This repository has been archived on 2026-08-19. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
tend/examples/README.md
T
gamertan 9d9fc83dd0 feat: publish Tend v0.2 Preview 2 source
Export the reviewed allowlisted snapshot from private source commit 8aab3db43f35e6a49aa497f45d73701b13fc9f32 and tree 992132ea4703437dc13ffdbb04a077816c02caf9. This includes routed singleton continuity, deployment evidence, strict schema-2 configuration, restricted transport, and the independently compilable public-tree guard.

AI-Assisted: OpenAI Codex
Signed-off-by: Cole Speelman <crspeelman@gmail.com>
2026-08-18 06:40:58 -04:00

2.0 KiB

Reusable Tend examples

This subtree is licensed 0BSD so an operator can copy and adapt it without bringing the Tend program's AGPL license into an application configuration.

The blue/green example expects one separately reviewed environment file that the two installed slots and transient validation use consistently:

# /etc/tend/environment/example-site.env
APP_SECRET=replace-on-server

The blue/green systemd slot units then read the nonsecret listen address from /etc/tend/slots/example-site-blue.env or -green.env; Tend overrides only the isolated candidate address. Secret values never enter tend.json.

The singleton example follows the same split: its shared root-only environment file omits the configured listen key, the installed unit owns the live address, and Tend supplies only the transient candidate address. This prevents a shared environment file from overriding the isolated candidate port. Its imported Caddy handler is also managed from one reviewed template. Tend temporarily routes the canonical origin to the proven candidate while the fixed-address unit restarts, then returns traffic to that unit only after it passes its local checks.

Production configuration belongs outside the source checkout, owned by root, and not group- or world-writable. The Caddy handler template is an entire imported handler fragment; the enclosing site, matchers, and routing precedence remain operator-owned.

event_log is a per-service, root-owned JSONL evidence stream below that service's release root. Grant an Observatory agent read access explicitly; do not make the release root broadly readable. activation_window_seconds keeps canonical routed probes active after Caddy reload and keeps the previous blue/green slot—or the singleton handoff candidate—under health/readiness observation until the activation is recorded.

server/ demonstrates the schema-2 receive policy, forced OpenSSH command, restricted sudo entry, two independent service configurations, and secret-file placement. The values are placeholders, not an installation script.