Cut production over (#26) #34

Merged
sulthan merged 3 commits from feat/cut-production-over into main 2026-08-08 16:06:48 +07:00
Owner

Preparatory work for #26, plus one blocker found by rehearsing the runbook against the real host.

  • Corrects CUTOVER.md and REDEPLOY.md against the actual deployment: volume derived from the compose project rather than hardcoded, WAL asserted instead of assumed, jq replaced with python3, stale $VOL and /opt paths fixed, REDEPLOY's pre-split table lists updated.
  • Completes README's environment contract, which listed 8 of the backend's 25 variables and omitted the whole DISCORD_* set that gates startup.
  • Fixes the guild-membership check, which called Discord's bot endpoint with a user Bearer token and would have made every sign-in fail with "Discord sign-in is unavailable right now".

Full suite green. Cutover itself is executed against production separately; ACs tracked on #26.

Preparatory work for #26, plus one blocker found by rehearsing the runbook against the real host. - Corrects CUTOVER.md and REDEPLOY.md against the actual deployment: volume derived from the compose project rather than hardcoded, WAL asserted instead of assumed, jq replaced with python3, stale $VOL and /opt paths fixed, REDEPLOY's pre-split table lists updated. - Completes README's environment contract, which listed 8 of the backend's 25 variables and omitted the whole DISCORD_* set that gates startup. - Fixes the guild-membership check, which called Discord's bot endpoint with a user Bearer token and would have made every sign-in fail with "Discord sign-in is unavailable right now". Full suite green. Cutover itself is executed against production separately; ACs tracked on #26.
sulthan added 3 commits 2026-08-08 16:05:51 +07:00
Dry-running CUTOVER.md against production surfaced four things that would
have failed mid-cutover:

- The volume is named after the compose project, which is the lowercased
  directory name (mangabookmark), not the repo name. Both runbooks hardcoded
  bookmarkmanager_bookmarks-data. Derive it from docker instead.
- §1 asserted a clean stop leaves no -wal. compose stop SIGKILLs after 10s,
  and a surviving -wal holds writes bookmarks.db alone does not, so the
  export would silently lose them. Check rather than assume.
- jq is not installed on the server; §5's read-path check now uses python3,
  which the runbook already requires.
- REDEPLOY §1 still listed the pre-split table set, omitting readers and
  sessions from both the \dt output and the pg_restore contents.

Also records the git-pull failure the redeploy hits on a checkout whose
remote is the HTTPS clone URL.
Review findings on the previous commit:

- README's config table listed 8 of the backend's 25 environment variables,
  omitting the whole DISCORD_* set that the backend refuses to start without.
  The canonical reference cannot be missing the vars that gate startup.
- `docker volume ls --filter name=` is a substring match. Both runbooks used
  it to find a volume they then mount read-only or delete; a second matching
  volume makes the mount fail obscurely and the delete take both. Derive the
  name exactly from the compose project instead.
- CUTOVER §6 removes the retired volume 'once the Postgres data has been
  trusted for a while', in a shell where §1's $VOL no longer exists.
- REDEPLOY and DEPLOY still pointed at /opt/bookmarkmanager, so CUTOVER §6's
  handoff to REDEPLOY §1 sent the operator to a path that does not exist.
The login gate called GET /guilds/{guild}/members/{user} — the Guild
resource's Get Guild Member, which wants a Bot token and the application
present in the guild. Handed a user Bearer token it answers 401, which
discordMember reports as an error, so every sign-in rendered "Discord
sign-in is unavailable right now" and nobody could get in.

The endpoint guilds.members.read actually grants is Get Current User Guild
Member, GET /users/@me/guilds/{guild}/member. Same single-guild question,
same privacy property, and it takes the token we hold. #18 flagged this as
verified from Discord's documentation but never from a live flow; it was
wrong.

The stub mirrored the implementation, so the suite could not see it. It now
serves the OAuth path and answers the bot path 401 the way Discord does —
without that, a regression falls through to 404 and reads as an ordinary
"not a member" refusal instead of failing.
sulthan merged commit 1b1820d85a into main 2026-08-08 16:06:48 +07:00
Sign in to join this conversation.