feat(deploy): add production one-click deployment

This commit is contained in:
2026-09-11 14:10:39 +08:00
parent 6eee55860f
commit a06d4f4199
5 changed files with 126 additions and 12 deletions
+13 -10
View File
@@ -9,19 +9,22 @@ sha256sum -c SHA256SUMS
docker load --input images/gochat-*-images.tgz
cp .env.example .env
# Replace every CHANGE_ME value and create the external secret/mount paths.
docker compose --env-file .env -f deploy/docker/docker-compose.prod.yml config --quiet
docker compose --env-file .env -f deploy/docker/docker-compose.prod.yml --profile ops run --rm migrate
docker compose --env-file .env -f deploy/docker/docker-compose.prod.yml up -d --wait
deploy/docker/deploy.sh .env --allow-local-images
```
`--allow-local-images` is only for this SHA256-verified bundle, whose loaded
application images use source-versioned local tags. For registry promotion,
replace both application image references with immutable `@sha256:` digests and
run the same command without that flag:
```bash
deploy/docker/deploy.sh .env
```
The bundle uses source-versioned local image tags so it can start immediately
after `docker load`; `SHA256SUMS` protects the handoff. Before registry-based
production promotion, push both images, replace the two image references in
`.env` with immutable `@sha256:` references, then run:
```bash
deploy/docker/preflight.sh .env
```
after `docker load`; `SHA256SUMS` protects the handoff. Registry-based
production promotion requires immutable `@sha256:` references and the strict
preflight performed by `deploy.sh` without `--allow-local-images`.
See `docs/ops/02-production-operations.md` for TLS, backup, rollback, and drill
requirements.