# Deployment ## Production Production runs directly on Debian 13 with systemd. The only services deployed by this project are: - `sip-go-agent-dispatcher.service` - `sip-go-agent-agent.service` - the separately managed native `go-sip-asterisk.service` under `rogee`'s `systemd --user` (production requires lingering) RabbitMQ, OSS, AI providers and SaaS are external endpoints. They are not installed by the production package and are not started by systemd or Docker. Build a release candidate from the project root: ```sh deploys/build-package.sh # output: dist/packages/sip-go-agent--linux-amd64.tar.gz ``` Run `make release-check-local` for a disposable, checksum-verified local release and package **without installing anything**. Both builders reject any existing release directory, staging directory, archive, or checksum file; use a new version/output path instead of overwriting a prior package. The local builder intentionally marks the manifest as not production-approved. Only an externally approved, clean release (`source_dirty=false` and `production_approval=true`) may be installed on a Debian 13 amd64 host as root: ```sh tar -xzf sip-go-agent--linux-amd64.tar.gz ./install.sh ``` The package contains only the two Go services, their systemd units, production environment templates, the endpoint inventory, the version lock and the installer. Credentials, certificates, broker URLs and the approved static Cell artifact are injected separately. Asterisk is built or installed with the scripts under [`cell/`](cell/), and its management-owned configuration is never overwritten. The business call runtime remains **isolated Mock-only**; mixed/real startup is rejected. A separate `agent --mode sip-only` / `dispatcher --mode sip-only` lane can update native Asterisk endpoint/AOR objects from a complete approved SIP snapshot and durable `sip.config` notification. It requires preinstalled, management-reviewed UDP transport plus a private endpoint include, and never opens call admission or enables dialing. SIP-only does not make the current release production-approved. `config/agent-endpoints.example.json` is the only current local configuration example. Earlier Dispatcher and static Cell JSON examples are preserved byte-for-byte under [`docs/archive/deployment-examples/`](../docs/archive/deployment-examples/) for history only; they must not be loaded as current configuration or treated as management approval. Native Asterisk and non-production host diagnostics remain separately required when a real stage is explicitly authorized. The production install does not install test scripts, test fixtures, Docker or sudo rules for test tooling. ## Test-only tooling Test dependencies must run in disposable Docker containers. The existing `make mq-integration-local` target starts a temporary RabbitMQ container, runs the integration tests, and removes the container. Do not install RabbitMQ or other test infrastructure as a host service. [`test/nonprod-call-evidence.sh`](test/nonprod-call-evidence.sh) is a host-side capture-first gate for non-production mixed/real calls against native Asterisk. It is deliberately outside the production package and is not a business service. It still fails closed when root, `tcpdump`, Asterisk or the required system diagnostics are unavailable. The test directory also contains the offline OSS environment example and the AI fixture. They are test inputs only; they do not authorize external access and are never copied into a production release.