# Deploy notes ## Shape Standalone service: commit-SHA images → registry `forgejo.coulomb.social/coulomb/coulomb-social` → `railiance-apps` Helm values → railiance01 (same lane as `vergabe-teilnahme`). Chart/values/ingress live in **`railiance-apps`** (`helm/coulomb-social-values.yaml`, `docs/coulomb-social.md`). ## Current cluster status (2026-08-09) | Item | State | |------|--------| | Namespace | `coulomb-social` Active | | Deployment | 1/1 Ready, image `:7067145` | | Service | ClusterIP :80 | | Ingress | `coulomb.social` → Traefik, cert-manager annotation | | Env secret | `coulomb-social-env` (`SECRET_KEY`, `DATABASE_URL`, `USER_ENGINE_PROXY_SECRET`) | | OIDC | enabled; issuer `https://kc.coulomb.social`; public client | | Public DNS | **still Cloudflare / Bubble** | | TLS secret | **pending** HTTP-01 until DNS points at the cluster | In-cluster smoke (with `Host: coulomb.social`): `/healthz` ok, landing 200, `/auth/login/` → KeyCape authorize. Full browser session needs cutover. ## Runtime secrets (names only) K8s Secret `coulomb-social-env` in namespace `coulomb-social` (chart `envFrom`): | Key | Source | |-----|--------| | `SECRET_KEY` | generated by env-secret script | | `DATABASE_URL` | cnpg app role secret (URL-encoded password) | | `USER_ENGINE_PROXY_SECRET` | `user-engine/user-engine-runtime` | ```bash # from railiance-apps: make coulomb-social-env-secret-dry-run make coulomb-social-env-secret # from this repo: ./scripts/create-env-secret.sh --dry-run ./scripts/create-env-secret.sh ``` OIDC is a **public** client — no client secret. Non-secret env (OIDC, ALLOWED_HOSTS, user-engine URL) lives in Helm values. ## Health - `GET /healthz` → `{"status":"ok","service":"coulomb-social"}` - Probes use `Host: coulomb.social` (`probes.hostHeader`) ## Build / deploy ```bash SHA=$(git rev-parse --short HEAD) docker build -t forgejo.coulomb.social/coulomb/coulomb-social:$SHA . # push, then: # COULOMB_SOCIAL_IMAGE_TAG=$SHA make coulomb-social-deploy # in railiance-apps ``` ## Cutover checklist (DNS → live Railiance) **Goal:** `https://coulomb.social` serves this app (identity shell), not Bubble. ### Preconditions 1. [x] Image + Helm release healthy 2. [x] KeyCape client `coulomb-social` with prod redirect `https://coulomb.social/auth/callback/` 3. [x] In-cluster OIDC start redirect works 4. [ ] Local browser OIDC + MFA completed once (proves IdP + user-engine path) 5. [ ] Operator accepts brief public outage / Bubble freeze during DNS switch 6. [ ] Optional: export Bubble data if still needed (CSOC-WP-0001) — not required for identity-only cutover ### DNS switch 1. In Cloudflare (or DNS host): lower TTL on `coulomb.social` if possible (e.g. 300s) ahead of time. 2. Point apex (and `www` if used) **A** to **`92.205.62.239`** (railiance01 ingress). - Prefer DNS-only (grey cloud) first so LE HTTP-01 and Traefik see real traffic; re-enable proxy only if you understand TLS termination path. 3. Wait for propagation: `dig +short coulomb.social A` → `92.205.62.239`. 4. cert-manager should finish HTTP-01; confirm: ```bash kubectl -n coulomb-social get certificate coulomb-social-tls # READY=True ``` 5. Smoke public HTTPS: ```bash curl -fsS https://coulomb.social/healthz curl -sI https://coulomb.social/auth/login/ | grep -i location # Location: https://kc.coulomb.social/authorize?... ``` 6. **Browser:** Sign in → Authelia MFA → land on `/app/` with principal. 7. Sign out; confirm `/app/` requires login. 8. Second login: same member row / user-engine user_id. ### Rollback - Point DNS A (or Cloudflare origin) back to Bubble/Cloudflare target. - Cluster release can stay; it only receives traffic when DNS aims at the node. ### After cutover residuals | Item | Note | |------|------| | Bubble freeze | Stop editing live Bubble as source of truth | | Content/UI | CSOC-WP-0001 + design extract — not required for identity shell | | flex-auth Service | leave `FLEX_AUTH_BASE_URL` unset (local vocabulary) until PDP exists | | apps-pg backup/HA | business-app contract | | OpenBao CCR | replace kubectl-sourced env secret when ready | | Image CI | Forgejo/Gitea pipeline for SHA tags | ## Local verification (no cutover) ```bash make test make run # offline identity # or OIDC vars from docs/identity/oidc-client.md ```