
|
||||||
|
5. Write `.claude/deploy/NEXT.sh`.
|
||||||
|
|
||||||
**[GATE] — present `NEXT.sh` → `all / edit / skip-all`.**
|
**[GATE] — present `NEXT.sh` → `all / edit / skip-all`.**
|
||||||
- `all` → proceed. `edit` → revise the listed steps, re-present.
|
- `all` → proceed. `edit` → revise the listed steps, re-present.
|
||||||
@@ -288,9 +298,15 @@ Set the base, compute the changed-file list, capture the target.
|
|||||||
"started_at": "<now, ISO-8601>",
|
"started_at": "<now, ISO-8601>",
|
||||||
"runbook_rev": "<git log -1 --format=%H -- .claude/deploy/PROCEDURE.md>" }
|
"runbook_rev": "<git log -1 --format=%H -- .claude/deploy/PROCEDURE.md>" }
|
||||||
```
|
```
|
||||||
**Then HAND BACK** (AskUserQuestion): *"Run NEXT.sh step by step against prod.
|
**Then HAND BACK — the checklist lands in the conversation, not just on disk.**
|
||||||
|
Print the FULL final `NEXT.sh` content inline (fenced code block) so the user
|
||||||
|
sees exactly what to run without opening the file — the gate preview is not
|
||||||
|
enough (an `edit` round may have changed it; the hand-back shows the final
|
||||||
|
text). Then (AskUserQuestion): *"Run NEXT.sh step by step against prod.
|
||||||
Report back: **Deployed OK** / **Failed at step X: <err>** / **Not yet**."* Then
|
Report back: **Deployed OK** / **Failed at step X: <err>** / **Not yet**."* Then
|
||||||
**stop** — control is the user's; `PENDING.json` on disk now marks the wait.
|
**stop** — control is the user's; `PENDING.json` on disk now marks the wait.
|
||||||
|
The same rule applies to every re-hand-back (STEP 4.3): regenerated `NEXT.sh`
|
||||||
|
⇒ reprinted in full.
|
||||||
|
|
||||||
## STEP 3 — RESUME / REACT
|
## STEP 3 — RESUME / REACT
|
||||||
|
|
||||||
|
|||||||
@@ -4,22 +4,31 @@
|
|||||||
# @config push_deploy_tags=false
|
# @config push_deploy_tags=false
|
||||||
# NOTE grammar: glob=<pat>:each repeats the command per matching file (e.g. psql -f <each>);
|
# NOTE grammar: glob=<pat>:each repeats the command per matching file (e.g. psql -f <each>);
|
||||||
# glob=<pat>:list runs once + lists matching files as VERIFY items; when=<pat,...> is conditional.
|
# glob=<pat>:list runs once + lists matching files as VERIFY items; when=<pat,...> is conditional.
|
||||||
|
# Style: one command per line, as typed in an interactive session — step 1 opens
|
||||||
|
# the ssh session, later steps run ON the box; local steps say "(from your machine)".
|
||||||
|
|
||||||
# 1) backup BEFORE any forward-only migration
|
# 1) connect + pull the desired branch (fixed)
|
||||||
ssh "$DEPLOY_HOST" 'pg_dump "$DB" > ~/backups/pre-deploy-$(date +%F-%H%M).sql' # VERIFY: dump size > 0
|
ssh "$DEPLOY_HOST"
|
||||||
|
cd "$APP_DIR"
|
||||||
|
git pull # VERIFY: HEAD == target sha
|
||||||
|
|
||||||
|
# 2) backup BEFORE any forward-only migration
|
||||||
|
pg_dump "$DB" > ~/backups/pre-deploy-$(date +%F-%H%M).sql # VERIFY: dump size > 0
|
||||||
|
|
||||||
# @delta:migrations glob=supabase/migrations/*.sql:list
|
# @delta:migrations glob=supabase/migrations/*.sql:list
|
||||||
# 2) apply NEW migrations (one command; skill lists the delta migrations to VERIFY)
|
# 3) apply NEW migrations (one command; the skill lists the delta migrations to VERIFY)
|
||||||
ssh "$DEPLOY_HOST" 'supabase migration up' # VERIFY: "Applied" for each
|
supabase migration up # VERIFY: "Applied" for each
|
||||||
|
|
||||||
# @delta:rebuild when=docker-compose*.yml,Dockerfile,Dockerfile.*
|
# @delta:rebuild when=docker-compose*.yml,Dockerfile,Dockerfile.*
|
||||||
# 3) rebuild + restart services (only if build inputs changed)
|
# 4) rebuild + restart services (only if build inputs changed)
|
||||||
ssh "$DEPLOY_HOST" 'docker compose up -d --build' # VERIFY: docker compose ps healthy
|
docker compose up -d --build # VERIFY: docker compose ps healthy
|
||||||
|
|
||||||
# @delta:deps when=package.json,*lock*,requirements.txt,pyproject.toml
|
# @delta:deps when=package.json,*lock*,requirements.txt,pyproject.toml
|
||||||
# 4) install deps (only if manifests changed)
|
# 5) install deps (only if manifests changed)
|
||||||
ssh "$DEPLOY_HOST" 'cd app && npm ci' # VERIFY: exit 0
|
cd app
|
||||||
|
npm ci # VERIFY: exit 0
|
||||||
|
|
||||||
# 5) reload cache + smoke test (fixed)
|
# 6) reload + smoke test
|
||||||
ssh "$DEPLOY_HOST" 'systemctl reload app'
|
systemctl reload app
|
||||||
|
# (from your machine)
|
||||||
curl -fsS https://$DEPLOY_HOST/health # VERIFY: HTTP 200
|
curl -fsS https://$DEPLOY_HOST/health # VERIFY: HTTP 200
|
||||||
|
|||||||
Reference in New Issue
Block a user