feat: publish Tend v0.2 Preview 2 source
Export the reviewed allowlisted snapshot from private source commit 8aab3db43f35e6a49aa497f45d73701b13fc9f32 and tree 992132ea4703437dc13ffdbb04a077816c02caf9. This includes routed singleton continuity, deployment evidence, strict schema-2 configuration, restricted transport, and the independently compilable public-tree guard. AI-Assisted: OpenAI Codex Signed-off-by: Cole Speelman <crspeelman@gmail.com>
This commit is contained in:
+12
-1
@@ -18,13 +18,24 @@ the isolated candidate address. Secret values never enter `tend.json`.
|
||||
The singleton example follows the same split: its shared root-only environment
|
||||
file omits the configured listen key, the installed unit owns the live address,
|
||||
and Tend supplies only the transient candidate address. This prevents a shared
|
||||
environment file from overriding the isolated candidate port.
|
||||
environment file from overriding the isolated candidate port. Its imported
|
||||
Caddy handler is also managed from one reviewed template. Tend temporarily
|
||||
routes the canonical origin to the proven candidate while the fixed-address
|
||||
unit restarts, then returns traffic to that unit only after it passes its local
|
||||
checks.
|
||||
|
||||
Production configuration belongs outside the source checkout, owned by root,
|
||||
and not group- or world-writable. The Caddy handler template is an entire
|
||||
imported handler fragment; the enclosing site, matchers, and routing precedence
|
||||
remain operator-owned.
|
||||
|
||||
`event_log` is a per-service, root-owned JSONL evidence stream below that
|
||||
service's release root. Grant an Observatory agent read access explicitly; do
|
||||
not make the release root broadly readable. `activation_window_seconds` keeps
|
||||
canonical routed probes active after Caddy reload and keeps the previous
|
||||
blue/green slot—or the singleton handoff candidate—under health/readiness
|
||||
observation until the activation is recorded.
|
||||
|
||||
`server/` demonstrates the schema-2 receive policy, forced OpenSSH command,
|
||||
restricted sudo entry, two independent service configurations, and secret-file
|
||||
placement. The values are placeholders, not an installation script.
|
||||
|
||||
@@ -7,9 +7,11 @@
|
||||
"root": "/opt/example-site",
|
||||
"lock_file": "/run/lock/tend-deploy.lock",
|
||||
"state_file": "/opt/example-site/tend-state.json",
|
||||
"event_log": "/opt/example-site/deployment-events.jsonl",
|
||||
"health_path": "/healthz",
|
||||
"readiness_path": "/readyz",
|
||||
"candidate_timeout_seconds": 30,
|
||||
"activation_window_seconds": 10,
|
||||
"smoke": [{ "path": "/", "contains": "Example site" }],
|
||||
"public_smoke": [{ "url": "https://example.test/", "contains": "Example site" }],
|
||||
"blue_green": {
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
# Managed by Tend. The enclosing site and route matchers remain operator-owned.
|
||||
reverse_proxy {{UPSTREAM}}
|
||||
@@ -0,0 +1,2 @@
|
||||
# Managed by Tend. The enclosing site and route matchers remain operator-owned.
|
||||
reverse_proxy {{UPSTREAM}}
|
||||
@@ -7,9 +7,11 @@
|
||||
"root": "/opt/docs-site",
|
||||
"lock_file": "/run/lock/tend-deploy.lock",
|
||||
"state_file": "/opt/docs-site/tend-state.json",
|
||||
"event_log": "/opt/docs-site/deployment-events.jsonl",
|
||||
"health_path": "/healthz",
|
||||
"readiness_path": "/readyz",
|
||||
"candidate_timeout_seconds": 30,
|
||||
"activation_window_seconds": 10,
|
||||
"smoke": [{ "path": "/", "contains": "Documentation" }],
|
||||
"public_smoke": [{ "url": "https://docs.example.test/", "contains": "Documentation" }],
|
||||
"singleton": {
|
||||
@@ -18,7 +20,10 @@
|
||||
"candidate_address": "127.0.0.1:18102",
|
||||
"listen_env": "DOCS_LISTEN",
|
||||
"current_link": "/opt/docs-site/current",
|
||||
"previous_link": "/opt/docs-site/previous"
|
||||
"previous_link": "/opt/docs-site/previous",
|
||||
"caddy_config": "/etc/caddy/Caddyfile",
|
||||
"caddy_handler": "/etc/caddy/docs-site-handler.caddy",
|
||||
"caddy_handler_template": "/etc/tend/caddy/docs-site.template"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,9 +7,11 @@
|
||||
"root": "/opt/example-site",
|
||||
"lock_file": "/run/lock/tend-deploy.lock",
|
||||
"state_file": "/opt/example-site/tend-state.json",
|
||||
"event_log": "/opt/example-site/deployment-events.jsonl",
|
||||
"health_path": "/healthz",
|
||||
"readiness_path": "/readyz",
|
||||
"candidate_timeout_seconds": 30,
|
||||
"activation_window_seconds": 10,
|
||||
"smoke": [{ "path": "/", "contains": "Example site" }],
|
||||
"public_smoke": [{ "url": "https://example.test/", "contains": "Example site" }],
|
||||
"singleton": {
|
||||
@@ -18,7 +20,10 @@
|
||||
"candidate_address": "127.0.0.1:18092",
|
||||
"listen_env": "EXAMPLE_LISTEN",
|
||||
"current_link": "/opt/example-site/current",
|
||||
"previous_link": "/opt/example-site/previous"
|
||||
"previous_link": "/opt/example-site/previous",
|
||||
"caddy_config": "/etc/caddy/Caddyfile",
|
||||
"caddy_handler": "/etc/caddy/example-site-handler.caddy",
|
||||
"caddy_handler_template": "/etc/tend/caddy/example-site.template"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
# Managed by Tend. The enclosing site and route matchers remain operator-owned.
|
||||
reverse_proxy {{UPSTREAM}}
|
||||
@@ -7,9 +7,11 @@
|
||||
"root": "/opt/example-site",
|
||||
"lock_file": "/run/lock/tend-deploy.lock",
|
||||
"state_file": "/opt/example-site/tend-state.json",
|
||||
"event_log": "/opt/example-site/deployment-events.jsonl",
|
||||
"health_path": "/healthz",
|
||||
"readiness_path": "/readyz",
|
||||
"candidate_timeout_seconds": 30,
|
||||
"activation_window_seconds": 10,
|
||||
"smoke": [{ "path": "/", "contains": "Example site" }],
|
||||
"public_smoke": [{ "url": "https://example.test/", "contains": "Example site" }],
|
||||
"singleton": {
|
||||
@@ -18,7 +20,10 @@
|
||||
"candidate_address": "127.0.0.1:18092",
|
||||
"listen_env": "EXAMPLE_LISTEN",
|
||||
"current_link": "/opt/example-site/current",
|
||||
"previous_link": "/opt/example-site/previous"
|
||||
"previous_link": "/opt/example-site/previous",
|
||||
"caddy_config": "/etc/caddy/Caddyfile",
|
||||
"caddy_handler": "/etc/caddy/example-site-handler.caddy",
|
||||
"caddy_handler_template": "/etc/tend/caddy/example-site.template"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user