Roadmap
The goal: rehearse every gobank release on preprod with a fresh copy of prod's data, gate it, then promote the same release to prod. Blue/green inside the box first; expand/contract migrations through gobank-db.
Prerequisites in gobank
- Demo resumes from an existing PostgreSQL database instead of dropping all tables on start (nothing below is real until this lands)
- Version and applied migrations as JSON on the about endpoint
- Schema applied through gobank-db
Apply(expand / cutover / contract)
Stories
- Story 1 —
up,down,statusfor a named environment (port of the bash scripts, tested behind interfaces) - Story 1a —
ui: environment states and controls on a polling page - Story 1b —
uias a status-and-down console on hydrogen (gokrazy): no toolchain there, so nothing that needs a release is offered - Story 1c —
upfrom a release store:buildon the laptop putsdemofor linux/amd64 and arm64 (built where the charts-fork replace applies) intobuild/releases,task pushcopies the latest into hydrogen's/perm/gobank-deploy/releases, and-storemakes that the Deployer's Builder there. Create / Redeploy on hydrogen deploy what was last pushed; pushing an older version again is a rollback - Story 1d — Versions on the page and in
status: what each environment runs against what the nextupwould deploy - Story 1e — First workflow on gobank-workflow: the temporary demo environment (create, serve until expiry, remove), resumed from the server's expiry label after a restart. Run records in memory until the go-postgres store lands (issue #1)
- Story 2 — Snapshot: copy prod's database into preprod over ssh
- Story 3 — Gates: version, schema, invariants (account count and total balances unchanged, trial balance balances), BFF journeys
- Story 4 — Rehearse then promote: preprod on a fresh snapshot, gates, same release to prod
- Story 5 — Blue/green in the box: second systemd unit, port switch, rollback is redeploying the previous release
- Story 6 — Run on gokrazy (pure Go; ssh agent replaced by a key on
the appliance):
GOBANK_DEPLOY_SSH_KEYfrom the gokrazy secrets, known_hosts and the release store on /perm. Done by 1b + 1c
Later
- Separate database box: the app's memory share rises from 50% of the
box (see
appShareWithLocalPostgres) once PostgreSQL is elsewhere; logical replication for Postgres version upgrades and zone moves (researched in gobank-db) - Masking step in the snapshot once real PII exists
- Kubernetes targets (gobank Phase 3) behind the same vocabulary