47 lines
2.5 KiB
Markdown
47 lines
2.5 KiB
Markdown
# Production release checklist
|
|
|
|
Every item is required. A checked box records reviewed evidence; it is not a
|
|
substitute for `production_preflight.py`, CI, staging acceptance, or change approval.
|
|
|
|
## Application and external contracts
|
|
|
|
- [ ] `PRODUCTION_INPUTS.md` has owners, decisions, and evidence for every item.
|
|
- [ ] Production R2, freight, Mercado Pago, Tiny/Olist, and WhatsApp adapters have
|
|
sandbox contract tests and least-privilege credentials.
|
|
- [ ] Payment webhook authenticity, replay handling, and idempotency are tested.
|
|
- [ ] Docker secret `*_FILE` loading is implemented and tested without logging values.
|
|
- [ ] Production account verification/recovery and the length/grade authority flow
|
|
are approved.
|
|
- [ ] No factory automation or automatic print pre-flight was added by inference.
|
|
|
|
## Platform and recovery
|
|
|
|
- [ ] DNS/TLS proxy routes and firewall rules are approved; only Site and Kanban
|
|
have published web ports.
|
|
- [ ] External, versioned Swarm secrets exist and match the configured names.
|
|
- [ ] The PostgreSQL volume is encrypted/backed up and pinned to the labeled node.
|
|
- [ ] Scheduled offsite database/object backups and an isolated restore rehearsal pass.
|
|
- [ ] ClamAV signatures are current and have a controlled update/rebuild process.
|
|
- [ ] Central alerts, logs, clocks, capacity, and on-call ownership are verified.
|
|
|
|
## Release and deploy
|
|
|
|
- [ ] Protected Gitea runner, `main` branch, registry permissions, and variables are reviewed.
|
|
- [ ] Base, database, and scanner images use approved immutable digests; application
|
|
SHA tags remain pullable and the digest resolved by each deployment is recorded.
|
|
- [ ] Full regressions and production preflight pass on the exact release commit.
|
|
- [ ] HIGH/CRITICAL Trivy findings are fixed or formally risk-accepted with evidence.
|
|
- [ ] Staging acceptance passes with provider sandboxes and production-like topology.
|
|
- [ ] Four production approval variables equal `approved` only after their reviews.
|
|
- [ ] The generated `docker stack config` contains no secret values or placeholders.
|
|
- [ ] Health probes, monitoring, rollback, and a backup restore are observed in staging.
|
|
- [ ] The Portainer webhook redeploys the one `dtf-cloud` stack and post-deploy
|
|
HTTPS health probes pass.
|
|
|
|
## Rollback
|
|
|
|
- [ ] Previous application image digests remain pullable.
|
|
- [ ] Portainer rollback by full commit `IMAGE_TAG` has been rehearsed; it does
|
|
not roll back the database.
|
|
- [ ] Database migration forward/restore ownership and maintenance procedure are approved.
|