ci: deploy from the keycloak-production environment - #21
Merged
Merged
Conversation
auth.civicdatalab.in serves production auth for every CivicDataLab product, so the deploy should not run under an environment named staging. This could not be done in the promotion PR: GitHub cannot move secrets between environments, and the deploy's SSH credentials were scoped to keycloak-staging. EC2_HOST, EC2_USERNAME and EC2_PRIVATE_KEY have now been added to keycloak-production, verified present, so the workflow can point at it. keycloak-staging is deliberately left in place. A missing environment secret surfaces as an opaque ssh authentication failure rather than "secret not found", so being able to flip back in one line is worth keeping until a deploy has succeeded from the new environment. The container names, the kc_postgres_data volume and DEPLOY_PATH still say staging and still must not be renamed - those are on the running server, and changing them orphans the container or empties the database.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Completes the promotion started in #19/#20.
auth.civicdatalab.in serves production auth for every CivicDataLab product, so the deploy should not run under an environment named staging.
Why this is a separate PR
GitHub cannot move secrets between environments, and the deploy's SSH credentials were scoped to
keycloak-staging. Pointing at a new environment before the secrets existed there would have broken the deploy.EC2_HOST,EC2_USERNAMEandEC2_PRIVATE_KEYare now present onkeycloak-productionand verified, so the switch is safe.keycloak-staging is left in place
Deliberately. A missing environment secret surfaces as an opaque
ssh: handshake failedrather than "secret not found", so the ability to flip back in one line is worth keeping until a deploy has succeeded from the new environment. Delete it after that.Still not renamed
Container names, the
kc_postgres_datavolume andDEPLOY_PATHstill say "staging" — those live on the running server. Renaming the container orphans the live one; renaming the volume empties the database. Comments in the workflow explain this at each site.Worth doing while you are here
keycloak-productionis where a required reviewer would be configured if production auth deploys should need approval before running. That is the main practical benefit of the rename beyond naming, and it is a one-click setting on the environment.