2.3 KiB
policy-nexus production release
railiance-apps owns only the approved production binding for
policy.coulomb.social. Policy sources and the OCI artifact belong to
policy-nexus; the Helm chart, hardening, verification, and rollback belong to
rapp-policy-nexus. This repository must not copy either the generated site or
the chart.
Binding a release
The source-controlled binding is
bindings/policy-nexus-production.json. Before deployment, record all four
candidate identities and set status to release-approved:
image_digest: the registry-resolvedsha256:...digest of the image published bypolicy-nexus;publication_manifest_digest: the 64-hex SHA-256 printed by the release verifier for the exactpublication-manifest.jsonin that image.source_inventory_digest: the 64-hex SHA-256 of the exactsource-inventory.jsonin that image;source_set_digest: the deterministic 64-hex digest of every upstream repository revision audited for that candidate.
Tags are not accepted as production identity. All four identities must be reviewed in the same change; this binds runtime bytes to policy source provenance without making this repository a second policy authority.
Preflight and deployment
With sibling checkouts of railiance-apps and rapp-policy-nexus:
make policy-nexus-check-binding
make policy-nexus-check-image
make policy-nexus-render
make policy-nexus-server-dry-run
make policy-nexus-deploy
make policy-nexus-status
make policy-nexus-smoke
Production deployment is an operator action. The current Forgejo build runner
has registry-publication authority but intentionally has no cluster-deploy
authority, kubeconfig, or SSH lane. Do not add those credentials to make this
release automatic. The guarded Make targets refuse the current
approved-awaiting-artifact binding and provide the reviewed execution path
from an authorized operator workstation.
Rollback
Find the last known-good Helm revision with make policy-nexus-status, then:
make policy-nexus-rollback POLICY_NEXUS_REVISION=<revision>
make policy-nexus-smoke
After an emergency rollback, restore the binding file to the four immutable identities actually serving and capture the smoke output. The package promises restart recovery on the single-node reef, not multi-node high availability.