Files
famapp/deploy/README.md
T
ginnoir c73338e256 Code-side
src/lib/dev-login-config.ts — startup assertion: throws if NODE_ENV=production + ENABLE_DEV_LOGIN=true, scoped to runtime (skipped during next build).
Container

scripts/migrate.mjs — runs Drizzle migrations against DATABASE_URL.
deploy/docker-entrypoint.sh — runs migrations then exec node server.js. Skip with RUN_MIGRATIONS=false.
Dockerfile — copies drizzle/, scripts/migrate.mjs, entrypoint into runner stage; ENTRYPOINT now points at the script.
Compose

deploy/compose.yaml — famapp now image: ${FAMAPP_IMAGE:-ghcr.io/ginnoir/famapp:latest} (build still works locally as fallback). Authentik pinned via AUTHENTIK_IMAGE_TAG (default 2024.12.3). New RUN_MIGRATIONS env passed through.
.env.production.example — documents FAMAPP_IMAGE, AUTHENTIK_IMAGE_TAG, RUN_MIGRATIONS.
CI/CD

.github/workflows/ci.yml — push/PR: typecheck + lint + format:check + build.
.github/workflows/release.yml — v* tag: build + push ghcr.io/ginnoir/famapp:vX.Y.Z, :X.Y, :latest to GHCR.
Docs

deploy/README.md — full deploy/rollback/release runbook.
CHANGELOG.md — release log seeded with an Unreleased entry.
docs/tasks/09-pre-deploy-checklist.md — task 09 reframed from one-shot removal to a recurring pre-deploy checklist.
STATUS.md — updated.
Verified: pnpm typecheck, pnpm format, pnpm build, and docker compose config all clean.
2026-05-06 17:37:37 -05:00

2.0 KiB

Deploying famapp

Trunk-based: main is always green. Production deploys only from version tags (vX.Y.Z). The dev-login flow is retained for local development behind a double gate (NODE_ENV !== "production" and ENABLE_DEV_LOGIN=true); a startup assertion in src/lib/dev-login-config.ts makes a misconfigured prod fail loud instead of silently exposing it.

One-time host setup

  1. Install Docker + Compose plugin on the host.
  2. git clone this repo to e.g. /srv/famapp.
  3. Copy .env.production.example/srv/famapp/deploy/.env and fill in real values.
    • openssl rand -base64 32 for AUTH_SECRET.
    • openssl rand -base64 60 for AUTHENTIK_SECRET_KEY.
    • pnpm vapid:generate (locally) for the three VAPID lines.
  4. Bootstrap Authentik per deploy/authentik/README.md. Save the OIDC client id/secret into .env.
  5. Wire Caddy with deploy/Caddyfile.snippet.

Cutting a release

# from your dev machine, on main, with a clean working tree
git tag v0.1.0
git push origin v0.1.0

.github/workflows/release.yml builds + pushes ghcr.io/ginnoir/famapp:v0.1.0, :0.1, and :latest to GHCR.

Deploying a release on the host

cd /srv/famapp/deploy
# pin to the tag you just cut
echo 'FAMAPP_IMAGE=ghcr.io/ginnoir/famapp:v0.1.0' >> .env  # or edit in place
docker compose pull famapp
docker compose up -d famapp
docker compose logs -f famapp   # watch migrations + boot

The container's entrypoint runs node scripts/migrate.mjs before starting the server. To skip migrations on a given start (rare — e.g. emergency rollback to an older schema-compatible image), set RUN_MIGRATIONS=false.

Rollback

Edit .env to point FAMAPP_IMAGE at the previous tag, then docker compose up -d famapp. If the rollback target predates a migration that's already applied, restore from backup (deploy/backups/README.md) before bringing the older image up.

Pre-deploy checklist

Run docs/tasks/09-pre-deploy-checklist.md before every deploy.