Add registry-based prod promotion, separate from auto dev deploy
Deploy to Dev / Deploy & Smoke Test (push) Successful in 20s
Deploy to Prod / Deploy & Smoke Test (prod) (push) Failing after 30s

Dev keeps auto-deploying on every push to main, same as before, but now
also publishes each build to git.jerodrigged.com's container registry
tagged by short commit SHA (best-effort - never blocks the dev deploy
if REGISTRY_TOKEN isn't set yet).

Prod deploys only on an intentional `git push origin main:prod`, and
only ever pulls a pre-built SHA-tagged image - it never rebuilds from
source. This guarantees prod runs the exact artifact dev already
validated, and makes promoting an untested commit fail loudly (pull of
a nonexistent tag) instead of silently rebuilding something new.

Needs new secrets before the prod path works: PROD_SSH_KEY, PROD_HOST,
PROD_USER, REGISTRY_USER, REGISTRY_TOKEN. PROD_SSH_KEY/PROD_HOST/
REGISTRY_USER are already set; PROD_USER and REGISTRY_TOKEN still need
Jerod's input.
This commit is contained in:
2026-07-20 04:47:49 +00:00
parent 53677c9f6c
commit 016256cd2f
5 changed files with 130 additions and 6 deletions
+2
View File
@@ -5,6 +5,7 @@ services:
build:
context: .
dockerfile: Dockerfile
image: lisilou-portfolio-web:local
container_name: lisilou-portfolio
restart: unless-stopped
ports:
@@ -29,6 +30,7 @@ services:
build:
context: ./api
dockerfile: Dockerfile
image: lisilou-portfolio-api:local
container_name: lisilou-api
restart: unless-stopped
env_file: