Repository navigation
Rehearse and execute the modernized production rollout with a tested rollback #176
Description
Activity
- addedenhancementNew feature or requestNew feature or requestpriority: P0Release blocker or critical operational prerequisiteRelease blocker or critical operational prerequisitearea: dataMongoDB, PostgreSQL, migrations, backfills, and data integrityMongoDB, PostgreSQL, migrations, backfills, and data integrityarea: platformBuild, CI, deployment, operations, and repository infrastructureBuild, CI, deployment, operations, and repository infrastructure
on Jul 10, 2026 Completed a safe, hermetic rollout safeguard in #245, promoted through #246 to master (1aefb3a). The new CI rehearsal verifies the existing MongoDB backup/restore command contract with synthetic bytes only: backup archive creation, explicit restore confirmation, no Docker action before confirmation, and the expected mongorestore drop/archive/gzip invocation. Master CI, Cypress, and CodeQL passed.\n\nThis is intentionally not a substitute for the remaining acceptance items: a fresh backup restored into a real non-production environment, production-shaped Compose/migration/startup rehearsal, rollback rehearsal against deployed-like services, and separately authorized production rollout/monitoring.
Further rollout preparation completed in #247 and promoted through #248 to master (5dd4256). The CI configuration now runs a live, isolated MongoDB rehearsal: two disposable mongo:7 containers on a temporary network, one synthetic attempt, mongodump, mongorestore --drop, verification, and cleanup. It passed locally and in PR/dev/master CI, Cypress, and CodeQL.\n\nThis validates the backup/restore mechanics without reading, copying, or restoring user data. It does not satisfy the remaining real non-production restore, production-shaped Compose/migration/rollback, or authorized production rollout requirements.
Goal
Ship the Node 22, Vite, MongoDB 7, Redis, Docker Compose, and PostgreSQL dual-write stack without making production the first full migration test.
Acceptance criteria
migrate deploy, API/socket startup, and health checks using production-shaped configuration.METRICS_HASH_SECRET, retention, TLS/CA settings where applicable, and confirm secrets are not logged.dev → masterrelease and monitor API/socket errors, auth failures, room events, PostgreSQL write failures, and resource use.References
README_DEPLOYMENT.md