first commit
This commit is contained in:
24
staging/README.md
Normal file
24
staging/README.md
Normal file
@@ -0,0 +1,24 @@
|
||||
# Staging readiness gate
|
||||
|
||||
This directory does not contain a staging deployment and does not authorize any
|
||||
real integration. It provides a separate, network-disabled validation root for
|
||||
the non-secret decisions in `PRODUCTION_INPUTS.md`.
|
||||
|
||||
1. Complete the business and technical decisions in `PRODUCTION_INPUTS.md`.
|
||||
2. Copy `staging.env.example` to `staging.env` and replace the `TBD` values with
|
||||
non-secret metadata only. `staging.env` is ignored by Git and Docker builds.
|
||||
3. Run:
|
||||
|
||||
```bash
|
||||
docker compose -f compose.staging.yaml run --rm readiness
|
||||
```
|
||||
|
||||
The gate rejects incomplete values, local endpoints, fake provider selections,
|
||||
embedded secret-like settings, and unsafe secret-source choices. The readiness
|
||||
container has no network. A pass means only that the required non-secret inputs
|
||||
are structurally complete; it does not prove provider access, security, business
|
||||
approval, compatibility, or production readiness.
|
||||
|
||||
The actual staging application composition must be created only after these
|
||||
inputs and provider contracts are approved. Secrets must be injected from the
|
||||
approved external mechanism and must never be copied into this repository.
|
||||
Reference in New Issue
Block a user