1.6 KiB
WeatherTool VPS deployment bundle
This directory contains the reviewed templates for the temporary UAT deployment. It is intentionally separate from the Rocky development Compose project.
Boundaries
- Compose project:
weathertool-uat - WeatherTool host binding:
127.0.0.1:8002 - Authelia host binding:
127.0.0.1:9091 - PostgreSQL: private Docker network only; no host port
- Scheduled provider jobs: disabled
- Existing VPS applications, networks, volumes, and Nginx sites: untouched
The committed configuration contains no live password, password hash, or
cryptographic secret. Runtime material belongs only under /srv/weathertool.
Runtime layout
Copy the committed bundle into /srv/weathertool, then create these untracked
paths before the first start:
/srv/weathertool/
.env.staging
compose.yml
config/authelia/configuration.yml
config/authelia/users_database.yml
data/app/
data/authelia/
data/postgres/
secrets/jwt_secret
secrets/session_secret
secrets/storage_encryption_key
The Nginx files remain examples until the domain, Cloudflare origin certificate, trusted client-address configuration, and private upstream tests are complete. Do not enable the virtual host merely because the containers start successfully.
Release image
Build the exact committed revision on Rocky:
git archive HEAD | docker build \
-f deploy/vps/Dockerfile \
-t "weathertool:$(git rev-parse HEAD)" -
Export the image, calculate its SHA-256 checksum, transfer both files, verify the
checksum on the VPS, and only then load it. The detailed operator sequence is in
docs/VPS_STAGING_PLAN.md.