deployment files

This commit is contained in:
2026-08-19 10:39:38 +01:00
parent 20786a9e14
commit 8fb8d507a4
5 changed files with 95 additions and 10 deletions
+7 -8
View File
@@ -93,7 +93,6 @@ hagfish/
- [ ] 🔒 CORS hardening — Replace `CorsLayer::permissive()` with explicit allowed origins before production deployment
- [ ] 🔒 Rate limiting — Optional: add `tower_governor` middleware to prevent abuse on public deployments
- [ ] ⚠️ Startup config validation — Verify `data_source_url` is reachable, `duckdb_path` is writable before accepting connections
- [ ] 📊 Metrics export (Prometheus) — Optional: track request counts, latencies, error rates via `prometheus` crate
### Phase 4: Frontend
@@ -115,17 +114,17 @@ hagfish/
### Phase 6: Bare Metal Deployment
- [ ] 6.1 Write systemd service unit file (hagfish.service) — ExecStart=/usr/local/bin/hagfish serve, restart policy
- [ ] 6.2 Write systemd timer (hagfish-ingest.timer + hagfish-ingest.service) — monthly, runs hagfish ingest
- [ ] 6.3 Taskfile: build (release, static), deploy (rsync binary + config + units, ssh reload)
- [x] 6.1 Write systemd service unit file (hagfish.service) — ExecStart=/usr/local/bin/hagfish serve, restart policy
- [x] 6.2 Write systemd timer (hagfish-ingest.timer + hagfish-ingest.service) — monthly, runs hagfish ingest
- [x] 6.3 Taskfile: build (release, static), deploy (rsync binary + config + units, ssh reload)
- [ ] 6.4 README with ELI5 Technology Choices section (why DuckDB, why Rust, why embedded static assets)
### Phase 7: post deploy fixes
---
## Current Status
**Phase 1**: Complete ✅
**Phase 2**: Complete ✅
**Phase 3**: Complete ✅ (API operational, tests passing)
**Bug Fixes**: Next up
**Production Hardening**: Deferred ⏸️
**Phase 4-6**: Pending — Start after MVP validation