Files
go-sip/deploys/physical-deployment.md
T

2.8 KiB

Physical production deployment

This is the target host layout, not an approved deployment of the current binary. The current business commands are isolated Mock-only and reject mixed/real before opening resources; the local release manifest has production_approval=false. Neither the steps below nor a local package/check authorize real services or calls. Native Asterisk loading and required non-production diagnostics still need separate evidence.

Debian 12 amd64 is supported only for explicitly marked non-production test hosts. Build the native Asterisk archive on Debian 12 with NONPROD=1; the installer requires its matching build-platform marker and --nonprod. The existing Debian 13 binary requires newer glibc and must never be copied to Debian 12. This exception does not approve production deployment or real calls.

Production remains a small systemd installation on Debian 13 amd64:

  1. native Asterisk Cell (go-sip-asterisk.service) under rogee's systemd --user, with lingering enabled and reboot-persistent enabled+active verified;
  2. sip-go-agent-agent.service;
  3. sip-go-agent-dispatcher.service.

This project does not run production services in Docker and does not install RabbitMQ, OSS, AI or SaaS infrastructure. Those systems are supplied through injected endpoints and credentials.

The pinned versions are in versions.lock.json. Build a release candidate with build-package.sh; it writes the archive to dist/packages/ and is intentionally not production-approved. Production installation requires a clean, externally approved manifest. Build/install Asterisk separately with the scripts in cell/. The Asterisk user installer preserves existing files and places the Cell configuration under ~rogee/.config/go-sip-asterisk/; management approves and updates pjsip.conf separately. Run install-asterisk-user.sh --nonprod <native-package-dir> for a Debian 12 test build; without --nonprod, user lingering is required before installation. Without lingering, non-production start is session-scoped and reboot persistence must be reported as unverified.

The Go installer creates /opt/sip-go-agent, /etc/sip-go-agent and /var/lib/sip-go-agent, installs the two Go units, and enables them. It does not install test tooling, Docker, a broker, provider SDK credentials or AI snapshots. Start services only after the injected environment, mTLS identity, broker ACL and static Cell artifact have been reviewed.

For local or isolated testing, use the Docker-backed RabbitMQ target make mq-integration-local. Use test/nonprod-call-evidence.sh for the required capture-first gate when testing against a native non-production Asterisk host. Neither path is part of the production package.