2.8 KiB
Physical production deployment
This is the target host layout, not an approved deployment of the current binary. The current business commands are isolated Mock-only and reject mixed/real before opening resources; the local release manifest has production_approval=false. Neither the steps below nor a local package/check authorize real services or calls. Native Asterisk loading and required non-production diagnostics still need separate evidence.
Debian 12 amd64 is supported only for explicitly marked non-production test hosts.
Build the native Asterisk archive on Debian 12 with NONPROD=1; the
installer requires its matching build-platform marker and --nonprod.
The existing Debian 13 binary requires newer glibc and must never be copied
to Debian 12. This exception does not approve production deployment or real calls.
Production remains a small systemd installation on Debian 13 amd64:
- native Asterisk Cell (
go-sip-asterisk.service) underrogee'ssystemd --user, with lingering enabled and reboot-persistentenabled+activeverified; sip-go-agent-agent.service;sip-go-agent-dispatcher.service.
This project does not run production services in Docker and does not install RabbitMQ, OSS, AI or SaaS infrastructure. Those systems are supplied through injected endpoints and credentials.
The pinned versions are in versions.lock.json. Build
a release candidate with build-package.sh; it writes the archive to
dist/packages/ and is intentionally not production-approved. Production
installation requires a clean, externally approved manifest. Build/install
Asterisk separately with the scripts in cell/. The Asterisk user installer preserves existing files and places the Cell
configuration under ~rogee/.config/go-sip-asterisk/; management approves and
updates pjsip.conf separately. Run install-asterisk-user.sh --nonprod <native-package-dir>
for a Debian 12 test build; without --nonprod, user lingering is required
before installation. Without lingering, non-production start is session-scoped
and reboot persistence must be reported as unverified.
The Go installer creates /opt/sip-go-agent, /etc/sip-go-agent and
/var/lib/sip-go-agent, installs the two Go units, and enables them. It does
not install test tooling, Docker, a broker, provider SDK credentials or AI
snapshots. Start services only after the injected environment, mTLS identity,
broker ACL and static Cell artifact have been reviewed.
For local or isolated testing, use the Docker-backed RabbitMQ target
make mq-integration-local. Use test/nonprod-call-evidence.sh
for the required capture-first gate when testing against a native non-production
Asterisk host. Neither path is part of the production package.