Files
pikasTech-HWLAB/deploy/README.md
T
2026-05-22 06:59:29 +00:00

74 lines
3.3 KiB
Markdown

# Deploy Contract
`deploy.schema.json` defines the future `deploy/deploy.json` manifest shape.
The MVP acceptance environment is DEV only. Public endpoint source fields live in
`deploy/deploy.json`: frontend `http://74.48.78.17:16666` and API/edge
`http://74.48.78.17:16667`. PROD profile fields may be represented in schema
for future compatibility, but PROD deployment is not part of MVP acceptance.
## L5 DEV Skeleton
- `deploy/deploy.json` is the DEV-only deploy manifest.
- `deploy/deploy.json` is the single source for `health.path`,
`publicEndpoints`, `frp.proxies`, and `k3s.serviceMappings`.
- `deploy/k8s/base` contains parseable k3s resource skeletons for the frozen
HWLAB service IDs rendered from the manifest contract.
- `deploy/k8s/dev` contains the DEV health contract and endpoint metadata.
- `hwlab-cloud-api` declares the DEV DB env contract with
`HWLAB_CLOUD_DB_URL` from Secret reference
`hwlab-cloud-api-dev-db/database-url` and non-secret
`HWLAB_CLOUD_DB_SSL_MODE=require`. The repository records names only, never
secret values or a live DB connection string; runtime health reports redacted
env injection and DB connection result classifiers.
- `deploy/k8s/prod` is a disabled placeholder gate only.
- `deploy/frp` describes the D601-to-master reverse link without secrets.
- `deploy/master-edge` describes public edge ownership and health boundaries.
Dry-run source rendering:
```sh
node scripts/deploy-contract-plan.mjs --pretty
node scripts/deploy-contract-plan.mjs --check
```
The deploy contract plan renders and validates only. It does not run frps/frpc,
does not call `kubectl apply`, does not restart services, and does not touch
PROD. Later work can wire the same source fields into `hwlab edge apply` or
`deploy apply`.
Desired-state commit/image convergence review:
```sh
node scripts/deploy-desired-state-plan.mjs --pretty
node scripts/deploy-desired-state-plan.mjs --check
node scripts/deploy-desired-state-plan.mjs --target-ref origin/main --pretty
node scripts/deploy-desired-state-plan.mjs --target-tag <tag> --pretty
```
The desired-state plan reads only `deploy/deploy.json`,
`deploy/artifact-catalog.dev.json`, `deploy/k8s/base/workloads.yaml`, and the
optional artifact report snapshot. It checks that commit IDs, service image
tags, workload images, and present env mirrors such as `HWLAB_COMMIT_ID`,
`HWLAB_IMAGE`, `HWLAB_IMAGE_TAG`, and `HWLAB_SKILLS_COMMIT_ID` converge. With
`--target-ref` or `--target-tag`, a uniform older desired-state is reported as a
read-only promotion plan; `--check` fails only for missing/invalid source files,
internal mirror drift, invalid target tags, or partial target drift.
This is source/dry-run support only. It does not prove a registry image exists,
does not build, pull, push, apply, restart, or touch PROD, and must not be used
as M3 DEV-LIVE evidence.
Next DEV deploy smoke commands, for a separately authorized deployment task:
```sh
npm run check
node -e "JSON.parse(require('node:fs').readFileSync('deploy/deploy.json','utf8'))"
kubectl apply --dry-run=server -k deploy/k8s/dev
curl -fsS http://74.48.78.17:16667/health/live
node scripts/dev-edge-health-smoke.mjs --live --write-report
```
Do not run PROD deployment or substitute UniDesk backend, provider-gateway, or
microservice proxy for HWLAB runtime services.