# Production release checklist Every item is required. A checked box records reviewed evidence; it is not a substitute for `production_preflight.py`, CI, staging acceptance, or change approval. ## Application and external contracts - [ ] `docs/PRODUCTION_INPUTS.md` has owners, decisions, and evidence for every item. - [ ] Production R2, freight, Mercado Pago, Tiny/Olist, and WhatsApp adapters have sandbox contract tests and least-privilege credentials. - [ ] Payment webhook authenticity, replay handling, and idempotency are tested. - [ ] Docker secret `*_FILE` loading is implemented and tested without logging values. - [ ] Production account verification/recovery and the length/grade authority flow are approved. - [ ] No factory automation or automatic print pre-flight was added by inference. ## Platform and recovery - [ ] DNS/TLS proxy routes and firewall rules are approved; only Site and Kanban have published web ports. - [ ] External, versioned Swarm secrets exist and match the configured names. - [ ] The PostgreSQL volume is encrypted/backed up and pinned to the labeled node. - [ ] Scheduled offsite database/object backups and an isolated restore rehearsal pass. - [ ] ClamAV signatures are current and have a controlled update/rebuild process. - [ ] Central alerts, logs, clocks, capacity, and on-call ownership are verified. ## Release and deploy - [ ] Protected Gitea runner, `main` branch, registry permissions, and variables are reviewed. - [ ] Base, database, and scanner images use approved immutable digests; application SHA tags remain pullable and the digest resolved by each deployment is recorded. - [ ] Full regressions and production preflight pass on the exact release commit. - [ ] HIGH/CRITICAL Trivy findings are fixed or formally risk-accepted with evidence. - [ ] Staging acceptance passes with provider sandboxes and production-like topology. - [ ] Four production approval variables equal `approved` only after their reviews. - [ ] The generated `docker stack config` contains no secret values or placeholders. - [ ] Health probes, monitoring, rollback, and a backup restore are observed in staging. - [ ] The Portainer webhook redeploys the one `dtf-cloud` stack and post-deploy HTTPS health probes pass. ## Rollback - [ ] Previous application image digests remain pullable. - [ ] Portainer rollback by full commit `IMAGE_TAG` has been rehearsed; it does not roll back the database. - [ ] Database migration forward/restore ownership and maintenance procedure are approved.