Thirteen files at the repository root, seven of them documents. Only README.md earns a place there; the rest are now in docs/ beside the meeting notes, the client roadmap and the historical material. The compose files stay. docker-compose.yml is the path the dtf-cloud Portainer stack reads, so moving it would break deployment, and Docker resolves a compose file's relative build contexts against its own directory, so moving the other two would silently break every build. Both reasons are now written down where someone would otherwise try it. Correcting references turned up a live fault: the Portainer stack creation instructions still named deploy/stack.yaml as the compose path. That file was removed, so anyone recreating the stack from these instructions would have failed. It names docker-compose.yml now, with the reason it stays at the root. ROADMAP.md keeps the paths its closed findings were written with, and says so at the top. Those entries record where a fault was when it was found; rewriting them to match a later layout would make the record less true, not more. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
1.1 KiB
Staging readiness gate
This directory does not contain a staging deployment and does not authorize any
real integration. It provides a separate, network-disabled validation root for
the non-secret decisions in docs/PRODUCTION_INPUTS.md.
-
Complete the business and technical decisions in
docs/PRODUCTION_INPUTS.md. -
Copy
staging.env.exampletostaging.envand replace theTBDvalues with non-secret metadata only.staging.envis ignored by Git and Docker builds. -
Run:
docker compose -f compose.staging.yaml run --rm readiness
The gate rejects incomplete values, local endpoints, fake provider selections, embedded secret-like settings, and unsafe secret-source choices. The readiness container has no network. A pass means only that the required non-secret inputs are structurally complete; it does not prove provider access, security, business approval, compatibility, or production readiness.
The actual staging application composition must be created only after these inputs and provider contracts are approved. Secrets must be injected from the approved external mechanism and must never be copied into this repository.