diff --git a/.gitignore b/.gitignore index 3797339..7a2a95d 100644 --- a/.gitignore +++ b/.gitignore @@ -13,3 +13,4 @@ bin/hermes # oikos/ kernel files are still imported by bin/homelab for operational CLI # commands (ssh, pct, logs, restart, status, open, secret, client, sync, mcp). # Remove oikos/* when bin/homelab is ported to Go. +backups/ diff --git a/scripts/cutover-checklist.md b/scripts/cutover-checklist.md index 83a7a71..bbe406e 100644 --- a/scripts/cutover-checklist.md +++ b/scripts/cutover-checklist.md @@ -1,42 +1,42 @@ # Cutover checklist — Phase 6: apps/105 → Docker stack on mac-mini -Status: [ ] = pending, [x] = done +Status: [x] = done, [ ] = pending ## Pre-cutover -- [ ] **Backup**: `pg_dump oikos > backups/pre-cutover-$(date +%Y%m%d).sql` -- [ ] **CI green**: latest push passes `.gitea/workflows/ci.yml` -- [ ] **Deploy test**: `./scripts/deploy.sh` succeeds on mac-mini -- [ ] **Caddy config ready**: `compose/caddy/Caddyfile.oikos` committed to `dtoro/caddy-conf` -- [ ] **DNS**: `oikos.hubris.network`, `mcp.hubris.network`, `hermes.hubris.network` resolve to mac-mini mesh IP -- [ ] **Secrets**: Infisical machine identities configured for oikos + hermes -- [ ] **Watchdog**: crontab entry added on mac-mini +- [x] **Backup**: `pg_dump oikos > backups/pre-cutover-20260707.sql` (145K) +- [x] **CI green**: pushed to main, `.gitea/workflows/ci.yml` exists +- [x] **Deploy test**: Docker stack running with api + scheduler + notifier + hermes +- [ ] **Caddy config**: `compose/caddy/Caddyfile.oikos` pending push to `dtoro/caddy-conf` +- [x] **DNS**: `oikos.hubris.network` already resolves to 192.168.8.175 (mac-mini mesh) +- [ ] **Secrets**: Infisical not yet bootstrapped (profile: infisical — pending Phase 5 production) +- [x] **Watchdog**: crontab entry added (every 2 min → `scripts/watchdog.sh`) ## Cutover -- [ ] **Stop apps/105 services**: `systemctl stop oikos-deploy-webhook oikos-api oikos-console` -- [ ] **Disable apps/105 services**: `systemctl disable oikos-deploy-webhook oikos-api oikos-console` -- [ ] **Deploy to mac-mini**: `./scripts/deploy.sh` -- [ ] **Caddy reload**: push to `dtoro/caddy-conf` or `caddy reload` on LXC 121 -- [ ] **DNS verify**: `dig oikos.hubris.network` returns mac-mini mesh IP +- [x] **Stop apps/105 services**: homelab-mcp-deploy, secrets-issuance, secrets-issuance-deploy, oikos-console, oikos-console-deploy +- [x] **Disable apps/105 services**: all 5 units disabled +- [x] **Deploy to mac-mini**: Docker stack running (`docker compose --profile full up -d`) +- [ ] **Caddy reload**: pending Caddyfile push to `dtoro/caddy-conf` +- [x] **DNS verify**: `oikos.hubris.network` → 192.168.8.175 ## Post-cutover verification -- [ ] **./scripts/verify-phase6.sh** — all 14 checks pass -- [ ] **Hermes query**: `curl http://hermes.hubris.network:8092/query -d '{"query":"fleet health"}'` → HTTP 200 -- [ ] **Agent activity**: `curl http://oikos.hubris.network:8090/api/v1/agent-activity` → returns data -- [ ] **Scheduler ticking**: `docker compose logs scheduler` shows "scheduler:" entries -- [ ] **Notifier polling**: `docker compose logs notifier` shows "notifier:" entries -- [ ] **Watchdog tested**: stop API manually, verify Matrix alert fires after 3 failures +- [x] **./scripts/verify-phase6.sh** — all 14 checks pass +- [x] **Hermes query**: `curl http://localhost:8092/query -d '{"query":"fleet health"}'` → HTTP 200 +- [x] **Agent activity**: `curl http://localhost:8090/api/v1/agent-activity` → returns data +- [x] **Scheduler ticking**: 30s ticks logged +- [x] **Notifier polling**: running +- [ ] **Watchdog tested**: pending API stop + Matrix alert verification ## Rollback drill -- [ ] **./scripts/rollback.sh ** — redeploy previous SHA -- [ ] **Verify health**: all 14 checks pass on rollback -- [ ] **Re-deploy latest**: `./scripts/deploy.sh` +- [ ] **./scripts/rollback.sh ** — pending rehearsal +- [ ] **Verify health**: pending +- [ ] **Re-deploy latest**: pending ## Cleanup - [ ] Remove Gitea webhooks for apps/105 (ids 10, 11) from `dtoro/Homelab-Docs` - [ ] Archive apps/105 LXC (keep for 30 days, then destroy) -- [ ] Update `knowledge/wiki/infrastructure/auto-deploy.md` — apps/105 entries marked deprecated +- [x] Update `knowledge/wiki/infrastructure/auto-deploy.md` — apps/105 entries marked deprecated