Files
oikos/scripts/cutover-checklist.md

2.4 KiB

Cutover checklist — Phase 6: apps/105 → Docker stack on mac-mini

Status: [x] = done, [ ] = pending

Pre-cutover

  • Backup: pg_dump oikos > backups/pre-cutover-20260707.sql (145K)
  • CI green: pushed to main, .gitea/workflows/ci.yml exists
  • Deploy test: Docker stack running with api + scheduler + notifier + hermes
  • Caddy config: compose/caddy/Caddyfile.oikos pushed to dtoro/caddy-conf (ed20908). Auto-deploys to caddy (121).
  • DNS: oikos.hubris.network already resolves to 192.168.8.175 (mac-mini mesh)
  • Secrets: Infisical not yet bootstrapped — blocked by Infisical v0.162.0 KMS migration bug (ERR_CRYPTO_INVALID_KEYLEN). SOPS fallback is active and working. Deferred pending upstream fix or version pin.
  • Watchdog: crontab entry added (every 2 min → scripts/watchdog.sh). Path fixed 2026-07-07 (was stale worktree path).

Cutover

  • Stop apps/105 services: homelab-mcp-deploy, secrets-issuance, secrets-issuance-deploy, oikos-console, oikos-console-deploy
  • Disable apps/105 services: all 5 units disabled
  • Deploy to mac-mini: Docker stack running (docker compose --profile full up -d)
  • Caddy reload: pushed to dtoro/caddy-conf — auto-deploy triggers on LXC 121.
  • DNS verify: oikos.hubris.network → 192.168.8.175

Post-cutover verification

  • ./scripts/verify-phase6.sh — all 14 checks pass
  • Hermes query: curl http://localhost:8092/query -d '{"query":"fleet health"}' → HTTP 200
  • Agent activity: curl http://localhost:8090/api/v1/agent-activity → returns data
  • Scheduler ticking: 30s ticks logged
  • Notifier polling: running
  • Watchdog tested: 2026-07-07 — API stop/reset cycle verified. Failure detection + counting + automatic reset all work. Crontab path fixed (was stale .claude/worktrees/goofy-austin-b648b8 path, now /Users/dtoro/Projects/oikos). Matrix alert path not tested — needs MATRIX_TOKEN for full end-to-end.

Rollback drill

  • ./scripts/rollback.sh — pending rehearsal
  • Verify health: pending
  • Re-deploy latest: pending

Cleanup

  • Remove Gitea webhooks for apps/105 (ids 10, 11) from dtoro/Homelab-Docs
  • Archive apps/105 LXC (keep for 30 days, then destroy)
  • Update auto-deploy docs — apps/105 entries marked deprecated