feat(deploy): add stage tier — park-buzi as the staging booth

Model the staging-vs-production split that fleet-deployment-komodo flagged as open.
Three tiers: dev (working, no booth) -> stage (staging booth park-buzi, real-world
test) -> main (production, manual + pinned).

- build-images.yml: trigger on [dev, stage, main]. The tag computation is already
  branch-derived, so :stage / :stage-<sha> build with no other change.
- komodo/resources.toml: park-buzi now branch=stage + TAG=stage-<sha> (pinned;
  no webhook even on staging). BACKUP_KEY already wired as a per-booth secret.
- komodo/README.md: a Promotion (dev->stage->main) section; per-booth secret list
  now includes backup_key; hard-rule #1 generalised to pinned <branch>-<sha>.
- wiki: fleet-deployment-komodo open-item resolved + a Promotion-tiers table;
  deploy-trigger choice generalised; container-deployment tag list gains :stage.

Promotion is a merge: when dev is ready, merge dev->stage, CI builds the image,
bump TAG=stage-<sha> in resources.toml, deploy from Core. stage is branched from
dev HEAD so the first real-world test carries the full current app. Per-booth
secrets must pre-exist in Core; migrations run at boot so a promotion auto-migrates
the staging ledger (where a bad migration is caught before production).

Claude-Session: https://claude.ai/code/session_01Xcm6ikLgGoCxxHrxtjkk5V
This commit is contained in:
2026-06-29 13:11:35 +02:00
parent 84f00db48b
commit 381046190b
6 changed files with 93 additions and 27 deletions
+14
View File
@@ -1962,3 +1962,17 @@ komodo/.env.komodo.example as the ONLY backup env var — target+retention are U
trimmed to just BACKUP_KEY. build/lint/test green (218 server tests, incl. retention persist/reset/negative
+ updated status shape). NOTE: dev API process was down after this round (live process, not code) — verified
via the full test harness, not a live click-through this time. Updated [[backup-recovery]] as-built.
## [2026-06-29] decision | Staging tier: dev → stage → main; park-buzi is the staging booth
Modelled the staging-vs-production split that fleet-deployment-komodo flagged as open. THREE tiers: dev
(working, no booth runs it) → stage (staging booth park-buzi, real-world test) → main (production, manual+
pinned). park-buzi tracks the `stage` branch + `:stage` image but is deployed MANUAL + PINNED (TAG=stage-<sha>,
NO webhook — we hold the no-moving-tag-on-a-booth line even on staging, rejecting the earlier 'webhook on
staging' sketch). Promotion = merge dev→stage when confident → CI builds :stage/:stage-<sha> → bump TAG in
resources.toml → deploy from Core. `stage` branched from dev HEAD (84f00db) so the first real-world test
carries the full current app. Changes: build-images.yml triggers on [dev, stage, main] (tagging already
branch-derived, so :stage works with no other change); komodo/resources.toml park-buzi branch=stage +
TAG=stage-84f00db; komodo/README.md promotion section + per-booth secret list now includes backup_key;
fleet-deployment-komodo open-item resolved + new 'Promotion tiers' table; container-deployment tag list +
:stage. Per-booth secrets (jwt/event_signing/backup) must pre-exist in Core for park-buzi; migrations run at
boot so a promotion auto-migrates the staging ledger (where a bad migration is caught before prod).