Skip to content

ci: deploy from the keycloak-production environment - #21

Merged
saqibmanan merged 1 commit into
mainfrom
ci-point-at-production-environment
Sep 8, 2026
Merged

saqibmanan merged 1 commit into
mainfrom
ci-point-at-production-environment

Conversation

@saqibmanan

Copy link
Copy Markdown
Contributor

Completes the promotion started in #19/#20.

auth.civicdatalab.in serves production auth for every CivicDataLab product, so the deploy should not run under an environment named staging.

Why this is a separate PR

GitHub cannot move secrets between environments, and the deploy's SSH credentials were scoped to keycloak-staging. Pointing at a new environment before the secrets existed there would have broken the deploy.

EC2_HOST, EC2_USERNAME and EC2_PRIVATE_KEY are now present on keycloak-production and verified, so the switch is safe.

keycloak-staging is left in place

Deliberately. A missing environment secret surfaces as an opaque ssh: handshake failed rather than "secret not found", so the ability to flip back in one line is worth keeping until a deploy has succeeded from the new environment. Delete it after that.

Still not renamed

Container names, the kc_postgres_data volume and DEPLOY_PATH still say "staging" — those live on the running server. Renaming the container orphans the live one; renaming the volume empties the database. Comments in the workflow explain this at each site.

Worth doing while you are here

keycloak-production is where a required reviewer would be configured if production auth deploys should need approval before running. That is the main practical benefit of the rename beyond naming, and it is a one-click setting on the environment.

auth.civicdatalab.in serves production auth for every CivicDataLab
product, so the deploy should not run under an environment named
staging.

This could not be done in the promotion PR: GitHub cannot move secrets
between environments, and the deploy's SSH credentials were scoped to
keycloak-staging. EC2_HOST, EC2_USERNAME and EC2_PRIVATE_KEY have now
been added to keycloak-production, verified present, so the workflow can
point at it.

keycloak-staging is deliberately left in place. A missing environment
secret surfaces as an opaque ssh authentication failure rather than
"secret not found", so being able to flip back in one line is worth
keeping until a deploy has succeeded from the new environment.

The container names, the kc_postgres_data volume and DEPLOY_PATH still
say staging and still must not be renamed - those are on the running
server, and changing them orphans the container or empties the database.
@saqibmanan
saqibmanan merged commit f105af6 into main Sep 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant