deployment files
This commit is contained in:
@@ -1,2 +1,3 @@
|
|||||||
/target
|
/target
|
||||||
*.db*
|
*.db*
|
||||||
|
*.log*
|
||||||
|
|||||||
Generated
+1
-1
@@ -868,7 +868,7 @@ dependencies = [
|
|||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "hagfish"
|
name = "hagfisk"
|
||||||
version = "0.0.5"
|
version = "0.0.5"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
|
|||||||
+1
-1
@@ -1,5 +1,5 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "hagfish"
|
name = "hagfisk"
|
||||||
version = "0.0.5"
|
version = "0.0.5"
|
||||||
edition = "2024"
|
edition = "2024"
|
||||||
description = "Faroese fisheries data pipeline and dashboard"
|
description = "Faroese fisheries data pipeline and dashboard"
|
||||||
|
|||||||
@@ -0,0 +1,85 @@
|
|||||||
|
version: '3'
|
||||||
|
|
||||||
|
env:
|
||||||
|
HOST: bl@flo-homeserver
|
||||||
|
HAGFISK_DIR: ~/hagfisk
|
||||||
|
SERVICE_DIR: ~/.config/systemd/user
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
build:
|
||||||
|
desc: Build binary locally
|
||||||
|
cmds:
|
||||||
|
- echo "Building hagfisk binary..."
|
||||||
|
- cargo build --release
|
||||||
|
|
||||||
|
deploy:
|
||||||
|
desc: Sync binary to server
|
||||||
|
deps: [build]
|
||||||
|
cmds:
|
||||||
|
- ssh -q {{.HOST}} "rm -rf {{.HAGFISK_DIR}}/hagfisk"
|
||||||
|
- echo "Syncing binary to remote..."
|
||||||
|
- rsync -avz --progress ./target/release/hagfisk {{.HOST}}:{{.HAGFISK_DIR}}/hagfisk
|
||||||
|
- echo "Restoring SELinux contexts..."
|
||||||
|
- ssh -t -q {{.HOST}} "sudo restorecon -RF {{.HAGFISK_DIR}}"
|
||||||
|
- ssh -q {{.HOST}} "systemctl --user daemon-reload"
|
||||||
|
- ssh -q {{.HOST}} "systemctl --user restart hagfisk.service"
|
||||||
|
|
||||||
|
enable-now-app:
|
||||||
|
desc: Enable now service
|
||||||
|
cmds:
|
||||||
|
- ssh {{.HOST}} "systemctl --user enable --now hagfisk.service"
|
||||||
|
|
||||||
|
start-app:
|
||||||
|
desc: Start service on remote
|
||||||
|
cmds:
|
||||||
|
- ssh {{.HOST}} "systemctl --user start hagfisk.service"
|
||||||
|
|
||||||
|
stop-app:
|
||||||
|
desc: Stop service on remote
|
||||||
|
cmds:
|
||||||
|
- ssh {{.HOST}} "systemctl --user stop hagfisk.service"
|
||||||
|
|
||||||
|
restart-app:
|
||||||
|
desc: Restart service on remote
|
||||||
|
cmds:
|
||||||
|
- ssh {{.HOST}} "systemctl --user restart hagfisk.service"
|
||||||
|
|
||||||
|
logs-app:
|
||||||
|
desc: Stream logs from remote
|
||||||
|
cmds:
|
||||||
|
- ssh {{.HOST}} "journalctl --user -u hagfisk -f"
|
||||||
|
|
||||||
|
ps-app:
|
||||||
|
desc: Show status of hagfisk
|
||||||
|
cmds:
|
||||||
|
- ssh {{.HOST}} "systemctl --user status hagfisk.service"
|
||||||
|
|
||||||
|
enable-now-ingest:
|
||||||
|
desc: Enable now service
|
||||||
|
cmds:
|
||||||
|
- ssh {{.HOST}} "systemctl --user enable --now hagfisk-ingest.service hagfisk-ingest.timer"
|
||||||
|
|
||||||
|
start-ingest:
|
||||||
|
desc: Start service on remote
|
||||||
|
cmds:
|
||||||
|
- ssh {{.HOST}} "systemctl --user start hagfisk-ingest.service hagfisk-ingest.timer"
|
||||||
|
|
||||||
|
stop-ingest:
|
||||||
|
desc: Stop service on remote
|
||||||
|
cmds:
|
||||||
|
- ssh {{.HOST}} "systemctl --user stop hagfisk-ingest.service hagfisk-ingest.timer"
|
||||||
|
|
||||||
|
restart-ingest:
|
||||||
|
desc: Restart service on remote
|
||||||
|
cmds:
|
||||||
|
- ssh {{.HOST}} "systemctl --user restart hagfisk-ingest.service hagfisk-ingest.timer"
|
||||||
|
|
||||||
|
logs-ingest:
|
||||||
|
desc: Stream logs from remote
|
||||||
|
cmds:
|
||||||
|
- ssh {{.HOST}} "journalctl --user -u hagfisk-ingest -f"
|
||||||
|
|
||||||
|
ps-ingest:
|
||||||
|
desc: Show status of hagfisk
|
||||||
|
cmds:
|
||||||
|
- ssh {{.HOST}} "systemctl --user status hagfisk-ingest.service"
|
||||||
+7
-8
@@ -93,7 +93,6 @@ hagfish/
|
|||||||
- [ ] 🔒 CORS hardening — Replace `CorsLayer::permissive()` with explicit allowed origins before production deployment
|
- [ ] 🔒 CORS hardening — Replace `CorsLayer::permissive()` with explicit allowed origins before production deployment
|
||||||
- [ ] 🔒 Rate limiting — Optional: add `tower_governor` middleware to prevent abuse on public deployments
|
- [ ] 🔒 Rate limiting — Optional: add `tower_governor` middleware to prevent abuse on public deployments
|
||||||
- [ ] ⚠️ Startup config validation — Verify `data_source_url` is reachable, `duckdb_path` is writable before accepting connections
|
- [ ] ⚠️ Startup config validation — Verify `data_source_url` is reachable, `duckdb_path` is writable before accepting connections
|
||||||
- [ ] 📊 Metrics export (Prometheus) — Optional: track request counts, latencies, error rates via `prometheus` crate
|
|
||||||
|
|
||||||
### Phase 4: Frontend
|
### Phase 4: Frontend
|
||||||
|
|
||||||
@@ -115,17 +114,17 @@ hagfish/
|
|||||||
|
|
||||||
### Phase 6: Bare Metal Deployment
|
### Phase 6: Bare Metal Deployment
|
||||||
|
|
||||||
- [ ] 6.1 Write systemd service unit file (hagfish.service) — ExecStart=/usr/local/bin/hagfish serve, restart policy
|
- [x] 6.1 Write systemd service unit file (hagfish.service) — ExecStart=/usr/local/bin/hagfish serve, restart policy
|
||||||
- [ ] 6.2 Write systemd timer (hagfish-ingest.timer + hagfish-ingest.service) — monthly, runs hagfish ingest
|
- [x] 6.2 Write systemd timer (hagfish-ingest.timer + hagfish-ingest.service) — monthly, runs hagfish ingest
|
||||||
- [ ] 6.3 Taskfile: build (release, static), deploy (rsync binary + config + units, ssh reload)
|
- [x] 6.3 Taskfile: build (release, static), deploy (rsync binary + config + units, ssh reload)
|
||||||
- [ ] 6.4 README with ELI5 Technology Choices section (why DuckDB, why Rust, why embedded static assets)
|
- [ ] 6.4 README with ELI5 Technology Choices section (why DuckDB, why Rust, why embedded static assets)
|
||||||
|
|
||||||
|
### Phase 7: post deploy fixes
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Current Status
|
## Current Status
|
||||||
|
|
||||||
**Phase 1**: Complete ✅
|
**Bug Fixes**: Next up
|
||||||
**Phase 2**: Complete ✅
|
|
||||||
**Phase 3**: Complete ✅ (API operational, tests passing)
|
|
||||||
**Production Hardening**: Deferred ⏸️
|
**Production Hardening**: Deferred ⏸️
|
||||||
**Phase 4-6**: Pending — Start after MVP validation
|
|
||||||
|
|||||||
Reference in New Issue
Block a user