Files
dtf-system/deploy
Cauê Faleiros eae3dad306
All checks were successful
Build and deploy / Validate source (push) Successful in 5s
Build and deploy / Integration suite on a real stack (push) Successful in 2m3s
Build and deploy / Secret scan and release gate (push) Successful in 5s
Build and deploy / Publish images (push) Successful in 1m31s
feat: offer credit card, debit card and PIX, with the bank's 3-D Secure step
The payment page lists credit card (preselected), debit card and PIX. Each
card option limits Mercado Pago's form to its kind; debit is paid at once.
Card payments ask for 3-D Secure when the issuer requires it, and a
challenge opens the bank's page in a frame, which needs
PAYMENT_CHALLENGE_SOURCES=https: (frames and form posts only). A card left
waiting for that confirmation stops blocking a new attempt after ten
minutes, and a refusal reported by the notification returns the customer to
the payment choice. Written from the documentation; not yet run with a real
debit card.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 13:24:06 -03:00
..
2026-09-15 16:42:34 -03:00

Production deployment files

The DTF application is one Portainer-owned Docker Swarm stack. Gitea builds, tests, scans, and publishes the two application images, then calls the stack's Portainer webhook. Start with the short operator guide in ../PORTAINER.md.

  • The deployed stack is the repository's docker-compose.yml, not a file here.
  • Dockerfile.api and Dockerfile.web — prebuilt registry images.
  • portainer.env.example — non-secret Portainer variables.
  • production_preflight.py — fail-closed application/configuration validator.
  • PRODUCTION_CHECKLIST.md — production evidence checklist.

The current application remains deliberately blocked from production because real adapters and Docker-secret file loading are absent and current validation base images have unresolved HIGH/CRITICAL findings. No real provider or production service has been configured or contacted.