From 4ba5efc0aa116a51d9cb847b6833a2dcdb5a9279 Mon Sep 17 00:00:00 2001 From: b0txec Date: Thu, 20 Aug 2026 22:48:22 +0300 Subject: [PATCH] Document production-assets UAT deployment --- docs/DEVELOPMENT_AND_STAGING.md | 2 +- docs/README.md | 5 +++-- docs/UPDATE_ROADMAP.md | 8 +++++--- docs/VPS_STAGING_PLAN.md | 29 +++++++++++++++++++++++------ 4 files changed, 32 insertions(+), 12 deletions(-) diff --git a/docs/DEVELOPMENT_AND_STAGING.md b/docs/DEVELOPMENT_AND_STAGING.md index f56cb4d..8a2b7c8 100644 --- a/docs/DEVELOPMENT_AND_STAGING.md +++ b/docs/DEVELOPMENT_AND_STAGING.md @@ -123,7 +123,7 @@ The temporary VPS must not become another development checkout. The proposed rel Windows source and Git -> Rocky build and verification -> immutable image + checksum -> VPS deployment ``` -Releases are manual during user acceptance and are identified by the source commit SHA. The first installed release is `7dbc55b`. The VPS keeps WeatherTool in its own `/srv/weathertool` tree, publishes the application only to loopback ports, and relies on Nginx plus Authelia at the future public boundary. See `VPS_STAGING_PLAN.md` before changing the VPS deployment. +Releases are manual during user acceptance and are identified by the source commit SHA. The first installed release was `7dbc55b`; the current UAT release is `16a8c68`. The VPS keeps WeatherTool in its own `/srv/weathertool` tree, publishes the application only to loopback ports, and relies on Cloudflare, Nginx, and Authelia at the public boundary. See `VPS_STAGING_PLAN.md` before changing the VPS deployment. The committed templates live under `deploy/vps/`. They are not a second local development environment. Validate them on Rocky, build the exact Git revision, diff --git a/docs/README.md b/docs/README.md index 0f01685..5415ddf 100644 --- a/docs/README.md +++ b/docs/README.md @@ -13,12 +13,13 @@ This directory contains the working documentation for the WeatherTool modernizat - Faktiskā symbol placement is automatic after manual image selection and is anchored to each rendered temperature badge. - The first **Ūdens temperatūra** workspace is implemented with manual Latvian-named fields and required 1920×1080 and 3840×1440 exports; visual calibration remains in progress. - Confirmed local Monda Regular/Bold files provide interface and generated-graphic typography; weather symbols use normalized transparent image assets. -- Release `7dbc55b` was built and checksummed on Rocky, transferred to the VPS, verified, and loaded as the immutable `weathertool:7dbc55b` image. -- The isolated VPS UAT stack is running and healthy: WeatherTool is bound to `127.0.0.1:8002`, Authelia to `127.0.0.1:9091`, and PostgreSQL has no host port. Public Nginx routing is not enabled yet. +- Release `16a8c68` was built and checksummed on Rocky, transferred to the VPS, verified, and deployed as the immutable `weathertool:16a8c68` image. Release `7dbc55b` remains available for rollback. +- The isolated VPS UAT stack is running and healthy: WeatherTool is bound to `127.0.0.1:8002`, Authelia to `127.0.0.1:9091`, and PostgreSQL has no host port. Public access is routed through Cloudflare, Nginx, and Authelia. - Cloudflare delegation is active, strict origin TLS covers only `laikapstak.li` and `auth.laikapstak.li`, and the public Nginx/Authelia login flow is operational without changing the existing HOP site. - The VPS database contains a deliberately limited 14-day, 34-city synthetic dataset for newsroom visual testing. It must be cleared before authorized real-provider ingestion begins. - Approved 1920×1080 and 3840×1440 PNG production bases are now the rendering source for Faktiskā and Ūdens temperatūra; code draws only the changing values, selected weather symbols, and wind data over those fixed newsroom graphics. - Browser branding assets and Latvian Open Graph/Twitter metadata are included for favicon, Apple home-screen icon, and link-preview support. Public crawler access still depends on the Nginx/Authelia policy used for the metadata and preview image. +- Browser verification of release `16a8c68` confirmed both fixed-map workspaces and the favicon. The shared UAT login is ready for the first newsroom-user handoff on 2026-08-21. - This is not yet approved or hardened for workplace production. ## Documents diff --git a/docs/UPDATE_ROADMAP.md b/docs/UPDATE_ROADMAP.md index 2d1e878..e40a341 100644 --- a/docs/UPDATE_ROADMAP.md +++ b/docs/UPDATE_ROADMAP.md @@ -7,7 +7,7 @@ This document tracks proposed WeatherTool improvements. Work should be delivered - **Windows development:** source editing and Git workflow only; Docker runtime testing is performed on Rocky. - **Rocky staging:** production-like Docker deployment at `http://192.168.1.101:9190`. - **Git over SSH:** Windows pushes reviewed commits to a private bare repository on Rocky; the Rocky staging checkout pulls those commits and rebuilds. -- **Temporary VPS staging:** release `7dbc55b` is publicly operational behind Cloudflare strict TLS, Nginx, and Authelia with a limited 14-day synthetic dataset. +- **Temporary VPS staging:** release `16a8c68` is publicly operational behind Cloudflare strict TLS, Nginx, and Authelia with a limited 14-day synthetic dataset. - **Workplace production:** remains separate until changes are reviewed, tested, and explicitly approved for workplace use. Do not synchronize `.env`, database directories, generated dependencies, build output, or provider credentials between machines. @@ -68,6 +68,7 @@ Status: pending The first observed frontend install reported 15 vulnerabilities: 1 critical, 10 high, 3 moderate, and 1 low. Exact advisories must be reviewed before choosing upgrades. - [ ] Capture and review the full npm audit report. +- [x] Establish that the production dependency audit is primarily blocked by `solid-js@1.9.4` resolving vulnerable `seroval@1.2.0`; confirm that the full audit also contains development-tool advisories. - [ ] Update direct frontend dependencies in controlled groups. - [ ] Replace or remove obsolete frontend packages where appropriate. - [ ] Rebuild and visually compare every page after frontend upgrades. @@ -151,13 +152,13 @@ Status: in progress - [x] Provision a dedicated `/srv/weathertool` tree, Compose project, private network, database storage, and loopback-only application and Authelia ports. - [x] Configure Authelia with one temporary shared account, Argon2id password storage, rate limiting, and temporary IP bans. - [x] Add an exact-host Cloudflare origin certificate and Nginx authorization routing without disrupting the existing HOP site. -- [x] Build and verify commit-addressed image `weathertool:7dbc55b` on Rocky, then transfer and checksum-verify its image archive on the VPS. +- [x] Build and verify commit-addressed images on Rocky, transfer and checksum-verify them on the VPS, and update the application-only service to `weathertool:16a8c68` without restarting PostgreSQL or Authelia. - [ ] Complete UAT verification: public authentication and application health pass; direct-origin blocking, logout, throttling, PNG downloads, backups, logs, and rollback remain. - [ ] Run the month-long user test with manual releases and record feedback before any workplace-production decision. ## Known current limitations -- The new fixed production PNG bases and social metadata are implemented locally and require a Rocky build plus UAT release before newsroom validation. +- The fixed production PNG bases and browser/social metadata are deployed in UAT release `16a8c68`; newsroom workflow validation begins with the first tester handoff on 2026-08-21. - Link-preview crawlers cannot authenticate through Authelia; the final Nginx policy must deliberately expose only the minimum preview metadata/assets if WhatsApp previews are required. - Staging uses synthetic PostgreSQL station data. @@ -186,3 +187,4 @@ Record completed work here by date and commit after the Git workflow is establis | 2026-08-19 | `1868041`–`6c9290b` | Add Ūdens temperatūra, bundle and load Monda, fix overlay scaling, and center its locked nameplate | Yes | | 2026-08-19 | `0d641bd` | Replace runtime Daira glyph rendering with normalized transparent image assets | Yes | | 2026-08-20 | `754415a` | Match editable title/source overlays to production-safe right margins | Yes | +| 2026-08-20 | `16a8c68` | Deploy approved production map bases, normalized branding assets, favicon, Apple icon, and social metadata to public UAT | Yes — Rocky build and VPS/browser smoke checks | diff --git a/docs/VPS_STAGING_PLAN.md b/docs/VPS_STAGING_PLAN.md index f7319ad..1e7fd06 100644 --- a/docs/VPS_STAGING_PLAN.md +++ b/docs/VPS_STAGING_PLAN.md @@ -1,6 +1,6 @@ # Temporary VPS staging plan -Status: **Release `7dbc55b` publicly operational behind Cloudflare, Nginx, and Authelia with temporary synthetic data** +Status: **Release `16a8c68` publicly operational behind Cloudflare, Nginx, and Authelia with temporary synthetic data** This document defines the next deployment stage for approximately one month of newsroom-user testing. It records the intended boundary before any VPS changes @@ -58,9 +58,10 @@ Cloudflare -> Nginx -> Authelia authorization -> WeatherTool ``` The host root plus `releases/` and `backups/` exist with owner `ubuntu:ubuntu` -and mode `0750`. Release `7dbc55b` was transferred from Rocky, verified against -its SHA-256 manifest, loaded as `weathertool:7dbc55b`, and installed with the -reviewed deployment bundle. The dedicated Compose stack is now running; no +and mode `0750`. Baseline release `7dbc55b` installed the reviewed deployment +bundle. Release `16a8c68` was then built on Rocky, verified against its SHA-256 +manifest on both Rocky and the VPS, loaded as `weathertool:16a8c68`, and deployed +by recreating only the application service. The dedicated Compose stack is running; no existing HOP container, network, volume, port, or Nginx site was changed. The VPS receives a built release artifact, not a development checkout. It gets @@ -207,11 +208,27 @@ Additional public progress completed on 2026-08-20: - a checksummed seed derived from release `7dbc55b` inserted 11,458 hourly observations for 34 cities covering 14 days. +UAT application update completed on 2026-08-20: + +- immutable release `weathertool:16a8c68` was checksum-verified and loaded; +- `.env.staging` was backed up before changing the selected image tag; +- only the WeatherTool application container was recreated; PostgreSQL and + Authelia were left running; +- the application became healthy and returned HTTP 200 on its loopback port; +- Authelia health returned HTTP 200 and the unauthenticated public route kept + returning the expected login redirect; +- the existing HOP route retained its previous HTTP behavior; +- browser checks confirmed the approved Faktiskā and Ūdens temperatūra bases, + both output-size choices, weather-symbol assets, and favicon; and +- `weathertool:7dbc55b` plus the protected pre-update environment copy remain + available as the immediate application rollback path. + The shortened seed exists only to support visual user testing. Before real API credentials or scheduled ingestion are enabled, clear the synthetic `weather` table in a controlled maintenance step while scheduled jobs remain disabled. -Logout, throttling/ban recovery, direct-origin rejection, representative PNG -downloads, and backup/rollback rehearsal remain acceptance checkpoints. +Logout, throttling/ban recovery, direct-origin rejection, downloaded-file pixel +dimension checks, social-preview crawler behavior, backups, and a rollback +rehearsal remain acceptance checkpoints. Known application constraint: provider clients are constructed during startup even when `ENABLE_SCHEDULED_JOBS=false`. The synthetic UAT Compose file therefore