43 lines
2.8 KiB
Markdown
43 lines
2.8 KiB
Markdown
# Physical production deployment
|
|
|
|
This is the **target host layout**, not an approved deployment of the current binary. The current business commands are isolated Mock-only and reject mixed/real before opening resources; the local release manifest has `production_approval=false`. Neither the steps below nor a local package/check authorize real services or calls. Native Asterisk loading and required non-production diagnostics still need separate evidence.
|
|
|
|
Debian 12 amd64 is supported only for explicitly marked non-production test hosts.
|
|
Build the native Asterisk archive **on Debian 12** with `NONPROD=1`; the
|
|
installer requires its matching `build-platform` marker and `--nonprod`.
|
|
The existing Debian 13 binary requires newer glibc and must never be copied
|
|
to Debian 12. This exception does not approve production deployment or real calls.
|
|
|
|
Production remains a small systemd installation on Debian 13 amd64:
|
|
|
|
1. native Asterisk Cell (`go-sip-asterisk.service`) under `rogee`'s `systemd --user`,
|
|
with lingering enabled and reboot-persistent `enabled+active` verified;
|
|
2. `sip-go-agent-agent.service`;
|
|
3. `sip-go-agent-dispatcher.service`.
|
|
|
|
This project does not run production services in Docker and does not install
|
|
RabbitMQ, OSS, AI or SaaS infrastructure. Those systems are supplied through
|
|
injected endpoints and credentials.
|
|
|
|
The pinned versions are in [`versions.lock.json`](versions.lock.json). Build
|
|
a release candidate with `build-package.sh`; it writes the archive to
|
|
`dist/packages/` and is intentionally not production-approved. Production
|
|
installation requires a clean, externally approved manifest. Build/install
|
|
Asterisk separately with the scripts in [`cell/`](cell/). The Asterisk user installer preserves existing files and places the Cell
|
|
configuration under `~rogee/.config/go-sip-asterisk/`; management approves and
|
|
updates `pjsip.conf` separately. Run `install-asterisk-user.sh --nonprod <native-package-dir>`
|
|
for a Debian 12 test build; without `--nonprod`, user lingering is required
|
|
before installation. Without lingering, non-production start is session-scoped
|
|
and reboot persistence must be reported as unverified.
|
|
|
|
The Go installer creates `/opt/sip-go-agent`, `/etc/sip-go-agent` and
|
|
`/var/lib/sip-go-agent`, installs the two Go units, and enables them. It does
|
|
not install test tooling, Docker, a broker, provider SDK credentials or AI
|
|
snapshots. Start services only after the injected environment, mTLS identity,
|
|
broker ACL and static Cell artifact have been reviewed.
|
|
|
|
For local or isolated testing, use the Docker-backed RabbitMQ target
|
|
`make mq-integration-local`. Use [`test/nonprod-call-evidence.sh`](test/nonprod-call-evidence.sh)
|
|
for the required capture-first gate when testing against a native non-production
|
|
Asterisk host. Neither path is part of the production package.
|